I have 2 copies of svchost.exe, the one in c:\windows\SysWow64\svchost.exe is being blocked by bitdefender.
I have run MBAM, Combofix, JRT, Roguekiller etc. Roguekiller is the only program that sees anything but only reports.
Thanks for any ideas.
my MBAM and DDS logs:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 9/23/2014
Scan Time: 2:37:53 PM
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.09.23.10
Rootkit Database: v2014.09.19.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Jim
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 318666
Time Elapsed: 8 min, 7 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
DS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17126
Run by Jim at 14:47:52 on 2014-09-23
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8096.6023 [GMT -7:00]
.
AV: Bitdefender Antivirus Free Edition *Enabled/Updated* {9B5F5313-CAF9-DD97-C460-E778420237B4}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Bitdefender Antivirus Free Edition *Enabled/Updated* {203EB2F7-ECC3-D219-FED0-DC0A39857D09}
.
============== Running Processes ===============
.
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\system32\BtwRSupportService.exe
c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
C:\windows\system32\taskhost.exe
C:\Program Files (x86)\PDF Complete\pdfsvc.exe
C:\windows\system32\Dwm.exe
C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\System32\rundll32.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\System32\WUDFHost.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files (x86)\Juno\exec.exe
C:\Program Files (x86)\Cyberlink\Power2Go\CLMLSvc.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Juno\exec.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\windows\explorer.exe
C:\windows\system32\SearchProtocolHost.exe
C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe
svchost.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\taskeng.exe
C:\windows\SysWow64\svchost.exe
svchost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
BHO: Pop-up Blocker: {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files (x86)\Juno\qsacc\X1IEBHO.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Juno Toolbar Helper: {FE3098B1-04A3-41fd-8CA9-BEA39CB14C87} - C:\Program Files (x86)\Juno\UCReg.dll
uRun: [Juno_uoltray] C:\Program Files (x86)\Juno\exec.exe regrun
mRun: [CLMLServer] "C:\Program Files (x86)\Cyberlink\Power2Go\CLMLSvc.exe"
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: juno.com
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{0CF0B3A7-7A5F-499F-AC1C-C92C9A435074} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{16760264-83FA-4395-A83D-9AC9928FF753} : DHCPNameServer = 192.168.1.1
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
x64-Run: [Persistence] C:\windows\System32\igfxpers.exe
x64-Run: [IgfxTray] C:\windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\windows\System32\hkcmd.exe
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
x64-Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {B34A07DD-C6F7-414A-AE63-01019482EAF0} - msiexec /fu {B34A07DD-C6F7-414A-AE63-01019482EAF0} /qn
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\15csr2rs.default\
FF - prefs.js: browser.startup.homepage - hxxp://hp-desktop.us.msn.com/
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
.
============= SERVICES / DRIVERS ===============
.
