Hi, I would like to know whether my computer is infected with any virus or spyware. Thank you. Here's the logs required.
MBAM Log :
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 4/24/2014
Scan Time: 10:29:58 PM
Logfile:
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.04.24.07
Rootkit Database: v2014.03.27.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: lion
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 271855
Time Elapsed: 8 min, 19 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 1
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://start.mysearchdial.com/?f=1&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir=, Good: (http://www.google.com), Bad: (http://start.mysearchdial.com/?f=1&...),Replaced,[0b1ca589e398221438c0cd602bd957a9]
Folders: 0
(No malicious items detected)
Files: 65
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\searchplugins\Mysearchdial.xml, Quarantined, [71b62806afcc95a108e11c5c50b28b75],
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "homepage": "http://start.mysearchdial.com/?f=1&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir=",), Replaced,[8d9aa18d25562412acb5e9712dd7fe02]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "startup_urls": [ "http://start.mysearchdial.com/?f=1&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir=" ],), Replaced,[28ffda54d7a4102600933822907416ea]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.AL", 2), Replaced,[2dfab47a106b9b9be6de87d2cf3553ad]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.aflt", "irmsd0202ch"), Replaced,[35f248e6d9a2cf67566e9dbc758f738d]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"), Replaced,[47e05bd33843b08614b08ecb0bf949b7]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuyC0CyCtByC0DtA0ByByBzzyB0EtAzy0EtN0D0Tzu0SyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytDtCtG1TtN1L1G1B1V1N2Y1L1Qzu2StBtA0Czy0CzytCtCtGtByCyDtAtG0BzztCyDtG0AyD0ByEtGyBtCtDtC0CzztDyCtAzz0DtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByDyCyByByC0B0DtGzy0CyCyCtGzztC0AzytGtCtC0B0DtGtByB0CtDyD0ByCyE0E0AtD0A2Q"), Replaced,[14138aa4cdae90a6269ed089a064e11f]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.cntry", "SG"), Replaced,[2ff86cc2a0dbe6509c28a3b6e12351af]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.cr", "2125331065"), Replaced,[c562af7f88f3e5517351c99011f335cb]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.dfltLng", ""), Replaced,[f532e64893e8211502c260f906fe22de]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.dfltSrch", true), Replaced,[eb3c9c925823ca6c299b4a0f0301f808]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.dnsErr", true), Replaced,[e542ab83780340f6f7cdf564679de020]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,1828564131,3396905322,2787570089,1850357963,3855095921,1516386922,3836221436,2015489896,270173904,3729539987,424611005,965674394,609003582,2041931190,3874294282,2774755777,931959409,398575749,3999997753,1104451911,1233863968,4280856088,1554076246,1949401179,1770772786,3253391265,3778438159,1649478750,2848156272,2476712966,3103989719,475488147,1715867073,3594694113,3774606882,4036647035,1593922001,4110151693,2941033654,3206511613"), Replaced,[87a081ad6219bf773d87b0a935cfbf41]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.excTlbr", false), Replaced,[9493fa34e09bb97d05bf104959abf40c]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.hdrMd5", "3D0D29CD53FA3539C57751280CCE503D"), Replaced,[f0370d218bf0e94d16ae68f1a262738d]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.hmpg", true), Replaced,[69bee34b7cff48eeaf15d7821be99769]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.hmpgUrl", "http://start.mysearchdial.com/?f=1&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir="), Replaced,[db4c062880fb072fa71d70e93aca7987]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.id", "6C626D3B7787E39E"), Replaced,[49de8aa4e19a320492321c3dff05c43c]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.instlDay", "16133"), Replaced,[d651f03e97e47bbbcff5e772c73d07f9]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.instlRef", "0901-a"), Replaced,[1b0ce5497a010b2ba4201247966e847c]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.lastB", "http://start.mysearchdial.com/?f=1&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir="), Replaced,[c364d9557ffcaf873b89bf9a709430d0]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.29.08:26:56"), Replaced,[56d11a143a4181b5269e273272922bd5]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.newTabUrl", "http://start.mysearchdial.com/?f=2&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir="), Replaced,[21064de1a6d5ef47a81c461313f1ac54]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.prdct", "mysearchdial"), Replaced,[ca5de846a3d820165e66104916eebf41]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"), Replaced,[48dfb17d116a0036cbf983d664a007f9]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.sg", "none"), Replaced,[56d128066615c571bf0523366c986a96]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"), Replaced,[84a3d45a116a0f27ae161049a06460a0]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.tlbrId", "base"), Replaced,[df4888a6403b74c27c485efbf014aa56]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.tlbrSrchUrl", "http://start.mysearchdial.com/?f=3&...yB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir=&q="), Replaced,[58cf101e1665d1654480c891798be31d]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.vrsn", "1.8.29.0"), Replaced,[9f8882ac03780c2a04c07bdefe06857b]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.vrsni", "1.8.29.0"), Replaced,[44e3032bcfacf24407bd1148ec180af6]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.hmpg", true), Replaced,[e542d05e7ffceb4b6d5773e67b89659b]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.newTab", false), Replaced,[47e0fb33611aab8b457ff36611f3f010]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.smplGrp", "none"), Replaced,[a681bf6fdaa178be1fa565f48d777f81]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.08:26:56"), Replaced,[87a084aad4a791a53f857adf1aeab54b]
PUP.Optional.MySearch.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.irmysearch.aflt", "irmsd0202ch"), Replaced,[3bec9a940675fd393389bd9c52b25fa1]
PUP.Optional.MySearch.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.irmysearch.instlRef", "0901-a"), Replaced,[ce5938f6bcbff541516bdc7d32d23bc5]
PUP.Optional.MySearch.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.irmysearch.cr", "2125331065"), Replaced,[4bdc1d119cdfa78f16a60257768eb050]
