Dale Ferrier
Posts: 34 +0
I have obviously gotten some kind of trojan or something. This all started when I stupidly tried to install a cheat for a game. The installer kept going for a long time and I realized something was up so I killed it and then after a few days all these shopping popups started appearing in firefox.
They had been installed as both running software which I removed from programs and features and also as plugins in firefox which I also removed.
I have used two different malware removers which take all installed software off but then after a day or so they begin appearing again.
Here are the logs from the malware removal instructions:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2/7/2015
Scan Time: 1:55:27 PM
Logfile: my_scan_150207.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.02.07.08
Rootkit Database: v2015.02.03.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: dferrier
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 404089
Time Elapsed: 20 min, 25 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 1
PUP.Optional.MiniAdblocker.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{37476589-E48E-439E-A706-56189E2ED4C4}_is1, Quarantined, [515358c3eb9fba7cf590e294df245ca4],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 1
PUP.Optional.MiniAdblocker.A, C:\ProgramData\Mini - Adblocker, Quarantined, [515358c3eb9fba7cf590e294df245ca4],
Files: 1
PUP.Optional.MiniAdblocker.A, C:\ProgramData\Mini - Adblocker\Mini - Adblocker.exe, Quarantined, [515358c3eb9fba7cf590e294df245ca4],
Physical Sectors: 0
(No malicious items detected)
(end)
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
.
==== Disk Partitions =========================
.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
µTorrent
AccelerometerP11
Adobe Acrobat X Pro - English, Français, Deutsch
Adobe AIR
Adobe CS6 Design and Web Premium
Adobe Download Assistant
Adobe Flash Player 16 NPAPI
Adobe Help Manager
Adobe Photoshop Lightroom 3.6 64-bit
Adobe Reader XI (11.0.01)
Adobe Refresh Manager
Adobe Story
Adobe Widget Browser
Adobe® Content Viewer
Advanced Audio FX Engine
AFPL Ghostscript 8.54
AFPL Ghostscript Fonts
ANT Drivers Installer x64
Apple Application Support
AudibleManager
Audiograbber 1.83 SE
Audiograbber MP3 Plugin (64 bit)
BioShock 2
Bonjour
Canon MX920 series MP Drivers
ColorMunki Photo 1.1.1
CompanionLink
Complete Gun Inventory Clerk Pro 7
Creative Pack Volume 1
CyberLink LabelPrint 2.5
CyberLink Media Suite 10
CyberLink Power2Go 8
CyberLink PowerDirector 10
CyberLink PowerDirector 12
CyberLink PowerDVD 10
dBpoweramp DirectShow Decoder
dBpoweramp DSP Effects
dBpoweramp Music Converter
dBPowerAMP Real Audio (Helix) Encoder
DDC Driver 1.5
Dell Edoc Viewer
Deponia
Dillon XL650
DivX Setup
Driver Fusion Premium
DVD Shrink 3.2
Elevated Installer
FastRawViewer x64 1.0.4.530
FileZilla Client 3.8.0
Filmmaker's Toolkit for Studio
FLV to MP3 Converter 2.2.2.0
Font Viewer 2.0
Garmin Communicator Plugin
Garmin Communicator Plugin x64
Garmin Express
Garmin Express Tray
Garmin Training Center
Garmin Training Center 3.4.3
Getting Started with Avid Studio MULTILINGUAL
Getting Started with the new Pinnacle Studio MULTILINGUAL
GoldWave v5.69
Google Update Helper
HandBrake 0.9.9.1
Hollywood FX Volumes 1-3
ImgBurn
Indeo® Software
Instant JPEG From RAW
Intel PROSet Wireless
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
Intel(R) Turbo Boost Technology Monitor 2.0
Intel(R) WiDi
Intel(R) Wireless Display
Intel® PROSet/Wireless WiFi Software
iTunes
Java 7 Update 71
Java Auto Updater
K-Lite Codec Pack 8.9.2 (Full)
Knoll Light Factory EZ Studio 15
Kolor Autopano Pro 2.6
License Support
LIMBO
Logitech Gaming Software
LRTimelapse 3.4.1
