Hi,
I really don't think I have malware; however, from my thread some glitches after restored win7 http://www.techsupportforum.com/forums/f217/some-glitches-after-restored-win7-1014026.html spunk.funk thinks it may be malware.
Right now the biggest problem is with FF, making the tabs the same when I try to open a new one or change one, clicking on links in email or forum doesn't work and loss of icon on taskbar in general account only. I've uninstalled and reinstalled FF 4 times since the reinstall of the OS (the first one I had a BSOD in the middle of updating windows and had many, many problems, so did a full reinstall - and ran anti-malware programs both before and after the reinstalls (MSSE, Malwarebytes, and ESET online scanner) and none found any problems. I didn't load the 3 PUPs windows updates when updating windows, although before the reinstall and before I knew the windows7 updates were PUP's for win10 I had them downloaded and installed.
One other program isn't showing up on in my general account. Also, a few desktop icons I can't seem to get rid of that have to do with my cannon printer.
Since the BSOD in the first try to reinstall had to do with hardware, I've loaded the drivers for my other USB hardware but removed them, so only my mouse and keyboard are plugged in.
I have the factory disc (which I used for the reinstalls) and the windows disc for my computer.
Thank you
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17840
Run by 93 at 14:16:49 on 2015-07-05
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.7104.5233 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: Microsoft Security Essentials *Enabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files\Microsoft LifeCam\MSCamS64.exe
C:\Windows\system32\svchost.exe -k imgsvc
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Users\93\AppData\Local\FluxSoftware\Flux\flux.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\splwow64.exe
C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\PrintIsolationHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.pugetsystems.com/welcome.php?oid=117561
mWinlogon: Userinit = userinit.exe
BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
EB: Canon Easy-WebPrint EX: {21347690-EC41-4F9A-8887-1F4AEE672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
uRun: [f.lux] "C:\Users\93\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
uRun: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
uRun: [WinPatrol] C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe -expressboot
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
mRun: [CanonQuickMenu] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.0.1 205.171.3.25
TCP: Interfaces\{649FED28-E5CC-41A3-A3E0-B1852BA10A06} : DHCPNameServer = 192.168.0.1 205.171.3.25
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [IAStorIcon] "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
x64-Run: [IgfxTray] "C:\Windows\System32\igfxtray.exe"
x64-Run: [HotKeysCmds] "C:\Windows\System32\hkcmd.exe"
x64-Run: [Persistence] "C:\Windows\System32\igfxpers.exe"
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\syowip1a.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.pugetsystems.com/welcome.php?oid=117561
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll
FF - plugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrlui.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_194.dll
.
============= SERVICES / DRIVERS ===============
.
R0 iaStorA;iaStorA;C:\Windows\System32\drivers\iaStorA.sys [2013-1-31 652784]
R0 iaStorF;iaStorF;C:\Windows\System32\drivers\iaStorF.sys [2013-1-31 28656]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2013-11-21 20464]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2015-3-4 280376]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-5-29 77128]
R2 asComSvc;ASUS Com Service;C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe [2013-11-21 927232]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-4-11 103608]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-4-11 124088]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-1-31 15344]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-2-13 731648]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-11-21 169432]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-6-18 124568]
R3 e1dexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver D;C:\Windows\System32\drivers\e1d62x64.sys [2013-11-21 496400]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-11-21 452088]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2013-11-21 368112]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2013-11-21 786416]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-11-21 25816]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-4-30 366544]
R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2015-6-23 190088]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-7-4 1133880]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-6-3 327296]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2015-7-4 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-2-13 820184]
S3 MBAMWebAccessControl;MBAMWebAccessControl;C:\Windows\System32\drivers\mwac.sys [2015-7-4 63704]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;C:\Windows\System32\drivers\nx6000.sys [2010-5-20 36720]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-11-21 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2015-7-5 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-11-21 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-11-21 1255736]
.
=============== Created Last 30 ================
.
2015-07-05 21:05:39 75888 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8CDF2AE-9704-4AC7-A361-33BB8383E557}\offreg.936.dll
