I am using a laptop with Windows 7.
SP1 is installed. I am connected to the
internet by high speed cable.
I was using Firefox the other day. While on
Craigslist, the browser suddenly closed. When I
re-opened it, a window appeared that said my
computer may have been infected with adware or
spyware that could steal my information and I should call
a toll free number immediately for help.
I closed that window, but other windows with ads kept
popping up. Eventually they stopped. But any time I
opened a new tab in Firefox, ads would pop up. Sometimes
a completely new tab would open with an ad. (most of the ads
are little boxes that float above the tab I am viewing.)
When I used Internet Explorer, there were no ads at first. But
eventually they started popping up there too.
DDS.txt:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17496
Run by [removed] at 17:49:04 on 2015-01-21
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8140.3966 [GMT -10:00]
.
AV: Bitdefender Antivirus *Enabled/Updated* {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
SP: Bitdefender Antispyware *Enabled/Updated* {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall *Enabled* {A23392FD-84B9-F933-2C71-81E751F6EF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe
C:\Program Files (x86)\HP SimplePass 2012\TrueSuiteService.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\Hpservice.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k WbioSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Device Center\itype.exe
C:\Program Files\Microsoft Device Center\ipoint.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe
C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\ProgramData\{60e2beaa-bd65-ff41-60e2-2beaabd6faaa}\PowerTool x64 V1.6 (en).zip.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
c:\program files (x86)\mozilla firefox\firefox.exe
c:\program files (x86)\mozilla firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_257.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_257.exe
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe
Q:\140066.enu\Office14\WINWORDC.EXE
C:\Windows\splwow64.exe
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
Q:\140066.enu\Office14\OffSpon.EXE
C:\Program Files (x86)\HP SimplePass 2012\TouchControl.exe
C:\Program Files (x86)\HP SimplePass 2012\BioMonitor.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mStart Page = about:blank
uURLSearchHooks: {e9df9360-97f8-4690-afe6-996c80790da4} - <orphaned>
mURLSearchHooks: {e9df9360-97f8-4690-afe6-996c80790da4} - <orphaned>
mWinlogon: Userinit = userinit.exe
BHO: Bitdefender Wallet: {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll
BHO: TakeToheCouuPoN: {58fc6b83-6927-4261-a1a7-d352809a0d56} - C:\ProgramData\TakeToheCouuPoN\9iwrpbULiJwYle.dll
BHO: EnjoyyCouppOn: {6da2fa7b-1bd5-431a-b9f7-39cd46349339} - C:\ProgramData\EnjoyyCouppOn\K5hTqyqRTiPAtZ.dll
BHO: IEExtension.VDownloaderBHO: {7b523e7c-f096-4e36-a0cb-7efeb5c675c1} -
BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2012\IEBHO.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: LastPass Vault: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
TB: Bitdefender Wallet: {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll
TB: Bitdefender Wallet: {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll
TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll
uRun: [Bitdefender Wallet Agent] "C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe"
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [HPQuickWebProxy] "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
mRun: [NSU_agent] "C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe"
StartupFolder: C:\Users\HP\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\POWERT~1.LNK - C:\ProgramData\{60e2beaa-bd65-ff41-60e2-2beaabd6faaa}\PowerTool x64 V1.6 (en).zip.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\INSTAL~2.LNK - C:\Program Files (x86)\Common Files\lpuninstall.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\INSTAL~1.LNK - C:\Program Files (x86)\Common Files\lpuninstall.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: LastPass - C:\Users\HP\AppData\LocalLow\LastPass\context.html?cmd=lastpass
IE: LastPass Fill Forms - C:\Users\HP\AppData\LocalLow\LastPass\context.html?cmd=fillforms
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{5A449985-CFE0-4281-9648-AFCCD42E1850} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{AD0B90CC-A6D8-4A02-97F1-9378739D6B6F} : DHCPNameServer = [removed]
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} - msiexec /fu {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} /qn
x64-mStart Page = about:blank
x64-BHO: Bitdefender Wallet : {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll
x64-BHO: TakeToheCouuPoN: {58fc6b83-6927-4261-a1a7-d352809a0d56} - C:\ProgramData\TakeToheCouuPoN\9iwrpbULiJwYle.x64.dll
x64-BHO: SoavearEExtenusion: {63f863af-e230-4396-ab4e-571711f68308} - C:\ProgramData\SoavearEExtenusion\Q4gAqQ59xk2W0z.x64.dll
x64-BHO: EnjoyyCouppOn: {6da2fa7b-1bd5-431a-b9f7-39cd46349339} - C:\ProgramData\EnjoyyCouppOn\K5hTqyqRTiPAtZ.x64.dll
x64-BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2012\x64\IEBHO.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: LastPass Vault: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll
x64-TB: Bitdefender Wallet : {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll
x64-TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [SetDefault] C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe
x64-Run: [IntelliType Pro] "c:\Program Files\Microsoft Device Center\itype.exe"
x64-Run: [IntelliPoint] "c:\Program Files\Microsoft Device Center\ipoint.exe"
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [Bdagent] "C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe"
x64-RunOnce: [NCPluginUpdater] "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update
x64-IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
x64-IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {0CE7EBAF-157D-4111-9146-057CB2A4023E} - msiexec /fu {0CE7EBAF-157D-4111-9146-057CB2A4023E} /qn
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\0ci3wn1n.default\
FF - prefs.js: browser.search.defaulturl - hxxp://websearch.thesearchpage.info/?pi ... =74&l=1&q=
FF - prefs.js: browser.search.selectedEngine - WebSearch
FF - prefs.js: browser.startup.homepage - hxxp://websearch.thesearchpage.info/?pi ... S&unqvl=74
FF - prefs.js: keyword.URL - hxxp://websearch.thesearchpage.info/?pi ... =74&l=1&q=
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Services\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Services\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\LastPass\nplastpass.dll
FF - plugin: C:\Program Files (x86)\LastPass\nplastpass64.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\VDownloader\Addons\npVDownloader.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.funmoods.hmpg - true
FF - user.js: extensions.funmoods.hmpgUrl - hxxp://searchfunmoods.com/?f=1&a=downlo ... =959841047
FF - user.js: extensions.funmoods.dfltSrch - false
FF - user.js: extensions.funmoods.srchPrvdr - Search
