it has been roughly several months ever since i know i had ALOT of adwares/malwares in my laptop. ive been through countless scanners and im sure half of them are fake. One such adware gives creates a new tab named as "Sup" or "surprise" then redirects to some ad. Another adware just simply creates links in articles. One of the scanners(do not remember name) allowed a scan but didn't allow a cleaning of these files. This specific scanner said that i had around 500 malware/adware files in my computer whereas non other scanners had found that much
here are the DDS logs
Attatch.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 12/08/2012 3:26:05 AM
System Uptime: 11/03/2014 10:21:23 PM (0 hours ago)
.
Motherboard: ASUSTeK Computer Inc. | | K43SV
Processor: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz | CPU 1 | 984/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 306 GiB total, 227.219 GiB free.
D: is FIXED (NTFS) - 368 GiB total, 250.931 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP135: 02/03/2014 7:57:38 AM - Windows Update
RP136: 02/03/2014 7:00:10 PM - Windows Backup
RP137: 05/03/2014 4:22:37 PM - Windows Update
RP138: 09/03/2014 8:50:16 AM - Windows Update
RP139: 09/03/2014 7:00:10 PM - Windows Backup
RP140: 11/03/2014 10:07:08 PM - Windows Update
.
==== Installed Programs ======================
.
??????? Windows Live Mesh ActiveX ??(????)
??????? Windows Live Mesh ActiveX ???
Adobe Flash Player 10 Plugin
Adobe Flash Player 11 ActiveX
Asmedia ASM104x USB 3.0 Host Controller Driver
ASUS AI Recovery
ASUS FancyStart
ASUS K3 Series ScreenSaver
ASUS LifeFrame3
ASUS Live Update
ASUS Power4Gear Hybrid
ASUS SmartLogon
ASUS Splendid Video Enhancement Technology
ASUS Virtual Camera
ASUS WebStorage
AsusVibe2.0
Atheros Client Installation Program
ATK Package
Bluetooth Win7 Suite (64)
CCleaner
Compatibility Pack for the 2007 Office system
Contrôle ActiveX Windows Live Mesh pour connexions à distance
Control ActiveX de Windows Live Mesh para conexiones remotas
Controlo ActiveX do Windows Live Mesh para Ligações Remotas
CyberLink LabelPrint
CyberLink Power2Go
D3DX10
ETDWare PS/2-X64 8.0.5.3_WHQL
Fast Boot
ffdshow [rev 3154] [2009-12-09]
Galeria de Fotografias do Windows Live
Galerie de photos Windows Live
Galería fotográfica de Windows Live
GIMP 2.8.0
Google Chrome
Google Update Helper
Intel(R) Turbo Boost Technology Monitor
Java 7 Update 51
Java Auto Updater
Junk Mail filter update
League of Legends
lightshot-5.1.0.15
LOLReplay
Malwarebytes Anti-Malware version 1.75.0.1300
MapleStory
Mesh Runtime
Microsoft .NET Framework 4.5.1
Microsoft Application Error Reporting
Microsoft Office 2010
Microsoft Office File Validation Add-In
Microsoft Office Professional Edition 2003
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MSVCRT
MSVCRT_amd64
Nexon Game Manager
Nuance PDF Reader
NVIDIA 3D Vision Driver 311.44
NVIDIA Control Panel 311.44
NVIDIA Graphics Driver 311.44
NVIDIA HD Audio Driver 1.2.23.3
NVIDIA Install Application
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.11.3
NVIDIA Update Components
PDF Architect
PDFCreator
Razer Game Booster
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek USB 2.0 Reader Driver
Robocraft version 0.3.204
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Skype™ 6.11
Sonic Focus
StarCraft II
syncables desktop SE
ThreatFire
Visual Studio 2010 x64 Redistributables
Wacom Tablet
WebTablet FB Plugin 32 bit
WebTablet FB Plugin 64 bit
Windows Live
Windows Live ???
Windows Live ????
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinFlash
WinRAR 4.20 (64 ??)
Wireless Console 3
YTD Video Downloader 4.0
.
==== Event Viewer Messages From Past Week ========
.
11/03/2014 5:47:00 PM, Error: Service Control Manager [7000] - The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
11/03/2014 5:46:59 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Presentation Foundation Font Cache 3.0.0.0 service to connect.
11/03/2014 10:41:48 PM, Error: Service Control Manager [7034] - The RzKLService service terminated unexpectedly. It has done this 1 time(s).