2015-07-05 14:58:35 -------- d-----r- C:\Sandbox
2015-07-05 14:53:41 12221144 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8CDF2AE-9704-4AC7-A361-33BB8383E557}\mpengine.dll
2015-07-05 13:55:51 12221144 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-07-05 13:11:54 -------- d-----w- C:\Program Files (x86)\ESET
2015-07-05 13:08:09 -------- d-----w- C:\Windows\pss
2015-07-05 12:53:06 -------- d-----w- C:\Users\93\AppData\Roaming\WinPatrol
2015-07-05 12:53:01 -------- d-----w- C:\ProgramData\InstallMate
2015-07-05 12:53:01 -------- d-----w- C:\Program Files (x86)\Ruiware
2015-07-05 12:47:28 -------- d-----w- C:\Program Files\iTunes
2015-07-05 12:47:28 -------- d-----w- C:\Program Files\iPod
2015-07-05 12:47:28 -------- d-----w- C:\Program Files (x86)\iTunes
2015-07-05 12:33:13 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin5.dll
2015-07-05 12:33:13 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin4.dll
2015-07-05 12:33:13 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin3.dll
2015-07-05 12:33:13 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin2.dll
2015-07-05 12:33:13 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin.dll
2015-07-05 12:20:59 -------- d-----w- C:\Users\93\AppData\Local\Macromedia
2015-07-05 12:19:17 -------- d-----w- C:\Users\93\AppData\Roaming\Canneverbe Limited
2015-07-05 12:09:38 778416 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2015-07-05 12:09:38 142512 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-07-05 12:01:58 336896 ----a-w- C:\Windows\SysWow64\CNC_C9L.dll
2015-07-05 12:01:58 15872 ----a-w- C:\Windows\SysWow64\CNHMCA.dll
2015-07-05 11:59:58 -------- d-----w- C:\ProgramData\CanonIJWSpt
2015-07-05 11:56:22 -------- d-----w- C:\Program Files\Canon
2015-07-05 11:55:41 30208 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPDC9.DLL
2015-07-05 11:55:41 102912 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPPC9.DLL
2015-07-05 11:55:39 369664 ----a-w- C:\Windows\System32\CNC_C9L.dll
2015-07-05 11:55:39 316928 ----a-w- C:\Windows\System32\CNC_C9C.dll
2015-07-05 11:55:39 17920 ----a-w- C:\Windows\System32\CNHMCA6.dll
2015-07-05 11:55:39 105984 ----a-w- C:\Windows\System32\CNC_C9I.dll
2015-07-05 11:55:35 406016 ----a-w- C:\Windows\System32\CNMLMC9.DLL
2015-07-05 11:30:34 -------- d-----w- C:\Users\93\AppData\Roaming\Canon_Inc_IC
2015-07-05 11:30:00 -------- d-----w- C:\Program Files (x86)\Canon
2015-07-05 11:29:57 -------- d-----w- C:\Program Files (x86)\Common Files\Canon_Inc_IC
2015-07-05 11:28:38 -------- d-----w- C:\ProgramData\Canon_Inc_IC
2015-07-05 11:23:42 -------- d-----w- C:\Temp
2015-07-05 08:46:41 6584320 ----a-w- C:\Windows\System32\mstscax.dll
2015-07-05 08:45:58 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2015-07-05 08:45:58 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2015-07-05 08:45:57 3179520 ----a-w- C:\Windows\System32\rdpcorets.dll
2015-07-05 08:45:57 243200 ----a-w- C:\Windows\System32\rdpudd.dll
2015-07-05 08:45:57 16384 ----a-w- C:\Windows\System32\RdpGroupPolicyExtension.dll
2015-07-05 08:45:42 460800 ----a-w- C:\Windows\System32\certcli.dll
2015-07-05 08:45:42 342016 ----a-w- C:\Windows\SysWow64\certcli.dll
2015-07-05 08:45:22 1647104 ----a-w- C:\Windows\System32\DWrite.dll
2015-07-05 08:45:22 1250816 ----a-w- C:\Windows\SysWow64\DWrite.dll
2015-07-05 08:45:22 1179136 ----a-w- C:\Windows\System32\FntCache.dll
2015-07-05 08:45:17 683520 ----a-w- C:\Windows\System32\termsrv.dll
2015-07-05 08:43:02 52224 ----a-w- C:\Windows\SysWow64\nlaapi.dll
2015-07-05 08:43:02 303616 ----a-w- C:\Windows\System32\nlasvc.dll
2015-07-05 08:43:02 156672 ----a-w- C:\Windows\SysWow64\ncsi.dll
2015-07-05 08:43:00 335360 ----a-w- C:\Windows\System32\msieftp.dll
2015-07-05 08:43:00 301568 ----a-w- C:\Windows\SysWow64\msieftp.dll
2015-07-05 08:42:58 210432 ----a-w- C:\Windows\System32\profsvc.dll
2015-07-05 08:42:56 484864 ----a-w- C:\Windows\System32\wer.dll
2015-07-05 08:42:56 381440 ----a-w- C:\Windows\SysWow64\wer.dll
2015-07-05 08:42:54 141312 ----a-w- C:\Windows\System32\drivers\mrxdav.sys
2015-07-05 08:27:44 -------- d-s---w- C:\Windows\SysWow64\GWX
2015-07-05 08:27:44 -------- d-s---w- C:\Windows\System32\GWX
2015-07-05 08:27:44 -------- d-----w- C:\Windows\Migration
2015-07-05 08:17:05 2777088 ----a-w- C:\Windows\System32\msmpeg2vdec.dll
2015-07-05 08:17:05 2285056 ----a-w- C:\Windows\SysWow64\msmpeg2vdec.dll
2015-07-05 07:35:58 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2015-07-05 07:35:58 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2015-07-05 07:35:56 504320 ----a-w- C:\Windows\System32\msihnd.dll
2015-07-05 07:35:56 337408 ----a-w- C:\Windows\SysWow64\msihnd.dll
2015-07-05 07:35:56 1941504 ----a-w- C:\Windows\System32\authui.dll
2015-07-05 07:35:56 1805824 ----a-w- C:\Windows\SysWow64\authui.dll
2015-07-05 07:35:56 112064 ----a-w- C:\Windows\System32\consent.exe
2015-07-05 07:35:45 497152 ----a-w- C:\Windows\System32\drivers\afd.sys
2015-07-05 07:35:44 624128 ----a-w- C:\Windows\System32\qedit.dll
2015-07-05 07:35:44 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2015-07-05 07:12:31 -------- d-----w- C:\Program Files\Sandboxie
2015-07-05 07:09:35 -------- d-----w- C:\Users\93\AppData\Local\FluxSoftware
2015-07-05 06:52:17 124112 ----a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2015-07-05 06:52:17 102608 ----a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-07-05 06:39:09 230400 ----a-w- C:\Windows\System32\drivers\portcls.sys
2015-07-05 06:39:09 116736 ----a-w- C:\Windows\System32\drivers\drmk.sys
2015-07-05 06:39:04 99840 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2015-07-05 06:39:04 7808 ----a-w- C:\Windows\System32\drivers\usbd.sys