PUP.Optional.MySearch.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzuyC0CyCtByC0DtA0ByByBzzyB0EtAzy0EtN0D0Tzu0SyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytDtCtG1TtN1L1G1B1V1N2Y1L1Qzu2StBtA0Czy0CzytCtCtGtByCyDtAtG0BzztCyDtG0AyD0ByEtGyBtCtDtC0CzztDyCtAzz0DtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByDyCyByByC0B0DtGzy0CyCyCtGzztC0AzytGtCtC0B0DtGtByB0CtDyD0ByCyE0E0AtD0A2Q"), Replaced,[13147bb3dd9ea88e407cadac8d771fe1]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.hmpg", true), Replaced,[c95eec420774ff37daebb1a825df0bf5]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.hmpgUrl", "http://start.mysearchdial.com/?f=1&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir="), Replaced,[52d584aa364590a601c4b0a96c98fe02]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.dfltSrch", true), Replaced,[40e7ab83651692a4616406530ef6936d]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"), Replaced,[1d0ac26c146739fdebdae970d3317a86]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.dnsErr", true), Replaced,[9097ba74bfbcd56171543821857fa858]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.newTab", false), Replaced,[21060a2482f958de1ea73e1b986cde22]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.newTabUrl", "http://start.mysearchdial.com/?f=2&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir="), Replaced,[2304a18d5b2093a39d2884d50400c040]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.tlbrSrchUrl", "http://start.mysearchdial.com/?f=3&...yB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir=&q="), Replaced,[4bdc63cb6f0c70c6e1e470e946be50b0]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.id", "6C626D3B7787E39E"), Replaced,[899e5dd1cdaebe784e771a3f25df0df3]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.instlDay", "16133"), Replaced,[41e6999534472115b51000592fd547b9]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.vrsn", "1.8.29.0"), Replaced,[f1366cc2275443f308bd2e2bf70df20e]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.vrsni", "1.8.29.0"), Replaced,[8c9bd559dc9fb68001c4a3b658ac946c]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.08:26:56"), Replaced,[b47366c8e794e5519e27c0990ef6fc04]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"), Replaced,[929537f70378ab8b24a1194013f19c64]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.prdct", "mysearchdial"), Replaced,[93941f0f6c0f5adcd4f178e1fd07b14f]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.aflt", "irmsd0202ch"), Replaced,[d0570e20631840f6f2d389d0c73d768a]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.smplGrp", "none"), Replaced,[29fed95538430a2cffc6a3b6798b6799]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.tlbrId", "base"), Replaced,[c3642fff8eed9c9a6461421726de14ec]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.instlRef", "0901-a"), Replaced,[5ccb19153249a98daf1620392cd827d9]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.dfltLng", ""), Replaced,[1611dc521665072ff5d00b4e9b69ad53]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"), Replaced,[f037d45a097241f5a124b1a8937139c7]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.excTlbr", false), Replaced,[39ee41ed4f2c1224695c26334bb941bf]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.hmpg", true), Replaced,[82a530fe5229bf7704c173e62ed6a55b]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.cr", "2125331065"), Replaced,[e5428da1e596122490358dcc56aedf21]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuyC0CyCtByC0DtA0ByByBzzyB0EtAzy0EtN0D0Tzu0SyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytDtCtG1TtN1L1G1B1V1N2Y1L1Qzu2StBtA0Czy0CzytCtCtGtByCyDtAtG0BzztCyDtG0AyD0ByEtGyBtCtDtC0CzztDyCtAzz0DtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByDyCyByByC0B0DtGzy0CyCyCtGzztC0AzytGtCtC0B0DtGtByB0CtDyD0ByCyE0E0AtD0A2Q"), Replaced,[f6313af4e59601350eb7095049bb24dc]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.AL", 2), Replaced,[0c1b54da35463cfa844148117e86c23e]
Physical Sectors: 0
(No malicious items detected)
(end)
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17041 BrowserJavaVersion: 10.55.2
Run by lion at 22:34:31 on 2014-04-24
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8142.5495 [GMT 8:00]
.
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
E:\Program Files\Sandboxie\SbieSvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
E:\Program Files\Avast!\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\sysWow64\CtHdaSvc.exe
C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler.exe
E:\Program Files\Scarlet.Crush Productions\ScpService.exe
E:\Program Files (x86)\Garena Plus\ggdllhost.exe
C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler64.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
E:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
E:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
E:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
E:\Program Files\Eraser\Eraser.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
E:\Program Files\Steam\Steam.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
E:\Program Files\Origin\Origin.exe
E:\Program Files\Supercopier\supercopier.exe
C:\Users\lion\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Users\lion\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
E:\Program Files\Sandboxie\SbieCtrl.exe
C:\Windows\system32\RunDll32.exe
E:\Program Files\Creative\Sound Blaster Z-Series\Sound Blaster Z-Series Control Panel\SBZ.exe
E:\Program Files\Avast!\AvastUI.exe
C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
E:\Program Files (x86)\ROCCAT\Kova[+] Mouse\Kova[+]Monitor.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
E:\Program Files (x86)\MSI\Live Update 5\LU5.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://g.live.com/1rewlive4startup/home
uWindow Title = Internet Explorer, enhanced for Bing and MSN
mStart Page = hxxp://www.google.com
mWinlogon: Userinit = userinit.exe,
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\Avast!\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [Steam] "E:\Program Files\Steam\Steam.exe" -silent
uRun: [EADM] "E:\Program Files\Origin\Origin.exe" -AutoStart
uRun: [ultracopier] "E:\Program Files\Supercopier\supercopier.exe"
uRun: [SansaDispatch] C:\Users\lion\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
uRun: [Spotify Web Helper] "C:\Users\lion\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
uRun: [SandboxieControl] "E:\Program Files\Sandboxie\SbieCtrl.exe"
uRun: [GarenaPlus] "E:\Program Files (x86)\Garena Plus\GarenaMessenger.exe" -autolaunch
mRun: [UpdReg] C:\Windows\UpdReg.EXE