R0 avc3;avc3;C:\windows\System32\drivers\avc3.sys [2014-9-23 718840]
R1 bdfwfpf;bdfwfpf;C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys [2014-9-23 121928]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};Power Control [2013/03/10 16:40:40];C:\Program Files (x86)\Cyberlink\PowerDVD8\000.fcl [2009-8-28 146928]
R2 BcmBtRSupport;Bluetooth Driver Management Service;C:\windows\System32\BtwRSupportService.exe [2013-8-9 2252504]
R2 CalendarSynchService;CalendarSynchService;C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [2011-8-16 16384]
R2 gzserv;Bitdefender Antivirus Free Edition;C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe [2014-9-23 69368]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2012-12-6 1128952]
R2 SSPORT;SSPORT;C:\windows\System32\drivers\SSPORT.SYS [2013-3-11 11576]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-12-6 2656536]
R3 avckf;avckf;C:\windows\System32\drivers\avckf.sys [2014-9-23 593144]
R3 bcbtums;Bluetooth USB LD Filter;C:\windows\System32\drivers\bcbtums.sys [2013-8-9 170712]
R3 BTWAMPFL;BTWAMPFL;C:\windows\System32\drivers\btwampfl.sys [2013-8-9 166104]
R3 btwl2cap;Bluetooth L2CAP Service;C:\windows\System32\drivers\btwl2cap.sys [2012-12-6 39464]
R3 gzflt;gzflt;C:\windows\System32\drivers\gzflt.sys [2014-9-23 148696]
R3 RTL8167;Realtek 8167 NT Driver;C:\windows\System32\drivers\Rt64win7.sys [2012-12-6 533096]
R3 tihub3;TI USB3 Hub Service;C:\windows\System32\drivers\tihub3.sys [2011-6-17 131656]
R3 tixhci;TI XHCI Service;C:\windows\System32\drivers\tixhci.sys [2011-6-17 405064]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\windows\System32\ieetwcollector.exe [2014-6-14 111616]
S3 Impcd;Impcd;C:\windows\System32\drivers\Impcd.sys [2012-12-6 158976]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\windows\System32\drivers\rdpvideominiport.sys [2013-3-4 19456]
S3 TsUsbFlt;TsUsbFlt;C:\windows\System32\drivers\TsUsbFlt.sys [2014-8-29 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\System32\drivers\TsUsbGD.sys [2013-3-4 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\System32\Wat\WatAdminSvc.exe [2013-3-4 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2014-09-23 21:16:27 261056 ----a-w- C:\windows\System32\drivers\avchv.sys
2014-09-23 21:15:34 196903 ----a-w- C:\ProgramData\1411506838.bdinstall.bin
2014-09-23 21:14:35 718840 ----a-w- C:\windows\System32\drivers\avc3.sys
2014-09-23 21:14:35 593144 ----a-w- C:\windows\System32\drivers\avckf.sys
2014-09-23 21:14:12 -------- d-----w- C:\Program Files\Bitdefender
2014-09-23 21:14:10 382536 ----a-w- C:\windows\System32\drivers\trufos.sys
2014-09-23 21:14:10 148696 ----a-w- C:\windows\System32\drivers\gzflt.sys
2014-09-23 04:29:25 1721576 ----a-w- C:\windows\System32\WdfCoInstaller01009.dll
2014-09-23 04:29:24 261056 ----a-w- C:\windows\System32\drivers\SET6C69.tmp
2014-09-23 04:28:26 -------- d-----w- C:\Users\Jim\AppData\Roaming\QuickScan
2014-09-23 03:58:50 -------- d-----w- C:\Program Files\Windows XP Mode
2014-09-23 03:55:53 -------- d-----w- C:\ProgramData\Licenses
2014-09-23 03:54:05 -------- d-----w- C:\Program Files (x86)\Trojan Remover
2014-09-23 02:50:47 -------- d-----r- C:\Users\Jim\Virtual Machines
