DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 11.0.9600.17280 BrowserJavaVersion: 10.5.1 Run by [removed] at 10:20:27 on 2014-09-17 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6058.3382 [GMT -4:00] . AV: Norton 360 *Enabled/Updated* {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB} SP: Norton 360 *Enabled/Updated* {631E4324-D31C-783F-EC5C-35AD42B18466} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Norton 360 *Enabled* {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0} . ============== Running Processes =============== . C:\windows\system32\lsm.exe C:\windows\system32\svchost.exe -k DcomLaunch C:\windows\system32\nvvsvc.exe C:\windows\system32\svchost.exe -k RPCSS C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\windows\system32\svchost.exe -k LocalService C:\windows\system32\svchost.exe -k netsvcs C:\windows\system32\svchost.exe -k NetworkService C:\windows\system32\WLANExt.exe C:\windows\System32\spoolsv.exe C:\windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe C:\windows\system32\svchost.exe -k bthsvcs C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe c:\Program Files\Microsoft SQL Server\MSSQL11.SHIPWORKS\MSSQL\Binn\sqlservr.exe C:\Program Files (x86)\Norton 360\Engine\21.5.0.19\N360.exe C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\windows\system32\wbem\unsecapp.exe C:\windows\system32\wbem\wmiprvse.exe C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\windows\system32\SearchIndexer.exe C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe C:\windows\system32\taskhost.exe C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe C:\windows\system32\Dwm.exe C:\windows\Explorer.EXE C:\windows\system32\taskeng.exe C:\Program Files (x86)\Norton 360\Engine\21.5.0.19\N360.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Windows\System32\rundll32.exe C:\Program Files\Elantech\ETDCtrl.exe C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe C:\windows\system32\taskeng.exe C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe C:\Program Files\Elantech\ETDCtrlHelper.exe C:\windows\system32\igfxext.exe C:\windows\system32\igfxsrvc.exe C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe C:\windows\system32\hkcmd.exe C:\windows\system32\igfxtray.exe C:\Program Files (x86)\Samsung\Easy Support Center\SSCKbdHk.exe C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe C:\windows\system32\igfxpers.exe C:\windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\Stamps.com Internet Postage\ipostage.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\windows\system32\rundll32.exe C:\windows\system32\taskeng.exe C:\Program Files (x86)\Google\Update\GoogleUpdate.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\windows\system32\CompatTel\WicaInventory.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\windows\system32\taskhost.