mRun: [Sound Blaster Z-Series Control Panel] "E:\Program Files\Creative\Sound Blaster Z-Series\Sound Blaster Z-Series Control Panel\SBZ.exe" /r
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AvastUI.exe] "E:\Program Files\Avast!\AvastUI.exe" /nogui
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
mRun: [ControlCenterCount] C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [RoccatKova+] "E:\Program Files (x86)\ROCCAT\Kova[+] Mouse\Kova[+]Monitor.EXE"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [LiveUpdate 5] E:\Program Files (x86)\MSI\Live Update 5\BootStartLiveupdate.exe /reminder
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\lion\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MONITO~1.LNK - C:\Windows\System32\RunDll32.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{5E0F1CAA-A50E-4DED-A675-0F17C72E3824} : DHCPNameServer = 192.168.1.254
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mStart Page = hxxp://www.google.com
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\Avast!\aswWebRepIE64.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-Run: [Nvtmru] "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
x64-Run: [ShadowPlay] C:\Windows\System32\rundll32.exe C:\Windows\System32\nvspcap64.dll,ShadowPlayOnSystemStart
x64-Run: [NvBackend] "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
x64-Run: [Eraser] "E:\PROGRA~1\Eraser\Eraser.exe" --atRestart
x64-Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
x64-Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - <orphaned>
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL -
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\lion\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll
FF - plugin: E:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll
FF - plugin: E:\Program Files\VideoLAN\VLC\npvlc.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2013-8-7 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2013-8-7 208416]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-8-7 1039096]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswsp.sys [2013-8-7 423240]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2013-8-12 45856]
R2 aswHwid;avast! HardwareID;C:\Windows\System32\drivers\aswHwid.sys [2014-4-19 29208]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-8-7 79184]
R2 avast! Antivirus;avast! Antivirus;E:\Program Files\Avast!\AvastSvc.exe [2014-4-19 50344]
R2 CtHdaSvc;Sound Blaster Audio Service;C:\Windows\SysWOW64\CtHdaSvc.exe [2013-7-3 112640]
R2 Ds3Service;SCP DS3 Service;E:\Program Files\Scarlet.Crush Productions\ScpService.exe [2014-4-9 381952]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-8-7 169432]
R2 MBAMScheduler;MBAMScheduler;E:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-4-24 1809720]
R2 MBAMService;MBAMService;E:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-4-24 857912]
R2 MSI_SuperCharger;MSI_SuperCharger;C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [2013-12-15 161776]
R2 NvNetworkService;NVIDIA Network Service;C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2013-12-3 1615192]
R2 NvStreamSvc;NVIDIA Streamer Service;C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-12-1 20541216]
R2 PassThru Service;Internet Pass-Through Service;C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-7 167424]
R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-9-16 3273088]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-3-11 411936]
R3 cthda;Sound Blaster Audio Driver;C:\Windows\System32\drivers\cthda.sys [2013-7-3 1060632]
R3 cthdb;Sound Blaster Audio Controller Driver;C:\Windows\System32\drivers\cthdb.sys [2013-7-3 34072]
R3 ISCT;Intel(R) Smart Connect Technology Device Driver;C:\Windows\System32\drivers\ISCTD64.sys [2013-1-19 46568]
R3 KovaPlusFltr;ROCCAT Kova[+] Mouse;C:\Windows\System32\drivers\KovaPlusFltr.sys [2010-1-25 15104]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2014-4-24 25816]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\MBAMSwissArmy.sys [2014-4-24 119512]
R3 MBAMWebAccessControl;MBAMWebAccessControl;C:\Windows\System32\drivers\mwac.sys [2014-4-24 63192]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3;C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [2013-12-15 13368]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4;E:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [2014-2-23 14136]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\Windows\System32\drivers\nvvad64v.sys [2014-4-8 40392]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2013-8-7 849992]
R3 SbieDrv;SbieDrv;E:\Program Files\Sandboxie\SbieDrv.sys [2014-1-18 202600]
R3 ScpVBus;Scp Virtual Bus Driver;C:\Windows\System32\drivers\ScpVBus.sys [2014-4-9 39168]
S2 aswStm;aswStm;C:\Windows\System32\drivers\aswstm.sys [2013-12-22 85328]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 SetupARService;SetupARService;C:\Program Files (x86)\Realtek\Audio\SetupAfterRebootService.exe [2013-11-5 24576]
S2 SkypeUpdate;Skype Updater;E:\Program Files (x86)\Skype\Updater\Updater.exe [2013-9-5 171680]
S2 vToolbarUpdater15.4.0;vToolbarUpdater15.4.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe --> C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [?]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2013-8-7 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2013-8-7 79360]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2011-4-12 71168]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2014-2-3 57840]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2013-2-5 1512448]
S3 HTCAND64;HTC Device Driver;C:\Windows\System32\drivers\ANDROIDUSB.sys [2009-11-2 33736]
S3 htcnprot;HTC NDIS Protocol Driver;C:\Windows\System32\drivers\htcnprot.sys [2012-12-7 36928]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-4-22 111616]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;C:\Windows\System32\drivers\MijXfilt.sys [2013-9-11 121416]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\System32\GameMon.des -service --> C:\Windows\System32\GameMon.des -service [?]
S3 NTIOLib_MSISMB_CC;NTIOLib_MSISMB_CC;C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [2013-12-15 13368]
S3 pwdrvio;pwdrvio;C:\Windows\System32\pwdrvio.sys [2013-8-7 19152]
S3 pwdspio;pwdspio;C:\Windows\System32\pwdspio.sys [2013-8-7 12504]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-8-7 1255736]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464]
.
=============== File Associations ===============
.
FileExt: .js: JSFile=C:\Windows\System32\Notepad.exe %1 [default=Edit - 'Open' doesn't exist]
.
=============== Created Last 30 ================
.
