Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

ZeroAccess.C, Trojan.Gen.2, and Trojan.Gen.3 -- Google/Desktop/Install


  • This topic is locked This topic is locked
17 replies to this topic

#1 Krampus1

Krampus1

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 22 September 2013 - 09:26 PM

Hi,

Recently I have been infected with a Trojan that others here seem to have been struggling with too. I realized something was wrong immediately and soon found the folder Google/Desktop/Install….. and tried to delete it. Anyway I tried to delete it and scan it many different ways for days until I read some of the other forum posts on this website. The first two times ComboFix didn’t work, but when I ran it in safe mode it finally got the Google file! Anyway, I thought things were finally over, but then Symantec Antivirus popped up again with similar warnings about the same Trojans. This time found only under C:\Users\Sean\AppData\Local\Temp\ and I went to this file and did see many files appearing and then disappearing with filenames such as DWH6F74.tmp; I’m assuming they were disappearing as they were being quarantined. Anyways, I was hoping for help discovering the rest of this infection, as I have been working for days and have no idea anymore. Thanks in advance for your time and help!

 

Here is my DDS log:

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16686
Run by Sean at 19:06:17 on 2013-09-22
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.8082.4898 [GMT -7:00]
.
AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
AV: Panda Antivirus Pro 2014 *Enabled/Updated* {86971480-9989-6750-B122-681A86518D59}
SP: Panda Antivirus Pro 2014 *Enabled/Updated* {3DF6F564-BFB3-68DE-8B92-5368FDD6C7E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PskSvc.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\TPSrvWow.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\PROGRAM FILES (X86)\PANDA SECURITY\PANDA ANTIVIRUS PRO 2014\WebProxy.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Windows\system32\WLANExt.exe
C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k WbioSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
C:\Windows\SysWOW64\lkcitdl.exe
C:\Windows\SysWOW64\lkads.exe
C:\Windows\SysWOW64\lktsrv.exe
c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\BisonCam\PID_0361\DeLay.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
C:\Program Files (x86)\Hotkey\Hotkey.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PsCtrls.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PavFnSvr.exe
C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\pavsrvx86.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\AVENGINE.EXE
c:\Program Files (x86)\Hotkey\PowerBiosServer.exe
C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe
C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\ApVxdWin.exe
C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PsImSvc.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Windows\system32\svchost.exe -k iissvcs
C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SavUI.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\AuthenTec TrueSuite\TouchControl.exe
C:\Program Files\AuthenTec TrueSuite\BioMonitor.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://fe.eng.usf.edu/
BHO: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\x86\IEBHO.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} -
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} -
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" 60
mRun: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe" /r
mRun: [UpdReg] C:\Windows\UpdReg.EXE
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"
mRun: [APVXDWIN] "C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\APVXDWIN.EXE" /s
mRun: [SCANINICIO] "C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\Inicio.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\Hotkey.lnk - C:\Program Files (x86)\Hotkey\Hotkey.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{768A72AB-1196-4DF4-A2F5-B485BF40326E} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{768A72AB-1196-4DF4-A2F5-B485BF40326E}\0596C6F64737 : DHCPNameServer = 10.5.128.8 10.5.128.5
TCP: Interfaces\{768A72AB-1196-4DF4-A2F5-B485BF40326E}\26162656E6569676862637 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{768A72AB-1196-4DF4-A2F5-B485BF40326E}\7756F5E656675627F5573756F5478656F547F696C65647 : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{768A72AB-1196-4DF4-A2F5-B485BF40326E}\84F4D454D2832303 : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{B3265568-0556-46F9-B28D-156A1D8F7F0E} : DHCPNameServer = 75.75.75.75 75.75.76.76
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
AppInit_DLLs= C:\Windows\SysWOW64\nvinit.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\IEBHO.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} -
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [THXCfg64] C:\Windows\System32\RunDLL32.exe C:\Windows\System32\THXCfg64.dll,RunDLLEntry THXCfg64
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
x64-Run: [DeLay] C:\Program Files (x86)\BisonCam\PID_0361\DeLay.exe
x64-Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
x64-Run: [Nvtmru] "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - <orphaned>
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Notify: avldr - avldr64.dll
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\3y43bv1n.default\
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 iaStorA;iaStorA;C:\Windows\System32\drivers\iaStorA.sys [2012-12-21 645952]
R0 iaStorF;iaStorF;C:\Windows\System32\drivers\iaStorF.sys [2012-12-21 27456]
R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2012-8-2 19264]
R0 nvpciflt;nvpciflt;C:\Windows\System32\drivers\nvpciflt.sys [2013-9-20 32032]
R0 pavboot;Panda boot driver;C:\Windows\System32\drivers\pavboot64.sys [2013-9-21 30792]
R1 ShldFlt;Panda File Shield Driver;C:\Windows\System32\drivers\ShldFlt.sys [2013-9-21 48136]
R2 AmFSM;AmFSM;C:\Windows\System32\drivers\amm6460.sys [2013-9-21 71432]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2012-1-9 659968]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-12-19 1014096]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2011-12-19 1104208]
R2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-1-11 135952]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
R2 FPLService;TrueSuiteService;C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe [2011-11-3 299848]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-12-21 7168]
R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 Intel® ME Service;Intel® ME Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [2012-12-21 128280]
R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2012-12-21 165144]
R2 NvStreamSvc;NVIDIA Streamer Service;C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-9-20 14997280]
R2 Panda Software Controller;Panda Software Controller;C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PsCtrlS.exe [2013-9-21 177440]
R2 PAVFNSVR;Panda Function Service;C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PavFnSvr.exe [2013-9-21 202016]
R2 PavPrSrv;Panda Process Protection Service;C:\Program Files (x86)\Common Files\Panda Security\PavShld\PavPrSrv.exe [2013-9-21 62768]
R2 PAVSRV;Panda On-Access Anti-Malware Service;C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\pavsrvx86.exe [2013-9-21 313664]
R2 PowerBiosServer;PowerBiosServer;C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [2012-5-22 35328]
R2 PskSvcRetail;Panda PSK service;C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\psksvc.exe [2013-9-21 28992]
R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-8-14 3291008]
R2 Symantec AntiVirus;Symantec Endpoint Protection;C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe [2010-7-23 1822296]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-12-21 363800]
R2 ZeroConfigService;Intel® PROSet/Wireless Zero Configuration Service;C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2011-12-8 594704]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;C:\Windows\System32\drivers\AmpPal.sys [2012-1-9 195584]
R3 Bluetooth Media Service;Bluetooth Media Service;C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2011-12-19 1304912]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-8-26 140376]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2012-5-15 331264]
R3 iusb3hub;Intel® USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2012-8-2 357184]
R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2012-8-2 789824]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-9-21 25928]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\Windows\System32\drivers\nvvad64v.sys [2013-9-20 39200]
R3 RSBASTOR;Realtek PCIE CardReader Driver - BA;C:\Windows\System32\drivers\RtsBaStor.sys [2012-12-21 295056]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-12-21 677480]
S2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-9-21 418376]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-9-21 701512]
S2 NIApplicationWebServer;NI Application Web Server;"C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe" -user --> C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [?]
S2 nimDNSResponder;National Instruments mDNS Responder Service;"C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe" --> C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [?]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-6-21 162408]
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;C:\Windows\System32\drivers\AmpPal.sys [2012-1-9 195584]
S3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2011-12-13 94720]
S3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2011-12-13 747008]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ibtfltcoex;ibtfltcoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2011-12-14 60416]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-12-8 273168]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-1-3 1255736]
S4 NIApplicationWebServer64;NI Application Web Server (64-bit);C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [2010-6-22 63648]
.
=============== File Associations ===============
.
FileExt: .jse: JSEFile=C:\PROGRA~2\PANDAS~1\PANDAA~1\PavScrip.exe "%1" %*
FileExt: .wsf: WSFFile=C:\PROGRA~2\PANDAS~1\PANDAA~1\PavScrip.exe  "%1" %*
.
=============== Created Last 30 ================
.
2013-09-22 19:37:41    --------    d-sh--w-    C:\$RECYCLE.BIN
2013-09-22 00:54:07    --------    d-----w-    C:\Panda Software
2013-09-22 00:49:41    --------    d-----w-    C:\Users\Sean\AppData\Local\Macromedia
2013-09-22 00:48:35    71048    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-22 00:48:35    692616    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe
2013-09-22 00:46:06    --------    d-----w-    C:\Users\Sean\AppData\Local\Adobe
2013-09-22 00:02:50    25928    ----a-w-    C:\Windows\System32\drivers\mbam.sys
2013-09-21 23:54:42    --------    d-----w-    C:\Windows\pss
2013-09-21 23:07:08    --------    d-----w-    C:\Users\Sean\AppData\Local\Panda Security
2013-09-21 23:06:16    30792    ----a-w-    C:\Windows\System32\drivers\pavboot64.sys
2013-09-21 22:45:13    --------    d-----w-    C:\Program Files\CCleaner
2013-09-21 22:37:32    --------    d-----w-    C:\Program Files (x86)\Common Files\Panda Security
2013-09-21 22:12:22    --------    d-----w-    C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-21 21:42:42    --------    d-----w-    C:\ProgramData\HitmanPro
2013-09-21 21:29:47    --------    d-----w-    C:\Program Files (x86)\Panda Security
2013-09-21 21:07:38    --------    d-----w-    C:\Program Files (x86)\VS Revo Group
2013-09-21 20:43:58    98816    ----a-w-    C:\Windows\sed.exe
2013-09-21 20:43:58    256000    ----a-w-    C:\Windows\PEV.exe
2013-09-21 20:43:58    208896    ----a-w-    C:\Windows\MBR.exe
2013-09-21 20:32:04    737072    ----a-w-    C:\ProgramData\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
2013-09-21 20:31:37    2876528    ----a-w-    C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2013-09-21 20:31:26    42776    ----a-w-    C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2013-09-21 20:31:17    539984    ----a-w-    C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2013-09-21 20:31:08    --------    d-----w-    C:\Windows\ERUNT
2013-09-21 20:17:24    --------    d-----w-    C:\AdwCleaner
2013-09-21 07:32:52    --------    d-----w-    C:\Windows\SysWow64\BestPractices
2013-09-21 07:32:50    --------    d-----w-    C:\Windows\System32\BestPractices
2013-09-21 07:32:50    --------    d-----w-    C:\inetpub
2013-09-21 06:43:19    --------    d-----w-    C:\Users\Sean\AppData\Local\NVIDIA
2013-09-21 06:40:46    --------    d-----w-    C:\Windows\SysWow64\NV
2013-09-21 06:40:46    --------    d-----w-    C:\Windows\System32\NV
2013-09-20 06:40:45    --------    d-----w-    C:\Users\Sean\AppData\Roaming\Malwarebytes
2013-09-20 06:40:38    --------    d-----w-    C:\ProgramData\Malwarebytes
2013-09-11 04:47:13    1292192    ----a-w-    C:\Windows\SysWow64\ntdll.dll
2013-09-11 04:47:10    112640    ----a-w-    C:\Windows\System32\smss.exe
2013-09-11 04:47:07    3584    ---ha-w-    C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 04:47:06    3072    ---ha-w-    C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 04:47:03    3155456    ----a-w-    C:\Windows\System32\win32k.sys
2013-08-27 23:30:24    --------    d-----w-    C:\ProgramData\Package Cache
2013-08-27 23:16:48    --------    d-----w-    C:\Users\Sean\AppData\Local\Apps
2013-08-27 23:01:47    --------    d-----w-    C:\Program Files (x86)\Common Files\Steam
2013-08-27 23:01:46    --------    d-----w-    C:\Program Files (x86)\Steam
2013-08-26 18:55:20    --------    d-----w-    C:\Windows\System32\appmgmt
.
==================== Find3M  ====================
.
2013-09-12 07:25:43    6599968    ----a-w-    C:\Windows\System32\nvcpl.dll
2013-09-12 07:25:43    3452192    ----a-w-    C:\Windows\System32\nvsvc64.dll
2013-09-12 07:25:40    920864    ----a-w-    C:\Windows\System32\nvvsvc.exe
2013-09-12 07:25:40    67072    ----a-w-    C:\Windows\System32\nv3dappshextr.dll
2013-09-12 07:25:40    63776    ----a-w-    C:\Windows\System32\nvshext.dll
2013-09-12 07:25:40    2559776    ----a-w-    C:\Windows\System32\nvsvcr.dll
2013-09-12 07:25:40    219424    ----a-w-    C:\Windows\System32\nvmctray.dll
2013-09-12 07:25:40    1042208    ----a-w-    C:\Windows\System32\nv3dappshext.dll
2013-09-11 22:06:31    3361114    ----a-w-    C:\Windows\System32\nvcoproc.bin
2013-08-20 13:33:40    39200    ----a-w-    C:\Windows\System32\drivers\nvvad64v.sys
2013-08-20 13:32:58    29984    ----a-w-    C:\Windows\System32\nvaudcap64v.dll
2013-08-20 13:32:46    28448    ----a-w-    C:\Windows\SysWow64\nvaudcap32v.dll
2013-08-10 05:22:18    2241024    ----a-w-    C:\Windows\System32\wininet.dll
2013-08-10 05:20:59    3959296    ----a-w-    C:\Windows\System32\jscript9.dll
2013-08-10 05:20:55    67072    ----a-w-    C:\Windows\System32\iesetup.dll
2013-08-10 05:20:55    136704    ----a-w-    C:\Windows\System32\iesysprep.dll
2013-08-10 03:59:10    1767936    ----a-w-    C:\Windows\SysWow64\wininet.dll
2013-08-10 03:58:09    2876928    ----a-w-    C:\Windows\SysWow64\jscript9.dll
2013-08-10 03:58:06    61440    ----a-w-    C:\Windows\SysWow64\iesetup.dll
2013-08-10 03:58:06    109056    ----a-w-    C:\Windows\SysWow64\iesysprep.dll
2013-08-10 03:17:38    2706432    ----a-w-    C:\Windows\System32\mshtml.tlb
2013-08-10 03:07:50    2706432    ----a-w-    C:\Windows\SysWow64\mshtml.tlb
2013-08-10 02:27:59    89600    ----a-w-    C:\Windows\System32\RegisterIEPKEYs.exe
2013-08-10 02:17:19    71680    ----a-w-    C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-08-05 02:25:45    155584    ----a-w-    C:\Windows\System32\drivers\ataport.sys
2013-08-02 02:23:53    5550528    ----a-w-    C:\Windows\System32\ntoskrnl.exe
2013-08-02 02:15:44    1732032    ----a-w-    C:\Windows\System32\ntdll.dll
2013-08-02 02:15:03    362496    ----a-w-    C:\Windows\System32\wow64win.dll
2013-08-02 02:15:03    243712    ----a-w-    C:\Windows\System32\wow64.dll
2013-08-02 02:15:03    13312    ----a-w-    C:\Windows\System32\wow64cpu.dll
2013-08-02 02:14:57    215040    ----a-w-    C:\Windows\System32\winsrv.dll
2013-08-02 02:14:11    16384    ----a-w-    C:\Windows\System32\ntvdm64.dll
2013-08-02 02:13:34    424448    ----a-w-    C:\Windows\System32\KernelBase.dll
2013-08-02 01:59:30    3968960    ----a-w-    C:\Windows\SysWow64\ntkrnlpa.exe
2013-08-02 01:59:30    3913664    ----a-w-    C:\Windows\SysWow64\ntoskrnl.exe
2013-08-02 01:50:42    5120    ----a-w-    C:\Windows\SysWow64\wow32.dll
2013-08-02 01:50:42    274944    ----a-w-    C:\Windows\SysWow64\KernelBase.dll
2013-08-02 01:09:17    338432    ----a-w-    C:\Windows\System32\conhost.exe
2013-08-02 00:45:37    25600    ----a-w-    C:\Windows\SysWow64\setup16.exe
2013-08-02 00:45:36    14336    ----a-w-    C:\Windows\SysWow64\ntvdm64.dll
2013-08-02 00:45:35    7680    ----a-w-    C:\Windows\SysWow64\instnm.exe
2013-08-02 00:45:34    2048    ----a-w-    C:\Windows\SysWow64\user.exe
2013-08-02 00:43:05    6144    ---ha-w-    C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2013-08-02 00:43:05    4608    ---ha-w-    C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 00:43:05    3584    ---ha-w-    C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 00:43:05    3072    ---ha-w-    C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2013-07-25 09:25:54    1888768    ----a-w-    C:\Windows\System32\WMVDECOD.DLL
2013-07-25 08:57:27    1620992    ----a-w-    C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58:42    2048    ----a-w-    C:\Windows\System32\tzres.dll
2013-07-19 01:41:01    2048    ----a-w-    C:\Windows\SysWow64\tzres.dll
2013-07-09 05:52:52    224256    ----a-w-    C:\Windows\System32\wintrust.dll
2013-07-09 05:51:16    1217024    ----a-w-    C:\Windows\System32\rpcrt4.dll
2013-07-09 05:46:20    184320    ----a-w-    C:\Windows\System32\cryptsvc.dll
2013-07-09 05:46:20    1472512    ----a-w-    C:\Windows\System32\crypt32.dll
2013-07-09 05:46:20    139776    ----a-w-    C:\Windows\System32\cryptnet.dll
2013-07-09 04:52:33    663552    ----a-w-    C:\Windows\SysWow64\rpcrt4.dll
2013-07-09 04:52:10    175104    ----a-w-    C:\Windows\SysWow64\wintrust.dll
2013-07-09 04:46:31    140288    ----a-w-    C:\Windows\SysWow64\cryptsvc.dll
2013-07-09 04:46:31    1166848    ----a-w-    C:\Windows\SysWow64\crypt32.dll
2013-07-09 04:46:31    103936    ----a-w-    C:\Windows\SysWow64\cryptnet.dll
2013-07-06 06:03:53    1910208    ----a-w-    C:\Windows\System32\drivers\tcpip.sys
2013-06-26 00:03:54    24544    ----a-w-    C:\Windows\System32\sysHelper64.dll
2011-08-05 19:56:34    645856    ----a-w-    C:\Program Files\UIX.renderapi.dll
2011-08-05 19:56:34    1530592    ----a-w-    C:\Program Files\UIX.dll
2011-08-05 19:56:34    1288928    ----a-w-    C:\Program Files\UIXcontrols.dll
2011-08-05 19:56:34    1272544    ----a-w-    C:\Program Files\ZuneShell.dll
2011-08-05 19:56:34    1175264    ----a-w-    C:\Program Files\ZuneDBApi.dll
2011-08-05 19:31:32    182784    ----a-w-    C:\Program Files\l3codecp.acm
2011-06-06 20:48:50    856576    ----a-w-    C:\Program Files\msvcp90.dll
2011-06-06 20:48:50    626688    ----a-w-    C:\Program Files\msvcr90.dll
2011-06-06 20:48:50    245760    ----a-w-    C:\Program Files\msvcm90.dll
2007-10-02 21:12:44    1642568    ----a-w-    C:\Program Files\msidcrl40.dll
.
============= FINISH: 19:06:38.14 ===============

