I have a problem with single clicks on my mouse been converted to double clicks. It is extremely frustrating with programs closing and being maximised. I have removed cookies from *.doubleclick.com and *.doubleclick.net. I have installed a small utility which is meant to prevent problems with aging mice. But nothing is preventing the double clicks. I read the thread on the 4 steps to getting logs and have added the results below. I thank you all in advance of any help you can give.
Antimalware log.
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
Database version: v2013.08.03.02
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16635
User :: PARTY [administrator]
Protection: Enabled
03/08/2013 08:53:45
mbam-log-2013-08-03 (08-53-45).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 376055
Time elapsed: 2 minute(s), 47 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 1
C:\Users\User\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
Files Detected: 7
D:\WinSystem\Users\User\AppData\Local\TMP\KQ0ytax9.exe.part (PUP.Optional.Softonic) -> Quarantined and deleted successfully.
D:\WinSystem\Users\User\AppData\Local\TMP\PassportPhotoSoftwareFreeFullSetup.exe (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.
D:\WinSystem\Users\User\AppData\Local\TMP\YVRlmBpq.exe.part (PUP.Optional.Softonic) -> Quarantined and deleted successfully.
D:\WinSystem\Users\User\AppData\Local\TMP\26A701D1-BAB0-7891-8516-132EB8E4BEA6\Latest\MyDeltaTB.exe (PUP.Delta.A) -> Quarantined and deleted successfully.
D:\WinSystem\Users\User\AppData\Local\TMP\26A701D1-BAB0-7891-8516-132EB8E4BEA6\Latest\Setup.exe (PUP.Babylon.A) -> Quarantined and deleted successfully.
D:\WinSystem\Users\User\AppData\Local\TMP\E0425DAD-BAB0-7891-B600-394B751114C5\Latest\Setup.exe (PUP.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
(end)
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.25.2
Run by User at 9:12:02 on 2013-08-03
Microsoft Windows 8 Pro with Media Center 6.2.9200.0.1252.353.2057.18.12265.9932 [GMT 1:00]
.
AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\WINDOWS\system32\nvvsvc.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\WINDOWS\system32\svchost.exe -k apphost
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\Bin\IpOverUsbSvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\sqlservr.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files (x86)\Hotkey\PowerBiosServer.exe
C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe
C:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k iissvcs
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\vmms.exe
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Hotkey\Hotkey.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe
C:\Windows\BisonCam\BisonHK.exe
C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FixMouseLMB.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ie/
mWinlogon: Userinit = userinit.exe,
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: Microsoft Web Test Recorder 10.0 Helper: {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
EB: Developer Tools: {1A6FE369-F28C-4AD9-A3E6-2BCB50807CF1} - C:\Program Files (x86)\Internet Explorer\iedvtool.dll
EB: <No Name>: {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 - <no file>
EB: <No Name>: {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 - <no file>
EB: Web Test Recorder 10.0: {5802D092-1784-4908-8CDB-99B6842D353D} -
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [RESTART_STICKY_NOTES] C:\WINDOWS\System32\StikyNot.exe
uRun: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [BisonHK] C:\WINDOWS\BisonCam\BisonHK.exe
StartupFolder: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FixMouseLMB.exe
StartupFolder: C:\Users\User\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\FreeClip.lnk - C:\Program Files (x86)\FreeClip\FreeClip.exe
StartupFolder: C:\Users\User\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\LOGITE~1.LNK - C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
StartupFolder: C:\Users\User\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MICROS~1.LNK - C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
StartupFolder: C:\Users\User\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
StartupFolder: C:\Users\User\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\PASSPO~1.LNK - C:\Program Files (x86)\CamToPrint\PassportPhoto\CamToPrintTray.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\Hotkey.lnk - C:\Program Files (x86)\Hotkey\Hotkey.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\QUALCO~1.LNK - C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
LSP: %SYSTEMROOT%\system32\BfLLR.dll
TCP: NameServer = 89.101.160.4 89.101.160.5
TCP: Interfaces\{26967A5F-03C4-49FA-AB74-B3CAC6AEC2F0} : DHCPNameServer = 89.101.160.4 89.101.160.5
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\WINDOWS\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [Logitech Download Assistant] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\LogiLDA.dll,LogiFetch
x64-Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
x64-Run: [IntelliPoint] "C:\Program Files\Microsoft Device Center\ipoint.exe"
x64-Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
x64-Run: [Nvtmru] "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
x64-Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab
x64-DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\571nmlrd.default\
FF - prefs.js: browser.startup.homepage - www.google.ie
FF - prefs.js: network.proxy.http - 46.231.14.49
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\npBrowserPlugin.dll
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll
FF - plugin: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll
FF - plugin: C:\WINDOWS\SysWOW64\npDeployJava1.dll
FF - plugin: C:\WINDOWS\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-06-16 22:36; {F003DA68-8256-4b37-A6C4-350FA04494DF}; C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - 94bb6a870000000000001aa3c434fd2f
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15919
FF - user.js: extensions.delta.vrsn - 1.8.22.0
FF - user.js: extensions.delta.vrsni - 1.8.22.0
FF - user.js: extensions.delta.vrsnTs - 1.8.22.022:51:38
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=119826&tsp=4962
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
============= SERVICES / DRIVERS ===============
.
