DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 11.0.9600.17840 BrowserJavaVersion: 11.40.2 Run by [removed] at 8:31:34 on 2015-07-13 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3317.1979 [GMT -5:00] . AV: Norton 360 *Enabled/Updated* {53C7D717-52E2-B95E-FA61-6F32ECC805DB} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton 360 *Enabled/Updated* {E8A636F3-74D8-B6D0-C0D1-5440974F4F66} FW: Norton 360 *Enabled* {6BFC5632-188D-B806-D13E-C607121B42A0} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Intel\AMT\atchksrv.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Coupons\CouponPrinterService.exe C:\Program Files\Intel\AMT\LMS.exe C:\Program Files\Norton 360\Engine\22.5.0.124\N360.exe C:\Program Files\Online Games Manager\ogmservice.exe C:\Program Files\Intel\AMT\UNS.exe C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\Yahoo!\Companion\Installs\cpn0\YNanoService.exe C:\Program Files\Norton 360\Engine\22.5.0.124\N360.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskhost.exe C:\Program Files\Google\Update\1.3.27.5\GoogleCrashHandler.exe C:\Program Files\Intel\AMT\atchk.exe C:\Program Files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe C:\Program Files\HP\HP Software Update\hpwuschd2.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\System32\igfxpers.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\system32\RunDll32.exe C:\Program Files\Belkin\Router Setup and Monitor\BelkinSetup.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\GWX\GWX.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_18_0_0_203.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_18_0_0_203.exe C:\Program Files\Common Files\Motive\pcCMService.exe C:\Program Files\ATT\8.5.0.48\ma\bin\pcTrayApp.exe C:\Program Files\ATT\8.5.0.48\ma\bin\MAHostService.exe C:\Program Files\ATT\8.5.0.48\ma\bin\node.exe C:\Windows\system32\conhost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\System32\svchost.exe -k utcsvc C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted . ============== Pseudo HJT Report =============== . uStart Page = hxxps://us-mg5.mail.yahoo.com/neo/launch?.partner=sbc&.rand=2ul7sd4nlerd8 mStart Page = hxxp://www.yahoo.com mDefault_Page_URL = hxxp://www.yahoo.com mURLSearchHooks: Yahoo! Toolbar for IE: {276C8F18-7FD1-4156-A564-A2D2208AD116} - c:\program files\yahoo!\companion\installs\cpn1\YNanoClient_IE.dll BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - BHO: : {236FE2ED-19AA-4392-A880-DA19F61AE10C} - LocalServer32 - BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\program files\norton 360\engine\22.5.0.124\coieplg.dll BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.8.0_40\bin\ssv.dll BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre1.8.0_40\bin\jp2ssv.dll TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\program files\norton 360\engine\22.5.0.124\coieplg.dll TB: Yahoo! Toolbar for IE: {276C8F18-7FD1-4156-A564-A2D2208AD116} - c:\program files\yahoo!\companion\installs\cpn1\YNanoClient_IE.dll mRun: [atchk] "c:\program files\intel\amt\atchk.exe" mRun: [InstaLAN] "c:\program files\belkin\router setup and monitor\BelkinRouterMonitor.exe" startup mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [gmsd_us_596] StartupFolder: c:\users\ritta\appdata\roaming\micros~1\windows\startm~1\programs\startup\monito~1.lnk - c:\windows\system32\RunDll32.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 TCP: NameServer = 192.168.1.254 TCP: Interfaces\{8DE253C6-3834-480A-997B-FCACCE7CC8D1} : DHCPNameServer = 192.168.5.2 TCP: Interfaces\{E6131277-44DA-461E-81F8-7B6A9D5A6D79} : DHCPNameServer = 192.168.1.254 Notify: igfxcui - igfxdev.dll SSODL: WebCheck - . ================= FIREFOX =================== . FF - ProfilePath - c:\users\ritta\appdata\roaming\mozilla\firefox\profiles\93ux2bqd.default-1434930940506\ FF - prefs.js: browser.search.defaulturl - hxxps://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc-sc&p= FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxps://us-mg5.mail.yahoo.com/neo/launch?.partner=sbc&.rand=7t7r0glq34ggb FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll FF - plugin: c:\program files\att\8.5.0.48\ma\bin\npMotive.dll FF - plugin: c:\program files\common files\motive\npMotiveRequest.