Hello,
A week ago my computer started playing ad sounds randomly but I first couldn't see where it was coming from. I thought it was from a page I had opened but even with Firefox closed it kept on doing it. And it sounded like it would play only a portion of the ad, like a few seconds. Later I started seeing small ad windows and experiencing random redirections to commercial websites on Firefox. I also noticed I was using up a lot of internet data (it went up to 15 GB in a day). And finally I noticed internet explorer was open in task manager but I didn’t open open it and there was no window to be seen.
I have Kaspersky AV and ran it with no results. I ran MBAM and it found a bunch of potentially unwanted program which I all removed. I also went through my program list, googled the ones that I din’t know and uninstalled a couple that were suspicious. After that, the random sounds and ads and redirections stopped, everything seemed to be OK.
But, a couple of days ago I noticed high data usage again and checked task manager. Here it was again, internet explorer open with no visible window. There was none of the other symptoms though. I ran Kaspersky and MBAM again with no results. I also tried MBAM anti-rootkit with no luck. I installed NetWorx in order to try identifying what was using so much data. I found that avp.exe was using a lot but I later read that this was actually Kaspersky and that some programs would connect to the internet via Kaspersky hence the high data usage. Internet explorer does not use much data, if at all. I can’t end the task from the application tab in the task manager but I can end the processes in the processes tab and the internet explorer disappears from the task tab then. However, it comes back after a while.
So after desperate hours of search for a solution I found your website. Below are the logs for MBAM and DSS. I posted two logs for MBAM, the first one I got before I removed all the PUPs and a new one (clean). These were obtained while internet explorer is opened in task manager.
Thank you for your help.
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 15/02/2015
Scan Time: 6:24:00 PM
Logfile: MBAM log 150215.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.02.15.01
Rootkit Database: v2015.02.03.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Reungoat
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 422887
Time Elapsed: 19 min, 49 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 3
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2935964518-2361115088-2651154713-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, No Action By User, [685577a7ddada88ecc8b986f689ba759],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-2935964518-2361115088-2651154713-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, No Action By User, [79440519eb9f21157ff5aa45d82c01ff],
PUP.Optional.Softonic.A, HKU\S-1-5-21-2935964518-2361115088-2651154713-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, No Action By User, [6f4ee23cc4c687af61d6b6e216ed05fb],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 63
PUP.Optional.Conduit.A, C:\Users\Reungoat\AppData\Roaming\uTorrent\ism.exe, No Action By User, [a11cea34fe8c9b9be4a4882758a98977],
PUP.Optional.Amonetize.A, C:\$Recycle.Bin\S-1-5-21-2935964518-2361115088-2651154713-1000\$RPTMVC1.exe, No Action By User, [09b487979af083b388d374f7dc2415eb],
PUP.Optional.SearchProtect.A, C:\Users\Reungoat\AppData\Local\Temp\SPSetup.exe, No Action By User, [a01d928cfe8c3402b986328212ef1de3],
PUP.Optional.Conduit.A, C:\Users\Reungoat\AppData\Local\Temp\utt6643.tmp.exe, No Action By User, [10ad3ae4bdcd340250afc97a8081af51],
PUP.Optional.SearchProtect.A, C:\Users\Reungoat\AppData\Local\Temp\nsd3D16.exe, No Action By User, [08b5e638e6a4c5713897b0a0e02102fe],
PUP.Optional.Conduit.A, C:\Users\Reungoat\AppData\Local\Temp\nsnB3A9.exe, No Action By User, [ae0f8a94e3a759dd2002486225dc8b75],
PUP.Optional.SearchProtect.A, C:\Users\Reungoat\AppData\Local\Temp\nsnF0D8.exe, No Action By User, [0bb2d34bff8bc670527dcb859c658779],
PUP.Optional.SearchProtect.A, C:\Users\Reungoat\AppData\Local\Temp\nsnF349.exe, No Action By User, [e7d6c35b4d3dce68b01fce822dd4b749],
PUP.Optional.SearchProtect.A, C:\Users\Reungoat\AppData\Local\Temp\nst3EFB.exe, No Action By User, [16a7e13d8efc40f64d822c243dc4da26],
PUP.Optional.MyStartSearch.A, C:\Users\Reungoat\AppData\Local\Temp\awh1D7C.tmp, No Action By User, [10ad4fcf6b1f92a4d6229464887df60a],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsc256E.exe, No Action By User, [8835f7275a309f979e313c146d9409f7],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsc2F8D.exe, No Action By User, [04b9da44c9c1ca6cd2fdc38d877a50b0],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsc3B6E.exe, No Action By User, [1aa3011d2a60b6804a85b7996a9703fd],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsc430C.exe, No Action By User, [5865af6f7614eb4b755a222e5fa22cd4],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsc4493.exe, No Action By User, [3b829c82bfcb76c0a52aafa113ee30d0],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsc4609.exe, No Action By User, [8439d9455c2e5bdbf9d6b0a069984fb1],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nscBDD7.exe, No Action By User, [e0dd99851b6f4de900cfd0801de4718f],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nss910C.exe, No Action By User, [912c5fbf6b1f2e08715e38187988c43c],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nss910D.exe, No Action By User, [cdf04fcf7a101e18e5eafc5461a0847c],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nssA8D1.exe, No Action By User, [08b5a07e92f83bfbce01044cad549f61],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nstE68C.exe, No Action By User, [437aea345139350124ab7bd517eaf60a],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsw207E.exe, No Action By User, [00bd68b647432e08bb149bb5649d42be],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsw207F.exe, No Action By User, [f8c58599503a8babd3fc76da07fab64a],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsx4B18.exe, No Action By User, [635aed31f991a98d12bda3ad3dc42bd5],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsx4B19.exe, No Action By User, [44794ad4becc2c0a1cb3a9a70100ba46],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsx6202.exe, No Action By User, [4776a27c73172d096a65133d7b8637c9],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsx65F8.exe, No Action By User, [87367ea08dfdc5715c7385cb60a115eb],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsx73AD.exe, No Action By User, [2e8f3ee03456cf6727a8f85807fa18e8],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsx8F1A.exe, No Action By User, [fcc12cf2f3973600943b4e02d22f2dd3],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsyC315.exe, No Action By User, [3a8371ad9af0f73f180a8d1d9b6617e9],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsi1B71.exe, No Action By User, [e2db35e92a6059dd438cd27ecf32a15f],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsiAC89.exe, No Action By User, [932adc425535a096e8e7014fc23f0ff1],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsiD4A0.exe, No Action By User, [ead3c35b0b7f2d09f5daa1afe51ce21e],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsiD4A1.exe, No Action By User, [6e4f22fc58323600745b7dd357aa5ea2],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsiE69B.exe, No Action By User, [ecd179a5f6941026dcf37ed2ec15a060],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsm2F7D.exe, No Action By User, [704d2fef93f765d1d8f75af60af7ff01],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsm73BC.exe, No Action By User, [912c7ca209811e183996e070c041c63a],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsm7F51.exe, No Action By User, [a419f42ae3a79f97daf586ca956cbc44],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsmB761.exe, No Action By User, [655843dbc4c6e84e5a75d080c23fa45c],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nss2E06.exe, No Action By User, [f4c9140a1872c86eca053b1550b18977],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsmDA6A.exe, No Action By User, [378623fb7713c670438ce36de71a3dc3],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsmF1E1.exe, No Action By User, [a21b76a8533747efb41b54fcfd04cf31],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsn321C.exe, No Action By User, [04b9c7570189310500226941907138c8],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsnA289.exe, No Action By User, [19a470aee2a86ccac260b7f3bf42956b],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr2149.exe, No Action By User, [b50850ce533744f2fbd49bb54fb2be42],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr30D3.exe, No Action By User, [29949d81d6b42e08814e68e8689940c0],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr4147.exe, No Action By User, [e7d68995602a73c3c807143cb34e916f],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr4675.exe, No Action By User, [4875a37bdfab9e98d5fade726a9745bb],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr4676.exe, No Action By User, [7e3f8d91aedce452e5ea85cb56ab659b],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr5120.exe, No Action By User, [308dad71088287af02cdd08010f1e61a],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr5479.exe, No Action By User, [6e4f8797f694e650755a3d136b964bb5],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr547A.exe, No Action By User, [546945d961299c9ab41b153b9f62f50b],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsrA44E.exe, No Action By User, [fac3f32ba7e33204f6d989c7f11002fe],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsrACD6.exe, No Action By User, [24990b13b5d5d561349bd878d9282bd5],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nscDA7A.exe, No Action By User, [ecd172ac4446dc5af9d62a26b849d62a],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nscF599.exe, No Action By User, [635ad747800ac76f7b54cd83d52ce21e],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nscF71F.exe, No Action By User, [e5d863bba3e7989e23ac450b847d11ef],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsd34EA.exe, No Action By User, [3885e638d7b353e3745bff51ed14dc24],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsh8B14.exe, No Action By User, [cfeedb431971e3533a95ada3f90803fd],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsh9965.exe, No Action By User, [318cf9255634f4421eb1b69a4eb38c74],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsh9966.exe, No Action By User, [a8154ad4e8a293a3bf1070e0728fc63a],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsi13D2.exe, No Action By User, [d3ea0b132c5e1125cc56634757aa58a8],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsi1B70.exe, No Action By User, [dedf59c5f99196a06867e967946de020],