R1 BfLwf;Qualcomm Atheros Bandwidth Control;C:\WINDOWS\System32\Drivers\bwcW8x64.sys [2012-9-25 74096]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-7-18 13592]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-3-7 629984]
R2 IpOverUsbSvc;Windows Phone IP over USB Transport (IpOverUsbSvc);C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\Bin\IpOverUsbSvc.exe [2012-9-26 14760]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-8-3 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-8-3 701512]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2012-7-13 769432]
R2 PowerBiosServer;PowerBiosServer;C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [2012-9-13 45568]
R2 Qualcomm Atheros Killer Service;Qualcomm Atheros Killer Service;C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [2012-9-25 490496]
R2 ReportServer;SQL Server Reporting Services (MSSQLSERVER);C:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2012-10-20 2423792]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-6-21 413472]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-7-18 363800]
R3 akw8x64;Killer Wireless-N 1102 device driver;C:\WINDOWS\System32\Drivers\akw8x64.sys [2012-9-25 3203440]
R3 JMCR;JMCR;C:\WINDOWS\System32\Drivers\jmcr.sys [2012-6-6 174200]
R3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);C:\WINDOWS\System32\Drivers\JME.sys [2011-11-17 145424]
R3 johci;JMicron 1394 Filter Driver;C:\WINDOWS\System32\Drivers\johci.sys [2012-12-6 26208]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\WINDOWS\System32\Drivers\LEqdUsb.sys [2013-1-3 79240]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\WINDOWS\System32\Drivers\LHidEqd.sys [2013-1-3 15752]
R3 MBAMProtector;MBAMProtector;C:\WINDOWS\System32\Drivers\mbam.sys [2013-8-3 25928]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\WINDOWS\System32\Drivers\nusb3hub.sys [2012-8-27 107912]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\WINDOWS\System32\Drivers\nusb3xhc.sys [2012-8-27 226696]
R3 vmbusr;Virtual Machine Bus Provider;C:\WINDOWS\System32\Drivers\vmbusr.sys [2012-7-26 117248]
R3 VMSMP;VMSMP;C:\WINDOWS\System32\Drivers\vmswitch.sys [2013-3-13 569344]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\Drivers\WUDFRd.sys [2012-7-26 198656]
S2 NPVR Recording Service;NPVR Recording Service;"C:\Program Files (x86)\NPVR\NRecord.exe" --> C:\Program Files (x86)\NPVR\NRecord.exe [?]
S3 cpudrv64;cpudrv64;C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2011-6-2 17864]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-7-29 1315592]
S3 LADF_CaptureOnly;LADF Capture Filter Driver;C:\WINDOWS\System32\Drivers\ladfGSCamd64.sys [2011-4-11 410184]
S3 LADF_RenderOnly;LADF Render Filter Driver;C:\WINDOWS\System32\Drivers\ladfGSRamd64.sys [2011-4-11 341832]
S3 ManyCam;ManyCam Virtual Webcam;C:\WINDOWS\System32\Drivers\mcvidrv_x64.sys [2013-4-11 44544]
S3 mcaudrv_simple;ManyCam Virtual Microphone;C:\WINDOWS\System32\Drivers\mcaudrv_x64.sys [2013-1-31 28160]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 Te.Service;Te.Service;C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [2012-7-25 126976]
S3 vhdparser;vhdparser;C:\WINDOWS\System32\Drivers\vhdparser.sys [2012-7-26 16384]
S3 VMSP;VMSP;C:\WINDOWS\System32\Drivers\vmswitch.sys [2013-3-13 569344]
S3 VMSVSP;VMSVSP;C:\WINDOWS\System32\Drivers\vmswitch.sys [2013-3-13 569344]
S3 VSPerfDrv100;Performance Tools Driver 10.0;C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2011-1-18 68440]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\System32\Drivers\wdcsam64.sys [2009-2-13 14464]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2009-7-22 61976]
S4 RsFx0105;RsFx0105 Driver;C:\WINDOWS\System32\Drivers\RsFx0105.sys [2011-9-22 311144]
S4 RsFx0201;RsFx0201 Driver;C:\WINDOWS\System32\Drivers\RsFx0201.sys [2012-10-20 336880]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-9-22 431464]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\WINDOWS\System32\NOTEPAD.EXE %1 [UserChoice]
FileExt: .vbe: VBEFile="C:\WINDOWS\System32\CScript.exe" "%1" %* [default=Open2]
FileExt: .vbs: VBSFile="C:\WINDOWS\System32\CScript.exe" "%1" %* [default=Open2]
FileExt: .js: JSFile=C:\WINDOWS\System32\CScript.exe "%1" %* [default=Open2]
FileExt: .jse: JSEFile=C:\WINDOWS\System32\CScript.exe "%1" %* [default=Open2]
FileExt: .wsf: WSFFile="C:\WINDOWS\System32\CScript.exe" "%1" %* [default=Open2]
.
=============== Created Last 30 ================
.
2013-08-03 07:53:03 -------- d-----w- C:\Users\User\AppData\Roaming\Malwarebytes
2013-08-03 07:51:26 -------- d-----w- C:\ProgramData\Malwarebytes
2013-08-03 07:51:25 25928 ----a-w- C:\WINDOWS\System32\drivers\mbam.sys
2013-08-03 07:51:25 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-03 07:48:04 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{914CAB4E-9D16-4923-9286-993915547510}\mpengine.dll
2013-08-03 07:43:07 -------- d-----w- C:\Users\User\AppData\Local\{8EE1375A-B26B-49C0-9B12-177D0FD660B4}
