Jump to content

I have seen a Malware called Searce.Conduit.com please help


Recommended Posts

Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.

  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

 
 
 
 
Scan with DDS

Download DDS and save it to your desktop from here or here or
here.

Disable any script blocker, and then double click dds.scr to run the tool.

When done, DDS will open two (2) logs
DDS.txt
Attach.txt
Save both reports to your desktop.
 
 
 
 
Scan with Gmer rootkit scanner

Please download Gmer from here by clicking on the "Download EXE" Button.
  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )

    [*]Leave everything else as it is. [*]Close all other running programs as well as your Browser. [*]Click the Scan button & wait for it to finish. [*]Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post. [*]Save it where you can easily find it, such as your desktop. [*]Please post the content of the ark.txt here.


**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Link to post
Share on other sites

Here is the report

 

Advanced SystemCare Diagnose Report v1.0

Date: 2013/07/11 00:06:35

 

----------------------------------

01 - Operating System

----------------------------------

 

0101 - Operating System         : Windows 7 Professional 64-bit (6.1, Build 7601) Service Pack 1 (7601.win7sp1_gdr.130318-1533)

0102 - Language                 : English (Regional Setting: English)

0103 - BIOS                     : BIOS Version 1.80   

0104 - Processor                : Intel® Pentium® Dual  CPU  T2330  @ 1.60GHz (2 CPUs), ~1.6GHz

0105 - Memory                   : 1024MB RAM

0106 - Available OS Memory      : 1014MB RAM

0107 - Page File                : 1336MB used, 894MB available

0108 - Windows Dir              : C:\Windows

0109 - DirectX Version          : DirectX 11

0110 - DX Setup Parameters      : Not found

0111 - User DPI Setting         : Using System DPI

0112 - System DPI Setting       : 96 DPI (100 percent)

0113 - DWM DPI Scaling          : Disabled

0114 - DxDiag Version           : 6.01.7601.17514

 

----------------------------------

02 - Processor

----------------------------------

 

0201 - Caption                  : Intel® Pentium® Dual  CPU  T2330  @ 1.60GHz x2 ~1600MHz

0202 - Current Clock Speed      : 1600MHz

0203 - L1 Cache                 : 64.00 KB

0204 - L2 Cache                 : 1.00 MB

 

----------------------------------

03 - Video Adapter

----------------------------------

 

0301 - Card Name                : Mobile Intel® 965 Express Chipset Family

0302 - Manufacturer             : Intel Corporation

0303 - Chip Type                : Mobile Intel® 965 Express Chipset Family

0304 - DAC Type                 : Internal

0305 - Device Key               : Enum\PCI\VEN_8086&DEV_2A02&SUBSYS_FF101179&REV_03

0306 - Display Memory           : 251 MB

0307 - AdapterRAM               : 256.00 MB

0308 - Current Mode             : 1280 x 800 (32 bit) (60Hz)

0309 - Monitor Name             : Generic PnP Monitor

0310 - Driver Name              : igdumd64.dll,igd10umd64.dll,igdumdx32,igd10umd32

0311 - Driver Version           : 8.14.0010.1930

0312 - Driver Language          : English

0313 - DDI Version              : 10

0314 - Driver Model             : WDDM 1.1

0315 - Driver Beta              : False

0316 - Driver Debug             : False

0317 - Driver Date              : 9/23/2009 19:22:58

0318 - Driver Size              : 5472256

0319 - VDD                      : n/a

0320 - Mini VDD                 : n/a

0321 - Mini VDD Date            : n/a

0322 - Mini VDD Size            : 0

0323 - Device Identifier        : {D7B78E66-6942-11CF-4375-1ADFA2C2C535}

0324 - Vendor ID                : 0x8086

0325 - Device ID                : 0x2A02

0326 - SubSys ID                : 0xFF101179

0327 - Revision ID              : 0x0003

0328 - Driver Strong Name       : oem2.inf:Intel.Mfg.NTamd64:i965GM0:8.15.10.1930:pci\ven_8086&dev_2a02

0329 - Rank Of Driver           : 00EC2001

0330 - Video Accel              : ModeMPEG2_A ModeMPEG2_C ModeWMV9_B ModeVC1_B

0331 - Deinterlace Caps         : {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

                                  {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

                                  {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

                                  {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

                                  {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

                                  {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

                                  {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

                                  {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

0332 - D3D9 Overlay             : Not Supported

0333 - DXVA-HD                  : Not Supported

0334 - DDraw Status             : Enabled

0335 - D3D Status               : Enabled

0336 - AGP Status               : Enabled

0337 - Notes                    : No problems found.

