"Microsoft" called my phone. They knew my name and my e-mail address. They knew I had teamviewer installed. They wanted access. I gave them access to log in but then they wanted control of my keyboard and my boyfriend immediately told me to close the connection and shut off the call. They provided no credentials and they tried to scare me into following their instructions by telling me to look at Event Viewer in Windows. Obviously Event Viewer is full of errors and warnings, most of which I was told are not problematic. As soon as I began questioning my caller, they ditched.
My boyfriend told me that I needed to run CCleaner and do scans, and pointed me out to this forum section because I have already had credit card fraud in the last few weeks. I'm afraid there is a rootkit or something malicious hiding in my computer. Here are the logs. I sincerely appreciate any help you can provide.
Malware Bytes Scan:
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
Database version: v2013.10.18.11
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16721
Aidan :: SARAH [administrator]
Protection: Enabled
10/18/2013 8:19:59 PM
MBAM-log-2013-10-18 (21-15-55).txt
Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 433539
Time elapsed: 55 minute(s), 21 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKCR\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} (PUP.Optional.BrowseFox.A) -> No action taken.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 2
C:\ProgramData\IBUpdaterService (Adware.InstallBrain) -> No action taken.
C:\Users\Aidan\AppData\Roaming\File Scout (PUP.Optional.FileScout.A) -> No action taken.
Files Detected: 7
C:\Users\Aidan\AppData\Roaming\File Scout\filescout.exe (PUP.Optional.FileScout.A) -> No action taken.
C:\Users\Aidan\Downloads\CodecPerformerSetup.exe (Adware.InstallBrain) -> No action taken.
C:\Users\Aidan\Downloads\FlvPlayerSetup.exe (PUP.Optional.InstallCore.A) -> No action taken.
C:\Users\Aidan\Downloads\Player_Setup.exe (PUP.Optional.DomaIQ) -> No action taken.
C:\Users\Aidan\Downloads\Open Canvas Redo\setup_oC5514_en.exe (PUP.Optional.BundleInstaller) -> No action taken.
C:\ProgramData\IBUpdaterService\repository.xml (Adware.InstallBrain) -> No action taken.
C:\Users\Aidan\AppData\Roaming\File Scout\uninst.exe (PUP.Optional.FileScout.A) -> No action taken.
(end)
DDS Attach:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 8
Boot Device: \Device\HarddiskVolume1
Install Date: 8/7/2013 7:40:20 PM
System Uptime: 10/13/2013 10:35:38 PM (119 hours ago)
.
Motherboard: ASUSTeK COMPUTER INC. | | X501A1
Processor: Intel(R) Pentium(R) CPU B980 @ 2.40GHz | SOCKET 0 | 2400/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 119 GiB total, 24.495 GiB free.
D: is FIXED (NTFS) - 158 GiB total, 157.472 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
µTorrent
7-Zip 9.20 (x64 edition)
Adobe AIR
Adobe Flash Player 11 Plugin
Adobe Reader XI (11.0.05)
Adobe Shockwave Player 12.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ASUS InstantOn
ASUS LifeFrame3
ASUS Live Update
ASUS Power4Gear Hybrid
ASUS Smart Gesture
ASUS Splendid Video Enhancement Technology
ASUS WebStorage Sync Agent
AsusVibe2.0
ATK Package
Audacity 2.0.3
avast! Free Antivirus
Bonjour
CCleaner
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
D3DX10
ffdshow v1.2.4422 [2012-04-09]
FlvPlayer
Google Chrome
Google Update Helper
Haunted Memories
Heroes of Newerth
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946040)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946308)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946344)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947540)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789)
HP Deskjet 3510 series Basic Device Software
HP Update
Intel(R) Manageability Engine Firmware Recovery Agent
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) SDK for OpenCL - CPU Only Runtime Package
Intel® Trusted Connect Service Client
iTunes
Java 7 Update 25
Java 7 Update 25 (64-bit)
Java Auto Updater
K-Lite Codec Pack 9.9.5 (64-bit)
K-Lite Codec Pack 9.9.5 (Full)
League of Legends
LibreOffice 4.1.1.2
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft Application Error Reporting
Microsoft IntelliPoint 8.2
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual Studio Tools for Applications 2.0 - ENU
Microsoft Visual Studio Tools for Applications 2.0 Runtime
Microsoft XNA Framework Redistributable 4.0
Movie Maker
Mozilla Firefox 24.0 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSVCRT110
MSVCRT110_amd64
NVIDIA PhysX v8.10.17
Open Broadcaster Software
openCanvas 5.5.17
Origin
Pando Media Booster
PESTERCHUM
Photo Common
Photo Gallery
Portal
QuickTime
Ralink RT2860 Wireless LAN Card
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek PCIE Card Reader
Shared C Run-time for x64
Skype™ 6.7
Steam
swMSM
System Requirements Lab for Intel
Team Fortress 2
TechPowerUp GPU-Z
Terraria v1.2.0.2 cracked-KEBAB
The Sims™ 3
The Sims™ 3 High-End Loft Stuff
The Sims™ 3 Late Night
The Weather Channel App
VLC media player 2.0.8
Wacom
WebTablet FB Plugin 32 bit
WebTablet FB Plugin 64 bit
Windows Driver Package - ASUS (ATP) Mouse (10/29/2012 1.0.0.148)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinFlash
WinRAR 4.20 (64-bit)
World of Warcraft
.
