  1. I recently uninstalled a free AV program (ClamAV) that was misbehaving on my old Win 7 laptop. (For the record, my new — primary — laptop runs Win 10.) Am now running Windows Defender and Malwarebytes Premium on both computers. Is there any reason to supplement these two with additional AV software, or am I good to go? My browsing habits, for what it's worth, are pretty dull! Thanks.
  2. Hello, today, I wanted to install a game, long story short, it came with a virus, it came in a zip file, I ran the executable and it installed me 2 programs: "Garbage Cleaner" and a disk cleaning program, I already knew it was a virus in that moment, I deleted it, checked the task manager, many processes with random names were open, I tried to delete as much as posible, but there were 2 files I couldn't, I ran the Windows defender scan (back then I didn't have malwarebytes) and it said it didn't detect any threats besides the exceptions (I didn't add anything to the exceptions), so I checked the exceptions and found many programs that I couldn't remove from the exceptions: https://i.gyazo.com/d941cb222177cd751fca0d7db7938229.mp4. I tried editing the registry, but it didn't let me remove the files from the Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths directory, so I tried running multiple scans with many antivirus programs (avast, emsisoft, kaspersky, etc) and the only one that detected something was Malwarebytes, I quarantined the items and deleted them, but the virus is still there, the exceptions are still there, my PC is running really slow, heating without doing anything and my Chrome browser shows third-party ads when I search for something in Google (they are not chrome ads). Here's the file that contained the virus: https://landtoumodo.ml/89b848616374564be015cad52bb0bc25GyP/gY2yQ6H39ALLsTgmZjVSID7kb/5Du6BEj7F3dILfLgc=/435EERoU/setupdf.zip I would really appreciate if you could help me with this issue.
  3. Hi, I have a use case where I scan external drives with Malwarebytes and Windows Defender before attaching them to the network using a defence in depth approach. Prior to the latest updates (Windows and Malwarebytes), when scanning the drives, the file count was the same. Since the latest updates applied last week, the file count is different by approximately 25 files. Could you provide guidance regarding this disparity please? Thanks Dave
  4. Hi; we just installed the latest MBAM 4.1.0. We recently made the move to windows 10 ver. 1903. We are using the windows defender. With you newest version, can we now turn on your realtime protection and run defender at the same time? Thanks!
  5. A few days ago I restarted my computer before a long time without re-starting it (like 1 week with the pc on) and I noticed that "Explorer.exe" was requesting to initialize, but the real explorer.exe task was already running... I said no but then I checked the directory of the file and the system said that the file was on %windir%/resources/themes, well going into folder to check if the file exists I noticed that theres nothing more than aero themes in this folder. So did a scan in the folder using malwarebytes and it recognized svchost.exe malware and explorer.exe, before adding they do quarentine I wanted to check why the files didnt apeared, so I enabled "show hidden folders" in explorer (the real one, from microsoft) and it changed nothing, well, so I tried to open the archive by going with %windir%/resources/themes/explorer.exe in the explorer path, it worked, but I still uncapable of seeing this file... So I started CMD as admin and did " cd " to %windir%/resources/themes and did " dir " inside the folder, as I expected the dir shows the same as explorer, but appeared 2 new items that the was named as " . " and " .. " I deleted both sucessfully. Searching for this in internet I found that there's an other way to hide files in windows, that was adding them to" important system files or protected system files" list, and following the instructions to disable this privilege, I finally could see the archives, well, I added them to the quarentine list and continued using my computer since yesterday that I realized that everytime malwarebytes send two addwares to quarentine (I left the results of scan in the post as "Annoying addware.txt") they come back right after I finish the task... When trying to solve these issues I realized many things... 1- I cant use commands as DISM, sfc /scannow, windows update, windows defender( I will let write happens when i try to use them bellow this part) , net start/stop wuauserv (the wuauserv service doesnt even exists in registry, I didnt checked windows defender one...) 2- there was a folder called QEMU hidden with the "important system files" method, I deleted all content Inside and then deleted the folder after taking out the folder privilegies 3- Theres two "program" files in "Inicialize" section of task manager wich I cant go to proprieties ( I dropped the print down on anexed files named as "Program" unknow files) When I try to use with /checkhealth everything go fine, but when I try to use dism with /restorehealth it stops at 87,5% and gives an error 1060 messages saying " the specified service does not exist as an installed service " ( I left the DISM log file right bellow named as DISM.txt ) When I try to use sfc /scannow it says that cannot fix all issues When i try to use windows update it says that my organizations disable windows updates ( ? ) When I try windows defender it just goes black screen on the window Well, it would be great if someone could help me, I dont really want to re-install windows... I would take a month to setup my pc again Also, I run Windows 10 Pro 64bits, version 1809... dism.log Annoying Adware.txt Rkill.txt FRST.txt Addition.txt
  6. Hello, Could you help me with my problem ? I installed a program that turned out to be a malware, installed several bad programs on my computer. I could delete them all with Malwarebytes but it changed something in the IT access and now my windows defender "virus & thread protection" and "protection updates" won't be enabled now because : Your IT administrator has limited access to some area of this app, and the item you tried to access is not available. Contact IT helpdesk for more information. It is my personal computer and it is not normal that there is these restrictions, I'm pretty sure it is because of this bad program. I've tried changing the registry for windows defender but won't work still. Would do have a solution please ?? Thanks a lot
  7. Hi - is it possible to run Windows Defender alongside Malwarebytes? Since I installed Malwarebytes, Defender will not start.
