Combofix worked OK.
ComboFix 15-02-09.01 - MIKE 02/12/2015 23:18:31.1.4 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3564.1340 [GMT -6:00]
Running from: c:\users\MIKE\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: Microsoft Security Essentials *Enabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Spybot - Search and Destroy *Disabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\MIKE\AppData\Local\Adobe\downloader.dll
c:\users\MIKE\AppData\Local\Adobe\gccheck.exe
c:\users\MIKE\AppData\Local\Adobe\gtbcheck.exe
c:\users\MIKE\AppData\Local\assembly\tmp
c:\windows\system32\AdobePDF.dll
c:\windows\wininit.ini
E:\install.exe
G:\Autorun.inf
G:\setup.exe
I:\Autorun.inf
I:\Setup.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NETHFDRV
-------\Service_CltMngSvc
.
.
((((((((((((((((((((((((( Files Created from 2015-01-13 to 2015-02-13 )))))))))))))))))))))))))))))))
.
.
2015-02-13 05:23 . 2015-02-13 05:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-02-13 03:37 . 2015-02-13 03:53 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-02-13 03:11 . 2015-02-13 03:22 35064 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2015-02-13 03:11 . 2015-02-13 03:11 -------- d-----w- c:\programdata\RogueKiller
2015-02-13 03:04 . 2015-02-13 03:04 39464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6ED336A9-2A7B-403C-8F57-37024D575ADC}\MpKsl7e8d1ddc.sys
2015-02-13 02:52 . 2015-02-13 03:05 62576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6ED336A9-2A7B-403C-8F57-37024D575ADC}\offreg.dll
2015-02-13 02:34 . 2015-02-13 02:34 -------- d--h--w- c:\windows\PIF
2015-02-13 02:18 . 2015-02-13 02:18 -------- d-----w- c:\programdata\explauncher
2015-02-13 02:07 . 2015-02-13 02:07 -------- dc----w- c:\windows\system32\DRVSTORE
2015-02-13 02:07 . 2013-02-18 19:59 27136 ----a-w- c:\windows\system32\drivers\hotcore3.sys
2015-02-13 01:52 . 2015-02-13 02:02 -------- d-----w- c:\users\MIKE\AppData\Roaming\dlg
2015-02-13 01:47 . 2015-02-13 01:47 -------- d-----w- c:\programdata\launcher
2015-02-12 23:53 . 2014-12-02 11:01 9054624 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6ED336A9-2A7B-403C-8F57-37024D575ADC}\mpengine.dll
2015-02-12 21:39 . 2015-02-12 21:47 -------- d-----w- C:\FRST
2015-02-12 04:14 . 2015-02-12 04:14 -------- d-----w- c:\users\MIKE\AppData\Roaming\com.adobe.formscentral.FormsCentralForAcrobat
2015-02-12 04:12 . 2015-02-12 04:12 -------- d-----w- c:\programdata\{77089FCB-278A-4E4D-960C-3ECF468EED41}
2015-02-11 19:42 . 2014-09-16 17:44 908840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BA3F2B3D-386D-46DE-91D5-203D9E389B36}\gapaengine.dll
2015-02-11 19:42 . 2014-12-02 11:01 9054624 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-02-11 16:37 . 2015-01-23 03:00 1810944 ----a-w- c:\windows\system32\jscript9.dll
2015-02-05 21:01 . 2015-01-23 10:40 73816 ----a-w- c:\program files\Mozilla Firefox\wow_helper.exe
2015-02-05 21:01 . 2015-01-23 10:38 922168 ----a-w- c:\program files\Mozilla Firefox\uninstall\helper.exe
2015-02-05 21:01 . 2015-01-23 10:38 49776 ----a-w- c:\program files\Mozilla Firefox\browser\components\browsercomps.dll
2015-02-05 16:09 . 2014-10-18 01:33 3209728 ----a-w- c:\windows\system32\mf.dll
2015-02-05 16:09 . 2014-07-07 01:40 103424 ----a-w- c:\windows\system32\mfps.dll
2015-02-05 16:09 . 2014-07-07 01:39 50176 ----a-w- c:\windows\system32\rrinstaller.exe
2015-02-05 16:09 . 2014-07-07 01:39 23040 ----a-w- c:\windows\system32\mfpmp.exe
2015-02-05 16:09 . 2014-07-07 01:37 2048 ----a-w- c:\windows\system32\mferror.dll
2015-02-05 15:58 . 2014-10-14 01:50 2363904 ----a-w- c:\windows\system32\msi.dll
2015-02-05 15:58 . 2014-11-11 01:32 74752 ----a-w- c:\windows\system32\drivers\tdx.sys
2015-02-05 15:58 . 2014-11-08 02:45 2048 ----a-w- c:\windows\system32\tzres.dll
2015-02-05 15:58 . 2014-10-30 01:45 155136 ----a-w- c:\windows\system32\charmap.exe
2015-02-05 15:58 . 2014-10-03 01:45 1177088 ----a-w- c:\windows\system32\WsmSvc.dll
2015-02-05 15:58 . 2014-10-03 01:45 248832 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll
2015-02-05 15:58 . 2014-10-03 01:45 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll
2015-02-05 15:58 . 2014-10-03 01:45 145920 ----a-w- c:\windows\system32\WsmAuto.dll