==== Event Viewer Messages From Past Week ========
.
10/18/2013 7:04:03 PM, Error: Microsoft-Windows-Kernel-Power [137] - The system firmware has changed the processor's memory type range registers (MTRRs) across a sleep state transition (S4). This can result in reduced resume performance.
10/16/2013 1:39:33 AM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
10/15/2013 9:46:33 AM, Error: Service Control Manager [7031] - The avast! Antivirus service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
10/13/2013 10:35:54 PM, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
10/12/2013 1:30:05 AM, Error: Schannel [36888] - A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 107.
10/12/2013 1:30:05 AM, Error: Schannel [36874] - An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
10/11/2013 11:05:45 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
10/11/2013 11:05:45 PM, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
.
==== End Of File ===========================
DDS.txt:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.25.2
Run by Aidan at 21:40:36 on 2013-10-18
Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.3980.1788 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\dwm.exe
C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\ASUS\P4G\BatteryLife.exe
C:\Windows\system32\taskhostex.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
C:\Windows\Explorer.EXE
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Tablet\Pen\WacomHost.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.6.112\AsusWSPanel.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://asus13.msn.com
uDefault_Page_URL = hxxp://asus13.msn.com
mWinlogon: Userinit = userinit.exe
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
uRun: [DW7] "C:\Program Files (x86)\The Weather Channel\The Weather Channel App\TWCApp.exe"
mRun: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
mRun: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.6.112\AsusWSPanel.exe /S
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\ASUSVI~1.LNK - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0} : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0}\1436275702055726C696360275966496 : DHCPNameServer = 8.8.8.8 8.8.4.4
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0}\2375942554734363 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0}\7796E647562726F64747F6D6 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0}\84F4D454D233439303 : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0}\D434450275962756C6563737 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0}\E4548545 : DHCPNameServer = 10.13.25.2 10.1.2.1 10.1.2.2
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0}\E4963656D41607C656D27657563747 : DHCPNameServer = 192.168.33.1 75.75.75.75 75.75.76.76
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [AuditSHD] C:\Windows\System32\oobe\auditshd.exe
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
x64-Run: [IgfxTray] "C:\Windows\System32\igfxtray.exe"
x64-Run: [HotKeysCmds] "C:\Windows\System32\hkcmd.exe"
x64-Run: [Persistence] "C:\Windows\System32\igfxpers.exe"
x64-Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Aidan\AppData\Roaming\Mozilla\Firefox\Profiles\07op7def.default\
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;C:\Windows\System32\Drivers\aswRvrt.sys [2013-8-17 65336]
R0 aswVmm;aswVmm;C:\Windows\System32\Drivers\aswVmm.sys [2013-8-17 189936]
R0 iaStorA;iaStorA;C:\Windows\System32\Drivers\iaStorA.sys [2012-7-5 645952]
R1 aswSnx;aswSnx;C:\Windows\System32\Drivers\aswSnx.sys [2013-8-17 1030952]
R1 aswSP;aswSP;C:\Windows\System32\Drivers\aswSP.sys [2013-8-17 378944]
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-9-7 17536]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-2 15416]
R2 ASUS InstantOn;ASUS InstantOn Service;C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-4-13 277120]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\Drivers\aswFsBlk.sys [2013-8-17 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\Drivers\aswMonFlt.sys [2013-8-17 80816]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-8-17 46808]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-12-19 129856]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-12-19 166720]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-10-18 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-10-18 701512]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-12-19 365376]
R2 WTabletServiceCon;Wacom Consumer Service;C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [2013-10-2 619904]
R3 ATP;ASUS PS/2 Port Input Device;C:\Windows\System32\Drivers\AsusTP.sys [2012-10-31 61824]
R3 HIDSwitch;ASUS Wireless Radio Control;C:\Windows\System32\Drivers\AsHIDSwitch64.sys [2012-8-28 21152]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-8-30 169752]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\Drivers\IntcDAud.sys [2012-8-28 342528]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\Drivers\mbam.sys [2013-10-18 25928]
R3 RSBASTOR;Realtek PCIE CardReader Driver - BA;C:\Windows\System32\Drivers\RtsBaStor.sys [2012-12-19 294544]