Physical Sectors: 0
(No malicious items detected)
(end)
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 24/02/2015
Scan Time: 9:52:55 AM
Logfile: MBAM log 240215.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.02.23.09
Rootkit Database: v2015.02.22.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Reungoat
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 400515
Time Elapsed: 9 min, 56 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17631 BrowserJavaVersion: 11.31.2
Run by Reungoat at 16:20:53 on 2015-02-24
Microsoft Windows 7 Professional 6.1.7601.1.1252.61.1033.18.8097.2777 [GMT 10:00]
.
AV: Kaspersky Anti-Virus *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
SP: Kaspersky Anti-Virus *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Common Files\SPBA\upeksvr.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe
C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Windows\system32\IProsetMonitor.exe
C:\Windows\SysWOW64\lkads.exe
C:\Windows\system32\lxdncoms.exe
C:\Program Files (x86)\National Instruments\MAX\nimxs.exe
C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe
C:\Program Files (x86)\National Instruments\Shared\niSvcLoc\nisvcloc.exe
C:\Windows\system32\o2flash.exe
C:\Program Files (x86)\PDF Architect\HelperService.exe
C:\Program Files (x86)\PDF Architect\ConversionService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\SysWOW64\lkcitdl.exe
C:\Windows\SysWOW64\lktsrv.exe
C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe
C:\Program Files (x86)\National Instruments\Shared\Tagger\tagsrv.exe
C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\dell\DBRM\Reminder\DbrmTrayicon.exe
C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe
C:\Program Files\BOINC\boinctray.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\NetWorx\networx.exe
C:\Program Files (x86)\Simnet\Simple Sticky Notes\ssn.exe
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files\BOINC\boincmgr.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Digital Line Detect\DLG.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\National Instruments\Shared\NI Error Reporting\nierserver.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Users\Reungoat\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files\BOINC\boinc.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_anz_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_anz_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_anz_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadcm3s_7.24_windows_intelx86.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\ProgramData\BOINC\projects\climateprediction.net\hadcm3s_um_7.24_windows_intelx86.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_anz_um_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadrm3p_anz_um_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_anz_um_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_anz_um_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadrm3p_anz_um_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadrm3p_anz_um_6.10_windows_intelx86.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\spotify.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Program Files (x86)\Google\Picasa3\Picasa3.exe
C:\Windows\system32\taskmgr.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe
C:\Windows\System32\perfmon.exe
C:\Windows\System32\mobsync.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
C:\Windows\splwow64.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uSearch Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit = userinit.exe,
BHO: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -
BHO: PDF Architect Helper: {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll
TB: PDF Architect Toolbar: {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll
uRun: [Simple Sticky Notes] C:\Program Files (x86)\Simnet\Simple Sticky Notes\ssn.exe
uRun: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
uRun: [Google Update] "C:\Users\Reungoat\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [boincmgr] "C:\Program Files\BOINC\boincmgr.exe" /a /s
uRun: [Spotify Web Helper] "C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
dRun: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
StartupFolder: C:\Users\Reungoat\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Reungoat\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\Reungoat\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\SMARTS~1.LNK - C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\DIGITA~1.LNK - C:\Program Files (x86)\Digital Line Detect\DLG.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\NIERRO~1.LNK - C:\Program Files (x86)\National Instruments\Shared\NI Error Reporting\nierserver.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:28
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: DisableCAD = dword:1
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{07F2CA96-10A6-4614-8BC8-76A37E6161B5} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{07F2CA96-10A6-4614-8BC8-76A37E6161B5}\75776457475727563702D41696E6 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{07F2CA96-10A6-4614-8BC8-76A37E6161B5}\E4564734F6D6D60275962756C6563737 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{07F2CA96-10A6-4614-8BC8-76A37E6161B5}\E4564734F6D6D60275962756C65637370223835373 : DHCPNameServer = 192.168.20.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} -
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
LSA: Authentication Packages = msv1_0 wvauth
LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
x64-BHO: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -
x64-BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
x64-BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
x64-Run: [DBRMTray] C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe
x64-Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe
x64-Run: [TdmNotify] C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [DFEPApplication] C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe
x64-Run: [boinctray] "C:\Program Files\BOINC\boinctray.exe"
x64-Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
x64-Run: [NetWorx] "C:\Program Files\NetWorx\networx.exe" /auto
x64-RunOnce: [DBRMTray] C:\Dell\DBRM\Reminder\TrayApp.exe
x64-IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} -
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-Notify: spba - C:\Program Files\Common Files\SPBA\homefus2.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Reungoat\AppData\Roaming\Mozilla\Firefox\Profiles\7r4gvv1o.default-1423976232471\
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Reungoat\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll
FF - plugin: C:\Users\Reungoat\AppData\Local\Hola\firefox\app\vlc\npvlc.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll
.
============= SERVICES / DRIVERS ===============
.
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2013-11-10 20464]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdcfltn.sys [2014-4-10 22128]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2014-6-6 29792]
R1 klpd;klpd;C:\Windows\System32\drivers\klpd.sys [2013-4-12 15456]
R1 kltdi;kltdi;C:\Windows\System32\drivers\kltdi.sys [2013-5-14 55904]
R1 kneps;kneps;C:\Windows\System32\drivers\kneps.sys [2014-6-6 178272]
R1 networx;networx;C:\Windows\System32\drivers\networx.sys [2015-2-23 60408]
R1 nm3;Microsoft Network Monitor 3 Driver;C:\Windows\System32\drivers\nm3.sys [2010-6-9 46392]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-1-19 77128]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe [2014-6-6 214512]
R2 DFEPService;Dell Feature Enhancement Pack Service;C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2012-8-16 2280504]
R2 EmbassyService;EmbassyService;C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe [2012-1-17 218504]
R2 Garmin Core Update Service;Garmin Core Update Service;C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [2014-12-31 451416]
R2 HsfXAudioService;HsfXAudioService;C:\Windows\System32\svchost.exe -k HsfXAudioService [2009-7-14 27136]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-1-22 13632]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-8-27 747520]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;C:\Windows\System32\IPROSetMonitor.exe [2013-1-22 189608]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-1-22 169432]
R2 lxdn_device;lxdn_device;C:\Windows\System32\lxdncoms.exe -service --> C:\Windows\System32\lxdncoms.exe -service [?]