Magic Bullet Looks Studio 15
Magic ISO Maker v5.5 (build 0281)
MagicDisc 2.7.106
Malwarebytes Anti-Malware version 2.0.4.1028
Mandelbulber
McAfee Security Scan Plus
MDF to ISO version 1.0
MediaInfo 0.7.65
Microsoft .NET Framework 4 Multi-Targeting Pack
Microsoft .NET Framework 4.5 Multi-Targeting Pack
Microsoft .NET Framework 4.5 SDK
Microsoft .NET Framework 4.5.1
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU)
Microsoft Help Viewer 2.0
Microsoft Help Viewer 2.1
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Office 64-bit Components 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared 64-bit MUI (English) 2007
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
Microsoft Visual Studio Team Foundation Server 2012 Object Model
Microsoft Visual Studio Team Foundation Server 2012 Object Model Language Pack - ENU
Microsoft XNA Framework Redistributable 3.1
Microsoft_VC80_ATL_x86
Microsoft_VC80_ATL_x86_x64
Microsoft_VC80_CRT_x86
Microsoft_VC80_CRT_x86_x64
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFC_x86_x64
Microsoft_VC80_MFCLOC_x86
Microsoft_VC80_MFCLOC_x86_x64
Microsoft_VC90_ATL_x86
Microsoft_VC90_ATL_x86_x64
Microsoft_VC90_CRT_x86
Microsoft_VC90_CRT_x86_x64
Microsoft_VC90_MFC_x86
Microsoft_VC90_MFC_x86_x64
Microsoft_VC90_MFCLOC_x86
Microsoft_VC90_MFCLOC_x86_x64
Motion Graphics Toolkit for Studio
Mozilla Firefox 35.0.1 (x86 en-US)
MPC-HC 1.7.6
MSVCRT Redists
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser
MuseScore 1.3
NewBlue Video Essentials for PowerDirector
NVIDIA Control Panel 285.77
NVIDIA HD Audio Driver 1.2.24.0
NVIDIA Install Application
NVIDIA Optimus 1.5.21
NVIDIA PhysX
NVIDIA Update Components
ODIR
PC Study Bible (remove only)
PDF Password Remover v3.1
PDF Printer Pro v1.3
PDF Settings CS6
Perfect Photo Suite 6.1
Photomatix Pro version 5.0.5a
Pinnacle Studio 15
Pinnacle Studio 15 Ultimate Collection Plugins
Pinnacle Studio 16
Pinnacle Studio 16 - Install Manager
Pinnacle Studio 16 - Standard Content Pack
Pinnacle Studio Bonus Content
Pinnacle Video Driver
PL-2303 USB-to-Serial
PlayReady PC Runtime x86
Portrait Professional Studio 10.6
PRE10STI64Installer
Premium Pack Volumes 1-2
Prerequisites for SSDT
PxMergeModule
Quickset64
QuickTime
Realtek High Definition Audio Driver
Red Giant ToonIt Studio 15
Renesas Electronics USB 3.0 Host Controller Driver
SAMSUNG USB Driver for Mobile Phones
ScoreFitter Volumes 1-2
SDK
Security Task Manager 1.8c
Security Update for Microsoft Office 2007 suites (KB2596666) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2596786) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition
SmartSound Common Data
SmartSound Quicktracks 5
Snagit 11
Sound Blaster X-Fi MB
SpamBayes 1.1a6
SportTracks 3.1
Steam
Still Life
StreamTorrent 1.0
SureThing Disc Labeler Deluxe
Synaptics Pointing Device Driver
Title Extreme
Total Recorder 8.2
Transistor
Trapcode 3DStroke Studio 15
Trapcode Particular Studio
Trapcode Shine Studio 15
True Launch Bar
UltraEdit
UninstallDeviceDll 1.1
Universal Adb Driver
Update for (KB2504637)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2596598) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687310) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VC80CRTRedist - 8.0.50727.6195
Visual Basic for Applications (R) Core
Visual Basic for Applications (R) Core - English
Visual C++ 64-bit Redistributables
Visual C++ Redistributables
VLC media player 2.1.3
VOB2MPG v3
Windows Driver Package - Dynastream Innovations (libusb0) LibUsbDevices (07/07/2009 1.12.2)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1)
Windows Live ID Sign-in Assistant
WinRAR archiver
Wondershare Video Converter Ultimate(Build 7.1.3.3)
X-Rite Device ColorMunki Service
X-Rite Device Manager
.