 

 

 



BC AdBot (Login to Remove)

 


#2 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,458 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:06:10 PM

Posted 23 September 2013 - 01:01 PM

please post the ComboFix log for me to review,

Please run the following:

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif
Microsoft MVP - 2010, 2011, 2012, 2013

#3 Krampus1

Krampus1
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 23 September 2013 - 03:03 PM

Here is the ComboFix log that got it:

 

ComboFix 13-09-19.01 - Sean 09/21/2013  20:08:08.3.8 - x64 MINIMAL
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.8082.6592 [GMT -7:00]
Running from: c:\users\Sean\Desktop\ComboFix.exe
AV: Panda Antivirus Pro 2014 *Enabled/Updated* {86971480-9989-6750-B122-681A86518D59}
AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
SP: Panda Antivirus Pro 2014 *Enabled/Updated* {3DF6F564-BFB3-68DE-8B92-5368FDD6C7E4}
SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Desktop\Install
c:\program files (x86)\Google\Desktop\Install\Virus\9519~1\A535~1\E628~1\{6c4c9e42-e383-6691-9b91-81da14f464fb}\@
.
.
(((((((((((((((((((((((((   Files Created from 2013-08-22 to 2013-09-22  )))))))))))))))))))))))))))))))
.
.
2013-09-22 03:11 . 2013-09-22 03:11    --------    d-----w-    c:\users\UpdatusUser\AppData\Local\temp
2013-09-22 03:11 . 2013-09-22 03:11    --------    d-----w-    c:\users\Default\AppData\Local\temp
2013-09-22 00:54 . 2013-09-22 00:54    --------    d-----w-    C:\Panda Software
2013-09-22 00:49 . 2013-09-22 00:49    --------    d-----w-    c:\users\Sean\AppData\Local\Macromedia
2013-09-22 00:48 . 2013-09-22 00:48    71048    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-22 00:48 . 2013-09-22 00:48    692616    ----a-w-    c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-22 00:46 . 2013-09-22 00:48    --------    d-----w-    c:\users\Sean\AppData\Local\Adobe
2013-09-22 00:02 . 2013-04-04 21:50    25928    ----a-w-    c:\windows\system32\drivers\mbam.sys
2013-09-21 23:07 . 2013-09-21 23:07    --------    d-----w-    c:\users\Sean\AppData\Local\Panda Security
2013-09-21 23:06 . 2010-06-23 01:20    30792    ----a-w-    c:\windows\system32\drivers\pavboot64.sys
2013-09-21 22:45 . 2013-09-21 22:45    --------    d-----w-    c:\program files\CCleaner
2013-09-21 22:37 . 2013-09-21 22:37    --------    d-----w-    c:\program files (x86)\Common Files\Panda Security
2013-09-21 22:12 . 2013-09-22 00:02    --------    d-----w-    c:\program files (x86)\Malwarebytes' Anti-Malware
2013-09-21 21:42 . 2013-09-21 21:58    --------    d-----w-    c:\programdata\HitmanPro
2013-09-21 21:29 . 2013-09-22 00:46    --------    d-----w-    c:\program files (x86)\Panda Security
2013-09-21 21:07 . 2013-09-21 21:07    --------    d-----w-    c:\program files (x86)\VS Revo Group
2013-09-21 20:32 . 2013-09-21 20:32    737072    ----a-w-    c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
2013-09-21 20:31 . 2013-09-21 20:31    2876528    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2013-09-21 20:31 . 2013-09-21 20:31    42776    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2013-09-21 20:31 . 2013-09-21 20:31    539984    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2013-09-21 20:31 . 2013-09-21 20:31    --------    d-----w-    c:\windows\ERUNT
2013-09-21 20:17 . 2013-09-21 22:27    --------    d-----w-    C:\AdwCleaner
2013-09-21 19:26 . 2013-09-02 00:08    79143768    ----a-w-    c:\windows\system32\MRT.exe
2013-09-21 07:32 . 2013-09-21 07:32    --------    d-----w-    c:\windows\SysWow64\BestPractices
2013-09-21 07:32 . 2013-09-21 07:32    --------    d-----w-    c:\windows\system32\BestPractices
2013-09-21 07:32 . 2013-09-21 07:32    --------    d-----w-    C:\inetpub
2013-09-21 06:43 . 2013-09-21 06:43    --------    d-----w-    c:\users\Sean\AppData\Local\NVIDIA
2013-09-21 06:40 . 2013-09-21 06:40    --------    d-----w-    c:\windows\SysWow64\NV
2013-09-21 06:40 . 2013-09-21 06:40    --------    d-----w-    c:\windows\system32\NV
2013-09-20 06:40 . 2013-09-20 06:40    --------    d-----w-    c:\users\Sean\AppData\Roaming\Malwarebytes
2013-09-20 06:40 . 2013-09-20 06:40    --------    d-----w-    c:\programdata\Malwarebytes
2013-09-20 06:37 . 2013-07-26 02:24    14172672    ----a-w-    c:\windows\system32\shell32.dll
2013-09-20 06:37 . 2013-07-26 02:24    197120    ----a-w-    c:\windows\system32\shdocvw.dll
2013-09-20 06:35 . 2013-09-20 06:35    --------    d-----w-    c:\users\Sean\AppData\Local\Mozilla
2013-09-20 06:35 . 2013-09-20 06:35    --------    d-----w-    c:\program files (x86)\Mozilla Maintenance Service
2013-09-20 05:38 . 2013-09-21 03:20    --------    d-----w-    c:\program files (x86)\Google
2013-09-11 04:47 . 2013-08-02 01:51    1292192    ----a-w-    c:\windows\SysWow64\ntdll.dll
2013-09-11 04:47 . 2013-08-02 00:59    112640    ----a-w-    c:\windows\system32\smss.exe
2013-09-11 04:47 . 2013-08-02 01:48    3584    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 04:47 . 2013-08-02 01:48    3072    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 04:47 . 2013-08-08 01:20    3155456    ----a-w-    c:\windows\system32\win32k.sys
2013-08-27 23:30 . 2013-08-27 23:30    --------    d-----w-    c:\programdata\Package Cache
2013-08-27 23:16 . 2013-08-27 23:16    --------    d-----w-    c:\users\Sean\AppData\Local\Apps
2013-08-27 23:01 . 2013-09-20 06:32    --------    d-----w-    c:\program files (x86)\Common Files\Steam
2013-08-27 23:01 . 2013-09-21 22:46    --------    d-----w-    c:\program files (x86)\Steam
2013-08-26 18:55 . 2013-09-20 05:41    --------    d-----w-    c:\windows\system32\appmgmt
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-12 08:58 . 2012-12-21 22:27    2986672    ----a-w-    c:\windows\system32\nvapi64.dll
2013-09-12 08:58 . 2012-12-21 22:27    168616    ----a-w-    c:\windows\system32\nvinitx.dll
2013-09-12 08:58 . 2012-12-21 22:27    141336    ----a-w-    c:\windows\SysWow64\nvinit.dll
2013-09-12 08:58 . 2012-12-21 22:27    1412832    ----a-w-    c:\windows\system32\nvumdshimx.dll
2013-09-12 07:25 . 2012-12-21 22:28    6599968    ----a-w-    c:\windows\system32\nvcpl.dll
2013-09-12 07:25 . 2012-12-21 22:28    3452192    ----a-w-    c:\windows\system32\nvsvc64.dll
2013-09-12 07:25 . 2012-12-21 22:28    920864    ----a-w-    c:\windows\system32\nvvsvc.exe
2013-09-12 07:25 . 2012-12-21 22:28    67072    ----a-w-    c:\windows\system32\nv3dappshextr.dll
2013-09-12 07:25 . 2012-12-21 22:28    63776    ----a-w-    c:\windows\system32\nvshext.dll
2013-09-12 07:25 . 2012-12-21 22:28    2559776    ----a-w-    c:\windows\system32\nvsvcr.dll
2013-09-12 07:25 . 2012-12-21 22:28    219424    ----a-w-    c:\windows\system32\nvmctray.dll
2013-09-12 07:25 . 2012-12-21 22:28    1042208    ----a-w-    c:\windows\system32\nv3dappshext.dll
2013-09-11 22:06 . 2012-12-21 22:28    3361114    ----a-w-    c:\windows\system32\nvcoproc.bin
2013-08-20 20:42 . 2013-08-20 20:42    737072    ----a-w-    c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2013-08-20 20:42 . 2013-08-20 20:42    2876528    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2013-08-20 20:42 . 2013-08-20 20:42    42776    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2013-08-20 20:42 . 2013-08-20 20:42    539984    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2013-08-02 01:48 . 2013-09-20 06:38    44032    ----a-w-    c:\windows\apppatch\acwow64.dll
2013-07-25 09:25 . 2013-08-17 03:35    1888768    ----a-w-    c:\windows\system32\WMVDECOD.DLL
2013-07-25 08:57 . 2013-08-17 03:35    1620992    ----a-w-    c:\windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58 . 2013-08-17 03:35    2048    ----a-w-    c:\windows\system32\tzres.dll
2013-07-19 01:41 . 2013-08-17 03:35    2048    ----a-w-    c:\windows\SysWow64\tzres.dll
2013-07-09 05:52 . 2013-08-17 03:35    224256    ----a-w-    c:\windows\system32\wintrust.dll
2013-07-09 05:51 . 2013-08-17 03:35    1217024    ----a-w-    c:\windows\system32\rpcrt4.dll
2013-07-09 05:46 . 2013-08-17 03:35    1472512    ----a-w-    c:\windows\system32\crypt32.dll
2013-07-09 05:46 . 2013-08-17 03:35    184320    ----a-w-    c:\windows\system32\cryptsvc.dll
2013-07-09 05:46 . 2013-08-17 03:35    139776    ----a-w-    c:\windows\system32\cryptnet.dll
2013-07-09 04:52 . 2013-08-17 03:35    663552    ----a-w-    c:\windows\SysWow64\rpcrt4.dll
2013-07-09 04:52 . 2013-08-17 03:35    175104    ----a-w-    c:\windows\SysWow64\wintrust.dll
2013-07-09 04:46 . 2013-08-17 03:35    1166848    ----a-w-    c:\windows\SysWow64\crypt32.dll
2013-07-09 04:46 . 2013-08-17 03:35    140288    ----a-w-    c:\windows\SysWow64\cryptsvc.dll
2013-07-09 04:46 . 2013-08-17 03:35    103936    ----a-w-    c:\windows\SysWow64\cryptnet.dll
2013-07-06 06:03 . 2013-08-17 03:35    1910208    ----a-w-    c:\windows\system32\drivers\tcpip.sys
2011-08-05 19:56 . 2011-08-05 19:56    645856    ----a-w-    c:\program files\UIX.renderapi.dll
2011-08-05 19:56 . 2011-08-05 19:56    1530592    ----a-w-    c:\program files\UIX.dll
2011-08-05 19:56 . 2011-08-05 19:56    1288928    ----a-w-    c:\program files\UIXcontrols.dll
2011-08-05 19:56 . 2011-08-05 19:56    1272544    ----a-w-    c:\program files\ZuneShell.dll
2011-08-05 19:56 . 2011-08-05 19:56    1175264    ----a-w-    c:\program files\ZuneDBApi.dll
2011-08-05 19:53 . 2011-08-05 19:53    9440    ----a-w-    c:\program files\ZuneWmduResources.dll
2011-08-05 19:53 . 2011-08-05 19:53    863968    ----a-w-    c:\program files\ZuneWmdu.dll
2011-08-05 19:53 . 2011-08-05 19:53    74464    ----a-w-    c:\program files\ZuneShellExt.dll
2011-08-05 19:53 . 2011-08-05 19:53    507104    ----a-w-    c:\program files\ZuneSP.dll
2011-08-05 19:53 . 2011-08-05 19:53    467680    ----a-w-    c:\program files\ZuneWlanCfgSvc.exe
2011-08-05 19:53 . 2011-08-05 19:53    4020448    ----a-w-    c:\program files\ZuneSetup.exe
2011-08-05 19:53 . 2011-08-05 19:53    366816    ----a-w-    c:\program files\ZuneSrcWrp.dll
2011-08-05 19:53 . 2011-08-05 19:53    306400    ----a-w-    c:\program files\WMZuneComm.exe
2011-08-05 19:53 . 2011-08-05 19:53    27872    ----a-w-    c:\program files\WMZuneTCP2UDP.dll
2011-08-05 19:53 . 2011-08-05 19:53    21216    ----a-w-    c:\program files\WMZuneDTPTDNS.dll
2011-08-05 19:53 . 2011-08-05 19:53    196832    ----a-w-    c:\program files\ZuneZMDB.Mobile.dll
2011-08-05 19:53 . 2011-08-05 19:53    18656    ----a-w-    c:\program files\WMZuneCommProxyStub.dll
2011-08-05 19:53 . 2011-08-05 19:53    17632    ----a-w-    c:\program files\ZuneShare.exe
2011-08-05 19:53 . 2011-08-05 19:53    16921312    ----a-w-    c:\program files\ZuneShellResources.dll
2011-08-05 19:53 . 2011-08-05 19:53    157920    ----a-w-    c:\program files\ZuneZMDB.Library.dll
2011-08-05 19:53 . 2011-08-05 19:53    157408    ----a-w-    c:\program files\ZuneZMDB.ZuneHD.dll
2011-08-05 19:53 . 2011-08-05 19:53    152288    ----a-w-    c:\program files\ZuneZMDB.Classic.dll
2011-08-05 19:53 . 2011-08-05 19:53    100064    ----a-w-    c:\program files\ZuneTaskbar.dll
2011-08-05 19:53 . 2011-08-05 19:53    916704    ----a-w-    c:\program files\ZuneQP.dll
2011-08-05 19:53 . 2011-08-05 19:53    683744    ----a-w-    c:\program files\ZuneSH.dll
2011-08-05 19:53 . 2011-08-05 19:53    514272    ----a-w-    c:\program files\ZuneSE.dll
2011-08-05 19:53 . 2011-08-05 19:53    3889376    ----a-w-    c:\program files\ZuneResources.dll
2011-08-05 19:53 . 2011-08-05 19:53    155872    ----a-w-    c:\program files\ZuneSA.dll
2011-08-05 19:53 . 2011-08-05 19:53    1257184    ----a-w-    c:\program files\ZuneService.dll
2011-08-05 19:53 . 2011-08-05 19:53    879328    ----a-w-    c:\program files\ZuneMBR.dll
2011-08-05 19:53 . 2011-08-05 19:53    8277728    ----a-w-    c:\program files\ZuneNss.exe
2011-08-05 19:53 . 2011-08-05 19:53    72928    ----a-w-    c:\program files\ZuneDXVA2.dll
2011-08-05 19:53 . 2011-08-05 19:53    707808    ----a-w-    c:\program files\ZUNEMP4SDECD.dll
2011-08-05 19:53 . 2011-08-05 19:53    61664    ----a-w-    c:\program files\ZuneCfg.dll
2011-08-05 19:53 . 2011-08-05 19:53    56544    ----a-w-    c:\program files\ZuneConfig.exe
2011-08-05 19:53 . 2011-08-05 19:53    38624    ----a-w-    c:\program files\ZuneEnc.exe
2011-08-05 19:53 . 2011-08-05 19:53    376544    ----a-w-    c:\program files\ZuneEvr.dll
2011-08-05 19:53 . 2011-08-05 19:53    35552    ----a-w-    c:\program files\UIXsup.dll
2011-08-05 19:53 . 2011-08-05 19:53    347872    ----a-w-    c:\program files\ZuneNssci.dll
2011-08-05 19:53 . 2011-08-05 19:53    223968    ----a-w-    c:\program files\Zune.exe
2011-08-05 19:53 . 2011-08-05 19:53    218848    ----a-w-    c:\program files\ZuneHost.exe
2011-08-05 19:53 . 2011-08-05 19:53    212192    ----a-w-    c:\program files\ZuneDB.dll
2011-08-05 19:53 . 2011-08-05 19:53    2110176    ----a-w-    c:\program files\ZuneEncEng.dll
2011-08-05 19:53 . 2011-08-05 19:53    20704    ----a-w-    c:\program files\ZunePS.dll
2011-08-05 19:53 . 2011-08-05 19:53    1752288    ----a-w-    c:\program files\UIXrender.dll
2011-08-05 19:53 . 2011-08-05 19:53    163552    ----a-w-    c:\program files\ZuneLauncher.exe
2011-08-05 19:53 . 2011-08-05 19:53    1481440    ----a-w-    c:\program files\ZuneCore.dll
2011-08-05 19:53 . 2011-08-05 19:53    131296    ----a-w-    c:\program files\ZunePresenter.dll
2011-08-05 19:53 . 2011-08-05 19:53    129248    ----a-w-    c:\program files\ZuneEffects.dll
2011-08-05 19:53 . 2011-08-05 19:53    121056    ----a-w-    c:\program files\ZuneAACDec.dll
2011-08-05 19:53 . 2011-08-05 19:53    1184480    ----a-w-    c:\program files\ZuneH264Dec.dll
2011-08-05 19:53 . 2011-08-05 19:53    1161440    ----a-w-    c:\program files\ZuneMde.dll
2011-08-05 19:53 . 2011-08-05 19:53    1096928    ----a-w-    c:\program files\ZuneMarketplaceResources.dll
2011-08-05 19:53 . 2011-08-05 19:53    10061536    ----a-w-    c:\program files\ZuneNativeLib.dll
2011-08-05 19:31 . 2011-08-05 19:31    182784    ----a-w-    c:\program files\l3codecp.acm
2011-06-06 20:48 . 2011-06-06 20:48    856576    ----a-w-    c:\program files\msvcp90.dll
2011-06-06 20:48 . 2011-06-06 20:48    626688    ----a-w-    c:\program files\msvcr90.dll
2011-06-06 20:48 . 2011-06-06 20:48    245760    ----a-w-    c:\program files\msvcm90.dll
2007-10-02 21:12 . 2007-10-02 21:12    1642568    ----a-w-    c:\program files\msidcrl40.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe" [2012-07-17 56128]
"THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe" [2010-11-01 1374720]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"USB3MON"="c:\program files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-05-20 291648]
"ccApp"="c:\program files (x86)\Common Files\Symantec Shared\ccApp.exe" [2010-07-24 115560]
"APVXDWIN"="c:\program files (x86)\Panda Security\Panda Antivirus Pro 2014\APVXDWIN.EXE" [2013-07-05 1062880]
"SCANINICIO"="c:\program files (x86)\Panda Security\Panda Antivirus Pro 2014\Inicio.exe" [2012-11-08 70432]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Hotkey.lnk - c:\program files (x86)\Hotkey\Hotkey.exe [2012-7-26 4730880]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
R0 pavboot;Panda boot driver;c:\windows\system32\Drivers\pavboot64.sys;c:\windows\SYSNATIVE\Drivers\pavboot64.sys [x]
R1 ShldFlt;Panda File Shield Driver;c:\windows\system32\DRIVERS\ShldFlt.sys;c:\windows\SYSNATIVE\DRIVERS\ShldFlt.sys [x]
R2 AmFSM;AmFSM;c:\windows\system32\DRIVERS\amm6460.sys;c:\windows\SYSNATIVE\DRIVERS\amm6460.sys [x]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
R2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 FPLService;TrueSuiteService;c:\program files\AuthenTec TrueSuite\TrueSuiteService.exe;c:\program files\AuthenTec TrueSuite\TrueSuiteService.exe [x]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
R2 Intel® ME Service;Intel® ME Service;c:\program files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [x]
R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [x]
R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R2 NIApplicationWebServer;NI Application Web Server;c:\program files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe;c:\program files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [x]
R2 nimDNSResponder;National Instruments mDNS Responder Service;c:\program files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe;c:\program files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [x]
R2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
R2 PowerBiosServer;PowerBiosServer;c:\program files (x86)\Hotkey\PowerBiosServer.exe;c:\program files (x86)\Hotkey\PowerBiosServer.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x]
R2 ZeroConfigService;Intel® PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x]
R3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]
R3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
R3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 PavTPK.sys;PavTPK.sys;c:\windows\system32\PavTPK.sys;c:\windows\SYSNATIVE\PavTPK.sys [x]
R3 RSBASTOR;Realtek PCIE CardReader Driver - BA;c:\windows\system32\DRIVERS\RtsBaStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsBaStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 NIApplicationWebServer64;NI Application Web Server (64-bit);c:\program files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe;c:\program files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [x]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
S0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S2 PskSvcRetail;Panda PSK service;c:\program files (x86)\Panda Security\Panda Antivirus Pro 2014\PskSvc.exe;c:\program files (x86)\Panda Security\Panda Antivirus Pro 2014\PskSvc.exe [x]
S3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs    REG_MULTI_SZ       w3svc was
apphost    REG_MULTI_SZ       apphostsvc
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{BC6D10E6-AE59-4cef-83DB-FD4C9BC7B7F2}"
[HKEY_CLASSES_ROOT\CLSID\{BC6D10E6-AE59-4cef-83DB-FD4C9BC7B7F2}]
2011-10-21 22:00    4014408    ----a-w-    c:\program files\AuthenTec TrueSuite\KeepSafe\fvns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{93BB455E-3D52-4fba-9733-E5103B30FC12}"
[HKEY_CLASSES_ROOT\CLSID\{93BB455E-3D52-4fba-9733-E5103B30FC12}]
2011-10-21 22:00    4014408    ----a-w-    c:\program files\AuthenTec TrueSuite\KeepSafe\fvns.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-03-30 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-03-30 398616]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-03-30 439064]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-02-21 12452456]
"THXCfg64"="c:\windows\system32\THXCfg64.dll" [2010-09-14 25600]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-12-20 11406608]
"DeLay"="c:\program files (x86)\BisonCam\PID_0361\DeLay.exe" [2008-12-05 53248]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-08-27 1028896]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://fe.eng.usf.edu/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\3y43bv1n.default\
.
.
------- File Associations -------
.
JSEFile=c:\progra~2\PANDAS~1\PANDAA~1\PavScrip.exe "%1" %*
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-09-21  20:12:30
ComboFix-quarantined-files.txt  2013-09-22 03:12
ComboFix2.txt  2013-09-21 21:04
ComboFix3.txt  2013-09-21 20:49
.
Pre-Run: 330,383,224,832 bytes free
Post-Run: 330,082,807,808 bytes free
.
- - End Of File - - 4A6F3F3D6185AA58D0FEC2C37B2091E6
 

