Hi,
My Computer runs Win 7 Home Premium 64-bit. I had a virus infestation a few months ago and I formatted my entire HDD and reinstalled Win 7 :uhoh:
The computer ran well after that... During the past few weeks, I noticed that it was getting slower and slower. Firefox started to slow down more than usual... Ok, I know Ff is a bit of a heavy program, but 8GB RAM and still?
I installed a new MSI R7870 Hawk gfx card a couple of days ago and got the latest drivers installed from their website too... But since this install, it got even worse than ever before...
I ran the DDS.scr and GMER as requested. The DDS ran fine, but running the GMER was a bit of an issue. It gave me 3 BSODs with the message IQRL_NOT_LESS_OR_EQUAL and once my computer froze and I had to hard reset. I ran it with the lesser options selected as mentioned in the instructions and it didn't give me any logs, just told me that it did not find any changes to the system...
Please help... I'm going :banghead:
Thanks in advance for your help!!!
ThePrambler
Edit: My rig is as follows: Intel i5 2400 processor on an Intel DH67GD board, sticks of 4GB RAM each, 500GB HDD, MSI R7870 Hawk 2GB GDDR5 and running an NZXT Sentry 2 fan controller
LOG:
DDS.txt:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.9.2
Run by Praveen at 8:56:38 on 2013-01-15
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.91.1033.18.8169.6449 [GMT -6:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\IProsetMonitor.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\DIGISOL\DG-WN3150Nu Wireless LAN Utility\RtlService.exe
C:\Program Files (x86)\DIGISOL\DG-WN3150Nu Wireless LAN Utility\RtWlan.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\Dwm.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Windows\FixCamera.exe
C:\Windows\tsnp2std.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\taskeng.exe
C:\Users\Praveen\Desktop\gmer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.dell.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [Google Update] "C:\Users\Praveen\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [googletalk] C:\Users\Praveen\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
uRun: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
uRunOnce: [Uninstall C:\Users\Praveen\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] C:\Windows\System32\cmd.exe /q /c rmdir /s /q "C:\Users\Praveen\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [FixCamera] C:\Windows\FixCamera.exe
mRun: [tsnp2std] C:\Windows\tsnp2std.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
StartupFolder: C:\Users\Praveen\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\EVERNO~1.LNK - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: SoftwareSASGeneration = dword:1
IE: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
TCP: NameServer = 192.168.100.254 142.161.130.155
TCP: Interfaces\{1EC71034-0DDF-43A4-951E-4135114DF59D} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{5F61D0D6-104C-441B-AD82-F6F0FF947C15} : DHCPNameServer = 192.168.100.254 142.161.130.155
TCP: Interfaces\{5F61D0D6-104C-441B-AD82-F6F0FF947C15}\3797275707 : DHCPNameServer = 192.168.100.254 142.161.130.155
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
x64-Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [IntelliType Pro] "C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe"
x64-Run: [IntelliPoint] "C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe"
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Praveen\AppData\Roaming\Mozilla\Firefox\Profiles\v5tlx7kp.default\
FF - prefs.js: browser.startup.homepage - about:home|hxxp://harvsair.com/current-students/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - prefs.js: network.proxy.http - 58.68.56.25
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Praveen\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: C:\Users\Praveen\AppData\Roaming\Mozilla\Firefox\Profiles\v5tlx7kp.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\npGarmin.dll
FF - plugin: C:\Users\Praveen\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Praveen\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2012-11-16 17:56; r2d2b2g@mozilla.org; C:\Users\Praveen\AppData\Roaming\Mozilla\Firefox\Profiles\v5tlx7kp.default\extensions\r2d2b2g@mozilla.org
FF - ExtSQL: 2012-11-18 18:49; https-everywhere@eff.org; C:\Users\Praveen\AppData\Roaming\Mozilla\Firefox\Profiles\v5tlx7kp.default\extensions\https-everywhere@eff.org
FF - ExtSQL: 2012-11-18 23:22; {23fcfd51-4958-4f00-80a3-ae97e717ed8b}; C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF - ExtSQL: 2012-11-19 06:46; {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}; C:\Users\Praveen\AppData\Roaming\Mozilla\Firefox\Profiles\v5tlx7kp.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2012-8-30 228768]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2013-1-12 239616]
R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;C:\Windows\System32\IPROSetMonitor.exe [2012-10-31 133800]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2012-12-29 72216]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-31 398184]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-31 682344]
R2 Realtek11nCU;Realtek11nCU;C:\Program Files (x86)\DIGISOL\DG-WN3150Nu Wireless LAN Utility\RtlService.exe [2012-11-15 36864]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-10-31 2655768]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2013-1-12 96896]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-10-31 24176]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-4-26 83080]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-4-26 184968]
R3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\Windows\System32\drivers\rtl8192cu.sys [2012-11-15 848384]
R3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-10-19 160944]
S3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2012-10-31 317440]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2012-8-30 128456]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-9-12 368896]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-10-31 1255736]
.