==== End Of File ===========================
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16428 BrowserJavaVersion: 10.71.2
Run by dferrier at 14:25:50 on 2015-02-07
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uStart Page = www.google.com
uSearch Bar = Preserve
mStart Page = www.google.com
uWinlogon: Shell = -
mWinlogon: Userinit = userinit.exe,
BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.10.106\McAfeeMSS_IE.dll
BHO: 50COauPonns: {5426d494-2d8f-4c5a-98fd-8abc2fc2240d} - C:\Program Files (x86)\50COauPonns\TzroCyYMSyMeeI.dll
BHO: GirreatSavee4U: {c26a5ded-a57b-43e1-be18-ad1c8361efe0} - C:\Program Files (x86)\GirreatSavee4U\bsFElqYSiFdRkK.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
uRun: [AdobeBridge] <no file>
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
dRun: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
dRun: [Reasonable NoClone] "C:\Program Files (x86)\Reasonable NoClone 2011 Enterprise\NoClone.exe" null /startup
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files\McAfee Security Scan\3.10.106\SSScheduler.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
mPolicies-System: EnableUIPI = dword:1
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
Trusted Zone: dell.com
DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxps://support.dell.com/systemprofiler/SysProExe.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{BD2D18FB-1FBF-413C-94DD-79A3E1FE2F06} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{BD2D18FB-1FBF-413C-94DD-79A3E1FE2F06}\1443358303 : DHCPNameServer = 192.168.1.1 68.238.96.12
TCP: Interfaces\{BD2D18FB-1FBF-413C-94DD-79A3E1FE2F06}\4416973794E6E67596669664F62764275656 : DHCPNameServer = 4.2.2.2 4.2.2.3
TCP: Interfaces\{BD2D18FB-1FBF-413C-94DD-79A3E1FE2F06}\44443556276756271405 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{BD2D18FB-1FBF-413C-94DD-79A3E1FE2F06}\7597E6468616D602255637F6274737 : DHCPNameServer = 24.223.107.5 24.72.200.5
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - <orphaned>
AppInit_DLLs= c:\windows\syswow64\nvinit.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} -
x64-BHO: 50COauPonns: {5426d494-2d8f-4c5a-98fd-8abc2fc2240d} - C:\Program Files (x86)\50COauPonns\TzroCyYMSyMeeI.x64.dll
x64-BHO: GirreatSavee4U: {c26a5ded-a57b-43e1-be18-ad1c8361efe0} - C:\Program Files (x86)\GirreatSavee4U\bsFElqYSiFdRkK.x64.dll
x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [RunDLLEntry] C:\Windows\System32\RunDLL32.exe C:\Windows\System32\AmbRunE.dll,RunDLLEntry
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX3
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
x64-Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
x64-DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\dferrier\AppData\Roaming\Mozilla\Firefox\Profiles\bzysztwx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://websearch.searchoholic.info/?pid=21858&r=2015/01/02&hid=2024647092360809010&lg=EN&cc=US&unqvl=72&l=1&q=
FF - prefs.js: browser.search.selectedEngine - WebSearch
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/?gws_rd=ssl
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: C:\Users\dferrier\AppData\Roaming\Mozilla\Firefox\Profiles\bzysztwx.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\npGarmin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll
.
============= SERVICES / DRIVERS ===============
.
.
=============== File Associations ===============
.
FileExt: .txt: Applications\Uedit32.exe="C:\Program Files (x86)\IDM Computer Solutions\UltraEdit\Uedit32.exe" "%1" [UserChoice]
FileExt: .js: jsfile="C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"
ShellExec: dreamweaver.exe: Open="C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\dreamweaver.exe", "%1"
ShellExec: PortraitProfessional.exe: open="C:\Program Files (x86)\Portrait Professional Studio 10\PortraitProfessionalStudio.exe" /P "%1"
.
=============== Created Last 30 ================
.