R2 NIApplicationWebServer;NI Application Web Server;C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [2013-6-8 57696]
R2 nimDNSResponder;NI mDNS Responder Service;C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [2013-5-11 260976]
R2 NISystemWebServer;NI System Web Server;C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe [2013-6-8 57680]
R2 PDF Architect Helper Service;PDF Architect Helper Service;C:\Program Files (x86)\PDF Architect\HelperService.exe [2013-1-9 1324104]
R2 PDF Architect Service;PDF Architect Service;C:\Program Files (x86)\PDF Architect\ConversionService.exe [2013-1-9 795208]
R2 vpnagent;Cisco AnyConnect Secure Mobility Agent;C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2013-12-13 560528]
R2 Wave Authentication Manager Service;Wave Authentication Manager Service;C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [2012-1-6 1679872]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\System32\drivers\bcbtums.sys [2013-1-22 165688]
R3 btwampfl;btwampfl Bluetooth filter driver;C:\Windows\System32\drivers\btwampfl.sys [2013-1-22 598808]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2013-12-10 39976]
R3 CAXHWAZL;CAXHWAZL;C:\Windows\System32\drivers\CAXHWAZL.sys [2013-1-22 292864]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2013-1-22 176096]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-12-10 169752]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-12-10 342528]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2013-11-10 358896]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2013-11-10 792560]
R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\drivers\iwdbus.sys [2012-11-29 25528]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;C:\Windows\System32\drivers\klkbdflt.sys [2014-6-6 29280]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2014-6-6 29280]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\MBAMSwissArmy.sys [2015-2-9 129752]
R3 O2SDJRDR;O2SDJRDR;C:\Windows\System32\drivers\o2sdjw7x64.sys [2013-1-22 84712]
R3 ST_ACCEL;STMicroelectronics Accelerometer Service;C:\Windows\System32\drivers\ST_Accel.sys [2014-4-10 89312]
R3 usb3Hub;USB-IF USB 3.0 Hub;C:\Windows\System32\drivers\usb3Hub.sys [2012-11-29 47072]
R3 XHCIPort;USB-IF xHCI USB Host Controller;C:\Windows\System32\drivers\xHCIPort.sys [2012-10-10 188896]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 acsock;acsock;C:\Windows\System32\drivers\acsock64.sys [2012-10-18 112496]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ggflt;SOMC USB Flash Driver Filter;C:\Windows\System32\drivers\ggflt.sys [2014-11-2 16088]
S3 ggsomc;SOMC USB Flash Driver;C:\Windows\System32\drivers\ggsomc.sys [2014-11-2 30424]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2015-2-11 114688]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\drivers\intelaud.sys [2012-11-29 35256]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-8-27 828376]
S3 netvsc;netvsc;C:\Windows\System32\drivers\netvsc60.sys [2010-11-21 168448]
S3 O2MDFRDR;O2MDFRDR;C:\Windows\System32\drivers\o2mdfw7x64.sys [2013-1-22 72808]
S3 O2MDRRDR;O2MDRRDR;C:\Windows\System32\drivers\O2MDRw7x64.sys [2013-1-22 74984]
S3 SIUSBXP;SIUSBXP;C:\Windows\System32\drivers\SiUSBXp.sys [2009-11-3 19456]
S3 Sony PC Companion;Sony PC Companion;C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2014-8-3 155824]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136]
S3 SynthVid;SynthVid;C:\Windows\System32\drivers\VMBusVideoM.sys [2010-11-21 22528]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2014-7-28 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-2-1 1255736]
S3 WSDScan;WSD Scan Support via UMB;C:\Windows\System32\drivers\WSDScan.sys [2009-7-14 25088]
S3 WvPCR;WvPCR;C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe [2012-1-17 198144]
S4 klflt;klflt;C:\Windows\System32\drivers\klflt.sys [2014-7-25 115296]
S4 NIApplicationWebServer64;NI Application Web Server (64-bit);C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [2013-6-8 81248]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2015-02-24 02:17:34 -------- d-----w- C:\Program Files (x86)\Common Files\OPC Foundation
2015-02-24 02:16:04 -------- d-----w- C:\Program Files (x86)\Common Files\Merge Modules
2015-02-24 02:15:43 -------- d-----w- C:\Program Files\National Instruments
2015-02-24 02:13:23 -------- d-----w- C:\National Instruments Downloads
2015-02-24 00:23:07 -------- d-----w- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-02-23 00:37:23 60408 ----a-w- C:\Windows\System32\drivers\networx.sys
2015-02-23 00:37:21 -------- d-----w- C:\ProgramData\SoftPerfect
2015-02-23 00:37:21 -------- d-----w- C:\Program Files\NetWorx
2015-02-22 09:27:31 -------- d-----w- C:\Program Files\Microsoft Network Monitor 3
2015-02-21 06:59:48 -------- d-----w- C:\ProgramData\SeriousBit
2015-02-21 06:57:47 -------- d-----w- C:\Users\Reungoat\AppData\Local\Rainmaker_Software_Group_
2015-02-21 06:57:02 -------- d-----w- C:\Users\Reungoat\AppData\Roaming\Rainmaker Software Group LLC.?
2015-02-17 23:45:49 -------- d-----w- C:\Windows\pss
2015-02-15 05:15:26 -------- d-----w- C:\Users\Reungoat\AppData\Roaming\ggcenzvn
2015-02-12 02:04:21 -------- d-----w- C:\Users\Reungoat\AppData\Roaming\Uniblue
2015-02-12 02:02:18 -------- d-----w- C:\Program Files (x86)\download Manager
2015-02-11 23:01:55 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2015-02-11 23:01:55 6041600 ----a-w- C:\Windows\System32\jscript9.dll
2015-02-11 23:01:55 4300800 ----a-w- C:\Windows\SysWow64\jscript9.dll
2015-02-11 23:01:54 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2015-02-11 04:56:14 -------- d-----w- C:\Users\Reungoat\.imagej
2015-02-11 02:32:05 -------- d-----w- C:\Program Files (x86)\ImageJ
2015-02-10 22:55:57 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2015-02-10 22:54:53 3201536 ----a-w- C:\Windows\System32\win32k.sys
2015-02-10 00:56:12 -------- d-----w- C:\Users\Reungoat\AppData\Local\PDFCreator
2015-02-09 00:08:59 129752 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2015-02-09 00:08:45 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys
2015-02-09 00:08:45 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2015-02-09 00:08:45 107736 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2015-02-09 00:08:45 -------- d-----w- C:\ProgramData\Malwarebytes
2015-02-09 00:08:45 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-08 23:34:32 -------- d-----w- C:\Users\Reungoat\AppData\Roaming\pdfforge
2015-02-08 23:34:26 114872 ----a-w- C:\Windows\System32\pdfcmon.dll
2015-02-08 23:34:25 -------- d-----w- C:\Program Files\PDFCreator
2015-01-31 04:15:11 -------- d-----w- C:\Program Files\iPod
2015-01-31 04:15:11 -------- d-----w- C:\Program Files (x86)\iTunes
2015-01-31 04:15:09 -------- d-----w- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-01-31 04:15:09 -------- d-----w- C:\Program Files\iTunes
2015-01-28 06:10:31 -------- d-----w- C:\Users\Reungoat\AppData\Local\Diagnostics
2015-01-27 06:32:35 -------- d-----w- C:\Users\Reungoat\AppData\Local\Spotify
2015-01-27 06:31:25 -------- d-----w- C:\Users\Reungoat\AppData\Roaming\Spotify
.