=============== Created Last 30 ================
.
2013-01-15 14:17:37 9125352 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{17D97075-AE35-47C9-8DC4-04AE3DC44EE5}\mpengine.dll
2013-01-14 13:32:11 9125352 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-14 04:16:23 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-01-14 04:16:14 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-01-13 03:55:18 -------- d-----w- C:\Program Files (x86)\AMD AVT
2013-01-13 03:55:10 -------- d-----w- C:\Program Files (x86)\AMD APP
2013-01-12 23:32:06 -------- d-----w- C:\Program Files\Microsoft Mouse and Keyboard Center
2013-01-12 23:29:59 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2013-01-12 23:29:59 458712 ----a-w- C:\Windows\System32\drivers\cng.sys
2013-01-12 23:29:59 340992 ----a-w- C:\Windows\System32\schannel.dll
2013-01-12 23:29:59 247808 ----a-w- C:\Windows\SysWow64\schannel.dll
2013-01-12 23:29:59 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2013-01-12 23:29:59 154480 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2013-01-12 23:29:59 1448448 ----a-w- C:\Windows\System32\lsasrv.dll
2013-01-12 23:29:58 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2013-01-12 23:29:58 366592 ----a-w- C:\Windows\System32\qdvd.dll
2013-01-12 22:37:09 94208 ----a-w- C:\Windows\amcap.exe
2013-01-12 22:37:09 344064 ----a-w- C:\Windows\vsnp2std.exe
2013-01-12 22:37:09 274432 ----a-w- C:\Windows\tsnp2std.exe
2013-01-12 22:37:09 188928 ----a-w- C:\Windows\FixCamera.exe
2013-01-12 22:37:08 255488 ----a-w- C:\Windows\SysWow64\vsnp2std.dll
2013-01-12 22:37:08 25472 ----a-w- C:\Windows\SysWow64\drivers\sncamd.sys
2013-01-12 22:37:08 18944 ----a-w- C:\Windows\System32\csnp2std.dll
2013-01-12 22:37:08 151552 ----a-w- C:\Windows\SysWow64\rsnp2std.dll
2013-01-12 22:37:08 12260352 ----a-w- C:\Windows\SysWow64\drivers\snp2sxp.sys
2013-01-12 22:37:08 -------- d-----w- C:\Program Files (x86)\Common Files\snp2std
2013-01-12 22:33:07 -------- d-----w- C:\Users\Praveen\AppData\Local\ElevatedDiagnostics
2013-01-11 23:25:39 -------- d-----w- C:\Program Files (x86)\MSI Kombustor 2.4
2013-01-11 23:19:52 11832 ----a-w- C:\Windows\acpimof.dll
2013-01-11 23:08:12 -------- d-----w- C:\Users\Praveen\AppData\Local\ATI
2013-01-11 23:06:59 -------- d-----w- C:\Program Files (x86)\MSI Afterburner
2013-01-11 23:05:14 0 ----a-w- C:\Windows\ativpsrm.bin
2013-01-11 23:03:33 -------- d-----w- C:\ProgramData\AMD
2013-01-11 23:03:22 -------- d-----w- C:\Program Files\Common Files\ATI Technologies
2013-01-11 23:03:22 -------- d-----w- C:\Program Files (x86)\Common Files\ATI Technologies
2013-01-11 23:02:14 442368 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2013-01-11 23:01:58 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2013-01-11 23:01:46 -------- d-----w- C:\Program Files\ATI
2013-01-11 23:00:57 -------- d-----w- C:\Program Files\ATI Technologies
2013-01-11 13:13:24 -------- d-----w- C:\Program Files\CCleaner
2013-01-11 12:54:05 -------- d-----w- C:\ProgramData\Western Digital
2013-01-11 12:53:23 -------- d-----w- C:\Users\Praveen\AppData\Local\Western Digital
2013-01-09 16:10:23 -------- d-----w- C:\Program Files (x86)\NCH Software
2013-01-09 14:18:33 -------- d-----w- C:\PhSp_CS2_UE_Ret
2013-01-09 11:45:59 6144 ---ha-w- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2013-01-06 14:46:34 -------- d-----w- C:\Program Files (x86)\Yahoo!