2015-02-05 15:58 . 2014-10-03 01:44 198656 ----a-w- c:\windows\system32\WSManHTTPConfig.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-02-13 03:37 . 2014-07-04 00:56 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-02-13 03:37 . 2014-07-04 00:56 82648 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-02-12 04:10 . 2014-01-12 00:11 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-02-12 04:10 . 2014-01-12 00:11 701616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-12-31 11:13 . 2014-01-12 04:57 249488 ------w- c:\windows\system32\MpSigStub.exe
2014-12-19 02:43 . 2015-01-13 21:48 164864 ----a-w- c:\windows\system32\profsvc.dll
2014-12-19 01:34 . 2015-01-13 21:48 116224 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2014-12-13 00:12 . 2014-09-19 17:31 1291464 ----a-w- c:\windows\system32\nvspbridge.dll
2014-12-13 00:12 . 2014-04-18 15:05 2210040 ----a-w- c:\windows\system32\nvspcap.dll
2014-12-11 17:47 . 2015-01-13 21:48 74240 ----a-w- c:\windows\system32\TSWbPrxy.exe
2014-12-06 03:50 . 2015-01-13 21:48 242688 ----a-w- c:\windows\system32\nlasvc.dll
2014-11-22 10:46 . 2014-12-18 20:40 32912 ----a-w- c:\windows\system32\drivers\nvvad32v.sys
2014-11-22 10:46 . 2014-04-18 15:04 32400 ----a-w- c:\windows\system32\nvaudcap32v.dll
2014-11-21 12:14 . 2014-07-04 00:56 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-11-21 12:14 . 2014-07-04 00:56 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-11-15 20:46 . 2014-11-15 20:46 239224 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2014-11-15 20:46 . 2014-03-11 14:52 95408 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-01-12 03:50 222832 ----a-w- c:\users\MIKE\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811_1\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-01-12 03:50 222832 ----a-w- c:\users\MIKE\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811_1\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-01-12 03:50 222832 ----a-w- c:\users\MIKE\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811_1\SkyDriveShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"="c:\users\MIKE\AppData\Local\Akamai\netsession_win.exe" [2014-10-30 4673432]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2014-05-09 6983168]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2015-02-06 110160]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2012-06-11 10996368]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2012-01-26 1058400]
"FUFAXRCV"="c:\program files\Epson Software\FAX Utility\FUFAXRCV.exe" [2012-02-29 502912]
"FUFAXSTM"="c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe" [2012-02-29 863360]
"RUSB3MON"="c:\program files\Rocketfish\USB 3.0 Host Controller Driver\Application\rusb3mon.exe" [2011-09-20 115048]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\\isuspm.exe" [2010-05-21 324976]
"PaperPort PTD"="d:\paperport\PaperPort\pptd40nt.exe" [2011-10-29 38824]
"IndexSearch"="d:\paperport\PaperPort\IndexSearch.exe" [2011-10-29 51120]
"PPort14reminder"="d:\paperport\PaperPort\Ereg\Ereg.exe" [2011-05-16 333088]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2014-02-28 558496]
"Acrobat Assistant 8.0"="d:\adobe pro xi\Acrobat\Acrotray.exe" [2014-12-03 3498728]
"Launchpad"="c:\program files\Windows Server\Bin\Launchpad.exe" [2012-11-03 1099360]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2013-07-31 2296600]
"NvBackend"="c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-12-13 2531472]
"ShadowPlay"="c:\windows\system32\nvspcap.dll" [2014-12-13 2210040]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2015-01-30 978520]
"SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2013-07-25 5624784]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2013-06-13 19:31 64280 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 MpKsl1a28ae8c;MpKsl1a28ae8c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6ED336A9-2A7B-403C-8F57-37024D575ADC}\MpKsl1a28ae8c.sys [2015-02-13 39464]
R2 initMonitor;Windows Server Initialization Service;c:\program files\Windows Server\Bin\SharedServiceHost.exe [2011-03-02 30592]
R3 FlexRadioSystemDAXService_Audio;DAX RX Audio (WDM);c:\windows\system32\DRIVERS\audiodax.sys [2014-06-05 43776]
R3 FlexRadioSystemDAXService_IQ;DAX RX IQ (WDM);c:\windows\system32\DRIVERS\iqdax.sys [2014-06-05 43648]
R3 FlexRadioSystemDAXService_TX;DAX TX Audio (WDM);c:\windows\system32\DRIVERS\txdax.sys [2014-06-05 43648]