==================== Find3M ====================
.
2015-02-15 00:10:41 98216 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2015-02-09 00:04:57 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-02-09 00:04:57 701616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2015-02-04 03:16:29 609280 ----a-w- C:\Windows\System32\generaltel.dll
2015-02-04 03:16:20 762368 ----a-w- C:\Windows\System32\invagent.dll
2015-02-04 03:16:16 414720 ----a-w- C:\Windows\System32\devinv.dll
2015-02-04 03:16:14 894976 ----a-w- C:\Windows\System32\appraiser.dll
2015-02-04 03:16:13 227328 ----a-w- C:\Windows\System32\aepdu.dll
2015-02-04 03:16:13 192000 ----a-w- C:\Windows\System32\aepic.dll
2015-02-04 03:13:28 1098752 ----a-w- C:\Windows\System32\aeinv.dll
2015-01-27 23:36:21 1239720 ----a-w- C:\Windows\System32\aitstatic.exe
2015-01-15 08:14:17 155072 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2015-01-15 08:14:16 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2015-01-15 08:09:58 29184 ----a-w- C:\Windows\System32\sspisrv.dll
2015-01-15 08:09:58 136192 ----a-w- C:\Windows\System32\sspicli.dll
2015-01-15 08:09:57 28160 ----a-w- C:\Windows\System32\secur32.dll
2015-01-15 08:09:51 1461760 ----a-w- C:\Windows\System32\lsasrv.dll
2015-01-15 08:09:15 31232 ----a-w- C:\Windows\System32\lsass.exe
2015-01-15 08:08:59 64000 ----a-w- C:\Windows\System32\auditpol.exe
2015-01-15 08:06:22 60416 ----a-w- C:\Windows\System32\msobjs.dll
2015-01-15 08:06:11 146432 ----a-w- C:\Windows\System32\msaudite.dll
2015-01-15 08:04:23 686080 ----a-w- C:\Windows\System32\adtschema.dll
2015-01-15 07:42:59 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2015-01-15 07:42:05 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2015-01-15 07:39:53 60416 ----a-w- C:\Windows\SysWow64\msobjs.dll
2015-01-15 07:39:36 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll
2015-01-15 07:37:55 686080 ----a-w- C:\Windows\SysWow64\adtschema.dll
2015-01-15 04:22:18 458824 ----a-w- C:\Windows\System32\drivers\cng.sys
2015-01-14 06:09:27 5554112 ----a-w- C:\Windows\System32\ntoskrnl.exe
2015-01-14 06:05:30 503808 ----a-w- C:\Windows\System32\srcore.dll
2015-01-14 06:05:30 50176 ----a-w- C:\Windows\System32\srclient.dll
2015-01-14 06:04:56 296960 ----a-w- C:\Windows\System32\rstrui.exe
2015-01-14 05:44:59 3972544 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2015-01-14 05:44:58 3917760 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2015-01-14 05:41:09 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
2015-01-13 03:10:22 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2015-01-13 02:49:19 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2015-01-12 03:05:32 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2015-01-12 03:05:19 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2015-01-12 02:49:42 66560 ----a-w- C:\Windows\System32\iesetup.dll
2015-01-12 02:48:57 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2015-01-12 02:48:52 584192 ----a-w- C:\Windows\System32\vbscript.dll
2015-01-12 02:47:25 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2015-01-12 02:34:42 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2015-01-12 02:34:30 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
2015-01-12 02:25:28 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2015-01-12 02:21:19 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2015-01-12 02:13:27 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2015-01-12 02:08:09 503296 ----a-w- C:\Windows\SysWow64\vbscript.dll
2015-01-12 02:07:51 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2015-01-12 02:07:06 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2015-01-12 02:05:36 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2015-01-12 01:55:47 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2015-01-12 01:46:29 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2015-01-12 01:46:00 2125824 ----a-w- C:\Windows\System32\inetcpl.cpl
2015-01-12 01:40:43 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2015-01-12 01:27:32 2358272 ----a-w- C:\Windows\System32\wininet.dll
2015-01-12 01:23:09 2052608 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2015-01-12 01:22:17 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2015-01-12 01:00:17 1888256 ----a-w- C:\Windows\SysWow64\wininet.dll
2015-01-10 06:48:22 210944 ----a-w- C:\Windows\System32\wdigest.dll
2015-01-10 06:48:19 86528 ----a-w- C:\Windows\System32\TSpkg.dll
2015-01-10 06:48:17 341504 ----a-w- C:\Windows\System32\schannel.dll
2015-01-10 06:48:13 309760 ----a-w- C:\Windows\System32\ncrypt.dll
2015-01-10 06:48:12 314880 ----a-w- C:\Windows\System32\msv1_0.dll
2015-01-10 06:48:10 728064 ----a-w- C:\Windows\System32\kerberos.dll
2015-01-10 06:48:05 22016 ----a-w- C:\Windows\System32\credssp.dll
2015-01-10 06:27:54 172032 ----a-w- C:\Windows\SysWow64\wdigest.dll
2015-01-10 06:27:51 65536 ----a-w- C:\Windows\SysWow64\TSpkg.dll
2015-01-10 06:27:47 248832 ----a-w- C:\Windows\SysWow64\schannel.dll
2015-01-10 06:27:44 221184 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2015-01-10 06:27:43 259584 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2015-01-10 06:27:39 550912 ----a-w- C:\Windows\SysWow64\kerberos.dll
2015-01-10 06:27:32 17408 ----a-w- C:\Windows\SysWow64\credssp.dll
2014-12-19 03:06:55 210432 ----a-w- C:\Windows\System32\profsvc.dll
2014-12-19 01:46:45 141312 ----a-w- C:\Windows\System32\drivers\mrxdav.sys
2014-12-12 05:31:39 1480192 ----a-w- C:\Windows\System32\crypt32.dll
2014-12-12 05:07:26 1174528 ----a-w- C:\Windows\SysWow64\crypt32.dll
2014-12-11 17:47:12 52736 ----a-w- C:\Windows\System32\TSWbPrxy.exe
2014-12-11 08:12:56 1120752 ----a-w- C:\Windows\boinc.scr
2014-12-08 03:09:05 406528 ----a-w- C:\Windows\System32\scesrv.dll
2014-12-08 02:46:05 308224 ----a-w- C:\Windows\SysWow64\scesrv.dll
2014-12-06 04:17:27 303616 ----a-w- C:\Windows\System32\nlasvc.dll
2014-12-06 03:50:19 52224 ----a-w- C:\Windows\SysWow64\nlaapi.dll
2014-12-06 03:50:18 156672 ----a-w- C:\Windows\SysWow64\ncsi.dll
.