2014-04-24 14:18:05 119512 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-04-24 14:17:59 88280 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-04-24 14:17:59 63192 ----a-w- C:\Windows\System32\drivers\mwac.sys
2014-04-24 14:17:59 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-04-24 14:17:59 -------- d-----w- C:\ProgramData\Malwarebytes
2014-04-24 12:48:18 -------- d-----w- C:\Windows\SysWow64\AILogix
2014-04-24 12:48:18 -------- d-----w- C:\Program Files (x86)\R-CDN
2014-04-23 12:48:28 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-04-23 00:15:55 10651704 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7D617B24-5638-496A-8FC7-A9BD1E770962}\mpengine.dll
2014-04-22 14:28:59 8011776 ----a-w- C:\Program Files\Internet Explorer\F12Resources.dll
2014-04-19 14:53:38 -------- d-----w- C:\Users\lion\AppData\Roaming\RotMG.Production
2014-04-19 05:17:03 29208 ----a-w- C:\Windows\System32\drivers\aswHwid.sys
2014-04-19 05:17:00 43152 ----a-w- C:\Windows\avastSS.scr
2014-04-13 08:11:29 -------- d-----w- C:\Users\lion\AppData\Local\Darksiders2
2014-04-12 12:41:15 -------- d-----w- C:\Users\lion\AppData\Roaming\Hothead Games
2014-04-09 14:31:28 1721576 ----a-w- C:\Windows\System32\WdfCoInstaller01009.dll
2014-04-09 14:26:05 -------- d-----w- C:\Program Files\Microsoft Xbox 360 Accessories
2014-04-09 12:12:59 39168 ----a-w- C:\Windows\System32\drivers\ScpVBus.sys
2014-04-09 02:02:38 362496 ----a-w- C:\Windows\System32\wow64win.dll
2014-04-09 02:02:38 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2014-04-09 02:02:38 243712 ----a-w- C:\Windows\System32\wow64.dll
2014-04-09 02:02:38 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2014-04-09 02:02:38 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2014-04-09 02:02:38 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2014-04-09 02:02:37 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2014-04-09 02:02:37 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2014-04-09 02:02:37 2048 ----a-w- C:\Windows\SysWow64\user.exe
2014-04-09 01:40:27 27584 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2014-04-09 01:40:27 274880 ----a-w- C:\Windows\System32\drivers\msiscsi.sys
2014-04-09 01:40:27 2048 ----a-w- C:\Windows\SysWow64\iologmsg.dll
2014-04-09 01:40:27 2048 ----a-w- C:\Windows\System32\iologmsg.dll
2014-04-09 01:40:27 190912 ----a-w- C:\Windows\System32\drivers\storport.sys
2014-04-09 00:24:56 1684928 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2014-04-08 13:24:27 40392 ----a-w- C:\Windows\System32\drivers\nvvad64v.sys
2014-04-08 13:24:27 33568 ----a-w- C:\Windows\SysWow64\nvaudcap32v.dll
2014-04-06 06:35:33 5221784 ----a-w- C:\Windows\SysWow64\GameMon.des
2014-04-06 06:35:19 -------- d-----w- C:\Program Files\Common Files\INCA Shared
2014-03-30 09:52:24 -------- d-----w- C:\Users\lion\AppData\Roaming\LolClient
2014-03-29 11:02:32 -------- d-----w- C:\Users\lion\AppData\Local\Garena
2014-03-29 11:02:28 -------- d-----w- C:\GarenaDownload
2014-03-29 10:58:46 -------- d-----w- C:\Users\lion\AppData\Roaming\Garena
2014-03-29 10:58:46 -------- d-----w- C:\ProgramData\Garena
2014-03-29 10:58:42 -------- d-----w- C:\Users\lion\AppData\Roaming\xim
2014-03-29 10:54:36 534016 ----a-w- C:\Windows\System32\SafeIPs64.dll
2014-03-29 10:54:33 373760 ----a-w- C:\Windows\SysWow64\SafeIPs.dll
2014-03-28 07:15:44 -------- d-----w- C:\Users\lion\AppData\Roaming\Windows Live Writer
2014-03-28 07:15:44 -------- d-----w- C:\Users\lion\AppData\Local\Windows Live Writer
.
==================== Find3M ====================
.
2014-04-19 05:17:01 93568 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2014-04-19 05:17:01 85328 ----a-w- C:\Windows\System32\drivers\aswstm.sys
2014-04-19 05:17:01 79184 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2014-04-19 05:17:01 65776 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2014-04-19 05:17:01 208416 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2014-04-19 05:17:01 1039096 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2014-04-13 00:01:27 70832 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-13 00:01:27 692400 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-04-02 13:27:17 1081112 ----a-w- C:\Windows\SysWow64\nvspcap.dll
2014-04-02 13:27:05 1225920 ----a-w- C:\Windows\System32\nvspcap64.dll
2014-03-31 01:35:08 270496 ------w- C:\Windows\System32\MpSigStub.exe
2014-03-21 19:43:50 37320 ----a-w- C:\Windows\System32\nvaudcap64v.dll
2014-03-06 09:32:16 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-03-06 09:31:33 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-03-06 08:59:04 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-03-06 08:57:34 548352 ----a-w- C:\Windows\System32\vbscript.dll
2014-03-06 08:57:20 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-03-06 08:32:07 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-03-06 08:29:40 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-03-06 08:29:14 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-03-06 08:28:15 752640 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-03-06 08:15:54 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-03-06 08:11:41 5784064 ----a-w- C:\Windows\System32\jscript9.dll
2014-03-06 08:02:34 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-03-06 08:02:33 455168 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-03-06 08:01:01 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-03-06 07:56:43 38400 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-03-06 07:46:36 4254720 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-03-06 07:38:13 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-03-06 07:36:40 592896 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-03-06 07:13:43 32256 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-03-06 07:11:15 2043904 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-03-06 06:40:39 1967104 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-03-06 06:22:40 2260480 ----a-w- C:\Windows\System32\wininet.dll
2014-03-06 05:41:49 1789440 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-03-04 13:06:00 6714312 ----a-w- C:\Windows\System32\nvcpl.dll
2014-03-04 13:06:00 3497816 ----a-w- C:\Windows\System32\nvsvc64.dll
2014-03-04 13:05:58 922968 ----a-w- C:\Windows\System32\nvvsvc.exe
2014-03-04 13:05:58 64968 ----a-w- C:\Windows\System32\nvshext.dll
2014-03-04 13:05:57 386336 ----a-w- C:\Windows\System32\nvmctray.dll
2014-03-04 13:05:53 3649185 ----a-w- C:\Windows\System32\nvcoproc.bin
2014-03-04 11:32:59 599840 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2014-03-04 09:17:05 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2014-02-08 18:34:51 1885472 ----a-w- C:\Windows\System32\nvdispco6433489.dll
2014-02-08 18:34:51 1515296 ----a-w- C:\Windows\System32\nvdispgenco6433489.dll
2014-02-07 01:23:30 3156480 ----a-w- C:\Windows\System32\win32k.sys
2014-02-04 02:32:22 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2014-02-04 02:32:12 624128 ----a-w- C:\Windows\System32\qedit.dll
2014-02-04 02:04:22 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2014-02-04 02:04:11 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2014-01-29 02:32:18 484864 ----a-w- C:\Windows\System32\wer.dll
2014-01-29 02:06:47 381440 ----a-w- C:\Windows\SysWow64\wer.dll
2014-01-28 02:32:46 228864 ----a-w- C:\Windows\System32\wwansvc.dll
.
