Jump to content

Well, SOMETHING's wrong here


Ezra
 Share

Recommended Posts

The log that said attach said not to attach, so I didn't.

Was sent here from previous thread. DDS log:

.

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.4.1

Run by Ezra at 21:52:19 on 2012-09-15

Microsoft Windows 7 Starter 6.1.7601.1.1252.1.1033.18.2036.253 [GMT -4:00]

.

AV: Norton Internet Security *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Norton Internet Security *Disabled/Outdated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Windows\system32\Dwm.exe

C:\Program Files\Oceanis\SystemSetting\WallPaperAgent.exe

C:\Windows\system32\taskhost.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Windows\system32\svchost.exe -k bthsvcs

C:\Windows\Explorer.exe

C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\Launch Manager\dsiwmis.exe

C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe

C:\Program Files\Launch Manager\LMworker.exe

C:\Program Files\Launch Manager\LMutilps32.exe

C:\Program Files\Gateway\Registration\GREGsvc.exe

C:\Windows\system32\svchost.exe -k bthaudiosvc

C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe

C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe

C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe

C:\Program Files\Microsoft\BingBar\SeaPort.EXE

C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe

C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Launch Manager\LManager.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE

C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\ManyCam\Bin\ManyCam.exe

C:\Program Files\Steam\Steam.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.bing.com/?pc=MAGW

uDefault_Page_URL = hxxp://www.bing.com/?pc=MAGW

mDefault_Page_URL = hxxp://www.bing.com/?pc=MAGW

mStart Page = hxxp://www.bing.com/?pc=MAGW

uInternet Settings,ProxyOverride = *.local

uWinlogon: Shell=c:\program files\oceanis\systemsetting\WallPaperAgent.exe

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\18.7.2.3\coIEPlg.dll

BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\18.7.2.3\ips\IPSBHO.DLL

BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll

BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"

BHO: Windows 7 Starter Helper: {d381ff29-7cfb-4d4e-b92a-c4eddc696614} - c:\program files\oceanis\systemsetting\StarterHelper.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll

TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\18.7.2.3\coIEPlg.dll

TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"

uRun: [Google Update] "c:\users\ezra\appdata\local\google\update\GoogleUpdate.exe" /c

uRun: [ManyCam] "c:\program files\manycam\bin\ManyCam.exe" /silent

uRun: [steam] "c:\program files\steam\steam.exe" -silent

uRun: [Facebook Update] "c:\users\ezra\appdata\local\facebook\update\FacebookUpdate.exe" /c /nocrashserver

uRun: [chromium] c:\users\ezra\appdata\local\google\chrome\application\chrome.exe --no-startup-window

uRun: [c:\users\ezra\downloads\livestreamprocaster.exe] c:\users\ezra\downloads\LivestreamProcaster.exe /exenoupdates /exelang 0 /prereqs "0"

uRun: [spotify] "c:\users\ezra\appdata\roaming\spotify\Spotify.exe" /uri spotify:autostart

uRun: [spotify Web Helper] "c:\users\ezra\appdata\roaming\spotify\data\SpotifyWebHelper.exe"

uRun: [napat] rundll32.exe "c:\users\ezra\appdata\roaming\napat.dll",StreamSubStringMatch

uRun: [phexp] "c:\windows\system32\rundll32.exe" "c:\users\ezra\appdata\roaming\phexp.dll",get_copyright

mRun: [iAStorIcon] c:\program files\intel\intel® rapid storage technology\IAStorIcon.exe

mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [igfxTray] c:\windows\system32\igfxtray.exe

mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe

mRun: [Persistence] c:\windows\system32\igfxpers.exe

mRun: [LManager] c:\program files\launch manager\LManager.exe

mRun: [synTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe

mRun: [Power Management] c:\program files\gateway\gateway power management\ePowerTray.exe

mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"

mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [amd_dc_opt] c:\program files\amd\dual-core optimizer\amd_dc_opt.exe

mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

LSP: mswsock.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

TCP: DhcpNameServer = 75.75.75.75 75.75.76.76

TCP: Interfaces\{4FFE7118-9BE0-4D45-BD54-524FA01283CB} : DhcpNameServer = 75.75.75.75 75.75.76.76

TCP: Interfaces\{D62790A9-D08B-4F0C-A8BF-9926DD11B809} : DhcpNameServer = 75.75.75.75 75.75.76.76

TCP: Interfaces\{D62790A9-D08B-4F0C-A8BF-9926DD11B809}\3736861647A796 : DhcpNameServer = 192.168.1.1

TCP: Interfaces\{D62790A9-D08B-4F0C-A8BF-9926DD11B809}\37C616577686475627 : DhcpNameServer = 192.168.2.1

TCP: Interfaces\{D62790A9-D08B-4F0C-A8BF-9926DD11B809}\44F6E647573756D69777966696 : DhcpNameServer = 192.168.1.1

TCP: Interfaces\{D62790A9-D08B-4F0C-A8BF-9926DD11B809}\E6564777F627B693 : DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll

Notify: igfxcui - igfxdev.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\users\ezra\appdata\roaming\mozilla\firefox\profiles\tgvm9fe1.default\

FF - plugin: c:\progra~1\mif5ba~1\office14\NPSPWRAP.DLL

FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll

FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll

FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll

FF - plugin: c:\programdata\best buy pc app\npBestBuyPcAppDetector.dll

FF - plugin: c:\users\ezra\appdata\local\facebook\video\skype\npFacebookVideoCalling.dll

FF - plugin: c:\users\ezra\appdata\local\google\update\1.3.21.115\npGoogleUpdate3.dll

FF - plugin: c:\users\ezra\appdata\local\roblox\versions\version-684ac714abb74f38\NPRobloxProxy.dll

FF - plugin: c:\users\ezra\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll

FF - plugin: c:\users\ezra\appdata\roaming\mozilla\plugins\npgoogletalk.dll

FF - plugin: c:\users\ezra\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll

FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_265.dll

FF - plugin: c:\windows\system32\npDeployJava1.dll

FF - plugin: c:\windows\system32\npmproxy.dll

.

============= SERVICES / DRIVERS ===============

.

R? AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service

R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0

R? BBSvc;Bing Bar Update Service

R? BthAudioHF;BthAudioHF Service

R? BthAvrcp;Bluetooth AVRCP Profile

R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86

R? csr_a2dp;Bluetooth AV Profile

R? fssfltr;fssfltr

R? fsssvc;Windows Live Family Safety Service

R? MBAMSwissArmy;MBAMSwissArmy

R? MozillaMaintenance;Mozilla Maintenance Service

R? osppsvc;Office Software Protection Platform

R? RTL8167;Realtek 8167 NT Driver

R? SkypeUpdate;Skype Updater

R? TsUsbFlt;TsUsbFlt

R? TsUsbGD;Remote Desktop Generic USB Device

R? wlcrasvc;Windows Live Mesh remote connections service

S? BHDrvx86;BHDrvx86

S? cvhsvc;Client Virtualization Handler

S? DsiWMIService;Dritek WMI Service

S? ePowerSvc;Acer ePower Service

S? EraserUtilRebootDrv;EraserUtilRebootDrv

S? GREGService;GREGService

S? HFGService;Handsfree Headset Service

S? IAStorDataMgrSvc;Intel® Rapid Storage Technology

S? IconMan_R;IconMan_R

S? IDSVix86;IDSVix86

S? Live Updater Service;Live Updater Service

S? ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver

S? MBAMProtector;MBAMProtector

S? MBAMService;MBAMService

S? NIS;Norton Internet Security

S? RSPCIESTOR;Realtek PCIE CardReader Driver

S? Sftfs;Sftfs

S? sftlist;Application Virtualization Client

S? Sftplay;Sftplay

S? Sftredir;Sftredir

S? Sftvol;Sftvol

S? sftvsa;Application Virtualization Service Agent

S? SymDS;Symantec Data Store

S? SymEFA;Symantec Extended File Attributes

S? SymIRON;Symantec Iron Driver

S? SymNetS;Symantec Network Security WFP Driver

S? vwififlt;Virtual WiFi Filter Driver

.

=============== Created Last 30 ================

.

2012-09-15 17:41:14 -------- d-----w- c:\users\ezra\appdata\local\{291E54C4-7177-4B0B-9A4A-01428308D0AE}

2012-09-15 02:35:25 -------- d-----w- c:\users\ezra\appdata\local\{26801BEC-90E7-44D0-BC64-9EA4059B63EF}

2012-09-14 02:35:03 -------- d-----w- c:\users\ezra\appdata\local\{DC3B1FDF-D6EA-4146-9057-E03B2D382432}

2012-09-13 00:19:54 -------- d-----w- c:\program files\Microsoft Security Client

2012-09-10 01:50:33 -------- d-----w- c:\users\ezra\appdata\local\{52FAF193-5BA0-46AA-B9FE-DB5A22993B66}

2012-09-09 13:50:19 -------- d-----w- c:\users\ezra\appdata\local\{9B999E00-6F44-4333-9F3F-6C6D60106610}

2012-09-09 01:50:05 -------- d-----w- c:\users\ezra\appdata\local\{5FE7C98B-815C-4F1E-A70C-3E87BDC1504B}

2012-09-08 13:49:37 -------- d-----w- c:\users\ezra\appdata\local\{31FFA18D-7D17-4087-9F57-9FAFD14BC82B}

2012-09-08 01:49:18 -------- d-----w- c:\users\ezra\appdata\local\{92DC56B1-3CFC-46BF-8634-7C6929B19B34}

2012-09-07 10:24:30 -------- d-----w- c:\users\ezra\appdata\local\{4CE1E0E4-E51D-4641-A0DE-BCB2044A77C7}

2012-09-06 22:24:19 -------- d-----w- c:\users\ezra\appdata\local\{6D0AF75A-9892-4F29-A939-F037D10099C7}

2012-09-06 10:24:08 -------- d-----w- c:\users\ezra\appdata\local\{58EF7FC2-B9A0-4330-9B7E-10ADFF3857A4}

2012-09-05 22:23:57 -------- d-----w- c:\users\ezra\appdata\local\{E9EE8997-CE4B-4A46-A26F-CEBD34B2592A}

2012-09-05 10:23:46 -------- d-----w- c:\users\ezra\appdata\local\{794B92AB-A317-4E77-B28D-56F138D622E0}

2012-09-04 22:23:35 -------- d-----w- c:\users\ezra\appdata\local\{E33F83DD-62CF-4084-A817-9C0952E9551B}

2012-09-04 10:23:24 -------- d-----w- c:\users\ezra\appdata\local\{F57878D7-B3E8-4D60-83B1-EC00377374C8}

2012-09-03 22:23:13 -------- d-----w- c:\users\ezra\appdata\local\{671B3AF7-43EB-4892-8C25-C6324A6D34E7}

2012-09-03 10:23:01 -------- d-----w- c:\users\ezra\appdata\local\{2727C25B-CFDD-4531-9A47-22F48BADF920}

2012-09-02 22:22:50 -------- d-----w- c:\users\ezra\appdata\local\{8183E3ED-F5CB-4BED-8832-16522B067140}

2012-09-02 10:22:38 -------- d-----w- c:\users\ezra\appdata\local\{28C34163-E948-4BAA-9261-CCCD55C646CD}

2012-09-01 22:21:56 -------- d-----w- c:\users\ezra\appdata\local\{F73B4DF0-B803-4E75-B2C4-9265FA8ACD4C}

2012-08-31 09:39:56 -------- d-----w- c:\users\ezra\appdata\local\{E8B61C71-3CE6-4F4F-9358-AC733CEA1EFA}

2012-08-30 21:39:44 -------- d-----w- c:\users\ezra\appdata\local\{8AC71A78-CD07-4A57-B824-8B2C1F275465}

2012-08-30 09:39:32 -------- d-----w- c:\users\ezra\appdata\local\{CC4A3E93-F69F-4D31-B5BC-22FB00E52744}

2012-08-29 21:38:58 -------- d-----w- c:\users\ezra\appdata\local\{92DA15C8-3E4A-4B10-B8CE-62464AE922C5}

2012-08-29 09:38:47 -------- d-----w- c:\users\ezra\appdata\local\{4ABA01D4-1609-4EE3-932A-55B2336D2EB5}

2012-08-28 21:38:37 -------- d-----w- c:\users\ezra\appdata\local\{4E652D62-0C6B-487F-A056-38976C19364F}

2012-08-28 09:38:25 -------- d-----w- c:\users\ezra\appdata\local\{3459167F-7D89-42C2-84A4-6A6B5EBBB274}

2012-08-27 21:37:23 -------- d-----w- c:\users\ezra\appdata\local\{E1FF171E-CF22-44DA-9C88-CDB6514AED82}

2012-08-27 09:37:08 -------- d-----w- c:\users\ezra\appdata\local\{0DCDF5AF-B7D0-401B-A603-A390C73BFDDA}

2012-08-26 17:12:18 -------- d-----w- c:\users\ezra\appdata\local\{43D1DAE9-A60A-4931-98C2-22BA247ED96D}

2012-08-26 05:12:04 -------- d-----w- c:\users\ezra\appdata\local\{5A31CE6B-D06D-4193-BE0A-BF798406B9FB}

2012-08-25 17:11:51 -------- d-----w- c:\users\ezra\appdata\local\{4FF96460-462D-4A4E-BC02-FB4AE2947CD9}

2012-08-25 05:11:39 -------- d-----w- c:\users\ezra\appdata\local\{288189CD-1886-4B6D-B93D-9596BB0E8A9B}

2012-08-24 17:11:28 -------- d-----w- c:\users\ezra\appdata\local\{C67C51E1-F619-4345-87CE-D58CF1CA75B3}

