Hi, I have popup malware on my computer and hoping that someone can help me.
DDS log followed by Attach log below
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537
Run by [removed] at 18:01:47 on 2013-06-08
Microsoft Windows 8 6.2.9200.0.1252.61.1033.18.16324.14061 [GMT 9.5:30]
.
AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Aware *Disabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
.
============== Running Processes ===============
.
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\nvvsvc.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\IDT\WDM\STacSV64.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\ProgramData\eSafe\eGdpSvc.exe
C:\windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\windows\system32\svchost.exe -k apphost
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\windows\system32\BtwRSupportService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\windows\system32\dashost.exe
C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\System32\dwm.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\windows\system32\nvvsvc.exe
C:\windows\system32\taskhostex.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\windows\Explorer.EXE
C:\Program Files\IDT\WDM\Beats64.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe
C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR_HIDList.exe
C:\windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
C:\PROGRA~2\AD-AWA~1\AdAware.exe
C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteUser.exe
C:\Program Files\Microsoft Office 15\root\office15\outlook.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://securedsearch2.lavasoft.com/inde ... 51AC69F814
uDefault_Page_URL = hxxp://www.portaldosites.com/?utm_sourc ... 1369913946
mStart Page = hxxp://www.portaldosites.com/?utm_sourc ... 1369913946
mDefault_Page_URL = hxxp://www.portaldosites.com/?utm_sourc ... 1369913946
mWinlogon: Userinit = userinit.exe
BHO: WebCake: {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} -
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\office15\OCHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL
BHO: Lyrics Kid: {BA146CF5-1875-4EA8-AAEA-A90142FC2EC9} - C:\Program Files (x86)\LyricsKid\lkid.dll
BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\office15\GROOVEEX.DLL
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
uRun: [Desk 365] "C:\Program Files (x86)\Desk 365\desk365.exe" /autorun
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
mRun: [CLMLServer_For_P2G8] "c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
mRun: [CLVirtualDrive] "c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
mRun: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe
mRun: [BATINDICATORHL] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR_HIDList.exe
mRun: [OSDTool] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"
mRun: [Search Protection] C:\ProgramData\Search Protection\SearchProtection.exe
mRun: [Ad-Aware Antivirus] "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
IE: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\office15\OCHelper.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{4DAEF880-29E2-4B5A-AF4F-F345B1B8CFF6} : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{4DAEF880-29E2-4B5A-AF4F-F345B1B8CFF6}\24967605F6E646535383430303 : DHCPNameServer = 10.0.0.138
TCP: Interfaces\{D89C42DA-19E8-4186-AE96-88F8206B9154} : DHCPNameServer = 192.168.2.1
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mStart Page = hxxp://www.portaldosites.com/?utm_sourc ... 1369913946
x64-mDefault_Page_URL = hxxp://www.portaldosites.com/?utm_sourc ... 1369913946
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL
x64-BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL
x64-Run: [BeatsOSDApp] C:\Program Files\IDT\WDM\beats64.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\bntj1sm8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.adelaidenow.com.au/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&o ... &gfns=1&q=
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
FF - plugin: C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll
FF - ExtSQL: 2013-06-01 13:33; [removed]; C:\Program Files (x86)\LyricsKid\FF
FF - ExtSQL: 2013-06-01 13:34; c0a5ee61-5128-44f7-bb3c-75c72f490e65@e6 ... 24effe.com; C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\bntj1sm8.default\extensions\[removed]
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.autoDisableScopes - 0
FF - user.js: extensions.shownSelectionUI - true
.
============= SERVICES / DRIVERS ===============
.
R0 gfibto;gfibto;C:\windows\System32\Drivers\gfibto.sys [2013-6-3 14456]
R0 iaStorA;iaStorA;C:\windows\System32\Drivers\iaStorA.sys [2012-8-3 645952]
R1 avkmgr;avkmgr;C:\windows\System32\Drivers\avkmgr.sys [2013-5-31 28600]
R1 CLVirtualDrive;CLVirtualDrive;C:\windows\System32\Drivers\CLVirtualDrive.sys [2012-9-12 92536]
R1 ElRawDisk;ElRawDisk;C:\windows\System32\Drivers\ElRawDsk.sys [2013-6-2 30752]
R2 Ad-Aware Service;Ad-Aware Service;C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2013-3-18 1236336]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-5-31 86752]
R2 AntiVirService;Avira Real-Time Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-5-31 110816]
R2 avgntflt;avgntflt;C:\windows\System32\Drivers\avgntflt.sys [2013-5-31 100712]
R2 BcmBtRSupport;Bluetooth Radio Control Service;C:\windows\System32\BtwRSupportService.exe [2012-7-27 2252600]
R2 eSafeSvc;eSafe Service;C:\ProgramData\eSafe\eGdpSvc.exe [2013-5-30 360512]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-8-16 85504]
R2 HPConnectedRemote;HP Connected Remote Service;C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [2012-8-30 35232]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-21 635104]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-9-12 128896]
R2 ioloSystemService;iolo System Service;C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2013-6-2 1070080]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-9-12 165760]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-6-5 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-6-5 701512]
R2 OfficeSvc;Microsoft Office Service;C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-5-29 1872568]
R2 PDFsFilter;PDFsFilter;C:\windows\System32\Drivers\PDFsFilter.sys [2013-6-2 82160]
R2 SBAMSvc;Ad-Aware;C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2012-9-20 3677000]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2013-6-2 1153368]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-9-12 364416]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\windows\System32\Drivers\bcbtums.sys [2012-7-27 164152]
R3 BthLEEnum;Bluetooth Low Energy Driver;C:\windows\System32\Drivers\BthLEEnum.sys [2012-7-26 202752]
R3 btwampfl;btwampfl Bluetooth filter driver;C:\windows\System32\Drivers\btwampfl.sys [2012-9-12 156472]
R3 btwl2cap;Bluetooth L2CAP Service;C:\windows\System32\Drivers\btwl2cap.sys [2012-9-12 40248]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;C:\windows\System32\Drivers\L1C63x64.sys [2012-6-27 110744]
R3 MBAMProtector;MBAMProtector;C:\windows\System32\Drivers\mbam.sys [2013-6-5 25928]
S2 CLKMSVC10_38F51D56;CyberLink Product - 2012/09/11 15:38:48;C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2012-7-17 243728]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-13 206072]
S3 USBAAPL64;Apple Mobile USB Driver;C:\windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 WUDFWpdMtp;WUDFWpdMtp;C:\windows\System32\Drivers\WUDFRd.sys [2012-7-26 198656]
.
=============== Created Last 30 ================
.
