Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all 2798 articles
Browse latest View live

Malware help thread went inactive

$
0
0
Couldn't reply to my existing thread. here are the logs i was told to provide from AdwCleaner and FRST:

# AdwCleaner v5.008 - Logfile created 25/09/2015 at 11:45:47
# Updated 18/09/2015 by Xplode
# Database : 2015-09-23.1 [Server]
# Operating system : Windows 10 Home (x64)
# Username : Chris - CHRIS-PC
# Running from : C:\Users\Chris\Downloads\AdwCleaner(1).exe
# Option : Cleaning
# Support : Forum - ToolsLib

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[-] Folder Deleted : C:\Users\Chris\AppData\Local\Mobogenie
[-] Folder Deleted : C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xampi2j7.default\StumbleUpon
[-] Folder Deleted : C:\Users\Chris\Documents\Mobogenie

***** [ Files ] *****

[-] File Deleted : C:\Users\Chris\daemonprocess.txt
[-] File Deleted : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
[-] File Deleted : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
[-] File Deleted : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
[-] File Deleted : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
[-] File Deleted : C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xampi2j7.default\searchplugins\bing-lavasoft.xml
[-] File Deleted : C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
[-] File Deleted : C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
[-] File Deleted : C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
[-] File Deleted : C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
[-] Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Key Deleted : HKCU\Software\IGearSettings
[-] Key Deleted : HKCU\Software\AppDataLow\Software\adawarebp
[!] Key Not Deleted : [x64] HKCU\Software\IGearSettings
[!] Key Not Deleted : HKU\S-1-5-21-802191358-1188049126-1924190515-1000\Software\AppDataLow\Software\adawarebp
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKU\S-1-5-21-802191358-1188049126-1924190515-1000\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[!] Key Not Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
[!] Key Not Deleted : HKU\S-1-5-21-802191358-1188049126-1924190515-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[!] Key Not Deleted : HKU\S-1-5-21-802191358-1188049126-1924190515-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}

***** [ Web browsers ] *****

[-] [C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : netlfix.com
[-] [C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : netflix.com
[-] [C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com

*************************

:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4860 bytes] ##########


Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:23-09-2015
Ran by Chris (administrator) on CHRIS-PC (25-09-2015 12:02:11)
Running from C:\Users\Chris\Downloads
Loaded Profiles: Chris (Available Profiles: Chris & Jeff)
Platform: Windows 10 Home (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_185.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_185.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634872 2015-08-26] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-802191358-1188049126-1924190515-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2899136 2015-08-19] (Valve Corporation)
HKU\S-1-5-21-802191358-1188049126-1924190515-1000\...\Run: [GoogleChromeAutoLaunch_4E6299B33FA0592A57BB7C6E94F010D2] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944 2015-09-23] (Google Inc.)
HKU\S-1-5-21-802191358-1188049126-1924190515-1000\...\Run: [Spotify Web Helper] => C:\Users\Chris\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2025016 2015-09-20] (Spotify Ltd)
HKU\S-1-5-21-802191358-1188049126-1924190515-1000\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1411344 2015-09-12] (Lavasoft)
HKU\S-1-5-21-802191358-1188049126-1924190515-1000\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-802191358-1188049126-1924190515-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-802191358-1188049126-1924190515-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-09-11] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-09-11] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-09-11] (Microsoft Corporation)
Startup: C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Citrix Receiver.lnk [2015-06-19]
ShortcutTarget: Citrix Receiver.lnk -> C:\Users\Chris\AppData\Local\Citrix\SelfService\Program Files\SelfServicePlugin.exe (No File)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicyUsers\S-1-5-21-802191358-1188049126-1924190515-1005\User: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: 127.0.0.1 nlsk.neulion.com
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{1ac715e4-524d-40eb-8e44-73e6ef19aed1}: [DhcpNameServer] 75.75.75.75 75.75.76.76

Internet Explorer:
==================
HKU\S-1-5-21-802191358-1188049126-1924190515-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-802191358-1188049126-1924190515-1000 -> DefaultScope {53EF7820-ECA2-4E78-9D02-A80D6A1A9512} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=903578&p={searchTerms}
SearchScopes: HKU\S-1-5-21-802191358-1188049126-1924190515-1000 -> {53EF7820-ECA2-4E78-9D02-A80D6A1A9512} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=903578&p={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-08-04] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-09-11] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18] (Adobe Systems Incorporated)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2015-08-04] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-30] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll [2013-08-28] (Perfect World Entertainment Inc)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-09-11] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-30] (Oracle Corporation)
DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xampi2j7.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Bing
FF DefaultSearchEngine.US: Google
FF SelectedSearchEngine: Bing
FF Homepage: google.com
FF Keyword.URL: hxxps://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=903578&p=
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-22] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-22] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-30] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-04-25] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2013-07-10] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-08-25] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-08-25] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll [2013-08-28] (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2012-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-802191358-1188049126-1924190515-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Chris\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2013-08-29] (Citrix Online)
FF Extension: Blue Fox - C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xampi2j7.default\Extensions\{241aae70-0022-11de-87af-0800200c9a66} [2014-08-01]
FF Extension: StumbleUpon - C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xampi2j7.default\Extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi [2012-09-04]
FF Extension: Adblock Plus - C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\xampi2j7.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-12]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.99\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.99\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.99\pdf.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll => No File
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Microsoft Office 2013) - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Profile: C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-08-25]
CHR Extension: (Google Drive) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-25]
CHR Extension: (YouTube) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-25]
CHR Extension: (Adblock Plus) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-02-05]
CHR Extension: (Google Search) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-25]
CHR Extension: (Google Docs Offline) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-07]
CHR Extension: (Norton Identity Safe) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2014-08-08]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-25]
CHR Extension: (Gmail) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-25]
CHR HKLM\...\Chrome\Extension: [hkhkiakolggnnicallabhkobalpeplpi] - <no Path/update_url>
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [hkhkiakolggnnicallabhkobalpeplpi] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
S4 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88424 2013-08-28] (Perfect World Entertainment Inc)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2774104 2015-09-11] (Microsoft Corporation)
S4 DAUpdaterSvc; C:\Program Files (x86)\Steam\steamapps\common\Dragon Age Ultimate Edition\bin_ship\DAUpdaterSvc.Service.exe [25832 2014-05-09] (BioWare)
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [238376 2015-08-07] (EasyAntiCheat Ltd)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155192 2015-08-26] (NVIDIA Corporation)
R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe [2751760 2015-09-12] (Lavasoft Limited)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-07-30] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-08-26] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544568 2015-08-26] (NVIDIA Corporation)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 SearchProtectionService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [16656 2015-09-12] ()
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-07-30] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-07-30] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 cancel; C:\Program Files (x86)\MSI\Super-Charger\cancel_64.sys [16184 2010-05-21] (Windows (R) Win 7 DDK provider)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-07-30] (Microsoft Corporation)
S3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [14136 2010-07-12] (MSI)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-08-26] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2014-08-02] (Scarlet.Crush Productions)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
U5 vwifimp; C:\Windows\System32\Drivers\vwifimp.sys [39936 2015-07-10] (Microsoft Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 idsvc; no ImagePath
S3 NAVENG; \??\C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\VirusDefs\20150911.017\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\VirusDefs\20150911.017\EX64.SYS [X]
S3 VBoxNetFlt; \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-25 12:02 - 2015-09-25 12:02 - 00021527 _____ C:\Users\Chris\Downloads\FRST.txt
2015-09-25 12:01 - 2015-09-25 12:02 - 00000000 ____D C:\FRST
2015-09-25 12:01 - 2015-09-25 12:01 - 00000000 ____D C:\Users\Chris\Downloads\FRST-OlderVersion
2015-09-25 11:49 - 2015-09-25 11:49 - 00016148 _____ C:\WINDOWS\system32\CHRIS-PC_Chris_HistoryPrediction.bin
2015-09-25 11:44 - 2015-09-25 11:45 - 00000000 ____D C:\AdwCleaner
2015-09-25 11:44 - 2015-09-25 11:44 - 01662976 _____ C:\Users\Chris\Downloads\AdwCleaner(1).exe
2015-09-25 11:39 - 2015-09-25 11:39 - 01110960 _____ (Symantec Corporation) C:\Users\Chris\Downloads\NortonN360PDownloader.exe
2015-09-22 06:11 - 2015-09-22 06:11 - 18819272 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2015-09-21 14:42 - 2015-09-25 11:41 - 00001001 _____ C:\Users\Public\Desktop\Guild Wars 2 Port Test.lnk
2015-09-21 14:41 - 2015-09-21 14:42 - 26068984 _____ (ArenaNet) C:\Users\Chris\Downloads\Gw2Setup.exe
2015-09-20 16:26 - 2015-09-20 16:26 - 01381888 _____ C:\Users\Chris\Downloads\2015 Beer Pool Standings.xls
2015-09-19 17:49 - 2015-09-19 17:49 - 00016148 _____ C:\WINDOWS\system32\CHRIS-PC_Jeff_HistoryPrediction.bin
2015-09-19 17:49 - 2015-09-19 17:49 - 00000000 ____D C:\WMSDK
2015-09-19 17:48 - 2015-09-19 17:48 - 06756704 _____ (Microsoft Corporation) C:\Users\Chris\Downloads\mtppk12.exe
2015-09-19 17:36 - 2015-09-19 17:36 - 19298440 _____ (One Click Root) C:\Users\Chris\Downloads\OneClickRoot.exe
2015-09-14 19:30 - 2015-09-14 19:30 - 01114112 _____ C:\Users\Chris\Downloads\MicrosoftFixit50440.msi
2015-09-14 19:22 - 2015-09-14 19:22 - 01112064 _____ C:\Users\Chris\Downloads\MicrosoftFixit50409.msi
2015-09-12 16:01 - 2015-09-12 16:01 - 00958104 _____ C:\Users\Chris\Downloads\Norton_Removal_Tool.exe
2015-09-12 15:42 - 2015-09-25 12:01 - 02192384 _____ (Farbar) C:\Users\Chris\Downloads\FRST64.exe
2015-09-12 15:42 - 2015-09-12 15:42 - 01660416 _____ C:\Users\Chris\Downloads\AdwCleaner.exe
2015-09-09 23:22 - 2015-09-09 23:22 - 00000000 ____D C:\Program Files\Common Files\AV
2015-09-09 23:17 - 2015-09-12 15:38 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Lavasoft
2015-09-09 23:17 - 2015-09-10 18:27 - 00002888 _____ C:\WINDOWS\SysWOW64\LavasoftTcpServiceOff.ini
2015-09-09 23:17 - 2015-09-10 18:27 - 00002888 _____ C:\WINDOWS\system32\LavasoftTcpServiceOff.ini
2015-09-09 23:17 - 2015-09-09 23:17 - 00425744 _____ (Lavasoft Limited) C:\WINDOWS\system32\LavasoftTcpService64.dll
2015-09-09 23:17 - 2015-09-09 23:17 - 00345360 _____ (Lavasoft Limited) C:\WINDOWS\SysWOW64\LavasoftTcpService.dll
2015-09-09 23:17 - 2015-09-09 23:17 - 00000000 ____D C:\Users\Chris\AppData\Local\Lavasoft
2015-09-09 23:17 - 2015-09-09 23:17 - 00000000 ____D C:\Program Files (x86)\Lavasoft
2015-09-09 23:16 - 2015-09-12 15:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2015-09-09 23:15 - 2015-09-09 23:15 - 00001460 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2015-09-09 23:15 - 2015-09-09 23:15 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2015-09-09 23:15 - 2015-09-09 23:15 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-09-09 23:15 - 2015-09-09 23:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2015-09-09 23:15 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean64.exe
2015-09-09 23:14 - 2015-09-09 23:22 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-09-09 23:14 - 2015-09-09 23:17 - 00000000 ____D C:\ProgramData\Lavasoft
2015-09-09 23:13 - 2015-09-09 23:14 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Chris\Downloads\spybot-2.4.exe
2015-09-09 23:13 - 2015-09-09 23:14 - 02012464 _____ C:\Users\Chris\Downloads\Adaware_Installer.exe
2015-09-09 23:01 - 2015-09-09 23:01 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2015-09-09 22:59 - 2015-09-09 22:59 - 00000000 ____D C:\WINDOWS\pss
2015-09-08 20:30 - 2015-09-01 21:20 - 00077400 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-09-08 20:30 - 2015-09-01 20:25 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-09-08 20:30 - 2015-09-01 20:25 - 01382912 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-09-08 20:30 - 2015-08-27 02:36 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-08 20:30 - 2015-08-27 02:32 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-09-08 20:30 - 2015-08-27 02:04 - 21874688 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-09-08 20:30 - 2015-08-27 01:59 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-08 20:30 - 2015-08-27 01:55 - 24594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-09-08 20:30 - 2015-08-27 01:54 - 00541248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-09-08 20:30 - 2015-08-27 01:54 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-08 20:30 - 2015-08-27 01:51 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-08 20:30 - 2015-08-27 01:51 - 01774592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-08 20:30 - 2015-08-27 01:49 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-08 20:30 - 2015-08-27 01:47 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-08 20:30 - 2015-08-27 01:43 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-08 20:30 - 2015-08-27 01:43 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-08 20:30 - 2015-08-27 01:42 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-08 20:30 - 2015-08-27 01:42 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-09-08 20:30 - 2015-08-27 01:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2015-09-08 20:30 - 2015-08-27 01:42 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-08 20:30 - 2015-08-27 01:39 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-08 20:30 - 2015-08-27 01:23 - 19324416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-09-08 20:30 - 2015-08-27 01:23 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-08 20:30 - 2015-08-27 01:16 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-09-08 20:30 - 2015-08-27 01:16 - 02153472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-08 20:30 - 2015-08-27 01:16 - 01612288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-08 20:30 - 2015-08-27 01:12 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-08 20:30 - 2015-08-27 01:12 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-08 20:30 - 2015-08-27 01:11 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-08 20:30 - 2015-08-27 01:11 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-08 20:30 - 2015-08-27 01:09 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-08 20:30 - 2015-08-27 01:08 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-09-04 19:42 - 2015-09-04 22:37 - 00000000 ____D C:\Users\Jeff\AppData\Local\Deployment
2015-09-01 21:08 - 2015-08-25 10:18 - 00574072 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2015-09-01 21:06 - 2015-08-25 14:38 - 42840184 _____ C:\WINDOWS\system32\nvcompiler.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 37819184 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 22559352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 18569336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 16646624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 15630616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 14945552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 13667032 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 12192048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 02354808 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 02105976 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 01898104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435582.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 01558648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435582.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 01178576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 01075320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 01064752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 01001440 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 00986232 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 00945272 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 00176904 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 00155976 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 00150648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 00128512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2015-09-01 21:06 - 2015-08-25 14:38 - 00040280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2015-09-01 20:57 - 2015-08-11 00:52 - 00069416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2015-08-28 16:44 - 2015-08-28 16:44 - 00000221 _____ C:\Users\Chris\Desktop\Mount & Blade Warband.url
2015-08-28 07:53 - 2015-08-28 07:58 - 00000000 ____D C:\Users\Jeff\AppData\Local\Comms
2015-08-28 07:31 - 2015-08-20 02:07 - 08019296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-08-28 07:31 - 2015-08-20 02:02 - 22324656 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-08-28 07:31 - 2015-08-20 01:16 - 20857848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-08-28 07:31 - 2015-08-20 01:13 - 02235904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-08-28 07:31 - 2015-08-18 03:56 - 02498808 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-28 07:31 - 2015-08-18 03:54 - 01396064 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-08-28 07:31 - 2015-08-18 03:27 - 01771592 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-08-28 07:31 - 2015-08-18 03:24 - 00963920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-08-28 07:31 - 2015-08-18 03:12 - 02225664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-08-28 07:31 - 2015-08-18 03:04 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-08-28 07:31 - 2015-08-18 02:52 - 01888768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-08-28 07:31 - 2015-08-18 02:29 - 01593344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-08-28 07:30 - 2015-08-20 02:06 - 00609592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-08-28 07:30 - 2015-08-20 01:26 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-08-28 07:30 - 2015-08-20 01:21 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-28 07:30 - 2015-08-18 03:55 - 00373072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2015-08-28 07:30 - 2015-08-18 03:13 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
2015-08-28 07:30 - 2015-08-18 03:13 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2015-08-28 07:30 - 2015-08-18 03:07 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-08-28 07:30 - 2015-08-18 03:04 - 01234944 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2015-08-28 07:30 - 2015-08-18 02:59 - 01294336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll
2015-08-28 07:30 - 2015-08-18 02:59 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2015-08-28 07:30 - 2015-08-18 02:58 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2015-08-28 07:30 - 2015-08-18 02:58 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWCN.dll
2015-08-28 07:30 - 2015-08-18 02:58 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWCN.dll
2015-08-28 07:30 - 2015-08-18 02:58 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnNetsh.dll
2015-08-28 07:30 - 2015-08-18 02:57 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2015-08-28 07:30 - 2015-08-18 02:56 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2015-08-28 07:30 - 2015-08-18 02:55 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-08-28 07:30 - 2015-08-18 02:54 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2015-08-28 07:30 - 2015-08-18 02:54 - 00247296 _____ C:\WINDOWS\system32\facecredentialprovider.dll
2015-08-28 07:30 - 2015-08-18 02:50 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-08-28 07:30 - 2015-08-18 02:49 - 01061888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2015-08-28 07:30 - 2015-08-18 02:49 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2015-08-28 07:30 - 2015-08-18 02:49 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2015-08-28 07:30 - 2015-08-18 02:36 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
2015-08-28 07:30 - 2015-08-18 02:35 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2015-08-28 07:30 - 2015-08-18 02:35 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWCN.dll
2015-08-28 07:30 - 2015-08-18 02:34 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2015-08-28 07:30 - 2015-08-18 02:26 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2015-08-28 07:30 - 2015-08-18 00:44 - 00008847 _____ C:\WINDOWS\system32\ResPriHMImageList
2015-08-26 23:28 - 2015-08-26 23:54 - 00061197 _____ C:\Users\Jeff\Documents\Cheat Sheet.xlsx
2015-08-26 23:03 - 2015-08-26 23:03 - 00037030 _____ C:\Users\Jeff\Downloads\rotoviz_cheat_sheet.csv
2015-08-26 22:12 - 2015-08-26 22:12 - 02556416 _____ C:\Users\Jeff\Downloads\15app_J1 (1).xls
2015-08-26 22:11 - 2015-08-26 22:12 - 02556416 _____ C:\Users\Jeff\Downloads\15app_J1.xls

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-25 11:50 - 2013-08-25 18:20 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-25 11:50 - 2012-09-04 21:31 - 00000000 ____D C:\Program Files (x86)\Steam
2015-09-25 11:49 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-09-25 11:48 - 2015-07-30 07:55 - 00347582 _____ C:\WINDOWS\PFRO.log
2015-09-25 11:48 - 2015-07-10 08:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-25 11:48 - 2015-07-10 08:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-09-25 11:48 - 2012-09-05 08:15 - 00000000 ____D C:\ProgramData\NVIDIA
2015-09-25 11:47 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-09-25 11:47 - 2015-07-10 05:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-09-25 11:45 - 2015-07-30 08:05 - 00000000 ____D C:\Users\Chris
2015-09-25 11:36 - 2014-08-05 20:11 - 00000372 _____ C:\WINDOWS\Tasks\WpsUpdateTask_Jeff.job
2015-09-25 11:36 - 2014-08-05 20:11 - 00000372 _____ C:\WINDOWS\Tasks\WpsNotifyTask_Jeff.job
2015-09-25 11:27 - 2014-05-01 19:17 - 00000398 _____ C:\WINDOWS\Tasks\WpsNotifyTask_Chris.job
2015-09-25 11:14 - 2013-08-25 18:20 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-25 11:11 - 2014-05-01 19:17 - 00000398 _____ C:\WINDOWS\Tasks\WpsUpdateTask_Chris.job
2015-09-25 11:11 - 2012-09-05 18:04 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-09-24 19:15 - 2013-08-25 18:20 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-09-24 18:38 - 2013-03-11 18:50 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-09-23 19:18 - 2013-02-03 19:33 - 00000000 ____D C:\Users\Chris\AppData\Local\CrashDumps
2015-09-23 19:18 - 2012-09-05 18:20 - 00000000 ____D C:\Users\Chris\AppData\Roaming\TS3Client
2015-09-21 19:41 - 2015-07-10 06:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-09-21 10:24 - 2013-08-29 09:22 - 00000000 ____D C:\Users\Chris\AppData\Local\Citrix
2015-09-20 20:36 - 2014-01-22 16:50 - 00000000 ____D C:\Users\Chris\AppData\Local\Spotify
2015-09-20 20:27 - 2014-01-22 16:49 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Spotify
2015-09-20 16:26 - 2015-07-30 18:59 - 00000000 ____D C:\Users\Chris\AppData\Local\Packages
2015-09-19 17:49 - 2015-07-30 08:05 - 00000000 ____D C:\Users\Jeff
2015-09-19 12:16 - 2012-09-07 19:09 - 00000000 ____D C:\Users\Chris\Documents\Guild Wars 2
2015-09-19 12:02 - 2013-10-05 03:13 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Guild Wars 2
2015-09-19 11:52 - 2015-08-07 18:51 - 00204056 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
2015-09-18 00:55 - 2014-09-03 23:04 - 00000000 ____D C:\Users\Jeff\AppData\Roaming\CarbonPoker
2015-09-18 00:45 - 2015-08-07 07:55 - 00000000 ____D C:\Users\Jeff\AppData\Local\Packages
2015-09-17 11:09 - 2013-08-25 18:20 - 00003982 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-17 11:09 - 2013-08-25 18:20 - 00003750 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-09-14 23:04 - 2013-08-25 18:20 - 00000000 ____D C:\Users\Chris\AppData\Local\Google
2015-09-12 16:18 - 2012-10-09 21:13 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2015-09-12 16:18 - 2012-10-09 21:06 - 00000000 ____D C:\ProgramData\Norton
2015-09-12 16:17 - 2015-07-02 08:07 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton 360
2015-09-11 09:53 - 2015-03-31 19:38 - 00000000 ____D C:\Users\Jeff\AppData\Local\CrashDumps
2015-09-11 03:03 - 2015-07-10 08:20 - 04980648 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-09-11 03:00 - 2015-07-10 09:14 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-11 03:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-09-10 21:02 - 2013-08-18 03:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-09-09 23:39 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-09-08 20:19 - 2015-07-10 05:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-09-01 21:08 - 2015-07-30 07:57 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-09-01 21:08 - 2015-01-14 21:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-08-30 18:47 - 2015-07-23 04:02 - 11188880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2015-08-28 17:08 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\rescache
2015-08-28 16:55 - 2012-11-19 01:00 - 00000000 ____D C:\Program Files (x86)\Pando Networks
2015-08-28 16:55 - 2012-09-04 21:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-28 16:53 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-08-28 16:44 - 2015-06-03 22:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-28 16:34 - 2015-08-01 12:36 - 00000000 ____D C:\Program Files\InterActual
2015-08-27 19:02 - 2015-06-23 21:25 - 00007618 _____ C:\Users\Chris\AppData\Local\Resmon.ResmonCfg
2015-08-26 20:37 - 2015-01-14 21:11 - 01423120 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2015-08-26 20:37 - 2015-01-14 21:11 - 01316000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2015-08-26 20:36 - 2015-01-14 21:11 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2015-08-26 20:36 - 2015-01-14 21:11 - 01710568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2015-08-26 18:37 - 2012-09-04 20:20 - 134753440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

==================== Files in the root of some directories =======

2013-02-03 14:53 - 2013-02-03 14:53 - 0703117 _____ () C:\Users\Chris\AppData\Roaming\technic-launcher.jar
2013-01-17 08:14 - 2013-01-17 08:14 - 0000093 _____ () C:\Users\Chris\AppData\Local\fusioncache.dat
2015-06-23 21:25 - 2015-08-27 19:02 - 0007618 _____ () C:\Users\Chris\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
C:\Users\Chris\AppData\Local\Temp\Gw2.exe
C:\Users\Chris\AppData\Local\Temp\sqlite3.dll
C:\Users\Jeff\AppData\Local\Temp\javasysmo4932160886512875812.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-09-21 07:57

==================== End of FRST.txt ============================

cmd.exe on the fritz still even after minimized img system restore

$
0
0
cmd.exe will not stay open when I try to run programs, this is with elevated privileges and without either way no luck. I suspect a backdoor is on the computer because this is a newly installed os. anyone???? The command prompt flashes on the screen then closes whenever i try to run an application. If I open a cmd.exe window it will stay open but doesnt recognize the commands I type in. ????????:banghead:

dds.txt is below



DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17840
Run by at 0:26:36 on 2015-09-26
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.7659.4611 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: Microsoft Security Essentials *Enabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\system32\atieclxx.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
C:\Windows\system32\svchost.exe -k WbioSvcGroup
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe
C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Browny02\BrYNSvc.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\system32\prevhost.exe
C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\WmiApSrv.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
C:\Windows\system32\SearchFilterHost.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: Skype for Business Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\office15\OCHelper.dll
BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL
BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\office15\GROOVEEX.DLL
uRun: [GoogleChromeAutoLaunch_8444C81AF347914E6C73A77AA14C32B9] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
mRun: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
mRun: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
StartupFolder: C:\Users\Brooke\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\SENDTO~1.LNK - C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\office15\OCHelper.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{0A114AE5-11F7-43F1-9E6A-A5FFC53AD917} : DHCPNameServer = 192.168.2.1
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.99\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Skype for Business Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL
x64-BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2011-3-4 78976]
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2011-3-4 38528]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2015-3-4 280376]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2015-9-24 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-4-2 204288]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-4-2 365568]
R2 ClickToRunSvc;Microsoft Office ClickToRun Service;C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe [2015-9-24 2774104]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-4-11 103608]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-4-11 124088]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-2-18 265544]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-2-28 92216]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2011-1-26 30520]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-11-9 26680]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2015-9-24 2375168]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2015-3-4 124568]
R3 amdhub30;AMD USB 3.0 Hub Driver;C:\Windows\System32\drivers\amdhub30.sys [2011-3-18 87168]
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2015-9-24 46136]
R3 amdxhc;AMD USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\amdxhc.sys [2011-3-18 188544]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2010-11-17 115216]
R3 BrYNSvc;BrYNSvc;C:\Program Files (x86)\Browny02\BrYNSvc.exe [2015-9-24 266240]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys [2010-7-28 31088]
R3 hpCMSrv;HP Connection Manager 4.0 Service;C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-2-15 1071160]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-4-30 366544]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2015-9-24 337512]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2015-9-24 428136]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\Windows\System32\drivers\rtl8192ce.sys [2015-9-24 1142376]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2015-9-24 47232]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2015-9-25 114688]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2015-9-25 1255736]
.
=============== Created Last 30 ================
.
2015-09-26 04:24:00 75888 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B3CD29F4-423B-41C2-9E02-AA92B9CAF33F}\offreg.964.dll
2015-09-26 04:18:35 -------- d-----w- C:\Windows\System32\MRT
2015-09-26 00:48:34 -------- d-----w- C:\Windows\Migration
2015-09-26 00:48:33 -------- d-s---w- C:\Windows\System32\CompatTel
2015-09-26 00:48:33 -------- d-----w- C:\Windows\System32\appraiser
2015-09-26 00:47:51 -------- d-----w- C:\Windows\SysWow64\Wat
2015-09-26 00:47:51 -------- d-----w- C:\Windows\System32\Wat
2015-09-25 23:30:11 124624 ----a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2015-09-25 23:30:11 103120 ----a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-09-25 22:56:12 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-09-25 21:22:04 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2015-09-25 19:43:26 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2015-09-25 19:43:26 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2015-09-25 19:43:25 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2015-09-25 19:43:25 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2015-09-25 19:43:24 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2015-09-25 19:43:23 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2015-09-25 19:43:23 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2015-09-25 19:08:15 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2015-09-25 19:08:14 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2015-09-25 19:08:14 5120 ----a-w- C:\Windows\System32\wmi.dll
2015-09-25 18:44:03 99480 ----a-w- C:\Windows\SysWow64\infocardapi.dll
2015-09-25 18:44:03 171160 ----a-w- C:\Windows\System32\infocardapi.dll
2015-09-25 18:44:02 619672 ----a-w- C:\Windows\SysWow64\icardagt.exe
2015-09-25 18:44:02 1389208 ----a-w- C:\Windows\System32\icardagt.exe
2015-09-25 18:44:00 8856 ----a-w- C:\Windows\SysWow64\icardres.dll
2015-09-25 18:44:00 8856 ----a-w- C:\Windows\System32\icardres.dll
2015-09-25 18:43:26 35480 ----a-w- C:\Windows\SysWow64\TsWpfWrp.exe
2015-09-25 18:43:26 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe
2015-09-25 03:03:22 -------- d-----w- C:\Users\Brooke\AppData\Roaming\ControlCenter4
2015-09-25 02:58:44 -------- d-----r- C:\Users\Brooke\ODBA
2015-09-24 22:42:06 -------- d-----w- C:\Brother
2015-09-24 22:39:04 -------- d-----w- C:\ProgramData\Brother
2015-09-24 22:26:19 -------- d-----w- C:\Users\Brooke\AppData\Local\ElevatedDiagnostics
2015-09-24 17:33:55 950272 ----a-w- C:\Windows\System32\perftrack.dll
2015-09-24 17:33:55 91136 ----a-w- C:\Windows\System32\wdi.dll
2015-09-24 17:33:55 29696 ----a-w- C:\Windows\System32\powertracker.dll
2015-09-24 17:33:54 76800 ----a-w- C:\Windows\SysWow64\wdi.dll
2015-09-24 17:26:39 328704 ----a-w- C:\Windows\System32\services.exe
2015-09-24 17:25:50 55296 ----a-w- C:\Windows\System32\dhcpcsvc6.dll
2015-09-24 17:24:21 404992 ----a-w- C:\Windows\System32\tracerpt.exe
2015-09-24 17:24:21 364544 ----a-w- C:\Windows\SysWow64\tracerpt.exe
2015-09-24 17:24:21 113664 ----a-w- C:\Windows\System32\sechost.dll
2015-09-24 17:24:21 104448 ----a-w- C:\Windows\System32\logman.exe
2015-09-24 17:24:20 92160 ----a-w- C:\Windows\SysWow64\sechost.dll
2015-09-24 17:24:20 82944 ----a-w- C:\Windows\SysWow64\logman.exe
2015-09-24 17:24:20 47104 ----a-w- C:\Windows\System32\typeperf.exe
2015-09-24 17:24:19 43008 ----a-w- C:\Windows\System32\relog.exe
2015-09-24 17:24:19 40448 ----a-w- C:\Windows\SysWow64\typeperf.exe
2015-09-24 17:24:19 37888 ----a-w- C:\Windows\SysWow64\relog.exe
2015-09-24 17:24:18 19456 ----a-w- C:\Windows\System32\diskperf.exe
2015-09-24 17:24:18 17408 ----a-w- C:\Windows\SysWow64\diskperf.exe
2015-09-24 17:22:57 1743360 ----a-w- C:\Windows\System32\sysmain.dll
2015-09-24 17:22:56 94656 ----a-w- C:\Windows\System32\drivers\mountmgr.sys
2015-09-24 17:22:53 2560 ----a-w- C:\Windows\System32\drivers\en-US\mountmgr.sys.mui
2015-09-24 17:22:53 11264 ----a-w- C:\Windows\System32\msmmsp.dll
2015-09-24 17:20:24 314880 ----a-w- C:\Windows\SysWow64\webio.dll
2015-09-24 17:20:23 395776 ----a-w- C:\Windows\System32\webio.dll
2015-09-24 17:20:19 878080 ----a-w- C:\Windows\System32\IMJP10K.DLL
2015-09-24 17:20:18 701440 ----a-w- C:\Windows\SysWow64\IMJP10K.DLL
2015-09-24 17:20:12 1031168 ----a-w- C:\Windows\System32\TSWorkspace.dll
2015-09-24 17:20:11 793600 ----a-w- C:\Windows\SysWow64\TSWorkspace.dll
2015-09-24 17:19:53 9728 ----a-w- C:\Windows\System32\Wdfres.dll
2015-09-24 17:19:53 785624 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys
2015-09-24 17:19:53 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys
2015-09-24 17:19:49 185344 ----a-w- C:\Windows\System32\drivers\usbvideo.sys
2015-09-24 17:19:48 100864 ----a-w- C:\Windows\System32\drivers\usbcir.sys
2015-09-24 17:19:46 -------- d-----w- C:\ProgramData\regid.1991-06.com.microsoft
2015-09-24 17:18:17 241152 ----a-w- C:\Windows\System32\pku2u.dll
2015-09-24 17:18:17 186880 ----a-w- C:\Windows\SysWow64\pku2u.dll
2015-09-24 17:16:59 265216 ----a-w- C:\Windows\SysWow64\msnetobj.dll
2015-09-24 17:15:13 683520 ----a-w- C:\Windows\System32\termsrv.dll
2015-09-24 17:14:39 -------- d-----w- C:\Program Files\Microsoft Office 15
2015-09-24 17:12:38 478208 ----a-w- C:\Windows\System32\dpnet.dll
2015-09-24 17:12:38 376832 ----a-w- C:\Windows\SysWow64\dpnet.dll
2015-09-24 17:12:35 156824 ----a-w- C:\Windows\SysWow64\mscorier.dll
2015-09-24 17:12:35 156312 ----a-w- C:\Windows\System32\mscorier.dll
2015-09-24 17:12:34 1943696 ----a-w- C:\Windows\System32\dfshim.dll
2015-09-24 17:12:34 1131664 ----a-w- C:\Windows\SysWow64\dfshim.dll
2015-09-24 17:12:33 81560 ----a-w- C:\Windows\SysWow64\mscories.dll
2015-09-24 17:12:33 73880 ----a-w- C:\Windows\System32\mscories.dll
2015-09-24 17:12:16 142336 ----a-w- C:\Windows\System32\poqexec.exe
2015-09-24 17:12:16 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2015-09-24 17:12:01 404992 ----a-w- C:\Windows\System32\gdi32.dll
2015-09-24 17:12:01 312320 ----a-w- C:\Windows\SysWow64\gdi32.dll
2015-09-24 17:11:16 52736 ----a-w- C:\Windows\System32\basesrv.dll
2015-09-24 17:10:27 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2015-09-24 17:10:27 2048 ----a-w- C:\Windows\System32\tzres.dll
2015-09-24 17:08:42 19968 ----a-w- C:\Windows\System32\drivers\usb8023.sys
2015-09-24 17:06:20 230400 ----a-w- C:\Windows\System32\drivers\portcls.sys
2015-09-24 17:06:20 116736 ----a-w- C:\Windows\System32\drivers\drmk.sys
2015-09-24 17:06:18 828928 ----a-w- C:\Windows\SysWow64\msctf.dll
2015-09-24 17:06:18 1067520 ----a-w- C:\Windows\System32\msctf.dll
2015-09-24 17:06:07 515584 ----a-w- C:\Windows\System32\timedate.cpl
2015-09-24 17:06:06 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl
2015-09-24 17:06:03 52224 ----a-w- C:\Windows\SysWow64\nlaapi.dll
2015-09-24 17:06:03 303616 ----a-w- C:\Windows\System32\nlasvc.dll
2015-09-24 17:06:03 156672 ----a-w- C:\Windows\SysWow64\ncsi.dll
2015-09-24 17:04:45 3242496 ----a-w- C:\Windows\System32\msi.dll
2015-09-24 17:03:53 70656 ----a-w- C:\Windows\System32\appinfo.dll
2015-09-24 17:02:53 658432 ----a-w- C:\Windows\System32\RMActivate_isv.exe
2015-09-24 17:01:33 722944 ----a-w- C:\Windows\System32\objsel.dll
2015-09-24 17:00:52 1888768 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2015-09-24 16:59:40 950128 ----a-w- C:\Windows\System32\drivers\ndis.sys
2015-09-24 16:59:40 41472 ----a-w- C:\Windows\System32\drivers\RNDISMP.sys
2015-09-24 16:59:38 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2015-09-24 16:59:33 27584 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2015-09-24 16:59:33 274880 ----a-w- C:\Windows\System32\drivers\msiscsi.sys
2015-09-24 16:59:33 2048 ----a-w- C:\Windows\SysWow64\iologmsg.dll
2015-09-24 16:59:33 2048 ----a-w- C:\Windows\System32\iologmsg.dll
2015-09-24 16:59:33 190912 ----a-w- C:\Windows\System32\drivers\storport.sys
2015-09-24 16:59:10 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2015-09-24 16:59:10 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
2015-09-24 16:59:10 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
2015-09-24 16:58:32 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
2015-09-24 16:58:32 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys
2015-09-24 16:58:31 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2015-09-24 16:58:30 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2015-09-24 16:58:30 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2015-09-24 16:58:29 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2015-09-24 16:58:29 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2015-09-24 16:58:22 20352 ----a-w- C:\Windows\System32\kdusb.dll
2015-09-24 16:58:22 19328 ----a-w- C:\Windows\System32\kd1394.dll
2015-09-24 16:58:22 17792 ----a-w- C:\Windows\System32\kdcom.dll
2015-09-24 16:58:00 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2015-09-24 16:58:00 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2015-09-24 16:57:24 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
2015-09-24 16:57:24 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll
2015-09-24 16:57:24 404480 ----a-w- C:\Windows\System32\umpnpmgr.dll
2015-09-24 16:57:24 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe
2015-09-24 16:57:24 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll
2015-09-24 16:56:17 72192 ----a-w- C:\Windows\System32\aelupsvc.dll
2015-09-24 16:56:17 342016 ----a-w- C:\Windows\System32\apphelp.dll
2015-09-24 16:56:17 295936 ----a-w- C:\Windows\SysWow64\apphelp.dll
2015-09-24 16:56:16 6656 ----a-w- C:\Windows\System32\shimeng.dll
2015-09-24 16:56:16 5120 ----a-w- C:\Windows\SysWow64\shimeng.dll
2015-09-24 16:56:16 23552 ----a-w- C:\Windows\System32\sdbinst.exe
2015-09-24 16:56:16 20992 ----a-w- C:\Windows\SysWow64\sdbinst.exe
2015-09-24 16:56:03 77824 ----a-w- C:\Windows\System32\packager.dll
2015-09-24 16:56:03 67584 ----a-w- C:\Windows\SysWow64\packager.dll
2015-09-24 16:54:11 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2015-09-24 16:54:11 31232 ----a-w- C:\Windows\System32\prevhost.exe
2015-09-24 16:54:10 223752 ----a-w- C:\Windows\System32\drivers\fvevol.sys
2015-09-24 16:54:07 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2015-09-24 16:54:05 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2015-09-24 16:54:05 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2015-09-24 16:54:04 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll
2015-09-24 16:54:04 634880 ----a-w- C:\Windows\System32\msvcrt.dll
2015-09-24 16:54:02 1684928 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2015-09-24 16:54:01 406528 ----a-w- C:\Windows\System32\scesrv.dll
2015-09-24 16:54:00 308224 ----a-w- C:\Windows\SysWow64\scesrv.dll
2015-09-24 16:53:56 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2015-09-24 16:53:56 1192448 ----a-w- C:\Windows\System32\certutil.exe
2015-09-24 16:53:55 52224 ----a-w- C:\Windows\System32\certenc.dll
2015-09-24 16:53:54 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2015-09-24 16:53:33 202752 ----a-w- C:\Windows\System32\scrrun.dll
2015-09-24 16:53:33 168960 ----a-w- C:\Windows\System32\wscript.exe
2015-09-24 16:53:33 163840 ----a-w- C:\Windows\SysWow64\scrrun.dll
2015-09-24 16:53:33 156160 ----a-w- C:\Windows\System32\cscript.exe
2015-09-24 16:53:33 150016 ----a-w- C:\Windows\System32\wshom.ocx
2015-09-24 16:53:33 141824 ----a-w- C:\Windows\SysWow64\wscript.exe
2015-09-24 16:53:33 126976 ----a-w- C:\Windows\SysWow64\cscript.exe
2015-09-24 16:53:33 121856 ----a-w- C:\Windows\SysWow64\wshom.ocx
2015-09-24 16:52:48 956928 ----a-w- C:\Windows\System32\localspl.dll
2015-09-24 16:52:43 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2015-09-24 16:52:40 331776 ----a-w- C:\Windows\System32\oleacc.dll
2015-09-24 16:52:40 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2015-09-24 16:52:35 723456 ----a-w- C:\Windows\System32\EncDec.dll
2015-09-24 16:52:35 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2015-09-24 16:52:34 79360 ----a-w- C:\Windows\System32\clfsw32.dll
2015-09-24 16:52:34 367552 ----a-w- C:\Windows\System32\clfs.sys
2015-09-24 16:52:33 58880 ----a-w- C:\Windows\SysWow64\clfsw32.dll
2015-09-24 16:47:02 3209216 ----a-w- C:\Windows\System32\win32k.sys
2015-09-24 16:47:01 372736 ----a-w- C:\Windows\System32\atmfd.dll
2015-09-24 16:47:00 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2015-09-24 16:47:00 46080 ----a-w- C:\Windows\System32\atmlib.dll
2015-09-24 16:47:00 41984 ----a-w- C:\Windows\System32\lpk.dll
2015-09-24 16:47:00 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2015-09-24 16:47:00 299520 ----a-w- C:\Windows\SysWow64\atmfd.dll
2015-09-24 16:47:00 25600 ----a-w- C:\Windows\SysWow64\lpk.dll
2015-09-24 16:47:00 14336 ----a-w- C:\Windows\System32\dciman32.dll
2015-09-24 16:47:00 10240 ----a-w- C:\Windows\SysWow64\dciman32.dll
2015-09-24 16:47:00 100864 ----a-w- C:\Windows\System32\fontsub.dll
2015-09-24 16:40:47 859648 ----a-w- C:\Windows\System32\IKEEXT.DLL
2015-09-24 16:40:47 830464 ----a-w- C:\Windows\System32\nshwfp.dll
2015-09-24 16:40:47 324096 ----a-w- C:\Windows\System32\FWPUCLNT.DLL
2015-09-24 16:40:46 656896 ----a-w- C:\Windows\SysWow64\nshwfp.dll
2015-09-24 16:40:46 216576 ----a-w- C:\Windows\SysWow64\FWPUCLNT.DLL
2015-09-24 16:40:30 461312 ----a-w- C:\Windows\System32\scavengeui.dll
2015-09-24 05:57:18 -------- d-----w- C:\Windows\ehome
2015-09-24 05:24:15 -------- d-----w- C:\Program Files (x86)\Common Files\Telespree
2015-09-24 05:23:56 -------- d-----w- C:\Program Files (x86)\HP SimplePass 2011
2015-09-24 05:23:50 -------- d-----w- C:\ProgramData\Downloaded Installations
2015-09-24 05:23:50 -------- d-----w- C:\Program Files\Common Files\AuthenTec
2015-09-24 05:23:50 -------- d-----w- C:\Program Files (x86)\Common Files\AuthenTec
2015-09-24 05:19:43 -------- d-----w- C:\ProgramData\{E91883C8-8CDC-46A4-A45F-CB40EB82ED60}
2015-09-24 05:19:30 -------- d-----w- C:\Program Files (x86)\AMD
2015-09-24 05:18:37 0 ----a-w- C:\Windows\ativpsrm.bin
2015-09-24 05:17:55 -------- d-----w- C:\Windows\Hewlett-Packard
2015-09-24 05:17:10 -------- d-----w- C:\Program Files (x86)\Cisco
2015-09-24 05:16:45 1142376 ----a-w- C:\Windows\System32\drivers\rtl8192ce.sys
2015-09-24 05:16:44 451072 ----a-w- C:\Windows\SysWow64\ISSRemoveSP.exe
2015-09-24 05:16:24 -------- d-----w- C:\Windows\Driver Cache
2015-09-24 05:16:23 -------- d-----w- C:\Program Files (x86)\HP
2015-09-24 05:15:39 -------- d-----w- C:\Program Files\Validity Sensors
2015-09-24 05:15:31 -------- d-----w- C:\Windows\SysWow64\sda
2015-09-24 05:15:24 9888360 ----a-w- C:\Windows\SysWow64\RtsPStorIcon.dll
2015-09-24 05:15:24 337512 ----a-w- C:\Windows\System32\drivers\RtsPStor.sys
2015-09-24 05:14:36 74272 ----a-w- C:\Windows\System32\RtNicProp64.dll
2015-09-24 05:14:36 428136 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys
2015-09-24 05:14:36 107552 ----a-w- C:\Windows\System32\RTNUninst64.dll
2015-09-24 05:14:33 -------- d-----w- C:\Program Files (x86)\Realtek
2015-09-24 05:14:22 -------- d-----w- C:\Program Files\Synaptics
2015-09-24 05:09:50 1190000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CEFBEE4A-420D-48A3-B768-6CC6FC7888C7}\gapaengine.dll
2015-09-24 05:09:41 11062400 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B3CD29F4-423B-41C2-9E02-AA92B9CAF33F}\mpengine.dll
2015-09-24 05:06:44 -------- d-----w- C:\Program Files (x86)\AMD APP
2015-09-24 05:06:42 -------- d-----w- C:\Program Files\Common Files\ATI Technologies
2015-09-24 05:06:42 -------- d-----w- C:\Program Files (x86)\Common Files\ATI Technologies
2015-09-24 05:06:00 46136 ----a-w- C:\Windows\System32\drivers\amdiox64.sys
2015-09-24 05:06:00 -------- d-----w- C:\ProgramData\AMD
2015-09-24 05:05:59 -------- d-----w- C:\Program Files\ATI Technologies
2015-09-24 05:05:53 47232 ----a-w- C:\Windows\System32\drivers\usbfilter.sys
2015-09-24 05:05:26 -------- d-----w- C:\Program Files\ATI
2015-09-24 05:05:24 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2015-09-24 05:05:19 -------- d-sh--w- C:\Windows\Installer
2015-09-24 04:33:46 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2015-09-24 04:33:44 -------- d-----w- C:\Program Files\Microsoft Security Client
2015-09-24 03:59:06 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2015-09-24 03:59:06 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2015-09-24 03:59:06 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2015-09-24 03:09:02 -------- d-----w- C:\Users\Brooke\AppData\Local\Google
2015-09-24 03:08:47 -------- d-----w- C:\Users\Brooke\AppData\Local\Apps
2015-09-24 03:08:46 -------- d-----w- C:\Users\Brooke\AppData\Local\Deployment
2015-09-24 02:38:51 -------- d-----w- C:\Users\Brooke\AppData\Local\AMD
2015-09-24 02:38:43 -------- d-----w- C:\Users\Brooke\AppData\Local\ATI
2015-09-24 02:37:43 -------- d-----w- C:\Users\Brooke\AppData\Roaming\Synaptics
2015-09-24 02:37:43 -------- d-----w- C:\Users\Brooke\AppData\Roaming\hpqLog
2015-09-11 22:48:46 94208 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInViews\Microsoft.Office.Tools.v9.0.dll
2015-09-11 21:44:26 773968 ----a-w- C:\Windows\SysWow64\msvcr100.dll
2015-09-11 21:44:26 421200 ----a-w- C:\Windows\SysWow64\msvcp100.dll
.
==================== Find3M ====================
.
2015-09-25 22:56:12 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-09-11 22:48:44 829264 ----a-w- C:\Windows\System32\msvcr100.dll
2015-09-11 22:48:44 608080 ----a-w- C:\Windows\System32\msvcp100.dll
2015-08-27 18:18:27 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2015-08-27 18:18:27 1887232 ----a-w- C:\Windows\System32\msxml3.dll
2015-08-27 18:13:03 2048 ----a-w- C:\Windows\System32\msxml6r.dll
2015-08-27 18:13:03 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2015-08-27 17:58:14 1391104 ----a-w- C:\Windows\SysWow64\msxml6.dll
2015-08-27 17:58:14 1241088 ----a-w- C:\Windows\SysWow64\msxml3.dll
2015-08-27 17:51:26 2048 ----a-w- C:\Windows\SysWow64\msxml6r.dll
2015-08-27 17:51:26 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2015-08-26 18:07:11 98304 ----a-w- C:\Windows\System32\wudriver.dll
2015-08-26 18:07:11 3165696 ----a-w- C:\Windows\System32\wucltux.dll
2015-08-26 18:07:11 192000 ----a-w- C:\Windows\System32\wuwebv.dll
2015-08-26 18:06:43 91136 ----a-w- C:\Windows\System32\WinSetupUI.dll
2015-08-26 18:06:33 12288 ----a-w- C:\Windows\System32\wu.upgrade.ps.dll
2015-08-26 18:06:30 37376 ----a-w- C:\Windows\System32\wuapp.exe
2015-08-26 17:56:25 93184 ----a-w- C:\Windows\SysWow64\wudriver.dll
2015-08-26 17:56:25 173056 ----a-w- C:\Windows\SysWow64\wuwebv.dll
2015-08-26 17:55:37 34816 ----a-w- C:\Windows\SysWow64\wuapp.exe
2015-08-05 17:56:14 1110016 ----a-w- C:\Windows\System32\schedsvc.dll
2015-08-05 17:56:06 275456 ----a-w- C:\Windows\System32\InkEd.dll
2015-08-05 17:40:50 216064 ----a-w- C:\Windows\SysWow64\InkEd.dll
2015-08-04 18:03:10 692672 ----a-w- C:\Windows\System32\winload.efi
2015-08-04 18:00:24 616360 ----a-w- C:\Windows\System32\winresume.efi
2015-08-04 17:56:54 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
2015-08-04 17:56:37 59392 ----a-w- C:\Windows\System32\appidapi.dll
2015-08-04 17:56:37 32768 ----a-w- C:\Windows\System32\appidsvc.dll
2015-08-04 17:55:57 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2015-08-04 17:55:57 147456 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2015-08-04 17:47:42 50688 ----a-w- C:\Windows\SysWow64\appidapi.dll
2015-08-04 16:58:09 61440 ----a-w- C:\Windows\System32\drivers\appid.sys
2015-07-28 20:09:44 17344 ----a-w- C:\Windows\System32\CompatTelRunner.exe
2015-07-28 20:05:53 774656 ----a-w- C:\Windows\System32\invagent.dll
2015-07-28 20:05:50 743424 ----a-w- C:\Windows\System32\generaltel.dll
2015-07-28 20:05:47 437760 ----a-w- C:\Windows\System32\devinv.dll
2015-07-28 20:05:45 1116672 ----a-w- C:\Windows\System32\appraiser.dll
2015-07-28 20:05:44 69120 ----a-w- C:\Windows\System32\acmigration.dll
2015-07-28 20:05:44 227328 ----a-w- C:\Windows\System32\aepdu.dll
2015-07-28 19:55:14 1148416 ----a-w- C:\Windows\System32\aeinv.dll
2015-07-23 00:06:26 5568960 ----a-w- C:\Windows\System32\ntoskrnl.exe
2015-07-23 00:06:25 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2015-07-23 00:06:25 155584 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2015-07-23 00:03:19 1730496 ----a-w- C:\Windows\System32\ntdll.dll
2015-07-23 00:03:07 362496 ----a-w- C:\Windows\System32\wow64win.dll
2015-07-23 00:03:07 243712 ----a-w- C:\Windows\System32\wow64.dll
2015-07-23 00:03:07 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2015-07-23 00:03:06 215040 ----a-w- C:\Windows\System32\winsrv.dll
2015-07-23 00:01:53 31232 ----a-w- C:\Windows\System32\lsass.exe
2015-07-23 00:01:39 338432 ----a-w- C:\Windows\System32\conhost.exe
2015-07-23 00:01:32 64000 ----a-w- C:\Windows\System32\auditpol.exe
2015-07-22 23:58:17 60416 ----a-w- C:\Windows\System32\msobjs.dll
2015-07-22 23:57:53 146432 ----a-w- C:\Windows\System32\msaudite.dll
2015-07-22 23:51:59 686080 ----a-w- C:\Windows\System32\adtschema.dll
2015-07-22 17:57:49 3989952 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2015-07-22 17:57:49 3934656 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2015-07-22 17:54:12 1311768 ----a-w- C:\Windows\SysWow64\ntdll.dll
2015-07-22 17:52:52 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2015-07-22 17:52:19 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2015-07-22 17:52:03 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2015-07-22 17:52:03 665088 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2015-07-22 17:52:03 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2015-07-22 17:52:03 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2015-07-22 17:47:28 60416 ----a-w- C:\Windows\SysWow64\msobjs.dll
2015-07-22 17:46:50 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll
2015-07-22 16:48:49 41984 ----a-w- C:\Windows\System32\UtcResources.dll
2015-07-22 16:45:48 159232 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2015-07-22 16:44:51 290816 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2015-07-22 16:44:45 129024 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2015-07-22 16:34:31 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2015-07-22 16:34:29 2048 ----a-w- C:\Windows\SysWow64\user.exe
2015-07-22 16:31:52 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2015-07-22 16:31:52 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2015-07-22 16:31:52 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2015-07-22 16:31:52 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2015-07-10 17:51:27 44032 ----a-w- C:\Windows\System32\tsgqec.dll
2015-07-10 17:51:19 3722752 ----a-w- C:\Windows\System32\mstscax.dll
2015-07-10 17:51:10 158720 ----a-w- C:\Windows\System32\aaclient.dll
2015-07-10 17:34:09 36864 ----a-w- C:\Windows\SysWow64\tsgqec.dll
2015-07-10 17:34:02 3221504 ----a-w- C:\Windows\SysWow64\mstscax.dll
2015-07-10 17:33:50 131584 ----a-w- C:\Windows\SysWow64\aaclient.dll
2015-07-09 17:58:26 82944 ----a-w- C:\Windows\System32\dwmapi.dll
2015-07-09 17:58:26 1632256 ----a-w- C:\Windows\System32\dwmcore.dll
2015-07-09 17:57:57 193536 ----a-w- C:\Windows\System32\notepad.exe
2015-07-09 17:57:57 193536 ----a-w- C:\Windows\notepad.exe
2015-07-09 17:42:54 67584 ----a-w- C:\Windows\SysWow64\dwmapi.dll
2015-07-09 17:42:54 1372160 ----a-w- C:\Windows\SysWow64\dwmcore.dll
2015-07-09 17:42:27 179712 ----a-w- C:\Windows\SysWow64\notepad.exe
2015-07-05 10:08:23 300704 ------w- C:\Windows\System32\MpSigStub.exe
2015-07-04 18:07:11 2087424 ----a-w- C:\Windows\System32\ole32.dll
2015-07-04 17:48:36 1414656 ----a-w- C:\Windows\SysWow64\ole32.dll
2015-07-01 20:49:56 260096 ----a-w- C:\Windows\System32\WebClnt.dll
2015-07-01 20:48:36 102912 ----a-w- C:\Windows\System32\davclnt.dll
2015-07-01 20:30:43 206848 ----a-w- C:\Windows\SysWow64\WebClnt.dll
2015-07-01 20:30:21 82432 ----a-w- C:\Windows\SysWow64\davclnt.dll
.
============= FINISH: 0:27:49.22 ===============