 

0338 - OpenGL                   : 6.1.7600.16385 (win7_rtm.090713-1255)

 

----------------------------------

04 - Memory

----------------------------------

 

0401 - Total Memory             : 1014.40 MB

0402 - Free Memory              : 192.43 MB

0403 - Total Pagefile           : 2.18 GB

0404 - Free Pagefile            : 882.07 MB

 

0405 - Bank Label               : Bank 0

0406 - Speed                    : 667 MHz

0407 - Total Width              : 64 Bits

0408 - Capacity                 : 512.00 MB

 

0405 - Bank Label               : Bank 1

0406 - Speed                    : 667 MHz

0407 - Total Width              : 64 Bits

0408 - Capacity                 : 512.00 MB

 

----------------------------------

05 - Network

----------------------------------

 

0501 - Description              : Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter

0502 - Driver Date              : 3-31-2010

0503 - Driver Version           : 62.1182.331.2010

 

----------------------------------

06 - Motherboard

----------------------------------

 

0601 - Model                    : SANTA ROSA CRB

0602 - Manufacturer             : Intel Corporation

 

----------------------------------

07 - Sound Device

----------------------------------

 

0701 - Description              : Speakers (High Definition Audio Device)

0702 - Default Sound Playback   : True

0703 - Default Voice Playback   : True

0704 - Hardware ID              : HDAUDIO\FUNC_01&VEN_10EC&DEV_0268&SUBSYS_1179FF14&REV_1000

0705 - Manufacturer ID          : 1

0706 - Product ID               : 65535

0707 - Type                     : WDM

0708 - Driver Name              : HdAudio.sys

0709 - Driver Version           : 6.01.7601.17514

0710 - Driver attributes        : Final Retail

0711 - Date and Size            : 11/20/2010 20:23:47

0713 - Driver Provider          : Microsoft

0714 - Min/Max Sample Rate      : 4316782, 4316782

0715 - Static/Strm HW Mix Bufs  : 4316782, 4316782

0716 - Static/Strm HW 3D Bufs   : 4316782, 4316782

0717 - HW Memory                : 4316790

0718 - Voice Management         : False

0719 - EAX 2.0 Listen/Src   : False, False

0720 - I3DL2 Listen/Src     : False, False

0721 - Notes                    : No problems found.

 

 

----------------------------------

08 - Hard Disk

----------------------------------

 

0801 - Model                    : FUJITSU MHY2120BH ATA Device

0802 - Media Type               : Fixed hard disk media

0803 - Size                     : 111.79 GB

0805 - Driver Date              : 6-21-2006

0806 - Driver Version           : 6.1.7600.16385

 

0807 - Caption                  : C:\

0808 - Capacity                 : 111.69 GB

0809 - Free Space               : 78.57 GB

0810 - Drive Type               : 3-Fixed

0811 - File System              : NTFS

 

----------------------------------

09 - Process

----------------------------------

 

0901 - 0000 Idle                   0 0    0               

0901 - 0004 System                 0 0    0               

0901 - 0134 smss.exe               0 0    0   normal      

0901 - 01ac csrss.exe              0 0    0   normal      

0901 - 01dc csrss.exe              1 174  81  normal      

0901 - 01e4 wininit.exe            0 0    0   high        

0901 - 021c winlogon.exe           1 6    0   high        

0901 - 0244 services.exe           0 0    0   normal      

0901 - 024c lsass.exe              0 0    0   normal      

0901 - 0254 lsm.exe                0 0    0   normal      

0901 - 02b4 svchost.exe            0 0    0   normal      

0901 - 02ec ASCService.exe         0 0    0   high         C:\Program Files (x86)\IObit\Advanced SystemCare 6