2015-02-07 19:31:20 -------- d-----w- C:\Program Files (x86)\NickelBlock
2015-02-07 19:31:18 -------- d-----w- C:\Program Files (x86)\GRaeatSaavE4U
2015-02-07 19:31:11 -------- d-----w- C:\Program Files (x86)\50COauPonns
2015-02-06 19:40:31 11870360 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8E62312D-3891-4C4B-9488-CEEB3FCC1D97}\mpengine.dll
2015-02-06 14:17:40 11870360 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-02-05 18:24:38 -------- d-----w- C:\Users\dferrier\AppData\Roaming\Athentech
2015-02-05 18:24:35 -------- d-----w- C:\Program Files\Athentech
2015-02-03 22:22:45 -------- d-----w- C:\Users\dferrier\AppData\Local\LibRaw LLC
2015-02-03 22:22:36 -------- d-----w- C:\Program Files\LibRaw
2015-01-31 23:43:34 -------- d-----w- C:\ProgramData\McAfee Security Scan
2015-01-31 23:43:29 -------- d-----w- C:\Program Files\McAfee Security Scan
2015-01-31 12:22:05 -------- d-----w- C:\Program Files (x86)\DiScounttExitEnsii
2015-01-31 12:22:03 -------- d-----w- C:\Program Files (x86)\NBA Live News
2015-01-31 12:21:58 -------- d-----w- C:\Program Files (x86)\GirreatSavee4U
2015-01-23 06:30:49 1188440 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{92762E6E-7F7C-443D-B16D-494C84DB1F9A}\gapaengine.dll
2015-01-17 02:53:44 -------- d-----w- C:\Users\dferrier\AppData\Roaming\Avg_Update_1014av
2015-01-17 02:53:29 -------- d-----w- C:\ProgramData\Avg_Update_1014av
2015-01-17 02:49:07 -------- d-----w- C:\Users\dferrier\AppData\Roaming\TuneUp Software
2015-01-17 02:43:20 -------- d--h--w- C:\ProgramData\Common Files
2015-01-17 02:43:19 -------- d-----w- C:\Users\dferrier\AppData\Local\MFAData
2015-01-17 02:43:19 -------- d-----w- C:\ProgramData\MFAData
2015-01-17 02:35:37 -------- d-----w- C:\ProgramData\DiSCCountExtaensi
2015-01-17 02:29:13 129752 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2015-01-17 02:28:59 93400 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2015-01-17 02:28:59 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys
2015-01-17 02:28:59 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2015-01-17 02:28:59 -------- d-----w- C:\ProgramData\Malwarebytes
2015-01-17 02:28:59 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-17 02:20:16 -------- d-----w- C:\Program Files (x86)\NNetoCoouupon
2015-01-17 02:20:13 -------- d-----w- C:\Program Files (x86)\RAnDommPRice
2015-01-17 02:15:23 -------- d-----w- C:\Program Files (x86)\RelayAppend
2015-01-16 12:14:50 -------- d-----w- C:\ProgramData\EaxsttraSSaviings
2015-01-15 14:40:31 82112 ----a-w- C:\Windows\System32\drivers\ssudbus.sys
2015-01-15 14:40:31 202560 ----a-w- C:\Windows\System32\drivers\ssudserd.sys
2015-01-15 14:40:31 202560 ----a-w- C:\Windows\System32\drivers\ssudmdm.sys
2015-01-14 04:16:24 -------- d-----w- C:\ProgramData\RAnDommPRice
2015-01-12 03:35:19 -------- d-----w- C:\Users\dferrier\AppData\Roaming\chc
2015-01-12 03:21:50 -------- d-----w- C:\Program Files\PhotomatixPro5
2015-01-11 02:11:39 -------- d-----w- C:\Users\dferrier\AppData\Roaming\DslrDashboard
2015-01-11 02:06:44 -------- d-----w- C:\Program Files (x86)\qdslrdashboard windows
2015-01-09 22:25:13 -------- d-----w- C:\ProgramData\GreoatSuavoe4U
2015-01-09 22:24:54 -------- d-----w- C:\ProgramData\NNetoCoouupon
2015-01-09 06:34:51 -------- d-----w- C:\ProgramData\81154615f828cc82
2015-01-09 00:00:07 -------- d-----w- C:\Users\dferrier\AppData\Roaming\LRTimelapse
2015-01-08 23:55:31 -------- d-----w- C:\Program Files (x86)\LRTimelapse 3
.
==================== Find3M ====================
.
2015-02-06 19:34:21 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-02-06 19:34:21 701616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2015-02-02 22:03:16 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2014-12-31 11:14:31 298120 ------w- C:\Windows\System32\MpSigStub.exe
2014-12-16 15:53:53 98216 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2008-03-19 21:50:26 97280 ----a-w- C:\Program Files (x86)\Common Files\pcsbClean.exe
2008-03-07 01:31:44 134656 ----a-w- C:\Program Files (x86)\Common Files\PCSBoff.exe
.