============= FINISH: 16:21:27.91 ===============
A week ago my computer started playing ad sounds randomly but I first couldn't see where it was coming from. I thought it was from a page I had opened but even with Firefox closed it kept on doing it. And it sounded like it would play only a portion of the ad, like a few seconds. Later I started seeing small ad windows and experiencing random redirections to commercial websites on Firefox. I also noticed I was using up a lot of internet data (it went up to 15 GB in a day). And finally I noticed internet explorer was open in task manager but I didn’t open open it and there was no window to be seen.
I have Kaspersky AV and ran it with no results. I ran MBAM and it found a bunch of potentially unwanted program which I all removed. I also went through my program list, googled the ones that I din’t know and uninstalled a couple that were suspicious. After that, the random sounds and ads and redirections stopped, everything seemed to be OK.
But, a couple of days ago I noticed high data usage again and checked task manager. Here it was again, internet explorer open with no visible window. There was none of the other symptoms though. I ran Kaspersky and MBAM again with no results. I also tried MBAM anti-rootkit with no luck. I installed NetWorx in order to try identifying what was using so much data. I found that avp.exe was using a lot but I later read that this was actually Kaspersky and that some programs would connect to the internet via Kaspersky hence the high data usage. Internet explorer does not use much data, if at all. I can’t end the task from the application tab in the task manager but I can end the processes in the processes tab and the internet explorer disappears from the task tab then. However, it comes back after a while.
So after desperate hours of search for a solution I found your website. Below are the logs for MBAM and DSS. I posted two logs for MBAM, the first one I got before I removed all the PUPs and a new one (clean). These were obtained while internet explorer is opened in task manager.
Thank you for your help.
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 15/02/2015
Scan Time: 6:24:00 PM
Logfile: MBAM log 150215.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.02.15.01
Rootkit Database: v2015.02.03.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Reungoat
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 422887
Time Elapsed: 19 min, 49 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 3
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2935964518-2361115088-2651154713-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, No Action By User, [685577a7ddada88ecc8b986f689ba759],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-2935964518-2361115088-2651154713-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, No Action By User, [79440519eb9f21157ff5aa45d82c01ff],
PUP.Optional.Softonic.A, HKU\S-1-5-21-2935964518-2361115088-2651154713-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, No Action By User, [6f4ee23cc4c687af61d6b6e216ed05fb],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 63
PUP.Optional.Conduit.A, C:\Users\Reungoat\AppData\Roaming\uTorrent\ism.exe, No Action By User, [a11cea34fe8c9b9be4a4882758a98977],
PUP.Optional.Amonetize.A, C:\$Recycle.Bin\S-1-5-21-2935964518-2361115088-2651154713-1000\$RPTMVC1.exe, No Action By User, [09b487979af083b388d374f7dc2415eb],
PUP.Optional.SearchProtect.A, C:\Users\Reungoat\AppData\Local\Temp\SPSetup.exe, No Action By User, [a01d928cfe8c3402b986328212ef1de3],
PUP.Optional.Conduit.A, C:\Users\Reungoat\AppData\Local\Temp\utt6643.tmp.exe, No Action By User, [10ad3ae4bdcd340250afc97a8081af51],
PUP.Optional.SearchProtect.A, C:\Users\Reungoat\AppData\Local\Temp\nsd3D16.exe, No Action By User, [08b5e638e6a4c5713897b0a0e02102fe],
PUP.Optional.Conduit.A, C:\Users\Reungoat\AppData\Local\Temp\nsnB3A9.exe, No Action By User, [ae0f8a94e3a759dd2002486225dc8b75],
PUP.Optional.SearchProtect.A, C:\Users\Reungoat\AppData\Local\Temp\nsnF0D8.exe, No Action By User, [0bb2d34bff8bc670527dcb859c658779],
PUP.Optional.SearchProtect.A, C:\Users\Reungoat\AppData\Local\Temp\nsnF349.exe, No Action By User, [e7d6c35b4d3dce68b01fce822dd4b749],
PUP.Optional.SearchProtect.A, C:\Users\Reungoat\AppData\Local\Temp\nst3EFB.exe, No Action By User, [16a7e13d8efc40f64d822c243dc4da26],
PUP.Optional.MyStartSearch.A, C:\Users\Reungoat\AppData\Local\Temp\awh1D7C.tmp, No Action By User, [10ad4fcf6b1f92a4d6229464887df60a],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsc256E.exe, No Action By User, [8835f7275a309f979e313c146d9409f7],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsc2F8D.exe, No Action By User, [04b9da44c9c1ca6cd2fdc38d877a50b0],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsc3B6E.exe, No Action By User, [1aa3011d2a60b6804a85b7996a9703fd],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsc430C.exe, No Action By User, [5865af6f7614eb4b755a222e5fa22cd4],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsc4493.exe, No Action By User, [3b829c82bfcb76c0a52aafa113ee30d0],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsc4609.exe, No Action By User, [8439d9455c2e5bdbf9d6b0a069984fb1],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nscBDD7.exe, No Action By User, [e0dd99851b6f4de900cfd0801de4718f],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nss910C.exe, No Action By User, [912c5fbf6b1f2e08715e38187988c43c],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nss910D.exe, No Action By User, [cdf04fcf7a101e18e5eafc5461a0847c],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nssA8D1.exe, No Action By User, [08b5a07e92f83bfbce01044cad549f61],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nstE68C.exe, No Action By User, [437aea345139350124ab7bd517eaf60a],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsw207E.exe, No Action By User, [00bd68b647432e08bb149bb5649d42be],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsw207F.exe, No Action By User, [f8c58599503a8babd3fc76da07fab64a],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsx4B18.exe, No Action By User, [635aed31f991a98d12bda3ad3dc42bd5],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsx4B19.exe, No Action By User, [44794ad4becc2c0a1cb3a9a70100ba46],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsx6202.exe, No Action By User, [4776a27c73172d096a65133d7b8637c9],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsx65F8.exe, No Action By User, [87367ea08dfdc5715c7385cb60a115eb],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsx73AD.exe, No Action By User, [2e8f3ee03456cf6727a8f85807fa18e8],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsx8F1A.exe, No Action By User, [fcc12cf2f3973600943b4e02d22f2dd3],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsyC315.exe, No Action By User, [3a8371ad9af0f73f180a8d1d9b6617e9],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsi1B71.exe, No Action By User, [e2db35e92a6059dd438cd27ecf32a15f],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsiAC89.exe, No Action By User, [932adc425535a096e8e7014fc23f0ff1],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsiD4A0.exe, No Action By User, [ead3c35b0b7f2d09f5daa1afe51ce21e],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsiD4A1.exe, No Action By User, [6e4f22fc58323600745b7dd357aa5ea2],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsiE69B.exe, No Action By User, [ecd179a5f6941026dcf37ed2ec15a060],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsm2F7D.exe, No Action By User, [704d2fef93f765d1d8f75af60af7ff01],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsm73BC.exe, No Action By User, [912c7ca209811e183996e070c041c63a],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsm7F51.exe, No Action By User, [a419f42ae3a79f97daf586ca956cbc44],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsmB761.exe, No Action By User, [655843dbc4c6e84e5a75d080c23fa45c],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nss2E06.exe, No Action By User, [f4c9140a1872c86eca053b1550b18977],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsmDA6A.exe, No Action By User, [378623fb7713c670438ce36de71a3dc3],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsmF1E1.exe, No Action By User, [a21b76a8533747efb41b54fcfd04cf31],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsn321C.exe, No Action By User, [04b9c7570189310500226941907138c8],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsnA289.exe, No Action By User, [19a470aee2a86ccac260b7f3bf42956b],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr2149.exe, No Action By User, [b50850ce533744f2fbd49bb54fb2be42],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr30D3.exe, No Action By User, [29949d81d6b42e08814e68e8689940c0],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr4147.exe, No Action By User, [e7d68995602a73c3c807143cb34e916f],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr4675.exe, No Action By User, [4875a37bdfab9e98d5fade726a9745bb],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr4676.exe, No Action By User, [7e3f8d91aedce452e5ea85cb56ab659b],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr5120.exe, No Action By User, [308dad71088287af02cdd08010f1e61a],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr5479.exe, No Action By User, [6e4f8797f694e650755a3d136b964bb5],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsr547A.exe, No Action By User, [546945d961299c9ab41b153b9f62f50b],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsrA44E.exe, No Action By User, [fac3f32ba7e33204f6d989c7f11002fe],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsrACD6.exe, No Action By User, [24990b13b5d5d561349bd878d9282bd5],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nscDA7A.exe, No Action By User, [ecd172ac4446dc5af9d62a26b849d62a],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nscF599.exe, No Action By User, [635ad747800ac76f7b54cd83d52ce21e],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nscF71F.exe, No Action By User, [e5d863bba3e7989e23ac450b847d11ef],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsd34EA.exe, No Action By User, [3885e638d7b353e3745bff51ed14dc24],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsh8B14.exe, No Action By User, [cfeedb431971e3533a95ada3f90803fd],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsh9965.exe, No Action By User, [318cf9255634f4421eb1b69a4eb38c74],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsh9966.exe, No Action By User, [a8154ad4e8a293a3bf1070e0728fc63a],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsi13D2.exe, No Action By User, [d3ea0b132c5e1125cc56634757aa58a8],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsi1B70.exe, No Action By User, [dedf59c5f99196a06867e967946de020],
