I ran MBAM as per posting instructions and rebooted after removal.
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.08.04.10
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
deano :: DEANO-HP [administrator]
5/08/2012 1:38:59 PM
mbam-log-2012-08-05 (13-41-59).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 213016
Time elapsed: 2 minute(s), 34 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Windows\Installer\{3db0ba6e-f958-7601-468e-97dfc5d91fb2}\U\00000008.@ (Trojan.Dropper.BCMiner) -> No action taken.
C:\Windows\Installer\{3db0ba6e-f958-7601-468e-97dfc5d91fb2}\U\000000cb.@ (Rootkit.0Access) -> No action taken.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-08-05 14:26:44
Windows 6.1.7601 Service Pack 1
Running: gmer.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c01885fb7858
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c01885fb7858 (not active ControlSet)
---- Files - GMER 1.0.15 ----
File C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5\st[2] 4506 bytes
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
Run by deano at 14:28:18 on 2012-08-05
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.8089.6082 [GMT 8:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Program Files\Tablet\Pen\Pen_TouchService.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k WbioSvcGroup
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\SysWOW64\nlssrv32.exe
C:\Program Files\CyberLink\Shared files\RichVideo64.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskhost.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\HP SimplePass\TouchControl.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files (x86)\HP SimplePass\BioMonitor.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe
C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Windows\SysWOW64\ctfmon.exe
"C:\Windows\SysWOW64\svchost.exe" -k LocalServiceDns
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=127.0.0.1:56990
uURLSearchHooks: YTD Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - C:\Program Files (x86)\YTD Toolbar\IE\6.2\ytdToolbarIE.dll
uURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
mURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
BHO: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO: HP SimplePass Browser Helper Object: {8590886e-ec8c-43c1-a32c-e4c2b0b6395b} - C:\Program Files (x86)\HP SimplePass\IEBHO.DLL
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
BHO: YTD Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - C:\Program Files (x86)\YTD Toolbar\IE\6.2\ytdToolbarIE.dll
TB: HP SimplePass Toolbar: {c98ee38d-21e4-4a50-907d-2b56fec7013e} - C:\Program Files (x86)\HP SimplePass\IEBHO.DLL
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
TB: YTD Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - C:\Program Files (x86)\YTD Toolbar\IE\6.2\ytdToolbarIE.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
uRun: [AdobeBridge]
uRun: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
mRun: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
mRun: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [<NO NAME>]
mRun: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"
mRun: [install.exe] C:\Users\deano\AppData\Local\Temp\install.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Customize Menu - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Fill Forms - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
LSP: mswsock.dll
Trusted Zone: bendigobank.com.au\www
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{588A3F7D-D4BD-4E99-881D-3B16D9F61CD6} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{62F1A5E9-4B3B-44BB-9221-B24DA491008A} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{798B02D3-8942-4826-B841-4056C041C611} : DhcpNameServer = 10.143.147.147 10.143.147.148
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
mASetup: {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} - msiexec /fu {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} /qn
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
BHO-X64: AskBar BHO - No File
BHO-X64: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
BHO-X64: uTorrentControl2 - No File
C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
BHO-X64: RoboForm - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO-X64: HP SimplePass Browser Helper Object: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass\IEBHO.DLL
BHO-X64: TSBHO Class - No File
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
BHO-X64: YTD Toolbar: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YTD Toolbar\IE\6.2\ytdToolbarIE.dll
TB-X64: HP SimplePass Toolbar: {C98EE38D-21E4-4A50-907D-2B56FEC7013E} - C:\Program Files (x86)\HP SimplePass\IEBHO.DLL
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB-X64: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
TB-X64: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
TB-X64: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
TB-X64: YTD Toolbar: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YTD Toolbar\IE\6.2\ytdToolbarIE.dll
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
mRun-x64: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun-x64: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun-x64: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
mRun-x64: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
mRun-x64: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun-x64: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun-x64: [(Default)]
mRun-x64: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"
mRun-x64: [install.exe] C:\Users\deano\AppData\Local\Temp\install.exe
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
IE-X64: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE-X64: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE-X64: {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE-X64: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\deano\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://au.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=
.
============= SERVICES / DRIVERS ===============
.
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\Windows\system32\drivers\iusb3hcs.sys --> C:\Windows\system32\drivers\iusb3hcs.sys [?]
R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --> C:\Windows\system32\DRIVERS\nvpciflt.sys [?]
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-3 63928]
R2 Application Updater;Application Updater;C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe [2012-7-26 794560]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-8-5 44808]
R2 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-7-14 249648]
R2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe [2011-12-11 260424]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-10 86072]
R2 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-2-17 682040]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe --> C:\Windows\system32\Hpservice.exe [?]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-3-5 35200]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-4-20 13592]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2011-12-9 607456]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-4-20 128280]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-4-20 161560]
R2 nlsX86cc;Nalpeiron Licensing Service;C:\Windows\SysWOW64\nlssrv32.exe [2012-7-10 66560]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-4-20 2458944]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS);C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2012-7-8 386344]
R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-7-5 3048136]
R2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2012-7-9 6583160]
R2 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2012-7-9 528760]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-4-20 363800]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\system32\DRIVERS\clwvd.sys --> C:\Windows\system32\DRIVERS\clwvd.sys [?]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\iusb3hub.sys --> C:\Windows\system32\DRIVERS\iusb3hub.sys [?]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\Windows\system32\DRIVERS\iusb3xhc.sys --> C:\Windows\system32\DRIVERS\iusb3xhc.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface ;C:\Windows\system32\drivers\HECIx64.sys --> C:\Windows\system32\drivers\HECIx64.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 SmbDrv;SmbDrv;C:\Windows\system32\DRIVERS\Smb_driver.sys --> C:\Windows\system32\DRIVERS\Smb_driver.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-9-16 195320]
S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\system32\drivers\bcbtums.sys --> C:\Windows\system32\drivers\bcbtums.sys [?]