2013-06-05 11:38:46 -------- d-----w- C:\Users\Mark\AppData\Roaming\Malwarebytes
2013-06-05 11:38:33 25928 ----a-w- C:\windows\System32\drivers\mbam.sys
2013-06-05 11:38:33 -------- d-----w- C:\ProgramData\Malwarebytes
2013-06-05 11:38:33 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-05 11:38:17 -------- d-----w- C:\Users\Mark\AppData\Local\Programs
2013-06-05 11:25:17 222384 ----a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10205.bin
2013-06-03 10:15:27 -------- d-----w- C:\Users\Mark\AppData\Roaming\LavasoftStatistics
2013-06-03 10:15:27 -------- d-----w- C:\ProgramData\Ad-Aware Antivirus
2013-06-03 10:06:02 -------- d-----w- C:\Users\Mark\AppData\Local\adawarebp
2013-06-03 10:04:05 -------- d-----w- C:\Program Files (x86)\Ad-Aware Antivirus
2013-06-03 10:04:00 -------- d-----w- C:\ProgramData\Downloaded Installations
2013-06-03 10:03:56 -------- d-----w- C:\ProgramData\Ad-Aware Browsing Protection
2013-06-03 10:02:32 47496 ----a-w- C:\windows\System32\sbbd.exe
2013-06-03 10:02:32 14456 ----a-w- C:\windows\System32\drivers\gfibto.sys
2013-06-03 10:02:31 -------- d-----w- C:\Users\Mark\AppData\Roaming\Ad-Aware Antivirus
2013-06-02 11:20:35 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-06-02 11:20:35 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2013-06-02 05:09:53 82160 ----a-w- C:\windows\System32\drivers\PDFsFilter.sys
2013-06-02 05:09:53 69000 ----a-w- C:\windows\System32\offreg.dll
2013-06-02 05:09:53 57584 ----a-w- C:\windows\System32\iolobtdfg.exe
2013-06-02 05:09:53 56200 ----a-w- C:\windows\SysWow64\offreg.dll
2013-06-02 05:09:53 511328 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\CAPICOM\CAPICOM.DLL
2013-06-02 05:09:53 26184 ----a-w- C:\windows\System32\smrgdf.exe
2013-06-02 05:09:53 2155688 ----a-w- C:\windows\System32\Incinerator64.dll
2013-06-02 05:09:53 2097472 ----a-w- C:\windows\SysWow64\Incinerator32.dll
2013-06-02 05:09:52 -------- d-----w- C:\Program Files (x86)\iolo
2013-06-02 04:37:26 30752 ----a-w- C:\windows\System32\drivers\ElRawDsk.sys
2013-06-02 04:36:52 74703 ----a-w- C:\windows\SysWow64\mfc45.dat
2013-06-02 04:36:52 -------- d-----w- C:\Users\Mark\AppData\Roaming\iolo
2013-06-02 04:36:52 -------- d-----w- C:\ProgramData\iolo
2013-06-01 04:14:48 -------- d-----w- C:\Program Files (x86)\VideoLAN
2013-06-01 04:14:01 -------- d-----w- C:\ProgramData\PC Optimizer Pro
2013-06-01 04:04:21 -------- d-----w- C:\Program Files (x86)\GVU Technologies
2013-06-01 04:04:00 -------- d-----w- C:\Program Files\PC Optimizer Pro
2013-06-01 04:03:57 -------- d-----w- C:\Program Files (x86)\LyricsKid
2013-05-31 12:53:57 -------- d-----w- C:\Users\Mark\AppData\Local\Macromedia
2013-05-31 12:21:20 87392 ----a-w- C:\windows\twain.dll
2013-05-31 12:19:52 306688 ----a-w- C:\windows\IsUninst.exe
2013-05-31 12:13:22 -------- d-----w- C:\Users\Mark\AppData\Local\Adobe
2013-05-31 11:25:21 -------- d-----w- C:\Users\Mark\AppData\Roaming\Avira
2013-05-31 11:23:30 83160 ----a-w- C:\windows\System32\drivers\avnetflt.sys
2013-05-31 11:20:04 28600 ----a-w- C:\windows\System32\drivers\avkmgr.sys
2013-05-31 11:20:04 100712 ----a-w- C:\windows\System32\drivers\avgntflt.sys
2013-05-31 11:20:04 -------- d-----w- C:\ProgramData\Avira
2013-05-31 11:20:04 -------- d-----w- C:\Program Files (x86)\Avira
2013-05-31 08:29:57 929792 ----a-w- C:\windows\SysWow64\mfnetsrc.dll
2013-05-31 08:29:57 677888 ----a-w- C:\windows\System32\mfnetcore.dll
2013-05-31 08:29:57 673280 ----a-w- C:\windows\System32\mfmpeg2srcsnk.dll
2013-05-31 08:29:57 568832 ----a-w- C:\windows\SysWow64\mfnetcore.dll
2013-05-31 08:29:57 513024 ----a-w- C:\windows\SysWow64\mfmpeg2srcsnk.dll
2013-05-31 08:29:57 1172992 ----a-w- C:\windows\System32\mfnetsrc.dll
2013-05-31 08:29:48 82944 ----a-w- C:\windows\SysWow64\dskquota.dll
2013-05-31 08:29:48 109568 ----a-w- C:\windows\System32\dskquota.dll
2013-05-30 12:08:01 3236864 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\tipskins.dll
2013-05-30 12:08:01 2206208 ----a-w- C:\windows\System32\dwmcore.dll
2013-05-30 12:08:00 2380944 ----a-w- C:\windows\explorer.exe
2013-05-30 12:08:00 2115952 ----a-w- C:\windows\SysWow64\explorer.exe
2013-05-30 12:08:00 1841152 ----a-w- C:\windows\SysWow64\dwmcore.dll
2013-05-30 12:08:00 1395712 ----a-w- C:\windows\System32\Windows.UI.Immersive.dll
2013-05-30 12:02:51 1131520 ----a-w- C:\windows\System32\AppXDeploymentServer.dll
2013-05-30 12:01:27 11459584 ----a-w- C:\windows\System32\glcndFilter.dll
2013-05-30 12:00:56 68608 ----a-w- C:\windows\System32\wwanprotdim.dll
2013-05-30 11:59:59 93696 ----a-w- C:\windows\System32\psmsrv.dll
2013-05-30 11:51:25 -------- d-----w- C:\Users\Mark\AppData\Local\Apple Computer
2013-05-30 11:51:21 33240 ----a-w- C:\windows\System32\drivers\GEARAspiWDM.sys
2013-05-30 11:51:14 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-05-30 11:51:14 -------- d-----w- C:\Program Files\iTunes
2013-05-30 11:51:14 -------- d-----w- C:\Program Files\iPod
2013-05-30 11:51:14 -------- d-----w- C:\Program Files (x86)\iTunes
2013-05-30 11:51:10 -------- d-----w- C:\Users\Mark\AppData\Local\Apple
2013-05-30 11:41:28 69632 ----a-r- C:\Users\Mark\AppData\Roaming\Microsoft\Installer\{89505A66-35F0-4401-B3AD-D077051F8698}\ARPPRODUCTICON.exe
2013-05-30 11:41:28 49152 ----a-r- C:\Users\Mark\AppData\Roaming\Microsoft\Installer\{89505A66-35F0-4401-B3AD-D077051F8698}\UNINST_Uninstall_Q_336D8C9DB2424DE5BC518E574B25652F.exe
2013-05-30 11:41:27 -------- d-----w- C:\Users\Mark\AppData\Local\Downloaded Installations
2013-05-30 11:38:33 -------- d-----w- C:\Users\Mark\AppData\Roaming\eIntaller
2013-05-30 11:38:33 -------- d-----w- C:\ProgramData\Tarma Installer
2013-05-30 09:21:19 -------- d-----w- C:\Users\Mark\AppData\Local\Google