11/03/2014 10:24:01 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GS-Supporter service to connect.
11/03/2014 10:23:29 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the WebPlat service to connect.
10/03/2014 3:45:42 PM, Error: NetBT [4321] - The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.1.68. The computer with the IP address 192.168.1.70 did not allow the name to be claimed by this computer.
08/03/2014 3:16:48 PM, Error: Service Control Manager [7034] - The ThreatFire service terminated unexpectedly. It has done this 1 time(s).
06/03/2014 7:23:02 AM, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
.
==== End Of File ===========================
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16521 BrowserJavaVersion: 10.51.2
Run by [removed] at 22:41:10 on 2014-03-11
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4073.1733 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\FBAgent.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\PDF Architect\HelperService.exe
C:\Program Files (x86)\PDF Architect\ConversionService.exe
C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\ThreatFire\TFService.exe
C:\Program Files\Intel\TurboBoost\TurboBoost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
C:\Program Files\Tablet\Wacom\WacomHost.exe
C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Hanks\AppData\Local\Skillbrains\lightshot\5.1.0.15\Lightshot.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ThreatFire\TFTray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\system32\taskeng.exe
C:\Users\Hanks\AppData\Local\Temp\RzUpdater\RzUpdateManager.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uProxyServer = 184.107.159.158:3128
mURLSearchHooks: {d2cf9842-af95-48cd-b873-bfbb48cd7f5e} - <orphaned>
mWinlogon: Userinit = userinit.exe,
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [LightShot] C:\Users\Hanks\AppData\Local\Skillbrains\lightshot\Lightshot.exe Flags: uninsdeletevalue
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [Nuance PDF Reader-reminder] "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
mRun: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
mRun: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe /S
mRun: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
mRun: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
mRun: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
mRun: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
mRun: [ThreatFire] C:\Program Files (x86)\ThreatFire\TFTray.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [RazerGameBooster] C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe -autorun
StartupFolder: C:\Users\Hanks\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\RAZERG~1.LNK - C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ASUSVI~1.LNK - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FANCYS~1.LNK - C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe
uPolicies-Explorer: NoDriveAutoRun = dword:0
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: ??? Microsoft Office Excel(&X) - <no file>
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.1.254 75.153.176.1
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574} : DHCPNameServer = 192.168.1.254 [removed]
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\3495E4355414E4 : NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\3495E4355414E4 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\44C696E6B6 : DHCPNameServer = [removed] 192.168.0.1
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\642716E6B6723702960586F6E656 : NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\642716E6B6723702960586F6E656 : DHCPNameServer = [removed] [removed]
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\7516C64756271405 : DHCPNameServer = 192.168.43.1
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\A4F6373656C697E6 : NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\A4F6373656C697E6 : DHCPNameServer = 192.168.1.254
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3
x64-Run: [ETDCtrl] C:\Program Files (x86)\Elantech\ETDCtrl.exe
x64-Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
x64-Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
x64-Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
x64-Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-9-27 248240]
R0 TfFsMon;TfFsMon;C:\Windows\System32\drivers\TfFsMon.sys [2012-10-7 65072]
R0 TfSysMon;TfSysMon;C:\Windows\System32\drivers\TfSysMon.sys [2012-10-7 59880]
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-5-25 17536]
R2 AFBAgent;AFBAgent;C:\Windows\System32\FBAgent.exe [2011-11-18 379520]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-2 15416]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-3-13 138400]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2011-3-13 74912]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-13 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-13 701512]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-9-27 134944]
R2 PDF Architect Helper Service;PDF Architect Helper Service;C:\Program Files (x86)\PDF Architect\HelperService.exe [2013-4-8 1320496]
R2 PDF Architect Service;PDF Architect Service;C:\Program Files (x86)\PDF Architect\ConversionService.exe [2013-4-8 799280]