 

But, I have ran it since, and here is the most recent:

 

ComboFix 13-09-19.01 - Sean 09/22/2013  12:33:26.4.8 - x64 MINIMAL
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.8082.5755 [GMT -7:00]
Running from: c:\users\Sean\Desktop\ComboFix.exe
AV: Panda Antivirus Pro 2014 *Enabled/Updated* {86971480-9989-6750-B122-681A86518D59}
AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
SP: Panda Antivirus Pro 2014 *Enabled/Updated* {3DF6F564-BFB3-68DE-8B92-5368FDD6C7E4}
SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
.
(((((((((((((((((((((((((   Files Created from 2013-08-22 to 2013-09-22  )))))))))))))))))))))))))))))))
.
.
2013-09-22 19:36 . 2013-09-22 19:36    --------    d-----w-    c:\users\UpdatusUser\AppData\Local\temp
2013-09-22 19:36 . 2013-09-22 19:36    --------    d-----w-    c:\users\Default\AppData\Local\temp
2013-09-22 00:54 . 2013-09-22 00:54    --------    d-----w-    C:\Panda Software
2013-09-22 00:49 . 2013-09-22 00:49    --------    d-----w-    c:\users\Sean\AppData\Local\Macromedia
2013-09-22 00:48 . 2013-09-22 00:48    71048    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-22 00:48 . 2013-09-22 00:48    692616    ----a-w-    c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-22 00:46 . 2013-09-22 00:48    --------    d-----w-    c:\users\Sean\AppData\Local\Adobe
2013-09-22 00:02 . 2013-04-04 21:50    25928    ----a-w-    c:\windows\system32\drivers\mbam.sys
2013-09-21 23:07 . 2013-09-21 23:07    --------    d-----w-    c:\users\Sean\AppData\Local\Panda Security
2013-09-21 23:06 . 2010-06-23 01:20    30792    ----a-w-    c:\windows\system32\drivers\pavboot64.sys
2013-09-21 22:45 . 2013-09-21 22:45    --------    d-----w-    c:\program files\CCleaner
2013-09-21 22:37 . 2013-09-21 22:37    --------    d-----w-    c:\program files (x86)\Common Files\Panda Security
2013-09-21 22:12 . 2013-09-22 00:02    --------    d-----w-    c:\program files (x86)\Malwarebytes' Anti-Malware
2013-09-21 21:42 . 2013-09-21 21:58    --------    d-----w-    c:\programdata\HitmanPro
2013-09-21 21:29 . 2013-09-22 00:46    --------    d-----w-    c:\program files (x86)\Panda Security
2013-09-21 21:07 . 2013-09-21 21:07    --------    d-----w-    c:\program files (x86)\VS Revo Group
2013-09-21 20:32 . 2013-09-21 20:32    737072    ----a-w-    c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
2013-09-21 20:31 . 2013-09-21 20:31    2876528    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2013-09-21 20:31 . 2013-09-21 20:31    42776    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2013-09-21 20:31 . 2013-09-21 20:31    539984    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2013-09-21 20:31 . 2013-09-21 20:31    --------    d-----w-    c:\windows\ERUNT
2013-09-21 20:17 . 2013-09-21 22:27    --------    d-----w-    C:\AdwCleaner
2013-09-21 19:26 . 2013-09-02 00:08    79143768    ----a-w-    c:\windows\system32\MRT.exe
2013-09-21 07:32 . 2013-09-21 07:32    --------    d-----w-    c:\windows\SysWow64\BestPractices
2013-09-21 07:32 . 2013-09-21 07:32    --------    d-----w-    c:\windows\system32\BestPractices
2013-09-21 07:32 . 2013-09-21 07:32    --------    d-----w-    C:\inetpub
2013-09-21 06:43 . 2013-09-21 06:43    --------    d-----w-    c:\users\Sean\AppData\Local\NVIDIA
2013-09-21 06:40 . 2013-09-21 06:40    --------    d-----w-    c:\windows\SysWow64\NV
2013-09-21 06:40 . 2013-09-21 06:40    --------    d-----w-    c:\windows\system32\NV
2013-09-20 06:40 . 2013-09-20 06:40    --------    d-----w-    c:\users\Sean\AppData\Roaming\Malwarebytes
2013-09-20 06:40 . 2013-09-20 06:40    --------    d-----w-    c:\programdata\Malwarebytes
2013-09-20 06:37 . 2013-07-26 02:24    14172672    ----a-w-    c:\windows\system32\shell32.dll
2013-09-20 06:37 . 2013-07-26 02:24    197120    ----a-w-    c:\windows\system32\shdocvw.dll
2013-09-20 06:35 . 2013-09-20 06:35    --------    d-----w-    c:\users\Sean\AppData\Local\Mozilla
2013-09-20 06:35 . 2013-09-20 06:35    --------    d-----w-    c:\program files (x86)\Mozilla Maintenance Service
2013-09-11 04:47 . 2013-08-02 01:51    1292192    ----a-w-    c:\windows\SysWow64\ntdll.dll
2013-09-11 04:47 . 2013-08-02 00:59    112640    ----a-w-    c:\windows\system32\smss.exe
2013-09-11 04:47 . 2013-08-02 01:48    3584    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 04:47 . 2013-08-02 01:48    3072    ---ha-w-    c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 04:47 . 2013-08-08 01:20    3155456    ----a-w-    c:\windows\system32\win32k.sys
2013-08-27 23:30 . 2013-08-27 23:30    --------    d-----w-    c:\programdata\Package Cache
2013-08-27 23:16 . 2013-08-27 23:16    --------    d-----w-    c:\users\Sean\AppData\Local\Apps
2013-08-27 23:01 . 2013-09-20 06:32    --------    d-----w-    c:\program files (x86)\Common Files\Steam
2013-08-27 23:01 . 2013-09-21 22:46    --------    d-----w-    c:\program files (x86)\Steam
2013-08-26 18:55 . 2013-09-20 05:41    --------    d-----w-    c:\windows\system32\appmgmt
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-12 08:58 . 2012-12-21 22:27    2986672    ----a-w-    c:\windows\system32\nvapi64.dll
2013-09-12 08:58 . 2012-12-21 22:27    168616    ----a-w-    c:\windows\system32\nvinitx.dll
2013-09-12 08:58 . 2012-12-21 22:27    141336    ----a-w-    c:\windows\SysWow64\nvinit.dll
2013-09-12 08:58 . 2012-12-21 22:27    1412832    ----a-w-    c:\windows\system32\nvumdshimx.dll
2013-09-12 07:25 . 2012-12-21 22:28    6599968    ----a-w-    c:\windows\system32\nvcpl.dll
2013-09-12 07:25 . 2012-12-21 22:28    3452192    ----a-w-    c:\windows\system32\nvsvc64.dll
2013-09-12 07:25 . 2012-12-21 22:28    920864    ----a-w-    c:\windows\system32\nvvsvc.exe
2013-09-12 07:25 . 2012-12-21 22:28    67072    ----a-w-    c:\windows\system32\nv3dappshextr.dll
2013-09-12 07:25 . 2012-12-21 22:28    63776    ----a-w-    c:\windows\system32\nvshext.dll
2013-09-12 07:25 . 2012-12-21 22:28    2559776    ----a-w-    c:\windows\system32\nvsvcr.dll
2013-09-12 07:25 . 2012-12-21 22:28    219424    ----a-w-    c:\windows\system32\nvmctray.dll
2013-09-12 07:25 . 2012-12-21 22:28    1042208    ----a-w-    c:\windows\system32\nv3dappshext.dll
2013-09-11 22:06 . 2012-12-21 22:28    3361114    ----a-w-    c:\windows\system32\nvcoproc.bin
2013-08-20 20:42 . 2013-08-20 20:42    737072    ----a-w-    c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2013-08-20 20:42 . 2013-08-20 20:42    2876528    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2013-08-20 20:42 . 2013-08-20 20:42    42776    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2013-08-20 20:42 . 2013-08-20 20:42    539984    ----a-w-    c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2013-08-02 01:48 . 2013-09-20 06:38    44032    ----a-w-    c:\windows\apppatch\acwow64.dll
2013-07-25 09:25 . 2013-08-17 03:35    1888768    ----a-w-    c:\windows\system32\WMVDECOD.DLL
2013-07-25 08:57 . 2013-08-17 03:35    1620992    ----a-w-    c:\windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58 . 2013-08-17 03:35    2048    ----a-w-    c:\windows\system32\tzres.dll
2013-07-19 01:41 . 2013-08-17 03:35    2048    ----a-w-    c:\windows\SysWow64\tzres.dll
2013-07-09 05:52 . 2013-08-17 03:35    224256    ----a-w-    c:\windows\system32\wintrust.dll
2013-07-09 05:51 . 2013-08-17 03:35    1217024    ----a-w-    c:\windows\system32\rpcrt4.dll
2013-07-09 05:46 . 2013-08-17 03:35    1472512    ----a-w-    c:\windows\system32\crypt32.dll
2013-07-09 05:46 . 2013-08-17 03:35    184320    ----a-w-    c:\windows\system32\cryptsvc.dll
2013-07-09 05:46 . 2013-08-17 03:35    139776    ----a-w-    c:\windows\system32\cryptnet.dll
2013-07-09 04:52 . 2013-08-17 03:35    663552    ----a-w-    c:\windows\SysWow64\rpcrt4.dll
2013-07-09 04:52 . 2013-08-17 03:35    175104    ----a-w-    c:\windows\SysWow64\wintrust.dll
2013-07-09 04:46 . 2013-08-17 03:35    1166848    ----a-w-    c:\windows\SysWow64\crypt32.dll
2013-07-09 04:46 . 2013-08-17 03:35    140288    ----a-w-    c:\windows\SysWow64\cryptsvc.dll
2013-07-09 04:46 . 2013-08-17 03:35    103936    ----a-w-    c:\windows\SysWow64\cryptnet.dll
2013-07-06 06:03 . 2013-08-17 03:35    1910208    ----a-w-    c:\windows\system32\drivers\tcpip.sys
2011-08-05 19:56 . 2011-08-05 19:56    645856    ----a-w-    c:\program files\UIX.renderapi.dll
2011-08-05 19:56 . 2011-08-05 19:56    1530592    ----a-w-    c:\program files\UIX.dll
2011-08-05 19:56 . 2011-08-05 19:56    1288928    ----a-w-    c:\program files\UIXcontrols.dll
2011-08-05 19:56 . 2011-08-05 19:56    1272544    ----a-w-    c:\program files\ZuneShell.dll
2011-08-05 19:56 . 2011-08-05 19:56    1175264    ----a-w-    c:\program files\ZuneDBApi.dll
2011-08-05 19:53 . 2011-08-05 19:53    9440    ----a-w-    c:\program files\ZuneWmduResources.dll
2011-08-05 19:53 . 2011-08-05 19:53    863968    ----a-w-    c:\program files\ZuneWmdu.dll
2011-08-05 19:53 . 2011-08-05 19:53    74464    ----a-w-    c:\program files\ZuneShellExt.dll
2011-08-05 19:53 . 2011-08-05 19:53    507104    ----a-w-    c:\program files\ZuneSP.dll
2011-08-05 19:53 . 2011-08-05 19:53    467680    ----a-w-    c:\program files\ZuneWlanCfgSvc.exe
2011-08-05 19:53 . 2011-08-05 19:53    4020448    ----a-w-    c:\program files\ZuneSetup.exe
2011-08-05 19:53 . 2011-08-05 19:53    366816    ----a-w-    c:\program files\ZuneSrcWrp.dll
2011-08-05 19:53 . 2011-08-05 19:53    306400    ----a-w-    c:\program files\WMZuneComm.exe
2011-08-05 19:53 . 2011-08-05 19:53    27872    ----a-w-    c:\program files\WMZuneTCP2UDP.dll
2011-08-05 19:53 . 2011-08-05 19:53    21216    ----a-w-    c:\program files\WMZuneDTPTDNS.dll
2011-08-05 19:53 . 2011-08-05 19:53    196832    ----a-w-    c:\program files\ZuneZMDB.Mobile.dll
2011-08-05 19:53 . 2011-08-05 19:53    18656    ----a-w-    c:\program files\WMZuneCommProxyStub.dll
2011-08-05 19:53 . 2011-08-05 19:53    17632    ----a-w-    c:\program files\ZuneShare.exe
2011-08-05 19:53 . 2011-08-05 19:53    16921312    ----a-w-    c:\program files\ZuneShellResources.dll
2011-08-05 19:53 . 2011-08-05 19:53    157920    ----a-w-    c:\program files\ZuneZMDB.Library.dll
2011-08-05 19:53 . 2011-08-05 19:53    157408    ----a-w-    c:\program files\ZuneZMDB.ZuneHD.dll
2011-08-05 19:53 . 2011-08-05 19:53    152288    ----a-w-    c:\program files\ZuneZMDB.Classic.dll
2011-08-05 19:53 . 2011-08-05 19:53    100064    ----a-w-    c:\program files\ZuneTaskbar.dll
2011-08-05 19:53 . 2011-08-05 19:53    916704    ----a-w-    c:\program files\ZuneQP.dll
2011-08-05 19:53 . 2011-08-05 19:53    683744    ----a-w-    c:\program files\ZuneSH.dll
2011-08-05 19:53 . 2011-08-05 19:53    514272    ----a-w-    c:\program files\ZuneSE.dll
2011-08-05 19:53 . 2011-08-05 19:53    3889376    ----a-w-    c:\program files\ZuneResources.dll
2011-08-05 19:53 . 2011-08-05 19:53    155872    ----a-w-    c:\program files\ZuneSA.dll
2011-08-05 19:53 . 2011-08-05 19:53    1257184    ----a-w-    c:\program files\ZuneService.dll
2011-08-05 19:53 . 2011-08-05 19:53    879328    ----a-w-    c:\program files\ZuneMBR.dll
2011-08-05 19:53 . 2011-08-05 19:53    8277728    ----a-w-    c:\program files\ZuneNss.exe
2011-08-05 19:53 . 2011-08-05 19:53    72928    ----a-w-    c:\program files\ZuneDXVA2.dll
2011-08-05 19:53 . 2011-08-05 19:53    707808    ----a-w-    c:\program files\ZUNEMP4SDECD.dll
2011-08-05 19:53 . 2011-08-05 19:53    61664    ----a-w-    c:\program files\ZuneCfg.dll
2011-08-05 19:53 . 2011-08-05 19:53    56544    ----a-w-    c:\program files\ZuneConfig.exe
2011-08-05 19:53 . 2011-08-05 19:53    38624    ----a-w-    c:\program files\ZuneEnc.exe
2011-08-05 19:53 . 2011-08-05 19:53    376544    ----a-w-    c:\program files\ZuneEvr.dll
2011-08-05 19:53 . 2011-08-05 19:53    35552    ----a-w-    c:\program files\UIXsup.dll
2011-08-05 19:53 . 2011-08-05 19:53    347872    ----a-w-    c:\program files\ZuneNssci.dll
2011-08-05 19:53 . 2011-08-05 19:53    223968    ----a-w-    c:\program files\Zune.exe
2011-08-05 19:53 . 2011-08-05 19:53    218848    ----a-w-    c:\program files\ZuneHost.exe
2011-08-05 19:53 . 2011-08-05 19:53    212192    ----a-w-    c:\program files\ZuneDB.dll
2011-08-05 19:53 . 2011-08-05 19:53    2110176    ----a-w-    c:\program files\ZuneEncEng.dll
2011-08-05 19:53 . 2011-08-05 19:53    20704    ----a-w-    c:\program files\ZunePS.dll
2011-08-05 19:53 . 2011-08-05 19:53    1752288    ----a-w-    c:\program files\UIXrender.dll
2011-08-05 19:53 . 2011-08-05 19:53    163552    ----a-w-    c:\program files\ZuneLauncher.exe
2011-08-05 19:53 . 2011-08-05 19:53    1481440    ----a-w-    c:\program files\ZuneCore.dll
2011-08-05 19:53 . 2011-08-05 19:53    131296    ----a-w-    c:\program files\ZunePresenter.dll
2011-08-05 19:53 . 2011-08-05 19:53    129248    ----a-w-    c:\program files\ZuneEffects.dll
2011-08-05 19:53 . 2011-08-05 19:53    121056    ----a-w-    c:\program files\ZuneAACDec.dll
2011-08-05 19:53 . 2011-08-05 19:53    1184480    ----a-w-    c:\program files\ZuneH264Dec.dll
2011-08-05 19:53 . 2011-08-05 19:53    1161440    ----a-w-    c:\program files\ZuneMde.dll
2011-08-05 19:53 . 2011-08-05 19:53    1096928    ----a-w-    c:\program files\ZuneMarketplaceResources.dll
2011-08-05 19:53 . 2011-08-05 19:53    10061536    ----a-w-    c:\program files\ZuneNativeLib.dll
2011-08-05 19:31 . 2011-08-05 19:31    182784    ----a-w-    c:\program files\l3codecp.acm
2011-06-06 20:48 . 2011-06-06 20:48    856576    ----a-w-    c:\program files\msvcp90.dll
2011-06-06 20:48 . 2011-06-06 20:48    626688    ----a-w-    c:\program files\msvcr90.dll
2011-06-06 20:48 . 2011-06-06 20:48    245760    ----a-w-    c:\program files\msvcm90.dll
2007-10-02 21:12 . 2007-10-02 21:12    1642568    ----a-w-    c:\program files\msidcrl40.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe" [2012-07-17 56128]
"THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe" [2010-11-01 1374720]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"USB3MON"="c:\program files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-05-20 291648]
"ccApp"="c:\program files (x86)\Common Files\Symantec Shared\ccApp.exe" [2010-07-24 115560]
"APVXDWIN"="c:\program files (x86)\Panda Security\Panda Antivirus Pro 2014\APVXDWIN.EXE" [2013-07-05 1062880]
"SCANINICIO"="c:\program files (x86)\Panda Security\Panda Antivirus Pro 2014\Inicio.exe" [2012-11-08 70432]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Hotkey.lnk - c:\program files (x86)\Hotkey\Hotkey.exe [2012-7-26 4730880]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
R0 pavboot;Panda boot driver;c:\windows\system32\Drivers\pavboot64.sys;c:\windows\SYSNATIVE\Drivers\pavboot64.sys [x]
R1 ShldFlt;Panda File Shield Driver;c:\windows\system32\DRIVERS\ShldFlt.sys;c:\windows\SYSNATIVE\DRIVERS\ShldFlt.sys [x]
R2 AmFSM;AmFSM;c:\windows\system32\DRIVERS\amm6460.sys;c:\windows\SYSNATIVE\DRIVERS\amm6460.sys [x]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
R2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 FPLService;TrueSuiteService;c:\program files\AuthenTec TrueSuite\TrueSuiteService.exe;c:\program files\AuthenTec TrueSuite\TrueSuiteService.exe [x]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
R2 Intel® ME Service;Intel® ME Service;c:\program files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [x]
R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [x]
R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R2 NIApplicationWebServer;NI Application Web Server;c:\program files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe;c:\program files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [x]
R2 nimDNSResponder;National Instruments mDNS Responder Service;c:\program files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe;c:\program files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [x]
R2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
R2 PowerBiosServer;PowerBiosServer;c:\program files (x86)\Hotkey\PowerBiosServer.exe;c:\program files (x86)\Hotkey\PowerBiosServer.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x]
R2 ZeroConfigService;Intel® PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x]
R3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]
R3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
R3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 PavTPK.sys;PavTPK.sys;c:\windows\system32\PavTPK.sys;c:\windows\SYSNATIVE\PavTPK.sys [x]
R3 RSBASTOR;Realtek PCIE CardReader Driver - BA;c:\windows\system32\DRIVERS\RtsBaStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsBaStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 NIApplicationWebServer64;NI Application Web Server (64-bit);c:\program files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe;c:\program files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [x]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
S0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S2 PskSvcRetail;Panda PSK service;c:\program files (x86)\Panda Security\Panda Antivirus Pro 2014\PskSvc.exe;c:\program files (x86)\Panda Security\Panda Antivirus Pro 2014\PskSvc.exe [x]
S3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs    REG_MULTI_SZ       w3svc was
apphost    REG_MULTI_SZ       apphostsvc
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{BC6D10E6-AE59-4cef-83DB-FD4C9BC7B7F2}"
[HKEY_CLASSES_ROOT\CLSID\{BC6D10E6-AE59-4cef-83DB-FD4C9BC7B7F2}]
2011-10-21 22:00    4014408    ----a-w-    c:\program files\AuthenTec TrueSuite\KeepSafe\fvns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{93BB455E-3D52-4fba-9733-E5103B30FC12}"
[HKEY_CLASSES_ROOT\CLSID\{93BB455E-3D52-4fba-9733-E5103B30FC12}]
2011-10-21 22:00    4014408    ----a-w-    c:\program files\AuthenTec TrueSuite\KeepSafe\fvns.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-03-30 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-03-30 398616]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-03-30 439064]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-02-21 12452456]
"THXCfg64"="c:\windows\system32\THXCfg64.dll" [2010-09-14 25600]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-12-20 11406608]
"DeLay"="c:\program files (x86)\BisonCam\PID_0361\DeLay.exe" [2008-12-05 53248]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-08-27 1028896]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://fe.eng.usf.edu/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\3y43bv1n.default\
.
.
------- File Associations -------
.
JSEFile=c:\progra~2\PANDAS~1\PANDAA~1\PavScrip.exe "%1" %*
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-09-22  12:37:38
ComboFix-quarantined-files.txt  2013-09-22 19:37
ComboFix2.txt  2013-09-22 03:12
ComboFix3.txt  2013-09-21 21:04
ComboFix4.txt  2013-09-21 20:49
.
Pre-Run: 329,959,878,656 bytes free
Post-Run: 329,665,536,000 bytes free
.
- - End Of File - - 1A20372A221CB146E965DD17238FCDC9
 