0901 - 0330 svchost.exe            0 0    0   normal      

0901 - 038c svchost.exe            0 0    0   normal      

0901 - 03b8 svchost.exe            0 0    0   normal      

0901 - 03d0 svchost.exe            0 0    0   normal      

0901 - 03e8 svchost.exe            0 0    0   normal      

0901 - 01b4 svchost.exe            0 0    0   normal      

0901 - 040c svchost.exe            0 0    0   normal      

0901 - 04a4 AvastSvc.exe           0 0    0   normal       C:\Program Files\AVAST Software\Avast

0901 - 0580 spoolsv.exe            0 0    0   normal      

0901 - 05b4 svchost.exe            0 0    0   normal      

0901 - 05cc IMFsrv.exe             0 0    0   normal       C:\Program Files (x86)\IObit\IObit Malware Fighter

0901 - 065c svchost.exe            0 0    0   normal      

0901 - 0690 rndlresolversvc.exe    0 0    0   normal       C:\Program Files (x86)\RealNetworks\RealDownloader

0901 - 06dc svchost.exe            0 0    0   normal      

0901 - 0714 TeamViewer_Service.exe 0 0    0   normal       C:\Program Files (x86)\TeamViewer\Version8

0901 - 0a2c taskhost.exe           1 26   20  normal      

0901 - 0a70 explorer.exe           1 383  244 normal      

0901 - 0b00 rundll32.exe           1 15   6   normal      

0901 - 0b90 dwm.exe                1 17   2   high        

0901 - 08b8 ASCTray.exe            1 89   37  normal       C:\Program Files (x86)\IObit\Advanced SystemCare 6

0901 - 074c Suo10_SmartRAM.exe     1 206  39  normal       C:\Program Files (x86)\IObit\Advanced SystemCare 6

0901 - 0a7c AvastUI.exe            1 147  43  normal       C:\Program Files\AVAST Software\Avast

0901 - 016c SearchIndexer.exe      0 0    0   normal      

0901 - 095c realsched.exe          1 9    11  normal       C:\Program Files (x86)\Real\RealPlayer\Update

0901 - 0c40 jusched.exe            1 9    2   normal       C:\Program Files (x86)\Common Files\Java\Java Update

0901 - 0c64 wmpnetwk.exe           0 0    0   normal      

0901 - 0e18 svchost.exe            0 0    0   normal      

0901 - 0e2c IMF.exe                1 167  93  normal       C:\Program Files (x86)\IObit\IObit Malware Fighter

0901 - 0f0c svchost.exe            0 0    0   normal      

0901 - 0ed0 SynTPEnh.exe           1 64   33  above normal

0901 - 0610 igfxpers.exe           1 9    4   normal      

0901 - 0d84 hkcmd.exe              1 9    16  normal      

0901 - 0b58 igfxsrvc.exe           1 9    2   normal      

0901 - 0e34 igfxtray.exe           1 11   5   normal      

0901 - 0d38 SynTPHelper.exe        1 9    3   above normal

0901 - 0ab8 wuauclt.exe            1 12   5   normal      

0901 - 05dc Asc.exe                1 2898 200 normal       C:\Program Files (x86)\IObit\Advanced SystemCare 6

0901 - 087c taskhost.exe           1 9    4   normal      

0901 - 1448 mscorsvw.exe           0 0    0   normal      

0901 - 1030 mscorsvw.exe           0 0    0   normal       C:\Windows\Microsoft.NET\Framework\v4.0.30319

0901 - 17ec TrustedInstaller.exe   0 0    0   normal      

0901 - 1bcc Sus10_SysExplorer.exe  1 102  47  normal       C:\Program Files (x86)\IObit\Advanced SystemCare 6

0901 - 1c6c WmiPrvSE.exe           0 0    0   normal      

0901 - 1e70 audiodg.exe            0 0    0               

 

 

----------------------------------

10 - Service

----------------------------------

 

1001 - Advanced SystemCare Service 6 - [C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe]

1001 - Application Experience - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - Application Information - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - Windows Audio Endpoint Builder - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - Windows Audio - [C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted]

1001 - avast! Antivirus - ["C:\Program Files\AVAST Software\Avast\AvastSvc.exe"]

1001 - Base Filtering Engine - [C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork]

1001 - Background Intelligent Transfer Service - [C:\Windows\System32\svchost.exe -k netsvcs]

1001 - Computer Browser - [C:\Windows\System32\svchost.exe -k netsvcs]