2013-08-03 03:47:39 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-08-03 03:41:41 954368 ----a-w- C:\WINDOWS\SysWow64\Mfc45d8c.rra
2013-08-02 23:21:39 -------- d-----w- C:\Program Files (x86)\BisonCam
2013-08-02 23:17:37 -------- d-----w- C:\Users\User\.yawcam
2013-08-02 23:17:28 -------- d-----w- C:\Program Files (x86)\Yawcam
2013-08-02 23:07:28 -------- d-----w- C:\Users\User\AppData\Roaming\DRPSu
2013-08-02 23:04:30 -------- d-----w- C:\WINDOWS\System32\wbem\Framework\root\OpenHardwareMonitor
2013-08-02 23:04:30 -------- d-----w- C:\WINDOWS\System32\wbem\Framework\root
2013-08-02 23:04:30 -------- d-----w- C:\WINDOWS\System32\wbem\Framework
2013-08-02 22:51:46 -------- d-----w- C:\WINDOWS\Options
2013-08-02 22:51:46 -------- d-----w- C:\WINDOWS\BisonCam
2013-08-02 22:25:25 -------- d-----w- C:\Users\User\AppData\Roaming\Visan
2013-08-02 22:24:10 -------- d-----w- C:\ProgramData\Visan
2013-08-02 21:51:03 -------- d-----w- C:\ProgramData\Babylon
2013-08-02 21:49:13 -------- d-----w- C:\Program Files (x86)\CamToPrint
2013-08-02 19:45:31 216064 ----a-w- C:\WINDOWS\SysWow64\gcapi_dll.dll
2013-08-02 18:01:23 -------- d-----w- C:\Users\User\AppData\Local\{AAC90E8F-45E1-40D1-8A75-CFB831B7C393}
2013-08-01 17:37:04 -------- d-----w- C:\Users\User\AppData\Local\{BA741D8B-5994-45F6-8572-04C044E5BA32}
2013-07-31 22:08:16 -------- d-----w- C:\Users\User\AppData\Local\{169C470D-B31A-40D5-931C-CF8AB8A91422}
2013-07-31 02:31:24 -------- d-----w- C:\Intel
2013-07-30 14:35:35 -------- d-----w- C:\Users\User\AppData\Local\{2BE297EC-7A81-40CF-A055-253CF5DB7CF9}
2013-07-29 20:37:50 -------- d-----w- C:\Users\User\AppData\Local\{3BF314D8-9D7A-496F-B294-D6B62BD96203}
2013-07-28 20:44:47 -------- d-----w- C:\Users\User\AppData\Local\{081C1716-6FE6-44CE-8946-79670C0A17FC}
2013-07-27 23:42:27 -------- d-----w- C:\Users\User\AppData\Local\{E7D53F3B-231A-4208-8E90-63E45F64E01F}
2013-07-26 12:33:33 -------- d-----w- C:\Users\User\AppData\Local\{F422368A-295F-4541-86D7-48A9EC80739B}
2013-07-25 17:41:23 -------- d-----w- C:\Users\User\AppData\Local\{4FCD2BDE-C15C-4A92-BB4D-051048268330}
2013-07-25 00:08:34 -------- d-----w- C:\Users\User\AppData\Local\{3C802EF1-2618-48AD-8077-ACEC3E61E0F3}
2013-07-23 18:46:30 -------- d-----w- C:\Users\User\AppData\Local\{BC6DC233-9B8F-4B72-A4AE-6421B705ED06}
2013-07-22 22:16:23 -------- d-----w- C:\Users\User\AppData\Local\{C0542F61-43B5-494B-A351-355086F5735D}
2013-07-21 17:12:51 -------- d-----w- C:\Users\User\AppData\Local\{FE633B98-DAEA-4842-B20E-759E18D54655}
2013-07-21 01:59:40 -------- d-----w- C:\Users\User\AppData\Local\{EDAFC625-5BA9-445C-AF51-75837123063A}
2013-07-19 22:44:45 -------- d-----w- C:\Users\User\AppData\Local\{6B76BCFF-BEA7-4989-968D-933C80423C5B}
2013-07-17 17:42:11 -------- d-----w- C:\Users\User\AppData\Local\{925742A5-CEE9-489D-8B87-8C06C861E2FF}
2013-07-16 22:05:24 -------- d-----w- C:\Users\User\AppData\Local\{3E48B55C-350F-41B4-8DD6-C6152DE492B6}
2013-07-16 08:49:42 -------- d-----w- C:\Users\User\AppData\Local\{D587D5D6-D100-428E-8DF7-F4E5A8682AD2}
2013-07-15 17:53:09 -------- d-----w- C:\Users\User\AppData\Local\{C329A1C2-C4F8-40A2-A7F3-8ADDD6E852E3}
2013-07-13 21:32:12 -------- d-----w- C:\Users\User\AppData\Local\{C9E68C7E-6BAC-4107-85E7-AA92EDF8ACD7}
2013-07-12 23:08:55 -------- d-----w- C:\Users\User\AppData\Local\{E15AFE88-6D8D-4E85-8CB2-E86E361483F0}
2013-07-11 16:00:27 -------- d-----w- C:\Users\User\AppData\Local\{4D786F56-A583-4086-B403-A17A5AD65A27}
2013-07-10 19:49:04 -------- d-----w- C:\WINDOWS\System32\MRT
2013-07-10 16:27:48 -------- d-----w- C:\Users\User\AppData\Local\{E21CD5AE-5F33-40F0-80D0-45386744704A}
2013-07-09 18:27:53 -------- d-----w- C:\Users\User\AppData\Local\{1EC5EC08-EF7C-47A1-8E8A-58E583AF4274}
2013-07-07 08:36:03 96168 ----a-w- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
2013-07-07 08:33:08 108968 ----a-w- C:\WINDOWS\System32\WindowsAccessBridge-64.dll
2013-07-07 08:06:43 -------- d-----w- C:\Users\User\AppData\Local\{7BDFC2CD-D94F-41A6-92F8-714AD32DAB7E}
2013-07-05 22:11:42 77824 ----a-w- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FixMouseLMB.exe
2013-07-05 21:49:34 -------- d-----w- C:\Users\User\AppData\Local\{A88FDDDD-7D15-4AB0-8D61-D0E2E15AE133}
2013-07-04 16:48:43 -------- d-----w- C:\Users\User\AppData\Local\{1E71996A-D142-4255-B384-68FE26826DF0}
.
==================== Find3M ====================
.
2013-07-07 08:35:59 867240 ----a-w- C:\WINDOWS\SysWow64\npDeployJava1.dll
2013-07-07 08:35:59 789416 ----a-w- C:\WINDOWS\SysWow64\deployJava1.dll
2013-07-07 08:33:03 972712 ----a-w- C:\WINDOWS\System32\deployJava1.dll
2013-07-07 08:33:03 1093032 ----a-w- C:\WINDOWS\System32\npDeployJava1.dll
2013-06-27 22:04:51 78200 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2013-06-27 22:04:51 693112 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2013-06-21 10:23:16 6496544 ----a-w- C:\WINDOWS\System32\nvcpl.dll