#4 Krampus1

Krampus1
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 23 September 2013 - 03:08 PM

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-09-2013
Ran by Sean (administrator) on SEAN-PC on 23-09-2013 13:03:43
Running from C:\Users\Sean\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AuthenTec, Inc) C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PskSvc.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\TPSrvWow.exe
(Panda Security) C:\PROGRAM FILES (X86)\PANDA SECURITY\PANDA ANTIVIRUS PRO 2014\WebProxy.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Symantec Corporation) C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel® Corporation) c:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(National Instruments, Inc.) C:\Windows\SysWOW64\lkcitdl.exe
(National Instruments Corporation) C:\Windows\SysWOW64\lkads.exe
(National Instruments Corporation) C:\Windows\SysWOW64\lktsrv.exe
(Microsoft Corporation) c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SmcGui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Bison Inc.) C:\Program Files (x86)\BisonCam\PID_0361\DeLay.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
() C:\Program Files (x86)\Hotkey\Hotkey.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PsCtrls.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PavFnSvr.exe
(Panda Security, S.L.) C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\pavsrvx86.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\AVENGINE.EXE
() c:\Program Files (x86)\Hotkey\PowerBiosServer.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Symantec Corporation) C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\ApVxdWin.exe
(Panda Security S.L.) C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PsImSvc.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel® Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
() C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\system32\msiexec.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(AuthenTec Inc.) C:\Program Files\AuthenTec TrueSuite\TouchControl.exe
(AuthenTec Inc.) C:\Program Files\AuthenTec TrueSuite\BioMonitor.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12452456 2012-02-21] (Realtek Semiconductor)
HKLM\...\Run: [THXCfg64] - C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2905912 2012-06-28] (Synaptics Incorporated)
HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [DeLay] - C:\Program Files (x86)\BisonCam\PID_0361\DeLay.exe [53248 2008-12-05] (Bison Inc.)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation)
Winlogon\Notify\avldr: C:\Windows\system32\avldr64.dll (On-Access Anti-Malware Scanner Sync)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation)
HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe [1374720 2010-11-01] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] - C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM-x32\...\Run: [ccApp] - C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe [115560 2010-07-23] (Symantec Corporation)
HKLM-x32\...\Run: [APVXDWIN] - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\APVXDWIN.EXE [1062880 2013-07-05] (Panda Security, S.L.)
HKLM-x32\...\Run: [SCANINICIO] - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\Inicio.exe [70432 2012-11-08] (Panda Security, S.L.)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [168616 2013-09-12] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [141336 2013-09-12] (NVIDIA Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fe.eng.usf.edu/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x13902E0524EACD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\IEBHO.dll (AuthenTec Inc.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll No File
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\x86\IEBHO.dll (AuthenTec Inc.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll No File
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll No File
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 08 C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll File Not found ()
Winsock: Catalog5-x64 08 C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll [26328] (National Instruments Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\3y43bv1n.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.11.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5

==================== Services (Whitelisted) =================

R2 ccEvtMgr; C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe [108392 2010-07-23] (Symantec Corporation)
R2 ccSetMgr; C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe [108392 2010-07-23] (Symantec Corporation)
R2 FPLService; C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe [299848 2011-11-03] (AuthenTec, Inc)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-05-15] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [165144 2012-05-15] (Intel Corporation)
S3 LiveUpdate; C:\PROGRA~2\Symantec\LIVEUP~1\LUCOMS~1.EXE [3093880 2010-02-17] (Symantec Corporation)
R2 LkCitadelServer; C:\Windows\SysWOW64\lkcitdl.exe [695136 2010-03-05] (National Instruments, Inc.)
R2 lkClassAds; C:\Windows\SysWOW64\lkads.exe [45168 2010-06-16] (National Instruments Corporation)
R2 lkTimeSync; C:\Windows\SysWOW64\lktsrv.exe [55416 2010-06-16] (National Instruments Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] ()
S4 NIApplicationWebServer64; C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [63648 2010-06-22] (National Instruments Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation)
R2 Panda Software Controller; C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PsCtrls.exe [177440 2012-11-19] (Panda Security, S.L.)
R2 PAVFNSVR; C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PavFnSvr.exe [202016 2012-09-21] (Panda Security, S.L.)
R2 PavPrSrv; C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe [62768 2008-02-04] (Panda Security, S.L.)
R2 PAVSRV; C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\pavsrvx86.exe [313664 2011-04-13] (Panda Security, S.L.)
R2 PowerBiosServer; c:\Program Files (x86)\Hotkey\PowerBiosServer.exe [35328 2012-05-22] ()
R2 PSIMSVC; C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PsImSvc.exe [108288 2008-06-19] (Panda Security S.L.)
R2 PskSvcRetail; C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PskSvc.exe [28992 2010-08-16] (Panda Security, S.L.)
R2 SmcService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe [3217344 2010-07-23] (Symantec Corporation)
S4 SNAC; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SNAC64.EXE [419656 2010-07-23] (Symantec Corporation)
R2 Symantec AntiVirus; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe [1822296 2010-07-23] (Symantec Corporation)
R2 TPSrv; C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\TPSrvWow.exe [173344 2012-11-16] (Panda Security, S.L.)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
S3 WMZuneComm; C:\Program Files\WMZuneComm.exe [306400 2011-08-05] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation)
S3 ZuneNetworkSvc; C:\Program Files\ZuneNss.exe [8277728 2011-08-05] (Microsoft Corporation)
S3 ZuneWlanCfgSvc; C:\Program Files\ZuneWlanCfgSvc.exe [467680 2011-08-05] (Microsoft Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [x]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [x]
S3 gusvc; "C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe" [x]
S2 mxssvr; "C:\Program Files (x86)\National Instruments\MAX\nimxs.exe" [x]
S2 NIApplicationWebServer; "C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe" -user [x]
S2 NIDomainService; "C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe" [x]
S4 NILM License Manager; "C:\Program Files (x86)\National Instruments\Shared\License Manager\Bin\lmgrd.exe" [x]
S2 nimDNSResponder; "C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe" [x]
S2 niSvcLoc; "C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe" -system [x]
S2 NITaggerService; "C:\Program Files (x86)\National Instruments\Shared\Tagger\tagsrv.exe" [x]