R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [2010-07-29 25112]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2015-01-30 284472]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2014-01-21 1343400]
R4 SqmProviderSvc;Windows Server SQM Service;c:\program files\Windows Server\Bin\SharedServiceHost.exe [2011-03-02 30592]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [2013-02-18 27136]
S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys [2013-12-03 26248]
S1 MpKsl7e8d1ddc;MpKsl7e8d1ddc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6ED336A9-2A7B-403C-8F57-37024D575ADC}\MpKsl7e8d1ddc.sys [2015-02-13 39464]
S1 Uim_Vim;UIM Virtual Image Plugin;c:\windows\system32\Drivers\Uim_Vim.sys [2013-02-18 283600]
S2 arXfrSvc;Windows Server Media Center TV Archive Transfer Service;c:\program files\Windows Server\Bin\Microsoft.HomeServer.Archive.TransferService.exe [2012-11-03 84576]
S2 ClickToRunSvc;Microsoft Office ClickToRun Service;c:\program files\Microsoft Office 15\ClientX86\OfficeClickToRun.exe [2014-11-11 1679536]
S2 EPSON_PM_RPCV4_05;EPSON V3 Service4(05);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE [2012-02-27 142432]
S2 EpsonCustomerParticipation;EpsonCustomerParticipation;c:\program files\EPSON\EpsonCustomerParticipation\EPCP.exe [2012-05-10 539744]
S2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc.exe [2011-12-12 122000]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 915600]
S2 HealthAlertsSvc;Windows Server Health Service;c:\program files\Windows Server\Bin\SharedServiceHost.exe [2011-03-02 30592]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-04-20 462048]
S2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2014-09-19 14624]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
S2 LANConfig;Windows Server LAN Configuration;c:\program files\Windows Server\Bin\LANConfigSvc.exe [2011-03-02 27520]
S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-11-21 1871160]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [2014-11-21 969016]
S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2014-11-15 95408]
S2 NotificationsProviderSvc;Windows Server Notifications Provider Service;c:\program files\Windows Server\Bin\SharedServiceHost.exe [2011-03-02 30592]
S2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 18186896]
S2 PDFProFiltSrvPP;PDFProFiltSrvPP;d:\paperport\PaperPort\PDFProFiltSrvPP.exe [2011-10-29 219496]
S2 providers_system;Windows Server Download Service;c:\program files\Windows Server\Bin\SharedServiceHost.exe [2011-03-02 30592]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-10-15 3921880]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-09-20 1042272]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-09-13 171416]
S2 ServiceProviderRegistry;Windows Server Service Provider Registry;c:\program files\Windows Server\Bin\ProviderRegistryService.exe [2012-11-03 41568]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-11-12 410768]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 365376]
S2 WhsMcClient;Windows Server Media Center Client Service;c:\program files\Windows Server\Bin\WhsMcClient.exe [2012-11-03 98400]
S2 WSConnectorUpdate;Windows Server Connector Update;c:\program files\Windows Server\Bin\WSConnectorUpdate.exe [2011-03-02 162176]
S2 WSS_ComputerBackupProviderSvc;Windows Server Client Computer Backup Provider Service;c:\program files\Windows Server\Bin\SharedServiceHost.exe [2011-03-02 30592]
S3 BackupReader;BackupReader;c:\windows\system32\DRIVERS\BackupReader.sys [2011-03-02 53504]
ComboFix 15-02-09.01 - MIKE 02/12/2015 23:18:31.1.4 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3564.1340 [GMT -6:00]
Running from: c:\users\MIKE\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: Microsoft Security Essentials *Enabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Spybot - Search and Destroy *Disabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\MIKE\AppData\Local\Adobe\downloader.dll
c:\users\MIKE\AppData\Local\Adobe\gccheck.exe
c:\users\MIKE\AppData\Local\Adobe\gtbcheck.exe
c:\users\MIKE\AppData\Local\assembly\tmp
c:\windows\system32\AdobePDF.dll
c:\windows\wininit.ini
E:\install.exe
G:\Autorun.inf
G:\setup.exe
I:\Autorun.inf
I:\Setup.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NETHFDRV
-------\Service_CltMngSvc
.
