:banghead:
Good day.
I am attaching both dds and gmer logs for your kind review and check.
Please let me know if I am infected. :dance:
Thanks.
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.17148 BrowserJavaVersion: 11.25.2
Run by AAA at 1:28:43 on 2014-11-30
Microsoft Windows 8 Enterprise 6.2.9200.0.1252.1.1033.18.4007.1304 [GMT 3:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: IObit Malware Fighter *Enabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ===============
.
C:\Windows\system32\svchost.exe -k DcomLaunch
E:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\dwm.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
E:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhostex.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Windows\Explorer.EXE
E:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
C:\Program Files (x86)\AVG Security Toolbar\AVG-Secure-Search-Update_0814tb.exe
C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
D:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
C:\Windows\system32\dashost.exe
D:\Program Files\Everything\Everything.exe
C:\Windows\system32\svchost.exe -k ftpsvc
C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
C:\Users\AAA\AppData\Local\Pokki\Engine\pokki.exe
D:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Windows\system32\HPSIsvc.exe
C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Users\AAA\AppData\Local\Pokki\Engine\pokki.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
D:\Program files\Everything\Everything.exe
C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
D:\Program Files (x86)\Glary Utilities 5\Integrator.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
C:\Users\AAA\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\ProgramData\DatacardService\HWDeviceService64.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Windows\System32\svchost.exe -k LPDService
C:\Windows\system32\mqsvc.exe
C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft SQL Server\MSSQL10_50.INFLOWSQL\MSSQL\Binn\sqlservr.exe
C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
E:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe
C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Users\AAA\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
E:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
D:\Program Files (x86)\EaseUS\TrayPopup\TrayTipAgent.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Windows\System32\tcpsvcs.exe
C:\Windows\System32\snmp.exe
E:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
D:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k iissvcs
C:\Windows\system32\nfsclnt.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
D:\Program Files\CCleaner\CCleaner64.exe
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\System32\vds.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Totalcmd\TOTALCMD64.EXE
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Download Manager\idmBroker.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
E:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe
C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
h:\Program Files (x86)\NoteTab Light\NoteTab.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:Tabs
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit = userinit.exe,
BHO: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
BHO: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - <orphaned>
BHO: RoboForm Toolbar Helper: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files (x86)\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: {95B7759C-8C7F-4BF1-B163-73684A933233} - <orphaned>
BHO: Ads Removal: {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} - C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Skype Click to Call for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Advanced SystemCare Surfing Protection: {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files (x86)\bin\jp2ssv.dll
TB: &RoboForm Toolbar: {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: &RoboForm Toolbar: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
uRun: [SkyDrive] "C:\Users\AAA\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
uRun: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
uRun: [GoogleChromeAutoLaunch_A9208FCD4CA26FAC663319374273DF73] "C:\Users\AAA\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window
uRun: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean
uRun: [Pokki] C:\Windows\System32\rundll32.exe "C:\Users\AAA\AppData\Local\Pokki\Engine\Launcher.dll",RunLaunchPlatform
uRun: [IncrediMail] C:\Program Files (x86)\IncrediMail\bin\IncMail.exe /c
uRun: [GUDelayStartup] "D:\Program Files (x86)\Glary Utilities 5\StartupManager.exe" -delayrun
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [CCleaner Monitoring] "D:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
uRun: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
uRun: [Advanced SystemCare 8] "E:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto
uRunOnce: [Application Restart #5] C:\Users\AAA\AppData\Local\Pokki\Engine\pokki.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend="C:\Users\AAA\AppData\Local\Pokki\Engine\inspector" --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --flag-switches-begin --flag-switches-end --restore-last-session
mRun: [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
mRun: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AvastUI.exe] "E:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [EaseUS TB Tray Agent] "D:\Program Files (x86)\EaseUS\TrayPopup\TrayTipAgent.exe"
mRun: [IObit Malware Fighter] "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
StartupFolder: C:\Users\AAA\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\AAA\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\AAA\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\HipChat.lnk - C:\Program Files (x86)\Atlassian\HipChat\hipchat.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: SoftwareSASGeneration = dword:1
IE: Customize Menu - C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComCustomizeIEMenu.html
IE: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Fill Forms - C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComFillForms.html
IE: Inbox Search - tbr:iemenu
IE: Save Forms - C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComSavePass.html
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
IE: Show RoboForm Toolbar - C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComShowToolbar.html
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-001051-0002-0051-ABCDEFFEDCBC} - <orphaned>
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - <orphaned>
IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com/bin/srldetect_intel_4.5.24.0.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{068E33F3-1A71-4E5A-BC80-D9268D7AFA75} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{068E33F3-1A71-4E5A-BC80-D9268D7AFA75}\3716D61627F54374 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{068E33F3-1A71-4E5A-BC80-D9268D7AFA75}\7416D696C616F575966696 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{164C9E2A-E42D-466E-AE18-FC857AFFAB59} : DHCPNameServer = 84.235.6.55 84.235.57.230
TCP: Interfaces\{4393D3FE-0961-4AEC-B38A-F207D12F1414}\4516D697F657A7E236F6D6 : DHCPNameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{4393D3FE-0961-4AEC-B38A-F207D12F1414}\7416D696C616F575966696 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{E0ED986C-B430-4230-B469-9641FC64D88A} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{EA0B51A7-2CF9-4570-8DA5-E9AD07A92ABA} : DHCPNameServer = 192.168.1.1 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: livecall - <Clsid value has no data>
Handler: msnim - <Clsid value has no data>
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
Handler: tbr - <Clsid value has no data>
Handler: wlpg - <Clsid value has no data>
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll
x64-BHO: ExplorerWnd Helper: {10921475-03CE-4E04-90CE-E2E7EF20C814} - E:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
x64-BHO: RoboForm Toolbar Helper: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Skype Click to Call for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - <orphaned>
x64-TB: &RoboForm Toolbar: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [IgfxTray] "C:\Windows\System32\igfxtray.exe"
x64-Run: [HotKeysCmds] "C:\Windows\System32\hkcmd.exe"
x64-Run: [Persistence] "C:\Windows\System32\igfxpers.exe"
x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
x64-Run: [Everything] "D:\Program Files\Everything\Everything.exe" -startup
x64-Run: [StartupDelayer] "D:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe" /LaunchType=Auto /LaunchApps=Common
x64-Run: [CDAServer] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
x64-mPolicies-System: SoftwareSASGeneration = dword:1
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {724d43aa-0d85-11d4-9908-00400523e39a} - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: livecall - <Clsid value has no data>
x64-Handler: msnim - <Clsid value has no data>
x64-Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: tbr - <Clsid value has no data>
x64-Handler: wlpg - <Clsid value has no data>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
Hosts: 127.0.0.1 Spyware Info | Spyware Info
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\AAA\AppData\Roaming\Mozilla\Firefox\Profiles\qsf0nrji.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo!
FF - prefs.js: browser.startup.homepage - about:Tabs
FF - prefs.js: keyword.URL - hxxps://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=407453&p=
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll
FF - plugin: C:\Users\AAA\AppData\Local\Pokki\Download Helper\npPokkiDownloadHelper.1.2.0.78.dll
FF - plugin: C:\Users\AAA\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\AAA\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Users\AAA\AppData\Roaming\Mozilla\plugins\npo1d.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_233.dll
FF - plugin: D:\Program Files (x86)\bin\dtplugin\npdeployJava1.dll
FF - plugin: D:\Program Files (x86)\bin\plugin2\npjp2.dll
.
