Hi.
I have been having trouble with blue screens, boot up problems, slow, disc read errors, high disk usage.
We reset the computer all the way back to original. Then started loading our programs. Again, the same type of thing is happening. We also did a check disc.
Can you help?
........................................................................... ..................................................................
Hijackthis log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:44:25 AM, on 6/12/2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17126)
Boot mode: Normal
Running processes:
C:\Users\Joanne\AppData\Roaming\Dashlane\Dashlane.exe
C:\Program Files (x86)\Microsoft Money\System\mnyexpr.exe
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Joanne\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://emachines.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://emachines.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Dashlane BHO - {42D79B50-CC4A-4A8E-860F-BE674AF053A2} - C:\Users\Joanne\AppData\Roaming\Dashlane\ie\Dashlanei.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\IPS\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Dashlane Toolbar - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Joanne\AppData\Roaming\Dashlane\ie\KWIEBar.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Hotkey Utility] C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe
O4 - HKLM\..\Run: [Intuit SyncManager] c:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"
O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
O4 - HKCU\..\Run: [Dashlane] "C:\Users\Joanne\AppData\Roaming\Dashlane\Dashlane.exe" autoLaunchAtStartup
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files (x86)\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHSA.EXE /EPT "EPLTarget\P0000000000000000" /M "WorkForce 845" /EF "HKCU"
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: intu-help-qb3 - {C5E479EA-0A65-4B05-8C6C-2FC8CC682EB4} - c:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonCustomerParticipation - SEIKO EPSON CORPORATION - C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\N360.exe
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - c:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - c:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10605 bytes
........................................................................... ............................................
dds file
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17126
Run by Joanne at 7:47:56 on 2014-06-12
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2815.1400 [GMT -5:00]
.
AV: Norton 360 *Enabled/Updated* {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
SP: Norton 360 *Enabled/Updated* {631E4324-D31C-783F-EC5C-35AD42B18466}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton 360 *Enabled* {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe
C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\N360.exe
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
c:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\N360.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Users\Joanne\AppData\Roaming\Dashlane\Dashlane.exe
C:\Program Files (x86)\Microsoft Money\System\mnyexpr.exe
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHSA.EXE
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskmgr.exe
C:\Users\Joanne\Desktop\HijackThis.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://emachines.msn.com
uDefault_Page_URL = hxxp://emachines.msn.com
mWinlogon: Userinit = userinit.exe
BHO: Dashlane BHO: {42D79B50-CC4A-4A8E-860F-BE674AF053A2} - C:\Users\Joanne\AppData\Roaming\Dashlane\ie\Dashlanei.dll
BHO: {549B5CA7-4A86-11D7-A4DF-000874180BB3} - <orphaned>
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\CoIEPlg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\IPS\IPSBHO.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - <orphaned>
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} -
TB: Dashlane Toolbar: {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Joanne\AppData\Roaming\Dashlane\ie\KWIEBar.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\CoIEPlg.dll
uRun: [Dashlane] "C:\Users\Joanne\AppData\Roaming\Dashlane\Dashlane.exe" autoLaunchAtStartup
uRun: [AdobeBridge] <no file>
mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Hotkey Utility] C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe
mRun: [Intuit SyncManager] c:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
mRun: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
mRun: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"
mRun: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\QUICKB~1.LNK - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{AF5734B3-C8D3-4EC6-863D-6B90B39F75E0} : DHCPNameServer = 192.168.1.1
Handler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - c:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} -
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
x64-BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine64\21.3.0.12\CoIEPlg.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.3.0.12\CoIEPlg.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Handler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - <orphaned>
x64-Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Joanne\AppData\Roaming\Mozilla\Firefox\Profiles\d8oo6l36.default\
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\N360x64\1503000.00C\SymDS64.sys [2014-6-10 493656]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\N360x64\1503000.00C\SymEFA64.sys [2014-6-10 1148120]
R1 BHDrvx64;BHDrvx64;C:\Program Files (x86)\Norton 360\NortonData\21.3.0.12\Definitions\BASHDefs\20140606.001_385\BHDrvx64.sys [2014-6-6 1530160]
R1 ccSet_N360;N360 Settings Manager;C:\Windows\System32\drivers\N360x64\1503000.00C\ccSetx64.sys [2014-6-10 162392]
R1 IDSVia64;IDSVia64;C:\Program Files (x86)\Norton 360\NortonData\21.3.0.12\Definitions\IPSDefs\20140611.001\IDSviA64.sys [2014-6-12 525016]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\N360x64\1503000.00C\Ironx64.sys [2014-6-10 264280]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\N360x64\1503000.00C\symnets.sys [2014-6-10 593112]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
R2 EpsonCustomerParticipation;EpsonCustomerParticipation;C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe [2011-6-9 555392]
R2 GREGService;GREGService;C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe [2010-1-8 23584]
R2 Live Updater Service;Live Updater Service;C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [2011-3-31 244624]
R2 N360;Norton 360;C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\N360.exe [2014-6-10 265040]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-5-4 503080]