R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2012-12-19 690832]
S3 hidkmdf;KMDF Driver;C:\Windows\System32\Drivers\hidkmdf.sys [2013-10-2 13728]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\Drivers\netr28x.sys [2012-12-19 1951304]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 WacHidRouter;Wacom Hid Router;C:\Windows\System32\Drivers\wachidrouter.sys [2013-10-2 81824]
S3 wacomrouterfilter;Wacom Router Filter Driver;C:\Windows\System32\Drivers\wacomrouterfilter.sys [2013-10-2 15776]
S3 WUDFWpdMtp;WUDFWpdMtp;C:\Windows\System32\Drivers\WUDFRd.sys [2012-7-25 198656]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2013-10-19 00:00:23 -------- dc----w- C:\Users\Aidan\AppData\Roaming\Malwarebytes
2013-10-19 00:00:14 -------- dc----w- C:\ProgramData\Malwarebytes
2013-10-19 00:00:13 25928 -c--a-w- C:\Windows\System32\drivers\mbam.sys
2013-10-19 00:00:12 -------- dc----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-18 23:54:54 -------- dc----w- C:\Program Files\CCleaner
2013-10-14 02:17:19 566784 -c--a-w- C:\Windows\System32\wvc.dll
2013-10-14 02:17:19 1374208 -c--a-w- C:\Windows\System32\wdc.dll
2013-10-14 02:17:18 462336 -c--a-w- C:\Windows\System32\sysmon.ocx
2013-10-14 02:17:18 437248 -c--a-w- C:\Windows\SysWow64\wvc.dll
2013-10-14 02:17:18 399360 -c--a-w- C:\Windows\SysWow64\sysmon.ocx
2013-10-14 02:17:18 1245696 -c--a-w- C:\Windows\SysWow64\wdc.dll
2013-10-12 04:44:14 467984 -c--a-w- C:\Windows\SysWow64\d3dx10_39.dll
2013-10-12 04:44:14 1493528 -c--a-w- C:\Windows\SysWow64\D3DCompiler_39.dll
2013-10-12 04:44:13 3851784 -c--a-w- C:\Windows\SysWow64\D3DX9_39.dll
2013-10-12 04:44:06 -------- dc----w- C:\Riot Games
2013-10-12 04:42:08 -------- dc----w- C:\Users\Aidan\AppData\Local\PMB Files
2013-10-12 04:42:04 -------- dc----w- C:\ProgramData\PMB Files
2013-10-12 04:41:55 -------- dc----w- C:\Program Files (x86)\Pando Networks
2013-10-12 04:41:28 -------- dc----w- C:\Users\Aidan\AppData\Roaming\Riot Games
2013-10-10 21:09:04 652288 -c--a-w- C:\Windows\System32\comctl32.dll
2013-10-10 21:09:04 541696 -c--a-w- C:\Windows\SysWow64\comctl32.dll
2013-10-10 21:09:00 44032 -c--a-w- C:\Windows\SysWow64\UXInit.dll
2013-10-10 21:07:58 79192 -c--a-w- C:\Windows\System32\drivers\usbehci.sys
2013-10-10 21:07:58 32256 -c--a-w- C:\Windows\System32\drivers\usbuhci.sys
2013-10-10 21:07:58 21848 -c--a-w- C:\Windows\System32\drivers\usbd.sys
2013-10-10 21:07:58 120832 -c--a-w- C:\Windows\System32\drivers\usbccgp.sys
2013-10-10 21:07:57 337752 -c--a-w- C:\Windows\System32\drivers\USBXHCI.SYS
2013-10-10 21:07:57 124112 -c--a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 21:07:57 102608 -c--a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 21:07:56 447320 -c--a-w- C:\Windows\System32\drivers\USBHUB3.SYS
2013-10-10 21:07:56 213336 -c--a-w- C:\Windows\System32\drivers\UCX01000.SYS
2013-10-08 23:52:05 79360 -c--a-w- C:\Windows\SysWow64\ff_vfw.dll
2013-10-08 23:51:54 -------- dc----w- C:\ProgramData\IBUpdaterService
2013-10-08 23:51:53 -------- dc----w- C:\Users\Aidan\AppData\Roaming\File Scout
2013-10-03 01:06:58 -------- dc----w- C:\Program Files (x86)\portalgraphics
2013-10-03 00:52:21 -------- dc----w- C:\ProgramData\Protexis
2013-10-03 00:49:46 -------- dc----w- C:\Users\Aidan\AppData\Local\Microsoft Help
2013-10-03 00:46:03 -------- dc----w- C:\ProgramData\Corel
2013-10-03 00:38:53 -------- dc----w- C:\ProgramData\CorelDRAW Graphics Suite X6
2013-10-03 00:28:08 -------- dc----w- C:\Users\Aidan\AppData\Roaming\WTablet
2013-10-01 23:55:52 -------- dc----w- C:\Program Files (x86)\Microsoft XNA
2013-09-27 14:30:11 -------- dc----w- C:\Windows\en
2013-09-27 14:29:14 -------- dc----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-09-27 14:23:56 89944 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\310e34391cebb8d04\DSETUP.dll
2013-09-27 14:23:56 537432 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\310e34391cebb8d04\DXSETUP.exe
2013-09-27 14:23:56 1801048 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\310e34391cebb8d04\dsetup32.dll
2013-09-27 14:23:52 525656 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2e087cbe1cebb8d03\DXSETUP.exe
2013-09-27 14:23:51 94040 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2e087cbe1cebb8d03\DSETUP.dll
2013-09-27 14:23:51 1691480 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2e087cbe1cebb8d03\dsetup32.dll
2013-09-27 14:23:47 89944 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2c7032021cebb8d02\DSETUP.dll
2013-09-27 14:23:47 537432 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2c7032021cebb8d02\DXSETUP.exe
2013-09-27 14:23:47 1801048 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2c7032021cebb8d02\dsetup32.dll
2013-09-27 14:23:37 -------- dc----w- C:\Users\Aidan\AppData\Local\Windows Live
2013-09-27 14:23:14 -------- dc----w- C:\Program Files (x86)\Common Files\Windows Live
2013-09-26 18:00:39 208760 -c--a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
2013-09-25 20:20:35 -------- dc----w- C:\Users\Aidan\AppData\Local\Blizzard Entertainment
2013-09-23 02:15:21 -------- dc----w- C:\Program Files (x86)\FlvPlayer
.
==================== Find3M ====================
.