.
((((((((((((((((((((((((( Files Created from 2015-01-13 to 2015-02-13 )))))))))))))))))))))))))))))))
.
.
2015-02-13 05:23 . 2015-02-13 05:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-02-13 03:37 . 2015-02-13 03:53 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-02-13 03:11 . 2015-02-13 03:22 35064 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2015-02-13 03:11 . 2015-02-13 03:11 -------- d-----w- c:\programdata\RogueKiller
2015-02-13 03:04 . 2015-02-13 03:04 39464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6ED336A9-2A7B-403C-8F57-37024D575ADC}\MpKsl7e8d1ddc.sys
2015-02-13 02:52 . 2015-02-13 03:05 62576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6ED336A9-2A7B-403C-8F57-37024D575ADC}\offreg.dll
2015-02-13 02:34 . 2015-02-13 02:34 -------- d--h--w- c:\windows\PIF
2015-02-13 02:18 . 2015-02-13 02:18 -------- d-----w- c:\programdata\explauncher
2015-02-13 02:07 . 2015-02-13 02:07 -------- dc----w- c:\windows\system32\DRVSTORE
2015-02-13 02:07 . 2013-02-18 19:59 27136 ----a-w- c:\windows\system32\drivers\hotcore3.sys
2015-02-13 01:52 . 2015-02-13 02:02 -------- d-----w- c:\users\MIKE\AppData\Roaming\dlg
2015-02-13 01:47 . 2015-02-13 01:47 -------- d-----w- c:\programdata\launcher
2015-02-12 23:53 . 2014-12-02 11:01 9054624 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6ED336A9-2A7B-403C-8F57-37024D575ADC}\mpengine.dll
2015-02-12 21:39 . 2015-02-12 21:47 -------- d-----w- C:\FRST
2015-02-12 04:14 . 2015-02-12 04:14 -------- d-----w- c:\users\MIKE\AppData\Roaming\com.adobe.formscentral.FormsCentralForAcrobat
2015-02-12 04:12 . 2015-02-12 04:12 -------- d-----w- c:\programdata\{77089FCB-278A-4E4D-960C-3ECF468EED41}
2015-02-11 19:42 . 2014-09-16 17:44 908840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BA3F2B3D-386D-46DE-91D5-203D9E389B36}\gapaengine.dll
2015-02-11 19:42 . 2014-12-02 11:01 9054624 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-02-11 16:37 . 2015-01-23 03:00 1810944 ----a-w- c:\windows\system32\jscript9.dll
2015-02-05 21:01 . 2015-01-23 10:40 73816 ----a-w- c:\program files\Mozilla Firefox\wow_helper.exe
2015-02-05 21:01 . 2015-01-23 10:38 922168 ----a-w- c:\program files\Mozilla Firefox\uninstall\helper.exe
2015-02-05 21:01 . 2015-01-23 10:38 49776 ----a-w- c:\program files\Mozilla Firefox\browser\components\browsercomps.dll
2015-02-05 16:09 . 2014-10-18 01:33 3209728 ----a-w- c:\windows\system32\mf.dll
2015-02-05 16:09 . 2014-07-07 01:40 103424 ----a-w- c:\windows\system32\mfps.dll
2015-02-05 16:09 . 2014-07-07 01:39 50176 ----a-w- c:\windows\system32\rrinstaller.exe
2015-02-05 16:09 . 2014-07-07 01:39 23040 ----a-w- c:\windows\system32\mfpmp.exe
2015-02-05 16:09 . 2014-07-07 01:37 2048 ----a-w- c:\windows\system32\mferror.dll
2015-02-05 15:58 . 2014-10-14 01:50 2363904 ----a-w- c:\windows\system32\msi.dll
2015-02-05 15:58 . 2014-11-11 01:32 74752 ----a-w- c:\windows\system32\drivers\tdx.sys
2015-02-05 15:58 . 2014-11-08 02:45 2048 ----a-w- c:\windows\system32\tzres.dll
2015-02-05 15:58 . 2014-10-30 01:45 155136 ----a-w- c:\windows\system32\charmap.exe
2015-02-05 15:58 . 2014-10-03 01:45 1177088 ----a-w- c:\windows\system32\WsmSvc.dll
2015-02-05 15:58 . 2014-10-03 01:45 248832 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll
2015-02-05 15:58 . 2014-10-03 01:45 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll
2015-02-05 15:58 . 2014-10-03 01:45 145920 ----a-w- c:\windows\system32\WsmAuto.dll
2015-02-05 15:58 . 2014-10-03 01:44 198656 ----a-w- c:\windows\system32\WSManHTTPConfig.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-02-13 03:37 . 2014-07-04 00:56 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-02-13 03:37 . 2014-07-04 00:56 82648 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-02-12 04:10 . 2014-01-12 00:11 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-02-12 04:10 . 2014-01-12 00:11 701616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-12-31 11:13 . 2014-01-12 04:57 249488 ------w- c:\windows\system32\MpSigStub.exe
