My friend's Windows 8 computer has become infected with Taplika Search and other programs. This happened when she attempted to download and install Chrome but got tricked into downloading malicious software.
The symptom is that browsers have become hijacked by Taplika and ads are popping up constantly including video ads.
Looking at the control panel, some other suspicious programs which just showed up are Pro PC Cleaner, KNTCTR, and snipsmart.
Logs follow:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.17183
Run by [removed] at 20:57:05 on 2014-12-11
Microsoft Windows 8 Single Language 6.2.9200.0.1252.1.1033.18.3970.1453 [GMT -8:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus *Enabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
.
============== Running Processes ===============
.
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Users\Connie\AppData\Roaming\VOPackage\VOsrv.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\snipsmart\updatesnipsmart.exe
C:\Program Files (x86)\snipsmart\bin\utilsnipsmart.exe
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\dashost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
C:\Program Files (x86)\snipsmart\bin\snipsmart.PurBrowse64.exe
C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
C:\Program Files\AVAST Software\Avast\ng\ngtool.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\windows\System32\dwm.exe
C:\windows\system32\taskhostex.exe
C:\windows\Explorer.EXE
C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4396.1016_x64__8wekyb3d8bbwe\LiveComm.exe
C:\Program Files (x86)\Samsung\Settings\sSettings.exe
C:\windows\system32\igfxext.exe
C:\Program Files (x86)\snipsmart\bin\snipsmart.expext.exe
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\snipsmart\bin\snipsmart.BrowserAdapter64.exe
C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
C:\Program Files (x86)\snipsmart\bin\snipsmart.BrowserAdapter.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe
C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\windows\system32\wbem\unsecapp.exe
C:\Program Files\Samsung\S Agent\CommonAgent.exe
C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
C:\windows\ImmersiveControlPanel\SystemSettings.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\windows\system32\taskhost.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
C:\windows\system32\vssvc.exe
C:\windows\System32\svchost.exe -k swprv
C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
\\?\C:\windows\system32\wbem\WMIADAP.EXE
C:\Windows\System32\WUDFHost.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://Taplika.com/?f=1&a=tpl_otbrw1_14 ... 909650&ir=
mWinlogon: Userinit = userinit.exe
BHO: snipsmart 1.0.0.5: {68261aaa-dc9f-4c2b-a168-c323e304c3a2} - C:\Program Files (x86)\snipsmart\snipsmartbho.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [Driver Support] C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe /applicationMode:systemTray /showWelcome:false
uRun: [Itibiti.exe] C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe
mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
mRun: [CLMLServer_For_P2G8] "C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
mRun: [CLVirtualDrive] "C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mExplorerRun: [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
mPolicies-System: DisableCAD = dword:1
mPolicies-System: SoftwareSASGeneration = dword:1
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{0C1EBBCF-314B-4A8A-8D72-8D764850C655} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{0C1EBBCF-314B-4A8A-8D72-8D764850C655}\16378666F62746 : DHCPNameServer = [removed] [removed]
TCP: Interfaces\{0C1EBBCF-314B-4A8A-8D72-8D764850C655}\57E696175756F57657563747 : DHCPNameServer = 10.0.0.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\SysWow64\CbFsMntNtf3.dll
STS: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /S3HpProtect
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [Bitcasa] C:\Program Files\Bitcasa\Bitcasa.exe /startup
x64-Run: [IgfxTray] C:\windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\windows\System32\igfxpers.exe
x64-ExplorerRun: [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
x64-mPolicies-System: DisableCAD = dword:1
x64-mPolicies-System: SoftwareSASGeneration = dword:1
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\System32\CbFsMntNtf3.dll
x64-STS: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\System32\CbFsMntNtf3.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswNdisFlt;Avast! Firewall Driver;C:\windows\System32\Drivers\aswNdisFlt.sys [2014-12-11 449936]
R0 aswRvrt;avast! Revert;C:\windows\System32\Drivers\aswRvrt.sys [2014-7-12 65776]
R0 aswVmm;avast! VM Monitor;C:\windows\System32\Drivers\aswVmm.sys [2014-7-12 267632]
R0 iaStorA;iaStorA;C:\windows\System32\Drivers\iaStorA.sys [2013-5-24 652344]
R0 PxHlpa64;PxHlpa64;C:\windows\System32\Drivers\PxHlpa64.sys [2013-5-24 56336]
R1 {1993b064-46e3-4c7d-8b20-2161564a7685}Gw64;{1993b064-46e3-4c7d-8b20-2161564a7685}Gw64;C:\windows\System32\Drivers\{1993b064-46e3-4c7d-8b20-2161564a7685}Gw64.sys [2014-12-11 48784]
R1 aswKbd;aswKbd;C:\windows\System32\Drivers\aswKbd.sys [2014-12-11 28184]
R1 aswSnx;aswSnx;C:\windows\System32\Drivers\aswsnx.sys [2014-7-12 1050432]
R1 aswSP;aswSP;C:\windows\System32\Drivers\aswsp.sys [2014-7-12 436624]
R1 cbfs3;cbfs3;C:\windows\System32\Drivers\cbfs3.sys [2013-5-24 352456]
R1 CLVirtualDrive;CLVirtualDrive;C:\windows\System32\Drivers\CLVirtualDrive.sys [2013-5-24 92536]
R2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [2013-1-26 172104]
R2 aswHwid;avast! HardwareID;C:\windows\System32\Drivers\aswHwid.sys [2014-7-12 29208]