R2 RzKLService;RzKLService;C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [2013-11-28 105448]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-3-14 383264]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2010-4-16 13832]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2011-6-2 128488]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2011-6-2 401896]
R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\System32\drivers\btath_bus.sys [2011-3-13 28832]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\System32\drivers\ETD.sys [2011-8-31 142632]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-10-13 25928]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-10-23 348376]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\rtsuvstor.sys [2011-11-18 311400]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-11-18 413800]
R3 TfNetMon;TfNetMon;C:\Windows\System32\drivers\TfNetMon.sys [2012-10-7 41888]
S2 976137e5;WebPlat;C:\Windows\System32\rundll32.exe [2009-7-13 45568]
S2 e81a9dc1;GS-Supporter;C:\Windows\System32\rundll32.exe [2009-7-13 45568]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-9-5 171680]
S3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\System32\drivers\btath_flt.sys [2011-3-13 36000]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\drivers\btath_a2dp.sys [2011-3-13 298656]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\drivers\btath_hcrp.sys [2011-3-13 201376]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\drivers\btath_lwflt.sys [2011-3-13 55456]
S3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\drivers\btath_rcp.sys [2011-3-13 154272]
S3 BtFilter;BtFilter;C:\Windows\System32\drivers\btfilter.sys [2011-3-13 280224]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2014-1-22 108800]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2011-4-1 48488]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-3-11 111616]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);C:\Windows\System32\drivers\L1C62x64.sys [2009-6-10 57344]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2014-2-10 19456]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\System32\drivers\SiSG664.sys [2009-6-10 56832]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\System32\drivers\ssudmdm.sys [2014-1-22 206080]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-3-11 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2014-2-10 30208]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2014-03-12 05:17:21 10536864 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{AABCF0B9-D539-418A-A560-582235D2D9ED}\mpengine.dll
2014-03-12 05:09:04 548864 ----a-w- C:\Windows\System32\vbscript.dll
2014-03-12 05:09:04 454656 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-03-12 05:07:03 228864 ----a-w- C:\Windows\System32\wwansvc.dll
2014-03-12 05:07:02 792576 ----a-w- C:\Windows\SysWow64\TSWorkspace.dll
2014-03-12 05:07:02 1030144 ----a-w- C:\Windows\System32\TSWorkspace.dll
2014-03-12 05:05:35 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2014-03-12 05:05:35 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2014-03-12 05:05:14 624128 ----a-w- C:\Windows\System32\qedit.dll
2014-03-12 05:05:14 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2014-03-12 04:34:45 -------- d-----w- C:\AdwCleaner
2014-03-12 00:57:11 10536864 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-03-09 18:11:11 -------- d-----w- C:\Windows\pss
2014-03-09 16:56:41 -------- d-----w- C:\Program Files\CCleaner
2014-03-09 15:52:23 1031560 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{06503358-9058-4E51-9434-BC4794D5E8F3}\gapaengine.dll
2014-03-07 00:07:22 -------- d-----w- C:\Users\Hanks\AppData\Roaming\NVIDIA
2014-03-05 07:12:23 -------- d-----w- C:\Users\Hanks\AppData\Roaming\rcru
2014-02-28 00:21:50 1031560 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-02-24 00:06:00 -------- d-----w- C:\Users\Hanks\AppData\Local\VirtualStore
2014-02-23 21:28:20 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2014-02-23 21:28:20 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2014-02-23 21:28:20 1882112 ----a-w- C:\Windows\System32\msxml3.dll
2014-02-23 21:28:20 1237504 ----a-w- C:\Windows\SysWow64\msxml3.dll
2014-02-23 21:27:59 3928064 ----a-w- C:\Windows\System32\d2d1.dll
2014-02-23 21:27:59 3419136 ----a-w- C:\Windows\SysWow64\d2d1.dll
2014-02-23 21:27:59 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2014-02-23 21:27:59 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2014-02-23 21:19:08 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2014-02-23 21:19:04 -------- d-----w- C:\Program Files\Microsoft Security Client
2014-02-23 21:03:32 -------- d-----w- C:\ProgramData\Anvisoft
2014-02-23 20:42:14 -------- d-----w- C:\Windows\ERUNT
2014-02-23 19:15:10 -------- d-----w- C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-02-23 19:15:06 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2014-02-14 04:09:30 -------- d-----w- C:\Users\Hanks\AppData\Roaming\.mono
2014-02-12 00:11:12 -------- d-----w- C:\Games
