Greetings! I am having difficulties removing a trojan. After reinstalling my Windows 7, I ran a Malwarebytes scan and detected a Trojan labeled as svchost. Malwarebytes remove does not work. I see other topics about the same trojan, but I have seen warnings against following instructions made for other users. Here are the requested logs:
MBAM log:
Malwarebytes Anti-Malware (Trial) 1.65.1.1000
www.malwarebytes.org
Database version: v2012.11.22.08
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Alex :: ALEX-PC [administrator]
Protection: Enabled
11/22/2012 1:26:56 PM
mbam-log-2012-11-22 (13-26-56).txt
Scan type: Full scan (C:\|E:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 298563
Time elapsed: 4 minute(s), 34 second(s)
Memory Processes Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> 1124 -> Delete on reboot.
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot.
(end)
DDS LOG
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 8.0.7600.16385
Run by Alex at 13:37:09 on 2012-11-22
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.16337.13557 [GMT -5:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\ASGT.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\msiexec.exe
C:\Program Files\NVIDIA Corporation\Display\NvTray.exe
E:\Downloads\LeagueofLegends(1).exe
C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{13DAF992-5B15-4BB3-B20C-3423E1ACBE4B} : DHCPNameServer = 192.168.1.1
SSODL: WebCheck - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xjzmhujg.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll
.
============= SERVICES / DRIVERS ===============
.
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2012-11-22 16152]
R1 ElRawDisk;ElRawDisk;C:\Windows\System32\drivers\ElRawDsk.sys [2012-11-22 30752]
R2 ASGT;ASGT;C:\Windows\SysWOW64\ASGT.exe [2012-1-17 55296]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-2-2 628448]
R2 ioloSystemService;iolo System Service;C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2012-11-22 1028464]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-11-22 162648]
R2 MBAMScheduler;MBAMScheduler;E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-8 399432]
R2 MBAMService;MBAMService;E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-8 676936]
R2 MSI_SuperCharger;MSI_SuperCharger;C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [2012-11-22 138768]
R2 PDFsFilter;PDFsFilter;C:\Windows\System32\drivers\PDFsFilter.sys [2012-11-22 82160]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-11-22 362840]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2012-11-22 356120]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2012-11-22 788760]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-11-22 25928]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3;C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [2012-11-22 14136]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-11-22 676968]
R4 IOMap;IOMap;C:\Windows\System32\drivers\IOMap64.sys [2012-11-22 23680]
.
=============== Created Last 30 ================
.
2012-11-22 20:49:58 -------- d-----w- C:\Windows\Panther
2012-11-22 18:35:07 -------- d-----w- C:\Users\Alex\AppData\Local\Macromedia
2012-11-22 18:34:38 -------- d-----w- C:\Users\Alex\AppData\Local\PMB Files
2012-11-22 18:34:38 -------- d-----w- C:\ProgramData\PMB Files
2012-11-22 18:34:32 -------- d-----w- C:\Program Files (x86)\Pando Networks
2012-11-22 18:34:27 -------- d-----w- C:\Users\Alex\.swt
2012-11-22 18:33:47 73656 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-11-22 18:33:47 697272 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-11-22 18:30:51 20480 ----a-w- C:\Windows\svchost.exe
2012-11-22 18:26:43 9125352 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CF6DD7CA-0871-4656-8F02-8D8ED97EA5EC}\mpengine.dll
2012-11-22 18:26:43 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-11-22 18:25:18 -------- d-----w- C:\Users\Alex\AppData\Roaming\Malwarebytes
2012-11-22 18:25:12 -------- d-----w- C:\ProgramData\Malwarebytes
2012-11-22 18:25:11 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-11-22 18:15:45 82160 ----a-w- C:\Windows\System32\drivers\PDFsFilter.sys
2012-11-22 18:15:45 69000 ----a-w- C:\Windows\System32\offreg.dll
2012-11-22 18:15:45 57144 ----a-w- C:\Windows\System32\iolobtdfg.exe
2012-11-22 18:15:45 56200 ----a-w- C:\Windows\SysWow64\offreg.dll
2012-11-22 18:15:45 25744 ----a-w- C:\Windows\System32\smrgdf.exe
2012-11-22 18:15:45 2155248 ----a-w- C:\Windows\System32\Incinerator64.dll
2012-11-22 18:15:45 2097032 ----a-w- C:\Windows\SysWow64\Incinerator32.dll
2012-11-22 18:15:45 -------- d-----w- C:\Program Files (x86)\iolo
2012-11-22 18:14:53 30752 ----a-w- C:\Windows\System32\drivers\ElRawDsk.sys
2012-11-22 18:14:51 74703 ----a-w- C:\Windows\SysWow64\mfc45.dat