R2 aswMonFlt;aswMonFlt;C:\windows\System32\Drivers\aswMonFlt.sys [2014-7-12 83280]
R2 aswStm;aswStm;C:\windows\System32\Drivers\aswStm.sys [2014-7-12 116728]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2014-1-7 318592]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-12-11 50344]
R2 avast! Firewall;avast! Firewall;C:\Program Files\AVAST Software\Avast\afwServ.exe [2014-12-11 104416]
R2 Easy Launcher;Easy Launcher;C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [2013-1-31 1594416]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-9 732160]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-5-24 131032]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-5-24 165336]
R2 servervo;VO Service component;C:\Users\Connie\AppData\Roaming\VOPackage\VOsrv.exe [2014-12-11 133120]
R2 SWUpdateService;SW Update Service;C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [2014-4-4 3020632]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-5-24 366040]
R2 Update snipsmart;Update snipsmart;C:\Program Files (x86)\snipsmart\updatesnipsmart.exe [2014-12-11 524016]
R2 Util snipsmart;Util snipsmart;C:\Program Files (x86)\snipsmart\bin\utilsnipsmart.exe [2014-12-11 524016]
R2 VBoxAswDrv;VBoxAsw Support Driver;C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2014-12-11 271752]
R2 ZAtheros Bt and Wlan Coex Agent;ZAtheros Bt and Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2014-1-7 323584]
R3 AvastVBoxSvc;AvastVBox COM Service;C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2014-12-11 4012248]
R3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;C:\windows\System32\Drivers\btath_bus.sys [2014-1-7 34384]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-5-24 169752]
R3 IntcDAud;Intel(R) Display Audio;C:\windows\System32\Drivers\IntcDAud.sys [2013-1-22 342528]
R3 RadioHIDMini;Radio HID Mini-driver;C:\windows\System32\Drivers\RadioHIDMini.sys [2012-11-13 23408]
R3 RTL8168;Realtek 8168 NT Driver;C:\windows\System32\Drivers\Rt630x64.sys [2013-5-24 719504]
S3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;C:\windows\System32\Drivers\btath_flt.sys [2014-1-7 89800]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\windows\System32\Drivers\btath_a2dp.sys [2014-1-7 338120]
S3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;C:\windows\System32\Drivers\btath_avdt.sys [2014-1-7 116424]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\windows\System32\Drivers\btath_hcrp.sys [2014-1-7 179432]
S3 BTATH_HID;Bluetooth HID Device;C:\windows\System32\Drivers\btath_hid.sys [2014-1-7 223432]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\windows\System32\Drivers\btath_lwflt.sys [2014-1-7 77464]
S3 BTATH_RCP;Bluetooth AVRCP Device;C:\windows\System32\Drivers\btath_rcp.sys [2014-1-7 137928]
S3 BtFilter;BtFilter;C:\windows\System32\Drivers\btfilter.sys [2014-1-7 597192]
S3 BthLEEnum;Bluetooth Low Energy Driver;C:\windows\System32\Drivers\BthLEEnum.sys [2012-7-25 202752]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-9 803872]
.
=============== Created Last 30 ================
.
2014-12-12 03:03:46 -------- d-----w- C:\windows\SysWow64\vbox
2014-12-12 03:03:46 -------- d-----w- C:\windows\System32\vbox
2014-12-12 02:54:44 28184 ----a-w- C:\windows\System32\drivers\aswKbd.sys
2014-12-12 02:54:30 43152 ----a-w- C:\windows\avastSS.scr
2014-12-12 02:53:45 449936 ----a-w- C:\windows\System32\drivers\aswNdisFlt.sys
2014-12-12 02:50:05 48784 ----a-w- C:\windows\System32\drivers\{1993b064-46e3-4c7d-8b20-2161564a7685}Gw64.sys
2014-12-12 02:45:19 -------- d-----w- C:\Users\Connie\AppData\Local\Google
2014-12-12 02:44:21 -------- d-----w- C:\Users\Connie\AppData\Roaming\VOPackage
2014-12-12 02:42:03 -------- d-----w- C:\Users\Connie\AppData\Roaming\Itibiti
2014-12-12 02:41:41 -------- d-----w- C:\Users\Connie\AppData\Local\Pro_PC_Cleaner
2014-12-12 02:41:39 -------- d-----w- C:\Program Files (x86)\Itibiti Soft Phone
2014-12-12 02:41:35 -------- d-sh--w- C:\windows\SysWow64\AI_RecycleBin
2014-12-12 02:41:25 -------- d-----w- C:\Program Files (x86)\Pro PC Cleaner
2014-12-12 02:41:02 -------- d-----w- C:\Users\Connie\AppData\Roaming\Pro PC Cleaner
2014-12-12 02:40:14 -------- d-----w- C:\Program Files (x86)\snipsmart
2014-12-11 17:30:07 714184 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2014-12-11 17:30:07 106440 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-12-11 17:28:05 -------- d-----w- C:\windows\System32\appraiser
2014-12-11 04:30:45 69632 ----a-w- C:\windows\System32\vsstrace.dll
2014-12-11 04:30:45 52224 ----a-w- C:\windows\SysWow64\vsstrace.dll
2014-12-11 04:30:44 1195520 ----a-w- C:\windows\SysWow64\vssapi.dll
2014-12-11 04:30:43 1519104 ----a-w- C:\windows\System32\vssapi.dll
2014-12-11 04:30:42 1484288 ----a-w- C:\windows\System32\VSSVC.exe
2014-12-10 18:43:58 673792 ----a-w- C:\windows\System32\mfmpeg2srcsnk.dll
2014-12-10 18:43:57 513536 ----a-w- C:\windows\SysWow64\mfmpeg2srcsnk.dll
2014-12-10 18:43:54 212992 ----a-w- C:\windows\System32\dnsrslvr.dll
2014-12-10 18:40:25 1890816 ----a-w- C:\windows\System32\crypt32.dll
2014-12-10 18:40:24 1569792 ----a-w- C:\windows\SysWow64\crypt32.dll
2014-11-26 16:44:27 582552 ----a-w- C:\windows\System32\AutoUpdate.exe
2014-11-26 16:44:27 462760 ----a-w- C:\windows\System32\NotificationUI.exe
2014-11-18 19:54:20 827904 ----a-w- C:\windows\System32\kerberos.dll
2014-11-18 19:54:20 666624 ----a-w- C:\windows\SysWow64\kerberos.dll
2014-11-18 19:54:18 238080 ----a-w- C:\windows\System32\pku2u.dll
2014-11-18 19:54:18 187904 ----a-w- C:\windows\SysWow64\pku2u.dll
2014-11-16 00:10:29 269992 ----a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10248.bin
2014-11-12 13:42:57 2837504 ----a-w- C:\windows\System32\WsmSvc.dll
.