Physical Sectors: 0
(No malicious items detected)
(end)
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 24/02/2015
Scan Time: 9:52:55 AM
Logfile: MBAM log 240215.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.02.23.09
Rootkit Database: v2015.02.22.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Reungoat
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 400515
Time Elapsed: 9 min, 56 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17631 BrowserJavaVersion: 11.31.2
Run by Reungoat at 16:20:53 on 2015-02-24
Microsoft Windows 7 Professional 6.1.7601.1.1252.61.1033.18.8097.2777 [GMT 10:00]
.
AV: Kaspersky Anti-Virus *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
SP: Kaspersky Anti-Virus *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Common Files\SPBA\upeksvr.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe
C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Windows\system32\IProsetMonitor.exe
C:\Windows\SysWOW64\lkads.exe
C:\Windows\system32\lxdncoms.exe
C:\Program Files (x86)\National Instruments\MAX\nimxs.exe
C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe
C:\Program Files (x86)\National Instruments\Shared\niSvcLoc\nisvcloc.exe
C:\Windows\system32\o2flash.exe
C:\Program Files (x86)\PDF Architect\HelperService.exe
C:\Program Files (x86)\PDF Architect\ConversionService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\SysWOW64\lkcitdl.exe
C:\Windows\SysWOW64\lktsrv.exe
C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe
C:\Program Files (x86)\National Instruments\Shared\Tagger\tagsrv.exe
C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\dell\DBRM\Reminder\DbrmTrayicon.exe
C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe
C:\Program Files\BOINC\boinctray.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\NetWorx\networx.exe
C:\Program Files (x86)\Simnet\Simple Sticky Notes\ssn.exe
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files\BOINC\boincmgr.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Digital Line Detect\DLG.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\National Instruments\Shared\NI Error Reporting\nierserver.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Users\Reungoat\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files\BOINC\boinc.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_anz_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_anz_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_anz_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadcm3s_7.24_windows_intelx86.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\ProgramData\BOINC\projects\climateprediction.net\hadcm3s_um_7.24_windows_intelx86.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_anz_um_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadrm3p_anz_um_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_anz_um_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_anz_um_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadrm3p_anz_um_6.10_windows_intelx86.exe
C:\ProgramData\BOINC\projects\climateprediction.net\hadrm3p_anz_um_6.10_windows_intelx86.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\spotify.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Program Files (x86)\Google\Picasa3\Picasa3.exe
C:\Windows\system32\taskmgr.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe
C:\Windows\System32\perfmon.exe
C:\Windows\System32\mobsync.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
C:\Windows\splwow64.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uSearch Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit = userinit.exe,
BHO: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -
BHO: PDF Architect Helper: {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll
TB: PDF Architect Toolbar: {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll
uRun: [Simple Sticky Notes] C:\Program Files (x86)\Simnet\Simple Sticky Notes\ssn.exe
uRun: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
uRun: [Google Update] "C:\Users\Reungoat\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [boincmgr] "C:\Program Files\BOINC\boincmgr.exe" /a /s
uRun: [Spotify Web Helper] "C:\Users\Reungoat\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
dRun: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
StartupFolder: C:\Users\Reungoat\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Reungoat\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\Reungoat\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\SMARTS~1.LNK - C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\DIGITA~1.LNK - C:\Program Files (x86)\Digital Line Detect\DLG.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\NIERRO~1.LNK - C:\Program Files (x86)\National Instruments\Shared\NI Error Reporting\nierserver.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:28
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: DisableCAD = dword:1
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{07F2CA96-10A6-4614-8BC8-76A37E6161B5} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{07F2CA96-10A6-4614-8BC8-76A37E6161B5}\75776457475727563702D41696E6 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{07F2CA96-10A6-4614-8BC8-76A37E6161B5}\E4564734F6D6D60275962756C6563737 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{07F2CA96-10A6-4614-8BC8-76A37E6161B5}\E4564734F6D6D60275962756C65637370223835373 : DHCPNameServer = 192.168.20.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} -
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
LSA: Authentication Packages = msv1_0 wvauth
LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
x64-BHO: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -
x64-BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
x64-BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
x64-Run: [DBRMTray] C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe
x64-Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe
x64-Run: [TdmNotify] C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [DFEPApplication] C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe
x64-Run: [boinctray] "C:\Program Files\BOINC\boinctray.exe"
x64-Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
x64-Run: [NetWorx] "C:\Program Files\NetWorx\networx.exe" /auto
x64-RunOnce: [DBRMTray] C:\Dell\DBRM\Reminder\TrayApp.exe
x64-IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} -
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-Notify: spba - C:\Program Files\Common Files\SPBA\homefus2.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Reungoat\AppData\Roaming\Mozilla\Firefox\Profiles\7r4gvv1o.default-1423976232471\
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Reungoat\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll
FF - plugin: C:\Users\Reungoat\AppData\Local\Hola\firefox\app\vlc\npvlc.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll
.
============= SERVICES / DRIVERS ===============
.
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2013-11-10 20464]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdcfltn.sys [2014-4-10 22128]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2014-6-6 29792]
R1 klpd;klpd;C:\Windows\System32\drivers\klpd.sys [2013-4-12 15456]
R1 kltdi;kltdi;C:\Windows\System32\drivers\kltdi.sys [2013-5-14 55904]
R1 kneps;kneps;C:\Windows\System32\drivers\kneps.sys [2014-6-6 178272]
R1 networx;networx;C:\Windows\System32\drivers\networx.sys [2015-2-23 60408]
R1 nm3;Microsoft Network Monitor 3 Driver;C:\Windows\System32\drivers\nm3.sys [2010-6-9 46392]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-1-19 77128]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe [2014-6-6 214512]
R2 DFEPService;Dell Feature Enhancement Pack Service;C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2012-8-16 2280504]
R2 EmbassyService;EmbassyService;C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe [2012-1-17 218504]
R2 Garmin Core Update Service;Garmin Core Update Service;C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [2014-12-31 451416]
R2 HsfXAudioService;HsfXAudioService;C:\Windows\System32\svchost.exe -k HsfXAudioService [2009-7-14 27136]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-1-22 13632]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-8-27 747520]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;C:\Windows\System32\IPROSetMonitor.exe [2013-1-22 189608]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-1-22 169432]
R2 lxdn_device;lxdn_device;C:\Windows\System32\lxdncoms.exe -service --> C:\Windows\System32\lxdncoms.exe -service [?]