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\windows\system32\SearchProtocolHost.exe C:\windows\system32\SearchFilterHost.exe C:\windows\system32\wbem\wmiprvse.exe C:\windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://Lasaoren.com/?f=1&a=lrn_dnldstr_14_38_ff&cd=2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtAzytD0EyByDtDyC0ByDtN0D0Tzu0SzyzzzytN1L2XzutAtFtBtFyEtFtBtN1L1CzutCyEtBzytDyD1V1PtN1L1G1B1V1N2Y1L1Qzu2StA0FyCtB0D0F0CyBtG0EyDtCzytGyE0E0BtCtGzzzztBtCtGtCyC0E0CtC0AyD0D0D0EyEtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0AzytC0DyE0DyDtG0BtB0C0EtGyEzz0AyCtG0AtC0AyCtG0EzytC0A0Fzz0ByBtByC0A0A2Q&cr=2142292687&ir= uDefault_Page_URL = hxxp://samsung.msn.com mWinlogon: Userinit = userinit.exe, BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\21.5.0.19\coieplg.dll BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\21.5.0.19\ips\ipsbho.dll BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.5.0.19\coieplg.dll uRun: [{0FD71A81-C5E5-4F64-8F2F-BD3737AD852D}] rundll32.exe "C:\Users\Owner\AppData\Local\{39D69420-12AB-4BF7-A903-FAC50996614A}\{0FD71A81-C5E5-4F64-8F2F-BD3737AD852D}\jabevlv.dll",vlc_entry__1_1_0gW uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe uRunOnce: [SpybotDeletingB8511] command.com /c del "C:\Program Files\DomaIQ Uninstaller\DomaIQUninstall.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [Monitor] "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe" mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . . INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . TCP: NameServer = 192.168.1.1 TCP: Interfaces\{BB3D9686-D9F1-4655-83D8-E1CE98C8A70D} : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{BB3D9686-D9F1-4655-83D8-E1CE98C8A70D}\16474777966696 : DHCPNameServer = 192.168.5.1 TCP: Interfaces\{BB3D9686-D9F1-4655-83D8-E1CE98C8A70D}\75540545572656A7 : DHCPNameServer = [removed] [removed] TCP: Interfaces\{BB3D9686-D9F1-4655-83D8-E1CE98C8A70D}\A456E6E696665627D27657563747 : DHCPNameServer = 75.75.75.75 75.75.76.76 192.168.33.1 TCP: Interfaces\{F58AC125-2B33-4A4B-9846-AB63748E74AC} : DHCPNameServer = 192.168.1.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll AppInit_DLLs= C:\windows\SysWOW64\nvinit.dll SSODL: WebCheck - mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome x64-BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine64\21.5.0.19\coieplg.dll x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.5.0.19\coieplg.dll x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp x64-Run: [ETDCtrl] C:\Program Files (x86)\Elantech\ETDCtrl.exe x64-Run: [Logitech Download Assistant] C:\windows\System32\rundll32.exe C:\windows\System32\LogiLDA.dll,LogiFetch x64-Run: [ShipWorksScheduler$5EEBE8EDAC7E4AC8B49956CD068C6AAB] C:\Program Files\ShipWorks\ShipWorks.exe /s=Scheduler x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll . INFO: x64-HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - x64-Notify: igfxcui - igfxdev.dll x64-SSODL: WebCheck - Hosts: 127.0.0.1 www.spywareinfo.com . ============= SERVICES / DRIVERS =============== . R0 nvpciflt;nvpciflt;C:\windows\System32\drivers\nvpciflt.sys [2011-11-30 25960] R0 SymDS;Symantec Data Store;C:\windows\System32\drivers\N360x64\1505000.013\symds64.sys [2014-8-15 493656] R0 SymEFA;Symantec Extended File Attributes;C:\windows\System32\drivers\N360x64\1505000.013\symefa64.sys [2014-8-15 1148120] R1 BHDrvx64;BHDrvx64;C:\Program Files (x86)\Norton 360\NortonData\21.3.0.12\Definitions\BASHDefs\20140912.003\BHDrvx64.sys [2014-9-12 1586904] R1 ccSet_N360;N360 Settings