==================== Find3M ====================
.
2014-12-12 02:55:12 1050432 ----a-w- C:\windows\System32\drivers\aswsnx.sys
2014-12-12 02:54:31 93568 ----a-w- C:\windows\System32\drivers\aswRdr2.sys
2014-12-12 02:54:31 83280 ----a-w- C:\windows\System32\drivers\aswMonFlt.sys
2014-12-12 02:54:31 65776 ----a-w- C:\windows\System32\drivers\aswRvrt.sys
2014-12-12 02:54:31 29208 ----a-w- C:\windows\System32\drivers\aswHwid.sys
2014-12-12 02:54:31 267632 ----a-w- C:\windows\System32\drivers\aswVmm.sys
2014-12-12 02:54:31 116728 ----a-w- C:\windows\System32\drivers\aswStm.sys
2014-12-05 01:41:41 740864 ----a-w- C:\windows\System32\invagent.dll
2014-12-05 01:41:22 396288 ----a-w- C:\windows\System32\devinv.dll
2014-12-05 01:41:01 830464 ----a-w- C:\windows\System32\appraiser.dll
2014-12-05 01:40:59 227328 ----a-w- C:\windows\System32\aepdu.dll
2014-12-03 01:48:02 412672 ----a-w- C:\windows\System32\generaltel.dll
2014-12-03 01:48:01 192000 ----a-w- C:\windows\System32\aepic.dll
2014-12-03 01:48:01 1083392 ----a-w- C:\windows\System32\aeinv.dll
2014-11-21 08:38:00 2237952 ----a-w- C:\windows\System32\wininet.dll
2014-11-21 08:37:51 915968 ----a-w- C:\windows\System32\uxtheme.dll
2014-11-21 08:37:51 53760 ----a-w- C:\windows\System32\UXInit.dll
2014-11-21 08:36:24 3959296 ----a-w- C:\windows\System32\jscript9.dll
2014-11-21 08:36:17 67072 ----a-w- C:\windows\System32\iesetup.dll
2014-11-21 08:36:17 136704 ----a-w- C:\windows\System32\iesysprep.dll
2014-11-21 08:35:42 1509376 ----a-w- C:\windows\System32\inetcpl.cpl
2014-11-21 07:17:51 1762816 ----a-w- C:\windows\SysWow64\wininet.dll
2014-11-21 07:17:44 44032 ----a-w- C:\windows\SysWow64\UXInit.dll
2014-11-21 07:16:46 2861568 ----a-w- C:\windows\SysWow64\jscript9.dll
2014-11-21 07:16:42 61440 ----a-w- C:\windows\SysWow64\iesetup.dll
2014-11-21 07:16:42 109056 ----a-w- C:\windows\SysWow64\iesysprep.dll
2014-11-21 07:16:16 1441280 ----a-w- C:\windows\SysWow64\inetcpl.cpl
2014-11-21 07:00:18 2706432 ----a-w- C:\windows\System32\mshtml.tlb
2014-11-21 06:54:49 2706432 ----a-w- C:\windows\SysWow64\mshtml.tlb
2014-11-21 04:30:26 534528 ----a-w- C:\windows\SysWow64\uxtheme.dll
2014-11-06 06:50:46 1627648 ----a-w- C:\windows\System32\WindowsCodecs.dll
2014-11-06 05:03:42 1339392 ----a-w- C:\windows\SysWow64\WindowsCodecs.dll
2014-10-23 12:47:53 79872 ----a-w- C:\windows\System32\packager.dll
2014-10-23 11:04:41 68096 ----a-w- C:\windows\SysWow64\packager.dll
2014-10-22 01:08:16 568832 ----a-w- C:\windows\SysWow64\WSShared.dll
2014-10-22 01:08:16 124928 ----a-w- C:\windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-22 01:01:22 695808 ----a-w- C:\windows\System32\WSShared.dll
2014-10-22 01:01:22 198656 ----a-w- C:\windows\System32\Windows.ApplicationModel.Store.dll
2014-10-22 01:01:22 163840 ----a-w- C:\windows\System32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-22 01:00:53 125952 ----a-w- C:\windows\System32\WinSetupUI.dll
2014-10-18 08:44:05 778240 ----a-w- C:\windows\System32\oleaut32.dll
2014-10-18 07:05:16 567808 ----a-w- C:\windows\SysWow64\oleaut32.dll
2014-10-11 08:35:58 171840 ----a-w- C:\windows\System32\drivers\ksecpkg.sys
2014-10-11 07:45:07 10115072 ----a-w- C:\windows\System32\twinui.dll
2014-10-11 07:44:56 588288 ----a-w- C:\windows\System32\SHCore.dll
2014-10-11 07:44:47 3248640 ----a-w- C:\windows\System32\rdpcorets.dll
2014-10-11 07:44:07 393216 ----a-w- C:\windows\System32\msihnd.dll
2014-10-11 07:44:07 2885632 ----a-w- C:\windows\System32\msi.dll
2014-10-11 07:43:51 1281536 ----a-w- C:\windows\System32\lsasrv.dll
2014-10-11 07:43:08 2307072 ----a-w- C:\windows\System32\authui.dll
2014-10-11 05:58:05 8858624 ----a-w- C:\windows\SysWow64\twinui.dll
2014-10-11 05:57:57 452608 ----a-w- C:\windows\SysWow64\SHCore.dll
2014-10-11 05:57:21 295424 ----a-w- C:\windows\SysWow64\msihnd.dll
2014-10-11 05:57:21 2416640 ----a-w- C:\windows\SysWow64\msi.dll
2014-10-11 05:56:37 2037760 ----a-w- C:\windows\SysWow64\authui.dll
2014-10-11 05:41:57 146944 ----a-w- C:\windows\System32\msaudite.dll
2014-10-11 05:41:43 713728 ----a-w- C:\windows\System32\adtschema.dll
2014-10-11 05:05:20 146944 ----a-w- C:\windows\SysWow64\msaudite.dll
2014-10-11 05:04:59 713728 ----a-w- C:\windows\SysWow64\adtschema.dll