S3 btwampfl;btwampfl Bluetooth filter driver;\??\C:\Windows\system32\drivers\btwampfl.sys --> C:\Windows\system32\drivers\btwampfl.sys [?]
S3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\system32\DRIVERS\btwdpan.sys --> C:\Windows\system32\DRIVERS\btwdpan.sys [?]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 cphs;Intel(R) Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-4-20 276248]
S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2012-7-19 14216]
S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2012-7-19 8456]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-13 206072]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-7-5 113120]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\system32\DRIVERS\netaapl64.sys --> C:\Windows\system32\DRIVERS\netaapl64.sys [?]
S3 RSP2STOR;Realtek PCIE CardReader Driver - P2;C:\Windows\system32\DRIVERS\RtsP2Stor.sys --> C:\Windows\system32\DRIVERS\RtsP2Stor.sys [?]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TrueService;TrueAPI Service component;C:\Program Files\Common Files\AuthenTec\TrueService.exe [2011-12-9 269640]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2012-08-05 05:37:54 -------- d-----w- C:\Users\deano\AppData\Roaming\Malwarebytes
2012-08-05 05:37:41 -------- d-----w- C:\ProgramData\Malwarebytes
2012-08-05 05:37:40 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-08-05 05:37:40 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-05 04:40:17 -------- d-----w- C:\ProgramData\Blio
2012-08-05 04:39:59 -------- d-----w- C:\Users\deano\AppData\Roaming\Blio
2012-08-05 03:41:22 54072 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2012-08-05 03:41:18 958400 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2012-08-05 03:41:13 71064 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2012-08-05 03:40:58 41224 ----a-w- C:\Windows\avastSS.scr
2012-08-05 03:40:50 -------- d-----w- C:\ProgramData\AVAST Software
2012-08-05 03:40:50 -------- d-----w- C:\Program Files\AVAST Software
2012-08-05 02:46:09 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
2012-08-05 02:06:53 -------- d-----w- C:\Program Files (x86)\Oracle
2012-08-05 02:06:12 772592 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-08-05 02:06:12 687544 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-08-04 03:22:57 -------- d-----w- C:\Program Files\Easypano
2012-08-04 02:30:59 82432 ----a-w- C:\Windows\SysWow64\msxml4r.dll
2012-08-04 02:30:59 44544 ----a-w- C:\Windows\SysWow64\msxml4a.dll
2012-08-04 02:30:59 1233920 ----a-w- C:\Windows\SysWow64\msxml4.dll
2012-08-04 02:30:41 -------- d-----w- C:\Program Files (x86)\Easypano
2012-08-03 06:14:42 9133488 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{78AE9436-F37F-4960-8E19-9D39420BB35C}\mpengine.dll
2012-07-31 01:30:49 -------- d-----w- C:\Program Files (x86)\YTD Toolbar
2012-07-31 01:30:49 -------- d-----w- C:\Program Files (x86)\Common Files\Spigot
2012-07-31 01:30:49 -------- d-----w- C:\Program Files (x86)\Application Updater
2012-07-30 10:39:56 -------- d-----w- C:\Users\deano\AppData\Local\Kolor
2012-07-30 10:38:35 -------- d-----w- C:\Program Files\Kolor
2012-07-30 02:26:15 -------- d-----w- C:\ProgramData\YTD Video Downloader
2012-07-28 19:05:23 -------- d-----w- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2012-07-28 01:58:39 -------- d-----w- C:\Windows\WICCodecs
2012-07-24 02:37:48 -------- d-----w- C:\ProgramData\RedGiant
2012-07-24 02:24:23 -------- d-----w- C:\PSCS5PLUGINPATH64BIT
2012-07-23 01:22:48 -------- d-----w- C:\Program Files\indii.org
2012-07-21 04:01:25 -------- d-----w- C:\Program Files (x86)\GeniuXPhotoEFX3
2012-07-19 04:41:55 9096 ----a-w- C:\Windows\System32\EuGdiDrv.sys
2012-07-19 04:41:55 86408 ----a-w- C:\Windows\SysWow64\setupempdrv03.exe
2012-07-19 04:41:55 8456 ----a-w- C:\Windows\SysWow64\EuGdiDrv.sys
2012-07-19 04:41:55 3316736 ----a-w- C:\Windows\System32\BootMan.exe
2012-07-19 04:41:55 2468520 ----a-w- C:\Windows\SysWow64\BootMan.exe
2012-07-19 04:41:55 19840 ----a-w- C:\Windows\SysWow64\EuEpmGdi.dll
2012-07-19 04:41:55 16776 ----a-w- C:\Windows\System32\epmntdrv.sys
2012-07-19 04:41:55 16256 ----a-w- C:\Windows\System32\EuEpmGdi.dll
2012-07-19 04:41:55 14216 ----a-w- C:\Windows\SysWow64\epmntdrv.sys
2012-07-19 04:41:55 100232 ----a-w- C:\Windows\System32\setupempdrvx64.exe
2012-07-19 04:41:51 -------- d-----w- C:\Program Files (x86)\EaseUS
2012-07-19 01:41:17 -------- d-----w- C:\Program Files (x86)\Disk Heal
2012-07-16 07:32:30 -------- d-----w- C:\Users\deano\AppData\Roaming\HandBrake
2012-07-16 07:21:41 -------- d-----w- C:\Program Files\Handbrake