2013-10-14 02:39:28 408 -c--a-w- C:\Users\Aidan\AppData\Roaming\sp_data.sys
2013-10-02 01:38:13 78296 -c--a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-02 01:38:13 694232 -c--a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-09-22 23:28:06 1767936 -c--a-w- C:\Windows\SysWow64\wininet.dll
2013-09-22 23:27:49 2876928 -c--a-w- C:\Windows\SysWow64\jscript9.dll
2013-09-22 22:55:10 2241024 -c--a-w- C:\Windows\System32\wininet.dll
2013-09-22 22:54:51 3959296 -c--a-w- C:\Windows\System32\jscript9.dll
2013-09-14 12:38:50 21 -c--a-w- C:\Users\Aidan\AppData\Roaming\my_intel.sys
2013-08-23 05:11:57 4040192 -c--a-w- C:\Windows\System32\win32k.sys
2013-08-18 02:55:26 189936 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-08-18 02:55:26 1030952 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-08-16 20:35:19 447752 -c--a-w- C:\Windows\SysWow64\vp6vfw.dll
2013-08-16 05:41:13 58200 -c--a-w- C:\Windows\System32\drivers\dam.sys
2013-08-16 05:39:26 2371728 -c--a-w- C:\Windows\System32\WSService.dll
2013-08-16 05:32:48 209200 -c--a-w- C:\Windows\System32\NotificationUI.exe
2013-08-16 05:22:22 40448 -c--a-w- C:\Windows\System32\wuapp.exe
2013-08-16 05:22:11 4917760 -c--a-w- C:\Windows\System32\sppsvc.exe
2013-08-16 05:20:30 105984 -c--a-w- C:\Windows\System32\WinSetupUI.dll
2013-08-15 22:43:21 35328 -c--a-w- C:\Windows\SysWow64\wuapp.exe
2013-08-15 22:43:07 84992 -c--a-w- C:\Windows\SysWow64\wudriver.dll
2013-08-15 22:43:07 126976 -c--a-w- C:\Windows\SysWow64\wuwebv.dll
2013-08-15 22:43:03 562688 -c--a-w- C:\Windows\SysWow64\WSShared.dll
2013-08-15 22:43:03 159232 -c--a-w- C:\Windows\SysWow64\WSSync.dll
2013-08-15 22:43:02 83968 -c--a-w- C:\Windows\SysWow64\OEMLicense.dll
2013-08-15 22:43:02 167424 -c--a-w- C:\Windows\SysWow64\WSClient.dll
2013-08-15 22:43:02 143872 -c--a-w- C:\Windows\SysWow64\Windows.ApplicationModel.Store.dll
2013-08-15 22:43:02 124928 -c--a-w- C:\Windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-08-15 22:42:52 76800 -c--a-w- C:\Windows\SysWow64\setupcln.dll
2013-08-15 22:42:47 91648 -c--a-w- C:\Windows\SysWow64\sppc.dll
2013-08-10 05:21:51 448512 -c--a-w- C:\Windows\System32\SettingSync.dll
2013-08-10 05:21:51 128512 -c--a-w- C:\Windows\System32\SettingSyncInfo.dll
2013-08-10 03:58:51 356352 -c--a-w- C:\Windows\SysWow64\SettingSync.dll
2013-08-09 20:26:10 279024 -c--a-w- C:\Windows\SysWow64\IntelCpHeciSvc.exe
2013-08-09 20:26:08 515568 -c--a-w- C:\Windows\System32\igfxsrvc.exe
2013-08-09 20:26:08 442352 -c--a-w- C:\Windows\System32\igfxpers.exe
2013-08-09 20:26:08 172016 -c--a-w- C:\Windows\System32\igfxtray.exe
2013-08-09 20:26:06 5905904 -c--a-w- C:\Windows\System32\GfxUI.exe
2013-08-09 20:26:06 399856 -c--a-w- C:\Windows\System32\hkcmd.exe
2013-08-09 20:26:06 254960 -c--a-w- C:\Windows\System32\igfxext.exe
2013-08-09 20:26:04 185840 -c--a-w- C:\Windows\System32\difx64.exe
2013-08-08 00:02:15 972712 -c--a-w- C:\Windows\System32\deployJava1.dll
2013-08-08 00:02:15 1093032 -c--a-w- C:\Windows\System32\npDeployJava1.dll
2013-08-08 00:02:15 108968 -c--a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2013-08-08 00:01:40 96168 -c--a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-08-08 00:01:40 867240 -c--a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-08-08 00:01:40 789416 -c--a-w- C:\Windows\SysWow64\deployJava1.dll
2013-08-07 05:15:02 144896 -c--a-w- C:\Windows\System32\tssdisai.dll
2013-08-02 06:28:29 10116608 -c--a-w- C:\Windows\System32\twinui.dll
2013-08-02 06:26:53 2304512 -c--a-w- C:\Windows\System32\authui.dll
2013-08-02 05:08:18 8858112 -c--a-w- C:\Windows\SysWow64\twinui.dll
2013-08-02 05:06:50 2035712 -c--a-w- C:\Windows\SysWow64\authui.dll
2013-08-01 10:41:31 2233688 -c--a-w- C:\Windows\System32\drivers\tcpip.sys
2013-07-27 03:58:39 2207232 -c--a-w- C:\Windows\SysWow64\PrintConfig.dll
2013-07-24 23:10:08 158208 -c--a-w- C:\Windows\SysWow64\mbsmsapi.dll
2013-07-24 23:06:39 225280 -c--a-w- C:\Windows\System32\mbsmsapi.dll
.