2013-01-05 01:10:58 -------- d-----w- C:\Users\Praveen\AppData\Local\Downloaded Installations
2013-01-02 19:45:24 -------- d-----w- C:\Program Files (x86)\Veoh Networks
2012-12-29 14:40:27 88600 ----a-w- C:\Windows\System32\LMIRfsClientNP.dll
2012-12-29 14:40:27 72216 ----a-w- C:\Windows\System32\drivers\LMIRfsDriver.sys
2012-12-29 14:40:27 60920 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\LMIproc.dll
2012-12-29 14:40:27 35832 ----a-w- C:\Windows\System32\LMIport.dll
2012-12-29 14:40:25 84472 ----a-w- C:\Windows\System32\LMIinit.dll
2012-12-29 14:40:13 -------- d-----w- C:\Program Files (x86)\LogMeIn
2012-12-29 14:26:54 -------- d-----w- C:\ProgramData\Ask
2012-12-29 14:18:20 -------- d-----w- C:\Users\Praveen\AppData\Roaming\TightVNC
2012-12-21 13:47:58 46080 ----a-w- C:\Windows\System32\atmlib.dll
2012-12-21 13:47:58 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2012-12-21 13:47:57 367616 ----a-w- C:\Windows\System32\atmfd.dll
2012-12-21 13:47:56 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2012-12-19 12:56:17 -------- d-----w- C:\Users\Praveen\AppData\Roaming\6Wunderkinder
2012-12-19 09:01:00 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-12-19 09:01:00 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-12-19 00:54:19 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-12-19 00:54:19 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-12-19 00:49:09 478208 ----a-w- C:\Windows\System32\dpnet.dll
2012-12-19 00:49:09 376832 ----a-w- C:\Windows\SysWow64\dpnet.dll
2012-12-18 19:08:32 209112 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2012-12-17 02:44:16 -------- d-----w- C:\Users\Praveen\AppData\Local\Microsoft Games
.
==================== Find3M ====================
.