2015-07-05 06:39:04 53248 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2015-07-05 06:39:04 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2015-07-05 06:39:04 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2015-07-05 06:39:04 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2015-07-05 06:39:04 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2015-07-05 06:38:46 -------- d-----w- C:\Users\93\AppData\Roaming\Contaware
2015-07-05 06:38:46 -------- d-----w- C:\ContaCam
2015-07-05 06:38:39 -------- d-----w- C:\Program Files (x86)\ContaCam
2015-07-05 06:36:02 -------- d-----w- C:\ProgramData\Licenses
2015-07-05 06:36:01 129872 ----a-w- C:\Windows\SysWow64\MSSTDFMT.DLL
2015-07-05 06:35:59 -------- d-----w- C:\Program Files (x86)\SpywareBlaster
2015-07-05 06:28:45 -------- d-----w- C:\Users\93\AppData\Local\Skype
2015-07-05 06:27:01 -------- d-----w- C:\Program Files\Microsoft LifeCam
2015-07-05 06:27:01 -------- d-----w- C:\Program Files (x86)\Microsoft LifeCam
2015-07-05 06:08:24 -------- d-----w- C:\Program Files\Microsoft Mouse and Keyboard Center
2015-07-05 06:03:46 878080 ----a-w- C:\Windows\System32\IMJP10K.DLL
2015-07-05 06:03:46 701440 ----a-w- C:\Windows\SysWow64\IMJP10K.DLL
2015-07-05 06:03:45 3928064 ----a-w- C:\Windows\System32\d2d1.dll
2015-07-05 06:03:45 3419136 ----a-w- C:\Windows\SysWow64\d2d1.dll
2015-07-05 06:03:44 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2015-07-05 06:03:44 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2015-07-05 06:03:44 1882624 ----a-w- C:\Windows\System32\msxml3.dll
2015-07-05 06:03:44 1237504 ----a-w- C:\Windows\SysWow64\msxml3.dll
2015-07-05 06:03:41 985536 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2015-07-05 06:00:13 459336 ----a-w- C:\Windows\System32\drivers\cng.sys
2015-07-05 05:59:21 3206144 ----a-w- C:\Windows\System32\win32k.sys
2015-07-05 05:51:44 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2015-07-05 05:51:44 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2015-07-05 05:51:40 142336 ----a-w- C:\Windows\System32\poqexec.exe
2015-07-05 05:51:40 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2015-07-05 05:49:08 241152 ----a-w- C:\Windows\System32\pku2u.dll
2015-07-05 05:49:08 186880 ----a-w- C:\Windows\SysWow64\pku2u.dll
2015-07-05 05:46:48 828928 ----a-w- C:\Windows\SysWow64\msctf.dll
2015-07-05 05:45:53 72192 ----a-w- C:\Windows\System32\aelupsvc.dll
2015-07-05 05:44:57 1684928 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2015-07-05 05:44:55 406528 ----a-w- C:\Windows\System32\scesrv.dll
2015-07-05 05:44:55 308224 ----a-w- C:\Windows\SysWow64\scesrv.dll
2015-07-05 05:44:53 3241984 ----a-w- C:\Windows\System32\msi.dll
2015-07-05 05:44:53 2363904 ----a-w- C:\Windows\SysWow64\msi.dll
2015-07-05 05:44:35 202752 ----a-w- C:\Windows\System32\scrrun.dll
2015-07-05 05:44:35 168960 ----a-w- C:\Windows\System32\wscript.exe
2015-07-05 05:44:35 163840 ----a-w- C:\Windows\SysWow64\scrrun.dll
2015-07-05 05:44:35 156160 ----a-w- C:\Windows\System32\cscript.exe
2015-07-05 05:44:35 150016 ----a-w- C:\Windows\System32\wshom.ocx
2015-07-05 05:44:35 141824 ----a-w- C:\Windows\SysWow64\wscript.exe
2015-07-05 05:44:35 126976 ----a-w- C:\Windows\SysWow64\cscript.exe
2015-07-05 05:44:35 121856 ----a-w- C:\Windows\SysWow64\wshom.ocx
2015-07-05 05:43:02 465920 ----a-w- C:\Windows\System32\WMPhoto.dll
2015-07-05 05:43:02 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll
2015-07-05 05:43:01 664064 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2015-07-05 05:43:01 1216000 ----a-w- C:\Windows\System32\rpcrt4.dll
2015-07-05 05:21:55 -------- d-----w- C:\Windows\TempF557102D-152E-62A5-F388-7DC92BE60855-Signatures
2015-07-05 05:15:25 -------- d-----r- C:\Program Files (x86)\Skype
2015-07-05 05:11:12 99480 ----a-w- C:\Windows\SysWow64\infocardapi.dll
2015-07-05 05:11:11 8856 ----a-w- C:\Windows\SysWow64\icardres.dll
2015-07-05 05:11:11 8856 ----a-w- C:\Windows\System32\icardres.dll
2015-07-05 05:11:11 619672 ----a-w- C:\Windows\SysWow64\icardagt.exe
2015-07-05 05:11:11 171160 ----a-w- C:\Windows\System32\infocardapi.dll
2015-07-05 05:11:11 1389208 ----a-w- C:\Windows\System32\icardagt.exe
2015-07-05 05:10:59 35480 ----a-w- C:\Windows\SysWow64\TsWpfWrp.exe
2015-07-05 05:10:59 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe
2015-07-05 04:50:35 1480192 ----a-w- C:\Windows\System32\crypt32.dll
2015-07-05 04:30:30 493504 ----a-w- C:\Windows\System32\mcupdate_GenuineIntel.dll
2015-07-05 04:26:21 81560 ----a-w- C:\Windows\SysWow64\mscories.dll
2015-07-05 04:26:21 73880 ----a-w- C:\Windows\System32\mscories.dll
2015-07-05 04:26:21 1943696 ----a-w- C:\Windows\System32\dfshim.dll
2015-07-05 04:26:21 156824 ----a-w- C:\Windows\SysWow64\mscorier.dll
2015-07-05 04:26:21 156312 ----a-w- C:\Windows\System32\mscorier.dll
2015-07-05 04:26:21 1131664 ----a-w- C:\Windows\SysWow64\dfshim.dll
2015-07-05 04:24:57 82944 ----a-w- C:\Windows\System32\dwmapi.dll
2015-07-05 04:24:57 67584 ----a-w- C:\Windows\SysWow64\dwmapi.dll
2015-07-05 04:24:57 1632768 ----a-w- C:\Windows\System32\dwmcore.dll
2015-07-05 04:24:57 1372160 ----a-w- C:\Windows\SysWow64\dwmcore.dll
2015-07-05 04:18:08 965000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2015-07-05 04:18:08 1190000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A3917C19-9C92-466A-9D63-AE4A0B6E4827}\gapaengine.dll
2015-07-05 04:09:59 -------- d-----w- C:\Windows\PCHEALTH
2015-07-05 04:06:53 -------- d-----w- C:\Program Files (x86)\Microsoft Analysis Services
2015-07-05 04:06:41 -------- d-----w- C:\Users\93\AppData\Local\Microsoft Help
2015-06-17 07:23:50 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2015-06-17 07:23:50 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
.
==================== Find3M ====================
.