2012-07-16 07:02:10 -------- d-----w- C:\Program Files\MediaInfo
2012-07-16 06:27:30 -------- d-----w- C:\Users\deano\AppData\Roaming\PictureCode
2012-07-15 03:48:49 -------- d-----w- C:\Users\deano\AppData\Roaming\FastStone
2012-07-11 23:43:03 -------- d-----w- C:\Users\deano\AppData\Roaming\Boilsoft
2012-07-11 23:43:02 -------- d-----w- C:\Program Files (x86)\Boilsoft Video Converter
2012-07-11 19:04:34 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-11 18:18:04 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2012-07-11 18:18:04 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2012-07-11 18:18:04 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-07-11 18:18:04 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-07-11 18:18:04 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-07-11 18:18:04 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-07-11 07:07:32 696832 ----a-w- C:\Windows\System32\xvidcore.dll
2012-07-11 07:07:32 645632 ----a-w- C:\Windows\SysWow64\xvidcore.dll
2012-07-11 07:07:32 255488 ----a-w- C:\Windows\System32\xvidvfw.dll
2012-07-11 07:07:32 240640 ----a-w- C:\Windows\SysWow64\xvidvfw.dll
2012-07-11 07:07:32 173568 ----a-w- C:\Windows\System32\xvid.ax
2012-07-11 07:07:32 153088 ----a-w- C:\Windows\SysWow64\xvid.ax
2012-07-11 07:07:32 -------- d-----w- C:\Program Files (x86)\Xvid
2012-07-11 07:05:38 -------- d-----w- C:\Program Files\DivX
2012-07-11 07:05:33 -------- d-----w- C:\Program Files (x86)\Common Files\DivX Shared
2012-07-11 07:03:29 -------- d-----w- C:\Program Files (x86)\DivX
2012-07-11 07:02:02 -------- d-----w- C:\ProgramData\DivX
2012-07-11 06:26:51 -------- d-----w- C:\Users\deano\AppData\Roaming\Jasc
2012-07-11 06:21:41 -------- d-----w- C:\Program Files (x86)\Jasc Software Inc
2012-07-11 01:43:08 -------- d-----w- C:\Users\deano\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2012-07-11 01:03:55 28672 ----a-w- C:\Windows\SysWow64\AVEQT.dll
2012-07-11 01:03:55 129024 ----a-w- C:\Windows\SysWow64\AVERM.dll
2012-07-11 00:57:45 421888 ----a-w- C:\Windows\SysWow64\Mpeg2DecFilter.ax
2012-07-11 00:57:45 376832 ----a-w- C:\Windows\SysWow64\MpegSplitter.ax
2012-07-11 00:57:43 -------- d-----w- C:\Program Files (x86)\Allok Video Splitter
2012-07-10 07:03:57 -------- d-----w- C:\Users\deano\AppData\Local\HP
2012-07-10 05:26:02 -------- d-----w- C:\Users\deano\AppData\Roaming\AKVIS LLC
2012-07-10 04:57:32 -------- d-----w- C:\ProgramData\Digital Film Tools
2012-07-10 04:57:31 -------- d-----w- C:\Program Files\Digital Film Tools
2012-07-10 02:33:34 -------- d-----w- C:\Program Files\Pano2VR
2012-07-10 02:11:46 -------- d-----w- C:\Users\deano\AppData\Roaming\GardenGnomeSoftware
2012-07-10 00:12:46 -------- d-----w- C:\Program Files\onOne Software
2012-07-09 23:11:44 -------- d-----w- C:\Users\deano\AppData\Roaming\Digital Film Tools
2012-07-09 21:50:21 66560 ----a-w- C:\Windows\SysWow64\nlssrv32.exe
2012-07-09 21:50:21 66560 ----a-w- C:\Windows\System32\nlssrv32.exe
2012-07-09 21:24:48 -------- d-----w- C:\Users\deano\OnOne Perfect Resize 7.0.6 Pro + Keygen{H33T}{Easypath}
2012-07-09 09:05:35 -------- d-----w- C:\ProgramData\CanonIJ
2012-07-09 04:43:49 -------- d-----w- C:\Users\deano\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
2012-07-09 04:36:38 -------- d-----w- C:\Users\deano\AppData\Roaming\Wacom
2012-07-09 04:36:32 -------- d-----w- C:\ProgramData\Wacom
2012-07-09 04:36:02 -------- d-----w- C:\Program Files (x86)\Bamboo Dock
2012-07-09 04:31:29 -------- d-----w- C:\Users\deano\AppData\Roaming\WTablet
2012-07-09 04:31:28 1326456 ----a-w- C:\Windows\System32\Pen_Touch_Tablet.dll
2012-07-09 04:31:28 1107832 ----a-w- C:\Windows\SysWow64\Pen_Touch_Tablet.dll
2012-07-09 04:31:23 -------- d-----w- C:\Program Files (x86)\TabletPlugins
2012-07-09 04:31:07 12848 ----a-w- C:\Windows\System32\drivers\wacommousefilter.sys
2012-07-09 04:31:01 16168 ----a-w- C:\Windows\System32\drivers\wacomvhid.sys
2012-07-09 04:30:59 1401208 ----a-w- C:\Windows\System32\Wintab32.dll
2012-07-09 04:30:59 1392504 ----a-w- C:\Windows\System32\WacomMT.dll
2012-07-09 04:30:59 1156472 ----a-w- C:\Windows\SysWow64\Wintab32.dll
2012-07-09 04:30:59 1152888 ----a-w- C:\Windows\SysWow64\WacomMT.dll
2012-07-09 04:30:58 1665400 ----a-w- C:\Windows\System32\Pen_Tablet.dll
2012-07-09 04:30:58 1369464 ----a-w- C:\Windows\SysWow64\Pen_Tablet.dll
2012-07-09 04:30:55 -------- d-----w- C:\Program Files\Tablet
2012-07-09 04:27:30 -------- d--h--w- C:\ProgramData\CanonIJMyPrinter
2012-07-09 04:26:51 -------- d-----w- C:\ProgramData\CanonIJPLM
2012-07-09 04:26:12 -------- d-----w- C:\ProgramData\Canon IJ Network Tool
2012-07-09 04:26:06 323584 ----a-w- C:\Windows\SysWow64\CNC_ATL.dll