  8. Hello. I was trying to install Malwarebytes but it seems whatever I've caught is blocking me from installing it since I get a message that the Admin has blocked it, but I am the only Admin. I also noticed a new process in my Task Manager that keeps popping up every one in a while even when I delete it, and a file in my Windows folder that also keep re-appearing when I delete it in safemode. My browser (firefox) is now riddled with ads that don't get blocked by uBlock Origin, and I notice that when I click on links sometimes they get parsed through some website. I also know I am infected because Windows Defender went ballistic with trying to block and quarantine files before finally collapsing, and now it won't turn back on again. Any recommendations?
  9. I have always had Malwarebytes and Windows Defender running together with no problems. After the Fall Update, Defender keeps shutting down and will not let me turn it back on because there is already another antivirus program monitoring the system (I assume it is Malwarebytes). I uninstalled MWB and reinstalled it and it worked for a while, then shut down Defender again. I tried looking in Settings to allow both to run but cannot find anything relevant. Any suggestions would be greatly appreciated.
  10. Windows defender has found a Trojan Jupitr A exploit on my hard drive twice and quarantined and deleted. I only use Defender for occasional scans but have MBAM working for full-time protection. Why won't it pick this up and block it before it gets on the system? Thanks for your feedback
  11. Hello! I stumbled onto your forum and I am now concerned. My computer is being strange, It rebooted itself without a timer (after windows updates, etc.). I also have noticed that Avira is not turned on, and I can't seem to turn it back on, it keeps giving me notifications that I need to update it. Once I do, it says that Windows Defender and Avira are not running. Malwarebytes has not detected anything after Trojan-Dropper rtop_svc.exe. Attached are my log files. Thank you so so much! aswMBR.txt Attach.rar DDS.txt
  12. Two days ago I installed Anti Exploit Premium ver on a PC running Windows 10 Home, 64-bit 10.0, build 10586. I run Windows Defender on this computer, along with Malwarebytes Anti-Malware Home Premium ver This morning Windows Defender is reporting that its Real-Time Protection is turned off, and that I should turn it on. Did the install Anti Exploit Premium turn off Windows Defender Real-Time Protection? And I guess my bigger question is, what setting should I be using with these three applications? For example, should Windows Defender Real-Time Protection be turned off when Anti Exploit Premium is also running on a PC? Any suggestions would be appreciated.
  13. Hi, I'm using Windows 7 Professional. I was prompted to Turn On the Real-Time Protection for the computer. But when I turn it on, I get this error message, "The specific service does not exist as an installed service. (Error Code: 0x80070424). This is both for Windows Security Essentials and Defender. I hope you can help me. This is my HijackThis log. hijackthis.log
  14. I know malwarebytes does not protect against virus, so I want to deploy Windows Defender, but can't, as it generates error and warns in action center that it would be competing with current malware product if it was to be turned on, which can't be forced anyway, So, what do I do? What settings can I change to be sure I have both aspects of security covered? It starts with Windows and I checked of Self-protection mode, so mwbytes doesn't quarantine windows files . . . thinking starting with windows is real-time setting? Not clear, option language!