2012-08-24 05:11:17 -------- d-----w- c:\users\ezra\appdata\local\{555AA932-C702-472F-B2C4-20A5EC096BE3}

2012-08-23 17:11:06 -------- d-----w- c:\users\ezra\appdata\local\{74F3D0E7-329B-4C4E-BAB3-6B60977EF1AC}

2012-08-23 05:35:21 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2012-08-23 05:10:40 -------- d-----w- c:\users\ezra\appdata\local\{287974BD-39B8-4E6A-9B60-0B1CFD7A9B1E}

2012-08-22 17:10:29 -------- d-----w- c:\users\ezra\appdata\local\{CFA75570-8A3D-4732-82DE-5D3B2D06903E}

2012-08-22 05:10:14 -------- d-----w- c:\users\ezra\appdata\local\{CFFB1B20-8050-42EF-843C-DAF34F1D6CB5}

2012-08-21 17:10:00 -------- d-----w- c:\users\ezra\appdata\local\{6B5DD27D-04D2-4353-A5E5-FCF3454E0D4A}

2012-08-21 05:09:38 -------- d-----w- c:\users\ezra\appdata\local\{E08EA2F1-DDD4-4FC6-8EF9-0E046B43AA11}

2012-08-20 21:23:16 -------- d-----w- c:\users\ezra\appdata\roaming\Malwarebytes

2012-08-20 21:22:58 -------- d-----w- c:\programdata\Malwarebytes

2012-08-20 21:22:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-08-20 21:22:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2012-08-20 20:16:57 -------- d-----w- c:\users\ezra\appdata\local\Symantec

2012-08-20 20:05:16 -------- d-sh--w- c:\windows\system32\%APPDATA%

2012-08-20 19:53:03 -------- d-----w- c:\users\ezra\appdata\local\{8F8A7BC8-EB00-11E1-8270-B8AC6F996F26}

2012-08-20 19:52:24 440320 ----a-w- c:\users\ezra\appdata\roaming\phexp.dll

2012-08-20 19:51:00 154112 ----a-w- c:\users\ezra\appdata\roaming\napat.dll

2012-08-20 19:50:45 -------- d-----w- c:\users\ezra\appdata\roaming\xsecva

2012-08-20 17:09:11 -------- d-----w- c:\users\ezra\appdata\local\{FD25C1C9-249E-4334-A695-06A0EC2DC023}

2012-08-20 09:36:26 6891424 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{5ca800d4-3ff6-4de9-979c-4bd998957685}\mpengine.dll

2012-08-20 04:49:19 -------- d-----w- c:\users\ezra\appdata\local\{6B339CBA-6E85-4402-94BC-CAB898342B9B}

2012-08-20 04:34:17 393728 ----a-w- c:\windows\system32\drivers\bthport.sys

2012-08-20 04:28:18 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-08-20 04:28:13 140920 ----a-w- c:\program files\internet explorer\sqmapi.dll

2012-08-20 04:28:12 194560 ----a-w- c:\program files\internet explorer\ieproxy.dll

2012-08-20 04:28:10 194048 ----a-w- c:\program files\internet explorer\IEShims.dll

2012-08-20 04:28:06 142848 ----a-w- c:\windows\system32\ieUnatt.exe

2012-08-20 04:28:02 1129472 ----a-w- c:\windows\system32\wininet.dll

2012-08-20 04:28:00 1800704 ----a-w- c:\windows\system32\jscript9.dll

2012-08-20 04:27:56 748664 ----a-w- c:\program files\internet explorer\iexplore.exe

2012-08-20 04:27:55 387584 ----a-w- c:\program files\internet explorer\jsdbgui.dll

2012-08-20 04:27:52 678912 ----a-w- c:\program files\internet explorer\iedvtool.dll

2012-08-20 04:27:49 1427968 ----a-w- c:\windows\system32\inetcpl.cpl

.

==================== Find3M ====================

.

2012-08-14 21:19:09 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-08-14 21:19:09 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2012-07-18 17:47:53 2345984 ----a-w- c:\windows\system32\win32k.sys

2012-07-04 21:14:34 41984 ----a-w- c:\windows\system32\browcli.dll

2012-07-04 21:14:34 102912 ----a-w- c:\windows\system32\browser.dll

.

============= FINISH: 21:58:00.85 ===============

Link to post
Share on other sites

Hello Ezra! My name is Maniac and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.

Please post your Attach.txt content.

Link to post
Share on other sites

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2011-08-26.01)

.

Microsoft Windows 7 Starter

Boot Device: \Device\HarddiskVolume2

Install Date: 7/30/2011 6:35:04 PM

System Uptime: 9/13/2012 9:37:19 AM (60 hours ago)

.

Motherboard: Gateway | | SJE06_PT

Processor: Intel® Atom CPU N455 @ 1.66GHz | CPU | 1666/667mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 220 GiB total, 142.03 GiB free.

.

==== Disabled Device Manager Items =============

.

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}

Description: Realtek PCIe FE Family Controller

Device ID: PCI\VEN_10EC&DEV_8136&SUBSYS_058F1025&REV_05\4&5183B94&0&00E0

Manufacturer: Realtek

Name: Realtek PCIe FE Family Controller

PNP Device ID: PCI\VEN_10EC&DEV_8136&SUBSYS_058F1025&REV_05\4&5183B94&0&00E0

Service: RTL8167

.

==== System Restore Points ===================

.

.

==== Installed Programs ======================

.

Acrobat.com

Adobe AIR

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Reader 9.1 MUI

AIM 7

Apple Application Support

Apple Mobile Device Support

Apple Software Update

Best Buy pc app

Bing Bar

Bonjour

Complément Messenger

Contrôle ActiveX Windows Live Mesh pour connexions à distance

D3DX10

Download Updater (AOL LLC)

Dual-Core Optimizer

Facebook Video Calling 1.2.0.159

Galerie de photos Windows Live

Gateway Power Management

Gateway Recovery Management

Gateway Registration

Gateway ScreenSaver

Gateway Social Networks

Gateway Updater

Google Chrome

Google SketchUp 8

Google Talk Plugin

iCloud

Identity Card

Intel® Control Center

Intel® Graphics Media Accelerator Driver

Intel® Rapid Storage Technology

iTunes

Java Auto Updater

Java 6 Update 26

Java 6 Update 31

Java 7 Update 4

JavaFX 2.1.0

join.me

Junk Mail filter update

Launch Manager

Livestream Procaster

Malwarebytes Anti-Malware version 1.62.0.1300

ManyCam 2.6.55 (remove only)

Mesh Runtime

Messenger Companion

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Extended

Microsoft Application Error Reporting

Microsoft Office 2010

Microsoft Office Click-to-Run 2010

Microsoft Office Starter 2010 - English

Microsoft Silverlight

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2005 Redistributable - KB2467175

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319

Microsoft XNA Framework Redistributable 4.0

Moonbase Alpha

Mozilla Firefox 13.0.1 (x86 en-US)