---- FIREFOX POLICIES ----
?FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: content.notify.ontimer - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.switch.threshold - 750000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\Drivers\aswRvrt.sys [2014-10-30 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\Drivers\aswVmm.sys [2014-10-30 267632]
R0 EUBAKUP;EUBAKUP;C:\Windows\System32\Drivers\eubakup.sys [2014-11-17 60936]
R0 EUBKMON;EUBKMON;C:\Windows\System32\Drivers\EUBKMON.sys [2014-11-17 48136]
R0 SmartDefragDriver;SmartDefragDriver;C:\Windows\System32\Drivers\SmartDefragDriver.sys [2014-11-28 21184]
R1 aswSnx;aswSnx;C:\Windows\System32\Drivers\aswsnx.sys [2014-11-22 1050432]
R1 aswSP;aswSP;C:\Windows\System32\Drivers\aswSP.sys [2014-10-30 436624]
R1 EUDSKACS;EUDSKACS;C:\Windows\System32\Drivers\eudskacs.sys [2014-11-17 18440]
R1 EUFDDISK;EUFDDISK;C:\Windows\System32\Drivers\EuFdDisk.sys [2014-11-17 188936]
R1 GUBootStartup;GUBootStartup;C:\Windows\System32\Drivers\GUBootStartup.sys [2014-9-12 20160]
R2 AdvancedSystemCareService8;Advanced SystemCare Service 8;E:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [2014-11-28 815392]
R2 aswHwid;avast! HardwareID;C:\Windows\System32\Drivers\aswHwid.sys [2014-10-30 29208]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\Drivers\aswmonflt.sys [2014-10-30 83280]
R2 avast! Antivirus;avast! Antivirus;E:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-11-11 50344]
R2 c2cautoupdatesvc;Skype Click to Call Updater;C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-7-14 1390176]
R2 c2cpnrsvc;Skype Click to Call PNR Service;C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-7-14 1767520]
R2 EaseUS Agent;EaseUS Agent Service;D:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [2014-11-17 37384]
R2 Everything;Everything;D:\Program files\Everything\Everything.exe [2014-10-8 1441792]
R2 ftpsvc;Microsoft FTP Service;C:\Windows\System32\svchost.exe -k ftpsvc [2013-7-6 29696]
R2 HP LaserJet Service;HP LaserJet Service;C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2009-6-24 136704]
R2 HPSIService;HP SI Service;C:\Windows\System32\HPSIsvc.exe [2014-11-16 127800]
R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe [2014-9-15 89352]
R2 HWDeviceService64.exe;HWDeviceService64.exe;C:\ProgramData\DatacardService\HWDeviceService64.exe [2011-3-14 346976]
R2 IDMWFP;IDMWFP;C:\Windows\System32\Drivers\idmwfp.sys [2014-11-7 180136]
R2 IMFservice;IMF Service;C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2014-11-28 344896]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 MSSQL$INFLOWSQL;SQL Server (INFLOWSQL);C:\Program Files\Microsoft SQL Server\MSSQL10_50.INFLOWSQL\MSSQL\Binn\sqlservr.exe [2014-7-10 62379184]
R2 NfsClnt;Client for NFS;C:\Windows\System32\nfsclnt.exe [2012-7-26 101376]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-7-4 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-7-4 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-7-4 171928]
R2 ss_conn_service;SAMSUNG Mobile Connectivity Service;D:\Program files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [2014-10-13 741640]
R2 SSPORT;SSPORT;C:\Windows\System32\Drivers\SSPORT.SYS [2011-3-14 11576]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-11-27 364416]
R3 FileMonitor;FileMonitor;C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [2014-11-28 23048]
R3 huawei_enumerator;huawei_enumerator;C:\Windows\System32\Drivers\ew_jubusenum.sys [2014-11-14 91648]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-11-7 169752]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\Drivers\IntcDAud.sys [2013-11-7 342528]
R3 MBfilt;MBfilt;C:\Windows\System32\Drivers\MBfilt64.sys [2014-9-20 32344]
R3 NfsRdr;Client for NFS Redirector;C:\Windows\System32\Drivers\nfsrdr.sys [2014-7-13 262656]
R3 RegFilter;RegFilter;C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\RegFilter.sys [2014-11-28 34848]
R3 RpcXdr;Server for NFS Open RPC (ONCRPC);C:\Windows\System32\Drivers\rpcxdr.sys [2012-7-26 132096]
R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2014-11-14 874712]
R3 SmbDrvI;SmbDrvI;C:\Windows\System32\Drivers\Smb_driver_Intel.sys [2014-11-14 33008]
R3 UrlFilter;UrlFilter;C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\UrlFilter.sys [2014-11-28 23016]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\Windows\System32\Drivers\WUDFRd.sys [2012-7-26 198656]
S2 aswStm;aswStm;C:\Windows\System32\Drivers\aswStm.sys [2014-10-30 116728]
S2 LiveUpdateSvc;LiveUpdate;C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2014-11-14 2630432]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-4-3 315008]
S3 athrusb;Atheros Wireless LAN USB device driver;C:\Windows\System32\Drivers\athrxusb.sys [2008-7-29 1075712]
S3 athur;Qualcomm Atheros AR9271 Wireless Network Adapter Service;C:\Windows\System32\Drivers\athuw8x.sys [2013-8-29 2919936]
S3 bthav;Bluetooth AV Profile;C:\Windows\System32\Drivers\bthav.sys [2008-7-10 40448]
S3 c2wts;Claims to Windows Token Service;C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [2012-7-26 5632]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\Drivers\ssudbus.sys [2014-10-13 110336]
S3 DrvAgent64;DrvAgent64;C:\Windows\SysWOW64\drivers\DrvAgent64.SYS [2014-2-8 21712]
S3 DsRoleSvc;DS Role Server;C:\Windows\System32\lsass.exe [2014-5-14 35840]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;C:\Windows\System32\Drivers\ew_hwusbdev.sys [2014-11-4 117248]
S3 ew_usbenumfilter;huawei_CompositeFilter;C:\Windows\System32\Drivers\ew_usbenumfilter.sys [2014-11-4 13952]
S3 huawei_cdcacm;huawei_cdcacm;C:\Windows\System32\Drivers\ew_jucdcacm.sys [2014-11-4 98816]
S3 huawei_cdcecm;huawei_cdcecm;C:\Windows\System32\Drivers\ew_jucdcecm.sys [2014-11-4 69632]
S3 huawei_ext_ctrl;huawei_ext_ctrl;C:\Windows\System32\Drivers\ew_juextctrl.sys [2014-11-4 28672]
S3 mvusbews;USB EWS Device;C:\Windows\System32\Drivers\mvusbews.sys [2014-10-21 20480]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\Drivers\netaapl64.sys [2013-7-25 23040]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 pwdrvio;pwdrvio;C:\Windows\System32\pwdrvio.sys [2014-11-2 19152]
S3 pwdspio;pwdspio;C:\Windows\System32\pwdspio.sys [2014-11-2 12504]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;C:\Windows\System32\Drivers\RTL8187B.sys [2012-6-2 416768]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\System32\Drivers\ssudmdm.sys [2014-10-13 206080]
S3 SWDUMon;SWDUMon;C:\Windows\System32\Drivers\SWDUMon.sys [2014-9-19 16152]
S3 taphss6;Anchorfree HSS VPN Adapter;C:\Windows\System32\Drivers\taphss6.sys [2014-5-17 42184]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 vmbusr;Virtual Machine Bus Provider;C:\Windows\System32\Drivers\vmbusr.sys [2012-7-26 117248]
S3 WSDScan;WSD Scan Support;C:\Windows\System32\Drivers\WSDScan.sys [2013-7-6 23552]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2010-4-3 59744]
S4 RsFx0153;RsFx0153 Driver;C:\Windows\System32\Drivers\RsFx0153.sys [2014-7-10 322736]
S4 SQLAgent$INFLOWSQL;SQL Server Agent (INFLOWSQL);C:\Program Files\Microsoft SQL Server\MSSQL10_50.INFLOWSQL\MSSQL\Binn\SQLAGENT.EXE [2014-7-10 442536]
.