============= FINISH: 22:34:44.22 ===============
MBAM Log :
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 4/24/2014
Scan Time: 10:29:58 PM
Logfile:
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.04.24.07
Rootkit Database: v2014.03.27.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: lion
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 271855
Time Elapsed: 8 min, 19 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 1
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://start.mysearchdial.com/?f=1&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir=, Good: (http://www.google.com), Bad: (http://start.mysearchdial.com/?f=1&...),Replaced,[0b1ca589e398221438c0cd602bd957a9]
Folders: 0
(No malicious items detected)
Files: 65
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\searchplugins\Mysearchdial.xml, Quarantined, [71b62806afcc95a108e11c5c50b28b75],
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "homepage": "http://start.mysearchdial.com/?f=1&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir=",), Replaced,[8d9aa18d25562412acb5e9712dd7fe02]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "startup_urls": [ "http://start.mysearchdial.com/?f=1&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir=" ],), Replaced,[28ffda54d7a4102600933822907416ea]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.AL", 2), Replaced,[2dfab47a106b9b9be6de87d2cf3553ad]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.aflt", "irmsd0202ch"), Replaced,[35f248e6d9a2cf67566e9dbc758f738d]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"), Replaced,[47e05bd33843b08614b08ecb0bf949b7]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuyC0CyCtByC0DtA0ByByBzzyB0EtAzy0EtN0D0Tzu0SyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytDtCtG1TtN1L1G1B1V1N2Y1L1Qzu2StBtA0Czy0CzytCtCtGtByCyDtAtG0BzztCyDtG0AyD0ByEtGyBtCtDtC0CzztDyCtAzz0DtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByDyCyByByC0B0DtGzy0CyCyCtGzztC0AzytGtCtC0B0DtGtByB0CtDyD0ByCyE0E0AtD0A2Q"), Replaced,[14138aa4cdae90a6269ed089a064e11f]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.cntry", "SG"), Replaced,[2ff86cc2a0dbe6509c28a3b6e12351af]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.cr", "2125331065"), Replaced,[c562af7f88f3e5517351c99011f335cb]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.dfltLng", ""), Replaced,[f532e64893e8211502c260f906fe22de]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.dfltSrch", true), Replaced,[eb3c9c925823ca6c299b4a0f0301f808]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.dnsErr", true), Replaced,[e542ab83780340f6f7cdf564679de020]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,1828564131,3396905322,2787570089,1850357963,3855095921,1516386922,3836221436,2015489896,270173904,3729539987,424611005,965674394,609003582,2041931190,3874294282,2774755777,931959409,398575749,3999997753,1104451911,1233863968,4280856088,1554076246,1949401179,1770772786,3253391265,3778438159,1649478750,2848156272,2476712966,3103989719,475488147,1715867073,3594694113,3774606882,4036647035,1593922001,4110151693,2941033654,3206511613"), Replaced,[87a081ad6219bf773d87b0a935cfbf41]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.excTlbr", false), Replaced,[9493fa34e09bb97d05bf104959abf40c]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.hdrMd5", "3D0D29CD53FA3539C57751280CCE503D"), Replaced,[f0370d218bf0e94d16ae68f1a262738d]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.hmpg", true), Replaced,[69bee34b7cff48eeaf15d7821be99769]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.hmpgUrl", "http://start.mysearchdial.com/?f=1&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir="), Replaced,[db4c062880fb072fa71d70e93aca7987]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.id", "6C626D3B7787E39E"), Replaced,[49de8aa4e19a320492321c3dff05c43c]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.instlDay", "16133"), Replaced,[d651f03e97e47bbbcff5e772c73d07f9]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.instlRef", "0901-a"), Replaced,[1b0ce5497a010b2ba4201247966e847c]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.lastB", "http://start.mysearchdial.com/?f=1&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir="), Replaced,[c364d9557ffcaf873b89bf9a709430d0]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.29.08:26:56"), Replaced,[56d11a143a4181b5269e273272922bd5]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.newTabUrl", "http://start.mysearchdial.com/?f=2&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir="), Replaced,[21064de1a6d5ef47a81c461313f1ac54]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.prdct", "mysearchdial"), Replaced,[ca5de846a3d820165e66104916eebf41]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"), Replaced,[48dfb17d116a0036cbf983d664a007f9]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.sg", "none"), Replaced,[56d128066615c571bf0523366c986a96]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"), Replaced,[84a3d45a116a0f27ae161049a06460a0]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.tlbrId", "base"), Replaced,[df4888a6403b74c27c485efbf014aa56]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.tlbrSrchUrl", "http://start.mysearchdial.com/?f=3&...yB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir=&q="), Replaced,[58cf101e1665d1654480c891798be31d]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.vrsn", "1.8.29.0"), Replaced,[9f8882ac03780c2a04c07bdefe06857b]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial.vrsni", "1.8.29.0"), Replaced,[44e3032bcfacf24407bd1148ec180af6]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.hmpg", true), Replaced,[e542d05e7ffceb4b6d5773e67b89659b]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.newTab", false), Replaced,[47e0fb33611aab8b457ff36611f3f010]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.smplGrp", "none"), Replaced,[a681bf6fdaa178be1fa565f48d777f81]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\prefs.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.08:26:56"), Replaced,[87a084aad4a791a53f857adf1aeab54b]
PUP.Optional.MySearch.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.irmysearch.aflt", "irmsd0202ch"), Replaced,[3bec9a940675fd393389bd9c52b25fa1]
PUP.Optional.MySearch.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.irmysearch.instlRef", "0901-a"), Replaced,[ce5938f6bcbff541516bdc7d32d23bc5]
PUP.Optional.MySearch.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.irmysearch.cr", "2125331065"), Replaced,[4bdc1d119cdfa78f16a60257768eb050]
