Computing Staff
  • 11

Can Anyone Help Me With This REPLICATING VIRUS?

  • 11

I also have the same problem. I am using windows 8. Here are the logs that came up after I ran the DDS. Please help. Thanks

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 8 Pro
Boot Device: \Device\HarddiskVolume1
Install Date: 12/5/2012 2:40:32 AM
System Uptime: 8/1/2013 10:14:59 PM (19 hours ago)
.
Motherboard: ASUSTeK COMPUTER INC. | | K55VD
Processor: Intel(R) Core(TM) i7-3610QM CPU @ 2.30GHz | SOCKET 0 | 2301/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) – 279 GiB total, 0.001 GiB free.
D: is FIXED (NTFS) – 394 GiB total, 116.566 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is FIXED (NTFS) – 932 GiB total, 764.43 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description:
Device ID: USB\VID_13D3&PID;_3362\ALASKA_DAY_2006
Manufacturer:
Name:
PNP Device ID: USB\VID_13D3&PID;_3362\ALASKA_DAY_2006
Service:
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
???? ??? Windows Live
???? ???? ActiveX ????? ?? Windows Live Mesh ????????? ???????
???? Windows Live
??????? Windows Live Mesh ActiveX ??(????)
??????? Windows Live Mesh ActiveX ???
????????? ActiveX ?? Windows Live Mesh ????????????????????????? (???)
µTorrent
Adobe Flash Player 10 Plugin
Adobe Reader X (10.1.7) MUI
Akamai NetSession Interface
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
Assassin’s Creed ® III
ASUS AI Recovery
ASUS FaceLogon
ASUS Instant Connect
ASUS InstantOn
ASUS LifeFrame3
ASUS Live Update
ASUS Power4Gear Hybrid
ASUS Smart Gesture
ASUS Splendid Video Enhancement Technology
ASUS USB Charger Plus
ASUS Virtual Camera
ASUS Virtual Touch
ASUS WebStorage
ASUSDVD
AsusVibe2.0
ATK Package
AutoCAD 2013 – English
AutoCAD 2013 Language Pack – English
Autodesk Content Service
Autodesk Content Service Language Pack
Autodesk Design Review 2013
Autodesk Inventor Fusion 2013
Autodesk Inventor Fusion plug-in for AutoCAD 2013
Autodesk Inventor Fusion plug-in language pack for AutoCAD 2013
Autodesk Material Library 2013
Autodesk Material Library Base Resolution Image Library 2013
Autodesk Sync
Battle Realms
Bing Bar
BlueStacks Notification Center
Bonjour
Bubbletown
Call of Duty Black Ops II
Combined Community Codec Pack 2012-12-30
Company of Heroes 2
Contrôle ActiveX Windows Live Mesh pour connexions à distance
Control ActiveX de Windows Live Mesh para conexiones remotas
Controle ActiveX do Windows Live Mesh para Conexões Remotas
Crysis® 2
Crysis® 3
CyberLink LabelPrint
CyberLink Media Suite
CyberLink Power2Go
D3DX10
DAEMON Tools Lite
Dead Island Riptide 1.1.0
Dead Space™ 3
Deadtime Stories
DefaultTab
Dishonored
Dream Day First Home
Dream Vacation Solitaire
EVGA Precision X 4.0.0
Facebook Video Calling 1.2.0.287
Far Cry 3
Farm Frenzy 3 – Madagascar
FARO LS 1.1.406.58
FIFA 13 Crack
Front Mission Evolved
Galapago
Galerie de photos Windows Live
Galería fotográfica de Windows Live
Game Park Console
Garena – Heroes of Newerth
Garena Plus
Go Go Gourmet Chef of the Year
Google Chrome
Google Update Helper
Grand Theft Auto IV
Hitman Absolution
Intel(R) Manageability Engine Firmware Recovery Agent
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
Intel® Trusted Connect Service Client
iTunes
Java 7 Update 25
Java Auto Updater
Junk Mail filter update
Mahjong Memoirs
Mass Effect 3
Mesh Runtime
Metro: Last Light (c) Deep Silver version 1
Microsoft Application Error Reporting
Microsoft Games for Windows – LIVE Redistributable
Microsoft Office 2010
Microsoft Office Click-to-Run 2010
Microsoft Office Starter 2010 – English
Microsoft PowerPoint Viewer
Microsoft Save as PDF Add-in for 2007 Microsoft Office programs
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable – x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable – x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable – x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable – x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable – x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable – x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable – x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable – 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable – 10.0.40219
Microsoft WSE 3.0 Runtime
Mozilla Firefox 22.0 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
myBitCast 1.0.0.3
NBA 2K13
NBA 2K13 Crack
Need for Speed™ Carbon
NVIDIA Control Panel 326.19
NVIDIA GeForce Experience 1.6
NVIDIA Graphics Driver 326.19
NVIDIA Install Application
NVIDIA Optimus 7.2.17
NVIDIA PhysX
NVIDIA PhysX System Software 9.13.0604
NVIDIA Update 7.2.17
NVIDIA Update Components
NVIDIA Virtual Audio 1.2.1
OpenAL
Plants vs Zombies
PunkBuster Services
Qualcomm Atheros Bluetooth Suite (64)
Qualcomm Atheros Client Installation Program
Qualcomm Atheros WiFi Driver Installation
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek PCIE Card Reader
SceneSwitch
Secure Download Manager
SHIELD Streaming
Silent Hill Homecoming
Skype Click to Call
Skype™ 6.5
Sniper: Ghost Warrior 2
Spec Ops The Line
SpeedFan (remove only)
Star Wars: The Force Unleashed 2
Steam
System Requirements Lab CYRI
The Sims™ 3
Titanium Internet Security
Tom Clancy’s H.A.W.X. 2
Tomb Raider
Trend Micro Titanium
Turbo Fiesta
Uplay
uTorrentControl_v2 Toolbar
Uzak Baglantilar Için Windows Live Mesh ActiveX Denetimi
Viber
VirtualDJ Home FREE
VLC media player 2.0.5
WebCake 3.00
Windows Driver Package – ASUS (ATP) Mouse (10/29/2012 1.0.0.148)
Windows Live
Windows Live ???
Windows Live ????
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Fotograf Galerisi
Windows Live Galeria de Fotos
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Temel Parçalar
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinFlash
WinRAR 4.20 (32-bit)
WinRAR 4.20 (64-bit)
Wireless Console 3
World of Goo
Yahoo! Messenger
.
==== Event Viewer Messages From Past Week ========
.
8/2/2013 3:02:27 AM, Error: Schannel [36888] – A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
8/1/2013 8:48:04 PM, Error: Service Control Manager [7022] – The Intel(R) Management and Security Application User Notification Service service hung on starting.
8/1/2013 10:18:18 PM, Error: Service Control Manager [7009] – A timeout was reached (30000 milliseconds) while waiting for the Trend Micro Solution Platform service to connect.
8/1/2013 10:18:18 PM, Error: Service Control Manager [7000] – The Trend Micro Solution Platform service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/1/2013 10:17:26 PM, Error: Service Control Manager [7024] – The HomeGroup Listener service terminated with the following service-specific error: There are no more endpoints available from the endpoint mapper.
8/1/2013 10:17:20 PM, Error: Service Control Manager [7034] – The DefaultTabSearch service terminated unexpectedly. It has done this 1 time(s).
8/1/2013 10:16:25 PM, Error: Service Control Manager [7000] – The Globe Tattoo Broadband. OUC service failed to start due to the following error: The system cannot find the file specified.
8/1/2013 10:14:30 PM, Error: Service Control Manager [7011] – A timeout (30000 milliseconds) was reached while waiting for a transaction response from the FontCache3.0.0.0 service.
7/31/2013 10:12:32 PM, Error: Microsoft-Windows-DistributedCOM [10016] – The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
7/30/2013 8:26:40 PM, Error: Service Control Manager [7009] – A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
7/30/2013 8:26:40 PM, Error: Service Control Manager [7000] – The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
.
==== End Of File ===========================