2013-01-09 00:07:30 74248 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-09 00:07:30 697864 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-12-14 22:49:28 24176 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-12-07 13:20:16 441856 ----a-w- C:\Windows\System32\Wpc.dll
2012-12-07 13:15:31 2746368 ----a-w- C:\Windows\System32\gameux.dll
2012-12-07 12:26:17 308736 ----a-w- C:\Windows\SysWow64\Wpc.dll
2012-12-07 12:20:43 2576384 ----a-w- C:\Windows\SysWow64\gameux.dll
2012-12-07 11:20:04 30720 ----a-w- C:\Windows\System32\usk.rs
2012-12-07 11:20:03 43520 ----a-w- C:\Windows\System32\csrr.rs
2012-12-07 11:20:03 23552 ----a-w- C:\Windows\System32\oflc.rs
2012-12-07 11:20:01 45568 ----a-w- C:\Windows\System32\oflc-nz.rs
2012-12-07 11:20:01 44544 ----a-w- C:\Windows\System32\pegibbfc.rs
2012-12-07 11:20:01 20480 ----a-w- C:\Windows\System32\pegi-fi.rs
2012-12-07 11:20:00 20480 ----a-w- C:\Windows\System32\pegi-pt.rs
2012-12-07 11:19:59 20480 ----a-w- C:\Windows\System32\pegi.rs
2012-12-07 11:19:58 46592 ----a-w- C:\Windows\System32\fpb.rs
2012-12-07 11:19:57 40960 ----a-w- C:\Windows\System32\cob-au.rs
2012-12-07 11:19:57 21504 ----a-w- C:\Windows\System32\grb.rs
2012-12-07 11:19:57 15360 ----a-w- C:\Windows\System32\djctq.rs
2012-12-07 11:19:56 55296 ----a-w- C:\Windows\System32\cero.rs
2012-12-07 11:19:55 51712 ----a-w- C:\Windows\System32\esrb.rs
2012-12-03 13:58:17 34816 ----a-w- C:\Windows\SysWow64\~bwcrc32.dll
2012-11-30 05:45:35 362496 ----a-w- C:\Windows\System32\wow64win.dll
2012-11-30 05:45:35 243200 ----a-w- C:\Windows\System32\wow64.dll
2012-11-30 05:45:35 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2012-11-30 05:45:14 215040 ----a-w- C:\Windows\System32\winsrv.dll
2012-11-30 05:43:12 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2012-11-30 05:41:07 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2012-11-30 04:54:00 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2012-11-30 04:53:59 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2012-11-30 03:23:48 338432 ----a-w- C:\Windows\System32\conhost.exe
2012-11-30 02:44:06 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2012-11-30 02:44:04 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2012-11-30 02:44:04 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-11-30 02:44:03 2048 ----a-w- C:\Windows\SysWow64\user.exe
2012-11-30 02:38:59 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:38:59 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:38:59 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:38:59 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-11-29 17:56:30 35616 ----a-w- C:\Windows\System32\lmimirr.dll
2012-11-29 17:56:30 14624 ----a-w- C:\Windows\System32\lmimirr2.dll
2012-11-29 17:56:30 11552 ----a-w- C:\Windows\System32\drivers\lmimirr.sys
2012-11-23 03:26:31 3149824 ----a-w- C:\Windows\System32\win32k.sys
2012-11-23 03:13:57 68608 ----a-w- C:\Windows\System32\taskhost.exe
2012-11-22 05:44:23 800768 ----a-w- C:\Windows\System32\usp10.dll
2012-11-22 04:45:03 626688 ----a-w- C:\Windows\SysWow64\usp10.dll
2012-11-20 05:48:49 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-11-20 04:51:09 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-11-16 23:54:35 95208 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-16 23:54:32 821736 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-11-16 23:54:32 746984 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-11-16 18:00:00 127488 ----a-w- C:\Windows\System32\ff_vfw.dll
2012-11-14 06:11:44 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2012-11-14 06:04:11 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-11-14 06:02:49 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-11-14 05:57:46 599040 ----a-w- C:\Windows\System32\vbscript.dll
2012-11-14 05:57:35 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-11-14 02:09:22 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-11-14 01:58:15 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-11-14 01:57:37 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-11-14 01:49:25 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-11-14 01:48:27 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2012-11-13 20:29:04 354216 ----a-w- C:\Windows\SysWow64\DivXControlPanelApplet.cpl
2012-11-09 05:45:32 750592 ----a-w- C:\Windows\System32\win32spl.dll
2012-11-09 04:43:04 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll
2012-11-01 05:43:42 2002432 ----a-w- C:\Windows\System32\msxml6.dll
2012-11-01 05:43:42 1882624 ----a-w- C:\Windows\System32\msxml3.dll
2012-11-01 04:47:54 1389568 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-11-01 04:47:54 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-10-31 14:51:27 108008 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2012-10-31 14:51:25 916456 ----a-w- C:\Windows\System32\deployJava1.dll
2012-10-31 14:51:25 1034216 ----a-w- C:\Windows\System32\npDeployJava1.dll
.