FF - user.js: extensions.funmoods.dnsErr - true
FF - user.js: extensions.funmoods_i.newTab - true
FF - user.js: extensions.funmoods.newTabUrl - hxxp://searchfunmoods.com/?f=2&a=downlo ... =959841047
FF - user.js: extensions.funmoods.tlbrSrchUrl - hxxp://searchfunmoods.com/?f=3&a=downlo ... 9841047&q=
FF - user.js: extensions.funmoods.id - 20107A321F8CA213
FF - user.js: extensions.funmoods.instlDay - 15663
FF - user.js: extensions.funmoods.vrsn - 1.5.23.22
FF - user.js: extensions.funmoods.vrsni - 1.5.23.22
FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2221:22:42
FF - user.js: extensions.funmoods.prtnrId - funmoods
FF - user.js: extensions.funmoods.prdct - funmoods
FF - user.js: extensions.funmoods.aflt - download
FF - user.js: extensions.funmoods_i.smplGrp - none
FF - user.js: extensions.funmoods.tlbrId - base
FF - user.js: extensions.funmoods.instlRef - download
FF - user.js: extensions.funmoods.dfltLng -
FF - user.js: extensions.funmoods.excTlbr - true
FF - user.js: extensions.funmoods.autoRvrt - false
FF - user.js: extensions.funmoods.envrmnt - production
FF - user.js: extensions.funmoods.isdcmntcmplt - true
FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R0 avc3;avc3;C:\Windows\System32\drivers\avc3.sys [2015-1-12 1288472]
R0 gzflt;gzflt;C:\Windows\System32\drivers\gzflt.sys [2015-1-12 155912]
R1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [2015-1-12 93600]
R1 bdfwfpf;bdfwfpf;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [2015-1-12 107080]
R1 BDVEDISK;BDVEDISK;C:\Windows\System32\drivers\bdvedisk.sys [2015-1-12 76944]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2012-12-19 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-3-14 204288]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2013-4-22 822504]
R2 fc67e7a0;DeltaFix;C:\Windows\System32\rundll32.exe [2009-7-13 45568]
R2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass 2012\TrueSuiteService.exe [2011-8-26 260424]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-9-27 86528]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-8-10 197536]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2011-5-27 30520]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-3-5 35200]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-3-14 13592]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-3-14 2413056]
R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-9-28 212944]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2013-6-26 523944]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-3-14 2656536]
R2 UPDATESRV;Bitdefender Desktop Update Service;C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe [2015-1-12 67320]
R3 avckf;avckf;C:\Windows\System32\drivers\avckf.sys [2015-1-12 647752]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys [2010-7-28 31088]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2012-3-14 317440]
R3 intelkmd;intelkmd;C:\Windows\System32\drivers\igdpmd64.sys [2012-3-14 12289472]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2011-6-10 91648]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2011-6-10 208896]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2012-3-14 338536]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-3-14 428136]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\Windows\System32\drivers\rtl8192ce.sys [2012-3-14 1145448]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2013-6-26 767144]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2013-6-26 273576]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2013-6-26 28840]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2013-6-26 23208]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2013-6-26 207528]
R3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464]
S2 CLKMSVC10_38F51D56;CyberLink Product - 2012/05/30 21:41:31;C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2012-2-8 244720]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 BdDesktopParental;Bitdefender Desktop Parental Control;C:\Program Files\Bitdefender\Bitdefender 2015\bdparentalservice.exe [2015-1-12 78144]
S3 bdfwfpf_pc;bdfwfpf_pc;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [2015-1-12 121928]
S3 BDSandBox;BDSandBox;C:\Windows\System32\drivers\bdsandbox.sys [2015-1-12 82824]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2015-1-12 114688]
S3 nmwcdnsucx64;Nokia USB Flashing Generic;C:\Windows\System32\drivers\nmwcdnsucx64.sys [2012-11-9 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent;C:\Windows\System32\drivers\nmwcdnsux64.sys [2012-11-9 171008]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-2-12 19456]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2015-1-12 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-2-12 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-3-22 1255736]
S4 SafeBox;SafeBox;C:\Program Files\Bitdefender\Bitdefender Safebox\safeboxservice.exe [2015-1-12 94624]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile="C:\Windows\System32\NOTEPAD.EXE" %1
FileExt: .ini: inifile="C:\Windows\System32\NOTEPAD.EXE" %1
FileExt: .inf: inffile="C:\Windows\System32\NOTEPAD.EXE" %1
.
=============== Created Last 30 ================
.
2015-01-22 01:02:20 -------- d-----w- C:\ProgramData\EnjoyyCouppOn
2015-01-20 13:41:02 -------- d-----w- C:\ProgramData\TakeToheCouuPoN
2015-01-20 13:40:44 -------- d-----w- C:\ProgramData\SoavearEExtenusion
2015-01-20 01:28:19 -------- d-----w- C:\ProgramData\eefb4b070ef35721
2015-01-19 04:30:49 -------- d-sh--w- C:\Users\HP\AppData\Local\EmieUserList
2015-01-19 04:30:49 -------- d-sh--w- C:\Users\HP\AppData\Local\EmieSiteList
2015-01-19 04:30:49 -------- d-sh--w- C:\Users\HP\AppData\Local\EmieBrowserModeList
2015-01-19 04:19:06 15641088 ----a-w- C:\Program Files (x86)\Common Files\lpuninstall.exe
2015-01-19 04:18:58 -------- d-----w- C:\Program Files (x86)\LastPass
2015-01-14 14:45:29 -------- dc----w- C:\Users\HP\AppData\Local\MigWiz
2015-01-14 13:43:09 -------- d-----w- C:\Users\HP\AppData\Local\Thunderbird
2015-01-14 03:11:57 5553592 ----a-w- C:\Windows\System32\ntoskrnl.exe
2015-01-14 03:11:56 3971512 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2015-01-14 03:11:55 503808 ----a-w- C:\Windows\System32\srcore.dll
2015-01-14 03:11:55 50176 ----a-w- C:\Windows\System32\srclient.dll
2015-01-14 03:11:55 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
2015-01-14 03:11:55 3916728 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2015-01-14 03:11:55 296960 ----a-w- C:\Windows\System32\rstrui.exe
2015-01-14 02:31:51 210432 ----a-w- C:\Windows\System32\profsvc.dll
2015-01-14 02:31:50 52224 ----a-w- C:\Windows\SysWow64\nlaapi.dll
2015-01-14 02:31:50 303616 ----a-w- C:\Windows\System32\nlasvc.dll
2015-01-14 02:31:50 156672 ----a-w- C:\Windows\SysWow64\ncsi.dll
2015-01-14 02:31:50 141312 ----a-w- C:\Windows\System32\drivers\mrxdav.sys
2015-01-14 02:31:48 87040 ----a-w- C:\Windows\System32\TSWbPrxy.exe
2015-01-13 14:07:30 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2015-01-13 14:07:30 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2015-01-13 11:50:21 -------- d-----w- C:\Users\HP\AppData\Local\Deployment
2015-01-13 11:46:35 5703168 ----a-w- C:\Windows\SysWow64\mstscax.dll