2014-10-03 01:21:18 522728 ----a-w- C:\windows\System32\AUDIOKSE.dll
2014-10-02 22:29:25 267264 ----a-w- C:\windows\System32\EncDump.dll
2014-10-02 22:29:16 783872 ----a-w- C:\windows\System32\audiosrv.dll
2014-10-02 22:29:16 169472 ----a-w- C:\windows\System32\AudioEndpointBuilder.dll
2014-10-01 23:05:12 4068864 ----a-w- C:\windows\System32\win32k.sys
2014-09-24 23:29:59 318976 ----a-w- C:\windows\SysWow64\schannel.dll
2014-09-24 23:29:51 72192 ----a-w- C:\windows\SysWow64\ncryptsslp.dll
2014-09-24 23:01:14 414208 ----a-w- C:\windows\System32\schannel.dll
2014-09-24 23:01:00 86528 ----a-w- C:\windows\System32\ncryptsslp.dll
2014-09-22 05:53:10 35320 ----a-w- C:\windows\System32\drivers\WdBoot.sys
2014-09-13 06:24:47 2233152 ----a-w- C:\windows\System32\drivers\tcpip.sys
.
============= FINISH: 20:58:55.95 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 8 Single Language
Boot Device: \Device\HarddiskVolume2
Install Date: 7/12/2014 8:22:29 PM
System Uptime: 12/11/2014 7:28:07 PM (1 hours ago)
.
Motherboard: SAMSUNG ELECTRONICS CO., LTD. | | NP270E4E-K01JM
Processor: Intel(R) Celeron(R) CPU 1007U @ 1.50GHz | CPU Socket - U3E1 | 800/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 442 GiB total, 395.689 GiB free.
D: is CDROM ()
E: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft Teredo Tunneling Adapter
Device ID: ROOT\*TEREDO\0000
Manufacturer: Microsoft
Name: Teredo Tunneling Pseudo-Interface
PNP Device ID: ROOT\*TEREDO\0000
Service: tunnel
.
Class GUID: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Description: Qualcomm Atheros AR3012 Bluetooth 4.0 + HS
Device ID: USB\VID_0CF3&PID_3004\ALASKA_DAY_2006
Manufacturer: Qualcomm Atheros Communications
Name: Qualcomm Atheros AR3012 Bluetooth 4.0 + HS
PNP Device ID: USB\VID_0CF3&PID_3004\ALASKA_DAY_2006
Service: BTHUSB
.
==== System Restore Points ===================
.
RP21: 11/12/2014 7:58:18 PM - Windows Update
RP22: 11/18/2014 4:12:24 PM - Windows Update
RP23: 11/26/2014 9:21:03 AM - Windows Update
RP24: 12/10/2014 8:11:24 PM - Windows Update
.
==== Installed Programs ======================
.
Adobe Photoshop Elements 11
Adobe Reader X (10.1.13) MUI
Avast Internet Security
Bitcasa version 0.9.20.4135
CyberLink Power2Go 8
CyberLink PowerDVD 10
D3DX10
Driver Support
E-POP
Easy File Share
Elements 11 Organizer
Help Desk
Intel(R) Manageability Engine Firmware Recovery Agent
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) Rapid Storage Technology
Intel(R) SDK for OpenCL - CPU Only Runtime Package
Intel® Trusted Connect Service Client
Itibiti RTC
KNCTR
Microsoft Application Error Reporting
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Movie Maker
MSVCRT
MSVCRT110
MSVCRT110_amd64
OpenOffice 4.1.0
Photo Common
Photo Gallery
Pro PC Cleaner
PSE11 STI Installer
Qualcomm Atheros Bluetooth Suite (64)
Qualcomm Atheros Client Installation Program
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Recovery
Remote Desktop Access (VuuPC)
S Agent
Samsung Kies
SAMSUNG USB Driver for Mobile Phones
Settings
snipsmart
Support Center
Support Center FAQ
SW Update
Synaptics Pointing Device Driver
User Guide
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
WordBiz 1.8.7
.
==== Event Viewer Messages From Past Week ========
.
12/9/2014 12:39:39 AM, Error: Schannel [36887] - A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 70.
12/9/2014 12:39:39 AM, Error: Schannel [36887] - A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 40.
12/11/2014 8:27:39 PM, Error: Microsoft-Windows-Kernel-Power [137] - The system firmware has changed the processor's memory type range registers (MTRRs) across a sleep state transition (S4). This can result in reduced resume performance.
12/11/2014 7:29:59 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service AvastVBoxSvc with arguments "Unavailable" in order to run the server: {F319F1B8-7587-4146-AF9C-0D6D77819BF1}
12/11/2014 7:29:57 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the AvastVBox COM Service service to connect.
12/11/2014 7:29:57 PM, Error: Service Control Manager [7000] - The AvastVBox COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/11/2014 7:28:14 PM, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
.