R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-1-26 378984]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-3-1 183560]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-6-11 111616]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2014-6-9 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2014-06-11 16:31:38 77824 ----a-w- C:\Windows\SysWow64\adistres.dll
2014-06-11 16:31:38 20588 ----a-w- C:\Windows\SysWow64\PdfPorts.dll
2014-06-11 16:30:03 306688 ----a-w- C:\Windows\IsUninst.exe
2014-06-11 11:31:57 2871808 ----a-w- C:\Windows\explorer.exe
2014-06-11 04:25:57 -------- d-----w- C:\Kpcms
2014-06-11 04:20:20 -------- d-----w- C:\Users\Joanne\AppData\Roaming\StageManager.BD092818F67280F4B42B0487760098 7F0111B594.1
2014-06-11 04:06:02 -------- d-----w- C:\Program Files (x86)\PatternMaker Software
2014-06-11 03:48:19 -------- d-----w- C:\Users\Joanne\AppData\Roaming\Leader Technologies
2014-06-10 23:48:27 -------- d-----w- C:\Users\Joanne\AppData\Local\Programs
2014-06-10 15:05:45 -------- d-----w- C:\Program Files (x86)\LTCM Client
2014-06-10 15:04:06 -------- d-----w- C:\Users\Joanne\AppData\Local\ABBYY
2014-06-10 15:02:06 -------- d-----w- C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint
2014-06-10 15:02:05 -------- d-----w- C:\ProgramData\ABBYY
2014-06-10 15:02:05 -------- d-----w- C:\Program Files (x86)\Common Files\ABBYY
2014-06-10 14:56:30 -------- d-----w- C:\Program Files\Common Files\EPSON
2014-06-10 14:53:40 558592 ----a-w- C:\Windows\System32\ensppmon.dll
2014-06-10 14:53:40 558592 ----a-w- C:\Windows\System32\enppmon.dll
2014-06-10 14:53:40 538112 ----a-w- C:\Windows\System32\ensppui.dll
2014-06-10 14:53:40 538112 ----a-w- C:\Windows\System32\enppui.dll
2014-06-10 14:53:40 250880 ----a-w- C:\Windows\System32\enspres.dll
2014-06-10 14:53:40 250880 ----a-w- C:\Windows\System32\enpres.dll
2014-06-10 14:53:40 -------- d-----w- C:\Program Files\EpsonNet
2014-06-10 14:52:42 -------- d-----w- C:\Program Files (x86)\Common Files\EPSON
2014-06-10 14:52:30 -------- d-----w- C:\Program Files (x86)\Epson America Inc
2014-06-10 14:52:17 77824 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2014-06-10 14:52:17 32768 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2014-06-10 14:52:17 225280 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\IScript\iscript.dll
2014-06-10 14:52:17 176128 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2014-06-10 14:52:15 614532 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
2014-06-10 14:51:58 -------- d-----w- C:\Program Files\EPSON
2014-06-10 14:51:09 118784 ----a-w- C:\Windows\System32\E_YLMHSA.DLL
2014-06-10 14:51:06 83456 ----a-w- C:\Windows\System32\E_YD4BHSA.DLL
2014-06-10 14:50:52 -------- d-----w- C:\ProgramData\EPSON
2014-06-10 14:50:26 -------- d-----w- C:\Program Files (x86)\Epson Software
2014-06-10 14:49:39 464384 ----a-w- C:\Windows\System32\esxw2ud.dll
2014-06-10 14:49:39 13824 ----a-w- C:\Windows\System32\esxcdev.dll
2014-06-10 14:49:39 132560 ----a-w- C:\Windows\System32\esdevapp.exe
2014-06-10 14:49:38 -------- d-----w- C:\Program Files (x86)\epson
2014-06-10 14:36:53 -------- d-----w- C:\Program Files (x86)\NortonInstaller
2014-06-10 06:02:24 -------- d-----w- C:\Program Files\Common Files\Intuit
2014-06-10 05:58:23 -------- d-----w- C:\Users\Joanne\AppData\Local\Intuit
2014-06-10 05:57:40 4194304 ----a-w- C:\Windows\SysWow64\cdintf400.dll
2014-06-10 05:55:50 -------- d-----w- C:\ProgramData\Nuance
2014-06-10 05:55:49 -------- d-----w- C:\ProgramData\Intuit
2014-06-10 05:55:49 -------- d-----w- C:\Program Files (x86)\Intuit
2014-06-10 05:55:49 -------- d-----w- C:\Program Files (x86)\Common Files\Intuit
2014-06-10 05:55:29 -------- d-----w- C:\ProgramData\SQL Anywhere 11
2014-06-10 05:55:29 -------- d-----w- C:\ProgramData\COMMON FILES
2014-06-10 05:51:40 -------- d-----w- C:\Windows\Intuit
2014-06-10 05:46:15 -------- d-----w- C:\Program Files (x86)\Akamai
2014-06-10 04:47:35 -------- d-----w- C:\Program Files (x86)\Microsoft Money
2014-06-10 04:38:15 -------- d-----w- C:\Program Files (x86)\Microsoft Streets and Trips
2014-06-10 04:28:17 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe
2014-06-10 03:15:31 -------- d-----w- C:\Program Files (x86)\Microsoft ActiveSync
2014-06-10 03:06:13 -------- d-----w- C:\Users\Joanne\AppData\Local\Mozilla
2014-06-10 02:58:40 -------- d-----w- C:\Program Files (x86)\Dashlane
2014-06-10 02:57:05 -------- d-----w- C:\Users\Joanne\AppData\Roaming\Dashlane
2014-06-10 02:57:05 -------- d-----w- C:\Users\Joanne\AppData\Local\Packages
2014-06-10 01:32:37 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2014-06-10 01:32:13 -------- d-----w- C:\Windows\SysWow64\Wat
2014-06-10 01:32:12 -------- d-----w- C:\Windows\System32\Wat
2014-06-10 01:14:45 -------- d-s---w- C:\Windows\System32\CompatTel
2014-06-10 01:08:21 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2014-06-10 00:54:56 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2014-06-10 00:54:56 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2014-06-10 00:54:56 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2014-06-10 00:54:55 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2014-06-10 00:41:40 -------- d-----w- C:\Windows\Migration
2014-06-10 00:23:16 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-10 00:12:52 -------- d-----w- C:\Windows\NAPP_Dism_Log
2014-06-10 00:01:28 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2014-06-09 23:46:03 -------- d-----w- C:\Program Files\Realtek
2014-06-09 23:46:02 518896 ----a-w- C:\Windows\System32\SRSTSX64.dll
2014-06-09 23:46:02 2719504 ----a-w- C:\Windows\System32\WavesGUILib.dll
2014-06-09 23:46:02 211184 ----a-w- C:\Windows\System32\SRSTSH64.dll
2014-06-09 23:46:02 198896 ----a-w- C:\Windows\System32\SRSHP64.dll
2014-06-09 23:46:02 155888 ----a-w- C:\Windows\System32\SRSWOW64.dll
2014-06-09 23:46:01 612384 ----a-w- C:\Windows\System32\RTSnMg64.cpl
2014-06-09 23:46:01 332320 ----a-w- C:\Windows\System32\RtlCPAPI64.dll
2014-06-09 23:46:01 2269600 ----a-w- C:\Windows\System32\drivers\RTKVHD64.sys
2014-06-09 23:46:01 1872416 ----a-w- C:\Windows\System32\RtPgEx64.dll
2014-06-09 23:44:46 -------- d-----w- C:\Program Files\NVIDIA Corporation
2014-06-09 23:42:43 704000 ----a-w- C:\Windows\System32\cohelper.dll
2014-06-09 23:42:43 6136 ----a-w- C:\Windows\System32\drivers\nvphy.bin
2014-06-09 23:41:34 -------- d-----w- C:\Windows\System32\MRT
2014-06-09 23:38:24 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2014-06-09 23:38:24 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2014-06-09 23:38:24 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2014-06-09 23:38:24 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2014-06-09 23:38:23 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2014-06-09 23:38:23 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2014-06-09 23:38:23 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2014-06-09 23:33:54 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2014-06-09 23:32:41 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2014-06-09 23:32:40 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2014-06-09 23:32:40 5120 ----a-w- C:\Windows\System32\wmi.dll