Manager;C:\windows\System32\drivers\N360x64\1505000.013\ccsetx64.sys [2014-8-15 162392] R1 IDSVia64;IDSVia64;C:\Program Files (x86)\Norton 360\NortonData\21.3.0.12\Definitions\IPSDefs\20140915.001\IDSviA64.sys [2014-9-16 633560] R1 SABI;SAMSUNG Kernel Driver For Windows 7;C:\windows\System32\drivers\SABI.sys [2011-11-30 13824] R1 SymIRON;Symantec Iron Driver;C:\windows\System32\drivers\N360x64\1505000.013\ironx64.sys [2014-8-15 264280] R1 SymNetS;Symantec Network Security WFP Driver;C:\windows\System32\drivers\N360x64\1505000.013\symnets.sys [2014-8-15 593112] R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-10-18 936272] R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2011-10-18 1001808] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088] R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-9-15 1809720] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-9-15 860472] R2 MSSQL$SHIPWORKS;SQL Server (SHIPWORKS);C:\Program Files\Microsoft SQL Server\MSSQL11.SHIPWORKS\MSSQL\Binn\sqlservr.exe [2012-2-11 191064] R2 N360;Norton 360;C:\Program Files (x86)\Norton 360\Engine\21.5.0.19\n360.exe [2014-8-15 265040] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2014-9-16 1153368] R2 SGDrv;SGDrv;C:\windows\System32\drivers\SGDrv64.sys [2011-11-30 7680] R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-11-30 2656536] R3 Bluetooth Media Service;Bluetooth Media Service;C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2011-10-18 1354064] R3 btmaux;Intel Bluetooth Auxiliary Service;C:\windows\System32\drivers\btmaux.sys [2011-8-29 53760] R3 btmhsf;btmhsf;C:\windows\System32\drivers\btmhsf.sys [2011-10-10 288768] R3 clwvd;CyberLink WebCam Virtual Driver;C:\windows\System32\drivers\clwvd.sys [2011-8-17 31216] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2014-9-9 142640] R3 ETD;ELAN PS/2 Port Input Device;C:\windows\System32\drivers\ETD.sys [2011-8-31 197416] R3 iBtFltCoex;iBtFltCoex;C:\windows\System32\drivers\iBtFltCoex.sys [2011-10-11 59904] R3 IntcDAud;Intel(R) Display Audio;C:\windows\System32\drivers\IntcDAud.sys [2011-7-21 317440] R3 iwdbus;IWD Bus Enumerator;C:\windows\System32\drivers\iwdbus.sys [2011-5-16 25496] R3 MBAMProtector;MBAMProtector;C:\windows\System32\drivers\mbam.sys [2014-9-15 25816] R3 MBAMSwissArmy;MBAMSwissArmy;C:\windows\System32\drivers\MBAMSwissArmy.sys [2014-9-15 122584] R3 MBAMWebAccessControl;MBAMWebAccessControl;C:\windows\System32\drivers\mwac.sys [2014-9-15 63704] R3 RTL8167;Realtek 8167 NT Driver;C:\windows\System32\drivers\Rt64win7.sys [2011-11-30 471144] R3 wdkmd;Intel WiDi KMD;C:\windows\System32\drivers\WDKMD.sys [2011-5-16 42392] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192] S3 FlyUsb;FLY Fusion;C:\windows\System32\drivers\FlyUsb.sys [2012-9-28 24576] S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\windows\System32\ieetwcollector.exe [2014-9-16 111616] S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\windows\System32\drivers\intelaud.sys [2011-5-16 34200] S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-5-31 340240] S3 TsUsbFlt;TsUsbFlt;C:\windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232] S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\System32\Wat\WatAdminSvc.exe [2012-6-12 1255736] S4 