R2 NIApplicationWebServer;NI Application Web Server;C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [2013-6-8 57696]
R2 nimDNSResponder;NI mDNS Responder Service;C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [2013-5-11 260976]
R2 NISystemWebServer;NI System Web Server;C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe [2013-6-8 57680]
R2 PDF Architect Helper Service;PDF Architect Helper Service;C:\Program Files (x86)\PDF Architect\HelperService.exe [2013-1-9 1324104]
R2 PDF Architect Service;PDF Architect Service;C:\Program Files (x86)\PDF Architect\ConversionService.exe [2013-1-9 795208]
R2 vpnagent;Cisco AnyConnect Secure Mobility Agent;C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2013-12-13 560528]
R2 Wave Authentication Manager Service;Wave Authentication Manager Service;C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [2012-1-6 1679872]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\System32\drivers\bcbtums.sys [2013-1-22 165688]
R3 btwampfl;btwampfl Bluetooth filter driver;C:\Windows\System32\drivers\btwampfl.sys [2013-1-22 598808]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2013-12-10 39976]
R3 CAXHWAZL;CAXHWAZL;C:\Windows\System32\drivers\CAXHWAZL.sys [2013-1-22 292864]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2013-1-22 176096]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-12-10 169752]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-12-10 342528]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2013-11-10 358896]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2013-11-10 792560]
R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\drivers\iwdbus.sys [2012-11-29 25528]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;C:\Windows\System32\drivers\klkbdflt.sys [2014-6-6 29280]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2014-6-6 29280]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\MBAMSwissArmy.sys [2015-2-9 129752]
R3 O2SDJRDR;O2SDJRDR;C:\Windows\System32\drivers\o2sdjw7x64.sys [2013-1-22 84712]
R3 ST_ACCEL;STMicroelectronics Accelerometer Service;C:\Windows\System32\drivers\ST_Accel.sys [2014-4-10 89312]
R3 usb3Hub;USB-IF USB 3.0 Hub;C:\Windows\System32\drivers\usb3Hub.sys [2012-11-29 47072]
R3 XHCIPort;USB-IF xHCI USB Host Controller;C:\Windows\System32\drivers\xHCIPort.sys [2012-10-10 188896]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 acsock;acsock;C:\Windows\System32\drivers\acsock64.sys [2012-10-18 112496]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ggflt;SOMC USB Flash Driver Filter;C:\Windows\System32\drivers\ggflt.sys [2014-11-2 16088]
S3 ggsomc;SOMC USB Flash Driver;C:\Windows\System32\drivers\ggsomc.sys [2014-11-2 30424]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2015-2-11 114688]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\drivers\intelaud.sys [2012-11-29 35256]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-8-27 828376]
S3 netvsc;netvsc;C:\Windows\System32\drivers\netvsc60.sys [2010-11-21 168448]
S3 O2MDFRDR;O2MDFRDR;C:\Windows\System32\drivers\o2mdfw7x64.sys [2013-1-22 72808]
S3 O2MDRRDR;O2MDRRDR;C:\Windows\System32\drivers\O2MDRw7x64.sys [2013-1-22 74984]
S3 SIUSBXP;SIUSBXP;C:\Windows\System32\drivers\SiUSBXp.sys [2009-11-3 19456]
S3 Sony PC Companion;Sony PC Companion;C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2014-8-3 155824]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136]
S3 SynthVid;SynthVid;C:\Windows\System32\drivers\VMBusVideoM.sys [2010-11-21 22528]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2014-7-28 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-2-1 1255736]
S3 WSDScan;WSD Scan Support via UMB;C:\Windows\System32\drivers\WSDScan.sys [2009-7-14 25088]
S3 WvPCR;WvPCR;C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe [2012-1-17 198144]
S4 klflt;klflt;C:\Windows\System32\drivers\klflt.sys [2014-7-25 115296]
S4 NIApplicationWebServer64;NI Application Web Server (64-bit);C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [2013-6-8 81248]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2015-02-24 02:17:34 -------- d-----w- C:\Program Files (x86)\Common Files\OPC Foundation
2015-02-24 02:16:04 -------- d-----w- C:\Program Files (x86)\Common Files\Merge Modules
2015-02-24 02:15:43 -------- d-----w- C:\Program Files\National Instruments
2015-02-24 02:13:23 -------- d-----w- C:\National Instruments Downloads
2015-02-24 00:23:07 -------- d-----w- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-02-23 00:37:23 60408 ----a-w- C:\Windows\System32\drivers\networx.sys
2015-02-23 00:37:21 -------- d-----w- C:\ProgramData\SoftPerfect
2015-02-23 00:37:21 -------- d-----w- C:\Program Files\NetWorx
2015-02-22 09:27:31 -------- d-----w- C:\Program Files\Microsoft Network Monitor 3
2015-02-21 06:59:48 -------- d-----w- C:\ProgramData\SeriousBit
2015-02-21 06:57:47 -------- d-----w- C:\Users\Reungoat\AppData\Local\Rainmaker_Software_Group_
2015-02-21 06:57:02 -------- d-----w- C:\Users\Reungoat\AppData\Roaming\Rainmaker Software Group LLC.?
2015-02-17 23:45:49 -------- d-----w- C:\Windows\pss
2015-02-15 05:15:26 -------- d-----w- C:\Users\Reungoat\AppData\Roaming\ggcenzvn
2015-02-12 02:04:21 -------- d-----w- C:\Users\Reungoat\AppData\Roaming\Uniblue
2015-02-12 02:02:18 -------- d-----w- C:\Program Files (x86)\download Manager
2015-02-11 23:01:55 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2015-02-11 23:01:55 6041600 ----a-w- C:\Windows\System32\jscript9.dll
2015-02-11 23:01:55 4300800 ----a-w- C:\Windows\SysWow64\jscript9.dll
2015-02-11 23:01:54 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2015-02-11 04:56:14 -------- d-----w- C:\Users\Reungoat\.imagej
2015-02-11 02:32:05 -------- d-----w- C:\Program Files (x86)\ImageJ
2015-02-10 22:55:57 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2015-02-10 22:54:53 3201536 ----a-w- C:\Windows\System32\win32k.sys
2015-02-10 00:56:12 -------- d-----w- C:\Users\Reungoat\AppData\Local\PDFCreator
2015-02-09 00:08:59 129752 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2015-02-09 00:08:45 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys
2015-02-09 00:08:45 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2015-02-09 00:08:45 107736 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2015-02-09 00:08:45 -------- d-----w- C:\ProgramData\Malwarebytes
2015-02-09 00:08:45 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-08 23:34:32 -------- d-----w- C:\Users\Reungoat\AppData\Roaming\pdfforge
2015-02-08 23:34:26 114872 ----a-w- C:\Windows\System32\pdfcmon.dll
2015-02-08 23:34:25 -------- d-----w- C:\Program Files\PDFCreator
2015-01-31 04:15:11 -------- d-----w- C:\Program Files\iPod
2015-01-31 04:15:11 -------- d-----w- C:\Program Files (x86)\iTunes
2015-01-31 04:15:09 -------- d-----w- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-01-31 04:15:09 -------- d-----w- C:\Program Files\iTunes
2015-01-28 06:10:31 -------- d-----w- C:\Users\Reungoat\AppData\Local\Diagnostics
2015-01-27 06:32:35 -------- d-----w- C:\Users\Reungoat\AppData\Local\Spotify
2015-01-27 06:31:25 -------- d-----w- C:\Users\Reungoat\AppData\Roaming\Spotify
.