2014-02-10 19:25:07 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2014-02-10 19:25:07 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2014-02-10 19:25:06 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2014-02-10 19:25:05 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2014-02-10 19:23:52 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2014-02-10 19:14:17 -------- d-----w- C:\Windows\Migration
2014-02-10 19:07:56 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2014-02-10 19:07:10 15360 ----a-w- C:\Windows\System32\RdpGroupPolicyExtension.dll
2014-02-10 19:07:06 30208 ----a-w- C:\Windows\System32\drivers\TsUsbGD.sys
2014-02-10 19:07:06 19456 ----a-w- C:\Windows\System32\drivers\rdpvideominiport.sys
2014-02-10 19:07:03 192000 ----a-w- C:\Windows\SysWow64\rdpendp_winip.dll
2014-02-10 19:07:02 3174912 ----a-w- C:\Windows\System32\rdpcorets.dll
2014-02-10 19:07:02 243200 ----a-w- C:\Windows\System32\rdpudd.dll
2014-02-10 19:07:02 228864 ----a-w- C:\Windows\System32\rdpendp_winip.dll
2014-02-10 18:59:20 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2014-02-10 18:59:20 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2014-02-10 18:59:18 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2014-02-10 18:59:18 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2014-02-10 18:59:17 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2014-02-10 18:59:17 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2014-02-10 18:59:16 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2014-02-10 18:50:46 1930752 ----a-w- C:\Windows\System32\authui.dll
2014-02-10 18:49:51 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll
2014-02-10 18:46:47 461312 ----a-w- C:\Windows\System32\scavengeui.dll
2014-02-10 18:46:39 223752 ----a-w- C:\Windows\System32\drivers\fvevol.sys
2014-02-10 17:45:02 1887232 ----a-w- C:\Windows\System32\d3d11.dll
2014-02-10 17:45:02 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2014-02-10 17:34:17 10315576 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DFC6CAE1-27FF-436E-ACB2-F39A50E2B134}\mpengine.dll
2014-02-10 17:21:55 -------- d-----w- C:\Windows\System32\MRT
2014-02-10 17:19:30 224256 ----a-w- C:\Windows\System32\wintrust.dll
2014-02-10 17:19:30 175104 ----a-w- C:\Windows\SysWow64\wintrust.dll
2014-02-10 17:19:20 1888768 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2014-02-10 17:19:20 1620992 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2014-02-10 17:16:56 2002432 ----a-w- C:\Windows\System32\msxml6.dll
2014-02-10 17:15:59 656896 ----a-w- C:\Windows\SysWow64\nshwfp.dll
2014-02-10 17:13:28 202752 ----a-w- C:\Windows\System32\scrrun.dll
2014-02-10 17:13:28 168960 ----a-w- C:\Windows\System32\wscript.exe
2014-02-10 17:13:28 156160 ----a-w- C:\Windows\System32\cscript.exe
2014-02-10 17:13:28 150016 ----a-w- C:\Windows\System32\wshom.ocx
2014-02-10 17:13:28 141824 ----a-w- C:\Windows\SysWow64\wscript.exe
2014-02-10 17:13:28 121856 ----a-w- C:\Windows\SysWow64\wshom.ocx
2014-02-10 17:13:27 163840 ----a-w- C:\Windows\SysWow64\scrrun.dll
2014-02-10 17:13:27 126976 ----a-w- C:\Windows\SysWow64\cscript.exe
2014-02-10 17:10:47 983488 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2014-02-10 17:10:47 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2014-02-10 17:10:47 144384 ----a-w- C:\Windows\System32\cdd.dll
.
==================== Find3M ====================
.
2014-03-12 04:54:57 45056 ----a-w- C:\Windows\SysWow64\acovcnt.exe
2014-03-01 05:17:02 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-03-01 05:16:26 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-03-01 04:52:55 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-03-01 04:51:59 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-03-01 04:33:52 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-03-01 04:33:34 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-03-01 04:32:59 708608 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-03-01 04:23:49 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-03-01 04:11:20 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-03-01 03:54:33 5768704 ----a-w- C:\Windows\System32\jscript9.dll
2014-03-01 03:52:43 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-03-01 03:51:53 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-03-01 03:38:26 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-03-01 03:37:35 553472 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-03-01 03:35:11 2041856 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-03-01 03:14:15 4244480 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-03-01 03:10:28 2334208 ----a-w- C:\Windows\System32\wininet.dll
2014-03-01 03:00:08 1964032 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-03-01 02:32:16 1820160 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-02-10 17:47:12 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-02-07 01:23:30 3156480 ----a-w- C:\Windows\System32\win32k.sys
2014-01-29 02:32:18 484864 ----a-w- C:\Windows\System32\wer.dll
2014-01-29 02:06:47 381440 ----a-w- C:\Windows\SysWow64\wer.dll
2014-01-22 16:52:10 206080 ----a-w- C:\Windows\System32\drivers\ssudmdm.sys
2014-01-22 16:52:10 108800 ----a-w- C:\Windows\System32\drivers\ssudbus.sys
2014-01-19 07:33:29 270496 ------w- C:\Windows\System32\MpSigStub.exe
2013-12-19 05:09:39 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
.