2015-01-13 11:46:34 6584320 ----a-w- C:\Windows\System32\mstscax.dll
2015-01-13 11:44:24 -------- d-----w- C:\Users\HP\AppData\Local\Apps
2015-01-13 08:25:34 7168 ----a-w- C:\Windows\SysWow64\KBDYAK.DLL
2015-01-13 08:25:34 6656 ----a-w- C:\Windows\SysWow64\KBDBASH.DLL
2015-01-13 08:25:33 7168 ----a-w- C:\Windows\System32\KBDYAK.DLL
2015-01-13 08:25:33 7168 ----a-w- C:\Windows\System32\KBDBASH.DLL
2015-01-13 08:25:29 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2015-01-13 08:13:04 44544 ----a-w- C:\Windows\System32\TsUsbGDCoInstaller.dll
2015-01-13 07:51:57 -------- d-s---w- C:\Windows\System32\CompatTel
2015-01-13 07:51:57 -------- d-----w- C:\Windows\System32\appraiser
2015-01-13 06:28:53 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2015-01-13 06:28:53 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2015-01-13 06:28:52 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2015-01-13 06:28:52 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2015-01-13 06:21:04 -------- d-----w- C:\Windows\Migration
2015-01-13 06:06:59 -------- d-----r- C:\Program Files (x86)\Skype
2015-01-13 05:56:34 55808 ----a-w- C:\Windows\System32\rrinstaller.exe
2015-01-13 05:56:34 50176 ----a-w- C:\Windows\SysWow64\rrinstaller.exe
2015-01-13 05:56:34 3209728 ----a-w- C:\Windows\SysWow64\mf.dll
2015-01-13 05:56:34 24576 ----a-w- C:\Windows\System32\mfpmp.exe
2015-01-13 05:56:34 23040 ----a-w- C:\Windows\SysWow64\mfpmp.exe
2015-01-13 05:56:34 206848 ----a-w- C:\Windows\System32\mfps.dll
2015-01-13 05:56:34 2048 ----a-w- C:\Windows\SysWow64\mferror.dll
2015-01-13 05:56:34 2048 ----a-w- C:\Windows\System32\mferror.dll
2015-01-13 05:56:34 103424 ----a-w- C:\Windows\SysWow64\mfps.dll
2015-01-13 05:56:33 4121600 ----a-w- C:\Windows\System32\mf.dll
2015-01-13 05:50:54 2777088 ----a-w- C:\Windows\System32\msmpeg2vdec.dll
2015-01-13 05:50:54 2285056 ----a-w- C:\Windows\SysWow64\msmpeg2vdec.dll
2015-01-13 03:21:46 99480 ----a-w- C:\Windows\SysWow64\infocardapi.dll
2015-01-13 03:21:46 619672 ----a-w- C:\Windows\SysWow64\icardagt.exe
2015-01-13 03:21:46 171160 ----a-w- C:\Windows\System32\infocardapi.dll
2015-01-13 03:21:46 1389208 ----a-w- C:\Windows\System32\icardagt.exe
2015-01-13 03:21:32 8856 ----a-w- C:\Windows\SysWow64\icardres.dll
2015-01-13 03:21:32 8856 ----a-w- C:\Windows\System32\icardres.dll
2015-01-13 03:21:14 35480 ----a-w- C:\Windows\SysWow64\TsWpfWrp.exe
2015-01-13 03:21:14 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe
2015-01-13 03:19:36 830976 ----a-w- C:\Windows\System32\appraiser.dll
2015-01-13 03:19:36 741376 ----a-w- C:\Windows\System32\invagent.dll
2015-01-13 03:19:36 413184 ----a-w- C:\Windows\System32\generaltel.dll
2015-01-13 03:19:36 396800 ----a-w- C:\Windows\System32\devinv.dll
2015-01-13 03:19:36 192000 ----a-w- C:\Windows\System32\aepic.dll
2015-01-13 03:19:36 1232040 ----a-w- C:\Windows\System32\aitstatic.exe
2015-01-13 03:19:36 1083392 ----a-w- C:\Windows\System32\aeinv.dll
2015-01-13 03:19:34 227328 ----a-w- C:\Windows\System32\aepdu.dll
2015-01-13 03:19:00 683520 ----a-w- C:\Windows\System32\termsrv.dll
2015-01-13 03:19:00 681984 ----a-w- C:\Windows\SysWow64\adtschema.dll
2015-01-13 03:19:00 681984 ----a-w- C:\Windows\System32\adtschema.dll
2015-01-13 03:19:00 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll
2015-01-13 03:19:00 146432 ----a-w- C:\Windows\System32\msaudite.dll
2015-01-13 03:18:58 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2015-01-13 03:18:58 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2015-01-13 03:18:03 335360 ----a-w- C:\Windows\System32\msieftp.dll
2015-01-13 03:18:03 301568 ----a-w- C:\Windows\SysWow64\msieftp.dll
2015-01-13 03:18:02 228864 ----a-w- C:\Windows\System32\wwansvc.dll
2015-01-13 03:18:01 633856 ----a-w- C:\Windows\System32\comctl32.dll
2015-01-13 03:18:01 530432 ----a-w- C:\Windows\SysWow64\comctl32.dll
2015-01-13 03:16:53 2048 ----a-w- C:\Windows\SysWow64\msxml6r.dll
2015-01-13 03:15:55 497152 ----a-w- C:\Windows\System32\drivers\afd.sys
2015-01-13 03:14:55 680960 ----a-w- C:\Windows\System32\audiosrv.dll
2015-01-13 03:08:43 3198976 ----a-w- C:\Windows\System32\win32k.sys
2015-01-13 03:07:59 458712 ----a-w- C:\Windows\System32\drivers\cng.sys
2015-01-13 03:07:31 404480 ----a-w- C:\Windows\System32\gdi32.dll
2015-01-13 03:07:31 311808 ----a-w- C:\Windows\SysWow64\gdi32.dll
2015-01-13 03:07:28 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2015-01-13 03:07:28 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2015-01-13 03:07:16 859648 ----a-w- C:\Windows\System32\IKEEXT.DLL
2015-01-13 03:07:16 830464 ----a-w- C:\Windows\System32\nshwfp.dll
2015-01-13 03:07:16 656896 ----a-w- C:\Windows\SysWow64\nshwfp.dll
2015-01-13 03:07:16 324096 ----a-w- C:\Windows\System32\FWPUCLNT.DLL
2015-01-13 03:07:16 216576 ----a-w- C:\Windows\SysWow64\FWPUCLNT.DLL
2015-01-13 02:58:46 664064 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2015-01-13 02:58:46 1216000 ----a-w- C:\Windows\System32\rpcrt4.dll
2015-01-13 02:25:14 74000 ----a-w- C:\Windows\System32\bdsandboxuiskin32.dll
2015-01-13 02:25:14 263032 ----a-w- C:\Windows\System32\drivers\avchv.sys
2015-01-13 02:22:30 2620928 ----a-w- C:\Windows\System32\wucltux.dll
2015-01-13 02:22:24 -------- d-----w- C:\Program Files\Unlocker
2015-01-13 02:22:02 97792 ----a-w- C:\Windows\System32\wudriver.dll
2015-01-13 02:22:02 92672 ----a-w- C:\Windows\SysWow64\wudriver.dll
2015-01-13 02:21:31 36864 ----a-w- C:\Windows\System32\wuapp.exe
2015-01-13 02:21:31 33792 ----a-w- C:\Windows\SysWow64\wuapp.exe
2015-01-13 02:21:31 198600 ----a-w- C:\Windows\System32\wuwebv.dll
2015-01-13 02:21:31 179656 ----a-w- C:\Windows\SysWow64\wuwebv.dll
2015-01-13 02:16:06 -------- d-----w- C:\Users\HP\AppData\Local\Programs
2015-01-13 02:15:39 -------- d-----w- C:\Program Files (x86)\DeltaFix
2015-01-13 02:14:41 -------- d-----w- C:\Program Files\6315EBB8-4968-4AE5-8956-C5CABDE87E54
2015-01-13 02:14:41 -------- d-----w- C:\Program Files\010
2015-01-13 02:12:55 -------- d-----w- C:\ProgramData\{60e2beaa-bd65-ff41-60e2-2beaabd6faaa}
2015-01-13 02:08:39 -------- d-----w- C:\Program Files\UVK - Ultra Virus Killer
2015-01-13 02:00:51 593904 ----a-w- C:\ProgramData\1421113858.bdinstall.bin
2015-01-13 01:54:46 76944 ----a-w- C:\Windows\System32\drivers\bdvedisk.sys
2015-01-13 01:54:45 93600 ----a-w- C:\Windows\System32\drivers\BdfNdisf6.sys
2015-01-13 01:54:45 82824 ----a-w- C:\Windows\System32\drivers\bdsandbox.sys
2015-01-13 01:54:45 74000 ----a-w- C:\Windows\SysWow64\bdsandboxuiskin32.dll
2015-01-13 01:54:34 647752 ----a-w- C:\Windows\System32\drivers\avckf.sys
2015-01-13 01:54:34 1288472 ----a-w- C:\Windows\System32\drivers\avc3.sys
2015-01-13 01:54:03 -------- d-----w- C:\Users\HP\AppData\Roaming\Bitdefender
2015-01-13 01:53:59 3271472 ---ha-w- C:\bdr-bz01
2015-01-13 01:51:18 155912 ----a-w- C:\Windows\System32\drivers\gzflt.sys
2015-01-13 01:51:12 452040 ----a-w- C:\Windows\System32\drivers\trufos.sys
2015-01-13 01:44:05 84336 ----a-w- C:\Windows\System32\BDSandBoxUISkin.dll
2015-01-13 01:44:05 33360 ----a-w- C:\Windows\System32\BDSandBoxUH.dll
2015-01-13 01:44:05 -------- d-----w- C:\ProgramData\Bitdefender
.