==================== Find3M ====================
.
2015-02-15 00:10:41 98216 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2015-02-09 00:04:57 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-02-09 00:04:57 701616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2015-02-04 03:16:29 609280 ----a-w- C:\Windows\System32\generaltel.dll
2015-02-04 03:16:20 762368 ----a-w- C:\Windows\System32\invagent.dll
2015-02-04 03:16:16 414720 ----a-w- C:\Windows\System32\devinv.dll
2015-02-04 03:16:14 894976 ----a-w- C:\Windows\System32\appraiser.dll
2015-02-04 03:16:13 227328 ----a-w- C:\Windows\System32\aepdu.dll
2015-02-04 03:16:13 192000 ----a-w- C:\Windows\System32\aepic.dll
2015-02-04 03:13:28 1098752 ----a-w- C:\Windows\System32\aeinv.dll
2015-01-27 23:36:21 1239720 ----a-w- C:\Windows\System32\aitstatic.exe
2015-01-15 08:14:17 155072 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2015-01-15 08:14:16 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2015-01-15 08:09:58 29184 ----a-w- C:\Windows\System32\sspisrv.dll
2015-01-15 08:09:58 136192 ----a-w- C:\Windows\System32\sspicli.dll
2015-01-15 08:09:57 28160 ----a-w- C:\Windows\System32\secur32.dll
2015-01-15 08:09:51 1461760 ----a-w- C:\Windows\System32\lsasrv.dll
2015-01-15 08:09:15 31232 ----a-w- C:\Windows\System32\lsass.exe
2015-01-15 08:08:59 64000 ----a-w- C:\Windows\System32\auditpol.exe
2015-01-15 08:06:22 60416 ----a-w- C:\Windows\System32\msobjs.dll
2015-01-15 08:06:11 146432 ----a-w- C:\Windows\System32\msaudite.dll
2015-01-15 08:04:23 686080 ----a-w- C:\Windows\System32\adtschema.dll
2015-01-15 07:42:59 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2015-01-15 07:42:05 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2015-01-15 07:39:53 60416 ----a-w- C:\Windows\SysWow64\msobjs.dll
2015-01-15 07:39:36 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll
2015-01-15 07:37:55 686080 ----a-w- C:\Windows\SysWow64\adtschema.dll
2015-01-15 04:22:18 458824 ----a-w- C:\Windows\System32\drivers\cng.sys
2015-01-14 06:09:27 5554112 ----a-w- C:\Windows\System32\ntoskrnl.exe
2015-01-14 06:05:30 503808 ----a-w- C:\Windows\System32\srcore.dll
2015-01-14 06:05:30 50176 ----a-w- C:\Windows\System32\srclient.dll
2015-01-14 06:04:56 296960 ----a-w- C:\Windows\System32\rstrui.exe
2015-01-14 05:44:59 3972544 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2015-01-14 05:44:58 3917760 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2015-01-14 05:41:09 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
2015-01-13 03:10:22 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2015-01-13 02:49:19 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2015-01-12 03:05:32 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2015-01-12 03:05:19 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2015-01-12 02:49:42 66560 ----a-w- C:\Windows\System32\iesetup.dll
2015-01-12 02:48:57 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2015-01-12 02:48:52 584192 ----a-w- C:\Windows\System32\vbscript.dll
2015-01-12 02:47:25 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2015-01-12 02:34:42 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2015-01-12 02:34:30 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
2015-01-12 02:25:28 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2015-01-12 02:21:19 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2015-01-12 02:13:27 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2015-01-12 02:08:09 503296 ----a-w- C:\Windows\SysWow64\vbscript.dll
2015-01-12 02:07:51 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2015-01-12 02:07:06 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2015-01-12 02:05:36 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2015-01-12 01:55:47 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2015-01-12 01:46:29 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2015-01-12 01:46:00 2125824 ----a-w- C:\Windows\System32\inetcpl.cpl
2015-01-12 01:40:43 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2015-01-12 01:27:32 2358272 ----a-w- C:\Windows\System32\wininet.dll
2015-01-12 01:23:09 2052608 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2015-01-12 01:22:17 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2015-01-12 01:00:17 1888256 ----a-w- C:\Windows\SysWow64\wininet.dll
2015-01-10 06:48:22 210944 ----a-w- C:\Windows\System32\wdigest.dll
2015-01-10 06:48:19 86528 ----a-w- C:\Windows\System32\TSpkg.dll
2015-01-10 06:48:17 341504 ----a-w- C:\Windows\System32\schannel.dll
2015-01-10 06:48:13 309760 ----a-w- C:\Windows\System32\ncrypt.dll
2015-01-10 06:48:12 314880 ----a-w- C:\Windows\System32\msv1_0.dll
2015-01-10 06:48:10 728064 ----a-w- C:\Windows\System32\kerberos.dll
2015-01-10 06:48:05 22016 ----a-w- C:\Windows\System32\credssp.dll
2015-01-10 06:27:54 172032 ----a-w- C:\Windows\SysWow64\wdigest.dll
2015-01-10 06:27:51 65536 ----a-w- C:\Windows\SysWow64\TSpkg.dll
2015-01-10 06:27:47 248832 ----a-w- C:\Windows\SysWow64\schannel.dll
2015-01-10 06:27:44 221184 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2015-01-10 06:27:43 259584 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2015-01-10 06:27:39 550912 ----a-w- C:\Windows\SysWow64\kerberos.dll
2015-01-10 06:27:32 17408 ----a-w- C:\Windows\SysWow64\credssp.dll
2014-12-19 03:06:55 210432 ----a-w- C:\Windows\System32\profsvc.dll
2014-12-19 01:46:45 141312 ----a-w- C:\Windows\System32\drivers\mrxdav.sys
2014-12-12 05:31:39 1480192 ----a-w- C:\Windows\System32\crypt32.dll
2014-12-12 05:07:26 1174528 ----a-w- C:\Windows\SysWow64\crypt32.dll
2014-12-11 17:47:12 52736 ----a-w- C:\Windows\System32\TSWbPrxy.exe
2014-12-11 08:12:56 1120752 ----a-w- C:\Windows\boinc.scr
2014-12-08 03:09:05 406528 ----a-w- C:\Windows\System32\scesrv.dll
2014-12-08 02:46:05 308224 ----a-w- C:\Windows\SysWow64\scesrv.dll
2014-12-06 04:17:27 303616 ----a-w- C:\Windows\System32\nlasvc.dll
2014-12-06 03:50:19 52224 ----a-w- C:\Windows\SysWow64\nlaapi.dll
2014-12-06 03:50:18 156672 ----a-w- C:\Windows\SysWow64\ncsi.dll
.
============= FINISH: 16:21:27.91 ===============
Last edited: