jipse
2014-03-10, 21:30
My computer has been taken over by the S-1-5-9 type account to the point where it has blocked me from doing most anything. I cannot update with windows, it also took over the HP critical update that would allow windows updates. It has taken over my spybot teatimer which I have disabled. I was able to gain the two information files for you as instructed in the before you post thread.
Computer life for me is at a standstill without your help.
Now most my restore points are gone but I did have backup on an external G drive but this think has taken admin rights on that too.
I did reinstall/backup my system several times before I realized what was happening. My sincere apologies if this becomes a hinderance. I see no happy ending at this point, only request for mercy and justice.
DDS
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: BrowserJavaVersion: 10.21.2
Run by Kim at 13:17:13 on 2014-03-10
#Option MBR scan is disabled.
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.1918.779 [GMT -6:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\CISVC.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\System32\tcpsvcs.exe
C:\Windows\System32\snmp.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Opera\18.0.1284.63\opera.exe
C:\Program Files\Opera\18.0.1284.63\opera.exe
C:\Program Files\Opera\18.0.1284.63\opera.exe
C:\Program Files\Opera\18.0.1284.63\opera.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Opera\18.0.1284.63\opera.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\spybot - search & destroy\SpybotSD.exe
C:\Program Files\Opera\18.0.1284.63\opera.exe
C:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Program Files\Opera\18.0.1284.63\opera.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k apphost
C:\Windows\System32\svchost.exe -k ipripsvc
C:\Windows\system32\svchost.exe -k iissvcs
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://s17-us2.startpage.com/do/mypage.pl?prfh=sslEEE1N1Nfont_sizeEEEmediumN1Ndisable_open_in_new_windowEEE0N1Nnum_of_resultsEEE10N1N
uSearch Bar = about:blank
uSearch Page = about:blank
mStart Page = about:blank
uProxyServer = hxxp=127.0.0.1:49248;https=127.0.0.1:49248
mSearchAssistant = about:blank
mCustomizeSearch = about:blank
BHO: <No Name>: {02478D38-C3F9-4efb-9B51-7695ECA05670} -
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} -
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} -
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} -
BHO: DVDVideoSoft WebPageAdjuster Class: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -
mRun: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe" /autocheck /autofix /autoclose /waitstart /waitmore
mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe"
StartupFolder: c:\users\kim\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Open with WordPerfect - c:\program files\wordperfect office x3\programs\WPLauncher.hta
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
IE: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.15.1
TCP: Interfaces\{45B92B1C-5EB6-4F63-910D-235D9D70E117} : DHCPNameServer = 192.168.42.129
TCP: Interfaces\{AA1B8839-BB67-4B20-857F-20287593E2F8} : DHCPNameServer = 192.168.15.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\33.0.1750.146\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\kim\appdata\roaming\mozilla\firefox\profiles\h6rwaysc.default\
FF - prefs.js: browser.startup.homepage - hxxps://s17-us2.startpage.com/do/mypage.pl?prfh=sslEEE1N1Nfont_sizeEEEmediumN1Ndisable_open_in_new_windowEEE0N1Nnum_of_resultsEEE10N1N
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.165\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprpplugin.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\program files\wildtangent games\app\browserintegration\registered\0\NP_wtapp.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlchromebrowserrecordext.dll
FF - plugin: c:\programdata\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlhtml5videoshim.dll
FF - plugin: c:\programdata\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlpepperflashvideoshim.dll
FF - plugin: c:\programdata\realnetworks\realdownloader\browserplugins\npdlplugin.dll
FF - plugin: c:\users\kim\appdata\local\directv player\npPlayerPlugin.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1200112.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_9_900_117.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2013-9-27 214696]
R1 RapportCerberus_59849;RapportCerberus_59849;c:\programdata\trusteer\rapport\store\exts\rapportcerberus\baseline\RapportCerberus32_59849.sys [2013-10-29 340432]
R1 RapportEI;RapportEI;c:\program files\trusteer\rapport\bin\RapportEI.sys [2013-10-25 157264]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2013-10-25 230448]
R2 iprip;RIP Listener;c:\windows\system32\svchost.exe -k ipripsvc [2009-7-13 20992]
R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2013-9-27 104768]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2013-10-23 280288]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dsiarhwprog;dsiarhwprog;c:\windows\system32\drivers\dsiarhwprog.sys [2013-8-22 35256]
S3 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [2013-10-25 108816]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-20 52224]
S3 usbdpfp;Fingerprint Reader Class Driver;c:\windows\system32\drivers\usbdpfp.sys [2006-9-16 47360]
S3 V0500Dev;Dynex 1.3MP Webcam Driver;c:\windows\system32\drivers\V0500Vid.sys [2009-8-10 251264]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2014-3-9 1343400]
S4 NTI BackupNowEZSvr;NTI BackupNowEZSvr;c:\program files\nti\nti backup now ez\BackupNowEZSvr.exe [2013-2-5 46072]
S4 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2013-10-25 1444120]
S4 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\realnetworks\realdownloader\rndlresolversvc.exe [2013-3-6 39056]
.