Need Help With Malware Issues

$
0
0
All,

I followed the instructions and ran DDS since I've been having some spyware issues. The results are below; please let me know if you have any questions. Thanks for your help!

FYI; I also do not have access to a boot CD.

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.18015 BrowserJavaVersion: 10.5.1
Run by Home at 11:42:15 on 2015-09-26
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.883 [GMT -4:00]
.
AV: Ad-Aware Antivirus *Disabled/Outdated* {B0CC18C6-E527-6EE6-874C-9D19920E5619}
SP: Ad-Aware Antivirus *Disabled/Outdated* {0BADF922-C31D-6168-BDFC-A66BE9891CA4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
FW: Ad-Aware Firewall *Disabled* {88F799E3-AF48-6FBE-AC13-342C6CDD1162}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Windows\system32\GWX\GWX.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files\daugava\Ejemidvlf64.exe
C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.8.586.8535\AdAwareTray.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Download Manager\DownloadManager.exe
C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.8.586.8535\AdAwareService.exe
C:\Users\Home\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Users\Home\AppData\Roaming\Spotify\Spotify.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
C:\Program Files (x86)\PDF Complete\pdfsvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Users\Home\AppData\Roaming\GVU Technologies\Free YouTube Downloader Converter\CertifiedBrowserService.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Users\Home\AppData\Roaming\Spotify\Spotify.exe
C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Users\Home\AppData\Roaming\Spotify\Spotify.exe
c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\consent.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\GWX\GWXConfigManager.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mStart Page = about:blank
mWinlogon: Userinit = userinit.exe
BHO: Bing Bar Helper: {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Download Manager: {E5C66DD8-308B-4a4f-AF0A-3D04F25B5343} -
TB: Bing Bar: {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll
uRun: [DownloadManager] "C:\Program Files (x86)\Download Manager\DownloadManager.exe" /as
uRun: [Spotify Web Helper] "C:\Users\Home\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
uRun: [Google Update] "C:\Users\Home\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [SpybotPostWindows10UpgradeReInstall] "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
uRun: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean
uRun: [Spotify] "C:\Users\Home\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized
uRun: [GoogleChromeAutoLaunch_F8F9C1389199C5D42EF0F1FE1D081D59] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
mRun: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
dRunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"Troubleshoot problems installing Service Pack 1 (SP1) for Windows 7 and Windows Server 2008 R2 - Windows Help" /build:7601
StartupFolder: C:\Users\Home\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\EVERNO~1.LNK - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
StartupFolder: C:\Users\Home\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SNAPFI~1.LNK - C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
TCP: NameServer = 64.233.217.2 64.233.217.3
TCP: Interfaces\{3DE02E36-3C2C-40C4-8E90-A7B28B29CF40} : DHCPNameServer = 64.233.217.2 64.233.217.3
TCP: Interfaces\{66962012-7C72-4938-B010-F294F7B57AE4} : DHCPNameServer = 64.233.217.2 64.233.217.3
TCP: Interfaces\{8AD655ED-AC8E-4780-955D-3428D5A509C1} : DHCPNameServer = 64.233.217.2 64.233.217.3
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.101\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mStart Page = about:blank
x64-BHO: Bing Bar Helper: {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-TB: Bing Bar: {eec0f710-38b5-4aba-99bf-ec87564a4e13} -
x64-Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
x64-Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background
x64-Run: [daugava64] C:\Program Files\daugava\Ejemidvlf64.exe
x64-Run: [AdAwareTray] "C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.8.586.8535\AdAwareTray.exe"
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\riag9emv.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://start.sweetpacks.com/?src=2&st=12&crg=3.5000006.10045&barid={B7AD0FC7-DF2A-11E2-B7D0-6431503402C2}&q=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\nphdplg.dll
FF - plugin: C:\Users\Home\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll
FF - plugin: C:\Users\Home\AppData\Roaming\GVU Technologies\Free YouTube Downloader Converter\npCertifiedBrowser.dll
FF - plugin: C:\Users\Home\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Home\AppData\Roaming\Mozilla\plugins\npo1d.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110014
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 583dcb0f0000000000006431503402c2
FF - user.js: extensions.BabylonToolbar_i.hardId - 583dcb0f0000000000006431503402c2
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15399
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1718:40:43
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2010-11-22 75904]
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2010-11-22 38016]
R1 cherimoya;cherimoya;C:\Windows\System32\drivers\cherimoya.sys [2015-7-22 61336]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-11-22 203264]
R2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.EXE [2014-3-11 193696]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-8-5 291896]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-8-20 92216]
R2 LavasoftAdAwareService11;Ad-Aware Service 11;C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.8.586.8535\AdAwareService.exe [2015-8-27 712432]
R2 LVPrcS64;Process Monitor;C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe [2009-10-7 191000]
R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568]
R2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2010-11-22 1119768]
R2 RoxioNow Service;RoxioNow Service;C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-9-11 399344]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2015-9-4 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2015-9-4 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2015-9-4 171928]
R2 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-1-18 450848]
R2 Updater By SweetPacks;Updater By SweetPacks;C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe [2013-6-27 188760]
R2 YouTubeDownloaderConverter;YouTubeDownloaderConverter;C:\Users\Home\AppData\Roaming\GVU Technologies\Free YouTube Downloader Converter\CertifiedBrowserService.exe [2013-6-5 104448]
R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;C:\Windows\System32\drivers\bcmwlhigh664.sys [2011-4-19 1254464]
R3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\System32\drivers\LVPr2M64.sys [2009-10-7 30232]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2010-11-22 1002848]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-11-22 349800]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2010-11-22 38456]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-4-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-4-11 124088]
S3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE [2014-3-11 247968]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2015-9-9 114688]
S3 LVUVC64;Logitech Webcam 120(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2012-8-10 6379288]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-2-6 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-2-6 1255736]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile="C:\Windows\System32\NOTEPAD.EXE" %1
FileExt: .ini: inifile="C:\Windows\System32\NOTEPAD.EXE" %1
FileExt: .inf: inffile="C:\Windows\System32\NOTEPAD.EXE" %1
.
=============== Created Last 30 ================
.
2015-09-22 11:19:37 18819272 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2015-09-19 20:45:40 -------- d-----w- C:\Windows\System32\uopi
2015-09-19 20:45:31 -------- d-----w- C:\Windows\TEMPfolder
2015-09-09 16:45:26 41984 ----a-w- C:\Windows\System32\UtcResources.dll
2015-09-09 16:44:54 1941504 ----a-w- C:\Windows\System32\authui.dll
2015-09-09 16:43:59 98304 ----a-w- C:\Windows\System32\wudriver.dll
2015-09-05 08:51:45 -------- d-----w- C:\Users\Home\AppData\Local\CEF
2015-09-05 04:22:44 -------- d-----w- C:\Users\Home\AppData\Roaming\LavasoftStatistics
2015-09-05 04:21:22 -------- d-----w- C:\Program Files\Lavasoft
2015-09-05 04:20:28 -------- d-----w- C:\Program Files\Common Files\Lavasoft
2015-09-05 03:11:35 -------- d-----w- C:\Program Files\Common Files\AV
2015-09-05 03:02:42 21040 ----a-w- C:\Windows\System32\sdnclean64.exe
2015-09-05 03:02:37 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
.
==================== Find3M ====================
.
2015-09-22 11:19:40 780488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2015-09-22 11:19:40 142536 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-09-02 03:04:49 41984 ----a-w- C:\Windows\System32\lpk.dll
2015-09-02 03:04:46 100864 ----a-w- C:\Windows\System32\fontsub.dll
2015-09-02 03:04:44 14336 ----a-w- C:\Windows\System32\dciman32.dll
2015-09-02 03:04:42 46080 ----a-w- C:\Windows\System32\atmlib.dll
2015-09-02 02:48:31 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2015-09-02 02:48:28 10240 ----a-w- C:\Windows\SysWow64\dciman32.dll
2015-09-02 02:48:25 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2015-09-02 02:47:18 25600 ----a-w- C:\Windows\SysWow64\lpk.dll
2015-09-02 01:51:28 3209216 ----a-w- C:\Windows\System32\win32k.sys
2015-09-02 01:47:08 372736 ----a-w- C:\Windows\System32\atmfd.dll
2015-09-02 01:33:48 299520 ----a-w- C:\Windows\SysWow64\atmfd.dll
2015-08-27 18:18:27 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2015-08-27 18:18:27 1887232 ----a-w- C:\Windows\System32\msxml3.dll
2015-08-27 18:13:03 2048 ----a-w- C:\Windows\System32\msxml6r.dll
2015-08-27 18:13:03 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2015-08-27 17:58:14 1391104 ----a-w- C:\Windows\SysWow64\msxml6.dll
2015-08-27 17:58:14 1241088 ----a-w- C:\Windows\SysWow64\msxml3.dll
2015-08-27 17:51:26 2048 ----a-w- C:\Windows\SysWow64\msxml6r.dll
2015-08-27 17:51:26 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2015-08-26 18:07:11 3165696 ----a-w- C:\Windows\System32\wucltux.dll
2015-08-26 18:07:11 192000 ----a-w- C:\Windows\System32\wuwebv.dll
2015-08-26 18:06:43 91136 ----a-w- C:\Windows\System32\WinSetupUI.dll
2015-08-26 18:06:33 12288 ----a-w- C:\Windows\System32\wu.upgrade.ps.dll
2015-08-26 18:06:30 37376 ----a-w- C:\Windows\System32\wuapp.exe
2015-08-26 17:56:25 93184 ----a-w- C:\Windows\SysWow64\wudriver.dll
2015-08-26 17:56:25 173056 ----a-w- C:\Windows\SysWow64\wuwebv.dll
2015-08-26 17:55:37 34816 ----a-w- C:\Windows\SysWow64\wuapp.exe
2015-08-15 06:34:10 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2015-08-15 06:33:56 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2015-08-15 06:18:47 66560 ----a-w- C:\Windows\System32\iesetup.dll
2015-08-15 06:18:00 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2015-08-15 06:17:54 417792 ----a-w- C:\Windows\System32\html.iec
2015-08-15 06:17:49 585216 ----a-w- C:\Windows\System32\vbscript.dll
2015-08-15 06:17:25 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2015-08-15 06:04:47 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
2015-08-15 06:04:46 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2015-08-15 06:04:25 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2015-08-15 06:00:44 5923328 ----a-w- C:\Windows\System32\jscript9.dll
2015-08-15 05:57:20 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2015-08-15 05:53:22 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2015-08-15 05:46:15 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2015-08-15 05:40:29 504832 ----a-w- C:\Windows\SysWow64\vbscript.dll
2015-08-15 05:40:12 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2015-08-15 05:39:32 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2015-08-15 05:39:22 341504 ----a-w- C:\Windows\SysWow64\html.iec
2015-08-15 05:38:34 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2015-08-15 05:29:36 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2015-08-15 05:29:12 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2015-08-15 05:22:47 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2015-08-15 05:22:03 2126336 ----a-w- C:\Windows\System32\inetcpl.cpl
2015-08-15 05:16:37 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2015-08-15 05:10:32 4520448 ----a-w- C:\Windows\SysWow64\jscript9.dll
2015-08-15 05:07:28 2427392 ----a-w- C:\Windows\System32\wininet.dll
2015-08-15 05:01:47 2052608 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2015-08-15 05:01:23 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2015-08-15 04:43:00 1951232 ----a-w- C:\Windows\SysWow64\wininet.dll
2015-08-05 17:56:14 1110016 ----a-w- C:\Windows\System32\schedsvc.dll
2015-08-05 17:56:07 24576 ----a-w- C:\Windows\System32\jnwmon.dll
2015-08-05 17:56:06 275456 ----a-w- C:\Windows\System32\InkEd.dll
2015-08-05 17:40:50 216064 ----a-w- C:\Windows\SysWow64\InkEd.dll
2015-08-04 18:03:10 692672 ----a-w- C:\Windows\System32\winload.efi
2015-08-04 18:00:24 616360 ----a-w- C:\Windows\System32\winresume.efi
2015-08-04 17:56:54 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
2015-08-04 17:56:37 59392 ----a-w- C:\Windows\System32\appidapi.dll
2015-08-04 17:56:37 32768 ----a-w- C:\Windows\System32\appidsvc.dll
2015-08-04 17:55:57 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2015-08-04 17:55:57 147456 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2015-08-04 17:47:42 50688 ----a-w- C:\Windows\SysWow64\appidapi.dll
2015-08-04 16:58:09 61440 ----a-w- C:\Windows\System32\drivers\appid.sys
2015-07-30 18:06:57 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2015-07-30 18:06:57 1648128 ----a-w- C:\Windows\System32\DWrite.dll
2015-07-30 18:06:57 1180160 ----a-w- C:\Windows\System32\FntCache.dll
2015-07-30 17:57:30 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2015-07-30 17:57:30 1251328 ----a-w- C:\Windows\SysWow64\DWrite.dll
2015-07-30 13:13:38 103120 ----a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-07-30 13:13:11 124624 ----a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2015-07-28 20:09:44 17344 ----a-w- C:\Windows\System32\CompatTelRunner.exe
2015-07-28 20:05:53 774656 ----a-w- C:\Windows\System32\invagent.dll
2015-07-28 20:05:50 743424 ----a-w- C:\Windows\System32\generaltel.dll
2015-07-28 20:05:47 437760 ----a-w- C:\Windows\System32\devinv.dll
2015-07-28 20:05:45 1116672 ----a-w- C:\Windows\System32\appraiser.dll
2015-07-28 20:05:44 69120 ----a-w- C:\Windows\System32\acmigration.dll
2015-07-28 20:05:44 227328 ----a-w- C:\Windows\System32\aepdu.dll
2015-07-28 19:55:14 1148416 ----a-w- C:\Windows\System32\aeinv.dll
2015-07-23 00:06:26 5568960 ----a-w- C:\Windows\System32\ntoskrnl.exe
2015-07-23 00:06:25 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2015-07-23 00:06:25 155584 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2015-07-23 00:03:19 1730496 ----a-w- C:\Windows\System32\ntdll.dll
2015-07-23 00:03:07 362496 ----a-w- C:\Windows\System32\wow64win.dll
2015-07-23 00:03:07 243712 ----a-w- C:\Windows\System32\wow64.dll
2015-07-23 00:03:07 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2015-07-23 00:03:06 215040 ----a-w- C:\Windows\System32\winsrv.dll
2015-07-23 00:01:53 31232 ----a-w- C:\Windows\System32\lsass.exe
2015-07-23 00:01:39 338432 ----a-w- C:\Windows\System32\conhost.exe
2015-07-23 00:01:32 64000 ----a-w- C:\Windows\System32\auditpol.exe
2015-07-22 23:58:17 60416 ----a-w- C:\Windows\System32\msobjs.dll
2015-07-22 23:57:53 146432 ----a-w- C:\Windows\System32\msaudite.dll
2015-07-22 23:51:59 686080 ----a-w- C:\Windows\System32\adtschema.dll
.
============= FINISH: 11:44:04.38 ===============

Attached Files
File Type: txt attach.txt (10.0 KB)

Possible unresolved Malware infection

$
0
0
Hello.
I was prompted to begin a new thread in this category because there might be a possibility that my laptop might still be infected with malware.

As I explained in my other thread "Need Drivers for Multimedia Video Controller and PCI Devices", I have taken my laptop to the repair shop to rid it of what I thought might be malware.

Whatever it was was preventing MalwareBytes from reinstalling, as well as a nonfunctional Live Protection prior to uninstalling and trying to reinstall.

The repair shop fixed the problem but left my laptop in a jumbles. I have been trying to put my desktop back together again as well as get other things and programs rearranged back to my liking. Some things I've kept, others not.

But it was pointed out to me that in order to be safe, you experts might want to take a second look at my laptop to be sure it is clean.

Therefore, here are the DDS logs you request. I hope you can determine if I have any issues. Thank you.

Attached Files
File Type: txt attach.txt (11.1 KB)
File Type: txt dds.txt (13.1 KB)

Help Please

$
0
0
Dear Sirs

I recently opened an email, (despite being warned not to do so by Goole), sent to me from BrianandSally!

Sally is my stepbrother’s daughter & Brian is her husband, but the email was not from my relatives.

Ever since I opened the email, Google has had problems:

It keeps locking on me, and I cannot go forwards, backwards or open another link.

The only way to get out of the problem is to reboot my computer.

My computer has Windows 8

Jack Willday

Possible virus

$
0
0
Hello, and thank you for being here. I believe my neighbors machine has a virus of some sort. He ran HouseCall on it and it didn't find anything on it, but the AVast antivirus that is installed has been disabled and I can't get it to run.

In addition, the machine is running more slowly than normal, and last week he had one of the "FBI virus" things come up in his browser.

I do have the original Win7 Home 64 bit install available if it is necessary.

The requested logs are attached.


DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.18015 BrowserJavaVersion: 10.80.2
Run by Christy Kuebler at 14:06:12 on 2015-09-27
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.7884.5967 [GMT -5:00]
.
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe
C:\Program Files\HP\HP Officejet 5740 series\Bin\ScanToPCActivationApp.exe
C:\Program Files\HP\HP Officejet 5740 series\Bin\HPNetworkCommunicatorCom.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files\AVAST Software\Avast\setup\New\instup.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
mWinlogon: Userinit = userinit.exe,
BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
uRun: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
uRun: [iCloudDrive] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
uRun: [Fitbit Connect] "C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe" /autorun
uRun: [HP Officejet 5740 series (NET)] "C:\Program Files\HP\HP Officejet 5740 series\Bin\ScanToPCActivationApp.exe" -deviceID "TH5483X1TS05ZF:NW" -scfn "HP Officejet 5740 series (NET)" -AutoStart 1
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [Monitor] "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe"
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Fitbit Connect] "C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe" /autorun
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: SoftwareSASGeneration = dword:1
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{63A08692-E15C-4AE6-91EB-8D57E934EF65} : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{63A08692-E15C-4AE6-91EB-8D57E934EF65} : DHCPNameServer = 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.101\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
x64-IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Christy Kuebler\AppData\Roaming\Mozilla\Firefox\Profiles\uglcgrlq.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2014-3-13 65736]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2014-3-13 272248]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2012-7-23 16152]
R1 aswKbd;aswKbd;C:\Windows\System32\drivers\aswKbd.sys [2015-6-22 28144]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2014-3-13 1047320]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswsp.sys [2014-3-13 442264]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-5-29 77128]
R2 aswHwid;avast! HardwareID;C:\Windows\System32\drivers\aswHwid.sys [2014-8-6 29168]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2014-3-13 89944]
R2 aswStm;aswStm;C:\Windows\System32\drivers\aswStm.sys [2014-3-13 137288]
R2 avast! Antivirus;Avast Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-6-22 343336]
R2 Fitbit Connect;Fitbit Connect Service;C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [2015-9-4 5750440]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-7-23 13592]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-7-23 165760]
R2 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [2012-1-18 450848]
R2 VBoxAswDrv;VBoxAsw Support Driver;C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2015-6-22 273824]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-11-4 169752]
R3 ICCWDT;Intel(R) Watchdog Timer Driver (Intel(R) WDT);C:\Windows\System32\drivers\ICCWDT.sys [2010-8-17 26136]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-11-4 442368]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2012-7-23 355096]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2012-7-23 786200]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-7-23 646248]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-7-9 327296]
S2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-7-23 364416]
S2 Util PlurPush;Util PlurPush;"C:\Program Files (x86)\PlurPush\bin\utilPlurPush.exe" --> C:\Program Files (x86)\PlurPush\bin\utilPlurPush.exe [?]
S3 AvastVBoxSvc;AvastVBox COM Service;C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2015-6-22 4034896]
S3 FlyUsb;FLY Fusion;C:\Windows\System32\drivers\FlyUsb.sys [2012-9-28 24576]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2015-9-8 114688]
S3 Leapfrog-USBLAN;Leapfrog-USBLAN;C:\Windows\System32\drivers\btblan.sys [2012-9-28 40320]
S3 lvpopf64;Logitech POP Suppression Filter;C:\Windows\System32\drivers\lvpopf64.sys [2010-5-14 271712]
S3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\System32\drivers\LVPr2M64.sys [2010-5-7 30304]
S3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\System32\drivers\lvrs64.sys [2012-1-18 351136]
S3 LVUVC64;Logitech HD Webcam C310(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2012-1-18 4865568]
S3 SWDUMon;SWDUMon;C:\Windows\System32\drivers\SWDUMon.sys [2013-11-4 16152]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2015-6-10 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-7-23 1255736]
.
=============== Created Last 30 ================
.
2015-09-25 11:22:03 11062400 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{50FC4E19-0F8C-489E-A758-EC73F4BC9111}\mpengine.dll
2015-09-24 00:02:43 307352 ----a-w- C:\Windows\System32\drivers\tmcomm.sys
2015-09-16 03:41:50 -------- d-----w- C:\ProgramData\Visan
2015-09-16 03:41:50 -------- d-----w- C:\ProgramData\HP Photo Creations
2015-09-16 03:41:50 -------- d-----w- C:\Program Files (x86)\HP Photo Creations
2015-09-16 03:41:20 751624 ------w- C:\Windows\System32\HPDiscoPMCD11.dll
2015-09-16 03:41:09 -------- d-----w- C:\Program Files\HP
2015-09-12 15:36:56 -------- d-----w- C:\Program Files (x86)\Fitbit Connect
2015-09-08 20:52:58 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2015-09-08 20:52:58 2048 ----a-w- C:\Windows\System32\tzres.dll
2015-09-08 20:48:06 692672 ----a-w- C:\Windows\System32\winload.efi
2015-09-08 20:48:06 616360 ----a-w- C:\Windows\System32\winresume.efi
2015-09-08 20:48:06 147456 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2015-09-08 20:48:05 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
2015-09-08 20:48:05 61440 ----a-w- C:\Windows\System32\drivers\appid.sys
2015-09-08 20:48:05 59392 ----a-w- C:\Windows\System32\appidapi.dll
2015-09-08 20:48:05 50688 ----a-w- C:\Windows\SysWow64\appidapi.dll
2015-09-08 20:48:05 32768 ----a-w- C:\Windows\System32\appidsvc.dll
2015-09-08 20:48:05 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
.
==================== Find3M ====================
.
2015-09-21 17:26:13 780488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2015-09-21 17:26:13 142536 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-09-20 22:50:51 113880 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2015-09-02 03:04:49 41984 ----a-w- C:\Windows\System32\lpk.dll
2015-09-02 03:04:46 100864 ----a-w- C:\Windows\System32\fontsub.dll
2015-09-02 03:04:44 14336 ----a-w- C:\Windows\System32\dciman32.dll
2015-09-02 03:04:42 46080 ----a-w- C:\Windows\System32\atmlib.dll
2015-09-02 02:48:31 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2015-09-02 02:48:28 10240 ----a-w- C:\Windows\SysWow64\dciman32.dll
2015-09-02 02:48:25 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2015-09-02 02:47:18 25600 ----a-w- C:\Windows\SysWow64\lpk.dll
2015-09-02 01:51:28 3209216 ----a-w- C:\Windows\System32\win32k.sys
2015-09-02 01:47:08 372736 ----a-w- C:\Windows\System32\atmfd.dll
2015-09-02 01:33:48 299520 ----a-w- C:\Windows\SysWow64\atmfd.dll
2015-08-26 18:07:11 98304 ----a-w- C:\Windows\System32\wudriver.dll
2015-08-26 18:07:11 3165696 ----a-w- C:\Windows\System32\wucltux.dll
2015-08-26 18:07:11 192000 ----a-w- C:\Windows\System32\wuwebv.dll
2015-08-26 18:06:43 91136 ----a-w- C:\Windows\System32\WinSetupUI.dll
2015-08-26 18:06:33 12288 ----a-w- C:\Windows\System32\wu.upgrade.ps.dll
2015-08-26 18:06:30 37376 ----a-w- C:\Windows\System32\wuapp.exe
2015-08-26 17:56:25 93184 ----a-w- C:\Windows\SysWow64\wudriver.dll
2015-08-26 17:56:25 173056 ----a-w- C:\Windows\SysWow64\wuwebv.dll
2015-08-26 17:55:37 34816 ----a-w- C:\Windows\SysWow64\wuapp.exe
2015-08-15 06:34:10 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2015-08-15 06:33:56 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2015-08-15 06:18:47 66560 ----a-w- C:\Windows\System32\iesetup.dll
2015-08-15 06:18:00 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2015-08-15 06:17:54 417792 ----a-w- C:\Windows\System32\html.iec
2015-08-15 06:17:49 585216 ----a-w- C:\Windows\System32\vbscript.dll
2015-08-15 06:17:25 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2015-08-15 06:04:47 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
2015-08-15 06:04:46 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2015-08-15 06:04:25 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2015-08-15 06:00:44 5923328 ----a-w- C:\Windows\System32\jscript9.dll
2015-08-15 05:57:20 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2015-08-15 05:53:22 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2015-08-15 05:46:15 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2015-08-15 05:40:29 504832 ----a-w- C:\Windows\SysWow64\vbscript.dll
2015-08-15 05:40:12 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2015-08-15 05:39:32 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2015-08-15 05:39:22 341504 ----a-w- C:\Windows\SysWow64\html.iec
2015-08-15 05:38:34 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2015-08-15 05:29:36 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2015-08-15 05:29:12 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2015-08-15 05:22:47 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2015-08-15 05:22:03 2126336 ----a-w- C:\Windows\System32\inetcpl.cpl
2015-08-15 05:16:37 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2015-08-15 05:10:32 4520448 ----a-w- C:\Windows\SysWow64\jscript9.dll
2015-08-15 05:07:28 2427392 ----a-w- C:\Windows\System32\wininet.dll
2015-08-15 05:01:47 2052608 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2015-08-15 05:01:23 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2015-08-15 04:43:00 1951232 ----a-w- C:\Windows\SysWow64\wininet.dll
2015-08-05 17:56:14 1110016 ----a-w- C:\Windows\System32\schedsvc.dll
2015-08-05 17:56:07 24576 ----a-w- C:\Windows\System32\jnwmon.dll
2015-08-05 17:56:06 275456 ----a-w- C:\Windows\System32\InkEd.dll
2015-08-05 17:40:50 216064 ----a-w- C:\Windows\SysWow64\InkEd.dll
2015-07-30 18:06:57 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2015-07-30 18:06:57 1648128 ----a-w- C:\Windows\System32\DWrite.dll
2015-07-30 18:06:57 1180160 ----a-w- C:\Windows\System32\FntCache.dll
2015-07-30 17:57:30 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2015-07-30 17:57:30 1251328 ----a-w- C:\Windows\SysWow64\DWrite.dll
2015-07-30 13:13:38 103120 ----a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-07-30 13:13:11 124624 ----a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2015-07-15 18:15:12 5568960 ----a-w- C:\Windows\System32\ntoskrnl.exe
2015-07-15 18:15:11 94656 ----a-w- C:\Windows\System32\drivers\mountmgr.sys
2015-07-15 18:15:10 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2015-07-15 18:15:10 155584 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2015-07-15 18:12:09 1730496 ----a-w- C:\Windows\System32\ntdll.dll
2015-07-15 18:11:14 362496 ----a-w- C:\Windows\System32\wow64win.dll
2015-07-15 18:11:14 243712 ----a-w- C:\Windows\System32\wow64.dll
2015-07-15 18:11:14 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2015-07-15 18:11:13 215040 ----a-w- C:\Windows\System32\winsrv.dll
2015-07-15 18:11:01 210944 ----a-w- C:\Windows\System32\wdigest.dll
2015-07-15 18:09:57 338432 ----a-w- C:\Windows\System32\conhost.exe
2015-07-15 18:09:52 64000 ----a-w- C:\Windows\System32\auditpol.exe
2015-07-15 18:05:47 60416 ----a-w- C:\Windows\System32\msobjs.dll
2015-07-15 18:05:26 146432 ----a-w- C:\Windows\System32\msaudite.dll
2015-07-15 17:59:45 3989952 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2015-07-15 17:59:45 3934656 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2015-07-15 17:56:24 1311768 ----a-w- C:\Windows\SysWow64\ntdll.dll
2015-07-15 17:55:07 172032 ----a-w- C:\Windows\SysWow64\wdigest.dll
2015-07-15 17:55:04 65536 ----a-w- C:\Windows\SysWow64\TSpkg.dll
2015-07-15 17:55:02 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
2015-07-15 17:55:00 248832 ----a-w- C:\Windows\SysWow64\schannel.dll
2015-07-15 17:55:00 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2015-07-15 17:54:56 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2015-07-15 17:54:55 221184 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2015-07-15 17:54:54 259584 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2015-07-15 17:54:49 552960 ----a-w- C:\Windows\SysWow64\kerberos.dll
2015-07-15 17:54:43 36864 ----a-w- C:\Windows\SysWow64\cryptbase.dll
2015-07-15 17:54:43 17408 ----a-w- C:\Windows\SysWow64\credssp.dll
2015-07-15 17:54:40 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2015-07-15 17:54:22 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2015-07-15 17:53:53 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2015-07-15 17:53:37 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2015-07-15 17:53:36 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2015-07-15 17:53:36 665088 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2015-07-15 17:53:36 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2015-07-15 17:49:10 60416 ----a-w- C:\Windows\SysWow64\msobjs.dll
2015-07-15 17:48:14 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll
.
============= FINISH: 14:09:06.30 ===============

