Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Random attempt to reach IP every 6 minutes


  • This topic is locked This topic is locked
4 replies to this topic

#1 dialsoft

dialsoft

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:32 PM

Posted 03 December 2012 - 04:27 PM

As requested.

Please also note this is Windows 8 machine. I have tried everything other than combofix because it wouldn't work on windows 8. I uninstalled any software I felt may be questionable. I tried using AVG, various online scanners. Spybot 2 and spyware doctor as well as malwarebytes and other things requested by bleepingcomputer forum watchers. I am an expert level troubleshooter and was hoping someone knew more than I to figure this out.
Attached is the error popup from malwarebytes
Here is an example of the outbound war dial on ports that malwarebytes is reporting.

2012/12/03 00:01:26 -0500 MARCX797-28-12 (null) IP-BLOCK 222.231.8.226 (Type: outgoing, Port: 51498, Process: explorer.exe)
2012/12/03 00:01:26 -0500 MARCX797-28-12 (null) IP-BLOCK 222.231.8.226 (Type: outgoing, Port: 51499, Process: explorer.exe)
2012/12/03 00:01:26 -0500 MARCX797-28-12 (null) IP-BLOCK 222.231.8.226 (Type: outgoing, Port: 51500, Process: explorer.exe)
2012/12/03 00:01:26 -0500 MARCX797-28-12 (null) IP-BLOCK 222.231.8.226 (Type: outgoing, Port: 51501, Process: explorer.exe)
2012/12/03 00:01:26 -0500 MARCX797-28-12 (null) IP-BLOCK 222.231.8.226 (Type: outgoing, Port: 51502, Process: explorer.exe)
2012/12/03 00:01:26 -0500 MARCX797-28-12 (null) IP-BLOCK 222.231.8.226 (Type: outgoing, Port: 51503, Process: explorer.exe)
2012/12/03 00:07:26 -0500 MARCX797-28-12 (null) IP-BLOCK 222.231.8.226 (Type: outgoing, Port: 51573, Process: explorer.exe)
2012/12/03 00:07:26 -0500 MARCX797-28-12 (null) IP-BLOCK 222.231.8.226 (Type: outgoing, Port: 51574, Process: explorer.exe)
2012/12/03 00:07:26 -0500 MARCX797-28-12 (null) IP-BLOCK 222.231.8.226 (Type: outgoing, Port: 51575, Process: explorer.exe)
2012/12/03 00:07:26 -0500 MARCX797-28-12 (null) IP-BLOCK 222.231.8.226 (Type: outgoing, Port: 51576, Process: explorer.exe)
2012/12/03 00:07:26 -0500 MARCX797-28-12 (null) IP-BLOCK 222.231.8.226 (Type: outgoing, Port: 51577, Process: explorer.exe)

