DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 10.0.9200.16720
Run by [removed] at 2:55:26 on 2013-11-05
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3070.1936 [GMT -5:00]
.
AV: Kaspersky Internet Security *Enabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
SP: Kaspersky Internet Security *Enabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security *Enabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe
C:\Windows\System32\CtHelper.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Users\Legend\AppData\Local\Skillbrains\lightshot\4.4.2.10\LightShot.exe
C:\Users\Legend\AppData\Roaming\Explorer\Explorer.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\VyprVPN\VyprVPN.exe
C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
C:\Program Files\TeamViewer\Version8\TeamViewer.exe
C:\Program Files\TeamViewer\Version8\tv_w32.exe
C:\Users\Legend\AppData\Roaming\win update\win update.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\program files\teamviewer\version8\TeamViewer_Desktop.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
BHO: BitComet Helper: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - c:\program files\bitcomet\tools\BitCometBHO_1.5.4.11.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ieext\contentblocker\ie_content_blocker_plugin.dll
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ieext\onlinebanking\online_banking_bho.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ieext\urladvisor\klwtbbho.dll
uRun: [LightShot] c:\users\legend\appdata\local\skillbrains\lightshot\LightShot.exe Flags: uninsdeletevalue
uRun: [Win Update] c:\users\legend\appdata\local\temp\win update\Win Update.exe
uRun: [] c:\users\legend\appdata\roaming\explorer\Explorer.exe
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [DevconDefaultDB] c:\windows\system32\READREG /SILENT /FAIL=1
StartupFolder: c:\users\legend\appdata\roaming\micros~1\windows\startm~1\programs\startup\vyprvpn.lnk - c:\windows\system32\schtasks.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ie_banner_deny.htm
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - c:\program files\bitcomet\tools\BitCometBHO_1.5.4.11.dll/206
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{02FD2760-5B02-4937-9FEB-EB59125814DA} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{7F41ACF0-AB2E-49A8-B653-94C82CF6A84B} : NameServer = 209.99.109.53 209.99.109.54
SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\legend\appdata\roaming\mozilla\firefox\profiles\drlbpvfw.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_9_900_117.dll
FF - ExtSQL: !HIDDEN! 2013-07-14 02:05; {0113D088-8ED1-468C-B225-585A9C53B5E3}; c:\users\legend\appdata\roaming\mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0113D088-8ED1-468C-B225-585A9C53B5E3}
.
============= SERVICES / DRIVERS ===============
.
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2013-10-8 25696]
R1 klpd;klpd;c:\windows\system32\drivers\klpd.sys [2013-4-12 14432]
R1 kltdi;kltdi;c:\windows\system32\drivers\kltdi.sys [2013-5-14 45024]
R1 kneps;kneps;c:\windows\system32\drivers\kneps.sys [2013-6-6 145120]
R2 AcuWVSSchedulerv8;Acunetix WVS Scheduler v8;c:\program files\acunetix\web vulnerability scanner 8\WVSScheduler.exe [2013-10-20 1006112]
R2 AVP;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky internet security 14.0.0\avp.exe [2013-10-8 214512]
R2 TeamViewer8;TeamViewer 8;c:\program files\teamviewer\version8\TeamViewer_Service.exe [2013-4-16 5087584]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\drivers\klkbdflt.sys [2013-10-8 25696]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2013-10-8 25696]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;c:\program files\bitcomet\tools\bitcometservice.exe -service --> c:\program files\bitcomet\tools\BitCometService.exe -service [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2013-4-16 14848]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2013-4-16 27192]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2013-4-16 49664]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2013-4-16 27136]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2013-4-17 1343400]
S4 klflt;klflt;c:\windows\system32\drivers\klflt.sys [2013-11-3 94304]
.
=============== Created Last 30 ================
.