============= FINISH: 22:43:23.00 ===============
thank you for your help.
here are the DDS logs
Attatch.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 12/08/2012 3:26:05 AM
System Uptime: 11/03/2014 10:21:23 PM (0 hours ago)
.
Motherboard: ASUSTeK Computer Inc. | | K43SV
Processor: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz | CPU 1 | 984/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 306 GiB total, 227.219 GiB free.
D: is FIXED (NTFS) - 368 GiB total, 250.931 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP135: 02/03/2014 7:57:38 AM - Windows Update
RP136: 02/03/2014 7:00:10 PM - Windows Backup
RP137: 05/03/2014 4:22:37 PM - Windows Update
RP138: 09/03/2014 8:50:16 AM - Windows Update
RP139: 09/03/2014 7:00:10 PM - Windows Backup
RP140: 11/03/2014 10:07:08 PM - Windows Update
.
==== Installed Programs ======================
.
??????? Windows Live Mesh ActiveX ??(????)
??????? Windows Live Mesh ActiveX ???
Adobe Flash Player 10 Plugin
Adobe Flash Player 11 ActiveX
Asmedia ASM104x USB 3.0 Host Controller Driver
ASUS AI Recovery
ASUS FancyStart
ASUS K3 Series ScreenSaver
ASUS LifeFrame3
ASUS Live Update
ASUS Power4Gear Hybrid
ASUS SmartLogon
ASUS Splendid Video Enhancement Technology
ASUS Virtual Camera
ASUS WebStorage
AsusVibe2.0
Atheros Client Installation Program
ATK Package
Bluetooth Win7 Suite (64)
CCleaner
Compatibility Pack for the 2007 Office system
Contrôle ActiveX Windows Live Mesh pour connexions à distance
Control ActiveX de Windows Live Mesh para conexiones remotas
Controlo ActiveX do Windows Live Mesh para Ligações Remotas
CyberLink LabelPrint
CyberLink Power2Go
D3DX10
ETDWare PS/2-X64 8.0.5.3_WHQL
Fast Boot
ffdshow [rev 3154] [2009-12-09]
Galeria de Fotografias do Windows Live
Galerie de photos Windows Live
Galería fotográfica de Windows Live
GIMP 2.8.0
Google Chrome
Google Update Helper
Intel(R) Turbo Boost Technology Monitor
Java 7 Update 51
Java Auto Updater
Junk Mail filter update
League of Legends
lightshot-5.1.0.15
LOLReplay
Malwarebytes Anti-Malware version 1.75.0.1300
MapleStory
Mesh Runtime
Microsoft .NET Framework 4.5.1
Microsoft Application Error Reporting
Microsoft Office 2010
Microsoft Office File Validation Add-In
Microsoft Office Professional Edition 2003
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MSVCRT
MSVCRT_amd64
Nexon Game Manager
Nuance PDF Reader
NVIDIA 3D Vision Driver 311.44
NVIDIA Control Panel 311.44
NVIDIA Graphics Driver 311.44
NVIDIA HD Audio Driver 1.2.23.3
NVIDIA Install Application
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.11.3
NVIDIA Update Components
PDF Architect
PDFCreator
Razer Game Booster
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek USB 2.0 Reader Driver
Robocraft version 0.3.204
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Skype™ 6.11
Sonic Focus
StarCraft II
syncables desktop SE
ThreatFire
Visual Studio 2010 x64 Redistributables
Wacom Tablet
WebTablet FB Plugin 32 bit
WebTablet FB Plugin 64 bit
Windows Live
Windows Live ???
Windows Live ????
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinFlash
WinRAR 4.20 (64 ??)
Wireless Console 3
YTD Video Downloader 4.0
.
==== Event Viewer Messages From Past Week ========
.
11/03/2014 5:47:00 PM, Error: Service Control Manager [7000] - The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
11/03/2014 5:46:59 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Presentation Foundation Font Cache 3.0.0.0 service to connect.
11/03/2014 10:41:48 PM, Error: Service Control Manager [7034] - The RzKLService service terminated unexpectedly. It has done this 1 time(s).
11/03/2014 10:24:01 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GS-Supporter service to connect.
11/03/2014 10:23:29 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the WebPlat service to connect.
10/03/2014 3:45:42 PM, Error: NetBT [4321] - The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.1.68. The computer with the IP address 192.168.1.70 did not allow the name to be claimed by this computer.