2013-06-21 10:23:16 3514656 ----a-w- C:\WINDOWS\System32\nvsvc64.dll
2013-06-21 10:23:11 884512 ----a-w- C:\WINDOWS\System32\nvvsvc.exe
2013-06-21 10:23:10 63776 ----a-w- C:\WINDOWS\System32\nvshext.dll
2013-06-21 10:23:10 2555680 ----a-w- C:\WINDOWS\System32\nvsvcr.dll
2013-06-21 10:23:10 237856 ----a-w- C:\WINDOWS\System32\nvmctray.dll
2013-06-21 04:16:02 566048 ----a-w- C:\WINDOWS\SysWow64\nvStreaming.exe
2013-06-16 22:41:31 997632 ----a-w- C:\WINDOWS\System32\drivers\ndis.sys
2013-06-16 21:36:12 18960 ----a-w- C:\WINDOWS\System32\drivers\LNonPnP.sys
2013-06-11 23:43:37 1767936 ----a-w- C:\WINDOWS\SysWow64\wininet.dll
2013-06-11 23:43:00 2877440 ----a-w- C:\WINDOWS\SysWow64\jscript9.dll
2013-06-11 23:26:20 2241024 ----a-w- C:\WINDOWS\System32\wininet.dll
2013-06-11 23:25:16 3958784 ----a-w- C:\WINDOWS\System32\jscript9.dll
2013-06-06 19:56:22 21712 ----a-w- C:\WINDOWS\SysWow64\drivers\DrvAgent64.SYS
2013-06-01 12:02:14 998144 ----a-w- C:\WINDOWS\System32\hvloader.exe
2013-06-01 12:02:14 1133824 ----a-w- C:\WINDOWS\System32\hvix64.exe
2013-06-01 12:02:14 1117440 ----a-w- C:\WINDOWS\System32\hvax64.exe
2013-06-01 12:02:14 1084160 ----a-w- C:\WINDOWS\System32\hvloader.efi
2013-06-01 11:54:16 194816 ----a-w- C:\WINDOWS\System32\drivers\sdbus.sys
2013-06-01 11:54:10 125184 ----a-w- C:\WINDOWS\System32\drivers\dumpsd.sys
2013-06-01 11:34:21 2391280 ----a-w- C:\WINDOWS\explorer.exe
2013-06-01 11:33:13 2233600 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2013-06-01 11:29:35 337152 ----a-w- C:\WINDOWS\System32\drivers\USBXHCI.SYS
2013-06-01 11:29:35 213248 ----a-w- C:\WINDOWS\System32\drivers\UCX01000.SYS
2013-06-01 11:26:33 327936 ----a-w- C:\WINDOWS\System32\drivers\volsnap.sys
2013-06-01 11:26:31 6987008 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2013-06-01 10:24:46 2106176 ----a-w- C:\WINDOWS\SysWow64\explorer.exe
2013-06-01 09:25:52 364544 ----a-w- C:\WINDOWS\SysWow64\XpsGdiConverter.dll
2013-06-01 09:25:05 67584 ----a-w- C:\WINDOWS\SysWow64\samlib.dll
2013-06-01 09:25:03 496640 ----a-w- C:\WINDOWS\SysWow64\qedit.dll
2013-06-01 09:24:19 493056 ----a-w- C:\WINDOWS\SysWow64\mscms.dll
2013-06-01 09:24:09 850944 ----a-w- C:\WINDOWS\SysWow64\mfasfsrcsnk.dll
2013-06-01 09:24:09 1453568 ----a-w- C:\WINDOWS\SysWow64\mfcore.dll
2013-06-01 09:23:46 1842176 ----a-w- C:\WINDOWS\SysWow64\dwmcore.dll
2013-06-01 09:23:06 680960 ----a-w- C:\WINDOWS\System32\vds.exe
2013-06-01 09:22:47 80896 ----a-w- C:\WINDOWS\System32\MbaeParserTask.exe
2013-06-01 09:22:33 523264 ----a-w- C:\WINDOWS\System32\XpsGdiConverter.dll
2013-06-01 09:22:33 446976 ----a-w- C:\WINDOWS\System32\wwansvc.dll
2013-06-01 09:22:09 190976 ----a-w- C:\WINDOWS\System32\vdsutil.dll
2013-06-01 09:21:39 729600 ----a-w- C:\WINDOWS\System32\samsrv.dll
2013-06-01 09:21:39 106496 ----a-w- C:\WINDOWS\System32\samlib.dll
2013-06-01 09:21:34 595968 ----a-w- C:\WINDOWS\System32\qedit.dll
2013-06-01 09:20:45 583168 ----a-w- C:\WINDOWS\System32\mscms.dll
2013-06-01 09:20:34 1527808 ----a-w- C:\WINDOWS\System32\mfcore.dll
2013-06-01 09:20:34 1048576 ----a-w- C:\WINDOWS\System32\mfasfsrcsnk.dll
2013-06-01 09:20:04 2219520 ----a-w- C:\WINDOWS\System32\dwmcore.dll
2013-06-01 09:19:58 207872 ----a-w- C:\WINDOWS\System32\DeviceSetupManager.dll
2013-06-01 09:19:42 785408 ----a-w- C:\WINDOWS\System32\audiosrv.dll
2013-06-01 03:08:57 37632 ----a-w- C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
2013-06-01 01:21:46 4040704 ----a-w- C:\WINDOWS\System32\vmwp.exe
2013-06-01 01:02:46 11201536 ----a-w- C:\WINDOWS\System32\vmms.exe
2013-05-30 23:14:23 4036096 ----a-w- C:\WINDOWS\System32\win32k.sys
2013-05-24 22:09:20 1403296 ----a-w- C:\WINDOWS\System32\winload.efi
2013-05-24 22:09:20 1271584 ----a-w- C:\WINDOWS\System32\winload.exe
2013-05-24 22:09:20 1217352 ----a-w- C:\WINDOWS\System32\winresume.efi
2013-05-24 22:09:20 1093904 ----a-w- C:\WINDOWS\System32\winresume.exe
2013-05-23 23:01:46 1300992 ----a-w- C:\WINDOWS\System32\gdi32.dll
2013-05-23 22:27:05 1022464 ----a-w- C:\WINDOWS\SysWow64\gdi32.dll
2013-05-15 22:37:03 44032 ----a-w- C:\WINDOWS\SysWow64\UXInit.dll
2013-05-15 22:35:49 53760 ----a-w- C:\WINDOWS\System32\UXInit.dll
2013-05-15 22:35:47 144384 ----a-w- C:\WINDOWS\System32\tssdisai.dll
2013-05-15 02:25:59 888320 ----a-w- C:\WINDOWS\System32\autochk.exe
2013-05-15 02:25:44 542208 ----a-w- C:\WINDOWS\System32\untfs.dll
2013-05-15 02:24:10 793088 ----a-w- C:\WINDOWS\SysWow64\autochk.exe
2013-05-15 02:24:01 482816 ----a-w- C:\WINDOWS\SysWow64\untfs.dll
2013-05-14 13:14:01 2706432 ----a-w- C:\WINDOWS\System32\mshtml.tlb
2013-05-14 09:23:31 2706432 ----a-w- C:\WINDOWS\SysWow64\mshtml.tlb
2013-05-12 21:42:27 1832224 ----a-w- C:\WINDOWS\System32\nvdispco6432018.dll
2013-05-12 21:42:27 1511712 ----a-w- C:\WINDOWS\System32\nvdispgenco6432018.dll
2013-05-08 03:33:47 1832224 ----a-w- C:\WINDOWS\System32\nvdispco6432014.dll
2013-05-08 03:33:47 1511712 ----a-w- C:\WINDOWS\System32\nvdispgenco6432014.dll
.