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16442 BrowserJavaVersion: 10.9.2
Run by Marc at 16:19:40 on 2012-12-03
Microsoft Windows 8 Pro 6.2.9200.0.1252.1.1033.18.32711.28125 [GMT -5:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\Windows\VPDAgent_x64.exe
C:\WINDOWS\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\WINDOWS\system32\nvvsvc.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
C:\WINDOWS\system32\svchost.exe -k apphost
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\SmartErgo\ErgoSuite\ESUpdater.exe
C:\WINDOWS\system32\dashost.exe
C:\Windows\system32\IProsetMonitor.exe
C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
C:\WINDOWS\system32\svchost.exe -k iissvcs
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\taskhostex.exe
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\PIXELA\Everio MediaBrowser 3\MBCameraMonitor.exe
C:\Program Files (x86)\SmartErgo\ErgoSuite\ErgoSuite.exe
C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Users\Marc\AppData\Local\AOL\AIM\aim.exe
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\WinStore\WSHost.exe
C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
C:\WINDOWS\System32\spoolsv.exe
C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe
\\192.168.44.15\cameras\MxCC\MxCC.exe
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
C:\Program Files\Microsoft Office\Office15\EXCEL.EXE
C:\WINDOWS\system32\notepad.exe
\\192.168.44.15\cameras\MxCC\MxCC.exe
C:\WINDOWS\system32\svchost.exe -k GPSvcGroup
C:\Program Files (x86)\SmartErgo\ErgoSuite\smergo.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\pi_brokers\64BitMAPIBroker.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\Office15\OUTLOOK.EXE
C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\Marc\Downloads\putty.exe
C:\Program Files (x86)\FileZilla FTP Client\fzsftp.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.dialsoft.com/startpage.htm
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL
BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
uRun: [Google Update] "C:\Users\Marc\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [ErgoSuite] C:\Program Files (x86)\SmartErgo\ErgoSuite\ErgoSuite.exe
mRun: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [TrueImageMonitor.exe] "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe"
mRun: [AcronisTibMounterMonitor] C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [StatusAlerts] "C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on
mRunOnce: [Z1] C:\mbar\mbar\mbar.exe /cleanup /s
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\DEVICE~1.LNK - C:\Program Files (x86)\PIXELA\Everio MediaBrowser 3\MBCameraMonitor.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: PromptOnSecureDesktop = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~3\Office15\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
IE: {36ECAF82-3300-8F84-092E-AFF36D6C7040} - {86529161-034E-4F8A-88D2-3C625E612E04} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {33415AC7-AFFA-4D55-B41C-C64C0D07DFCA} - hxxps://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISWebManager.CAB
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.2.cab
DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} - hxxps://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab
DPF: {CAA6C3B6-662B-4D14-BB64-EADB88213BFE} - hxxp://192.168.44.18/IPCamPluginTM.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.9.0.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com//activex/ractrl.cab?lmi=972
TCP: NameServer = 192.168.44.1
TCP: Interfaces\{BF9CAAA5-EED2-4717-B203-A0250D3243B1} : DHCPNameServer = 192.168.44.1
TCP: Interfaces\{CB07CE6B-1452-49C0-9938-899927AC79BF} : NameServer = 8.8.8.8,8.8.4.4
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\WINDOWS\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL
x64-BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL
x64-Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
x64-Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
x64-Run: [Acronis Scheduler2 Service] "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"
x64-Run: [HP LJ300-400 color MFP M375-M475 Series Fax] C:\Program Files (x86)\HP\Digital Imaging\Fax\Fax Driver 0.6 Base\hppfaxprintersrv.exe "HP LJ300-400 color MFP M375-M475 Series Fax"
x64-mPolicies-System: PromptOnSecureDesktop = dword:0
x64-mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 asahci64;asahci64;C:\WINDOWS\System32\Drivers\asahci64.sys [2011-9-21 49760]
R0 fltsrv;Acronis Storage Filter Management;C:\WINDOWS\System32\Drivers\fltsrv.sys [2012-11-10 155272]
R0 mv91cons;Marvell 91xx Config Device Driver;C:\WINDOWS\System32\Drivers\mv91cons.sys [2011-9-21 25904]
R0 SMR311;Symantec SMR Utility Service 3.1.1;C:\WINDOWS\System32\Drivers\SMR311.SYS [2012-11-28 95392]
R0 tib_mounter;Acronis TIB Mounter;C:\WINDOWS\System32\Drivers\tib_mounter.sys [2012-11-10 1093256]
R0 vidsflt67;Acronis Disk Storage Filter (67);C:\WINDOWS\System32\Drivers\vsflt67.sys [2012-8-24 146528]
R1 ElRawDisk;ElRawDisk;C:\WINDOWS\System32\Drivers\ffs64.sys [2012-8-1 26080]
R2 afcdpsrv;Acronis Nonstop Backup Service;C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2012-11-10 3696632]
R2 Agent;VPDAgent;C:\Windows\VPDAgent_x64.exe [2012-9-17 148480]
R2 ESUpdater.exe;ErgoSuite Updater Service;C:\Program Files (x86)\SmartErgo\ErgoSuite\ESUpdater.exe [2012-8-17 44544]
R2 HP LaserJet Service;HP LaserJet Service;C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2012-5-2 164864]
R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;C:\WINDOWS\System32\IPROSetMonitor.exe [2012-7-28 178344]
R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-7-5 375728]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2012-6-8 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\System32\Drivers\LMIRfsDriver.sys [2012-7-28 72216]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-9-10 399432]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-9-10 676936]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2012-7-13 769432]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]
R2 syncagentsrv;Acronis Sync Agent Service;C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [2012-8-18 7017888]
R3 afcdp;afcdp;C:\WINDOWS\System32\Drivers\afcdp.sys [2012-11-10 367200]
R3 MBAMProtector;MBAMProtector;C:\WINDOWS\System32\Drivers\mbam.sys [2012-8-29 25928]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\Drivers\WUDFRd.sys [2012-7-25 198656]
S3 cpudrv64;cpudrv64;C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2011-6-2 17864]
S3 ESUpdater2.exe;ErgoSuite Updater Service Companion;C:\Program Files (x86)\SmartErgo\ErgoSuite\ESUpdater2.exe [2012-8-12 15360]
S3 HP DS Service;HP DS Service;C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe [2011-10-17 13824]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE [2012-10-1 178824]
S3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\WINDOWS\System32\Drivers\RTWlanU.sys [2012-9-17 1576080]
