2014-12-03

I am getting a message that my Windows 7 Home Premium has been hijacked.

Version 6.1.7601 Service Pack 1 Build 7601

Dell Inspiron 1750

x-64 based PC

Intel(R) Core(TM)2 Duo CPU T6600 @ 2.2 GHz, 2200MHz, 2Core(s), 2 Log

Bios Version Date Dell Inc A03. 8/27/2009

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 12/3/2014

Scan Time: 12:31:01 AM

Logfile: mbam.txt

Administrator: Yes

Version: 0.00.0.0000

Malware Database: v2014.12.03.03

Rootkit Database: v2014.12.02.02

License: Premium

Malware Protection: Enabled

Malicious Website Protection: Enabled

Self-protection: Disabled

OS: Windows 7 Service Pack 1

CPU: x64

File System: NTFS

User: Kevin

Scan Type: Threat Scan

Result: Completed

Objects Scanned: 353492

Time Elapsed: 25 min, 36 sec

Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Warn

PUM: Enabled

Processes: 0

(No malicious items detected)

Modules: 0

(No malicious items detected)

Registry Keys: 0

(No malicious items detected)

Registry Values: 0

(No malicious items detected)

Registry Data: 0

(No malicious items detected)

Folders: 0

(No malicious items detected)

Files: 0

(No malicious items detected)

Physical Sectors: 0

(No malicious items detected)

(end)

DDS (Ver_2012-11-20.01) - NTFS_AMD64

Internet Explorer: 11.0.9600.17420 BrowserJavaVersion: 11.25.2

Run by Kevin at 2:55:09 on 2014-12-03

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4056.2308 [GMT -5:00]

.

AV: Microsoft Security Essentials *Enabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}

SP: Microsoft Security Essentials *Enabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C}

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ===============

.

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

c:\Program Files\Microsoft Security Client\MsMpEng.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe

C:\Program Files\Dell\DellDock\DockLogin.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE

C:\Windows\system32\WLANExt.exe

C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files (x86)\Time Warner Cable\TWC WiFi\AffinegyService.exe

C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files (x86)\Bonjour\mDNSResponder.exe

C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe

C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe

C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe

C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe

C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE

C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\IDT\WDM\sttray64.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE

C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe

C:\Windows\WindowsMobile\wmdc.exe

C:\Program Files\Microsoft Security Client\msseces.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE

C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe

C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe

C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe

C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe

C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe

C:\Program Files (x86)\CCleaner\CCleaner64.exe

C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe

C:\Program Files (x86)\Time Warner Cable\TWC WiFi\TrayApp.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\system32\svchost.exe -k WindowsMobile

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Program Files (x86)\Time Warner Cable\TWC WiFi\TWC WiFi.exe

C:\Windows\system32\SearchIndexer.exe

C:\Windows\System32\WUDFHost.exe

C:\Windows\system32\sppsvc.exe

C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\wuauclt.exe

C:\Program Files\HP\HP Photosmart 6510 series\Bin\HPNetworkCommunicator.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

c:\Program Files\Microsoft Security Client\NisSrv.exe

C:\Program Files (x86)\FxPro - MetaTrader 4\terminal.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\System32\cscript.exe

.

============== Pseudo HJT Report ===============

.

mStart Page = hxxp://www.google.com

BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll

BHO: Skype Click to Call for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll

BHO: Adblock Plus for IE Browser Helper Object: {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll

uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

uRun: [HP Photosmart 6510 series (NET)] "C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN1AK422Y105QB:NW" -scfn "HP Photosmart 6510 series (NET)" -AutoStart 1

uRun: [CCleaner Monitoring] "C:\Program Files (x86)\CCleaner\CCleaner64.exe" /MONITOR

mRun: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m

mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2

mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter

mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe

mRun: [DigiDo] "C:\Program Files (x86)\Time Warner Cable\TWC WiFi\TrayApp.exe" startup

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"