==================== Drivers (Whitelisted) ====================

R2 AmFSM; C:\Windows\System32\DRIVERS\amm6460.sys [71432 2012-03-26] (Panda Security, S.L.)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-26] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-26] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-08-26] (Symantec Corporation)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [27456 2012-07-09] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NAVENG; C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20130922.002\ENG64.SYS [126040 2013-09-16] (Symantec Corporation)
R3 NAVENG; C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20130922.002\ENG64.SYS [126040 2013-09-16] (Symantec Corporation)
R3 NAVEX15; C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20130922.002\EX64.SYS [2099288 2013-09-16] (Symantec Corporation)
R3 NAVEX15; C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20130922.002\EX64.SYS [2099288 2013-09-16] (Symantec Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation)
R0 pavboot; C:\Windows\System32\Drivers\pavboot64.sys [30792 2010-06-22] (Panda Security, S.L.)
R1 ShldFlt; C:\Windows\System32\DRIVERS\ShldFlt.sys [48136 2009-10-27] (Panda Security, S.L.)
R1 SRTSP; C:\Windows\System32\Drivers\SRTSP64.SYS [447536 2010-07-23] (Symantec Corporation)
R1 SRTSP; C:\Windows\SysWow64\Drivers\SRTSP64.SYS [447536 2010-07-23] (Symantec Corporation)
S3 SRTSPL; C:\Windows\System32\Drivers\SRTSPL64.SYS [482352 2010-07-23] (Symantec Corporation)
S3 SRTSPL; C:\Windows\SysWow64\Drivers\SRTSPL64.SYS [482352 2010-07-23] (Symantec Corporation)
R1 SRTSPX; C:\Windows\System32\Drivers\SRTSPX64.SYS [32304 2010-07-23] (Symantec Corporation)
R1 SRTSPX; C:\Windows\SysWow64\Drivers\SRTSPX64.SYS [32304 2010-07-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [172592 2013-01-20] (Symantec Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
R3 PavTPK.sys; \??\C:\Windows\system32\PavTPK.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-23 13:02 - 2013-09-23 13:02 - 01955550 _____ (Farbar) C:\Users\Sean\Downloads\FRST64.exe
2013-09-23 13:02 - 2013-09-23 13:02 - 00000000 ____D C:\FRST
2013-09-22 19:00 - 2013-09-22 19:00 - 00688992 ____R (Swearware) C:\Users\Sean\Downloads\dds(1).com
2013-09-22 16:26 - 2013-09-23 13:04 - 00239977 _____ C:\Windows\WindowsUpdate.log
2013-09-22 16:23 - 2013-09-23 02:02 - 00000280 _____ C:\Windows\setupact.log
2013-09-22 16:23 - 2013-09-22 16:23 - 00000000 _____ C:\Windows\setuperr.log
2013-09-22 16:22 - 2013-09-22 16:22 - 00000998 _____ C:\Windows\PFRO.log
2013-09-22 12:37 - 2013-09-22 12:37 - 00026266 _____ C:\ComboFix.txt
2013-09-21 18:10 - 2013-09-22 19:09 - 00021693 _____ C:\Users\Sean\Desktop\attach.txt
2013-09-21 18:10 - 2013-09-22 19:08 - 00029061 _____ C:\Users\Sean\Desktop\dds.txt
2013-09-21 18:09 - 2013-09-21 18:08 - 00688992 ____R (Swearware) C:\Users\Sean\Desktop\dds.com
2013-09-21 17:54 - 2013-09-21 17:54 - 00000000 ____D C:\Panda Software
2013-09-21 17:49 - 2013-09-21 17:49 - 00000000 ____D C:\Users\Sean\AppData\Local\Macromedia
2013-09-21 17:48 - 2013-09-21 17:48 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-21 17:48 - 2013-09-21 17:48 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-21 17:46 - 2013-09-21 17:48 - 00000000 ____D C:\Users\Sean\AppData\Local\Adobe
2013-09-21 17:46 - 2013-09-21 17:46 - 00001293 _____ C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk
2013-09-21 17:02 - 2013-09-21 17:02 - 00001120 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-21 17:02 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-09-21 16:58 - 2013-09-21 17:00 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Sean\Downloads\mbam-setup-1.75.0.1300(3).exe
2013-09-21 16:54 - 2013-09-21 16:54 - 00000000 ____D C:\Windows\pss
2013-09-21 16:10 - 2013-09-21 16:36 - 00008627 _____ C:\Windows\SysWOW64\PAV_FOG.OPC
2013-09-21 16:07 - 2013-09-21 16:07 - 00000000 ____D C:\Users\Sean\AppData\Local\Panda Security
2013-09-21 16:06 - 2013-09-21 16:06 - 00002222 _____ C:\Users\Public\Desktop\Panda Antivirus Pro 2014.lnk
2013-09-21 16:06 - 2013-09-21 16:06 - 00000262 _____ C:\Windows\system32\PavCPL64.dat
2013-09-21 16:06 - 2010-06-22 18:20 - 00030792 _____ (Panda Security, S.L.) C:\Windows\system32\Drivers\pavboot64.sys
2013-09-21 16:05 - 2013-09-21 16:05 - 00000000 ____D C:\Windows\SysWOW64\PAV
2013-09-21 16:05 - 2013-09-21 16:05 - 00000000 ____D C:\Users\Sean\AppData\Roaming\Panda Security
2013-09-21 16:05 - 2013-09-21 16:05 - 00000000 ____D C:\ProgramData\Panda Security
2013-09-21 16:05 - 2013-06-25 17:03 - 00024544 _____ (Panda Security, S.L.) C:\Windows\system32\sysHelper64.dll
2013-09-21 16:05 - 2012-11-20 12:20 - 00545056 _____ (Panda Security, S.L.) C:\Windows\SysWOW64\PavSHookWow.dll
2013-09-21 16:05 - 2012-11-16 12:08 - 00837920 _____ (Panda Security, S.L.) C:\Windows\system32\PavSHook64.dll
2013-09-21 16:05 - 2012-05-22 15:54 - 00087328 _____ (Panda Security, S.L.) C:\Windows\SysWOW64\PavLspHookWow.dll
2013-09-21 16:05 - 2012-05-22 15:52 - 00117024 _____ (Panda Security, S.L.) C:\Windows\system32\PavLspHook64.dll
2013-09-21 16:05 - 2012-03-26 18:57 - 00071432 _____ (Panda Security, S.L.) C:\Windows\system32\Drivers\amm6460.sys
2013-09-21 16:05 - 2010-06-21 17:02 - 00323392 _____ (Panda Security, S.L.) C:\Windows\system32\TpUtil64.dll
2013-09-21 16:05 - 2010-06-21 17:02 - 00202048 _____ (Panda Security, S.L.) C:\Windows\SysWOW64\TpUtilWow.dll
2013-09-21 16:05 - 2010-06-21 17:01 - 00090944 _____ (Panda Security, S.L.) C:\Windows\system32\PavIpc64.dll
2013-09-21 16:05 - 2010-06-21 17:01 - 00066880 _____ (Panda Security, S.L.) C:\Windows\SysWOW64\PavIpcWow.dll
2013-09-21 16:05 - 2010-03-24 12:56 - 00064768 _____ (On-Access Anti-Malware Scanner Sync) C:\Windows\system32\avldr64.dll
2013-09-21 16:05 - 2009-10-27 12:07 - 00048136 _____ (Panda Security, S.L.) C:\Windows\system32\Drivers\ShldFlt.sys
2013-09-21 16:05 - 2009-08-10 13:46 - 00025344 _____ (Panda Security, S.L.) C:\Windows\SysWOW64\sysHelper32.dll
2013-09-21 16:05 - 2007-03-15 19:38 - 00046640 _____ (Panda Software) C:\Windows\system32\pavcpl64.cpl
2013-09-21 16:05 - 2003-10-22 18:23 - 00446464 _____ (eHelp Corporation.) C:\Windows\SysWOW64\HHActiveX.dll
2013-09-21 16:03 - 2013-09-21 16:04 - 99195296 _____ C:\Users\Sean\Downloads\AP14ESD(1).exe
2013-09-21 16:01 - 2013-09-21 16:01 - 01062728 _____ C:\Users\Sean\Downloads\PANDAAP14(3).exe
2013-09-21 15:55 - 2013-09-21 15:55 - 00001459 _____ C:\Users\Sean\Desktop\RKreport[0]_S_09212013_155531.txt
2013-09-21 15:54 - 2013-09-21 15:54 - 00001910 _____ C:\Users\Sean\Desktop\RKreport[0]_D_09212013_155432.txt
2013-09-21 15:53 - 2013-09-21 15:53 - 00001808 _____ C:\Users\Sean\Desktop\RKreport[0]_S_09212013_155358.txt
2013-09-21 15:52 - 2013-09-21 23:41 - 00000000 ____D C:\Users\Sean\Desktop\RK_Quarantine
2013-09-21 15:51 - 2013-09-21 15:52 - 03812352 _____ C:\Users\Sean\Downloads\RogueKillerX64.exe
2013-09-21 15:48 - 2013-09-21 15:48 - 01062728 _____ C:\Users\Sean\Downloads\PANDAAP14(2).exe
2013-09-21 15:47 - 2013-09-21 15:47 - 00808224 _____ C:\Users\Sean\Downloads\PandaCloudAntivirus.exe
2013-09-21 15:45 - 2013-09-21 15:45 - 00002770 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-09-21 15:45 - 2013-09-21 15:45 - 00000829 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-09-21 15:45 - 2013-09-21 15:45 - 00000000 ____D C:\Program Files\CCleaner
2013-09-21 15:44 - 2013-09-21 15:44 - 04454952 _____ (Piriform Ltd) C:\Users\Sean\Downloads\ccsetup405.exe
2013-09-21 15:40 - 2013-09-21 15:40 - 99195296 _____ C:\Users\Sean\Downloads\AP14ESD.exe
2013-09-21 15:12 - 2013-09-21 17:02 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-21 15:09 - 2013-09-21 15:09 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Sean\Downloads\mbam-setup-1.75.0.1300(2).exe
2013-09-21 15:08 - 2013-09-21 15:08 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Sean\Downloads\mbam-setup-1.75.0.1300(1).exe
2013-09-21 14:42 - 2013-09-21 14:58 - 00000000 ____D C:\ProgramData\HitmanPro
2013-09-21 14:39 - 2013-09-21 14:42 - 09879648 _____ (SurfRight B.V.) C:\Users\Sean\Downloads\HitmanPro_x64.exe
2013-09-21 14:34 - 2013-09-21 14:34 - 01062728 _____ C:\Users\Sean\Downloads\PANDAAP14(1).exe
2013-09-21 14:30 - 2013-09-21 14:32 - 99195296 _____ C:\Users\Sean\Downloads\AP14.exe
2013-09-21 14:29 - 2013-09-21 17:46 - 00000000 ____D C:\Program Files (x86)\Panda Security
2013-09-21 14:28 - 2013-09-21 14:28 - 01062728 _____ C:\Users\Sean\Downloads\PANDAAP14.exe
2013-09-21 14:23 - 2013-09-21 14:23 - 00000000 ____D C:\Users\Sean\AppData\Roaming\Adobe
2013-09-21 14:15 - 2013-09-21 14:15 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Sean\Downloads\revosetup(1).exe
2013-09-21 14:07 - 2013-09-21 14:07 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Sean\Downloads\revosetup.exe
2013-09-21 14:07 - 2013-09-21 14:07 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2013-09-21 13:55 - 2013-09-21 13:40 - 05128554 ____R (Swearware) C:\Users\Sean\Desktop\ComboFix.exe
2013-09-21 13:43 - 2011-06-25 23:45 - 00256000 _____ C:\Windows\PEV.exe
2013-09-21 13:43 - 2010-11-07 10:20 - 00208896 _____ C:\Windows\MBR.exe
2013-09-21 13:43 - 2009-04-19 21:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-09-21 13:43 - 2000-08-30 17:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-09-21 13:43 - 2000-08-30 17:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-09-21 13:43 - 2000-08-30 17:00 - 00098816 _____ C:\Windows\sed.exe
2013-09-21 13:43 - 2000-08-30 17:00 - 00080412 _____ C:\Windows\grep.exe
2013-09-21 13:43 - 2000-08-30 17:00 - 00068096 _____ C:\Windows\zip.exe
2013-09-21 13:42 - 2013-09-22 12:37 - 00000000 ____D C:\Qoobox
2013-09-21 13:42 - 2013-09-21 13:49 - 00000000 ____D C:\Windows\erdnt
2013-09-21 13:40 - 2013-09-21 13:40 - 05128554 ____R (Swearware) C:\Users\Sean\Downloads\ComboFix.exe
2013-09-21 13:35 - 2013-09-21 13:35 - 00000802 _____ C:\Users\Sean\Desktop\JRT.txt
2013-09-21 13:31 - 2013-09-21 13:31 - 00000000 ____D C:\Windows\ERUNT
2013-09-21 13:18 - 2013-09-21 13:18 - 01029675 _____ (Thisisu) C:\Users\Sean\Downloads\JRT.exe
2013-09-21 13:17 - 2013-09-21 15:27 - 00000000 ____D C:\AdwCleaner
2013-09-21 13:16 - 2013-09-21 13:16 - 01039554 _____ C:\Users\Sean\Downloads\AdwCleaner.exe
2013-09-21 12:26 - 2013-09-01 17:08 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-21 01:12 - 2013-09-21 01:50 - 00007611 _____ C:\Users\Sean\AppData\Local\Resmon.ResmonCfg
2013-09-21 00:34 - 2013-09-21 00:34 - 00003128 _____ C:\Windows\System32\Tasks\{C24BA02D-0ACF-473B-BFB8-72FE646F0C70}
2013-09-21 00:32 - 2013-09-21 00:32 - 00000000 ____D C:\Windows\SysWOW64\BestPractices
2013-09-21 00:32 - 2013-09-21 00:32 - 00000000 ____D C:\Windows\system32\BestPractices
2013-09-21 00:32 - 2013-09-21 00:32 - 00000000 ____D C:\inetpub
2013-09-20 23:43 - 2013-09-20 23:43 - 00000000 ____D C:\Users\Sean\AppData\Local\NVIDIA
2013-09-20 23:40 - 2013-09-20 23:40 - 00000000 ____D C:\Windows\SysWOW64\NV
2013-09-20 23:40 - 2013-09-20 23:40 - 00000000 ____D C:\Windows\system32\NV
2013-09-20 23:36 - 2013-09-12 01:58 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 15901448 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 12947360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-09-20 23:36 - 2013-09-12 01:58 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 02630304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 00458528 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 00388384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-09-20 23:36 - 2013-09-12 01:58 - 00032032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
2013-09-20 23:36 - 2013-08-20 06:33 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2013-09-20 23:36 - 2013-08-20 06:32 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2013-09-20 23:36 - 2013-08-20 06:32 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2013-09-20 22:54 - 2013-09-20 23:10 - 246695752 _____ (NVIDIA Corporation) C:\Users\Sean\Downloads\327.23-notebook-win8-win7-64bit-international-whql.exe
2013-09-20 04:01 - 2013-08-09 22:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-20 04:01 - 2013-08-09 22:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-20 04:01 - 2013-08-09 22:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-20 04:01 - 2013-08-09 22:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-20 04:01 - 2013-08-09 22:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-20 04:01 - 2013-08-09 22:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-20 04:01 - 2013-08-09 22:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-20 04:01 - 2013-08-09 22:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-20 04:01 - 2013-08-09 22:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-20 04:01 - 2013-08-09 22:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-20 04:01 - 2013-08-09 22:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-20 04:01 - 2013-08-09 22:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-20 04:01 - 2013-08-09 22:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-20 04:01 - 2013-08-09 22:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-20 04:01 - 2013-08-09 20:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-20 04:01 - 2013-08-09 20:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-20 04:01 - 2013-08-09 20:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-20 04:01 - 2013-08-09 20:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-20 04:01 - 2013-08-09 20:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-20 04:01 - 2013-08-09 20:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-20 04:01 - 2013-08-09 20:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-20 04:01 - 2013-08-09 20:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-20 04:01 - 2013-08-09 20:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-20 04:01 - 2013-08-09 20:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-20 04:01 - 2013-08-09 20:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-20 04:01 - 2013-08-09 20:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-20 04:01 - 2013-08-09 20:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-20 04:01 - 2013-08-09 20:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-20 04:01 - 2013-08-09 20:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-20 04:01 - 2013-08-09 19:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-20 04:01 - 2013-08-09 19:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-19 23:40 - 2013-09-19 23:40 - 00000000 ____D C:\Users\Sean\AppData\Roaming\Malwarebytes
2013-09-19 23:40 - 2013-09-19 23:40 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-19 23:39 - 2013-09-19 23:39 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Sean\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-19 23:38 - 2013-08-04 19:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-19 23:38 - 2013-08-01 19:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-19 23:38 - 2013-08-01 19:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-19 23:38 - 2013-08-01 19:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-19 23:38 - 2013-08-01 19:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-19 23:38 - 2013-08-01 19:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-19 23:38 - 2013-08-01 19:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-19 23:38 - 2013-08-01 19:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-19 23:38 - 2013-08-01 19:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-19 23:38 - 2013-08-01 19:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-19 23:38 - 2013-08-01 18:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-19 23:38 - 2013-08-01 18:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-19 23:38 - 2013-08-01 18:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-19 23:38 - 2013-08-01 18:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 18:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-19 23:38 - 2013-08-01 17:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-19 23:38 - 2013-08-01 17:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-19 23:38 - 2013-08-01 17:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-19 23:38 - 2013-08-01 17:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-19 23:38 - 2013-08-01 17:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 17:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 17:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-19 23:38 - 2013-08-01 17:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-19 23:37 - 2013-07-25 19:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-19 23:37 - 2013-07-25 19:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-19 23:37 - 2013-07-25 18:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-19 23:37 - 2013-07-25 18:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-09-19 23:35 - 2013-09-22 19:07 - 00000000 ____D C:\Users\Sean\AppData\Local\Mozilla
2013-09-19 23:35 - 2013-09-19 23:35 - 00001158 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-19 23:35 - 2013-09-19 23:35 - 00000000 ____D C:\Users\Sean\AppData\Roaming\Mozilla
2013-09-19 23:35 - 2013-09-19 23:35 - 00000000 ____D C:\ProgramData\Mozilla
2013-09-19 23:35 - 2013-09-19 23:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-19 23:35 - 2013-09-19 23:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-10 21:47 - 2013-08-07 18:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-10 21:47 - 2013-08-01 18:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-10 21:47 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-10 21:47 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-10 21:47 - 2013-08-01 17:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-08-27 16:31 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2013-08-27 16:31 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2013-08-27 16:31 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2013-08-27 16:31 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2013-08-27 16:31 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2013-08-27 16:31 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2013-08-27 16:31 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2013-08-27 16:31 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2013-08-27 16:31 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2013-08-27 16:31 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2013-08-27 16:31 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2013-08-27 16:31 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2013-08-27 16:31 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2013-08-27 16:31 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2013-08-27 16:31 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2013-08-27 16:31 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2013-08-27 16:31 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2013-08-27 16:31 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2013-08-27 16:31 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2013-08-27 16:31 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2013-08-27 16:31 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2013-08-27 16:31 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2013-08-27 16:31 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2013-08-27 16:31 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2013-08-27 16:31 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2013-08-27 16:31 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2013-08-27 16:31 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2013-08-27 16:31 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2013-08-27 16:31 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2013-08-27 16:31 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2013-08-27 16:31 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2013-08-27 16:31 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2013-08-27 16:31 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2013-08-27 16:31 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2013-08-27 16:31 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2013-08-27 16:31 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2013-08-27 16:31 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2013-08-27 16:31 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2013-08-27 16:31 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2013-08-27 16:31 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2013-08-27 16:31 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2013-08-27 16:31 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2013-08-27 16:31 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2013-08-27 16:31 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2013-08-27 16:31 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2013-08-27 16:31 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2013-08-27 16:31 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2013-08-27 16:31 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2013-08-27 16:31 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2013-08-27 16:31 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2013-08-27 16:31 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2013-08-27 16:31 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2013-08-27 16:31 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2013-08-27 16:31 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2013-08-27 16:31 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2013-08-27 16:31 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2013-08-27 16:31 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2013-08-27 16:31 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2013-08-27 16:31 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2013-08-27 16:31 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2013-08-27 16:31 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2013-08-27 16:31 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2013-08-27 16:31 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2013-08-27 16:31 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2013-08-27 16:31 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2013-08-27 16:31 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2013-08-27 16:31 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2013-08-27 16:31 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2013-08-27 16:31 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2013-08-27 16:31 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2013-08-27 16:31 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2013-08-27 16:31 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2013-08-27 16:31 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2013-08-27 16:31 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2013-08-27 16:31 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2013-08-27 16:31 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2013-08-27 16:31 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2013-08-27 16:31 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2013-08-27 16:31 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2013-08-27 16:31 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2013-08-27 16:31 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2013-08-27 16:31 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2013-08-27 16:31 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2013-08-27 16:31 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2013-08-27 16:31 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2013-08-27 16:31 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2013-08-27 16:31 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2013-08-27 16:31 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2013-08-27 16:31 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2013-08-27 16:31 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2013-08-27 16:31 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2013-08-27 16:31 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2013-08-27 16:31 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2013-08-27 16:31 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2013-08-27 16:31 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2013-08-27 16:31 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2013-08-27 16:31 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2013-08-27 16:31 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2013-08-27 16:31 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2013-08-27 16:31 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2013-08-27 16:31 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2013-08-27 16:31 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2013-08-27 16:31 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2013-08-27 16:31 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2013-08-27 16:31 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2013-08-27 16:31 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2013-08-27 16:31 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2013-08-27 16:31 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2013-08-27 16:31 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2013-08-27 16:31 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2013-08-27 16:31 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2013-08-27 16:31 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2013-08-27 16:31 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2013-08-27 16:31 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2013-08-27 16:31 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2013-08-27 16:31 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2013-08-27 16:31 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2013-08-27 16:31 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2013-08-27 16:31 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2013-08-27 16:31 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2013-08-27 16:31 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2013-08-27 16:31 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2013-08-27 16:31 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2013-08-27 16:31 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2013-08-27 16:31 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2013-08-27 16:31 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2013-08-27 16:31 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2013-08-27 16:31 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2013-08-27 16:31 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2013-08-27 16:31 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2013-08-27 16:31 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2013-08-27 16:31 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2013-08-27 16:31 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2013-08-27 16:31 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2013-08-27 16:31 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2013-08-27 16:31 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2013-08-27 16:31 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2013-08-27 16:31 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2013-08-27 16:31 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2013-08-27 16:31 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2013-08-27 16:31 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2013-08-27 16:31 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2013-08-27 16:31 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2013-08-27 16:31 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2013-08-27 16:31 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2013-08-27 16:31 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2013-08-27 16:31 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2013-08-27 16:31 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2013-08-27 16:31 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2013-08-27 16:31 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2013-08-27 16:31 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2013-08-27 16:31 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2013-08-27 16:31 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2013-08-27 16:31 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2013-08-27 16:31 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2013-08-27 16:31 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2013-08-27 16:31 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2013-08-27 16:31 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2013-08-27 16:31 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2013-08-27 16:31 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2013-08-27 16:31 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2013-08-27 16:31 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2013-08-27 16:31 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2013-08-27 16:31 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2013-08-27 16:31 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2013-08-27 16:31 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2013-08-27 16:31 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2013-08-27 16:31 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2013-08-27 16:31 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2013-08-27 16:31 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2013-08-27 16:31 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2013-08-27 16:31 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2013-08-27 16:31 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2013-08-27 16:31 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2013-08-27 16:31 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2013-08-27 16:31 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2013-08-27 16:31 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2013-08-27 16:31 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2013-08-27 16:31 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2013-08-27 16:31 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2013-08-27 16:31 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2013-08-27 16:31 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2013-08-27 16:30 - 2013-08-27 16:30 - 00000000 ____D C:\ProgramData\Package Cache
2013-08-27 16:26 - 2013-09-19 23:29 - 00000000 ____D C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2013-08-27 16:16 - 2013-08-27 16:16 - 00000000 ____D C:\Users\Sean\AppData\Local\Apps\2.0
2013-08-27 16:01 - 2013-09-21 15:46 - 00000000 ____D C:\Program Files (x86)\Steam
2013-08-27 16:01 - 2013-08-27 16:01 - 00000924 _____ C:\Users\Public\Desktop\Steam.lnk
2013-08-26 11:55 - 2013-09-19 22:41 - 00000000 ____D C:\Windows\system32\appmgmt
2013-08-26 11:51 - 2013-08-26 11:51 - 00002302 _____ C:\Users\Sean\Desktop\Slender - The Arrival.lnk
2013-08-26 11:39 - 2013-08-26 11:49 - 832348796 _____ (Blue Isle Studios                                           ) C:\Users\Sean\Downloads\Slender - The Arrival Installer.exe