AND THIS IS THE OTHER===============

DDS (Ver_2012-11-20.01) – NTFS_AMD64
Internet Explorer: 10.0.9200.16453 BrowserJavaVersion: 10.25.2
Run by john edmund at 17:07:11 on 2013-08-02
Microsoft Windows 8 Pro 6.2.9200.0.1252.63.1033.18.3982.1259 [GMT 8:00]
.
AV: Titanium Internet Security *Enabled/Updated* {B7599298-8445-728A-A5C7-A26A082C8BDA}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Titanium Internet Security *Enabled/Updated* {0C38737C-A27F-7D04-9F77-991873ABC167}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\nvvsvc.exe
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\WINDOWS\system32\nvvsvc.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\SysWOW64\rundll32.exe
C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\system32\taskeng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe
C:\WINDOWS\system32\taskeng.exe
C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
C:\Program Files\ASUS\P4G\BatteryLife.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\WINDOWS\system32\svchost.exe -k apphost
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
C:\Users\john edmund\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe
C:\ProgramData\DatacardService\HWDeviceService64.exe
C:\WINDOWS\system32\dashost.exe
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\WINDOWS\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k iissvcs
C:\Program Files (x86)\WebCake\WebCakeDesktop.Updater.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Users\john edmund\AppData\Local\Akamai\netsession_win.exe
D:\uTorrent.exe
C:\Users\john edmund\AppData\Roaming\WebCake\WebCakeDesktop.exe
D:\STEAM\Steam.exe
C:\Users\john edmund\AppData\Local\Akamai\netsession_win.exe
C:\WINDOWS\SysWOW64\WScript.exe
C:\Program Files (x86)\Ask.com\Updater\Updater.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\BlueStacks\HD-Agent.exe
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\system32\AdminService.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\GFExperience.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files (x86)\BlueStacks\HD-Frontend.exe
C:\Program Files (x86)\BlueStacks\HD-Service.exe
C:\Program Files (x86)\BlueStacks\HD-Network.exe
C:\Program Files (x86)\BlueStacks\HD-BlockDevice.exe
C:\Program Files (x86)\BlueStacks\HD-SharedFolder.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\CCleaner64.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Java\jre7\bin\jp2launcher.exe
C:\Program Files (x86)\Java\jre7\bin\java.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.delta-search.com/?affID=119776&babsrc;=HP_ss&mntrId;=E0945E85DE320805
uDefault_Page_URL = hxxp://asus.msn.com
uProxyOverride = <local>;*.local
uURLSearchHooks: {c95a4e8e-816d-4655-8c79-d736da1adb6d} – <orphaned>
uURLSearchHooks: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} – C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
mURLSearchHooks: {c95a4e8e-816d-4655-8c79-d736da1adb6d} – <orphaned>
mWinlogon: Userinit = userinit.exe
BHO: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} – C:\Program Files\Trend Micro\AMSP\module\20004\2.0.1361\6.8.1078\TmIEPlg32.dll
BHO: WebCake: {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} – C:\Program Files (x86)\WebCake\WebCakeIEClient.dll
BHO: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} – C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} – C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: DefaultTab Browser Helper: {7F6AFBF1-E065-4627-A2FD-810366367D01} – C:\Users\john edmund\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} – LocalServer32 – <no file>
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} – C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: TmBpIeBHO Class: {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} – C:\Program Files\Trend Micro\AMSP\module\20002\7.1.1104\7.1.1104\TmBpIe32.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll
BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} – C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} – C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: uTorrentControl_v2 Toolbar: {7473B6BD-4691-4744-A82B-7854EB3D70B6} – C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} – C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} –