============= FINISH: 9:00:39.08 ===============
My Computer runs Win 7 Home Premium 64-bit. I had a virus infestation a few months ago and I formatted my entire HDD and reinstalled Win 7 :uhoh:
The computer ran well after that... During the past few weeks, I noticed that it was getting slower and slower. Firefox started to slow down more than usual... Ok, I know Ff is a bit of a heavy program, but 8GB RAM and still?
I installed a new MSI R7870 Hawk gfx card a couple of days ago and got the latest drivers installed from their website too... But since this install, it got even worse than ever before...
I ran the DDS.scr and GMER as requested. The DDS ran fine, but running the GMER was a bit of an issue. It gave me 3 BSODs with the message IQRL_NOT_LESS_OR_EQUAL and once my computer froze and I had to hard reset. I ran it with the lesser options selected as mentioned in the instructions and it didn't give me any logs, just told me that it did not find any changes to the system...
Please help... I'm going :banghead:
Thanks in advance for your help!!!
ThePrambler
Edit: My rig is as follows: Intel i5 2400 processor on an Intel DH67GD board, sticks of 4GB RAM each, 500GB HDD, MSI R7870 Hawk 2GB GDDR5 and running an NZXT Sentry 2 fan controller
LOG:
DDS.txt:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.9.2
Run by Praveen at 8:56:38 on 2013-01-15
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.91.1033.18.8169.6449 [GMT -6:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\IProsetMonitor.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\DIGISOL\DG-WN3150Nu Wireless LAN Utility\RtlService.exe
C:\Program Files (x86)\DIGISOL\DG-WN3150Nu Wireless LAN Utility\RtWlan.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\Dwm.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Windows\FixCamera.exe
C:\Windows\tsnp2std.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\taskeng.exe
C:\Users\Praveen\Desktop\gmer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.dell.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [Google Update] "C:\Users\Praveen\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [googletalk] C:\Users\Praveen\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
uRun: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
uRunOnce: [Uninstall C:\Users\Praveen\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] C:\Windows\System32\cmd.exe /q /c rmdir /s /q "C:\Users\Praveen\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [FixCamera] C:\Windows\FixCamera.exe
mRun: [tsnp2std] C:\Windows\tsnp2std.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
StartupFolder: C:\Users\Praveen\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\EVERNO~1.LNK - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: SoftwareSASGeneration = dword:1
IE: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
TCP: NameServer = 192.168.100.254 142.161.130.155
TCP: Interfaces\{1EC71034-0DDF-43A4-951E-4135114DF59D} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{5F61D0D6-104C-441B-AD82-F6F0FF947C15} : DHCPNameServer = 192.168.100.254 142.161.130.155
TCP: Interfaces\{5F61D0D6-104C-441B-AD82-F6F0FF947C15}\3797275707 : DHCPNameServer = 192.168.100.254 142.161.130.155
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
x64-Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [IntelliType Pro] "C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe"
x64-Run: [IntelliPoint] "C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe"
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Praveen\AppData\Roaming\Mozilla\Firefox\Profiles\v5tlx7kp.default\
FF - prefs.js: browser.startup.homepage - about:home|hxxp://harvsair.com/current-students/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - prefs.js: network.proxy.http - 58.68.56.25
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Praveen\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: C:\Users\Praveen\AppData\Roaming\Mozilla\Firefox\Profiles\v5tlx7kp.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\npGarmin.dll
FF - plugin: C:\Users\Praveen\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Praveen\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2012-11-16 17:56; r2d2b2g@mozilla.org; C:\Users\Praveen\AppData\Roaming\Mozilla\Firefox\Profiles\v5tlx7kp.default\extensions\r2d2b2g@mozilla.org
FF - ExtSQL: 2012-11-18 18:49; https-everywhere@eff.org; C:\Users\Praveen\AppData\Roaming\Mozilla\Firefox\Profiles\v5tlx7kp.default\extensions\https-everywhere@eff.org
FF - ExtSQL: 2012-11-18 23:22; {23fcfd51-4958-4f00-80a3-ae97e717ed8b}; C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF - ExtSQL: 2012-11-19 06:46; {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}; C:\Users\Praveen\AppData\Roaming\Mozilla\Firefox\Profiles\v5tlx7kp.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2012-8-30 228768]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2013-1-12 239616]
R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;C:\Windows\System32\IPROSetMonitor.exe [2012-10-31 133800]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2012-12-29 72216]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-31 398184]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-31 682344]
R2 Realtek11nCU;Realtek11nCU;C:\Program Files (x86)\DIGISOL\DG-WN3150Nu Wireless LAN Utility\RtlService.exe [2012-11-15 36864]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-10-31 2655768]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2013-1-12 96896]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-10-31 24176]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-4-26 83080]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-4-26 184968]
R3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\Windows\System32\drivers\rtl8192cu.sys [2012-11-15 848384]
R3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-10-19 160944]
S3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2012-10-31 317440]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2012-8-30 128456]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-9-12 368896]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-10-31 1255736]
.