============= FINISH: 21:41:02.90 ===============
My boyfriend told me that I needed to run CCleaner and do scans, and pointed me out to this forum section because I have already had credit card fraud in the last few weeks. I'm afraid there is a rootkit or something malicious hiding in my computer. Here are the logs. I sincerely appreciate any help you can provide.
Malware Bytes Scan:
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
Database version: v2013.10.18.11
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16721
Aidan :: SARAH [administrator]
Protection: Enabled
10/18/2013 8:19:59 PM
MBAM-log-2013-10-18 (21-15-55).txt
Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 433539
Time elapsed: 55 minute(s), 21 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKCR\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} (PUP.Optional.BrowseFox.A) -> No action taken.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 2
C:\ProgramData\IBUpdaterService (Adware.InstallBrain) -> No action taken.
C:\Users\Aidan\AppData\Roaming\File Scout (PUP.Optional.FileScout.A) -> No action taken.
Files Detected: 7
C:\Users\Aidan\AppData\Roaming\File Scout\filescout.exe (PUP.Optional.FileScout.A) -> No action taken.
C:\Users\Aidan\Downloads\CodecPerformerSetup.exe (Adware.InstallBrain) -> No action taken.
C:\Users\Aidan\Downloads\FlvPlayerSetup.exe (PUP.Optional.InstallCore.A) -> No action taken.
C:\Users\Aidan\Downloads\Player_Setup.exe (PUP.Optional.DomaIQ) -> No action taken.
C:\Users\Aidan\Downloads\Open Canvas Redo\setup_oC5514_en.exe (PUP.Optional.BundleInstaller) -> No action taken.
C:\ProgramData\IBUpdaterService\repository.xml (Adware.InstallBrain) -> No action taken.
C:\Users\Aidan\AppData\Roaming\File Scout\uninst.exe (PUP.Optional.FileScout.A) -> No action taken.
(end)
DDS Attach:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 8
Boot Device: \Device\HarddiskVolume1
Install Date: 8/7/2013 7:40:20 PM
System Uptime: 10/13/2013 10:35:38 PM (119 hours ago)
.
Motherboard: ASUSTeK COMPUTER INC. | | X501A1
Processor: Intel(R) Pentium(R) CPU B980 @ 2.40GHz | SOCKET 0 | 2400/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 119 GiB total, 24.495 GiB free.
D: is FIXED (NTFS) - 158 GiB total, 157.472 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
µTorrent
7-Zip 9.20 (x64 edition)
Adobe AIR
Adobe Flash Player 11 Plugin
Adobe Reader XI (11.0.05)
Adobe Shockwave Player 12.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ASUS InstantOn
ASUS LifeFrame3
ASUS Live Update
ASUS Power4Gear Hybrid
ASUS Smart Gesture
ASUS Splendid Video Enhancement Technology
ASUS WebStorage Sync Agent
AsusVibe2.0
ATK Package
Audacity 2.0.3
avast! Free Antivirus
Bonjour
CCleaner
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
D3DX10
ffdshow v1.2.4422 [2012-04-09]
FlvPlayer
Google Chrome
Google Update Helper
Haunted Memories
Heroes of Newerth
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946040)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946308)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946344)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947540)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789)
HP Deskjet 3510 series Basic Device Software
HP Update
Intel(R) Manageability Engine Firmware Recovery Agent
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) SDK for OpenCL - CPU Only Runtime Package
Intel® Trusted Connect Service Client
iTunes
Java 7 Update 25
Java 7 Update 25 (64-bit)
Java Auto Updater
K-Lite Codec Pack 9.9.5 (64-bit)
K-Lite Codec Pack 9.9.5 (Full)
League of Legends
LibreOffice 4.1.1.2
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft Application Error Reporting
Microsoft IntelliPoint 8.2
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual Studio Tools for Applications 2.0 - ENU
Microsoft Visual Studio Tools for Applications 2.0 Runtime
Microsoft XNA Framework Redistributable 4.0
Movie Maker
Mozilla Firefox 24.0 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSVCRT110
MSVCRT110_amd64
NVIDIA PhysX v8.10.17
Open Broadcaster Software
openCanvas 5.5.17
Origin
Pando Media Booster
PESTERCHUM
Photo Common
Photo Gallery
Portal
QuickTime
Ralink RT2860 Wireless LAN Card
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek PCIE Card Reader
Shared C Run-time for x64
Skype™ 6.7
Steam
swMSM
System Requirements Lab for Intel
Team Fortress 2
TechPowerUp GPU-Z
Terraria v1.2.0.2 cracked-KEBAB
The Sims™ 3
The Sims™ 3 High-End Loft Stuff
The Sims™ 3 Late Night
The Weather Channel App
VLC media player 2.0.8
Wacom
WebTablet FB Plugin 32 bit
WebTablet FB Plugin 64 bit
Windows Driver Package - ASUS (ATP) Mouse (10/29/2012 1.0.0.148)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinFlash
WinRAR 4.20 (64-bit)
World of Warcraft
.
==== Event Viewer Messages From Past Week ========
.
10/18/2013 7:04:03 PM, Error: Microsoft-Windows-Kernel-Power [137] - The system firmware has changed the processor's memory type range registers (MTRRs) across a sleep state transition (S4). This can result in reduced resume performance.