==================== Find3M ====================
.
2015-01-14 02:52:12 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-01-14 02:52:12 701616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-11-11 03:09:06 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2014-11-11 03:08:52 241152 ----a-w- C:\Windows\System32\pku2u.dll
2014-11-11 03:08:48 728064 ----a-w- C:\Windows\System32\kerberos.dll
2014-11-11 02:44:45 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2014-11-11 02:44:32 186880 ----a-w- C:\Windows\SysWow64\pku2u.dll
2014-11-11 02:44:25 550912 ----a-w- C:\Windows\SysWow64\kerberos.dll
2014-11-11 01:46:26 119296 ----a-w- C:\Windows\System32\drivers\tdx.sys
2014-11-08 03:16:08 2048 ----a-w- C:\Windows\System32\tzres.dll
2014-11-08 02:45:09 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2014-10-30 02:03:43 165888 ----a-w- C:\Windows\System32\charmap.exe
2014-10-30 01:45:43 155136 ----a-w- C:\Windows\SysWow64\charmap.exe
2014-10-25 01:57:59 77824 ----a-w- C:\Windows\System32\packager.dll
2014-10-25 01:32:37 67584 ----a-w- C:\Windows\SysWow64\packager.dll
2010-01-26 21:11:08 444283 ----a-w- C:\Program Files\Common Files\WinPcapNmap.exe
.
============= FINISH: 17:49:31.75 ===============
ATTACH.TXT:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 3/21/2012 3:55:56 AM
System Uptime: 1/21/2015 2:35:15 PM (3 hours ago)
.
Motherboard: Hewlett-Packard | | 1801
Processor: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz | CPU1 | 2201/1333mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 673 GiB total, 597.068 GiB free.
D: is FIXED (NTFS) - 21 GiB total, 2.265 GiB free.
E: is FIXED (FAT32) - 4 GiB total, 2.881 GiB free.
F: is CDROM ()
G: is FIXED (NTFS) - 931 GiB total, 735.83 GiB free.
H: is FIXED (NTFS) - 298 GiB total, 124.594 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP116: 1/12/2015 10:11:47 PM - Windows Update
RP117: 1/12/2015 10:27:29 PM - Windows Update
RP118: 1/13/2015 2:20:56 AM - Windows Update
RP119: 1/13/2015 6:16:28 AM - Windows Update
RP120: 1/13/2015 7:31:56 PM - Windows Update
.
==== Installed Programs ======================
.
µTorrent
7-Zip 9.20 (x64 edition)
Adobe Flash Player 16 ActiveX
Adobe Flash Player 16 NPAPI
Adobe Reader X (10.1.13) MUI
AMD APP SDK Runtime
AMD Catalyst Install Manager
Ashampoo Burning Studio 6 FREE v.6.81
Audacity 2.0.2
AuthenTec TrueAPI
Bejeweled 3
Bitdefender Total Security 2015
Blackhawk Striker 2
CamStudio OSS Desktop Recorder
Catalyst Control Center
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
Catalyst Control Center Profiles Mobile
ccc-utility64
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Chuzzle Deluxe
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Core Temp 1.0 RC4
Cradle of Rome 2
CyberLink PowerDVD
CyberLink YouCam
D3DX10
Dora's World Adventure
ESU for Microsoft Windows 7 SP1
Evernote v. 4.2.3
Farm Frenzy
Farmscapes
FATE
Final Drive Fury
Free FLAC to MP3 Converter 1.0
Free M4a to MP3 Converter 7.1
Freemake Video Converter version 3.0.2
Google Drive
Google Update Helper
Hewlett-Packard ACLM.NET v1.2.1.1
Hoyle Card Games
HP 3D DriveGuard
HP Application Assistant
HP Auto
HP Client Services
HP CoolSense
HP Customer Experience Enhancements
HP Documentation
HP Games
HP Launch Box
HP MovieStore
HP On Screen Display
HP Power Manager
HP Quick Launch
HP QuickWeb
HP Recovery Manager
HP Security Assistant
HP Setup
HP Setup Manager
HP SimplePass 2012
HP Software Framework
IDT Audio
ImgBurn
Intel(R) Control Center
Intel(R) Display Audio Driver
Intel(R) Identity Protection Technology 1.2.22.0
Intel(R) Management Engine Components
Intel(R) Rapid Storage Technology
Jewel Match 3
Jewel Quest Mysteries: The Seventh Gate Collector's Edition
John Deere Drive Green
Junk Mail filter update
LastPass (uninstall only)
Letters from Nowhere 2
Luxor HD
Mah Jong Medley
Mesh Runtime
Microsoft .NET Framework 4.5.1
Microsoft Application Error Reporting
Microsoft Mouse and Keyboard Center
Microsoft Office 2010
Microsoft Office Click-to-Run 2010
Microsoft Office Starter 2010 - English
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft WSE 3.0 Runtime
Microsoft_VC100_CRT_SP1_x64
Microsoft_VC100_CRT_SP1_x86
Mozilla Firefox 35.0 (x86 en-US)
Mozilla Maintenance Service
Mozilla Thunderbird 31.4.0 (x86 en-US)
MSVC80_x64_v2
MSVC80_x86_v2
MSVC90_x64
MSVC90_x86
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB2758694)
Nokia Connectivity Cable Driver
Nokia PC Suite
Nokia Software Updater
Nokia Suite
opensource
Pando Media Booster
PathProc
PC Connectivity Solution
Penguins!
Plants vs. Zombies - Game of the Year
PlayReady PC Runtime x86
Poker Superstars III
Polar Bowler
Polar Golfer
PX Profile Update
Realtek Ethernet Controller Driver
Realtek PCIE Card Reader
REALTEK Wireless LAN Driver
Renesas Electronics USB 3.0 Host Controller Driver
RollerCoaster Tycoon 3: Platinum
Security Update for Microsoft .NET Framework 4.5.1 (KB2894854v2)
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Security Update for Microsoft .NET Framework 4.5.1 (KB2972107)
Security Update for Microsoft .NET Framework 4.5.1 (KB2972216)
Security Update for Microsoft .NET Framework 4.5.1 (KB2978128)
Security Update for Microsoft .NET Framework 4.5.1 (KB2979578v2)
Skype™ 6.11
SpeedFan (remove only)
swMSM
Synaptics TouchPad Driver
The Treasures of Mystery Island: The Ghost Ship
Torchlight
Total Commander (Remove or Repair)
Unlocker 1.9.2
Update Installer for WildTangent Games App
uTorrentControl Toolbar
UVK - Ultra Virus Killer
Validity WBF DDK
VDownloader 3.9.1280
VIP Access SDK (1.1.0.4)
Virtual Villagers 4 - The Tree of Life
Visual Studio 2008 x64 Redistributables
Visual Studio 2010 x64 Redistributables
VLC media player 2.0.1
WildTangent Games App (HP Games)
Windows 7 Codec Pack 4.0.2
Windows Driver Package - Nokia Modem (02/25/2011 4.7)
Windows Driver Package - Nokia Modem (02/25/2011 7.01.0.9)
Windows Driver Package - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0)
Windows Essentials Media Codec Pack 4.0 [64-Bit]
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinPcap 4.1.1
WinX DVD Ripper Platinum 7.0.0
Zuma's Revenge
.