============= FINISH: 14:26:51.57 ===============
They had been installed as both running software which I removed from programs and features and also as plugins in firefox which I also removed.
I have used two different malware removers which take all installed software off but then after a day or so they begin appearing again.
Here are the logs from the malware removal instructions:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2/7/2015
Scan Time: 1:55:27 PM
Logfile: my_scan_150207.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.02.07.08
Rootkit Database: v2015.02.03.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: dferrier
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 404089
Time Elapsed: 20 min, 25 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 1
PUP.Optional.MiniAdblocker.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{37476589-E48E-439E-A706-56189E2ED4C4}_is1, Quarantined, [515358c3eb9fba7cf590e294df245ca4],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 1
PUP.Optional.MiniAdblocker.A, C:\ProgramData\Mini - Adblocker, Quarantined, [515358c3eb9fba7cf590e294df245ca4],
Files: 1
PUP.Optional.MiniAdblocker.A, C:\ProgramData\Mini - Adblocker\Mini - Adblocker.exe, Quarantined, [515358c3eb9fba7cf590e294df245ca4],
Physical Sectors: 0
(No malicious items detected)
(end)
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
.
==== Disk Partitions =========================
.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
µTorrent
AccelerometerP11
Adobe Acrobat X Pro - English, Français, Deutsch
Adobe AIR
Adobe CS6 Design and Web Premium
Adobe Download Assistant
Adobe Flash Player 16 NPAPI
Adobe Help Manager
Adobe Photoshop Lightroom 3.6 64-bit
Adobe Reader XI (11.0.01)
Adobe Refresh Manager
Adobe Story
Adobe Widget Browser
Adobe® Content Viewer
Advanced Audio FX Engine
AFPL Ghostscript 8.54
AFPL Ghostscript Fonts
ANT Drivers Installer x64
Apple Application Support
AudibleManager
Audiograbber 1.83 SE
Audiograbber MP3 Plugin (64 bit)
BioShock 2
Bonjour
Canon MX920 series MP Drivers
ColorMunki Photo 1.1.1
CompanionLink
Complete Gun Inventory Clerk Pro 7
Creative Pack Volume 1
CyberLink LabelPrint 2.5
CyberLink Media Suite 10
CyberLink Power2Go 8
CyberLink PowerDirector 10
CyberLink PowerDirector 12
CyberLink PowerDVD 10
dBpoweramp DirectShow Decoder
dBpoweramp DSP Effects
dBpoweramp Music Converter
dBPowerAMP Real Audio (Helix) Encoder
DDC Driver 1.5
Dell Edoc Viewer
Deponia
Dillon XL650
DivX Setup
Driver Fusion Premium
DVD Shrink 3.2
Elevated Installer
FastRawViewer x64 1.0.4.530
FileZilla Client 3.8.0
Filmmaker's Toolkit for Studio
FLV to MP3 Converter 2.2.2.0
Font Viewer 2.0
Garmin Communicator Plugin
Garmin Communicator Plugin x64
Garmin Express
Garmin Express Tray
Garmin Training Center
Garmin Training Center 3.4.3
Getting Started with Avid Studio MULTILINGUAL
Getting Started with the new Pinnacle Studio MULTILINGUAL
GoldWave v5.69
Google Update Helper
HandBrake 0.9.9.1
Hollywood FX Volumes 1-3
ImgBurn
Indeo® Software
Instant JPEG From RAW
Intel PROSet Wireless
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
Intel(R) Turbo Boost Technology Monitor 2.0
Intel(R) WiDi
Intel(R) Wireless Display
Intel® PROSet/Wireless WiFi Software
iTunes
Java 7 Update 71
Java Auto Updater
K-Lite Codec Pack 8.9.2 (Full)
Knoll Light Factory EZ Studio 15
Kolor Autopano Pro 2.6
License Support
LIMBO
Logitech Gaming Software
LRTimelapse 3.4.1
Magic Bullet Looks Studio 15
Magic ISO Maker v5.5 (build 0281)
MagicDisc 2.7.106
Malwarebytes Anti-Malware version 2.0.4.1028
Mandelbulber