=============== Created Last 30 ================
.
2013-01-15 14:17:37 9125352 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{17D97075-AE35-47C9-8DC4-04AE3DC44EE5}\mpengine.dll
2013-01-14 13:32:11 9125352 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-14 04:16:23 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-01-14 04:16:14 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-01-13 03:55:18 -------- d-----w- C:\Program Files (x86)\AMD AVT
2013-01-13 03:55:10 -------- d-----w- C:\Program Files (x86)\AMD APP
2013-01-12 23:32:06 -------- d-----w- C:\Program Files\Microsoft Mouse and Keyboard Center
2013-01-12 23:29:59 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2013-01-12 23:29:59 458712 ----a-w- C:\Windows\System32\drivers\cng.sys
2013-01-12 23:29:59 340992 ----a-w- C:\Windows\System32\schannel.dll
2013-01-12 23:29:59 247808 ----a-w- C:\Windows\SysWow64\schannel.dll
2013-01-12 23:29:59 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2013-01-12 23:29:59 154480 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2013-01-12 23:29:59 1448448 ----a-w- C:\Windows\System32\lsasrv.dll
2013-01-12 23:29:58 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2013-01-12 23:29:58 366592 ----a-w- C:\Windows\System32\qdvd.dll
2013-01-12 22:37:09 94208 ----a-w- C:\Windows\amcap.exe
2013-01-12 22:37:09 344064 ----a-w- C:\Windows\vsnp2std.exe
2013-01-12 22:37:09 274432 ----a-w- C:\Windows\tsnp2std.exe
2013-01-12 22:37:09 188928 ----a-w- C:\Windows\FixCamera.exe
2013-01-12 22:37:08 255488 ----a-w- C:\Windows\SysWow64\vsnp2std.dll
2013-01-12 22:37:08 25472 ----a-w- C:\Windows\SysWow64\drivers\sncamd.sys
2013-01-12 22:37:08 18944 ----a-w- C:\Windows\System32\csnp2std.dll
2013-01-12 22:37:08 151552 ----a-w- C:\Windows\SysWow64\rsnp2std.dll
2013-01-12 22:37:08 12260352 ----a-w- C:\Windows\SysWow64\drivers\snp2sxp.sys
2013-01-12 22:37:08 -------- d-----w- C:\Program Files (x86)\Common Files\snp2std
2013-01-12 22:33:07 -------- d-----w- C:\Users\Praveen\AppData\Local\ElevatedDiagnostics
2013-01-11 23:25:39 -------- d-----w- C:\Program Files (x86)\MSI Kombustor 2.4
2013-01-11 23:19:52 11832 ----a-w- C:\Windows\acpimof.dll
2013-01-11 23:08:12 -------- d-----w- C:\Users\Praveen\AppData\Local\ATI
2013-01-11 23:06:59 -------- d-----w- C:\Program Files (x86)\MSI Afterburner
2013-01-11 23:05:14 0 ----a-w- C:\Windows\ativpsrm.bin
2013-01-11 23:03:33 -------- d-----w- C:\ProgramData\AMD
2013-01-11 23:03:22 -------- d-----w- C:\Program Files\Common Files\ATI Technologies
2013-01-11 23:03:22 -------- d-----w- C:\Program Files (x86)\Common Files\ATI Technologies
2013-01-11 23:02:14 442368 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2013-01-11 23:01:58 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2013-01-11 23:01:46 -------- d-----w- C:\Program Files\ATI
2013-01-11 23:00:57 -------- d-----w- C:\Program Files\ATI Technologies
2013-01-11 13:13:24 -------- d-----w- C:\Program Files\CCleaner
2013-01-11 12:54:05 -------- d-----w- C:\ProgramData\Western Digital
2013-01-11 12:53:23 -------- d-----w- C:\Users\Praveen\AppData\Local\Western Digital
2013-01-09 16:10:23 -------- d-----w- C:\Program Files (x86)\NCH Software
2013-01-09 14:18:33 -------- d-----w- C:\PhSp_CS2_UE_Ret
2013-01-09 11:45:59 6144 ---ha-w- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2013-01-06 14:46:34 -------- d-----w- C:\Program Files (x86)\Yahoo!
