Jump to content

Cannot seem to remove trojans from computer! Help :(

Recommended Posts

Alright I'm extremely new to this and I've been having this problem for a week and a half now. If I seem retarded I'm sorry. :(

My computer started freezing randomly awhile back, first it was just the internet freezing then it was the whole desktop. My uncle had installed Avanced Care on my computer and running that, and Avast and Malwarbytes (not at the same time mind you) Avanced Care was the only one that picked up: Trojan.Win32/dropper, trojan.win32/agent, trojan.win32/vundo and trojan.win32/tracer. I wiped the computer, reformatted it and reinstalled Windows 7, it worked fine for a few days and just now it started freezing up again. It even froze once in safe mode with networking. That's what I'm on right now and so far I'm alright.

I downloaded those files and here are the things from the notepad files:





DDS (Ver_2012-11-20.01)


Microsoft Windows 7 Home Premium

Boot Device: \Device\HarddiskVolume1

Install Date: 2/13/2013 7:26:32 PM

System Uptime: 2/19/2013 9:51:46 AM (1 hours ago)


Motherboard: TOSHIBA | | Portable PC

Processor: Intel® Core i7 CPU Q 720 @ 1.60GHz | CPU | 1600/1066mhz


==== Disk Partitions =========================


C: is FIXED (NTFS) - 443 GiB total, 357.982 GiB free.

D: is CDROM ()


==== Disabled Device Manager Items =============


Class GUID:


Device ID: ACPI\TOS1901\2&DABA3FF&1



PNP Device ID: ACPI\TOS1901\2&DABA3FF&1



Class GUID:

Description: PCI Simple Communications Controller

Device ID: PCI\VEN_8086&DEV_3B64&SUBSYS_FF1E1179&REV_06\3&11583659&0&B0


Name: PCI Simple Communications Controller

PNP Device ID: PCI\VEN_8086&DEV_3B64&SUBSYS_FF1E1179&REV_06\3&11583659&0&B0



Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}

Description: avast! Network Shield Support



Name: avast! Network Shield Support


Service: aswTdi


Class GUID:


Device ID: ACPI\TOS620A\2&DABA3FF&1






Class GUID:

Description: Base System Device

Device ID: PCI\VEN_1180&DEV_E230&SUBSYS_FF1E1179&REV_01\4&1BA2E409&0&01E3


Name: Base System Device

PNP Device ID: PCI\VEN_1180&DEV_E230&SUBSYS_FF1E1179&REV_01\4&1BA2E409&0&01E3



Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}

Description: Security Processor Loader Driver



Name: Security Processor Loader Driver


Service: spldr


Class GUID:

Description: Base System Device

Device ID: PCI\VEN_1180&DEV_E852&SUBSYS_FF1E1179&REV_01\4&1BA2E409&0&02E3


Name: Base System Device

PNP Device ID: PCI\VEN_1180&DEV_E852&SUBSYS_FF1E1179&REV_01\4&1BA2E409&0&02E3



==== System Restore Points ===================


No restore point in system.


==== Installed Programs ======================


Adobe Flash Player 11 Plugin

Advanced SystemCare 6

Apple Application Support

Apple Mobile Device Support

Apple Software Update

Applian FLV and Media Player

avast! Free Antivirus



DivX Setup

DmC Devil May Cry

Elsword version v3.0213.5.1

Google Update Helper


Java 7 Update 13

Java Auto Updater

Left 4 Dead 2


Malwarebytes Anti-Malware version

McAfee Security Scan Plus

Microsoft .NET Framework 4 Client Profile

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Mozilla Firefox 18.0.2 (x86 en-US)

Mozilla Maintenance Service

Nexon Game Manager

NVIDIA Control Panel 310.90

NVIDIA Graphics Driver 310.90

NVIDIA HD Audio Driver

NVIDIA Install Application


NVIDIA PhysX System Software 9.12.1031

Pando Media Booster

Portal 2

Realtek High Definition Audio Driver

Realtek WLAN Driver

Skype™ 6.2


The Elder Scrolls IV: Oblivion

Vampire: The Masquerade - Bloodlines

VC80CRTRedist - 8.0.50727.6195

Windows 7 Logon Background Changer


==== Event Viewer Messages From Past Week ========


2/19/2013 9:58:46 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service SkypeUpdate with arguments "/ComService" in order to run the server: {CC957078-B838-47C4-A7CF-626E7A82FC58}