McAfee Security Scan Plus
MDF to ISO version 1.0
MediaInfo 0.7.65
Microsoft .NET Framework 4 Multi-Targeting Pack
Microsoft .NET Framework 4.5 Multi-Targeting Pack
Microsoft .NET Framework 4.5 SDK
Microsoft .NET Framework 4.5.1
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU)
Microsoft Help Viewer 2.0
Microsoft Help Viewer 2.1
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Office 64-bit Components 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared 64-bit MUI (English) 2007
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
Microsoft Visual Studio Team Foundation Server 2012 Object Model
Microsoft Visual Studio Team Foundation Server 2012 Object Model Language Pack - ENU
Microsoft XNA Framework Redistributable 3.1
Microsoft_VC80_ATL_x86
Microsoft_VC80_ATL_x86_x64
Microsoft_VC80_CRT_x86
Microsoft_VC80_CRT_x86_x64
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFC_x86_x64
Microsoft_VC80_MFCLOC_x86
Microsoft_VC80_MFCLOC_x86_x64
Microsoft_VC90_ATL_x86
Microsoft_VC90_ATL_x86_x64
Microsoft_VC90_CRT_x86
Microsoft_VC90_CRT_x86_x64
Microsoft_VC90_MFC_x86
Microsoft_VC90_MFC_x86_x64
Microsoft_VC90_MFCLOC_x86
Microsoft_VC90_MFCLOC_x86_x64
Motion Graphics Toolkit for Studio
Mozilla Firefox 35.0.1 (x86 en-US)
MPC-HC 1.7.6
MSVCRT Redists
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser
MuseScore 1.3
NewBlue Video Essentials for PowerDirector
NVIDIA Control Panel 285.77
NVIDIA HD Audio Driver 1.2.24.0
NVIDIA Install Application
NVIDIA Optimus 1.5.21
NVIDIA PhysX
NVIDIA Update Components
ODIR
PC Study Bible (remove only)
PDF Password Remover v3.1
PDF Printer Pro v1.3
PDF Settings CS6
Perfect Photo Suite 6.1
Photomatix Pro version 5.0.5a
Pinnacle Studio 15
Pinnacle Studio 15 Ultimate Collection Plugins
Pinnacle Studio 16
Pinnacle Studio 16 - Install Manager
Pinnacle Studio 16 - Standard Content Pack
Pinnacle Studio Bonus Content
Pinnacle Video Driver
PL-2303 USB-to-Serial
PlayReady PC Runtime x86
Portrait Professional Studio 10.6
PRE10STI64Installer
Premium Pack Volumes 1-2
Prerequisites for SSDT
PxMergeModule
Quickset64
QuickTime
Realtek High Definition Audio Driver
Red Giant ToonIt Studio 15
Renesas Electronics USB 3.0 Host Controller Driver
SAMSUNG USB Driver for Mobile Phones
ScoreFitter Volumes 1-2
SDK
Security Task Manager 1.8c
Security Update for Microsoft Office 2007 suites (KB2596666) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2596786) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition
SmartSound Common Data
SmartSound Quicktracks 5
Snagit 11
Sound Blaster X-Fi MB
SpamBayes 1.1a6
SportTracks 3.1
Steam
Still Life
StreamTorrent 1.0
SureThing Disc Labeler Deluxe
Synaptics Pointing Device Driver
Title Extreme
Total Recorder 8.2
Transistor
Trapcode 3DStroke Studio 15
Trapcode Particular Studio
Trapcode Shine Studio 15
True Launch Bar
UltraEdit
UninstallDeviceDll 1.1
Universal Adb Driver
Update for (KB2504637)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2596598) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687310) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VC80CRTRedist - 8.0.50727.6195
Visual Basic for Applications (R) Core
Visual Basic for Applications (R) Core - English
Visual C++ 64-bit Redistributables
Visual C++ Redistributables
VLC media player 2.1.3
VOB2MPG v3
Windows Driver Package - Dynastream Innovations (libusb0) LibUsbDevices (07/07/2009 1.12.2)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1)
Windows Live ID Sign-in Assistant
WinRAR archiver
Wondershare Video Converter Ultimate(Build 7.1.3.3)
X-Rite Device ColorMunki Service
X-Rite Device Manager
.