S3 RtlWlanu;Realtek Wireless LAN 802.11n USB 2.0 Network Adapter;C:\WINDOWS\System32\Drivers\RTWlanU.sys [2012-9-17 1576080]
S3 tapoas;TAP-Win32 Adapter OAS;C:\WINDOWS\System32\Drivers\tapoas.sys [2012-7-15 30720]
S3 USBAAPL64;Apple Mobile USB Driver;C:\WINDOWS\System32\Drivers\usbaapl64.sys [2012-7-9 52736]
S3 vmbusr;Virtual Machine Bus Provider;C:\WINDOWS\System32\Drivers\vmbusr.sys [2012-7-25 117248]
.
=============== Created Last 30 ================
.
2012-12-03 21:11:20 -------- d-----w- C:\jclofts
2012-12-02 03:47:26 -------- d-----w- C:\mbar
2012-12-01 12:51:33 -------- d-----w- C:\Users\Marc\AppData\Local\{DB83C0BE-860D-45A1-BEF8-8461256B7F8D}
2012-12-01 02:59:36 -------- d-----w- C:\HP_LJ300-400_color_MFP_M375-M475
2012-12-01 02:54:39 -------- d-----w- C:\Users\Marc\AppData\Local\HP
2012-12-01 02:39:20 -------- d-----w- C:\HP_SI_9D1DE902-8058-4555-A16A-FBFAA49587DB
2012-11-30 15:31:41 -------- d-----w- C:\flashterm
2012-11-30 12:51:09 -------- d-----w- C:\Users\Marc\AppData\Local\{FA863195-FE1D-494E-9427-30A45E8FED68}
2012-11-30 02:37:43 -------- d-----w- C:\Users\Marc\DoctorWeb
2012-11-30 02:07:02 -------- d-----w- C:\Program Files (x86)\Nero
2012-11-30 00:50:48 -------- d-----w- C:\Users\Marc\AppData\Local\{2FFB83F9-1410-424F-89C3-749A7327F6B0}
2012-11-29 19:42:51 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-11-29 19:42:51 -------- d-----w- C:\Program Files\iTunes
2012-11-29 19:42:51 -------- d-----w- C:\Program Files\iPod
2012-11-29 12:50:30 -------- d-----w- C:\Users\Marc\AppData\Local\{6530164B-D199-4EFC-8353-50D0C2329128}
2012-11-29 00:50:12 -------- d-----w- C:\Users\Marc\AppData\Local\{0E4D28AB-001F-4EAD-9EF7-26E8523FD8F3}
2012-11-29 00:08:37 95392 ----a-w- C:\WINDOWS\System32\drivers\SMR311.SYS
2012-11-29 00:08:35 -------- d-----w- C:\Users\Marc\AppData\Local\NPE
2012-11-29 00:08:35 -------- d-----w- C:\ProgramData\Norton
2012-11-29 00:04:06 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2012-11-29 00:03:59 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2012-11-29 00:03:46 -------- d-----w- C:\Users\Marc\AppData\Local\Programs
2012-11-28 23:56:15 -------- d-----w- C:\Program Files (x86)\PC Tools
2012-11-28 23:55:27 253256 ----a-w- C:\WINDOWS\System32\drivers\PCTSD64.sys
2012-11-28 23:55:27 -------- d-----w- C:\Program Files (x86)\Common Files\PC Tools
2012-11-28 23:55:03 -------- d-----w- C:\Users\Marc\AppData\Roaming\TestApp
2012-11-28 23:55:03 -------- d-----w- C:\ProgramData\PC Tools
2012-11-28 23:42:21 -------- d-----w- C:\cheese
2012-11-28 23:22:07 -------- d-----w- C:\Users\Marc\AppData\Roaming\TuneUp Software
2012-11-28 23:20:42 -------- d-----w- C:\Users\Marc\AppData\Local\MFAData
2012-11-28 23:20:42 -------- d-----w- C:\Users\Marc\AppData\Local\Avg2013
2012-11-28 23:20:42 -------- d-----w- C:\ProgramData\MFAData
2012-11-28 12:58:31 9125352 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C06B6045-7395-4388-B1E3-74C0084F6DB0}\mpengine.dll
2012-11-28 12:49:50 -------- d-----w- C:\Users\Marc\AppData\Local\{E503A197-D267-4066-8307-68A6BE06701E}
2012-11-28 01:39:33 9125352 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-11-28 00:49:45 -------- d-----w- C:\Users\Marc\AppData\Local\{7E73CAA8-F72B-432C-AC2F-19434AF8ACA9}
2012-11-27 20:06:06 405504 ----a-w- C:\WINDOWS\System32\pcasvc.dll
2012-11-27 20:06:06 31232 ----a-w- C:\WINDOWS\System32\pcadm.dll
2012-11-27 20:06:06 13312 ----a-w- C:\WINDOWS\System32\pcalua.exe
2012-11-27 20:06:06 11776 ----a-w- C:\WINDOWS\System32\pcaevts.dll
2012-11-27 12:49:39 -------- d-----w- C:\Users\Marc\AppData\Local\{AED6522C-864B-4BA4-B7F5-05D0EA28ECB6}
2012-11-27 00:49:33 -------- d-----w- C:\Users\Marc\AppData\Local\{0AD9F784-5A9F-4CA9-B608-953655C9E132}
2012-11-26 12:49:27 -------- d-----w- C:\Users\Marc\AppData\Local\{BA78179E-1C22-4D2D-A973-67FB62D2C36F}
2012-11-26 00:49:21 -------- d-----w- C:\Users\Marc\AppData\Local\{815292B4-5542-4D8D-B3E3-4190E67C1905}
2012-11-26 00:44:45 -------- d-----w- C:\Users\Marc\saran
2012-11-24 14:58:40 -------- d-----w- C:\Program Files (x86)\GoFTP
2012-11-16 02:12:22 -------- d-----w- C:\Program Files (x86)\Common Files\Software Update Utility
2012-11-16 00:47:27 -------- d-----w- C:\Users\Marc\AppData\Local\{A8FAFAD7-5416-48A1-9816-2349F9D95CDA}
2012-11-14 22:09:47 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server
2012-11-14 22:09:30 -------- d-----w- C:\WINDOWS\PCHEALTH
2012-11-14 22:09:30 -------- d-----w- C:\Program Files\Microsoft SQL Server
2012-11-14 15:20:09 -------- d-----w- C:\Users\Marc\AppData\Local\Deployment
2012-11-14 00:46:51 -------- d-----w- C:\Users\Marc\AppData\Local\{C2EA1490-CC8B-441C-B933-AF0728950C81}
2012-11-13 21:56:56 17888 ----a-w- C:\WINDOWS\System32\msvcr100_clr0400.dll
2012-11-11 00:46:04 -------- d-----w- C:\Users\Marc\AppData\Local\{F62DCC24-6479-4356-88E3-A8D557AA2780}
2012-11-10 21:43:21 367200 ----a-w- C:\WINDOWS\System32\drivers\afcdp.sys
2012-11-10 21:43:19 1340040 ----a-w- C:\WINDOWS\System32\drivers\tdrpman.sys
2012-11-10 21:43:18 1093256 ----a-w- C:\WINDOWS\System32\drivers\tib_mounter.sys
2012-11-10 21:43:17 340104 ----a-w- C:\WINDOWS\System32\drivers\snapman.sys
2012-11-10 21:43:17 155272 ----a-w- C:\WINDOWS\System32\drivers\fltsrv.sys
2012-11-10 12:45:46 -------- d-----w- C:\Users\Marc\AppData\Local\{6E8BC86A-52DA-4B9F-BEFA-72721BC35E9D}
2012-11-09 00:45:16 -------- d-----w- C:\Users\Marc\AppData\Local\{E9CD6ACB-8C9F-4812-AA14-73FB913163BB}
2012-11-08 18:13:54 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin7.dll
2012-11-08 18:13:54 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin6.dll
2012-11-08 18:13:54 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin5.dll
2012-11-08 18:13:54 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin4.dll
2012-11-08 18:13:54 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin3.dll
2012-11-08 18:13:54 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin2.dll
2012-11-08 18:13:54 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin.dll
2012-11-08 16:47:24 27704 ------w- C:\WINDOWS\System32\hppfaxprintermon5.dll
2012-11-08 16:47:24 22072 ------w- C:\WINDOWS\System32\hppfaxprintermonui5.dll
2012-11-08 16:46:12 342016 ----a-w- C:\WINDOWS\System32\Spool\prtprocs\x64\hpcpp120.DLL
2012-11-08 16:46:12 342016 ----a-w- C:\WINDOWS\System32\Spool\prtprocs\x64\1_hpcpp120.DLL
2012-11-08 16:42:59 322048 ----a-w- C:\WINDOWS\SysWow64\hpcc3120.DLL
2012-11-08 16:42:59 286720 ----a-w- C:\WINDOWS\System32\hpcpn120.dll
2012-11-08 15:06:55 310272 ----a-w- C:\WINDOWS\System32\hpbcoins64.dll
2012-11-05 14:50:15 -------- d-----w- C:\Users\Marc\AppData\Local\Diagnostics
.
==================== Find3M ====================
.
2012-12-01 03:18:49 608 --sha-w- C:\WINDOWS\System32\winzvprt5.sys
2012-11-06 12:42:16 88008 ----a-w- C:\WINDOWS\System32\LMIRfsClientNP.dll
2012-11-06 12:42:16 35240 ----a-w- C:\WINDOWS\System32\LMIport.dll
2012-11-06 12:42:15 83880 ----a-w- C:\WINDOWS\System32\LMIinit.dll