2014-09-23 02:35:52 4096 ----a-w- C:\windows\System32\drivers\pl-PL\vpchbus.sys.mui
2014-09-23 01:49:32 -------- d-----w- C:\Users\Jim\AppData\Roaming\NewspaperDirect
2014-09-23 01:43:45 -------- d-----w- C:\Users\Jim\AppData\Roaming\WinBatch
2014-09-23 00:52:41 -------- d-----w- C:\Program Files (x86)\ESET
2014-09-23 00:41:17 6574592 ----a-w- C:\windows\System32\mstscax.dll
2014-09-23 00:41:17 5694464 ----a-w- C:\windows\SysWow64\mstscax.dll
2014-09-23 00:22:22 -------- d-----w- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-09-23 00:06:57 -------- d-----w- C:\ProgramData\HitmanPro
2014-09-22 22:28:38 122584 ----a-w- C:\windows\System32\drivers\MBAMSwissArmy.sys
2014-09-22 22:28:27 92888 ----a-w- C:\windows\System32\drivers\mbamchameleon.sys
2014-09-22 22:28:27 63704 ----a-w- C:\windows\System32\drivers\mwac.sys
2014-09-22 22:28:27 25816 ----a-w- C:\windows\System32\drivers\mbam.sys
2014-09-22 22:28:27 -------- d-----w- C:\ProgramData\Malwarebytes
2014-09-22 22:28:27 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-22 22:28:17 -------- d-----w- C:\Users\Jim\AppData\Local\Programs
2014-09-22 22:14:08 -------- d-----w- C:\Users\Jim\AppData\Roaming\Roxio Log Files
2014-09-22 22:10:49 -------- d-----w- C:\windows\System32\appmgmt
2014-09-22 22:07:47 536576 ----a-w- C:\windows\SysWow64\sqlite3.dll
2014-09-22 22:06:48 -------- d-----w- C:\AdwCleaner
2014-09-22 21:55:30 37624 ----a-w- C:\windows\System32\drivers\TrueSight.sys
2014-09-22 21:55:28 -------- d-----w- C:\ProgramData\RogueKiller
2014-09-22 21:44:36 -------- d-----w- C:\Program Files\CCleaner
2014-09-22 20:58:53 -------- d-----w- C:\windows\Hewlett-Packard
2014-09-21 23:48:22 -------- d-----w- C:\windows\ERUNT
2014-09-15 15:47:33 0 ----a-w- C:\windows\System32\sxuhrju.dll
2014-09-15 15:47:31 79872 ----a-w- C:\windows\System32\prrinj.dll
2014-09-11 01:44:44 265728 ----a-w- C:\Program Files\Internet Explorer\DiagnosticsHub.ScriptedSandboxPlugin.dll
2014-08-31 00:57:08 -------- d-----w- C:\windows\pss
2014-08-31 00:57:08 -------- d-----w- C:\Users\Jim\AppData\Local\ElevatedDiagnostics
2014-08-29 23:41:30 438272 ----a-w- C:\windows\SysWow64\CNQ2414L.dll
2014-08-29 23:41:28 515072 ----a-w- C:\windows\System32\CNQ2414L.dll
2014-08-29 23:25:23 -------- d-----w- C:\Users\Jim\AppData\Local\NarratorNoteworthy
.
==================== Find3M ====================
.
2014-09-10 16:34:12 71344 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-09-10 16:34:12 701104 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
.
============= FINISH: 14:48:09.44 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 3/3/2013 4:27:34 PM
System Uptime: 9/23/2014 1:50:08 PM (1 hours ago)
.
Motherboard: PEGATRON CORPORATION | | 2AC2
Processor: Intel(R) Pentium(R) CPU G630 @ 2.70GHz | CPU 1 | 2700/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 449 GiB total, 401.982 GiB free.
D: is FIXED (NTFS) - 17 GiB total, 2.071 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: SBRE
Device ID: ROOT\LEGACY_SBRE\0000
Manufacturer:
Name: SBRE
PNP Device ID: ROOT\LEGACY_SBRE\0000
Service: SBRE
.
==== System Restore Points ===================
.