2013-01-05 01:10:58 -------- d-----w- C:\Users\Praveen\AppData\Local\Downloaded Installations
2013-01-02 19:45:24 -------- d-----w- C:\Program Files (x86)\Veoh Networks
2012-12-29 14:40:27 88600 ----a-w- C:\Windows\System32\LMIRfsClientNP.dll
2012-12-29 14:40:27 72216 ----a-w- C:\Windows\System32\drivers\LMIRfsDriver.sys
2012-12-29 14:40:27 60920 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\LMIproc.dll
2012-12-29 14:40:27 35832 ----a-w- C:\Windows\System32\LMIport.dll
2012-12-29 14:40:25 84472 ----a-w- C:\Windows\System32\LMIinit.dll
2012-12-29 14:40:13 -------- d-----w- C:\Program Files (x86)\LogMeIn
2012-12-29 14:26:54 -------- d-----w- C:\ProgramData\Ask
2012-12-29 14:18:20 -------- d-----w- C:\Users\Praveen\AppData\Roaming\TightVNC
2012-12-21 13:47:58 46080 ----a-w- C:\Windows\System32\atmlib.dll
2012-12-21 13:47:58 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2012-12-21 13:47:57 367616 ----a-w- C:\Windows\System32\atmfd.dll
2012-12-21 13:47:56 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2012-12-19 12:56:17 -------- d-----w- C:\Users\Praveen\AppData\Roaming\6Wunderkinder
2012-12-19 09:01:00 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-12-19 09:01:00 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-12-19 00:54:19 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-12-19 00:54:19 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-12-19 00:49:09 478208 ----a-w- C:\Windows\System32\dpnet.dll
2012-12-19 00:49:09 376832 ----a-w- C:\Windows\SysWow64\dpnet.dll
2012-12-18 19:08:32 209112 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2012-12-17 02:44:16 -------- d-----w- C:\Users\Praveen\AppData\Local\Microsoft Games
.
==================== Find3M ====================
.