StartupFolder: C:\Users\Kevin\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

uPolicies-Explorer: NoDrives = dword:0

uPolicies-Explorer: NoDriveTypeAutoRun = dword:145

mPolicies-Explorer: NoDrives = dword:0

mPolicies-System: ConsentPromptBehaviorAdmin = dword:5

mPolicies-System: ConsentPromptBehaviorUser = dword:3

mPolicies-System: EnableUIADesktopToggle = dword:0

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll

IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab

DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab

TCP: NameServer = 209.18.47.61 209.18.47.62

TCP: Interfaces\{29CAC180-7BC8-4DAC-9416-809FFD9F6C10} : DHCPNameServer = 209.18.47.61 209.18.47.62

TCP: Interfaces\{B4CAAAAA-263E-4921-ABE2-39B9699A6FEC} : DHCPNameServer = 209.18.47.61 209.18.47.62

TCP: Interfaces\{B4CAAAAA-263E-4921-ABE2-39B9699A6FEC}\B4566796E6 : DHCPNameServer = 209.18.47.61 209.18.47.62

TCP: Interfaces\{B4CAAAAA-263E-4921-ABE2-39B9699A6FEC}\C696E6B6379737 : DHCPNameServer = 209.18.47.61 209.18.47.62

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

x64-mStart Page = www.google.com

x64-BHO: Skype Click to Call for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll

x64-BHO: Adblock Plus for IE Browser Helper Object: {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll

x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe

x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe

x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe

x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe

x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe

x64-Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe

x64-Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe

x64-Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe

x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey

x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll

x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>

x64-Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll

x64-Notify: igfxcui - igfxdev.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\6huj2awo.default\

FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll

FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll

FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\thinkorswim\npthinkorswim.dll

FF - plugin: C:\Program Files (x86)\thinkorswim\nptossc.dll

FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll

.

============= SERVICES / DRIVERS ===============

.

R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2014-7-17 269008]

R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2009-11-22 55280]

R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]

R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]

R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-8-11 172344]

R2 Autodesk Content Service;Autodesk Content Service;C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2011-2-2 18656]

R2 c2cautoupdatesvc;Skype Click to Call Updater;C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-7-14 1390176]

R2 c2cpnrsvc;Skype Click to Call PNR Service;C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-7-14 1767520]

R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648]

R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-6-7 1871160]

R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-6-7 968504]

R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2012-8-30 125584]

R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2009-11-22 1692480]

R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2010-11-2 25816]

R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\MBAMSwissArmy.sys [2014-6-7 129752]

R3 MBAMWebAccessControl;MBAMWebAccessControl;C:\Windows\System32\drivers\mwac.sys [2014-6-7 63704]

R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2014-8-22 368624]

R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2009-11-22 215552]

R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-11-22 393728]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]

S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]

S3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [2014-4-20 31920]

S3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2009-11-22 172704]

S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-3-17 1431888]

S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-11-11 114688]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-6-8 59392]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-2-24 1255736]

.

=============== File Associations ===============

.

FileExt: .scr: AutoCADScriptFile=C:\Windows\System32\notepad.exe "%1"

.

=============== Created Last 30 ================

.

2014-12-03 06:29:41 1188440 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{713D2A95-A6E4-485C-9EC8-BF557635992D}\gapaengine.dll

2014-12-03 06:29:20 11632448 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{34FFB75F-0A84-429F-98E4-78BFBCBEAF84}\mpengine.dll

2014-12-03 04:23:04 1188440 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{18329A3A-3A11-2279-E3FC-4B1DE309D06E}\GapaEngine.dll

2014-12-03 04:22:56 1188440 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{902D26C9-FF39-4CF4-9B2C-DE50E3472C7D}\gapaengine.dll

2014-12-03 04:08:23 11632448 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2014-12-03 03:56:54 1188440 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4190B07D-B2CF-5F73-9A0F-B91BF53B3ECB}\GapaEngine.dll

2014-11-22 19:20:59 -------- d-----w- C:\Users\Kevin\AppData\Local\SpeedFixTool

2014-11-21 10:59:34 1188440 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{13642CD5-DD21-422F-8D45-B46A21610249}\gapaengine.dll