08/03/2014 3:16:48 PM, Error: Service Control Manager [7034] - The ThreatFire service terminated unexpectedly. It has done this 1 time(s).
06/03/2014 7:23:02 AM, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
.
==== End Of File ===========================
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16521 BrowserJavaVersion: 10.51.2
Run by [removed] at 22:41:10 on 2014-03-11
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4073.1733 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\FBAgent.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\PDF Architect\HelperService.exe
C:\Program Files (x86)\PDF Architect\ConversionService.exe
C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\ThreatFire\TFService.exe
C:\Program Files\Intel\TurboBoost\TurboBoost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
C:\Program Files\Tablet\Wacom\WacomHost.exe
C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Hanks\AppData\Local\Skillbrains\lightshot\5.1.0.15\Lightshot.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ThreatFire\TFTray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\system32\taskeng.exe
C:\Users\Hanks\AppData\Local\Temp\RzUpdater\RzUpdateManager.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uProxyServer = 184.107.159.158:3128
mURLSearchHooks: {d2cf9842-af95-48cd-b873-bfbb48cd7f5e} - <orphaned>
mWinlogon: Userinit = userinit.exe,
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [LightShot] C:\Users\Hanks\AppData\Local\Skillbrains\lightshot\Lightshot.exe Flags: uninsdeletevalue
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [Nuance PDF Reader-reminder] "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
mRun: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
mRun: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe /S
mRun: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
mRun: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
mRun: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
mRun: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
mRun: [ThreatFire] C:\Program Files (x86)\ThreatFire\TFTray.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [RazerGameBooster] C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe -autorun
StartupFolder: C:\Users\Hanks\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\RAZERG~1.LNK - C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ASUSVI~1.LNK - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FANCYS~1.LNK - C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe
uPolicies-Explorer: NoDriveAutoRun = dword:0
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: ??? Microsoft Office Excel(&X) - <no file>
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.1.254 75.153.176.1
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574} : DHCPNameServer = 192.168.1.254 [removed]
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\3495E4355414E4 : NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\3495E4355414E4 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\44C696E6B6 : DHCPNameServer = [removed] 192.168.0.1
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\642716E6B6723702960586F6E656 : NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\642716E6B6723702960586F6E656 : DHCPNameServer = [removed] [removed]
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\7516C64756271405 : DHCPNameServer = 192.168.43.1
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\A4F6373656C697E6 : NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{E5B94548-5252-4885-9A07-48475642F574}\A4F6373656C697E6 : DHCPNameServer = 192.168.1.254
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3
x64-Run: [ETDCtrl] C:\Program Files (x86)\Elantech\ETDCtrl.exe
x64-Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
x64-Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
x64-Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
x64-Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-9-27 248240]
R0 TfFsMon;TfFsMon;C:\Windows\System32\drivers\TfFsMon.sys [2012-10-7 65072]
R0 TfSysMon;TfSysMon;C:\Windows\System32\drivers\TfSysMon.sys [2012-10-7 59880]
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-5-25 17536]
R2 AFBAgent;AFBAgent;C:\Windows\System32\FBAgent.exe [2011-11-18 379520]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-2 15416]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-3-13 138400]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2011-3-13 74912]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-13 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-13 701512]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-9-27 134944]
R2 PDF Architect Helper Service;PDF Architect Helper Service;C:\Program Files (x86)\PDF Architect\HelperService.exe [2013-4-8 1320496]
R2 PDF Architect Service;PDF Architect Service;C:\Program Files (x86)\PDF Architect\ConversionService.exe [2013-4-8 799280]
R2 RzKLService;RzKLService;C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [2013-11-28 105448]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-3-14 383264]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2010-4-16 13832]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2011-6-2 128488]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2011-6-2 401896]