2012-11-02 05:22:08 34304 ----a-w- C:\WINDOWS\SysWow64\wuapp.exe
2012-11-02 05:21:44 83968 ----a-w- C:\WINDOWS\SysWow64\wudriver.dll
2012-11-02 05:21:44 125952 ----a-w- C:\WINDOWS\SysWow64\wuwebv.dll
2012-11-02 05:21:28 246784 ----a-w- C:\WINDOWS\SysWow64\ubpm.dll
2012-11-02 05:20:31 39424 ----a-w- C:\WINDOWS\System32\wuapp.exe
2012-11-02 05:20:28 77824 ----a-w- C:\WINDOWS\System32\taskhost.exe
2012-11-02 05:20:28 72192 ----a-w- C:\WINDOWS\System32\taskhostex.exe
2012-11-02 05:20:10 141824 ----a-w- C:\WINDOWS\System32\wuwebv.dll
2012-11-02 05:20:09 98304 ----a-w- C:\WINDOWS\System32\wudriver.dll
2012-11-02 05:20:09 251904 ----a-w- C:\WINDOWS\System32\WUSettingsProvider.dll
2012-11-02 05:20:09 17408 ----a-w- C:\WINDOWS\System32\wuaext.dll
2012-11-02 05:20:09 1619968 ----a-w- C:\WINDOWS\System32\wucltux.dll
2012-11-02 05:19:50 318464 ----a-w- C:\WINDOWS\System32\ubpm.dll
2012-11-02 05:01:27 99328 ----a-w- C:\WINDOWS\System32\wushareduxresources.dll
2012-11-02 04:55:32 212992 ----a-w- C:\WINDOWS\System32\drivers\mrxsmb20.sys
2012-11-02 04:53:13 366080 ----a-w- C:\WINDOWS\System32\drivers\mrxsmb.sys
2012-10-29 05:04:47 522640 ----a-w- C:\WINDOWS\System32\AUDIOKSE.dll
2012-10-29 05:04:47 490064 ----a-w- C:\WINDOWS\System32\AudioEng.dll
2012-10-29 05:04:47 447792 ----a-w- C:\WINDOWS\System32\AudioSes.dll
2012-10-29 05:04:47 253512 ----a-w- C:\WINDOWS\System32\audiodg.exe
2012-10-29 03:21:53 1526784 ----a-w- C:\WINDOWS\System32\mfcore.dll
2012-10-29 03:21:21 267264 ----a-w- C:\WINDOWS\System32\EncDump.dll
2012-10-29 03:20:49 785920 ----a-w- C:\WINDOWS\System32\audiosrv.dll
2012-10-29 03:20:49 169472 ----a-w- C:\WINDOWS\System32\AudioEndpointBuilder.dll
2012-10-29 03:19:08 463768 ----a-w- C:\WINDOWS\SysWow64\AUDIOKSE.dll
2012-10-29 03:19:08 427568 ----a-w- C:\WINDOWS\SysWow64\AudioEng.dll
2012-10-29 03:19:08 324344 ----a-w- C:\WINDOWS\SysWow64\AudioSes.dll
2012-10-29 02:46:23 1451520 ----a-w- C:\WINDOWS\SysWow64\mfcore.dll
2012-10-26 22:19:09 80728 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2012-10-26 22:19:09 695648 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2012-10-25 08:12:26 94208 ----a-w- C:\WINDOWS\SysWow64\QuickTimeVR.qtx
2012-10-25 08:12:26 69632 ----a-w- C:\WINDOWS\SysWow64\QuickTime.qts
2012-10-24 04:54:06 6972136 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2012-10-24 03:25:41 26624 ----a-w- C:\WINDOWS\System32\ReAgentc.exe
2012-10-24 03:24:42 439296 ----a-w- C:\WINDOWS\System32\ReAgent.dll
2012-10-24 03:06:12 2706432 ----a-w- C:\WINDOWS\System32\mshtml.tlb
2012-10-24 02:48:12 24064 ----a-w- C:\WINDOWS\SysWow64\ReAgentc.exe
2012-10-24 02:47:29 371712 ----a-w- C:\WINDOWS\SysWow64\ReAgent.dll
2012-10-24 02:27:01 2706432 ----a-w- C:\WINDOWS\SysWow64\mshtml.tlb
2012-10-20 03:22:05 39936 ----a-w- C:\WINDOWS\apppatch\apppatch64\acspecfc.dll
2012-10-20 02:44:53 431104 ----a-w- C:\WINDOWS\apppatch\AcSpecfc.dll
2012-10-20 02:25:35 310784 ----a-w- C:\WINDOWS\apppatch\AcRes.dll
2012-10-19 04:59:28 4056576 ----a-w- C:\WINDOWS\System32\win32k.sys
2012-10-19 04:03:02 12501352 ----a-w- C:\WINDOWS\SysWow64\nvwgf2um.dll
2012-10-19 04:03:00 1760104 ----a-w- C:\WINDOWS\System32\nvdispco64.dll
2012-10-18 06:17:18 69864 ----a-w- C:\WINDOWS\System32\drivers\pdc.sys
2012-10-18 03:20:46 10096640 ----a-w- C:\WINDOWS\System32\twinui.dll
2012-10-18 03:18:40 2302464 ----a-w- C:\WINDOWS\System32\authui.dll
2012-10-18 03:18:33 2146816 ----a-w- C:\WINDOWS\System32\actxprxy.dll
2012-10-18 02:46:00 8856576 ----a-w- C:\WINDOWS\SysWow64\twinui.dll
2012-10-18 02:44:38 2033664 ----a-w- C:\WINDOWS\SysWow64\authui.dll
2012-10-18 02:44:33 753664 ----a-w- C:\WINDOWS\SysWow64\actxprxy.dll
2012-10-17 04:32:52 1172992 ----a-w- C:\WINDOWS\System32\mfnetsrc.dll
2012-10-17 04:32:51 677888 ----a-w- C:\WINDOWS\System32\mfnetcore.dll
2012-10-17 04:32:51 673280 ----a-w- C:\WINDOWS\System32\mfmpeg2srcsnk.dll
2012-10-17 04:32:50 1048064 ----a-w- C:\WINDOWS\System32\mfasfsrcsnk.dll
2012-10-17 03:57:37 929792 ----a-w- C:\WINDOWS\SysWow64\mfnetsrc.dll
2012-10-17 03:57:37 568832 ----a-w- C:\WINDOWS\SysWow64\mfnetcore.dll
2012-10-17 03:57:37 513024 ----a-w- C:\WINDOWS\SysWow64\mfmpeg2srcsnk.dll
2012-10-17 03:57:36 850944 ----a-w- C:\WINDOWS\SysWow64\mfasfsrcsnk.dll
2012-10-12 08:08:01 27880 ----a-w- C:\WINDOWS\System32\drivers\rdpvideominiport.sys
2012-10-12 06:14:54 87040 ----a-w- C:\WINDOWS\System32\srmtrace.dll
2012-10-12 06:14:54 652800 ----a-w- C:\WINDOWS\System32\srmscan.dll
2012-10-12 06:14:54 30720 ----a-w- C:\WINDOWS\System32\srm_ps.dll
2012-10-12 06:14:54 279040 ----a-w- C:\WINDOWS\System32\srm.dll
2012-10-12 06:14:54 274432 ----a-w- C:\WINDOWS\System32\srmstormod.dll
2012-10-12 06:14:54 172032 ----a-w- C:\WINDOWS\System32\srmshell.dll
2012-10-12 06:14:54 1347072 ----a-w- C:\WINDOWS\System32\srmclient.dll
2012-10-12 06:14:54 134144 ----a-w- C:\WINDOWS\System32\adrclient.dll
2012-10-12 06:14:40 36352 ----a-w- C:\WINDOWS\System32\rfxvmt.dll
2012-10-12 06:14:39 3244032 ----a-w- C:\WINDOWS\System32\rdpcorets.dll
2012-10-12 06:14:34 115712 ----a-w- C:\WINDOWS\System32\wbem\PolicMan.dll
2012-10-12 06:13:32 109568 ----a-w- C:\WINDOWS\System32\dskquota.dll
2012-10-12 05:50:01 235520 ----a-w- C:\WINDOWS\System32\rdpudd.dll
2012-10-12 05:46:28 618496 ----a-w- C:\WINDOWS\System32\drivers\srv2.sys
2012-10-12 05:41:02 987648 ----a-w- C:\WINDOWS\SysWow64\srmclient.dll
2012-10-12 05:41:02 68096 ----a-w- C:\WINDOWS\SysWow64\srmtrace.dll
2012-10-12 05:41:02 487936 ----a-w- C:\WINDOWS\SysWow64\srmscan.dll
2012-10-12 05:41:02 278528 ----a-w- C:\WINDOWS\SysWow64\srm.dll
2012-10-12 05:41:02 202240 ----a-w- C:\WINDOWS\SysWow64\srmstormod.dll
2012-10-12 05:41:02 15872 ----a-w- C:\WINDOWS\SysWow64\srm_ps.dll
2012-10-12 05:41:02 128000 ----a-w- C:\WINDOWS\SysWow64\srmshell.dll
2012-10-12 05:41:02 104448 ----a-w- C:\WINDOWS\SysWow64\adrclient.dll
2012-10-12 05:40:49 84992 ----a-w- C:\WINDOWS\SysWow64\wbem\PolicMan.dll
2012-10-12 05:39:54 82944 ----a-w- C:\WINDOWS\SysWow64\dskquota.dll
2012-10-11 07:47:18 793200 ----a-w- C:\WINDOWS\System32\mfplat.dll
2012-10-11 07:35:16 2380944 ----a-w- C:\WINDOWS\explorer.exe
2012-10-11 07:26:44 336104 ----a-w- C:\WINDOWS\System32\drivers\Classpnp.sys
2012-10-11 07:25:48 56552 ----a-w- C:\WINDOWS\System32\drivers\sdstor.sys
2012-10-11 07:23:33 1001192 ----a-w- C:\WINDOWS\System32\drivers\ndis.sys
2012-10-11 07:23:32 441576 ----a-w- C:\WINDOWS\System32\drivers\netio.sys
2012-10-11 07:18:25 172264 ----a-w- C:\WINDOWS\System32\drivers\ksecpkg.sys
2012-10-11 07:16:20 1403784 ----a-w- C:\WINDOWS\System32\winload.efi
2012-10-11 07:16:20 1267424 ----a-w- C:\WINDOWS\System32\winload.exe
2012-10-11 07:16:20 1217328 ----a-w- C:\WINDOWS\System32\winresume.efi
2012-10-11 07:16:19 1093880 ----a-w- C:\WINDOWS\System32\winresume.exe
2011-11-17 06:35:25 30720 --sha-w- C:\WINDOWS\Secur32.dll
2009-07-14 01:40:56 862056 --sha-w- C:\WINDOWS\System32\prfn0885.dat
.
============= FINISH: 16:19:47.44 ===============