=============== File Associations ===============
.
FileExt: .txt: Applications\NoteTab.exe="h:\Program Files (x86)\NoteTab Light\NoteTab.exe" "%1" [UserChoice]
FileExt: .vbs: VBSFile="C:\Windows\System32\WScript.exe" "%1" %* [UserChoice]
.
=============== Created Last 30 ================
.
2014-11-28 09:26:06 128288 ----a-w- C:\Windows\System32\IObitSmartDefragExtension.dll
2014-11-28 09:03:33 34080 ----a-w- C:\Windows\System32\SmartDefragBootTime.exe
2014-11-28 09:02:41 21184 ----a-w- C:\Windows\System32\drivers\SmartDefragDriver.sys
2014-11-26 09:06:03 -------- d-----w- C:\Windows\softwaredistribution.bak1
2014-11-26 08:36:19 74703 ----a-w- C:\Windows\SysWow64\mfc45.dat
2014-11-26 08:36:19 -------- d-----w- C:\ProgramData\iolo
2014-11-26 08:36:19 -------- d-----w- C:\Program Files (x86)\iolo
2014-11-26 03:54:27 -------- d-----w- C:\Program Files (x86)\Atlassian
2014-11-26 02:53:02 97280 ----a-w- C:\Windows\SysWow64\vspell32.ocx
2014-11-26 02:53:02 70656 ----a-w- C:\Windows\SysWow64\vspell32.dll
2014-11-26 02:53:02 102912 ----a-w- C:\Windows\SysWow64\Vb6stkit.dll
2014-11-26 02:52:59 89600 ----a-w- C:\Windows\SysWow64\Leocx32.ocx
2014-11-26 02:52:59 84992 ----a-w- C:\Windows\SysWow64\Ledit32.dll
2014-11-26 02:52:59 369696 ----a-w- C:\Windows\SysWow64\Comct332.ocx
2014-11-26 02:52:55 659456 ----a-w- C:\Windows\SysWow64\ckstring.dll
2014-11-26 02:52:54 1847296 ----a-w- C:\Windows\SysWow64\ChilkatFtp2.dll
2014-11-26 02:52:54 1531904 ----a-w- C:\Windows\SysWow64\ChilkatCert.dll
2014-11-26 02:02:53 69632 ----a-w- C:\Windows\System32\vsstrace.dll
2014-11-26 02:02:53 52224 ----a-w- C:\Windows\SysWow64\vsstrace.dll
2014-11-26 02:02:52 1195520 ----a-w- C:\Windows\SysWow64\vssapi.dll
2014-11-26 02:02:51 1519104 ----a-w- C:\Windows\System32\vssapi.dll
2014-11-26 02:02:50 1484288 ----a-w- C:\Windows\System32\VSSVC.exe
2014-11-26 02:01:12 713672 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-11-26 02:01:12 106440 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-11-24 04:29:31 -------- d-----w- C:\Users\AAA\AppData\Local\fontconfig
2014-11-22 12:01:33 -------- d-----w- C:\Program Files\Common Files\Common Desktop Agent
2014-11-22 12:01:33 -------- d-----w- C:\Program Files (x86)\Common Files\Common Desktop Agent
2014-11-22 12:00:09 36864 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\ssj1mpc.dll
2014-11-22 10:49:50 1050432 ----a-w- C:\Windows\System32\drivers\aswsnx.sys
2014-11-18 21:20:21 827904 ----a-w- C:\Windows\System32\kerberos.dll
2014-11-18 21:20:21 666624 ----a-w- C:\Windows\SysWow64\kerberos.dll
2014-11-18 21:20:20 238080 ----a-w- C:\Windows\System32\pku2u.dll
2014-11-18 21:20:20 187904 ----a-w- C:\Windows\SysWow64\pku2u.dll
2014-11-17 23:58:34 299520 --sha-w- C:\EUMONBMP.SYS
2014-11-16 22:39:19 60936 ----a-w- C:\Windows\System32\drivers\eubakup.sys
2014-11-16 22:39:19 188936 ----a-w- C:\Windows\System32\drivers\EuFdDisk.sys
2014-11-16 22:39:19 18440 ----a-w- C:\Windows\System32\drivers\eudskacs.sys
2014-11-16 22:39:16 48136 ----a-w- C:\Windows\System32\drivers\EUBKMON.sys
2014-11-16 22:37:14 24072 ----a-w- C:\Windows\System32\fbnative.exe
2014-11-16 16:50:19 -------- dc----w- C:\Users\AAA\AppData\Local\MigWiz
2014-11-16 16:00:38 17536 ----a-w- C:\ProgramData\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2014-11-15 22:56:16 127800 ----a-w- C:\Windows\System32\HPSIsvc.exe
2014-11-14 04:06:58 874712 ----a-w- C:\Windows\System32\drivers\Rt630x64.sys
2014-11-14 04:06:58 73800 ----a-w- C:\Windows\System32\RtNicProp64.dll
2014-11-14 04:06:34 100312 ----a-w- C:\Windows\System32\drivers\TeeDriverx64.sys
2014-11-14 04:04:34 -------- d-----w- C:\Program Files\Synaptics
2014-11-14 04:04:13 33008 ----a-w- C:\Windows\System32\drivers\Smb_driver_Intel.sys
2014-11-14 02:12:49 91648 ----a-w- C:\Windows\System32\drivers\ew_jubusenum.sys
2014-11-14 01:53:29 -------- d-----w- C:\Users\AAA\AppData\Roaming\ProductData
2014-11-14 01:51:52 -------- d-----w- C:\Program Files (x86)\IObit
2014-11-14 01:51:45 -------- d-----w- C:\ProgramData\ProductData
2014-11-14 01:51:22 -------- d-----w- C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
2014-11-14 01:51:10 -------- d-----w- C:\Program Files (x86)\Common Files\IObit
2014-11-14 01:50:34 -------- d-----w- C:\Users\AAA\AppData\Roaming\IObit
2014-11-12 04:47:37 28616704 ----a-w- C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2014-11-12 04:47:36 27853824 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2014-11-12 04:38:21 1845760 ----a-w- C:\Windows\System32\msxml3.dll
2014-11-12 04:38:20 1418752 ----a-w- C:\Windows\SysWow64\msxml3.dll
2014-11-12 04:25:03 783872 ----a-w- C:\Windows\System32\audiosrv.dll
2014-11-12 04:25:03 522728 ----a-w- C:\Windows\System32\AUDIOKSE.dll
2014-11-12 04:25:03 267264 ----a-w- C:\Windows\System32\EncDump.dll
2014-11-12 04:25:03 169472 ----a-w- C:\Windows\System32\AudioEndpointBuilder.dll
2014-11-12 04:24:20 778240 ----a-w- C:\Windows\System32\oleaut32.dll
2014-11-12 04:24:20 567808 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2014-11-12 04:23:33 4068864 ----a-w- C:\Windows\System32\win32k.sys
2014-11-12 04:22:57 8858624 ----a-w- C:\Windows\SysWow64\twinui.dll
2014-11-12 04:22:56 10115072 ----a-w- C:\Windows\System32\twinui.dll
2014-11-12 04:22:55 2885632 ----a-w- C:\Windows\System32\msi.dll
2014-11-12 04:22:55 2416640 ----a-w- C:\Windows\SysWow64\msi.dll
2014-11-12 04:22:54 393216 ----a-w- C:\Windows\System32\msihnd.dll
2014-11-12 04:22:54 2307072 ----a-w- C:\Windows\System32\authui.dll
2014-11-12 04:22:54 2037760 ----a-w- C:\Windows\SysWow64\authui.dll
2014-11-12 04:22:53 295424 ----a-w- C:\Windows\SysWow64\msihnd.dll
2014-11-12 04:04:17 79872 ----a-w- C:\Windows\System32\packager.dll
2014-11-12 04:04:17 68096 ----a-w- C:\Windows\SysWow64\packager.dll
2014-11-11 15:48:09 43152 ----a-w- C:\Windows\avastSS.scr
2014-11-08 12:48:54 -------- d--h--w- C:\CanoScan