2013-05-30 09:21:09 -------- d-----w- C:\Users\Mark\AppData\Local\Deployment
2013-05-30 09:21:09 -------- d-----w- C:\Users\Mark\AppData\Local\Apps
2013-05-30 09:08:42 50784 ----a-w- C:\ProgramData\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin
2013-05-30 09:08:39 17536 ----a-w- C:\ProgramData\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-05-29 13:30:53 -------- d-----w- C:\Users\Mark\AppData\Local\Hewlett-Packard
2013-05-29 13:16:52 16114176 ----a-w- C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-05-29 13:16:52 15541248 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-05-29 13:07:31 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2013-05-29 12:33:10 563920 ----a-w- C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2013-05-29 12:32:11 -------- d-----w- C:\Program Files\Microsoft Office 15
2013-05-29 12:20:06 13648384 ----a-w- C:\windows\System32\Windows.UI.Xaml.dll
2013-05-29 12:19:59 804352 ----a-w- C:\windows\System32\RecoveryDrive.exe
2013-05-29 12:16:55 94208 ----a-w- C:\windows\System32\synceng.dll
2013-05-29 12:15:42 1455368 ----a-w- C:\windows\System32\drivers\dxgkrnl.sys
2013-05-29 12:15:18 148480 ----a-w- C:\windows\System32\poqexec.exe
2013-05-29 12:15:18 144384 ----a-w- C:\windows\System32\tssdisai.dll
2013-05-29 12:15:18 135680 ----a-w- C:\windows\System32\appserverai.dll
2013-05-29 12:15:18 132608 ----a-w- C:\windows\SysWow64\poqexec.exe
2013-05-29 12:15:18 126976 ----a-w- C:\windows\System32\RDWebAI.dll
2013-05-29 12:15:18 122880 ----a-w- C:\windows\System32\VmHostAI.dll
2013-05-29 12:13:59 96256 ----a-w- C:\windows\System32\fontsub.dll
2013-05-29 12:08:46 -------- d-----w- C:\Users\Mark\AppData\Local\Broadcom
2013-05-29 12:08:43 -------- d-----w- C:\Users\Mark\AppData\Local\Power2Go8
2013-05-29 12:08:21 -------- d-----r- C:\Users\Mark\Searches
2013-05-29 12:08:21 -------- d-----r- C:\Users\Mark\Contacts
2013-05-29 12:07:36 -------- d-----w- C:\Users\Mark\AppData\Local\assembly
.
==================== Find3M ====================
.
2013-05-07 20:07:50 78200 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-07 20:07:50 693112 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2013-04-13 05:56:35 444416 ----a-w- C:\windows\apppatch\AcSpecfc.dll
2013-04-11 06:40:48 6987528 ----a-w- C:\windows\System32\ntoskrnl.exe
2013-04-09 23:17:44 2242048 ----a-w- C:\windows\System32\wininet.dll
2013-04-09 23:17:36 915968 ----a-w- C:\windows\System32\uxtheme.dll
2013-04-09 23:16:58 3958784 ----a-w- C:\windows\System32\jscript9.dll
2013-04-09 22:30:26 1767424 ----a-w- C:\windows\SysWow64\wininet.dll
2013-04-09 22:29:44 2877440 ----a-w- C:\windows\SysWow64\jscript9.dll
2013-04-09 05:33:02 489576 ----a-w- C:\windows\System32\AudioEng.dll
2013-04-09 05:33:02 446792 ----a-w- C:\windows\System32\AudioSes.dll
2013-04-09 05:33:02 253544 ----a-w- C:\windows\System32\audiodg.exe
2013-04-09 05:27:43 284424 ----a-w- C:\windows\System32\drivers\spaceport.sys
2013-04-09 05:20:02 86280 ----a-w- C:\windows\System32\kdnet.dll
2013-04-09 05:20:02 306952 ----a-w- C:\windows\System32\kd_02_10ec.dll
2013-04-09 05:18:05 77960 ----a-w- C:\windows\System32\kdvm.dll
2013-04-09 05:17:57 1829408 ----a-w- C:\windows\System32\ntdll.dll
2013-04-09 04:52:07 816128 ----a-w- C:\windows\System32\SearchIndexer.exe
2013-04-09 04:52:07 373760 ----a-w- C:\windows\System32\SearchProtocolHost.exe
2013-04-09 04:52:07 197120 ----a-w- C:\windows\System32\SearchFilterHost.exe
2013-04-09 04:52:07 126464 ----a-w- C:\windows\System32\Robocopy.exe
2013-04-09 04:51:51 367616 ----a-w- C:\windows\System32\conhost.exe
2013-04-09 04:51:45 523264 ----a-w- C:\windows\System32\XpsGdiConverter.dll
2013-04-09 04:51:41 99840 ----a-w- C:\windows\System32\wscsvc.dll
2013-04-09 04:51:41 456704 ----a-w- C:\windows\System32\wpncore.dll
2013-04-09 04:51:17 595456 ----a-w- C:\windows\System32\Windows.Networking.dll
2013-04-09 04:51:17 391168 ----a-w- C:\windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-04-09 04:51:05 10116096 ----a-w- C:\windows\System32\twinui.dll
2013-04-09 04:51:03 3552768 ----a-w- C:\windows\System32\tquery.dll
2013-04-09 04:50:53 414720 ----a-w- C:\windows\System32\GenuineCenter.dll
2013-04-09 04:50:39 422400 ----a-w- C:\windows\System32\schannel.dll
2013-04-09 04:50:39 1285632 ----a-w- C:\windows\System32\schedsvc.dll
2013-04-09 04:50:03 96256 ----a-w- C:\windows\System32\mssprxy.dll
2013-04-09 04:50:03 745984 ----a-w- C:\windows\System32\mssvp.dll
2013-04-09 04:50:03 2107904 ----a-w- C:\windows\System32\mssrch.dll
2013-04-09 04:50:02 65024 ----a-w- C:\windows\System32\msscntrs.dll
2013-04-09 04:50:02 435200 ----a-w- C:\windows\System32\mssph.dll
2013-04-09 04:50:02 13824 ----a-w- C:\windows\System32\msshooks.dll
2013-04-09 04:49:54 1444864 ----a-w- C:\windows\System32\MSAudDecMFT.dll
2013-04-09 04:49:45 468992 ----a-w- C:\windows\System32\MFMediaEngine.dll
2013-04-09 04:49:45 281088 ----a-w- C:\windows\System32\mfreadwrite.dll
2013-04-09 04:49:36 817152 ----a-w- C:\windows\System32\kerberos.dll
2013-04-09 04:49:33 210432 ----a-w- C:\windows\System32\iuilp.dll
2013-04-09 04:49:16 50176 ----a-w- C:\windows\System32\fmifs.dll
2013-04-09 04:49:16 231936 ----a-w- C:\windows\System32\fhengine.dll
2013-04-09 04:49:09 172544 ----a-w- C:\windows\System32\dwmredir.dll
2013-04-09 04:49:06 196096 ----a-w- C:\windows\System32\dmvdsitf.dll
2013-04-09 04:48:43 2303488 ----a-w- C:\windows\System32\authui.dll
2013-04-09 04:48:42 785408 ----a-w- C:\windows\System32\audiosrv.dll
2013-04-09 04:48:42 169472 ----a-w- C:\windows\System32\AudioEndpointBuilder.dll
2013-04-09 04:48:34 419840 ----a-w- C:\windows\System32\intl.cpl
2013-04-09 02:35:13 4038144 ----a-w- C:\windows\System32\win32k.sys