==== End Of File ===========================
The symptom is that browsers have become hijacked by Taplika and ads are popping up constantly including video ads.
Looking at the control panel, some other suspicious programs which just showed up are Pro PC Cleaner, KNTCTR, and snipsmart.
Logs follow:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.17183
Run by [removed] at 20:57:05 on 2014-12-11
Microsoft Windows 8 Single Language 6.2.9200.0.1252.1.1033.18.3970.1453 [GMT -8:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus *Enabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
.
============== Running Processes ===============
.
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Users\Connie\AppData\Roaming\VOPackage\VOsrv.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\snipsmart\updatesnipsmart.exe
C:\Program Files (x86)\snipsmart\bin\utilsnipsmart.exe
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\dashost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
C:\Program Files (x86)\snipsmart\bin\snipsmart.PurBrowse64.exe
C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
C:\Program Files\AVAST Software\Avast\ng\ngtool.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\windows\System32\dwm.exe
C:\windows\system32\taskhostex.exe
C:\windows\Explorer.EXE
C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4396.1016_x64__8wekyb3d8bbwe\LiveComm.exe
C:\Program Files (x86)\Samsung\Settings\sSettings.exe
C:\windows\system32\igfxext.exe
C:\Program Files (x86)\snipsmart\bin\snipsmart.expext.exe
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\snipsmart\bin\snipsmart.BrowserAdapter64.exe
C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
C:\Program Files (x86)\snipsmart\bin\snipsmart.BrowserAdapter.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe
C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\windows\system32\wbem\unsecapp.exe
C:\Program Files\Samsung\S Agent\CommonAgent.exe
C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
C:\windows\ImmersiveControlPanel\SystemSettings.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\windows\system32\taskhost.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
C:\windows\system32\vssvc.exe
C:\windows\System32\svchost.exe -k swprv
C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
\\?\C:\windows\system32\wbem\WMIADAP.EXE
C:\Windows\System32\WUDFHost.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://Taplika.com/?f=1&a=tpl_otbrw1_14 ... 909650&ir=
mWinlogon: Userinit = userinit.exe
BHO: snipsmart 1.0.0.5: {68261aaa-dc9f-4c2b-a168-c323e304c3a2} - C:\Program Files (x86)\snipsmart\snipsmartbho.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [Driver Support] C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe /applicationMode:systemTray /showWelcome:false
uRun: [Itibiti.exe] C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe
mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
mRun: [CLMLServer_For_P2G8] "C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
mRun: [CLVirtualDrive] "C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mExplorerRun: [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
mPolicies-System: DisableCAD = dword:1
mPolicies-System: SoftwareSASGeneration = dword:1
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{0C1EBBCF-314B-4A8A-8D72-8D764850C655} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{0C1EBBCF-314B-4A8A-8D72-8D764850C655}\16378666F62746 : DHCPNameServer = [removed] [removed]
TCP: Interfaces\{0C1EBBCF-314B-4A8A-8D72-8D764850C655}\57E696175756F57657563747 : DHCPNameServer = 10.0.0.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\SysWow64\CbFsMntNtf3.dll
STS: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /S3HpProtect
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [Bitcasa] C:\Program Files\Bitcasa\Bitcasa.exe /startup
x64-Run: [IgfxTray] C:\windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\windows\System32\igfxpers.exe
x64-ExplorerRun: [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
x64-mPolicies-System: DisableCAD = dword:1
x64-mPolicies-System: SoftwareSASGeneration = dword:1
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\System32\CbFsMntNtf3.dll
x64-STS: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\System32\CbFsMntNtf3.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswNdisFlt;Avast! Firewall Driver;C:\windows\System32\Drivers\aswNdisFlt.sys [2014-12-11 449936]
R0 aswRvrt;avast! Revert;C:\windows\System32\Drivers\aswRvrt.sys [2014-7-12 65776]
R0 aswVmm;avast! VM Monitor;C:\windows\System32\Drivers\aswVmm.sys [2014-7-12 267632]
R0 iaStorA;iaStorA;C:\windows\System32\Drivers\iaStorA.sys [2013-5-24 652344]
R0 PxHlpa64;PxHlpa64;C:\windows\System32\Drivers\PxHlpa64.sys [2013-5-24 56336]
R1 {1993b064-46e3-4c7d-8b20-2161564a7685}Gw64;{1993b064-46e3-4c7d-8b20-2161564a7685}Gw64;C:\windows\System32\Drivers\{1993b064-46e3-4c7d-8b20-2161564a7685}Gw64.sys [2014-12-11 48784]
R1 aswKbd;aswKbd;C:\windows\System32\Drivers\aswKbd.sys [2014-12-11 28184]
R1 aswSnx;aswSnx;C:\windows\System32\Drivers\aswsnx.sys [2014-7-12 1050432]
R1 aswSP;aswSP;C:\windows\System32\Drivers\aswsp.sys [2014-7-12 436624]
R1 cbfs3;cbfs3;C:\windows\System32\Drivers\cbfs3.sys [2013-5-24 352456]
R1 CLVirtualDrive;CLVirtualDrive;C:\windows\System32\Drivers\CLVirtualDrive.sys [2013-5-24 92536]
R2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [2013-1-26 172104]
R2 aswHwid;avast! HardwareID;C:\windows\System32\Drivers\aswHwid.sys [2014-7-12 29208]
R2 aswMonFlt;aswMonFlt;C:\windows\System32\Drivers\aswMonFlt.sys [2014-7-12 83280]