2015-07-05 10:08:23 300704 ------w- C:\Windows\System32\MpSigStub.exe
2015-07-05 05:54:57 113880 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2015-06-18 15:41:56 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys
2015-06-18 15:41:44 109272 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2015-06-18 15:41:40 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2015-05-25 18:24:00 5569984 ----a-w- C:\Windows\System32\ntoskrnl.exe
2015-05-25 18:23:59 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2015-05-25 18:23:59 155584 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2015-05-25 18:21:21 1728960 ----a-w- C:\Windows\System32\ntdll.dll
2015-05-25 18:18:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2015-05-25 18:18:56 22016 ----a-w- C:\Windows\System32\credssp.dll
2015-05-25 18:18:54 879104 ----a-w- C:\Windows\System32\advapi32.dll
2015-05-25 18:18:45 47104 ----a-w- C:\Windows\System32\typeperf.exe
2015-05-25 18:18:45 404992 ----a-w- C:\Windows\System32\tracerpt.exe
2015-05-25 18:18:39 112640 ----a-w- C:\Windows\System32\smss.exe
2015-05-25 18:18:32 296960 ----a-w- C:\Windows\System32\rstrui.exe
2015-05-25 18:18:30 43008 ----a-w- C:\Windows\System32\relog.exe
2015-05-25 18:18:19 31232 ----a-w- C:\Windows\System32\lsass.exe
2015-05-25 18:18:19 104448 ----a-w- C:\Windows\System32\logman.exe
2015-05-25 18:18:11 19456 ----a-w- C:\Windows\System32\diskperf.exe
2015-05-25 18:18:08 338432 ----a-w- C:\Windows\System32\conhost.exe
2015-05-25 18:18:04 64000 ----a-w- C:\Windows\System32\auditpol.exe
2015-05-25 18:14:26 60416 ----a-w- C:\Windows\System32\msobjs.dll
2015-05-25 18:14:04 146432 ----a-w- C:\Windows\System32\msaudite.dll
2015-05-25 18:07:34 3989440 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2015-05-25 18:07:34 3934144 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2015-05-25 18:04:08 1310744 ----a-w- C:\Windows\SysWow64\ntdll.dll
2015-05-25 18:00:44 40448 ----a-w- C:\Windows\SysWow64\typeperf.exe
2015-05-25 18:00:40 364544 ----a-w- C:\Windows\SysWow64\tracerpt.exe
2015-05-25 18:00:28 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2015-05-25 18:00:25 37888 ----a-w- C:\Windows\SysWow64\relog.exe
2015-05-25 18:00:17 82944 ----a-w- C:\Windows\SysWow64\logman.exe
2015-05-25 18:00:09 17408 ----a-w- C:\Windows\SysWow64\diskperf.exe
2015-05-25 18:00:04 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2015-05-25 17:59:52 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2015-05-25 17:59:52 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2015-05-25 17:59:51 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2015-05-25 17:57:31 60416 ----a-w- C:\Windows\SysWow64\msobjs.dll
2015-05-25 17:57:15 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll
2015-05-25 17:00:56 36864 ----a-w- C:\Windows\System32\UtcResources.dll
2015-05-25 16:50:38 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2015-05-25 16:50:36 2048 ----a-w- C:\Windows\SysWow64\user.exe
2015-05-25 16:48:25 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2015-05-25 16:48:25 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-25 16:48:25 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-25 16:48:25 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2015-05-23 03:28:17 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2015-05-23 03:15:54 503808 ----a-w- C:\Windows\SysWow64\vbscript.dll
2015-05-23 03:15:40 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2015-05-23 03:15:02 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2015-05-23 03:14:51 341504 ----a-w- C:\Windows\SysWow64\html.iec
2015-05-23 03:13:48 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2015-05-23 03:05:21 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2015-05-23 03:04:50 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2015-05-23 02:52:43 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2015-05-23 02:47:31 4305920 ----a-w- C:\Windows\SysWow64\jscript9.dll
2015-05-23 02:37:45 2052608 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2015-05-23 02:37:25 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2015-05-23 02:20:35 1950720 ----a-w- C:\Windows\SysWow64\wininet.dll
2015-05-22 19:16:55 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2015-05-22 19:16:44 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2015-05-22 19:01:42 66560 ----a-w- C:\Windows\System32\iesetup.dll
2015-05-22 19:00:54 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2015-05-22 19:00:47 417792 ----a-w- C:\Windows\System32\html.iec
2015-05-22 19:00:25 584192 ----a-w- C:\Windows\System32\vbscript.dll
2015-05-22 18:59:27 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2015-05-22 18:52:21 6026240 ----a-w- C:\Windows\System32\jscript9.dll
2015-05-22 18:47:49 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2015-05-22 18:47:34 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
2015-05-22 18:47:03 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2015-05-22 18:40:17 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2015-05-22 18:29:31 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2015-05-22 18:05:28 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2015-05-22 18:05:06 2125824 ----a-w- C:\Windows\System32\inetcpl.cpl
2015-05-22 17:50:20 2426880 ----a-w- C:\Windows\System32\wininet.dll
2015-05-09 03:27:37 98304 ----a-w- C:\Windows\System32\wudriver.dll
2015-05-09 03:27:37 3147776 ----a-w- C:\Windows\System32\wucltux.dll
2015-05-09 03:27:37 191488 ----a-w- C:\Windows\System32\wuwebv.dll
2015-05-09 03:26:38 87040 ----a-w- C:\Windows\System32\WinSetupUI.dll
2015-05-09 03:26:30 12288 ----a-w- C:\Windows\System32\wu.upgrade.ps.dll
2015-05-09 03:26:27 36864 ----a-w- C:\Windows\System32\wuapp.exe
2015-05-09 03:14:46 92672 ----a-w- C:\Windows\SysWow64\wudriver.dll
2015-05-09 03:14:46 173056 ----a-w- C:\Windows\SysWow64\wuwebv.dll
2015-05-09 03:13:32 33792 ----a-w- C:\Windows\SysWow64\wuapp.exe
2015-04-29 18:21:50 5120 ----a-w- C:\Windows\System32\msdxm.ocx
2015-04-29 18:21:50 5120 ----a-w- C:\Windows\System32\dxmasf.dll
2015-04-29 18:21:46 9728 ----a-w- C:\Windows\System32\spwmp.dll
2015-04-29 18:19:43 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2015-04-29 18:07:12 4096 ----a-w- C:\Windows\SysWow64\msdxm.ocx
2015-04-29 18:07:12 4096 ----a-w- C:\Windows\SysWow64\dxmasf.dll
2015-04-29 18:07:07 8192 ----a-w- C:\Windows\SysWow64\spwmp.dll
2015-04-29 18:05:19 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2015-04-27 19:23:45 229376 ----a-w- C:\Windows\System32\wintrust.dll
2015-04-27 19:23:13 188416 ----a-w- C:\Windows\System32\cryptsvc.dll
2015-04-27 19:23:13 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2015-04-27 19:05:58 179200 ----a-w- C:\Windows\SysWow64\wintrust.dll
2015-04-27 19:04:37 143872 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2015-04-27 19:04:37 1174528 ----a-w- C:\Windows\SysWow64\crypt32.dll
2015-04-27 19:04:37 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2015-04-24 18:17:26 633856 ----a-w- C:\Windows\System32\comctl32.dll
.