2012-07-09 04:26:06 15872 ----a-w- C:\Windows\SysWow64\CNHMCA.dll
2012-07-09 04:26:06 114688 ----a-w- C:\Windows\SysWow64\CNC_ATU.dll
2012-07-09 04:25:35 -------- d-----w- C:\ProgramData\CanonIJWSpt
2012-07-09 04:25:35 -------- d-----w- C:\Program Files\Common Files\CANON
2012-07-09 04:24:44 -------- d-----w- C:\Program Files\Canon
2012-07-09 04:24:31 98816 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPPAT.DLL
2012-07-09 04:24:31 30208 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPDAT.DLL
2012-07-09 04:24:07 385536 ----a-w- C:\Windows\System32\CNMLMAT.DLL
2012-07-09 04:23:59 256000 ----a-w- C:\Windows\System32\CNMIUAT.DLL
2012-07-09 04:23:34 38400 ----a-w- C:\Windows\System32\CNMN6UI.DLL
2012-07-09 04:23:34 355840 ----a-w- C:\Windows\System32\CNMN6PPM.DLL
2012-07-09 04:23:34 -------- d-----w- C:\Windows\System32\STRING
2012-07-09 04:15:19 -------- d-----w- C:\Program Files (x86)\Canon
2012-07-09 02:54:14 -------- d-----w- C:\Program Files\CCleaner
2012-07-08 12:48:17 -------- d-----w- C:\ProgramData\SmartSound Software Inc
2012-07-08 12:48:16 -------- d-----w- C:\ProgramData\eSellerate
2012-07-08 12:48:16 -------- d-----w- C:\Program Files (x86)\SmartSound Software
2012-07-08 10:28:10 -------- d-----w- C:\ProgramData\YouTube Downloader
2012-07-08 10:26:33 -------- d-----w- C:\Program Files (x86)\YouTube Downloader
2012-07-08 10:22:57 -------- dc-h--w- C:\ProgramData\{654BBB15-6EFB-44E9-9E8B-F75DAF1B3B4C}
2012-07-08 10:22:12 -------- d-----w- C:\Users\deano\AppData\Local\PackageAware
2012-07-08 06:30:56 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-07-08 06:30:56 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-07-08 06:30:56 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-07-08 06:30:56 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-07-08 06:30:56 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-07-08 06:30:56 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-07-08 06:30:56 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-07-08 01:40:08 -------- d-----w- C:\ProgramData\Image Trends Inc
2012-07-08 01:38:48 -------- d-----w- C:\AuthLog
2012-07-08 01:38:33 -------- d-----w- C:\Program Files (x86)\Image Trends Inc
2012-07-07 07:00:42 -------- d-----w- C:\Program Files (x86)\AKVIS
2012-07-07 06:06:52 4608 ----a-w- C:\Windows\SysWow64\ColorEfexPro4FC64.dll
2012-07-07 06:03:06 -------- d-----w- C:\Users\deano\AppData\Roaming\ThePluginSite
2012-07-07 05:37:47 -------- d-----w- C:\Users\deano\AppData\Roaming\Auto FX Software
2012-07-07 05:37:17 90112 ----a-w- C:\Windows\unvise32.exe
2012-07-07 04:57:18 -------- d-----w- C:\Users\deano\AppData\Local\Alien Skin
2012-07-07 04:43:50 -------- d-----w- C:\Program Files\Imagenomic
2012-07-07 03:07:58 -------- d-----w- C:\Program Files (x86)\FastStone Capture
2012-07-07 01:02:36 21264 ----a-w- C:\Windows\System32\drivers\Smb_driver.sys
2012-07-07 01:01:26 95544 ----a-w- C:\Windows\System32\bcmwlcoi.dll
2012-07-07 01:01:26 4747328 ----a-w- C:\Windows\System32\drivers\BCMWL664.SYS
2012-07-07 01:01:25 3617792 ----a-w- C:\Windows\System32\bcmihvui64.dll
2012-07-07 01:01:22 3952640 ----a-w- C:\Windows\System32\bcmihvsrv64.dll
2012-07-06 21:31:57 -------- d-----w- C:\Users\deano\AppData\Roaming\ts3overlay
2012-07-06 21:30:13 -------- d-----w- C:\Users\deano\AppData\Roaming\TS3Client
.
==================== Find3M ====================
.
2012-07-28 23:33:17 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-28 23:33:17 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-07-07 06:32:36 4608 ----a-w- C:\Windows\System32\Viveza2FC64.dll
2012-07-06 23:54:59 3072 ----a-w- C:\Windows\System32\Viveza2FC32.dll
2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-02 12:12:17 2311680 ----a-w- C:\Windows\System32\jscript9.dll
2012-06-02 12:05:28 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-06-02 12:04:50 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-06-02 12:01:40 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-06-02 11:57:08 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-02 08:33:25 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-02 08:25:08 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-02 08:25:03 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-02 08:20:33 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-02 08:16:52 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-02 07:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 07:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-05-31 04:25:12 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-05-21 08:47:06 264064 ----a-w- C:\Coloriage.8bf
.