R2 aswStm;aswStm;C:\windows\System32\Drivers\aswStm.sys [2014-7-12 116728]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2014-1-7 318592]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-12-11 50344]
R2 avast! Firewall;avast! Firewall;C:\Program Files\AVAST Software\Avast\afwServ.exe [2014-12-11 104416]
R2 Easy Launcher;Easy Launcher;C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [2013-1-31 1594416]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-9 732160]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-5-24 131032]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-5-24 165336]
R2 servervo;VO Service component;C:\Users\Connie\AppData\Roaming\VOPackage\VOsrv.exe [2014-12-11 133120]
R2 SWUpdateService;SW Update Service;C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [2014-4-4 3020632]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-5-24 366040]
R2 Update snipsmart;Update snipsmart;C:\Program Files (x86)\snipsmart\updatesnipsmart.exe [2014-12-11 524016]
R2 Util snipsmart;Util snipsmart;C:\Program Files (x86)\snipsmart\bin\utilsnipsmart.exe [2014-12-11 524016]
R2 VBoxAswDrv;VBoxAsw Support Driver;C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2014-12-11 271752]
R2 ZAtheros Bt and Wlan Coex Agent;ZAtheros Bt and Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2014-1-7 323584]
R3 AvastVBoxSvc;AvastVBox COM Service;C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2014-12-11 4012248]
R3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;C:\windows\System32\Drivers\btath_bus.sys [2014-1-7 34384]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-5-24 169752]
R3 IntcDAud;Intel(R) Display Audio;C:\windows\System32\Drivers\IntcDAud.sys [2013-1-22 342528]
R3 RadioHIDMini;Radio HID Mini-driver;C:\windows\System32\Drivers\RadioHIDMini.sys [2012-11-13 23408]
R3 RTL8168;Realtek 8168 NT Driver;C:\windows\System32\Drivers\Rt630x64.sys [2013-5-24 719504]
S3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;C:\windows\System32\Drivers\btath_flt.sys [2014-1-7 89800]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\windows\System32\Drivers\btath_a2dp.sys [2014-1-7 338120]
S3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;C:\windows\System32\Drivers\btath_avdt.sys [2014-1-7 116424]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\windows\System32\Drivers\btath_hcrp.sys [2014-1-7 179432]
S3 BTATH_HID;Bluetooth HID Device;C:\windows\System32\Drivers\btath_hid.sys [2014-1-7 223432]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\windows\System32\Drivers\btath_lwflt.sys [2014-1-7 77464]
S3 BTATH_RCP;Bluetooth AVRCP Device;C:\windows\System32\Drivers\btath_rcp.sys [2014-1-7 137928]
S3 BtFilter;BtFilter;C:\windows\System32\Drivers\btfilter.sys [2014-1-7 597192]
S3 BthLEEnum;Bluetooth Low Energy Driver;C:\windows\System32\Drivers\BthLEEnum.sys [2012-7-25 202752]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-9 803872]
.
=============== Created Last 30 ================
.
2014-12-12 03:03:46 -------- d-----w- C:\windows\SysWow64\vbox
2014-12-12 03:03:46 -------- d-----w- C:\windows\System32\vbox
2014-12-12 02:54:44 28184 ----a-w- C:\windows\System32\drivers\aswKbd.sys
2014-12-12 02:54:30 43152 ----a-w- C:\windows\avastSS.scr
2014-12-12 02:53:45 449936 ----a-w- C:\windows\System32\drivers\aswNdisFlt.sys
2014-12-12 02:50:05 48784 ----a-w- C:\windows\System32\drivers\{1993b064-46e3-4c7d-8b20-2161564a7685}Gw64.sys
2014-12-12 02:45:19 -------- d-----w- C:\Users\Connie\AppData\Local\Google
2014-12-12 02:44:21 -------- d-----w- C:\Users\Connie\AppData\Roaming\VOPackage
2014-12-12 02:42:03 -------- d-----w- C:\Users\Connie\AppData\Roaming\Itibiti
2014-12-12 02:41:41 -------- d-----w- C:\Users\Connie\AppData\Local\Pro_PC_Cleaner
2014-12-12 02:41:39 -------- d-----w- C:\Program Files (x86)\Itibiti Soft Phone
2014-12-12 02:41:35 -------- d-sh--w- C:\windows\SysWow64\AI_RecycleBin
2014-12-12 02:41:25 -------- d-----w- C:\Program Files (x86)\Pro PC Cleaner
2014-12-12 02:41:02 -------- d-----w- C:\Users\Connie\AppData\Roaming\Pro PC Cleaner
2014-12-12 02:40:14 -------- d-----w- C:\Program Files (x86)\snipsmart
2014-12-11 17:30:07 714184 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2014-12-11 17:30:07 106440 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-12-11 17:28:05 -------- d-----w- C:\windows\System32\appraiser
2014-12-11 04:30:45 69632 ----a-w- C:\windows\System32\vsstrace.dll
2014-12-11 04:30:45 52224 ----a-w- C:\windows\SysWow64\vsstrace.dll
2014-12-11 04:30:44 1195520 ----a-w- C:\windows\SysWow64\vssapi.dll
2014-12-11 04:30:43 1519104 ----a-w- C:\windows\System32\vssapi.dll
2014-12-11 04:30:42 1484288 ----a-w- C:\windows\System32\VSSVC.exe
2014-12-10 18:43:58 673792 ----a-w- C:\windows\System32\mfmpeg2srcsnk.dll
2014-12-10 18:43:57 513536 ----a-w- C:\windows\SysWow64\mfmpeg2srcsnk.dll
2014-12-10 18:43:54 212992 ----a-w- C:\windows\System32\dnsrslvr.dll
2014-12-10 18:40:25 1890816 ----a-w- C:\windows\System32\crypt32.dll
2014-12-10 18:40:24 1569792 ----a-w- C:\windows\SysWow64\crypt32.dll
2014-11-26 16:44:27 582552 ----a-w- C:\windows\System32\AutoUpdate.exe
2014-11-26 16:44:27 462760 ----a-w- C:\windows\System32\NotificationUI.exe
2014-11-18 19:54:20 827904 ----a-w- C:\windows\System32\kerberos.dll
2014-11-18 19:54:20 666624 ----a-w- C:\windows\SysWow64\kerberos.dll
2014-11-18 19:54:18 238080 ----a-w- C:\windows\System32\pku2u.dll
2014-11-18 19:54:18 187904 ----a-w- C:\windows\SysWow64\pku2u.dll
2014-11-16 00:10:29 269992 ----a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10248.bin
2014-11-12 13:42:57 2837504 ----a-w- C:\windows\System32\WsmSvc.dll
.