2013-11-05 07:29:26 -------- d-----w- c:\users\legend\appdata\roaming\win update
2013-11-04 20:23:36 -------- d-sh--w- c:\users\legend\appdata\roaming\msgre
2013-11-04 20:07:31 -------- d-sh--w- c:\users\legend\appdata\roaming\msgr
2013-11-04 03:08:35 -------- d-----w- c:\windows\ELAMBKUP
2013-11-04 03:08:31 -------- d-----w- c:\programdata\Kaspersky Lab
2013-11-04 03:08:31 -------- d-----w- c:\program files\Kaspersky Lab
2013-11-04 03:08:22 94304 ----a-w- c:\windows\system32\drivers\klflt.sys
2013-11-02 19:08:31 -------- d-----w- c:\users\legend\appdata\roaming\Explorer
2013-11-02 19:06:25 53 ----a-w- c:\users\legend\appdata\roaming\r58Ies.tmp
2013-11-02 19:06:20 -------- d-----w- c:\users\legend\appdata\roaming\vertex
2013-11-01 05:47:24 7796464 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{df700856-d5ac-41f3-8e4f-e190bf761f89}\mpengine.dll
2013-10-30 20:00:38 -------- d-----w- c:\users\legend\appdata\local\Apple Computer
2013-10-30 19:59:49 26840 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2013-10-30 19:58:52 -------- d-----w- c:\program files\iPod
2013-10-30 19:58:50 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-10-30 19:58:50 -------- d-----w- c:\program files\iTunes
2013-10-30 19:55:44 159744 ----a-w- c:\program files\mozilla firefox\plugins\npqtplugin5.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\mozilla firefox\plugins\npqtplugin4.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\mozilla firefox\plugins\npqtplugin3.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\mozilla firefox\plugins\npqtplugin2.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\mozilla firefox\plugins\npqtplugin.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2013-10-30 19:54:32 -------- d-----w- c:\program files\Bonjour
2013-10-20 23:12:52 -------- d-----w- c:\program files\Acunetix
2013-10-16 17:03:11 -------- d-----w- C:\xampp
2013-10-14 23:17:31 -------- d-----w- c:\programdata\Globalscape
2013-10-14 23:17:26 -------- d-----w- c:\users\legend\appdata\local\Globalscape
2013-10-14 23:16:13 225280 ----a-w- c:\program files\common files\installshield\iscript\iscript.dll
2013-10-14 23:16:13 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2013-10-14 23:16:12 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2013-10-14 23:16:12 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2013-10-14 23:16:11 614532 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
2013-10-14 23:16:10 -------- d-----w- c:\program files\Globalscape
2013-10-08 18:49:18 25696 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2013-10-08 18:49:18 25696 ----a-w- c:\windows\system32\drivers\klkbdflt.sys
2013-10-08 18:49:18 25696 ----a-w- c:\windows\system32\drivers\klim6.sys
2013-10-08 18:49:18 135776 ----a-w- c:\windows\system32\drivers\kl1.sys
.
==================== Find3M ====================
.
2013-10-08 23:53:06 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-10-08 23:53:06 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-22 23:28:06 1767936 ----a-w- c:\windows\system32\wininet.dll
2013-09-22 23:27:49 2876928 ----a-w- c:\windows\system32\jscript9.dll
2013-09-22 23:27:48 61440 ----a-w- c:\windows\system32\iesetup.dll
2013-09-22 23:27:48 109056 ----a-w- c:\windows\system32\iesysprep.dll
2013-09-21 03:30:24 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2013-09-21 02:39:47 71680 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-09-14 00:48:58 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2013-09-08 02:07:12 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-09-08 02:03:58 231424 ----a-w- c:\windows\system32\mswsock.dll
2013-09-04 01:15:32 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-09-04 01:14:52 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-09-04 01:14:52 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-09-04 01:14:45 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-09-04 01:14:45 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-09-04 01:14:43 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-09-04 01:14:40 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-09-03 18:35:12 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-08-29 01:51:45 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-08-29 01:51:45 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-29 01:50:30 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-08-29 01:50:16 619520 ----a-w- c:\windows\system32\tdh.dll
2013-08-29 01:48:17 640512 ----a-w- c:\windows\system32\advapi32.dll
2013-08-28 01:04:30 2348544 ----a-w- c:\windows\system32\win32k.sys
2013-08-28 00:57:20 434688 ----a-w- c:\windows\system32\scavengeui.dll
.
============= FINISH: 2:56:37.95 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 4/16/2013 10:24:18 PM
System Uptime: 11/5/2013 2:28:44 AM (0 hours ago)
.
Motherboard: Dell Inc. | | 0U7084
Processor: Intel(R) Pentium(R) 4 CPU 3.46GHz | Microprocessor | 3458/1066mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 466 GiB total, 413.854 GiB free.
D: is FIXED (NTFS) - 149 GiB total, 145.763 GiB free.
E: is CDROM ()
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: PCI Input Device
Device ID: PCI\VEN_1102&DEV_7003&SUBSYS_00401102&REV_04\4&10416D21&0&11F0
Manufacturer:
Name: PCI Input Device
PNP Device ID: PCI\VEN_1102&DEV_7003&SUBSYS_00401102&REV_04\4&10416D21&0&11F0
Service:
.
==== System Restore Points ===================
.