PUP.Optional.MySearch.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzuyC0CyCtByC0DtA0ByByBzzyB0EtAzy0EtN0D0Tzu0SyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytDtCtG1TtN1L1G1B1V1N2Y1L1Qzu2StBtA0Czy0CzytCtCtGtByCyDtAtG0BzztCyDtG0AyD0ByEtGyBtCtDtC0CzztDyCtAzz0DtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByDyCyByByC0B0DtGzy0CyCyCtGzztC0AzytGtCtC0B0DtGtByB0CtDyD0ByCyE0E0AtD0A2Q"), Replaced,[13147bb3dd9ea88e407cadac8d771fe1]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.hmpg", true), Replaced,[c95eec420774ff37daebb1a825df0bf5]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.hmpgUrl", "http://start.mysearchdial.com/?f=1&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir="), Replaced,[52d584aa364590a601c4b0a96c98fe02]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.dfltSrch", true), Replaced,[40e7ab83651692a4616406530ef6936d]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"), Replaced,[1d0ac26c146739fdebdae970d3317a86]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.dnsErr", true), Replaced,[9097ba74bfbcd56171543821857fa858]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.newTab", false), Replaced,[21060a2482f958de1ea73e1b986cde22]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.newTabUrl", "http://start.mysearchdial.com/?f=2&...GtByB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir="), Replaced,[2304a18d5b2093a39d2884d50400c040]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.tlbrSrchUrl", "http://start.mysearchdial.com/?f=3&...yB0CtDyD0ByCyE0E0AtD0A2Q&cr=2125331065&ir=&q="), Replaced,[4bdc63cb6f0c70c6e1e470e946be50b0]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.id", "6C626D3B7787E39E"), Replaced,[899e5dd1cdaebe784e771a3f25df0df3]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.instlDay", "16133"), Replaced,[41e6999534472115b51000592fd547b9]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.vrsn", "1.8.29.0"), Replaced,[f1366cc2275443f308bd2e2bf70df20e]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.vrsni", "1.8.29.0"), Replaced,[8c9bd559dc9fb68001c4a3b658ac946c]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.08:26:56"), Replaced,[b47366c8e794e5519e27c0990ef6fc04]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"), Replaced,[929537f70378ab8b24a1194013f19c64]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.prdct", "mysearchdial"), Replaced,[93941f0f6c0f5adcd4f178e1fd07b14f]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.aflt", "irmsd0202ch"), Replaced,[d0570e20631840f6f2d389d0c73d768a]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.smplGrp", "none"), Replaced,[29fed95538430a2cffc6a3b6798b6799]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.tlbrId", "base"), Replaced,[c3642fff8eed9c9a6461421726de14ec]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.instlRef", "0901-a"), Replaced,[5ccb19153249a98daf1620392cd827d9]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.dfltLng", ""), Replaced,[1611dc521665072ff5d00b4e9b69ad53]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"), Replaced,[f037d45a097241f5a124b1a8937139c7]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.excTlbr", false), Replaced,[39ee41ed4f2c1224695c26334bb941bf]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial_i.hmpg", true), Replaced,[82a530fe5229bf7704c173e62ed6a55b]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.cr", "2125331065"), Replaced,[e5428da1e596122490358dcc56aedf21]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuyC0CyCtByC0DtA0ByByBzzyB0EtAzy0EtN0D0Tzu0SyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytDtCtG1TtN1L1G1B1V1N2Y1L1Qzu2StBtA0Czy0CzytCtCtGtByCyDtAtG0BzztCyDtG0AyD0ByEtGyBtCtDtC0CzztDyCtAzz0DtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByDyCyByByC0B0DtGzy0CyCyCtGzztC0AzytGtCtC0B0DtGtByB0CtDyD0ByCyE0E0AtD0A2Q"), Replaced,[f6313af4e59601350eb7095049bb24dc]
PUP.Optional.MySearchDial.A, C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\user.js, Good: (), Bad: (user_pref("extensions.mysearchdial.AL", 2), Replaced,[0c1b54da35463cfa844148117e86c23e]
Physical Sectors: 0
(No malicious items detected)
(end)
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17041 BrowserJavaVersion: 10.55.2
Run by lion at 22:34:31 on 2014-04-24
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8142.5495 [GMT 8:00]
.
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
E:\Program Files\Sandboxie\SbieSvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
E:\Program Files\Avast!\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\sysWow64\CtHdaSvc.exe
C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler.exe
E:\Program Files\Scarlet.Crush Productions\ScpService.exe
E:\Program Files (x86)\Garena Plus\ggdllhost.exe
C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler64.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
E:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
E:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
E:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
E:\Program Files\Eraser\Eraser.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
E:\Program Files\Steam\Steam.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
E:\Program Files\Origin\Origin.exe
E:\Program Files\Supercopier\supercopier.exe
C:\Users\lion\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Users\lion\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
E:\Program Files\Sandboxie\SbieCtrl.exe
C:\Windows\system32\RunDll32.exe
E:\Program Files\Creative\Sound Blaster Z-Series\Sound Blaster Z-Series Control Panel\SBZ.exe
E:\Program Files\Avast!\AvastUI.exe
C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
E:\Program Files (x86)\ROCCAT\Kova[+] Mouse\Kova[+]Monitor.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
E:\Program Files (x86)\MSI\Live Update 5\LU5.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://g.live.com/1rewlive4startup/home
uWindow Title = Internet Explorer, enhanced for Bing and MSN
mStart Page = hxxp://www.google.com
mWinlogon: Userinit = userinit.exe,
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\Avast!\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [Steam] "E:\Program Files\Steam\Steam.exe" -silent
uRun: [EADM] "E:\Program Files\Origin\Origin.exe" -AutoStart
uRun: [ultracopier] "E:\Program Files\Supercopier\supercopier.exe"
uRun: [SansaDispatch] C:\Users\lion\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
uRun: [Spotify Web Helper] "C:\Users\lion\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
uRun: [SandboxieControl] "E:\Program Files\Sandboxie\SbieCtrl.exe"
uRun: [GarenaPlus] "E:\Program Files (x86)\Garena Plus\GarenaMessenger.exe" -autolaunch
mRun: [UpdReg] C:\Windows\UpdReg.EXE
mRun: [Sound Blaster Z-Series Control Panel] "E:\Program Files\Creative\Sound Blaster Z-Series\Sound Blaster Z-Series Control Panel\SBZ.exe" /r