=============== File Associations ===============
.
ShellExec: Opera.exe: open="c:\program files\opera\Launcher.exe" "%1"
.
=============== Created Last 30 ================
.
2014-03-10 04:37:27 7947048 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{8c651b31-d9d3-4542-b51e-e37af8dc0d9d}\mpengine.dll
2014-03-10 04:35:47 -------- d-----w- c:\windows\system32\Wat
2014-03-09 22:53:19 154624 ----a-w- c:\windows\system32\iisRtl.dll
2014-03-09 22:53:18 50688 ----a-w- c:\windows\system32\admwprox.dll
2014-03-09 22:53:18 15360 ----a-w- c:\windows\system32\iisreset.exe
2014-03-09 22:53:17 8192 ----a-w- c:\windows\system32\iisrstap.dll
2014-03-09 22:53:17 26624 ----a-w- c:\windows\system32\ahadmin.dll
2014-03-09 22:53:17 10752 ----a-w- c:\windows\system32\wamregps.dll
2014-03-09 21:25:29 765968 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{656ee378-71a0-4b62-abcd-5672e85b06aa}\gapaengine.dll
2014-03-09 21:24:44 7947048 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2014-03-09 21:10:19 -------- d-----w- c:\windows\system32\BestPractices
2014-03-09 21:10:16 -------- d-----w- C:\inetpub
2014-03-09 21:03:20 -------- d-----w- c:\users\kim\appdata\roaming\HpUpdate
2014-03-09 21:03:13 -------- d-----w- c:\windows\Hewlett-Packard
2014-03-09 20:52:35 -------- d-----w- c:\users\kim\appdata\local\ElevatedDiagnostics
2014-03-07 20:22:21 -------- d-----w- c:\program files\Roxio Creator 2011
2014-03-07 19:34:10 3419136 ----a-w- c:\windows\system32\d2d1.dll
2014-03-07 19:34:10 1987584 ----a-w- c:\windows\system32\d3d10warp.dll
.
==================== Find3M ====================
.
2014-03-07 20:34:42 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-03-07 20:34:42 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-01-19 07:32:23 231584 ------w- c:\windows\system32\MpSigStub.exe
.
============= FINISH: 13:19:09.44 ===============
for ERUNT my access was denied and I could garnish nothing
Please please help.
Thank You,
Jipse
I get thru this in one piece I promise my continuous donation to your network
Computer life for me is at a standstill without your help.
Now most my restore points are gone but I did have backup on an external G drive but this think has taken admin rights on that too.
I did reinstall/backup my system several times before I realized what was happening. My sincere apologies if this becomes a hinderance. I see no happy ending at this point, only request for mercy and justice.
DDS
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: BrowserJavaVersion: 10.21.2
Run by Kim at 13:17:13 on 2014-03-10
#Option MBR scan is disabled.
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.1918.779 [GMT -6:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\CISVC.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\System32\tcpsvcs.exe
C:\Windows\System32\snmp.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Opera\18.0.1284.63\opera.exe
C:\Program Files\Opera\18.0.1284.63\opera.exe
C:\Program Files\Opera\18.0.1284.63\opera.exe
C:\Program Files\Opera\18.0.1284.63\opera.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Opera\18.0.1284.63\opera.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\spybot - search & destroy\SpybotSD.exe
C:\Program Files\Opera\18.0.1284.63\opera.exe
C:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Program Files\Opera\18.0.1284.63\opera.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k apphost
C:\Windows\System32\svchost.exe -k ipripsvc
C:\Windows\system32\svchost.exe -k iissvcs
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://s17-us2.startpage.com/do/mypage.pl?prfh=sslEEE1N1Nfont_sizeEEEmediumN1Ndisable_open_in_new_windowEEE0N1Nnum_of_resultsEEE10N1N
uSearch Bar = about:blank
uSearch Page = about:blank
mStart Page = about:blank
uProxyServer = hxxp=127.0.0.1:49248;https=127.0.0.1:49248
mSearchAssistant = about:blank
mCustomizeSearch = about:blank
BHO: <No Name>: {02478D38-C3F9-4efb-9B51-7695ECA05670} -
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} -
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} -
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} -
BHO: DVDVideoSoft WebPageAdjuster Class: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -
mRun: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe" /autocheck /autofix /autoclose /waitstart /waitmore
mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe"
StartupFolder: c:\users\kim\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Open with WordPerfect - c:\program files\wordperfect office x3\programs\WPLauncher.hta
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
IE: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.15.1
TCP: Interfaces\{45B92B1C-5EB6-4F63-910D-235D9D70E117} : DHCPNameServer = 192.168.42.129