2014-06-09 23:27:44 878080 ----a-w- C:\Windows\System32\advapi32.dll
2014-06-09 23:26:51 46592 ----a-w- C:\Windows\SysWow64\fpb.rs
2014-06-09 23:24:59 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2014-06-09 23:23:58 95744 ----a-w- C:\Windows\System32\synceng.dll
2014-06-09 23:14:24 1192448 ----a-w- C:\Windows\System32\certutil.exe
2014-06-09 23:14:23 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2014-06-09 23:14:23 52224 ----a-w- C:\Windows\System32\certenc.dll
2014-06-09 23:14:23 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2014-06-09 23:08:47 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2014-06-09 23:07:28 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2014-06-09 23:07:28 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2014-06-09 23:07:28 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2014-06-09 23:04:57 -------- d-----w- C:\Users\Joanne\AppData\Roaming\Tific
2014-06-09 23:04:56 -------- d-----w- C:\Users\Joanne\AppData\Local\Symantec
2014-06-09 22:58:18 -------- d-----w- C:\Users\Joanne\AppData\Roaming\OEM
2014-06-09 22:57:58 -------- d-----w- C:\Users\Joanne\AppData\Local\VirtualStore
2014-06-09 22:57:15 -------- d-----w- C:\Program Files (x86)\OEM
2014-06-09 22:57:04 -------- d-----w- C:\ProgramData\OEM_E471269A730D
2014-06-09 22:56:51 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2014-06-09 22:56:47 -------- d-----w- C:\Program Files (x86)\Times Reader
2014-06-09 22:56:42 99840 ----a-w- C:\Windows\System32\wudriver.dll
2014-06-09 22:56:07 36864 ----a-w- C:\Windows\System32\wuapp.exe
2014-06-09 22:56:07 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2014-06-09 22:36:14 -------- d-----w- C:\Program Files (x86)\Barnes & Noble
2014-06-09 22:35:24 -------- d-----w- C:\Windows\en
2014-06-09 22:34:47 -------- d-----w- C:\Windows\fr
2014-06-09 22:34:26 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-06-09 22:32:41 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\b98ab4201cf843203\MeshBetaRemover.exe
2014-06-09 22:32:40 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\b93764001cf843202\DSETUP.dll
2014-06-09 22:32:40 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\b93764001cf843202\DXSETUP.exe
2014-06-09 22:32:40 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\b93764001cf843202\dsetup32.dll
2014-06-09 22:32:39 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\b884dce01cf843201\DSETUP.dll
2014-06-09 22:32:39 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\b884dce01cf843201\DXSETUP.exe
2014-06-09 22:32:39 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\b884dce01cf843201\dsetup32.dll
2014-06-09 22:30:30 -------- d-----w- C:\Program Files (x86)\Microsoft
2014-06-09 21:54:15 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2014-06-09 21:49:16 -------- d---a-w- C:\book
2014-06-09 21:46:19 -------- d-----w- C:\Windows\SysWow64\RTCOM
.
==================== Find3M ====================
.
2014-06-10 14:37:42 177752 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2014-06-10 00:23:16 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-08 09:13:05 506368 ----a-w- C:\Windows\System32\aepdu.dll
2014-06-08 09:08:04 424448 ----a-w- C:\Windows\System32\aeinv.dll
2014-05-30 10:02:37 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-05-30 10:02:09 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-05-30 09:39:43 548352 ----a-w- C:\Windows\System32\vbscript.dll
2014-05-30 09:39:23 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-05-30 09:38:29 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-05-30 09:21:23 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-05-30 09:21:05 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-05-30 09:20:36 752640 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-05-30 09:11:24 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-05-30 09:08:22 5782528 ----a-w- C:\Windows\System32\jscript9.dll
2014-05-30 09:02:39 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-05-30 08:55:36 38400 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-05-30 08:44:28 455168 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-05-30 08:43:06 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-05-30 08:42:16 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-05-30 08:28:33 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-05-30 08:27:56 592896 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-05-30 08:24:19 1249280 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2014-05-30 08:23:22 2040832 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-05-30 08:10:46 32256 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-05-30 07:56:56 2266112 ----a-w- C:\Windows\System32\wininet.dll
2014-05-30 07:56:50 4244992 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-05-30 07:50:09 1068032 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2014-05-30 07:49:38 1964544 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-05-30 07:21:10 1790976 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-04-25 02:34:59 801280 ----a-w- C:\Windows\System32\usp10.dll
2014-04-25 02:06:17 626688 ----a-w- C:\Windows\SysWow64\usp10.dll
2014-04-12 02:22:05 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2014-04-12 02:22:05 155072 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2014-04-12 02:19:38 29184 ----a-w- C:\Windows\System32\sspisrv.dll
2014-04-12 02:19:38 136192 ----a-w- C:\Windows\System32\sspicli.dll
2014-04-12 02:19:37 28160 ----a-w- C:\Windows\System32\secur32.dll
2014-04-12 02:19:32 1460736 ----a-w- C:\Windows\System32\lsasrv.dll
2014-04-12 02:19:05 31232 ----a-w- C:\Windows\System32\lsass.exe
2014-04-12 02:12:06 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2014-04-12 02:10:56 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2014-04-05 02:47:20 1903552 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2014-04-05 02:47:09 288192 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2014-03-26 14:44:48 2002432 ----a-w- C:\Windows\System32\msxml6.dll
2014-03-26 14:44:48 1882112 ----a-w- C:\Windows\System32\msxml3.dll
2014-03-26 14:41:39 2048 ----a-w- C:\Windows\System32\msxml6r.dll
2014-03-26 14:41:39 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2014-03-26 14:27:50 1389056 ----a-w- C:\Windows\SysWow64\msxml6.dll
2014-03-26 14:27:50 1237504 ----a-w- C:\Windows\SysWow64\msxml3.dll
2014-03-26 14:25:14 2048 ----a-w- C:\Windows\SysWow64\msxml6r.dll
2014-03-26 14:25:14 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
.