============= FINISH: 14:17:16.38 ===============
I really don't think I have malware; however, from my thread some glitches after restored win7 http://www.techsupportforum.com/forums/f217/some-glitches-after-restored-win7-1014026.html spunk.funk thinks it may be malware.
Right now the biggest problem is with FF, making the tabs the same when I try to open a new one or change one, clicking on links in email or forum doesn't work and loss of icon on taskbar in general account only. I've uninstalled and reinstalled FF 4 times since the reinstall of the OS (the first one I had a BSOD in the middle of updating windows and had many, many problems, so did a full reinstall - and ran anti-malware programs both before and after the reinstalls (MSSE, Malwarebytes, and ESET online scanner) and none found any problems. I didn't load the 3 PUPs windows updates when updating windows, although before the reinstall and before I knew the windows7 updates were PUP's for win10 I had them downloaded and installed.
One other program isn't showing up on in my general account. Also, a few desktop icons I can't seem to get rid of that have to do with my cannon printer.
Since the BSOD in the first try to reinstall had to do with hardware, I've loaded the drivers for my other USB hardware but removed them, so only my mouse and keyboard are plugged in.
I have the factory disc (which I used for the reinstalls) and the windows disc for my computer.
Thank you
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17840
Run by 93 at 14:16:49 on 2015-07-05
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.7104.5233 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: Microsoft Security Essentials *Enabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files\Microsoft LifeCam\MSCamS64.exe
C:\Windows\system32\svchost.exe -k imgsvc
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Users\93\AppData\Local\FluxSoftware\Flux\flux.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\splwow64.exe
C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\PrintIsolationHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.pugetsystems.com/welcome.php?oid=117561
mWinlogon: Userinit = userinit.exe
BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
EB: Canon Easy-WebPrint EX: {21347690-EC41-4F9A-8887-1F4AEE672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
uRun: [f.lux] "C:\Users\93\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
uRun: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
uRun: [WinPatrol] C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe -expressboot
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
mRun: [CanonQuickMenu] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.0.1 205.171.3.25
TCP: Interfaces\{649FED28-E5CC-41A3-A3E0-B1852BA10A06} : DHCPNameServer = 192.168.0.1 205.171.3.25
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [IAStorIcon] "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
x64-Run: [IgfxTray] "C:\Windows\System32\igfxtray.exe"
x64-Run: [HotKeysCmds] "C:\Windows\System32\hkcmd.exe"
x64-Run: [Persistence] "C:\Windows\System32\igfxpers.exe"
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\syowip1a.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.pugetsystems.com/welcome.php?oid=117561
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll
FF - plugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrlui.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_194.dll
.
============= SERVICES / DRIVERS ===============
.
R0 iaStorA;iaStorA;C:\Windows\System32\drivers\iaStorA.sys [2013-1-31 652784]
R0 iaStorF;iaStorF;C:\Windows\System32\drivers\iaStorF.sys [2013-1-31 28656]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2013-11-21 20464]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2015-3-4 280376]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-5-29 77128]
R2 asComSvc;ASUS Com Service;C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe [2013-11-21 927232]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-4-11 103608]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-4-11 124088]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-1-31 15344]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-2-13 731648]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-11-21 169432]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-6-18 124568]
R3 e1dexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver D;C:\Windows\System32\drivers\e1d62x64.sys [2013-11-21 496400]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-11-21 452088]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2013-11-21 368112]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2013-11-21 786416]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-11-21 25816]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-4-30 366544]
R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2015-6-23 190088]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-7-4 1133880]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-6-3 327296]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2015-7-4 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-2-13 820184]
S3 MBAMWebAccessControl;MBAMWebAccessControl;C:\Windows\System32\drivers\mwac.sys [2015-7-4 63704]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;C:\Windows\System32\drivers\nx6000.sys [2010-5-20 36720]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-11-21 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2015-7-5 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-11-21 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-11-21 1255736]
.
=============== Created Last 30 ================
.
2015-07-05 21:05:39 75888 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8CDF2AE-9704-4AC7-A361-33BB8383E557}\offreg.936.dll