==== End Of File ===========================
SP1 is installed. I am connected to the
internet by high speed cable.
I was using Firefox the other day. While on
Craigslist, the browser suddenly closed. When I
re-opened it, a window appeared that said my
computer may have been infected with adware or
spyware that could steal my information and I should call
a toll free number immediately for help.
I closed that window, but other windows with ads kept
popping up. Eventually they stopped. But any time I
opened a new tab in Firefox, ads would pop up. Sometimes
a completely new tab would open with an ad. (most of the ads
are little boxes that float above the tab I am viewing.)
When I used Internet Explorer, there were no ads at first. But
eventually they started popping up there too.
DDS.txt:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17496
Run by [removed] at 17:49:04 on 2015-01-21
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8140.3966 [GMT -10:00]
.
AV: Bitdefender Antivirus *Enabled/Updated* {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
SP: Bitdefender Antispyware *Enabled/Updated* {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall *Enabled* {A23392FD-84B9-F933-2C71-81E751F6EF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe
C:\Program Files (x86)\HP SimplePass 2012\TrueSuiteService.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\Hpservice.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k WbioSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Device Center\itype.exe
C:\Program Files\Microsoft Device Center\ipoint.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe
C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\ProgramData\{60e2beaa-bd65-ff41-60e2-2beaabd6faaa}\PowerTool x64 V1.6 (en).zip.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
c:\program files (x86)\mozilla firefox\firefox.exe
c:\program files (x86)\mozilla firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_257.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_257.exe
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe
Q:\140066.enu\Office14\WINWORDC.EXE
C:\Windows\splwow64.exe
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
Q:\140066.enu\Office14\OffSpon.EXE
C:\Program Files (x86)\HP SimplePass 2012\TouchControl.exe
C:\Program Files (x86)\HP SimplePass 2012\BioMonitor.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mStart Page = about:blank
uURLSearchHooks: {e9df9360-97f8-4690-afe6-996c80790da4} - <orphaned>
mURLSearchHooks: {e9df9360-97f8-4690-afe6-996c80790da4} - <orphaned>
mWinlogon: Userinit = userinit.exe
BHO: Bitdefender Wallet: {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll
BHO: TakeToheCouuPoN: {58fc6b83-6927-4261-a1a7-d352809a0d56} - C:\ProgramData\TakeToheCouuPoN\9iwrpbULiJwYle.dll
BHO: EnjoyyCouppOn: {6da2fa7b-1bd5-431a-b9f7-39cd46349339} - C:\ProgramData\EnjoyyCouppOn\K5hTqyqRTiPAtZ.dll
BHO: IEExtension.VDownloaderBHO: {7b523e7c-f096-4e36-a0cb-7efeb5c675c1} -
BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2012\IEBHO.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: LastPass Vault: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
TB: Bitdefender Wallet: {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll
TB: Bitdefender Wallet: {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll
TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll
uRun: [Bitdefender Wallet Agent] "C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe"
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [HPQuickWebProxy] "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
mRun: [NSU_agent] "C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe"
StartupFolder: C:\Users\HP\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\POWERT~1.LNK - C:\ProgramData\{60e2beaa-bd65-ff41-60e2-2beaabd6faaa}\PowerTool x64 V1.6 (en).zip.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\INSTAL~2.LNK - C:\Program Files (x86)\Common Files\lpuninstall.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\INSTAL~1.LNK - C:\Program Files (x86)\Common Files\lpuninstall.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: LastPass - C:\Users\HP\AppData\LocalLow\LastPass\context.html?cmd=lastpass
IE: LastPass Fill Forms - C:\Users\HP\AppData\LocalLow\LastPass\context.html?cmd=fillforms
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{5A449985-CFE0-4281-9648-AFCCD42E1850} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{AD0B90CC-A6D8-4A02-97F1-9378739D6B6F} : DHCPNameServer = [removed]
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} - msiexec /fu {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} /qn
x64-mStart Page = about:blank
x64-BHO: Bitdefender Wallet : {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll
x64-BHO: TakeToheCouuPoN: {58fc6b83-6927-4261-a1a7-d352809a0d56} - C:\ProgramData\TakeToheCouuPoN\9iwrpbULiJwYle.x64.dll
x64-BHO: SoavearEExtenusion: {63f863af-e230-4396-ab4e-571711f68308} - C:\ProgramData\SoavearEExtenusion\Q4gAqQ59xk2W0z.x64.dll
x64-BHO: EnjoyyCouppOn: {6da2fa7b-1bd5-431a-b9f7-39cd46349339} - C:\ProgramData\EnjoyyCouppOn\K5hTqyqRTiPAtZ.x64.dll
x64-BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2012\x64\IEBHO.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: LastPass Vault: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll
x64-TB: Bitdefender Wallet : {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll
x64-TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [SetDefault] C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe
x64-Run: [IntelliType Pro] "c:\Program Files\Microsoft Device Center\itype.exe"
x64-Run: [IntelliPoint] "c:\Program Files\Microsoft Device Center\ipoint.exe"
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [Bdagent] "C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe"
x64-RunOnce: [NCPluginUpdater] "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update
x64-IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
x64-IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {0CE7EBAF-157D-4111-9146-057CB2A4023E} - msiexec /fu {0CE7EBAF-157D-4111-9146-057CB2A4023E} /qn
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\0ci3wn1n.default\
FF - prefs.js: browser.search.defaulturl - hxxp://websearch.thesearchpage.info/?pi ... =74&l=1&q=
FF - prefs.js: browser.search.selectedEngine - WebSearch
FF - prefs.js: browser.startup.homepage - hxxp://websearch.thesearchpage.info/?pi ... S&unqvl=74
FF - prefs.js: keyword.URL - hxxp://websearch.thesearchpage.info/?pi ... =74&l=1&q=
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Services\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Services\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\LastPass\nplastpass.dll
FF - plugin: C:\Program Files (x86)\LastPass\nplastpass64.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\VDownloader\Addons\npVDownloader.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.funmoods.hmpg - true
FF - user.js: extensions.funmoods.hmpgUrl - hxxp://searchfunmoods.com/?f=1&a=downlo ... =959841047
FF - user.js: extensions.funmoods.dfltSrch - false
FF - user.js: extensions.funmoods.srchPrvdr - Search