============= FINISH: 7:49:22.39 ===============
........................................................................... ................................................................
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 6/9/2014 5:54:45 PM
System Uptime: 6/12/2014 7:09:01 AM (0 hours ago)
.
Motherboard: eMachines | | EL1358G
Processor: AMD Athlon(tm) II X2 220 Processor | CPU 1 | 784/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 912 GiB total, 869.93 GiB free.
D: is CDROM ()
E: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP11: 6/10/2014 9:50:01 AM - Installed Epson Event Manager
RP12: 6/10/2014 9:52:19 AM - Installed Epson Connect
RP13: 6/10/2014 9:52:57 AM - Installed EpsonNet Print
RP14: 6/10/2014 9:54:13 AM - Installed FAX Utility
RP15: 6/10/2014 10:00:46 AM - Installed ABBYY FineReader 9.0 Sprint
RP16: 6/11/2014 11:20:14 AM - After emails have been put in Outlook
RP17: 6/11/2014 4:56:31 PM - Windows Update
.
==== Installed Programs ======================
.
Acrobat.com
Adobe Acrobat 5.0
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Help Manager
Adobe Reader 9.1 MUI
Agatha Christie - 4:50 from Paddington
Bejeweled 2 Deluxe
Bing Bar
Build-a-lot 2
Chuzzle Deluxe
D3DX10
Dashlane
Diner Dash 2 Restaurant Rescue
Dora's World Adventure
eBay Worldwide
eMachines Games
eMachines Recovery Management
eMachines Registration
eMachines ScreenSaver
eMachines Updater
Epson Connect
Epson Customer Participation
Epson Download Navigator
Epson Event Manager
Epson FAX Utility
Epson PC-FAX Driver
EPSON Scan
EPSON WorkForce 845 Series Printer Uninstall
EpsonNet Print
Final Drive: Nitro
Galerie de photos Windows Live
Hotkey Utility
Identity Card
Jewel Quest Heritage
Junk Mail filter update
Mesh Runtime
Microsoft .NET Framework 4.5.1
Microsoft Application Error Reporting
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft Office 2003 Primary Interop Assemblies
Microsoft Office 2010
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Streets and Trips 2004
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual Studio 2005 Tools for Office Runtime
Microsoft_VC80_CRT_x86
Microsoft_VC90_CRT_x86
Mozilla Firefox 29.0.1 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Mystery P.I. - Stolen in San Francisco
Namco All-Stars: PAC-MAN
Nero Control Center 10
Nero ControlCenter 10 Help (CHM)
Nero Core Components 10
Nero DiscSpeed 10
Nero DiscSpeed 10 Help (CHM)
Nero Express 10
Nero Express 10 Help (CHM)
Nero Multimedia Suite 10 Essentials
Nero StartSmart 10
Nero StartSmart 10 Help (CHM)
Nero Update
NOOK for PC
Norton 360
Norton Online Backup
NVIDIA Control Panel 307.83
NVIDIA Display Control Panel
NVIDIA Drivers
NVIDIA ForceWare Network Access Manager
NVIDIA Graphics Driver 307.83
NVIDIA Install Application
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.10.8
NVIDIA Update Components
Penguins!
Plants vs. Zombies - Game of the Year
Poker Superstars III
Polar Bowler
Polar Golfer
QuickBooks
QuickBooks Simple Start 2010 Free Edition
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Security Update for Microsoft .NET Framework 4.5.1 (KB2931368)
Times Reader
Torchlight
Update Installer for WildTangent Games App
Virtual Villagers 4 - The Tree of Life
Welcome Center
WildTangent Games App (eMachines Games)
Windows Live
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Zuma's Revenge
.
==== Event Viewer Messages From Past Week ========
.
6/9/2014 8:24:50 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Update for Internet Explorer 8 Compatibility View List for Windows 7 for x64-based Systems (KB2598845).
6/9/2014 8:24:49 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Security Update for Internet Explorer 8 for Windows 7 for x64-based Systems (KB2953522).
6/9/2014 8:22:54 PM, Error: Service Control Manager [7023] -
6/11/2014 6:23:29 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: BHDrvx64
6/11/2014 5:06:06 PM, Error: nvstor64 [3] - Data error on device. Device: \Device\RaidPort0 Model: ST31000528AS Firmware Version: CC46 Serial Number: 6VPDWTH8 Port: 0
6/11/2014 5:06:06 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\DR0.
6/10/2014 10:48:41 PM, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
.
==== End Of File ===========================
........................................................................... ...................................................................
ARK log
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-06-12 07:55:01
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\0000005e ST310005 rev.CC46 931.51GB
Running: 85z6wr1h.exe; Driver: C:\Users\Joanne\AppData\Local\Temp\pgriqpob.sys
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\WUDFHost.exe [2128:2164] 000007fef7bc24a0
Thread C:\Windows\System32\svchost.exe [3924:3772] 000007fef6705170
Thread C:\Windows\System32\svchost.exe [3924:3392] 000007fef94c9874
Thread C:\Windows\system32\DllHost.exe [3600:4024] 000007fef087ae40
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3828:664] 0000000075767587
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3828:5112] 0000000064497712
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3828:5116] 0000000077d42e65
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3828:4048] 0000000077d43e85
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3828:3684] 0000000077d43e85
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3828:4736] 0000000077d43e85
---- EOF - GMER 2.1 ----
I have been having trouble with blue screens, boot up problems, slow, disc read errors, high disk usage.