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AvastUI.exe] "E:\Program Files\Avast!\AvastUI.exe" /nogui
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
mRun: [ControlCenterCount] C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [RoccatKova+] "E:\Program Files (x86)\ROCCAT\Kova[+] Mouse\Kova[+]Monitor.EXE"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [LiveUpdate 5] E:\Program Files (x86)\MSI\Live Update 5\BootStartLiveupdate.exe /reminder
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\lion\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MONITO~1.LNK - C:\Windows\System32\RunDll32.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{5E0F1CAA-A50E-4DED-A675-0F17C72E3824} : DHCPNameServer = 192.168.1.254
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mStart Page = hxxp://www.google.com
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\Avast!\aswWebRepIE64.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-Run: [Nvtmru] "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
x64-Run: [ShadowPlay] C:\Windows\System32\rundll32.exe C:\Windows\System32\nvspcap64.dll,ShadowPlayOnSystemStart
x64-Run: [NvBackend] "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
x64-Run: [Eraser] "E:\PROGRA~1\Eraser\Eraser.exe" --atRestart
x64-Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
x64-Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - <orphaned>
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\lion\AppData\Roaming\Mozilla\Firefox\Profiles\exoi61ul.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL -
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\lion\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll
FF - plugin: E:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll
FF - plugin: E:\Program Files\VideoLAN\VLC\npvlc.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2013-8-7 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2013-8-7 208416]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-8-7 1039096]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswsp.sys [2013-8-7 423240]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2013-8-12 45856]
R2 aswHwid;avast! HardwareID;C:\Windows\System32\drivers\aswHwid.sys [2014-4-19 29208]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-8-7 79184]
R2 avast! Antivirus;avast! Antivirus;E:\Program Files\Avast!\AvastSvc.exe [2014-4-19 50344]
R2 CtHdaSvc;Sound Blaster Audio Service;C:\Windows\SysWOW64\CtHdaSvc.exe [2013-7-3 112640]
R2 Ds3Service;SCP DS3 Service;E:\Program Files\Scarlet.Crush Productions\ScpService.exe [2014-4-9 381952]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-8-7 169432]
R2 MBAMScheduler;MBAMScheduler;E:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-4-24 1809720]
R2 MBAMService;MBAMService;E:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-4-24 857912]
R2 MSI_SuperCharger;MSI_SuperCharger;C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [2013-12-15 161776]
R2 NvNetworkService;NVIDIA Network Service;C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2013-12-3 1615192]
R2 NvStreamSvc;NVIDIA Streamer Service;C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-12-1 20541216]
R2 PassThru Service;Internet Pass-Through Service;C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-7 167424]
R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-9-16 3273088]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-3-11 411936]
R3 cthda;Sound Blaster Audio Driver;C:\Windows\System32\drivers\cthda.sys [2013-7-3 1060632]
R3 cthdb;Sound Blaster Audio Controller Driver;C:\Windows\System32\drivers\cthdb.sys [2013-7-3 34072]
R3 ISCT;Intel(R) Smart Connect Technology Device Driver;C:\Windows\System32\drivers\ISCTD64.sys [2013-1-19 46568]
R3 KovaPlusFltr;ROCCAT Kova[+] Mouse;C:\Windows\System32\drivers\KovaPlusFltr.sys [2010-1-25 15104]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2014-4-24 25816]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\MBAMSwissArmy.sys [2014-4-24 119512]
R3 MBAMWebAccessControl;MBAMWebAccessControl;C:\Windows\System32\drivers\mwac.sys [2014-4-24 63192]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3;C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [2013-12-15 13368]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4;E:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [2014-2-23 14136]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\Windows\System32\drivers\nvvad64v.sys [2014-4-8 40392]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2013-8-7 849992]
R3 SbieDrv;SbieDrv;E:\Program Files\Sandboxie\SbieDrv.sys [2014-1-18 202600]
R3 ScpVBus;Scp Virtual Bus Driver;C:\Windows\System32\drivers\ScpVBus.sys [2014-4-9 39168]
S2 aswStm;aswStm;C:\Windows\System32\drivers\aswstm.sys [2013-12-22 85328]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 SetupARService;SetupARService;C:\Program Files (x86)\Realtek\Audio\SetupAfterRebootService.exe [2013-11-5 24576]
S2 SkypeUpdate;Skype Updater;E:\Program Files (x86)\Skype\Updater\Updater.exe [2013-9-5 171680]
S2 vToolbarUpdater15.4.0;vToolbarUpdater15.4.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe --> C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [?]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2013-8-7 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2013-8-7 79360]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2011-4-12 71168]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2014-2-3 57840]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2013-2-5 1512448]
S3 HTCAND64;HTC Device Driver;C:\Windows\System32\drivers\ANDROIDUSB.sys [2009-11-2 33736]
S3 htcnprot;HTC NDIS Protocol Driver;C:\Windows\System32\drivers\htcnprot.sys [2012-12-7 36928]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-4-22 111616]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;C:\Windows\System32\drivers\MijXfilt.sys [2013-9-11 121416]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\System32\GameMon.des -service --> C:\Windows\System32\GameMon.des -service [?]
S3 NTIOLib_MSISMB_CC;NTIOLib_MSISMB_CC;C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [2013-12-15 13368]
S3 pwdrvio;pwdrvio;C:\Windows\System32\pwdrvio.sys [2013-8-7 19152]
S3 pwdspio;pwdspio;C:\Windows\System32\pwdspio.sys [2013-8-7 12504]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-8-7 1255736]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464]
.
=============== File Associations ===============
.
FileExt: .js: JSFile=C:\Windows\System32\Notepad.exe %1 [default=Edit - 'Open' doesn't exist]
.
=============== Created Last 30 ================
.