2013-01-09 00:07:30 74248 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-09 00:07:30 697864 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-12-14 22:49:28 24176 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-12-07 13:20:16 441856 ----a-w- C:\Windows\System32\Wpc.dll
2012-12-07 13:15:31 2746368 ----a-w- C:\Windows\System32\gameux.dll
2012-12-07 12:26:17 308736 ----a-w- C:\Windows\SysWow64\Wpc.dll
2012-12-07 12:20:43 2576384 ----a-w- C:\Windows\SysWow64\gameux.dll
2012-12-07 11:20:04 30720 ----a-w- C:\Windows\System32\usk.rs
2012-12-07 11:20:03 43520 ----a-w- C:\Windows\System32\csrr.rs
2012-12-07 11:20:03 23552 ----a-w- C:\Windows\System32\oflc.rs
2012-12-07 11:20:01 45568 ----a-w- C:\Windows\System32\oflc-nz.rs
2012-12-07 11:20:01 44544 ----a-w- C:\Windows\System32\pegibbfc.rs
2012-12-07 11:20:01 20480 ----a-w- C:\Windows\System32\pegi-fi.rs
2012-12-07 11:20:00 20480 ----a-w- C:\Windows\System32\pegi-pt.rs
2012-12-07 11:19:59 20480 ----a-w- C:\Windows\System32\pegi.rs
2012-12-07 11:19:58 46592 ----a-w- C:\Windows\System32\fpb.rs
2012-12-07 11:19:57 40960 ----a-w- C:\Windows\System32\cob-au.rs
2012-12-07 11:19:57 21504 ----a-w- C:\Windows\System32\grb.rs
2012-12-07 11:19:57 15360 ----a-w- C:\Windows\System32\djctq.rs
2012-12-07 11:19:56 55296 ----a-w- C:\Windows\System32\cero.rs
2012-12-07 11:19:55 51712 ----a-w- C:\Windows\System32\esrb.rs
2012-12-03 13:58:17 34816 ----a-w- C:\Windows\SysWow64\~bwcrc32.dll
2012-11-30 05:45:35 362496 ----a-w- C:\Windows\System32\wow64win.dll
2012-11-30 05:45:35 243200 ----a-w- C:\Windows\System32\wow64.dll
2012-11-30 05:45:35 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2012-11-30 05:45:14 215040 ----a-w- C:\Windows\System32\winsrv.dll
2012-11-30 05:43:12 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2012-11-30 05:41:07 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2012-11-30 04:54:00 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2012-11-30 04:53:59 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2012-11-30 03:23:48 338432 ----a-w- C:\Windows\System32\conhost.exe
2012-11-30 02:44:06 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2012-11-30 02:44:04 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2012-11-30 02:44:04 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-11-30 02:44:03 2048 ----a-w- C:\Windows\SysWow64\user.exe
2012-11-30 02:38:59 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:38:59 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:38:59 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:38:59 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-11-29 17:56:30 35616 ----a-w- C:\Windows\System32\lmimirr.dll
2012-11-29 17:56:30 14624 ----a-w- C:\Windows\System32\lmimirr2.dll
2012-11-29 17:56:30 11552 ----a-w- C:\Windows\System32\drivers\lmimirr.sys
2012-11-23 03:26:31 3149824 ----a-w- C:\Windows\System32\win32k.sys
2012-11-23 03:13:57 68608 ----a-w- C:\Windows\System32\taskhost.exe
2012-11-22 05:44:23 800768 ----a-w- C:\Windows\System32\usp10.dll
2012-11-22 04:45:03 626688 ----a-w- C:\Windows\SysWow64\usp10.dll
2012-11-20 05:48:49 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-11-20 04:51:09 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-11-16 23:54:35 95208 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-16 23:54:32 821736 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-11-16 23:54:32 746984 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-11-16 18:00:00 127488 ----a-w- C:\Windows\System32\ff_vfw.dll
2012-11-14 06:11:44 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2012-11-14 06:04:11 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-11-14 06:02:49 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-11-14 05:57:46 599040 ----a-w- C:\Windows\System32\vbscript.dll
2012-11-14 05:57:35 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-11-14 02:09:22 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-11-14 01:58:15 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-11-14 01:57:37 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-11-14 01:49:25 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-11-14 01:48:27 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2012-11-13 20:29:04 354216 ----a-w- C:\Windows\SysWow64\DivXControlPanelApplet.cpl
2012-11-09 05:45:32 750592 ----a-w- C:\Windows\System32\win32spl.dll
2012-11-09 04:43:04 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll
2012-11-01 05:43:42 2002432 ----a-w- C:\Windows\System32\msxml6.dll
2012-11-01 05:43:42 1882624 ----a-w- C:\Windows\System32\msxml3.dll
2012-11-01 04:47:54 1389568 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-11-01 04:47:54 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-10-31 14:51:27 108008 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2012-10-31 14:51:25 916456 ----a-w- C:\Windows\System32\deployJava1.dll
2012-10-31 14:51:25 1034216 ----a-w- C:\Windows\System32\npDeployJava1.dll
.
============= FINISH: 9:00:39.08 ===============