Attached Files
File Type: txt attach.txt (10.6 KB)

possible bing virus

$
0
0
.Was instructed to post this dds scan as I think there may be a virus on my computer that is leaving me unable to get rid of bing as my homepage and search engine.I wish to have only google for this

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 15/06/2015 12:21:12
System Uptime: 28/09/2015 08:38:33 (0 hours ago)
.
Motherboard: Hewlett-Packard | | 3069
Processor: Celeron(R) Dual-Core CPU T3100 @ 1.90GHz | CPU | 1895/800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 931 GiB total, 890.948 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Description: USB Video Device
Device ID: USB\VID_04F2&PID_B153&MI_00\6&2A5231CD&0&0000
Manufacturer: Microsoft
Name: HP Webcam-101
PNP Device ID: USB\VID_04F2&PID_B153&MI_00\6&2A5231CD&0&0000
Service: usbvideo
.
==== System Restore Points ===================
.
RP42: 13/09/2015 09:31:09 - Windows Update
RP43: 16/09/2015 11:26:07 - Windows Update
RP44: 20/09/2015 11:16:08 - Windows Update
RP45: 23/09/2015 18:02:22 - Windows Update
RP46: 27/09/2015 09:23:45 - Windows Update
.
==== Hosts File Hijack ======================
.
Hosts: 127.0.0.1 ads.mcafee.com
Hosts: 127.0.0.1 ads.mcafee.com
Hosts: 127.0.0.1 analytics.microsoft.com
Hosts: 127.0.0.1 metrics.bitdefender.com
Hosts: 127.0.0.1 metrics.mcafee.com
Hosts: 127.0.0.1 om.symantec.com
Hosts: 127.0.0.1 ads.bleepingcomputer.com
Hosts: 127.0.0.1 wdcs.trendmicro.com
.
==== Installed Programs ======================
.
Adobe Flash Player 19 ActiveX
Adobe Reader XI (11.0.12)
Adobe Refresh Manager
Ashampoo Burning Studio FREE v.1.14.5
globalupdate Helper
Gmail Notifier
GT-Soft Ad Blocker
Malwarebytes Anti-Malware version 2.1.8.1057
Metric Collection SDK 35
Microsoft .NET Framework 4.5.2
Microsoft .NET Framework 4.5.2 (???????)
Microsoft .NET Framework 4.5.2 (RUS)
Microsoft Corporation
Microsoft LifeCam
Microsoft Security Client
Microsoft Security Essentials
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
Security Update for Microsoft .NET Framework 4.5.2 (KB2972107)
Security Update for Microsoft .NET Framework 4.5.2 (KB2972216)
Security Update for Microsoft .NET Framework 4.5.2 (KB2978128)
Security Update for Microsoft .NET Framework 4.5.2 (KB2979578v2)
Security Update for Microsoft .NET Framework 4.5.2 (KB3023224)
Security Update for Microsoft .NET Framework 4.5.2 (KB3035490)
Security Update for Microsoft .NET Framework 4.5.2 (KB3037581)
Security Update for Microsoft .NET Framework 4.5.2 (KB3074230)
Security Update for Microsoft .NET Framework 4.5.2 (KB3074550)
Setup
Synaptics Pointing Device Driver
Temp File Cleaner
VLC media player
.
==== Event Viewer Messages From Past Week ========
.
27/09/2015 09:25:21, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Microsoft Security Essentials - KB2310138 (Definition 1.207.1184.0).
27/09/2015 09:24:43, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.207.1176.0 Update Source: Microsoft Update Server Update Stage: Install Source Path: Microsoft ? Official Home Page Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.12101.0 Error code: 0x80070643 Error description: Fatal error during installation.
26/09/2015 10:30:50, Error: Schannel [36888] - The following fatal alert was generated: 43. The internal error state is 252.
25/09/2015 10:27:59, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Network Inspection System Error Code: 0x80070005 Error description: Access is denied. Reason: The system is missing updates that are required for running Network Inspection System. Install the required updates and restart the computer.
25/09/2015 10:27:58, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Start with the following error: Access is denied.
24/09/2015 17:45:10, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
24/09/2015 17:32:32, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
24/09/2015 17:32:32, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
24/09/2015 17:32:32, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
24/09/2015 17:32:32, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
24/09/2015 17:32:31, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
24/09/2015 17:32:25, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
24/09/2015 17:32:19, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DfsC discache MpFilter NetBIOS NetBT nsiproxy Psched rdbss SASDIFSV SASKUTIL spldr tdx vwififlt Wanarpv6 WfpLwf
24/09/2015 17:32:19, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
24/09/2015 17:32:19, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
24/09/2015 17:32:19, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
24/09/2015 17:32:19, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
24/09/2015 17:32:19, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
24/09/2015 17:32:19, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
24/09/2015 17:32:19, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
24/09/2015 17:32:19, Error: Service Control Manager [7001] - The Microsoft Network Inspection System service depends on the Microsoft Malware Protection Driver service which failed to start because of the following error: A device attached to the system is not functioning.
24/09/2015 17:32:19, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
24/09/2015 17:32:19, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
24/09/2015 17:32:19, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
22/09/2015 19:29:40, Error: Schannel [36887] - The following fatal alert was received: 20.
.
==== End Of File ===========================

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.18015
Run by User at 8:51:21 on 2015-09-28
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.3003.1965 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: Microsoft Security Essentials *Enabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\vVX1000.exe
C:\Program Files\Microsoft LifeCam\MSCamS64.exe
C:\Program Files (x86)\Softcomp Software\privoxy.exe
C:\Windows\system32\svchost.exe -k imgsvc
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Windows\system32\GWX\GWX.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Reader_sl.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uSearch Page = hxxp://www.google.com
uProxyOverride = <-loopback>
mWinlogon: Userinit = userinit.exe,
mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{8D8907E9-F3C5-49EE-908E-5C9E09CFDD2D} : DHCPNameServer = 192.168.1.1 0.0.0.0
AppInit_DLLs= C:\PROGRA~3\{01A6E~1\1173~1.1\mote.dll _C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC32LO~1.DLL
SSODL: WebCheck - <orphaned>
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [VX1000] C:\Windows\vVX1000.exe
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1 ads.mcafee.com
Hosts: 127.0.0.1 ads.mcafee.com
Hosts: 127.0.0.1 analytics.microsoft.com
Hosts: 127.0.0.1 metrics.bitdefender.com
Hosts: 127.0.0.1 metrics.mcafee.com
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2015-3-4 280376]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [2009-3-2 89600]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-14 27136]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2015-3-4 124568]
R2 PrivoxyService;Privoxy (PrivoxyService);C:\Program Files (x86)\Softcomp Software\privoxy.exe [2015-9-19 371200]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-4-30 366544]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-3-1 187392]
RUnknown SASKUTIL;SASKUTIL; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-4-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-4-11 124088]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2015-9-9 114688]
S3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\MBAMSwissArmy.sys [2015-6-16 113880]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2015-6-15 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2015-6-15 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2015-6-15 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2015-6-16 1255736]
.
=============== Created Last 30 ================
.
2015-09-27 08:29:01 11062400 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{DCEAF69A-257D-48BE-BAE7-309E1A3B1DB0}\mpengine.dll
2015-09-27 08:24:09 11062400 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-09-23 17:03:14 1190000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4DE014D5-3AAB-402E-9BBD-9A57262A5A8E}\gapaengine.dll
2015-09-22 07:45:44 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2015-09-20 12:10:18 -------- d-----w- C:\Program Files (x86)\Anti Virus Service
2015-09-19 14:34:57 -------- d-----w- C:\Program Files (x86)\Softcomp Software
2015-09-18 10:57:00 -------- d--h--w- C:\$Windows.~BT
2015-09-18 10:55:42 30208 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPDB8.DLL
2015-09-18 10:55:42 100352 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPPB8.DLL
2015-09-18 10:53:31 389120 ----a-w- C:\Windows\System32\CNMLMB8.DLL
2015-09-18 10:52:10 287744 ----a-w- C:\Windows\System32\CNC_B8C.dll
2015-09-18 10:52:10 106496 ----a-w- C:\Windows\System32\CNC_B8I.dll
2015-09-18 10:52:09 363520 ----a-w- C:\Windows\System32\CNC_B8L.dll
2015-09-18 10:52:09 17920 ----a-w- C:\Windows\System32\CNHMCA6.dll
2015-09-17 10:59:27 -------- d-----w- C:\Users\User\AppData\Roaming\InetStat
2015-09-16 11:01:29 -------- d-----w- C:\Users\User\AppData\Local\Lenovo
2015-09-16 11:00:34 -------- d-----w- C:\Program Files (x86)\Lenovo
2015-09-16 11:00:25 -------- d-----w- C:\Windows\Downloaded Installations
2015-09-16 11:00:12 -------- d-----w- C:\Users\User\AppData\Roaming\RPEng
2015-09-16 10:54:56 -------- d-----w- C:\Users\User\AppData\Roaming\Win Cleaner
2015-09-09 09:03:59 82944 ----a-w- C:\Windows\System32\dwmapi.dll
2015-09-09 09:02:58 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2015-09-06 11:16:22 -------- d-----w- C:\Program Files\Microsoft LifeCam
2015-09-06 11:16:22 -------- d-----w- C:\Program Files (x86)\Microsoft LifeCam
2015-09-06 11:16:10 1974616 ----a-w- C:\Windows\SysWow64\D3DCompiler_42.dll
2015-09-06 11:16:09 1892184 ----a-w- C:\Windows\SysWow64\D3DX9_42.dll
.
==================== Find3M ====================
.
2015-09-24 16:33:34 113880 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2015-09-22 14:12:51 780488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2015-09-22 14:12:51 142536 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-09-02 03:04:49 41984 ----a-w- C:\Windows\System32\lpk.dll
2015-09-02 03:04:46 100864 ----a-w- C:\Windows\System32\fontsub.dll
2015-09-02 03:04:44 14336 ----a-w- C:\Windows\System32\dciman32.dll
2015-09-02 03:04:42 46080 ----a-w- C:\Windows\System32\atmlib.dll
2015-09-02 02:48:31 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2015-09-02 02:48:28 10240 ----a-w- C:\Windows\SysWow64\dciman32.dll
2015-09-02 02:48:25 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2015-09-02 02:47:18 25600 ----a-w- C:\Windows\SysWow64\lpk.dll
2015-09-02 01:51:28 3209216 ----a-w- C:\Windows\System32\win32k.sys
2015-09-02 01:47:08 372736 ----a-w- C:\Windows\System32\atmfd.dll
2015-09-02 01:33:48 299520 ----a-w- C:\Windows\SysWow64\atmfd.dll
2015-08-27 18:18:27 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2015-08-27 18:18:27 1887232 ----a-w- C:\Windows\System32\msxml3.dll
2015-08-27 18:13:03 2048 ----a-w- C:\Windows\System32\msxml6r.dll
2015-08-27 18:13:03 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2015-08-27 17:58:14 1391104 ----a-w- C:\Windows\SysWow64\msxml6.dll
2015-08-27 17:58:14 1241088 ----a-w- C:\Windows\SysWow64\msxml3.dll
2015-08-27 17:51:26 2048 ----a-w- C:\Windows\SysWow64\msxml6r.dll
2015-08-27 17:51:26 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2015-08-26 18:07:11 98304 ----a-w- C:\Windows\System32\wudriver.dll
2015-08-26 18:07:11 3165696 ----a-w- C:\Windows\System32\wucltux.dll
2015-08-26 18:07:11 192000 ----a-w- C:\Windows\System32\wuwebv.dll
2015-08-26 18:06:43 91136 ----a-w- C:\Windows\System32\WinSetupUI.dll
2015-08-26 18:06:33 12288 ----a-w- C:\Windows\System32\wu.upgrade.ps.dll
2015-08-26 18:06:30 37376 ----a-w- C:\Windows\System32\wuapp.exe
2015-08-26 17:56:25 93184 ----a-w- C:\Windows\SysWow64\wudriver.dll
2015-08-26 17:56:25 173056 ----a-w- C:\Windows\SysWow64\wuwebv.dll
2015-08-26 17:55:37 34816 ----a-w- C:\Windows\SysWow64\wuapp.exe
2015-08-15 06:34:10 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2015-08-15 06:33:56 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2015-08-15 06:18:47 66560 ----a-w- C:\Windows\System32\iesetup.dll
2015-08-15 06:18:00 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2015-08-15 06:17:54 417792 ----a-w- C:\Windows\System32\html.iec
2015-08-15 06:17:49 585216 ----a-w- C:\Windows\System32\vbscript.dll
2015-08-15 06:17:25 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2015-08-15 06:04:47 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
2015-08-15 06:04:46 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2015-08-15 06:04:25 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2015-08-15 06:00:44 5923328 ----a-w- C:\Windows\System32\jscript9.dll
2015-08-15 05:57:20 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2015-08-15 05:53:22 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2015-08-15 05:46:15 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2015-08-15 05:40:29 504832 ----a-w- C:\Windows\SysWow64\vbscript.dll
2015-08-15 05:40:12 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2015-08-15 05:39:32 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2015-08-15 05:39:22 341504 ----a-w- C:\Windows\SysWow64\html.iec
2015-08-15 05:38:34 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2015-08-15 05:29:36 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2015-08-15 05:29:12 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2015-08-15 05:22:47 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2015-08-15 05:22:03 2126336 ----a-w- C:\Windows\System32\inetcpl.cpl
2015-08-15 05:16:37 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2015-08-15 05:10:32 4520448 ----a-w- C:\Windows\SysWow64\jscript9.dll
2015-08-15 05:07:28 2427392 ----a-w- C:\Windows\System32\wininet.dll
2015-08-15 05:01:47 2052608 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2015-08-15 05:01:23 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2015-08-15 04:43:00 1951232 ----a-w- C:\Windows\SysWow64\wininet.dll
2015-08-05 17:56:14 1110016 ----a-w- C:\Windows\System32\schedsvc.dll
2015-08-05 17:56:07 24576 ----a-w- C:\Windows\System32\jnwmon.dll
2015-08-05 17:56:06 275456 ----a-w- C:\Windows\System32\InkEd.dll
2015-08-05 17:40:50 216064 ----a-w- C:\Windows\SysWow64\InkEd.dll
2015-08-04 18:03:10 692672 ----a-w- C:\Windows\System32\winload.efi
2015-08-04 18:00:24 616360 ----a-w- C:\Windows\System32\winresume.efi
2015-08-04 17:56:54 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
2015-08-04 17:56:37 59392 ----a-w- C:\Windows\System32\appidapi.dll
2015-08-04 17:56:37 32768 ----a-w- C:\Windows\System32\appidsvc.dll
2015-08-04 17:55:57 147456 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2015-08-04 17:47:42 50688 ----a-w- C:\Windows\SysWow64\appidapi.dll
2015-08-04 16:58:09 61440 ----a-w- C:\Windows\System32\drivers\appid.sys
2015-08-03 08:50:43 113880 ----a-w- C:\Windows\System32\drivers\5BF44898.sys
2015-07-30 18:06:57 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2015-07-30 18:06:57 1648128 ----a-w- C:\Windows\System32\DWrite.dll
2015-07-30 18:06:57 1180160 ----a-w- C:\Windows\System32\FntCache.dll
2015-07-30 17:57:30 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2015-07-30 17:57:30 1251328 ----a-w- C:\Windows\SysWow64\DWrite.dll
2015-07-30 13:13:38 103120 ----a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-07-30 13:13:11 124624 ----a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2015-07-28 20:09:44 17344 ----a-w- C:\Windows\System32\CompatTelRunner.exe
2015-07-28 20:05:53 774656 ----a-w- C:\Windows\System32\invagent.dll
2015-07-28 20:05:50 743424 ----a-w- C:\Windows\System32\generaltel.dll
2015-07-28 20:05:47 437760 ----a-w- C:\Windows\System32\devinv.dll
2015-07-28 20:05:45 1116672 ----a-w- C:\Windows\System32\appraiser.dll
2015-07-28 20:05:44 69120 ----a-w- C:\Windows\System32\acmigration.dll
2015-07-28 20:05:44 227328 ----a-w- C:\Windows\System32\aepdu.dll
2015-07-28 19:55:14 1148416 ----a-w- C:\Windows\System32\aeinv.dll
2015-07-23 00:06:26 5568960 ----a-w- C:\Windows\System32\ntoskrnl.exe
2015-07-23 00:06:25 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2015-07-23 00:06:25 155584 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2015-07-23 00:03:19 1730496 ----a-w- C:\Windows\System32\ntdll.dll
2015-07-23 00:03:07 362496 ----a-w- C:\Windows\System32\wow64win.dll
2015-07-23 00:03:07 243712 ----a-w- C:\Windows\System32\wow64.dll
2015-07-23 00:03:07 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2015-07-23 00:03:06 215040 ----a-w- C:\Windows\System32\winsrv.dll
2015-07-23 00:01:53 31232 ----a-w- C:\Windows\System32\lsass.exe
2015-07-23 00:01:39 338432 ----a-w- C:\Windows\System32\conhost.exe
2015-07-23 00:01:32 64000 ----a-w- C:\Windows\System32\auditpol.exe
2015-07-22 23:58:17 60416 ----a-w- C:\Windows\System32\msobjs.dll
.
============= FINISH: 8:51:36.96 ===============

Attached Files
File Type: txt attach.txt (9.0 KB)
File Type: txt dds.txt (15.0 KB)

About:blank Flashes in Address Bar

$
0
0
My web pages are timing out or I get page cannot be displayed errors. The browser address bar briefly flashes about:blank and then tries to load the web page. The pages won't load or times out. I hadn't been able to update Microsoft Security Essentials and when I tried to scan my laptop - the scan process would get stuck on WOW64 files and I'd have to cancel the scan.

I ran MalwareBytes and it found nothing. I searched forums and found RogueKiller. So downloaded the free version and it found a removed something and I was then able to update Microsoft Essentials. I've since upgraded RogueKiller to premium status yesterday and today it said new update ready for download. I tried to update Rogue and I don't think it was successful.

RogueKiller continues to find something with the numbers 8.8.8.8 216.252.23.242 209.55.27.13 and resets it to 0 but doesn't remove it. It shows deleted but immediately shows up the next time I use the laptop.

I found a website called PC Hell and it said about:blank needs to be removed. I looked in the registry and found the key listed on the PC Hell website. I haven't done anything with it yet. I'm waiting to hear from the help on here.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

I removed MalwareBytes and Microsoft Essential. Left RogueKiller since it's a paid version. I disabled add blockers. I believe I've completed all the pre-steps for help from your forum. I'm attaching the DDS file. Thanks all.

I tried to post this thread 3-4 times using IE and all I got was can't display page.

Removing last traces of Malware

$
0
0
Hello Everyone,

I once was helped immensely back in the day resolving a virus infection on my computer, and someone here talked me through the whole process. I have a laptop that was used for downloading free games by a child and it was a mess.

The major issue I solved is there was a virus that was blocking me from running windows defender, screwing with the windows update and freezing the program and giving me an Windows Update error 800705b4. I'm happy to say I fixed this, but would like to see if I have the all clear for anything else.

The laptop is running windows 7, and I do not have access to the original install disk with validation codes. Thus, I did not reformat the hard drive..though I am eligible for windows 10 if the free download allows for a clean install (at this point I am wary of windows 10, thus it is a last case scenario).

For background, I have run EST online scanner, adaware from lavasoft, spybot search and destroy, and TDSSKiller from Kapersky.

Here is my DDS Text File:

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16521
Run by owner at 11:00:33 on 2015-10-01
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3894.1444 [GMT -4:00]
.
AV: Ad-Aware Antivirus *Enabled/Updated* {B0CC18C6-E527-6EE6-874C-9D19920E5619}
SP: Ad-Aware Antivirus *Enabled/Updated* {0BADF922-C31D-6168-BDFC-A66BE9891CA4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
FW: Ad-Aware Firewall *Disabled* {88F799E3-AF48-6FBE-AC13-342C6CDD1162}
.
============== Running Processes ===============
.
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\taskeng.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\windows\System32\svchost.exe -k utcsvc
C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.8.586.8535\AdAwareService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.8.586.8535\AdAwareTray.exe
C:\windows\system32\GWX\GWX.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\windows\system32\svchost.exe -k SDRSVC
C:\windows\servicing\TrustedInstaller.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\windows\system32\SearchProtocolHost.exe
C:\Users\owner\Downloads\FRST64.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\windows\system32\vssvc.exe
C:\windows\System32\svchost.exe -k swprv
C:\windows\system32\taskeng.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uLocal Page =
mStart Page = about:blank
mLocal Page =
uProxyServer = hxxp=127.0.0.1:49852;https=127.0.0.1:49852
uProxyOverride = <-loopback>
BHO: MRI_DISABLED - <orphaned>
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: TOSHIBA Media Controller Plug-in: {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
uRun: [SpybotPostWindows10UpgradeReInstall] "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{6BBD2F09-F8FB-4720-B5BE-E7CAE3B8F0AE} : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{6BBD2F09-F8FB-4720-B5BE-E7CAE3B8F0AE}\84F4D454D203132313F5548545 : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{6BBD2F09-F8FB-4720-B5BE-E7CAE3B8F0AE}\E424054502E4564777F627B6 : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{6BBD2F09-F8FB-4720-B5BE-E7CAE3B8F0AE}\F6365616E6 : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{C005F787-1D9B-4111-82C1-4B6E2C6F70BF} : DHCPNameServer = 75.75.75.75 75.75.76.76
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.101\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll",CreateReaderUserSettings
x64-mStart Page = about:blank
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-Run: [AdAwareTray] "C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.8.586.8535\AdAwareTray.exe"
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdfndisf6.sys [2015-1-6 93160]
R1 bdfwfpf;bdfwfpf;C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdfwfpf.sys [2015-1-6 102992]
R2 DiagTrack;Diagnostics Tracking Service;C:\windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 LavasoftAdAwareService11;Ad-Aware Service 11;C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.8.586.8535\AdAwareService.exe [2015-8-27 712432]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2015-9-30 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2015-9-30 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2015-9-30 171928]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\windows\System32\drivers\TVALZFL.sys [2009-6-19 14472]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-1-9 2320920]
R3 avc3;avc3;C:\windows\System32\drivers\avc3.sys [2015-7-29 1369288]
R3 avchv;avchv Function Driver;C:\windows\System32\drivers\avchv.sys [2015-7-29 271272]
R3 avckf;avckf;C:\windows\System32\drivers\avckf.sys [2015-7-29 747120]
R3 gzflt;gzflt;C:\Program Files\Lavasoft\Ad-Aware Antivirus\Antimalware Engine\3.0.98.0\gzflt.sys [2015-1-22 155912]
R3 HECIx64;Intel(R) Management Engine Interface;C:\windows\System32\drivers\HECIx64.sys [2009-9-17 56344]
R3 Impcd;Impcd;C:\windows\System32\drivers\Impcd.sys [2010-2-27 158976]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\windows\System32\drivers\L1C62x64.sys [2011-4-20 169584]
R3 PGEffect;Pangu effect driver;C:\windows\System32\drivers\PGEffect.sys [2011-1-9 35008]
R3 QIOMem;Generic IO & Memory Access;C:\windows\System32\drivers\QIOMem.sys [2009-6-15 12800]
R3 RTWlanE;Realtek Wireless LAN 802.11n PCI-E Network Adapter;C:\windows\System32\drivers\rtwlane.sys [2013-5-2 1514568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-4-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-4-11 124088]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-2-25 252928]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\windows\System32\ieetwcollector.exe [2014-3-20 111616]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\windows\System32\drivers\rdpvideominiport.sys [2015-9-29 19456]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\windows\System32\drivers\RtsUStor.sys [2011-1-9 239136]
S3 rtl8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\windows\System32\drivers\rtl8192Ce.sys [2010-4-28 932384]
S3 SrvHsfHDA;SrvHsfHDA;C:\windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-1-9 51512]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-2-5 137560]
S3 TPCHSrv;TPCH Service;C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-2-23 835952]
S3 TsUsbFlt;TsUsbFlt;C:\windows\System32\drivers\TsUsbFlt.sys [2015-9-29 56832]
S3 USBAAPL64;Apple Mobile USB Driver;C:\windows\System32\drivers\usbaapl64.sys [2011-5-10 51712]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\System32\Wat\WatAdminSvc.exe [2011-3-17 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile="C:\windows\System32\NOTEPAD.EXE" %1
FileExt: .ini: inifile="C:\windows\System32\NOTEPAD.EXE" %1
.
=============== Created Last 30 ================
.
2015-10-01 14:55:05 -------- d-----w- C:\FRST
2015-10-01 14:26:29 75888 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A40DA617-32C5-4600-9B6C-2788F163513E}\offreg.2492.dll
2015-10-01 13:30:38 11062400 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A40DA617-32C5-4600-9B6C-2788F163513E}\mpengine.dll
2015-10-01 04:24:53 -------- d-sh--w- C:\$RECYCLE.BIN
2015-10-01 03:28:59 98816 ----a-w- C:\windows\sed.exe
2015-10-01 03:28:59 256000 ----a-w- C:\windows\PEV.exe
2015-10-01 03:28:59 208896 ----a-w- C:\windows\MBR.exe
2015-10-01 02:58:19 -------- d-----w- C:\Program Files\Common Files\AV
2015-10-01 02:50:02 21040 ----a-w- C:\windows\System32\sdnclean64.exe
2015-10-01 02:50:01 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2015-10-01 02:49:53 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-10-01 01:48:42 246952 ------w- C:\windows\SysWow64\MpSigStub.exe
2015-10-01 01:43:44 -------- d-----w- C:\Program Files (x86)\ESET
2015-10-01 01:41:38 -------- d-----w- C:\ProgramData\Licenses
2015-10-01 01:41:36 129872 ----a-w- C:\windows\SysWow64\MSSTDFMT.DLL
2015-10-01 01:41:35 -------- d-----w- C:\Program Files (x86)\SpywareBlaster
2015-10-01 01:09:36 -------- d-----w- C:\ProgramData\BitDefender
2015-10-01 01:06:33 -------- d-----w- C:\Users\owner\AppData\Roaming\LavasoftStatistics
2015-10-01 01:06:32 2084072 ----a-w- C:\windows\System32\bdnc.dll
2015-10-01 01:06:29 96160 ----a-w- C:\windows\System32\bdpredir.dll
2015-10-01 01:06:29 209984 ----a-w- C:\windows\System32\BdFirewallSDK.dll
2015-10-01 01:06:29 195016 ----a-w- C:\windows\System32\httproxy.dll
2015-10-01 01:06:29 156936 ----a-w- C:\windows\System32\bdfwcore.dll
2015-10-01 01:06:29 155912 ----a-w- C:\windows\System32\bdpop3p.dll
2015-10-01 01:06:29 122928 ----a-w- C:\windows\System32\OEMbdpredir.dll
2015-10-01 01:06:29 1061776 ----a-w- C:\windows\System32\bdsmtpp.dll
2015-10-01 01:05:26 -------- d-----w- C:\Program Files\Lavasoft
2015-10-01 01:04:17 -------- d-----w- C:\Program Files\Common Files\Lavasoft
2015-09-30 23:34:13 429568 ----a-w- C:\windows\System32\wksprt.exe
2015-09-30 23:34:12 7077376 ----a-w- C:\windows\System32\mstscax.dll
2015-09-30 23:34:12 6131200 ----a-w- C:\windows\SysWow64\mstscax.dll
2015-09-30 23:34:11 856064 ----a-w- C:\windows\SysWow64\rdvidcrl.dll
2015-09-30 23:34:11 62976 ----a-w- C:\windows\System32\tsgqec.dll
2015-09-30 23:34:11 53248 ----a-w- C:\windows\SysWow64\tsgqec.dll
2015-09-30 23:34:11 1057792 ----a-w- C:\windows\System32\rdvidcrl.dll
2015-09-30 21:22:13 3180544 ----a-w- C:\windows\System32\rdpcorets.dll
2015-09-30 21:22:12 243200 ----a-w- C:\windows\System32\rdpudd.dll
2015-09-30 21:22:12 16384 ----a-w- C:\windows\System32\RdpGroupPolicyExtension.dll
2015-09-30 21:21:54 87040 ----a-w- C:\windows\System32\TSWbPrxy.exe
2015-09-29 21:38:28 44544 ----a-w- C:\windows\System32\TsUsbGDCoInstaller.dll
2015-09-29 21:38:21 3072 ----a-w- C:\windows\System32\drivers\en-US\tsusbflt.sys.mui
2015-09-29 21:38:11 56832 ----a-w- C:\windows\System32\drivers\TsUsbFlt.sys
2015-09-29 21:38:11 13824 ----a-w- C:\windows\System32\TsUsbRedirectionGroupPolicyControl.exe
2015-09-29 21:38:11 12800 ----a-w- C:\windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2015-09-29 21:38:09 56832 ----a-w- C:\windows\System32\MsRdpWebAccess.dll
2015-09-29 21:38:09 50176 ----a-w- C:\windows\SysWow64\MsRdpWebAccess.dll
2015-09-29 21:38:09 18944 ----a-w- C:\windows\System32\wksprtPS.dll
2015-09-29 21:38:09 17920 ----a-w- C:\windows\SysWow64\wksprtPS.dll
2015-09-29 21:38:09 1147392 ----a-w- C:\windows\System32\mstsc.exe
2015-09-29 21:38:09 1068544 ----a-w- C:\windows\SysWow64\mstsc.exe
2015-09-29 19:25:24 -------- d-----w- C:\278070e1c7b09d6a5638d70919fa7ef0
2015-09-29 19:22:47 19456 ----a-w- C:\windows\System32\drivers\rdpvideominiport.sys
2015-09-29 19:22:46 192000 ----a-w- C:\windows\SysWow64\rdpendp_winip.dll
2015-09-29 19:22:45 228864 ----a-w- C:\windows\System32\rdpendp_winip.dll
2015-09-29 19:19:00 97112 ----a-w- C:\windows\System32\drivers\ksecdd.sys
2015-09-29 19:19:00 157016 ----a-w- C:\windows\System32\drivers\ksecpkg.sys
2015-09-29 19:19:00 1461760 ----a-w- C:\windows\System32\lsasrv.dll
2015-09-29 17:44:20 124624 ----a-w- C:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2015-09-29 17:44:20 103120 ----a-w- C:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-09-29 16:16:42 2048 ----a-w- C:\windows\SysWow64\tzres.dll
2015-09-29 16:15:59 1987584 ----a-w- C:\windows\SysWow64\d3d10warp.dll
2015-09-29 16:14:52 2004480 ----a-w- C:\windows\System32\msxml6.dll
2015-09-10 06:58:25 -------- d-----w- C:\$Windows.~BT
.
==================== Find3M ====================
.
2015-09-29 16:41:06 780488 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2015-09-29 16:41:06 142536 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-09-02 03:04:49 41984 ----a-w- C:\windows\System32\lpk.dll
2015-09-02 03:04:46 100864 ----a-w- C:\windows\System32\fontsub.dll
2015-09-02 03:04:44 14336 ----a-w- C:\windows\System32\dciman32.dll
2015-09-02 03:04:42 46080 ----a-w- C:\windows\System32\atmlib.dll
2015-09-02 02:48:31 70656 ----a-w- C:\windows\SysWow64\fontsub.dll
2015-09-02 02:48:28 10240 ----a-w- C:\windows\SysWow64\dciman32.dll
2015-09-02 02:48:25 34304 ----a-w- C:\windows\SysWow64\atmlib.dll
2015-09-02 02:47:18 25600 ----a-w- C:\windows\SysWow64\lpk.dll
2015-09-02 01:51:28 3209216 ----a-w- C:\windows\System32\win32k.sys
2015-09-02 01:47:08 372736 ----a-w- C:\windows\System32\atmfd.dll
2015-09-02 01:33:48 299520 ----a-w- C:\windows\SysWow64\atmfd.dll
2015-08-27 18:18:27 1887232 ----a-w- C:\windows\System32\msxml3.dll
2015-08-27 18:13:03 2048 ----a-w- C:\windows\System32\msxml6r.dll
2015-08-27 18:13:03 2048 ----a-w- C:\windows\System32\msxml3r.dll
2015-08-27 17:58:14 1391104 ----a-w- C:\windows\SysWow64\msxml6.dll
2015-08-27 17:58:14 1241088 ----a-w- C:\windows\SysWow64\msxml3.dll
2015-08-27 17:51:26 2048 ----a-w- C:\windows\SysWow64\msxml6r.dll
2015-08-27 17:51:26 2048 ----a-w- C:\windows\SysWow64\msxml3r.dll
2015-08-26 18:07:11 98304 ----a-w- C:\windows\System32\wudriver.dll
2015-08-26 18:07:11 3165696 ----a-w- C:\windows\System32\wucltux.dll
2015-08-26 18:07:11 192000 ----a-w- C:\windows\System32\wuwebv.dll
2015-08-26 18:06:43 91136 ----a-w- C:\windows\System32\WinSetupUI.dll
2015-08-26 18:06:33 12288 ----a-w- C:\windows\System32\wu.upgrade.ps.dll
2015-08-26 18:06:30 37376 ----a-w- C:\windows\System32\wuapp.exe
2015-08-26 17:56:25 93184 ----a-w- C:\windows\SysWow64\wudriver.dll
2015-08-26 17:56:25 173056 ----a-w- C:\windows\SysWow64\wuwebv.dll
2015-08-26 17:55:37 34816 ----a-w- C:\windows\SysWow64\wuapp.exe
2015-08-05 17:55:24 31232 ----a-w- C:\windows\System32\lsass.exe
2015-08-05 17:55:07 64000 ----a-w- C:\windows\System32\auditpol.exe
2015-08-05 17:50:36 60416 ----a-w- C:\windows\System32\msobjs.dll
2015-08-05 17:50:25 146432 ----a-w- C:\windows\System32\msaudite.dll
2015-08-05 17:46:22 686080 ----a-w- C:\windows\System32\adtschema.dll
2015-08-05 17:41:08 172032 ----a-w- C:\windows\SysWow64\wdigest.dll
2015-08-05 17:41:05 65536 ----a-w- C:\windows\SysWow64\TSpkg.dll
2015-08-05 17:41:01 22016 ----a-w- C:\windows\SysWow64\secur32.dll
2015-08-05 17:41:00 248832 ----a-w- C:\windows\SysWow64\schannel.dll
2015-08-05 17:40:56 221184 ----a-w- C:\windows\SysWow64\ncrypt.dll
2015-08-05 17:40:55 259584 ----a-w- C:\windows\SysWow64\msv1_0.dll
2015-08-05 17:40:50 552960 ----a-w- C:\windows\SysWow64\kerberos.dll
2015-08-05 17:40:50 216064 ----a-w- C:\windows\SysWow64\InkEd.dll
2015-08-05 17:40:43 36864 ----a-w- C:\windows\SysWow64\cryptbase.dll
2015-08-05 17:40:43 17408 ----a-w- C:\windows\SysWow64\credssp.dll
2015-08-05 17:39:50 50176 ----a-w- C:\windows\SysWow64\auditpol.exe
2015-08-05 17:39:36 96768 ----a-w- C:\windows\SysWow64\sspicli.dll
2015-08-05 17:39:36 665088 ----a-w- C:\windows\SysWow64\rpcrt4.dll
2015-08-05 17:34:50 60416 ----a-w- C:\windows\SysWow64\msobjs.dll
2015-08-05 17:34:27 146432 ----a-w- C:\windows\SysWow64\msaudite.dll
2015-08-05 17:30:33 686080 ----a-w- C:\windows\SysWow64\adtschema.dll
2015-08-05 17:06:37 39936 ----a-w- C:\windows\System32\drivers\tssecsrv.sys
2015-08-05 16:38:01 159232 ----a-w- C:\windows\System32\drivers\mrxsmb.sys
2015-08-05 16:37:17 290816 ----a-w- C:\windows\System32\drivers\mrxsmb10.sys
2015-08-05 16:37:11 129024 ----a-w- C:\windows\System32\drivers\mrxsmb20.sys
2015-08-04 18:03:10 692672 ----a-w- C:\windows\System32\winload.efi
2015-08-04 18:00:24 616360 ----a-w- C:\windows\System32\winresume.efi
2015-08-04 17:56:54 63488 ----a-w- C:\windows\System32\setbcdlocale.dll
2015-08-04 17:56:37 59392 ----a-w- C:\windows\System32\appidapi.dll
2015-08-04 17:56:37 32768 ----a-w- C:\windows\System32\appidsvc.dll
2015-08-04 17:55:57 17920 ----a-w- C:\windows\System32\appidcertstorecheck.exe
2015-08-04 17:55:57 147456 ----a-w- C:\windows\System32\appidpolicyconverter.exe
2015-08-04 17:47:42 50688 ----a-w- C:\windows\SysWow64\appidapi.dll
2015-08-04 16:58:09 61440 ----a-w- C:\windows\System32\drivers\appid.sys
2015-07-30 18:06:57 2565120 ----a-w- C:\windows\System32\d3d10warp.dll
2015-07-30 18:06:57 1648128 ----a-w- C:\windows\System32\DWrite.dll
2015-07-30 18:06:57 1180160 ----a-w- C:\windows\System32\FntCache.dll
2015-07-30 17:57:30 1251328 ----a-w- C:\windows\SysWow64\DWrite.dll
2015-07-29 19:16:14 747120 ----a-w- C:\windows\System32\drivers\avckf.sys
2015-07-29 19:16:14 271272 ----a-w- C:\windows\System32\drivers\avchv.sys
2015-07-29 19:16:14 1721576 ----a-w- C:\windows\System32\WdfCoInstaller01009.dll
2015-07-29 19:16:14 1369288 ----a-w- C:\windows\System32\drivers\avc3.sys
2015-07-28 20:09:44 17344 ----a-w- C:\windows\System32\CompatTelRunner.exe
2015-07-28 20:05:53 774656 ----a-w- C:\windows\System32\invagent.dll
2015-07-28 20:05:50 743424 ----a-w- C:\windows\System32\generaltel.dll
2015-07-28 20:05:47 437760 ----a-w- C:\windows\System32\devinv.dll
2015-07-28 20:05:45 1116672 ----a-w- C:\windows\System32\appraiser.dll
2015-07-28 20:05:44 69120 ----a-w- C:\windows\System32\acmigration.dll
2015-07-28 20:05:44 227328 ----a-w- C:\windows\System32\aepdu.dll
2015-07-28 19:55:14 1148416 ----a-w- C:\windows\System32\aeinv.dll
2015-07-23 00:06:26 5568960 ----a-w- C:\windows\System32\ntoskrnl.exe
2015-07-23 00:03:19 1730496 ----a-w- C:\windows\System32\ntdll.dll
2015-07-23 00:03:07 362496 ----a-w- C:\windows\System32\wow64win.dll
2015-07-23 00:03:07 243712 ----a-w- C:\windows\System32\wow64.dll
2015-07-23 00:03:07 13312 ----a-w- C:\windows\System32\wow64cpu.dll
2015-07-23 00:03:06 215040 ----a-w- C:\windows\System32\winsrv.dll
2015-07-23 00:02:54 1390592 ----a-w- C:\windows\System32\diagtrack.dll
2015-07-23 00:02:51 879104 ----a-w- C:\windows\System32\tdh.dll
2015-07-23 00:02:49 503808 ----a-w- C:\windows\System32\srcore.dll
2015-07-23 00:02:49 50176 ----a-w- C:\windows\System32\srclient.dll
2015-07-23 00:02:43 16384 ----a-w- C:\windows\System32\ntvdm64.dll
2015-07-23 00:02:40 424448 ----a-w- C:\windows\System32\KernelBase.dll
2015-07-23 00:02:33 43520 ----a-w- C:\windows\System32\csrsrv.dll
2015-07-23 00:02:31 879104 ----a-w- C:\windows\System32\advapi32.dll
2015-07-23 00:02:14 112640 ----a-w- C:\windows\System32\smss.exe
2015-07-23 00:02:05 296960 ----a-w- C:\windows\System32\rstrui.exe
2015-07-23 00:01:39 338432 ----a-w- C:\windows\System32\conhost.exe
2015-07-22 17:57:49 3989952 ----a-w- C:\windows\SysWow64\ntkrnlpa.exe
2015-07-22 17:57:49 3934656 ----a-w- C:\windows\SysWow64\ntoskrnl.exe
2015-07-22 17:54:12 1311768 ----a-w- C:\windows\SysWow64\ntdll.dll
2015-07-22 17:53:31 635392 ----a-w- C:\windows\SysWow64\tdh.dll
.
============= FINISH: 11:00:54.97 ===============

Attached Files
File Type: txt attach.txt (18.3 KB)

Constant browser pop-ups (ad-type.google.com)

$
0
0
Hello!