RP83: 9/23/2014 2:13:09 PM - ComboFix created restore point
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Flash Player 15 ActiveX
Adobe Flash Player 15 Plugin
Belarc Advisor 8.3
Bitdefender Antivirus Free Edition
Bluetooth by hp
Bubble Wrap
Canon CanoScan LiDE 110 User Registration
Canon Inkjet Printer/Scanner/Fax Extended Survey Program
Canon MP Navigator EX 4.0
Canon Solution Menu EX
CanoScan LiDE 110 Scanner Driver
CCleaner
CyberLink BD Advisor 2.0
CyberLink Blu-ray Disc Suite
CyberLink MediaShow
CyberLink Power2Go
CyberLink PowerDVD 8
CyberLink PowerProducer
CyberLink YouCam
D3DX10
DirectX for Managed Code Update (Summer 2004)
DVD Decrypter (Remove Only)
ESET Online Scanner v3
Facebook
Hewlett-Packard ACLM.NET v1.1.2.0
Hoyle Card Games
HP Application Assistant
HP Auto
HP Calendar
HP Client Services
HP Customer Experience Enhancements
HP Games
HP Odometer
HP Setup
HP Setup Manager
HP Support Information
HP Vision Hardware Diagnostics
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) Rapid Storage Technology
Junk Mail filter update
Juno Internet
LabelPrint
Malwarebytes Anti-Malware version 2.0.2.1012
Mesh Runtime
Metric Converter
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Mathematics
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft WSE 3.0 Runtime
Mozilla Firefox 32.0.2 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
opensource
PDF Complete Special Edition
PlayReady PC Runtime amd64
PlayReady PC Runtime x86
Realtek High Definition Audio Driver
Recovery Manager
RollerCoaster Tycoon 3: Platinum
Samsung ML-1200 Series
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2894842v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2898855v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2901110v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2931365)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2972215)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft .NET Framework 4 Extended (KB2858302v2)
Security Update for Microsoft .NET Framework 4 Extended (KB2894842v2)
Security Update for Microsoft .NET Framework 4 Extended (KB2901110v2)
Skype™ 5.5
Spot
Tap Tap Bear
TI USB 3.0 Host Controller Driver
TI USB3 Host Driver
TSHostedAppLauncher
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2836939)
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Media Player Firefox Plugin
Windows XP Mode
Zinio Reader 4
.
==== Event Viewer Messages From Past Week ========
.
9/23/2014 2:14:38 PM, Error: Service Control Manager [7000] - The bdfwfpf service failed to start due to the following error: The system cannot find the file specified.
9/23/2014 1:57:24 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
9/23/2014 1:57:03 PM, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
9/23/2014 1:50:33 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SBRE
9/23/2014 1:50:25 PM, Error: Service Control Manager [7000] - The DgiVecp service failed to start due to the following error: The system cannot find the device specified.
9/23/2014 1:49:40 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for DeleteFlag with the following error: Access is denied.
9/23/2014 1:49:39 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied.
.
==== End Of File ===========================
I have run MBAM, Combofix, JRT, Roguekiller etc. Roguekiller is the only program that sees anything but only reports.
Thanks for any ideas.
my MBAM and DDS logs:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 9/23/2014
Scan Time: 2:37:53 PM
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.09.23.10
Rootkit Database: v2014.09.19.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Jim
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 318666
Time Elapsed: 8 min, 7 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
DS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17126
Run by Jim at 14:47:52 on 2014-09-23
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8096.6023 [GMT -7:00]
.
AV: Bitdefender Antivirus Free Edition *Enabled/Updated* {9B5F5313-CAF9-DD97-C460-E778420237B4}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Bitdefender Antivirus Free Edition *Enabled/Updated* {203EB2F7-ECC3-D219-FED0-DC0A39857D09}
.
============== Running Processes ===============
.
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\system32\BtwRSupportService.exe
c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
C:\windows\system32\taskhost.exe
C:\Program Files (x86)\PDF Complete\pdfsvc.exe
C:\windows\system32\Dwm.exe
C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\System32\rundll32.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\System32\WUDFHost.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files (x86)\Juno\exec.exe
C:\Program Files (x86)\Cyberlink\Power2Go\CLMLSvc.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Juno\exec.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\windows\explorer.exe
C:\windows\system32\SearchProtocolHost.exe
C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe
svchost.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\taskeng.exe
C:\windows\SysWow64\svchost.exe
svchost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
BHO: Pop-up Blocker: {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files (x86)\Juno\qsacc\X1IEBHO.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Juno Toolbar Helper: {FE3098B1-04A3-41fd-8CA9-BEA39CB14C87} - C:\Program Files (x86)\Juno\UCReg.dll
uRun: [Juno_uoltray] C:\Program Files (x86)\Juno\exec.exe regrun
mRun: [CLMLServer] "C:\Program Files (x86)\Cyberlink\Power2Go\CLMLSvc.exe"
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: juno.com
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{0CF0B3A7-7A5F-499F-AC1C-C92C9A435074} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{16760264-83FA-4395-A83D-9AC9928FF753} : DHCPNameServer = 192.168.1.1
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
x64-Run: [Persistence] C:\windows\System32\igfxpers.exe
x64-Run: [IgfxTray] C:\windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\windows\System32\hkcmd.exe
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
x64-Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {B34A07DD-C6F7-414A-AE63-01019482EAF0} - msiexec /fu {B34A07DD-C6F7-414A-AE63-01019482EAF0} /qn
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\15csr2rs.default\
FF - prefs.js: browser.startup.homepage - hxxp://hp-desktop.us.msn.com/
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
.