2014-12-19 02:43 . 2015-01-13 21:48 164864 ----a-w- c:\windows\system32\profsvc.dll
2014-12-19 01:34 . 2015-01-13 21:48 116224 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2014-12-13 00:12 . 2014-09-19 17:31 1291464 ----a-w- c:\windows\system32\nvspbridge.dll
2014-12-13 00:12 . 2014-04-18 15:05 2210040 ----a-w- c:\windows\system32\nvspcap.dll
2014-12-11 17:47 . 2015-01-13 21:48 74240 ----a-w- c:\windows\system32\TSWbPrxy.exe
2014-12-06 03:50 . 2015-01-13 21:48 242688 ----a-w- c:\windows\system32\nlasvc.dll
2014-11-22 10:46 . 2014-12-18 20:40 32912 ----a-w- c:\windows\system32\drivers\nvvad32v.sys
2014-11-22 10:46 . 2014-04-18 15:04 32400 ----a-w- c:\windows\system32\nvaudcap32v.dll
2014-11-21 12:14 . 2014-07-04 00:56 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-11-21 12:14 . 2014-07-04 00:56 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-11-15 20:46 . 2014-11-15 20:46 239224 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2014-11-15 20:46 . 2014-03-11 14:52 95408 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-01-12 03:50 222832 ----a-w- c:\users\MIKE\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811_1\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-01-12 03:50 222832 ----a-w- c:\users\MIKE\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811_1\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-01-12 03:50 222832 ----a-w- c:\users\MIKE\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811_1\SkyDriveShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"="c:\users\MIKE\AppData\Local\Akamai\netsession_win.exe" [2014-10-30 4673432]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2014-05-09 6983168]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2015-02-06 110160]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2012-06-11 10996368]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2012-01-26 1058400]
"FUFAXRCV"="c:\program files\Epson Software\FAX Utility\FUFAXRCV.exe" [2012-02-29 502912]
"FUFAXSTM"="c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe" [2012-02-29 863360]
"RUSB3MON"="c:\program files\Rocketfish\USB 3.0 Host Controller Driver\Application\rusb3mon.exe" [2011-09-20 115048]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\\isuspm.exe" [2010-05-21 324976]
"PaperPort PTD"="d:\paperport\PaperPort\pptd40nt.exe" [2011-10-29 38824]
"IndexSearch"="d:\paperport\PaperPort\IndexSearch.exe" [2011-10-29 51120]
"PPort14reminder"="d:\paperport\PaperPort\Ereg\Ereg.exe" [2011-05-16 333088]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2014-02-28 558496]
"Acrobat Assistant 8.0"="d:\adobe pro xi\Acrobat\Acrotray.exe" [2014-12-03 3498728]
"Launchpad"="c:\program files\Windows Server\Bin\Launchpad.exe" [2012-11-03 1099360]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2013-07-31 2296600]
"NvBackend"="c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-12-13 2531472]
"ShadowPlay"="c:\windows\system32\nvspcap.dll" [2014-12-13 2210040]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2015-01-30 978520]
"SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2013-07-25 5624784]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2013-06-13 19:31 64280 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 MpKsl1a28ae8c;MpKsl1a28ae8c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6ED336A9-2A7B-403C-8F57-37024D575ADC}\MpKsl1a28ae8c.sys [2015-02-13 39464]
R2 initMonitor;Windows Server Initialization Service;c:\program files\Windows Server\Bin\SharedServiceHost.exe [2011-03-02 30592]
R3 FlexRadioSystemDAXService_Audio;DAX RX Audio (WDM);c:\windows\system32\DRIVERS\audiodax.sys [2014-06-05 43776]