RsFx0200;RsFx0200 Driver;C:\windows\System32\drivers\RsFx0200.sys [2012-2-11 334936] S4 SQLAgent$SHIPWORKS;SQL Server Agent (SHIPWORKS);C:\Program Files\Microsoft SQL Server\MSSQL11.SHIPWORKS\MSSQL\Binn\SQLAGENT.EXE [2012-2-11 597080] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2014-09-16 13:10:40 2777088 ----a-w- C:\windows\System32\msmpeg2vdec.dll 2014-09-16 13:10:39 2285056 ----a-w- C:\windows\SysWow64\msmpeg2vdec.dll 2014-09-15 14:54:24 122584 ----a-w- C:\windows\System32\drivers\MBAMSwissArmy.sys 2014-09-15 14:54:12 91352 ----a-w- C:\windows\System32\drivers\mbamchameleon.sys 2014-09-15 14:54:12 63704 ----a-w- C:\windows\System32\drivers\mwac.sys 2014-09-15 14:54:12 25816 ----a-w- C:\windows\System32\drivers\mbam.sys 2014-09-15 14:54:12 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-09-15 14:49:53 3231696 ----a-w- C:\Program Files (x86)\Mozilla Firefox\d3dcompiler_46.dll 2014-09-15 14:49:47 28272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe 2014-09-15 14:49:46 800368 ----a-w- C:\Program Files (x86)\Mozilla Firefox\icuuc52.dll 2014-09-15 14:49:46 1023600 ----a-w- C:\Program Files (x86)\Mozilla Firefox\icuin52.dll 2014-09-15 14:49:45 10397296 ----a-w- C:\Program Files (x86)\Mozilla Firefox\icudt52.dll 2014-09-15 14:49:44 47216 ----a-w- C:\Program Files (x86)\Mozilla Firefox\browser\components\browsercomps.dll 2014-09-15 14:25:47 -------- d-----w- C:\Users\Owner\AppData\Roaming\UpdaterEX 2014-09-15 14:25:25 -------- d-----w- C:\Program Files (x86)\SmarterPower 2014-09-15 14:23:06 -------- d-----w- C:\ProgramData\BoostSoftware 2014-09-15 14:22:57 -------- d-----w- C:\Users\Owner\AppData\Local\StormAlerts 2014-09-15 14:22:37 -------- d-----w- C:\Users\Owner\AppData\Local\Programs 2014-09-15 13:37:59 793600 ----a-w- C:\windows\SysWow64\TSWorkspace.dll 2014-09-15 13:37:59 1031168 ----a-w- C:\windows\System32\TSWorkspace.dll 2014-09-15 13:37:45 2565120 ----a-w- C:\windows\System32\d3d10warp.dll 2014-09-15 13:37:44 1987584 ----a-w- C:\windows\SysWow64\d3d10warp.dll 2014-09-15 13:37:31 96768 ----a-w- C:\windows\SysWow64\sspicli.dll 2014-09-15 13:37:31 728064 ----a-w- C:\windows\System32\kerberos.dll 2014-09-15 13:37:31 550912 ----a-w- C:\windows\SysWow64\kerberos.dll 2014-09-15 13:37:31 22016 ----a-w- C:\windows\SysWow64\secur32.dll 2014-09-15 13:37:31 1460736 ----a-w- C:\windows\System32\lsasrv.dll 2014-09-15 13:37:25 578048 ----a-w- C:\windows\System32\aepdu.dll 2014-09-15 13:37:25 424448 ----a-w- C:\windows\System32\aeinv.dll 2014-09-08 13:02:41 99480 ----a-w- C:\windows\SysWow64\infocardapi.dll 2014-09-08 13:02:41 619672 ----a-w- C:\windows\SysWow64\icardagt.exe 2014-09-08 13:02:41 171160 ----a-w- C:\windows\System32\infocardapi.dll 2014-09-08 13:02:41 1389208 ----a-w- C:\windows\System32\icardagt.exe 2014-09-08 13:02:38 8856 ----a-w- C:\windows\SysWow64\icardres.dll 2014-09-08 13:02:38 8856 ----a-w- C:\windows\System32\icardres.dll 2014-09-08 13:02:16 35480 ----a-w- C:\windows\SysWow64\TsWpfWrp.exe 2014-09-08 13:02:16 35480 ----a-w- C:\windows\System32\TsWpfWrp.exe 2014-08-28 00:37:00 404480 ----a-w- C:\windows\System32\gdi32.dll 2014-08-28 00:37:00 3163648 ----a-w- C:\windows\System32\win32k.sys 2014-08-28 00:37:00 311808 ----a-w- C:\windows\SysWow64\gdi32.dll 2014-08-25 03:41:01 -------- d-----w- C:\Users\Owner\AppData\Local\{BCF6BF12-74BE-4B61-8458-B674BFF54A0C} 2014-08-25 00:46:13 2620928 ----a-w- C:\windows\System32\wucltux.dll 2014-08-25 00:45:49 97792 ----a-w- C:\windows\System32\wudriver.dll 2014-08-25 00:45:49 92672 ----a-w- C:\windows\SysWow64\wudriver.dll 2014-08-25 00:45:20 36864 ----a-w- C:\windows\System32\wuapp.exe 2014-08-25 00:45:20 33792 ----a-w- C:\windows\SysWow64\wuapp.exe 2014-08-25 00:45:20 198600 ----a-w- C:\windows\System32\wuwebv.dll 2014-08-25 00:45:20 179656 ----a-w- C:\windows\SysWow64\wuwebv.dll . ==================== Find3M ==================== . 2014-09-10 15:21:23 71344 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-09-10 15:21:23 701104 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe 2014-08-18 22:29:49 2724864 ----a-w- C:\windows\System32\mshtml.tlb 2014-08-18 22:29:35 4096 ----a-w- C:\windows\System32\ieetwcollectorres.dll 2014-08-18 22:19:53 5833728 ----a-w- C:\windows\System32\jscript9.dll 2014-08-18 22:15:34 547328 ----a-w- C:\windows\System32\vbscript.dll 2014-08-18 22:15:09 66048 ----a-w- C:\windows\System32\iesetup.dll 2014-08-18 22:14:38 48640 ----a-w- C:\windows\System32\ieetwproxystub.dll 2014-08-18 22:14:10 83968 ----a-w- C:\windows\System32\MshtmlDac.dll 2014-08-18 22:08:55 4232704 ----a-w- C:\windows\SysWow64\jscript9.dll 2014-08-18 22:03:47 139264 ----a-w- C:\windows\System32\ieUnatt.exe 2014-08-18 22:03:37 111616 ----a-w- C:\windows\System32\ieetwcollector.exe 2014-08-18 22:03:01 758272 ----a-w- C:\windows\System32\jscript9diag.dll 2014-08-18 21:57:44 2724864 ----a-w- C:\windows\SysWow64\mshtml.tlb 2014-08-18 21:56:17 940032 ----a-w- C:\windows\System32\MsSpellCheckingFacility.exe 2014-08-18 21:46:26 454656 ----a-w- C:\windows\SysWow64\vbscript.dll 2014-08-18 21:45:23 61952 ----a-w- C:\windows\SysWow64\iesetup.dll 2014-08-18 21:45:12 72704 ----a-w- C:\windows\System32\JavaScriptCollectionAgent.dll 2014-08-18 21:44:44 51200 ----a-w- C:\windows\SysWow64\ieetwproxystub.dll 2014-08-18 21:44:09 61952 ----a-w- C:\windows\SysWow64\MshtmlDac.dll 2014-08-18 21:36:07 112128 ----a-w- C:\windows\SysWow64\ieUnatt.exe 2014-08-18 21:35:24 597504 ----a-w- C:\windows\SysWow64\jscript9diag.dll 2014-08-18 21:23:17 2104832 ----a-w- C:\windows\System32\inetcpl.cpl 2014-08-18 21:23:16 1249280 ----a-w- C:\windows\System32\mshtmlmedia.dll 2014-08-18 21:22:48 60416 ----a-w- C:\windows\SysWow64\JavaScriptCollectionAgent.dll 2014-08-18 21:15:13 2310656 ----a-w- C:\windows\System32\wininet.dll 2014-08-18 21:08:54 2014208 ----a-w- C:\windows\SysWow64\inetcpl.cpl 2014-08-18 21:07:44 1068032 ----a-w- C:\windows\SysWow64\mshtmlmedia.dll 2014-08-18 20:46:48 1812992 ----a-w- C:\windows\SysWow64\wininet.dll 2014-07-25 06:35:46 875688 ----a-w- C:\windows\SysWow64\msvcr120_clr0400.dll 2014-07-25 03:47:06 869544 ----a-w- C:\windows\System32\msvcr120_clr0400.dll 2014-07-16 03:23:41 2048 ----a-w- C:\windows\System32\tzres.dll 2014-07-16 02:46:02 2048 ----a-w- C:\windows\SysWow64\tzres.dll 2014-07-14 02:02:45 1216000 ----a-w- C:\windows\System32\rpcrt4.dll 2014-07-14 01:40:58 664064 ----a-w- C:\windows\SysWow64\rpcrt4.dll . ============= FINISH: 10:21:30.00 ===============