============= FINISH: 14:28:41.66 ===============
.
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.08.04.10
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
deano :: DEANO-HP [administrator]
5/08/2012 1:38:59 PM
mbam-log-2012-08-05 (13-41-59).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 213016
Time elapsed: 2 minute(s), 34 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Windows\Installer\{3db0ba6e-f958-7601-468e-97dfc5d91fb2}\U\00000008.@ (Trojan.Dropper.BCMiner) -> No action taken.
C:\Windows\Installer\{3db0ba6e-f958-7601-468e-97dfc5d91fb2}\U\000000cb.@ (Rootkit.0Access) -> No action taken.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-08-05 14:26:44
Windows 6.1.7601 Service Pack 1
Running: gmer.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c01885fb7858
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c01885fb7858 (not active ControlSet)
---- Files - GMER 1.0.15 ----
File C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5\st[2] 4506 bytes
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
Run by deano at 14:28:18 on 2012-08-05
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.8089.6082 [GMT 8:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Program Files\Tablet\Pen\Pen_TouchService.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k WbioSvcGroup
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\SysWOW64\nlssrv32.exe
C:\Program Files\CyberLink\Shared files\RichVideo64.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskhost.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\HP SimplePass\TouchControl.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files (x86)\HP SimplePass\BioMonitor.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe
C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Windows\SysWOW64\ctfmon.exe
"C:\Windows\SysWOW64\svchost.exe" -k LocalServiceDns
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=127.0.0.1:56990
uURLSearchHooks: YTD Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - C:\Program Files (x86)\YTD Toolbar\IE\6.2\ytdToolbarIE.dll
uURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
mURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
BHO: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO: HP SimplePass Browser Helper Object: {8590886e-ec8c-43c1-a32c-e4c2b0b6395b} - C:\Program Files (x86)\HP SimplePass\IEBHO.DLL
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
BHO: YTD Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - C:\Program Files (x86)\YTD Toolbar\IE\6.2\ytdToolbarIE.dll
TB: HP SimplePass Toolbar: {c98ee38d-21e4-4a50-907d-2b56fec7013e} - C:\Program Files (x86)\HP SimplePass\IEBHO.DLL
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
TB: YTD Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - C:\Program Files (x86)\YTD Toolbar\IE\6.2\ytdToolbarIE.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
uRun: [AdobeBridge]
uRun: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
mRun: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
mRun: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [<NO NAME>]
mRun: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"
mRun: [install.exe] C:\Users\deano\AppData\Local\Temp\install.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Customize Menu - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Fill Forms - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
LSP: mswsock.dll
Trusted Zone: bendigobank.com.au\www
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{588A3F7D-D4BD-4E99-881D-3B16D9F61CD6} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{62F1A5E9-4B3B-44BB-9221-B24DA491008A} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{798B02D3-8942-4826-B841-4056C041C611} : DhcpNameServer = 10.143.147.147 10.143.147.148
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
mASetup: {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} - msiexec /fu {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} /qn
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
BHO-X64: AskBar BHO - No File
BHO-X64: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
BHO-X64: uTorrentControl2 - No File
C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
BHO-X64: RoboForm - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO-X64: HP SimplePass Browser Helper Object: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass\IEBHO.DLL
BHO-X64: TSBHO Class - No File
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
BHO-X64: YTD Toolbar: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YTD Toolbar\IE\6.2\ytdToolbarIE.dll
TB-X64: HP SimplePass Toolbar: {C98EE38D-21E4-4A50-907D-2B56FEC7013E} - C:\Program Files (x86)\HP SimplePass\IEBHO.DLL
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB-X64: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
TB-X64: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
TB-X64: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
TB-X64: YTD Toolbar: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YTD Toolbar\IE\6.2\ytdToolbarIE.dll
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
mRun-x64: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun-x64: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun-x64: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
mRun-x64: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
mRun-x64: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun-x64: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun-x64: [(Default)]
mRun-x64: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"
mRun-x64: [install.exe] C:\Users\deano\AppData\Local\Temp\install.exe
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
IE-X64: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE-X64: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE-X64: {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE-X64: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\deano\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://au.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=
.
============= SERVICES / DRIVERS ===============
.
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\Windows\system32\drivers\iusb3hcs.sys --> C:\Windows\system32\drivers\iusb3hcs.sys [?]
R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --> C:\Windows\system32\DRIVERS\nvpciflt.sys [?]
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-3 63928]
R2 Application Updater;Application Updater;C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe [2012-7-26 794560]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-8-5 44808]
R2 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-7-14 249648]
R2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe [2011-12-11 260424]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-10 86072]
R2 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-2-17 682040]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe --> C:\Windows\system32\Hpservice.exe [?]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-3-5 35200]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-4-20 13592]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2011-12-9 607456]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-4-20 128280]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-4-20 161560]
R2 nlsX86cc;Nalpeiron Licensing Service;C:\Windows\SysWOW64\nlssrv32.exe [2012-7-10 66560]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-4-20 2458944]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS);C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2012-7-8 386344]
R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-7-5 3048136]
R2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2012-7-9 6583160]
R2 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2012-7-9 528760]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-4-20 363800]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\system32\DRIVERS\clwvd.sys --> C:\Windows\system32\DRIVERS\clwvd.sys [?]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\iusb3hub.sys --> C:\Windows\system32\DRIVERS\iusb3hub.sys [?]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\Windows\system32\DRIVERS\iusb3xhc.sys --> C:\Windows\system32\DRIVERS\iusb3xhc.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface ;C:\Windows\system32\drivers\HECIx64.sys --> C:\Windows\system32\drivers\HECIx64.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 SmbDrv;SmbDrv;C:\Windows\system32\DRIVERS\Smb_driver.sys --> C:\Windows\system32\DRIVERS\Smb_driver.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-9-16 195320]
S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\system32\drivers\bcbtums.sys --> C:\Windows\system32\drivers\bcbtums.sys [?]