FF - user.js: extensions.funmoods.dnsErr - true
FF - user.js: extensions.funmoods_i.newTab - true
FF - user.js: extensions.funmoods.newTabUrl - hxxp://searchfunmoods.com/?f=2&a=downlo ... =959841047
FF - user.js: extensions.funmoods.tlbrSrchUrl - hxxp://searchfunmoods.com/?f=3&a=downlo ... 9841047&q=
FF - user.js: extensions.funmoods.id - 20107A321F8CA213
FF - user.js: extensions.funmoods.instlDay - 15663
FF - user.js: extensions.funmoods.vrsn - 1.5.23.22
FF - user.js: extensions.funmoods.vrsni - 1.5.23.22
FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2221:22:42
FF - user.js: extensions.funmoods.prtnrId - funmoods
FF - user.js: extensions.funmoods.prdct - funmoods
FF - user.js: extensions.funmoods.aflt - download
FF - user.js: extensions.funmoods_i.smplGrp - none
FF - user.js: extensions.funmoods.tlbrId - base
FF - user.js: extensions.funmoods.instlRef - download
FF - user.js: extensions.funmoods.dfltLng -
FF - user.js: extensions.funmoods.excTlbr - true
FF - user.js: extensions.funmoods.autoRvrt - false
FF - user.js: extensions.funmoods.envrmnt - production
FF - user.js: extensions.funmoods.isdcmntcmplt - true
FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R0 avc3;avc3;C:\Windows\System32\drivers\avc3.sys [2015-1-12 1288472]
R0 gzflt;gzflt;C:\Windows\System32\drivers\gzflt.sys [2015-1-12 155912]
R1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [2015-1-12 93600]
R1 bdfwfpf;bdfwfpf;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [2015-1-12 107080]
R1 BDVEDISK;BDVEDISK;C:\Windows\System32\drivers\bdvedisk.sys [2015-1-12 76944]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2012-12-19 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-3-14 204288]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2013-4-22 822504]
R2 fc67e7a0;DeltaFix;C:\Windows\System32\rundll32.exe [2009-7-13 45568]
R2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass 2012\TrueSuiteService.exe [2011-8-26 260424]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-9-27 86528]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-8-10 197536]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2011-5-27 30520]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-3-5 35200]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-3-14 13592]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-3-14 2413056]
R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-9-28 212944]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2013-6-26 523944]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-3-14 2656536]
R2 UPDATESRV;Bitdefender Desktop Update Service;C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe [2015-1-12 67320]
R3 avckf;avckf;C:\Windows\System32\drivers\avckf.sys [2015-1-12 647752]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys [2010-7-28 31088]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2012-3-14 317440]
R3 intelkmd;intelkmd;C:\Windows\System32\drivers\igdpmd64.sys [2012-3-14 12289472]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2011-6-10 91648]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2011-6-10 208896]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2012-3-14 338536]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-3-14 428136]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\Windows\System32\drivers\rtl8192ce.sys [2012-3-14 1145448]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2013-6-26 767144]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2013-6-26 273576]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2013-6-26 28840]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2013-6-26 23208]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2013-6-26 207528]
R3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464]
S2 CLKMSVC10_38F51D56;CyberLink Product - 2012/05/30 21:41:31;C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2012-2-8 244720]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 BdDesktopParental;Bitdefender Desktop Parental Control;C:\Program Files\Bitdefender\Bitdefender 2015\bdparentalservice.exe [2015-1-12 78144]
S3 bdfwfpf_pc;bdfwfpf_pc;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [2015-1-12 121928]
S3 BDSandBox;BDSandBox;C:\Windows\System32\drivers\bdsandbox.sys [2015-1-12 82824]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2015-1-12 114688]
S3 nmwcdnsucx64;Nokia USB Flashing Generic;C:\Windows\System32\drivers\nmwcdnsucx64.sys [2012-11-9 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent;C:\Windows\System32\drivers\nmwcdnsux64.sys [2012-11-9 171008]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-2-12 19456]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2015-1-12 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-2-12 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-3-22 1255736]
S4 SafeBox;SafeBox;C:\Program Files\Bitdefender\Bitdefender Safebox\safeboxservice.exe [2015-1-12 94624]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile="C:\Windows\System32\NOTEPAD.EXE" %1
FileExt: .ini: inifile="C:\Windows\System32\NOTEPAD.EXE" %1
FileExt: .inf: inffile="C:\Windows\System32\NOTEPAD.EXE" %1
.
=============== Created Last 30 ================
.
2015-01-22 01:02:20 -------- d-----w- C:\ProgramData\EnjoyyCouppOn
2015-01-20 13:41:02 -------- d-----w- C:\ProgramData\TakeToheCouuPoN
2015-01-20 13:40:44 -------- d-----w- C:\ProgramData\SoavearEExtenusion
2015-01-20 01:28:19 -------- d-----w- C:\ProgramData\eefb4b070ef35721
2015-01-19 04:30:49 -------- d-sh--w- C:\Users\HP\AppData\Local\EmieUserList
2015-01-19 04:30:49 -------- d-sh--w- C:\Users\HP\AppData\Local\EmieSiteList
2015-01-19 04:30:49 -------- d-sh--w- C:\Users\HP\AppData\Local\EmieBrowserModeList
2015-01-19 04:19:06 15641088 ----a-w- C:\Program Files (x86)\Common Files\lpuninstall.exe
2015-01-19 04:18:58 -------- d-----w- C:\Program Files (x86)\LastPass
2015-01-14 14:45:29 -------- dc----w- C:\Users\HP\AppData\Local\MigWiz
2015-01-14 13:43:09 -------- d-----w- C:\Users\HP\AppData\Local\Thunderbird
2015-01-14 03:11:57 5553592 ----a-w- C:\Windows\System32\ntoskrnl.exe
2015-01-14 03:11:56 3971512 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2015-01-14 03:11:55 503808 ----a-w- C:\Windows\System32\srcore.dll
2015-01-14 03:11:55 50176 ----a-w- C:\Windows\System32\srclient.dll
2015-01-14 03:11:55 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
2015-01-14 03:11:55 3916728 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2015-01-14 03:11:55 296960 ----a-w- C:\Windows\System32\rstrui.exe
2015-01-14 02:31:51 210432 ----a-w- C:\Windows\System32\profsvc.dll
2015-01-14 02:31:50 52224 ----a-w- C:\Windows\SysWow64\nlaapi.dll
2015-01-14 02:31:50 303616 ----a-w- C:\Windows\System32\nlasvc.dll
2015-01-14 02:31:50 156672 ----a-w- C:\Windows\SysWow64\ncsi.dll
2015-01-14 02:31:50 141312 ----a-w- C:\Windows\System32\drivers\mrxdav.sys
2015-01-14 02:31:48 87040 ----a-w- C:\Windows\System32\TSWbPrxy.exe
2015-01-13 14:07:30 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2015-01-13 14:07:30 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2015-01-13 11:50:21 -------- d-----w- C:\Users\HP\AppData\Local\Deployment
2015-01-13 11:46:35 5703168 ----a-w- C:\Windows\SysWow64\mstscax.dll