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} – LocalServer32 – <no file>
TB: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} – C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} – C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
uRun: [Akamai NetSession Interface] “C:\Users\john edmund\AppData\Local\Akamai\netsession_win.exe”
uRun: [DAEMON Tools Lite] “C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe” -autorun
uRun: [GarenaPlus] “C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe” -autolaunch
uRun: [uTorrent] “D:\uTorrent.exe” /MINIMIZED
uRun: [Skype] “C:\Program Files (x86)\Skype\Phone\Skype.exe” /minimized /regrun
uRun: [Viber] “C:\Users\john edmund\AppData\Local\Viber\Viber.exe” StartMinimized
uRun: [WebCake Desktop] “C:\Users\john edmund\AppData\Roaming\WebCake\WebCakeDesktop.exe”
uRun: [Steam] “D:\STEAM\Steam.exe” -silent
mRun: [APSDaemon] “C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe”
mRun: [Adobe] C:\ProgramData\Adobe\97C3E8D.vbe
mRun: [Adobe ARM] “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
mRun: [ApnUpdater] “C:\Program Files (x86)\Ask.com\Updater\Updater.exe”
mRun: [iTunesHelper] “D:\iTunesHelper.exe”
mRun: [SunJavaUpdateSched] “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
mRun: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe
StartupFolder: C:\Users\john edmund\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerReg Scheduler.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: HideSCAHealth = dword:1
IE: Send to Bluetooth – C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} – {5F7B1267-94A9-47F5-98DB-E99415F33AEC} – C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} – {898EA8C8-E7FF-479B-8935-AEC46303B9E5} – C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
TCP: NameServer = 121.1.3.81 121.1.3.16 121.1.3.66
TCP: Interfaces\{201133BC-8A28-40D4-971F-FCF0C071A237} : DHCPNameServer = 121.1.3.81 121.1.3.16 121.1.3.66
TCP: Interfaces\{4DD3553D-20B8-4533-9519-84E946BA014C}\05C44445D4974435C4 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{4DD3553D-20B8-4533-9519-84E946BA014C}\24F4747435 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{4DD3553D-20B8-4533-9519-84E946BA014C}\44D4050545F425255435 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{4DD3553D-20B8-4533-9519-84E946BA014C}\6796275737030373 : DHCPNameServer = 121.1.3.81 121.1.3.16 121.1.3.66
TCP: Interfaces\{4DD3553D-20B8-4533-9519-84E946BA014C}\C696E6B6379737 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{4DD3553D-20B8-4533-9519-84E946BA014C}\D4140555140264275656027596D26696 : DHCPNameServer = 8.8.8.8
TCP: Interfaces\{4DD3553D-20B8-4533-9519-84E946BA014C}\F40756E6752747 : DHCPNameServer = 192.168.1.1
Handler: skype-ie-addon-data – {91774881-D725-4E58-B298-07617B9B86A8} – C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com – {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} – C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: tmbp – {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} – C:\Program Files\Trend Micro\AMSP\module\20002\7.1.1104\7.1.1104\TmBpIe32.dll
Handler: tmpx – {0E526CB5-7446-41D1-A403-19BFE95E8C23} – C:\Program Files\Trend Micro\AMSP\module\20004\2.0.1361\6.8.1078\TmIEPlg32.dll
Handler: wlpg – {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} – C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs= C:\WINDOWS\SysWOW64\nvinit.dll, C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll
SSODL: WebCheck – <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} – “C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe” –configure-user-settings –verbose-logging –system-level –multi-install –chrome
x64-mStart Page = hxxp://asus.msn.com
x64-BHO: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} – C:\Program Files\Trend Micro\AMSP\module\20004\2.0.1361\6.8.1078\TmIEPlg.dll
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} – LocalServer32 – <no file>
x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} – C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-BHO: TmBpIeBHO Class: {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} – C:\Program Files\Trend Micro\AMSP\module\20002\7.1.1104\7.1.1104\TmBpIe64.dll
x64-BHO: {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} – <orphaned>