10/16/2013 1:39:33 AM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
10/15/2013 9:46:33 AM, Error: Service Control Manager [7031] - The avast! Antivirus service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
10/13/2013 10:35:54 PM, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
10/12/2013 1:30:05 AM, Error: Schannel [36888] - A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 107.
10/12/2013 1:30:05 AM, Error: Schannel [36874] - An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
10/11/2013 11:05:45 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
10/11/2013 11:05:45 PM, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
.
==== End Of File ===========================
DDS.txt:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.25.2
Run by Aidan at 21:40:36 on 2013-10-18
Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.3980.1788 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\dwm.exe
C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\ASUS\P4G\BatteryLife.exe
C:\Windows\system32\taskhostex.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
C:\Windows\Explorer.EXE
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Tablet\Pen\WacomHost.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.6.112\AsusWSPanel.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://asus13.msn.com
uDefault_Page_URL = hxxp://asus13.msn.com
mWinlogon: Userinit = userinit.exe
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
uRun: [DW7] "C:\Program Files (x86)\The Weather Channel\The Weather Channel App\TWCApp.exe"
mRun: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
mRun: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.6.112\AsusWSPanel.exe /S
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\ASUSVI~1.LNK - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0} : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0}\1436275702055726C696360275966496 : DHCPNameServer = 8.8.8.8 8.8.4.4
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0}\2375942554734363 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0}\7796E647562726F64747F6D6 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0}\84F4D454D233439303 : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0}\D434450275962756C6563737 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0}\E4548545 : DHCPNameServer = 10.13.25.2 10.1.2.1 10.1.2.2
TCP: Interfaces\{8CB6C7F1-0210-410B-9A10-7DCE210A95F0}\E4963656D41607C656D27657563747 : DHCPNameServer = 192.168.33.1 75.75.75.75 75.75.76.76
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [AuditSHD] C:\Windows\System32\oobe\auditshd.exe
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
x64-Run: [IgfxTray] "C:\Windows\System32\igfxtray.exe"
x64-Run: [HotKeysCmds] "C:\Windows\System32\hkcmd.exe"
x64-Run: [Persistence] "C:\Windows\System32\igfxpers.exe"
x64-Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Aidan\AppData\Roaming\Mozilla\Firefox\Profiles\07op7def.default\
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;C:\Windows\System32\Drivers\aswRvrt.sys [2013-8-17 65336]
R0 aswVmm;aswVmm;C:\Windows\System32\Drivers\aswVmm.sys [2013-8-17 189936]
R0 iaStorA;iaStorA;C:\Windows\System32\Drivers\iaStorA.sys [2012-7-5 645952]
R1 aswSnx;aswSnx;C:\Windows\System32\Drivers\aswSnx.sys [2013-8-17 1030952]
R1 aswSP;aswSP;C:\Windows\System32\Drivers\aswSP.sys [2013-8-17 378944]
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-9-7 17536]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-2 15416]
R2 ASUS InstantOn;ASUS InstantOn Service;C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-4-13 277120]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\Drivers\aswFsBlk.sys [2013-8-17 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\Drivers\aswMonFlt.sys [2013-8-17 80816]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-8-17 46808]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-12-19 129856]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-12-19 166720]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-10-18 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-10-18 701512]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-12-19 365376]
R2 WTabletServiceCon;Wacom Consumer Service;C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [2013-10-2 619904]
R3 ATP;ASUS PS/2 Port Input Device;C:\Windows\System32\Drivers\AsusTP.sys [2012-10-31 61824]
R3 HIDSwitch;ASUS Wireless Radio Control;C:\Windows\System32\Drivers\AsHIDSwitch64.sys [2012-8-28 21152]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-8-30 169752]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\Drivers\IntcDAud.sys [2012-8-28 342528]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\Drivers\mbam.sys [2013-10-18 25928]
R3 RSBASTOR;Realtek PCIE CardReader Driver - BA;C:\Windows\System32\Drivers\RtsBaStor.sys [2012-12-19 294544]
R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2012-12-19 690832]