==== End Of File ===========================
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16428 BrowserJavaVersion: 10.71.2
Run by dferrier at 14:25:50 on 2015-02-07
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uStart Page = www.google.com
uSearch Bar = Preserve
mStart Page = www.google.com
uWinlogon: Shell = -
mWinlogon: Userinit = userinit.exe,
BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.10.106\McAfeeMSS_IE.dll
BHO: 50COauPonns: {5426d494-2d8f-4c5a-98fd-8abc2fc2240d} - C:\Program Files (x86)\50COauPonns\TzroCyYMSyMeeI.dll
BHO: GirreatSavee4U: {c26a5ded-a57b-43e1-be18-ad1c8361efe0} - C:\Program Files (x86)\GirreatSavee4U\bsFElqYSiFdRkK.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
uRun: [AdobeBridge] <no file>
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
dRun: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
dRun: [Reasonable NoClone] "C:\Program Files (x86)\Reasonable NoClone 2011 Enterprise\NoClone.exe" null /startup
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files\McAfee Security Scan\3.10.106\SSScheduler.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
mPolicies-System: EnableUIPI = dword:1
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
Trusted Zone: dell.com
DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxps://support.dell.com/systemprofiler/SysProExe.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{BD2D18FB-1FBF-413C-94DD-79A3E1FE2F06} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{BD2D18FB-1FBF-413C-94DD-79A3E1FE2F06}\1443358303 : DHCPNameServer = 192.168.1.1 68.238.96.12
TCP: Interfaces\{BD2D18FB-1FBF-413C-94DD-79A3E1FE2F06}\4416973794E6E67596669664F62764275656 : DHCPNameServer = 4.2.2.2 4.2.2.3
TCP: Interfaces\{BD2D18FB-1FBF-413C-94DD-79A3E1FE2F06}\44443556276756271405 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{BD2D18FB-1FBF-413C-94DD-79A3E1FE2F06}\7597E6468616D602255637F6274737 : DHCPNameServer = 24.223.107.5 24.72.200.5
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - <orphaned>
AppInit_DLLs= c:\windows\syswow64\nvinit.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} -
x64-BHO: 50COauPonns: {5426d494-2d8f-4c5a-98fd-8abc2fc2240d} - C:\Program Files (x86)\50COauPonns\TzroCyYMSyMeeI.x64.dll
x64-BHO: GirreatSavee4U: {c26a5ded-a57b-43e1-be18-ad1c8361efe0} - C:\Program Files (x86)\GirreatSavee4U\bsFElqYSiFdRkK.x64.dll
x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [RunDLLEntry] C:\Windows\System32\RunDLL32.exe C:\Windows\System32\AmbRunE.dll,RunDLLEntry
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX3
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
x64-Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
x64-DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\dferrier\AppData\Roaming\Mozilla\Firefox\Profiles\bzysztwx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://websearch.searchoholic.info/?pid=21858&r=2015/01/02&hid=2024647092360809010&lg=EN&cc=US&unqvl=72&l=1&q=
FF - prefs.js: browser.search.selectedEngine - WebSearch
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/?gws_rd=ssl
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: C:\Users\dferrier\AppData\Roaming\Mozilla\Firefox\Profiles\bzysztwx.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\npGarmin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll
.
============= SERVICES / DRIVERS ===============
.
.
=============== File Associations ===============
.
FileExt: .txt: Applications\Uedit32.exe="C:\Program Files (x86)\IDM Computer Solutions\UltraEdit\Uedit32.exe" "%1" [UserChoice]
FileExt: .js: jsfile="C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"
ShellExec: dreamweaver.exe: Open="C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\dreamweaver.exe", "%1"
ShellExec: PortraitProfessional.exe: open="C:\Program Files (x86)\Portrait Professional Studio 10\PortraitProfessionalStudio.exe" /P "%1"
.
=============== Created Last 30 ================
.