2/19/2013 9:52:34 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}

2/19/2013 9:52:34 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

2/19/2013 9:52:29 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

2/19/2013 9:52:23 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}

2/19/2013 9:52:11 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: aswSnx aswSP aswTdi discache spldr Wanarpv6

2/19/2013 9:21:44 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service McComponentHostService with arguments "" in order to run the server: {CC6F4D12-8575-4CFF-9455-CF5774AEB13B}

2/19/2013 9:16:25 AM, Error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort1.

2/19/2013 9:10:29 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR3.

2/19/2013 12:47:38 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.

2/19/2013 10:15:28 AM, Error: Microsoft-Windows-Eventlog [23] - The event logging service encountered an error (res=1500) while initializing logging resources for channel Microsoft-Windows-Kernel-EventTracing/Admin.

2/19/2013 10:12:41 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}

2/19/2013 10:11:02 AM, Error: Service Control Manager [7030] - The Advanced SystemCare Service 6 service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

2/18/2013 6:10:31 PM, Error: volsnap [14] - The shadow copies of volume C: were aborted because of an IO failure on volume C:.

2/16/2013 9:34:47 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.

2/16/2013 9:34:47 PM, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

2/15/2013 12:47:58 PM, Error: Service Control Manager [7023] -

2/15/2013 12:45:45 PM, Error: Service Control Manager [7038] - The avast! Antivirus service was unable to log on as NT AUTHORITY\SYSTEM with the currently configured password due to the following error: The request is not supported. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

2/15/2013 12:45:45 PM, Error: Service Control Manager [7000] - The avast! Antivirus service failed to start due to the following error: The service did not start due to a logon failure.

2/15/2013 12:45:40 PM, Error: Service Control Manager [7031] - The avast! Antivirus service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.

2/15/2013 12:45:35 PM, Error: Service Control Manager [7034] - The Google Update Service (gupdate) service terminated unexpectedly. It has done this 1 time(s).

2/15/2013 12:45:31 PM, Error: Service Control Manager [7031] - The avast! Antivirus service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.

2/15/2013 1:04:25 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x800736cc: Security Update for Windows 7 for x64-based Systems (KB2393802).

2/13/2013 10:52:48 PM, Error: Ntfs [138] - The transaction resource manager at C:\ encountered a fatal error and was shut down. The data contains the error code.

2/13/2013 10:05:27 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Error Reporting Service service to connect.


==== End Of File ===========================

DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK

Internet Explorer: 9.0.8112.16464 BrowserJavaVersion: 10.13.2

Run by Shay at 10:48:26 on 2013-02-19

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4031.2685 [GMT -8:00]


AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


============== Running Processes ===============



C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork



C:\Windows\System32\svchost.exe -k secsvcs

C:\Program Files (x86)\Skype\Phone\Skype.exe

C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASC.exe

C:\Program Files (x86)\IObit\Advanced SystemCare 6\Monitor.exe

C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe

C:\Program Files\AVAST Software\Avast\AvastUI.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe




============== Pseudo HJT Report ===============


uStart Page = hxxp://www.google.com/

mWinlogon: Userinit = userinit.exe

BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll

BHO: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

uRun: [steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent

uRun: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe

uRun: [Advanced SystemCare 6] "C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui

mRun: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe

mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW

mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe

mPolicies-Explorer: NoActiveDesktop = dword:1

mPolicies-System: ConsentPromptBehaviorAdmin = dword:5

mPolicies-System: ConsentPromptBehaviorUser = dword:3

mPolicies-System: EnableUIADesktopToggle = dword:0

mPolicies-Windows\System: UseOEMBackground = dword:1

TCP: NameServer =

TCP: Interfaces\{D6A97D58-A2D6-4A8F-82CC-135AD64530E1} : DHCPNameServer =

TCP: Interfaces\{D6A97D58-A2D6-4A8F-82CC-135AD64530E1}\130364851323034343236353 : DHCPNameServer =