============= SERVICES / DRIVERS ===============
.
R0 avc3;avc3;C:\windows\System32\drivers\avc3.sys [2014-9-23 718840]
R1 bdfwfpf;bdfwfpf;C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys [2014-9-23 121928]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};Power Control [2013/03/10 16:40:40];C:\Program Files (x86)\Cyberlink\PowerDVD8\000.fcl [2009-8-28 146928]
R2 BcmBtRSupport;Bluetooth Driver Management Service;C:\windows\System32\BtwRSupportService.exe [2013-8-9 2252504]
R2 CalendarSynchService;CalendarSynchService;C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [2011-8-16 16384]
R2 gzserv;Bitdefender Antivirus Free Edition;C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe [2014-9-23 69368]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2012-12-6 1128952]
R2 SSPORT;SSPORT;C:\windows\System32\drivers\SSPORT.SYS [2013-3-11 11576]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-12-6 2656536]
R3 avckf;avckf;C:\windows\System32\drivers\avckf.sys [2014-9-23 593144]
R3 bcbtums;Bluetooth USB LD Filter;C:\windows\System32\drivers\bcbtums.sys [2013-8-9 170712]
R3 BTWAMPFL;BTWAMPFL;C:\windows\System32\drivers\btwampfl.sys [2013-8-9 166104]
R3 btwl2cap;Bluetooth L2CAP Service;C:\windows\System32\drivers\btwl2cap.sys [2012-12-6 39464]
R3 gzflt;gzflt;C:\windows\System32\drivers\gzflt.sys [2014-9-23 148696]
R3 RTL8167;Realtek 8167 NT Driver;C:\windows\System32\drivers\Rt64win7.sys [2012-12-6 533096]
R3 tihub3;TI USB3 Hub Service;C:\windows\System32\drivers\tihub3.sys [2011-6-17 131656]
R3 tixhci;TI XHCI Service;C:\windows\System32\drivers\tixhci.sys [2011-6-17 405064]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\windows\System32\ieetwcollector.exe [2014-6-14 111616]
S3 Impcd;Impcd;C:\windows\System32\drivers\Impcd.sys [2012-12-6 158976]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\windows\System32\drivers\rdpvideominiport.sys [2013-3-4 19456]
S3 TsUsbFlt;TsUsbFlt;C:\windows\System32\drivers\TsUsbFlt.sys [2014-8-29 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\System32\drivers\TsUsbGD.sys [2013-3-4 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\System32\Wat\WatAdminSvc.exe [2013-3-4 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2014-09-23 21:16:27 261056 ----a-w- C:\windows\System32\drivers\avchv.sys
2014-09-23 21:15:34 196903 ----a-w- C:\ProgramData\1411506838.bdinstall.bin
2014-09-23 21:14:35 718840 ----a-w- C:\windows\System32\drivers\avc3.sys
2014-09-23 21:14:35 593144 ----a-w- C:\windows\System32\drivers\avckf.sys
2014-09-23 21:14:12 -------- d-----w- C:\Program Files\Bitdefender
2014-09-23 21:14:10 382536 ----a-w- C:\windows\System32\drivers\trufos.sys
2014-09-23 21:14:10 148696 ----a-w- C:\windows\System32\drivers\gzflt.sys