============= FINISH: 9:12:10.55 ===============
attach.txt is in the following thread
.
Hopefully you can help!
Liam
Antimalware log.
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
Database version: v2013.08.03.02
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16635
User :: PARTY [administrator]
Protection: Enabled
03/08/2013 08:53:45
mbam-log-2013-08-03 (08-53-45).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 376055
Time elapsed: 2 minute(s), 47 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 1
C:\Users\User\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
Files Detected: 7
D:\WinSystem\Users\User\AppData\Local\TMP\KQ0ytax9.exe.part (PUP.Optional.Softonic) -> Quarantined and deleted successfully.
D:\WinSystem\Users\User\AppData\Local\TMP\PassportPhotoSoftwareFreeFullSetup.exe (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.
D:\WinSystem\Users\User\AppData\Local\TMP\YVRlmBpq.exe.part (PUP.Optional.Softonic) -> Quarantined and deleted successfully.
D:\WinSystem\Users\User\AppData\Local\TMP\26A701D1-BAB0-7891-8516-132EB8E4BEA6\Latest\MyDeltaTB.exe (PUP.Delta.A) -> Quarantined and deleted successfully.
D:\WinSystem\Users\User\AppData\Local\TMP\26A701D1-BAB0-7891-8516-132EB8E4BEA6\Latest\Setup.exe (PUP.Babylon.A) -> Quarantined and deleted successfully.
D:\WinSystem\Users\User\AppData\Local\TMP\E0425DAD-BAB0-7891-B600-394B751114C5\Latest\Setup.exe (PUP.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
(end)
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.25.2
Run by User at 9:12:02 on 2013-08-03
Microsoft Windows 8 Pro with Media Center 6.2.9200.0.1252.353.2057.18.12265.9932 [GMT 1:00]
.
AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\WINDOWS\system32\nvvsvc.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\WINDOWS\system32\svchost.exe -k apphost
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\Bin\IpOverUsbSvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\sqlservr.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files (x86)\Hotkey\PowerBiosServer.exe
C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe
C:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k iissvcs
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\vmms.exe
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Hotkey\Hotkey.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe
C:\Windows\BisonCam\BisonHK.exe
C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FixMouseLMB.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ie/
mWinlogon: Userinit = userinit.exe,
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: Microsoft Web Test Recorder 10.0 Helper: {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
EB: Developer Tools: {1A6FE369-F28C-4AD9-A3E6-2BCB50807CF1} - C:\Program Files (x86)\Internet Explorer\iedvtool.dll
EB: <No Name>: {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 - <no file>
EB: <No Name>: {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 - <no file>
EB: Web Test Recorder 10.0: {5802D092-1784-4908-8CDB-99B6842D353D} -
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [RESTART_STICKY_NOTES] C:\WINDOWS\System32\StikyNot.exe
uRun: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [BisonHK] C:\WINDOWS\BisonCam\BisonHK.exe
StartupFolder: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FixMouseLMB.exe
StartupFolder: C:\Users\User\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\FreeClip.lnk - C:\Program Files (x86)\FreeClip\FreeClip.exe
StartupFolder: C:\Users\User\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\LOGITE~1.LNK - C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
StartupFolder: C:\Users\User\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MICROS~1.LNK - C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
StartupFolder: C:\Users\User\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
StartupFolder: C:\Users\User\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\PASSPO~1.LNK - C:\Program Files (x86)\CamToPrint\PassportPhoto\CamToPrintTray.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\Hotkey.lnk - C:\Program Files (x86)\Hotkey\Hotkey.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\QUALCO~1.LNK - C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
LSP: %SYSTEMROOT%\system32\BfLLR.dll
TCP: NameServer = 89.101.160.4 89.101.160.5
TCP: Interfaces\{26967A5F-03C4-49FA-AB74-B3CAC6AEC2F0} : DHCPNameServer = 89.101.160.4 89.101.160.5
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\WINDOWS\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [Logitech Download Assistant] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\LogiLDA.dll,LogiFetch
x64-Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
x64-Run: [IntelliPoint] "C:\Program Files\Microsoft Device Center\ipoint.exe"
x64-Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
x64-Run: [Nvtmru] "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
x64-Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab
x64-DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\571nmlrd.default\
FF - prefs.js: browser.startup.homepage - www.google.ie
FF - prefs.js: network.proxy.http - 46.231.14.49
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\npBrowserPlugin.dll
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll
FF - plugin: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll
FF - plugin: C:\WINDOWS\SysWOW64\npDeployJava1.dll
FF - plugin: C:\WINDOWS\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-06-16 22:36; {F003DA68-8256-4b37-A6C4-350FA04494DF}; C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - 94bb6a870000000000001aa3c434fd2f
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15919
FF - user.js: extensions.delta.vrsn - 1.8.22.0
FF - user.js: extensions.delta.vrsni - 1.8.22.0
FF - user.js: extensions.delta.vrsnTs - 1.8.22.022:51:38
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=119826&tsp=4962
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
============= SERVICES / DRIVERS ===============
.
R1 BfLwf;Qualcomm Atheros Bandwidth Control;C:\WINDOWS\System32\Drivers\bwcW8x64.sys [2012-9-25 74096]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-7-18 13592]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-3-7 629984]
R2 IpOverUsbSvc;Windows Phone IP over USB Transport (IpOverUsbSvc);C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\Bin\IpOverUsbSvc.exe [2012-9-26 14760]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-8-3 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-8-3 701512]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2012-7-13 769432]
R2 PowerBiosServer;PowerBiosServer;C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [2012-9-13 45568]
R2 Qualcomm Atheros Killer Service;Qualcomm Atheros Killer Service;C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [2012-9-25 490496]
R2 ReportServer;SQL Server Reporting Services (MSSQLSERVER);C:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2012-10-20 2423792]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-6-21 413472]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-7-18 363800]
R3 akw8x64;Killer Wireless-N 1102 device driver;C:\WINDOWS\System32\Drivers\akw8x64.sys [2012-9-25 3203440]
R3 JMCR;JMCR;C:\WINDOWS\System32\Drivers\jmcr.sys [2012-6-6 174200]
R3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);C:\WINDOWS\System32\Drivers\JME.sys [2011-11-17 145424]
R3 johci;JMicron 1394 Filter Driver;C:\WINDOWS\System32\Drivers\johci.sys [2012-12-6 26208]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\WINDOWS\System32\Drivers\LEqdUsb.sys [2013-1-3 79240]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\WINDOWS\System32\Drivers\LHidEqd.sys [2013-1-3 15752]
R3 MBAMProtector;MBAMProtector;C:\WINDOWS\System32\Drivers\mbam.sys [2013-8-3 25928]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\WINDOWS\System32\Drivers\nusb3hub.sys [2012-8-27 107912]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\WINDOWS\System32\Drivers\nusb3xhc.sys [2012-8-27 226696]
R3 vmbusr;Virtual Machine Bus Provider;C:\WINDOWS\System32\Drivers\vmbusr.sys [2012-7-26 117248]
R3 VMSMP;VMSMP;C:\WINDOWS\System32\Drivers\vmswitch.sys [2013-3-13 569344]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\Drivers\WUDFRd.sys [2012-7-26 198656]
S2 NPVR Recording Service;NPVR Recording Service;"C:\Program Files (x86)\NPVR\NRecord.exe" --> C:\Program Files (x86)\NPVR\NRecord.exe [?]