We reset the computer all the way back to original. Then started loading our programs. Again, the same type of thing is happening. We also did a check disc.
Can you help?
........................................................................... ..................................................................
Hijackthis log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:44:25 AM, on 6/12/2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17126)
Boot mode: Normal
Running processes:
C:\Users\Joanne\AppData\Roaming\Dashlane\Dashlane.exe
C:\Program Files (x86)\Microsoft Money\System\mnyexpr.exe
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Joanne\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://emachines.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://emachines.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Dashlane BHO - {42D79B50-CC4A-4A8E-860F-BE674AF053A2} - C:\Users\Joanne\AppData\Roaming\Dashlane\ie\Dashlanei.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\IPS\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Dashlane Toolbar - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Joanne\AppData\Roaming\Dashlane\ie\KWIEBar.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Hotkey Utility] C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe
O4 - HKLM\..\Run: [Intuit SyncManager] c:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"
O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
O4 - HKCU\..\Run: [Dashlane] "C:\Users\Joanne\AppData\Roaming\Dashlane\Dashlane.exe" autoLaunchAtStartup
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files (x86)\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHSA.EXE /EPT "EPLTarget\P0000000000000000" /M "WorkForce 845" /EF "HKCU"
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: intu-help-qb3 - {C5E479EA-0A65-4B05-8C6C-2FC8CC682EB4} - c:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonCustomerParticipation - SEIKO EPSON CORPORATION - C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\N360.exe
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - c:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - c:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10605 bytes
........................................................................... ............................................
dds file
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17126
Run by Joanne at 7:47:56 on 2014-06-12
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2815.1400 [GMT -5:00]
.
AV: Norton 360 *Enabled/Updated* {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
SP: Norton 360 *Enabled/Updated* {631E4324-D31C-783F-EC5C-35AD42B18466}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton 360 *Enabled* {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe
C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\N360.exe
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
c:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\N360.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Users\Joanne\AppData\Roaming\Dashlane\Dashlane.exe
C:\Program Files (x86)\Microsoft Money\System\mnyexpr.exe
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHSA.EXE
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskmgr.exe
C:\Users\Joanne\Desktop\HijackThis.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://emachines.msn.com
uDefault_Page_URL = hxxp://emachines.msn.com
mWinlogon: Userinit = userinit.exe
BHO: Dashlane BHO: {42D79B50-CC4A-4A8E-860F-BE674AF053A2} - C:\Users\Joanne\AppData\Roaming\Dashlane\ie\Dashlanei.dll
BHO: {549B5CA7-4A86-11D7-A4DF-000874180BB3} - <orphaned>
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\CoIEPlg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\IPS\IPSBHO.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - <orphaned>
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} -
TB: Dashlane Toolbar: {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Joanne\AppData\Roaming\Dashlane\ie\KWIEBar.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\CoIEPlg.dll
uRun: [Dashlane] "C:\Users\Joanne\AppData\Roaming\Dashlane\Dashlane.exe" autoLaunchAtStartup
uRun: [AdobeBridge] <no file>
mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Hotkey Utility] C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe
mRun: [Intuit SyncManager] c:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
mRun: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
mRun: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"
mRun: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\QUICKB~1.LNK - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{AF5734B3-C8D3-4EC6-863D-6B90B39F75E0} : DHCPNameServer = 192.168.1.1
Handler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - c:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} -
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
x64-BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine64\21.3.0.12\CoIEPlg.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.3.0.12\CoIEPlg.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Handler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - <orphaned>
x64-Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Joanne\AppData\Roaming\Mozilla\Firefox\Profiles\d8oo6l36.default\
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\N360x64\1503000.00C\SymDS64.sys [2014-6-10 493656]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\N360x64\1503000.00C\SymEFA64.sys [2014-6-10 1148120]
R1 BHDrvx64;BHDrvx64;C:\Program Files (x86)\Norton 360\NortonData\21.3.0.12\Definitions\BASHDefs\20140606.001_385\BHDrvx64.sys [2014-6-6 1530160]
R1 ccSet_N360;N360 Settings Manager;C:\Windows\System32\drivers\N360x64\1503000.00C\ccSetx64.sys [2014-6-10 162392]
R1 IDSVia64;IDSVia64;C:\Program Files (x86)\Norton 360\NortonData\21.3.0.12\Definitions\IPSDefs\20140611.001\IDSviA64.sys [2014-6-12 525016]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\N360x64\1503000.00C\Ironx64.sys [2014-6-10 264280]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\N360x64\1503000.00C\symnets.sys [2014-6-10 593112]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
R2 EpsonCustomerParticipation;EpsonCustomerParticipation;C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe [2011-6-9 555392]
R2 GREGService;GREGService;C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe [2010-1-8 23584]
R2 Live Updater Service;Live Updater Service;C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [2011-3-31 244624]
R2 N360;Norton 360;C:\Program Files (x86)\Norton 360\Engine\21.3.0.12\N360.exe [2014-6-10 265040]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-5-4 503080]