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} – LocalServer32 – <no file>
x64-Run: [Trend Micro Client Framework] “C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe”
x64-Run: [Trend Micro Titanium] “C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe” -set Silent “1” SplashURL “”
x64-Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [BtTray] “C:\Program Files (x86)\Bluetooth Suite\BtTray.exe”
x64-Run: [BtvStack] “C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe”
x64-Run: [Nvtmru] “C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe”
x64-Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
x64-Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
x64-mPolicies-Explorer: HideSCAHealth = dword:1
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} – {898EA8C8-E7FF-479B-8935-AEC46303B9E5} – C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype-ie-addon-data – {91774881-D725-4E58-B298-07617B9B86A8} – C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com – {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} – <orphaned>
x64-Handler: tmbp – {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} – C:\Program Files\Trend Micro\AMSP\module\20002\7.1.1104\7.1.1104\TmBpIe64.dll
x64-Handler: tmpx – {0E526CB5-7446-41D1-A403-19BFE95E8C23} – C:\Program Files\Trend Micro\AMSP\module\20004\2.0.1361\6.8.1078\TmIEPlg.dll
x64-Handler: wlpg – {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} – <orphaned>
x64-Notify: igfxcui – igfxdev.dll
x64-SSODL: WebCheck – <orphaned>
.
================= FIREFOX ===================
.
FF – ProfilePath – C:\Users\john edmund\AppData\Roaming\Mozilla\Firefox\Profiles\eu8al5sl.default\
FF – prefs.js: browser.search.selectedEngine – Search Here
FF – plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF – plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF – plugin: C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll
FF – plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF – plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF – plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF – plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF – plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF – plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF – plugin: C:\Users\john edmund\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF – plugin: C:\WINDOWS\SysWOW64\npDeployJava1.dll
FF – plugin: C:\WINDOWS\SysWOW64\npmproxy.dll
FF – plugin: D:\Mozilla Plugins\npitunes.dll
FF – plugin: D:\Tom Clancys HAWX 2\orbitlauncher\npuplaypc.dll
FF – plugin: D:\Tom Clancys HAWX 2\orbitlauncher\npuplaypchub.dll
FF – plugin: D:\VLC\npvlc.dll
FF – ExtSQL: 2013-06-23 23:47; torntv2@torntv.com; C:\Users\john edmund\AppData\Roaming\Mozilla\Firefox\Profiles\eu8al5sl.default\extensions\torntv2@torntv.com.xpi
FF – ExtSQL: 2013-06-23 23:48; plugin@getwebcake.com; C:\Users\john edmund\AppData\Roaming\Mozilla\Firefox\Profiles\eu8al5sl.default\extensions\plugin@getwebcake.com
.
—- FIREFOX POLICIES —-
FF – user.js: extentions.webcake.installId – 095bfc2a-34c6-47ff-863d-35d78f8b2b24
FF – user.js: extentions.webcake.defaultEnableAppsList – layers,brain/features,newOffers/wc
FF – user.js: extensions.delta.tlbrSrchUrl –
FF – user.js: extensions.delta.id – e094a2d20000000000005e85de320805
FF – user.js: extensions.delta.appId – {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF – user.js: extensions.delta.instlDay – 15879
FF – user.js: extensions.delta.vrsn – 1.8.21.5
FF – user.js: extensions.delta.vrsni – 1.8.21.5
FF – user.js: extensions.delta.vrsnTs – 1.8.21.523:48:39
FF – user.js: extensions.delta.prtnrId – delta
FF – user.js: extensions.delta.prdct – delta
FF – user.js: extensions.delta.aflt – babsst
FF – user.js: extensions.delta.smplGrp – none
FF – user.js: extensions.delta.tlbrId – base
FF – user.js: extensions.delta.instlRef – sst
FF – user.js: extensions.delta.dfltLng – en
FF – user.js: extensions.delta.excTlbr – false
FF – user.js: extensions.delta.ffxUnstlRst – true
FF – user.js: extensions.delta.admin – false
FF – user.js: extensions.delta_i.babTrack – affID=119776
FF – user.js: extensions.delta_i.babExt –
FF – user.js: extensions.delta_i.srcExt – ss
FF – user.js: extensions.delta.autoRvrt – false
FF – user.js: extensions.delta.rvrt – false
FF – user.js: extensions.delta.newTab – false
.