S3 hidkmdf;KMDF Driver;C:\Windows\System32\Drivers\hidkmdf.sys [2013-10-2 13728]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\Drivers\netr28x.sys [2012-12-19 1951304]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 WacHidRouter;Wacom Hid Router;C:\Windows\System32\Drivers\wachidrouter.sys [2013-10-2 81824]
S3 wacomrouterfilter;Wacom Router Filter Driver;C:\Windows\System32\Drivers\wacomrouterfilter.sys [2013-10-2 15776]
S3 WUDFWpdMtp;WUDFWpdMtp;C:\Windows\System32\Drivers\WUDFRd.sys [2012-7-25 198656]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2013-10-19 00:00:23 -------- dc----w- C:\Users\Aidan\AppData\Roaming\Malwarebytes
2013-10-19 00:00:14 -------- dc----w- C:\ProgramData\Malwarebytes
2013-10-19 00:00:13 25928 -c--a-w- C:\Windows\System32\drivers\mbam.sys
2013-10-19 00:00:12 -------- dc----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-18 23:54:54 -------- dc----w- C:\Program Files\CCleaner
2013-10-14 02:17:19 566784 -c--a-w- C:\Windows\System32\wvc.dll
2013-10-14 02:17:19 1374208 -c--a-w- C:\Windows\System32\wdc.dll
2013-10-14 02:17:18 462336 -c--a-w- C:\Windows\System32\sysmon.ocx
2013-10-14 02:17:18 437248 -c--a-w- C:\Windows\SysWow64\wvc.dll
2013-10-14 02:17:18 399360 -c--a-w- C:\Windows\SysWow64\sysmon.ocx
2013-10-14 02:17:18 1245696 -c--a-w- C:\Windows\SysWow64\wdc.dll
2013-10-12 04:44:14 467984 -c--a-w- C:\Windows\SysWow64\d3dx10_39.dll
2013-10-12 04:44:14 1493528 -c--a-w- C:\Windows\SysWow64\D3DCompiler_39.dll
2013-10-12 04:44:13 3851784 -c--a-w- C:\Windows\SysWow64\D3DX9_39.dll
2013-10-12 04:44:06 -------- dc----w- C:\Riot Games
2013-10-12 04:42:08 -------- dc----w- C:\Users\Aidan\AppData\Local\PMB Files
2013-10-12 04:42:04 -------- dc----w- C:\ProgramData\PMB Files
2013-10-12 04:41:55 -------- dc----w- C:\Program Files (x86)\Pando Networks
2013-10-12 04:41:28 -------- dc----w- C:\Users\Aidan\AppData\Roaming\Riot Games
2013-10-10 21:09:04 652288 -c--a-w- C:\Windows\System32\comctl32.dll
2013-10-10 21:09:04 541696 -c--a-w- C:\Windows\SysWow64\comctl32.dll
2013-10-10 21:09:00 44032 -c--a-w- C:\Windows\SysWow64\UXInit.dll
2013-10-10 21:07:58 79192 -c--a-w- C:\Windows\System32\drivers\usbehci.sys
2013-10-10 21:07:58 32256 -c--a-w- C:\Windows\System32\drivers\usbuhci.sys
2013-10-10 21:07:58 21848 -c--a-w- C:\Windows\System32\drivers\usbd.sys
2013-10-10 21:07:58 120832 -c--a-w- C:\Windows\System32\drivers\usbccgp.sys
2013-10-10 21:07:57 337752 -c--a-w- C:\Windows\System32\drivers\USBXHCI.SYS
2013-10-10 21:07:57 124112 -c--a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 21:07:57 102608 -c--a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 21:07:56 447320 -c--a-w- C:\Windows\System32\drivers\USBHUB3.SYS
2013-10-10 21:07:56 213336 -c--a-w- C:\Windows\System32\drivers\UCX01000.SYS
2013-10-08 23:52:05 79360 -c--a-w- C:\Windows\SysWow64\ff_vfw.dll
2013-10-08 23:51:54 -------- dc----w- C:\ProgramData\IBUpdaterService
2013-10-08 23:51:53 -------- dc----w- C:\Users\Aidan\AppData\Roaming\File Scout
2013-10-03 01:06:58 -------- dc----w- C:\Program Files (x86)\portalgraphics
2013-10-03 00:52:21 -------- dc----w- C:\ProgramData\Protexis
2013-10-03 00:49:46 -------- dc----w- C:\Users\Aidan\AppData\Local\Microsoft Help
2013-10-03 00:46:03 -------- dc----w- C:\ProgramData\Corel
2013-10-03 00:38:53 -------- dc----w- C:\ProgramData\CorelDRAW Graphics Suite X6
2013-10-03 00:28:08 -------- dc----w- C:\Users\Aidan\AppData\Roaming\WTablet
2013-10-01 23:55:52 -------- dc----w- C:\Program Files (x86)\Microsoft XNA
2013-09-27 14:30:11 -------- dc----w- C:\Windows\en
2013-09-27 14:29:14 -------- dc----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-09-27 14:23:56 89944 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\310e34391cebb8d04\DSETUP.dll
2013-09-27 14:23:56 537432 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\310e34391cebb8d04\DXSETUP.exe
2013-09-27 14:23:56 1801048 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\310e34391cebb8d04\dsetup32.dll
2013-09-27 14:23:52 525656 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2e087cbe1cebb8d03\DXSETUP.exe
2013-09-27 14:23:51 94040 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2e087cbe1cebb8d03\DSETUP.dll
2013-09-27 14:23:51 1691480 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2e087cbe1cebb8d03\dsetup32.dll
2013-09-27 14:23:47 89944 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2c7032021cebb8d02\DSETUP.dll
2013-09-27 14:23:47 537432 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2c7032021cebb8d02\DXSETUP.exe
2013-09-27 14:23:47 1801048 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2c7032021cebb8d02\dsetup32.dll
2013-09-27 14:23:37 -------- dc----w- C:\Users\Aidan\AppData\Local\Windows Live
2013-09-27 14:23:14 -------- dc----w- C:\Program Files (x86)\Common Files\Windows Live
2013-09-26 18:00:39 208760 -c--a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
2013-09-25 20:20:35 -------- dc----w- C:\Users\Aidan\AppData\Local\Blizzard Entertainment
2013-09-23 02:15:21 -------- dc----w- C:\Program Files (x86)\FlvPlayer
.
==================== Find3M ====================
.