R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-1-26 378984]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-3-1 183560]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-6-11 111616]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2014-6-9 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2014-06-11 16:31:38 77824 ----a-w- C:\Windows\SysWow64\adistres.dll
2014-06-11 16:31:38 20588 ----a-w- C:\Windows\SysWow64\PdfPorts.dll
2014-06-11 16:30:03 306688 ----a-w- C:\Windows\IsUninst.exe
2014-06-11 11:31:57 2871808 ----a-w- C:\Windows\explorer.exe
2014-06-11 04:25:57 -------- d-----w- C:\Kpcms
2014-06-11 04:20:20 -------- d-----w- C:\Users\Joanne\AppData\Roaming\StageManager.BD092818F67280F4B42B0487760098 7F0111B594.1
2014-06-11 04:06:02 -------- d-----w- C:\Program Files (x86)\PatternMaker Software
2014-06-11 03:48:19 -------- d-----w- C:\Users\Joanne\AppData\Roaming\Leader Technologies
2014-06-10 23:48:27 -------- d-----w- C:\Users\Joanne\AppData\Local\Programs
2014-06-10 15:05:45 -------- d-----w- C:\Program Files (x86)\LTCM Client
2014-06-10 15:04:06 -------- d-----w- C:\Users\Joanne\AppData\Local\ABBYY
2014-06-10 15:02:06 -------- d-----w- C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint
2014-06-10 15:02:05 -------- d-----w- C:\ProgramData\ABBYY
2014-06-10 15:02:05 -------- d-----w- C:\Program Files (x86)\Common Files\ABBYY
2014-06-10 14:56:30 -------- d-----w- C:\Program Files\Common Files\EPSON
2014-06-10 14:53:40 558592 ----a-w- C:\Windows\System32\ensppmon.dll
2014-06-10 14:53:40 558592 ----a-w- C:\Windows\System32\enppmon.dll
2014-06-10 14:53:40 538112 ----a-w- C:\Windows\System32\ensppui.dll
2014-06-10 14:53:40 538112 ----a-w- C:\Windows\System32\enppui.dll
2014-06-10 14:53:40 250880 ----a-w- C:\Windows\System32\enspres.dll
2014-06-10 14:53:40 250880 ----a-w- C:\Windows\System32\enpres.dll
2014-06-10 14:53:40 -------- d-----w- C:\Program Files\EpsonNet
2014-06-10 14:52:42 -------- d-----w- C:\Program Files (x86)\Common Files\EPSON
2014-06-10 14:52:30 -------- d-----w- C:\Program Files (x86)\Epson America Inc
2014-06-10 14:52:17 77824 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2014-06-10 14:52:17 32768 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2014-06-10 14:52:17 225280 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\IScript\iscript.dll
2014-06-10 14:52:17 176128 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2014-06-10 14:52:15 614532 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
2014-06-10 14:51:58 -------- d-----w- C:\Program Files\EPSON
2014-06-10 14:51:09 118784 ----a-w- C:\Windows\System32\E_YLMHSA.DLL
2014-06-10 14:51:06 83456 ----a-w- C:\Windows\System32\E_YD4BHSA.DLL
2014-06-10 14:50:52 -------- d-----w- C:\ProgramData\EPSON
2014-06-10 14:50:26 -------- d-----w- C:\Program Files (x86)\Epson Software
2014-06-10 14:49:39 464384 ----a-w- C:\Windows\System32\esxw2ud.dll
2014-06-10 14:49:39 13824 ----a-w- C:\Windows\System32\esxcdev.dll
2014-06-10 14:49:39 132560 ----a-w- C:\Windows\System32\esdevapp.exe
2014-06-10 14:49:38 -------- d-----w- C:\Program Files (x86)\epson
2014-06-10 14:36:53 -------- d-----w- C:\Program Files (x86)\NortonInstaller
2014-06-10 06:02:24 -------- d-----w- C:\Program Files\Common Files\Intuit
2014-06-10 05:58:23 -------- d-----w- C:\Users\Joanne\AppData\Local\Intuit
2014-06-10 05:57:40 4194304 ----a-w- C:\Windows\SysWow64\cdintf400.dll
2014-06-10 05:55:50 -------- d-----w- C:\ProgramData\Nuance
2014-06-10 05:55:49 -------- d-----w- C:\ProgramData\Intuit
2014-06-10 05:55:49 -------- d-----w- C:\Program Files (x86)\Intuit
2014-06-10 05:55:49 -------- d-----w- C:\Program Files (x86)\Common Files\Intuit
2014-06-10 05:55:29 -------- d-----w- C:\ProgramData\SQL Anywhere 11
2014-06-10 05:55:29 -------- d-----w- C:\ProgramData\COMMON FILES
2014-06-10 05:51:40 -------- d-----w- C:\Windows\Intuit
2014-06-10 05:46:15 -------- d-----w- C:\Program Files (x86)\Akamai
2014-06-10 04:47:35 -------- d-----w- C:\Program Files (x86)\Microsoft Money
2014-06-10 04:38:15 -------- d-----w- C:\Program Files (x86)\Microsoft Streets and Trips
2014-06-10 04:28:17 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe
2014-06-10 03:15:31 -------- d-----w- C:\Program Files (x86)\Microsoft ActiveSync
2014-06-10 03:06:13 -------- d-----w- C:\Users\Joanne\AppData\Local\Mozilla
2014-06-10 02:58:40 -------- d-----w- C:\Program Files (x86)\Dashlane
2014-06-10 02:57:05 -------- d-----w- C:\Users\Joanne\AppData\Roaming\Dashlane
2014-06-10 02:57:05 -------- d-----w- C:\Users\Joanne\AppData\Local\Packages
2014-06-10 01:32:37 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2014-06-10 01:32:13 -------- d-----w- C:\Windows\SysWow64\Wat
2014-06-10 01:32:12 -------- d-----w- C:\Windows\System32\Wat
2014-06-10 01:14:45 -------- d-s---w- C:\Windows\System32\CompatTel
2014-06-10 01:08:21 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2014-06-10 00:54:56 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2014-06-10 00:54:56 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2014-06-10 00:54:56 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2014-06-10 00:54:55 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2014-06-10 00:41:40 -------- d-----w- C:\Windows\Migration
2014-06-10 00:23:16 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-10 00:12:52 -------- d-----w- C:\Windows\NAPP_Dism_Log
2014-06-10 00:01:28 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2014-06-09 23:46:03 -------- d-----w- C:\Program Files\Realtek
2014-06-09 23:46:02 518896 ----a-w- C:\Windows\System32\SRSTSX64.dll
2014-06-09 23:46:02 2719504 ----a-w- C:\Windows\System32\WavesGUILib.dll
2014-06-09 23:46:02 211184 ----a-w- C:\Windows\System32\SRSTSH64.dll
2014-06-09 23:46:02 198896 ----a-w- C:\Windows\System32\SRSHP64.dll
2014-06-09 23:46:02 155888 ----a-w- C:\Windows\System32\SRSWOW64.dll
2014-06-09 23:46:01 612384 ----a-w- C:\Windows\System32\RTSnMg64.cpl
2014-06-09 23:46:01 332320 ----a-w- C:\Windows\System32\RtlCPAPI64.dll
2014-06-09 23:46:01 2269600 ----a-w- C:\Windows\System32\drivers\RTKVHD64.sys
2014-06-09 23:46:01 1872416 ----a-w- C:\Windows\System32\RtPgEx64.dll
2014-06-09 23:44:46 -------- d-----w- C:\Program Files\NVIDIA Corporation
2014-06-09 23:42:43 704000 ----a-w- C:\Windows\System32\cohelper.dll
2014-06-09 23:42:43 6136 ----a-w- C:\Windows\System32\drivers\nvphy.bin
2014-06-09 23:41:34 -------- d-----w- C:\Windows\System32\MRT
2014-06-09 23:38:24 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2014-06-09 23:38:24 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2014-06-09 23:38:24 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2014-06-09 23:38:24 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2014-06-09 23:38:23 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2014-06-09 23:38:23 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2014-06-09 23:38:23 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2014-06-09 23:33:54 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2014-06-09 23:32:41 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2014-06-09 23:32:40 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2014-06-09 23:32:40 5120 ----a-w- C:\Windows\System32\wmi.dll