Mozilla Maintenance Service

MSVCRT

Nintendo_History_ScreenSaver

Norton Internet Security

NVIDIA PhysX v8.10.29

Oceanis Change Background Windows 7

Pidgin

Poker Night at the Inventory

Portal

Project64 1.6

Reactants, Products and Leftovers

Realtek Ethernet Controller Driver

Realtek High Definition Audio Driver

Realtek PCIE Card Reader

Roblox for Ezra

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Skype Click to Call

Skype™ 5.9

Spiral Knights

Spotify

Steam

Synaptics Pointing Device Driver

Team Fortress 2

Terraria

TrackMania Nations Forever

Unity Web Player

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

Video Web Camera

Welcome Center

Windows Live

Windows Live Communications Platform

Windows Live Essentials

Windows Live Family Safety

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Mail

Windows Live Mesh

Windows Live Mesh ActiveX Control for Remote Connections

Windows Live Messenger

Windows Live Messenger Companion Core

Windows Live MIME IFilter

Windows Live Movie Maker

Windows Live Photo Common

Windows Live Photo Gallery

Windows Live PIMT Platform

Windows Live Remote Client

Windows Live Remote Client Resources

Windows Live Remote Service

Windows Live Remote Service Resources

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

WinRAR 4.01 (32-bit)

XSplit

Yahoo! Detect

Yahoo! Messenger

.

==== Event Viewer Messages From Past Week ========

.

9/9/2012 5:19:43 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AudioEndpointBuilder service.

9/9/2012 5:19:26 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the NIS service.

9/9/2012 2:43:24 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the eventlog service.

9/8/2012 3:39:16 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.

9/8/2012 3:39:16 AM, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

9/15/2012 6:18:42 PM, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: %%-2147024891

9/15/2012 6:18:42 PM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: %%-2147024891

9/15/2012 6:18:05 PM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: After starting, the service hung in a start-pending state.

9/15/2012 6:18:02 PM, Error: Service Control Manager [7022] - The Function Discovery Resource Publication service hung on starting.

9/15/2012 5:00:20 AM, Error: Schannel [36888] - The following fatal alert was generated: 10. The internal error state is 10.

9/14/2012 5:41:45 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.

9/14/2012 3:45:05 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.

9/12/2012 9:28:16 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom

9/12/2012 9:27:55 PM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

9/12/2012 9:27:55 PM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

9/12/2012 9:27:52 PM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

9/12/2012 9:19:27 PM, Error: Microsoft Antimalware [1119] -

9/12/2012 9:18:27 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}

9/12/2012 9:18:25 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.

9/12/2012 9:18:25 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

9/12/2012 9:18:20 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}

9/12/2012 9:18:20 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}

9/12/2012 9:18:19 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

9/12/2012 9:18:05 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}

9/12/2012 9:17:49 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD BHDrvx86 cdrom DfsC discache eeCtrl IDSVix86 MpFilter NetBIOS NetBT nsiproxy Psched rdbss spldr SRTSPX SymIRON SymNetS tdx vwififlt Wanarpv6 WfpLwf

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The Client Virtualization Handler service depends on the Application Virtualization Client service which failed to start because of the following error: The dependency service or group failed to start.

9/12/2012 9:15:17 PM, Error: Service Control Manager [7023] - The iPod Service service terminated with the following error: %%-2147417831

9/12/2012 8:38:17 PM, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.

9/12/2012 8:30:05 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

9/12/2012 8:30:05 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}

9/12/2012 8:30:03 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.

9/12/2012 8:29:18 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Client Virtualization Handler service to connect.

9/12/2012 8:29:18 PM, Error: Service Control Manager [7000] - The Client Virtualization Handler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

9/10/2012 8:12:56 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Error Reporting Service service to connect.

9/10/2012 7:47:26 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Intel® Rapid Storage Technology service to connect.

9/10/2012 7:47:26 PM, Error: Service Control Manager [7000] - The Intel® Rapid Storage Technology service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

.

==== End Of File ===========================

Link to post
Share on other sites

Step 1

  • Launch Malwarebytes' Anti-Malware
  • Go to Update tab and select Check for Updates. If an update is found, it will download and install the latest version.
  • Go to Scanner tab and select Perform Quick Scan, then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer,please do so immediately.

Step 2

Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan

aswMBR2-1.gif

On completion of the scan click save log, save it to your desktop and post in your next reply

aswMBR2.png

In your next reply, post the following log files:

  • Malwarebytes' Anti-Malware log
  • aswMBR log
  • a new fresh DDS Log

Link to post
Share on other sites

I think that's all the things you asked to send.

Malwarebytes Anti-Malware 1.65.0.1400

www.malwarebytes.org

Database version: v2012.09.17.07

Windows 7 Service Pack 1 x86 NTFS

Internet Explorer 9.0.8112.16421

Ezra :: EZRAS-PC [administrator]

Protection: Enabled

9/17/2012 11:12:54 AM

mbam-log-2012-09-17 (11-12-54).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 205391

Time elapsed: 38 minute(s), 52 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 1

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|napat (Trojan.RedirRdll2.Gen) -> Data: rundll32.exe "C:\Users\Ezra\AppData\Roaming\napat.dll",StreamSubStringMatch -> Quarantined and deleted successfully.

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 6

C:\Windows\assembly\GAC\Desktop.ini (Trojan.0access) -> Delete on reboot.

C:\Windows\Installer\{3fd07168-5676-e625-2677-3186ba1e234d}\U\00000004.@ (Rootkit.Zaccess) -> Quarantined and deleted successfully.

C:\Windows\Installer\{3fd07168-5676-e625-2677-3186ba1e234d}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Quarantined and deleted successfully.

C:\Windows\Installer\{3fd07168-5676-e625-2677-3186ba1e234d}\U\000000cb.@ (Rootkit.0Access) -> Quarantined and deleted successfully.

C:\Windows\Installer\{3fd07168-5676-e625-2677-3186ba1e234d}\U\80000000.@ (Trojan.Small) -> Quarantined and deleted successfully.

C:\Users\Ezra\AppData\Roaming\napat.dll (Trojan.RedirRdll2.Gen) -> Quarantined and deleted successfully.

(end)

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software

Run date: 2012-09-17 12:04:47

-----------------------------

12:04:47.301 OS Version: Windows 6.1.7601 Service Pack 1

12:04:47.301 Number of processors: 2 586 0x1C0A

12:04:47.313 ComputerName: EZRAS-PC UserName: Ezra

12:05:27.130 Initialize success

12:06:01.097 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0

12:06:01.111 Disk 0 Vendor: WDC_WD25 01.0 Size: 238475MB BusType: 3

12:06:01.141 Disk 0 MBR read successfully

12:06:01.155 Disk 0 MBR scan

12:06:01.172 Disk 0 Windows 7 default MBR code

12:06:01.198 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 13312 MB offset 2048

12:06:01.239 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 27265024

12:06:01.279 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 225061 MB offset 27469824

12:06:01.304 Disk 0 scanning sectors +488394752

12:06:01.427 Disk 0 scanning C:\Windows\system32\drivers

12:06:17.782 Service scanning

12:07:29.043 Modules scanning

12:07:57.401 Disk 0 trace - called modules:

12:07:57.468 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys

12:07:57.512 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8644a648]

12:07:57.551 3 CLASSPNP.SYS[883d759e] -> nt!IofCallDriver -> [0x84d4d428]

12:07:57.586 5 ACPI.sys[880a83d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x84d62028]

12:07:57.623 Scan finished successfully

12:08:09.147 Disk 0 MBR has been saved successfully to "C:\Users\Ezra\Downloads\MBR.dat"

12:08:09.179 The log file has been saved successfully to "C:\Users\Ezra\Downloads\aswMBR.txt"

.