2014-09-23 04:29:25 1721576 ----a-w- C:\windows\System32\WdfCoInstaller01009.dll
2014-09-23 04:29:24 261056 ----a-w- C:\windows\System32\drivers\SET6C69.tmp
2014-09-23 04:28:26 -------- d-----w- C:\Users\Jim\AppData\Roaming\QuickScan
2014-09-23 03:58:50 -------- d-----w- C:\Program Files\Windows XP Mode
2014-09-23 03:55:53 -------- d-----w- C:\ProgramData\Licenses
2014-09-23 03:54:05 -------- d-----w- C:\Program Files (x86)\Trojan Remover
2014-09-23 02:50:47 -------- d-----r- C:\Users\Jim\Virtual Machines
2014-09-23 02:35:52 4096 ----a-w- C:\windows\System32\drivers\pl-PL\vpchbus.sys.mui
2014-09-23 01:49:32 -------- d-----w- C:\Users\Jim\AppData\Roaming\NewspaperDirect
2014-09-23 01:43:45 -------- d-----w- C:\Users\Jim\AppData\Roaming\WinBatch
2014-09-23 00:52:41 -------- d-----w- C:\Program Files (x86)\ESET
2014-09-23 00:41:17 6574592 ----a-w- C:\windows\System32\mstscax.dll
2014-09-23 00:41:17 5694464 ----a-w- C:\windows\SysWow64\mstscax.dll
2014-09-23 00:22:22 -------- d-----w- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-09-23 00:06:57 -------- d-----w- C:\ProgramData\HitmanPro
2014-09-22 22:28:38 122584 ----a-w- C:\windows\System32\drivers\MBAMSwissArmy.sys
2014-09-22 22:28:27 92888 ----a-w- C:\windows\System32\drivers\mbamchameleon.sys
2014-09-22 22:28:27 63704 ----a-w- C:\windows\System32\drivers\mwac.sys
2014-09-22 22:28:27 25816 ----a-w- C:\windows\System32\drivers\mbam.sys
2014-09-22 22:28:27 -------- d-----w- C:\ProgramData\Malwarebytes
2014-09-22 22:28:27 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-22 22:28:17 -------- d-----w- C:\Users\Jim\AppData\Local\Programs
2014-09-22 22:14:08 -------- d-----w- C:\Users\Jim\AppData\Roaming\Roxio Log Files
2014-09-22 22:10:49 -------- d-----w- C:\windows\System32\appmgmt
2014-09-22 22:07:47 536576 ----a-w- C:\windows\SysWow64\sqlite3.dll
2014-09-22 22:06:48 -------- d-----w- C:\AdwCleaner
2014-09-22 21:55:30 37624 ----a-w- C:\windows\System32\drivers\TrueSight.sys
2014-09-22 21:55:28 -------- d-----w- C:\ProgramData\RogueKiller
2014-09-22 21:44:36 -------- d-----w- C:\Program Files\CCleaner
2014-09-22 20:58:53 -------- d-----w- C:\windows\Hewlett-Packard
2014-09-21 23:48:22 -------- d-----w- C:\windows\ERUNT
2014-09-15 15:47:33 0 ----a-w- C:\windows\System32\sxuhrju.dll
2014-09-15 15:47:31 79872 ----a-w- C:\windows\System32\prrinj.dll
2014-09-11 01:44:44 265728 ----a-w- C:\Program Files\Internet Explorer\DiagnosticsHub.ScriptedSandboxPlugin.dll
2014-08-31 00:57:08 -------- d-----w- C:\windows\pss
2014-08-31 00:57:08 -------- d-----w- C:\Users\Jim\AppData\Local\ElevatedDiagnostics
2014-08-29 23:41:30 438272 ----a-w- C:\windows\SysWow64\CNQ2414L.dll
2014-08-29 23:41:28 515072 ----a-w- C:\windows\System32\CNQ2414L.dll
2014-08-29 23:25:23 -------- d-----w- C:\Users\Jim\AppData\Local\NarratorNoteworthy
.