==================== Find3M ====================
.
2014-12-12 02:55:12 1050432 ----a-w- C:\windows\System32\drivers\aswsnx.sys
2014-12-12 02:54:31 93568 ----a-w- C:\windows\System32\drivers\aswRdr2.sys
2014-12-12 02:54:31 83280 ----a-w- C:\windows\System32\drivers\aswMonFlt.sys
2014-12-12 02:54:31 65776 ----a-w- C:\windows\System32\drivers\aswRvrt.sys
2014-12-12 02:54:31 29208 ----a-w- C:\windows\System32\drivers\aswHwid.sys
2014-12-12 02:54:31 267632 ----a-w- C:\windows\System32\drivers\aswVmm.sys
2014-12-12 02:54:31 116728 ----a-w- C:\windows\System32\drivers\aswStm.sys
2014-12-05 01:41:41 740864 ----a-w- C:\windows\System32\invagent.dll
2014-12-05 01:41:22 396288 ----a-w- C:\windows\System32\devinv.dll
2014-12-05 01:41:01 830464 ----a-w- C:\windows\System32\appraiser.dll
2014-12-05 01:40:59 227328 ----a-w- C:\windows\System32\aepdu.dll
2014-12-03 01:48:02 412672 ----a-w- C:\windows\System32\generaltel.dll
2014-12-03 01:48:01 192000 ----a-w- C:\windows\System32\aepic.dll
2014-12-03 01:48:01 1083392 ----a-w- C:\windows\System32\aeinv.dll
2014-11-21 08:38:00 2237952 ----a-w- C:\windows\System32\wininet.dll
2014-11-21 08:37:51 915968 ----a-w- C:\windows\System32\uxtheme.dll
2014-11-21 08:37:51 53760 ----a-w- C:\windows\System32\UXInit.dll
2014-11-21 08:36:24 3959296 ----a-w- C:\windows\System32\jscript9.dll
2014-11-21 08:36:17 67072 ----a-w- C:\windows\System32\iesetup.dll
2014-11-21 08:36:17 136704 ----a-w- C:\windows\System32\iesysprep.dll
2014-11-21 08:35:42 1509376 ----a-w- C:\windows\System32\inetcpl.cpl
2014-11-21 07:17:51 1762816 ----a-w- C:\windows\SysWow64\wininet.dll
2014-11-21 07:17:44 44032 ----a-w- C:\windows\SysWow64\UXInit.dll
2014-11-21 07:16:46 2861568 ----a-w- C:\windows\SysWow64\jscript9.dll
2014-11-21 07:16:42 61440 ----a-w- C:\windows\SysWow64\iesetup.dll
2014-11-21 07:16:42 109056 ----a-w- C:\windows\SysWow64\iesysprep.dll
2014-11-21 07:16:16 1441280 ----a-w- C:\windows\SysWow64\inetcpl.cpl
2014-11-21 07:00:18 2706432 ----a-w- C:\windows\System32\mshtml.tlb
2014-11-21 06:54:49 2706432 ----a-w- C:\windows\SysWow64\mshtml.tlb
2014-11-21 04:30:26 534528 ----a-w- C:\windows\SysWow64\uxtheme.dll
2014-11-06 06:50:46 1627648 ----a-w- C:\windows\System32\WindowsCodecs.dll
2014-11-06 05:03:42 1339392 ----a-w- C:\windows\SysWow64\WindowsCodecs.dll
2014-10-23 12:47:53 79872 ----a-w- C:\windows\System32\packager.dll
2014-10-23 11:04:41 68096 ----a-w- C:\windows\SysWow64\packager.dll
2014-10-22 01:08:16 568832 ----a-w- C:\windows\SysWow64\WSShared.dll
2014-10-22 01:08:16 124928 ----a-w- C:\windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-22 01:01:22 695808 ----a-w- C:\windows\System32\WSShared.dll
2014-10-22 01:01:22 198656 ----a-w- C:\windows\System32\Windows.ApplicationModel.Store.dll
2014-10-22 01:01:22 163840 ----a-w- C:\windows\System32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-22 01:00:53 125952 ----a-w- C:\windows\System32\WinSetupUI.dll
2014-10-18 08:44:05 778240 ----a-w- C:\windows\System32\oleaut32.dll
2014-10-18 07:05:16 567808 ----a-w- C:\windows\SysWow64\oleaut32.dll
2014-10-11 08:35:58 171840 ----a-w- C:\windows\System32\drivers\ksecpkg.sys
2014-10-11 07:45:07 10115072 ----a-w- C:\windows\System32\twinui.dll
2014-10-11 07:44:56 588288 ----a-w- C:\windows\System32\SHCore.dll
2014-10-11 07:44:47 3248640 ----a-w- C:\windows\System32\rdpcorets.dll
2014-10-11 07:44:07 393216 ----a-w- C:\windows\System32\msihnd.dll
2014-10-11 07:44:07 2885632 ----a-w- C:\windows\System32\msi.dll
2014-10-11 07:43:51 1281536 ----a-w- C:\windows\System32\lsasrv.dll
2014-10-11 07:43:08 2307072 ----a-w- C:\windows\System32\authui.dll
2014-10-11 05:58:05 8858624 ----a-w- C:\windows\SysWow64\twinui.dll
2014-10-11 05:57:57 452608 ----a-w- C:\windows\SysWow64\SHCore.dll
2014-10-11 05:57:21 295424 ----a-w- C:\windows\SysWow64\msihnd.dll
2014-10-11 05:57:21 2416640 ----a-w- C:\windows\SysWow64\msi.dll
2014-10-11 05:56:37 2037760 ----a-w- C:\windows\SysWow64\authui.dll
2014-10-11 05:41:57 146944 ----a-w- C:\windows\System32\msaudite.dll
2014-10-11 05:41:43 713728 ----a-w- C:\windows\System32\adtschema.dll
2014-10-11 05:05:20 146944 ----a-w- C:\windows\SysWow64\msaudite.dll
2014-10-11 05:04:59 713728 ----a-w- C:\windows\SysWow64\adtschema.dll
2014-10-03 01:21:18 522728 ----a-w- C:\windows\System32\AUDIOKSE.dll