2013-04-09 02:34:49 83968 ----a-w- C:\windows\System32\drivers\hidclass.sys
2013-04-09 02:34:42 27648 ----a-w- C:\windows\System32\drivers\hidusb.sys
2013-04-09 02:34:30 95744 ----a-w- C:\windows\System32\drivers\hidbth.sys
2013-04-09 02:33:41 60416 ----a-w- C:\windows\System32\drivers\ndproxy.sys
2013-04-09 02:33:05 623104 ----a-w- C:\windows\System32\drivers\srv2.sys
2013-04-09 02:32:02 805376 ----a-w- C:\windows\System32\drivers\PEAuth.sys
2013-04-09 02:31:14 247808 ----a-w- C:\windows\System32\drivers\srvnet.sys
2013-04-09 02:31:01 83456 ----a-w- C:\windows\System32\drivers\wanarp.sys
2013-04-08 23:44:25 123880 ----a-w- C:\windows\SysWow64\wscapi.dll
2013-04-08 23:39:14 1408896 ----a-w- C:\windows\SysWow64\ntdll.dll
2013-04-08 23:37:29 426024 ----a-w- C:\windows\SysWow64\AudioEng.dll
2013-04-08 23:37:29 324368 ----a-w- C:\windows\SysWow64\AudioSes.dll
2013-04-08 21:52:16 670208 ----a-w- C:\windows\SysWow64\SearchIndexer.exe
2013-04-08 21:52:16 302592 ----a-w- C:\windows\SysWow64\SearchProtocolHost.exe
2013-04-08 21:52:16 171008 ----a-w- C:\windows\SysWow64\SearchFilterHost.exe
2013-04-08 21:52:16 106496 ----a-w- C:\windows\SysWow64\Robocopy.exe
2013-04-08 21:52:06 364544 ----a-w- C:\windows\SysWow64\XpsGdiConverter.dll
2013-04-04 23:30:17 503080 ----a-w- C:\windows\System32\ci.dll
2013-03-30 18:16:05 1403784 ----a-w- C:\windows\System32\winload.efi
2013-03-30 18:16:05 1267424 ----a-w- C:\windows\System32\winload.exe
2013-03-28 22:09:09 1093880 ----a-w- C:\windows\System32\winresume.exe
2013-03-28 22:09:04 1217328 ----a-w- C:\windows\System32\winresume.efi
2013-03-22 03:49:55 2382336 ----a-w- C:\windows\SysWow64\esent.dll
2013-03-21 22:47:13 2851840 ----a-w- C:\windows\System32\esent.dll
2013-03-15 22:05:34 298456 ----a-w- C:\windows\System32\rsaenh.dll
2013-03-15 22:05:16 252928 ----a-w- C:\windows\SysWow64\rsaenh.dll
2013-03-15 00:17:18 861184 ----a-w- C:\windows\System32\drivers\http.sys
.
============= FINISH: 18:02:00.58 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 8
Boot Device: \Device\HarddiskVolume2
Install Date: 29/05/2013 9:32:31 PM
System Uptime: 7/06/2013 5:35:19 PM (25 hours ago)
.
Motherboard: PEGATRON CORPORATION | | 2AD5
Processor: Intel(R) Core(TM) i7-3770 CPU @ 3.40GHz | SOCKET 0 | 3401/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 2774 GiB total, 2680.604 GiB free.
D: is FIXED (NTFS) - 19 GiB total, 2.425 GiB free.
E: is Removable
F: is CDROM (CDFS)
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (NTFS) - 466 GiB total, 92.195 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP4: 2/06/2013 2:04:36 PM - Removed Free YouTube Downloader Converter
.
==== Installed Programs ======================
.
4 Elements II
7 Wonders II
Ad-Aware Antivirus
Ad-Aware Browsing Protection
Adobe Flash Player 11 Plugin
Adobe Photoshop Elements 2.0
Aloha TriPeaks
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Avira Free Antivirus
Bejeweled 3
Bonjour
Broadcom 802.11 Wireless LAN Adapter
Broadcom Bluetooth Software
Build-a-lot 4 - Power Source
Chuzzle Deluxe
Cradle of Rome 2
Crazy Chicken Soccer
CyberLink LabelPrint
CyberLink Media Suite 10
CyberLink PhotoDirector
CyberLink Power2Go 8
CyberLink PowerDirector 10
CyberLink PowerDVD
D3DX10
Energy Star
eSafe Security Control 1.0.0.2359
Farm Frenzy
Final Drive Fury
FlatOut 2
Google Chrome
Google Update Helper
Governor of Poker 2 Premium Edition
GVU Technologies
Hewlett-Packard ACLM.NET v1.2.0.0
Hoyle Card Games
HP Connected Remote
HP Customer Experience Enhancements
HP Games
HP Keyboard
HP Postscript Converter
HP Registration Service
HP Support Information
IDT Audio
Intel(R) Management Engine Components
Intel® Trusted Connect Service Client
iolo technologies' System Mechanic
iTunes
Jewel Match 3
John Deere Drive Green
Letters from Nowhere 2
Luxor Evolved
Lyrics Kid
Mahjongg Dimensions Deluxe: Tiles in Time
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft Application Error Reporting
Microsoft Office Professional Plus 2013 - en-us
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Mozilla Firefox 21.0 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
NVIDIA Control Panel 305.29
NVIDIA Graphics Driver 305.29
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX System Software 9.12.0613
Office 15 Click-to-Run Extensibility Component
Office 15 Click-to-Run Licensing Component
Office 15 Click-to-Run Localization Component
Peggle Nights
Penguins!
Polar Bowler
Polar Golfer
Qtrax Player
Recovery Manager
Roads of Rome 3
Spybot - Search & Destroy
The Treasures of Mystery Island: The Ghost Ship
Trinklit Supreme
Update Installer for WildTangent Games App
VLC media player 2.0.6
WebCake 3.00
WildTangent Games
WildTangent Games App
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Language Selector
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Zuma's Revenge
.
==== Event Viewer Messages From Past Week ========
.
7/06/2013 9:04:10 PM, Error: Schannel [36870] - A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030D. The internal error state is 10001.
7/06/2013 5:35:49 PM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\windows\System32\bcmihvsrv64.dll Error Code: 126
3/06/2013 7:47:58 PM, Error: Service Control Manager [7034] - The WebCake Desktop Updater service terminated unexpectedly. It has done this 1 time(s).
3/06/2013 7:20:53 PM, Error: Service Control Manager [7034] - The iolo System Service service terminated unexpectedly. It has done this 1 time(s).
2/06/2013 11:36:31 PM, Error: Service Control Manager [7034] - The Desk 365 service service terminated unexpectedly. It has done this 1 time(s).
1/06/2013 1:34:17 PM, Error: Service Control Manager [7030] - The YouTubeDownloaderConverter service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
.