2014-11-19 13:34:21 728064 ----a-w- C:\Windows\System32\kerberos.dll

2014-11-19 13:34:21 241152 ----a-w- C:\Windows\System32\pku2u.dll

2014-11-19 13:34:21 186880 ----a-w- C:\Windows\SysWow64\pku2u.dll

2014-11-19 13:34:20 550912 ----a-w- C:\Windows\SysWow64\kerberos.dll

2014-11-15 11:20:05 -------- d-sh--w- C:\Users\Kevin\AppData\Local\EmieBrowserModeList

2014-11-12 01:39:02 304640 ----a-w- C:\Windows\System32\generaltel.dll

2014-11-12 01:39:01 424448 ----a-w- C:\Windows\System32\aeinv.dll

2014-11-12 01:39:01 228864 ----a-w- C:\Windows\System32\aepdu.dll

2014-11-12 01:37:59 309760 ----a-w- C:\Windows\System32\ncrypt.dll

.

==================== Find3M ====================

.

2014-12-03 05:31:01 129752 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys

2014-12-03 03:58:40 6368 ----a-w- C:\Windows\System32\PerfStringBackup.TMP

2014-11-26 16:33:23 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2014-11-26 16:33:23 701104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2014-11-06 04:04:03 2724864 ----a-w- C:\Windows\System32\mshtml.tlb

2014-11-06 04:03:50 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll

2014-11-06 03:47:03 66560 ----a-w- C:\Windows\System32\iesetup.dll

2014-11-06 03:46:12 580096 ----a-w- C:\Windows\System32\vbscript.dll

2014-11-06 03:46:12 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll

2014-11-06 03:44:28 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll

2014-11-06 03:30:22 144384 ----a-w- C:\Windows\System32\ieUnatt.exe

2014-11-06 03:30:08 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe

2014-11-06 03:29:18 814080 ----a-w- C:\Windows\System32\jscript9diag.dll

2014-11-06 03:28:20 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2014-11-06 03:23:57 6040064 ----a-w- C:\Windows\System32\jscript9.dll

2014-11-06 03:20:18 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe

2014-11-06 03:13:43 501248 ----a-w- C:\Windows\SysWow64\vbscript.dll

2014-11-06 03:13:36 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll

2014-11-06 03:12:44 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll

2014-11-06 03:10:58 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll

2014-11-06 03:07:29 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll

2014-11-06 02:59:36 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe

2014-11-06 02:58:38 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll

2014-11-06 02:42:36 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll

2014-11-06 02:39:39 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll

2014-11-06 02:38:25 2124288 ----a-w- C:\Windows\System32\inetcpl.cpl

2014-11-06 02:21:49 4298240 ----a-w- C:\Windows\SysWow64\jscript9.dll

2014-11-06 02:21:25 2051072 ----a-w- C:\Windows\SysWow64\inetcpl.cpl

2014-11-06 02:20:37 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll

2014-11-06 02:17:24 2365440 ----a-w- C:\Windows\System32\wininet.dll

2014-11-06 01:52:35 1892864 ----a-w- C:\Windows\SysWow64\wininet.dll

2014-11-02 21:11:53 4400264 ----a-w- C:\Windows\System32\MetaViewer64.dll

2014-10-30 11:25:26 275080 ------w- C:\Windows\System32\MpSigStub.exe

2014-10-25 01:57:59 77824 ----a-w- C:\Windows\System32\packager.dll

2014-10-25 01:32:37 67584 ----a-w- C:\Windows\SysWow64\packager.dll

2014-10-23 09:56:02 98216 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

2014-10-18 02:05:23 861696 ----a-w- C:\Windows\System32\oleaut32.dll

2014-10-18 01:33:18 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll

2014-10-14 02:16:37 155064 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys

2014-10-14 02:13:06 683520 ----a-w- C:\Windows\System32\termsrv.dll

2014-10-14 02:13:00 3241984 ----a-w- C:\Windows\System32\msi.dll

2014-10-14 02:12:57 1460736 ----a-w- C:\Windows\System32\lsasrv.dll

2014-10-14 02:09:31 146432 ----a-w- C:\Windows\System32\msaudite.dll

2014-10-14 02:07:31 681984 ----a-w- C:\Windows\System32\adtschema.dll

2014-10-14 01:50:47 22016 ----a-w- C:\Windows\SysWow64\secur32.dll

2014-10-14 01:50:41 2363904 ----a-w- C:\Windows\SysWow64\msi.dll

2014-10-14 01:49:38 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll

2014-10-14 01:47:30 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll

2014-10-14 01:46:02 681984 ----a-w- C:\Windows\SysWow64\adtschema.dll

2014-10-10 00:57:42 3198976 ----a-w- C:\Windows\System32\win32k.sys

2014-10-03 02:12:00 500224 ----a-w- C:\Windows\System32\AUDIOKSE.dll

2014-10-03 02:11:54 284672 ----a-w- C:\Windows\System32\EncDump.dll

2014-10-03 02:11:51 680960 ----a-w- C:\Windows\System32\audiosrv.dll

2014-10-03 02:11:51 440832 ----a-w- C:\Windows\System32\AudioEng.dll

2014-10-03 02:11:51 296448 ----a-w- C:\Windows\System32\AudioSes.dll

2014-10-03 01:44:42 442880 ----a-w- C:\Windows\SysWow64\AUDIOKSE.dll

2014-10-03 01:44:26 374784 ----a-w- C:\Windows\SysWow64\AudioEng.dll

2014-10-03 01:44:26 195584 ----a-w- C:\Windows\SysWow64\AudioSes.dll

2014-10-01 15:11:26 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys

2014-10-01 15:11:16 93400 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys

2014-10-01 15:11:12 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys

2014-09-25 02:08:38 371712 ----a-w- C:\Windows\System32\qdvd.dll

2014-09-25 01:40:50 519680 ----a-w- C:\Windows\SysWow64\qdvd.dll

2014-09-19 09:42:52 210944 ----a-w- C:\Windows\System32\wdigest.dll

2014-09-19 09:42:51 86528 ----a-w- C:\Windows\System32\TSpkg.dll

2014-09-19 09:42:49 342016 ----a-w- C:\Windows\System32\schannel.dll

2014-09-19 09:42:47 314880 ----a-w- C:\Windows\System32\msv1_0.dll

2014-09-19 09:42:41 22016 ----a-w- C:\Windows\System32\credssp.dll

2014-09-19 09:23:55 172032 ----a-w- C:\Windows\SysWow64\wdigest.dll

2014-09-19 09:23:52 65536 ----a-w- C:\Windows\SysWow64\TSpkg.dll

2014-09-19 09:23:49 248832 ----a-w- C:\Windows\SysWow64\schannel.dll

2014-09-19 09:23:46 221184 ----a-w- C:\Windows\SysWow64\ncrypt.dll

2014-09-19 09:23:45 259584 ----a-w- C:\Windows\SysWow64\msv1_0.dll

2014-09-19 09:23:36 17408 ----a-w- C:\Windows\SysWow64\credssp.dll

2014-09-09 22:11:04 2048 ----a-w- C:\Windows\System32\tzres.dll

2014-09-09 21:47:10 2048 ----a-w- C:\Windows\SysWow64\tzres.dll

2012-08-25 17:14:27 360736 ----a-w- C:\Program Files (x86)\WinZip165.exe

.

============= FINISH: 2:56:03.93 ===============

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2012-11-20.01)

.

Microsoft Windows 7 Home Premium

Boot Device: \Device\HarddiskVolume2

Install Date: 12/2/2009 4:47:49 PM

System Uptime: 12/2/2014 10:51:16 PM (4 hours ago)

.

Motherboard: Dell Inc. | | 0F642T

Processor: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz | Microprocessor | 2200/200mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 451 GiB total, 337.446 GiB free.