.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 8 Pro
Boot Device: \Device\HarddiskVolume1
Install Date: 10/26/2012 9:06:23 PM
System Uptime: 11/30/2012 10:10:44 PM (66 hours ago)
.
Motherboard: ASUSTeK COMPUTER INC. | | SABERTOOTH X79
Processor: Intel® Core™ i7-3930K CPU @ 3.20GHz | LGA2011 | 3201/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 223 GiB total, 19.372 GiB free.
D: is CDROM (CDFS)
E: is Removable
F: is Removable
G: is Removable
H: is Removable
M: is NetworkDisk (NTFS) - 7460 GiB total, 4272.927 GiB free.
Z: is NetworkDisk (NTFS) - 7460 GiB total, 4272.927 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {36fc9e60-c465-11cf-8056-444553540000}
Description: USB Root Hub (xHCI)
Device ID: USB\ROOT_HUB30\5&2639434C&1&0
Manufacturer: (Standard USB HUBs)
Name: USB Root Hub (xHCI)
PNP Device ID: USB\ROOT_HUB30\5&2639434C&1&0
Service: USBHUB3
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Realtek RTL8188CU Wireless LAN 802.11n USB 2.0 Network Adapter
Device ID: USB\VID_0BDA&PID_8176\00E04C000001
Manufacturer: Realtek Semiconductor Corp.
Name: Realtek RTL8188CU Wireless LAN 802.11n USB 2.0 Network Adapter
PNP Device ID: USB\VID_0BDA&PID_8176\00E04C000001
Service: RtlWlanu
.
==== System Restore Points ===================
.
RP28: 12/3/2012 3:20:15 AM - Scheduled Checkpoint
.
==== Installed Programs ======================
.
64 Bit HP CIO Components Installer
Adobe AIR
Adobe Flash Player 11 Plugin
Adobe Reader XI
Adobe Shockwave Player 11.6
AIM for Windows
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Asmedia ASM104x USB 3.0 Host Controller Driver
Asmedia ASM106x SATA Host Controller Driver
Attack Surface Analyzer
BlackBerry Desktop Software 7.1
Bonjour
BulletProof FTP Server 2011 (remove only)
Colasoft MAC Scanner 2.2 Pro
Corel PaintShop Pro X4
CutePDF Writer 3.0
D3DX10
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition
Download Updater (AOL LLC)
ErgoSuite
Everio MediaBrowser 3
FileZilla Client 3.6.0.2
FreshDiagnose
Google Chrome
Google Update Helper
HP LJ300-400 color MFP M375-M475
HP LJ300-400 color MFP M375-M475 Fax
HP LJ300-400 M375-M475 HP Scan
HP Product FWUpdater
HP Unified IO
HP Update
hpbDSService
hpbM375M475DSService
HPLaserJet300-400ColorM375-M475Series_HelpLearnCenter_SI
HPLJDXPHelper
HPLJUTCore
HPLJUTM375-M475
hppFaxDrvM375M475
hppLaserJetService
hppM375_M475LaserJetService
hppSendFaxM375M475
hppToolboxProxyM375
hpStatusAlerts
hpStatusAlertsM375_M475
ICA
iCloud
InstanceFinder
Intel® Network Connections 16.6.126.0
IPM_PSP_COM
iTunes
Java 7 Update 9
Java Auto Updater
JavaFX 2.1.1
LinkedIn Outlook Connector
LJDXPHelperUI
LogMeIn
Malwarebytes Anti-Malware version 1.65.1.1000
marvell 91xx driver
Microsoft Access MUI (English) 2013
Microsoft Access Setup Metadata MUI (English) 2013
Microsoft Application Error Reporting
Microsoft DCF MUI (English) 2013
Microsoft Excel MUI (English) 2013
Microsoft Groove MUI (English) 2013
Microsoft InfoPath MUI (English) 2013
Microsoft Lync MUI (English) 2013
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 32-bit Components 2013
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office Office 32-bit Components 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office OSM MUI (English) 2013
Microsoft Office OSM UX MUI (English) 2013
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Professional Plus 2013
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Proofing (English) 2013
Microsoft Office Proofing Tools 2013 - English
Microsoft Office Proofing Tools 2013 - Español
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared 32-bit MUI (English) 2010
Microsoft Office Shared 32-bit MUI (English) 2013
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared MUI (English) 2013
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2013
Microsoft Office Word MUI (English) 2010
Microsoft OneNote MUI (English) 2013
Microsoft Outlook MUI (English) 2013
Microsoft Outlook Social Connector Provider for Facebook 64-bit
Microsoft PowerPoint MUI (English) 2013
Microsoft Publisher MUI (English) 2013
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft SQL Server Compact 3.5 SP2 x64 ENU
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Word MUI (English) 2013
MSVCRT
MxControlCenter (x64) version 2.5.2
Neat
Neat ADF Scanner 2008 Driver
Neat ADF Scanner Driver
Neat Core Files
Neat Mobile Scanner (Silver) Driver
Neat Mobile Scanner 2008 Driver
Neat Mobile Scanner Driver
Nero 12
Nero Audio Pack 1
Nero BackItUp Help (CHM)
Nero Blu-ray Player
Nero Blu-ray Player Help (CHM)
Nero Burning ROM
Nero Burning ROM Help (CHM)
Nero ControlCenter
Nero ControlCenter Help (CHM)
Nero Core Components
Nero Disc Menus Basic
Nero Effects Basic
Nero Express Help (CHM)
Nero Kwik Media Help (CHM)
Nero Kwik Themes Basic
Nero Launcher
Nero PiP Effects Basic
Nero Recode Help (CHM)
Nero RescueAgent Help (CHM)
Nero SharedVideoCodecs
Nero Update
Nero Video Help (CHM)
neroxml
NVIDIA 3D Vision Controller Driver 306.97
NVIDIA 3D Vision Driver 306.97
NVIDIA Control Panel 306.97
NVIDIA Graphics Driver 306.97
NVIDIA HD Audio Driver 1.3.18.0
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX System Software 9.12.0604
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.10.8
NVIDIA Update Components
Octoshape add-in for Adobe Flash Player
Opera 12.02
OutBack Plus 8.0
Outils de vérification linguistique 2013 de Microsoft Office - Français
Prerequisite installer
PSPPContent
PSPPHelp
PSPPro64
QuickTime
Safari
SeaTools for Windows
Security Update for Microsoft Excel 2010 (KB2597126) 64-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2687417) 64-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2687436) 64-Bit Edition
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2553260) 64-Bit Edition
Security Update for Microsoft Office 2010 (KB2553371) 64-Bit Edition
Security Update for Microsoft Office 2010 (KB2553447) 64-Bit Edition
Security Update for Microsoft Office 2010 (KB2589320) 64-Bit Edition
Security Update for Microsoft Office 2010 (KB2589322) 64-Bit Edition
Security Update for Microsoft Office 2010 (KB2598243) 64-Bit Edition
Security Update for Microsoft PowerPoint 2010 (KB2553185) 64-Bit Edition
Security Update for Microsoft Visio Viewer 2010 (KB2598287) 64-Bit Edition
Security Update for Microsoft Word 2010 (KB2553488) 64-Bit Edition
Send To Neat
Setup
SmartDraw 2012
SmartDraw PDF Export (novaPDF 6.4 printer)
Source SDK Base 2007
Steam
swMSM
System Requirements Lab for Intel
ToolboxProxy
True Image 2013
TweetDeck
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553272) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2687509) 64-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition
Update for Microsoft OneNote 2010 (KB2687277) 64-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 64-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition
Visual Studio 2010 x64 Redistributables
Welcome App (Start-up experience)
Windows 7 USB/DVD Download Tool
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
WinHTTrack Website Copier 3.46-1 (x64)
WinRAR 4.20 (64-bit)
.
==== Event Viewer Messages From Past Week ========
.
12/3/2012 3:14:16 AM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
12/3/2012 2:29:06 PM, Error: Schannel [36888] - A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 51. The Windows SChannel error state is 900.
12/3/2012 1:15:20 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {000C101C-0000-0000-C000-000000000046} and APPID {000C101C-0000-0000-C000-000000000046} to the user MARCX797-28-12\Marc SID (S-1-5-21-2561492993-4184864888-1342817930-1000) from address LocalHost (Using LRPC) running in the application container Unavailable SID (S-1-15-2-1547483067-1722875394-2649438771-344752879-3610485692-1170447297-7736066). This security permission can be modified using the Component Services administrative tool.
12/1/2012 3:31:06 PM, Error: Schannel [36888] - A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 20. The Windows SChannel error state is 960.
11/30/2012 9:49:03 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user MARCX797-28-12\Marc SID (S-1-5-21-2561492993-4184864888-1342817930-1000) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
11/30/2012 9:23:55 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {B77C4C36-0154-4C52-AB49-FAA03837E47F} and APPID {EA022610-0748-4C24-B229-6C507EBDFDBB} to the user MARCX797-28-12\Marc SID (S-1-5-21-2561492993-4184864888-1342817930-1000) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
11/30/2012 5:33:42 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {000C101C-0000-0000-C000-000000000046} and APPID {000C101C-0000-0000-C000-000000000046} to the user MARCX797-28-12\Marc SID (S-1-5-21-2561492993-4184864888-1342817930-1000) from address LocalHost (Using LRPC) running in the application container Unavailable SID (S-1-15-2-3530718740-1279322847-1677945534-2140387140-3067279269-535928133-3743132526). This security permission can be modified using the Component Services administrative tool.
11/30/2012 3:20:24 PM, Error: Schannel [36887] - A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 51.
11/30/2012 10:34:29 PM, Error: Schannel [36888] - A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
11/30/2012 10:19:27 PM, Error: Service Control Manager [7023] - The Interactive Services Detection service terminated with the following error: Incorrect function.
11/29/2012 2:48:50 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {000C101C-0000-0000-C000-000000000046} and APPID {000C101C-0000-0000-C000-000000000046} to the user MARCX797-28-12\Marc SID (S-1-5-21-2561492993-4184864888-1342817930-1000) from address LocalHost (Using LRPC) running in the application container Unavailable SID (S-1-15-2-1714615354-863441280-2317539789-61404461-3350186080-2038428883-49485938). This security permission can be modified using the Component Services administrative tool.
11/29/2012 2:43:26 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Apple Mobile Device service, but this action failed with the following error: An instance of the service is already running.
11/29/2012 2:42:26 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
11/29/2012 2:42:24 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
11/29/2012 11:18:17 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {000C101C-0000-0000-C000-000000000046} and APPID {000C101C-0000-0000-C000-000000000046} to the user MARCX797-28-12\Marc SID (S-1-5-21-2561492993-4184864888-1342817930-1000) from address LocalHost (Using LRPC) running in the application container Unavailable SID (S-1-15-2-3511156758-3933384089-2094220618-4158294342-3159580957-1722781727-3342288421). This security permission can be modified using the Component Services administrative tool.
11/29/2012 10:46:21 AM, Error: Schannel [36888] - A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 107.
11/29/2012 10:46:21 AM, Error: Schannel [36874] - An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
11/28/2012 9:18:46 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied.
11/28/2012 9:18:45 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000003b (0x00000000c0000005, 0xfffff88001b722c5, 0xfffff8800cade090, 0x0000000000000000). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: 112812-42031-01.
11/28/2012 6:56:55 PM, Error: PCTCore [280] -
.
==== End Of File ===========================