============= SERVICES / DRIVERS ===============
.
R0 nvpciflt;nvpciflt;C:\WINDOWS\System32\Drivers\nvpciflt.sys [2013-7-19 30496]
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-9-8 17536]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\WINDOWS\System32\Drivers\dtsoftbus01.sys [2012-12-4 283200]
R1 tmevtmgr;tmevtmgr;C:\WINDOWS\System32\Drivers\tmevtmgr.sys [2012-3-10 77184]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-3 15416]
R2 ASUS InstantOn;ASUS InstantOn Service;C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-4-13 277120]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\System32\Drivers\aswFsBlk.sys [2012-11-27 25232]
R2 aswMonFlt;aswMonFlt;C:\WINDOWS\System32\Drivers\aswMonFlt.sys [2012-11-27 71064]
R2 Autodesk Content Service;Autodesk Content Service;C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2012-1-31 19232]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-8-27 1112000]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2012-9-6 1124288]
R2 BstHdAndroidSvc;BlueStacks Android Service;C:\Program Files (x86)\BlueStacks\HD-Service.exe [2013-7-4 393032]
R2 BstHdDrv;BlueStacks Hypervisor;C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [2013-7-4 70984]
R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [2013-7-4 384840]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]
R2 DefaultTabUpdate;DefaultTabUpdate;C:\Users\john edmund\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe [2013-3-17 107520]
R2 HWDeviceService64.exe;HWDeviceService64.exe;C:\ProgramData\DatacardService\HWDeviceService64.exe [2011-3-14 346976]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2013-1-22 2451456]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2011-12-9 607456]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-7-31 128280]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-7-31 161560]
R2 NvStreamSvc;NVIDIA Streamer Service;C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-8-1 14984480]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]
R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-7-12 3289472]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-7-31 363800]
R2 WebCake Desktop Updater;WebCake Desktop Updater;C:\Program Files (x86)\WebCake\WebCakeDesktop.Updater.exe [2013-6-23 23552]
R3 AiCharger;ASUS Charger Driver;C:\WINDOWS\System32\Drivers\AiCharger.sys [2012-7-31 17152]
R3 ATP;ASUS PS/2 Port Input Device;C:\WINDOWS\System32\Drivers\AsusTP.sys [2012-10-31 61824]
R3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE [2012-6-11 240208]
R3 huawei_enumerator;huawei_enumerator;C:\WINDOWS\System32\Drivers\ew_jubusenum.sys [2013-4-7 87040]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\WINDOWS\System32\Drivers\nvvad64v.sys [2013-8-1 39712]
R3 RSBASTOR;Realtek PCIE CardReader Driver – BA;C:\WINDOWS\System32\Drivers\RtsBaStor.sys [2013-1-22 295056]
R3 RTL8168;Realtek 8168 NT Driver;C:\WINDOWS\System32\Drivers\Rt630x64.sys [2012-6-2 589824]
R3 Sftfs;Sftfs;C:\WINDOWS\System32\Drivers\Sftfslh.sys [2011-10-1 764264]
R3 Sftplay;Sftplay;C:\WINDOWS\System32\Drivers\Sftplaylh.sys [2011-10-1 268648]
R3 Sftredir;Sftredir;C:\WINDOWS\System32\Drivers\Sftredirlh.sys [2011-10-1 25960]
R3 Sftvol;Sftvol;C:\WINDOWS\System32\Drivers\Sftvollh.sys [2011-10-1 22376]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]
R4 AtherosSvc;AtherosSvc;C:\WINDOWS\System32\AdminService.exe [2012-8-29 208384]
S1 aswSnx;aswSnx;C:\WINDOWS\System32\Drivers\aswSnx.sys [2012-11-27 958400]
S1 aswSP;aswSP;C:\WINDOWS\System32\Drivers\aswSP.sys [2012-11-27 355856]
S1 HssDRV6;Hotspot Shield Routing Driver 6;C:\WINDOWS\System32\Drivers\hssdrv6.sys [2012-11-15 42248]
S2 Amsp;Trend Micro Solution Platform;C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe [2012-3-10 275912]
S2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE [2012-6-11 193616]
S2 DefaultTabSearch;DefaultTabSearch;C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe [2013-2-11 572928]
S2 Globe Tattoo Broadband. RunOuc;Globe Tattoo Broadband. OUC;D:\Globe Tattoo Broadband\UpdateDog\ouc.exe –> D:\Globe Tattoo Broadband\UpdateDog\ouc.exe [?]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-6-3 162408]
S3 BtFilter;BtFilter;C:\WINDOWS\System32\Drivers\btfilter.sys [2012-8-29 565760]