==================== One Month Modified Files and Folders =======

2013-09-23 13:04 - 2013-09-22 16:26 - 00239977 _____ C:\Windows\WindowsUpdate.log
2013-09-23 13:02 - 2013-09-23 13:02 - 01955550 _____ (Farbar) C:\Users\Sean\Downloads\FRST64.exe
2013-09-23 13:02 - 2013-09-23 13:02 - 00000000 ____D C:\FRST
2013-09-23 12:54 - 2012-12-21 15:43 - 00855100 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-09-23 12:54 - 2009-07-13 22:13 - 00855100 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-23 02:02 - 2013-09-22 16:23 - 00000280 _____ C:\Windows\setupact.log
2013-09-22 19:09 - 2013-09-21 18:10 - 00021693 _____ C:\Users\Sean\Desktop\attach.txt
2013-09-22 19:08 - 2013-09-21 18:10 - 00029061 _____ C:\Users\Sean\Desktop\dds.txt
2013-09-22 19:07 - 2013-09-19 23:35 - 00000000 ____D C:\Users\Sean\AppData\Local\Mozilla
2013-09-22 19:00 - 2013-09-22 19:00 - 00688992 ____R (Swearware) C:\Users\Sean\Downloads\dds(1).com
2013-09-22 16:36 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\inetsrv
2013-09-22 16:31 - 2009-07-13 21:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-22 16:31 - 2009-07-13 21:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-22 16:23 - 2013-09-22 16:23 - 00000000 _____ C:\Windows\setuperr.log
2013-09-22 16:23 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-22 16:22 - 2013-09-22 16:22 - 00000998 _____ C:\Windows\PFRO.log
2013-09-22 12:37 - 2013-09-22 12:37 - 00026266 _____ C:\ComboFix.txt
2013-09-22 12:37 - 2013-09-21 13:42 - 00000000 ____D C:\Qoobox
2013-09-22 12:36 - 2009-07-13 19:34 - 00000215 _____ C:\Windows\system.ini
2013-09-22 12:25 - 2013-05-22 19:22 - 00000000 ____D C:\Users\Sean\AppData\Roaming\WebApp
2013-09-21 23:41 - 2013-09-21 15:52 - 00000000 ____D C:\Users\Sean\Desktop\RK_Quarantine
2013-09-21 18:08 - 2013-09-21 18:09 - 00688992 ____R (Swearware) C:\Users\Sean\Desktop\dds.com
2013-09-21 17:54 - 2013-09-21 17:54 - 00000000 ____D C:\Panda Software
2013-09-21 17:49 - 2013-09-21 17:49 - 00000000 ____D C:\Users\Sean\AppData\Local\Macromedia
2013-09-21 17:48 - 2013-09-21 17:48 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-21 17:48 - 2013-09-21 17:48 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-21 17:48 - 2013-09-21 17:46 - 00000000 ____D C:\Users\Sean\AppData\Local\Adobe
2013-09-21 17:46 - 2013-09-21 17:46 - 00001293 _____ C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk
2013-09-21 17:46 - 2013-09-21 14:29 - 00000000 ____D C:\Program Files (x86)\Panda Security
2013-09-21 17:02 - 2013-09-21 17:02 - 00001120 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-21 17:02 - 2013-09-21 15:12 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-21 17:00 - 2013-09-21 16:58 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Sean\Downloads\mbam-setup-1.75.0.1300(3).exe
2013-09-21 16:54 - 2013-09-21 16:54 - 00000000 ____D C:\Windows\pss
2013-09-21 16:36 - 2013-09-21 16:10 - 00008627 _____ C:\Windows\SysWOW64\PAV_FOG.OPC
2013-09-21 16:07 - 2013-09-21 16:07 - 00000000 ____D C:\Users\Sean\AppData\Local\Panda Security
2013-09-21 16:06 - 2013-09-21 16:06 - 00002222 _____ C:\Users\Public\Desktop\Panda Antivirus Pro 2014.lnk
2013-09-21 16:06 - 2013-09-21 16:06 - 00000262 _____ C:\Windows\system32\PavCPL64.dat
2013-09-21 16:05 - 2013-09-21 16:05 - 00000000 ____D C:\Windows\SysWOW64\PAV
2013-09-21 16:05 - 2013-09-21 16:05 - 00000000 ____D C:\Users\Sean\AppData\Roaming\Panda Security
2013-09-21 16:05 - 2013-09-21 16:05 - 00000000 ____D C:\ProgramData\Panda Security
2013-09-21 16:05 - 2012-12-21 15:29 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-09-21 16:04 - 2013-09-21 16:03 - 99195296 _____ C:\Users\Sean\Downloads\AP14ESD(1).exe
2013-09-21 16:01 - 2013-09-21 16:01 - 01062728 _____ C:\Users\Sean\Downloads\PANDAAP14(3).exe
2013-09-21 15:55 - 2013-09-21 15:55 - 00001459 _____ C:\Users\Sean\Desktop\RKreport[0]_S_09212013_155531.txt
2013-09-21 15:54 - 2013-09-21 15:54 - 00001910 _____ C:\Users\Sean\Desktop\RKreport[0]_D_09212013_155432.txt
2013-09-21 15:53 - 2013-09-21 15:53 - 00001808 _____ C:\Users\Sean\Desktop\RKreport[0]_S_09212013_155358.txt
2013-09-21 15:52 - 2013-09-21 15:51 - 03812352 _____ C:\Users\Sean\Downloads\RogueKillerX64.exe
2013-09-21 15:48 - 2013-09-21 15:48 - 01062728 _____ C:\Users\Sean\Downloads\PANDAAP14(2).exe
2013-09-21 15:47 - 2013-09-21 15:47 - 00808224 _____ C:\Users\Sean\Downloads\PandaCloudAntivirus.exe
2013-09-21 15:46 - 2013-08-27 16:01 - 00000000 ____D C:\Program Files (x86)\Steam
2013-09-21 15:46 - 2013-07-09 13:37 - 00000000 ____D C:\Windows\Minidump
2013-09-21 15:46 - 2011-02-11 18:20 - 00000000 ____D C:\Windows\PANTHER
2013-09-21 15:45 - 2013-09-21 15:45 - 00002770 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-09-21 15:45 - 2013-09-21 15:45 - 00000829 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-09-21 15:45 - 2013-09-21 15:45 - 00000000 ____D C:\Program Files\CCleaner
2013-09-21 15:44 - 2013-09-21 15:44 - 04454952 _____ (Piriform Ltd) C:\Users\Sean\Downloads\ccsetup405.exe
2013-09-21 15:40 - 2013-09-21 15:40 - 99195296 _____ C:\Users\Sean\Downloads\AP14ESD.exe
2013-09-21 15:27 - 2013-09-21 13:17 - 00000000 ____D C:\AdwCleaner
2013-09-21 15:09 - 2013-09-21 15:09 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Sean\Downloads\mbam-setup-1.75.0.1300(2).exe
2013-09-21 15:08 - 2013-09-21 15:08 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Sean\Downloads\mbam-setup-1.75.0.1300(1).exe
2013-09-21 14:58 - 2013-09-21 14:42 - 00000000 ____D C:\ProgramData\HitmanPro
2013-09-21 14:42 - 2013-09-21 14:39 - 09879648 _____ (SurfRight B.V.) C:\Users\Sean\Downloads\HitmanPro_x64.exe
2013-09-21 14:34 - 2013-09-21 14:34 - 01062728 _____ C:\Users\Sean\Downloads\PANDAAP14(1).exe
2013-09-21 14:32 - 2013-09-21 14:30 - 99195296 _____ C:\Users\Sean\Downloads\AP14.exe
2013-09-21 14:28 - 2013-09-21 14:28 - 01062728 _____ C:\Users\Sean\Downloads\PANDAAP14.exe
2013-09-21 14:23 - 2013-09-21 14:23 - 00000000 ____D C:\Users\Sean\AppData\Roaming\Adobe
2013-09-21 14:20 - 2013-01-31 21:21 - 00000000 ____D C:\ProgramData\Sun
2013-09-21 14:15 - 2013-09-21 14:15 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Sean\Downloads\revosetup(1).exe
2013-09-21 14:07 - 2013-09-21 14:07 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Sean\Downloads\revosetup.exe
2013-09-21 14:07 - 2013-09-21 14:07 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2013-09-21 13:50 - 2009-07-13 20:20 - 00000000 __RHD C:\Users\Default
2013-09-21 13:49 - 2013-09-21 13:42 - 00000000 ____D C:\Windows\erdnt
2013-09-21 13:40 - 2013-09-21 13:55 - 05128554 ____R (Swearware) C:\Users\Sean\Desktop\ComboFix.exe
2013-09-21 13:40 - 2013-09-21 13:40 - 05128554 ____R (Swearware) C:\Users\Sean\Downloads\ComboFix.exe
2013-09-21 13:35 - 2013-09-21 13:35 - 00000802 _____ C:\Users\Sean\Desktop\JRT.txt
2013-09-21 13:31 - 2013-09-21 13:31 - 00000000 ____D C:\Windows\ERUNT
2013-09-21 13:19 - 2013-01-03 00:25 - 00000000 ____D C:\Users\Sean\AppData\Roaming\Skype
2013-09-21 13:18 - 2013-09-21 13:18 - 01029675 _____ (Thisisu) C:\Users\Sean\Downloads\JRT.exe
2013-09-21 13:16 - 2013-09-21 13:16 - 01039554 _____ C:\Users\Sean\Downloads\AdwCleaner.exe
2013-09-21 12:27 - 2013-07-18 11:22 - 00000000 ____D C:\Windows\system32\MRT
2013-09-21 01:50 - 2013-09-21 01:12 - 00007611 _____ C:\Users\Sean\AppData\Local\Resmon.ResmonCfg
2013-09-21 00:34 - 2013-09-21 00:34 - 00003128 _____ C:\Windows\System32\Tasks\{C24BA02D-0ACF-473B-BFB8-72FE646F0C70}
2013-09-21 00:32 - 2013-09-21 00:32 - 00000000 ____D C:\Windows\SysWOW64\BestPractices
2013-09-21 00:32 - 2013-09-21 00:32 - 00000000 ____D C:\Windows\system32\BestPractices
2013-09-21 00:32 - 2013-09-21 00:32 - 00000000 ____D C:\inetpub
2013-09-21 00:32 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\SysWOW64\inetsrv
2013-09-20 23:43 - 2013-09-20 23:43 - 00000000 ____D C:\Users\Sean\AppData\Local\NVIDIA
2013-09-20 23:41 - 2012-12-21 15:28 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-09-20 23:41 - 2012-12-21 15:28 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-09-20 23:41 - 2012-12-21 15:27 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-09-20 23:40 - 2013-09-20 23:40 - 00000000 ____D C:\Windows\SysWOW64\NV
2013-09-20 23:40 - 2013-09-20 23:40 - 00000000 ____D C:\Windows\system32\NV
2013-09-20 23:40 - 2012-12-21 15:28 - 00000000 ____D C:\ProgramData\NVIDIA
2013-09-20 23:10 - 2013-09-20 22:54 - 246695752 _____ (NVIDIA Corporation) C:\Users\Sean\Downloads\327.23-notebook-win8-win7-64bit-international-whql.exe
2013-09-20 07:48 - 2013-05-20 14:50 - 00000000 ___RD C:\Users\Sean\Podcasts
2013-09-20 07:48 - 2012-12-29 00:48 - 00000000 ___RD C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-20 07:48 - 2012-12-29 00:48 - 00000000 ___RD C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-20 04:56 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\rescache
2013-09-20 04:19 - 2009-07-13 21:45 - 00421168 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-20 04:02 - 2013-01-19 18:13 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-19 23:40 - 2013-09-19 23:40 - 00000000 ____D C:\Users\Sean\AppData\Roaming\Malwarebytes
2013-09-19 23:40 - 2013-09-19 23:40 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-19 23:39 - 2013-09-19 23:39 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Sean\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-19 23:35 - 2013-09-19 23:35 - 00001158 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-19 23:35 - 2013-09-19 23:35 - 00000000 ____D C:\Users\Sean\AppData\Roaming\Mozilla
2013-09-19 23:35 - 2013-09-19 23:35 - 00000000 ____D C:\ProgramData\Mozilla
2013-09-19 23:35 - 2013-09-19 23:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-19 23:35 - 2013-09-19 23:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-19 23:31 - 2012-12-29 00:47 - 00000000 ____D C:\Users\Sean
2013-09-19 23:29 - 2013-08-27 16:26 - 00000000 ____D C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2013-09-19 23:29 - 2013-05-23 01:08 - 00000000 ____D C:\ProgramData\FLEXnet
2013-09-19 23:29 - 2013-01-19 18:13 - 00000000 ____D C:\Users\Sean\AppData\Local\Microsoft Help
2013-09-19 23:29 - 2013-01-10 03:03 - 00000000 ____D C:\Program Files (x86)\StarCraft II
2013-09-19 23:29 - 2012-12-29 00:47 - 00000000 ___RD C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-09-19 23:29 - 2012-12-29 00:47 - 00000000 ___RD C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-09-19 23:29 - 2012-12-21 15:37 - 00000000 ____D C:\ProgramData\CyberLink
2013-09-19 23:29 - 2009-07-13 22:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-09-19 23:29 - 2009-07-13 20:20 - 00000000 __RHD C:\Users\Public\Libraries
2013-09-19 23:29 - 2009-07-13 20:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-09-19 23:28 - 2010-11-21 00:16 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-09-19 23:28 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\registration
2013-09-19 23:20 - 2013-01-19 18:13 - 00000000 __RHD C:\MSOCache
2013-09-19 22:41 - 2013-08-26 11:55 - 00000000 ____D C:\Windows\system32\appmgmt
2013-09-12 01:58 - 2013-09-20 23:36 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 15901448 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 12947360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-09-12 01:58 - 2013-09-20 23:36 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 02630304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 00458528 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 00388384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-09-12 01:58 - 2013-09-20 23:36 - 00032032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
2013-09-12 01:58 - 2012-12-21 15:27 - 02986672 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-09-12 01:58 - 2012-12-21 15:27 - 01412832 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2013-09-12 01:58 - 2012-12-21 15:27 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-09-12 01:58 - 2012-12-21 15:27 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-09-12 01:58 - 2012-12-21 15:27 - 00022814 _____ C:\Windows\system32\nvinfo.pb
2013-09-12 00:25 - 2012-12-21 15:28 - 06599968 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2013-09-12 00:25 - 2012-12-21 15:28 - 03452192 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2013-09-12 00:25 - 2012-12-21 15:28 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2013-09-12 00:25 - 2012-12-21 15:28 - 01042208 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2013-09-12 00:25 - 2012-12-21 15:28 - 00920864 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2013-09-12 00:25 - 2012-12-21 15:28 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2013-09-12 00:25 - 2012-12-21 15:28 - 00067072 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2013-09-12 00:25 - 2012-12-21 15:28 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2013-09-11 15:06 - 2012-12-21 15:28 - 03361114 _____ C:\Windows\system32\nvcoproc.bin
2013-09-01 17:08 - 2013-09-21 12:26 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-27 16:30 - 2013-08-27 16:30 - 00000000 ____D C:\ProgramData\Package Cache
2013-08-27 16:19 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\NDF
2013-08-27 16:16 - 2013-08-27 16:16 - 00000000 ____D C:\Users\Sean\AppData\Local\Apps\2.0
2013-08-27 16:01 - 2013-08-27 16:01 - 00000924 _____ C:\Users\Public\Desktop\Steam.lnk
2013-08-26 11:51 - 2013-08-26 11:51 - 00002302 _____ C:\Users\Sean\Desktop\Slender - The Arrival.lnk
2013-08-26 11:50 - 2013-02-18 01:08 - 00000000 ____D C:\Program Files (x86)\Blue Isle Studios
2013-08-26 11:49 - 2013-08-26 11:39 - 832348796 _____ (Blue Isle Studios                                           ) C:\Users\Sean\Downloads\Slender - The Arrival Installer.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-09-20 02:49