Attached Files



BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,743 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:32 PM

Posted 08 December 2012 - 04:30 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

Posted Image In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/477288 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

Posted Image If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from one of the following links if you no longer have it available. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 dialsoft

dialsoft
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:32 PM

Posted 08 December 2012 - 08:17 PM

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16442 BrowserJavaVersion: 10.9.2
Run by Marc at 20:15:38 on 2012-12-08
Microsoft Windows 8 Pro 6.2.9200.0.1252.1.1033.18.32711.27545 [GMT -5:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\Windows\VPDAgent_x64.exe
C:\WINDOWS\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\WINDOWS\system32\nvvsvc.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
C:\WINDOWS\system32\svchost.exe -k apphost
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\SmartErgo\ErgoSuite\ESUpdater.exe
C:\WINDOWS\system32\dashost.exe
C:\Windows\system32\IProsetMonitor.exe
C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
C:\WINDOWS\system32\svchost.exe -k iissvcs
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\HP\Digital Imaging\Fax\Fax Driver 0.6 Base\hppfaxprintersrv.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\PIXELA\Everio MediaBrowser 3\MBCameraMonitor.exe
C:\Program Files (x86)\SmartErgo\ErgoSuite\ErgoSuite.exe
C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Marc\AppData\Local\AOL\AIM\aim.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\WINDOWS\system32\mstsc.exe
C:\Program Files\Microsoft Office\Office15\EXCEL.EXE
\\192.168.44.15\cameras\MxCC\MxCC.exe
\\192.168.44.15\cameras\MxCC\MxCC.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Microsoft Office\Office15\WINWORD.EXE
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4396.1016_x64__8wekyb3d8bbwe\LiveComm.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Microsoft Office\Office15\OUTLOOK.EXE
C:\Program Files (x86)\Nero\Update\NANotify.exe
C:\Program Files (x86)\SmartErgo\ErgoSuite\smergo.exe
C:\WINDOWS\system32\svchost.exe -k GPSvcGroup
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\splwow64.exe
C:\WINDOWS\system32\vssvc.exe
C:\WINDOWS\System32\svchost.exe -k swprv
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.dialsoft.com/startpage.htm
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL
BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
uRun: [Google Update] "C:\Users\Marc\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [ErgoSuite] C:\Program Files (x86)\SmartErgo\ErgoSuite\ErgoSuite.exe
mRun: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [TrueImageMonitor.exe] "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe"
mRun: [AcronisTibMounterMonitor] C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [StatusAlerts] "C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\DEVICE~1.LNK - C:\Program Files (x86)\PIXELA\Everio MediaBrowser 3\MBCameraMonitor.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: PromptOnSecureDesktop = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~3\Office15\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
IE: {36ECAF82-3300-8F84-092E-AFF36D6C7040} - {86529161-034E-4F8A-88D2-3C625E612E04} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {33415AC7-AFFA-4D55-B41C-C64C0D07DFCA} - hxxps://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISWebManager.CAB
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.2.cab
DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} - hxxps://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab
DPF: {CAA6C3B6-662B-4D14-BB64-EADB88213BFE} - hxxp://192.168.44.18/IPCamPluginTM.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.9.0.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com//activex/ractrl.cab?lmi=972
TCP: NameServer = 192.168.44.1
TCP: Interfaces\{BF9CAAA5-EED2-4717-B203-A0250D3243B1} : DHCPNameServer = 192.168.44.1
TCP: Interfaces\{CB07CE6B-1452-49C0-9938-899927AC79BF} : NameServer = 8.8.8.8,8.8.4.4
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\WINDOWS\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL
x64-BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL
x64-Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
x64-Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
x64-Run: [Acronis Scheduler2 Service] "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"
x64-Run: [HP LJ300-400 color MFP M375-M475 Series Fax] C:\Program Files (x86)\HP\Digital Imaging\Fax\Fax Driver 0.6 Base\hppfaxprintersrv.exe "HP LJ300-400 color MFP M375-M475 Series Fax"
x64-mPolicies-System: PromptOnSecureDesktop = dword:0
x64-mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 asahci64;asahci64;C:\WINDOWS\System32\Drivers\asahci64.sys [2011-9-21 49760]
R0 fltsrv;Acronis Storage Filter Management;C:\WINDOWS\System32\Drivers\fltsrv.sys [2012-11-10 155272]
R0 mv91cons;Marvell 91xx Config Device Driver;C:\WINDOWS\System32\Drivers\mv91cons.sys [2011-9-21 25904]
R0 SMR311;Symantec SMR Utility Service 3.1.1;C:\WINDOWS\System32\Drivers\SMR311.SYS [2012-11-28 95392]
R0 tib_mounter;Acronis TIB Mounter;C:\WINDOWS\System32\Drivers\tib_mounter.sys [2012-11-10 1093256]
R0 vidsflt67;Acronis Disk Storage Filter (67);C:\WINDOWS\System32\Drivers\vsflt67.sys [2012-8-24 146528]
R1 ElRawDisk;ElRawDisk;C:\WINDOWS\System32\Drivers\ffs64.sys [2012-8-1 26080]
R2 afcdpsrv;Acronis Nonstop Backup Service;C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2012-11-10 3696632]
R2 Agent;VPDAgent;C:\Windows\VPDAgent_x64.exe [2012-9-17 148480]
R2 ESUpdater.exe;ErgoSuite Updater Service;C:\Program Files (x86)\SmartErgo\ErgoSuite\ESUpdater.exe [2012-8-17 44544]
R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;C:\WINDOWS\System32\IPROSetMonitor.exe [2012-7-28 178344]
R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-7-5 375728]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2012-6-8 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\System32\Drivers\LMIRfsDriver.sys [2012-7-28 72216]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-9-10 399432]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-9-10 676936]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2012-7-13 769432]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]
R2 syncagentsrv;Acronis Sync Agent Service;C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [2012-8-18 7017888]
R3 afcdp;afcdp;C:\WINDOWS\System32\Drivers\afcdp.sys [2012-11-10 367200]
R3 MBAMProtector;MBAMProtector;C:\WINDOWS\System32\Drivers\mbam.sys [2012-8-29 25928]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\Drivers\WUDFRd.sys [2012-7-25 198656]