D: is CDROM ()

E: is Removable

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

RP497: 11/12/2014 3:47:02 PM - Windows Update

RP498: 11/15/2014 3:00:24 AM - Windows Update

RP499: 11/18/2014 10:23:15 PM - Windows Update

RP500: 11/22/2014 3:00:18 AM - Windows Update

RP501: 11/27/2014 3:32:23 AM - Windows Update

RP502: 12/1/2014 3:32:14 AM - Windows Update

RP503: 12/2/2014 11:04:16 PM - Windows Update

.

==== Installed Programs ======================

.

Update for Microsoft Office 2007 (KB2508958)

µTorrent

Adblock Plus for IE

Adblock Plus for IE (32-bit and 64-bit)

Adobe AIR

Adobe Community Help

Adobe Download Assistant

Adobe Flash Player 15 ActiveX

Adobe Flash Player 15 Plugin

Adobe Media Player

Adobe Reader XI (11.0.09)

Advanced Audio FX Engine

Apple Application Support

Apple Software Update

Audio Recorder for Free v14.0.2

AutoCAD 2012 - English

AutoCAD 2012 Language Pack - English

Autodesk Content Service

Autodesk Inventor Fusion 2012

Autodesk Inventor Fusion 2012 Language Pack

Autodesk Inventor Fusion plug-in for AutoCAD 2012

Autodesk Inventor Fusion plug-in language pack for AutoCAD 2012

Autodesk Material Library 2012

Autodesk Material Library Base Resolution Image Library 2012

Autodesk Material Library Medium Resolution Image Library 2012

Avi to Dvd Free Converter v6.6.0.95

Banctec Service Agreement

Bonjour

Camtasia Studio 8

CCleaner

Cisco EAP-FAST Module

Cisco LEAP Module

Cisco PEAP Module

D3DX10

Dell DataSafe Local Backup

Dell DataSafe Local Backup - Support Software

Dell DataSafe Online

Dell Dock

Dell Driver Download Manager

Dell Edoc Viewer

Dell Getting Started Guide

Dell Support Center (Support Software)

Dell Touchpad

Dell Webcam Central

Dell Wireless WLAN Card Utility

DellTouch

Digital Photo Navigator 1.5

doPDF 7.3 printer

Drivers.com

FARO LS 1.1.406.58

FileHippo.com Update Checker

Free File Viewer 2010

FXCM MetaTrader 4

FXCM Trading Station

FxPro - MetaTrader 4

Google Chrome

Google Update Helper

GoToAssist 8.0.0.514

Hijack Hunter 1.8.4.1

hotComm® CL

HotForex MetaTrader 4.00

HP Photo Creations

HP Photosmart 6510 series Basic Device Software

HP Photosmart 6510 series Help

HP Photosmart 6510 series Product Improvement Study

HP Update

HTC Touch Pro

Intel(R) Graphics Media Accelerator Driver

Intel® Matrix Storage Manager

Java 8 Update 25

Java Auto Updater

JavaFX 2.1.1

Junk Mail filter update

Live! Cam Avatar Creator

LoJack Factory Installer

Malwarebytes Anti-Malware version 2.0.3.1025

Microsoft .NET Framework 4.5.1

Microsoft Application Error Reporting

Microsoft Office 2007 Service Pack 3 (SP3)

Microsoft Office Access MUI (English) 2007

Microsoft Office Access Setup Metadata MUI (English) 2007

Microsoft Office Enterprise 2007

Microsoft Office Excel MUI (English) 2007

Microsoft Office File Validation Add-In

Microsoft Office Groove MUI (English) 2007

Microsoft Office Groove Setup Metadata MUI (English) 2007

Microsoft Office Home and Student 2007

Microsoft Office InfoPath MUI (English) 2007

Microsoft Office Office 64-bit Components 2007

Microsoft Office OneNote MUI (English) 2007

Microsoft Office Outlook MUI (English) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

Microsoft Office Publisher MUI (English) 2007

Microsoft Office Shared 64-bit MUI (English) 2007

Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office Word MUI (English) 2007

Microsoft Security Client

Microsoft Security Essentials

Microsoft Silverlight

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2005 Redistributable (x64)

Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319

Microsoft XML Parser

Microsoft_VC80_ATL_x86

Microsoft_VC80_ATL_x86_x64

Microsoft_VC80_CRT_x86

Microsoft_VC80_CRT_x86_x64

Microsoft_VC80_MFC_x86

Microsoft_VC80_MFC_x86_x64

Microsoft_VC80_MFCLOC_x86

Microsoft_VC80_MFCLOC_x86_x64

Microsoft_VC90_ATL_x86

Microsoft_VC90_ATL_x86_x64

Microsoft_VC90_CRT_x86

Microsoft_VC90_CRT_x86_x64

Microsoft_VC90_MFC_x86

Microsoft_VC90_MFC_x86_x64

Microsoft_VC90_MFCLOC_x86

Microsoft_VC90_MFCLOC_x86_x64

Mozilla Firefox 33.1.1 (x86 en-US)

Mozilla Maintenance Service

MSVCRT

MSVCRT_amd64

Newsprofiteer

Pdf995

PowerDVD DX

Quickset64

QuickTime

Roxio Burn

Roxio Update Manager

Security Update for CAPICOM (KB931906)

Security Update for Microsoft .NET Framework 4.5.1 (KB2894854v2)

Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)

Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)

Security Update for Microsoft .NET Framework 4.5.1 (KB2931368)

Security Update for Microsoft .NET Framework 4.5.1 (KB2972107)

Security Update for Microsoft .NET Framework 4.5.1 (KB2972216)

Security Update for Microsoft .NET Framework 4.5.1 (KB2978128)

Security Update for Microsoft .NET Framework 4.5.1 (KB2979578v2)

Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2760415) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2817330) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2827326) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2850022) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2878233) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2880507) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2880508) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2881069) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2899526) 32-Bit Edition

Security Update for Microsoft Office Excel 2007 (KB2827324) 32-Bit Edition

Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition

Security Update for Microsoft Office OneNote 2007 (KB2596857) 32-Bit Edition

Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition

Security Update for Microsoft Office Publisher 2007 (KB2817565) 32-Bit Edition

Security Update for Microsoft Office Word 2007 (KB2899527) 32-Bit Edition

Shared C Run-time for x64

Skype Click to Call

Skype™ 6.11

SolidWorks eDrawings 2011

Streaming Audio Recorder V3.3.4

SUPERAntiSpyware

thinkorswim

TWC WiFi

Update for 2007 Microsoft Office System (KB967642)

Update for Microsoft Office 2007 Help for Common Features (KB963673)

Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition

Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition

Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition

Update for Microsoft Office Access 2007 Help (KB963663)

Update for Microsoft Office Excel 2007 Help (KB963678)

Update for Microsoft Office Infopath 2007 Help (KB963662)

Update for Microsoft Office OneNote 2007 Help (KB963670)

Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition

Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition

Update for Microsoft Office Outlook 2007 Help (KB963677)

Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2899525) 32-Bit Edition

Update for Microsoft Office PowerPoint 2007 (KB2597972) 32-Bit Edition

Update for Microsoft Office Powerpoint 2007 Help (KB963669)

Update for Microsoft Office Publisher 2007 Help (KB963667)

Update for Microsoft Office Script Editor Help (KB963671)

Update for Microsoft Office Word 2007 Help (KB963665)

WD Diagnostics

Windows Live Communications Platform

Windows Live Essentials

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Language Selector

Windows Live Mail

Windows Live Messenger

Windows Live MIME IFilter

Windows Live Movie Maker

Windows Live Photo Common

Windows Live Photo Gallery

Windows Live PIMT Platform

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live Sync

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

Windows Mobile Device Center

Windows Mobile Device Center Driver Update

WinRAR 4.20 (64-bit)

WinZip 17.0

Zip Opener Packages

.

==== Event Viewer Messages From Past Week ========

.

12/2/2014 3:30:16 AM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.189.1066.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.11202.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

12/1/2014 9:12:58 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR2.

11/26/2014 3:30:11 AM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.189.522.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.11202.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

11/26/2014 3:30:08 AM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.189.522.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.11202.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

.

==== End Of File ===========================

Show more