S3 cpudrv64;cpudrv64;C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2011-6-2 17864]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-7-29 1315592]
S3 LADF_CaptureOnly;LADF Capture Filter Driver;C:\WINDOWS\System32\Drivers\ladfGSCamd64.sys [2011-4-11 410184]
S3 LADF_RenderOnly;LADF Render Filter Driver;C:\WINDOWS\System32\Drivers\ladfGSRamd64.sys [2011-4-11 341832]
S3 ManyCam;ManyCam Virtual Webcam;C:\WINDOWS\System32\Drivers\mcvidrv_x64.sys [2013-4-11 44544]
S3 mcaudrv_simple;ManyCam Virtual Microphone;C:\WINDOWS\System32\Drivers\mcaudrv_x64.sys [2013-1-31 28160]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 Te.Service;Te.Service;C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [2012-7-25 126976]
S3 vhdparser;vhdparser;C:\WINDOWS\System32\Drivers\vhdparser.sys [2012-7-26 16384]
S3 VMSP;VMSP;C:\WINDOWS\System32\Drivers\vmswitch.sys [2013-3-13 569344]
S3 VMSVSP;VMSVSP;C:\WINDOWS\System32\Drivers\vmswitch.sys [2013-3-13 569344]
S3 VSPerfDrv100;Performance Tools Driver 10.0;C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2011-1-18 68440]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\System32\Drivers\wdcsam64.sys [2009-2-13 14464]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2009-7-22 61976]
S4 RsFx0105;RsFx0105 Driver;C:\WINDOWS\System32\Drivers\RsFx0105.sys [2011-9-22 311144]
S4 RsFx0201;RsFx0201 Driver;C:\WINDOWS\System32\Drivers\RsFx0201.sys [2012-10-20 336880]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-9-22 431464]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\WINDOWS\System32\NOTEPAD.EXE %1 [UserChoice]
FileExt: .vbe: VBEFile="C:\WINDOWS\System32\CScript.exe" "%1" %* [default=Open2]
FileExt: .vbs: VBSFile="C:\WINDOWS\System32\CScript.exe" "%1" %* [default=Open2]
FileExt: .js: JSFile=C:\WINDOWS\System32\CScript.exe "%1" %* [default=Open2]
FileExt: .jse: JSEFile=C:\WINDOWS\System32\CScript.exe "%1" %* [default=Open2]
FileExt: .wsf: WSFFile="C:\WINDOWS\System32\CScript.exe" "%1" %* [default=Open2]
.
=============== Created Last 30 ================
.
2013-08-03 07:53:03 -------- d-----w- C:\Users\User\AppData\Roaming\Malwarebytes
2013-08-03 07:51:26 -------- d-----w- C:\ProgramData\Malwarebytes
2013-08-03 07:51:25 25928 ----a-w- C:\WINDOWS\System32\drivers\mbam.sys
2013-08-03 07:51:25 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-03 07:48:04 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{914CAB4E-9D16-4923-9286-993915547510}\mpengine.dll
2013-08-03 07:43:07 -------- d-----w- C:\Users\User\AppData\Local\{8EE1375A-B26B-49C0-9B12-177D0FD660B4}
2013-08-03 03:47:39 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-08-03 03:41:41 954368 ----a-w- C:\WINDOWS\SysWow64\Mfc45d8c.rra
2013-08-02 23:21:39 -------- d-----w- C:\Program Files (x86)\BisonCam
2013-08-02 23:17:37 -------- d-----w- C:\Users\User\.yawcam
2013-08-02 23:17:28 -------- d-----w- C:\Program Files (x86)\Yawcam
2013-08-02 23:07:28 -------- d-----w- C:\Users\User\AppData\Roaming\DRPSu
2013-08-02 23:04:30 -------- d-----w- C:\WINDOWS\System32\wbem\Framework\root\OpenHardwareMonitor
2013-08-02 23:04:30 -------- d-----w- C:\WINDOWS\System32\wbem\Framework\root
2013-08-02 23:04:30 -------- d-----w- C:\WINDOWS\System32\wbem\Framework
2013-08-02 22:51:46 -------- d-----w- C:\WINDOWS\Options
2013-08-02 22:51:46 -------- d-----w- C:\WINDOWS\BisonCam
2013-08-02 22:25:25 -------- d-----w- C:\Users\User\AppData\Roaming\Visan
2013-08-02 22:24:10 -------- d-----w- C:\ProgramData\Visan
2013-08-02 21:51:03 -------- d-----w- C:\ProgramData\Babylon
2013-08-02 21:49:13 -------- d-----w- C:\Program Files (x86)\CamToPrint
2013-08-02 19:45:31 216064 ----a-w- C:\WINDOWS\SysWow64\gcapi_dll.dll
2013-08-02 18:01:23 -------- d-----w- C:\Users\User\AppData\Local\{AAC90E8F-45E1-40D1-8A75-CFB831B7C393}
2013-08-01 17:37:04 -------- d-----w- C:\Users\User\AppData\Local\{BA741D8B-5994-45F6-8572-04C044E5BA32}
2013-07-31 22:08:16 -------- d-----w- C:\Users\User\AppData\Local\{169C470D-B31A-40D5-931C-CF8AB8A91422}
2013-07-31 02:31:24 -------- d-----w- C:\Intel
2013-07-30 14:35:35 -------- d-----w- C:\Users\User\AppData\Local\{2BE297EC-7A81-40CF-A055-253CF5DB7CF9}