2013-10-14 02:39:28 408 -c--a-w- C:\Users\Aidan\AppData\Roaming\sp_data.sys
2013-10-02 01:38:13 78296 -c--a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-02 01:38:13 694232 -c--a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-09-22 23:28:06 1767936 -c--a-w- C:\Windows\SysWow64\wininet.dll
2013-09-22 23:27:49 2876928 -c--a-w- C:\Windows\SysWow64\jscript9.dll
2013-09-22 22:55:10 2241024 -c--a-w- C:\Windows\System32\wininet.dll
2013-09-22 22:54:51 3959296 -c--a-w- C:\Windows\System32\jscript9.dll
2013-09-14 12:38:50 21 -c--a-w- C:\Users\Aidan\AppData\Roaming\my_intel.sys
2013-08-23 05:11:57 4040192 -c--a-w- C:\Windows\System32\win32k.sys
2013-08-18 02:55:26 189936 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-08-18 02:55:26 1030952 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-08-16 20:35:19 447752 -c--a-w- C:\Windows\SysWow64\vp6vfw.dll
2013-08-16 05:41:13 58200 -c--a-w- C:\Windows\System32\drivers\dam.sys
2013-08-16 05:39:26 2371728 -c--a-w- C:\Windows\System32\WSService.dll
2013-08-16 05:32:48 209200 -c--a-w- C:\Windows\System32\NotificationUI.exe
2013-08-16 05:22:22 40448 -c--a-w- C:\Windows\System32\wuapp.exe
2013-08-16 05:22:11 4917760 -c--a-w- C:\Windows\System32\sppsvc.exe
2013-08-16 05:20:30 105984 -c--a-w- C:\Windows\System32\WinSetupUI.dll
2013-08-15 22:43:21 35328 -c--a-w- C:\Windows\SysWow64\wuapp.exe
2013-08-15 22:43:07 84992 -c--a-w- C:\Windows\SysWow64\wudriver.dll
2013-08-15 22:43:07 126976 -c--a-w- C:\Windows\SysWow64\wuwebv.dll
2013-08-15 22:43:03 562688 -c--a-w- C:\Windows\SysWow64\WSShared.dll
2013-08-15 22:43:03 159232 -c--a-w- C:\Windows\SysWow64\WSSync.dll
2013-08-15 22:43:02 83968 -c--a-w- C:\Windows\SysWow64\OEMLicense.dll
2013-08-15 22:43:02 167424 -c--a-w- C:\Windows\SysWow64\WSClient.dll
2013-08-15 22:43:02 143872 -c--a-w- C:\Windows\SysWow64\Windows.ApplicationModel.Store.dll
2013-08-15 22:43:02 124928 -c--a-w- C:\Windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-08-15 22:42:52 76800 -c--a-w- C:\Windows\SysWow64\setupcln.dll
2013-08-15 22:42:47 91648 -c--a-w- C:\Windows\SysWow64\sppc.dll
2013-08-10 05:21:51 448512 -c--a-w- C:\Windows\System32\SettingSync.dll
2013-08-10 05:21:51 128512 -c--a-w- C:\Windows\System32\SettingSyncInfo.dll
2013-08-10 03:58:51 356352 -c--a-w- C:\Windows\SysWow64\SettingSync.dll
2013-08-09 20:26:10 279024 -c--a-w- C:\Windows\SysWow64\IntelCpHeciSvc.exe
2013-08-09 20:26:08 515568 -c--a-w- C:\Windows\System32\igfxsrvc.exe
2013-08-09 20:26:08 442352 -c--a-w- C:\Windows\System32\igfxpers.exe
2013-08-09 20:26:08 172016 -c--a-w- C:\Windows\System32\igfxtray.exe
2013-08-09 20:26:06 5905904 -c--a-w- C:\Windows\System32\GfxUI.exe
2013-08-09 20:26:06 399856 -c--a-w- C:\Windows\System32\hkcmd.exe
2013-08-09 20:26:06 254960 -c--a-w- C:\Windows\System32\igfxext.exe
2013-08-09 20:26:04 185840 -c--a-w- C:\Windows\System32\difx64.exe
2013-08-08 00:02:15 972712 -c--a-w- C:\Windows\System32\deployJava1.dll
2013-08-08 00:02:15 1093032 -c--a-w- C:\Windows\System32\npDeployJava1.dll
2013-08-08 00:02:15 108968 -c--a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2013-08-08 00:01:40 96168 -c--a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-08-08 00:01:40 867240 -c--a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-08-08 00:01:40 789416 -c--a-w- C:\Windows\SysWow64\deployJava1.dll
2013-08-07 05:15:02 144896 -c--a-w- C:\Windows\System32\tssdisai.dll
2013-08-02 06:28:29 10116608 -c--a-w- C:\Windows\System32\twinui.dll
2013-08-02 06:26:53 2304512 -c--a-w- C:\Windows\System32\authui.dll
2013-08-02 05:08:18 8858112 -c--a-w- C:\Windows\SysWow64\twinui.dll
2013-08-02 05:06:50 2035712 -c--a-w- C:\Windows\SysWow64\authui.dll
2013-08-01 10:41:31 2233688 -c--a-w- C:\Windows\System32\drivers\tcpip.sys
2013-07-27 03:58:39 2207232 -c--a-w- C:\Windows\SysWow64\PrintConfig.dll
2013-07-24 23:10:08 158208 -c--a-w- C:\Windows\SysWow64\mbsmsapi.dll
2013-07-24 23:06:39 225280 -c--a-w- C:\Windows\System32\mbsmsapi.dll
.
============= FINISH: 21:41:02.90 ===============