S3 BthLEEnum;Bluetooth Low Energy Driver;C:\WINDOWS\System32\Drivers\BthLEEnum.sys [2012-7-26 202752]
S3 btmaux;Intel Bluetooth Auxiliary Service;C:\WINDOWS\System32\Drivers\btmaux.sys [2012-8-27 121728]
S3 DrvAgent64;DrvAgent64;C:\Windows\SysWOW64\drivers\DrvAgent64.SYS [2013-1-22 21712]
S3 ewusbmbb;HUAWEI USB-WWAN miniport;C:\WINDOWS\System32\Drivers\ewusbwwan.sys [2013-4-7 421888]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2013-1-28 1432400]
S3 fssfltr;fssfltr;C:\WINDOWS\System32\Drivers\fssfltr.sys [2012-3-10 48488]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-14 1492840]
S3 IntcDAud;Intel(R) Display Audio;C:\WINDOWS\System32\Drivers\IntcDAud.sys [2012-10-26 342528]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\WINDOWS\System32\Drivers\iusb3hub.sys [2012-5-25 356120]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\WINDOWS\System32\Drivers\iusb3xhc.sys [2012-5-25 787736]
S3 USBAAPL64;Apple Mobile USB Driver;C:\WINDOWS\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 vmbusr;Virtual Machine Bus Provider;C:\WINDOWS\System32\Drivers\vmbusr.sys [2012-7-26 117248]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\System32\Drivers\wdcsam64.sys [2008-5-6 14464]
S3 WUDFWpdComp;WUDFWpdComp;C:\WINDOWS\System32\Drivers\WUDFRd.sys [2012-7-26 198656]
S3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\Drivers\WUDFRd.sys [2012-7-26 198656]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== File Associations ===============
.
FileExt: .scr: AutoCADScriptFile=C:\WINDOWS\System32\notepad.exe “%1”
.
=============== Created Last 30 ================
.
2013-08-01 14:14:34 0 —-a-w- C:\WINDOWS\SysWow64\sho8D0B.tmp
2013-08-01 13:09:11 ——– d—–w- C:\NvidiaLogging
2013-08-01 13:07:57 39712 —-a-w- C:\WINDOWS\System32\drivers\nvvad64v.sys
2013-08-01 13:07:57 29984 —-a-w- C:\WINDOWS\System32\nvaudcap64v.dll
2013-08-01 13:07:57 28448 —-a-w- C:\WINDOWS\SysWow64\nvaudcap32v.dll
2013-08-01 01:10:14 262832 —-a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10212.bin
2013-07-27 14:16:23 ——– d—–w- C:\Program Files (x86)\Common Files\Steam
2013-07-23 09:53:14 ——– d—–w- C:\Users\john edmund\AppData\Local\EA Games
2013-07-23 07:10:43 ——– d—–w- C:\ProgramData\Origin
2013-07-22 23:22:29 ——– d–h–w- C:\Program Files (x86)\Common Files\EAInstaller
2013-07-18 23:03:11 ——– d—–w- C:\WINDOWS\SysWow64\NV
2013-07-18 23:03:11 ——– d—–w- C:\WINDOWS\System32\NV
2013-07-16 16:44:40 ——– d—–w- C:\Program Files (x86)\BlueStacks
2013-07-16 16:44:22 ——– d—–w- C:\ProgramData\BlueStacksSetup
2013-07-16 16:44:21 ——– d—–w- C:\ProgramData\BlueStacks
2013-07-12 06:42:18 6129024 —-a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-07-12 06:42:18 6129024 —-a-w- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-07-09 15:08:21 53248 —-a-r- C:\Users\john edmund\AppData\Roaming\Microsoft\Installer\{9AA761E6-CA51-4FF2-A552-D51638BF0595}\_F522ED7EA612_4117_B86D_78467DE01E30.exe
.
==================== Find3M ====================
.
2013-07-18 10:46:26 281688 —-a-w- C:\WINDOWS\SysWow64\PnkBstrB.xtr
2013-07-18 10:46:26 281688 —-a-w- C:\WINDOWS\SysWow64\PnkBstrB.exe
2013-07-13 19:49:00 6598432 —-a-w- C:\WINDOWS\System32\nvcpl.dll
2013-07-13 19:49:00 3447072 —-a-w- C:\WINDOWS\System32\nvsvc64.dll
2013-07-13 19:48:57 911136 —-a-w- C:\WINDOWS\System32\nvvsvc.exe
2013-07-13 19:48:57 67072 —-a-w- C:\WINDOWS\System32\nv3dappshextr.dll
2013-07-13 19:48:57 63776 —-a-w- C:\WINDOWS\System32\nvshext.dll
2013-07-13 19:48:57 2559776 —-a-w- C:\WINDOWS\System32\nvsvcr.dll
2013-07-13 19:48:57 219424 —-a-w- C:\WINDOWS\System32\nvmctray.dll
2013-07-13 19:48:57 1042208 —-a-w- C:\WINDOWS\System32\nv3dappshext.dll
2013-07-13 19:48:55 3274475 —-a-w- C:\WINDOWS\System32\nvcoproc.bin
2013-07-09 03:47:12 281688 —-a-w- C:\WINDOWS\SysWow64\PnkBstrB.ex0
2013-07-03 02:23:33 96168 —-a-w- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
2013-07-03 02:23:32 867240 —-a-w- C:\WINDOWS\SysWow64\npDeployJava1.dll
2013-07-03 02:23:32 789416 —-a-w- C:\WINDOWS\SysWow64\deployJava1.dll
2013-06-21 17:11:43 76888 —-a-w- C:\WINDOWS\SysWow64\PnkBstrA.exe
2013-05-12 21:42:27 1832224 —-a-w- C:\WINDOWS\System32\nvdispco6432018.dll
2013-05-12 21:42:27 1511712 —-a-w- C:\WINDOWS\System32\nvdispgenco6432018.dll
2013-05-09 02:47:13 0 —-a-w- C:\WINDOWS\SysWow64\sho65C9.tmp
.
============= FINISH: 17:07:40.92 ===============