  15. Hello -- Does "ms defender" try to do the same as malware-bytes? Also, with the free version, the "quick scan to grayed out -- is this by design? Thanks
  16. Okay so yesterday I unknowingly installed a virus onto my computer... This virus wouldn't allow me to delete it or anything... If I tried it would say "explorer.exe crashed" or something like that... I ended up using a program called Unlocker to delete it and then I scanned my computer twice with Malware Bytes, AVG, and Trend Micro Housecall. I am fairly confident the virus is removed now but what it left me with is very frustrating =( ... Now that the virus is gone I am left with some very concerning problems: 1. My Windows Firewall cannot be enabled, if I try to access it my PC says: "There was an error opening the Windows Firewall with Advanced Security snap-in". "The Windows Firewall with Advanced Security snap-in failed to load. Restart the Windows Firewall service on the computer that you are managing. Error code: 0x6D9". If I go to services.msc the "Windows Firewall" service isn't even listed on the page. 2. My Windows Defender cannot be started/found. 3. There is a problem in Windows Action Center. Now there may be other issues but I am unsure if there is... If someone can please help me out with this it would be very appreciated! If you would like a link to the download page of the virus I could give it to you as it is a RAR file but it will give you a VIRUS so.... I don't think that is such a great idea... Oh and I heard about a program called Sandboxie which I guess I will be using from now on if I ever install anything...
  Hello, and thank you in advance for your time. Title tells the shortest version, here's a slightly longer one. My father-in-law gave me an old game of his yesterday, which was apparently attached to his steam account. I attempted to get a key for it, using a keygen that at the time appeared not to work. Then I notice today that facebook, anything google, windows defender, and anything malware removal or just plain search related kicks back revoked security certificate in chrome, or popups in explorer. I fully realize *I* screwed this up, but hopefully I can get help fixing this, and call it a lesson learned? The dds and attach copy pastes follow. dds : DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 10.0.9200.16576 BrowserJavaVersion: 10.21.2 Run by James at 15:44:05 on 2013-06-06 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8109.5908 [GMT -5:00] . SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe C:\Program Files\GIGABYTE\SMART6\Recovery\RPMDaemon.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Microsoft IntelliType Pro\itype.exe C:\Program Files (x86)\Steam\Steam.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files\iPod\bin\iPodService.exe C:\Users\James\AppData\Local\Google\Update\\GoogleCrashHandler.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Users\James\AppData\Local\Google\Update\\GoogleCrashHandler64.exe C:\Program Files (x86)\Common Files\Steam\SteamService.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\AlarmClock.exe C:\Windows\system32\taskhost.exe C:\Windows\SysWOW64\PnkBstrA.exe C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe C:\Users\James\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\James\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\James\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\James\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\James\AppData\Local\Google\Chrome\Application\chrome.exe "C:\Windows\SysWOW64\svchost.exe" -k LocalServiceDns C:\Users\James\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.msn.com uDefault_Page_URL = hxxp://www.msn.com mWinlogon: Userinit = userinit.exe BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned> BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll uRun: [Google Update] "C:\Users\James\AppData\Local\Google\Update\GoogleUpdate.exe" /c uRun: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe uRun: [steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent uRun: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" uRun: [Amazon Cloud Drive] C:\Users\James\AppData\Local\Amazon\Cloud Drive\AmazonCloudDrive.exe mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot mRun: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll LSP: mswsock.dll TCP: NameServer = TCP: Interfaces\{D61E13FA-C188-4A35-A59A-E178DE70E486} : DHCPNameServer = Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll SSODL: WebCheck - <orphaned> x64-BHO: GBHO.BHO: {45d30484-7ded-43d9-957a-d2fd1f046511} - x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll x64-TB: Smart Recovery 2: {1d09c093-f71e-43c3-b948-19316cbd695e} - x64-Run: [igfxTray] C:\Windows\System32\igfxtray.exe x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s x64-Run: [intelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" x64-Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe" x64-RunOnce: [RPMKickstart] C:\Program Files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned> x64-Notify: igfxcui - igfxdev.dll x64-SSODL: WebCheck - <orphaned> . ============= SERVICES / DRIVERS =============== . R1 AppleCharger;AppleCharger;C:\Windows\System32\drivers\AppleCharger.sys [2011-10-15 21104] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-12-19 240640] R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624] R2 DeviceMonitorService;DeviceMonitorService;C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe [2011-6-16 87368] R2 LVPrcS64;Process Monitor;C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe [2009-10-7 191000] R2 MotoHelper;MotoHelper Service;C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [2011-12-6 214896] R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-11-29 38608] R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776] R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-5-14 3289208] R2 Smart TimeLock;Smart TimeLock Service;C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe [2011-10-15 114688] R2 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2012-8-28 92632] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-11-6 96256] R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\System32\drivers\EtronHub3.sys [2011-3-7 40832] R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\System32\drivers\EtronXHCI.sys [2011-3-7 65280] R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-10-15 317440] R3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\System32\drivers\LVPr2M64.sys [2009-10-7 30232] R3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\System32\drivers\lvrs64.sys [2009-10-7 327704] R3 LVUVC64;Logitech QuickCam E3500(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2009-10-7 6379288] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-10-15 413800] R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2011-10-1 764264] R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2011-10-1 268648] R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2011-10-1 25960] R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2011-10-1 22376] R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496] S1 epcpmzca;epcpmzca;C:\Windows\System32\drivers\epcpmzca.sys [2013-6-5 49872] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-1-8 161536] S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?] S3 GVTDrv64;GVTDrv64;C:\Windows\GVTDrv64.sys [2011-10-15 30528] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-8-2 51712] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-3-1 1255736] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120] . =============== Created Last 30 ================ . 2013-06-06 17:18:46 2250024 ----a-w- C:\Windows\SysWow64\pbsvc.exe 2013-06-05 23:25:53 178800 ----a-w- C:\Windows\SysWow64\CmdLineExt_x64.dll 2013-06-05 23:22:17 -------- dc-h--w- C:\ProgramData\{0691F710-1ECA-4B5A-9727-25554F1BFDC6} 2013-06-05 23:08:40 2628 ----a-w- C:\Windows\SysWow64\ealregsnapshot1.reg 2013-06-05 22:02:38 49872 ----a-w- C:\Windows\System32\drivers\epcpmzca.sys 2013-06-05 18:50:14 9460464 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6C054FF2-31E3-4F43-A308-0128534D24B7}\mpengine.dll 2013-05-14 21:40:00 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2013-05-14 21:40:00 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys 2013-05-14 21:40:00 144384 ----a-w- C:\Windows\System32\cdd.dll 2013-05-14 21:39:53 1930752 ----a-w- C:\Windows\System32\authui.dll 2013-05-14 21:39:52 70144 ----a-w- C:\Windows\System32\appinfo.dll 2013-05-14 21:39:52 1796096 ----a-w- C:\Windows\SysWow64\authui.dll 2013-05-14 21:39:52 111448 ----a-w- C:\Windows\System32\consent.exe 2013-05-14 21:39:46 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll 2013-05-14 21:39:46 230400 ----a-w- C:\Windows\System32\wwansvc.dll 2013-05-14 21:39:45 3153920 ----a-w- C:\Windows\System32\win32k.sys . ==================== Find3M ==================== . 2013-06-06 17:18:54 107832 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe 2013-06-05 22:08:41 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-05 22:08:41 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-06-05 18:46:15 25640 ----a-w- C:\Windows\gdrv.sys 2013-05-22 04:23:57 291088 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr 2013-05-22 04:23:57 291088 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0 2013-05-02 07:06:08 278800 ------w- C:\Windows\System32\MpSigStub.exe 2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll 2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll 2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll 2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll 2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll 2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll 2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys 2013-04-05 06:52:14 2242048 ----a-w- C:\Windows\System32\wininet.dll 2013-04-05 06:50:36 3958784 ----a-w- C:\Windows\System32\jscript9.dll 2013-04-05 06:50:31 67072 ----a-w- C:\Windows\System32\iesetup.dll 2013-04-05 06:50:31 136704 ----a-w- C:\Windows\System32\iesysprep.dll 2013-04-05 05:28:24 1767424 ----a-w- C:\Windows\SysWow64\wininet.dll 2013-04-05 05:26:26 2877440 ----a-w- C:\Windows\SysWow64\jscript9.dll 2013-04-05 05:26:21 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll 2013-04-05 05:26:21 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll 2013-04-05 04:43:00 2706432 ----a-w- C:\Windows\System32\mshtml.tlb 2013-04-05 04:29:45 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb 2013-04-05 03:51:11 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe 2013-04-05 03:38:25 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe 2013-04-04 10:35:05 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2013-03-19 06:04:06 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe 2013-03-19 05:46:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll 2013-03-19 05:04:13 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2013-03-19 05:04:10 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe 2013-03-19 04:47:50 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll 2013-03-19 03:06:33 112640 ----a-w- C:\Windows\System32\smss.exe 2013-03-10 07:02:23 861088 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll 2013-03-10 07:02:23 782240 ----a-w- C:\Windows\SysWow64\deployJava1.dll . ============= FINISH: 15:45:46.12 =============== attach : . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 11/3/2011 12:33:46 AM System Uptime: 6/6/2013 1:39:37 AM (14 hours ago) . Motherboard: Gigabyte Technology Co., Ltd. | | Z68AP-D3 Processor: Intel® Core™ i7-2600K CPU @ 3.40GHz | Socket 1155 | 3701/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 931 GiB total, 404.165 GiB free. D: is CDROM (UDF) . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP199: 5/21/2013 8:31:43 AM - Windows Update RP200: 6/5/2013 1:49:59 PM - Windows Update RP201: 6/5/2013 4:08:22 PM - Installed DirectX RP203: 6/5/2013 5:02:32 PM - Windows Defender Checkpoint RP204: 6/5/2013 6:08:28 PM - Configured EA Download Manager RP205: 6/6/2013 12:14:03 PM - Installed Far Cry 2 RP206: 6/6/2013 12:19:19 PM - Installed DirectX . ==== Installed Programs ====================== . @BIOS Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader X (10.1.7) Amazon Cloud Drive AMD Accelerated Video Transcoding AMD APP SDK Runtime AMD Catalyst Install Manager AMD Drag and Drop Transcoding AMD Media Foundation Decoders Apple Application Support Apple Mobile Device Support Apple Software Update Audiosurf Battlefield 3™ Battlelog Web Plugins Bonjour Borderlands Catalyst Control Center Catalyst Control Center - Branding Catalyst Control Center Graphics Previews Common Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-utility64 CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish Combined Community Codec Pack 2011-11-11 Counter-Strike Counter-Strike: Condition Zero Counter-Strike: Condition Zero Deleted Scenes Crysis WARHEAD® Easy Tune 6 B11.0512.1 ESN Sonar Etron USB3.0 Host Controller Fallout: New Vegas Far Cry 2 Google Chrome Guild Wars 2 Intel® Control Center Intel® Management Engine Components Intel® Processor Graphics Internet TV for Windows Media Center iTunes Java 7 Update 21 Java Auto Updater Junk Mail filter update League of Legends Left 4 Dead 2 Logitech Vid HD Logitech Webcam Software Mass Effect™ 3 Medieval II Total War Medieval II Total War : Kingdoms : Americas Medieval II Total War : Kingdoms : Britannia Medieval II Total War : Kingdoms : Crusades Medieval II Total War : Kingdoms : Teutonic Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Flight Microsoft Games for Windows - LIVE Redistributable Microsoft Games for Windows Marketplace Microsoft IntelliPoint 8.2 Microsoft IntelliType Pro 8.2 Microsoft Office 2010 Microsoft Office Click-to-Run 2010 Microsoft Office Starter 2010 - English Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Mirror's Edge MotoHelper 2.1.32 Driver 5.4.0 MotoHelper MergeModules MOTOROLA MEDIA LINK Motorola Mobile Drivers Installation 5.4.0 MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Netflix in Windows Media Center NVIDIA PhysX ON_OFF Charge B11.0110.1 Origin Pando Media Booster PunkBuster Services RealDownloader RealNetworks - Microsoft Visual C++ 2008 Runtime RealNetworks - Microsoft Visual C++ 2010 Runtime RealPlayer Realtek Ethernet Controller Driver Realtek High Definition Audio Driver RealUpgrade 1.1 Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576) Skype Click to Call Skype™ 6.1 Smart 6 B11.0512.1 Steam TomTom HOME TomTom HOME Visual Studio Merge Modules Total War: SHOGUN 2 Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Mail Windows Live Messenger Windows Live Movie Maker Windows Live Photo Gallery Windows Live Sync Windows Live Upload Tool Windows Live Writer Windows Media Center Add-in for Flash . ==== Event Viewer Messages From Past Week ======== . 6/6/2013 3:04:40 PM, Error: Service Control Manager [7023] - The Windows Defender service terminated with the following error: Access is denied. . ==== End Of File ===========================