RP62: 10/1/2013 5:50:45 AM - Windows Update
RP63: 10/8/2013 5:50:41 AM - Windows Update
RP64: 10/9/2013 3:00:12 AM - Windows Update
RP66: 10/14/2013 7:16:22 PM - Installed CuteFTP 9
RP67: 10/15/2013 3:47:11 AM - Windows Update
RP69: 10/15/2013 8:00:09 PM - Revo Uninstaller Pro's restore point - Xlight FTP Server 3.7.8
RP70: 10/22/2013 5:41:28 AM - Windows Update
RP71: 10/29/2013 10:56:13 AM - Windows Update
.
==== Installed Programs ======================
.
Acunetix Web Vulnerability Scanner 8.0
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Apple Application Support
Apple Mobile Device Support
Apple Software Update
BitComet 1.35
Bonjour
CuteFTP 9
FileZilla Client 3.7.3
iCloud
iTunes
Kaspersky Internet Security
lightshot-4.4.2.10
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Mozilla Firefox 25.0 (x86 en-US)
Mozilla Maintenance Service
Netsparker - Web Application Security Scanner (2.3.0.0)
Notepad++
NVIDIA Control Panel 307.83
NVIDIA Graphics Driver 307.83
NVIDIA Install Application
NVIDIA Update 1.10.8
NVIDIA Update Components
QuickTime
Revo Uninstaller Pro 3.0.2
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft .NET Framework 4 Extended (KB2858302v2)
Spybot - Search & Destroy
TeamViewer 8
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3)
VyprVPN
WinRAR archiver
XAMPP
.
==== Event Viewer Messages From Past Week ========
.
11/4/2013 5:33:26 AM, Error: Service Control Manager [7023] - The Application Experience service terminated with the following error: Application Experience is not a valid Win32 application.
11/4/2013 5:32:56 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service.
11/4/2013 5:31:14 AM, Error: Microsoft-Windows-WMPNSS-Service [14360] - IPv4 support has been disabled in WMPNetworkSvc because NotifyAddrChange encountered error '1450'. To enable IPv4 support, restart the WMPNetworkSvc service.
11/4/2013 2:40:31 PM, Error: AeLookupSvc [1] - The Application Experience Lookup service failed to initialize.
.
==== End Of File ===========================
Internet Explorer: 10.0.9200.16720
Run by [removed] at 2:55:26 on 2013-11-05
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3070.1936 [GMT -5:00]
.
AV: Kaspersky Internet Security *Enabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
SP: Kaspersky Internet Security *Enabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security *Enabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe
C:\Windows\System32\CtHelper.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Users\Legend\AppData\Local\Skillbrains\lightshot\4.4.2.10\LightShot.exe
C:\Users\Legend\AppData\Roaming\Explorer\Explorer.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\VyprVPN\VyprVPN.exe
C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
C:\Program Files\TeamViewer\Version8\TeamViewer.exe
C:\Program Files\TeamViewer\Version8\tv_w32.exe
C:\Users\Legend\AppData\Roaming\win update\win update.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\program files\teamviewer\version8\TeamViewer_Desktop.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
BHO: BitComet Helper: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - c:\program files\bitcomet\tools\BitCometBHO_1.5.4.11.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ieext\contentblocker\ie_content_blocker_plugin.dll
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ieext\onlinebanking\online_banking_bho.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ieext\urladvisor\klwtbbho.dll
uRun: [LightShot] c:\users\legend\appdata\local\skillbrains\lightshot\LightShot.exe Flags: uninsdeletevalue
uRun: [Win Update] c:\users\legend\appdata\local\temp\win update\Win Update.exe
uRun: [] c:\users\legend\appdata\roaming\explorer\Explorer.exe
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [DevconDefaultDB] c:\windows\system32\READREG /SILENT /FAIL=1
StartupFolder: c:\users\legend\appdata\roaming\micros~1\windows\startm~1\programs\startup\vyprvpn.lnk - c:\windows\system32\schtasks.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ie_banner_deny.htm
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - c:\program files\bitcomet\tools\BitCometBHO_1.5.4.11.dll/206
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{02FD2760-5B02-4937-9FEB-EB59125814DA} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{7F41ACF0-AB2E-49A8-B653-94C82CF6A84B} : NameServer = 209.99.109.53 209.99.109.54
SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\legend\appdata\roaming\mozilla\firefox\profiles\drlbpvfw.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_9_900_117.dll
FF - ExtSQL: !HIDDEN! 2013-07-14 02:05; {0113D088-8ED1-468C-B225-585A9C53B5E3}; c:\users\legend\appdata\roaming\mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0113D088-8ED1-468C-B225-585A9C53B5E3}
.