==================== End Of Log ============================



Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-09-2013
Ran by Sean at 2013-09-23 13:04:54
Running from C:\Users\Sean\Downloads
Boot Mode: Normal
==========================================================


==================== Installed Programs ======================

Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168)
Age of Empires II: HD Edition (x32)
AuthenTec TrueSuite (Version: 5.2.0.642)
BisonCam (x32 Version: )
CCleaner (Version: 4.05)
CyberLink Media Suite (x32 Version: 8.0.3518)
CyberLink Power2Go (x32 Version: 7.0.0.2211)
CyberLink PowerDVD 10 (x32 Version: 10.0.3523.02)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition
DivX Setup (x32 Version: 2.6.1.41)
GeForce Experience NvStream Client Components (Version: 0.1.87)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0)
Hotkey 6.0058 (x32 Version: 6.0058)
Intel PROSet Wireless
Intel® Control Center (x32 Version: 1.2.1.1008)
Intel® Management Engine Components (x32 Version: 8.0.12.1498)
Intel® OpenCL CPU Runtime (x32)
Intel® Processor Graphics (x32 Version: 8.15.10.2712)
Intel® PROSet/Wireless for Bluetooth® + High Speed (Version: 15.0.0.0083)
Intel® PROSet/Wireless Software for Bluetooth® Technology (Version: 2.0.0.0086)
Intel® Rapid Storage Technology (x32 Version: 11.5.0.1207)
Intel® USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.5.235)
Intel® PROSet/Wireless WiFi Software (Version: 15.00.0000.0708)
Intel® Trusted Connect Service Client (Version: 1.24.388.1)
LiveUpdate 3.3 (Symantec Corporation) (x32 Version: 3.3.0.96)
Malwarebytes Anti-Malware version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Office 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Groove MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office InfoPath MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 32-bit MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (x32 Version: 11.0.51106.1)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (x32 Version: 11.0.51106.1)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (Version: 11.0.51106)
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (Version: 11.0.51106)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106)
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106)
Mozilla Firefox 24.0 (x86 en-US) (x32 Version: 24.0)
Mozilla Maintenance Service (x32 Version: 24.0)
NI Assistant Framework (x32 Version: 7.0.192.0)
NI Assistant Framework 64-bit (Version: 7.0.77.0)
NI Assistant Framework LabVIEW 2010 Support (x32 Version: 7.0.34.0)
NI Assistant Framework LabVIEW Code Generator 2010 (x32 Version: 7.0.152.0)
NI Authentication 1.0 (64-bit) (Version: 1.0.58.0)
NI Authentication 1.0 (x32 Version: 1.0.73.0)
NI CodeSignAPI (x32 Version: 2.70.346)
NI Curl 1.0 (64-bit) (Version: 1.0.82.0)
NI Curl 1.0 (x32 Version: 1.0.82.0)
NI DataSocket 4.8 (64-bit) (Version: 4.8.23.0)
NI DataSocket 4.8 (x32 Version: 4.8.20.0)
NI Distributed System Manager 2010 (x32 Version: 10.0.238.0)
NI DN 2.0 SP1 installer (x32 Version: 2.10.49152)
NI EULA Depot (x32 Version: 2.80.295)
NI Example Finder 10.0 (x32 Version: 10.0.213.0)
NI Help Assistant (64bit) (Version: 1.0.10)
NI Help Assistant (x32 Version: 1.0.10)
NI Instrument IO Assistant for LabVIEW 2010 32-bit (x32 Version: 1.0.13.0)
NI LabVIEW 2009 SP1 Run-Time Engine Web Services (x32 Version: 9.0.234.0)
NI LabVIEW 2010 (x32 Version: 10.0.250.0)
NI LabVIEW 2010 (x32 Version: 10.0.251.0)
NI LabVIEW 2010 (x32 Version: 10.0.252.0)
NI LabVIEW 2010 (x32 Version: 10.0.254.0)
NI LabVIEW 2010 (x32 Version: 10.0.255.0)
NI LabVIEW 2010 (x32 Version: 10.0.73.0)
NI LabVIEW 2010 Deployable License (x32 Version: 10.0.236.0)
NI LabVIEW 2010 Deployment Framework (x32 Version: 10.0.36.0)
NI LabVIEW 2010 Help (x32 Version: 10.0.247.0)
NI LabVIEW 2010 Help File (x32 Version: 10.0.233.0)
NI LabVIEW 2010 License (x32 Version: 10.0.238.0)
NI LabVIEW 2010 Manuals (x32 Version: 10.0.239.0)
NI LabVIEW 2010 MeasAppChm File (x32 Version: 10.0.234.0)
NI LabVIEW 2010 Real-Time Error Dialog (x32 Version: 10.0.85.0)
NI LabVIEW 2010 Real-Time NBFifo (x32 Version: 10.0.214.0)
NI LabVIEW 2010 Search (x32 Version: 10.0.41.0)
NI LabVIEW 2010 Simulation (x32 Version: 10.0.239.0)
NI LabVIEW 2010 Web Server (x32 Version: 10.0.234.0)
NI LabVIEW Broker (64 bit) (Version: 6.8.10.0)
NI LabVIEW Broker (x32 Version: 6.8.10.0)
NI LabVIEW C Interface (x32 Version: 1.0.1)
NI LabVIEW Compare Utility 10.0.0 (x32 Version: 10.0.10.0)
NI LabVIEW MAX XML (x32 Version: 9.0.6.0)
NI LabVIEW Merge Utility 10.0.0 (x32 Version: 10.0.10.0)
NI LabVIEW Real-Time NBFifo (x32 Version: 9.0.319.0)
NI LabVIEW Run-Time Engine 2009 SP1 (x32 Version: 9.0.1074.0)
NI LabVIEW Run-Time Engine 2010 (x32 Version: 10.0.240.0)
NI LabVIEW Run-Time Engine Interop 2009 (x32 Version: 9.0.146.0)
NI LabVIEW Run-Time Engine Interop 2010 (x32 Version: 10.0.243.0)
NI LabVIEW Web Server for Run-Time Engine (x32 Version: 10.0.235.0)
NI LabVIEW Web Server for Run-Time Engine (x32 Version: 9.0.185.0)
NI LabVIEW Web Services Runtime (x32 Version: 10.0.235.0)
NI LabWindows/CVI 2009 Code Generator (x32 Version: 9.1.0427)
NI LabWindows/CVI 9.0 Run-Time Engine (x32 Version: 9.0.0356)
NI LabWindows/CVI DLL Builder for LabVIEW (x32 Version: 9.0.1380)
NI License Manager (x32 Version: 3.5.23)
NI Logos 5.2.0 (x32 Version: 5.2.25.0)
NI Logos LabVIEW 2010 Support (x32 Version: 10.0.229.0)
NI Logos XT Support (x32 Version: 5.2.21.0)
NI Logos64 5.2.0 (Version: 5.2.25.0)
NI Logos64 XT Support (Version: 5.2.21.0)
NI Math Kernel Libraries (64-bit) (Version: 1.0.14.0)
NI Math Kernel Libraries (64-bit) (Version: 1.0.15.0)
NI Math Kernel Libraries (x32 Version: 1.0.25.0)
NI Math Kernel Libraries (x32 Version: 1.0.28.0)
NI Math Kernel Libraries (x32 Version: 1.0.861.0)
NI MAX Remote Configuration 64-bit Installer 4.7 (Version: 4.70.49153)
NI MAX Remote Configuration Installer 4.7 (x32 Version: 4.70.49153)
NI MAX Support for 64 Bit Windows (Version: 4.70.49156)
NI MDF Support (x32 Version: 2.80.295)
NI mDNS Responder 1.3 for Windows 64-bit (Version: 1.30.49157)
NI mDNS Responder 1.3.0 (x32 Version: 1.30.49157)
NI Measurement & Automation Explorer 4.7.0 (x32 Version: 4.70.49156)
NI Measurement Studio Recipe Processor (x32 Version: 8.0.0101)
NI MetaSuite Installer (x32 Version: 2.71.130)
NI MXS 4.7.0 (x32 Version: 4.70.49152)
NI MXS 4.7.0 for 64 Bit Windows (Version: 4.70.49152)
NI OPC Support (x32 Version: 10.0.158.0)
NI Portable Configuration 4.7.0 (x32 Version: 4.70.49152)
NI Portable Configuration for 64 Bit Windows 4.7.0 (Version: 4.70.49152)
NI Registration Wizard (x32 Version: 1.3.87.0)
NI Remote Provider for MAX 4.7.0 (x32 Version: 4.70.49153)
NI Remote PXI Provider for MAX 4.7.0 (x32 Version: 4.70.49152)
NI Software Provider for MAX 4.7.0 (x32 Version: 4.70.49152)
NI SSL LabVIEW 2010 Support (x32 Version: 10.0.208.0)
NI SSL Support (64-bit) (Version: 10.0.22.0)
NI SSL Support (x32 Version: 10.0.22.0)
NI System API Windows 32-bit 1.1.0 (x32 Version: 1.10.554.0)
NI System API Windows 64-bit 1.1.0 (Version: 1.10.551.0)
NI System Configuration 1.1.0 (x32 Version: 1.10.335.0)
NI System Configuration 1.1.0 for Windows 64-bit (Version: 1.10.337.0)
NI System State Publisher (64-bit) (Version: 10.0.84.0)
NI System State Publisher (x32 Version: 10.0.84.0)
NI System Web Server 1.0 (x32 Version: 10.0.278.0)
NI System Web Server Base 1.0 (64-bit) (Version: 1.0.59.0)
NI System Web Server Base 1.0 (x32 Version: 1.0.104.0)
NI TDM Excel Add-In 3.2 (x32 Version: 3.2.63.0)
NI TDMS (64-bit) (Version: 2.0.350.0)
NI TDMS (x32 Version: 2.0.350.0)
NI Trace Engine (64-bit) (Version: 10.0.237.0)
NI Trace Engine (x32 Version: 10.0.237.0)
NI Uninstaller (x32 Version: 2.80.295)
NI Update Service (x32 Version: 1.10.65.0)
NI Update Service Full (x32 Version: 1.10.65.0)
NI USI 1.8.0 (x32 Version: 1.8.04177)
NI USI 1.8.0 64-Bit (Version: 1.8.04177)
NI Variable Engine (64-bit) (Version: 2.4.158.0)
NI Variable Engine 2.4.0 (x32 Version: 2.4.159.0)
NI Variable Engine LabVIEW 2010 Support (x32 Version: 10.0.239.0)
NI VC2005MSMs x64 (Version: 8.02.0)
NI VC2005MSMs x86 (x32 Version: 8.02.0)
NI VC2008MSMs x64 (Version: 9.0.201)
NI VC2008MSMs x86 (x32 Version: 9.0.201)
NI Web Application Server 1.0 (64-bit) (Version: 1.0.59.0)
NI Web Application Server 1.0 (x32 Version: 1.0.109.0)
NI Web Interface Framework 1.0 (x32 Version: 1.0.114.0)
NI Web Pipeline 2.0.1 (x32 Version: 2.0.128.0)
NI Web Pipeline 2.0.1 64-bit support (Version: 2.0.122.0)
NI Xalan Delay Load 1.10.1 (x32 Version: 1.10.46.0)
NI Xalan Delay Load 1.10.1 64-bit (Version: 1.10.47.0)
NI Xerces Delay Load 2.7.1 (x32 Version: 2.7.123.0)
NI Xerces Delay Load 2.7.1 64-bit (Version: 2.7.128.0)
NI-DAQmx/LabVIEW shared documentation 1.7.5 (x32 Version: 1.75.49152)
NI-DAQmx/LabVIEW shared documentation for 64 Bit Windows 1.7.5 (Version: 1.75.49152)
NI-RPC 4.2.0f0 (x32 Version: 4.20.49152)
NI-RPC 4.2.0f0 for 64 Bit Windows (Version: 4.20.49152)
NI-RPC 4.2.0f0 for Phar Lap ETS (x32 Version: 4.20.49152)
NVIDIA Control Panel 327.23 (Version: 327.23)
NVIDIA GeForce Experience 1.6.1 (Version: 1.6.1)
NVIDIA Graphics Driver 327.23 (Version: 327.23)
NVIDIA Install Application (Version: 2.1002.133.902)
NVIDIA Optimus 8.3.14 (Version: 8.3.14)
NVIDIA PhysX (x32 Version: 9.13.0725)
NVIDIA PhysX System Software 9.13.0725 (Version: 9.13.0725)
NVIDIA Update 8.3.14 (Version: 8.3.14)
NVIDIA Update Components (Version: 8.3.14)
NVIDIA Virtual Audio 1.2.5 (Version: 1.2.5)
Panda Antivirus Pro 2014 (x32 Version: 13.01.00)
Panda Cloud Cleaner (x32 Version: 1.0.49)
Password Depot 6 - Panda Secure Vault Edition (x32 Version: 6.1.5)
Realtek Ethernet Controller Driver (x32 Version: 7.52.203.2012)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6581)
Realtek PCIE Card Reader (x32 Version: 6.2.8400.27024)
SHIELD Streaming (Version: 1.05.28)
Skype Click to Call (x32 Version: 6.11.13348)
Skype™ 6.6 (x32 Version: 6.6.106)
Slender - The Arrival 1.3 (x32 Version: 1.3)
StarCraft II (x32 Version: 2.0.11.26825)
Steam (x32 Version: 1.0.0.0)
Symantec Endpoint Protection (Version: 11.0.6000.550)
Synaptics Pointing Device Driver (Version: 16.2.4.0)
THX TruStudio Pro (x32 Version: TAMB-CVS1D-1-LB R07)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553157) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition
Update for Microsoft Office 2010 (KB2589370) 64-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition
Update for Microsoft Office 2010 (KB2598242) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760758) 64-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 64-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition
Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 64-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
WebCam Installer (x32 Version: 4.04)
Windows Mobile Device Updater Component (Version: 04.08.2345.00)
Zune (Version: 04.08.2345.00)
Zune Language Pack (CHS) (Version: 04.08.2345.00)
Zune Language Pack (CHT) (Version: 04.08.2345.00)
Zune Language Pack (CSY) (Version: 04.08.2345.00)
Zune Language Pack (DAN) (Version: 04.08.2345.00)
Zune Language Pack (DEU) (Version: 04.08.2345.00)
Zune Language Pack (ELL) (Version: 04.08.2345.00)
Zune Language Pack (ESP) (Version: 04.08.2345.00)
Zune Language Pack (FIN) (Version: 04.08.2345.00)
Zune Language Pack (FRA) (Version: 04.08.2345.00)
Zune Language Pack (HUN) (Version: 04.08.2345.00)
Zune Language Pack (IND) (Version: 04.08.2345.00)
Zune Language Pack (ITA) (Version: 04.08.2345.00)
Zune Language Pack (JPN) (Version: 04.08.2345.00)
Zune Language Pack (KOR) (Version: 04.08.2345.00)
Zune Language Pack (MSL) (Version: 04.08.2345.00)
Zune Language Pack (NLD) (Version: 04.08.2345.00)
Zune Language Pack (NOR) (Version: 04.08.2345.00)
Zune Language Pack (PLK) (Version: 04.08.2345.00)
Zune Language Pack (PTB) (Version: 04.08.2345.00)
Zune Language Pack (PTG) (Version: 04.08.2345.00)
Zune Language Pack (RUS) (Version: 04.08.2345.00)
Zune Language Pack (SVE) (Version: 04.08.2345.00)