R3 FlexRadioSystemDAXService_IQ;DAX RX IQ (WDM);c:\windows\system32\DRIVERS\iqdax.sys [2014-06-05 43648]
R3 FlexRadioSystemDAXService_TX;DAX TX Audio (WDM);c:\windows\system32\DRIVERS\txdax.sys [2014-06-05 43648]
R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [2010-07-29 25112]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2015-01-30 284472]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2014-01-21 1343400]
R4 SqmProviderSvc;Windows Server SQM Service;c:\program files\Windows Server\Bin\SharedServiceHost.exe [2011-03-02 30592]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [2013-02-18 27136]
S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys [2013-12-03 26248]
S1 MpKsl7e8d1ddc;MpKsl7e8d1ddc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6ED336A9-2A7B-403C-8F57-37024D575ADC}\MpKsl7e8d1ddc.sys [2015-02-13 39464]
S1 Uim_Vim;UIM Virtual Image Plugin;c:\windows\system32\Drivers\Uim_Vim.sys [2013-02-18 283600]
S2 arXfrSvc;Windows Server Media Center TV Archive Transfer Service;c:\program files\Windows Server\Bin\Microsoft.HomeServer.Archive.TransferService.exe [2012-11-03 84576]
S2 ClickToRunSvc;Microsoft Office ClickToRun Service;c:\program files\Microsoft Office 15\ClientX86\OfficeClickToRun.exe [2014-11-11 1679536]
S2 EPSON_PM_RPCV4_05;EPSON V3 Service4(05);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE [2012-02-27 142432]
S2 EpsonCustomerParticipation;EpsonCustomerParticipation;c:\program files\EPSON\EpsonCustomerParticipation\EPCP.exe [2012-05-10 539744]
S2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc.exe [2011-12-12 122000]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 915600]
S2 HealthAlertsSvc;Windows Server Health Service;c:\program files\Windows Server\Bin\SharedServiceHost.exe [2011-03-02 30592]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-04-20 462048]
S2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2014-09-19 14624]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
S2 LANConfig;Windows Server LAN Configuration;c:\program files\Windows Server\Bin\LANConfigSvc.exe [2011-03-02 27520]
S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-11-21 1871160]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [2014-11-21 969016]
S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2014-11-15 95408]
S2 NotificationsProviderSvc;Windows Server Notifications Provider Service;c:\program files\Windows Server\Bin\SharedServiceHost.exe [2011-03-02 30592]
S2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 18186896]
S2 PDFProFiltSrvPP;PDFProFiltSrvPP;d:\paperport\PaperPort\PDFProFiltSrvPP.exe [2011-10-29 219496]
S2 providers_system;Windows Server Download Service;c:\program files\Windows Server\Bin\SharedServiceHost.exe [2011-03-02 30592]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-10-15 3921880]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-09-20 1042272]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-09-13 171416]
S2 ServiceProviderRegistry;Windows Server Service Provider Registry;c:\program files\Windows Server\Bin\ProviderRegistryService.exe [2012-11-03 41568]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-11-12 410768]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 365376]
S2 WhsMcClient;Windows Server Media Center Client Service;c:\program files\Windows Server\Bin\WhsMcClient.exe [2012-11-03 98400]
S2 WSConnectorUpdate;Windows Server Connector Update;c:\program files\Windows Server\Bin\WSConnectorUpdate.exe [2011-03-02 162176]
S2 WSS_ComputerBackupProviderSvc;Windows Server Client Computer Backup Provider Service;c:\program files\Windows Server\Bin\SharedServiceHost.exe [2011-03-02 30592]
S3 BackupReader;BackupReader;c:\windows\system32\DRIVERS\BackupReader.sys [2011-03-02 53504]