2013-07-29 20:37:50 -------- d-----w- C:\Users\User\AppData\Local\{3BF314D8-9D7A-496F-B294-D6B62BD96203}
2013-07-28 20:44:47 -------- d-----w- C:\Users\User\AppData\Local\{081C1716-6FE6-44CE-8946-79670C0A17FC}
2013-07-27 23:42:27 -------- d-----w- C:\Users\User\AppData\Local\{E7D53F3B-231A-4208-8E90-63E45F64E01F}
2013-07-26 12:33:33 -------- d-----w- C:\Users\User\AppData\Local\{F422368A-295F-4541-86D7-48A9EC80739B}
2013-07-25 17:41:23 -------- d-----w- C:\Users\User\AppData\Local\{4FCD2BDE-C15C-4A92-BB4D-051048268330}
2013-07-25 00:08:34 -------- d-----w- C:\Users\User\AppData\Local\{3C802EF1-2618-48AD-8077-ACEC3E61E0F3}
2013-07-23 18:46:30 -------- d-----w- C:\Users\User\AppData\Local\{BC6DC233-9B8F-4B72-A4AE-6421B705ED06}
2013-07-22 22:16:23 -------- d-----w- C:\Users\User\AppData\Local\{C0542F61-43B5-494B-A351-355086F5735D}
2013-07-21 17:12:51 -------- d-----w- C:\Users\User\AppData\Local\{FE633B98-DAEA-4842-B20E-759E18D54655}
2013-07-21 01:59:40 -------- d-----w- C:\Users\User\AppData\Local\{EDAFC625-5BA9-445C-AF51-75837123063A}
2013-07-19 22:44:45 -------- d-----w- C:\Users\User\AppData\Local\{6B76BCFF-BEA7-4989-968D-933C80423C5B}
2013-07-17 17:42:11 -------- d-----w- C:\Users\User\AppData\Local\{925742A5-CEE9-489D-8B87-8C06C861E2FF}
2013-07-16 22:05:24 -------- d-----w- C:\Users\User\AppData\Local\{3E48B55C-350F-41B4-8DD6-C6152DE492B6}
2013-07-16 08:49:42 -------- d-----w- C:\Users\User\AppData\Local\{D587D5D6-D100-428E-8DF7-F4E5A8682AD2}
2013-07-15 17:53:09 -------- d-----w- C:\Users\User\AppData\Local\{C329A1C2-C4F8-40A2-A7F3-8ADDD6E852E3}
2013-07-13 21:32:12 -------- d-----w- C:\Users\User\AppData\Local\{C9E68C7E-6BAC-4107-85E7-AA92EDF8ACD7}
2013-07-12 23:08:55 -------- d-----w- C:\Users\User\AppData\Local\{E15AFE88-6D8D-4E85-8CB2-E86E361483F0}
2013-07-11 16:00:27 -------- d-----w- C:\Users\User\AppData\Local\{4D786F56-A583-4086-B403-A17A5AD65A27}
2013-07-10 19:49:04 -------- d-----w- C:\WINDOWS\System32\MRT
2013-07-10 16:27:48 -------- d-----w- C:\Users\User\AppData\Local\{E21CD5AE-5F33-40F0-80D0-45386744704A}
2013-07-09 18:27:53 -------- d-----w- C:\Users\User\AppData\Local\{1EC5EC08-EF7C-47A1-8E8A-58E583AF4274}
2013-07-07 08:36:03 96168 ----a-w- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
2013-07-07 08:33:08 108968 ----a-w- C:\WINDOWS\System32\WindowsAccessBridge-64.dll
2013-07-07 08:06:43 -------- d-----w- C:\Users\User\AppData\Local\{7BDFC2CD-D94F-41A6-92F8-714AD32DAB7E}
2013-07-05 22:11:42 77824 ----a-w- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FixMouseLMB.exe
2013-07-05 21:49:34 -------- d-----w- C:\Users\User\AppData\Local\{A88FDDDD-7D15-4AB0-8D61-D0E2E15AE133}
2013-07-04 16:48:43 -------- d-----w- C:\Users\User\AppData\Local\{1E71996A-D142-4255-B384-68FE26826DF0}
.
==================== Find3M ====================
.
2013-07-07 08:35:59 867240 ----a-w- C:\WINDOWS\SysWow64\npDeployJava1.dll
2013-07-07 08:35:59 789416 ----a-w- C:\WINDOWS\SysWow64\deployJava1.dll
2013-07-07 08:33:03 972712 ----a-w- C:\WINDOWS\System32\deployJava1.dll
2013-07-07 08:33:03 1093032 ----a-w- C:\WINDOWS\System32\npDeployJava1.dll
2013-06-27 22:04:51 78200 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2013-06-27 22:04:51 693112 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2013-06-21 10:23:16 6496544 ----a-w- C:\WINDOWS\System32\nvcpl.dll
2013-06-21 10:23:16 3514656 ----a-w- C:\WINDOWS\System32\nvsvc64.dll
2013-06-21 10:23:11 884512 ----a-w- C:\WINDOWS\System32\nvvsvc.exe
2013-06-21 10:23:10 63776 ----a-w- C:\WINDOWS\System32\nvshext.dll
2013-06-21 10:23:10 2555680 ----a-w- C:\WINDOWS\System32\nvsvcr.dll
2013-06-21 10:23:10 237856 ----a-w- C:\WINDOWS\System32\nvmctray.dll
2013-06-21 04:16:02 566048 ----a-w- C:\WINDOWS\SysWow64\nvStreaming.exe
2013-06-16 22:41:31 997632 ----a-w- C:\WINDOWS\System32\drivers\ndis.sys
2013-06-16 21:36:12 18960 ----a-w- C:\WINDOWS\System32\drivers\LNonPnP.sys
2013-06-11 23:43:37 1767936 ----a-w- C:\WINDOWS\SysWow64\wininet.dll
2013-06-11 23:43:00 2877440 ----a-w- C:\WINDOWS\SysWow64\jscript9.dll
2013-06-11 23:26:20 2241024 ----a-w- C:\WINDOWS\System32\wininet.dll
2013-06-11 23:25:16 3958784 ----a-w- C:\WINDOWS\System32\jscript9.dll
2013-06-06 19:56:22 21712 ----a-w- C:\WINDOWS\SysWow64\drivers\DrvAgent64.SYS