R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\System32\drivers\btath_bus.sys [2011-3-13 28832]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\System32\drivers\ETD.sys [2011-8-31 142632]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-10-13 25928]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-10-23 348376]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\rtsuvstor.sys [2011-11-18 311400]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-11-18 413800]
R3 TfNetMon;TfNetMon;C:\Windows\System32\drivers\TfNetMon.sys [2012-10-7 41888]
S2 976137e5;WebPlat;C:\Windows\System32\rundll32.exe [2009-7-13 45568]
S2 e81a9dc1;GS-Supporter;C:\Windows\System32\rundll32.exe [2009-7-13 45568]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-9-5 171680]
S3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\System32\drivers\btath_flt.sys [2011-3-13 36000]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\drivers\btath_a2dp.sys [2011-3-13 298656]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\drivers\btath_hcrp.sys [2011-3-13 201376]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\drivers\btath_lwflt.sys [2011-3-13 55456]
S3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\drivers\btath_rcp.sys [2011-3-13 154272]
S3 BtFilter;BtFilter;C:\Windows\System32\drivers\btfilter.sys [2011-3-13 280224]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2014-1-22 108800]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2011-4-1 48488]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-3-11 111616]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);C:\Windows\System32\drivers\L1C62x64.sys [2009-6-10 57344]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2014-2-10 19456]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\System32\drivers\SiSG664.sys [2009-6-10 56832]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\System32\drivers\ssudmdm.sys [2014-1-22 206080]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-3-11 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2014-2-10 30208]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2014-03-12 05:17:21 10536864 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{AABCF0B9-D539-418A-A560-582235D2D9ED}\mpengine.dll
2014-03-12 05:09:04 548864 ----a-w- C:\Windows\System32\vbscript.dll
2014-03-12 05:09:04 454656 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-03-12 05:07:03 228864 ----a-w- C:\Windows\System32\wwansvc.dll
2014-03-12 05:07:02 792576 ----a-w- C:\Windows\SysWow64\TSWorkspace.dll
2014-03-12 05:07:02 1030144 ----a-w- C:\Windows\System32\TSWorkspace.dll
2014-03-12 05:05:35 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2014-03-12 05:05:35 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2014-03-12 05:05:14 624128 ----a-w- C:\Windows\System32\qedit.dll
2014-03-12 05:05:14 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2014-03-12 04:34:45 -------- d-----w- C:\AdwCleaner
2014-03-12 00:57:11 10536864 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-03-09 18:11:11 -------- d-----w- C:\Windows\pss
2014-03-09 16:56:41 -------- d-----w- C:\Program Files\CCleaner
2014-03-09 15:52:23 1031560 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{06503358-9058-4E51-9434-BC4794D5E8F3}\gapaengine.dll
2014-03-07 00:07:22 -------- d-----w- C:\Users\Hanks\AppData\Roaming\NVIDIA
2014-03-05 07:12:23 -------- d-----w- C:\Users\Hanks\AppData\Roaming\rcru
2014-02-28 00:21:50 1031560 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-02-24 00:06:00 -------- d-----w- C:\Users\Hanks\AppData\Local\VirtualStore
2014-02-23 21:28:20 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2014-02-23 21:28:20 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2014-02-23 21:28:20 1882112 ----a-w- C:\Windows\System32\msxml3.dll
2014-02-23 21:28:20 1237504 ----a-w- C:\Windows\SysWow64\msxml3.dll
2014-02-23 21:27:59 3928064 ----a-w- C:\Windows\System32\d2d1.dll
2014-02-23 21:27:59 3419136 ----a-w- C:\Windows\SysWow64\d2d1.dll
2014-02-23 21:27:59 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2014-02-23 21:27:59 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2014-02-23 21:19:08 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2014-02-23 21:19:04 -------- d-----w- C:\Program Files\Microsoft Security Client
2014-02-23 21:03:32 -------- d-----w- C:\ProgramData\Anvisoft
2014-02-23 20:42:14 -------- d-----w- C:\Windows\ERUNT
2014-02-23 19:15:10 -------- d-----w- C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-02-23 19:15:06 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2014-02-14 04:09:30 -------- d-----w- C:\Users\Hanks\AppData\Roaming\.mono
2014-02-12 00:11:12 -------- d-----w- C:\Games
2014-02-10 19:25:07 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2014-02-10 19:25:07 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2014-02-10 19:25:06 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2014-02-10 19:25:05 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2014-02-10 19:23:52 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2014-02-10 19:14:17 -------- d-----w- C:\Windows\Migration