2015-07-05 14:58:35 -------- d-----r- C:\Sandbox
2015-07-05 14:53:41 12221144 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8CDF2AE-9704-4AC7-A361-33BB8383E557}\mpengine.dll
2015-07-05 13:55:51 12221144 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-07-05 13:11:54 -------- d-----w- C:\Program Files (x86)\ESET
2015-07-05 13:08:09 -------- d-----w- C:\Windows\pss
2015-07-05 12:53:06 -------- d-----w- C:\Users\93\AppData\Roaming\WinPatrol
2015-07-05 12:53:01 -------- d-----w- C:\ProgramData\InstallMate
2015-07-05 12:53:01 -------- d-----w- C:\Program Files (x86)\Ruiware
2015-07-05 12:47:28 -------- d-----w- C:\Program Files\iTunes
2015-07-05 12:47:28 -------- d-----w- C:\Program Files\iPod
2015-07-05 12:47:28 -------- d-----w- C:\Program Files (x86)\iTunes
2015-07-05 12:33:13 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin5.dll
2015-07-05 12:33:13 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin4.dll
2015-07-05 12:33:13 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin3.dll
2015-07-05 12:33:13 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin2.dll
2015-07-05 12:33:13 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin.dll
2015-07-05 12:20:59 -------- d-----w- C:\Users\93\AppData\Local\Macromedia
2015-07-05 12:19:17 -------- d-----w- C:\Users\93\AppData\Roaming\Canneverbe Limited
2015-07-05 12:09:38 778416 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2015-07-05 12:09:38 142512 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-07-05 12:01:58 336896 ----a-w- C:\Windows\SysWow64\CNC_C9L.dll
2015-07-05 12:01:58 15872 ----a-w- C:\Windows\SysWow64\CNHMCA.dll
2015-07-05 11:59:58 -------- d-----w- C:\ProgramData\CanonIJWSpt
2015-07-05 11:56:22 -------- d-----w- C:\Program Files\Canon
2015-07-05 11:55:41 30208 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPDC9.DLL
2015-07-05 11:55:41 102912 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPPC9.DLL
2015-07-05 11:55:39 369664 ----a-w- C:\Windows\System32\CNC_C9L.dll
2015-07-05 11:55:39 316928 ----a-w- C:\Windows\System32\CNC_C9C.dll
2015-07-05 11:55:39 17920 ----a-w- C:\Windows\System32\CNHMCA6.dll
2015-07-05 11:55:39 105984 ----a-w- C:\Windows\System32\CNC_C9I.dll
2015-07-05 11:55:35 406016 ----a-w- C:\Windows\System32\CNMLMC9.DLL
2015-07-05 11:30:34 -------- d-----w- C:\Users\93\AppData\Roaming\Canon_Inc_IC
2015-07-05 11:30:00 -------- d-----w- C:\Program Files (x86)\Canon
2015-07-05 11:29:57 -------- d-----w- C:\Program Files (x86)\Common Files\Canon_Inc_IC
2015-07-05 11:28:38 -------- d-----w- C:\ProgramData\Canon_Inc_IC
2015-07-05 11:23:42 -------- d-----w- C:\Temp
2015-07-05 08:46:41 6584320 ----a-w- C:\Windows\System32\mstscax.dll
2015-07-05 08:45:58 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2015-07-05 08:45:58 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2015-07-05 08:45:57 3179520 ----a-w- C:\Windows\System32\rdpcorets.dll
2015-07-05 08:45:57 243200 ----a-w- C:\Windows\System32\rdpudd.dll
2015-07-05 08:45:57 16384 ----a-w- C:\Windows\System32\RdpGroupPolicyExtension.dll
2015-07-05 08:45:42 460800 ----a-w- C:\Windows\System32\certcli.dll
2015-07-05 08:45:42 342016 ----a-w- C:\Windows\SysWow64\certcli.dll
2015-07-05 08:45:22 1647104 ----a-w- C:\Windows\System32\DWrite.dll
2015-07-05 08:45:22 1250816 ----a-w- C:\Windows\SysWow64\DWrite.dll
2015-07-05 08:45:22 1179136 ----a-w- C:\Windows\System32\FntCache.dll
2015-07-05 08:45:17 683520 ----a-w- C:\Windows\System32\termsrv.dll
2015-07-05 08:43:02 52224 ----a-w- C:\Windows\SysWow64\nlaapi.dll
2015-07-05 08:43:02 303616 ----a-w- C:\Windows\System32\nlasvc.dll
2015-07-05 08:43:02 156672 ----a-w- C:\Windows\SysWow64\ncsi.dll
2015-07-05 08:43:00 335360 ----a-w- C:\Windows\System32\msieftp.dll
2015-07-05 08:43:00 301568 ----a-w- C:\Windows\SysWow64\msieftp.dll
2015-07-05 08:42:58 210432 ----a-w- C:\Windows\System32\profsvc.dll
2015-07-05 08:42:56 484864 ----a-w- C:\Windows\System32\wer.dll
2015-07-05 08:42:56 381440 ----a-w- C:\Windows\SysWow64\wer.dll
2015-07-05 08:42:54 141312 ----a-w- C:\Windows\System32\drivers\mrxdav.sys
2015-07-05 08:27:44 -------- d-s---w- C:\Windows\SysWow64\GWX
2015-07-05 08:27:44 -------- d-s---w- C:\Windows\System32\GWX
2015-07-05 08:27:44 -------- d-----w- C:\Windows\Migration
2015-07-05 08:17:05 2777088 ----a-w- C:\Windows\System32\msmpeg2vdec.dll
2015-07-05 08:17:05 2285056 ----a-w- C:\Windows\SysWow64\msmpeg2vdec.dll
2015-07-05 07:35:58 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2015-07-05 07:35:58 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2015-07-05 07:35:56 504320 ----a-w- C:\Windows\System32\msihnd.dll
2015-07-05 07:35:56 337408 ----a-w- C:\Windows\SysWow64\msihnd.dll
2015-07-05 07:35:56 1941504 ----a-w- C:\Windows\System32\authui.dll
2015-07-05 07:35:56 1805824 ----a-w- C:\Windows\SysWow64\authui.dll
2015-07-05 07:35:56 112064 ----a-w- C:\Windows\System32\consent.exe
2015-07-05 07:35:45 497152 ----a-w- C:\Windows\System32\drivers\afd.sys
2015-07-05 07:35:44 624128 ----a-w- C:\Windows\System32\qedit.dll
2015-07-05 07:35:44 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2015-07-05 07:12:31 -------- d-----w- C:\Program Files\Sandboxie
2015-07-05 07:09:35 -------- d-----w- C:\Users\93\AppData\Local\FluxSoftware
2015-07-05 06:52:17 124112 ----a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2015-07-05 06:52:17 102608 ----a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-07-05 06:39:09 230400 ----a-w- C:\Windows\System32\drivers\portcls.sys
2015-07-05 06:39:09 116736 ----a-w- C:\Windows\System32\drivers\drmk.sys
2015-07-05 06:39:04 99840 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2015-07-05 06:39:04 7808 ----a-w- C:\Windows\System32\drivers\usbd.sys