2013-06-01 12:02:14 998144 ----a-w- C:\WINDOWS\System32\hvloader.exe
2013-06-01 12:02:14 1133824 ----a-w- C:\WINDOWS\System32\hvix64.exe
2013-06-01 12:02:14 1117440 ----a-w- C:\WINDOWS\System32\hvax64.exe
2013-06-01 12:02:14 1084160 ----a-w- C:\WINDOWS\System32\hvloader.efi
2013-06-01 11:54:16 194816 ----a-w- C:\WINDOWS\System32\drivers\sdbus.sys
2013-06-01 11:54:10 125184 ----a-w- C:\WINDOWS\System32\drivers\dumpsd.sys
2013-06-01 11:34:21 2391280 ----a-w- C:\WINDOWS\explorer.exe
2013-06-01 11:33:13 2233600 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2013-06-01 11:29:35 337152 ----a-w- C:\WINDOWS\System32\drivers\USBXHCI.SYS
2013-06-01 11:29:35 213248 ----a-w- C:\WINDOWS\System32\drivers\UCX01000.SYS
2013-06-01 11:26:33 327936 ----a-w- C:\WINDOWS\System32\drivers\volsnap.sys
2013-06-01 11:26:31 6987008 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2013-06-01 10:24:46 2106176 ----a-w- C:\WINDOWS\SysWow64\explorer.exe
2013-06-01 09:25:52 364544 ----a-w- C:\WINDOWS\SysWow64\XpsGdiConverter.dll
2013-06-01 09:25:05 67584 ----a-w- C:\WINDOWS\SysWow64\samlib.dll
2013-06-01 09:25:03 496640 ----a-w- C:\WINDOWS\SysWow64\qedit.dll
2013-06-01 09:24:19 493056 ----a-w- C:\WINDOWS\SysWow64\mscms.dll
2013-06-01 09:24:09 850944 ----a-w- C:\WINDOWS\SysWow64\mfasfsrcsnk.dll
2013-06-01 09:24:09 1453568 ----a-w- C:\WINDOWS\SysWow64\mfcore.dll
2013-06-01 09:23:46 1842176 ----a-w- C:\WINDOWS\SysWow64\dwmcore.dll
2013-06-01 09:23:06 680960 ----a-w- C:\WINDOWS\System32\vds.exe
2013-06-01 09:22:47 80896 ----a-w- C:\WINDOWS\System32\MbaeParserTask.exe
2013-06-01 09:22:33 523264 ----a-w- C:\WINDOWS\System32\XpsGdiConverter.dll
2013-06-01 09:22:33 446976 ----a-w- C:\WINDOWS\System32\wwansvc.dll
2013-06-01 09:22:09 190976 ----a-w- C:\WINDOWS\System32\vdsutil.dll
2013-06-01 09:21:39 729600 ----a-w- C:\WINDOWS\System32\samsrv.dll
2013-06-01 09:21:39 106496 ----a-w- C:\WINDOWS\System32\samlib.dll
2013-06-01 09:21:34 595968 ----a-w- C:\WINDOWS\System32\qedit.dll
2013-06-01 09:20:45 583168 ----a-w- C:\WINDOWS\System32\mscms.dll
2013-06-01 09:20:34 1527808 ----a-w- C:\WINDOWS\System32\mfcore.dll
2013-06-01 09:20:34 1048576 ----a-w- C:\WINDOWS\System32\mfasfsrcsnk.dll
2013-06-01 09:20:04 2219520 ----a-w- C:\WINDOWS\System32\dwmcore.dll
2013-06-01 09:19:58 207872 ----a-w- C:\WINDOWS\System32\DeviceSetupManager.dll
2013-06-01 09:19:42 785408 ----a-w- C:\WINDOWS\System32\audiosrv.dll
2013-06-01 03:08:57 37632 ----a-w- C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
2013-06-01 01:21:46 4040704 ----a-w- C:\WINDOWS\System32\vmwp.exe
2013-06-01 01:02:46 11201536 ----a-w- C:\WINDOWS\System32\vmms.exe
2013-05-30 23:14:23 4036096 ----a-w- C:\WINDOWS\System32\win32k.sys
2013-05-24 22:09:20 1403296 ----a-w- C:\WINDOWS\System32\winload.efi
2013-05-24 22:09:20 1271584 ----a-w- C:\WINDOWS\System32\winload.exe
2013-05-24 22:09:20 1217352 ----a-w- C:\WINDOWS\System32\winresume.efi
2013-05-24 22:09:20 1093904 ----a-w- C:\WINDOWS\System32\winresume.exe
2013-05-23 23:01:46 1300992 ----a-w- C:\WINDOWS\System32\gdi32.dll
2013-05-23 22:27:05 1022464 ----a-w- C:\WINDOWS\SysWow64\gdi32.dll
2013-05-15 22:37:03 44032 ----a-w- C:\WINDOWS\SysWow64\UXInit.dll
2013-05-15 22:35:49 53760 ----a-w- C:\WINDOWS\System32\UXInit.dll
2013-05-15 22:35:47 144384 ----a-w- C:\WINDOWS\System32\tssdisai.dll
2013-05-15 02:25:59 888320 ----a-w- C:\WINDOWS\System32\autochk.exe
2013-05-15 02:25:44 542208 ----a-w- C:\WINDOWS\System32\untfs.dll
2013-05-15 02:24:10 793088 ----a-w- C:\WINDOWS\SysWow64\autochk.exe
2013-05-15 02:24:01 482816 ----a-w- C:\WINDOWS\SysWow64\untfs.dll
2013-05-14 13:14:01 2706432 ----a-w- C:\WINDOWS\System32\mshtml.tlb
2013-05-14 09:23:31 2706432 ----a-w- C:\WINDOWS\SysWow64\mshtml.tlb
2013-05-12 21:42:27 1832224 ----a-w- C:\WINDOWS\System32\nvdispco6432018.dll
2013-05-12 21:42:27 1511712 ----a-w- C:\WINDOWS\System32\nvdispgenco6432018.dll
2013-05-08 03:33:47 1832224 ----a-w- C:\WINDOWS\System32\nvdispco6432014.dll
2013-05-08 03:33:47 1511712 ----a-w- C:\WINDOWS\System32\nvdispgenco6432014.dll
.
============= FINISH: 9:12:10.55 ===============
attach.txt is in the following thread
.
Hopefully you can help!
Liam