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.4.1

Run by Ezra at 12:15:31 on 2012-09-17

Microsoft Windows 7 Starter 6.1.7601.1.1252.1.1033.18.2036.624 [GMT -4:00]

.

AV: Norton Internet Security *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Norton Internet Security *Disabled/Outdated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Oceanis\SystemSetting\WallPaperAgent.exe

C:\Windows\system32\svchost.exe -k bthsvcs

C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\Launch Manager\dsiwmis.exe

C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe

C:\Program Files\Launch Manager\LMworker.exe

C:\Program Files\Launch Manager\LMutilps32.exe

C:\Program Files\Gateway\Registration\GREGsvc.exe

C:\Windows\system32\svchost.exe -k bthaudiosvc

C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe

C:\Windows\Explorer.exe

C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe

C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe

C:\Program Files\Microsoft\BingBar\SeaPort.EXE

C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files\Norton Internet Security\Engine\18.7.2.3\hsplayer.exe

C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Launch Manager\LManager.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\ManyCam\Bin\ManyCam.exe

C:\Program Files\Steam\Steam.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Users\Ezra\AppData\Roaming\Spotify\spotify.exe

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Users\Ezra\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe

C:\Windows\system32\igfxext.exe

C:\Windows\System32\rundll32.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files\Common Files\Steam\SteamService.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Pidgin\pidgin.exe

C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Users\Ezra\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Ezra\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Ezra\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Ezra\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Ezra\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Ezra\AppData\Local\Google\Chrome\Application\chrome.exe

"C:\Windows\System32\svchost.exe" -k LocalServiceDns

C:\Windows\system32\taskeng.exe

C:\Windows\system32\notepad.exe

C:\Users\Ezra\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\wbem\wmiprvse.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.bing.com/?pc=MAGW

uDefault_Page_URL = hxxp://www.bing.com/?pc=MAGW

mDefault_Page_URL = hxxp://www.bing.com/?pc=MAGW

mStart Page = hxxp://www.bing.com/?pc=MAGW

uInternet Settings,ProxyOverride = *.local

uWinlogon: Shell=c:\program files\oceanis\systemsetting\WallPaperAgent.exe

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\18.7.2.3\coIEPlg.dll

BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\18.7.2.3\ips\IPSBHO.DLL

BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll

BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"

BHO: Windows 7 Starter Helper: {d381ff29-7cfb-4d4e-b92a-c4eddc696614} - c:\program files\oceanis\systemsetting\StarterHelper.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll

TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\18.7.2.3\coIEPlg.dll

TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"

uRun: [Google Update] "c:\users\ezra\appdata\local\google\update\GoogleUpdate.exe" /c

uRun: [ManyCam] "c:\program files\manycam\bin\ManyCam.exe" /silent

uRun: [steam] "c:\program files\steam\steam.exe" -silent

uRun: [Facebook Update] "c:\users\ezra\appdata\local\facebook\update\FacebookUpdate.exe" /c /nocrashserver

uRun: [chromium] c:\users\ezra\appdata\local\google\chrome\application\chrome.exe --no-startup-window

uRun: [c:\users\ezra\downloads\livestreamprocaster.exe] c:\users\ezra\downloads\LivestreamProcaster.exe /exenoupdates /exelang 0 /prereqs "0"

uRun: [spotify] "c:\users\ezra\appdata\roaming\spotify\Spotify.exe" /uri spotify:autostart

uRun: [spotify Web Helper] "c:\users\ezra\appdata\roaming\spotify\data\SpotifyWebHelper.exe"

uRun: [phexp] "c:\windows\system32\rundll32.exe" "c:\users\ezra\appdata\roaming\phexp.dll",get_copyright

mRun: [iAStorIcon] c:\program files\intel\intel® rapid storage technology\IAStorIcon.exe

mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [igfxTray] c:\windows\system32\igfxtray.exe

mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe

mRun: [Persistence] c:\windows\system32\igfxpers.exe

mRun: [LManager] c:\program files\launch manager\LManager.exe

mRun: [synTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe

mRun: [Power Management] c:\program files\gateway\gateway power management\ePowerTray.exe

mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"

mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [amd_dc_opt] c:\program files\amd\dual-core optimizer\amd_dc_opt.exe

mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

LSP: mswsock.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

TCP: DhcpNameServer = 75.75.75.75 75.75.76.76

TCP: Interfaces\{4FFE7118-9BE0-4D45-BD54-524FA01283CB} : DhcpNameServer = 75.75.75.75 75.75.76.76

TCP: Interfaces\{D62790A9-D08B-4F0C-A8BF-9926DD11B809} : DhcpNameServer = 75.75.75.75 75.75.76.76

TCP: Interfaces\{D62790A9-D08B-4F0C-A8BF-9926DD11B809}\3736861647A796 : DhcpNameServer = 192.168.1.1

TCP: Interfaces\{D62790A9-D08B-4F0C-A8BF-9926DD11B809}\37C616577686475627 : DhcpNameServer = 192.168.2.1

TCP: Interfaces\{D62790A9-D08B-4F0C-A8BF-9926DD11B809}\44F6E647573756D69777966696 : DhcpNameServer = 192.168.1.1

TCP: Interfaces\{D62790A9-D08B-4F0C-A8BF-9926DD11B809}\E6564777F627B693 : DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll

Notify: igfxcui - igfxdev.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\users\ezra\appdata\roaming\mozilla\firefox\profiles\tgvm9fe1.default\

FF - plugin: c:\progra~1\mif5ba~1\office14\NPSPWRAP.DLL

FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll

FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll

FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll

FF - plugin: c:\programdata\best buy pc app\npBestBuyPcAppDetector.dll

FF - plugin: c:\users\ezra\appdata\local\facebook\video\skype\npFacebookVideoCalling.dll

FF - plugin: c:\users\ezra\appdata\local\google\update\1.3.21.115\npGoogleUpdate3.dll

FF - plugin: c:\users\ezra\appdata\local\roblox\versions\version-684ac714abb74f38\NPRobloxProxy.dll

FF - plugin: c:\users\ezra\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll

FF - plugin: c:\users\ezra\appdata\roaming\mozilla\plugins\npgoogletalk.dll

FF - plugin: c:\users\ezra\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll

FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_265.dll

FF - plugin: c:\windows\system32\npDeployJava1.dll

FF - plugin: c:\windows\system32\npmproxy.dll

.