2014-02-10 19:07:56 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2014-02-10 19:07:10 15360 ----a-w- C:\Windows\System32\RdpGroupPolicyExtension.dll
2014-02-10 19:07:06 30208 ----a-w- C:\Windows\System32\drivers\TsUsbGD.sys
2014-02-10 19:07:06 19456 ----a-w- C:\Windows\System32\drivers\rdpvideominiport.sys
2014-02-10 19:07:03 192000 ----a-w- C:\Windows\SysWow64\rdpendp_winip.dll
2014-02-10 19:07:02 3174912 ----a-w- C:\Windows\System32\rdpcorets.dll
2014-02-10 19:07:02 243200 ----a-w- C:\Windows\System32\rdpudd.dll
2014-02-10 19:07:02 228864 ----a-w- C:\Windows\System32\rdpendp_winip.dll
2014-02-10 18:59:20 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2014-02-10 18:59:20 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2014-02-10 18:59:18 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2014-02-10 18:59:18 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2014-02-10 18:59:17 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2014-02-10 18:59:17 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2014-02-10 18:59:16 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2014-02-10 18:50:46 1930752 ----a-w- C:\Windows\System32\authui.dll
2014-02-10 18:49:51 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll
2014-02-10 18:46:47 461312 ----a-w- C:\Windows\System32\scavengeui.dll
2014-02-10 18:46:39 223752 ----a-w- C:\Windows\System32\drivers\fvevol.sys
2014-02-10 17:45:02 1887232 ----a-w- C:\Windows\System32\d3d11.dll
2014-02-10 17:45:02 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2014-02-10 17:34:17 10315576 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DFC6CAE1-27FF-436E-ACB2-F39A50E2B134}\mpengine.dll
2014-02-10 17:21:55 -------- d-----w- C:\Windows\System32\MRT
2014-02-10 17:19:30 224256 ----a-w- C:\Windows\System32\wintrust.dll
2014-02-10 17:19:30 175104 ----a-w- C:\Windows\SysWow64\wintrust.dll
2014-02-10 17:19:20 1888768 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2014-02-10 17:19:20 1620992 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2014-02-10 17:16:56 2002432 ----a-w- C:\Windows\System32\msxml6.dll
2014-02-10 17:15:59 656896 ----a-w- C:\Windows\SysWow64\nshwfp.dll
2014-02-10 17:13:28 202752 ----a-w- C:\Windows\System32\scrrun.dll
2014-02-10 17:13:28 168960 ----a-w- C:\Windows\System32\wscript.exe
2014-02-10 17:13:28 156160 ----a-w- C:\Windows\System32\cscript.exe
2014-02-10 17:13:28 150016 ----a-w- C:\Windows\System32\wshom.ocx
2014-02-10 17:13:28 141824 ----a-w- C:\Windows\SysWow64\wscript.exe
2014-02-10 17:13:28 121856 ----a-w- C:\Windows\SysWow64\wshom.ocx
2014-02-10 17:13:27 163840 ----a-w- C:\Windows\SysWow64\scrrun.dll
2014-02-10 17:13:27 126976 ----a-w- C:\Windows\SysWow64\cscript.exe
2014-02-10 17:10:47 983488 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2014-02-10 17:10:47 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2014-02-10 17:10:47 144384 ----a-w- C:\Windows\System32\cdd.dll
.
==================== Find3M ====================
.
2014-03-12 04:54:57 45056 ----a-w- C:\Windows\SysWow64\acovcnt.exe
2014-03-01 05:17:02 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-03-01 05:16:26 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-03-01 04:52:55 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-03-01 04:51:59 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-03-01 04:33:52 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-03-01 04:33:34 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-03-01 04:32:59 708608 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-03-01 04:23:49 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-03-01 04:11:20 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-03-01 03:54:33 5768704 ----a-w- C:\Windows\System32\jscript9.dll
2014-03-01 03:52:43 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-03-01 03:51:53 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-03-01 03:38:26 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-03-01 03:37:35 553472 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-03-01 03:35:11 2041856 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-03-01 03:14:15 4244480 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-03-01 03:10:28 2334208 ----a-w- C:\Windows\System32\wininet.dll
2014-03-01 03:00:08 1964032 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-03-01 02:32:16 1820160 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-02-10 17:47:12 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-02-07 01:23:30 3156480 ----a-w- C:\Windows\System32\win32k.sys
2014-01-29 02:32:18 484864 ----a-w- C:\Windows\System32\wer.dll
2014-01-29 02:06:47 381440 ----a-w- C:\Windows\SysWow64\wer.dll
2014-01-22 16:52:10 206080 ----a-w- C:\Windows\System32\drivers\ssudmdm.sys
2014-01-22 16:52:10 108800 ----a-w- C:\Windows\System32\drivers\ssudbus.sys
2014-01-19 07:33:29 270496 ------w- C:\Windows\System32\MpSigStub.exe
2013-12-19 05:09:39 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
.
============= FINISH: 22:43:23.00 ===============
thank you for your help.

, then save the file to your desktop as ESETScan.txt.