TCP: Interfaces\{D6A97D58-A2D6-4A8F-82CC-135AD64530E1}\8496464656E602348616D626562737 : DHCPNameServer =

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

SSODL: WebCheck - <orphaned>

x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll

x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll

x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s

x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>

x64-SSODL: WebCheck - <orphaned>


================= FIREFOX ===================


FF - ProfilePath - C:\Users\Shay\AppData\Roaming\Mozilla\Firefox\Profiles\lxtxtgsd.default\

FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll

FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll

FF - plugin: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll

FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

FF - plugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMSS.dll

FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

FF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_168.dll

FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll

FF - plugin: C:\Windows\SysWOW64\npmproxy.dll

FF - ExtSQL: 2013-02-13 21:47; wrc@avast.com; C:\Program Files\AVAST Software\Avast\WebRep\FF

FF - ExtSQL: 2013-02-13 22:04; {4DC70064-89E2-4a55-8FC6-E8CDEAE3618C}; C:\Users\Shay\AppData\Roaming\Mozilla\Firefox\Profiles\lxtxtgsd.default\extensions\{4DC70064-89E2-4a55-8FC6-E8CDEAE3618C}.xpi

FF - ExtSQL: 2013-02-13 22:04; anttoolbar@ant.com; C:\Users\Shay\AppData\Roaming\Mozilla\Firefox\Profiles\lxtxtgsd.default\extensions\anttoolbar@ant.com

FF - ExtSQL: 2013-02-13 22:04; adblockpopups@jessehakanen.net; C:\Users\Shay\AppData\Roaming\Mozilla\Firefox\Profiles\lxtxtgsd.default\extensions\adblockpopups@jessehakanen.net.xpi

FF - ExtSQL: 2013-02-14 09:57; {23fcfd51-4958-4f00-80a3-ae97e717ed8b}; C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5



FF - user.js: network.http.pipelining.maxrequests - 8

FF - user.js: network.http.request.max-start-delay - 0

FF - user.js: network.http.max-connections - 48

FF - user.js: network.http.max-connections-per-server - 16

FF - user.js: network.http.max-persistent-connections-per-proxy - 16

FF - user.js: network.http.max-persistent-connections-per-server - 8

FF - user.js: browser.turbo.enabled - true

FF - user.js: browser.display.show_image_placeholders - true

FF - user.js: browser.chrome.favicons - false

FF - user.js: browser.urlbar.autocomplete.enabled - true

FF - user.js: browser.cache.memory.capacity - 65536

FF - user.js: content.notify.ontimer - true

FF - user.js: content.interrupt.parsing - true

FF - user.js: content.max.tokenizing.time - 2250000

FF - user.js: content.switch.threshold - 750000

FF - user.js: plugin.expose_full_path - true

FF - user.js: ui.submenuDelay - 0


============= SERVICES / DRIVERS ===============


R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-6-10 187392]

R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;C:\Windows\System32\drivers\rtl8192se.sys [2013-2-13 946688]

S1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-2-13 984144]

S1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-2-13 370288]

S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [2013-2-19 465216]

S2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-2-13 25232]

S2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-2-13 71600]

S2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-2-13 44808]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-2-7 161384]

S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [2013-2-5 235216]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-2-16 1255736]


=============== Created Last 30 ================


2013-02-19 18:26:29 -------- d-----w- C:\Program Files\CCleaner

2013-02-19 18:19:04 -------- d-----w- C:\Users\Shay\AppData\Roaming\Malwarebytes

2013-02-19 18:18:56 -------- d-----w- C:\ProgramData\Malwarebytes

2013-02-19 18:18:55 24176 ----a-w- C:\Windows\System32\drivers\mbam.sys

2013-02-19 18:18:55 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2013-02-19 18:18:42 -------- d-----w- C:\Users\Shay\AppData\Local\Programs

2013-02-19 18:16:38 76232 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{91FE7486-52F5-4172-96B9-09D7ACC28D95}\offreg.dll

2013-02-19 18:11:01 -------- d-----w- C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}