S2 HP LaserJet Service;HP LaserJet Service;C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2012-5-2 164864]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-9 160944]
S3 cpudrv64;cpudrv64;C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2011-6-2 17864]
S3 ESUpdater2.exe;ErgoSuite Updater Service Companion;C:\Program Files (x86)\SmartErgo\ErgoSuite\ESUpdater2.exe [2012-8-12 15360]
S3 HP DS Service;HP DS Service;C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe [2011-10-17 13824]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE [2012-10-1 178824]
S3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\WINDOWS\System32\Drivers\RTWlanU.sys [2012-9-17 1576080]
S3 RtlWlanu;Realtek Wireless LAN 802.11n USB 2.0 Network Adapter;C:\WINDOWS\System32\Drivers\RTWlanU.sys [2012-9-17 1576080]
S3 tapoas;TAP-Win32 Adapter OAS;C:\WINDOWS\System32\Drivers\tapoas.sys [2012-7-15 30720]
S3 USBAAPL64;Apple Mobile USB Driver;C:\WINDOWS\System32\Drivers\usbaapl64.sys [2012-7-9 52736]
S3 vmbusr;Virtual Machine Bus Provider;C:\WINDOWS\System32\Drivers\vmbusr.sys [2012-7-25 117248]
.
=============== Created Last 30 ================
.
2012-12-07 02:12:49 -------- d-----r- C:\Program Files (x86)\Skype
2012-12-03 21:11:20 -------- d-----w- C:\jclofts
2012-12-02 03:47:26 -------- d-----w- C:\mbar
2012-12-01 12:51:33 -------- d-----w- C:\Users\Marc\AppData\Local\{DB83C0BE-860D-45A1-BEF8-8461256B7F8D}
2012-12-01 02:59:36 -------- d-----w- C:\HP_LJ300-400_color_MFP_M375-M475
2012-12-01 02:54:39 -------- d-----w- C:\Users\Marc\AppData\Local\HP
2012-12-01 02:39:20 -------- d-----w- C:\HP_SI_9D1DE902-8058-4555-A16A-FBFAA49587DB
2012-11-30 15:31:41 -------- d-----w- C:\flashterm
2012-11-30 12:51:09 -------- d-----w- C:\Users\Marc\AppData\Local\{FA863195-FE1D-494E-9427-30A45E8FED68}
2012-11-30 02:37:43 -------- d-----w- C:\Users\Marc\DoctorWeb
2012-11-30 02:07:02 -------- d-----w- C:\Program Files (x86)\Nero
2012-11-30 00:50:48 -------- d-----w- C:\Users\Marc\AppData\Local\{2FFB83F9-1410-424F-89C3-749A7327F6B0}
2012-11-29 19:42:51 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-11-29 19:42:51 -------- d-----w- C:\Program Files\iTunes
2012-11-29 19:42:51 -------- d-----w- C:\Program Files\iPod
2012-11-29 12:50:30 -------- d-----w- C:\Users\Marc\AppData\Local\{6530164B-D199-4EFC-8353-50D0C2329128}
2012-11-29 00:50:12 -------- d-----w- C:\Users\Marc\AppData\Local\{0E4D28AB-001F-4EAD-9EF7-26E8523FD8F3}
2012-11-29 00:08:37 95392 ----a-w- C:\WINDOWS\System32\drivers\SMR311.SYS
2012-11-29 00:08:35 -------- d-----w- C:\Users\Marc\AppData\Local\NPE
2012-11-29 00:08:35 -------- d-----w- C:\ProgramData\Norton
2012-11-29 00:04:06 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2012-11-29 00:03:59 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2012-11-29 00:03:46 -------- d-----w- C:\Users\Marc\AppData\Local\Programs
2012-11-28 23:56:15 -------- d-----w- C:\Program Files (x86)\PC Tools
2012-11-28 23:55:27 253256 ----a-w- C:\WINDOWS\System32\drivers\PCTSD64.sys
2012-11-28 23:55:27 -------- d-----w- C:\Program Files (x86)\Common Files\PC Tools
2012-11-28 23:55:03 -------- d-----w- C:\Users\Marc\AppData\Roaming\TestApp
2012-11-28 23:55:03 -------- d-----w- C:\ProgramData\PC Tools
2012-11-28 23:42:21 -------- d-----w- C:\cheese
2012-11-28 23:22:07 -------- d-----w- C:\Users\Marc\AppData\Roaming\TuneUp Software
2012-11-28 23:20:42 -------- d-----w- C:\Users\Marc\AppData\Local\MFAData
2012-11-28 23:20:42 -------- d-----w- C:\Users\Marc\AppData\Local\Avg2013
2012-11-28 23:20:42 -------- d-----w- C:\ProgramData\MFAData
2012-11-28 12:58:31 9125352 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C06B6045-7395-4388-B1E3-74C0084F6DB0}\mpengine.dll
2012-11-28 12:49:50 -------- d-----w- C:\Users\Marc\AppData\Local\{E503A197-D267-4066-8307-68A6BE06701E}
2012-11-28 01:39:33 9125352 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-11-28 00:49:45 -------- d-----w- C:\Users\Marc\AppData\Local\{7E73CAA8-F72B-432C-AC2F-19434AF8ACA9}
2012-11-27 20:06:06 405504 ----a-w- C:\WINDOWS\System32\pcasvc.dll
2012-11-27 20:06:06 31232 ----a-w- C:\WINDOWS\System32\pcadm.dll
2012-11-27 20:06:06 13312 ----a-w- C:\WINDOWS\System32\pcalua.exe
2012-11-27 20:06:06 11776 ----a-w- C:\WINDOWS\System32\pcaevts.dll
2012-11-27 12:49:39 -------- d-----w- C:\Users\Marc\AppData\Local\{AED6522C-864B-4BA4-B7F5-05D0EA28ECB6}
2012-11-27 00:49:33 -------- d-----w- C:\Users\Marc\AppData\Local\{0AD9F784-5A9F-4CA9-B608-953655C9E132}
2012-11-26 12:49:27 -------- d-----w- C:\Users\Marc\AppData\Local\{BA78179E-1C22-4D2D-A973-67FB62D2C36F}
2012-11-26 00:49:21 -------- d-----w- C:\Users\Marc\AppData\Local\{815292B4-5542-4D8D-B3E3-4190E67C1905}
2012-11-26 00:44:45 -------- d-----w- C:\Users\Marc\saran
2012-11-24 14:58:40 -------- d-----w- C:\Program Files (x86)\GoFTP
2012-11-16 02:12:22 -------- d-----w- C:\Program Files (x86)\Common Files\Software Update Utility
2012-11-16 00:47:27 -------- d-----w- C:\Users\Marc\AppData\Local\{A8FAFAD7-5416-48A1-9816-2349F9D95CDA}
2012-11-14 22:09:47 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server
2012-11-14 22:09:30 -------- d-----w- C:\WINDOWS\PCHEALTH
2012-11-14 22:09:30 -------- d-----w- C:\Program Files\Microsoft SQL Server
2012-11-14 15:20:09 -------- d-----w- C:\Users\Marc\AppData\Local\Deployment
2012-11-14 00:46:51 -------- d-----w- C:\Users\Marc\AppData\Local\{C2EA1490-CC8B-441C-B933-AF0728950C81}
2012-11-13 21:56:56 17888 ----a-w- C:\WINDOWS\System32\msvcr100_clr0400.dll
2012-11-11 00:46:04 -------- d-----w- C:\Users\Marc\AppData\Local\{F62DCC24-6479-4356-88E3-A8D557AA2780}
2012-11-10 21:43:21 367200 ----a-w- C:\WINDOWS\System32\drivers\afcdp.sys
2012-11-10 21:43:19 1340040 ----a-w- C:\WINDOWS\System32\drivers\tdrpman.sys
2012-11-10 21:43:18 1093256 ----a-w- C:\WINDOWS\System32\drivers\tib_mounter.sys
2012-11-10 21:43:17 340104 ----a-w- C:\WINDOWS\System32\drivers\snapman.sys
2012-11-10 21:43:17 155272 ----a-w- C:\WINDOWS\System32\drivers\fltsrv.sys
2012-11-10 12:45:46 -------- d-----w- C:\Users\Marc\AppData\Local\{6E8BC86A-52DA-4B9F-BEFA-72721BC35E9D}
.
==================== Find3M ====================
.
2012-12-01 03:18:49 608 --sha-w- C:\WINDOWS\System32\winzvprt5.sys
2012-11-06 12:42:16 88008 ----a-w- C:\WINDOWS\System32\LMIRfsClientNP.dll
2012-11-06 12:42:16 35240 ----a-w- C:\WINDOWS\System32\LMIport.dll
2012-11-06 12:42:15 83880 ----a-w- C:\WINDOWS\System32\LMIinit.dll
2012-11-02 05:22:08 34304 ----a-w- C:\WINDOWS\SysWow64\wuapp.exe
2012-11-02 05:21:44 83968 ----a-w- C:\WINDOWS\SysWow64\wudriver.dll
2012-11-02 05:21:44 125952 ----a-w- C:\WINDOWS\SysWow64\wuwebv.dll
2012-11-02 05:21:28 246784 ----a-w- C:\WINDOWS\SysWow64\ubpm.dll
2012-11-02 05:20:31 39424 ----a-w- C:\WINDOWS\System32\wuapp.exe
2012-11-02 05:20:28 77824 ----a-w- C:\WINDOWS\System32\taskhost.exe
2012-11-02 05:20:28 72192 ----a-w- C:\WINDOWS\System32\taskhostex.exe
2012-11-02 05:20:10 141824 ----a-w- C:\WINDOWS\System32\wuwebv.dll
2012-11-02 05:20:09 98304 ----a-w- C:\WINDOWS\System32\wudriver.dll
2012-11-02 05:20:09 251904 ----a-w- C:\WINDOWS\System32\WUSettingsProvider.dll