S3 btwampfl;btwampfl Bluetooth filter driver;\??\C:\Windows\system32\drivers\btwampfl.sys --> C:\Windows\system32\drivers\btwampfl.sys [?]
S3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\system32\DRIVERS\btwdpan.sys --> C:\Windows\system32\DRIVERS\btwdpan.sys [?]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 cphs;Intel(R) Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-4-20 276248]
S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2012-7-19 14216]
S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2012-7-19 8456]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-13 206072]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-7-5 113120]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\system32\DRIVERS\netaapl64.sys --> C:\Windows\system32\DRIVERS\netaapl64.sys [?]
S3 RSP2STOR;Realtek PCIE CardReader Driver - P2;C:\Windows\system32\DRIVERS\RtsP2Stor.sys --> C:\Windows\system32\DRIVERS\RtsP2Stor.sys [?]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TrueService;TrueAPI Service component;C:\Program Files\Common Files\AuthenTec\TrueService.exe [2011-12-9 269640]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2012-08-05 05:37:54 -------- d-----w- C:\Users\deano\AppData\Roaming\Malwarebytes
2012-08-05 05:37:41 -------- d-----w- C:\ProgramData\Malwarebytes
2012-08-05 05:37:40 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-08-05 05:37:40 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-05 04:40:17 -------- d-----w- C:\ProgramData\Blio
2012-08-05 04:39:59 -------- d-----w- C:\Users\deano\AppData\Roaming\Blio
2012-08-05 03:41:22 54072 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2012-08-05 03:41:18 958400 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2012-08-05 03:41:13 71064 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2012-08-05 03:40:58 41224 ----a-w- C:\Windows\avastSS.scr
2012-08-05 03:40:50 -------- d-----w- C:\ProgramData\AVAST Software
2012-08-05 03:40:50 -------- d-----w- C:\Program Files\AVAST Software
2012-08-05 02:46:09 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
2012-08-05 02:06:53 -------- d-----w- C:\Program Files (x86)\Oracle
2012-08-05 02:06:12 772592 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-08-05 02:06:12 687544 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-08-04 03:22:57 -------- d-----w- C:\Program Files\Easypano
2012-08-04 02:30:59 82432 ----a-w- C:\Windows\SysWow64\msxml4r.dll
2012-08-04 02:30:59 44544 ----a-w- C:\Windows\SysWow64\msxml4a.dll
2012-08-04 02:30:59 1233920 ----a-w- C:\Windows\SysWow64\msxml4.dll
2012-08-04 02:30:41 -------- d-----w- C:\Program Files (x86)\Easypano
2012-08-03 06:14:42 9133488 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{78AE9436-F37F-4960-8E19-9D39420BB35C}\mpengine.dll
2012-07-31 01:30:49 -------- d-----w- C:\Program Files (x86)\YTD Toolbar
2012-07-31 01:30:49 -------- d-----w- C:\Program Files (x86)\Common Files\Spigot
2012-07-31 01:30:49 -------- d-----w- C:\Program Files (x86)\Application Updater
2012-07-30 10:39:56 -------- d-----w- C:\Users\deano\AppData\Local\Kolor
2012-07-30 10:38:35 -------- d-----w- C:\Program Files\Kolor
2012-07-30 02:26:15 -------- d-----w- C:\ProgramData\YTD Video Downloader
2012-07-28 19:05:23 -------- d-----w- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2012-07-28 01:58:39 -------- d-----w- C:\Windows\WICCodecs
2012-07-24 02:37:48 -------- d-----w- C:\ProgramData\RedGiant
2012-07-24 02:24:23 -------- d-----w- C:\PSCS5PLUGINPATH64BIT
2012-07-23 01:22:48 -------- d-----w- C:\Program Files\indii.org
2012-07-21 04:01:25 -------- d-----w- C:\Program Files (x86)\GeniuXPhotoEFX3
2012-07-19 04:41:55 9096 ----a-w- C:\Windows\System32\EuGdiDrv.sys
2012-07-19 04:41:55 86408 ----a-w- C:\Windows\SysWow64\setupempdrv03.exe
2012-07-19 04:41:55 8456 ----a-w- C:\Windows\SysWow64\EuGdiDrv.sys
2012-07-19 04:41:55 3316736 ----a-w- C:\Windows\System32\BootMan.exe
2012-07-19 04:41:55 2468520 ----a-w- C:\Windows\SysWow64\BootMan.exe
2012-07-19 04:41:55 19840 ----a-w- C:\Windows\SysWow64\EuEpmGdi.dll
2012-07-19 04:41:55 16776 ----a-w- C:\Windows\System32\epmntdrv.sys
2012-07-19 04:41:55 16256 ----a-w- C:\Windows\System32\EuEpmGdi.dll
2012-07-19 04:41:55 14216 ----a-w- C:\Windows\SysWow64\epmntdrv.sys
2012-07-19 04:41:55 100232 ----a-w- C:\Windows\System32\setupempdrvx64.exe
2012-07-19 04:41:51 -------- d-----w- C:\Program Files (x86)\EaseUS
2012-07-19 01:41:17 -------- d-----w- C:\Program Files (x86)\Disk Heal
2012-07-16 07:32:30 -------- d-----w- C:\Users\deano\AppData\Roaming\HandBrake
2012-07-16 07:21:41 -------- d-----w- C:\Program Files\Handbrake
2012-07-16 07:02:10 -------- d-----w- C:\Program Files\MediaInfo