2013-02-19 18:10:59 -------- d-----w- C:\Users\Shay\AppData\Roaming\IObit

2013-02-19 18:10:59 -------- d-----w- C:\ProgramData\IObit

2013-02-19 18:10:53 -------- d-----w- C:\Program Files (x86)\IObit

2013-02-19 17:13:33 9161176 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{91FE7486-52F5-4172-96B9-09D7ACC28D95}\mpengine.dll

2013-02-19 08:54:12 -------- d-----w- C:\Users\Shay\AppData\Local\Apple Computer

2013-02-19 08:53:52 33240 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys

2013-02-19 08:52:24 -------- d-----w- C:\Program Files\iPod

2013-02-19 08:52:20 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69

2013-02-19 08:52:20 -------- d-----w- C:\Program Files\iTunes

2013-02-19 08:52:20 -------- d-----w- C:\Program Files (x86)\iTunes

2013-02-19 08:50:39 -------- d-----w- C:\Users\Shay\AppData\Local\Apple

2013-02-19 08:49:44 -------- d-----w- C:\Program Files\Bonjour

2013-02-19 08:49:44 -------- d-----w- C:\Program Files (x86)\Bonjour

2013-02-18 17:25:18 -------- d-----w- C:\Users\Shay\AppData\Roaming\Applian FLV and Media Player

2013-02-17 11:00:41 768000 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll

2013-02-17 11:00:40 996352 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll

2013-02-16 11:21:51 -------- d-----w- C:\Windows\SysWow64\Wat

2013-02-16 11:21:51 -------- d-----w- C:\Windows\System32\Wat

2013-02-16 01:20:25 -------- d-----w- C:\Windows\SysWow64\RTCOM

2013-02-16 01:19:19 831488 ----a-w- C:\Windows\RtlExUpd.dll

2013-02-16 01:19:19 -------- d--h--w- C:\Program Files (x86)\Temp

2013-02-16 01:19:16 757760 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll

2013-02-16 01:19:16 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll

2013-02-16 01:19:16 65024 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe

2013-02-16 01:19:16 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe

2013-02-16 01:19:16 32768 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll

2013-02-16 01:19:16 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll

2013-02-16 01:19:16 204800 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll

2013-02-16 01:19:15 331908 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll

2013-02-16 01:19:15 200836 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll

2013-02-16 01:01:09 319456 ----a-w- C:\Windows\DIFxAPI.dll

2013-02-16 01:01:07 8 ----a-w- C:\Windows\SysWow64\drivers\RtkHDAud.dat

2013-02-16 01:01:07 176 ----a-w- C:\Windows\SysWow64\drivers\RTHDAEQ1.dat

2013-02-16 01:01:07 176 ----a-w- C:\Windows\SysWow64\drivers\RTHDAEQ0.dat

2013-02-16 00:59:39 -------- d-----w- C:\Users\Shay\AppData\Roaming\WinBatch

2013-02-16 00:40:05 -------- d-----w- C:\ProgramData\NexonUS

2013-02-16 00:38:56 -------- d-----w- C:\Nexon

2013-02-16 00:38:52 -------- d-----w- C:\Program Files (x86)\Kill3rCombo

2013-02-16 00:30:53 2566144 ----a-w- C:\Windows\System32\esent.dll

2013-02-16 00:30:53 1686016 ----a-w- C:\Windows\SysWow64\esent.dll

2013-02-16 00:30:53 166272 ----a-w- C:\Windows\System32\drivers\nvstor.sys

2013-02-16 00:30:53 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys

2013-02-16 00:30:53 107904 ----a-w- C:\Windows\System32\drivers\amdsata.sys

2013-02-16 00:30:52 187264 ----a-w- C:\Windows\System32\drivers\storport.sys

2013-02-16 00:30:51 96768 ----a-w- C:\Windows\System32\fsutil.exe

2013-02-16 00:30:51 410496 ----a-w- C:\Windows\System32\drivers\iaStorV.sys

2013-02-16 00:30:51 27008 ----a-w- C:\Windows\System32\drivers\amdxata.sys

2013-02-16 00:30:50 74240 ----a-w- C:\Windows\SysWow64\fsutil.exe

2013-02-16 00:07:16 98816 ----a-w- C:\Windows\System32\drivers\usbccgp.sys

2013-02-16 00:07:16 52224 ----a-w- C:\Windows\System32\drivers\usbehci.sys

2013-02-16 00:07:16 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys

2013-02-16 00:07:16 324608 ----a-w- C:\Windows\System32\drivers\usbport.sys

2013-02-16 00:07:16 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys

2013-02-16 00:07:16 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys

2013-02-16 00:07:15 7936 ----a-w- C:\Windows\System32\drivers\usbd.sys

2013-02-16 00:06:25 9161176 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll

2013-02-16 00:06:19 273840 ------w- C:\Windows\System32\MpSigStub.exe

2013-02-15 20:50:52 27008 ----a-w- C:\Windows\System32\drivers\Diskdump.sys

2013-02-15 09:23:57 367104 ----a-w- C:\Windows\System32\wcncsvc.dll

2013-02-15 09:23:57 276992 ----a-w- C:\Windows\SysWow64\wcncsvc.dll

2013-02-15 09:12:10 9728 ----a-w- C:\Windows\System32\Wdfres.dll

2013-02-15 09:12:10 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys

2013-02-15 09:12:10 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys

2013-02-15 09:12:10 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui

2013-02-15 09:08:18 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll

2013-02-15 09:08:18 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll

2013-02-15 09:08:18 444752 ----a-w- C:\Windows\System32\mscoree.dll

2013-02-15 09:08:18 320352 ----a-w- C:\Windows\System32\PresentationHost.exe

2013-02-15 09:08:18 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll

2013-02-15 09:08:18 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe

2013-02-15 09:08:18 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll

2013-02-15 09:08:18 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll

2013-02-15 09:08:17 48960 ----a-w- C:\Windows\System32\netfxperf.dll

2013-02-15 09:08:17 1942856 ----a-w- C:\Windows\System32\dfshim.dll

2013-02-15 09:03:30 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll

2013-02-15 09:03:29 46080 ----a-w- C:\Windows\System32\atmlib.dll

2013-02-15 09:03:29 367616 ----a-w- C:\Windows\System32\atmfd.dll

2013-02-15 09:03:29 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll

2013-02-15 09:02:52 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys

2013-02-15 09:02:52 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll

2013-02-15 09:02:52 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys

2013-02-15 09:02:52 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll

2013-02-15 09:02:50 744448 ----a-w- C:\Windows\System32\WUDFx.dll

2013-02-15 09:02:50 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll

2013-02-15 09:02:50 229888 ----a-w- C:\Windows\System32\WUDFHost.exe

2013-02-15 09:00:25 22896 ----a-w- C:\Windows\System32\drivers\fs_rec.sys

2013-02-15 09:00:24 80896 ----a-w- C:\Windows\System32\imagehlp.dll

2013-02-15 09:00:24 158720 ----a-w- C:\Windows\SysWow64\imagehlp.dll

2013-02-15 09:00:23 5120 ----a-w- C:\Windows\SysWow64\wmi.dll

2013-02-15 09:00:23 5120 ----a-w- C:\Windows\System32\wmi.dll

2013-02-15 08:58:03 243712 ----a-w- C:\Windows\System32\drivers\ks.sys

2013-02-15 08:58:03 184832 ----a-w- C:\Windows\System32\drivers\usbvideo.sys

2013-02-15 03:31:05 478208 ----a-w- C:\Windows\System32\dpnet.dll

2013-02-15 03:31:05 376832 ----a-w- C:\Windows\SysWow64\dpnet.dll

2013-02-15 03:30:50 182272 ----a-w- C:\Windows\System32\dnsrslvr.dll

2013-02-15 03:30:49 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe

2013-02-15 03:30:49 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe

2013-02-15 03:30:21 1024512 ----a-w- C:\Windows\System32\wmpmde.dll

2013-02-15 03:30:20 738816 ----a-w- C:\Windows\SysWow64\wmpmde.dll

2013-02-15 03:28:26 613888 ----a-w- C:\Windows\System32\psisdecd.dll

2013-02-15 03:28:26 108032 ----a-w- C:\Windows\System32\psisrndr.ax

2013-02-15 03:28:25 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax

2013-02-15 03:28:25 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll

2013-02-15 03:28:24 75776 ----a-w- C:\Windows\System32\MSDvbNP.ax

2013-02-15 03:28:24 72704 ----a-w- C:\Windows\SysWow64\Mpeg2Data.ax

2013-02-15 03:28:24 59904 ----a-w- C:\Windows\SysWow64\MSDvbNP.ax

2013-02-15 03:28:24 288256 ----a-w- C:\Windows\System32\MSNP.ax

2013-02-15 03:28:24 204288 ----a-w- C:\Windows\SysWow64\MSNP.ax

2013-02-15 03:28:24 104960 ----a-w- C:\Windows\System32\Mpeg2Data.ax

2013-02-15 03:26:59 708608 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll

2013-02-15 03:23:54 1572864 ----a-w- C:\Windows\System32\quartz.dll

2013-02-15 03:22:01 552960 ----a-w- C:\Windows\System32\msdri.dll

2013-02-15 03:20:47 4068864 ----a-w- C:\Windows\System32\mf.dll

2013-02-15 03:19:16 307200 ----a-w- C:\Windows\System32\ncrypt.dll

2013-02-15 03:18:43 295792 ----a-w- C:\Windows\System32\drivers\volsnap.sys

2013-02-15 03:17:33 204800 ----a-w- C:\Windows\System32\drivers\rdpwd.sys

2013-02-15 03:17:21 516096 ----a-w- C:\Program Files\Windows Mail\wab.exe

2013-02-15 03:17:20 516096 ----a-w- C:\Program Files (x86)\Windows Mail\wab.exe

2013-02-15 03:17:20 35328 ----a-w- C:\Program Files\Windows Mail\wabfind.dll

2013-02-15 03:17:15 75632 ----a-w- C:\Windows\System32\drivers\partmgr.sys

2013-02-15 03:17:12 714752 ----a-w- C:\Windows\System32\kerberos.dll

2013-02-15 03:17:12 541184 ----a-w- C:\Windows\SysWow64\kerberos.dll

2013-02-15 03:17:10 3213824 ----a-w- C:\Windows\System32\msi.dll

2013-02-15 03:17:10 2342400 ----a-w- C:\Windows\SysWow64\msi.dll

2013-02-15 03:14:58 861184 ----a-w- C:\Windows\System32\oleaut32.dll

2013-02-15 03:13:59 182272 ----a-w- C:\Windows\System32\cryptsvc.dll

2013-02-15 03:13:59 140288 ----a-w- C:\Windows\System32\cryptnet.dll

2013-02-15 03:13:59 139264 ----a-w- C:\Windows\SysWow64\cryptsvc.dll

2013-02-15 03:13:59 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll

2013-02-15 03:02:40 77312 ----a-w- C:\Windows\System32\packager.dll

2013-02-15 03:02:40 67072 ----a-w- C:\Windows\SysWow64\packager.dll

2013-02-15 02:19:54 -------- d-----w- C:\Users\Shay\AppData\Local\http___www.julien-manici

2013-02-14 22:09:34 -------- d-----w- C:\Program Files (x86)\Julien MANICI

2013-02-14 18:28:54 -------- d-----w- C:\Users\Shay\AppData\Local\PMB Files

2013-02-14 18:28:52 -------- d-----w- C:\ProgramData\PMB Files

2013-02-14 18:17:02 -------- d-----w- C:\Users\Shay\AppData\Local\DDMSettings

2013-02-14 17:56:50 -------- d-----w- C:\Program Files\DivX

2013-02-14 17:51:22 -------- d-----w- C:\Program Files (x86)\Applian Technologies