==== End Of File ===========================
DDS log followed by Attach log below
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537
Run by [removed] at 18:01:47 on 2013-06-08
Microsoft Windows 8 6.2.9200.0.1252.61.1033.18.16324.14061 [GMT 9.5:30]
.
AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Aware *Disabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
.
============== Running Processes ===============
.
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\nvvsvc.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\IDT\WDM\STacSV64.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\ProgramData\eSafe\eGdpSvc.exe
C:\windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\windows\system32\svchost.exe -k apphost
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\windows\system32\BtwRSupportService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\windows\system32\dashost.exe
C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\System32\dwm.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\windows\system32\nvvsvc.exe
C:\windows\system32\taskhostex.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\windows\Explorer.EXE
C:\Program Files\IDT\WDM\Beats64.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe
C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR_HIDList.exe
C:\windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
C:\PROGRA~2\AD-AWA~1\AdAware.exe
C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteUser.exe
C:\Program Files\Microsoft Office 15\root\office15\outlook.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://securedsearch2.lavasoft.com/inde ... 51AC69F814
uDefault_Page_URL = hxxp://www.portaldosites.com/?utm_sourc ... 1369913946
mStart Page = hxxp://www.portaldosites.com/?utm_sourc ... 1369913946
mDefault_Page_URL = hxxp://www.portaldosites.com/?utm_sourc ... 1369913946
mWinlogon: Userinit = userinit.exe
BHO: WebCake: {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} -
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\office15\OCHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL
BHO: Lyrics Kid: {BA146CF5-1875-4EA8-AAEA-A90142FC2EC9} - C:\Program Files (x86)\LyricsKid\lkid.dll
BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\office15\GROOVEEX.DLL
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
uRun: [Desk 365] "C:\Program Files (x86)\Desk 365\desk365.exe" /autorun
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
mRun: [CLMLServer_For_P2G8] "c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
mRun: [CLVirtualDrive] "c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
mRun: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe
mRun: [BATINDICATORHL] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR_HIDList.exe
mRun: [OSDTool] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"
mRun: [Search Protection] C:\ProgramData\Search Protection\SearchProtection.exe
mRun: [Ad-Aware Antivirus] "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
IE: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\office15\OCHelper.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{4DAEF880-29E2-4B5A-AF4F-F345B1B8CFF6} : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{4DAEF880-29E2-4B5A-AF4F-F345B1B8CFF6}\24967605F6E646535383430303 : DHCPNameServer = 10.0.0.138
TCP: Interfaces\{D89C42DA-19E8-4186-AE96-88F8206B9154} : DHCPNameServer = 192.168.2.1
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mStart Page = hxxp://www.portaldosites.com/?utm_sourc ... 1369913946
x64-mDefault_Page_URL = hxxp://www.portaldosites.com/?utm_sourc ... 1369913946
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL
x64-BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL
x64-Run: [BeatsOSDApp] C:\Program Files\IDT\WDM\beats64.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\bntj1sm8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.adelaidenow.com.au/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&o ... &gfns=1&q=
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
FF - plugin: C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll
FF - ExtSQL: 2013-06-01 13:33; [removed]; C:\Program Files (x86)\LyricsKid\FF
FF - ExtSQL: 2013-06-01 13:34; c0a5ee61-5128-44f7-bb3c-75c72f490e65@e6 ... 24effe.com; C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\bntj1sm8.default\extensions\[removed]
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.autoDisableScopes - 0
FF - user.js: extensions.shownSelectionUI - true
.
============= SERVICES / DRIVERS ===============
.
R0 gfibto;gfibto;C:\windows\System32\Drivers\gfibto.sys [2013-6-3 14456]
R0 iaStorA;iaStorA;C:\windows\System32\Drivers\iaStorA.sys [2012-8-3 645952]
R1 avkmgr;avkmgr;C:\windows\System32\Drivers\avkmgr.sys [2013-5-31 28600]
R1 CLVirtualDrive;CLVirtualDrive;C:\windows\System32\Drivers\CLVirtualDrive.sys [2012-9-12 92536]
R1 ElRawDisk;ElRawDisk;C:\windows\System32\Drivers\ElRawDsk.sys [2013-6-2 30752]
R2 Ad-Aware Service;Ad-Aware Service;C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2013-3-18 1236336]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-5-31 86752]
R2 AntiVirService;Avira Real-Time Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-5-31 110816]
R2 avgntflt;avgntflt;C:\windows\System32\Drivers\avgntflt.sys [2013-5-31 100712]
R2 BcmBtRSupport;Bluetooth Radio Control Service;C:\windows\System32\BtwRSupportService.exe [2012-7-27 2252600]
R2 eSafeSvc;eSafe Service;C:\ProgramData\eSafe\eGdpSvc.exe [2013-5-30 360512]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-8-16 85504]
R2 HPConnectedRemote;HP Connected Remote Service;C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [2012-8-30 35232]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-21 635104]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-9-12 128896]
R2 ioloSystemService;iolo System Service;C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2013-6-2 1070080]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-9-12 165760]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-6-5 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-6-5 701512]
R2 OfficeSvc;Microsoft Office Service;C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-5-29 1872568]
R2 PDFsFilter;PDFsFilter;C:\windows\System32\Drivers\PDFsFilter.sys [2013-6-2 82160]
R2 SBAMSvc;Ad-Aware;C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2012-9-20 3677000]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2013-6-2 1153368]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-9-12 364416]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\windows\System32\Drivers\bcbtums.sys [2012-7-27 164152]
R3 BthLEEnum;Bluetooth Low Energy Driver;C:\windows\System32\Drivers\BthLEEnum.sys [2012-7-26 202752]
R3 btwampfl;btwampfl Bluetooth filter driver;C:\windows\System32\Drivers\btwampfl.sys [2012-9-12 156472]
R3 btwl2cap;Bluetooth L2CAP Service;C:\windows\System32\Drivers\btwl2cap.sys [2012-9-12 40248]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;C:\windows\System32\Drivers\L1C63x64.sys [2012-6-27 110744]
R3 MBAMProtector;MBAMProtector;C:\windows\System32\Drivers\mbam.sys [2013-6-5 25928]
S2 CLKMSVC10_38F51D56;CyberLink Product - 2012/09/11 15:38:48;C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2012-7-17 243728]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-13 206072]
S3 USBAAPL64;Apple Mobile USB Driver;C:\windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 WUDFWpdMtp;WUDFWpdMtp;C:\windows\System32\Drivers\WUDFRd.sys [2012-7-26 198656]
.
=============== Created Last 30 ================
.