I posted about this issue a couple of weeks ago, but didn't know to look at thread replies instead of Private Messages, and so never realized I'd gotten a response. Here's the original post. I have copied the body of the post at the end of this one.

------------------------------------------------------

Response to original reply from Chemist (Thank you! Sorry!):

When you totally reset your router, did you create both a new userid and a new password?

The user id could not be changed because the ISP gave it to us and I could not find a way to change it. I did change the name of the wireless connection, but I suspect that might not have been what you mean...?

Below are the requested logs. I have attached the Addition.txt log from the Farbar Recovery Scan Tool with this message

AdwCleaner log:

# AdwCleaner v5.009 - Logfile created 02/10/2015 at 08:56:20
# Updated 27/09/2015 by Xplode
# Database : 2015-09-27.1 [Local]
# Operating system : Windows 8.1 Single Language (x64)
# Username : BALAN - LENOVO
# Running from : F:\SOFTWARE\AdwCleaner.exe
# Option : Scan
# Support : Forum - ToolsLib

***** [ Services ] *****


***** [ Folders ] *****

Folder Found : C:\ProgramData\Lenovo App Services

***** [ Files ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

Task Found : Lenovo App Services

***** [ Registry ] *****

Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL] - hxxp://mystart.lenovo.com
Data Found : HKU\S-1-5-21-3688482777-3306477040-3792482504-1001\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL] - hxxp://mystart.lenovo.com

***** [ Web browsers ] *****


########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [901 bytes] ##########


Farbar Recovery Scan Tool log (FRST.txt):

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:30-09-2015
Ran by BALAN (administrator) on LENOVO (02-10-2015 09:26:10)
Running from F:\SOFTWARE
Loaded Profiles: BALAN (Available Profiles: BALAN)
Platform: Windows 8.1 Single Language (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(CyberLink) C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
() C:\Program Files\Lenovo PhoneCompanion\adb.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
() C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
() C:\Program Files (x86)\Lenovo\CCSDK\WinGather.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-05] (Conexant Systems, Inc.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2891592 2014-02-11] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [216064 2014-01-07] (Realtek Semiconductor Corporation)
HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [6340312 2014-02-27] (Realtek semiconductor)
HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2015-05-28] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2015-05-28] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10842096 2015-05-28] (Lenovo(beijing) Limited)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-02-02] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe [110344 2014-09-09] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\Lenovo\Power2Go\VirtualDrive.exe [492808 2014-09-09] (CyberLink Corp.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-12-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-05] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [36710720 2015-09-26] (Dropbox, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [477064 2013-12-22] (Autodesk Inc.)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguix.exe [1125800 2015-09-22] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3812264 2015-09-30] (AVG Technologies CZ, s.r.o.)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3688482777-3306477040-3792482504-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8455960 2015-08-20] (Piriform Ltd)
HKU\S-1-5-21-3688482777-3306477040-3792482504-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3688482777-3306477040-3792482504-1001\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1193352 2014-02-08] (Autodesk, Inc.)
HKU\S-1-5-21-3688482777-3306477040-3792482504-1001\...\Policies\Explorer: []
HKU\S-1-5-18\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1193352 2014-02-08] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\windows\system32\AcSignIcon.dll [2014-02-07] (Autodesk, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-09-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-09-26] (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 5.152.219.53 5.152.219.52
Tcpip\..\Interfaces\{2B7F527A-0A19-47E0-B697-DBD59E957E91}: [DhcpNameServer] 150.208.1.2
Tcpip\..\Interfaces\{3C7520B1-E03C-426F-B13D-59AE07D6DB01}: [DhcpNameServer] 5.152.219.53 5.152.219.52

Internet Explorer:
==================
HKU\S-1-5-21-3688482777-3306477040-3792482504-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3688482777-3306477040-3792482504-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3688482777-3306477040-3792482504-1001 -> DefaultScope {3CFE6B59-7267-4B6D-9EAD-28A22D6B7764} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
SearchScopes: HKU\S-1-5-21-3688482777-3306477040-3792482504-1001 -> {260D1364-389F-4C71-899A-636DD5C0669F} URL =
SearchScopes: HKU\S-1-5-21-3688482777-3306477040-3792482504-1001 -> {3CFE6B59-7267-4B6D-9EAD-28A22D6B7764} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-28] (Oracle Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-28] (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-3688482777-3306477040-3792482504-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File

FireFox:
========
FF ProfilePath: C:\Users\BALAN\AppData\Roaming\Mozilla\Firefox\Profiles\zpqc17gi.default
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-28] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2011-09-05] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Extension: Block site - C:\Users\BALAN\AppData\Roaming\Mozilla\Firefox\Profiles\zpqc17gi.default\Extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc} [2015-09-28]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2015-09-21]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [576904 2013-12-22] (Autodesk Inc.)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [31192 2014-02-07] (Autodesk, Inc.)
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [604712 2015-09-30] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3792880 2015-09-30] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1042344 2015-09-22] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [596344 2015-09-30] (AVG Technologies CZ, s.r.o.)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [84992 2014-01-23] () [File not signed]
R2 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [592880 2014-07-10] ()
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-09-28] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-09-28] (Dropbox, Inc.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [99632 2013-10-09] (ELAN Microelectronics Corp.)
S2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [561408 2014-09-23] (Lenovo)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584632 2015-03-06] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2015-05-28] (Lenovo(beijing) Limited)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [272776 2014-09-04] ()
R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [38896 2014-02-18] (Lenovo(beijing) Limited)
S2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [782608 2015-08-21] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [332528 2014-03-13] (McAfee, Inc.)
S2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.6.1008.0\McCSPServiceHost.exe [1694152 2015-07-23] (McAfee, Inc.)
S4 McNaiAnn; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [639456 2015-07-17] (McAfee, Inc.)
S2 McProxy; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
S2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2015-05-28] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [308720 2015-05-28] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [51712 2014-02-24] (Advanced Micro Devices, Inc.)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [68880 2015-05-28] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
S2 mfemms; "C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe" [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [85704 2014-02-24] (Advanced Micro Devices, Inc. )
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [62152 2014-10-28] (Advanced Micro Devices, Inc.)
R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [230088 2014-02-24] (Advanced Micro Devices, Inc. )
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [229056 2014-10-29] (AppEx Networks Corporation)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [223232 2014-12-21] (Advanced Micro Devices)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [23152 2015-09-09] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [197040 2015-08-10] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [312752 2015-09-11] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [298416 2015-08-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [293296 2015-08-10] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [398256 2015-08-14] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [251312 2015-08-10] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-08-10] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [314800 2015-08-31] (AVG Technologies CZ, s.r.o.)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-11-21] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-13] (CyberLink)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [207208 2015-05-19] (McAfee, Inc.)
S3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [412440 2015-07-02] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [109728 2015-06-28] (McAfee, Inc.)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3344352 2013-07-09] (Intel Corporation)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [558296 2014-01-14] (Realtek Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [9109720 2014-02-27] (Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3593432 2014-10-07] (Realtek Semiconductor Corporation )
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-02 09:25 - 2015-10-02 09:26 - 00000000 ____D C:\FRST
2015-10-02 08:56 - 2015-10-02 09:05 - 00000000 ____D C:\AdwCleaner
2015-10-02 08:39 - 2015-10-02 08:39 - 00000000 ____D C:\windows\system32\appraiser
2015-10-02 08:11 - 2015-10-02 08:11 - 00001249 _____ C:\Users\BALAN\Desktop\TSF instructions.txt
2015-10-02 08:08 - 2015-10-02 09:26 - 00002125 _____ C:\Users\BALAN\Desktop\TechSupportForum.txt
2015-10-01 19:29 - 2015-10-01 19:29 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2015-10-01 19:29 - 2015-10-01 19:29 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
2015-10-01 17:48 - 2015-10-01 17:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dominion
2015-10-01 17:48 - 2015-10-01 17:48 - 00000000 ____D C:\Program Files (x86)\Dominion
2015-10-01 01:53 - 2015-10-01 01:53 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\AVG
2015-10-01 01:52 - 2015-10-01 19:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-10-01 01:52 - 2015-10-01 01:52 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\TuneUp Software
2015-10-01 01:51 - 2015-10-01 01:51 - 00000000 ___HD C:\$AVG
2015-10-01 01:27 - 2015-10-01 01:51 - 00000000 ____D C:\ProgramData\Avg
2015-10-01 01:27 - 2015-10-01 01:48 - 00000000 ____D C:\Program Files (x86)\AVG
2015-10-01 00:51 - 2015-10-01 01:32 - 00000000 ____D C:\Users\BALAN\AppData\Local\AvgSetupLog
2015-10-01 00:48 - 2015-10-01 19:27 - 00000000 ____D C:\Users\BALAN\AppData\Local\Avg
2015-09-30 23:21 - 2015-10-02 08:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-09-30 22:15 - 2015-09-30 22:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-09-30 12:11 - 2015-09-30 12:11 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\ATI
2015-09-30 12:11 - 2015-09-30 12:11 - 00000000 ____D C:\Users\BALAN\AppData\Local\ATI
2015-09-30 12:11 - 2015-09-30 12:11 - 00000000 ____D C:\ProgramData\ATI
2015-09-30 11:40 - 2015-09-30 11:41 - 00000000 ___SD C:\windows\system32\GWX
2015-09-30 11:40 - 2015-09-30 11:40 - 00000000 ___SD C:\windows\SysWOW64\GWX
2015-09-30 11:25 - 2015-10-01 00:44 - 00135964 _____ C:\Users\BALAN\Downloads\RWH3.htm
2015-09-30 11:25 - 2015-10-01 00:44 - 00126583 _____ C:\Users\BALAN\Downloads\RWH1.htm
2015-09-30 11:25 - 2015-10-01 00:44 - 00124871 _____ C:\Users\BALAN\Downloads\RWH4.htm
2015-09-30 11:25 - 2015-10-01 00:44 - 00120965 _____ C:\Users\BALAN\Downloads\RWH2.htm
2015-09-30 11:25 - 2015-09-30 11:25 - 00000000 ____D C:\Users\BALAN\Downloads\RWH4_files
2015-09-30 11:25 - 2015-09-30 11:25 - 00000000 ____D C:\Users\BALAN\Downloads\RWH3_files
2015-09-30 11:25 - 2015-09-30 11:25 - 00000000 ____D C:\Users\BALAN\Downloads\RWH2_files
2015-09-30 11:25 - 2015-09-30 11:25 - 00000000 ____D C:\Users\BALAN\Downloads\RWH1_files
2015-09-30 00:13 - 2015-09-30 00:18 - 00000000 ____D C:\windows\system32\MRT
2015-09-30 00:13 - 2015-08-26 18:37 - 134753440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-09-30 00:04 - 2015-09-30 00:04 - 00000000 ____D C:\Users\BALAN\Documents\Autodesk Application Manager
2015-09-30 00:02 - 2015-09-30 00:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk ReCap
2015-09-29 23:58 - 2015-09-29 23:58 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\AMD
2015-09-29 23:57 - 2015-09-30 00:23 - 00000000 ____D C:\Users\BALAN\AppData\Local\Autodesk
2015-09-29 23:57 - 2015-09-29 23:57 - 00000000 ____D C:\Users\BALAN\Documents\Inventor Server SDK ACAD 2015
2015-09-29 23:57 - 2015-09-29 23:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoCAD 2015 - English
2015-09-29 23:55 - 2015-09-29 23:55 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared
2015-09-29 23:51 - 2015-09-30 00:04 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared
2015-09-29 23:51 - 2015-09-30 00:03 - 00000000 ____D C:\Program Files\Autodesk
2015-09-29 23:51 - 2015-09-29 23:51 - 00000000 ____D C:\Users\Public\Documents\Autodesk
2015-09-29 23:45 - 2015-09-30 00:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
2015-09-29 23:44 - 2015-09-29 23:44 - 00000674 _____ C:\windows\DirectX.log
2015-09-29 23:44 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_7.dll
2015-09-29 23:44 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_7.dll
2015-09-29 23:44 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_7.dll
2015-09-29 23:44 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_7.dll
2015-09-29 23:44 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_5.dll
2015-09-29 23:44 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_5.dll
2015-09-29 23:44 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_43.dll
2015-09-29 23:44 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_43.dll
2015-09-29 23:44 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_43.dll
2015-09-29 23:44 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_43.dll
2015-09-29 23:44 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\windows\system32\d3dcsx_43.dll
2015-09-29 23:44 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dcsx_43.dll
2015-09-29 23:44 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_43.dll
2015-09-29 23:44 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_43.dll
2015-09-29 23:44 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\windows\system32\d3dx11_43.dll
2015-09-29 23:44 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx11_43.dll
2015-09-29 23:44 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_30.dll
2015-09-29 23:44 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_30.dll
2015-09-29 23:44 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_1.dll
2015-09-29 23:44 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_1.dll
2015-09-29 23:44 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\windows\system32\xinput1_1.dll
2015-09-29 23:44 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\windows\SysWOW64\xinput1_1.dll
2015-09-29 23:44 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\windows\system32\x3daudio1_0.dll
2015-09-29 23:44 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\windows\SysWOW64\x3daudio1_0.dll
2015-09-29 23:41 - 2015-09-30 00:04 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\Autodesk
2015-09-29 23:41 - 2015-09-30 00:04 - 00000000 ____D C:\ProgramData\Autodesk
2015-09-29 23:40 - 2015-09-29 23:40 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\My Bluetooth
2015-09-29 23:22 - 2015-09-29 23:46 - 00000000 ____D C:\Program Files (x86)\Autodesk
2015-09-29 12:23 - 2015-09-29 12:25 - 00000000 ____D C:\Users\BALAN\Desktop\Office 2010
2015-09-29 12:15 - 2015-09-29 12:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2015-09-29 12:15 - 2015-09-29 12:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-09-29 12:13 - 2015-09-29 12:13 - 00000000 ____D C:\windows\PCHEALTH
2015-09-29 12:13 - 2015-09-29 12:13 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services
2015-09-29 12:13 - 2015-09-29 12:13 - 00000000 ____D C:\Program Files (x86)\Microsoft Sync Framework
2015-09-29 12:13 - 2015-09-29 12:13 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-09-28 18:55 - 2015-10-02 08:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-09-28 18:55 - 2015-09-28 19:10 - 00000000 ____D C:\Users\BALAN\AppData\Local\Mozilla
2015-09-28 18:55 - 2015-09-28 19:06 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\Mozilla
2015-09-28 18:55 - 2015-09-28 18:55 - 00001186 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-09-28 11:54 - 2015-09-28 11:54 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-09-28 11:17 - 2015-09-28 11:17 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\Sun
2015-09-28 11:17 - 2015-09-28 11:17 - 00000000 ____D C:\Users\BALAN\.oracle_jre_usage
2015-09-28 11:17 - 2015-09-28 11:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-09-28 11:17 - 2015-09-28 11:16 - 00097888 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2015-09-28 11:16 - 2015-09-28 11:16 - 00000000 ____D C:\ProgramData\Oracle
2015-09-28 11:16 - 2015-09-28 11:16 - 00000000 ____D C:\Program Files (x86)\Java
2015-09-28 10:00 - 2015-09-28 10:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-09-28 09:59 - 2015-09-28 09:59 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\Dropbox
2015-09-28 09:37 - 2015-09-28 09:37 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\.mono
2015-09-28 09:37 - 2015-09-28 09:37 - 00000000 ____D C:\ProgramData\.mono
2015-09-28 09:36 - 2015-10-02 09:06 - 00000916 _____ C:\windows\Tasks\DropboxUpdateTaskMachineCore.job
2015-09-28 09:36 - 2015-10-02 07:41 - 00000920 _____ C:\windows\Tasks\DropboxUpdateTaskMachineUA.job
2015-09-28 09:36 - 2015-09-28 09:36 - 00003892 _____ C:\windows\System32\Tasks\DropboxUpdateTaskMachineUA
2015-09-28 09:36 - 2015-09-28 09:36 - 00003656 _____ C:\windows\System32\Tasks\DropboxUpdateTaskMachineCore
2015-09-22 12:27 - 2015-07-09 21:44 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-09-22 12:27 - 2015-03-20 09:19 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\compstui.dll
2015-09-22 12:27 - 2015-03-20 08:38 - 00477184 _____ (Microsoft Corporation) C:\windows\system32\puiobj.dll
2015-09-22 12:27 - 2015-03-20 08:07 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\puiobj.dll
2015-09-22 12:27 - 2015-03-20 07:37 - 01091072 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2015-09-22 12:27 - 2015-03-17 22:56 - 00467776 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS
2015-09-22 12:27 - 2015-03-13 07:32 - 00316416 _____ (Microsoft Corporation) C:\windows\system32\Drivers\udfs.sys
2015-09-22 12:27 - 2015-01-29 06:34 - 00864256 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2015-09-22 12:27 - 2015-01-28 07:54 - 00075264 _____ (Microsoft Corporation) C:\windows\system32\StorageContextHandler.dll
2015-09-22 12:27 - 2015-01-28 07:17 - 00060928 _____ (Microsoft Corporation) C:\windows\SysWOW64\StorageContextHandler.dll
2015-09-22 12:27 - 2015-01-27 09:14 - 00933888 _____ (Microsoft Corporation) C:\windows\system32\calc.exe
2015-09-22 12:27 - 2015-01-24 07:21 - 00816128 _____ (Microsoft Corporation) C:\windows\SysWOW64\calc.exe
2015-09-22 12:27 - 2015-01-23 12:47 - 00723072 _____ (Microsoft Corporation) C:\windows\system32\SHCore.dll
2015-09-22 12:27 - 2015-01-23 10:32 - 00560392 _____ (Microsoft Corporation) C:\windows\SysWOW64\SHCore.dll
2015-09-22 12:26 - 2015-09-03 07:48 - 02531400 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2015-09-22 12:26 - 2015-09-03 07:47 - 01903848 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2015-09-22 12:26 - 2015-09-03 00:18 - 02345472 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-09-22 12:26 - 2015-09-02 22:39 - 01556992 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-09-22 12:26 - 2015-05-07 23:20 - 22292672 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-09-22 12:26 - 2015-05-07 22:30 - 03109376 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2015-09-22 12:26 - 2015-05-07 22:23 - 19734960 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-09-22 12:26 - 2015-05-07 21:42 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2015-09-22 12:26 - 2015-05-07 20:51 - 00522240 _____ (Microsoft Corporation) C:\windows\system32\GeofenceMonitorService.dll
2015-09-22 12:26 - 2015-05-07 20:35 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\GeofenceMonitorService.dll
2015-09-22 12:26 - 2015-04-10 06:04 - 02256896 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
2015-09-22 12:26 - 2015-04-10 05:41 - 01943040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmcore.dll
2015-09-22 12:26 - 2015-03-14 13:50 - 01385256 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2015-09-22 12:26 - 2015-03-14 13:43 - 01124352 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctf.dll
2015-09-22 12:26 - 2015-03-09 07:32 - 00057856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthhfenum.sys
2015-09-22 12:26 - 2015-01-29 07:28 - 00347136 _____ (Microsoft Corporation) C:\windows\system32\photowiz.dll
2015-09-22 12:26 - 2015-01-29 06:59 - 00290816 _____ (Microsoft Corporation) C:\windows\SysWOW64\photowiz.dll
2015-09-22 12:26 - 2014-12-19 14:27 - 00788680 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2015-09-22 12:26 - 2014-12-19 13:55 - 00602776 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2015-09-22 12:25 - 2015-07-22 19:49 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\UtcResources.dll
2015-09-22 12:25 - 2015-07-22 19:22 - 01633792 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2015-09-22 12:25 - 2015-07-17 19:45 - 00951296 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2015-09-22 12:25 - 2015-07-17 19:40 - 00749568 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll
2015-09-22 12:25 - 2015-06-27 17:17 - 00118616 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2015-09-22 12:25 - 2015-05-11 23:47 - 01201664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthport.sys
2015-09-22 12:25 - 2015-04-09 04:11 - 00158720 _____ (Microsoft Corporation) C:\windows\SysWOW64\rgb9rast.dll
2015-09-22 12:25 - 2015-04-03 06:05 - 00445440 _____ (Microsoft Corporation) C:\windows\system32\PhotoMetadataHandler.dll
2015-09-22 12:25 - 2015-04-03 05:44 - 00364544 _____ (Microsoft Corporation) C:\windows\SysWOW64\PhotoMetadataHandler.dll
2015-09-22 12:25 - 2015-04-02 03:52 - 02985984 _____ (Microsoft Corporation) C:\windows\SysWOW64\dbgeng.dll
2015-09-22 12:25 - 2015-04-02 03:50 - 04417536 _____ (Microsoft Corporation) C:\windows\system32\dbgeng.dll
2015-09-22 12:25 - 2015-04-01 09:15 - 01491456 _____ (Microsoft Corporation) C:\windows\system32\dbghelp.dll
2015-09-22 12:25 - 2015-04-01 08:01 - 01207296 _____ (Microsoft Corporation) C:\windows\SysWOW64\dbghelp.dll
2015-09-22 12:25 - 2015-03-20 07:26 - 00080384 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ahcache.sys
2015-09-22 12:25 - 2015-03-13 06:41 - 02162176 _____ (Microsoft Corporation) C:\windows\system32\SRH.dll
2015-09-22 12:25 - 2015-03-13 06:09 - 01812992 _____ (Microsoft Corporation) C:\windows\SysWOW64\SRH.dll
2015-09-22 12:25 - 2015-03-04 07:02 - 00172544 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Input.Inking.dll
2015-09-22 12:25 - 2015-03-04 06:42 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Input.Inking.dll
2015-09-22 12:25 - 2015-03-02 07:13 - 00222208 _____ (Microsoft Corporation) C:\windows\system32\rastapi.dll
2015-09-22 12:25 - 2015-03-02 06:51 - 00207872 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastapi.dll
2015-09-22 12:25 - 2015-01-30 08:31 - 00097792 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidbth.sys
2015-09-22 12:25 - 2015-01-30 08:30 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rfcomm.sys
2015-09-22 12:25 - 2014-11-14 12:28 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\SystemSettingsDatabase.dll
2015-09-22 12:24 - 2015-07-15 03:29 - 01113944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2015-09-22 12:24 - 2015-07-15 03:29 - 00487256 _____ (Microsoft Corporation) C:\windows\system32\netcfgx.dll
2015-09-22 12:24 - 2015-07-15 03:29 - 00393560 _____ (Microsoft Corporation) C:\windows\SysWOW64\netcfgx.dll
2015-09-22 12:24 - 2015-07-14 00:40 - 00411455 _____ C:\windows\system32\ApnDatabase.xml
2015-09-22 12:24 - 2015-07-07 15:10 - 00270168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdFilter.sys
2015-09-22 12:24 - 2015-07-07 15:10 - 00114520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdNisDrv.sys
2015-09-22 12:24 - 2015-07-07 15:10 - 00044560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdBoot.sys
2015-09-22 12:24 - 2015-07-04 03:21 - 01380056 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-09-22 12:24 - 2015-07-03 19:30 - 01097216 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2015-09-22 12:24 - 2015-06-12 22:33 - 18823680 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Xaml.dll
2015-09-22 12:24 - 2015-06-12 22:06 - 15159296 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Xaml.dll
2015-09-22 12:24 - 2015-04-25 07:55 - 00020992 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usb8023.sys
2015-09-22 12:24 - 2015-02-03 05:23 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\winshfhc.dll
2015-09-22 12:24 - 2015-02-03 05:23 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\winshfhc.dll
2015-09-22 12:24 - 2014-12-11 11:06 - 00046456 _____ (Microsoft Corporation) C:\windows\system32\LockScreenContentServer.exe
2015-09-22 12:23 - 2015-06-19 22:37 - 02819072 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers.dll
2015-09-22 12:23 - 2015-03-06 08:17 - 01696256 _____ (Microsoft Corporation) C:\windows\system32\wevtsvc.dll
2015-09-22 12:23 - 2015-02-03 05:33 - 03551744 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_47.dll
2015-09-22 12:23 - 2015-02-03 05:32 - 04298240 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_47.dll
2015-09-22 12:23 - 2015-01-30 07:33 - 01488896 _____ (Microsoft Corporation) C:\windows\system32\mfc42u.dll
2015-09-22 12:23 - 2015-01-30 07:33 - 01464832 _____ (Microsoft Corporation) C:\windows\system32\mfc42.dll
2015-09-22 12:23 - 2015-01-30 07:14 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfc42u.dll
2015-09-22 12:23 - 2015-01-30 07:12 - 01204224 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfc42.dll
2015-09-22 12:23 - 2015-01-20 00:12 - 01487976 _____ (Microsoft Corporation) C:\windows\system32\sppobjs.dll
2015-09-22 12:22 - 2015-07-29 04:54 - 00025776 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2015-09-22 12:22 - 2015-07-28 19:54 - 01148416 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-09-22 12:22 - 2015-07-28 19:54 - 01116160 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-09-22 12:22 - 2015-07-28 19:54 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-09-22 12:22 - 2015-07-28 19:54 - 00743424 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-09-22 12:22 - 2015-07-28 19:54 - 00437248 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-09-22 12:22 - 2015-07-28 19:54 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-09-22 12:22 - 2015-06-27 04:51 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-09-22 12:22 - 2015-05-21 18:38 - 00193536 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-09-22 12:22 - 2015-05-03 20:39 - 00274944 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-09-22 12:22 - 2015-05-03 20:28 - 00210944 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-09-22 12:22 - 2015-05-03 20:25 - 00971776 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll
2015-09-22 12:22 - 2015-05-03 20:19 - 00811008 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll
2015-09-22 12:22 - 2015-02-18 04:49 - 00186368 _____ (Microsoft Corporation) C:\windows\system32\dpapisrv.dll
2015-09-22 12:20 - 2015-05-11 22:04 - 00332800 _____ (Microsoft Corporation) C:\windows\system32\fhcpl.dll
2015-09-22 12:20 - 2015-04-16 11:47 - 00325464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBXHCI.SYS
2015-09-22 12:20 - 2015-04-14 04:07 - 00275968 _____ (Microsoft Corporation) C:\windows\system32\authz.dll
2015-09-22 12:20 - 2015-04-14 04:04 - 00180224 _____ (Microsoft Corporation) C:\windows\SysWOW64\authz.dll
2015-09-22 12:20 - 2015-04-10 06:10 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\UIAutomationCore.dll
2015-09-22 12:20 - 2015-04-10 05:47 - 01018880 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIAutomationCore.dll
2015-09-22 12:19 - 2015-06-12 01:42 - 02476376 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2015-09-22 12:19 - 2015-06-12 01:42 - 00428888 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2015-09-22 12:19 - 2015-04-28 18:43 - 00513480 _____ C:\windows\SysWOW64\locale.nls
2015-09-22 12:19 - 2015-04-28 18:43 - 00513480 _____ C:\windows\system32\locale.nls
2015-09-22 12:19 - 2015-04-01 09:51 - 00337408 _____ (Microsoft Corporation) C:\windows\system32\SearchProtocolHost.exe
2015-09-22 12:19 - 2015-04-01 09:48 - 00468480 _____ (Microsoft Corporation) C:\windows\system32\mssph.dll
2015-09-22 12:19 - 2015-04-01 09:47 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\mssphtb.dll
2015-09-22 12:19 - 2015-04-01 09:38 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\mssvp.dll
2015-09-22 12:19 - 2015-04-01 09:16 - 03633664 _____ (Microsoft Corporation) C:\windows\system32\tquery.dll
2015-09-22 12:19 - 2015-04-01 08:47 - 02551808 _____ (Microsoft Corporation) C:\windows\system32\mssrch.dll
2015-09-22 12:19 - 2015-04-01 08:47 - 00903168 _____ (Microsoft Corporation) C:\windows\system32\SearchIndexer.exe
2015-09-22 12:19 - 2015-04-01 08:23 - 00391680 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssph.dll
2015-09-22 12:19 - 2015-04-01 08:23 - 00272896 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchProtocolHost.exe
2015-09-22 12:19 - 2015-04-01 08:15 - 02749952 _____ (Microsoft Corporation) C:\windows\SysWOW64\tquery.dll
2015-09-22 12:19 - 2015-04-01 08:15 - 00699392 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssvp.dll
2015-09-22 12:19 - 2015-04-01 07:44 - 01920000 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssrch.dll
2015-09-22 12:19 - 2015-04-01 07:42 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchIndexer.exe
2015-09-22 12:19 - 2015-03-13 09:33 - 00239424 _____ (Microsoft Corporation) C:\windows\system32\Drivers\sdbus.sys
2015-09-22 12:19 - 2015-03-13 09:33 - 00154432 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dumpsd.sys
2015-09-22 12:19 - 2015-01-30 07:32 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\eappgnui.dll
2015-09-22 12:19 - 2015-01-30 07:10 - 00091648 _____ (Microsoft Corporation) C:\windows\SysWOW64\eappgnui.dll
2015-09-22 12:19 - 2015-01-30 07:07 - 00331776 _____ (Microsoft Corporation) C:\windows\system32\eapp3hst.dll
2015-09-22 12:19 - 2015-01-30 06:54 - 00339456 _____ (Microsoft Corporation) C:\windows\system32\eapphost.dll
2015-09-22 12:19 - 2015-01-30 06:54 - 00250880 _____ (Microsoft Corporation) C:\windows\SysWOW64\eapp3hst.dll
2015-09-22 12:19 - 2015-01-30 06:46 - 00266752 _____ (Microsoft Corporation) C:\windows\SysWOW64\eapphost.dll
2015-09-22 12:19 - 2015-01-30 06:38 - 00346112 _____ (Microsoft Corporation) C:\windows\system32\eappcfg.dll
2015-09-22 12:19 - 2015-01-30 06:36 - 00278016 _____ (Microsoft Corporation) C:\windows\SysWOW64\eappcfg.dll
2015-09-22 12:17 - 2015-07-11 00:36 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthpan.sys
2015-09-22 12:17 - 2015-05-12 18:49 - 00294912 _____ (Microsoft Corporation) C:\windows\system32\SystemEventsBrokerServer.dll
2015-09-22 12:17 - 2015-05-03 20:37 - 07784448 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
2015-09-22 12:17 - 2015-05-03 20:27 - 05264384 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
2015-09-22 12:17 - 2015-04-23 21:17 - 03084288 _____ (Microsoft Corporation) C:\windows\system32\msftedit.dll
2015-09-22 12:17 - 2015-04-23 20:46 - 02471424 _____ (Microsoft Corporation) C:\windows\SysWOW64\msftedit.dll
2015-09-22 12:17 - 2015-03-06 08:38 - 02067968 _____ (Microsoft Corporation) C:\windows\system32\wpdshext.dll
2015-09-22 12:17 - 2015-03-06 08:13 - 01969664 _____ (Microsoft Corporation) C:\windows\SysWOW64\wpdshext.dll
2015-09-22 12:16 - 2015-02-08 05:27 - 01090048 _____ (Microsoft Corporation) C:\windows\system32\MrmCoreR.dll
2015-09-22 12:16 - 2015-02-08 05:19 - 00791040 _____ (Microsoft Corporation) C:\windows\SysWOW64\MrmCoreR.dll
2015-09-22 12:16 - 2015-01-28 05:17 - 02501368 _____ (Microsoft Corporation) C:\windows\explorer.exe
2015-09-22 12:16 - 2015-01-28 05:11 - 02207488 _____ (Microsoft Corporation) C:\windows\SysWOW64\explorer.exe
2015-09-22 12:13 - 2015-04-30 04:52 - 00130048 _____ (Microsoft Corporation) C:\windows\system32\WiFiDisplay.dll
2015-09-22 11:48 - 2015-10-02 08:39 - 00000000 ____D C:\ProgramData\MFAData
2015-09-22 11:48 - 2015-09-22 11:48 - 00000000 ____D C:\Users\BALAN\AppData\Local\MFAData
2015-09-22 11:48 - 2015-09-22 11:48 - 00000000 ____D C:\Users\BALAN\AppData\Local\Avg2015
2015-09-22 11:44 - 2015-09-22 11:44 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2015-09-21 22:08 - 2015-09-21 22:08 - 00003064 _____ C:\windows\System32\Tasks\McAfeeLogon
2015-09-21 22:08 - 2015-09-21 22:08 - 00000000 ____D C:\windows\System32\Tasks\McAfee
2015-09-21 21:01 - 2015-08-22 23:49 - 25188352 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-09-21 21:01 - 2015-08-22 23:05 - 02886144 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-09-21 21:01 - 2015-08-22 23:04 - 00585216 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-09-21 21:01 - 2015-08-22 22:52 - 19856384 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-09-21 21:01 - 2015-08-22 22:51 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-09-21 21:01 - 2015-08-22 22:50 - 05923840 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-09-21 21:01 - 2015-08-22 22:25 - 00504832 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-09-21 21:01 - 2015-08-22 22:20 - 02279424 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-09-21 21:01 - 2015-08-22 22:20 - 01032704 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2015-09-21 21:01 - 2015-08-22 22:15 - 00665600 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-09-21 21:01 - 2015-08-22 22:14 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-09-21 21:01 - 2015-08-22 22:11 - 14451712 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-09-21 21:01 - 2015-08-22 22:11 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-09-21 21:01 - 2015-08-22 22:11 - 00720384 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-09-21 21:01 - 2015-08-22 22:11 - 00374784 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-09-21 21:01 - 2015-08-22 22:09 - 02126336 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-09-21 21:01 - 2015-08-22 21:58 - 04520448 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-09-21 21:01 - 2015-08-22 21:56 - 02427392 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-09-21 21:01 - 2015-08-22 21:53 - 00880128 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2015-09-21 21:01 - 2015-08-22 21:52 - 12857344 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-09-21 21:01 - 2015-08-22 21:50 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-09-21 21:01 - 2015-08-22 21:48 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-09-21 21:01 - 2015-08-22 21:48 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-09-21 21:01 - 2015-08-22 21:48 - 00327168 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-09-21 21:01 - 2015-08-22 21:44 - 01545728 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-09-21 21:01 - 2015-08-22 21:31 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-09-21 21:01 - 2015-08-22 21:30 - 01951232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-09-21 21:01 - 2015-08-22 21:26 - 01310720 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-09-21 21:01 - 2015-08-22 21:25 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-09-21 21:01 - 2015-07-17 02:06 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-09-21 21:01 - 2015-07-17 01:53 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-09-21 21:01 - 2015-07-17 01:23 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2015-09-21 21:01 - 2015-07-17 01:20 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-09-21 21:01 - 2015-07-17 01:11 - 00479232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-09-21 21:01 - 2015-07-17 00:44 - 02880000 _____ (Microsoft Corporation) C:\windows\system32\actxprxy.dll
2015-09-21 21:01 - 2015-07-17 00:22 - 01048576 _____ (Microsoft Corporation) C:\windows\SysWOW64\actxprxy.dll
2015-09-21 21:01 - 2015-06-16 04:08 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-09-21 21:01 - 2015-06-16 03:32 - 00087552 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2015-09-21 21:01 - 2015-06-16 03:28 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-09-21 21:01 - 2015-06-16 03:27 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-09-21 21:01 - 2015-06-16 03:25 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-09-21 21:01 - 2015-06-16 02:43 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-09-21 21:01 - 2015-06-16 02:17 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2015-09-21 21:01 - 2015-06-16 02:14 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-09-21 21:01 - 2015-06-16 02:13 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-09-21 21:01 - 2015-06-16 02:12 - 00128000 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2015-09-21 21:01 - 2015-06-16 02:11 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-09-21 21:01 - 2015-05-23 08:34 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-09-21 21:01 - 2015-05-23 00:17 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-09-21 21:01 - 2015-04-21 21:43 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2015-09-21 21:01 - 2015-01-12 07:51 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-09-21 21:01 - 2015-01-12 07:15 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-09-21 20:45 - 2015-09-02 08:26 - 04175872 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-09-21 20:45 - 2015-09-02 08:25 - 00358912 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-09-21 20:45 - 2015-09-02 08:20 - 00044032 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-09-21 20:45 - 2015-09-02 07:47 - 00301568 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-09-21 20:45 - 2015-09-02 07:43 - 00035840 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-09-21 20:45 - 2015-07-22 20:04 - 02775552 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-09-21 20:45 - 2015-07-22 20:03 - 01728000 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Immersive.dll
2015-09-21 20:45 - 2015-07-22 19:55 - 02461184 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2015-09-21 20:45 - 2015-07-22 19:55 - 01546752 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Immersive.dll
2015-09-21 20:45 - 2015-07-19 00:01 - 00194048 _____ (Microsoft Corporation) C:\windows\system32\shacct.dll
2015-09-21 20:45 - 2015-07-18 23:59 - 00655872 _____ (Microsoft Corporation) C:\windows\system32\SettingSync.dll
2015-09-21 20:45 - 2015-07-18 23:59 - 00148480 _____ (Microsoft Corporation) C:\windows\SysWOW64\shacct.dll
2015-09-21 20:45 - 2015-07-18 23:57 - 00520192 _____ (Microsoft Corporation) C:\windows\SysWOW64\SettingSync.dll
2015-09-21 20:45 - 2015-07-02 03:49 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2015-09-21 20:45 - 2015-07-02 03:46 - 00104448 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2015-09-21 20:45 - 2015-07-02 03:07 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2015-09-21 20:45 - 2015-07-02 03:05 - 00087040 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2015-09-21 20:40 - 2015-07-14 01:16 - 00059392 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-09-21 20:40 - 2015-07-14 01:15 - 00059392 _____ (Microsoft Corporation) C:\windows\system32\basesrv.dll
2015-09-21 20:40 - 2015-06-16 04:11 - 00065024 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
2015-09-21 20:40 - 2015-06-16 03:54 - 03320320 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2015-09-21 20:40 - 2015-06-16 02:46 - 00059904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
2015-09-21 20:40 - 2015-06-16 02:39 - 03607552 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2015-09-21 20:31 - 2015-06-28 10:37 - 00442712 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-09-21 20:31 - 2015-06-28 10:37 - 00178008 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-09-21 20:31 - 2015-06-28 10:36 - 01311960 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-09-21 20:31 - 2015-06-28 10:36 - 00332120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-09-21 20:31 - 2015-06-27 22:12 - 00747520 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-09-21 20:31 - 2015-06-27 08:43 - 00202240 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-09-21 20:31 - 2015-06-27 08:42 - 00401408 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-09-21 20:31 - 2015-06-27 08:42 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-09-21 20:31 - 2015-06-27 08:10 - 00445440 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2015-09-21 20:31 - 2015-06-27 07:35 - 01441792 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-09-21 20:31 - 2015-06-27 07:30 - 00989184 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-09-21 20:31 - 2015-06-27 07:23 - 00324096 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2015-09-21 20:31 - 2015-06-27 06:56 - 00802816 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-09-21 20:31 - 2015-03-30 11:17 - 00561928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-09-21 20:30 - 2015-05-31 02:48 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\werdiagcontroller.dll
2015-09-21 20:30 - 2015-05-31 01:06 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\AudioEndpointBuilder.dll
2015-09-21 20:30 - 2015-05-31 01:05 - 00911360 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-09-21 20:30 - 2015-05-01 04:35 - 00429568 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-09-21 20:30 - 2015-05-01 04:18 - 00358912 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-09-21 20:30 - 2014-12-09 09:15 - 00393728 _____ (Microsoft Corporation) C:\windows\SysWOW64\scesrv.dll
2015-09-21 20:30 - 2014-12-09 07:26 - 00538624 _____ (Microsoft Corporation) C:\windows\system32\scesrv.dll
2015-09-21 20:26 - 2015-09-21 20:26 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2015-09-21 13:18 - 2015-09-21 13:18 - 00000029 _____ C:\Users\BALAN\Documents\serial.txt
2015-09-21 13:17 - 2015-09-21 13:17 - 00003498 _____ C:\windows\System32\Tasks\AdobeAAMUpdater-1.0-Lenovo-BALAN
2015-09-21 13:10 - 2015-09-21 13:17 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2015-09-21 12:36 - 2015-09-21 12:36 - 00000000 ____D C:\ProgramData\ALM
2015-09-21 12:26 - 2015-09-21 12:26 - 00000000 ____D C:\Users\BALAN\Adobe Flash Builder 4.6
2015-09-21 12:19 - 2015-09-21 12:19 - 00002481 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
2015-09-21 12:19 - 2015-09-21 12:19 - 00002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk
2015-09-21 12:19 - 2015-09-21 12:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2
2015-09-21 12:15 - 2015-09-21 12:15 - 00001124 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Widget Browser.lnk
2015-09-21 12:14 - 2015-09-21 12:14 - 00000000 ____D C:\Program Files (x86)\My Company Name
2015-09-21 12:14 - 2011-11-03 03:01 - 00056208 ____N (Rovi Corporation) C:\windows\system32\Drivers\PxHlpa64.sys
2015-09-21 12:14 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\windows\system32\Drivers\cdralw2k.sys
2015-09-21 12:14 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\windows\system32\Drivers\cdr4_xp.sys
2015-09-21 12:09 - 2015-09-21 12:09 - 00001024 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2015-09-21 12:02 - 2015-09-21 12:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS6
2015-09-21 12:01 - 2015-09-21 12:48 - 00000000 ____D C:\Program Files\Adobe
2015-09-21 12:00 - 2015-09-21 12:48 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-09-21 11:52 - 2015-07-30 19:34 - 00124624 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-09-21 11:52 - 2015-07-30 19:18 - 00103120 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-09-21 11:43 - 2015-10-02 08:39 - 00006324 _____ C:\windows\PFRO.log
2015-09-21 11:26 - 2015-08-27 08:18 - 00136904 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-09-21 11:26 - 2015-08-26 23:30 - 00721920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-09-21 11:26 - 2015-08-26 23:30 - 00124928 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-09-21 11:26 - 2015-08-26 23:30 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-09-21 11:26 - 2015-08-26 23:30 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-09-21 11:26 - 2015-08-26 20:16 - 03705344 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-09-21 11:26 - 2015-08-26 19:59 - 02240512 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-09-21 11:26 - 2015-08-26 19:57 - 00891904 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-09-21 11:26 - 2015-08-26 19:57 - 00409088 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2015-09-21 11:26 - 2015-08-26 19:56 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-09-21 11:26 - 2015-08-26 19:56 - 00095744 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-09-21 11:26 - 2015-08-26 19:56 - 00035840 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-09-21 11:26 - 2015-07-10 00:10 - 00359936 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-09-21 11:26 - 2015-06-27 08:38 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-09-21 11:26 - 2015-06-27 08:38 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-09-21 11:26 - 2015-06-27 07:44 - 00027136 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-09-21 11:20 - 2015-07-16 05:59 - 07458648 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-09-21 11:20 - 2015-07-16 05:59 - 01735000 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-09-21 11:20 - 2015-07-16 05:59 - 00101720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2015-09-21 11:20 - 2015-07-16 05:58 - 01499920 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-09-21 11:20 - 2015-07-10 23:24 - 01217024 _____ (Microsoft Corporation) C:\windows\system32\sysmain.dll
2015-09-21 11:20 - 2015-01-30 06:59 - 00035840 _____ (Microsoft Corporation) C:\windows\SysWOW64\atlthunk.dll
2015-09-21 11:19 - 2015-07-30 22:48 - 00268288 _____ (Microsoft Corporation) C:\windows\system32\InkEd.dll
2015-09-21 11:19 - 2015-07-30 21:52 - 00230912 _____ (Microsoft Corporation) C:\windows\SysWOW64\InkEd.dll
2015-09-21 11:13 - 2015-03-24 03:29 - 00360480 _____ (Microsoft Corporation) C:\windows\system32\sechost.dll
2015-09-21 11:13 - 2015-03-24 03:15 - 00257216 _____ (Microsoft Corporation) C:\windows\SysWOW64\sechost.dll
2015-09-21 11:13 - 2015-03-20 09:42 - 00246272 _____ (Microsoft Corporation) C:\windows\system32\microsoft-windows-system-events.dll
2015-09-21 11:13 - 2015-03-20 09:40 - 00285184 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-09-21 11:13 - 2015-03-20 09:40 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-09-21 11:13 - 2015-03-20 08:47 - 00411648 _____ (Microsoft Corporation) C:\windows\system32\tracerpt.exe
2015-09-21 11:13 - 2015-03-20 08:11 - 00369152 _____ (Microsoft Corporation) C:\windows\SysWOW64\tracerpt.exe
2015-09-21 11:12 - 2015-04-09 04:25 - 00410128 _____ (Microsoft Corporation) C:\windows\system32\services.exe
2015-09-21 11:12 - 2015-03-13 08:28 - 00259072 _____ (Microsoft Corporation) C:\windows\system32\pku2u.dll
2015-09-21 11:12 - 2015-03-13 08:07 - 00208896 _____ (Microsoft Corporation) C:\windows\SysWOW64\pku2u.dll
2015-09-21 11:12 - 2014-06-10 03:43 - 00035480 _____ (Microsoft Corporation) C:\windows\SysWOW64\TsWpfWrp.exe
2015-09-21 11:12 - 2014-06-10 03:43 - 00035480 _____ (Microsoft Corporation) C:\windows\system32\TsWpfWrp.exe
2015-09-20 16:20 - 2015-07-10 23:49 - 01101824 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2015-09-20 16:20 - 2015-07-10 22:44 - 00856064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2015-09-20 16:20 - 2015-07-10 22:43 - 07032320 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-09-20 16:20 - 2015-07-10 22:01 - 06213120 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2015-09-20 16:20 - 2015-03-14 07:21 - 00015360 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-09-20 16:20 - 2015-03-14 05:39 - 00200192 _____ (Microsoft Corporation) C:\windows\system32\storewuauth.dll
2015-09-20 16:20 - 2015-02-24 14:02 - 00991552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2015-09-20 16:19 - 2015-08-04 02:45 - 00074928 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2015-09-20 16:19 - 2015-08-04 02:45 - 00065600 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2015-09-20 16:19 - 2015-08-01 19:52 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2015-09-20 16:19 - 2015-08-01 09:17 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\schtasks.exe
2015-09-20 16:19 - 2015-08-01 09:15 - 00182784 _____ (Microsoft Corporation) C:\windows\SysWOW64\schtasks.exe
2015-09-20 16:19 - 2015-08-01 09:08 - 01265152 _____ (Microsoft Corporation) C:\windows\system32\schedsvc.dll
2015-09-20 16:19 - 2015-08-01 09:07 - 00468992 _____ (Microsoft Corporation) C:\windows\system32\taskeng.exe
2015-09-20 16:19 - 2015-08-01 09:07 - 00359936 _____ (Microsoft Corporation) C:\windows\SysWOW64\taskeng.exe
2015-09-20 16:19 - 2015-07-29 20:07 - 01994752 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-09-20 16:19 - 2015-07-29 20:00 - 01381888 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-09-20 16:19 - 2015-07-29 19:53 - 01559552 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2015-09-20 16:19 - 2015-07-14 08:57 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\tzsync.exe
2015-09-20 16:19 - 2015-07-09 22:43 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\notepad.exe
2015-09-20 16:19 - 2015-07-09 22:43 - 00221184 _____ (Microsoft Corporation) C:\windows\notepad.exe
2015-09-20 16:19 - 2015-07-09 22:00 - 00212992 _____ (Microsoft Corporation) C:\windows\SysWOW64\notepad.exe
2015-09-20 16:19 - 2015-06-16 11:06 - 01661576 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2015-09-20 16:19 - 2015-06-16 11:06 - 01212248 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2015-09-20 16:19 - 2015-04-25 08:04 - 00653824 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll
2015-09-20 16:19 - 2015-04-25 08:03 - 00549888 _____ (Microsoft Corporation) C:\windows\SysWOW64\comctl32.dll
2015-09-20 16:19 - 2015-03-04 15:55 - 00377152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\clfs.sys
2015-09-20 16:19 - 2015-03-04 08:34 - 00075264 _____ (Microsoft Corporation) C:\windows\system32\clfsw32.dll
2015-09-20 16:19 - 2015-03-04 07:49 - 00058880 _____ (Microsoft Corporation) C:\windows\SysWOW64\clfsw32.dll
2015-09-20 16:19 - 2015-01-31 04:50 - 00203264 _____ (Microsoft Corporation) C:\windows\system32\ubpm.dll
2015-09-20 16:19 - 2015-01-30 00:15 - 01763352 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-09-20 16:19 - 2015-01-30 00:04 - 01488040 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2015-09-20 16:19 - 2015-01-28 07:01 - 00402432 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2015-09-20 16:19 - 2015-01-28 06:41 - 00357376 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2015-09-20 16:19 - 2015-01-27 09:52 - 00131584 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2015-09-20 16:19 - 2015-01-27 07:41 - 03547648 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2015-09-20 16:19 - 2014-07-24 08:50 - 00875688 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr120_clr0400.dll
2015-09-20 16:19 - 2014-07-24 08:50 - 00869544 _____ (Microsoft Corporation) C:\windows\system32\msvcr120_clr0400.dll
2015-09-20 16:14 - 2015-05-07 22:17 - 00564224 _____ (Microsoft Corporation) C:\windows\system32\apphelp.dll
2015-09-20 16:14 - 2015-03-11 07:19 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\sdbinst.exe
2015-09-20 16:14 - 2015-03-11 06:39 - 00021504 _____ (Microsoft Corporation) C:\windows\SysWOW64\sdbinst.exe
2015-09-20 14:06 - 2015-05-19 13:59 - 00207208 ____N (McAfee, Inc.) C:\windows\system32\Drivers\HipShieldK.sys
2015-09-20 13:24 - 2015-10-02 09:17 - 00005574 _____ C:\windows\setupact.log
2015-09-20 13:24 - 2015-09-20 13:24 - 00000000 _____ C:\windows\setuperr.log
2015-09-20 13:23 - 2015-10-01 01:52 - 00000000 ____D C:\Program Files\Common Files\AV
2015-09-20 13:23 - 2015-09-21 11:06 - 00003348 _____ C:\windows\System32\Tasks\McAfee Remediation (Prepare)
2015-09-20 07:23 - 2015-09-20 07:23 - 00000000 ____D C:\windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-09-20 07:22 - 2015-09-20 07:22 - 00000000 ____D C:\Program Files\Microsoft Office
2015-09-20 07:22 - 2015-09-20 07:22 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2015-09-20 07:22 - 2015-09-20 07:22 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2015-09-20 07:21 - 2015-09-30 11:46 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-20 07:21 - 2015-09-20 07:21 - 00000000 __RHD C:\MSOCache
2015-09-20 07:21 - 2015-09-20 07:21 - 00000000 ____D C:\Users\BALAN\AppData\Local\Microsoft Help
2015-09-20 05:59 - 2015-09-20 05:59 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_ldiagio_uefi_01009.Wdf
2015-09-20 05:56 - 2015-10-02 02:00 - 00000000 ____D C:\Users\BALAN\AppData\Local\Adobe
2015-09-20 05:56 - 2015-09-20 05:56 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\LSC
2015-09-20 05:55 - 2015-10-02 09:18 - 00003600 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3688482777-3306477040-3792482504-1001
2015-09-20 05:50 - 2015-09-20 05:50 - 00000000 ____D C:\windows\System32\Tasks\WPD
2015-09-20 05:50 - 2015-09-20 05:50 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2015-09-20 05:50 - 2015-09-20 05:50 - 00000000 ____D C:\Users\BALAN\AppData\Local\Power2Go8
2015-09-20 05:49 - 2015-10-02 09:07 - 00040943 _____ C:\Users\BALAN\AppData\Local\BTServer.log
2015-09-20 05:49 - 2015-09-30 22:13 - 00000000 ____D C:\Users\BALAN\AppData\Local\Packages
2015-09-20 05:49 - 2015-09-28 11:17 - 00000000 ____D C:\Users\BALAN
2015-09-20 05:49 - 2015-09-21 20:26 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\Adobe
2015-09-20 05:49 - 2015-09-20 05:49 - 00001457 _____ C:\Users\BALAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-09-20 05:49 - 2015-09-20 05:49 - 00001264 _____ C:\Users\BALAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BTServer Toasts App.lnk
2015-09-20 05:49 - 2015-09-20 05:49 - 00000020 ___SH C:\Users\BALAN\ntuser.ini
2015-09-20 05:49 - 2015-09-20 05:49 - 00000000 ____D C:\Users\BALAN\Documents\My Bluetooth
2015-09-20 05:49 - 2015-09-20 05:49 - 00000000 ____D C:\Users\BALAN\AppData\Local\VirtualStore
2015-09-20 05:49 - 2015-05-28 02:47 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\Macromedia
2015-09-20 05:49 - 2015-05-28 02:01 - 00000000 ___RD C:\Users\BALAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-09-20 05:49 - 2014-11-21 17:48 - 00000000 ___RD C:\Users\BALAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-20 05:49 - 2014-11-21 17:48 - 00000000 ___RD C:\Users\BALAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-09-20 05:49 - 2014-11-21 10:22 - 00000369 _____ C:\Users\BALAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-09-20 05:49 - 2014-11-21 10:22 - 00000369 _____ C:\Users\BALAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-09-20 05:49 - 2013-08-22 21:06 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-09-19 17:53 - 2015-09-19 19:06 - 00001440 _____ C:\Users\BALAN\Desktop\ad-google popup.txt
2015-09-19 17:34 - 2015-09-19 17:34 - 00002786 _____ C:\windows\System32\Tasks\CCleanerSkipUAC
2015-09-19 17:34 - 2015-09-19 17:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-09-19 17:34 - 2015-09-19 17:34 - 00000000 ____D C:\Program Files\CCleaner
2015-09-19 17:02 - 2015-09-19 17:02 - 00000000 ____D C:\Users\Public\Documents\CyberLink
2015-09-19 17:02 - 2015-09-19 17:02 - 00000000 ____D C:\Users\BALAN\AppData\Roaming\CyberLink
2015-09-19 16:51 - 2015-09-19 16:51 - 00000000 ____D C:\Users\BALAN\AppData\Local\CyberLink
2015-09-19 16:50 - 2015-09-20 13:20 - 00000000 ____D C:\Users\BALAN\AppData\Local\Lenovo
2015-09-19 16:48 - 2015-09-19 17:47 - 00000000 ____D C:\Program Files (x86)\Google
2015-09-19 16:48 - 2015-09-19 17:46 - 00000000 ____D C:\Users\BALAN\AppData\Local\Google
2015-09-19 16:47 - 2015-10-02 09:08 - 00000000 ____D C:\Users\BALAN\AppData\Local\Dropbox
2015-09-19 16:47 - 2015-09-28 10:00 - 00000000 ____D C:\Program Files (x86)\Dropbox
2015-09-19 16:47 - 2015-09-19 16:47 - 00000000 ____D C:\ProgramData\Dropbox
2015-09-19 16:42 - 2015-09-19 16:42 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2015-09-19 16:40 - 2015-10-02 06:37 - 00003918 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{B5F70009-2C5A-4272-AE0F-C15BB4FA4B12}
2015-09-19 16:40 - 2015-09-19 16:40 - 00000000 __SHD C:\Users\BALAN\AppData\Local\EmieUserList
2015-09-19 16:40 - 2015-09-19 16:40 - 00000000 __SHD C:\Users\BALAN\AppData\Local\EmieSiteList
2015-09-19 16:40 - 2015-09-19 16:40 - 00000000 __SHD C:\Users\BALAN\AppData\Local\EmieBrowserModeList
2015-09-19 16:32 - 2015-10-02 09:16 - 00001283 _____ C:\Users\BALAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk
2015-09-11 15:59 - 2015-09-11 15:59 - 00312752 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgidsdrivera.sys
2015-09-09 03:23 - 2015-09-09 03:23 - 00023152 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgboota.sys