2014-10-02 22:29:25 267264 ----a-w- C:\windows\System32\EncDump.dll
2014-10-02 22:29:16 783872 ----a-w- C:\windows\System32\audiosrv.dll
2014-10-02 22:29:16 169472 ----a-w- C:\windows\System32\AudioEndpointBuilder.dll
2014-10-01 23:05:12 4068864 ----a-w- C:\windows\System32\win32k.sys
2014-09-24 23:29:59 318976 ----a-w- C:\windows\SysWow64\schannel.dll
2014-09-24 23:29:51 72192 ----a-w- C:\windows\SysWow64\ncryptsslp.dll
2014-09-24 23:01:14 414208 ----a-w- C:\windows\System32\schannel.dll
2014-09-24 23:01:00 86528 ----a-w- C:\windows\System32\ncryptsslp.dll
2014-09-22 05:53:10 35320 ----a-w- C:\windows\System32\drivers\WdBoot.sys
2014-09-13 06:24:47 2233152 ----a-w- C:\windows\System32\drivers\tcpip.sys
.
============= FINISH: 20:58:55.95 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 8 Single Language
Boot Device: \Device\HarddiskVolume2
Install Date: 7/12/2014 8:22:29 PM
System Uptime: 12/11/2014 7:28:07 PM (1 hours ago)
.
Motherboard: SAMSUNG ELECTRONICS CO., LTD. | | NP270E4E-K01JM
Processor: Intel(R) Celeron(R) CPU 1007U @ 1.50GHz | CPU Socket - U3E1 | 800/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 442 GiB total, 395.689 GiB free.
D: is CDROM ()
E: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft Teredo Tunneling Adapter
Device ID: ROOT\*TEREDO\0000
Manufacturer: Microsoft
Name: Teredo Tunneling Pseudo-Interface
PNP Device ID: ROOT\*TEREDO\0000
Service: tunnel
.
Class GUID: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Description: Qualcomm Atheros AR3012 Bluetooth 4.0 + HS
Device ID: USB\VID_0CF3&PID_3004\ALASKA_DAY_2006
Manufacturer: Qualcomm Atheros Communications
Name: Qualcomm Atheros AR3012 Bluetooth 4.0 + HS
PNP Device ID: USB\VID_0CF3&PID_3004\ALASKA_DAY_2006
Service: BTHUSB
.
==== System Restore Points ===================
.
RP21: 11/12/2014 7:58:18 PM - Windows Update
RP22: 11/18/2014 4:12:24 PM - Windows Update
RP23: 11/26/2014 9:21:03 AM - Windows Update
RP24: 12/10/2014 8:11:24 PM - Windows Update
.
==== Installed Programs ======================
.
Adobe Photoshop Elements 11
Adobe Reader X (10.1.13) MUI
Avast Internet Security
Bitcasa version 0.9.20.4135
CyberLink Power2Go 8
CyberLink PowerDVD 10
D3DX10
Driver Support
E-POP
Easy File Share
Elements 11 Organizer
Help Desk
Intel(R) Manageability Engine Firmware Recovery Agent
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) Rapid Storage Technology
Intel(R) SDK for OpenCL - CPU Only Runtime Package
Intel® Trusted Connect Service Client
Itibiti RTC
KNCTR
Microsoft Application Error Reporting
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Movie Maker
MSVCRT
MSVCRT110
MSVCRT110_amd64
OpenOffice 4.1.0
Photo Common
Photo Gallery
Pro PC Cleaner
PSE11 STI Installer
Qualcomm Atheros Bluetooth Suite (64)
Qualcomm Atheros Client Installation Program
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Recovery
Remote Desktop Access (VuuPC)
S Agent
Samsung Kies
SAMSUNG USB Driver for Mobile Phones
Settings
snipsmart
Support Center
Support Center FAQ
SW Update
Synaptics Pointing Device Driver
User Guide
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
WordBiz 1.8.7
.
==== Event Viewer Messages From Past Week ========
.
12/9/2014 12:39:39 AM, Error: Schannel [36887] - A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 70.
12/9/2014 12:39:39 AM, Error: Schannel [36887] - A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 40.
12/11/2014 8:27:39 PM, Error: Microsoft-Windows-Kernel-Power [137] - The system firmware has changed the processor's memory type range registers (MTRRs) across a sleep state transition (S4). This can result in reduced resume performance.
12/11/2014 7:29:59 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service AvastVBoxSvc with arguments "Unavailable" in order to run the server: {F319F1B8-7587-4146-AF9C-0D6D77819BF1}
12/11/2014 7:29:57 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the AvastVBox COM Service service to connect.
12/11/2014 7:29:57 PM, Error: Service Control Manager [7000] - The AvastVBox COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/11/2014 7:28:14 PM, Error: Microsoft-Windows-Kernel-General [6] - An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): ''.
.
==== End Of File ===========================