2014-11-07 23:52:29 -------- d-----w- C:\Users\AAA\AppData\Local\WEB2Print
2014-11-07 07:21:40 180136 ----a-w- C:\Windows\System32\drivers\idmwfp.sys
2014-11-07 02:00:37 -------- d-----w- C:\Users\AAA\.Virtualbox
2014-11-07 01:54:36 -------- d-----w- C:\Users\AAA\youwave
2014-11-05 20:03:00 -------- d-----w- C:\Users\AAA\AppData\Roaming\DVDVideoSoft
2014-11-04 23:22:26 -------- d-----w- C:\Program Files\Babylon
2014-11-04 19:18:16 98816 ----a-w- C:\Windows\System32\drivers\ew_jucdcacm.sys
2014-11-04 19:18:16 69632 ----a-w- C:\Windows\System32\drivers\ew_jucdcecm.sys
2014-11-04 19:18:16 415744 ----a-w- C:\Windows\System32\drivers\ewusbwwan.sys
2014-11-04 19:18:16 32768 ----a-w- C:\Windows\System32\drivers\ewdcsc.sys
2014-11-04 19:18:16 28672 ----a-w- C:\Windows\System32\drivers\ew_juextctrl.sys
2014-11-04 19:18:16 222464 ----a-w- C:\Windows\System32\drivers\ewusbmdm.sys
2014-11-04 19:18:16 22016 ----a-w- C:\Windows\System32\drivers\ew_hwupgrade.sys
2014-11-04 19:18:16 212992 ----a-w- C:\Windows\System32\drivers\ew_juwwanecm.sys
2014-11-04 19:18:16 13952 ----a-w- C:\Windows\System32\drivers\ew_usbenumfilter.sys
2014-11-04 19:18:16 117248 ----a-w- C:\Windows\System32\drivers\ew_hwusbdev.sys
2014-11-04 19:18:16 1001472 ----a-w- C:\Windows\System32\drivers\mod7700.sys
2014-11-02 20:47:35 -------- d-----w- C:\Users\AAA\AppData\Roaming\JAM Software
2014-11-02 19:49:49 3050808 ----a-w- C:\Windows\System32\pwNative.exe
2014-11-02 19:49:49 19152 ------w- C:\Windows\System32\pwdrvio.sys
2014-11-02 19:49:49 12504 ------w- C:\Windows\System32\pwdspio.sys
.
==================== Find3M ====================
.
2014-11-28 21:35:47 16152 ----a-w- C:\Windows\System32\drivers\SWDUMon.sys
2014-11-16 00:46:51 987136 ----a-w- C:\Windows\SysWow64\srmclient.dll
2014-11-16 00:46:51 673792 ----a-w- C:\Windows\System32\mfmpeg2srcsnk.dll
2014-11-16 00:46:51 652800 ----a-w- C:\Windows\System32\srmscan.dll
2014-11-16 00:46:51 513536 ----a-w- C:\Windows\SysWow64\mfmpeg2srcsnk.dll
2014-11-16 00:46:51 487936 ----a-w- C:\Windows\SysWow64\srmscan.dll
2014-11-16 00:46:51 279040 ----a-w- C:\Windows\System32\srm.dll
2014-11-16 00:46:51 278528 ----a-w- C:\Windows\SysWow64\srm.dll
2014-11-16 00:46:51 212992 ----a-w- C:\Windows\System32\dnsrslvr.dll
2014-11-16 00:46:51 1346560 ----a-w- C:\Windows\System32\srmclient.dll
2014-11-16 00:46:51 134144 ----a-w- C:\Windows\System32\adrclient.dll
2014-11-16 00:46:51 104448 ----a-w- C:\Windows\SysWow64\adrclient.dll
2014-11-14 02:07:49 98216 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-11-11 15:48:15 116728 ----a-w- C:\Windows\System32\drivers\aswStm.sys
2014-11-11 15:48:14 93568 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2014-11-11 15:48:14 83280 ----a-w- C:\Windows\System32\drivers\aswmonflt.sys
2014-11-11 15:48:14 65776 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2014-11-11 15:48:14 29208 ----a-w- C:\Windows\System32\drivers\aswHwid.sys
2014-11-11 15:48:14 267632 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2014-10-26 01:56:17 2237952 ----a-w- C:\Windows\System32\wininet.dll
2014-10-26 01:56:06 915968 ----a-w- C:\Windows\System32\uxtheme.dll
2014-10-26 01:56:06 53760 ----a-w- C:\Windows\System32\UXInit.dll
2014-10-26 01:54:43 3959296 ----a-w- C:\Windows\System32\jscript9.dll
2014-10-26 01:54:36 67072 ----a-w- C:\Windows\System32\iesetup.dll
2014-10-26 01:54:36 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2014-10-26 01:53:54 1509376 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-10-26 00:36:01 1762816 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-10-26 00:35:53 44032 ----a-w- C:\Windows\SysWow64\UXInit.dll
2014-10-26 00:34:48 2861568 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-10-26 00:34:43 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-10-26 00:34:43 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2014-10-26 00:34:16 1441280 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-10-26 00:19:11 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2014-10-26 00:13:06 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-10-25 21:48:29 534528 ----a-w- C:\Windows\SysWow64\uxtheme.dll
2014-10-18 13:09:48 334992 ----a-w- C:\Windows\System32\RaCoInstx.dll
2014-10-18 13:09:48 2217616 ----a-w- C:\Windows\System32\drivers\netr28ux.sys
2014-10-15 09:52:25 20160 ----a-w- C:\Windows\System32\drivers\GUBootStartup.sys
2014-10-11 08:35:58 171840 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2014-10-11 07:44:56 588288 ----a-w- C:\Windows\System32\SHCore.dll
2014-10-11 07:44:47 3248640 ----a-w- C:\Windows\System32\rdpcorets.dll
2014-10-11 07:43:51 1281536 ----a-w- C:\Windows\System32\lsasrv.dll
2014-10-11 05:57:57 452608 ----a-w- C:\Windows\SysWow64\SHCore.dll
2014-10-11 05:41:57 146944 ----a-w- C:\Windows\System32\msaudite.dll
2014-10-11 05:41:43 713728 ----a-w- C:\Windows\System32\adtschema.dll
2014-10-11 05:05:20 146944 ----a-w- C:\Windows\SysWow64\msaudite.dll
2014-10-11 05:04:59 713728 ----a-w- C:\Windows\SysWow64\adtschema.dll
2014-09-24 23:29:59 318976 ----a-w- C:\Windows\SysWow64\schannel.dll
2014-09-24 23:29:51 72192 ----a-w- C:\Windows\SysWow64\ncryptsslp.dll
2014-09-24 23:01:14 414208 ----a-w- C:\Windows\System32\schannel.dll
2014-09-24 23:01:00 86528 ----a-w- C:\Windows\System32\ncryptsslp.dll
2014-09-24 07:42:26 226424 ----a-w- C:\Windows\System32\SBuySupplies.exe
2014-09-22 05:53:10 35320 ----a-w- C:\Windows\System32\drivers\WdBoot.sys
2014-09-13 06:24:47 2233152 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2014-09-03 02:48:48 141824 ----a-w- C:\Windows\SysWow64\rpchttp.dll
2014-09-03 02:48:47 510464 ----a-w- C:\Windows\SysWow64\rastls.dll
2014-09-03 02:22:00 188928 ----a-w- C:\Windows\System32\rpchttp.dll
2014-09-03 02:21:59 585728 ----a-w- C:\Windows\System32\rastls.dll
.
============= FINISH: 1:30:38.79 ===============
Good day.