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\google\update\1.3.27.5\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre1.8.0_40\bin\dtplugin\npdeployJava1.dll FF - plugin: c:\program files\java\jre1.8.0_40\bin\plugin2\npjp2.dll FF - plugin: c:\program files\microsoft silverlight\5.1.40416.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\browser\plugins\npMozCouponPrinter.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_18_0_0_203.dll . ============= SERVICES / DRIVERS =============== . R0 SymEFASI;Symantec Extended File Attributes (SI);c:\windows\system32\drivers\n360\1605000.07c\SymEFASI.sys [2015-7-1 1278168] R1 BHDrvx86;BHDrvx86;c:\program files\norton 360\nortondata\22.5.0.124\definitions\bashdefs\20150706.001\BHDrvx86.sys [2015-7-7 1181424] R1 ccSet_N360;N360 Settings Manager;c:\windows\system32\drivers\n360\1605000.07c\ccSetx86.sys [2015-7-1 128728] R1 IDSVix86;IDSVix86;c:\program files\norton 360\nortondata\22.5.0.124\definitions\ipsdefs\20150710.001\IDSvix86.sys [2015-7-10 523512] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\1605000.07c\Ironx86.sys [2015-7-1 226008] R1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\n360\1605000.07c\symnets.sys [2015-7-1 421080] R2 AT&T Troubleshoot & Resolve;AT&T Troubleshoot & Resolve;c:\program files\att\8.5.0.48\ma\bin\MAHostService.exe [2015-1-22 321024] R2 CouponPrinterService;Coupon Printer Service;c:\program files\coupons\CouponPrinterService.exe [2014-2-13 1051120] R2 DiagTrack;Diagnostics Tracking Service;c:\windows\system32\svchost.exe -k utcsvc [2009-7-13 20992] R2 N360;Norton 360;c:\program files\norton 360\engine\22.5.0.124\N360.exe [2015-7-1 282016] R2 ogmservice;Online Games Manager;c:\program files\online games manager\ogmservice.exe [2014-3-27 581568] R2 pcCMService;pcCMService;c:\program files\common files\motive\pcCMService.exe [2015-7-13 369152] R2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files\intel\amt\UNS.exe [2012-7-23 2519040] R2 YTBService;Yahoo! Toolbar Service;c:\program files\yahoo!\companion\installs\cpn0\YNanoService.exe [2015-1-29 162072] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2015-7-11 122192] R3 Linksys_adapter_H;Linksys Adapter Network Driver;c:\windows\system32\drivers\AE2500w7.sys [2014-9-26 1092160] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2014-4-11 103608] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464] S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2015-6-10 102912] S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224] S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2015-2-13 1343400] . =============== File Associations =============== . FileExt: .txt: textfile="c:\program files\windows nt\accessories\WORDPAD.EXE" "%1" [UserChoice] . =============== Created Last 30 ================ . 2015-07-13 12:44:21 -------- d-----w- c:\program files\ATT 2015-07-13 12:44:00 -------- d-----w- c:\program files\common files\Motive 2015-07-01 09:43:47 702680 ----a-r- c:\windows\system32\drivers\n360\1605000.07c\srtsp.sys 2015-07-01 09:43:47 421080 ----a-r- c:\windows\system32\drivers\n360\1605000.07c\symnets.sys 2015-07-01 09:43:47 36056 ----a-r- c:\windows\system32\drivers\n360\1605000.07c\srtspx.sys 2015-07-01 09:43:47 226008 ----a-r- c:\windows\system32\drivers\n360\1605000.07c\Ironx86.sys 2015-07-01 09:43:47 21520 ----a-r- c:\windows\system32\drivers\n360\1605000.07c\SymELAM.sys 2015-07-01 09:43:47 1278168 ----a-r- c:\windows\system32\drivers\n360\1605000.07c\SymEFASI.sys 2015-07-01 09:43:46 128728 ----a-r- c:\windows\system32\drivers\n360\1605000.07c\ccSetx86.sys 2015-07-01 09:43:34 160334 ----a-r- c:\windows\system32\drivers\n360\1605000.07c\SymVTcer.dat 2015-07-01 09:43:34 -------- d-----w- c:\windows\system32\drivers\n360\1605000.07C . ==================== Find3M ==================== . 