2013-06-05 11:38:46 -------- d-----w- C:\Users\Mark\AppData\Roaming\Malwarebytes
2013-06-05 11:38:33 25928 ----a-w- C:\windows\System32\drivers\mbam.sys
2013-06-05 11:38:33 -------- d-----w- C:\ProgramData\Malwarebytes
2013-06-05 11:38:33 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-05 11:38:17 -------- d-----w- C:\Users\Mark\AppData\Local\Programs
2013-06-05 11:25:17 222384 ----a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10205.bin
2013-06-03 10:15:27 -------- d-----w- C:\Users\Mark\AppData\Roaming\LavasoftStatistics
2013-06-03 10:15:27 -------- d-----w- C:\ProgramData\Ad-Aware Antivirus
2013-06-03 10:06:02 -------- d-----w- C:\Users\Mark\AppData\Local\adawarebp
2013-06-03 10:04:05 -------- d-----w- C:\Program Files (x86)\Ad-Aware Antivirus
2013-06-03 10:04:00 -------- d-----w- C:\ProgramData\Downloaded Installations
2013-06-03 10:03:56 -------- d-----w- C:\ProgramData\Ad-Aware Browsing Protection
2013-06-03 10:02:32 47496 ----a-w- C:\windows\System32\sbbd.exe
2013-06-03 10:02:32 14456 ----a-w- C:\windows\System32\drivers\gfibto.sys
2013-06-03 10:02:31 -------- d-----w- C:\Users\Mark\AppData\Roaming\Ad-Aware Antivirus
2013-06-02 11:20:35 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-06-02 11:20:35 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2013-06-02 05:09:53 82160 ----a-w- C:\windows\System32\drivers\PDFsFilter.sys
2013-06-02 05:09:53 69000 ----a-w- C:\windows\System32\offreg.dll
2013-06-02 05:09:53 57584 ----a-w- C:\windows\System32\iolobtdfg.exe
2013-06-02 05:09:53 56200 ----a-w- C:\windows\SysWow64\offreg.dll
2013-06-02 05:09:53 511328 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\CAPICOM\CAPICOM.DLL
2013-06-02 05:09:53 26184 ----a-w- C:\windows\System32\smrgdf.exe
2013-06-02 05:09:53 2155688 ----a-w- C:\windows\System32\Incinerator64.dll
2013-06-02 05:09:53 2097472 ----a-w- C:\windows\SysWow64\Incinerator32.dll
2013-06-02 05:09:52 -------- d-----w- C:\Program Files (x86)\iolo
2013-06-02 04:37:26 30752 ----a-w- C:\windows\System32\drivers\ElRawDsk.sys
2013-06-02 04:36:52 74703 ----a-w- C:\windows\SysWow64\mfc45.dat
2013-06-02 04:36:52 -------- d-----w- C:\Users\Mark\AppData\Roaming\iolo
2013-06-02 04:36:52 -------- d-----w- C:\ProgramData\iolo
2013-06-01 04:14:48 -------- d-----w- C:\Program Files (x86)\VideoLAN
2013-06-01 04:14:01 -------- d-----w- C:\ProgramData\PC Optimizer Pro
2013-06-01 04:04:21 -------- d-----w- C:\Program Files (x86)\GVU Technologies
2013-06-01 04:04:00 -------- d-----w- C:\Program Files\PC Optimizer Pro
2013-06-01 04:03:57 -------- d-----w- C:\Program Files (x86)\LyricsKid
2013-05-31 12:53:57 -------- d-----w- C:\Users\Mark\AppData\Local\Macromedia
2013-05-31 12:21:20 87392 ----a-w- C:\windows\twain.dll
2013-05-31 12:19:52 306688 ----a-w- C:\windows\IsUninst.exe
2013-05-31 12:13:22 -------- d-----w- C:\Users\Mark\AppData\Local\Adobe
2013-05-31 11:25:21 -------- d-----w- C:\Users\Mark\AppData\Roaming\Avira
2013-05-31 11:23:30 83160 ----a-w- C:\windows\System32\drivers\avnetflt.sys
2013-05-31 11:20:04 28600 ----a-w- C:\windows\System32\drivers\avkmgr.sys
2013-05-31 11:20:04 100712 ----a-w- C:\windows\System32\drivers\avgntflt.sys
2013-05-31 11:20:04 -------- d-----w- C:\ProgramData\Avira
2013-05-31 11:20:04 -------- d-----w- C:\Program Files (x86)\Avira
2013-05-31 08:29:57 929792 ----a-w- C:\windows\SysWow64\mfnetsrc.dll
2013-05-31 08:29:57 677888 ----a-w- C:\windows\System32\mfnetcore.dll
2013-05-31 08:29:57 673280 ----a-w- C:\windows\System32\mfmpeg2srcsnk.dll
2013-05-31 08:29:57 568832 ----a-w- C:\windows\SysWow64\mfnetcore.dll
2013-05-31 08:29:57 513024 ----a-w- C:\windows\SysWow64\mfmpeg2srcsnk.dll
2013-05-31 08:29:57 1172992 ----a-w- C:\windows\System32\mfnetsrc.dll
2013-05-31 08:29:48 82944 ----a-w- C:\windows\SysWow64\dskquota.dll
2013-05-31 08:29:48 109568 ----a-w- C:\windows\System32\dskquota.dll
2013-05-30 12:08:01 3236864 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\tipskins.dll
2013-05-30 12:08:01 2206208 ----a-w- C:\windows\System32\dwmcore.dll
2013-05-30 12:08:00 2380944 ----a-w- C:\windows\explorer.exe
2013-05-30 12:08:00 2115952 ----a-w- C:\windows\SysWow64\explorer.exe
2013-05-30 12:08:00 1841152 ----a-w- C:\windows\SysWow64\dwmcore.dll
2013-05-30 12:08:00 1395712 ----a-w- C:\windows\System32\Windows.UI.Immersive.dll
2013-05-30 12:02:51 1131520 ----a-w- C:\windows\System32\AppXDeploymentServer.dll
2013-05-30 12:01:27 11459584 ----a-w- C:\windows\System32\glcndFilter.dll
2013-05-30 12:00:56 68608 ----a-w- C:\windows\System32\wwanprotdim.dll
2013-05-30 11:59:59 93696 ----a-w- C:\windows\System32\psmsrv.dll
2013-05-30 11:51:25 -------- d-----w- C:\Users\Mark\AppData\Local\Apple Computer
2013-05-30 11:51:21 33240 ----a-w- C:\windows\System32\drivers\GEARAspiWDM.sys
2013-05-30 11:51:14 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-05-30 11:51:14 -------- d-----w- C:\Program Files\iTunes
2013-05-30 11:51:14 -------- d-----w- C:\Program Files\iPod
2013-05-30 11:51:14 -------- d-----w- C:\Program Files (x86)\iTunes
2013-05-30 11:51:10 -------- d-----w- C:\Users\Mark\AppData\Local\Apple
2013-05-30 11:41:28 69632 ----a-r- C:\Users\Mark\AppData\Roaming\Microsoft\Installer\{89505A66-35F0-4401-B3AD-D077051F8698}\ARPPRODUCTICON.exe
2013-05-30 11:41:28 49152 ----a-r- C:\Users\Mark\AppData\Roaming\Microsoft\Installer\{89505A66-35F0-4401-B3AD-D077051F8698}\UNINST_Uninstall_Q_336D8C9DB2424DE5BC518E574B25652F.exe
2013-05-30 11:41:27 -------- d-----w- C:\Users\Mark\AppData\Local\Downloaded Installations
2013-05-30 11:38:33 -------- d-----w- C:\Users\Mark\AppData\Roaming\eIntaller
2013-05-30 11:38:33 -------- d-----w- C:\ProgramData\Tarma Installer
2013-05-30 09:21:19 -------- d-----w- C:\Users\Mark\AppData\Local\Google