2014-06-09 23:27:44 878080 ----a-w- C:\Windows\System32\advapi32.dll
2014-06-09 23:26:51 46592 ----a-w- C:\Windows\SysWow64\fpb.rs
2014-06-09 23:24:59 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2014-06-09 23:23:58 95744 ----a-w- C:\Windows\System32\synceng.dll
2014-06-09 23:14:24 1192448 ----a-w- C:\Windows\System32\certutil.exe
2014-06-09 23:14:23 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2014-06-09 23:14:23 52224 ----a-w- C:\Windows\System32\certenc.dll
2014-06-09 23:14:23 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2014-06-09 23:08:47 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2014-06-09 23:07:28 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2014-06-09 23:07:28 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2014-06-09 23:07:28 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2014-06-09 23:04:57 -------- d-----w- C:\Users\Joanne\AppData\Roaming\Tific
2014-06-09 23:04:56 -------- d-----w- C:\Users\Joanne\AppData\Local\Symantec
2014-06-09 22:58:18 -------- d-----w- C:\Users\Joanne\AppData\Roaming\OEM
2014-06-09 22:57:58 -------- d-----w- C:\Users\Joanne\AppData\Local\VirtualStore
2014-06-09 22:57:15 -------- d-----w- C:\Program Files (x86)\OEM
2014-06-09 22:57:04 -------- d-----w- C:\ProgramData\OEM_E471269A730D
2014-06-09 22:56:51 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2014-06-09 22:56:47 -------- d-----w- C:\Program Files (x86)\Times Reader
2014-06-09 22:56:42 99840 ----a-w- C:\Windows\System32\wudriver.dll
2014-06-09 22:56:07 36864 ----a-w- C:\Windows\System32\wuapp.exe
2014-06-09 22:56:07 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2014-06-09 22:36:14 -------- d-----w- C:\Program Files (x86)\Barnes & Noble
2014-06-09 22:35:24 -------- d-----w- C:\Windows\en
2014-06-09 22:34:47 -------- d-----w- C:\Windows\fr
2014-06-09 22:34:26 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-06-09 22:32:41 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\b98ab4201cf843203\MeshBetaRemover.exe
2014-06-09 22:32:40 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\b93764001cf843202\DSETUP.dll
2014-06-09 22:32:40 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\b93764001cf843202\DXSETUP.exe
2014-06-09 22:32:40 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\b93764001cf843202\dsetup32.dll
2014-06-09 22:32:39 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\b884dce01cf843201\DSETUP.dll
2014-06-09 22:32:39 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\b884dce01cf843201\DXSETUP.exe
2014-06-09 22:32:39 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\b884dce01cf843201\dsetup32.dll
2014-06-09 22:30:30 -------- d-----w- C:\Program Files (x86)\Microsoft
2014-06-09 21:54:15 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2014-06-09 21:49:16 -------- d---a-w- C:\book
2014-06-09 21:46:19 -------- d-----w- C:\Windows\SysWow64\RTCOM
.
==================== Find3M ====================
.
2014-06-10 14:37:42 177752 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2014-06-10 00:23:16 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-08 09:13:05 506368 ----a-w- C:\Windows\System32\aepdu.dll
2014-06-08 09:08:04 424448 ----a-w- C:\Windows\System32\aeinv.dll
2014-05-30 10:02:37 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-05-30 10:02:09 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-05-30 09:39:43 548352 ----a-w- C:\Windows\System32\vbscript.dll
2014-05-30 09:39:23 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-05-30 09:38:29 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-05-30 09:21:23 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-05-30 09:21:05 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-05-30 09:20:36 752640 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-05-30 09:11:24 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-05-30 09:08:22 5782528 ----a-w- C:\Windows\System32\jscript9.dll
2014-05-30 09:02:39 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-05-30 08:55:36 38400 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-05-30 08:44:28 455168 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-05-30 08:43:06 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-05-30 08:42:16 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-05-30 08:28:33 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-05-30 08:27:56 592896 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-05-30 08:24:19 1249280 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2014-05-30 08:23:22 2040832 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-05-30 08:10:46 32256 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-05-30 07:56:56 2266112 ----a-w- C:\Windows\System32\wininet.dll
2014-05-30 07:56:50 4244992 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-05-30 07:50:09 1068032 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2014-05-30 07:49:38 1964544 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-05-30 07:21:10 1790976 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-04-25 02:34:59 801280 ----a-w- C:\Windows\System32\usp10.dll
2014-04-25 02:06:17 626688 ----a-w- C:\Windows\SysWow64\usp10.dll
2014-04-12 02:22:05 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2014-04-12 02:22:05 155072 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2014-04-12 02:19:38 29184 ----a-w- C:\Windows\System32\sspisrv.dll
2014-04-12 02:19:38 136192 ----a-w- C:\Windows\System32\sspicli.dll
2014-04-12 02:19:37 28160 ----a-w- C:\Windows\System32\secur32.dll
2014-04-12 02:19:32 1460736 ----a-w- C:\Windows\System32\lsasrv.dll
2014-04-12 02:19:05 31232 ----a-w- C:\Windows\System32\lsass.exe
2014-04-12 02:12:06 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2014-04-12 02:10:56 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2014-04-05 02:47:20 1903552 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2014-04-05 02:47:09 288192 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2014-03-26 14:44:48 2002432 ----a-w- C:\Windows\System32\msxml6.dll
2014-03-26 14:44:48 1882112 ----a-w- C:\Windows\System32\msxml3.dll
2014-03-26 14:41:39 2048 ----a-w- C:\Windows\System32\msxml6r.dll
2014-03-26 14:41:39 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2014-03-26 14:27:50 1389056 ----a-w- C:\Windows\SysWow64\msxml6.dll
2014-03-26 14:27:50 1237504 ----a-w- C:\Windows\SysWow64\msxml3.dll
2014-03-26 14:25:14 2048 ----a-w- C:\Windows\SysWow64\msxml6r.dll
2014-03-26 14:25:14 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
.