I am attaching both dds and gmer logs for your kind review and check.
Please let me know if I am infected. :dance:
Thanks.
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.17148 BrowserJavaVersion: 11.25.2
Run by AAA at 1:28:43 on 2014-11-30
Microsoft Windows 8 Enterprise 6.2.9200.0.1252.1.1033.18.4007.1304 [GMT 3:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: IObit Malware Fighter *Enabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ===============
.
C:\Windows\system32\svchost.exe -k DcomLaunch
E:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\dwm.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
E:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhostex.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Windows\Explorer.EXE
E:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
C:\Program Files (x86)\AVG Security Toolbar\AVG-Secure-Search-Update_0814tb.exe
C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
D:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
C:\Windows\system32\dashost.exe
D:\Program Files\Everything\Everything.exe
C:\Windows\system32\svchost.exe -k ftpsvc
C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
C:\Users\AAA\AppData\Local\Pokki\Engine\pokki.exe
D:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Windows\system32\HPSIsvc.exe
C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Users\AAA\AppData\Local\Pokki\Engine\pokki.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
D:\Program files\Everything\Everything.exe
C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
D:\Program Files (x86)\Glary Utilities 5\Integrator.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
C:\Users\AAA\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\ProgramData\DatacardService\HWDeviceService64.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Windows\System32\svchost.exe -k LPDService
C:\Windows\system32\mqsvc.exe
C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft SQL Server\MSSQL10_50.INFLOWSQL\MSSQL\Binn\sqlservr.exe
C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
E:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe
C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Users\AAA\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
E:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
D:\Program Files (x86)\EaseUS\TrayPopup\TrayTipAgent.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Windows\System32\tcpsvcs.exe
C:\Windows\System32\snmp.exe
E:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
D:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k iissvcs
C:\Windows\system32\nfsclnt.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
D:\Program Files\CCleaner\CCleaner64.exe
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\System32\vds.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Totalcmd\TOTALCMD64.EXE
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Download Manager\idmBroker.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
E:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe
C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
h:\Program Files (x86)\NoteTab Light\NoteTab.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:Tabs
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit = userinit.exe,
BHO: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
BHO: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - <orphaned>
BHO: RoboForm Toolbar Helper: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files (x86)\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: {95B7759C-8C7F-4BF1-B163-73684A933233} - <orphaned>
BHO: Ads Removal: {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} - C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Skype Click to Call for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Advanced SystemCare Surfing Protection: {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files (x86)\bin\jp2ssv.dll
TB: &RoboForm Toolbar: {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: &RoboForm Toolbar: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
uRun: [SkyDrive] "C:\Users\AAA\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
uRun: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
uRun: [GoogleChromeAutoLaunch_A9208FCD4CA26FAC663319374273DF73] "C:\Users\AAA\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window
uRun: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean
uRun: [Pokki] C:\Windows\System32\rundll32.exe "C:\Users\AAA\AppData\Local\Pokki\Engine\Launcher.dll",RunLaunchPlatform
uRun: [IncrediMail] C:\Program Files (x86)\IncrediMail\bin\IncMail.exe /c
uRun: [GUDelayStartup] "D:\Program Files (x86)\Glary Utilities 5\StartupManager.exe" -delayrun
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [CCleaner Monitoring] "D:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
uRun: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
uRun: [Advanced SystemCare 8] "E:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto
uRunOnce: [Application Restart #5] C:\Users\AAA\AppData\Local\Pokki\Engine\pokki.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend="C:\Users\AAA\AppData\Local\Pokki\Engine\inspector" --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --flag-switches-begin --flag-switches-end --restore-last-session
mRun: [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
mRun: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AvastUI.exe] "E:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [EaseUS TB Tray Agent] "D:\Program Files (x86)\EaseUS\TrayPopup\TrayTipAgent.exe"
mRun: [IObit Malware Fighter] "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
StartupFolder: C:\Users\AAA\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\AAA\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\AAA\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\HipChat.lnk - C:\Program Files (x86)\Atlassian\HipChat\hipchat.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: SoftwareSASGeneration = dword:1
IE: Customize Menu - C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComCustomizeIEMenu.html
IE: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Fill Forms - C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComFillForms.html
IE: Inbox Search - tbr:iemenu
IE: Save Forms - C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComSavePass.html
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
IE: Show RoboForm Toolbar - C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComShowToolbar.html
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-001051-0002-0051-ABCDEFFEDCBC} - <orphaned>
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - <orphaned>
IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com/bin/srldetect_intel_4.5.24.0.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{068E33F3-1A71-4E5A-BC80-D9268D7AFA75} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{068E33F3-1A71-4E5A-BC80-D9268D7AFA75}\3716D61627F54374 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{068E33F3-1A71-4E5A-BC80-D9268D7AFA75}\7416D696C616F575966696 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{164C9E2A-E42D-466E-AE18-FC857AFFAB59} : DHCPNameServer = 84.235.6.55 84.235.57.230
TCP: Interfaces\{4393D3FE-0961-4AEC-B38A-F207D12F1414}\4516D697F657A7E236F6D6 : DHCPNameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{4393D3FE-0961-4AEC-B38A-F207D12F1414}\7416D696C616F575966696 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{E0ED986C-B430-4230-B469-9641FC64D88A} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{EA0B51A7-2CF9-4570-8DA5-E9AD07A92ABA} : DHCPNameServer = 192.168.1.1 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: livecall - <Clsid value has no data>
Handler: msnim - <Clsid value has no data>
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
Handler: tbr - <Clsid value has no data>
Handler: wlpg - <Clsid value has no data>
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll
x64-BHO: ExplorerWnd Helper: {10921475-03CE-4E04-90CE-E2E7EF20C814} - E:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
x64-BHO: RoboForm Toolbar Helper: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Skype Click to Call for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - <orphaned>
x64-TB: &RoboForm Toolbar: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [IgfxTray] "C:\Windows\System32\igfxtray.exe"
x64-Run: [HotKeysCmds] "C:\Windows\System32\hkcmd.exe"
x64-Run: [Persistence] "C:\Windows\System32\igfxpers.exe"
x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
x64-Run: [Everything] "D:\Program Files\Everything\Everything.exe" -startup
x64-Run: [StartupDelayer] "D:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe" /LaunchType=Auto /LaunchApps=Common
x64-Run: [CDAServer] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
x64-mPolicies-System: SoftwareSASGeneration = dword:1
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {724d43aa-0d85-11d4-9908-00400523e39a} - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: livecall - <Clsid value has no data>
x64-Handler: msnim - <Clsid value has no data>
x64-Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: tbr - <Clsid value has no data>
x64-Handler: wlpg - <Clsid value has no data>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
Hosts: 127.0.0.1 Spyware Info | Spyware Info
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\AAA\AppData\Roaming\Mozilla\Firefox\Profiles\qsf0nrji.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo!
FF - prefs.js: browser.startup.homepage - about:Tabs
FF - prefs.js: keyword.URL - hxxps://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=407453&p=
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll
FF - plugin: C:\Users\AAA\AppData\Local\Pokki\Download Helper\npPokkiDownloadHelper.1.2.0.78.dll
FF - plugin: C:\Users\AAA\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\AAA\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Users\AAA\AppData\Roaming\Mozilla\plugins\npo1d.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_233.dll
FF - plugin: D:\Program Files (x86)\bin\dtplugin\npdeployJava1.dll
FF - plugin: D:\Program Files (x86)\bin\plugin2\npjp2.dll
.