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-02 09:17 - 2015-05-28 03:03 - 00000000 ____D C:\ProgramData\LU
2015-10-02 09:16 - 2015-05-28 02:39 - 00000000 ____D C:\windows\System32\Tasks\Lenovo
2015-10-02 09:13 - 2014-11-21 10:14 - 00863592 _____ C:\windows\system32\PerfStringBackup.INI
2015-10-02 09:07 - 2015-05-28 02:15 - 00361644 _____ C:\windows\SysWOW64\rootpa.e2e
2015-10-02 09:06 - 2013-08-22 20:15 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-10-02 09:05 - 2015-05-28 02:06 - 00065536 _____ C:\windows\system32\spu_storage.bin
2015-10-02 09:05 - 2015-05-28 01:50 - 01160130 _____ C:\windows\WindowsUpdate.log
2015-10-02 09:04 - 2015-05-28 02:40 - 00002560 _____ C:\windows\system32\VfService.trf
2015-10-02 09:04 - 2015-05-28 02:10 - 00340524 _____ C:\Users\Public\CAFADEBUG.log
2015-10-02 08:49 - 2015-05-28 02:41 - 00000000 ____D C:\ProgramData\McAfee
2015-10-02 08:47 - 2013-08-22 20:14 - 05318112 _____ C:\windows\system32\FNTCACHE.DAT
2015-10-02 08:42 - 2013-08-22 18:55 - 00262144 ___SH C:\windows\system32\config\BBI
2015-10-02 08:40 - 2013-08-22 21:06 - 00000000 ___RD C:\windows\ToastData
2015-10-02 08:40 - 2013-08-22 21:06 - 00000000 ___RD C:\windows\ImmersiveControlPanel
2015-10-02 08:40 - 2013-08-22 21:06 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-02 08:40 - 2013-08-22 21:06 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-02 08:40 - 2013-08-22 21:06 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-02 08:39 - 2015-05-28 02:41 - 00000000 ____D C:\Program Files\Common Files\McAfee
2015-10-02 08:39 - 2014-11-21 17:47 - 00000000 ___SD C:\windows\system32\CompatTel
2015-10-02 08:39 - 2013-08-22 21:06 - 00000000 ___HD C:\windows\ELAMBKUP
2015-10-02 08:39 - 2013-08-22 21:06 - 00000000 ____D C:\windows\WinStore
2015-10-02 08:39 - 2013-08-22 21:06 - 00000000 ____D C:\windows\AppCompat
2015-10-02 08:39 - 2013-08-22 21:06 - 00000000 ____D C:\Program Files\Windows Defender
2015-10-02 08:39 - 2013-08-22 21:06 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2015-10-02 08:32 - 2013-08-22 21:06 - 00000000 ____D C:\windows\system32\sru
2015-10-01 19:34 - 2013-08-22 20:50 - 00000000 ____D C:\windows\CbsTemp
2015-10-01 02:27 - 2013-08-22 18:55 - 00262144 ___SH C:\windows\system32\config\ELAM
2015-09-30 22:19 - 2013-08-22 21:06 - 00000000 ____D C:\windows\AppReadiness
2015-09-30 11:51 - 2013-08-22 21:06 - 00000000 ____D C:\windows\rescache
2015-09-30 11:42 - 2013-08-22 21:06 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-09-30 00:04 - 2015-05-28 02:04 - 00000000 ____D C:\ProgramData\Package Cache
2015-09-29 23:38 - 2015-05-28 02:41 - 00000000 ____D C:\Program Files (x86)\McAfee
2015-09-29 23:34 - 2013-08-22 21:06 - 00000000 ____D C:\windows\system32\sr-Latn-RS
2015-09-29 23:34 - 2013-08-22 21:06 - 00000000 ____D C:\windows\system32\sr-Latn-CS
2015-09-29 23:34 - 2013-08-22 21:06 - 00000000 ____D C:\windows\PolicyDefinitions
2015-09-29 12:14 - 2014-12-10 07:27 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-09-29 12:13 - 2015-05-28 02:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-09-29 12:13 - 2014-11-21 09:50 - 00000000 ____D C:\windows\ShellNew
2015-09-28 11:53 - 2015-05-28 02:47 - 00000000 ____D C:\ProgramData\Adobe
2015-09-28 11:53 - 2015-05-28 02:47 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-09-21 11:49 - 2014-11-21 09:50 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-21 11:40 - 2013-08-22 21:06 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-21 11:40 - 2013-08-22 21:06 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-21 11:40 - 2013-08-22 19:06 - 00000000 ____D C:\windows\system32\AdvancedInstallers
2015-09-20 13:20 - 2015-05-28 02:40 - 00000000 ____D C:\ProgramData\Lenovo
2015-09-20 07:22 - 2013-08-22 18:55 - 00000167 _____ C:\windows\win.ini
2015-09-20 06:33 - 2015-05-28 02:40 - 00000000 ____D C:\ProgramData\OneKey Recovery
2015-09-19 18:07 - 2014-12-10 07:19 - 00000000 ____D C:\windows\Panther
2015-09-19 16:51 - 2015-05-28 02:50 - 00000000 ____D C:\ProgramData\CyberLink
2015-09-19 16:37 - 2015-05-28 02:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
2015-09-19 16:37 - 2015-05-28 02:38 - 00000000 ____D C:\Program Files (x86)\Lenovo
2015-09-15 06:48 - 2014-11-21 17:57 - 00812008 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-09-15 06:48 - 2014-11-21 17:57 - 00178152 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl

==================== Files in the root of some directories =======

2015-09-20 05:49 - 2015-10-02 09:07 - 0040943 _____ () C:\Users\BALAN\AppData\Local\BTServer.log
2015-05-28 02:09 - 2015-05-28 02:09 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\BALAN\AppData\Local\Temp\AcDeltree.exe
C:\Users\BALAN\AppData\Local\Temp\avg-e1009777-4eda-4c26-8d8a-7308706d280f.exe
C:\Users\BALAN\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmprtvxaq.dll
C:\Users\BALAN\AppData\Local\Temp\LenovoExperienceImprovement.exe
C:\Users\BALAN\AppData\Local\Temp\obexpf.dll
C:\Users\BALAN\AppData\Local\Temp\{1E4DCE63-3DD4-4D44-BCE0-D2716F6E61A5}-DropboxClient_3.8.9.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-10-01 19:43

==================== End of FRST.txt ============================

------------------------------------------------------

Original Post:

We've had some issues with browser pop-ups in our house for a few months, and we weren't able to figure out what the issue was. This affects every laptop and android device in the house, though not constantly.

The issue is that, every once in a while when we click on a link or open a new tab/page, there is a browser redirect (on android) or popup (laptops) to the following address:
http://ad-type.google.com/sh.aspx?f=...d1b83443fbc54d
This then directs to http://www.tradeadexchange.com/ and then to some scary-looking page full of warnings of outdated Java or something and links which nobody is stupid enough to click on, thankfully.
E.g.
http://www.tradeadexchange.com/a/dis...28611445186973
(This is a warning page)Warning!

Lots of internet help pages we originally looked at indicated that it might be a router issue, but a total reset hasn't fixed the problem for more than a few minutes.

Any help would be greatly appreciated. I purchased a brand new laptop today and would like to actually enjoy using it...

Thanks so much!!

Attached Files
File Type: txt Addition.txt (31.6 KB)

Constant browser pop-ups (ad-type.google.com)

$
0
0
Hello!

We've had some issues with browser pop-ups in our house for a few months, and we weren't able to figure out what the issue was. This affects every laptop and android device in the house, though not constantly.

The issue is that, every once in a while when we click on a link or open a new tab/page, there is a browser redirect (on android) or popup (laptops) to the following address:
http://ad-type.google.com/sh.aspx?f=...d1b83443fbc54d
This then directs to http://www.tradeadexchange.com/ and then to some scary-looking page full of warnings of outdated Java or something and links which nobody is stupid enough to click on, thankfully.
E.g.
http://www.tradeadexchange.com/a/dis...28611445186973
(This is a warning page)Warning!

Lots of internet help pages we originally looked at indicated that it might be a router issue, but a total reset hasn't fixed the problem for more than a few minutes.

Any help would be greatly appreciated. I purchased a brand new laptop today and would like to actually enjoy using it...

Thanks so much!! :smile:

Possible firewall breach via Scam

$
0
0
My wife was on the computer checking email or face book when apparently a blue screen came up (with beeping) with all kind of warnings about a possible security breach and a Toll Free number to call.
Sorry to say, she bought it hook line and sinker and called the number.
Tried selling her some fix or whatnot.

She called me and suddenly I am in a three way phone call with someone giving me options for a fix at X$ per year for protection, etc.

Obvious scam.

Came home and see that a Citrix remote access window was opened. Yikes!!

Restarted CPU and all seems fine for now.

Changed bank passwords via iPhones

The CPU is less than a year old and does not have a lot of files on it (purchased Nov 2014 - Costco with Windows 7 installed)

If someone could take a look...I would greatly appreciate it.

Thanks So Much


______________________________________

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.18015
Run by Home at 17:56:02 on 2015-10-02
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8097.6653 [GMT -6:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\stacsv64.exe
C:\windows\system32\igfxCUIService.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
c:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
C:\windows\Explorer.EXE
C:\PROGRA~2\COUPON~2\bar\1.bin\5zbarsvc.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\igfxEM.exe
C:\Windows\system32\WUDFHost.exe
C:\windows\system32\igfxHK.exe
C:\Program Files\IDT\WDM\Beats64.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\CouponXplorer_5z\bar\1.bin\APPINTEGRATOR.EXE
C:\Program Files (x86)\CouponXplorer_5z\bar\1.bin\AppIntegrator64.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\Keystatus.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\taskeng.exe
c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uURLSearchHooks: <No Name>: {9b138bf3-1d40-4e7e-84bb-2975198ad938} - C:\Program Files (x86)\CouponXplorer_5z\bar\1.bin\5zSrcAs.dll
mWinlogon: Userinit = userinit.exe
BHO: Toolbar BHO: {0297a026-3011-46d3-ad62-bb9a7612aea7} - C:\Program Files (x86)\CouponXplorer_5z\bar\1.bin\5zbar.dll
BHO: Search Assistant BHO: {7d69ed06-0171-4379-9528-08df51092727} - C:\Program Files (x86)\CouponXplorer_5z\bar\1.bin\5zSrcAs.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\urlredir.dll
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
TB: CouponXplorer: {65C72339-FB1D-4155-84E1-9AFACEE02D6F} - C:\Program Files (x86)\CouponXplorer_5z\bar\1.bin\5zbar.dll
TB: CouponXplorer: {65c72339-fb1d-4155-84e1-9afacee02d6f} - C:\Program Files (x86)\CouponXplorer_5z\bar\1.bin\5zbar.dll
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [HP KEYBOARDx] "C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [CouponXplorer EPM Support] "C:\PROGRA~2\COUPON~2\bar\1.bin\5zmedint.exe" T8EPMSUP.DLL,S
mRun: [CouponXplorer AppIntegrator 32-bit] C:\PROGRA~2\COUPON~2\bar\1.bin\AppIntegrator.exe
mRun: [CouponXplorer AppIntegrator 64-bit] C:\PROGRA~2\COUPON~2\bar\1.bin\AppIntegrator64.exe
mRun: [CouponXplorer Search Scope Monitor] "C:\PROGRA~2\COUPON~2\bar\1.bin\5zsrchmn.exe" /m=2 /w /h
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
dRunOnce: [iCloud] "C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloud.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\office15\onbttnie.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll
TCP: NameServer = 192.168.0.1 205.171.3.25
TCP: Interfaces\{01752DED-C1AD-45E7-B665-D0CB9F2D5047} : DHCPNameServer = 192.168.0.1 205.171.3.25
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\msosb.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {438363A8-F486-4C37-834C-4955773CB3D3} - msiexec /fu {438363A8-F486-4C37-834C-4955773CB3D3} /qn
x64-BHO: Skype for Business Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ochelper.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\urlredir.dll
x64-BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll
x64-BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll
x64-Run: [BeatsOSDApp] C:\Program Files\IDT\WDM\beats64.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [IgfxTray] "C:\windows\System32\igfxtray.exe"
x64-Run: [Persistence] "C:\windows\System32\igfxpers.exe"
x64-Run: [BoxSync] "C:\Program Files\Box\Box Sync\BoxSync.exe" -m
x64-Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
x64-IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnie.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ochelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 iaStorA;iaStorA;C:\windows\System32\drivers\iaStorA.sys [2013-8-29 644968]
R0 iaStorF;iaStorF;C:\windows\System32\drivers\iaStorF.sys [2013-8-29 28008]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\windows\System32\drivers\iusb3hcs.sys [2013-11-7 20464]
R1 CLVirtualDrive;CLVirtualDrive;C:\windows\System32\drivers\CLVirtualDrive.sys [2014-5-2 91912]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-9-2 77104]
R2 ClickToRunSvc;Microsoft Office ClickToRun Service;C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe [2014-10-21 2774104]
R2 CouponXplorer_5zService;CouponXplorerService;C:\PROGRA~2\COUPON~2\bar\1.bin\5zbarsvc.exe [2015-1-8 90696]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2013-11-4 99128]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service;C:\windows\System32\igfxCUIService.exe [2015-7-26 328296]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-2-13 731648]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2014-5-2 131544]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2014-5-2 169432]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\windows\System32\drivers\iusb3hub.sys [2013-11-7 368624]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\windows\System32\drivers\iusb3xhc.sys [2013-11-7 790000]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\windows\System32\drivers\RtsUStor.sys [2014-5-2 272088]
R3 RTL8167;Realtek 8167 NT Driver;C:\windows\System32\drivers\Rt64win7.sys [2012-12-27 805088]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-7-9 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-7-9 123856]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-4-19 161384]
S3 AmUStor;AM USB Stroage Driver;C:\windows\System32\drivers\AmUStor.sys [2013-7-18 83224]
S3 BoxSyncUpdateService;Box Sync Update Service;C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [2015-2-10 28696]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2014-5-2 169752]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\windows\System32\ieetwcollector.exe [2015-9-9 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-2-13 820184]
S3 TsUsbFlt;TsUsbFlt;C:\windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 USBAAPL64;Apple Mobile USB Driver;C:\windows\System32\drivers\usbaapl64.sys [2015-6-10 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\System32\Wat\WatAdminSvc.exe [2014-10-5 1255736]
.
=============== Created Last 30 ================
.
2015-10-02 21:58:24 11062400 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EE87DF5A-0DA5-4E5B-B17B-25A7C95C7C27}\mpengine.dll
2015-10-02 21:47:13 -------- d-----w- C:\Program Files (x86)\Citrix
2015-10-02 21:46:50 -------- d-----w- C:\Users\Home\AppData\Local\Citrix
2015-09-20 16:57:21 -------- d-----w- C:\Program Files\iPod
2015-09-20 16:57:21 -------- d-----w- C:\Program Files (x86)\iTunes
2015-09-20 16:57:20 -------- d-----w- C:\Program Files\iTunes
2015-09-20 16:55:53 -------- d-----w- C:\Program Files\Bonjour
2015-09-20 16:55:53 -------- d-----w- C:\Program Files (x86)\Bonjour
2015-09-09 16:07:08 692672 ----a-w- C:\windows\System32\winload.efi
.
==================== Find3M ====================
.
2015-09-22 13:12:08 780488 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2015-09-22 13:12:08 142536 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-09-02 03:04:49 41984 ----a-w- C:\windows\System32\lpk.dll
2015-09-02 03:04:46 100864 ----a-w- C:\windows\System32\fontsub.dll
2015-09-02 03:04:44 14336 ----a-w- C:\windows\System32\dciman32.dll
2015-09-02 03:04:42 46080 ----a-w- C:\windows\System32\atmlib.dll
2015-09-02 02:48:31 70656 ----a-w- C:\windows\SysWow64\fontsub.dll
2015-09-02 02:48:28 10240 ----a-w- C:\windows\SysWow64\dciman32.dll
2015-09-02 02:48:25 34304 ----a-w- C:\windows\SysWow64\atmlib.dll
2015-09-02 02:47:18 25600 ----a-w- C:\windows\SysWow64\lpk.dll
2015-09-02 01:51:28 3209216 ----a-w- C:\windows\System32\win32k.sys
2015-09-02 01:47:08 372736 ----a-w- C:\windows\System32\atmfd.dll
2015-09-02 01:33:48 299520 ----a-w- C:\windows\SysWow64\atmfd.dll
2015-08-26 18:07:11 98304 ----a-w- C:\windows\System32\wudriver.dll
2015-08-26 18:07:11 3165696 ----a-w- C:\windows\System32\wucltux.dll
2015-08-26 18:07:11 192000 ----a-w- C:\windows\System32\wuwebv.dll
2015-08-26 18:06:43 91136 ----a-w- C:\windows\System32\WinSetupUI.dll
2015-08-26 18:06:33 12288 ----a-w- C:\windows\System32\wu.upgrade.ps.dll
2015-08-26 18:06:30 37376 ----a-w- C:\windows\System32\wuapp.exe
2015-08-26 17:56:25 93184 ----a-w- C:\windows\SysWow64\wudriver.dll
2015-08-26 17:56:25 173056 ----a-w- C:\windows\SysWow64\wuwebv.dll
2015-08-26 17:55:37 34816 ----a-w- C:\windows\SysWow64\wuapp.exe
2015-08-15 06:34:10 2724864 ----a-w- C:\windows\System32\mshtml.tlb
2015-08-15 06:33:56 4096 ----a-w- C:\windows\System32\ieetwcollectorres.dll
2015-08-15 06:18:47 66560 ----a-w- C:\windows\System32\iesetup.dll
2015-08-15 06:18:00 48640 ----a-w- C:\windows\System32\ieetwproxystub.dll
2015-08-15 06:17:54 417792 ----a-w- C:\windows\System32\html.iec
2015-08-15 06:17:49 585216 ----a-w- C:\windows\System32\vbscript.dll
2015-08-15 06:17:25 88064 ----a-w- C:\windows\System32\MshtmlDac.dll
2015-08-15 06:04:47 114688 ----a-w- C:\windows\System32\ieetwcollector.exe
2015-08-15 06:04:46 144384 ----a-w- C:\windows\System32\ieUnatt.exe
2015-08-15 06:04:25 814080 ----a-w- C:\windows\System32\jscript9diag.dll
2015-08-15 06:00:44 5923328 ----a-w- C:\windows\System32\jscript9.dll
2015-08-15 05:57:20 968704 ----a-w- C:\windows\System32\MsSpellCheckingFacility.exe
2015-08-15 05:53:22 2724864 ----a-w- C:\windows\SysWow64\mshtml.tlb
2015-08-15 05:46:15 77824 ----a-w- C:\windows\System32\JavaScriptCollectionAgent.dll
2015-08-15 05:40:29 504832 ----a-w- C:\windows\SysWow64\vbscript.dll
2015-08-15 05:40:12 62464 ----a-w- C:\windows\SysWow64\iesetup.dll
2015-08-15 05:39:32 47616 ----a-w- C:\windows\SysWow64\ieetwproxystub.dll
2015-08-15 05:39:22 341504 ----a-w- C:\windows\SysWow64\html.iec
2015-08-15 05:38:34 64000 ----a-w- C:\windows\SysWow64\MshtmlDac.dll
2015-08-15 05:29:36 115712 ----a-w- C:\windows\SysWow64\ieUnatt.exe
2015-08-15 05:29:12 620032 ----a-w- C:\windows\SysWow64\jscript9diag.dll
2015-08-15 05:22:47 1359360 ----a-w- C:\windows\System32\mshtmlmedia.dll
2015-08-15 05:22:03 2126336 ----a-w- C:\windows\System32\inetcpl.cpl
2015-08-15 05:16:37 60416 ----a-w- C:\windows\SysWow64\JavaScriptCollectionAgent.dll
2015-08-15 05:10:32 4520448 ----a-w- C:\windows\SysWow64\jscript9.dll
2015-08-15 05:07:28 2427392 ----a-w- C:\windows\System32\wininet.dll
2015-08-15 05:01:47 2052608 ----a-w- C:\windows\SysWow64\inetcpl.cpl
2015-08-15 05:01:23 1155072 ----a-w- C:\windows\SysWow64\mshtmlmedia.dll
2015-08-15 04:43:00 1951232 ----a-w- C:\windows\SysWow64\wininet.dll
2015-08-13 09:23:07 118 ----a-w- C:\windows\System32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-08-12 22:03:42 96528 ----a-w- C:\windows\System32\dns-sd.exe
2015-08-12 22:03:42 86288 ----a-w- C:\windows\System32\dnssd.dll
2015-08-12 22:03:42 61712 ----a-w- C:\windows\System32\jdns_sd.dll
2015-08-12 22:03:42 213264 ----a-w- C:\windows\System32\dnssdX.dll
2015-08-12 22:03:38 84240 ----a-w- C:\windows\SysWow64\dns-sd.exe
2015-08-12 22:03:38 72976 ----a-w- C:\windows\SysWow64\dnssd.dll
2015-08-12 22:03:38 50960 ----a-w- C:\windows\SysWow64\jdns_sd.dll
2015-08-12 22:03:38 178960 ----a-w- C:\windows\SysWow64\dnssdX.dll
2015-08-06 23:31:12 425 ----a-w- C:\windows\System32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2015-08-06 17:43:02 94208 ----a-w- C:\windows\SysWow64\QuickTimeVR.qtx
2015-08-06 17:43:02 69632 ----a-w- C:\windows\SysWow64\QuickTime.qts
2015-08-05 17:56:14 1110016 ----a-w- C:\windows\System32\schedsvc.dll
2015-08-05 17:56:07 24576 ----a-w- C:\windows\System32\jnwmon.dll
2015-08-05 17:56:06 275456 ----a-w- C:\windows\System32\InkEd.dll
2015-08-05 17:40:50 216064 ----a-w- C:\windows\SysWow64\InkEd.dll
2015-08-04 18:00:24 616360 ----a-w- C:\windows\System32\winresume.efi
2015-08-04 17:56:54 63488 ----a-w- C:\windows\System32\setbcdlocale.dll
2015-08-04 17:56:37 59392 ----a-w- C:\windows\System32\appidapi.dll
2015-08-04 17:56:37 32768 ----a-w- C:\windows\System32\appidsvc.dll
2015-08-04 17:55:57 17920 ----a-w- C:\windows\System32\appidcertstorecheck.exe
2015-08-04 17:55:57 147456 ----a-w- C:\windows\System32\appidpolicyconverter.exe
2015-08-04 17:47:42 50688 ----a-w- C:\windows\SysWow64\appidapi.dll
2015-08-04 16:58:09 61440 ----a-w- C:\windows\System32\drivers\appid.sys
2015-07-30 18:06:57 2565120 ----a-w- C:\windows\System32\d3d10warp.dll
2015-07-30 18:06:57 1648128 ----a-w- C:\windows\System32\DWrite.dll
2015-07-30 18:06:57 1180160 ----a-w- C:\windows\System32\FntCache.dll
2015-07-30 17:57:30 1987584 ----a-w- C:\windows\SysWow64\d3d10warp.dll
2015-07-30 17:57:30 1251328 ----a-w- C:\windows\SysWow64\DWrite.dll
2015-07-30 13:13:38 103120 ----a-w- C:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-07-30 13:13:11 124624 ----a-w- C:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2015-07-15 18:15:12 5568960 ----a-w- C:\windows\System32\ntoskrnl.exe
2015-07-15 18:15:11 94656 ----a-w- C:\windows\System32\drivers\mountmgr.sys
2015-07-15 18:15:10 95680 ----a-w- C:\windows\System32\drivers\ksecdd.sys
2015-07-15 18:15:10 155584 ----a-w- C:\windows\System32\drivers\ksecpkg.sys
2015-07-15 18:12:09 1730496 ----a-w- C:\windows\System32\ntdll.dll
2015-07-15 18:11:14 362496 ----a-w- C:\windows\System32\wow64win.dll
2015-07-15 18:11:14 243712 ----a-w- C:\windows\System32\wow64.dll
2015-07-15 18:11:14 13312 ----a-w- C:\windows\System32\wow64cpu.dll
2015-07-15 18:11:13 215040 ----a-w- C:\windows\System32\winsrv.dll
2015-07-15 18:11:01 210944 ----a-w- C:\windows\System32\wdigest.dll
2015-07-15 18:09:57 338432 ----a-w- C:\windows\System32\conhost.exe
2015-07-15 18:09:52 64000 ----a-w- C:\windows\System32\auditpol.exe
2015-07-15 18:05:47 60416 ----a-w- C:\windows\System32\msobjs.dll
2015-07-15 18:05:26 146432 ----a-w- C:\windows\System32\msaudite.dll
2015-07-15 17:59:45 3989952 ----a-w- C:\windows\SysWow64\ntkrnlpa.exe
2015-07-15 17:59:45 3934656 ----a-w- C:\windows\SysWow64\ntoskrnl.exe
2015-07-15 17:56:24 1311768 ----a-w- C:\windows\SysWow64\ntdll.dll
2015-07-15 17:55:07 172032 ----a-w- C:\windows\SysWow64\wdigest.dll
.
============= FINISH: 17:56:18.39 ===============