2013-02-14 17:47:23 -------- d-----w- C:\ProgramData\APN

2013-02-14 17:40:48 -------- d-----w- C:\Users\Shay\AppData\Roaming\NVIDIA

2013-02-14 17:14:18 -------- d-----w- C:\Program Files (x86)\Pando Networks

2013-02-14 06:39:10 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation

2013-02-14 06:38:43 884152 ----a-w- C:\Windows\System32\nvvsvc.exe

2013-02-14 06:38:43 63928 ----a-w- C:\Windows\System32\nvshext.dll

2013-02-14 06:38:43 6382008 ----a-w- C:\Windows\System32\nvcpl.dll

2013-02-14 06:38:43 3455416 ----a-w- C:\Windows\System32\nvsvc64.dll

2013-02-14 06:38:43 2558392 ----a-w- C:\Windows\System32\nvsvcr.dll

2013-02-14 06:38:43 118712 ----a-w- C:\Windows\System32\nvmctray.dll

2013-02-14 06:38:20 61368 ----a-w- C:\Windows\System32\OpenCL.dll

2013-02-14 06:38:20 53176 ----a-w- C:\Windows\SysWow64\OpenCL.dll

2013-02-14 06:38:13 -------- d-----w- C:\ProgramData\NVIDIA Corporation

2013-02-14 06:36:54 -------- d-----w- C:\Program Files\NVIDIA Corporation

2013-02-14 06:36:18 -------- d-----w- C:\NVIDIA

2013-02-14 06:02:31 -------- d-----w- C:\Program Files (x86)\Common Files\DivX Shared

2013-02-14 05:57:01 -------- d-----w- C:\Program Files (x86)\DivX

2013-02-14 05:54:55 -------- d-----r- C:\Program Files (x86)\Skype

2013-02-14 05:54:35 -------- d-----w- C:\Users\Shay\AppData\Local\Macromedia

2013-02-14 05:53:39 -------- d-----w- C:\ProgramData\DivX

2013-02-14 05:53:31 -------- d-----w- C:\ProgramData\McAfee Security Scan

2013-02-14 05:53:30 71024 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2013-02-14 05:53:30 691568 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2013-02-14 05:53:30 -------- d-----w- C:\Program Files (x86)\McAfee Security Scan

2013-02-14 05:48:01 -------- d-----w- C:\Users\Shay\AppData\Local\Google

2013-02-14 05:47:56 54072 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys

2013-02-14 05:47:55 984144 ----a-w- C:\Windows\System32\drivers\aswSnx.sys

2013-02-14 05:47:52 71600 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys

2013-02-14 05:47:16 41224 ----a-w- C:\Windows\avastSS.scr

2013-02-14 05:47:02 -------- d-----w- C:\ProgramData\AVAST Software

2013-02-14 05:47:02 -------- d-----w- C:\Program Files\AVAST Software

2013-02-14 05:31:55 861088 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll

2013-02-14 05:31:55 782240 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2013-02-14 05:31:47 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

2013-02-14 05:29:46 -------- d-----w- C:\Program Files (x86)\Common Files\Steam

2013-02-14 05:29:45 -------- d-----w- C:\Program Files (x86)\Steam

2013-02-14 05:25:24 -------- d-----w- C:\Users\Shay\AppData\Local\ElevatedDiagnostics

2013-02-14 05:16:37 1031680 ----a-w- C:\Windows\System32\rdpcore.dll

2013-02-14 05:16:36 826368 ----a-w- C:\Windows\SysWow64\rdpcore.dll

2013-02-14 05:16:36 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys

2013-02-14 05:12:45 -------- d-----w- C:\Users\Shay\AppData\Local\Mozilla

2013-02-14 05:07:33 2622464 ----a-w- C:\Windows\System32\wucltux.dll

2013-02-14 05:07:26 99840 ----a-w- C:\Windows\System32\wudriver.dll

2013-02-14 05:07:16 36864 ----a-w- C:\Windows\System32\wuapp.exe

2013-02-14 05:07:16 186752 ----a-w- C:\Windows\System32\wuwebv.dll

2013-02-14 05:02:17 946688 ----a-w- C:\Windows\System32\drivers\rtl8192se.sys

2013-02-14 05:02:10 -------- d-----w- C:\Program Files (x86)\Realtek WLAN Driver

2013-02-14 05:01:53 -------- d-sh--w- C:\Windows\Installer

2013-02-14 05:01:36 -------- d-----w- C:\temp.realtek

2013-02-14 03:47:48 -------- d-----w- C:\Users\Shay\AppData\Local\Diagnostics

2013-02-14 03:27:01 -------- d-----w- C:\Users\Shay\AppData\Local\VirtualStore

2013-02-14 03:20:43 -------- d-----w- C:\Windows\Panther


==================== Find3M ====================


2013-01-05 05:57:43 5500776 ----a-w- C:\Windows\System32\ntoskrnl.exe

2013-01-05 05:02:17 3957608 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe

2013-01-05 05:02:17 3902312 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe

2013-01-04 05:41:01 1893224 ----a-w- C:\Windows\System32\drivers\tcpip.sys

2013-01-04 05:40:54 287576 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS

2013-01-04 05:37:01 362496 ----a-w- C:\Windows\System32\wow64win.dll

2013-01-04 05:37:00 243200 ----a-w- C:\Windows\System32\wow64.dll

2013-01-04 05:37:00 13312 ----a-w- C:\Windows\System32\wow64cpu.dll

2013-01-04 05:36:33 215040 ----a-w- C:\Windows\System32\winsrv.dll

2013-01-04 05:33:49 16384 ----a-w- C:\Windows\System32\ntvdm64.dll

2013-01-04 05:30:34 424960 ----a-w- C:\Windows\System32\KernelBase.dll

2013-01-04 05:27:03 6144 ---ha-w- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll

2013-01-04 05:27:03 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll

2013-01-04 05:27:03 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll

2013-01-04 05:27:02 4608 ---ha-w- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll

2013-01-04 05:27:02 4096 ---ha-w- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll

2013-01-04 05:27:02 4096 ---ha-w- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll

2013-01-04 05:27:01 3584 ---ha-w- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll

2013-01-04 05:27:01 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll

2013-01-04 05:27:00 4608 ---ha-w- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll

2013-01-04 05:27:00 3584 ---ha-w- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll

2013-01-04 05:27:00 3072 ---ha-w- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll

2013-01-04 04:51:09 5120 ----a-w- C:\Windows\SysWow64\wow32.dll

2013-01-04 04:51:08 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll

2013-01-04 03:22:49 3150848 ----a-w- C:\Windows\System32\win32k.sys

2013-01-04 03:19:55 338432 ----a-w- C:\Windows\System32\conhost.exe

2013-01-04 02:48:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe

2013-01-04 02:48:34 7680 ----a-w- C:\Windows\SysWow64\instnm.exe

2013-01-04 02:48:34 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll

2013-01-04 02:48:33 2048 ----a-w- C:\Windows\SysWow64\user.exe

2013-01-04 02:43:35 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll

2013-01-04 02:43:34 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll

2013-01-04 02:43:34 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll

2013-01-04 02:43:34 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll

2012-12-07 05:41:16 441856 ----a-w- C:\Windows\System32\Wpc.dll

2012-12-07 05:35:34 2745856 ----a-w- C:\Windows\System32\gameux.dll

2012-12-07 05:04:20 308736 ----a-w- C:\Windows\SysWow64\Wpc.dll

2012-12-07 04:57:38 2576384 ----a-w- C:\Windows\SysWow64\gameux.dll

2012-12-07 03:21:08 45568 ----a-w- C:\Windows\SysWow64\oflc-nz.rs

2012-11-22 10:32:45 801280 ----a-w- C:\Windows\System32\usp10.dll

2012-11-22 09:33:26 627712 ----a-w- C:\Windows\SysWow64\usp10.dll


============= FINISH: 10:49:19.86 ===============

PLEASE! I'm in dire need of help! I can't do my school work without this computer. :(

Link to post
Share on other sites

:welcome: I am TheDarkKnight and will be assisting you. Please ask questions if anything is unclear. :)

Please follow these instructions to run ComboFix.exe. Please visit this webpage for download links and instructions for running this tool:


* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix (CF).

Please go here to see a list of programs that need to be disabled.

**Note: Do not mouseclick ComboFix's window while it's running. That may cause it to stall.**

**Note 2: If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.**

Please include the C:\ComboFix.txt in your next reply for further review.

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.