2012-11-22 18:14:36 -------- d-----w- C:\Users\Alex\AppData\Roaming\iolo
2012-11-22 18:14:36 -------- d-----w- C:\ProgramData\iolo
2012-11-22 18:09:15 23680 ----a-w- C:\Windows\System32\drivers\IOMap64.sys
2012-11-22 18:08:42 -------- d-----w- C:\Program Files (x86)\ASUS
2012-11-22 18:08:36 -------- d-----w- C:\Windows\Downloaded Installations
2012-11-22 18:06:58 364352 ----a-w- C:\Windows\System32\nvdecodemft.dll
2012-11-22 18:06:58 301376 ----a-w- C:\Windows\SysWow64\nvdecodemft.dll
2012-11-22 18:06:56 15322432 ----a-w- C:\Windows\SysWow64\SET2542.tmp
2012-11-22 18:06:56 15309160 ----a-w- C:\Windows\SysWow64\nvd3dum.dll
2012-11-22 18:06:38 2741568 ----a-w- C:\Windows\System32\SET1353.tmp
2012-11-22 18:06:38 2731880 ----a-w- C:\Windows\System32\nvapi64.dll
2012-11-22 18:06:38 2428776 ----a-w- C:\Windows\SysWow64\nvapi.dll
2012-11-22 18:06:38 2368832 ----a-w- C:\Windows\SysWow64\SET1E4A.tmp
2012-11-22 18:06:19 -------- d-----w- C:\Program Files\NVIDIA Corporation
2012-11-22 18:00:16 -------- d-----w- C:\Program Files (x86)\MSI
2012-11-22 18:00:03 16152 ----a-w- C:\Windows\System32\drivers\iusb3hcs.sys
2012-11-22 17:59:53 788760 ----a-w- C:\Windows\System32\drivers\iusb3xhc.sys
2012-11-22 17:59:52 356120 ----a-w- C:\Windows\System32\drivers\iusb3hub.sys
2012-11-22 17:59:35 15128 ----a-r- C:\Windows\System32\drivers\IntelMEFWVer.dll
2012-11-22 17:58:49 -------- d-sh--w- C:\Windows\Installer
2012-11-22 17:58:31 -------- d-----w- C:\Program Files (x86)\Common Files\postureAgent
.
==================== Find3M ====================
.
2012-10-02 19:51:15 3536817 ----a-w- C:\Windows\System32\nvcoproc.bin
2012-10-02 19:51:11 3293544 ----a-w- C:\Windows\System32\nvsvc64.dll
2012-10-02 19:51:04 6200680 ----a-w- C:\Windows\System32\nvcpl.dll
2012-10-02 19:50:57 891240 ----a-w- C:\Windows\System32\nvvsvc.exe
2012-10-02 19:50:57 63336 ----a-w- C:\Windows\System32\nvshext.dll
2012-10-02 19:50:57 118120 ----a-w- C:\Windows\System32\nvmctray.dll
2012-10-02 18:15:52 430952 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
.
============= FINISH: 13:37:18.96 ===============
MBAM log:
Malwarebytes Anti-Malware (Trial) 1.65.1.1000
www.malwarebytes.org
Database version: v2012.11.22.08
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Alex :: ALEX-PC [administrator]
Protection: Enabled
11/22/2012 1:26:56 PM
mbam-log-2012-11-22 (13-26-56).txt
Scan type: Full scan (C:\|E:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 298563
Time elapsed: 4 minute(s), 34 second(s)
Memory Processes Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> 1124 -> Delete on reboot.
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot.
(end)
DDS LOG
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 8.0.7600.16385
Run by Alex at 13:37:09 on 2012-11-22
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.16337.13557 [GMT -5:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\ASGT.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\msiexec.exe
C:\Program Files\NVIDIA Corporation\Display\NvTray.exe
E:\Downloads\LeagueofLegends(1).exe
C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{13DAF992-5B15-4BB3-B20C-3423E1ACBE4B} : DHCPNameServer = 192.168.1.1
SSODL: WebCheck - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xjzmhujg.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll
.
============= SERVICES / DRIVERS ===============
.
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2012-11-22 16152]
R1 ElRawDisk;ElRawDisk;C:\Windows\System32\drivers\ElRawDsk.sys [2012-11-22 30752]
R2 ASGT;ASGT;C:\Windows\SysWOW64\ASGT.exe [2012-1-17 55296]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-2-2 628448]
R2 ioloSystemService;iolo System Service;C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2012-11-22 1028464]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-11-22 162648]
R2 MBAMScheduler;MBAMScheduler;E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-8 399432]
R2 MBAMService;MBAMService;E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-8 676936]
R2 MSI_SuperCharger;MSI_SuperCharger;C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [2012-11-22 138768]
R2 PDFsFilter;PDFsFilter;C:\Windows\System32\drivers\PDFsFilter.sys [2012-11-22 82160]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-11-22 362840]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2012-11-22 356120]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2012-11-22 788760]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-11-22 25928]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3;C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [2012-11-22 14136]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-11-22 676968]
R4 IOMap;IOMap;C:\Windows\System32\drivers\IOMap64.sys [2012-11-22 23680]
.
=============== Created Last 30 ================
.