PS: I hope you can help me with this. i will greatly appreciate it. Thank you

Share

3 Answers

  1. First thing, I’m a little surprised you posted a log before having one requested, especially because it recommends not posting it unless requested. Secondarily I agree with part of the above I see at least three semi malicious toolbars. If I am reading things right you may have too many anti virus programs running which may have been where the virus snuck in.

    Malwarebytes might be easier to remove the toolbars
    http://www.malwarebytes.org/product…

    What was the detection for the virus that caused you to know something was wrong?

    edit: I see there are multiple posts looking there now

    :: mike

    • 0
  2. As we dismantle the infection bit by bit, that may allow the repeat use of programs, which may in turn pick up more.
    Removal of infected parts of the system, may cause other parts to stop working, such as your Internet connection or Services. These we then, have to repair.

    If any program won’t run ( due to the infection ) let me know.

    Copy and Paste the contents of the log/logs after running each program mentioned above in the previous posts.

    1: Download & run Unhide
    http://www.bleepingcomputer.com/for…
    http://download.bleepingcomputer.co…
    To run Unhide, simply download it to your desktop and then double-click on the Unhide icon. The program will open a black box and start making the files on your fixed disks visible again. Please note, that this program will not unhide removable drives like flash cards and usb drives as the FakeHDD rogues do not target these types of drives. Once it has finished, the program will display a Windows alert stating that your files have been restored. You should then reboot your computer for all of the settings to go into effect.
    Copy & Paste the contents of the log. Let me know if it doesn’t produce a log please.

    2: Reboot

    3: Run AdwCleaner
    http://www.softpedia.com/get/Antivi…
    http://www.softpedia.com/progScreen…
    http://general-changelog-team.fr/en…
    http://www.raymond.cc/blog/adwclean…
    Please download AdwCleaner by Xplode onto your desktop.
    Close all open programs and internet browsers.
    Double click on AdwCleaner.exe to run the tool.
    Click on Delete.
    Confirm each time with Ok.
    Your computer will be rebooted automatically. A text file will open after the restart.
    Please Copy & Paste the contents of that logfile with your next answer.
    You can find the logfile at C:\AdwCleaner[S1].txt as well.