============= SERVICES / DRIVERS ===============
.
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2013-10-8 25696]
R1 klpd;klpd;c:\windows\system32\drivers\klpd.sys [2013-4-12 14432]
R1 kltdi;kltdi;c:\windows\system32\drivers\kltdi.sys [2013-5-14 45024]
R1 kneps;kneps;c:\windows\system32\drivers\kneps.sys [2013-6-6 145120]
R2 AcuWVSSchedulerv8;Acunetix WVS Scheduler v8;c:\program files\acunetix\web vulnerability scanner 8\WVSScheduler.exe [2013-10-20 1006112]
R2 AVP;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky internet security 14.0.0\avp.exe [2013-10-8 214512]
R2 TeamViewer8;TeamViewer 8;c:\program files\teamviewer\version8\TeamViewer_Service.exe [2013-4-16 5087584]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\drivers\klkbdflt.sys [2013-10-8 25696]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2013-10-8 25696]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;c:\program files\bitcomet\tools\bitcometservice.exe -service --> c:\program files\bitcomet\tools\BitCometService.exe -service [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2013-4-16 14848]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2013-4-16 27192]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2013-4-16 49664]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2013-4-16 27136]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2013-4-17 1343400]
S4 klflt;klflt;c:\windows\system32\drivers\klflt.sys [2013-11-3 94304]
.
=============== Created Last 30 ================
.
2013-11-05 07:29:26 -------- d-----w- c:\users\legend\appdata\roaming\win update
2013-11-04 20:23:36 -------- d-sh--w- c:\users\legend\appdata\roaming\msgre
2013-11-04 20:07:31 -------- d-sh--w- c:\users\legend\appdata\roaming\msgr
2013-11-04 03:08:35 -------- d-----w- c:\windows\ELAMBKUP
2013-11-04 03:08:31 -------- d-----w- c:\programdata\Kaspersky Lab
2013-11-04 03:08:31 -------- d-----w- c:\program files\Kaspersky Lab
2013-11-04 03:08:22 94304 ----a-w- c:\windows\system32\drivers\klflt.sys
2013-11-02 19:08:31 -------- d-----w- c:\users\legend\appdata\roaming\Explorer
2013-11-02 19:06:25 53 ----a-w- c:\users\legend\appdata\roaming\r58Ies.tmp
2013-11-02 19:06:20 -------- d-----w- c:\users\legend\appdata\roaming\vertex
2013-11-01 05:47:24 7796464 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{df700856-d5ac-41f3-8e4f-e190bf761f89}\mpengine.dll
2013-10-30 20:00:38 -------- d-----w- c:\users\legend\appdata\local\Apple Computer
2013-10-30 19:59:49 26840 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2013-10-30 19:58:52 -------- d-----w- c:\program files\iPod
2013-10-30 19:58:50 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-10-30 19:58:50 -------- d-----w- c:\program files\iTunes
2013-10-30 19:55:44 159744 ----a-w- c:\program files\mozilla firefox\plugins\npqtplugin5.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\mozilla firefox\plugins\npqtplugin4.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\mozilla firefox\plugins\npqtplugin3.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\mozilla firefox\plugins\npqtplugin2.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\mozilla firefox\plugins\npqtplugin.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2013-10-30 19:55:44 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2013-10-30 19:54:32 -------- d-----w- c:\program files\Bonjour
2013-10-20 23:12:52 -------- d-----w- c:\program files\Acunetix
2013-10-16 17:03:11 -------- d-----w- C:\xampp
2013-10-14 23:17:31 -------- d-----w- c:\programdata\Globalscape
2013-10-14 23:17:26 -------- d-----w- c:\users\legend\appdata\local\Globalscape
2013-10-14 23:16:13 225280 ----a-w- c:\program files\common files\installshield\iscript\iscript.dll
2013-10-14 23:16:13 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2013-10-14 23:16:12 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2013-10-14 23:16:12 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2013-10-14 23:16:11 614532 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
2013-10-14 23:16:10 -------- d-----w- c:\program files\Globalscape
2013-10-08 18:49:18 25696 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2013-10-08 18:49:18 25696 ----a-w- c:\windows\system32\drivers\klkbdflt.sys
2013-10-08 18:49:18 25696 ----a-w- c:\windows\system32\drivers\klim6.sys
2013-10-08 18:49:18 135776 ----a-w- c:\windows\system32\drivers\kl1.sys
.
==================== Find3M ====================
.