============= FINISH: 7:49:22.39 ===============
........................................................................... ................................................................
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 6/9/2014 5:54:45 PM
System Uptime: 6/12/2014 7:09:01 AM (0 hours ago)
.
Motherboard: eMachines | | EL1358G
Processor: AMD Athlon(tm) II X2 220 Processor | CPU 1 | 784/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 912 GiB total, 869.93 GiB free.
D: is CDROM ()
E: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP11: 6/10/2014 9:50:01 AM - Installed Epson Event Manager
RP12: 6/10/2014 9:52:19 AM - Installed Epson Connect
RP13: 6/10/2014 9:52:57 AM - Installed EpsonNet Print
RP14: 6/10/2014 9:54:13 AM - Installed FAX Utility
RP15: 6/10/2014 10:00:46 AM - Installed ABBYY FineReader 9.0 Sprint
RP16: 6/11/2014 11:20:14 AM - After emails have been put in Outlook
RP17: 6/11/2014 4:56:31 PM - Windows Update
.
==== Installed Programs ======================
.
Acrobat.com
Adobe Acrobat 5.0
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Help Manager
Adobe Reader 9.1 MUI
Agatha Christie - 4:50 from Paddington
Bejeweled 2 Deluxe
Bing Bar
Build-a-lot 2
Chuzzle Deluxe
D3DX10
Dashlane
Diner Dash 2 Restaurant Rescue
Dora's World Adventure
eBay Worldwide
eMachines Games
eMachines Recovery Management
eMachines Registration
eMachines ScreenSaver
eMachines Updater
Epson Connect
Epson Customer Participation
Epson Download Navigator
Epson Event Manager
Epson FAX Utility
Epson PC-FAX Driver
EPSON Scan
EPSON WorkForce 845 Series Printer Uninstall
EpsonNet Print
Final Drive: Nitro
Galerie de photos Windows Live
Hotkey Utility
Identity Card
Jewel Quest Heritage
Junk Mail filter update
Mesh Runtime
Microsoft .NET Framework 4.5.1
Microsoft Application Error Reporting
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft Office 2003 Primary Interop Assemblies
Microsoft Office 2010
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Streets and Trips 2004
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual Studio 2005 Tools for Office Runtime
Microsoft_VC80_CRT_x86
Microsoft_VC90_CRT_x86
Mozilla Firefox 29.0.1 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Mystery P.I. - Stolen in San Francisco
Namco All-Stars: PAC-MAN
Nero Control Center 10
Nero ControlCenter 10 Help (CHM)
Nero Core Components 10
Nero DiscSpeed 10
Nero DiscSpeed 10 Help (CHM)
Nero Express 10
Nero Express 10 Help (CHM)
Nero Multimedia Suite 10 Essentials
Nero StartSmart 10
Nero StartSmart 10 Help (CHM)
Nero Update
NOOK for PC
Norton 360
Norton Online Backup
NVIDIA Control Panel 307.83
NVIDIA Display Control Panel
NVIDIA Drivers
NVIDIA ForceWare Network Access Manager
NVIDIA Graphics Driver 307.83
NVIDIA Install Application
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.10.8
NVIDIA Update Components
Penguins!
Plants vs. Zombies - Game of the Year
Poker Superstars III
Polar Bowler
Polar Golfer
QuickBooks
QuickBooks Simple Start 2010 Free Edition
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Security Update for Microsoft .NET Framework 4.5.1 (KB2931368)
Times Reader
Torchlight
Update Installer for WildTangent Games App
Virtual Villagers 4 - The Tree of Life
Welcome Center
WildTangent Games App (eMachines Games)
Windows Live
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Zuma's Revenge
.
==== Event Viewer Messages From Past Week ========
.
6/9/2014 8:24:50 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Update for Internet Explorer 8 Compatibility View List for Windows 7 for x64-based Systems (KB2598845).
6/9/2014 8:24:49 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Security Update for Internet Explorer 8 for Windows 7 for x64-based Systems (KB2953522).
6/9/2014 8:22:54 PM, Error: Service Control Manager [7023] -
6/11/2014 6:23:29 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: BHDrvx64
6/11/2014 5:06:06 PM, Error: nvstor64 [3] - Data error on device. Device: \Device\RaidPort0 Model: ST31000528AS Firmware Version: CC46 Serial Number: 6VPDWTH8 Port: 0
6/11/2014 5:06:06 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\DR0.
6/10/2014 10:48:41 PM, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
.
==== End Of File ===========================
........................................................................... ...................................................................
ARK log
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-06-12 07:55:01
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\0000005e ST310005 rev.CC46 931.51GB
Running: 85z6wr1h.exe; Driver: C:\Users\Joanne\AppData\Local\Temp\pgriqpob.sys
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\WUDFHost.exe [2128:2164] 000007fef7bc24a0
Thread C:\Windows\System32\svchost.exe [3924:3772] 000007fef6705170
Thread C:\Windows\System32\svchost.exe [3924:3392] 000007fef94c9874
Thread C:\Windows\system32\DllHost.exe [3600:4024] 000007fef087ae40
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3828:664] 0000000075767587
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3828:5112] 0000000064497712
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3828:5116] 0000000077d42e65
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3828:4048] 0000000077d43e85
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3828:3684] 0000000077d43e85
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3828:4736] 0000000077d43e85
---- EOF - GMER 2.1 ----