2015-07-09 12:21:13 778416 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2015-07-09 12:21:13 142512 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2015-07-01 09:44:30 94424 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2015-05-25 18:07:34 3989440 ----a-w- c:\windows\system32\ntkrnlpa.exe 2015-05-25 18:07:34 3934144 ----a-w- c:\windows\system32\ntoskrnl.exe 2015-05-25 18:07:33 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys 2015-05-25 18:07:33 137664 ----a-w- c:\windows\system32\drivers\ksecpkg.sys 2015-05-25 18:04:08 1307648 ----a-w- c:\windows\system32\ntdll.dll 2015-05-25 18:00:44 40448 ----a-w- c:\windows\system32\typeperf.exe 2015-05-25 18:00:40 364544 ----a-w- c:\windows\system32\tracerpt.exe 2015-05-25 18:00:29 69632 ----a-w- c:\windows\system32\smss.exe 2015-05-25 18:00:26 262656 ----a-w- c:\windows\system32\rstrui.exe 2015-05-25 18:00:25 37888 ----a-w- c:\windows\system32\relog.exe 2015-05-25 18:00:17 82944 ----a-w- c:\windows\system32\logman.exe 2015-05-25 18:00:17 22528 ----a-w- c:\windows\system32\lsass.exe 2015-05-25 18:00:09 17408 ----a-w- c:\windows\system32\diskperf.exe 2015-05-25 18:00:04 50176 ----a-w- c:\windows\system32\auditpol.exe 2015-05-25 17:57:31 60416 ----a-w- c:\windows\system32\msobjs.dll 2015-05-25 17:57:15 146432 ----a-w- c:\windows\system32\msaudite.dll 2015-05-25 17:55:18 6656 ----a-w- c:\windows\system32\apisetschema.dll 2015-05-25 17:55:17 686080 ----a-w- c:\windows\system32\adtschema.dll 2015-05-25 17:00:20 2384384 ----a-w- c:\windows\system32\win32k.sys 2015-05-25 16:53:50 36864 ----a-w- c:\windows\system32\UtcResources.dll 2015-05-23 03:28:17 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2015-05-23 03:28:04 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2015-05-23 03:15:54 503808 ----a-w- c:\windows\system32\vbscript.dll 2015-05-23 03:15:40 62464 ----a-w- c:\windows\system32\iesetup.dll 2015-05-23 03:15:02 47616 ----a-w- c:\windows\system32\ieetwproxystub.dll 2015-05-23 03:14:51 341504 ----a-w- c:\windows\system32\html.iec 2015-05-23 03:13:48 64000 ----a-w- c:\windows\system32\MshtmlDac.dll 2015-05-23 03:05:21 115712 ----a-w- c:\windows\system32\ieUnatt.exe 2015-05-23 03:05:18 102912 ----a-w- c:\windows\system32\ieetwcollector.exe 2015-05-23 03:04:50 620032 ----a-w- c:\windows\system32\jscript9diag.dll 2015-05-23 03:00:14 667648 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2015-05-23 02:52:43 60416 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2015-05-23 02:47:31 4305920 ----a-w- c:\windows\system32\jscript9.dll 2015-05-23 02:37:45 2052608 ----a-w- c:\windows\system32\inetcpl.cpl 2015-05-23 02:37:25 1155072 ----a-w- c:\windows\system32\mshtmlmedia.dll 2015-05-23 02:20:35 1950720 ----a-w- c:\windows\system32\wininet.dll 2015-05-22 18:03:09 571392 ----a-w- c:\windows\system32\generaltel.dll 2015-05-22 18:02:54 621568 ----a-w- c:\windows\system32\invagent.dll 2015-05-22 18:02:49 333824 ----a-w- c:\windows\system32\devinv.dll 2015-05-22 18:02:46 879104 ----a-w- c:\windows\system32\appraiser.dll 2015-05-22 18:02:45 37888 ----a-w- c:\windows\system32\acmigration.dll 2015-05-22 18:02:45 202752 ----a-w- c:\windows\system32\aepdu.dll 2015-05-22 17:58:27 901120 ----a-w- c:\windows\system32\aeinv.dll 2015-05-21 13:20:34 163840 ----a-w- c:\windows\system32\aepic.dll 2015-05-09 03:14:43 169984 ----a-w- c:\windows\system32\winsrv.dll 2015-05-09 03:13:42 293376 ----a-w- c:\windows\system32\KernelBase.dll 2015-05-09 03:12:59 271360 ----a-w- c:\windows\system32\conhost.exe 2015-05-09 01:59:25 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-05-09 01:59:25 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-05-09 01:59:25 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-05-09 01:59:25 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-05-01 13:16:41 102608 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-04-29 18:07:12 4096 ----a-w- c:\windows\system32\msdxm.ocx 2015-04-29 18:07:12 4096 ----a-w- c:\windows\system32\dxmasf.dll 2015-04-29 18:07:07 8192 ----a-w- c:\windows\system32\spwmp.dll 2015-04-29 18:05:19 12625408 ----a-w- c:\windows\system32\wmploc.DLL 2015-04-24 17:56:58 530432 ----a-w- c:\windows\system32\comctl32.dll 2015-04-20 02:56:29 909312 ----a-w- c:\windows\system32\FntCache.dll 2015-04-20 02:56:29 1250816 ----a-w- c:\windows\system32\DWrite.dll 2015-04-18 02:56:57 342016 ----a-w- c:\windows\system32\certcli.dll . ============= FINISH: 8:32:26.57 ===============