---- FIREFOX POLICIES ----
?FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: content.notify.ontimer - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.switch.threshold - 750000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\Drivers\aswRvrt.sys [2014-10-30 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\Drivers\aswVmm.sys [2014-10-30 267632]
R0 EUBAKUP;EUBAKUP;C:\Windows\System32\Drivers\eubakup.sys [2014-11-17 60936]
R0 EUBKMON;EUBKMON;C:\Windows\System32\Drivers\EUBKMON.sys [2014-11-17 48136]
R0 SmartDefragDriver;SmartDefragDriver;C:\Windows\System32\Drivers\SmartDefragDriver.sys [2014-11-28 21184]
R1 aswSnx;aswSnx;C:\Windows\System32\Drivers\aswsnx.sys [2014-11-22 1050432]
R1 aswSP;aswSP;C:\Windows\System32\Drivers\aswSP.sys [2014-10-30 436624]
R1 EUDSKACS;EUDSKACS;C:\Windows\System32\Drivers\eudskacs.sys [2014-11-17 18440]
R1 EUFDDISK;EUFDDISK;C:\Windows\System32\Drivers\EuFdDisk.sys [2014-11-17 188936]
R1 GUBootStartup;GUBootStartup;C:\Windows\System32\Drivers\GUBootStartup.sys [2014-9-12 20160]
R2 AdvancedSystemCareService8;Advanced SystemCare Service 8;E:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [2014-11-28 815392]
R2 aswHwid;avast! HardwareID;C:\Windows\System32\Drivers\aswHwid.sys [2014-10-30 29208]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\Drivers\aswmonflt.sys [2014-10-30 83280]
R2 avast! Antivirus;avast! Antivirus;E:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-11-11 50344]
R2 c2cautoupdatesvc;Skype Click to Call Updater;C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-7-14 1390176]
R2 c2cpnrsvc;Skype Click to Call PNR Service;C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-7-14 1767520]
R2 EaseUS Agent;EaseUS Agent Service;D:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [2014-11-17 37384]
R2 Everything;Everything;D:\Program files\Everything\Everything.exe [2014-10-8 1441792]
R2 ftpsvc;Microsoft FTP Service;C:\Windows\System32\svchost.exe -k ftpsvc [2013-7-6 29696]
R2 HP LaserJet Service;HP LaserJet Service;C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2009-6-24 136704]
R2 HPSIService;HP SI Service;C:\Windows\System32\HPSIsvc.exe [2014-11-16 127800]
R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe [2014-9-15 89352]
R2 HWDeviceService64.exe;HWDeviceService64.exe;C:\ProgramData\DatacardService\HWDeviceService64.exe [2011-3-14 346976]
R2 IDMWFP;IDMWFP;C:\Windows\System32\Drivers\idmwfp.sys [2014-11-7 180136]
R2 IMFservice;IMF Service;C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2014-11-28 344896]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 MSSQL$INFLOWSQL;SQL Server (INFLOWSQL);C:\Program Files\Microsoft SQL Server\MSSQL10_50.INFLOWSQL\MSSQL\Binn\sqlservr.exe [2014-7-10 62379184]
R2 NfsClnt;Client for NFS;C:\Windows\System32\nfsclnt.exe [2012-7-26 101376]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-7-4 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-7-4 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-7-4 171928]
R2 ss_conn_service;SAMSUNG Mobile Connectivity Service;D:\Program files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [2014-10-13 741640]
R2 SSPORT;SSPORT;C:\Windows\System32\Drivers\SSPORT.SYS [2011-3-14 11576]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-11-27 364416]
R3 FileMonitor;FileMonitor;C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [2014-11-28 23048]
R3 huawei_enumerator;huawei_enumerator;C:\Windows\System32\Drivers\ew_jubusenum.sys [2014-11-14 91648]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-11-7 169752]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\Drivers\IntcDAud.sys [2013-11-7 342528]
R3 MBfilt;MBfilt;C:\Windows\System32\Drivers\MBfilt64.sys [2014-9-20 32344]
R3 NfsRdr;Client for NFS Redirector;C:\Windows\System32\Drivers\nfsrdr.sys [2014-7-13 262656]
R3 RegFilter;RegFilter;C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\RegFilter.sys [2014-11-28 34848]
R3 RpcXdr;Server for NFS Open RPC (ONCRPC);C:\Windows\System32\Drivers\rpcxdr.sys [2012-7-26 132096]
R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2014-11-14 874712]
R3 SmbDrvI;SmbDrvI;C:\Windows\System32\Drivers\Smb_driver_Intel.sys [2014-11-14 33008]
R3 UrlFilter;UrlFilter;C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\UrlFilter.sys [2014-11-28 23016]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\Windows\System32\Drivers\WUDFRd.sys [2012-7-26 198656]
S2 aswStm;aswStm;C:\Windows\System32\Drivers\aswStm.sys [2014-10-30 116728]
S2 LiveUpdateSvc;LiveUpdate;C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2014-11-14 2630432]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-4-3 315008]
S3 athrusb;Atheros Wireless LAN USB device driver;C:\Windows\System32\Drivers\athrxusb.sys [2008-7-29 1075712]
S3 athur;Qualcomm Atheros AR9271 Wireless Network Adapter Service;C:\Windows\System32\Drivers\athuw8x.sys [2013-8-29 2919936]
S3 bthav;Bluetooth AV Profile;C:\Windows\System32\Drivers\bthav.sys [2008-7-10 40448]
S3 c2wts;Claims to Windows Token Service;C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [2012-7-26 5632]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\Drivers\ssudbus.sys [2014-10-13 110336]
S3 DrvAgent64;DrvAgent64;C:\Windows\SysWOW64\drivers\DrvAgent64.SYS [2014-2-8 21712]
S3 DsRoleSvc;DS Role Server;C:\Windows\System32\lsass.exe [2014-5-14 35840]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;C:\Windows\System32\Drivers\ew_hwusbdev.sys [2014-11-4 117248]
S3 ew_usbenumfilter;huawei_CompositeFilter;C:\Windows\System32\Drivers\ew_usbenumfilter.sys [2014-11-4 13952]
S3 huawei_cdcacm;huawei_cdcacm;C:\Windows\System32\Drivers\ew_jucdcacm.sys [2014-11-4 98816]
S3 huawei_cdcecm;huawei_cdcecm;C:\Windows\System32\Drivers\ew_jucdcecm.sys [2014-11-4 69632]
S3 huawei_ext_ctrl;huawei_ext_ctrl;C:\Windows\System32\Drivers\ew_juextctrl.sys [2014-11-4 28672]
S3 mvusbews;USB EWS Device;C:\Windows\System32\Drivers\mvusbews.sys [2014-10-21 20480]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\Drivers\netaapl64.sys [2013-7-25 23040]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 pwdrvio;pwdrvio;C:\Windows\System32\pwdrvio.sys [2014-11-2 19152]
S3 pwdspio;pwdspio;C:\Windows\System32\pwdspio.sys [2014-11-2 12504]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;C:\Windows\System32\Drivers\RTL8187B.sys [2012-6-2 416768]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\System32\Drivers\ssudmdm.sys [2014-10-13 206080]
S3 SWDUMon;SWDUMon;C:\Windows\System32\Drivers\SWDUMon.sys [2014-9-19 16152]
S3 taphss6;Anchorfree HSS VPN Adapter;C:\Windows\System32\Drivers\taphss6.sys [2014-5-17 42184]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 vmbusr;Virtual Machine Bus Provider;C:\Windows\System32\Drivers\vmbusr.sys [2012-7-26 117248]
S3 WSDScan;WSD Scan Support;C:\Windows\System32\Drivers\WSDScan.sys [2013-7-6 23552]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2010-4-3 59744]
S4 RsFx0153;RsFx0153 Driver;C:\Windows\System32\Drivers\RsFx0153.sys [2014-7-10 322736]
S4 SQLAgent$INFLOWSQL;SQL Server Agent (INFLOWSQL);C:\Program Files\Microsoft SQL Server\MSSQL10_50.INFLOWSQL\MSSQL\Binn\SQLAGENT.EXE [2014-7-10 442536]
.