2013-10-08 23:53:06 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-10-08 23:53:06 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-22 23:28:06 1767936 ----a-w- c:\windows\system32\wininet.dll
2013-09-22 23:27:49 2876928 ----a-w- c:\windows\system32\jscript9.dll
2013-09-22 23:27:48 61440 ----a-w- c:\windows\system32\iesetup.dll
2013-09-22 23:27:48 109056 ----a-w- c:\windows\system32\iesysprep.dll
2013-09-21 03:30:24 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2013-09-21 02:39:47 71680 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-09-14 00:48:58 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2013-09-08 02:07:12 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-09-08 02:03:58 231424 ----a-w- c:\windows\system32\mswsock.dll
2013-09-04 01:15:32 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-09-04 01:14:52 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-09-04 01:14:52 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-09-04 01:14:45 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-09-04 01:14:45 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-09-04 01:14:43 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-09-04 01:14:40 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-09-03 18:35:12 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-08-29 01:51:45 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-08-29 01:51:45 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-29 01:50:30 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-08-29 01:50:16 619520 ----a-w- c:\windows\system32\tdh.dll
2013-08-29 01:48:17 640512 ----a-w- c:\windows\system32\advapi32.dll
2013-08-28 01:04:30 2348544 ----a-w- c:\windows\system32\win32k.sys
2013-08-28 00:57:20 434688 ----a-w- c:\windows\system32\scavengeui.dll
.
============= FINISH: 2:56:37.95 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 4/16/2013 10:24:18 PM
System Uptime: 11/5/2013 2:28:44 AM (0 hours ago)
.
Motherboard: Dell Inc. | | 0U7084
Processor: Intel(R) Pentium(R) 4 CPU 3.46GHz | Microprocessor | 3458/1066mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 466 GiB total, 413.854 GiB free.
D: is FIXED (NTFS) - 149 GiB total, 145.763 GiB free.
E: is CDROM ()
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: PCI Input Device
Device ID: PCI\VEN_1102&DEV_7003&SUBSYS_00401102&REV_04\4&10416D21&0&11F0
Manufacturer:
Name: PCI Input Device
PNP Device ID: PCI\VEN_1102&DEV_7003&SUBSYS_00401102&REV_04\4&10416D21&0&11F0
Service:
.
==== System Restore Points ===================
.
RP62: 10/1/2013 5:50:45 AM - Windows Update
RP63: 10/8/2013 5:50:41 AM - Windows Update
RP64: 10/9/2013 3:00:12 AM - Windows Update
RP66: 10/14/2013 7:16:22 PM - Installed CuteFTP 9
RP67: 10/15/2013 3:47:11 AM - Windows Update
RP69: 10/15/2013 8:00:09 PM - Revo Uninstaller Pro's restore point - Xlight FTP Server 3.7.8
RP70: 10/22/2013 5:41:28 AM - Windows Update
RP71: 10/29/2013 10:56:13 AM - Windows Update
.
==== Installed Programs ======================
.
Acunetix Web Vulnerability Scanner 8.0
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Apple Application Support
Apple Mobile Device Support
Apple Software Update
BitComet 1.35
Bonjour
CuteFTP 9
FileZilla Client 3.7.3
iCloud
iTunes
Kaspersky Internet Security
lightshot-4.4.2.10
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Mozilla Firefox 25.0 (x86 en-US)
Mozilla Maintenance Service
Netsparker - Web Application Security Scanner (2.3.0.0)
Notepad++
NVIDIA Control Panel 307.83
NVIDIA Graphics Driver 307.83
NVIDIA Install Application
NVIDIA Update 1.10.8
NVIDIA Update Components
QuickTime
Revo Uninstaller Pro 3.0.2
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft .NET Framework 4 Extended (KB2858302v2)
Spybot - Search & Destroy
TeamViewer 8
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3)
VyprVPN
WinRAR archiver
XAMPP
.
==== Event Viewer Messages From Past Week ========
.
11/4/2013 5:33:26 AM, Error: Service Control Manager [7023] - The Application Experience service terminated with the following error: Application Experience is not a valid Win32 application.
11/4/2013 5:32:56 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service.
11/4/2013 5:31:14 AM, Error: Microsoft-Windows-WMPNSS-Service [14360] - IPv4 support has been disabled in WMPNetworkSvc because NotifyAddrChange encountered error '1450'. To enable IPv4 support, restart the WMPNetworkSvc service.
11/4/2013 2:40:31 PM, Error: AeLookupSvc [1] - The Application Experience Lookup service failed to initialize.
.
==== End Of File ===========================


textbox. Do not include the words Code: select all
.