2015-01-13 11:46:34 6584320 ----a-w- C:\Windows\System32\mstscax.dll
2015-01-13 11:44:24 -------- d-----w- C:\Users\HP\AppData\Local\Apps
2015-01-13 08:25:34 7168 ----a-w- C:\Windows\SysWow64\KBDYAK.DLL
2015-01-13 08:25:34 6656 ----a-w- C:\Windows\SysWow64\KBDBASH.DLL
2015-01-13 08:25:33 7168 ----a-w- C:\Windows\System32\KBDYAK.DLL
2015-01-13 08:25:33 7168 ----a-w- C:\Windows\System32\KBDBASH.DLL
2015-01-13 08:25:29 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2015-01-13 08:13:04 44544 ----a-w- C:\Windows\System32\TsUsbGDCoInstaller.dll
2015-01-13 07:51:57 -------- d-s---w- C:\Windows\System32\CompatTel
2015-01-13 07:51:57 -------- d-----w- C:\Windows\System32\appraiser
2015-01-13 06:28:53 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2015-01-13 06:28:53 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2015-01-13 06:28:52 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2015-01-13 06:28:52 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2015-01-13 06:21:04 -------- d-----w- C:\Windows\Migration
2015-01-13 06:06:59 -------- d-----r- C:\Program Files (x86)\Skype
2015-01-13 05:56:34 55808 ----a-w- C:\Windows\System32\rrinstaller.exe
2015-01-13 05:56:34 50176 ----a-w- C:\Windows\SysWow64\rrinstaller.exe
2015-01-13 05:56:34 3209728 ----a-w- C:\Windows\SysWow64\mf.dll
2015-01-13 05:56:34 24576 ----a-w- C:\Windows\System32\mfpmp.exe
2015-01-13 05:56:34 23040 ----a-w- C:\Windows\SysWow64\mfpmp.exe
2015-01-13 05:56:34 206848 ----a-w- C:\Windows\System32\mfps.dll
2015-01-13 05:56:34 2048 ----a-w- C:\Windows\SysWow64\mferror.dll
2015-01-13 05:56:34 2048 ----a-w- C:\Windows\System32\mferror.dll
2015-01-13 05:56:34 103424 ----a-w- C:\Windows\SysWow64\mfps.dll
2015-01-13 05:56:33 4121600 ----a-w- C:\Windows\System32\mf.dll
2015-01-13 05:50:54 2777088 ----a-w- C:\Windows\System32\msmpeg2vdec.dll
2015-01-13 05:50:54 2285056 ----a-w- C:\Windows\SysWow64\msmpeg2vdec.dll
2015-01-13 03:21:46 99480 ----a-w- C:\Windows\SysWow64\infocardapi.dll
2015-01-13 03:21:46 619672 ----a-w- C:\Windows\SysWow64\icardagt.exe
2015-01-13 03:21:46 171160 ----a-w- C:\Windows\System32\infocardapi.dll
2015-01-13 03:21:46 1389208 ----a-w- C:\Windows\System32\icardagt.exe
2015-01-13 03:21:32 8856 ----a-w- C:\Windows\SysWow64\icardres.dll
2015-01-13 03:21:32 8856 ----a-w- C:\Windows\System32\icardres.dll
2015-01-13 03:21:14 35480 ----a-w- C:\Windows\SysWow64\TsWpfWrp.exe
2015-01-13 03:21:14 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe
2015-01-13 03:19:36 830976 ----a-w- C:\Windows\System32\appraiser.dll
2015-01-13 03:19:36 741376 ----a-w- C:\Windows\System32\invagent.dll
2015-01-13 03:19:36 413184 ----a-w- C:\Windows\System32\generaltel.dll
2015-01-13 03:19:36 396800 ----a-w- C:\Windows\System32\devinv.dll
2015-01-13 03:19:36 192000 ----a-w- C:\Windows\System32\aepic.dll
2015-01-13 03:19:36 1232040 ----a-w- C:\Windows\System32\aitstatic.exe
2015-01-13 03:19:36 1083392 ----a-w- C:\Windows\System32\aeinv.dll
2015-01-13 03:19:34 227328 ----a-w- C:\Windows\System32\aepdu.dll
2015-01-13 03:19:00 683520 ----a-w- C:\Windows\System32\termsrv.dll
2015-01-13 03:19:00 681984 ----a-w- C:\Windows\SysWow64\adtschema.dll
2015-01-13 03:19:00 681984 ----a-w- C:\Windows\System32\adtschema.dll
2015-01-13 03:19:00 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll
2015-01-13 03:19:00 146432 ----a-w- C:\Windows\System32\msaudite.dll
2015-01-13 03:18:58 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2015-01-13 03:18:58 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2015-01-13 03:18:03 335360 ----a-w- C:\Windows\System32\msieftp.dll
2015-01-13 03:18:03 301568 ----a-w- C:\Windows\SysWow64\msieftp.dll
2015-01-13 03:18:02 228864 ----a-w- C:\Windows\System32\wwansvc.dll
2015-01-13 03:18:01 633856 ----a-w- C:\Windows\System32\comctl32.dll
2015-01-13 03:18:01 530432 ----a-w- C:\Windows\SysWow64\comctl32.dll
2015-01-13 03:16:53 2048 ----a-w- C:\Windows\SysWow64\msxml6r.dll
2015-01-13 03:15:55 497152 ----a-w- C:\Windows\System32\drivers\afd.sys
2015-01-13 03:14:55 680960 ----a-w- C:\Windows\System32\audiosrv.dll
2015-01-13 03:08:43 3198976 ----a-w- C:\Windows\System32\win32k.sys
2015-01-13 03:07:59 458712 ----a-w- C:\Windows\System32\drivers\cng.sys
2015-01-13 03:07:31 404480 ----a-w- C:\Windows\System32\gdi32.dll
2015-01-13 03:07:31 311808 ----a-w- C:\Windows\SysWow64\gdi32.dll
2015-01-13 03:07:28 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2015-01-13 03:07:28 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2015-01-13 03:07:16 859648 ----a-w- C:\Windows\System32\IKEEXT.DLL
2015-01-13 03:07:16 830464 ----a-w- C:\Windows\System32\nshwfp.dll
2015-01-13 03:07:16 656896 ----a-w- C:\Windows\SysWow64\nshwfp.dll
2015-01-13 03:07:16 324096 ----a-w- C:\Windows\System32\FWPUCLNT.DLL
2015-01-13 03:07:16 216576 ----a-w- C:\Windows\SysWow64\FWPUCLNT.DLL
2015-01-13 02:58:46 664064 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2015-01-13 02:58:46 1216000 ----a-w- C:\Windows\System32\rpcrt4.dll
2015-01-13 02:25:14 74000 ----a-w- C:\Windows\System32\bdsandboxuiskin32.dll
2015-01-13 02:25:14 263032 ----a-w- C:\Windows\System32\drivers\avchv.sys
2015-01-13 02:22:30 2620928 ----a-w- C:\Windows\System32\wucltux.dll
2015-01-13 02:22:24 -------- d-----w- C:\Program Files\Unlocker
2015-01-13 02:22:02 97792 ----a-w- C:\Windows\System32\wudriver.dll
2015-01-13 02:22:02 92672 ----a-w- C:\Windows\SysWow64\wudriver.dll
2015-01-13 02:21:31 36864 ----a-w- C:\Windows\System32\wuapp.exe
2015-01-13 02:21:31 33792 ----a-w- C:\Windows\SysWow64\wuapp.exe
2015-01-13 02:21:31 198600 ----a-w- C:\Windows\System32\wuwebv.dll
2015-01-13 02:21:31 179656 ----a-w- C:\Windows\SysWow64\wuwebv.dll
2015-01-13 02:16:06 -------- d-----w- C:\Users\HP\AppData\Local\Programs
2015-01-13 02:15:39 -------- d-----w- C:\Program Files (x86)\DeltaFix
2015-01-13 02:14:41 -------- d-----w- C:\Program Files\6315EBB8-4968-4AE5-8956-C5CABDE87E54
2015-01-13 02:14:41 -------- d-----w- C:\Program Files\010
2015-01-13 02:12:55 -------- d-----w- C:\ProgramData\{60e2beaa-bd65-ff41-60e2-2beaabd6faaa}
2015-01-13 02:08:39 -------- d-----w- C:\Program Files\UVK - Ultra Virus Killer
2015-01-13 02:00:51 593904 ----a-w- C:\ProgramData\1421113858.bdinstall.bin
2015-01-13 01:54:46 76944 ----a-w- C:\Windows\System32\drivers\bdvedisk.sys
2015-01-13 01:54:45 93600 ----a-w- C:\Windows\System32\drivers\BdfNdisf6.sys
2015-01-13 01:54:45 82824 ----a-w- C:\Windows\System32\drivers\bdsandbox.sys
2015-01-13 01:54:45 74000 ----a-w- C:\Windows\SysWow64\bdsandboxuiskin32.dll
2015-01-13 01:54:34 647752 ----a-w- C:\Windows\System32\drivers\avckf.sys
2015-01-13 01:54:34 1288472 ----a-w- C:\Windows\System32\drivers\avc3.sys
2015-01-13 01:54:03 -------- d-----w- C:\Users\HP\AppData\Roaming\Bitdefender
2015-01-13 01:53:59 3271472 ---ha-w- C:\bdr-bz01
2015-01-13 01:51:18 155912 ----a-w- C:\Windows\System32\drivers\gzflt.sys
2015-01-13 01:51:12 452040 ----a-w- C:\Windows\System32\drivers\trufos.sys
2015-01-13 01:44:05 84336 ----a-w- C:\Windows\System32\BDSandBoxUISkin.dll
2015-01-13 01:44:05 33360 ----a-w- C:\Windows\System32\BDSandBoxUH.dll
2015-01-13 01:44:05 -------- d-----w- C:\ProgramData\Bitdefender
.