=============== File Associations ===============
.
FileExt: .txt: Applications\NoteTab.exe="h:\Program Files (x86)\NoteTab Light\NoteTab.exe" "%1" [UserChoice]
FileExt: .vbs: VBSFile="C:\Windows\System32\WScript.exe" "%1" %* [UserChoice]
.
=============== Created Last 30 ================
.
2014-11-28 09:26:06 128288 ----a-w- C:\Windows\System32\IObitSmartDefragExtension.dll
2014-11-28 09:03:33 34080 ----a-w- C:\Windows\System32\SmartDefragBootTime.exe
2014-11-28 09:02:41 21184 ----a-w- C:\Windows\System32\drivers\SmartDefragDriver.sys
2014-11-26 09:06:03 -------- d-----w- C:\Windows\softwaredistribution.bak1
2014-11-26 08:36:19 74703 ----a-w- C:\Windows\SysWow64\mfc45.dat
2014-11-26 08:36:19 -------- d-----w- C:\ProgramData\iolo
2014-11-26 08:36:19 -------- d-----w- C:\Program Files (x86)\iolo
2014-11-26 03:54:27 -------- d-----w- C:\Program Files (x86)\Atlassian
2014-11-26 02:53:02 97280 ----a-w- C:\Windows\SysWow64\vspell32.ocx
2014-11-26 02:53:02 70656 ----a-w- C:\Windows\SysWow64\vspell32.dll
2014-11-26 02:53:02 102912 ----a-w- C:\Windows\SysWow64\Vb6stkit.dll
2014-11-26 02:52:59 89600 ----a-w- C:\Windows\SysWow64\Leocx32.ocx
2014-11-26 02:52:59 84992 ----a-w- C:\Windows\SysWow64\Ledit32.dll
2014-11-26 02:52:59 369696 ----a-w- C:\Windows\SysWow64\Comct332.ocx
2014-11-26 02:52:55 659456 ----a-w- C:\Windows\SysWow64\ckstring.dll
2014-11-26 02:52:54 1847296 ----a-w- C:\Windows\SysWow64\ChilkatFtp2.dll
2014-11-26 02:52:54 1531904 ----a-w- C:\Windows\SysWow64\ChilkatCert.dll
2014-11-26 02:02:53 69632 ----a-w- C:\Windows\System32\vsstrace.dll
2014-11-26 02:02:53 52224 ----a-w- C:\Windows\SysWow64\vsstrace.dll
2014-11-26 02:02:52 1195520 ----a-w- C:\Windows\SysWow64\vssapi.dll
2014-11-26 02:02:51 1519104 ----a-w- C:\Windows\System32\vssapi.dll
2014-11-26 02:02:50 1484288 ----a-w- C:\Windows\System32\VSSVC.exe
2014-11-26 02:01:12 713672 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-11-26 02:01:12 106440 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-11-24 04:29:31 -------- d-----w- C:\Users\AAA\AppData\Local\fontconfig
2014-11-22 12:01:33 -------- d-----w- C:\Program Files\Common Files\Common Desktop Agent
2014-11-22 12:01:33 -------- d-----w- C:\Program Files (x86)\Common Files\Common Desktop Agent
2014-11-22 12:00:09 36864 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\ssj1mpc.dll
2014-11-22 10:49:50 1050432 ----a-w- C:\Windows\System32\drivers\aswsnx.sys
2014-11-18 21:20:21 827904 ----a-w- C:\Windows\System32\kerberos.dll
2014-11-18 21:20:21 666624 ----a-w- C:\Windows\SysWow64\kerberos.dll
2014-11-18 21:20:20 238080 ----a-w- C:\Windows\System32\pku2u.dll
2014-11-18 21:20:20 187904 ----a-w- C:\Windows\SysWow64\pku2u.dll
2014-11-17 23:58:34 299520 --sha-w- C:\EUMONBMP.SYS
2014-11-16 22:39:19 60936 ----a-w- C:\Windows\System32\drivers\eubakup.sys
2014-11-16 22:39:19 188936 ----a-w- C:\Windows\System32\drivers\EuFdDisk.sys
2014-11-16 22:39:19 18440 ----a-w- C:\Windows\System32\drivers\eudskacs.sys
2014-11-16 22:39:16 48136 ----a-w- C:\Windows\System32\drivers\EUBKMON.sys
2014-11-16 22:37:14 24072 ----a-w- C:\Windows\System32\fbnative.exe
2014-11-16 16:50:19 -------- dc----w- C:\Users\AAA\AppData\Local\MigWiz
2014-11-16 16:00:38 17536 ----a-w- C:\ProgramData\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2014-11-15 22:56:16 127800 ----a-w- C:\Windows\System32\HPSIsvc.exe
2014-11-14 04:06:58 874712 ----a-w- C:\Windows\System32\drivers\Rt630x64.sys
2014-11-14 04:06:58 73800 ----a-w- C:\Windows\System32\RtNicProp64.dll
2014-11-14 04:06:34 100312 ----a-w- C:\Windows\System32\drivers\TeeDriverx64.sys
2014-11-14 04:04:34 -------- d-----w- C:\Program Files\Synaptics
2014-11-14 04:04:13 33008 ----a-w- C:\Windows\System32\drivers\Smb_driver_Intel.sys
2014-11-14 02:12:49 91648 ----a-w- C:\Windows\System32\drivers\ew_jubusenum.sys
2014-11-14 01:53:29 -------- d-----w- C:\Users\AAA\AppData\Roaming\ProductData
2014-11-14 01:51:52 -------- d-----w- C:\Program Files (x86)\IObit
2014-11-14 01:51:45 -------- d-----w- C:\ProgramData\ProductData
2014-11-14 01:51:22 -------- d-----w- C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
2014-11-14 01:51:10 -------- d-----w- C:\Program Files (x86)\Common Files\IObit
2014-11-14 01:50:34 -------- d-----w- C:\Users\AAA\AppData\Roaming\IObit
2014-11-12 04:47:37 28616704 ----a-w- C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2014-11-12 04:47:36 27853824 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2014-11-12 04:38:21 1845760 ----a-w- C:\Windows\System32\msxml3.dll
2014-11-12 04:38:20 1418752 ----a-w- C:\Windows\SysWow64\msxml3.dll
2014-11-12 04:25:03 783872 ----a-w- C:\Windows\System32\audiosrv.dll
2014-11-12 04:25:03 522728 ----a-w- C:\Windows\System32\AUDIOKSE.dll
2014-11-12 04:25:03 267264 ----a-w- C:\Windows\System32\EncDump.dll
2014-11-12 04:25:03 169472 ----a-w- C:\Windows\System32\AudioEndpointBuilder.dll
2014-11-12 04:24:20 778240 ----a-w- C:\Windows\System32\oleaut32.dll
2014-11-12 04:24:20 567808 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2014-11-12 04:23:33 4068864 ----a-w- C:\Windows\System32\win32k.sys
2014-11-12 04:22:57 8858624 ----a-w- C:\Windows\SysWow64\twinui.dll
2014-11-12 04:22:56 10115072 ----a-w- C:\Windows\System32\twinui.dll
2014-11-12 04:22:55 2885632 ----a-w- C:\Windows\System32\msi.dll
2014-11-12 04:22:55 2416640 ----a-w- C:\Windows\SysWow64\msi.dll
2014-11-12 04:22:54 393216 ----a-w- C:\Windows\System32\msihnd.dll
2014-11-12 04:22:54 2307072 ----a-w- C:\Windows\System32\authui.dll
2014-11-12 04:22:54 2037760 ----a-w- C:\Windows\SysWow64\authui.dll
2014-11-12 04:22:53 295424 ----a-w- C:\Windows\SysWow64\msihnd.dll
2014-11-12 04:04:17 79872 ----a-w- C:\Windows\System32\packager.dll
2014-11-12 04:04:17 68096 ----a-w- C:\Windows\SysWow64\packager.dll
2014-11-11 15:48:09 43152 ----a-w- C:\Windows\avastSS.scr
2014-11-08 12:48:54 -------- d--h--w- C:\CanoScan