Attached Files
File Type: txt attach.txt (6.0 KB)

RAM usage goes up to 15.9/16gb

$
0
0
Go to this thread for more information: http://www.techsupportforum.com/foru...ml#post6658682

NOTE: I dont have the issue right now with the 15.9gb ram usage (when i ran the dds thing)


Quote:

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.10240.16412 BrowserJavaVersion: 11.60.2
Run by Mario at 1:41:14 on 2015-10-03
Microsoft Windows 10 Home 10.0.10240.0.1252.1.1033.18.16311.8021 [GMT -4:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG AntiVirus Free Edition 2015 *Enabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition 2015 *Enabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE}
.
============== Running Processes ===============
.
c:\PROGRA~2\AVG\AVG2015\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\WINDOWS\system32\nvvsvc.exe
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\WLANExt.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
C:\Windows\runSW.exe
C:\WINDOWS\SysWOW64\PnkBstrA.exe
C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\REALTEK\REALTEK USB Wireless LAN Driver\WPSService20.exe
C:\WINDOWS\system32\dashost.exe
C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\SwUSB.exe
svchost.exe
C:\WINDOWS\system32\sihost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
C:\Windows\System32\RuntimeBroker.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\taskhostw.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup
C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\WINDOWS\system32\SettingSyncHost.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Opera\32.0.1948.69\opera.exe
C:\Program Files (x86)\Opera\32.0.1948.69\opera_crashreporter.exe
C:\Program Files (x86)\Opera\32.0.1948.69\opera.exe
C:\Program Files (x86)\Opera\32.0.1948.69\opera.exe
C:\Program Files (x86)\Opera\32.0.1948.69\opera.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
C:\Program Files (x86)\Opera\32.0.1948.69\opera.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\WINDOWS\system32\fontdrvhost.exe
C:\WINDOWS\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\WINDOWS\system32\ApplicationFrameHost.exe
C:\Program Files (x86)\Opera\32.0.1948.69\opera.exe
C:\Program Files (x86)\Opera\32.0.1948.69\opera.exe
C:\WINDOWS\system32\taskhostw.exe
C:\Program Files (x86)\Opera\32.0.1948.69\opera.exe
C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe
C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayWebCore.exe
C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayWebCore.exe
C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayWebCore.exe
C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Rainbow Six Siege - Closed Beta\RainbowSix.exe
C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayWebCore.exe
C:\Program Files (x86)\Opera\32.0.1948.69\opera.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionUriServer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\SndVol.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [OneDrive] "C:\Users\Mario\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRunOnce: [Uninstall C:\Users\Mario\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1\amd64] C:\WINDOWS\System32\cmd.exe /q /c rmdir /s /q "C:\Users\Mario\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1\amd64"
mRun: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
mRun: [CAM] C:\Program Files (x86)\NZXT\CAM\CAMLauncher.exe -autostart
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\KILLER~1.LNK - C:\Windows\Installer\{401FADAA-1C16-4721-9F02-19067E1A1CA8}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe
mPolicies-System: DSCAutomationHostEnabled = dword:2
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{a56c5f8f-f101-4e87-aa91-b0850efb61cc} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{bd4f5a7b-8a7c-44aa-b316-f98182c38a2b} : DHCPNameServer = 192.168.1.1
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
SSODL: WebCheck - <orphaned>
LSA: Security Packages = ""
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.101\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll
x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
x64-Run: [NvBackend] "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
x64-Run: [ShadowPlay] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\nvspcap64.dll,ShadowPlayOnSystemStart
x64-Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
x64-mPolicies-System: DSCAutomationHostEnabled = dword:2
x64-Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
x64-CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Mario\AppData\Roaming\Mozilla\Firefox\Profiles\cy1j3h9x.default\
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
.
============= SERVICES / DRIVERS ===============
.
P2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2015-9-28 8704]
R0 AVGIDSHA;AVGIDSHA;C:\WINDOWS\System32\drivers\avgidsha.sys [2015-5-12 297904]
R0 Avgloga;AVG Logging Driver;C:\WINDOWS\System32\drivers\avgloga.sys [2015-5-7 378336]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\WINDOWS\System32\drivers\avgmfx64.sys [2015-8-4 250800]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\WINDOWS\System32\drivers\avgrkx64.sys [2015-3-20 40928]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [2015-7-10 106520]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [2015-7-10 17944]
R0 Wof;Windows Overlay File System Filter Driver;C:\WINDOWS\System32\drivers\wof.sys [2015-8-18 200528]
R1 ahcache;Application Compatibility Cache;C:\WINDOWS\System32\drivers\ahcache.sys [2015-7-10 215552]
R1 Avgdiska;AVG Disk Driver;C:\WINDOWS\System32\drivers\avgdiska.sys [2015-3-11 162784]
R1 AVGIDSDriver;AVGIDSDriver;C:\WINDOWS\System32\drivers\avgidsdrivera.sys [2015-7-28 313264]
R1 Avgldx64;AVG AVI Loader Driver;C:\WINDOWS\System32\drivers\avgldx64.sys [2015-6-16 259040]
R1 Avgwfpa;AVG Firewall Driver;C:\WINDOWS\System32\drivers\avgwfpa.sys [2015-8-4 304560]
R1 BfLwf;Qualcomm Atheros Bandwidth Control;C:\WINDOWS\System32\drivers\bwcW8x64.sys [2013-2-13 75056]
R1 FileCrypt;FileCrypt;C:\WINDOWS\System32\drivers\filecrypt.sys [2015-7-10 83968]
R1 GpuEnergyDrv;GPU Energy Driver;C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-7-10 8192]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2015-8-24 3637160]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2015-8-24 335656]
R2 CoreMessagingRegistrar;CoreMessaging;C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork [2015-7-10 39856]
R2 DiagTrack;Diagnostics Tracking Service;C:\WINDOWS\System32\svchost.exe -k utcsvc [2015-7-10 39856]
R2 GfExperienceService;NVIDIA GeForce Experience Service;C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2015-7-29 1155192]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2014-3-20 154584]
R2 NvNetworkService;NVIDIA Network Service;C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2015-7-29 1872504]
R2 NvStreamSvc;NVIDIA Streamer Service;C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2015-8-13 5544568]
R2 Qualcomm Atheros Killer Service V2;Qualcomm Atheros Killer Service V2;C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [2013-8-8 343040]
R2 RunSwUSB;RunSwUSB;C:\Windows\runSW.exe [2015-7-29 44104]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-7-29 410768]
R2 storqosflt;Storage QoS Filter Driver;C:\WINDOWS\System32\drivers\storqosflt.sys [2015-7-10 61952]
R2 TeamViewer;TeamViewer 10;C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2015-9-13 5702416]
R2 tiledatamodelsvc;Tile Data model server;C:\WINDOWS\System32\svchost.exe -k appmodel [2015-7-10 39856]
R2 UserManager;User Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
R2 WPSService20;WPS2.0 HW PBC Service;C:\Program Files (x86)\REALTEK\REALTEK USB Wireless LAN Driver\WPSService20.exe [2015-7-29 96768]
R3 ClipSVC;Client License Service (ClipSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2015-7-10 39856]
R3 DevQueryBroker;DevQuery Background Discovery Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
R3 DsSvc;Data Sharing Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
R3 Ke2200;NDIS Miniport Driver for the Killer e2200 Gigabit Ethernet Controller;C:\WINDOWS\System32\drivers\e22w8x64.sys [2013-3-20 163536]
R3 lfsvc;Geolocation Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
R3 LicenseManager;Windows License Manager Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2015-7-10 39856]
R3 MBfilt;MBfilt;C:\WINDOWS\System32\drivers\MBfilt64.sys [2015-6-24 41088]
R3 NcbService;Network Connection Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [2015-7-10 20992]
R3 NvStreamKms;NvStreamKms;C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2015-7-29 19576]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\WINDOWS\System32\drivers\nvvad64v.sys [2015-7-29 50472]
R3 RtlWlanu;Realtek Wireless LAN 802.11n USB 2.0 Network Adapter;C:\WINDOWS\System32\drivers\rtwlanu.sys [2015-7-24 3860224]
R3 StateRepository;State Repository Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2015-7-10 39856]
R3 XtuAcpiDriver;Intel(R) Extreme Tuning Utility Service;C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [2015-6-6 63840]
S0 Avgboota;AVG Early Launch Anti-Malware Driver;C:\WINDOWS\System32\drivers\avgboota.sys [2015-3-27 21152]
S2 dmwappushservice;dmwappushsvc;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S2 DoSvc;Delivery Optimization;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S2 MapsBroker;Downloaded Maps Manager;C:\WINDOWS\System32\svchost.exe -k NetworkService [2015-7-10 39856]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-7-9 327296]
S3 ADP80XX;ADP80XX;C:\WINDOWS\System32\drivers\adp80xx.sys [2015-7-10 1135456]
S3 AJRouter;AllJoyn Router Service;C:\WINDOWS\System32\svchost.exe -k LocalService [2015-7-10 39856]
S3 AppReadiness;App Readiness;C:\WINDOWS\System32\svchost.exe -k AppReadiness [2015-7-10 39856]
S3 AppXSvc;AppX Deployment Service (AppXSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2015-7-10 39856]
S3 bcmfn2;bcmfn2 Service;C:\WINDOWS\System32\drivers\bcmfn2.sys [2015-7-10 17624]
S3 BEService;BattlEye Service;C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2015-8-9 1125888]
S3 BthHFSrv;Bluetooth Handsfree Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation [2015-7-10 39856]
S3 buttonconverter;Service for Portable Device Control devices;C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-7-10 32256]
S3 CapImg;HID driver for CapImg touch screen;C:\WINDOWS\System32\drivers\capimg.sys [2015-7-10 116736]
S3 CDPSvc;CDPSvc;C:\WINDOWS\System32\svchost.exe -k LocalService [2015-7-10 39856]
S3 cpuz138;cpuz138;C:\Users\Mario\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [2015-8-22 27880]
S3 DcpSvc;DataCollectionPublishingService;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\WINDOWS\System32\drivers\ssudbus.sys [2015-8-31 108800]
S3 diagnosticshub.standardcollector.service;Microsoft (R) Diagnostics Hub Standard Collector Service;C:\WINDOWS\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-7-10 27136]
S3 DmEnrollmentSvc;Device Management Enrollment Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 embeddedmode;embeddedmode;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
S3 EntAppSvc;Enterprise App Management Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2015-7-10 39856]
S3 fcvsc;fcvsc;C:\WINDOWS\System32\drivers\fcvsc.sys [2015-7-10 31232]
S3 genericusbfn;Generic USB Function Class;C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-7-10 20992]
S3 hidinterrupt;Common Driver for HID Buttons implemented with interrupts;C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-7-10 50016]
S3 iaLPSSi_GPIO;Intel(R) Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [2015-7-10 38128]
S3 iaLPSSi_I2C;Intel(R) Serial IO I2C Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [2015-7-10 122608]
S3 iaStorAV;Intel(R) SATA RAID Controller Windows;C:\WINDOWS\System32\drivers\iaStorAV.sys [2015-7-10 673120]
S3 ibbus;Mellanox InfiniBand Bus/AL (Filter Driver);C:\WINDOWS\System32\drivers\ibbus.sys [2015-7-10 424800]
S3 icssvc;Windows Mobile Hotspot Service;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2015-7-10 39856]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\WINDOWS\System32\ieetwcollector.exe [2015-7-10 115200]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2014-1-31 887232]
S3 intelpep;Intel(R) Power Engine Plug-in Driver;C:\WINDOWS\System32\drivers\intelpep.sys [2015-7-10 43872]
S3 IoQos;IoQos;C:\WINDOWS\System32\drivers\ioqos.sys [2015-7-10 26624]
S3 LSI_SAS2i;LSI_SAS2i;C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-7-10 104800]
S3 LSI_SAS3i;LSI_SAS3i;C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-7-10 99168]
S3 mlx4_bus;Mellanox ConnectX Bus Enumerator;C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-7-10 705376]
S3 ndfltr;NetworkDirect Service;C:\WINDOWS\System32\drivers\ndfltr.sys [2015-7-10 76128]
S3 NetSetupSvc;Network Setup Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 netvsc;netvsc;C:\WINDOWS\System32\drivers\netvsc.sys [2015-7-10 94720]
S3 NgcCtnrSvc;Microsoft Passport Container;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2015-7-10 39856]
S3 NgcSvc;Microsoft Passport;C:\WINDOWS\System32\lsass.exe [2015-7-10 56344]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;C:\WINDOWS\System32\drivers\nvstusb.sys [2015-7-29 452240]
S3 percsas2i;percsas2i;C:\WINDOWS\System32\drivers\percsas2i.sys [2015-7-10 58208]
S3 percsas3i;percsas3i;C:\WINDOWS\System32\drivers\percsas3i.sys [2015-7-10 58720]
S3 ReFSv1;ReFSv1;C:\WINDOWS\System32\drivers\refsv1.sys [2015-8-18 934752]
S3 RetailDemo;Retail Demo Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
S3 SensorDataService;Sensor Data Service;C:\WINDOWS\System32\SensorDataService.exe [2015-8-18 1031680]
S3 SensorService;Sensor Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
S3 SerCx2;Serial UART Support Library;C:\WINDOWS\System32\drivers\SerCx2.sys [2015-7-10 155488]
S3 SIUSBXP;SIUSBXP;C:\WINDOWS\System32\drivers\SiUSBXp.sys [2014-11-20 19456]
S3 smphost;Microsoft Storage Spaces SMP;C:\WINDOWS\System32\svchost.exe -k smphost [2015-7-10 39856]
S3 SmsRouter;Microsoft Windows SMS Router Service.;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\WINDOWS\System32\drivers\ssudmdm.sys [2015-8-31 206080]
S3 stornvme;Microsoft Standard NVM Express Driver;C:\WINDOWS\System32\drivers\stornvme.sys [2015-8-19 80720]
S3 storufs;Microsoft Universal Flash Storage (UFS) Driver;C:\WINDOWS\System32\drivers\storufs.sys [2015-7-10 40288]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmCx.sys [2015-7-10 61952]
S3 UcmUcsi;USB Connector Manager UCSI Client;C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-8-18 46080]
S3 UdeCx;USB Device Emulation Support Library;C:\WINDOWS\System32\drivers\Udecx.sys [2015-7-10 44032]
S3 UEFI;Microsoft UEFI Driver;C:\WINDOWS\System32\drivers\uefi.sys [2015-7-10 28512]
S3 Ufx01000;USB Function Class Extension;C:\WINDOWS\System32\drivers\ufx01000.sys [2015-7-10 245088]
S3 UfxChipidea;USB Chipidea Controller;C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-7-10 94048]
S3 ufxsynopsys;USB Synopsys Controller;C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-7-10 127840]
S3 UrsChipidea;Chipidea USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urschipidea.sys [2015-7-10 28512]
S3 UrsCx01000;USB Role-Switch Support Library;C:\WINDOWS\System32\drivers\urscx01000.sys [2015-7-10 57696]
S3 UrsSynopsys;Synopsys USB Role-Switch Driver;C:\WINDOWS\System32\drivers\urssynopsys.sys [2015-7-10 27488]
S3 UsoSvc;Update Orchestrator Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 vhf;Virtual HID Framework (VHF) Driver;C:\WINDOWS\System32\drivers\vhf.sys [2015-7-10 31744]
S3 vmicguestinterface;Hyper-V Guest Service Interface;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
S3 vmicvmsession;Hyper-V VM Session Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
S3 WalletService;WalletService;C:\WINDOWS\System32\svchost.exe -k appmodel [2015-7-10 39856]
S3 wdiwifi;WDI Driver Framework;C:\WINDOWS\System32\drivers\WdiWiFi.sys [2015-8-18 685568]
S3 WdNisDrv;Windows Defender Network Inspection System Driver;C:\WINDOWS\System32\drivers\WdNisDrv.sys [2015-7-10 119648]
S3 WdNisSvc;Windows Defender Network Inspection Service;C:\Program Files\Windows Defender\NisSrv.exe [2015-7-10 362928]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;C:\WINDOWS\System32\svchost.exe -k WepHostSvcGroup [2015-7-10 39856]
S3 WinMad;WinMad Service;C:\WINDOWS\System32\drivers\winmad.sys [2015-7-10 26976]
S3 WinRing0_1_2_0;WinRing0_1_2_0;C:\Program Files (x86)\NZXT\CAM\CAM_Client.sys [2015-8-22 14544]
S3 WinVerbs;WinVerbs Service;C:\WINDOWS\System32\drivers\winverbs.sys [2015-7-10 59232]
S3 workfolderssvc;Work Folders;C:\WINDOWS\System32\svchost.exe -k LocalService [2015-7-10 39856]
S3 WpnService;Windows Push Notifications Service;C:\WINDOWS\System32\svchost.exe -k wswpnservice [2015-7-10 39856]
S3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\drivers\WUDFRd.sys [2015-7-10 214016]
S3 XblAuthManager;Xbox Live Auth Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 XblGameSave;Xbox Live Game Save;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 xboxgip;Xbox Game Input Protocol Driver;C:\WINDOWS\System32\drivers\xboxgip.sys [2015-7-10 222720]
S3 XboxNetApiSvc;Xbox Live Networking Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 xinputhid;XINPUT HID Filter Driver;C:\WINDOWS\System32\drivers\xinputhid.sys [2015-7-10 25600]
S3 xusb22;Xbox 360 Wireless Receiver Driver Service 22;C:\WINDOWS\System32\drivers\xusb22.sys [2015-7-10 95744]
.
=============== File Associations ===============
.
ShellExec: opera.exe: open="C:\Program Files (x86)\Opera\Launcher.exe" "%1"
.
=============== Created Last 30 ================
.
2015-10-03 04:44:03 16148 ----a-w- C:\WINDOWS\System32\MARIO-PC_Mario_HistoryPrediction.bin
2015-09-28 22:34:18 -------- d-----w- C:\ProgramData\Hi-Rez Studios
2015-09-28 22:34:16 -------- d-----w- C:\Program Files (x86)\Hi-Rez Studios
2015-09-27 13:52:14 -------- d-----w- C:\Users\Mario\AppData\Local\Ubisoft Game Launcher
2015-09-19 01:16:07 -------- d-----w- C:\Program Files (x86)\Adobe Photoshop CS6
2015-09-18 17:39:13 -------- d-----w- C:\Users\Mario\AppData\Local\CrashDumps
2015-09-18 04:50:53 -------- d-----w- C:\Users\Mario\8162
2015-09-14 14:43:00 -------- d-----w- C:\Users\Mario\AppData\Local\Mozilla
2015-09-14 00:19:39 -------- d-----w- C:\Users\Mario\AppData\Roaming\TeamViewer
2015-09-14 00:12:30 -------- d-----w- C:\Program Files (x86)\TeamViewer
2015-09-12 04:45:08 -------- d-----w- C:\Users\Mario\AppData\Roaming\KeePass
2015-09-09 03:00:02 1190000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{774054F9-5138-4AA2-A232-404AD7D38BE0}\gapaengine.dll
2015-09-09 03:00:02 1187344 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\NisBackup\gapaengine.dll
2015-09-09 02:59:55 11745192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8842E1F0-BBFB-49D0-8545-A539F67A35C7}\mpengine.dll
2015-09-09 02:59:50 300704 ------w- C:\WINDOWS\System32\MpSigStub.exe
2015-09-08 19:15:51 -------- d-----w- C:\Users\Mario\AppData\Roaming\BoL
2015-09-07 06:21:45 -------- d-----w- C:\Users\Mario\AppData\Local\ElevatedDiagnostics
2015-09-05 23:48:33 -------- d-----w- C:\Program Files\AutoHotkey
2015-09-05 00:53:25 1194185 ----a-w- C:\WINDOWS\unins001.exe
.
==================== Find3M ====================
.
2015-09-28 22:35:03 405360 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2015-09-15 16:12:10 812008 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2015-09-02 10:59:09 0 ----a-w- C:\WINDOWS\SysWow64\RENCF91.tmp
2015-09-02 10:58:43 110688 ----a-w- C:\WINDOWS\System32\WindowsAccessBridge-64.dll
2015-09-02 01:20:52 77400 ----a-w- C:\WINDOWS\System32\acmigration.dll
2015-09-02 00:25:58 3586560 ----a-w- C:\WINDOWS\System32\win32kfull.sys
2015-09-02 00:25:34 1382912 ----a-w- C:\WINDOWS\System32\win32kbase.sys
2015-08-31 09:43:43 206080 ----a-w- C:\WINDOWS\System32\drivers\ssudmdm.sys
2015-08-31 09:43:25 108800 ----a-w- C:\WINDOWS\System32\drivers\ssudbus.sys
2015-08-27 06:32:24 608936 ----a-w- C:\WINDOWS\System32\fontdrvhost.exe
2015-08-27 06:04:18 21874688 ----a-w- C:\WINDOWS\System32\edgehtml.dll
2015-08-27 05:54:40 365568 ----a-w- C:\WINDOWS\System32\atmfd.dll
2015-08-27 05:54:26 541248 ----a-w- C:\WINDOWS\SysWow64\fontdrvhost.exe
2015-08-27 05:51:48 1774592 ----a-w- C:\WINDOWS\System32\Windows.UI.Immersive.dll
2015-08-27 05:51:42 2350592 ----a-w- C:\WINDOWS\System32\authui.dll
2015-08-27 05:49:28 1008640 ----a-w- C:\WINDOWS\System32\schedsvc.dll
2015-08-27 05:43:31 576000 ----a-w- C:\WINDOWS\System32\vbscript.dll
2015-08-27 05:42:52 187904 ----a-w- C:\WINDOWS\System32\Windows.UI.PicturePassword.dll
2015-08-27 05:42:46 596480 ----a-w- C:\WINDOWS\System32\SettingSync.dll
2015-08-27 05:42:36 184320 ----a-w- C:\WINDOWS\System32\shacct.dll
2015-08-27 05:42:25 578560 ----a-w- C:\WINDOWS\System32\winlogon.exe
2015-08-27 05:39:42 45568 ----a-w- C:\WINDOWS\System32\atmlib.dll
2015-08-27 05:23:43 303104 ----a-w- C:\WINDOWS\SysWow64\atmfd.dll
2015-08-27 05:16:41 1612288 ----a-w- C:\WINDOWS\SysWow64\Windows.UI.Immersive.dll
2015-08-27 05:16:38 2153472 ----a-w- C:\WINDOWS\SysWow64\authui.dll
2015-08-27 05:16:03 18806272 ----a-w- C:\WINDOWS\SysWow64\edgehtml.dll
2015-08-27 05:12:35 504320 ----a-w- C:\WINDOWS\SysWow64\vbscript.dll
2015-08-27 05:11:54 484352 ----a-w- C:\WINDOWS\SysWow64\SettingSync.dll
2015-08-27 05:11:39 139776 ----a-w- C:\WINDOWS\SysWow64\shacct.dll
2015-08-27 05:08:18 37376 ----a-w- C:\WINDOWS\SysWow64\atmlib.dll
2015-08-27 00:37:01 1423120 ----a-w- C:\WINDOWS\SysWow64\nvspcap.dll
2015-08-27 00:37:01 1316000 ----a-w- C:\WINDOWS\SysWow64\nvspbridge.dll
2015-08-27 00:36:47 1756424 ----a-w- C:\WINDOWS\System32\nvspbridge64.dll
2015-08-27 00:36:47 1710568 ----a-w- C:\WINDOWS\System32\nvspcap64.dll
2015-08-20 06:07:55 8019296 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2015-08-20 06:06:53 609592 ----a-w- C:\WINDOWS\System32\ci.dll
2015-08-20 05:26:23 168960 ----a-w- C:\WINDOWS\System32\InstallAgent.exe
2015-08-20 05:21:13 193024 ----a-w- C:\WINDOWS\System32\EnterpriseModernAppMgmtCSP.dll
2015-08-19 15:53:56 297904 ----a-w- C:\WINDOWS\System32\drivers\avgidsha.sys
2015-08-19 15:52:30 313264 ----a-w- C:\WINDOWS\System32\drivers\avgidsdrivera.sys
2015-08-18 07:56:25 2498808 ----a-w- C:\WINDOWS\System32\CoreUIComponents.dll
2015-08-18 07:55:45 373072 ----a-w- C:\WINDOWS\System32\drivers\USBXHCI.SYS
2015-08-18 07:54:30 1396064 ----a-w- C:\WINDOWS\System32\LicenseManager.dll
2015-08-18 07:27:23 1771592 ----a-w- C:\WINDOWS\SysWow64\CoreUIComponents.dll
2015-08-18 07:24:35 963920 ----a-w- C:\WINDOWS\SysWow64\LicenseManager.dll
2015-08-18 07:13:10 497664 ----a-w- C:\WINDOWS\System32\WlanMediaManager.dll
2015-08-18 07:13:06 387584 ----a-w- C:\WINDOWS\System32\NetSetupShim.dll
2015-08-18 07:12:20 692224 ----a-w- C:\WINDOWS\System32\drivers\UMDF\NfcCx.dll
2015-08-18 07:12:18 2225664 ----a-w- C:\WINDOWS\System32\NetworkMobileSettings.dll
2015-08-18 07:07:34 2226688 ----a-w- C:\WINDOWS\System32\wlansvc.dll
2015-08-18 07:04:20 859136 ----a-w- C:\WINDOWS\System32\modernexecserver.dll
2015-08-18 07:04:14 1234944 ----a-w- C:\WINDOWS\System32\aitstatic.exe
2015-08-18 06:59:35 1294336 ----a-w- C:\WINDOWS\System32\wcnwiz.dll
2015-08-18 06:59:02 140288 ----a-w- C:\WINDOWS\System32\WcnApi.dll
2015-08-18 06:58:46 50176 ----a-w- C:\WINDOWS\System32\WcnNetsh.dll
2015-08-18 06:58:34 112640 ----a-w- C:\WINDOWS\System32\fdWCN.dll
2015-08-18 06:58:31 117760 ----a-w- C:\WINDOWS\System32\dafWCN.dll
2015-08-18 06:58:25 187392 ----a-w- C:\WINDOWS\System32\NetSetupSvc.dll
2015-08-18 06:57:54 45568 ----a-w- C:\WINDOWS\System32\wfdprov.dll
2015-08-18 06:56:48 79872 ----a-w- C:\WINDOWS\System32\BthRadioMedia.dll
2015-08-18 06:55:01 2178560 ----a-w- C:\WINDOWS\System32\AppXDeploymentServer.dll
2015-08-18 06:54:11 247296 ----a-w- C:\WINDOWS\System32\facecredentialprovider.dll
2015-08-18 06:54:03 322048 ----a-w- C:\WINDOWS\System32\vaultsvc.dll
2015-08-18 06:52:26 1888768 ----a-w- C:\WINDOWS\System32\dwmcore.dll
2015-08-18 06:50:04 1795072 ----a-w- C:\WINDOWS\System32\AppXDeploymentExtensions.dll
2015-08-18 06:49:52 1061888 ----a-w- C:\WINDOWS\System32\reseteng.dll
2015-08-18 06:49:20 246272 ----a-w- C:\WINDOWS\System32\PackageStateRoaming.dll
2015-08-18 06:49:03 274432 ----a-w- C:\WINDOWS\SysWow64\NetSetupShim.dll
2015-08-18 06:36:08 1226752 ----a-w- C:\WINDOWS\SysWow64\wcnwiz.dll
2015-08-18 06:35:49 100352 ----a-w- C:\WINDOWS\SysWow64\WcnApi.dll
2015-08-18 06:35:18 95744 ----a-w- C:\WINDOWS\SysWow64\fdWCN.dll
2015-08-18 06:34:44 37376 ----a-w- C:\WINDOWS\SysWow64\wfdprov.dll
2015-08-18 06:29:11 1593344 ----a-w- C:\WINDOWS\SysWow64\dwmcore.dll
2015-08-18 06:26:08 195584 ----a-w- C:\WINDOWS\SysWow64\PackageStateRoaming.dll
2015-08-18 06:04:57 47104 ----a-w- C:\WINDOWS\SysWow64\dpwsockx.dll
2015-08-13 04:22:26 2093056 ----a-w- C:\WINDOWS\System32\wlidsvc.dll
2015-08-13 04:20:39 414208 ----a-w- C:\WINDOWS\System32\AppXDeploymentClient.dll
2015-08-13 03:53:21 311808 ----a-w- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
2015-08-11 10:04:24 2462648 ----a-w- C:\WINDOWS\System32\mfcore.dll
2015-08-11 10:04:23 4532304 ----a-w- C:\WINDOWS\explorer.exe
2015-08-11 10:04:15 1087296 ----a-w- C:\WINDOWS\System32\mfplat.dll
2015-08-11 10:03:09 442208 ----a-w- C:\WINDOWS\System32\drivers\storport.sys
2015-08-11 10:02:57 554744 ----a-w- C:\WINDOWS\System32\directmanipulation.dll
2015-08-11 10:02:56 80720 ----a-w- C:\WINDOWS\System32\drivers\stornvme.sys
2015-08-11 10:02:49 292856 ----a-w- C:\WINDOWS\System32\LockAppHost.exe
2015-08-11 09:52:49 993104 ----a-w- C:\WINDOWS\System32\ReAgent.dll
2015-08-11 09:50:47 1643872 ----a-w- C:\WINDOWS\System32\diagtrack.dll
2015-08-11 09:40:22 4048808 ----a-w- C:\WINDOWS\SysWow64\explorer.exe
2015-08-11 09:40:12 918320 ----a-w- C:\WINDOWS\SysWow64\mfplat.dll
2015-08-11 09:40:08 2151208 ----a-w- C:\WINDOWS\SysWow64\mfcore.dll
2015-08-11 09:38:22 454000 ----a-w- C:\WINDOWS\SysWow64\directmanipulation.dll
2015-08-11 09:37:48 243800 ----a-w- C:\WINDOWS\SysWow64\LockAppHost.exe
2015-08-11 09:26:03 845664 ----a-w- C:\WINDOWS\SysWow64\ReAgent.dll
2015-08-11 09:23:59 16706560 ----a-w- C:\WINDOWS\System32\Windows.UI.Xaml.dll
2015-08-11 09:21:13 148992 ----a-w- C:\WINDOWS\System32\tetheringservice.dll
2015-08-11 09:21:04 52224 ----a-w- C:\WINDOWS\System32\tetheringclient.dll
2015-08-11 09:20:02 483328 ----a-w- C:\WINDOWS\System32\OneDriveSettingSyncProvider.dll
2015-08-11 09:19:45 235520 ----a-w- C:\WINDOWS\System32\SettingsHandlers_Notifications.dll
2015-08-11 09:18:44 235008 ----a-w- C:\WINDOWS\System32\UserMgrProxy.dll
2015-08-11 09:16:32 2416640 ----a-w- C:\WINDOWS\System32\MFMediaEngine.dll
.
============= FINISH: 1:41:29.82 ===============

Attached Files
File Type: txt attach.txt (22.5 KB)

What is this?

$
0
0
Hello,

When i click on my normal links during my normal browsing habits i keep on getting only the text below on a page. It will go to the correct page on a refresh, but any idea what's happening here? I'm located in Asia.

I've done an AV scan and a MBAR scan and all ok, so i wonder if it's more an ISP thing?

Cheers

��;o厾T�8瞾垁攄腰g8嶌糯K:c�@鈝�4鶆cL:鷪f驡b��诱覕B錨� 竀%┖~N棁,險�彟4姉靰潋闇鬘嶘t]䙡:"r`摢)q�.鵻繌.x�軛nR膘?W煾€'��&Z ┭0n]庶䦟+�p澶� L遰酉1簔浛U傥�哾欰&宊IA ,4H�4�.k�w毃l �E濒}9e]u"�6,�9�趑 蟔�+7揍宾1潚闇 C骦H繌j闤鮪%"Ei%w喂�8:惽'M�(虨9蔭挙诅阛v�1僂�ya�'V樽鵉�擻JX,A=,螞汽�> 瀓羘职QB铲>嗋o|磖�堣芻蜯{羷3� /V勲棂鰨Z荸H膙�/t1$癈烫gTi墵=熶踿幏鐏c�'oUP�(a忞U

Slow system - UDSDangerousObject.Multi.Generic

$
0
0
Well hello,

I'm a newcomer in this forum. The fact is that I've been handling my W7 OS quite laggy. Last night every single time I tried to post something in a forum, it was giving me force close every time I tried to copy and paste a link :banghead:. I already downloaded Kaspersky Antivirus full protection but there's that notification appearing still and it wasn't unable to delete it hence I'm here. Fortunately I came across this another thread which is opened in this forum (http://www.techsupportforum.com/foru...ic-738745.html), therefore here are my logs:

TDSSKiller #1: TDSSKiller1 - Pastebin.com
TDSSKiller #2: TDSSKiller2 - Pastebin.com
AdwCleaner: ADWCleaner - Pastebin.com

(I really hope I'm not breaking any rule by sharing these logs using pastebin but I wouldn't like to paste them all here since they're too long).

Beside of that, this is what I know so far about the trojan or whatever it is, also its location...

UDSDangerousObject.Multi.Generic
E:\CODEX\bin\steam_api.dll

Thanks in advance, guys!

DDS won't run

$
0
0
Hi,

I know I have something bad on my computer McAfee is continually popping up. I tried to view a manual using adobe, but it didn't come up, showed a message saying I must have adobe to view and said click here. I now have lots of new apps, which I have tried unsuccessfully to uninstall, McAfee is giving me warnings every 30 seconds and have pop ups preventing me from accessing webpages.

I have used advice from this site before and found it to be exceptionally helpful so returned and followed the instructions for DDS. When I click to run it, I get a message saying cannot run in compatibility mode and closes.

I am using a Lenovo laptop with windows 8 (.1 I think).

Please can you help me proceed?

Thanks

Jo

Major computer issue - pc only runs right in safe mode

$
0
0
Having some computer issues that seem a little advanced. Did all the usual...scan, looked at hijack log,etc etc. Vertical lines on the screen when loading...screen is fine in safe mode. Tried going to my driver cd....set-up wouldn't recognize my cdrom...kept saying floppy wasn't recognized or something. Tried reformatting and cdrom drive still not recognized. When I boot the pc though...I am able to install stuff from the cdrom. This problem started last night. I'm not sure what to do since I cannot get the recovery cd to work either.