2015-07-05 06:39:04 53248 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2015-07-05 06:39:04 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2015-07-05 06:39:04 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2015-07-05 06:39:04 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2015-07-05 06:39:04 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2015-07-05 06:38:46 -------- d-----w- C:\Users\93\AppData\Roaming\Contaware
2015-07-05 06:38:46 -------- d-----w- C:\ContaCam
2015-07-05 06:38:39 -------- d-----w- C:\Program Files (x86)\ContaCam
2015-07-05 06:36:02 -------- d-----w- C:\ProgramData\Licenses
2015-07-05 06:36:01 129872 ----a-w- C:\Windows\SysWow64\MSSTDFMT.DLL
2015-07-05 06:35:59 -------- d-----w- C:\Program Files (x86)\SpywareBlaster
2015-07-05 06:28:45 -------- d-----w- C:\Users\93\AppData\Local\Skype
2015-07-05 06:27:01 -------- d-----w- C:\Program Files\Microsoft LifeCam
2015-07-05 06:27:01 -------- d-----w- C:\Program Files (x86)\Microsoft LifeCam
2015-07-05 06:08:24 -------- d-----w- C:\Program Files\Microsoft Mouse and Keyboard Center
2015-07-05 06:03:46 878080 ----a-w- C:\Windows\System32\IMJP10K.DLL
2015-07-05 06:03:46 701440 ----a-w- C:\Windows\SysWow64\IMJP10K.DLL
2015-07-05 06:03:45 3928064 ----a-w- C:\Windows\System32\d2d1.dll
2015-07-05 06:03:45 3419136 ----a-w- C:\Windows\SysWow64\d2d1.dll
2015-07-05 06:03:44 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2015-07-05 06:03:44 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2015-07-05 06:03:44 1882624 ----a-w- C:\Windows\System32\msxml3.dll
2015-07-05 06:03:44 1237504 ----a-w- C:\Windows\SysWow64\msxml3.dll
2015-07-05 06:03:41 985536 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2015-07-05 06:00:13 459336 ----a-w- C:\Windows\System32\drivers\cng.sys
2015-07-05 05:59:21 3206144 ----a-w- C:\Windows\System32\win32k.sys
2015-07-05 05:51:44 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2015-07-05 05:51:44 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2015-07-05 05:51:40 142336 ----a-w- C:\Windows\System32\poqexec.exe
2015-07-05 05:51:40 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2015-07-05 05:49:08 241152 ----a-w- C:\Windows\System32\pku2u.dll
2015-07-05 05:49:08 186880 ----a-w- C:\Windows\SysWow64\pku2u.dll
2015-07-05 05:46:48 828928 ----a-w- C:\Windows\SysWow64\msctf.dll
2015-07-05 05:45:53 72192 ----a-w- C:\Windows\System32\aelupsvc.dll
2015-07-05 05:44:57 1684928 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2015-07-05 05:44:55 406528 ----a-w- C:\Windows\System32\scesrv.dll
2015-07-05 05:44:55 308224 ----a-w- C:\Windows\SysWow64\scesrv.dll
2015-07-05 05:44:53 3241984 ----a-w- C:\Windows\System32\msi.dll
2015-07-05 05:44:53 2363904 ----a-w- C:\Windows\SysWow64\msi.dll
2015-07-05 05:44:35 202752 ----a-w- C:\Windows\System32\scrrun.dll
2015-07-05 05:44:35 168960 ----a-w- C:\Windows\System32\wscript.exe
2015-07-05 05:44:35 163840 ----a-w- C:\Windows\SysWow64\scrrun.dll
2015-07-05 05:44:35 156160 ----a-w- C:\Windows\System32\cscript.exe
2015-07-05 05:44:35 150016 ----a-w- C:\Windows\System32\wshom.ocx
2015-07-05 05:44:35 141824 ----a-w- C:\Windows\SysWow64\wscript.exe
2015-07-05 05:44:35 126976 ----a-w- C:\Windows\SysWow64\cscript.exe
2015-07-05 05:44:35 121856 ----a-w- C:\Windows\SysWow64\wshom.ocx
2015-07-05 05:43:02 465920 ----a-w- C:\Windows\System32\WMPhoto.dll
2015-07-05 05:43:02 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll
2015-07-05 05:43:01 664064 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2015-07-05 05:43:01 1216000 ----a-w- C:\Windows\System32\rpcrt4.dll
2015-07-05 05:21:55 -------- d-----w- C:\Windows\TempF557102D-152E-62A5-F388-7DC92BE60855-Signatures
2015-07-05 05:15:25 -------- d-----r- C:\Program Files (x86)\Skype
2015-07-05 05:11:12 99480 ----a-w- C:\Windows\SysWow64\infocardapi.dll
2015-07-05 05:11:11 8856 ----a-w- C:\Windows\SysWow64\icardres.dll
2015-07-05 05:11:11 8856 ----a-w- C:\Windows\System32\icardres.dll
2015-07-05 05:11:11 619672 ----a-w- C:\Windows\SysWow64\icardagt.exe
2015-07-05 05:11:11 171160 ----a-w- C:\Windows\System32\infocardapi.dll
2015-07-05 05:11:11 1389208 ----a-w- C:\Windows\System32\icardagt.exe
2015-07-05 05:10:59 35480 ----a-w- C:\Windows\SysWow64\TsWpfWrp.exe
2015-07-05 05:10:59 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe
2015-07-05 04:50:35 1480192 ----a-w- C:\Windows\System32\crypt32.dll
2015-07-05 04:30:30 493504 ----a-w- C:\Windows\System32\mcupdate_GenuineIntel.dll
2015-07-05 04:26:21 81560 ----a-w- C:\Windows\SysWow64\mscories.dll
2015-07-05 04:26:21 73880 ----a-w- C:\Windows\System32\mscories.dll
2015-07-05 04:26:21 1943696 ----a-w- C:\Windows\System32\dfshim.dll
2015-07-05 04:26:21 156824 ----a-w- C:\Windows\SysWow64\mscorier.dll
2015-07-05 04:26:21 156312 ----a-w- C:\Windows\System32\mscorier.dll
2015-07-05 04:26:21 1131664 ----a-w- C:\Windows\SysWow64\dfshim.dll
2015-07-05 04:24:57 82944 ----a-w- C:\Windows\System32\dwmapi.dll
2015-07-05 04:24:57 67584 ----a-w- C:\Windows\SysWow64\dwmapi.dll
2015-07-05 04:24:57 1632768 ----a-w- C:\Windows\System32\dwmcore.dll
2015-07-05 04:24:57 1372160 ----a-w- C:\Windows\SysWow64\dwmcore.dll
2015-07-05 04:18:08 965000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2015-07-05 04:18:08 1190000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A3917C19-9C92-466A-9D63-AE4A0B6E4827}\gapaengine.dll
2015-07-05 04:09:59 -------- d-----w- C:\Windows\PCHEALTH
2015-07-05 04:06:53 -------- d-----w- C:\Program Files (x86)\Microsoft Analysis Services
2015-07-05 04:06:41 -------- d-----w- C:\Users\93\AppData\Local\Microsoft Help
2015-06-17 07:23:50 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2015-06-17 07:23:50 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
.
==================== Find3M ====================
.