2014-11-07 23:52:29 -------- d-----w- C:\Users\AAA\AppData\Local\WEB2Print
2014-11-07 07:21:40 180136 ----a-w- C:\Windows\System32\drivers\idmwfp.sys
2014-11-07 02:00:37 -------- d-----w- C:\Users\AAA\.Virtualbox
2014-11-07 01:54:36 -------- d-----w- C:\Users\AAA\youwave
2014-11-05 20:03:00 -------- d-----w- C:\Users\AAA\AppData\Roaming\DVDVideoSoft
2014-11-04 23:22:26 -------- d-----w- C:\Program Files\Babylon
2014-11-04 19:18:16 98816 ----a-w- C:\Windows\System32\drivers\ew_jucdcacm.sys
2014-11-04 19:18:16 69632 ----a-w- C:\Windows\System32\drivers\ew_jucdcecm.sys
2014-11-04 19:18:16 415744 ----a-w- C:\Windows\System32\drivers\ewusbwwan.sys
2014-11-04 19:18:16 32768 ----a-w- C:\Windows\System32\drivers\ewdcsc.sys
2014-11-04 19:18:16 28672 ----a-w- C:\Windows\System32\drivers\ew_juextctrl.sys
2014-11-04 19:18:16 222464 ----a-w- C:\Windows\System32\drivers\ewusbmdm.sys
2014-11-04 19:18:16 22016 ----a-w- C:\Windows\System32\drivers\ew_hwupgrade.sys
2014-11-04 19:18:16 212992 ----a-w- C:\Windows\System32\drivers\ew_juwwanecm.sys
2014-11-04 19:18:16 13952 ----a-w- C:\Windows\System32\drivers\ew_usbenumfilter.sys
2014-11-04 19:18:16 117248 ----a-w- C:\Windows\System32\drivers\ew_hwusbdev.sys
2014-11-04 19:18:16 1001472 ----a-w- C:\Windows\System32\drivers\mod7700.sys
2014-11-02 20:47:35 -------- d-----w- C:\Users\AAA\AppData\Roaming\JAM Software
2014-11-02 19:49:49 3050808 ----a-w- C:\Windows\System32\pwNative.exe
2014-11-02 19:49:49 19152 ------w- C:\Windows\System32\pwdrvio.sys
2014-11-02 19:49:49 12504 ------w- C:\Windows\System32\pwdspio.sys
.
==================== Find3M ====================
.
2014-11-28 21:35:47 16152 ----a-w- C:\Windows\System32\drivers\SWDUMon.sys
2014-11-16 00:46:51 987136 ----a-w- C:\Windows\SysWow64\srmclient.dll
2014-11-16 00:46:51 673792 ----a-w- C:\Windows\System32\mfmpeg2srcsnk.dll
2014-11-16 00:46:51 652800 ----a-w- C:\Windows\System32\srmscan.dll
2014-11-16 00:46:51 513536 ----a-w- C:\Windows\SysWow64\mfmpeg2srcsnk.dll
2014-11-16 00:46:51 487936 ----a-w- C:\Windows\SysWow64\srmscan.dll
2014-11-16 00:46:51 279040 ----a-w- C:\Windows\System32\srm.dll
2014-11-16 00:46:51 278528 ----a-w- C:\Windows\SysWow64\srm.dll
2014-11-16 00:46:51 212992 ----a-w- C:\Windows\System32\dnsrslvr.dll
2014-11-16 00:46:51 1346560 ----a-w- C:\Windows\System32\srmclient.dll
2014-11-16 00:46:51 134144 ----a-w- C:\Windows\System32\adrclient.dll
2014-11-16 00:46:51 104448 ----a-w- C:\Windows\SysWow64\adrclient.dll
2014-11-14 02:07:49 98216 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-11-11 15:48:15 116728 ----a-w- C:\Windows\System32\drivers\aswStm.sys
2014-11-11 15:48:14 93568 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2014-11-11 15:48:14 83280 ----a-w- C:\Windows\System32\drivers\aswmonflt.sys
2014-11-11 15:48:14 65776 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2014-11-11 15:48:14 29208 ----a-w- C:\Windows\System32\drivers\aswHwid.sys
2014-11-11 15:48:14 267632 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2014-10-26 01:56:17 2237952 ----a-w- C:\Windows\System32\wininet.dll
2014-10-26 01:56:06 915968 ----a-w- C:\Windows\System32\uxtheme.dll
2014-10-26 01:56:06 53760 ----a-w- C:\Windows\System32\UXInit.dll
2014-10-26 01:54:43 3959296 ----a-w- C:\Windows\System32\jscript9.dll
2014-10-26 01:54:36 67072 ----a-w- C:\Windows\System32\iesetup.dll
2014-10-26 01:54:36 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2014-10-26 01:53:54 1509376 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-10-26 00:36:01 1762816 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-10-26 00:35:53 44032 ----a-w- C:\Windows\SysWow64\UXInit.dll
2014-10-26 00:34:48 2861568 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-10-26 00:34:43 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-10-26 00:34:43 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2014-10-26 00:34:16 1441280 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-10-26 00:19:11 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2014-10-26 00:13:06 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-10-25 21:48:29 534528 ----a-w- C:\Windows\SysWow64\uxtheme.dll
2014-10-18 13:09:48 334992 ----a-w- C:\Windows\System32\RaCoInstx.dll
2014-10-18 13:09:48 2217616 ----a-w- C:\Windows\System32\drivers\netr28ux.sys
2014-10-15 09:52:25 20160 ----a-w- C:\Windows\System32\drivers\GUBootStartup.sys
2014-10-11 08:35:58 171840 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2014-10-11 07:44:56 588288 ----a-w- C:\Windows\System32\SHCore.dll
2014-10-11 07:44:47 3248640 ----a-w- C:\Windows\System32\rdpcorets.dll
2014-10-11 07:43:51 1281536 ----a-w- C:\Windows\System32\lsasrv.dll
2014-10-11 05:57:57 452608 ----a-w- C:\Windows\SysWow64\SHCore.dll
2014-10-11 05:41:57 146944 ----a-w- C:\Windows\System32\msaudite.dll
2014-10-11 05:41:43 713728 ----a-w- C:\Windows\System32\adtschema.dll
2014-10-11 05:05:20 146944 ----a-w- C:\Windows\SysWow64\msaudite.dll
2014-10-11 05:04:59 713728 ----a-w- C:\Windows\SysWow64\adtschema.dll
2014-09-24 23:29:59 318976 ----a-w- C:\Windows\SysWow64\schannel.dll
2014-09-24 23:29:51 72192 ----a-w- C:\Windows\SysWow64\ncryptsslp.dll
2014-09-24 23:01:14 414208 ----a-w- C:\Windows\System32\schannel.dll
2014-09-24 23:01:00 86528 ----a-w- C:\Windows\System32\ncryptsslp.dll
2014-09-24 07:42:26 226424 ----a-w- C:\Windows\System32\SBuySupplies.exe
2014-09-22 05:53:10 35320 ----a-w- C:\Windows\System32\drivers\WdBoot.sys
2014-09-13 06:24:47 2233152 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2014-09-03 02:48:48 141824 ----a-w- C:\Windows\SysWow64\rpchttp.dll
2014-09-03 02:48:47 510464 ----a-w- C:\Windows\SysWow64\rastls.dll
2014-09-03 02:22:00 188928 ----a-w- C:\Windows\System32\rpchttp.dll
2014-09-03 02:21:59 585728 ----a-w- C:\Windows\System32\rastls.dll
.
============= FINISH: 1:30:38.79 ===============