2015-02-07 19:31:20 -------- d-----w- C:\Program Files (x86)\NickelBlock
2015-02-07 19:31:18 -------- d-----w- C:\Program Files (x86)\GRaeatSaavE4U
2015-02-07 19:31:11 -------- d-----w- C:\Program Files (x86)\50COauPonns
2015-02-06 19:40:31 11870360 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8E62312D-3891-4C4B-9488-CEEB3FCC1D97}\mpengine.dll
2015-02-06 14:17:40 11870360 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-02-05 18:24:38 -------- d-----w- C:\Users\dferrier\AppData\Roaming\Athentech
2015-02-05 18:24:35 -------- d-----w- C:\Program Files\Athentech
2015-02-03 22:22:45 -------- d-----w- C:\Users\dferrier\AppData\Local\LibRaw LLC
2015-02-03 22:22:36 -------- d-----w- C:\Program Files\LibRaw
2015-01-31 23:43:34 -------- d-----w- C:\ProgramData\McAfee Security Scan
2015-01-31 23:43:29 -------- d-----w- C:\Program Files\McAfee Security Scan
2015-01-31 12:22:05 -------- d-----w- C:\Program Files (x86)\DiScounttExitEnsii
2015-01-31 12:22:03 -------- d-----w- C:\Program Files (x86)\NBA Live News
2015-01-31 12:21:58 -------- d-----w- C:\Program Files (x86)\GirreatSavee4U
2015-01-23 06:30:49 1188440 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{92762E6E-7F7C-443D-B16D-494C84DB1F9A}\gapaengine.dll
2015-01-17 02:53:44 -------- d-----w- C:\Users\dferrier\AppData\Roaming\Avg_Update_1014av
2015-01-17 02:53:29 -------- d-----w- C:\ProgramData\Avg_Update_1014av
2015-01-17 02:49:07 -------- d-----w- C:\Users\dferrier\AppData\Roaming\TuneUp Software
2015-01-17 02:43:20 -------- d--h--w- C:\ProgramData\Common Files
2015-01-17 02:43:19 -------- d-----w- C:\Users\dferrier\AppData\Local\MFAData
2015-01-17 02:43:19 -------- d-----w- C:\ProgramData\MFAData
2015-01-17 02:35:37 -------- d-----w- C:\ProgramData\DiSCCountExtaensi
2015-01-17 02:29:13 129752 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2015-01-17 02:28:59 93400 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2015-01-17 02:28:59 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys
2015-01-17 02:28:59 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2015-01-17 02:28:59 -------- d-----w- C:\ProgramData\Malwarebytes
2015-01-17 02:28:59 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-17 02:20:16 -------- d-----w- C:\Program Files (x86)\NNetoCoouupon
2015-01-17 02:20:13 -------- d-----w- C:\Program Files (x86)\RAnDommPRice
2015-01-17 02:15:23 -------- d-----w- C:\Program Files (x86)\RelayAppend
2015-01-16 12:14:50 -------- d-----w- C:\ProgramData\EaxsttraSSaviings
2015-01-15 14:40:31 82112 ----a-w- C:\Windows\System32\drivers\ssudbus.sys
2015-01-15 14:40:31 202560 ----a-w- C:\Windows\System32\drivers\ssudserd.sys
2015-01-15 14:40:31 202560 ----a-w- C:\Windows\System32\drivers\ssudmdm.sys
2015-01-14 04:16:24 -------- d-----w- C:\ProgramData\RAnDommPRice
2015-01-12 03:35:19 -------- d-----w- C:\Users\dferrier\AppData\Roaming\chc
2015-01-12 03:21:50 -------- d-----w- C:\Program Files\PhotomatixPro5
2015-01-11 02:11:39 -------- d-----w- C:\Users\dferrier\AppData\Roaming\DslrDashboard
2015-01-11 02:06:44 -------- d-----w- C:\Program Files (x86)\qdslrdashboard windows
2015-01-09 22:25:13 -------- d-----w- C:\ProgramData\GreoatSuavoe4U
2015-01-09 22:24:54 -------- d-----w- C:\ProgramData\NNetoCoouupon
2015-01-09 06:34:51 -------- d-----w- C:\ProgramData\81154615f828cc82
2015-01-09 00:00:07 -------- d-----w- C:\Users\dferrier\AppData\Roaming\LRTimelapse
2015-01-08 23:55:31 -------- d-----w- C:\Program Files (x86)\LRTimelapse 3
.
==================== Find3M ====================
.
2015-02-06 19:34:21 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-02-06 19:34:21 701616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2015-02-02 22:03:16 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2014-12-31 11:14:31 298120 ------w- C:\Windows\System32\MpSigStub.exe
2014-12-16 15:53:53 98216 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2008-03-19 21:50:26 97280 ----a-w- C:\Program Files (x86)\Common Files\pcsbClean.exe
2008-03-07 01:31:44 134656 ----a-w- C:\Program Files (x86)\Common Files\PCSBoff.exe
.
============= FINISH: 14:26:51.57 ===============