============= SERVICES / DRIVERS ===============

.

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nis\1207020.003\symds.sys [2012-6-11 340088]

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1207020.003\symefa.sys [2012-6-11 744568]

R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_18.1.0.37\definitions\bashdefs\20110920.001\BHDrvx86.sys [2011-9-26 816760]

R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_18.1.0.37\definitions\ipsdefs\20110928.030\IDSvix86.sys [2011-9-28 368248]

R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nis\1207020.003\ironx86.sys [2012-6-11 136312]

R1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\nis\1207020.003\symnets.sys [2012-6-11 299640]

R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]

R2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2012-1-4 822624]

R2 DsiWMIService;Dritek WMI Service;c:\program files\launch manager\dsiwmis.exe [2011-4-18 352336]

R2 ePowerSvc;Acer ePower Service;c:\program files\gateway\gateway power management\ePowerSvc.exe [2011-5-12 739944]

R2 GREGService;GREGService;c:\program files\gateway\registration\GREGsvc.exe [2010-1-8 23584]

R2 HFGService;Handsfree Headset Service;c:\windows\system32\svchost.exe -k bthaudiosvc [2009-7-13 20992]

R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\intel\intel® rapid storage technology\IAStorDataMgrSvc.exe [2011-4-18 13336]

R2 IconMan_R;IconMan_R;c:\program files\realtek\realtek pcie card reader\RIconMan.exe [2011-4-18 1751656]

R2 Live Updater Service;Live Updater Service;c:\program files\gateway\gateway updater\UpdaterService.exe [2011-4-18 244624]

R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-9-10 655944]

R2 NIS;Norton Internet Security;c:\program files\norton internet security\engine\18.7.2.3\ccsvchst.exe [2012-6-11 130008]

R2 sftlist;Application Virtualization Client;c:\program files\microsoft application virtualization client\sftlist.exe [2011-10-1 508776]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-7-31 105592]

R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2008-1-14 21632]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-8-20 22344]

R3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\drivers\RtsPStor.sys [2011-4-18 250984]

R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2011-10-1 579944]

R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2011-10-1 194408]

R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2011-10-1 21864]

R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2011-10-1 19304]

R3 sftvsa;Application Virtualization Service Agent;c:\program files\microsoft application virtualization client\sftvsa.exe [2011-10-1 219496]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-5-3 158856]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-6-26 250056]

S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]

S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-3-2 183560]

S3 BthAudioHF;BthAudioHF Service;c:\windows\system32\drivers\BthAudioHF.sys [2009-12-21 43008]

S3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\drivers\BthAvrcp.sys [2009-8-13 22528]

S3 csr_a2dp;Bluetooth AV Profile;c:\windows\system32\drivers\bthav.sys [2009-12-21 61952]

S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2012-6-27 39272]

S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840]

S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-7-11 113120]

S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-4-18 327784]

S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224]

S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]

S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]

.

=============== Created Last 30 ================

.

2012-09-17 05:42:00 -------- d-----w- c:\users\ezra\appdata\local\{D040F1BB-1D57-45E5-BF36-326CD3DBAA2F}

2012-09-16 17:41:48 -------- d-----w- c:\users\ezra\appdata\local\{5274892B-3C96-4AF7-8987-EA1C626772E4}

2012-09-16 05:41:37 -------- d-----w- c:\users\ezra\appdata\local\{F81E6447-74CF-4703-9D82-3ABB33A4A702}

2012-09-15 17:41:14 -------- d-----w- c:\users\ezra\appdata\local\{291E54C4-7177-4B0B-9A4A-01428308D0AE}

2012-09-15 02:35:25 -------- d-----w- c:\users\ezra\appdata\local\{26801BEC-90E7-44D0-BC64-9EA4059B63EF}

2012-09-14 02:35:03 -------- d-----w- c:\users\ezra\appdata\local\{DC3B1FDF-D6EA-4146-9057-E03B2D382432}

2012-09-13 00:19:54 -------- d-----w- c:\program files\Microsoft Security Client

2012-09-10 01:50:33 -------- d-----w- c:\users\ezra\appdata\local\{52FAF193-5BA0-46AA-B9FE-DB5A22993B66}

2012-09-09 13:50:19 -------- d-----w- c:\users\ezra\appdata\local\{9B999E00-6F44-4333-9F3F-6C6D60106610}

2012-09-09 01:50:05 -------- d-----w- c:\users\ezra\appdata\local\{5FE7C98B-815C-4F1E-A70C-3E87BDC1504B}

2012-09-08 13:49:37 -------- d-----w- c:\users\ezra\appdata\local\{31FFA18D-7D17-4087-9F57-9FAFD14BC82B}

2012-09-08 01:49:18 -------- d-----w- c:\users\ezra\appdata\local\{92DC56B1-3CFC-46BF-8634-7C6929B19B34}

2012-09-07 10:24:30 -------- d-----w- c:\users\ezra\appdata\local\{4CE1E0E4-E51D-4641-A0DE-BCB2044A77C7}

2012-09-06 22:24:19 -------- d-----w- c:\users\ezra\appdata\local\{6D0AF75A-9892-4F29-A939-F037D10099C7}

2012-09-06 10:24:08 -------- d-----w- c:\users\ezra\appdata\local\{58EF7FC2-B9A0-4330-9B7E-10ADFF3857A4}

2012-09-05 22:23:57 -------- d-----w- c:\users\ezra\appdata\local\{E9EE8997-CE4B-4A46-A26F-CEBD34B2592A}

2012-09-05 10:23:46 -------- d-----w- c:\users\ezra\appdata\local\{794B92AB-A317-4E77-B28D-56F138D622E0}

2012-09-04 22:23:35 -------- d-----w- c:\users\ezra\appdata\local\{E33F83DD-62CF-4084-A817-9C0952E9551B}

2012-09-04 10:23:24 -------- d-----w- c:\users\ezra\appdata\local\{F57878D7-B3E8-4D60-83B1-EC00377374C8}

2012-09-03 22:23:13 -------- d-----w- c:\users\ezra\appdata\local\{671B3AF7-43EB-4892-8C25-C6324A6D34E7}

2012-09-03 10:23:01 -------- d-----w- c:\users\ezra\appdata\local\{2727C25B-CFDD-4531-9A47-22F48BADF920}

2012-09-02 22:22:50 -------- d-----w- c:\users\ezra\appdata\local\{8183E3ED-F5CB-4BED-8832-16522B067140}

2012-09-02 10:22:38 -------- d-----w- c:\users\ezra\appdata\local\{28C34163-E948-4BAA-9261-CCCD55C646CD}

2012-09-01 22:21:56 -------- d-----w- c:\users\ezra\appdata\local\{F73B4DF0-B803-4E75-B2C4-9265FA8ACD4C}