2013-05-30 09:21:09 -------- d-----w- C:\Users\Mark\AppData\Local\Deployment
2013-05-30 09:21:09 -------- d-----w- C:\Users\Mark\AppData\Local\Apps
2013-05-30 09:08:42 50784 ----a-w- C:\ProgramData\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin
2013-05-30 09:08:39 17536 ----a-w- C:\ProgramData\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-05-29 13:30:53 -------- d-----w- C:\Users\Mark\AppData\Local\Hewlett-Packard
2013-05-29 13:16:52 16114176 ----a-w- C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-05-29 13:16:52 15541248 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-05-29 13:07:31 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2013-05-29 12:33:10 563920 ----a-w- C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2013-05-29 12:32:11 -------- d-----w- C:\Program Files\Microsoft Office 15
2013-05-29 12:20:06 13648384 ----a-w- C:\windows\System32\Windows.UI.Xaml.dll
2013-05-29 12:19:59 804352 ----a-w- C:\windows\System32\RecoveryDrive.exe
2013-05-29 12:16:55 94208 ----a-w- C:\windows\System32\synceng.dll
2013-05-29 12:15:42 1455368 ----a-w- C:\windows\System32\drivers\dxgkrnl.sys
2013-05-29 12:15:18 148480 ----a-w- C:\windows\System32\poqexec.exe
2013-05-29 12:15:18 144384 ----a-w- C:\windows\System32\tssdisai.dll
2013-05-29 12:15:18 135680 ----a-w- C:\windows\System32\appserverai.dll
2013-05-29 12:15:18 132608 ----a-w- C:\windows\SysWow64\poqexec.exe
2013-05-29 12:15:18 126976 ----a-w- C:\windows\System32\RDWebAI.dll
2013-05-29 12:15:18 122880 ----a-w- C:\windows\System32\VmHostAI.dll
2013-05-29 12:13:59 96256 ----a-w- C:\windows\System32\fontsub.dll
2013-05-29 12:08:46 -------- d-----w- C:\Users\Mark\AppData\Local\Broadcom
2013-05-29 12:08:43 -------- d-----w- C:\Users\Mark\AppData\Local\Power2Go8
2013-05-29 12:08:21 -------- d-----r- C:\Users\Mark\Searches
2013-05-29 12:08:21 -------- d-----r- C:\Users\Mark\Contacts
2013-05-29 12:07:36 -------- d-----w- C:\Users\Mark\AppData\Local\assembly
.
==================== Find3M ====================
.
2013-05-07 20:07:50 78200 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-07 20:07:50 693112 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2013-04-13 05:56:35 444416 ----a-w- C:\windows\apppatch\AcSpecfc.dll
2013-04-11 06:40:48 6987528 ----a-w- C:\windows\System32\ntoskrnl.exe
2013-04-09 23:17:44 2242048 ----a-w- C:\windows\System32\wininet.dll
2013-04-09 23:17:36 915968 ----a-w- C:\windows\System32\uxtheme.dll
2013-04-09 23:16:58 3958784 ----a-w- C:\windows\System32\jscript9.dll
2013-04-09 22:30:26 1767424 ----a-w- C:\windows\SysWow64\wininet.dll
2013-04-09 22:29:44 2877440 ----a-w- C:\windows\SysWow64\jscript9.dll
2013-04-09 05:33:02 489576 ----a-w- C:\windows\System32\AudioEng.dll
2013-04-09 05:33:02 446792 ----a-w- C:\windows\System32\AudioSes.dll
2013-04-09 05:33:02 253544 ----a-w- C:\windows\System32\audiodg.exe
2013-04-09 05:27:43 284424 ----a-w- C:\windows\System32\drivers\spaceport.sys
2013-04-09 05:20:02 86280 ----a-w- C:\windows\System32\kdnet.dll
2013-04-09 05:20:02 306952 ----a-w- C:\windows\System32\kd_02_10ec.dll
2013-04-09 05:18:05 77960 ----a-w- C:\windows\System32\kdvm.dll
2013-04-09 05:17:57 1829408 ----a-w- C:\windows\System32\ntdll.dll
2013-04-09 04:52:07 816128 ----a-w- C:\windows\System32\SearchIndexer.exe
2013-04-09 04:52:07 373760 ----a-w- C:\windows\System32\SearchProtocolHost.exe
2013-04-09 04:52:07 197120 ----a-w- C:\windows\System32\SearchFilterHost.exe
2013-04-09 04:52:07 126464 ----a-w- C:\windows\System32\Robocopy.exe
2013-04-09 04:51:51 367616 ----a-w- C:\windows\System32\conhost.exe
2013-04-09 04:51:45 523264 ----a-w- C:\windows\System32\XpsGdiConverter.dll
2013-04-09 04:51:41 99840 ----a-w- C:\windows\System32\wscsvc.dll
2013-04-09 04:51:41 456704 ----a-w- C:\windows\System32\wpncore.dll
2013-04-09 04:51:17 595456 ----a-w- C:\windows\System32\Windows.Networking.dll
2013-04-09 04:51:17 391168 ----a-w- C:\windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-04-09 04:51:05 10116096 ----a-w- C:\windows\System32\twinui.dll
2013-04-09 04:51:03 3552768 ----a-w- C:\windows\System32\tquery.dll
2013-04-09 04:50:53 414720 ----a-w- C:\windows\System32\GenuineCenter.dll
2013-04-09 04:50:39 422400 ----a-w- C:\windows\System32\schannel.dll
2013-04-09 04:50:39 1285632 ----a-w- C:\windows\System32\schedsvc.dll
2013-04-09 04:50:03 96256 ----a-w- C:\windows\System32\mssprxy.dll
2013-04-09 04:50:03 745984 ----a-w- C:\windows\System32\mssvp.dll
2013-04-09 04:50:03 2107904 ----a-w- C:\windows\System32\mssrch.dll
2013-04-09 04:50:02 65024 ----a-w- C:\windows\System32\msscntrs.dll
2013-04-09 04:50:02 435200 ----a-w- C:\windows\System32\mssph.dll
2013-04-09 04:50:02 13824 ----a-w- C:\windows\System32\msshooks.dll
2013-04-09 04:49:54 1444864 ----a-w- C:\windows\System32\MSAudDecMFT.dll
2013-04-09 04:49:45 468992 ----a-w- C:\windows\System32\MFMediaEngine.dll
2013-04-09 04:49:45 281088 ----a-w- C:\windows\System32\mfreadwrite.dll
2013-04-09 04:49:36 817152 ----a-w- C:\windows\System32\kerberos.dll
2013-04-09 04:49:33 210432 ----a-w- C:\windows\System32\iuilp.dll
2013-04-09 04:49:16 50176 ----a-w- C:\windows\System32\fmifs.dll
2013-04-09 04:49:16 231936 ----a-w- C:\windows\System32\fhengine.dll
2013-04-09 04:49:09 172544 ----a-w- C:\windows\System32\dwmredir.dll
2013-04-09 04:49:06 196096 ----a-w- C:\windows\System32\dmvdsitf.dll
2013-04-09 04:48:43 2303488 ----a-w- C:\windows\System32\authui.dll
2013-04-09 04:48:42 785408 ----a-w- C:\windows\System32\audiosrv.dll
2013-04-09 04:48:42 169472 ----a-w- C:\windows\System32\AudioEndpointBuilder.dll
2013-04-09 04:48:34 419840 ----a-w- C:\windows\System32\intl.cpl
2013-04-09 02:35:13 4038144 ----a-w- C:\windows\System32\win32k.sys
2013-04-09 02:34:49 83968 ----a-w- C:\windows\System32\drivers\hidclass.sys