2012-07-16 06:27:30 -------- d-----w- C:\Users\deano\AppData\Roaming\PictureCode
2012-07-15 03:48:49 -------- d-----w- C:\Users\deano\AppData\Roaming\FastStone
2012-07-11 23:43:03 -------- d-----w- C:\Users\deano\AppData\Roaming\Boilsoft
2012-07-11 23:43:02 -------- d-----w- C:\Program Files (x86)\Boilsoft Video Converter
2012-07-11 19:04:34 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-11 18:18:04 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2012-07-11 18:18:04 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2012-07-11 18:18:04 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-07-11 18:18:04 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-07-11 18:18:04 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-07-11 18:18:04 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-07-11 07:07:32 696832 ----a-w- C:\Windows\System32\xvidcore.dll
2012-07-11 07:07:32 645632 ----a-w- C:\Windows\SysWow64\xvidcore.dll
2012-07-11 07:07:32 255488 ----a-w- C:\Windows\System32\xvidvfw.dll
2012-07-11 07:07:32 240640 ----a-w- C:\Windows\SysWow64\xvidvfw.dll
2012-07-11 07:07:32 173568 ----a-w- C:\Windows\System32\xvid.ax
2012-07-11 07:07:32 153088 ----a-w- C:\Windows\SysWow64\xvid.ax
2012-07-11 07:07:32 -------- d-----w- C:\Program Files (x86)\Xvid
2012-07-11 07:05:38 -------- d-----w- C:\Program Files\DivX
2012-07-11 07:05:33 -------- d-----w- C:\Program Files (x86)\Common Files\DivX Shared
2012-07-11 07:03:29 -------- d-----w- C:\Program Files (x86)\DivX
2012-07-11 07:02:02 -------- d-----w- C:\ProgramData\DivX
2012-07-11 06:26:51 -------- d-----w- C:\Users\deano\AppData\Roaming\Jasc
2012-07-11 06:21:41 -------- d-----w- C:\Program Files (x86)\Jasc Software Inc
2012-07-11 01:43:08 -------- d-----w- C:\Users\deano\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2012-07-11 01:03:55 28672 ----a-w- C:\Windows\SysWow64\AVEQT.dll
2012-07-11 01:03:55 129024 ----a-w- C:\Windows\SysWow64\AVERM.dll
2012-07-11 00:57:45 421888 ----a-w- C:\Windows\SysWow64\Mpeg2DecFilter.ax
2012-07-11 00:57:45 376832 ----a-w- C:\Windows\SysWow64\MpegSplitter.ax
2012-07-11 00:57:43 -------- d-----w- C:\Program Files (x86)\Allok Video Splitter
2012-07-10 07:03:57 -------- d-----w- C:\Users\deano\AppData\Local\HP
2012-07-10 05:26:02 -------- d-----w- C:\Users\deano\AppData\Roaming\AKVIS LLC
2012-07-10 04:57:32 -------- d-----w- C:\ProgramData\Digital Film Tools
2012-07-10 04:57:31 -------- d-----w- C:\Program Files\Digital Film Tools
2012-07-10 02:33:34 -------- d-----w- C:\Program Files\Pano2VR
2012-07-10 02:11:46 -------- d-----w- C:\Users\deano\AppData\Roaming\GardenGnomeSoftware
2012-07-10 00:12:46 -------- d-----w- C:\Program Files\onOne Software
2012-07-09 23:11:44 -------- d-----w- C:\Users\deano\AppData\Roaming\Digital Film Tools
2012-07-09 21:50:21 66560 ----a-w- C:\Windows\SysWow64\nlssrv32.exe
2012-07-09 21:50:21 66560 ----a-w- C:\Windows\System32\nlssrv32.exe
2012-07-09 21:24:48 -------- d-----w- C:\Users\deano\OnOne Perfect Resize 7.0.6 Pro + Keygen{H33T}{Easypath}
2012-07-09 09:05:35 -------- d-----w- C:\ProgramData\CanonIJ
2012-07-09 04:43:49 -------- d-----w- C:\Users\deano\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
2012-07-09 04:36:38 -------- d-----w- C:\Users\deano\AppData\Roaming\Wacom
2012-07-09 04:36:32 -------- d-----w- C:\ProgramData\Wacom
2012-07-09 04:36:02 -------- d-----w- C:\Program Files (x86)\Bamboo Dock
2012-07-09 04:31:29 -------- d-----w- C:\Users\deano\AppData\Roaming\WTablet
2012-07-09 04:31:28 1326456 ----a-w- C:\Windows\System32\Pen_Touch_Tablet.dll
2012-07-09 04:31:28 1107832 ----a-w- C:\Windows\SysWow64\Pen_Touch_Tablet.dll
2012-07-09 04:31:23 -------- d-----w- C:\Program Files (x86)\TabletPlugins
2012-07-09 04:31:07 12848 ----a-w- C:\Windows\System32\drivers\wacommousefilter.sys
2012-07-09 04:31:01 16168 ----a-w- C:\Windows\System32\drivers\wacomvhid.sys
2012-07-09 04:30:59 1401208 ----a-w- C:\Windows\System32\Wintab32.dll
2012-07-09 04:30:59 1392504 ----a-w- C:\Windows\System32\WacomMT.dll
2012-07-09 04:30:59 1156472 ----a-w- C:\Windows\SysWow64\Wintab32.dll
2012-07-09 04:30:59 1152888 ----a-w- C:\Windows\SysWow64\WacomMT.dll
2012-07-09 04:30:58 1665400 ----a-w- C:\Windows\System32\Pen_Tablet.dll
2012-07-09 04:30:58 1369464 ----a-w- C:\Windows\SysWow64\Pen_Tablet.dll
2012-07-09 04:30:55 -------- d-----w- C:\Program Files\Tablet
2012-07-09 04:27:30 -------- d--h--w- C:\ProgramData\CanonIJMyPrinter
2012-07-09 04:26:51 -------- d-----w- C:\ProgramData\CanonIJPLM
2012-07-09 04:26:12 -------- d-----w- C:\ProgramData\Canon IJ Network Tool
2012-07-09 04:26:06 323584 ----a-w- C:\Windows\SysWow64\CNC_ATL.dll