==================== Find3M ====================
.
2014-09-10 16:34:12 71344 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-09-10 16:34:12 701104 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
.
============= FINISH: 14:48:09.44 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 3/3/2013 4:27:34 PM
System Uptime: 9/23/2014 1:50:08 PM (1 hours ago)
.
Motherboard: PEGATRON CORPORATION | | 2AC2
Processor: Intel(R) Pentium(R) CPU G630 @ 2.70GHz | CPU 1 | 2700/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 449 GiB total, 401.982 GiB free.
D: is FIXED (NTFS) - 17 GiB total, 2.071 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: SBRE
Device ID: ROOT\LEGACY_SBRE\0000
Manufacturer:
Name: SBRE
PNP Device ID: ROOT\LEGACY_SBRE\0000
Service: SBRE
.
==== System Restore Points ===================
.
RP83: 9/23/2014 2:13:09 PM - ComboFix created restore point
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Flash Player 15 ActiveX
Adobe Flash Player 15 Plugin
Belarc Advisor 8.3
Bitdefender Antivirus Free Edition
Bluetooth by hp
Bubble Wrap
Canon CanoScan LiDE 110 User Registration
Canon Inkjet Printer/Scanner/Fax Extended Survey Program
Canon MP Navigator EX 4.0
Canon Solution Menu EX
CanoScan LiDE 110 Scanner Driver
CCleaner
CyberLink BD Advisor 2.0
CyberLink Blu-ray Disc Suite
CyberLink MediaShow
CyberLink Power2Go
CyberLink PowerDVD 8
CyberLink PowerProducer
CyberLink YouCam
D3DX10
DirectX for Managed Code Update (Summer 2004)
DVD Decrypter (Remove Only)
ESET Online Scanner v3
Hewlett-Packard ACLM.NET v1.1.2.0
Hoyle Card Games
HP Application Assistant
HP Auto
HP Calendar
HP Client Services
HP Customer Experience Enhancements
HP Games
HP Odometer
HP Setup
HP Setup Manager
HP Support Information
HP Vision Hardware Diagnostics
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) Rapid Storage Technology
Junk Mail filter update
Juno Internet
LabelPrint
Malwarebytes Anti-Malware version 2.0.2.1012
Mesh Runtime
Metric Converter
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Mathematics
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft WSE 3.0 Runtime
Mozilla Firefox 32.0.2 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
opensource
PDF Complete Special Edition
PlayReady PC Runtime amd64
PlayReady PC Runtime x86
Realtek High Definition Audio Driver
Recovery Manager
RollerCoaster Tycoon 3: Platinum
Samsung ML-1200 Series
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2894842v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2898855v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2901110v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2931365)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2972215)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft .NET Framework 4 Extended (KB2858302v2)
Security Update for Microsoft .NET Framework 4 Extended (KB2894842v2)
Security Update for Microsoft .NET Framework 4 Extended (KB2901110v2)
Skype™ 5.5
Spot
Tap Tap Bear
TI USB 3.0 Host Controller Driver
TI USB3 Host Driver
TSHostedAppLauncher
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2836939)
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Media Player Firefox Plugin
Windows XP Mode
Zinio Reader 4
.
==== Event Viewer Messages From Past Week ========
.
9/23/2014 2:14:38 PM, Error: Service Control Manager [7000] - The bdfwfpf service failed to start due to the following error: The system cannot find the file specified.
9/23/2014 1:57:24 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
9/23/2014 1:57:03 PM, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
9/23/2014 1:50:33 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SBRE
9/23/2014 1:50:25 PM, Error: Service Control Manager [7000] - The DgiVecp service failed to start due to the following error: The system cannot find the device specified.
9/23/2014 1:49:40 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for DeleteFlag with the following error: Access is denied.
9/23/2014 1:49:39 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied.
.
==== End Of File ===========================