2014-04-24 14:18:05 119512 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-04-24 14:17:59 88280 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-04-24 14:17:59 63192 ----a-w- C:\Windows\System32\drivers\mwac.sys
2014-04-24 14:17:59 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-04-24 14:17:59 -------- d-----w- C:\ProgramData\Malwarebytes
2014-04-24 12:48:18 -------- d-----w- C:\Windows\SysWow64\AILogix
2014-04-24 12:48:18 -------- d-----w- C:\Program Files (x86)\R-CDN
2014-04-23 12:48:28 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-04-23 00:15:55 10651704 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7D617B24-5638-496A-8FC7-A9BD1E770962}\mpengine.dll
2014-04-22 14:28:59 8011776 ----a-w- C:\Program Files\Internet Explorer\F12Resources.dll
2014-04-19 14:53:38 -------- d-----w- C:\Users\lion\AppData\Roaming\RotMG.Production
2014-04-19 05:17:03 29208 ----a-w- C:\Windows\System32\drivers\aswHwid.sys
2014-04-19 05:17:00 43152 ----a-w- C:\Windows\avastSS.scr
2014-04-13 08:11:29 -------- d-----w- C:\Users\lion\AppData\Local\Darksiders2
2014-04-12 12:41:15 -------- d-----w- C:\Users\lion\AppData\Roaming\Hothead Games
2014-04-09 14:31:28 1721576 ----a-w- C:\Windows\System32\WdfCoInstaller01009.dll
2014-04-09 14:26:05 -------- d-----w- C:\Program Files\Microsoft Xbox 360 Accessories
2014-04-09 12:12:59 39168 ----a-w- C:\Windows\System32\drivers\ScpVBus.sys
2014-04-09 02:02:38 362496 ----a-w- C:\Windows\System32\wow64win.dll
2014-04-09 02:02:38 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2014-04-09 02:02:38 243712 ----a-w- C:\Windows\System32\wow64.dll
2014-04-09 02:02:38 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2014-04-09 02:02:38 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2014-04-09 02:02:38 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2014-04-09 02:02:37 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2014-04-09 02:02:37 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2014-04-09 02:02:37 2048 ----a-w- C:\Windows\SysWow64\user.exe
2014-04-09 01:40:27 27584 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2014-04-09 01:40:27 274880 ----a-w- C:\Windows\System32\drivers\msiscsi.sys
2014-04-09 01:40:27 2048 ----a-w- C:\Windows\SysWow64\iologmsg.dll
2014-04-09 01:40:27 2048 ----a-w- C:\Windows\System32\iologmsg.dll
2014-04-09 01:40:27 190912 ----a-w- C:\Windows\System32\drivers\storport.sys
2014-04-09 00:24:56 1684928 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2014-04-08 13:24:27 40392 ----a-w- C:\Windows\System32\drivers\nvvad64v.sys
2014-04-08 13:24:27 33568 ----a-w- C:\Windows\SysWow64\nvaudcap32v.dll
2014-04-06 06:35:33 5221784 ----a-w- C:\Windows\SysWow64\GameMon.des
2014-04-06 06:35:19 -------- d-----w- C:\Program Files\Common Files\INCA Shared
2014-03-30 09:52:24 -------- d-----w- C:\Users\lion\AppData\Roaming\LolClient
2014-03-29 11:02:32 -------- d-----w- C:\Users\lion\AppData\Local\Garena
2014-03-29 11:02:28 -------- d-----w- C:\GarenaDownload
2014-03-29 10:58:46 -------- d-----w- C:\Users\lion\AppData\Roaming\Garena
2014-03-29 10:58:46 -------- d-----w- C:\ProgramData\Garena
2014-03-29 10:58:42 -------- d-----w- C:\Users\lion\AppData\Roaming\xim
2014-03-29 10:54:36 534016 ----a-w- C:\Windows\System32\SafeIPs64.dll
2014-03-29 10:54:33 373760 ----a-w- C:\Windows\SysWow64\SafeIPs.dll
2014-03-28 07:15:44 -------- d-----w- C:\Users\lion\AppData\Roaming\Windows Live Writer
2014-03-28 07:15:44 -------- d-----w- C:\Users\lion\AppData\Local\Windows Live Writer
.
==================== Find3M ====================
.
2014-04-19 05:17:01 93568 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2014-04-19 05:17:01 85328 ----a-w- C:\Windows\System32\drivers\aswstm.sys
2014-04-19 05:17:01 79184 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2014-04-19 05:17:01 65776 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2014-04-19 05:17:01 208416 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2014-04-19 05:17:01 1039096 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2014-04-13 00:01:27 70832 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-13 00:01:27 692400 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-04-02 13:27:17 1081112 ----a-w- C:\Windows\SysWow64\nvspcap.dll
2014-04-02 13:27:05 1225920 ----a-w- C:\Windows\System32\nvspcap64.dll
2014-03-31 01:35:08 270496 ------w- C:\Windows\System32\MpSigStub.exe
2014-03-21 19:43:50 37320 ----a-w- C:\Windows\System32\nvaudcap64v.dll
2014-03-06 09:32:16 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-03-06 09:31:33 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-03-06 08:59:04 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-03-06 08:57:34 548352 ----a-w- C:\Windows\System32\vbscript.dll
2014-03-06 08:57:20 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-03-06 08:32:07 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-03-06 08:29:40 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-03-06 08:29:14 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-03-06 08:28:15 752640 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-03-06 08:15:54 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-03-06 08:11:41 5784064 ----a-w- C:\Windows\System32\jscript9.dll
2014-03-06 08:02:34 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-03-06 08:02:33 455168 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-03-06 08:01:01 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-03-06 07:56:43 38400 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-03-06 07:46:36 4254720 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-03-06 07:38:13 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-03-06 07:36:40 592896 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-03-06 07:13:43 32256 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-03-06 07:11:15 2043904 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-03-06 06:40:39 1967104 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-03-06 06:22:40 2260480 ----a-w- C:\Windows\System32\wininet.dll
2014-03-06 05:41:49 1789440 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-03-04 13:06:00 6714312 ----a-w- C:\Windows\System32\nvcpl.dll
2014-03-04 13:06:00 3497816 ----a-w- C:\Windows\System32\nvsvc64.dll
2014-03-04 13:05:58 922968 ----a-w- C:\Windows\System32\nvvsvc.exe
2014-03-04 13:05:58 64968 ----a-w- C:\Windows\System32\nvshext.dll
2014-03-04 13:05:57 386336 ----a-w- C:\Windows\System32\nvmctray.dll
2014-03-04 13:05:53 3649185 ----a-w- C:\Windows\System32\nvcoproc.bin
2014-03-04 11:32:59 599840 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2014-03-04 09:17:05 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2014-02-08 18:34:51 1885472 ----a-w- C:\Windows\System32\nvdispco6433489.dll
2014-02-08 18:34:51 1515296 ----a-w- C:\Windows\System32\nvdispgenco6433489.dll
2014-02-07 01:23:30 3156480 ----a-w- C:\Windows\System32\win32k.sys
2014-02-04 02:32:22 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2014-02-04 02:32:12 624128 ----a-w- C:\Windows\System32\qedit.dll
2014-02-04 02:04:22 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2014-02-04 02:04:11 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2014-01-29 02:32:18 484864 ----a-w- C:\Windows\System32\wer.dll
2014-01-29 02:06:47 381440 ----a-w- C:\Windows\SysWow64\wer.dll
2014-01-28 02:32:46 228864 ----a-w- C:\Windows\System32\wwansvc.dll
.
============= FINISH: 22:34:44.22 ===============