2012-11-02 05:20:09 17408 ----a-w- C:\WINDOWS\System32\wuaext.dll
2012-11-02 05:20:09 1619968 ----a-w- C:\WINDOWS\System32\wucltux.dll
2012-11-02 05:19:50 318464 ----a-w- C:\WINDOWS\System32\ubpm.dll
2012-11-02 05:01:27 99328 ----a-w- C:\WINDOWS\System32\wushareduxresources.dll
2012-11-02 04:55:32 212992 ----a-w- C:\WINDOWS\System32\drivers\mrxsmb20.sys
2012-11-02 04:53:13 366080 ----a-w- C:\WINDOWS\System32\drivers\mrxsmb.sys
2012-10-29 05:04:47 522640 ----a-w- C:\WINDOWS\System32\AUDIOKSE.dll
2012-10-29 05:04:47 490064 ----a-w- C:\WINDOWS\System32\AudioEng.dll
2012-10-29 05:04:47 447792 ----a-w- C:\WINDOWS\System32\AudioSes.dll
2012-10-29 05:04:47 253512 ----a-w- C:\WINDOWS\System32\audiodg.exe
2012-10-29 03:21:53 1526784 ----a-w- C:\WINDOWS\System32\mfcore.dll
2012-10-29 03:21:21 267264 ----a-w- C:\WINDOWS\System32\EncDump.dll
2012-10-29 03:20:49 785920 ----a-w- C:\WINDOWS\System32\audiosrv.dll
2012-10-29 03:20:49 169472 ----a-w- C:\WINDOWS\System32\AudioEndpointBuilder.dll
2012-10-29 03:19:08 463768 ----a-w- C:\WINDOWS\SysWow64\AUDIOKSE.dll
2012-10-29 03:19:08 427568 ----a-w- C:\WINDOWS\SysWow64\AudioEng.dll
2012-10-29 03:19:08 324344 ----a-w- C:\WINDOWS\SysWow64\AudioSes.dll
2012-10-29 02:46:23 1451520 ----a-w- C:\WINDOWS\SysWow64\mfcore.dll
2012-10-26 22:19:09 80728 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2012-10-26 22:19:09 695648 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2012-10-25 08:12:26 94208 ----a-w- C:\WINDOWS\SysWow64\QuickTimeVR.qtx
2012-10-25 08:12:26 69632 ----a-w- C:\WINDOWS\SysWow64\QuickTime.qts
2012-10-24 04:54:06 6972136 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2012-10-24 03:25:41 26624 ----a-w- C:\WINDOWS\System32\ReAgentc.exe
2012-10-24 03:24:42 439296 ----a-w- C:\WINDOWS\System32\ReAgent.dll
2012-10-24 03:06:12 2706432 ----a-w- C:\WINDOWS\System32\mshtml.tlb
2012-10-24 02:48:12 24064 ----a-w- C:\WINDOWS\SysWow64\ReAgentc.exe
2012-10-24 02:47:29 371712 ----a-w- C:\WINDOWS\SysWow64\ReAgent.dll
2012-10-24 02:27:01 2706432 ----a-w- C:\WINDOWS\SysWow64\mshtml.tlb
2012-10-20 03:22:05 39936 ----a-w- C:\WINDOWS\apppatch\apppatch64\acspecfc.dll
2012-10-20 02:44:53 431104 ----a-w- C:\WINDOWS\apppatch\AcSpecfc.dll
2012-10-20 02:25:35 310784 ----a-w- C:\WINDOWS\apppatch\AcRes.dll
2012-10-19 04:59:28 4056576 ----a-w- C:\WINDOWS\System32\win32k.sys
2012-10-19 04:03:02 12501352 ----a-w- C:\WINDOWS\SysWow64\nvwgf2um.dll
2012-10-19 04:03:00 1760104 ----a-w- C:\WINDOWS\System32\nvdispco64.dll
2012-10-18 06:17:18 69864 ----a-w- C:\WINDOWS\System32\drivers\pdc.sys
2012-10-18 03:20:46 10096640 ----a-w- C:\WINDOWS\System32\twinui.dll
2012-10-18 03:18:40 2302464 ----a-w- C:\WINDOWS\System32\authui.dll
2012-10-18 03:18:33 2146816 ----a-w- C:\WINDOWS\System32\actxprxy.dll
2012-10-18 02:46:00 8856576 ----a-w- C:\WINDOWS\SysWow64\twinui.dll
2012-10-18 02:44:38 2033664 ----a-w- C:\WINDOWS\SysWow64\authui.dll
2012-10-18 02:44:33 753664 ----a-w- C:\WINDOWS\SysWow64\actxprxy.dll
2012-10-17 04:32:52 1172992 ----a-w- C:\WINDOWS\System32\mfnetsrc.dll
2012-10-17 04:32:51 677888 ----a-w- C:\WINDOWS\System32\mfnetcore.dll
2012-10-17 04:32:51 673280 ----a-w- C:\WINDOWS\System32\mfmpeg2srcsnk.dll
2012-10-17 04:32:50 1048064 ----a-w- C:\WINDOWS\System32\mfasfsrcsnk.dll
2012-10-17 03:57:37 929792 ----a-w- C:\WINDOWS\SysWow64\mfnetsrc.dll
2012-10-17 03:57:37 568832 ----a-w- C:\WINDOWS\SysWow64\mfnetcore.dll
2012-10-17 03:57:37 513024 ----a-w- C:\WINDOWS\SysWow64\mfmpeg2srcsnk.dll
2012-10-17 03:57:36 850944 ----a-w- C:\WINDOWS\SysWow64\mfasfsrcsnk.dll
2012-10-12 08:08:01 27880 ----a-w- C:\WINDOWS\System32\drivers\rdpvideominiport.sys
2012-10-12 06:14:54 87040 ----a-w- C:\WINDOWS\System32\srmtrace.dll
2012-10-12 06:14:54 652800 ----a-w- C:\WINDOWS\System32\srmscan.dll
2012-10-12 06:14:54 30720 ----a-w- C:\WINDOWS\System32\srm_ps.dll
2012-10-12 06:14:54 279040 ----a-w- C:\WINDOWS\System32\srm.dll
2012-10-12 06:14:54 274432 ----a-w- C:\WINDOWS\System32\srmstormod.dll
2012-10-12 06:14:54 172032 ----a-w- C:\WINDOWS\System32\srmshell.dll
2012-10-12 06:14:54 1347072 ----a-w- C:\WINDOWS\System32\srmclient.dll
2012-10-12 06:14:54 134144 ----a-w- C:\WINDOWS\System32\adrclient.dll
2012-10-12 06:14:40 36352 ----a-w- C:\WINDOWS\System32\rfxvmt.dll
2012-10-12 06:14:39 3244032 ----a-w- C:\WINDOWS\System32\rdpcorets.dll
2012-10-12 06:14:34 115712 ----a-w- C:\WINDOWS\System32\wbem\PolicMan.dll
2012-10-12 06:13:32 109568 ----a-w- C:\WINDOWS\System32\dskquota.dll
2012-10-12 05:50:01 235520 ----a-w- C:\WINDOWS\System32\rdpudd.dll
2012-10-12 05:46:28 618496 ----a-w- C:\WINDOWS\System32\drivers\srv2.sys
2012-10-12 05:41:02 987648 ----a-w- C:\WINDOWS\SysWow64\srmclient.dll
2012-10-12 05:41:02 68096 ----a-w- C:\WINDOWS\SysWow64\srmtrace.dll
2012-10-12 05:41:02 487936 ----a-w- C:\WINDOWS\SysWow64\srmscan.dll
2012-10-12 05:41:02 278528 ----a-w- C:\WINDOWS\SysWow64\srm.dll
2012-10-12 05:41:02 202240 ----a-w- C:\WINDOWS\SysWow64\srmstormod.dll
2012-10-12 05:41:02 15872 ----a-w- C:\WINDOWS\SysWow64\srm_ps.dll
2012-10-12 05:41:02 128000 ----a-w- C:\WINDOWS\SysWow64\srmshell.dll
2012-10-12 05:41:02 104448 ----a-w- C:\WINDOWS\SysWow64\adrclient.dll
2012-10-12 05:40:49 84992 ----a-w- C:\WINDOWS\SysWow64\wbem\PolicMan.dll
2012-10-12 05:39:54 82944 ----a-w- C:\WINDOWS\SysWow64\dskquota.dll
2012-10-11 07:47:18 793200 ----a-w- C:\WINDOWS\System32\mfplat.dll
2012-10-11 07:35:16 2380944 ----a-w- C:\WINDOWS\explorer.exe
2012-10-11 07:26:44 336104 ----a-w- C:\WINDOWS\System32\drivers\Classpnp.sys
2012-10-11 07:25:48 56552 ----a-w- C:\WINDOWS\System32\drivers\sdstor.sys
2012-10-11 07:23:33 1001192 ----a-w- C:\WINDOWS\System32\drivers\ndis.sys
2012-10-11 07:23:32 441576 ----a-w- C:\WINDOWS\System32\drivers\netio.sys
2012-10-11 07:18:25 172264 ----a-w- C:\WINDOWS\System32\drivers\ksecpkg.sys
2012-10-11 07:16:20 1403784 ----a-w- C:\WINDOWS\System32\winload.efi
2012-10-11 07:16:20 1267424 ----a-w- C:\WINDOWS\System32\winload.exe
2012-10-11 07:16:20 1217328 ----a-w- C:\WINDOWS\System32\winresume.efi
2012-10-11 07:16:19 1093880 ----a-w- C:\WINDOWS\System32\winresume.exe
2011-11-17 06:35:25 30720 --sha-w- C:\WINDOWS\Secur32.dll
2009-07-14 01:40:56 862056 --sha-w- C:\WINDOWS\System32\prfn0885.dat
.
============= FINISH: 20:15:45.11 ===============

#4 dialsoft

dialsoft
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:32 PM

Posted 08 December 2012 - 08:19 PM

attach.txt as requested.

File attached.

Attached Files



#5 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,743 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:32 PM

Posted 13 December 2012 - 04:35 PM

Hello again!

I haven't heard from you in 5 days. Therefore, I am going to assume that you no longer need our help, and close this topic.

If you do still need help, please send a Private Message to any Moderator within the next five days. Be sure to include a link to your topic in your Private Message.

Thank you for using Bleeping Computer, and have a great day!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users