2012-11-22 20:49:58 -------- d-----w- C:\Windows\Panther
2012-11-22 18:35:07 -------- d-----w- C:\Users\Alex\AppData\Local\Macromedia
2012-11-22 18:34:38 -------- d-----w- C:\Users\Alex\AppData\Local\PMB Files
2012-11-22 18:34:38 -------- d-----w- C:\ProgramData\PMB Files
2012-11-22 18:34:32 -------- d-----w- C:\Program Files (x86)\Pando Networks
2012-11-22 18:34:27 -------- d-----w- C:\Users\Alex\.swt
2012-11-22 18:33:47 73656 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-11-22 18:33:47 697272 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-11-22 18:30:51 20480 ----a-w- C:\Windows\svchost.exe
2012-11-22 18:26:43 9125352 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CF6DD7CA-0871-4656-8F02-8D8ED97EA5EC}\mpengine.dll
2012-11-22 18:26:43 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-11-22 18:25:18 -------- d-----w- C:\Users\Alex\AppData\Roaming\Malwarebytes
2012-11-22 18:25:12 -------- d-----w- C:\ProgramData\Malwarebytes
2012-11-22 18:25:11 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-11-22 18:15:45 82160 ----a-w- C:\Windows\System32\drivers\PDFsFilter.sys
2012-11-22 18:15:45 69000 ----a-w- C:\Windows\System32\offreg.dll
2012-11-22 18:15:45 57144 ----a-w- C:\Windows\System32\iolobtdfg.exe
2012-11-22 18:15:45 56200 ----a-w- C:\Windows\SysWow64\offreg.dll
2012-11-22 18:15:45 25744 ----a-w- C:\Windows\System32\smrgdf.exe
2012-11-22 18:15:45 2155248 ----a-w- C:\Windows\System32\Incinerator64.dll
2012-11-22 18:15:45 2097032 ----a-w- C:\Windows\SysWow64\Incinerator32.dll
2012-11-22 18:15:45 -------- d-----w- C:\Program Files (x86)\iolo
2012-11-22 18:14:53 30752 ----a-w- C:\Windows\System32\drivers\ElRawDsk.sys
2012-11-22 18:14:51 74703 ----a-w- C:\Windows\SysWow64\mfc45.dat
2012-11-22 18:14:36 -------- d-----w- C:\Users\Alex\AppData\Roaming\iolo
2012-11-22 18:14:36 -------- d-----w- C:\ProgramData\iolo
2012-11-22 18:09:15 23680 ----a-w- C:\Windows\System32\drivers\IOMap64.sys
2012-11-22 18:08:42 -------- d-----w- C:\Program Files (x86)\ASUS
2012-11-22 18:08:36 -------- d-----w- C:\Windows\Downloaded Installations
2012-11-22 18:06:58 364352 ----a-w- C:\Windows\System32\nvdecodemft.dll
2012-11-22 18:06:58 301376 ----a-w- C:\Windows\SysWow64\nvdecodemft.dll
2012-11-22 18:06:56 15322432 ----a-w- C:\Windows\SysWow64\SET2542.tmp
2012-11-22 18:06:56 15309160 ----a-w- C:\Windows\SysWow64\nvd3dum.dll
2012-11-22 18:06:38 2741568 ----a-w- C:\Windows\System32\SET1353.tmp
2012-11-22 18:06:38 2731880 ----a-w- C:\Windows\System32\nvapi64.dll
2012-11-22 18:06:38 2428776 ----a-w- C:\Windows\SysWow64\nvapi.dll
2012-11-22 18:06:38 2368832 ----a-w- C:\Windows\SysWow64\SET1E4A.tmp
2012-11-22 18:06:19 -------- d-----w- C:\Program Files\NVIDIA Corporation
2012-11-22 18:00:16 -------- d-----w- C:\Program Files (x86)\MSI
2012-11-22 18:00:03 16152 ----a-w- C:\Windows\System32\drivers\iusb3hcs.sys
2012-11-22 17:59:53 788760 ----a-w- C:\Windows\System32\drivers\iusb3xhc.sys
2012-11-22 17:59:52 356120 ----a-w- C:\Windows\System32\drivers\iusb3hub.sys
2012-11-22 17:59:35 15128 ----a-r- C:\Windows\System32\drivers\IntelMEFWVer.dll
2012-11-22 17:58:49 -------- d-sh--w- C:\Windows\Installer
2012-11-22 17:58:31 -------- d-----w- C:\Program Files (x86)\Common Files\postureAgent
.
==================== Find3M ====================
.
2012-10-02 19:51:15 3536817 ----a-w- C:\Windows\System32\nvcoproc.bin
2012-10-02 19:51:11 3293544 ----a-w- C:\Windows\System32\nvsvc64.dll
2012-10-02 19:51:04 6200680 ----a-w- C:\Windows\System32\nvcpl.dll
2012-10-02 19:50:57 891240 ----a-w- C:\Windows\System32\nvvsvc.exe
2012-10-02 19:50:57 63336 ----a-w- C:\Windows\System32\nvshext.dll
2012-10-02 19:50:57 118120 ----a-w- C:\Windows\System32\nvmctray.dll
2012-10-02 18:15:52 430952 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
.
============= FINISH: 13:37:18.96 ===============