2015-07-05 10:08:23 300704 ------w- C:\Windows\System32\MpSigStub.exe
2015-07-05 05:54:57 113880 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2015-06-18 15:41:56 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys
2015-06-18 15:41:44 109272 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2015-06-18 15:41:40 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2015-05-25 18:24:00 5569984 ----a-w- C:\Windows\System32\ntoskrnl.exe
2015-05-25 18:23:59 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2015-05-25 18:23:59 155584 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2015-05-25 18:21:21 1728960 ----a-w- C:\Windows\System32\ntdll.dll
2015-05-25 18:18:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2015-05-25 18:18:56 22016 ----a-w- C:\Windows\System32\credssp.dll
2015-05-25 18:18:54 879104 ----a-w- C:\Windows\System32\advapi32.dll
2015-05-25 18:18:45 47104 ----a-w- C:\Windows\System32\typeperf.exe
2015-05-25 18:18:45 404992 ----a-w- C:\Windows\System32\tracerpt.exe
2015-05-25 18:18:39 112640 ----a-w- C:\Windows\System32\smss.exe
2015-05-25 18:18:32 296960 ----a-w- C:\Windows\System32\rstrui.exe
2015-05-25 18:18:30 43008 ----a-w- C:\Windows\System32\relog.exe
2015-05-25 18:18:19 31232 ----a-w- C:\Windows\System32\lsass.exe
2015-05-25 18:18:19 104448 ----a-w- C:\Windows\System32\logman.exe
2015-05-25 18:18:11 19456 ----a-w- C:\Windows\System32\diskperf.exe
2015-05-25 18:18:08 338432 ----a-w- C:\Windows\System32\conhost.exe
2015-05-25 18:18:04 64000 ----a-w- C:\Windows\System32\auditpol.exe
2015-05-25 18:14:26 60416 ----a-w- C:\Windows\System32\msobjs.dll
2015-05-25 18:14:04 146432 ----a-w- C:\Windows\System32\msaudite.dll
2015-05-25 18:07:34 3989440 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2015-05-25 18:07:34 3934144 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2015-05-25 18:04:08 1310744 ----a-w- C:\Windows\SysWow64\ntdll.dll
2015-05-25 18:00:44 40448 ----a-w- C:\Windows\SysWow64\typeperf.exe
2015-05-25 18:00:40 364544 ----a-w- C:\Windows\SysWow64\tracerpt.exe
2015-05-25 18:00:28 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2015-05-25 18:00:25 37888 ----a-w- C:\Windows\SysWow64\relog.exe
2015-05-25 18:00:17 82944 ----a-w- C:\Windows\SysWow64\logman.exe
2015-05-25 18:00:09 17408 ----a-w- C:\Windows\SysWow64\diskperf.exe
2015-05-25 18:00:04 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2015-05-25 17:59:52 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2015-05-25 17:59:52 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2015-05-25 17:59:51 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2015-05-25 17:57:31 60416 ----a-w- C:\Windows\SysWow64\msobjs.dll
2015-05-25 17:57:15 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll
2015-05-25 17:00:56 36864 ----a-w- C:\Windows\System32\UtcResources.dll
2015-05-25 16:50:38 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2015-05-25 16:50:36 2048 ----a-w- C:\Windows\SysWow64\user.exe
2015-05-25 16:48:25 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2015-05-25 16:48:25 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-25 16:48:25 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-25 16:48:25 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2015-05-23 03:28:17 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2015-05-23 03:15:54 503808 ----a-w- C:\Windows\SysWow64\vbscript.dll
2015-05-23 03:15:40 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2015-05-23 03:15:02 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2015-05-23 03:14:51 341504 ----a-w- C:\Windows\SysWow64\html.iec
2015-05-23 03:13:48 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2015-05-23 03:05:21 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2015-05-23 03:04:50 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2015-05-23 02:52:43 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2015-05-23 02:47:31 4305920 ----a-w- C:\Windows\SysWow64\jscript9.dll
2015-05-23 02:37:45 2052608 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2015-05-23 02:37:25 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2015-05-23 02:20:35 1950720 ----a-w- C:\Windows\SysWow64\wininet.dll
2015-05-22 19:16:55 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2015-05-22 19:16:44 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2015-05-22 19:01:42 66560 ----a-w- C:\Windows\System32\iesetup.dll
2015-05-22 19:00:54 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2015-05-22 19:00:47 417792 ----a-w- C:\Windows\System32\html.iec
2015-05-22 19:00:25 584192 ----a-w- C:\Windows\System32\vbscript.dll
2015-05-22 18:59:27 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2015-05-22 18:52:21 6026240 ----a-w- C:\Windows\System32\jscript9.dll
2015-05-22 18:47:49 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2015-05-22 18:47:34 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
2015-05-22 18:47:03 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2015-05-22 18:40:17 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2015-05-22 18:29:31 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2015-05-22 18:05:28 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2015-05-22 18:05:06 2125824 ----a-w- C:\Windows\System32\inetcpl.cpl
2015-05-22 17:50:20 2426880 ----a-w- C:\Windows\System32\wininet.dll
2015-05-09 03:27:37 98304 ----a-w- C:\Windows\System32\wudriver.dll
2015-05-09 03:27:37 3147776 ----a-w- C:\Windows\System32\wucltux.dll
2015-05-09 03:27:37 191488 ----a-w- C:\Windows\System32\wuwebv.dll
2015-05-09 03:26:38 87040 ----a-w- C:\Windows\System32\WinSetupUI.dll
2015-05-09 03:26:30 12288 ----a-w- C:\Windows\System32\wu.upgrade.ps.dll
2015-05-09 03:26:27 36864 ----a-w- C:\Windows\System32\wuapp.exe
2015-05-09 03:14:46 92672 ----a-w- C:\Windows\SysWow64\wudriver.dll
2015-05-09 03:14:46 173056 ----a-w- C:\Windows\SysWow64\wuwebv.dll
2015-05-09 03:13:32 33792 ----a-w- C:\Windows\SysWow64\wuapp.exe
2015-04-29 18:21:50 5120 ----a-w- C:\Windows\System32\msdxm.ocx
2015-04-29 18:21:50 5120 ----a-w- C:\Windows\System32\dxmasf.dll
2015-04-29 18:21:46 9728 ----a-w- C:\Windows\System32\spwmp.dll
2015-04-29 18:19:43 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2015-04-29 18:07:12 4096 ----a-w- C:\Windows\SysWow64\msdxm.ocx
2015-04-29 18:07:12 4096 ----a-w- C:\Windows\SysWow64\dxmasf.dll
2015-04-29 18:07:07 8192 ----a-w- C:\Windows\SysWow64\spwmp.dll
2015-04-29 18:05:19 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2015-04-27 19:23:45 229376 ----a-w- C:\Windows\System32\wintrust.dll
2015-04-27 19:23:13 188416 ----a-w- C:\Windows\System32\cryptsvc.dll
2015-04-27 19:23:13 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2015-04-27 19:05:58 179200 ----a-w- C:\Windows\SysWow64\wintrust.dll
2015-04-27 19:04:37 143872 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2015-04-27 19:04:37 1174528 ----a-w- C:\Windows\SysWow64\crypt32.dll
2015-04-27 19:04:37 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2015-04-24 18:17:26 633856 ----a-w- C:\Windows\System32\comctl32.dll
.
============= FINISH: 14:17:16.38 ===============