DDS (Ver_2012-11-20.01) - NTFS_x86 NETWORK
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.45.2
Run by Cathy at 13:46:21 on 2015-10-04
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.223 [GMT -5:00]
.
AV: AVG update module *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ================
.
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [CTDVDDET] "c:\program files\creative\sound blaster x-fi\dvdaudio\CTDVDDET.EXE"
mRun: [AVG_UI] "c:\program files\avg\avg2015\avgui.exe" /TRAYONLY
StartupFolder: c:\docume~1\cathy\startm~1\programs\startup\wkcalrem.lnk - c:\program files\common files\microsoft shared\works shared\WkCalRem.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
LSP: mswsock.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1359687139765
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E7DA7F8D-27AB-4EE9-8FC0-3FEC9ECFE758} - hxxps://access.wisconsin.gov/access/DynamicWebTWAIN.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{55982ACC-6D9F-4785-9DE9-4457C4DE1A1F} : DHCPNameServer = 192.168.1.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Security Packages = kerberos msv1_0 schannel wdigest wsauth
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\45.0.2454.101\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\cathy\application data\mozilla\firefox\profiles\vyy95sgh.default-1375703288875\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - hxxps://www.facebook.com/
FF - plugin: c:\documents and settings\cathy\application data\mozilla\firefox\profiles\vyy95sgh.default-1375703288875\extensions\jazz-plugin@jazz-soft.com\plugins\npJazz.dll
FF - plugin: c:\documents and settings\cathy\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\cathy\application data\mozilla\plugins\npo1d.dll
FF - plugin: c:\documents and settings\cathy\local settings\application data\google\update\1.3.28.15\npGoogleUpdate3.dll
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\canon\mycamera download plugin\NPCIG.dll
FF - plugin: c:\program files\free ride games\npExentCtl.dll
FF - plugin: c:\program files\free ride games\npGameTreatWidget.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1210150.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_19_0_0_185.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-4-19 190944]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 170464]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-1-19 35808]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-2-10 213984]
S0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2014-6-17 290272]
S1 Avgdiskx;AVG Disk Driver;c:\windows\system32\drivers\avgdiskx.sys [2014-6-17 132576]
S1 AVGIDSDriverl;AVGIDSDriverl;c:\windows\system32\drivers\avgidsdriverlx.sys [2014-6-17 217008]
S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2011-12-23 29664]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 207328]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2015\avgidsagent.exe [2015-8-24 3518376]
S2 avgwd;AVG WatchDog;c:\program files\avg\avg2015\avgwdsvc.exe [2015-8-24 314304]
S2 MBAMService;MBAMService;c:\program files\malwarebytes anti-malware\mbamservice.exe [2014-5-5 1133880]
S2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S2 ogmservice;Online Games Manager;c:\program files\online games manager\ogmservice.exe [2014-3-27 581568]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files\common files\vmware\usb\vmware-usbarbitrator.exe [2013-6-6 721488]
S2 vmware-view-usbd;VMware Horizon View USB;c:\program files\vmware\vmware view\client\bin\vmware-view-usbd.exe [2013-6-6 2436096]
S2 wsnm;VMware View Client;c:\program files\vmware\vmware view\client\bin\wsnm.exe [2013-7-9 472656]
S2 X4HSEx_Pr143;X4HSEx_Pr143;c:\program files\free ride games\X4HSEx_Pr143.sys [2014-7-16 59144]
S3 Amazon Download Agent;Amazon Download Agent;c:\program files\amazon\amazon games & software downloader\AmazonGSDownloaderService.exe [2011-4-21 401920]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-7-8 23256]
S3 sxuptp;SXUPTP Driver;c:\windows\system32\drivers\sxuptp.sys --> c:\windows\system32\drivers\sxuptp.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2005-8-16 14336]
S4 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes anti-malware\mbamscheduler.exe [2014-5-5 1871160]
.
=============== File Associations ===============
.
ShellExec: pi11.exe: Open="c:\program files\microsoft digital image 2006\pi.exe" "%1"
.
=============== Created Last 30 ================
.
2015-10-04 17:56:46 -------- d-----w- c:\windows\system32\wbem\repository\FS
2015-10-04 17:56:46 -------- d-----w- c:\windows\system32\wbem\Repository
2015-10-04 17:47:59 -------- d-----w- c:\program files\Jewel Match - Winter Wonderland
2015-10-04 17:24:06 -------- d-----w- c:\windows\LastGood(2)
2015-10-04 15:08:48 -------- d-----w- c:\program files\MyTurboPC.com
2015-10-04 15:08:48 -------- d-----w- c:\program files\common files\MyTurboPC.com
2015-10-04 15:08:48 -------- d-----w- c:\documents and settings\all users\application data\MyTurboPC.com
2015-10-04 06:42:40 -------- d-----w- c:\documents and settings\all users\Kaspersky Lab Setup Files
2015-10-02 16:25:30 -------- d-----w- c:\documents and settings\cathy\application data\Blackboard
2015-10-02 04:22:29 -------- d-----w- c:\program files\Jewel Match - Snowscapes(2)
2015-10-02 03:05:25 -------- d-----w- c:\documents and settings\cathy\local settings\application data\Blackboard
2015-10-02 03:05:11 -------- d-----w- c:\documents and settings\cathy\local settings\application data\Programs
2015-09-26 02:12:52 -------- d-----w- c:\documents and settings\cathy\application data\Jewel Match Snowscapes
2015-09-25 06:52:57 -------- d-----w- c:\documents and settings\cathy\local settings\application data\Christmas_Chocolate_Factory___windows
.
==================== Find3M ====================
.
2015-08-14 19:48:47 778440 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-08-14 19:48:46 142536 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-08-02 05:48:49 98520 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
.
============= FINISH: 13:47:10.64 ===============

Attached Files
File Type: txt attach.txt (23.2 KB)

Please Help. Virus locking me out of computer

$
0
0
I have tried everything. Lost my D drive and every recovery done I still have the same problems. Lose access to my own folders and everything being shared



DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17126 BrowserJavaVersion: 11.60.2
Run by Casey at 16:41:13 on 2015-10-05
Microsoft Windows 8.1 6.3.9600.0.1252.1.1033.18.8107.5095 [GMT -4:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall *Enabled* {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
.
============== Running Processes ===============
.
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\igfxCUIService.exe
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
C:\Program Files (x86)\Nuance\DragonAssistant3\DragonAssistantMaintenance.exe
C:\windows\SysWOW64\esif_uf.exe
C:\Program Files\Lenovo\OneKey Optimizer\bin\FbService.exe
C:\Program Files (x86)\Lenovo\Harmony\Picks\HarmonyPicksService.exe
C:\Program Files (x86)\Lenovo\Harmony\Setting\HarmonySettingService.exe
C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOUpdataService.exe
C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
C:\Program Files\Lenovo\iMController\SystemAgentService.exe
C:\Program Files\Lenovo PhoneCompanion\LPAWDService.exe
C:\Program Files (x86)\Lenovo\Lenovo Settings\x86\LenovoSetSvr.exe
C:\Windows\System32\LenovoWiFiHotspotSvr.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe
C:\windows\system32\mfevtps.exe
C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
C:\windows\SysWOW64\NLSSRV32.EXE
C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOControlSvc.exe
C:\Program Files (x86)\Lenovo\PaperDisplay\PaperLookingSrv.exe
C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe
C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterServer.exe
C:\Program Files (x86)\Lenovo\PaperDisplay\PLHotkeyService.exe
C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\WUDFHost.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\McAfee\CSP\1.3.336.0\McCSPServiceHost.exe
C:\Program Files\McAfee\MSC\McAPExe.exe
C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\taskhost.exe
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Lenovo PhoneCompanion\adb.exe
C:\windows\System32\dwm.exe
C:\windows\TEMP\DPTF\esif_assist.exe
C:\Program Files\Lenovo\Communications Utility\avfaudiosw.exe
C:\windows\system32\igfxEM.exe
C:\windows\system32\igfxHK.exe
C:\windows\system32\igfxTray.exe
C:\Windows\System32\skydrive.exe
C:\Program Files (x86)\Lenovo\CCSDK\WinGather.exe
C:\Windows\System32\SettingSyncHost.exe
C:\windows\system32\wbem\unsecapp.exe
C:\windows\system32\taskhostex.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
C:\Program Files\Lenovo\LenovoUtility\utility.exe
C:\Program Files (x86)\Lenovo\LenovoTransition\TransitionServer.exe
C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe
C:\Program Files\Lenovo\OneKey Optimizer\bin\OneKeyOptimizerTray.exe
C:\Program Files\Lenovo\OneKey Optimizer\bin\OnekeyOptimizerUpdata.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
C:\Program Files\Common Files\McAfee\platform\McUICnt.exe
C:\Program Files (x86)\Lenovo\Harmony\Picks\Lenovo.HarmonyPicks.exe
C:\Program Files (x86)\Lenovo\Harmony\Setting\Lenovo.HarmonySetting.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\windows\SysWOW64\RunDll32.exe
C:\Program Files\Lenovo\Communications Utility\tpknrres.exe
C:\Program Files\Lenovo\OneKey Optimizer\bin\OneKeyOptimizer.exe
C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\explorer.exe
C:\windows\System32\svchost.exe -k swprv
C:\windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\windows\System32\svchost.exe -k WerSvcGroup
C:\windows\SysWOW64\WerFault.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://www.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
mWinlogon: Userinit = userinit.exe
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll
mRun: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe -scheduler
mRun: [mcpltui_exe] "C:\Program Files\Common~1\McAfee\Platform\mcuicnt.exe" /platui /runkey
mRun: [HarmonyPicks] C:\Program Files (x86)\Lenovo\Harmony\Picks\Lenovo.HarmonyPicks.exe s
mRun: [HarmonySetting] C:\Program Files (x86)\Lenovo\Harmony\Setting\Lenovo.HarmonySetting.exe s
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\BLUETO~1.LNK - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{9BDE7AC4-539F-42DD-BB13-CE374A7D4011} : DHCPNameServer = 150.213.1.3
TCP: Interfaces\{FE7B55ED-F092-44BF-862E-A4B8D72CC32C} : DHCPNameServer = 192.168.1.1
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll
AppInit_DLLs= C:\PROGRA~2\LENOVO~1\LENOVO~1\bin\SPVC32~1.DLL
SSODL: WebCheck - <orphaned>
LSA: Security Packages = ""
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [IAStorIcon] "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
x64-Run: [RtHDVBg_BYPASS_AUDIO_EFFECT_WHEN_POWERSAVING] "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /BYPASS_AUDIO_EFFECT_WHEN_POWERSAVING
x64-Run: [RtHDVBg_MAXX6] "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX6
x64-Run: [RtHDVBg_LENOVO_DOLBYDRAGON] "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_DOLBYDRAGON
x64-Run: [RtHDVBg_LENOVO_MICPKEY] "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY
x64-Run: [WavesSvc] "C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe"
x64-Run: [LenovoUtility] "C:\Program Files\Lenovo\LenovoUtility\utility.exe"
x64-Run: [AutoStartTransition] C:\Program Files (x86)\Lenovo\LenovoTransition\TransitionServer.exe
x64-Run: [PhoneCompanion] C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe
x64-Run: [OneKeyOptimizer] "C:\Program Files\Lenovo\OneKey Optimizer\bin\OneKeyOptimizerTray.exe" /run
x64-Run: [LMCSSTART1] "C:\Program Files\Lenovo\Communications Utility\lmcsctrl.exe" /initsubsysproc:
x64-Run: [LMCSSTART2] "C:\Program Files\Lenovo\Communications Utility\lmcsctrl.exe" /proxystart:
x64-Run: [LMCSSTART3] "C:\Program Files\Lenovo\Communications Utility\lmcsctrl.exe" /setcamplusdrop:
x64-Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
.
============= SERVICES / DRIVERS ===============
.
R0 Fastboot;Fastboot;C:\windows\System32\drivers\Fastboot.sys [2014-12-22 69144]
R0 iaStorA;iaStorA;C:\windows\System32\drivers\iaStorA.sys [2014-6-25 670056]
R0 intelpep;Intel(R) Power Engine Plug-in Driver;C:\windows\System32\drivers\intelpep.sys [2014-3-18 39768]
R0 mfehidk;McAfee Inc. mfehidk;C:\windows\System32\drivers\mfehidk.sys [2014-4-3 786304]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\windows\System32\drivers\mfewfpk.sys [2014-4-3 348560]
R0 Wof;Windows Overlay File System Filter Driver;C:\windows\System32\drivers\wof.sys [2014-12-22 157016]
R1 ahcache;Application Compatibility Cache;C:\windows\System32\drivers\ahcache.sys [2013-8-22 76800]
R1 mbamchameleon;mbamchameleon;C:\windows\System32\drivers\mbamchameleon.sys [2015-10-5 109272]
R2 AVControlCenter;AVControlCenter;C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe [2015-10-5 560584]
R2 CCSDK;CCSDK;C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [2014-12-22 592880]
R2 DAMSvc;DragonAssistant3 Maintenance Service;C:\Program Files (x86)\Nuance\DragonAssistant3\DragonAssistantMaintenance.exe [2014-4-8 4260112]
R2 esifsvc;ESIF Upper Framework Service;C:\Windows\SysWOW64\esif_uf.exe [2014-12-22 953352]
R2 FastbootService;FastbootService;C:\Program Files\Lenovo\OneKey Optimizer\bin\FBService.exe [2014-12-22 194328]
R2 HarmonyPicksService;HarmonyPicksService;C:\Program Files (x86)\Lenovo\Harmony\Picks\HarmonyPicksService.exe [2014-12-22 17176]
R2 HarmonySettingService;HarmonySettingService;C:\Program Files (x86)\Lenovo\Harmony\Setting\HarmonySettingService.exe [2014-12-22 17688]
R2 HomeNetSvc;McAfee Home Network;C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [2014-12-22 335064]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2014-6-25 16232]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service;C:\windows\System32\igfxCUIService.exe [2014-11-22 328296]
R2 Intel(R) ME Service;Intel® ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2014-7-3 131544]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2014-7-3 154584]
R2 Lenovo OKO Service;Lenovo OKO Service;C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOUpdataService.exe [2014-12-22 2543896]
R2 Lenovo Settings Service;Lenovo Settings Service;C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [2014-12-22 2016040]
R2 Lenovo System Agent Service;Lenovo System Agent Service;C:\Program Files\Lenovo\iMController\SystemAgentService.exe [2014-5-21 584960]
R2 LenovoPAWDService;Lenovo PAWD Service;C:\Program Files\Lenovo PhoneCompanion\LPAWDService.exe [2014-12-22 133440]
R2 LenovoSetSvr;LenovoSetSvr;C:\Program Files (x86)\Lenovo\Lenovo Settings\x86\LenovoSetSvr.exe [2014-12-22 258544]
R2 LenovoWiFiHotspotSvr;Lenovo WiFiHotspot Service;C:\windows\System32\LenovoWiFiHotspotSvr.exe [2014-12-22 218952]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-10-5 1871160]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-10-5 1133880]
R2 McAPExe;McAfee AP Service;C:\Program Files\mcafee\msc\McAPExe.exe [2014-4-17 562200]
R2 mcbootdelaystartsvc;McAfee Boot Delay Start Service;C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [2014-12-22 335064]
R2 mccspsvc;McAfee CSP Service;C:\Program Files\Common Files\McAfee\CSP\1.3.336.0\McCSPServiceHost.exe [2014-11-21 422632]
R2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [2014-12-22 335064]
R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [2014-12-22 335064]
R2 mcpltsvc;McAfee Platform Services;C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [2014-12-22 335064]
R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [2014-12-22 335064]
R2 mfecore;McAfee Anti-Malware Core;C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [2014-12-22 1050952]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\systemcore\mfefire.exe [2014-12-22 221832]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\windows\System32\mfevtps.exe [2014-12-22 189920]
R2 NitroDriverReadSpool9;NitroPDFDriverCreatorReadSpool9;C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [2013-12-12 230920]
R2 nlsX86cc;Nalpeiron Licensing Service;C:\Windows\SysWOW64\NLSSRV32.EXE [2013-12-12 69640]
R2 OKOControlSvc;OKOControlSvc;C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOControlSvc.exe [2014-12-22 113944]
R2 PaperLookingSrv;PaperLookingSrv;C:\Program Files (x86)\Lenovo\PaperDisplay\PaperLookingSrv.exe [2014-8-11 173336]
R2 PG_Service_Launcher;PG_Service_Launcher;C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe [2014-5-28 524552]
R2 PGService;PGService;C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [2014-5-28 167176]
R2 PhoneCompanionPusher;Lenovo PhoneCompanionPusher Service;C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [2014-12-22 321520]
R2 PLHotkeyService;PLHotkeyService;C:\Program Files (x86)\Lenovo\PaperDisplay\PLHotkeyService.exe [2014-8-11 25368]
R2 SynTPEnhService;SynTPEnh Caller Service;C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2014-8-11 190704]
R2 VeriFaceSrv;VeriFaceSrv;C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [2014-12-22 68880]
R2 ymc;ymc;C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [2014-12-22 34576]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;C:\windows\System32\drivers\AcpiVpc.sys [2014-12-22 35064]
R3 cfwids;McAfee Inc. cfwids;C:\windows\System32\drivers\cfwids.sys [2014-4-3 72136]
R3 dptf_cpu;dptf_cpu;C:\windows\System32\drivers\dptf_cpu.sys [2014-12-22 35136]
R3 dptf_pch;dptf_pch;C:\windows\System32\drivers\dptf_pch.sys [2014-12-22 34072]
R3 esif_lf;esif_lf;C:\windows\System32\drivers\esif_lf.sys [2014-12-22 192624]
R3 iaLPSS_GPIO;Intel(R) Serial IO GPIO Driver;C:\windows\System32\drivers\iaLPSS_GPIO.sys [2014-6-10 35832]
R3 iaLPSS_I2C;Intel(R) Serial IO I2C Driver;C:\windows\System32\drivers\iaLPSS_I2C.sys [2014-6-10 120312]
R3 iwdbus;IWD Bus Enumerator;C:\windows\System32\drivers\iwdbus.sys [2014-11-17 30512]
R3 KMDFVirtualKbd;Lenovo Virtual Keyboard Device;C:\windows\System32\drivers\KMDFVirtualKbd.sys [2014-12-22 22264]
R3 KMDFVirtualMouse;Lenovo Virtual Mouse Device;C:\windows\System32\drivers\KMDFVirtualMouse.sys [2014-12-22 21240]
R3 MBAMProtector;MBAMProtector;C:\windows\System32\drivers\mbam.sys [2015-10-5 25816]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\windows\System32\drivers\MBAMSwissArmy.sys [2015-10-5 113880]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\windows\System32\drivers\mfeavfk.sys [2014-4-3 313680]
R3 mfefirek;McAfee Inc. mfefirek;C:\windows\System32\drivers\mfefirek.sys [2014-4-3 526360]
R3 mfencbdc;McAfee Inc. mfencbdc;C:\windows\System32\drivers\mfencbdc.sys [2014-9-19 447440]
R3 NcbService;Network Connection Broker;C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2013-8-22 37768]
R3 rtsuvc;Lenovo EasyCamera;C:\windows\System32\drivers\RtsUVC.sys [2014-12-22 7239384]
R3 SensorsHIDClassDriver;UMDF Reflector service for SensorsHIDClassDriver;C:\windows\System32\drivers\WUDFRd.sys [2014-12-22 227840]
R3 SensorsServiceDriver;UMDF Reflector service for SensorsServiceDriver;C:\windows\System32\drivers\WUDFRd.sys [2014-12-22 227840]
R3 SynRMIHID;Synaptics HID Service;C:\windows\System32\drivers\SynRMIHID.sys [2014-8-11 41200]
R3 UEFI;Microsoft UEFI Driver;C:\windows\System32\drivers\uefi.sys [2013-8-22 26976]
S0 mfeelamk;McAfee Inc. mfeelamk;C:\windows\System32\drivers\mfeelamk.sys [2014-4-3 70608]
S2 BcmBtRSupport;Bluetooth Driver Management Service;C:\windows\System32\BtwRSupportService.exe [2014-12-22 2251992]
S3 ADP80XX;ADP80XX;C:\windows\System32\drivers\adp80xx.sys [2013-8-22 782176]
S3 AppReadiness;App Readiness;C:\windows\System32\svchost.exe -k AppReadiness [2013-8-22 37768]
S3 AppXSvc;AppX Deployment Service (AppXSVC);C:\windows\System32\svchost.exe -k wsappx [2013-8-22 37768]
S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\windows\System32\drivers\bcbtums.sys [2014-12-22 170712]
S3 bcmfn2;bcmfn2 Service;C:\windows\System32\drivers\bcmfn2.sys [2013-8-22 17624]
S3 BthLEEnum;Bluetooth Low Energy Driver;C:\windows\System32\drivers\BthLEEnum.sys [2014-3-18 226304]
S3 btwampfl;btwampfl;C:\windows\System32\drivers\btwampfl.sys [2014-12-22 166616]
S3 btwl2cap;Bluetooth L2CAP Service;C:\windows\System32\drivers\btwl2cap.sys [2014-12-22 40248]
S3 HipShieldK;McAfee Inc. HipShieldK;C:\windows\System32\drivers\HipShieldK.sys [2015-10-5 197704]
S3 iaLPSSi_GPIO;Intel(R) Serial IO GPIO Controller Driver;C:\windows\System32\drivers\iaLPSSi_GPIO.sys [2013-8-22 24568]
S3 iaLPSSi_I2C;Intel(R) Serial IO I2C Controller Driver;C:\windows\System32\drivers\iaLPSSi_I2C.sys [2013-8-22 99320]
S3 iaStorAV;Intel(R) SATA RAID Controller Windows;C:\windows\System32\drivers\iaStorAV.sys [2013-8-22 651248]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2014-12-22 169752]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\windows\System32\ieetwcollector.exe [2014-12-22 111616]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\windows\System32\drivers\intelaud.sys [2014-11-17 42288]
S3 IntcDAud;Intel(R) Display Audio;C:\windows\System32\drivers\IntcDAud.sys [2014-11-22 455440]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2014-5-13 887256]
S3 iumsvc;Intel(R) Update Manager;C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-4-9 174368]
S3 Lenovo EasyPlus Hotspot;Lenovo EasyPlus Hotspot;C:\Program Files (x86)\Common Files\Lenovo\easyplussdk\bin\EPHotspot64.exe [2014-12-22 533760]
S3 LENOVO.CAMMUTE;Lenovo AVFramework Camera Privacy Controller;C:\Program Files\Lenovo\Communications Utility\cammute.exe [2014-12-22 456136]
S3 LENOVO.TPKNRSVC;Lenovo AVFramework Microphone Volume Controller and Dolby Interface;C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe [2014-12-22 453576]
S3 LENOVO.TVTVCAM;Lenovo AVFramework Virtual Camera Controller Service;C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [2014-12-22 625608]
S3 lfsvc;Windows Location Framework Service;C:\windows\System32\svchost.exe -k netsvcs [2013-8-22 37768]
S3 LSI_SAS3;LSI_SAS3;C:\windows\System32\drivers\lsi_sas3.sys [2013-8-22 81760]
S3 MBAMWebAccessControl;MBAMWebAccessControl;C:\windows\System32\drivers\mwac.sys [2015-10-5 64216]
S3 McAWFwk;McAfee Activation Service;C:\PROGRA~1\COMMON~1\mcafee\actwiz\mcawfwk.exe [2014-12-22 332528]
S3 mfencrk;McAfee Inc. mfencrk;C:\windows\System32\drivers\mfencrk.sys [2014-9-19 96600]
S3 mxtBootBridge;maxTouch I2C Boot Bridge Peripheral Service;C:\windows\System32\drivers\mxtBootBridge.sys [2013-12-18 36160]
S3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;C:\windows\System32\drivers\NdisVirtualBus.sys [2013-8-22 16384]
S3 netvsc;netvsc;C:\windows\System32\drivers\netvsc63.sys [2013-8-22 87040]
S3 NETwNe64;@netwew02.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit;C:\windows\System32\drivers\NETwew02.sys [2013-8-22 4649440]
S3 PhoneCompanionVap;Lenovo PhoneCompanionVap Service;C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [2014-12-22 338416]
S3 ReFS;ReFS;C:\windows\System32\drivers\refs.sys [2014-3-18 924504]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2013-8-22 37768]
S3 SerCx2;Serial UART Support Library;C:\windows\System32\drivers\SerCx2.sys [2014-3-18 146776]
S3 smphost;Microsoft Storage Spaces SMP;C:\windows\System32\svchost.exe -k smphost [2013-8-22 37768]
S3 stornvme;Microsoft Standard NVM Express Driver;C:\windows\System32\drivers\stornvme.sys [2014-3-18 57176]
S3 vmicguestinterface;Hyper-V Guest Service Interface;C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2013-8-22 37768]
S3 WdNisDrv;Windows Defender Network Inspection System Driver;C:\windows\System32\drivers\WdNisDrv.sys [2014-12-22 123224]
S3 WdNisSvc;Windows Defender Network Inspection Service;C:\Program Files\Windows Defender\NisSrv.exe [2014-12-22 347880]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;C:\windows\System32\svchost.exe -k WepHostSvcGroup [2013-8-22 37768]
S3 workfolderssvc;Work Folders;C:\windows\System32\svchost.exe -k LocalService [2013-8-22 37768]
S3 wsvd;wsvd;C:\windows\System32\drivers\wsvd.sys [2014-12-22 102376]
S4 McOobeSv2;McAfee OOBE Service2;C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [2014-12-22 335064]
.
=============== Created Last 30 ================
.
2015-10-05 17:22:51 -------- d-----w- C:\Users\Casey\AppData\Local\YSearchUtil
2015-10-05 17:22:49 -------- d-----w- C:\Program Files (x86)\Yahoo!
2015-10-05 17:20:31 -------- d-----w- C:\Users\Casey\.oracle_jre_usage
2015-10-05 17:20:22 97888 ----a-w- C:\windows\SysWow64\WindowsAccessBridge-32.dll
2015-10-05 17:19:49 -------- d-----w- C:\ProgramData\Oracle
2015-10-05 17:17:48 -------- d-----w- C:\Users\Casey\AppData\Local\ElevatedDiagnostics
2015-10-05 17:01:32 -------- d-----w- C:\Users\Casey\AppData\Local\Diagnostics
2015-10-05 17:01:05 197704 ----a-w- C:\windows\System32\drivers\HipShieldK.sys
2015-10-05 16:57:31 -------- d-----w- C:\Program Files\Common Files\AV
2015-10-05 16:51:47 113880 ----a-w- C:\windows\System32\drivers\MBAMSwissArmy.sys
2015-10-05 16:51:38 64216 ----a-w- C:\windows\System32\drivers\mwac.sys
2015-10-05 16:51:38 25816 ----a-w- C:\windows\System32\drivers\mbam.sys
2015-10-05 16:51:38 109272 ----a-w- C:\windows\System32\drivers\mbamchameleon.sys
2015-10-05 16:51:38 -------- d-----w- C:\ProgramData\Malwarebytes
2015-10-05 16:51:38 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-10-05 16:51:26 -------- d-----w- C:\Users\Casey\AppData\Local\Programs
2015-10-05 16:23:10 -------- d-----w- C:\ProgramData\OneKey Optimizer
2015-10-05 16:22:33 -------- d-----w- C:\Users\Casey\AppData\Local\Lenovo
2015-10-05 16:21:06 -------- d-----w- C:\Users\Casey\AppData\Roaming\Intel Corporation
2015-10-05 16:21:04 -------- d-sh--w- C:\Users\Casey\AppData\Local\EmieUserList
2015-10-05 16:21:04 -------- d-sh--w- C:\Users\Casey\AppData\Local\EmieSiteList
2015-10-05 16:20:55 -------- d-----w- C:\Users\Casey\AppData\Local\GWX
2015-10-05 16:20:46 -------- d---a-w- C:\Users\Casey\OneDrive
2015-10-05 16:20:16 -------- d-sh--w- C:\$RECYCLE.BIN
2015-10-05 16:20:08 -------- d-----w- C:\Users\Casey\AppData\Local\Broadcom
2015-10-05 16:19:41 -------- d-----r- C:\Users\Casey\Searches
2015-10-05 16:19:41 -------- d-----r- C:\Users\Casey\Contacts
2015-10-05 16:19:40 -------- d-----w- C:\Users\Casey\AppData\Local\VirtualStore
2015-10-05 16:19:39 -------- d-----w- C:\Users\Casey\AppData\Local\Packages
2015-10-05 16:19:36 118 ----a-w- C:\windows\System32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-10-05 16:19:36 -------- d-sh--w- C:\Users\Casey\IntelGraphicsProfiles
2015-10-05 16:09:48 2757072 ----a-w- C:\windows\explorer.exe
.
==================== Find3M ====================
.
2015-09-15 01:18:38 812008 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2015-09-15 01:18:38 178152 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-08-11 02:47:44 2414096 ----a-w- C:\windows\SysWow64\explorer.exe
2015-07-09 18:48:54 131712 ----a-w- C:\windows\System32\RestoreOptIn.exe
2015-07-09 18:40:34 359936 ----a-w- C:\windows\System32\WinSetupUI.dll
2015-07-09 17:59:32 112624 ----a-w- C:\windows\SysWow64\RestoreOptIn.exe
2015-07-09 15:54:39 35840 ----a-w- C:\windows\System32\wuapp.exe
2015-07-09 15:53:47 140288 ----a-w- C:\windows\System32\wuwebv.dll
2015-07-09 15:50:26 409088 ----a-w- C:\windows\System32\WUSettingsProvider.dll
2015-07-09 15:50:06 95744 ----a-w- C:\windows\System32\wudriver.dll
2015-07-09 15:46:59 2229248 ----a-w- C:\windows\System32\wucltux.dll
2015-07-09 15:38:21 29696 ----a-w- C:\windows\SysWow64\wuapp.exe
2015-07-09 15:37:44 124928 ----a-w- C:\windows\SysWow64\wuwebv.dll
2015-07-09 15:35:19 81920 ----a-w- C:\windows\SysWow64\wudriver.dll
.
============= FINISH: 16:41:34.13 ===============

Attached Files
File Type: txt Attach.txt (12.7 KB)
File Type: zip Attach.zip (2.8 KB)

Cannot Access any microsoft website and other issues

$
0
0
Hi,

This post is the continuation of http://www.techsupportforum.com/foru...e-1051314.html, after I was asked to move it to this section.
I run windows 10 on my desktop computer.
My issue started this morning where I was unable to connect to hotmail (firefox can not find the server etc). I then observed than I was unable to access any microsoft website.
In the afternoon, windows started to show heavy issues. No microsoft program worked : the photo displayer, edge, smart screen... even the toolbar at the bottom of the screen.
I restarted in safe mode and run malware byte, which did not find anything. When I restarted without internet access everything worked fine.

Fun fact: I am french, my internet provider is SFR, and I can not access any sfr page anymore. I tried to connect to windows pages and SFR pages with my laptop (running on ubuntu) and the same loading error occurs. However (obviously) I have no other new issue with this OS.
Last but not least, my girlfriend is connected to the same modem and she has no issue at all. Note that I use mutorrent and she does not.

Now for the dds logs (which contain some french as my os runs in this language :( )