TCP: Interfaces\{AA1B8839-BB67-4B20-857F-20287593E2F8} : DHCPNameServer = 192.168.15.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\33.0.1750.146\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\kim\appdata\roaming\mozilla\firefox\profiles\h6rwaysc.default\
FF - prefs.js: browser.startup.homepage - hxxps://s17-us2.startpage.com/do/mypage.pl?prfh=sslEEE1N1Nfont_sizeEEEmediumN1Ndisable_open_in_new_windowEEE0N1Nnum_of_resultsEEE10N1N
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.165\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprpplugin.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\program files\wildtangent games\app\browserintegration\registered\0\NP_wtapp.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlchromebrowserrecordext.dll
FF - plugin: c:\programdata\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlhtml5videoshim.dll
FF - plugin: c:\programdata\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlpepperflashvideoshim.dll
FF - plugin: c:\programdata\realnetworks\realdownloader\browserplugins\npdlplugin.dll
FF - plugin: c:\users\kim\appdata\local\directv player\npPlayerPlugin.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1200112.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_9_900_117.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2013-9-27 214696]
R1 RapportCerberus_59849;RapportCerberus_59849;c:\programdata\trusteer\rapport\store\exts\rapportcerberus\baseline\RapportCerberus32_59849.sys [2013-10-29 340432]
R1 RapportEI;RapportEI;c:\program files\trusteer\rapport\bin\RapportEI.sys [2013-10-25 157264]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2013-10-25 230448]
R2 iprip;RIP Listener;c:\windows\system32\svchost.exe -k ipripsvc [2009-7-13 20992]
R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2013-9-27 104768]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2013-10-23 280288]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dsiarhwprog;dsiarhwprog;c:\windows\system32\drivers\dsiarhwprog.sys [2013-8-22 35256]
S3 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [2013-10-25 108816]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-20 52224]
S3 usbdpfp;Fingerprint Reader Class Driver;c:\windows\system32\drivers\usbdpfp.sys [2006-9-16 47360]
S3 V0500Dev;Dynex 1.3MP Webcam Driver;c:\windows\system32\drivers\V0500Vid.sys [2009-8-10 251264]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2014-3-9 1343400]
S4 NTI BackupNowEZSvr;NTI BackupNowEZSvr;c:\program files\nti\nti backup now ez\BackupNowEZSvr.exe [2013-2-5 46072]
S4 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2013-10-25 1444120]
S4 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\realnetworks\realdownloader\rndlresolversvc.exe [2013-3-6 39056]
.
=============== File Associations ===============
.
ShellExec: Opera.exe: open="c:\program files\opera\Launcher.exe" "%1"
.
=============== Created Last 30 ================
.
2014-03-10 04:37:27 7947048 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{8c651b31-d9d3-4542-b51e-e37af8dc0d9d}\mpengine.dll
2014-03-10 04:35:47 -------- d-----w- c:\windows\system32\Wat
2014-03-09 22:53:19 154624 ----a-w- c:\windows\system32\iisRtl.dll
2014-03-09 22:53:18 50688 ----a-w- c:\windows\system32\admwprox.dll
2014-03-09 22:53:18 15360 ----a-w- c:\windows\system32\iisreset.exe
2014-03-09 22:53:17 8192 ----a-w- c:\windows\system32\iisrstap.dll
2014-03-09 22:53:17 26624 ----a-w- c:\windows\system32\ahadmin.dll
2014-03-09 22:53:17 10752 ----a-w- c:\windows\system32\wamregps.dll
2014-03-09 21:25:29 765968 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{656ee378-71a0-4b62-abcd-5672e85b06aa}\gapaengine.dll
2014-03-09 21:24:44 7947048 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2014-03-09 21:10:19 -------- d-----w- c:\windows\system32\BestPractices
2014-03-09 21:10:16 -------- d-----w- C:\inetpub
2014-03-09 21:03:20 -------- d-----w- c:\users\kim\appdata\roaming\HpUpdate
2014-03-09 21:03:13 -------- d-----w- c:\windows\Hewlett-Packard
2014-03-09 20:52:35 -------- d-----w- c:\users\kim\appdata\local\ElevatedDiagnostics
2014-03-07 20:22:21 -------- d-----w- c:\program files\Roxio Creator 2011
2014-03-07 19:34:10 3419136 ----a-w- c:\windows\system32\d2d1.dll
2014-03-07 19:34:10 1987584 ----a-w- c:\windows\system32\d3d10warp.dll
.
==================== Find3M ====================
.
2014-03-07 20:34:42 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-03-07 20:34:42 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-01-19 07:32:23 231584 ------w- c:\windows\system32\MpSigStub.exe
.
============= FINISH: 13:19:09.44 ===============
for ERUNT my access was denied and I could garnish nothing
Please please help.
Thank You,
Jipse
I get thru this in one piece I promise my continuous donation to your network