==================== Restore Points  =========================

20-09-2013 20:30:38 Scheduled Checkpoint
21-09-2013 06:37:03 Windows Update
21-09-2013 07:32:35 Windows Modules Installer
21-09-2013 08:47:38 Removed Adobe Reader XI (11.0.04).
21-09-2013 19:10:46 Windows Update
21-09-2013 21:17:20 Removed Java 7 Update 11
22-09-2013 23:27:57 Windows Update
23-09-2013 16:57:21 Windows Update

==================== Hosts content: ==========================

2009-07-13 19:34 - 2013-09-21 20:11 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {38CD8CD7-4A78-40C1-9385-035C04CE5B90} - System32\Tasks\{826EC96B-92D6-4F98-AC8A-B7AE9E9D3418} => Iexplore.exe http://ui.skype.com/ui/0/6.0.0.126/en/abandoninstall?page=tsMain
Task: {CA06B25E-FD55-4871-8DA4-9A3C1AA05130} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {DC11D189-4EA1-4A43-8A94-A479FECF286F} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2013-01-03] (Microsoft Corporation)
Task: {FB433286-5697-4B76-9C0A-2F818C3D3015} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd)

==================== Loaded Modules (whitelisted) =============

2009-07-13 17:22 - 2009-07-13 18:38 - 00081408 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\Windows\System32\l3codeca.acm
2011-03-17 01:07 - 2011-03-17 01:07 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:23 - 2010-10-20 16:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2011-10-21 15:00 - 2011-10-21 15:00 - 04014408 _____ (Authentec) C:\Program Files\AuthenTec TrueSuite\KeepSafe\fvns.dll
2011-10-21 14:49 - 2011-10-21 14:49 - 00829256 _____ (Authentec) C:\Program Files\AuthenTec TrueSuite\KeepSafe\inffv1.dll
2013-09-21 16:05 - 2012-05-22 15:52 - 00117024 _____ (Panda Security, S.L.) C:\WINDOWS\SYSTEM32\PavLspHook64.DLL
2013-09-21 16:05 - 2013-06-25 17:03 - 00024544 _____ (Panda Security, S.L.) C:\Windows\system32\sysHelper64.dll
2012-05-15 10:11 - 2012-03-26 02:37 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrENU.lrc
2010-06-23 17:20 - 2010-06-23 17:20 - 00026328 _____ (National Instruments Corporation) C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll
2012-05-15 10:10 - 2012-03-26 02:33 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-12-21 15:33 - 2010-11-12 13:38 - 00241152 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL
2013-09-21 16:05 - 2013-06-25 17:03 - 00024544 _____ (Panda Security, S.L.) C:\Windows\System32\sysHelper64.dll
2011-11-03 04:08 - 2011-11-03 04:08 - 00179016 _____ (AuthenTec) C:\Program Files\AuthenTec TrueSuite\TSLog.dll
2011-11-03 04:08 - 2011-11-03 04:08 - 00549192 _____ (AuthenTec Inc.) C:\Program Files\AuthenTec TrueSuite\biolayer.dll
2011-11-03 04:08 - 2011-11-03 04:08 - 00358728 _____ (Authentec Inc.) C:\Program Files\AuthenTec TrueSuite\TokenMachine.dll
2011-11-03 04:08 - 2011-11-03 04:08 - 00641864 _____ (AuthenTec Inc.) C:\Program Files\AuthenTec TrueSuite\TrueSuite.AutoSoftwareUpdate.dll
2011-11-03 04:09 - 2011-11-03 04:09 - 00087880 _____ () C:\Program Files\AuthenTec TrueSuite\ssutil.dll
2011-11-03 04:08 - 2011-11-03 04:08 - 00556360 _____ () C:\Program Files\AuthenTec TrueSuite\DataManager.dll
2011-10-26 10:45 - 2011-10-26 10:45 - 08190792 _____ (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueAPI.dll
2011-10-26 10:45 - 2011-10-26 10:45 - 00051016 _____ (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueOTPIntel.dll
2013-09-21 16:05 - 2012-05-22 15:54 - 00087328 _____ (Panda Security, S.L.) C:\WINDOWS\SYSWOW64\PavLspHookWow.DLL
2012-03-17 15:36 - 2012-03-17 15:36 - 00218112 _____ (TODO: <公司名稱>) C:\Program Files (x86)\Hotkey\GetProductdll.dll
2009-06-06 15:50 - 2009-06-06 15:50 - 00019968 _____ () C:\Program Files (x86)\Hotkey\Audiodll.dll
2011-12-13 21:37 - 2011-12-13 21:37 - 00221696 _____ (TODO: <公司名稱>) C:\Program Files (x86)\Hotkey\powerlife.dll
2010-06-21 11:10 - 2010-06-21 11:10 - 00204288 _____ (TODO: <公司名稱>) C:\Program Files (x86)\Hotkey\wlandll.dll
2010-07-27 06:30 - 2010-07-27 06:30 - 00210944 _____ (TODO: <公司名稱>) C:\Program Files (x86)\Hotkey\brightness.dll
2013-09-21 16:05 - 2009-01-14 21:03 - 00718848 _____ (CodeGear) C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\CC3290MT.DLL
2013-09-21 16:05 - 2010-02-23 12:09 - 00058624 _____ (Panda Software International) C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\CryptMng.dll
2013-09-21 16:06 - 2007-02-14 13:55 - 00165424 _____ () C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\MiniCrypto.dll
2013-09-21 16:06 - 2004-05-19 11:33 - 00507904 _____ () C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\libxml2.dll
2013-09-21 16:05 - 2007-03-08 21:45 - 00058928 _____ (Panda Software International) C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\Platc.DLL
2013-09-21 13:08 - 2013-09-21 13:08 - 00361472 _____ (Intel Corporation) C:\Windows\assembly\NativeImages_v4.0.30319_32\IAStorUtil\7378eb7695a9b15e303df16d43a4084f\IAStorUtil.ni.dll
2013-09-21 13:08 - 2013-09-21 13:08 - 00026112 _____ (Intel Corp.) C:\Windows\assembly\NativeImages_v4.0.30319_32\IAStorCommon\58e0f357dbe7cd9fb85de22272bc8526\IAStorCommon.ni.dll
2013-09-19 23:35 - 2013-09-10 19:26 - 03279768 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2011-03-17 01:11 - 2011-03-17 01:11 - 04297568 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:45 - 2010-10-20 16:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ccEvtMgr => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ccSetMgr => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SmcService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Symantec Antivirus => ""="Service"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/22/2013 04:50:42 PM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWHC84B.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:49:47 PM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWH2E87.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:49:31 PM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWH1710.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:49:15 PM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWHFF6A.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:49:00 PM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWHE802.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:48:44 PM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWHCC95.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:48:29 PM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWHB4A1.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:36:34 PM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWH301F.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:36:09 PM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWH10DC.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:35:45 PM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWHF965.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.


System errors:
=============
Error: (09/23/2013 01:02:20 PM) (Source: bowser) (User: )
Description: The master browser has received a server announcement from the computer FAMILYPC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{768A72AB-1196-4DF4-A2F5-B485BF40326E}.
The master browser is stopping or an election is being forced.

Error: (09/23/2013 09:59:23 AM) (Source: bowser) (User: )
Description: The master browser has received a server announcement from the computer FAMILYPC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{768A72AB-1196-4DF4-A2F5-B485BF40326E}.
The master browser is stopping or an election is being forced.

Error: (09/23/2013 02:07:00 AM) (Source: bowser) (User: )
Description: The master browser has received a server announcement from the computer FAMILYPC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{768A72AB-1196-4DF4-A2F5-B485BF40326E}.
The master browser is stopping or an election is being forced.

Error: (09/23/2013 00:26:59 AM) (Source: bowser) (User: )
Description: The master browser has received a server announcement from the computer FAMILYPC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{768A72AB-1196-4DF4-A2F5-B485BF40326E}.
The master browser is stopping or an election is being forced.

Error: (09/22/2013 06:43:31 PM) (Source: bowser) (User: )
Description: The master browser has received a server announcement from the computer FAMILYPC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{768A72AB-1196-4DF4-A2F5-B485BF40326E}.
The master browser is stopping or an election is being forced.

Error: (09/22/2013 04:30:30 PM) (Source: bowser) (User: )
Description: The master browser has received a server announcement from the computer FAMILYPC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{768A72AB-1196-4DF4-A2F5-B485BF40326E}.
The master browser is stopping or an election is being forced.

Error: (09/22/2013 04:26:35 PM) (Source: Service Control Manager) (User: )
Description: The Google Update Service (gupdate) service failed to start due to the following error:
%%2

Error: (09/22/2013 04:24:43 PM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (09/22/2013 04:24:43 PM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated with service-specific error %%-1073473535.

Error: (09/22/2013 04:23:38 PM) (Source: Service Control Manager) (User: )
Description: The MBAMService service failed to start due to the following error:
%%5


Microsoft Office Sessions:
=========================
Error: (09/22/2013 04:50:42 PM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWHC84B.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:49:47 PM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWH2E87.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:49:31 PM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWH1710.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:49:15 PM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWHFF6A.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:49:00 PM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWHE802.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:48:44 PM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWHCC95.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:48:29 PM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWHB4A1.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:36:34 PM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWH301F.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:36:09 PM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWH10DC.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.

Error: (09/22/2013 04:35:45 PM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Trojan.Gen.2 in File: C:\Users\Sean\AppData\Local\Temp\DWHF965.tmp by: Auto-Protect scan.  Action: Quarantine succeeded : Access denied.  Action Description: The file was quarantined successfully.


CodeIntegrity Errors:
===================================
  Date: 2013-09-21 20:10:57.409
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-09-21 20:10:57.377
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-09-21 20:10:57.346
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-09-21 20:10:57.299
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-09-21 13:48:36.188
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-09-21 13:48:36.168
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Percentage of memory in use: 39%
Total physical RAM: 8082.27 MB
Available physical RAM: 4854.77 MB
Total Pagefile: 16162.71 MB
Available Pagefile: 12521.64 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:698.29 GB) (Free:305.13 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 1F6FE223)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=698 GB) - (Type=07 NTFS)

==================== End Of Log ============================



#5 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,458 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:06:10 PM

Posted 23 September 2013 - 06:33 PM

looks good.

Please run the following:

Please download Junkware Removal Tool to your desktop.
  • Shutdown your antivirus to avoid any conflicts.
  • Right-mouse click JRT.exe and select Run as administrator
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message

NEXT


Download AdwCleaner from here and save it to your desktop.
  • Run AdwCleaner and select Clean
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
NEXT
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <-- very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish

The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif
Microsoft MVP - 2010, 2011, 2012, 2013

#6 Krampus1

Krampus1
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 24 September 2013 - 12:12 AM

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.2 (09.22.2013:1)
OS: Windows 7 Professional x64
Ran by Sean on Mon 09/23/2013 at 21:43:57.40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Emptied folder: C:\Users\Sean\AppData\Roaming\mozilla\firefox\profiles\3y43bv1n.default\minidumps [2 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 09/23/2013 at 22:08:05.77
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 



#7 Krampus1

Krampus1
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 24 September 2013 - 12:20 AM

# AdwCleaner v3.005 - Report created 23/09/2013 at 22:16:29
# Updated 22/09/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Sean - SEAN-PC
# Running from : C:\Users\Sean\Desktop\adwcleaner(1).exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16686


-\\ Mozilla Firefox v24.0 (en-US)

[ File : C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\3y43bv1n.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [1967 octets] - [21/09/2013 13:19:17]
AdwCleaner[R1].txt - [889 octets] - [21/09/2013 15:26:01]
AdwCleaner[R2].txt - [1008 octets] - [23/09/2013 22:14:27]
AdwCleaner[S0].txt - [2015 octets] - [21/09/2013 13:25:03]
AdwCleaner[S1].txt - [949 octets] - [21/09/2013 15:27:01]
AdwCleaner[S2].txt - [931 octets] - [23/09/2013 22:16:29]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [990 octets] ##########
 



#8 Krampus1

Krampus1
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 24 September 2013 - 12:34 AM

Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org

Database version: v2013.09.24.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16686
Sean :: SEAN-PC [administrator]

Protection: Disabled

9/23/2013 10:25:48 PM
mbam-log-2013-09-23 (22-25-48).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 223706
Time elapsed: 7 minute(s), 23 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
 



#9 Krampus1

Krampus1
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 24 September 2013 - 03:10 AM

Thank you very much for you time and help! Today as recently as a few hours ago I got another notification that suspicious files were being found and quarantined, again under C:\Users\Sean\AppData\Local\Temp and I again went to this file and saw many files appearing and then disappearing with filenames such as DWH7111.tmp. Is this a cause for alarm? I was also wondering if my computer will ever be fully safe/rid of this virus again. I ran the ESET scan and it said that there were no threats detected. I don't think I got the option to see a list of threats, only the finish button, but I'll try again tomorrow. Thanks again!



#10 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,458 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:06:10 PM

Posted 24 September 2013 - 11:21 AM


What is Symantec calling these files?

Are you on the internet when these files are created? What exactly are you doing?

As they are in a temp directory, they are not being installed on your computer.
The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif
Microsoft MVP - 2010, 2011, 2012, 2013

#11 Krampus1

Krampus1
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 24 September 2013 - 08:18 PM

It only happens when I am on the internet yes, and Symantec is calling the files Trojan.Gen.2. I was thinking it was something in my computer trying to reach out to the internet or the internet reaching for something in my computer.



#12 Krampus1

Krampus1
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 24 September 2013 - 08:37 PM

Its usually just when I first turn on the internet.



#13 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,458 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:06:10 PM

Posted 25 September 2013 - 10:57 AM

Here is an explanation here for what those files are

http://www.bleepingcomputer.com/forums/t/413529/symantec-and-dwhtmp-files/#entry2366881

It doesn't appear to be anything to be concerned about.


How is the computer running now, are there any outstanding issues?
The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif
Microsoft MVP - 2010, 2011, 2012, 2013

#14 Krampus1

Krampus1
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 25 September 2013 - 04:19 PM

It seems to be working fine, thanks!



#15 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,458 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:06:10 PM

Posted 25 September 2013 - 04:28 PM

We just have some housekeeping to do now,

Please do the following:


You can delete the DDS, JRT and FRST logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix
  • Make sure your security programs are totally disabled.
  • Press the WinKey +R to open a run box
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.
Combofix_uninstall_image.jpg


NEXT
  • Double click on adwcleaner.exe to run the tool.
  • Click on Uninstall.
  • Confirm with yes.
If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.
  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    %5BB%5DPC Safety and Security--What Do I Need?.[/b]
  • Simple and easy ways to keep your computer safe and secure on the Internet
Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif
Microsoft MVP - 2010, 2011, 2012, 2013




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users