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.10240.16412 BrowserJavaVersion: 11.60.2
Run by Corentin at 19:34:33 on 2015-10-06
Microsoft Windows 10 Famille 10.0.10240.0.1252.33.1036.18.4093.2440 [GMT 2:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\WINDOWS\system32\svchost.exe -k apphost
C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\svchost.exe -k iissvcs
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\dashost.exe
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\taskeng.exe
svchost.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\dwm.exe
C:\WINDOWS\system32\atieclxx.exe
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\system32\taskhostw.exe
C:\WINDOWS\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
C:\Users\Corentin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\System32\fontdrvhost.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\system32\ApplicationFrameHost.exe
C:\WINDOWS\System32\Taskmgr.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1001.16470.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.fr/
BHO: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
uRun: [OneDrive] "C:\Users\Corentin\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
uRunOnce: [Uninstall C:\Users\Corentin\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] C:\WINDOWS\System32\cmd.exe /q /c rmdir /s /q "C:\Users\Corentin\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
mRun: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mPolicies-System: DSCAutomationHostEnabled = dword:2
mPolicies-System: SoftwareSASGeneration = dword:1
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: NameServer = 89.2.0.10
TCP: Interfaces\{4041fdb2-23e9-4ce5-8713-621192056cfb} : DHCPNameServer = 89.2.0.10
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
SSODL: WebCheck - <orphaned>
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
x64-BHO: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-mPolicies-System: DSCAutomationHostEnabled = dword:2
x64-mPolicies-System: SoftwareSASGeneration = dword:1
x64-Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
x64-Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\WINDOWS\System32\tbauth.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
x64-CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\System32\windows.storage.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Corentin\AppData\Roaming\Mozilla\Firefox\Profiles\g757bgat.default-1429079499660\
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrlui.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\WINDOWS\System32\drivers\aswRvrt.sys [2013-5-30 65736]
R0 aswVmm;avast! VM Monitor;C:\WINDOWS\System32\drivers\aswVmm.sys [2013-5-30 272248]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [2015-7-10 106520]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [2015-7-10 17944]
R0 Wof;Windows Overlay File System Filter Driver;C:\WINDOWS\System32\drivers\wof.sys [2015-9-10 200528]
R1 ahcache;Application Compatibility Cache;C:\WINDOWS\System32\drivers\ahcache.sys [2015-7-10 215552]
R1 aswSP;aswSP;C:\WINDOWS\System32\drivers\aswsp.sys [2010-9-10 442264]
R1 FileCrypt;FileCrypt;C:\WINDOWS\System32\drivers\filecrypt.sys [2015-7-10 83968]
R1 GpuEnergyDrv;GPU Energy Driver;C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-7-10 8192]
R2 AMD External Events Utility;AMD External Events Utility;C:\WINDOWS\System32\atiesrxx.exe [2015-8-20 256992]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2015-8-3 344064]
R2 AODDriver4.01;AODDriver4.01;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2014-2-11 59616]
R2 aswHwid;avast! HardwareID;C:\WINDOWS\System32\drivers\aswHwid.sys [2014-8-6 29168]
R2 aswMonFlt;aswMonFlt;C:\WINDOWS\System32\drivers\aswMonFlt.sys [2010-9-10 89944]
R2 aswStm;aswStm;C:\WINDOWS\System32\drivers\aswStm.sys [2014-1-7 137288]
R2 avast! Antivirus;Avast Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-5-21 343336]
R2 CoreMessagingRegistrar;CoreMessaging;C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork [2015-7-10 39856]
R2 DiagTrack;Service de suivi des diagnostics;C:\WINDOWS\System32\svchost.exe -k utcsvc [2015-7-10 39856]
R2 ES lite Service;ES lite Service for program management.;C:\Program Files (x86)\Gigabyte\EasySaver\essvr.exe [2010-9-10 68136]
R2 storqosflt;Pilote de filtre de qualite de service de stockage;C:\WINDOWS\System32\drivers\storqosflt.sys [2015-7-10 61952]
R2 tiledatamodelsvc;Serveur de modeles de donnees de vignette;C:\WINDOWS\System32\svchost.exe -k appmodel [2015-7-10 39856]
R2 UserManager;Gestionnaire des utilisateurs;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
R3 amdiox64;AMD IO Driver;C:\WINDOWS\System32\drivers\amdiox64.sys [2010-9-10 46136]
R3 AppXSvc;Service de deploiement AppX (AppXSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2015-7-10 39856]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\WINDOWS\System32\drivers\AtihdWT6.sys [2015-5-28 102912]
R3 ClipSVC;Service de licences de client (ClipSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2015-7-10 39856]
R3 lfsvc;Service de geolocalisation;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
R3 LicenseManager;Serveur Gestionnaire de licences Windows;C:\WINDOWS\System32\svchost.exe -k LocalService [2015-7-10 39856]
R3 MBAMProtector;MBAMProtector;C:\WINDOWS\System32\drivers\mbam.sys [2015-10-6 25816]
R3 NcbService;Service Broker pour les connexions reseau;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
R3 NdisVirtualBus;enumerateur de cartes reseau virtuelles Microsoft;C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [2015-7-10 20992]
R3 rt640x64;Pilote NT RT640 Realtek;C:\WINDOWS\System32\drivers\rt640x64.sys [2015-7-10 587264]
R3 StateRepository;Service State Repository (StateRepository);C:\WINDOWS\System32\svchost.exe -k appmodel [2015-7-10 39856]
R3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\System32\drivers\wdcsam64.sys [2015-1-27 14464]
S1 AppleCharger;AppleCharger;C:\WINDOWS\System32\drivers\AppleCharger.sys [2010-9-10 21104]
S1 aswSnx;aswSnx;C:\WINDOWS\System32\drivers\aswSnx.sys [2010-9-10 1047320]
S2 AODDriver4.2;AODDriver4.2;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2014-2-11 59616]
S2 AODDriver4.3;AODDriver4.3;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2014-2-11 59616]
S2 dmwappushservice;dmwappushsvc;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S2 DoSvc;Optimisation de livraison;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S2 MapsBroker;Gestionnaire des cartes telechargees;C:\WINDOWS\System32\svchost.exe -k NetworkService [2015-7-10 39856]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-10-6 1133880]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-6-3 327296]
S3 ADP80XX;ADP80XX;C:\WINDOWS\System32\drivers\adp80xx.sys [2015-7-10 1135456]
S3 AJRouter;Service de routeur AllJoyn;C:\WINDOWS\System32\svchost.exe -k LocalService [2015-7-10 39856]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 AppReadiness;Preparation des applications;C:\WINDOWS\System32\svchost.exe -k AppReadiness [2015-7-10 39856]
S3 bcmfn2;bcmfn2 Service;C:\WINDOWS\System32\drivers\bcmfn2.sys [2015-7-10 17624]
S3 BthHFSrv;Service mains libres Bluetooth;C:\WINDOWS\System32\svchost.exe -k LocalServiceAndNoImpersonation [2015-7-10 39856]
S3 buttonconverter;Service pour appareils Portable Device Control;C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-1 36352]
S3 CapImg;Pilote HID pour ecran tactile CapImg;C:\WINDOWS\System32\drivers\capimg.sys [2015-7-10 116736]
S3 CDPSvc;CDPSvc;C:\WINDOWS\System32\svchost.exe -k LocalService [2015-7-10 39856]
S3 DcpSvc;DataCollectionPublishingService;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 DevQueryBroker;Service Broker de decouverte en arriere-plan DevQuery;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
S3 diagnosticshub.standardcollector.service;Service Collecteur standard du concentrateur de diagnostic Microsoft (R);C:\WINDOWS\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-7-10 27136]
S3 DmEnrollmentSvc;Service d'inscription de la gestion des peripheriques;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 DsSvc;Service de partage des donnees;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
S3 embeddedmode;embeddedmode;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
S3 EntAppSvc;Enterprise App Management Service;C:\WINDOWS\System32\svchost.exe -k appmodel [2015-7-10 39856]
S3 GalaxyClientService;GalaxyClientService;C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [2015-5-7 1738808]
S3 GalaxyCommunication;GalaxyCommunication;C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [2015-5-7 6951992]
S3 genericusbfn;Classe de fonction USB generique;C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-7-10 20992]
S3 hidinterrupt;Pilote global pour les boutons HID implementes avec des interruptions;C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-7-10 50016]
S3 iaLPSSi_GPIO;Pilote de controleur GPIO d'E/S serie Intel(R);C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [2015-7-10 38128]
S3 iaLPSSi_I2C;Pilote de contrleur I2C d'E/S s\E9rie Intel(R);C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [2015-7-10 122608]
S3 iaStorAV;Controleur RAID SATA Intel(R) pour Windows;C:\WINDOWS\System32\drivers\iaStorAV.sys [2015-7-10 673120]
S3 ibbus;Bus/AL Mellanox InfiniBand (pilote de filtre);C:\WINDOWS\System32\drivers\ibbus.sys [2015-7-10 424800]
S3 icssvc;Service Point d'acces sans fil mobile Windows;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2015-7-10 39856]
S3 IEEtwCollectorService;Service Collecteur ETW d'Internet Explorer;C:\WINDOWS\System32\ieetwcollector.exe [2015-7-10 115200]
S3 intelpep;Pilote de plug-in du moteur d'alimentation Intel(R);C:\WINDOWS\System32\drivers\intelpep.sys [2015-7-10 43872]
S3 IoQos;IoQos;C:\WINDOWS\System32\drivers\ioqos.sys [2015-7-10 26624]
S3 LSI_SAS2i;LSI_SAS2i;C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-7-10 104800]
S3 LSI_SAS3i;LSI_SAS3i;C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-7-10 99168]
S3 MBAMWebAccessControl;MBAMWebAccessControl;C:\WINDOWS\System32\drivers\mwac.sys [2015-10-6 64216]
S3 mlx4_bus;enumerateur de bus Mellanox ConnectX;C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-7-10 705376]
S3 ndfltr;Service NetworkDirect;C:\WINDOWS\System32\drivers\ndfltr.sys [2015-7-10 76128]
S3 NetSetupSvc;Service Configuration du reseau;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 netvsc;netvsc;C:\WINDOWS\System32\drivers\netvsc.sys [2015-7-10 94720]
S3 NgcCtnrSvc;Conteneur Microsoft Passport;C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted [2015-7-10 39856]
S3 NgcSvc;Microsoft Passport;C:\WINDOWS\System32\lsass.exe [2015-7-10 56344]
S3 Origin Client Service;Origin Client Service;C:\Program Files (x86)\Origin\OriginClientService.exe [2014-10-9 1997168]
S3 percsas2i;percsas2i;C:\WINDOWS\System32\drivers\percsas2i.sys [2015-7-10 58208]
S3 percsas3i;percsas3i;C:\WINDOWS\System32\drivers\percsas3i.sys [2015-7-10 58720]
S3 ReFSv1;ReFSv1;C:\WINDOWS\System32\drivers\refsv1.sys [2015-9-10 934752]
S3 RetailDemo;Service de demo du magasin;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 ScDeviceEnum;Service d'enumeration de peripheriques de carte a puce;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
S3 SensorDataService;Service Donnees de capteur;C:\WINDOWS\System32\SensorDataService.exe [2015-9-10 1031680]
S3 SensorService;Service de capteur;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
S3 SerCx2;Serial UART Support Library;C:\WINDOWS\System32\drivers\SerCx2.sys [2015-7-10 155488]
S3 smphost;SMP de l'Espace de stockages Microsoft;C:\WINDOWS\System32\svchost.exe -k smphost [2015-7-10 39856]
S3 SmsRouter;Service Routeur SMS Microsoft Windows.;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
S3 stornvme;Pilote NVM Express standard de Microsoft;C:\WINDOWS\System32\drivers\stornvme.sys [2015-9-10 80720]
S3 storufs;Pilote Universal Flash Storage (UFS) Microsoft;C:\WINDOWS\System32\drivers\storufs.sys [2015-7-10 40288]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;C:\WINDOWS\System32\drivers\UcmCx.sys [2015-7-10 61952]
S3 UcmUcsi;Client UCSI du gestionnaire de connecteur USB;C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-9-10 46080]
S3 UdeCx;USB Device Emulation Support Library;C:\WINDOWS\System32\drivers\Udecx.sys [2015-7-10 44032]
S3 UEFI;Pilote UEFI Microsoft;C:\WINDOWS\System32\drivers\uefi.sys [2015-7-10 28512]
S3 Ufx01000;USB Function Class Extension;C:\WINDOWS\System32\drivers\ufx01000.sys [2015-7-10 245088]
S3 UfxChipidea;Controleur Chipidea USB;C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-7-10 94048]
S3 ufxsynopsys;Controleur Synopsys USB;C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-7-10 127840]
S3 UrsChipidea;Pilote de commutateur de role Chipidea USB;C:\WINDOWS\System32\drivers\urschipidea.sys [2015-7-10 28512]
S3 UrsCx01000;USB Role-Switch Support Library;C:\WINDOWS\System32\drivers\urscx01000.sys [2015-7-10 57696]
S3 UrsSynopsys;Pilote de commutateur de role Synopsys USB;C:\WINDOWS\System32\drivers\urssynopsys.sys [2015-7-10 27488]
S3 UsoSvc;Mettre a jour le service Orchestrator;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 vhf;Pilote d'infrastructure HID virtuelle (VHF);C:\WINDOWS\System32\drivers\vhf.sys [2015-7-10 31744]
S3 vmicguestinterface;Interface de services d'invite Hyper-V;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
S3 vmicvmsession;Service de session d'ordinateur virtuel Hyper-V;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2015-7-10 39856]
S3 w3logsvc;Service de journalisation W3C;C:\WINDOWS\System32\svchost.exe -k apphost [2015-7-10 39856]
S3 WalletService;WalletService;C:\WINDOWS\System32\svchost.exe -k appmodel [2015-7-10 39856]
S3 wdiwifi;WDI Driver Framework;C:\WINDOWS\System32\drivers\WdiWiFi.sys [2015-9-10 685568]
S3 WdNisDrv;Pilote du systeme d'inspection du reseau Windows Defender;C:\WINDOWS\System32\drivers\WdNisDrv.sys [2015-7-10 119648]
S3 WdNisSvc;Service Inspection du reseau Windows Defender;C:\Program Files\Windows Defender\NisSrv.exe [2015-7-10 362928]
S3 WEPHOSTSVC;Service hote du fournisseur de chiffrement Windows;C:\WINDOWS\System32\svchost.exe -k WepHostSvcGroup [2015-7-10 39856]
S3 WinMad;Service WinMad;C:\WINDOWS\System32\drivers\winmad.sys [2015-7-10 26976]
S3 WinVerbs;Service WinVerbs;C:\WINDOWS\System32\drivers\winverbs.sys [2015-7-10 59232]
S3 workfolderssvc;Dossiers de travail;C:\WINDOWS\System32\svchost.exe -k LocalService [2015-7-10 39856]
S3 WpnService;Service de notifications Push Windows;C:\WINDOWS\System32\svchost.exe -k wswpnservice [2015-7-10 39856]
S3 XblAuthManager;Xbox Live Auth Manager;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 XblGameSave;Jeu sauvegarde sur Xbox Live;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 xboxgip;Xbox Game Input Protocol Driver;C:\WINDOWS\System32\drivers\xboxgip.sys [2015-7-10 222720]
S3 XboxNetApiSvc;Service de mise en reseau Xbox Live;C:\WINDOWS\System32\svchost.exe -k netsvcs [2015-7-10 39856]
S3 xinputhid;XINPUT HID Filter Driver;C:\WINDOWS\System32\drivers\xinputhid.sys [2015-7-10 25600]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\WINDOWS\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2015-10-06 17:32:27 16148 ----a-w- C:\WINDOWS\System32\COCOMPUTER_Corentin_HistoryPrediction.bin
2015-10-06 13:57:17 -------- d-----w- C:\ProgramData\Kaspersky Lab Setup Files
2015-10-06 06:34:58 113880 ----a-w- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
2015-10-06 06:34:46 64216 ----a-w- C:\WINDOWS\System32\drivers\mwac.sys
2015-10-06 06:34:46 25816 ----a-w- C:\WINDOWS\System32\drivers\mbam.sys
2015-10-06 06:34:46 109272 ----a-w- C:\WINDOWS\System32\drivers\mbamchameleon.sys
2015-10-06 06:34:46 -------- d-----w- C:\ProgramData\Malwarebytes
2015-10-06 06:34:46 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-10-06 06:12:53 -------- d-----w- C:\Users\Corentin\AppData\Local\MicrosoftEdge
2015-10-04 13:44:47 812008 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2015-10-04 13:44:47 178152 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2015-10-01 19:17:59 966416 ----a-w- C:\WINDOWS\System32\twinapi.appcore.dll
2015-10-01 19:16:57 221184 ----a-w- C:\WINDOWS\System32\LocationPeWiFi.dll
2015-10-01 19:16:57 169984 ----a-w- C:\WINDOWS\System32\mdmregistration.dll
2015-10-01 19:16:57 168960 ----a-w- C:\WINDOWS\System32\mdmmigrator.dll
2015-10-01 19:16:57 154624 ----a-w- C:\WINDOWS\System32\dmcertinst.exe
2015-10-01 19:16:57 121856 ----a-w- C:\WINDOWS\System32\dmcsps.dll
2015-10-01 19:16:56 204288 ----a-w- C:\WINDOWS\System32\LocationPeCell.dll
2015-10-01 19:16:55 324096 ----a-w- C:\WINDOWS\System32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-01 19:16:55 247808 ----a-w- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-01 17:36:39 187904 ----a-w- C:\WINDOWS\System32\provisioningcsp.dll
2015-10-01 17:36:32 317440 ----a-w- C:\WINDOWS\System32\configmanager2.dll
2015-10-01 17:36:32 30208 ----a-w- C:\WINDOWS\System32\syncmlhook.dll
2015-09-30 15:39:10 -------- d-----w- C:\WINDOWS\System32\SleepStudy
2015-09-28 18:41:35 -------- d-----w- C:\Users\Corentin\.oracle_jre_usage
2015-09-28 18:41:23 97888 ----a-w- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
2015-09-28 18:40:55 -------- d-----w- C:\ProgramData\Oracle
2015-09-28 18:22:09 -------- d-----w- C:\Users\Corentin\AppData\Roaming\AMD
2015-09-27 13:25:47 1187344 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\NisBackup\gapaengine.dll
2015-09-27 13:25:44 1190000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D4E75304-A244-4C5D-AC58-A5174BCED2A8}\gapaengine.dll
2015-09-27 13:24:39 11062400 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0E0D94F-DD67-4CBF-A0EA-5A2880CBAF85}\mpengine.dll
2015-09-27 11:46:41 -------- dc----w- C:\WINDOWS\Panther
2015-09-27 11:43:57 -------- d-----w- C:\Windows.old
2015-09-27 11:43:40 2639872 ----a-w- C:\WINDOWS\SysWow64\esent.dll
2015-09-27 11:43:39 2987520 ----a-w- C:\WINDOWS\System32\esent.dll
2015-09-27 11:38:12 -------- d-----w- C:\WINDOWS\SysWow64\XPSViewer
2015-09-27 11:38:12 -------- d-----w- C:\WINDOWS\SysWow64\BestPractices
2015-09-27 11:38:12 -------- d-----w- C:\WINDOWS\System32\msmq
2015-09-27 11:38:12 -------- d-----w- C:\WINDOWS\System32\BestPractices
2015-09-27 11:38:11 -------- d-----w- C:\inetpub
2015-09-27 11:37:08 778936 ----a-w- C:\WINDOWS\SysWow64\PresentationNative_v0300.dll
2015-09-27 11:37:08 35480 ----a-w- C:\WINDOWS\SysWow64\TsWpfWrp.exe
2015-09-27 11:37:08 102608 ----a-w- C:\WINDOWS\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-09-27 11:37:05 35480 ----a-w- C:\WINDOWS\System32\TsWpfWrp.exe
2015-09-27 11:37:05 1166520 ----a-w- C:\WINDOWS\System32\PresentationNative_v0300.dll
2015-09-27 11:37:04 124112 ----a-w- C:\WINDOWS\System32\PresentationCFFRasterizerNative_v0300.dll
2015-09-27 11:21:47 -------- d-----r- C:\Users\Corentin\OneDrive
2015-09-27 11:18:39 6358016 ----a-w- C:\WINDOWS\System32\NlsData0009.dll
2015-09-27 11:18:39 5739520 ----a-w- C:\WINDOWS\System32\prm0009.dll
2015-09-27 11:18:39 4847104 ----a-w- C:\WINDOWS\SysWow64\NlsData0009.dll
2015-09-27 11:18:39 2629632 ----a-w- C:\WINDOWS\SysWow64\NlsLexicons0009.dll
2015-09-27 11:18:39 2629632 ----a-w- C:\WINDOWS\System32\NlsLexicons0009.dll
2015-09-27 11:17:04 -------- d-----w- C:\Users\Corentin\AppData\Local\Publishers
2015-09-27 11:15:56 -------- d-----w- C:\Users\Corentin\AppData\Local\Packages
2015-09-27 11:15:55 -------- d-----w- C:\Users\Corentin\AppData\Local\TileDataLayer
2015-09-27 11:11:58 -------- d-sh--w- C:\Recovery
2015-09-27 11:07:58 -------- d-----w- C:\WINDOWS\System32\wbem\Performance
2015-09-27 10:57:02 -------- d-----w- C:\Program Files (x86)\Common Files\SpeechEngines
2015-09-27 10:56:59 -------- d-----w- C:\Program Files\Common Files\SpeechEngines
2015-09-27 10:51:06 -------- d-----w- C:\ProgramData\AMD
2015-09-27 10:51:02 -------- d-----w- C:\Program Files\ATI Technologies
2015-09-27 10:50:42 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2015-09-27 10:50:25 -------- d-----w- C:\ProgramData\Package Cache
2015-09-27 10:49:39 0 ----a-w- C:\WINDOWS\ativpsrm.bin
2015-09-27 10:49:30 -------- d-----w- C:\Program Files\Common Files\ATI Technologies
2015-09-27 10:49:25 -------- d-----w- C:\Program Files\AMD
2015-09-27 10:48:59 -------- d-----w- C:\WINDOWS\SysWow64\RTCOM
2015-09-27 10:48:59 -------- d-----w- C:\Program Files\Realtek
2015-09-25 17:28:44 -------- d-----w- C:\Program Files (x86)\World of Warcraft
2015-09-24 16:26:43 -------- d-----w- C:\Users\Corentin\AppData\Local\Ubisoft Game Launcher
2015-09-21 19:30:27 -------- d-----w- C:\Users\Corentin\AppData\Local\CEF
2015-09-21 19:27:10 968704 ----a-w- C:\WINDOWS\System32\MsSpellCheckingFacility.exe
2015-09-21 19:27:08 1155072 ----a-w- C:\WINDOWS\SysWow64\mshtmlmedia.dll
2015-09-21 19:27:07 1359360 ----a-w- C:\WINDOWS\System32\mshtmlmedia.dll
2015-09-21 19:26:15 41984 ----a-w- C:\WINDOWS\System32\UtcResources.dll
2015-09-21 19:23:24 12288 ----a-w- C:\WINDOWS\System32\wu.upgrade.ps.dll
2015-09-10 07:05:55 -------- d--h--w- C:\$Windows.~BT
2015-09-10 05:57:04 16148 ----a-w- C:\WINDOWS\System32\WIN-TVAQ5U78ATO_Administrator_HistoryPrediction.bin
2015-09-10 05:54:48 -------- d-----w- C:\ProgramData\Microsoft OneDrive
2015-09-10 05:53:54 -------- d-----w- C:\Logs
2015-09-10 05:46:23 2718208 ----a-w- C:\WINDOWS\SysWow64\PrintConfig.dll
2015-09-10 05:26:53 -------- d-----w- C:\WINDOWS\ShellNew
2015-09-10 05:26:53 -------- d-----w- C:\Program Files\Windows Journal
2015-09-10 05:12:08 -------- d-----w- C:\WINDOWS\OCR
2015-09-10 05:08:14 -------- d-----w- C:\WINDOWS\SysWow64\winrm
2015-09-10 05:07:33 9728 ----a-w- C:\WINDOWS\System32\drivers\fr-FR\synth3dvsc.sys.mui
2015-09-10 05:06:59 9216 ----a-w- C:\WINDOWS\System32\drivers\fr-FR\EhStorTcgDrv.sys.mui
.
==================== Find3M ====================
.
2015-10-06 15:28:22 25640 ----a-w- C:\WINDOWS\gdrv.sys
2015-09-27 11:38:03 96768 ----a-w- C:\WINDOWS\SysWow64\mqoa.tlb
2015-09-27 11:38:03 91136 ----a-w- C:\WINDOWS\SysWow64\mqoa30.tlb
2015-09-27 11:38:03 55808 ----a-w- C:\WINDOWS\SysWow64\mqoa20.tlb
2015-09-27 11:38:03 37376 ----a-w- C:\WINDOWS\SysWow64\mqoa10.tlb
2015-09-27 11:38:01 635904 ----a-w- C:\WINDOWS\SysWow64\mqsnap.dll
2015-09-27 11:38:01 14848 ----a-w- C:\WINDOWS\SysWow64\mqcertui.dll
2015-09-27 11:38:00 55808 ----a-w- C:\WINDOWS\System32\admwprox.dll
2015-09-27 11:38:00 53248 ----a-w- C:\WINDOWS\System32\ahadmin.dll
2015-09-27 11:38:00 202240 ----a-w- C:\WINDOWS\System32\iisRtl.dll
2015-09-27 11:38:00 18432 ----a-w- C:\WINDOWS\System32\iisreset.exe
2015-09-27 11:38:00 15360 ----a-w- C:\WINDOWS\System32\wamregps.dll
2015-09-25 00:35:02 257024 ----a-w- C:\WINDOWS\System32\UserDataAccountApis.dll
2015-09-25 00:34:58 223232 ----a-w- C:\WINDOWS\System32\PhoneCallHistoryApis.dll
2015-09-25 00:13:23 1276416 ----a-w- C:\WINDOWS\System32\wifinetworkmanager.dll
2015-09-24 23:34:42 195584 ----a-w- C:\WINDOWS\SysWow64\UserDataAccountApis.dll
2015-09-24 23:34:35 172032 ----a-w- C:\WINDOWS\SysWow64\PhoneCallHistoryApis.dll
2015-09-24 23:24:32 796160 ----a-w- C:\WINDOWS\System32\TokenBroker.dll
2015-09-24 23:24:24 689152 ----a-w- C:\WINDOWS\System32\Windows.Security.Authentication.Web.Core.dll
2015-09-24 23:23:48 579072 ----a-w- C:\WINDOWS\System32\winlogon.exe
2015-09-24 23:17:38 2178560 ----a-w- C:\WINDOWS\System32\AppXDeploymentServer.dll
2015-09-24 23:08:37 3586560 ----a-w- C:\WINDOWS\System32\win32kfull.sys
2015-09-24 23:07:45 1382400 ----a-w- C:\WINDOWS\System32\win32kbase.sys
2015-09-24 23:06:12 1423872 ----a-w- C:\WINDOWS\System32\UserDataService.dll
2015-09-24 23:05:14 288256 ----a-w- C:\WINDOWS\System32\PimIndexMaintenance.dll
2015-09-24 23:01:28 685568 ----a-w- C:\WINDOWS\System32\AppointmentApis.dll
2015-09-24 23:01:04 856576 ----a-w- C:\WINDOWS\System32\ContactApis.dll
2015-09-24 23:00:55 720896 ----a-w- C:\WINDOWS\System32\EmailApis.dll
2015-09-24 23:00:33 752640 ----a-w- C:\WINDOWS\System32\ChatApis.dll
2015-09-24 23:00:19 1205248 ----a-w- C:\WINDOWS\System32\Unistore.dll
2015-09-24 23:00:05 163840 ----a-w- C:\WINDOWS\System32\CallHistoryClient.dll
2015-09-24 22:53:13 590336 ----a-w- C:\WINDOWS\System32\MessagingDataModel2.dll
2015-09-24 22:43:30 613376 ----a-w- C:\WINDOWS\SysWow64\TokenBroker.dll
2015-09-24 22:43:14 480256 ----a-w- C:\WINDOWS\SysWow64\Windows.Security.Authentication.Web.Core.dll
2015-09-24 22:42:19 1795072 ----a-w- C:\WINDOWS\System32\AppXDeploymentExtensions.dll
2015-09-24 22:25:44 579584 ----a-w- C:\WINDOWS\SysWow64\AppointmentApis.dll
2015-09-24 22:25:34 625152 ----a-w- C:\WINDOWS\SysWow64\ContactApis.dll
2015-09-24 22:25:15 557568 ----a-w- C:\WINDOWS\SysWow64\ChatApis.dll
2015-09-24 22:25:02 928256 ----a-w- C:\WINDOWS\SysWow64\Unistore.dll
2015-09-24 22:25:00 525312 ----a-w- C:\WINDOWS\SysWow64\EmailApis.dll
2015-09-24 22:24:45 131072 ----a-w- C:\WINDOWS\SysWow64\CallHistoryClient.dll
2015-09-24 22:19:24 466432 ----a-w- C:\WINDOWS\SysWow64\MessagingDataModel2.dll
2015-09-19 05:14:37 102304 ----a-w- C:\WINDOWS\System32\omadmapi.dll
2015-09-17 06:50:17 99664 ----a-w- C:\WINDOWS\System32\drivers\pdc.sys
2015-09-17 06:50:10 2464216 ----a-w- C:\WINDOWS\System32\mfcore.dll
2015-09-17 06:50:05 1563392 ----a-w- C:\WINDOWS\System32\winmde.dll
2015-09-17 06:50:02 88384 ----a-w- C:\WINDOWS\System32\remoteaudioendpoint.dll
2015-09-17 06:49:33 1563472 ----a-w- C:\WINDOWS\System32\wmpmde.dll
2015-09-17 06:49:11 6487248 ----a-w- C:\WINDOWS\System32\windows.storage.dll
2015-09-17 06:49:11 501008 ----a-w- C:\WINDOWS\System32\AudioEng.dll
2015-09-17 06:49:10 894256 ----a-w- C:\WINDOWS\System32\drivers\Wdf01000.sys
2015-09-17 06:49:05 8020816 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2015-09-17 06:49:01 553808 ----a-w- C:\WINDOWS\System32\SettingSyncHost.exe
2015-09-17 06:47:11 1397088 ----a-w- C:\WINDOWS\System32\LicenseManager.dll
2015-09-17 06:44:22 781976 ----a-w- C:\WINDOWS\System32\mfds.dll
2015-09-17 06:39:29 81488 ----a-w- C:\WINDOWS\System32\acmigration.dll
2015-09-17 06:37:20 1168736 ----a-w- C:\WINDOWS\System32\drivers\ndis.sys
2015-09-17 06:37:19 1295712 ----a-w- C:\WINDOWS\System32\wpx.dll
2015-09-17 06:28:43 2154808 ----a-w- C:\WINDOWS\SysWow64\mfcore.dll
2015-09-17 06:28:40 5120056 ----a-w- C:\WINDOWS\SysWow64\windows.storage.dll
2015-09-17 06:28:38 74880 ----a-w- C:\WINDOWS\SysWow64\remoteaudioendpoint.dll
2015-09-17 06:28:36 1357888 ----a-w- C:\WINDOWS\SysWow64\winmde.dll
2015-09-17 06:28:29 441168 ----a-w- C:\WINDOWS\SysWow64\SettingSyncHost.exe
2015-09-17 06:28:21 407608 ----a-w- C:\WINDOWS\SysWow64\AudioSes.dll
2015-09-17 06:27:29 1766952 ----a-w- C:\WINDOWS\SysWow64\CoreUIComponents.dll
2015-09-17 06:27:16 454512 ----a-w- C:\WINDOWS\SysWow64\directmanipulation.dll
2015-09-17 06:26:49 434376 ----a-w- C:\WINDOWS\SysWow64\MFCaptureEngine.dll
2015-09-17 06:26:41 1895568 ----a-w- C:\WINDOWS\SysWow64\hevcdecoder.dll
2015-09-17 06:26:39 2446648 ----a-w- C:\WINDOWS\SysWow64\msmpeg2vdec.dll
2015-09-17 06:26:38 646672 ----a-w- C:\WINDOWS\SysWow64\mfsvr.dll
2015-09-17 06:26:32 508248 ----a-w- C:\WINDOWS\SysWow64\mf.dll
2015-09-17 06:26:31 428128 ----a-w- C:\WINDOWS\SysWow64\WWanAPI.dll
2015-09-17 06:25:10 962400 ----a-w- C:\WINDOWS\SysWow64\LicenseManager.dll
2015-09-17 06:21:38 658528 ----a-w- C:\WINDOWS\SysWow64\mfds.dll
2015-09-17 06:20:25 764416 ----a-w- C:\WINDOWS\SysWow64\twinapi.appcore.dll
2015-09-17 06:12:18 16708608 ----a-w- C:\WINDOWS\System32\Windows.UI.Xaml.dll
2015-09-17 06:11:07 160256 ----a-w- C:\WINDOWS\System32\enrollmentapi.dll
2015-09-17 06:09:54 269312 ----a-w- C:\WINDOWS\System32\provengine.dll
2015-09-17 06:09:50 143360 ----a-w- C:\WINDOWS\System32\provops.dll
2015-09-17 06:08:23 494592 ----a-w- C:\WINDOWS\System32\StoreAgent.dll
2015-09-17 06:08:03 26624 ----a-w- C:\WINDOWS\System32\LicenseManagerShellext.exe
2015-09-17 06:08:01 53760 ----a-w- C:\WINDOWS\System32\Windows.Speech.Pal.dll
2015-09-17 06:07:53 21875712 ----a-w- C:\WINDOWS\System32\edgehtml.dll
2015-09-17 06:06:11 467968 ----a-w- C:\WINDOWS\System32\MBMediaManager.dll
2015-09-17 06:06:10 690688 ----a-w- C:\WINDOWS\System32\CellularAPI.dll
2015-09-17 06:06:04 149504 ----a-w- C:\WINDOWS\System32\tetheringservice.dll
2015-09-17 06:05:53 2226688 ----a-w- C:\WINDOWS\System32\NetworkMobileSettings.dll
2015-09-17 06:05:02 483328 ----a-w- C:\WINDOWS\System32\OneDriveSettingSyncProvider.dll
2015-09-17 06:04:55 504320 ----a-w- C:\WINDOWS\System32\DataSenseHandlers.dll
2015-09-17 06:04:41 910848 ----a-w- C:\WINDOWS\System32\SharedStartModel.dll
2015-09-17 06:04:22 7569408 ----a-w- C:\WINDOWS\System32\mos.dll
2015-09-17 06:03:52 88064 ----a-w- C:\WINDOWS\System32\ngckeyenum.dll
2015-09-17 06:03:28 267776 ----a-w- C:\WINDOWS\System32\Windows.Internal.Management.dll
2015-09-17 06:03:02 83968 ----a-w- C:\WINDOWS\System32\DeviceEnroller.exe
2015-09-17 06:02:59 68096 ----a-w- C:\WINDOWS\System32\EnterpriseDesktopAppMgmtCSP.dll
2015-09-17 06:00:51 106496 ----a-w- C:\WINDOWS\System32\KeywordDetectorMsftSidAdapter.dll
2015-09-17 06:00:46 3248640 ----a-w- C:\WINDOWS\System32\Windows.Media.dll
2015-09-17 06:00:18 2417664 ----a-w- C:\WINDOWS\System32\MFMediaEngine.dll
2015-09-17 06:00:11 446976 ----a-w- C:\WINDOWS\System32\MapConfiguration.dll
2015-09-17 05:58:01 503808 ----a-w- C:\WINDOWS\System32\tileobjserver.dll
.
============= FINISH: 19:35:46,66 ===============


Thanks for your help !

Attached Files
File Type: txt attach.txt (4.8 KB)

Malware on laptop

$
0
0
Hi,
My laptop has become laggy and a little slow, and has been having the odd crash.
Sometimes it seems to be a graphics/display issue, where the computer goes into a hibernate/sleep mode but won't kick back in without a hard reset; other times it just shuts itself down. It has frozen a few times too.

I use a VAIO which I've had since 2010. In that time I've had reasonable virus protection, but I suspect it's picked up something.
While I use computers daily for work, I don't have a great understanding of their operation - therefore not very adept at rooting out the problems and would really appreciate some help please.
As per instructions, dds log here and attach log... attached...
Cheers,
Alice

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.18015 BrowserJavaVersion: 11.31.2
Run by Alice at 23:50:07 on 2015-10-06
Microsoft Windows 7 Professional 6.1.7601.1.1252.61.1033.18.3959.1914 [GMT 2:00]
.
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Windows\system32\GWX\GWX.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
C:\Program Files\Sony\VAIO Update\VUAgent.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.au/
BHO: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} -
BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} -
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} -
TB: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} -
TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -
TB: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} -
TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
EB: Canon Easy-WebPrint EX: {21347690-EC41-4F9A-8887-1F4AEE672439} -
uRun: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\CODEME~1.LNK - C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe
uPolicies-Explorer: NoDrives = dword:0
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - {BC0E0A5D-AB5A-4fa4-A5FA-280E1D58EEEE} - c:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} - hxxp://kitchenplanner.ikea.com/AUW/Core/Player/2020PlayerAX_IKEA_Win32.cab
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{8B2AE300-2433-4536-A446-71F6F6147159} : DHCPNameServer = 192.168.10.1
TCP: Interfaces\{C55D03F3-3692-4477-87EF-7461C0E45FB6} : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{C55D03F3-3692-4477-87EF-7461C0E45FB6}\0514C4055524C49434 : DHCPNameServer = 192.168.10.1
TCP: Interfaces\{C55D03F3-3692-4477-87EF-7461C0E45FB6}\0596E67616023543 : DHCPNameServer = 192.168.43.1
TCP: Interfaces\{C55D03F3-3692-4477-87EF-7461C0E45FB6}\14E64627F696461405 : DHCPNameServer = 192.168.43.1
TCP: Interfaces\{C55D03F3-3692-4477-87EF-7461C0E45FB6}\2556D6168702C416B65637 : DHCPNameServer = 10.0.0.2
TCP: Interfaces\{C55D03F3-3692-4477-87EF-7461C0E45FB6}\4556C637472716437414D264340343 : DHCPNameServer = 10.0.0.138
TCP: Interfaces\{C55D03F3-3692-4477-87EF-7461C0E45FB6}\84743543D494E494 : DHCPNameServer = 192.168.43.1
Notify: VESWinlogon - VESWinlogon.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.101\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} -
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} -
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
Hosts: 69.25.74.36 MAIL006 #Exchange Hosting 11/14/13 16:40:04
Hosts: 69.25.74.37 MAIL007 #Exchange Hosting 11/14/13 16:40:04
Hosts: 69.25.74.38 BE008 #Exchange Hosting 11/14/13 16:40:04
Hosts: 69.25.74.39 BE009 #Exchange Hosting 11/14/13 16:40:04
Hosts: 69.25.74.40 BE010 #Exchange Hosting 11/14/13 16:40:04
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2013-11-14 65224]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2013-11-14 274808]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-4-1 55280]
R0 shpf;Sony HDD Protection Filter Driver;C:\Windows\System32\drivers\shpf.sys [2009-11-27 25120]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswsnx.sys [2013-11-14 1048344]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-11-14 447944]
R2 aswHwid;avast! HardwareID;C:\Windows\System32\drivers\aswHwid.sys [2014-7-29 28656]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-11-14 90968]
R2 aswStm;aswStm;C:\Windows\System32\drivers\aswStm.sys [2014-7-29 150672]
R2 avast! Antivirus;Avast Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-9-8 146600]
R2 CodeMeter.exe;CodeMeter Runtime Server;C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe [2013-11-15 3105144]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-14 27136]
R2 rimspci;rimspci;C:\Windows\System32\drivers\rimssne64.sys [2009-11-27 93696]
R2 risdsnpe;risdsnpe;C:\Windows\System32\drivers\risdsne64.sys [2009-11-27 76800]
R2 ss_conn_service;SAMSUNG Mobile Connectivity Service;C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [2015-3-4 743688]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;C:\Windows\System32\drivers\ArcSoftKsUFilter.sys [2011-4-1 19968]
R3 btusbflt;Bluetooth USB Filter;C:\Windows\System32\drivers\btusbflt.sys [2009-11-27 52264]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2009-11-27 35104]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2009-11-27 56344]
R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2009-11-27 151936]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller (NDIS 6.20);C:\Windows\System32\drivers\L1C62x64.sys [2009-11-27 62464]
R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETw5s64.sys [2009-9-15 6952960]
R3 SFEP;Sony Firmware Extension Parser;C:\Windows\System32\drivers\SFEP.sys [2009-11-27 11392]
R3 VUAgent;VUAgent;C:\Program Files\Sony\VAIO Update\VUAgent.exe [2013-2-16 1286784]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-4-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-4-11 124088]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-7-9 327296]
S3 AvastVBoxSvc;AvastVBox COM Service;C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe --> C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [?]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2015-9-9 114688]
S3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2009-11-27 244736]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-11-14 19456]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-11-14 56832]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-4-1 1255736]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464]
S4 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-9-6 169312]
S4 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-11-27 13336]
S4 McMPFSvc;McAfee Personal Firewall Service;"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc --> C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [?]
S4 PMBDeviceInfoProvider;PMBDeviceInfoProvider;C:\Program Files (x86)\SONY\PMB\PMBDeviceInfoProvider.exe [2009-10-24 360224]
S4 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2009-8-31 313840]
S4 Roxio Upnp Server 10;Roxio Upnp Server 10;C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [2009-8-31 362992]
S4 SOHCImp;VAIO Media plus Content Importer;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2011-4-1 120104]
S4 SOHDBSvr;VAIO Media plus Database Manager;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [2011-4-1 70952]
S4 SOHDms;VAIO Media plus Digital Media Server;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe [2011-4-1 427304]
S4 SOHDs;VAIO Media plus Device Searcher;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [2011-4-1 75048]
S4 SOHPlMgr;VAIO Media plus Playlist Manager;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [2011-4-1 91432]
S4 uCamMonitor;CamMonitor;C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2011-4-1 104960]
S4 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-27 2314240]
S4 VAIO Power Management;VAIO Power Management;C:\Program Files\Sony\VAIO Power Management\SPMService.exe [2011-4-1 571248]
S4 VCFw;VAIO Content Folder Watcher;C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2009-9-15 642416]
S4 VSNService;VSNService;C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [2011-4-1 845312]
.
=============== Created Last 30 ================
.
2015-09-28 11:13:34 -------- d-----r- C:\Program Files (x86)\Skype
2015-09-12 21:09:41 -------- d-----w- C:\Users\Alice\AppData\Local\Toggl
2015-09-12 07:31:10 -------- d-----w- C:\Users\Alice\AppData\Local\TogglDesktop
2015-09-09 01:01:47 41984 ----a-w- C:\Windows\System32\UtcResources.dll
2015-09-08 22:45:10 939520 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2015-09-08 22:39:48 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2015-09-08 22:39:48 2048 ----a-w- C:\Windows\System32\tzres.dll
2015-09-08 22:39:36 82944 ----a-w- C:\Windows\System32\dwmapi.dll
2015-09-08 22:39:36 67584 ----a-w- C:\Windows\SysWow64\dwmapi.dll
2015-09-08 22:39:36 1632256 ----a-w- C:\Windows\System32\dwmcore.dll
2015-09-08 22:39:36 1372160 ----a-w- C:\Windows\SysWow64\dwmcore.dll
2015-09-08 22:28:45 98304 ----a-w- C:\Windows\System32\wudriver.dll
2015-09-08 10:49:23 43112 ----a-w- C:\Windows\avastSS.scr
.
==================== Find3M ====================
.
2015-09-08 10:50:47 1048344 ----a-w- C:\Windows\System32\drivers\aswsnx.sys
2015-09-08 10:49:29 93528 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2015-09-08 10:49:29 90968 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2015-09-08 10:49:29 65224 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2015-09-08 10:49:29 28656 ----a-w- C:\Windows\System32\drivers\aswHwid.sys
2015-09-08 10:49:29 274808 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2015-09-08 10:49:29 150672 ----a-w- C:\Windows\System32\drivers\aswStm.sys
2015-08-27 18:18:27 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2015-08-27 18:18:27 1887232 ----a-w- C:\Windows\System32\msxml3.dll
2015-08-27 18:13:03 2048 ----a-w- C:\Windows\System32\msxml6r.dll
2015-08-27 18:13:03 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2015-08-27 17:58:14 1391104 ----a-w- C:\Windows\SysWow64\msxml6.dll
2015-08-27 17:58:14 1241088 ----a-w- C:\Windows\SysWow64\msxml3.dll
2015-08-27 17:51:26 2048 ----a-w- C:\Windows\SysWow64\msxml6r.dll
2015-08-27 17:51:26 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2015-08-26 18:07:11 3165696 ----a-w- C:\Windows\System32\wucltux.dll
2015-08-26 18:07:11 192000 ----a-w- C:\Windows\System32\wuwebv.dll
2015-08-26 18:06:43 91136 ----a-w- C:\Windows\System32\WinSetupUI.dll
2015-08-26 18:06:33 12288 ----a-w- C:\Windows\System32\wu.upgrade.ps.dll
2015-08-26 18:06:30 37376 ----a-w- C:\Windows\System32\wuapp.exe
2015-08-26 17:56:25 93184 ----a-w- C:\Windows\SysWow64\wudriver.dll
2015-08-26 17:56:25 173056 ----a-w- C:\Windows\SysWow64\wuwebv.dll
2015-08-26 17:55:37 34816 ----a-w- C:\Windows\SysWow64\wuapp.exe
2015-08-15 06:34:10 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2015-08-15 06:33:56 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2015-08-15 06:18:47 66560 ----a-w- C:\Windows\System32\iesetup.dll
2015-08-15 06:18:00 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2015-08-15 06:17:54 417792 ----a-w- C:\Windows\System32\html.iec
2015-08-15 06:17:49 585216 ----a-w- C:\Windows\System32\vbscript.dll
2015-08-15 06:17:25 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2015-08-15 06:04:47 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
2015-08-15 06:04:46 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2015-08-15 06:04:25 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2015-08-15 06:00:44 5923328 ----a-w- C:\Windows\System32\jscript9.dll
2015-08-15 05:57:20 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2015-08-15 05:53:22 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2015-08-15 05:46:15 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2015-08-15 05:40:29 504832 ----a-w- C:\Windows\SysWow64\vbscript.dll
2015-08-15 05:40:12 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2015-08-15 05:39:32 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2015-08-15 05:39:22 341504 ----a-w- C:\Windows\SysWow64\html.iec
2015-08-15 05:38:34 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2015-08-15 05:29:36 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2015-08-15 05:29:12 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2015-08-15 05:22:47 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2015-08-15 05:22:03 2126336 ----a-w- C:\Windows\System32\inetcpl.cpl
2015-08-15 05:16:37 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2015-08-15 05:10:32 4520448 ----a-w- C:\Windows\SysWow64\jscript9.dll
2015-08-15 05:07:28 2427392 ----a-w- C:\Windows\System32\wininet.dll
2015-08-15 05:01:47 2052608 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2015-08-15 05:01:23 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2015-08-15 04:43:00 1951232 ----a-w- C:\Windows\SysWow64\wininet.dll
2015-08-05 17:56:14 1110016 ----a-w- C:\Windows\System32\schedsvc.dll
2015-08-05 17:56:07 24576 ----a-w- C:\Windows\System32\jnwmon.dll
2015-08-05 17:56:06 275456 ----a-w- C:\Windows\System32\InkEd.dll
2015-08-05 17:40:50 216064 ----a-w- C:\Windows\SysWow64\InkEd.dll
2015-08-04 18:03:10 692672 ----a-w- C:\Windows\System32\winload.efi
2015-08-04 18:00:24 616360 ----a-w- C:\Windows\System32\winresume.efi
2015-08-04 17:56:54 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
2015-08-04 17:56:37 59392 ----a-w- C:\Windows\System32\appidapi.dll
2015-08-04 17:56:37 32768 ----a-w- C:\Windows\System32\appidsvc.dll
2015-08-04 17:55:57 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2015-08-04 17:55:57 147456 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2015-08-04 17:47:42 50688 ----a-w- C:\Windows\SysWow64\appidapi.dll
2015-08-04 16:58:09 61440 ----a-w- C:\Windows\System32\drivers\appid.sys
2015-07-30 13:13:38 103120 ----a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-07-30 13:13:11 124624 ----a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2015-07-28 20:09:44 17344 ----a-w- C:\Windows\System32\CompatTelRunner.exe
2015-07-28 20:05:53 774656 ----a-w- C:\Windows\System32\invagent.dll
2015-07-28 20:05:50 743424 ----a-w- C:\Windows\System32\generaltel.dll
2015-07-28 20:05:47 437760 ----a-w- C:\Windows\System32\devinv.dll
2015-07-28 20:05:45 1116672 ----a-w- C:\Windows\System32\appraiser.dll
2015-07-28 20:05:44 69120 ----a-w- C:\Windows\System32\acmigration.dll
2015-07-28 20:05:44 227328 ----a-w- C:\Windows\System32\aepdu.dll
2015-07-28 19:55:14 1148416 ----a-w- C:\Windows\System32\aeinv.dll
2015-07-23 00:06:26 5568960 ----a-w- C:\Windows\System32\ntoskrnl.exe
2015-07-23 00:06:25 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2015-07-23 00:06:25 155584 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2015-07-23 00:03:19 1730496 ----a-w- C:\Windows\System32\ntdll.dll
2015-07-23 00:03:07 362496 ----a-w- C:\Windows\System32\wow64win.dll
2015-07-23 00:03:07 243712 ----a-w- C:\Windows\System32\wow64.dll
2015-07-23 00:03:07 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2015-07-23 00:03:06 215040 ----a-w- C:\Windows\System32\winsrv.dll
2015-07-23 00:01:53 31232 ----a-w- C:\Windows\System32\lsass.exe
2015-07-23 00:01:39 338432 ----a-w- C:\Windows\System32\conhost.exe
2015-07-23 00:01:32 64000 ----a-w- C:\Windows\System32\auditpol.exe
2015-07-22 23:58:17 60416 ----a-w- C:\Windows\System32\msobjs.dll
2015-07-22 23:57:53 146432 ----a-w- C:\Windows\System32\msaudite.dll
2015-07-22 23:51:59 686080 ----a-w- C:\Windows\System32\adtschema.dll
2015-07-22 17:57:49 3989952 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2015-07-22 17:57:49 3934656 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2015-07-22 17:54:12 1311768 ----a-w- C:\Windows\SysWow64\ntdll.dll
2015-07-22 17:52:52 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2015-07-22 17:52:19 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2015-07-22 17:52:03 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2015-07-22 17:52:03 665088 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2015-07-22 17:52:03 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2015-07-22 17:52:03 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2015-07-22 17:47:28 60416 ----a-w- C:\Windows\SysWow64\msobjs.dll
2015-07-22 17:46:50 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll
.
============= FINISH: 23:54:59.57 ===============

Attached Files
File Type: txt attach.txt (17.1 KB)
Viewing all 2798 articles
Browse latest View live