==================== Find3M ====================
.
2015-01-14 02:52:12 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-01-14 02:52:12 701616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-11-11 03:09:06 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2014-11-11 03:08:52 241152 ----a-w- C:\Windows\System32\pku2u.dll
2014-11-11 03:08:48 728064 ----a-w- C:\Windows\System32\kerberos.dll
2014-11-11 02:44:45 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2014-11-11 02:44:32 186880 ----a-w- C:\Windows\SysWow64\pku2u.dll
2014-11-11 02:44:25 550912 ----a-w- C:\Windows\SysWow64\kerberos.dll
2014-11-11 01:46:26 119296 ----a-w- C:\Windows\System32\drivers\tdx.sys
2014-11-08 03:16:08 2048 ----a-w- C:\Windows\System32\tzres.dll
2014-11-08 02:45:09 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2014-10-30 02:03:43 165888 ----a-w- C:\Windows\System32\charmap.exe
2014-10-30 01:45:43 155136 ----a-w- C:\Windows\SysWow64\charmap.exe
2014-10-25 01:57:59 77824 ----a-w- C:\Windows\System32\packager.dll
2014-10-25 01:32:37 67584 ----a-w- C:\Windows\SysWow64\packager.dll
2010-01-26 21:11:08 444283 ----a-w- C:\Program Files\Common Files\WinPcapNmap.exe
.
============= FINISH: 17:49:31.75 ===============
ATTACH.TXT:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 3/21/2012 3:55:56 AM
System Uptime: 1/21/2015 2:35:15 PM (3 hours ago)
.
Motherboard: Hewlett-Packard | | 1801
Processor: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz | CPU1 | 2201/1333mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 673 GiB total, 597.068 GiB free.
D: is FIXED (NTFS) - 21 GiB total, 2.265 GiB free.
E: is FIXED (FAT32) - 4 GiB total, 2.881 GiB free.
F: is CDROM ()
G: is FIXED (NTFS) - 931 GiB total, 735.83 GiB free.
H: is FIXED (NTFS) - 298 GiB total, 124.594 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP116: 1/12/2015 10:11:47 PM - Windows Update
RP117: 1/12/2015 10:27:29 PM - Windows Update
RP118: 1/13/2015 2:20:56 AM - Windows Update
RP119: 1/13/2015 6:16:28 AM - Windows Update
RP120: 1/13/2015 7:31:56 PM - Windows Update
.
==== Installed Programs ======================
.
µTorrent
7-Zip 9.20 (x64 edition)
Adobe Flash Player 16 ActiveX
Adobe Flash Player 16 NPAPI
Adobe Reader X (10.1.13) MUI
AMD APP SDK Runtime
AMD Catalyst Install Manager
Ashampoo Burning Studio 6 FREE v.6.81
Audacity 2.0.2
AuthenTec TrueAPI
Bejeweled 3
Bitdefender Total Security 2015
Blackhawk Striker 2
CamStudio OSS Desktop Recorder
Catalyst Control Center
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
Catalyst Control Center Profiles Mobile
ccc-utility64
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Chuzzle Deluxe
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Core Temp 1.0 RC4
Cradle of Rome 2
CyberLink PowerDVD
CyberLink YouCam
D3DX10
Dora's World Adventure
ESU for Microsoft Windows 7 SP1
Evernote v. 4.2.3
Farm Frenzy
Farmscapes
FATE
Final Drive Fury
Free FLAC to MP3 Converter 1.0
Free M4a to MP3 Converter 7.1
Freemake Video Converter version 3.0.2
Google Drive
Google Update Helper
Hewlett-Packard ACLM.NET v1.2.1.1
Hoyle Card Games
HP 3D DriveGuard
HP Application Assistant
HP Auto
HP Client Services
HP CoolSense
HP Customer Experience Enhancements
HP Documentation
HP Games
HP Launch Box
HP MovieStore
HP On Screen Display
HP Power Manager
HP Quick Launch
HP QuickWeb
HP Recovery Manager
HP Security Assistant
HP Setup
HP Setup Manager
HP SimplePass 2012
HP Software Framework
IDT Audio
ImgBurn
Intel(R) Control Center
Intel(R) Display Audio Driver
Intel(R) Identity Protection Technology 1.2.22.0
Intel(R) Management Engine Components
Intel(R) Rapid Storage Technology
Jewel Match 3
Jewel Quest Mysteries: The Seventh Gate Collector's Edition
John Deere Drive Green
Junk Mail filter update
LastPass (uninstall only)
Letters from Nowhere 2
Luxor HD
Mah Jong Medley
Mesh Runtime
Microsoft .NET Framework 4.5.1
Microsoft Application Error Reporting
Microsoft Mouse and Keyboard Center
Microsoft Office 2010
Microsoft Office Click-to-Run 2010
Microsoft Office Starter 2010 - English
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft WSE 3.0 Runtime
Microsoft_VC100_CRT_SP1_x64
Microsoft_VC100_CRT_SP1_x86
Mozilla Firefox 35.0 (x86 en-US)
Mozilla Maintenance Service
Mozilla Thunderbird 31.4.0 (x86 en-US)
MSVC80_x64_v2
MSVC80_x86_v2
MSVC90_x64
MSVC90_x86
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB2758694)
Nokia Connectivity Cable Driver
Nokia PC Suite
Nokia Software Updater
Nokia Suite
opensource
Pando Media Booster
PathProc
PC Connectivity Solution
Penguins!
Plants vs. Zombies - Game of the Year
PlayReady PC Runtime x86
Poker Superstars III
Polar Bowler
Polar Golfer
PX Profile Update
Realtek Ethernet Controller Driver
Realtek PCIE Card Reader
REALTEK Wireless LAN Driver
Renesas Electronics USB 3.0 Host Controller Driver
RollerCoaster Tycoon 3: Platinum
Security Update for Microsoft .NET Framework 4.5.1 (KB2894854v2)
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Security Update for Microsoft .NET Framework 4.5.1 (KB2972107)
Security Update for Microsoft .NET Framework 4.5.1 (KB2972216)
Security Update for Microsoft .NET Framework 4.5.1 (KB2978128)
Security Update for Microsoft .NET Framework 4.5.1 (KB2979578v2)
Skype™ 6.11
SpeedFan (remove only)
swMSM
Synaptics TouchPad Driver
The Treasures of Mystery Island: The Ghost Ship
Torchlight
Total Commander (Remove or Repair)
Unlocker 1.9.2
Update Installer for WildTangent Games App
uTorrentControl Toolbar
UVK - Ultra Virus Killer
Validity WBF DDK
VDownloader 3.9.1280
VIP Access SDK (1.1.0.4)
Virtual Villagers 4 - The Tree of Life
Visual Studio 2008 x64 Redistributables
Visual Studio 2010 x64 Redistributables
VLC media player 2.0.1
WildTangent Games App (HP Games)
Windows 7 Codec Pack 4.0.2
Windows Driver Package - Nokia Modem (02/25/2011 4.7)
Windows Driver Package - Nokia Modem (02/25/2011 7.01.0.9)
Windows Driver Package - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0)
Windows Essentials Media Codec Pack 4.0 [64-Bit]
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinPcap 4.1.1
WinX DVD Ripper Platinum 7.0.0
Zuma's Revenge
.
==== End Of File ===========================