2013-04-09 02:34:42 27648 ----a-w- C:\windows\System32\drivers\hidusb.sys
2013-04-09 02:34:30 95744 ----a-w- C:\windows\System32\drivers\hidbth.sys
2013-04-09 02:33:41 60416 ----a-w- C:\windows\System32\drivers\ndproxy.sys
2013-04-09 02:33:05 623104 ----a-w- C:\windows\System32\drivers\srv2.sys
2013-04-09 02:32:02 805376 ----a-w- C:\windows\System32\drivers\PEAuth.sys
2013-04-09 02:31:14 247808 ----a-w- C:\windows\System32\drivers\srvnet.sys
2013-04-09 02:31:01 83456 ----a-w- C:\windows\System32\drivers\wanarp.sys
2013-04-08 23:44:25 123880 ----a-w- C:\windows\SysWow64\wscapi.dll
2013-04-08 23:39:14 1408896 ----a-w- C:\windows\SysWow64\ntdll.dll
2013-04-08 23:37:29 426024 ----a-w- C:\windows\SysWow64\AudioEng.dll
2013-04-08 23:37:29 324368 ----a-w- C:\windows\SysWow64\AudioSes.dll
2013-04-08 21:52:16 670208 ----a-w- C:\windows\SysWow64\SearchIndexer.exe
2013-04-08 21:52:16 302592 ----a-w- C:\windows\SysWow64\SearchProtocolHost.exe
2013-04-08 21:52:16 171008 ----a-w- C:\windows\SysWow64\SearchFilterHost.exe
2013-04-08 21:52:16 106496 ----a-w- C:\windows\SysWow64\Robocopy.exe
2013-04-08 21:52:06 364544 ----a-w- C:\windows\SysWow64\XpsGdiConverter.dll
2013-04-04 23:30:17 503080 ----a-w- C:\windows\System32\ci.dll
2013-03-30 18:16:05 1403784 ----a-w- C:\windows\System32\winload.efi
2013-03-30 18:16:05 1267424 ----a-w- C:\windows\System32\winload.exe
2013-03-28 22:09:09 1093880 ----a-w- C:\windows\System32\winresume.exe
2013-03-28 22:09:04 1217328 ----a-w- C:\windows\System32\winresume.efi
2013-03-22 03:49:55 2382336 ----a-w- C:\windows\SysWow64\esent.dll
2013-03-21 22:47:13 2851840 ----a-w- C:\windows\System32\esent.dll
2013-03-15 22:05:34 298456 ----a-w- C:\windows\System32\rsaenh.dll
2013-03-15 22:05:16 252928 ----a-w- C:\windows\SysWow64\rsaenh.dll
2013-03-15 00:17:18 861184 ----a-w- C:\windows\System32\drivers\http.sys
.
============= FINISH: 18:02:00.58 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 8
Boot Device: \Device\HarddiskVolume2
Install Date: 29/05/2013 9:32:31 PM
System Uptime: 7/06/2013 5:35:19 PM (25 hours ago)
.
Motherboard: PEGATRON CORPORATION | | 2AD5
Processor: Intel(R) Core(TM) i7-3770 CPU @ 3.40GHz | SOCKET 0 | 3401/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 2774 GiB total, 2680.604 GiB free.
D: is FIXED (NTFS) - 19 GiB total, 2.425 GiB free.
E: is Removable
F: is CDROM (CDFS)
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (NTFS) - 466 GiB total, 92.195 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP4: 2/06/2013 2:04:36 PM - Removed Free YouTube Downloader Converter
.
==== Installed Programs ======================
.
4 Elements II
7 Wonders II
Ad-Aware Antivirus
Ad-Aware Browsing Protection
Adobe Flash Player 11 Plugin
Adobe Photoshop Elements 2.0
Aloha TriPeaks
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Avira Free Antivirus
Bejeweled 3
Bonjour
Broadcom 802.11 Wireless LAN Adapter
Broadcom Bluetooth Software
Build-a-lot 4 - Power Source
Chuzzle Deluxe
Cradle of Rome 2
Crazy Chicken Soccer
CyberLink LabelPrint
CyberLink Media Suite 10
CyberLink PhotoDirector
CyberLink Power2Go 8
CyberLink PowerDirector 10
CyberLink PowerDVD
D3DX10
Energy Star
eSafe Security Control 1.0.0.2359
Farm Frenzy
Final Drive Fury
FlatOut 2
Google Chrome
Google Update Helper
Governor of Poker 2 Premium Edition
GVU Technologies
Hewlett-Packard ACLM.NET v1.2.0.0
Hoyle Card Games
HP Connected Remote
HP Customer Experience Enhancements
HP Games
HP Keyboard
HP Postscript Converter
HP Registration Service
HP Support Information
IDT Audio
Intel(R) Management Engine Components
Intel® Trusted Connect Service Client
iolo technologies' System Mechanic
iTunes
Jewel Match 3
John Deere Drive Green
Letters from Nowhere 2
Luxor Evolved
Lyrics Kid
Mahjongg Dimensions Deluxe: Tiles in Time
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft Application Error Reporting
Microsoft Office Professional Plus 2013 - en-us
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Mozilla Firefox 21.0 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
NVIDIA Control Panel 305.29
NVIDIA Graphics Driver 305.29
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX System Software 9.12.0613
Office 15 Click-to-Run Extensibility Component
Office 15 Click-to-Run Licensing Component
Office 15 Click-to-Run Localization Component
Peggle Nights
Penguins!
Polar Bowler
Polar Golfer
Qtrax Player
Recovery Manager
Roads of Rome 3
Spybot - Search & Destroy
The Treasures of Mystery Island: The Ghost Ship
Trinklit Supreme
Update Installer for WildTangent Games App
VLC media player 2.0.6
WebCake 3.00
WildTangent Games
WildTangent Games App
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Language Selector
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Zuma's Revenge
.
==== Event Viewer Messages From Past Week ========
.
7/06/2013 9:04:10 PM, Error: Schannel [36870] - A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030D. The internal error state is 10001.
7/06/2013 5:35:49 PM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\windows\System32\bcmihvsrv64.dll Error Code: 126
3/06/2013 7:47:58 PM, Error: Service Control Manager [7034] - The WebCake Desktop Updater service terminated unexpectedly. It has done this 1 time(s).
3/06/2013 7:20:53 PM, Error: Service Control Manager [7034] - The iolo System Service service terminated unexpectedly. It has done this 1 time(s).
2/06/2013 11:36:31 PM, Error: Service Control Manager [7034] - The Desk 365 service service terminated unexpectedly. It has done this 1 time(s).
1/06/2013 1:34:17 PM, Error: Service Control Manager [7030] - The YouTubeDownloaderConverter service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
.
==== End Of File ===========================