2012-08-31 09:39:56 -------- d-----w- c:\users\ezra\appdata\local\{E8B61C71-3CE6-4F4F-9358-AC733CEA1EFA}

2012-08-30 21:39:44 -------- d-----w- c:\users\ezra\appdata\local\{8AC71A78-CD07-4A57-B824-8B2C1F275465}

2012-08-30 09:39:32 -------- d-----w- c:\users\ezra\appdata\local\{CC4A3E93-F69F-4D31-B5BC-22FB00E52744}

2012-08-29 21:38:58 -------- d-----w- c:\users\ezra\appdata\local\{92DA15C8-3E4A-4B10-B8CE-62464AE922C5}

2012-08-29 09:38:47 -------- d-----w- c:\users\ezra\appdata\local\{4ABA01D4-1609-4EE3-932A-55B2336D2EB5}

2012-08-28 21:38:37 -------- d-----w- c:\users\ezra\appdata\local\{4E652D62-0C6B-487F-A056-38976C19364F}

2012-08-28 09:38:25 -------- d-----w- c:\users\ezra\appdata\local\{3459167F-7D89-42C2-84A4-6A6B5EBBB274}

2012-08-27 21:37:23 -------- d-----w- c:\users\ezra\appdata\local\{E1FF171E-CF22-44DA-9C88-CDB6514AED82}

2012-08-27 09:37:08 -------- d-----w- c:\users\ezra\appdata\local\{0DCDF5AF-B7D0-401B-A603-A390C73BFDDA}

2012-08-26 17:12:18 -------- d-----w- c:\users\ezra\appdata\local\{43D1DAE9-A60A-4931-98C2-22BA247ED96D}

2012-08-26 05:12:04 -------- d-----w- c:\users\ezra\appdata\local\{5A31CE6B-D06D-4193-BE0A-BF798406B9FB}

2012-08-25 17:11:51 -------- d-----w- c:\users\ezra\appdata\local\{4FF96460-462D-4A4E-BC02-FB4AE2947CD9}

2012-08-25 05:11:39 -------- d-----w- c:\users\ezra\appdata\local\{288189CD-1886-4B6D-B93D-9596BB0E8A9B}

2012-08-24 17:11:28 -------- d-----w- c:\users\ezra\appdata\local\{C67C51E1-F619-4345-87CE-D58CF1CA75B3}

2012-08-24 05:11:17 -------- d-----w- c:\users\ezra\appdata\local\{555AA932-C702-472F-B2C4-20A5EC096BE3}

2012-08-23 17:11:06 -------- d-----w- c:\users\ezra\appdata\local\{74F3D0E7-329B-4C4E-BAB3-6B60977EF1AC}

2012-08-23 05:10:40 -------- d-----w- c:\users\ezra\appdata\local\{287974BD-39B8-4E6A-9B60-0B1CFD7A9B1E}

2012-08-22 17:10:29 -------- d-----w- c:\users\ezra\appdata\local\{CFA75570-8A3D-4732-82DE-5D3B2D06903E}

2012-08-22 05:10:14 -------- d-----w- c:\users\ezra\appdata\local\{CFFB1B20-8050-42EF-843C-DAF34F1D6CB5}

2012-08-21 17:10:00 -------- d-----w- c:\users\ezra\appdata\local\{6B5DD27D-04D2-4353-A5E5-FCF3454E0D4A}

2012-08-21 05:09:38 -------- d-----w- c:\users\ezra\appdata\local\{E08EA2F1-DDD4-4FC6-8EF9-0E046B43AA11}

2012-08-20 21:23:16 -------- d-----w- c:\users\ezra\appdata\roaming\Malwarebytes

2012-08-20 21:22:58 -------- d-----w- c:\programdata\Malwarebytes

2012-08-20 21:22:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-08-20 21:22:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2012-08-20 20:16:57 -------- d-----w- c:\users\ezra\appdata\local\Symantec

2012-08-20 20:05:16 -------- d-sh--w- c:\windows\system32\%APPDATA%

2012-08-20 19:53:03 -------- d-----w- c:\users\ezra\appdata\local\{8F8A7BC8-EB00-11E1-8270-B8AC6F996F26}

2012-08-20 19:52:24 440320 ----a-w- c:\users\ezra\appdata\roaming\phexp.dll

2012-08-20 19:50:45 -------- d-----w- c:\users\ezra\appdata\roaming\xsecva

2012-08-20 17:09:11 -------- d-----w- c:\users\ezra\appdata\local\{FD25C1C9-249E-4334-A695-06A0EC2DC023}

2012-08-20 09:36:26 6891424 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{5ca800d4-3ff6-4de9-979c-4bd998957685}\mpengine.dll

2012-08-20 04:49:19 -------- d-----w- c:\users\ezra\appdata\local\{6B339CBA-6E85-4402-94BC-CAB898342B9B}

2012-08-20 04:34:17 393728 ----a-w- c:\windows\system32\drivers\bthport.sys

2012-08-20 04:28:18 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-08-20 04:28:13 140920 ----a-w- c:\program files\internet explorer\sqmapi.dll

2012-08-20 04:28:12 194560 ----a-w- c:\program files\internet explorer\ieproxy.dll

2012-08-20 04:28:10 194048 ----a-w- c:\program files\internet explorer\IEShims.dll

2012-08-20 04:28:06 142848 ----a-w- c:\windows\system32\ieUnatt.exe

2012-08-20 04:28:02 1129472 ----a-w- c:\windows\system32\wininet.dll

2012-08-20 04:28:00 1800704 ----a-w- c:\windows\system32\jscript9.dll

2012-08-20 04:27:56 748664 ----a-w- c:\program files\internet explorer\iexplore.exe

2012-08-20 04:27:55 387584 ----a-w- c:\program files\internet explorer\jsdbgui.dll

2012-08-20 04:27:52 678912 ----a-w- c:\program files\internet explorer\iedvtool.dll

2012-08-20 04:27:49 1427968 ----a-w- c:\windows\system32\inetcpl.cpl

.

==================== Find3M ====================

.

2012-08-14 21:19:09 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-08-14 21:19:09 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2012-07-18 17:47:53 2345984 ----a-w- c:\windows\system32\win32k.sys

2012-07-04 21:14:34 41984 ----a-w- c:\windows\system32\browcli.dll

2012-07-04 21:14:34 102912 ----a-w- c:\windows\system32\browser.dll

.

============= FINISH: 12:20:14.75 ===============

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2011-08-26.01)

.

Microsoft Windows 7 Starter

Boot Device: \Device\HarddiskVolume2

Install Date: 7/30/2011 6:35:04 PM

System Uptime: 9/17/2012 11:56:49 AM (1 hours ago)

.

Motherboard: Gateway | | SJE06_PT

Processor: Intel® Atom CPU N455 @ 1.66GHz | CPU | 1666/667mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 220 GiB total, 141.382 GiB free.

.

==== Disabled Device Manager Items =============

.

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}

Description: Realtek PCIe FE Family Controller

Device ID: PCI\VEN_10EC&DEV_8136&SUBSYS_058F1025&REV_05\4&5183B94&0&00E0

Manufacturer: Realtek

Name: Realtek PCIe FE Family Controller

PNP Device ID: PCI\VEN_10EC&DEV_8136&SUBSYS_058F1025&REV_05\4&5183B94&0&00E0

Service: RTL8167

.

==== System Restore Points ===================

.

RP123: 8/3/2012 4:39:59 PM - Windows Update

RP124: 8/7/2012 5:28:18 AM - Windows Update

RP125: 8/14/2012 10:36:13 AM - Windows Update

RP126: 8/20/2012 12:22:33 AM - Windows Update

RP128: 9/10/2012 12:21:16 AM - Installed DirectX

.

==== Installed Programs ======================

.

Acrobat.com

Adobe AIR

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Reader 9.1 MUI

AIM 7

Apple Application Support

Apple Mobile Device Support

Apple Software Update

Best Buy pc app

Bing Bar

Bonjour

Complément Messenger

Contrôle ActiveX Windows Live Mesh pour connexions à distance

D3DX10

Download Updater (AOL LLC)

Dual-Core Optimizer

Facebook Video Calling 1.2.0.159

Galerie de photos Windows Live

Gateway Power Management

Gateway Recovery Management

Gateway Registration

Gateway ScreenSaver

Gateway Social Networks

Gateway Updater

Google Chrome

Google SketchUp 8

Google Talk Plugin

iCloud

Identity Card

Intel® Control Center

Intel® Graphics Media Accelerator Driver

Intel® Rapid Storage Technology

iTunes

Java Auto Updater

Java 6 Update 26

Java 6 Update 31

Java 7 Update 4

JavaFX 2.1.0

join.me

Junk Mail filter update

Launch Manager

Livestream Procaster

Malwarebytes Anti-Malware version 1.62.0.1300

ManyCam 2.6.55 (remove only)

Mesh Runtime

Messenger Companion

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Extended

Microsoft Application Error Reporting

Microsoft Office 2010

Microsoft Office Click-to-Run 2010

Microsoft Office Starter 2010 - English

Microsoft Silverlight

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2005 Redistributable - KB2467175

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319

Microsoft XNA Framework Redistributable 4.0

Moonbase Alpha

Mozilla Firefox 13.0.1 (x86 en-US)

Mozilla Maintenance Service

MSVCRT

Nintendo_History_ScreenSaver

Norton Internet Security

NVIDIA PhysX v8.10.29

Oceanis Change Background Windows 7

Pidgin

Poker Night at the Inventory

Portal

Project64 1.6

Reactants, Products and Leftovers

Realtek Ethernet Controller Driver

Realtek High Definition Audio Driver

Realtek PCIE Card Reader

Roblox for Ezra

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Skype Click to Call

Skype™ 5.9

Spiral Knights

Spotify

Steam

Synaptics Pointing Device Driver

Team Fortress 2

Terraria

TrackMania Nations Forever

Unity Web Player

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

Video Web Camera

Welcome Center

Windows Live

Windows Live Communications Platform

Windows Live Essentials

Windows Live Family Safety

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Mail

Windows Live Mesh

Windows Live Mesh ActiveX Control for Remote Connections

Windows Live Messenger

Windows Live Messenger Companion Core

Windows Live MIME IFilter

Windows Live Movie Maker

Windows Live Photo Common

Windows Live Photo Gallery

Windows Live PIMT Platform

Windows Live Remote Client

Windows Live Remote Client Resources

Windows Live Remote Service

Windows Live Remote Service Resources

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

WinRAR 4.01 (32-bit)

XSplit

Yahoo! Detect

Yahoo! Messenger

.

==== Event Viewer Messages From Past Week ========

.

9/17/2012 12:05:07 AM, Error: Schannel [36888] - The following fatal alert was generated: 10. The internal error state is 10.

9/17/2012 11:58:04 AM, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: %%-2147024891

9/17/2012 11:58:04 AM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: %%-2147024891

9/17/2012 11:57:41 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom

9/17/2012 11:57:25 AM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

9/17/2012 11:57:24 AM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

9/17/2012 11:57:22 AM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

9/15/2012 6:18:05 PM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: After starting, the service hung in a start-pending state.

9/15/2012 6:18:02 PM, Error: Service Control Manager [7022] - The Function Discovery Resource Publication service hung on starting.

9/14/2012 5:41:45 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.

9/14/2012 3:45:05 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.

9/12/2012 9:19:27 PM, Error: Microsoft Antimalware [1119] -

9/12/2012 9:18:27 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}

9/12/2012 9:18:25 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.

9/12/2012 9:18:25 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

9/12/2012 9:18:20 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}

9/12/2012 9:18:20 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}

9/12/2012 9:18:19 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

9/12/2012 9:18:05 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}

9/12/2012 9:17:49 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD BHDrvx86 cdrom DfsC discache eeCtrl IDSVix86 MpFilter NetBIOS NetBT nsiproxy Psched rdbss spldr SRTSPX SymIRON SymNetS tdx vwififlt Wanarpv6 WfpLwf

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.

9/12/2012 9:17:49 PM, Error: Service Control Manager [7001] - The Client Virtualization Handler service depends on the Application Virtualization Client service which failed to start because of the following error: The dependency service or group failed to start.

9/12/2012 9:15:17 PM, Error: Service Control Manager [7023] - The iPod Service service terminated with the following error: %%-2147417831

9/12/2012 8:38:17 PM, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.

9/12/2012 8:30:05 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

9/12/2012 8:30:05 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}

9/12/2012 8:30:03 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.

9/12/2012 8:29:18 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Client Virtualization Handler service to connect.

9/12/2012 8:29:18 PM, Error: Service Control Manager [7000] - The Client Virtualization Handler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

9/10/2012 8:12:56 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Error Reporting Service service to connect.

9/10/2012 7:47:26 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Intel® Rapid Storage Technology service to connect.

9/10/2012 7:47:26 PM, Error: Service Control Manager [7000] - The Intel® Rapid Storage Technology service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

.

==== End Of File ===========================

Link to post
Share on other sites

BACKDOOR WARNING

One or more of the identified infections is known to use a backdoor.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would advice you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the infection has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

Help: I Got Hacked. Now What Do I Do?

Help: I Got Hacked. Now What Do I Do? Part II

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you decide to go through with the cleanup, please proceed with the following steps.

Please download the latest version of TDSSKiller from here and save it to your Desktop.

  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
    image000q.png
  • Put a checkmark beside loaded modules.
    2012081514h0118.png
  • A reboot will be needed to apply the changes. Do it.
  • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
  • Then click on Change parameters in TDSSKiller.
  • Check all boxes then click OK.
    2012081517h0349.png
  • Click the Start Scan button.
    19695967.jpg
  • The scan should take no longer than 2 minutes.
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
    67776163.jpg
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    62117367.jpg
    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
  • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.