    4: Run Junkware Removal Tool
    http://www.softpedia.com/get/Securi…
    http://www.softpedia.com/progScreen…
    http://www.bleepingcomputer.com/dow…
    http://thisisudax.blogspot.com.au/2…
    Download Junkware Removal Tool to your desktop.
    Warning! Once the scan is complete JRT will shut down your browser with NO warning.
    Shut down your protection software now to avoid potential conflicts.
    Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. http://www.bleepingcomputer.com/for…
    Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator
    The tool will open and start scanning your system.
    Please be patient as this can take a while to complete depending on your system’s specifications.
    On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    Copy and Paste the contents of the JRT.txt log please.

    5: Run ESET Online Scanner, Copy and Paste the contents of the log please. This scan may take a very long while, so please be patient. Maybe start it before going to work or bed.
    http://www.eset.com/us/online-scann…
    http://www.eset.com/home/products/o…
    You may have to download ESET from a good computer, put it on a flash/thumb/pen drive & run it from there, if your comp is unbootable, or won’t let you download.
    Create a ESET SysRescue CD or USB drive
    http://kb.eset.com/esetkb/index?pag…
    How do I use my ESET SysRescue CD or USB flash drive to scan and clean my system?
    http://kb.eset.com/esetkb/index?pag…
    Configure ESET this way & disable your AV.
    http://i.imgur.com/3U7YC.gif
    How to Temporarily Disable your Anti-virus
    http://www.bleepingcomputer.com/for…
    Which web browsers are compatible with ESET Online Scanner?
    http://www.nod32.fi/eset-online-sca…
    http://kb.eset.com/esetkb/index?pag…
    Online Scanner not working
    http://kb.eset.com/esetkb/index?pag…
    Why Would I Ever Need an Online Virus Scanner?
    I already have an antivirus program installed, isn’t that enough?
    http://www.squidoo.com/the-best-fre…
    Once onto a machine, malware can disable antivirus programs, prevent antimalware programs from downloading updates, or prevent a user from running antivirus scans or installing new antivirus software or malware removal tools. At this point even though you are aware the computer is infected, removal is very difficult.
    5: Why does the ESET Online Scanner run slowly on my computer?
    If you have other antivirus, antispyware or anti-malware programs running on your computer, they may intercept the scan being performed by the ESET Online Scanner and hinder performance. You may wish to disable the real-time protection components of your other security software before running the ESET Online Scanner. Remember to turn them back on after you are finished.
    17: How can I view the log file from ESET Online Scanner?
    http://kb.eset.com/esetkb/index?pag…
    http://www.eset.com/home/products/o…
    The ESET Online Scanner saves a log file after running, which can be examined or sent in to ESET for further analysis. The path to the log file is “C:\Program Files\EsetOnlineScanner\log.txt”. You can view this file by navigating to the directory and double-clicking on it in Windows Explorer, or by copying and pasting the path specification above (including the quotation marks) into the Start ? Run dialog box from the Start Menu on the desktop.
    If no threats are found, you will simply see an information window that no threats were found.
    http://www.trishtech.com/security/s…

    • 0
  3. These hidden partitions are not required, do so research on these, to find out what is going on.

    Disk: 0
    Partition 1
    Type : c12a7328-f81f-11d2-ba4b-00a0c93ec93b
    Hidden : Yes
    Required: No
    Attrib : 0X8000000000000000

    Volume ### Ltr Label Fs Type Size Status Info
    ———- — ———– —– ———- ——- ——— ——–
    * Volume 4 SYSTEM FAT32 Partition 200 MB Healthy System (partition with boot components)

    ==================================================================

    Disk: 0
    Partition 2
    Type : e3c9e316-0b5c-4db8-817d-f92df00215ae
    Hidden : Yes
    Required: No
    Attrib : 0X8000000000000000

    There is no volume associated with this partition.

    I would reinstall W8.

    Make sure when you reinstall, you delete ALL partitions & format to NTFS.

    W8 – The complete guide to a Windows 8 clean installation
    http://i.imgur.com/2FOd60C.gif
    http://i.imgur.com/pm8d5Xm.gif
    http://pcsupport.about.com/od/windo…
    http://www.techrepublic.com/blog/wi…

    Here are some examples of why you delete all partitions.
    http://forums.spybot.info/showthrea…
    http://forums.whatthetech.com/index…
    http://blog.eset.com/2011/10/18/tdl…

    • 0