2012-07-09 04:26:06 15872 ----a-w- C:\Windows\SysWow64\CNHMCA.dll
2012-07-09 04:26:06 114688 ----a-w- C:\Windows\SysWow64\CNC_ATU.dll
2012-07-09 04:25:35 -------- d-----w- C:\ProgramData\CanonIJWSpt
2012-07-09 04:25:35 -------- d-----w- C:\Program Files\Common Files\CANON
2012-07-09 04:24:44 -------- d-----w- C:\Program Files\Canon
2012-07-09 04:24:31 98816 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPPAT.DLL
2012-07-09 04:24:31 30208 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPDAT.DLL
2012-07-09 04:24:07 385536 ----a-w- C:\Windows\System32\CNMLMAT.DLL
2012-07-09 04:23:59 256000 ----a-w- C:\Windows\System32\CNMIUAT.DLL
2012-07-09 04:23:34 38400 ----a-w- C:\Windows\System32\CNMN6UI.DLL
2012-07-09 04:23:34 355840 ----a-w- C:\Windows\System32\CNMN6PPM.DLL
2012-07-09 04:23:34 -------- d-----w- C:\Windows\System32\STRING
2012-07-09 04:15:19 -------- d-----w- C:\Program Files (x86)\Canon
2012-07-09 02:54:14 -------- d-----w- C:\Program Files\CCleaner
2012-07-08 12:48:17 -------- d-----w- C:\ProgramData\SmartSound Software Inc
2012-07-08 12:48:16 -------- d-----w- C:\ProgramData\eSellerate
2012-07-08 12:48:16 -------- d-----w- C:\Program Files (x86)\SmartSound Software
2012-07-08 10:28:10 -------- d-----w- C:\ProgramData\YouTube Downloader
2012-07-08 10:26:33 -------- d-----w- C:\Program Files (x86)\YouTube Downloader
2012-07-08 10:22:57 -------- dc-h--w- C:\ProgramData\{654BBB15-6EFB-44E9-9E8B-F75DAF1B3B4C}
2012-07-08 10:22:12 -------- d-----w- C:\Users\deano\AppData\Local\PackageAware
2012-07-08 06:30:56 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-07-08 06:30:56 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-07-08 06:30:56 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-07-08 06:30:56 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-07-08 06:30:56 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-07-08 06:30:56 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-07-08 06:30:56 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-07-08 01:40:08 -------- d-----w- C:\ProgramData\Image Trends Inc
2012-07-08 01:38:48 -------- d-----w- C:\AuthLog
2012-07-08 01:38:33 -------- d-----w- C:\Program Files (x86)\Image Trends Inc
2012-07-07 07:00:42 -------- d-----w- C:\Program Files (x86)\AKVIS
2012-07-07 06:06:52 4608 ----a-w- C:\Windows\SysWow64\ColorEfexPro4FC64.dll
2012-07-07 06:03:06 -------- d-----w- C:\Users\deano\AppData\Roaming\ThePluginSite
2012-07-07 05:37:47 -------- d-----w- C:\Users\deano\AppData\Roaming\Auto FX Software
2012-07-07 05:37:17 90112 ----a-w- C:\Windows\unvise32.exe
2012-07-07 04:57:18 -------- d-----w- C:\Users\deano\AppData\Local\Alien Skin
2012-07-07 04:43:50 -------- d-----w- C:\Program Files\Imagenomic
2012-07-07 03:07:58 -------- d-----w- C:\Program Files (x86)\FastStone Capture
2012-07-07 01:02:36 21264 ----a-w- C:\Windows\System32\drivers\Smb_driver.sys
2012-07-07 01:01:26 95544 ----a-w- C:\Windows\System32\bcmwlcoi.dll
2012-07-07 01:01:26 4747328 ----a-w- C:\Windows\System32\drivers\BCMWL664.SYS
2012-07-07 01:01:25 3617792 ----a-w- C:\Windows\System32\bcmihvui64.dll
2012-07-07 01:01:22 3952640 ----a-w- C:\Windows\System32\bcmihvsrv64.dll
2012-07-06 21:31:57 -------- d-----w- C:\Users\deano\AppData\Roaming\ts3overlay
2012-07-06 21:30:13 -------- d-----w- C:\Users\deano\AppData\Roaming\TS3Client
.
==================== Find3M ====================
.
2012-07-28 23:33:17 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-28 23:33:17 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-07-07 06:32:36 4608 ----a-w- C:\Windows\System32\Viveza2FC64.dll
2012-07-06 23:54:59 3072 ----a-w- C:\Windows\System32\Viveza2FC32.dll
2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-02 12:12:17 2311680 ----a-w- C:\Windows\System32\jscript9.dll
2012-06-02 12:05:28 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-06-02 12:04:50 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-06-02 12:01:40 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-06-02 11:57:08 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-02 08:33:25 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-02 08:25:08 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-02 08:25:03 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-02 08:20:33 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-02 08:16:52 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-02 07:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 07:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-05-31 04:25:12 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-05-21 08:47:06 264064 ----a-w- C:\Coloriage.8bf
.
============= FINISH: 14:28:41.66 ===============
.