1001 - Microsoft .NET Framework NGEN v4.0.30319_X86 - [C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe]

1001 - Microsoft .NET Framework NGEN v4.0.30319_X64 - [C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe]

1001 - Cryptographic Services - [C:\Windows\system32\svchost.exe -k NetworkService]

1001 - DHCP Client - [C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted]

1001 - DNS Client - [C:\Windows\system32\svchost.exe -k NetworkService]

1001 - Extensible Authentication Protocol - [C:\Windows\System32\svchost.exe -k netsvcs]

1001 - Windows Event Log - [C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted]

1001 - COM+ Event System - [C:\Windows\system32\svchost.exe -k LocalService]

1001 - Function Discovery Provider Host - [C:\Windows\system32\svchost.exe -k LocalService]

1001 - Function Discovery Resource Publication - [C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation]

1001 - Windows Font Cache Service - [C:\Windows\system32\svchost.exe -k LocalService]

1001 - HomeGroup Listener - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - HomeGroup Provider - [C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted]

1001 - IMF Service - [C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe]

1001 - CNG Key Isolation - [C:\Windows\system32\lsass.exe]

1001 - Server - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - Workstation - [C:\Windows\System32\svchost.exe -k NetworkService]

1001 - TCP/IP NetBIOS Helper - [C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted]

1001 - Windows Firewall - [C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork]

1001 - Network Connections - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - Network List Service - [C:\Windows\System32\svchost.exe -k LocalService]

1001 - Network Location Awareness - [C:\Windows\System32\svchost.exe -k NetworkService]

1001 - Network Store Interface Service - [C:\Windows\system32\svchost.exe -k LocalService]

1001 - Peer Networking Identity Manager - [C:\Windows\System32\svchost.exe -k LocalServicePeerNet]

1001 - Peer Networking Grouping - [C:\Windows\System32\svchost.exe -k LocalServicePeerNet]

1001 - Program Compatibility Assistant Service - [C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - Plug and Play - [C:\Windows\system32\svchost.exe -k DcomLaunch]

1001 - Peer Name Resolution Protocol - [C:\Windows\System32\svchost.exe -k LocalServicePeerNet]

1001 - Power - [C:\Windows\system32\svchost.exe -k DcomLaunch]

1001 - User Profile Service - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - RealNetworks Downloader Resolver Service - ["C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe"]

1001 - Security Accounts Manager - [C:\Windows\system32\lsass.exe]

1001 - System Event Notification Service - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - Shell Hardware Detection - [C:\Windows\System32\svchost.exe -k netsvcs]

1001 - Print Spooler - [C:\Windows\System32\spoolsv.exe]

1001 - SSDP Discovery - [C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation]

1001 - Windows Image Acquisition (WIA) - [C:\Windows\system32\svchost.exe -k imgsvc]

1001 - Superfetch - [C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - TeamViewer 8 - ["C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"]

1001 - Themes - [C:\Windows\System32\svchost.exe -k netsvcs]

1001 - Distributed Link Tracking Client - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - Desktop Window Manager Session Manager - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - Windows Defender - [C:\Windows\System32\svchost.exe -k secsvcs]

1001 - Windows Management Instrumentation - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - WLAN AutoConfig - [C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - Windows Media Player Network Sharing Service - ["C:\Program Files\Windows Media Player\wmpnetwk.exe"]

1001 - Security Center - [C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted]

1001 - Windows Search - [C:\Windows\system32\SearchIndexer.exe /Embedding]

1001 - Windows Update - [C:\Windows\system32\svchost.exe -k netsvcs]

 

----------------------------------

11 - Windows Express

----------------------------------

 

1101 - System Score             : 3

1102 - Memory Score             : 4.5

1103 - CPU Score                : 4.5

1104 - Graphics Score           : 3.1

1105 - Gaming Score             : 3

1106 - Disk Score               : 5

 

----------------------------------

12 - Event Log

----------------------------------

 

1201 - Time                     : 7/11/2013 1:12:50 PM

1202 - Source                   : WinMgmt

1203 - Description              : Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

 

1201 - Time                     : 7/11/2013 1:12:07 PM

1202 - Source                   : ESENT

1203 - Description              : taskhost (2604) WebCacheLocal: Error -1811 occurred while opening logfile C:\Users\Anthony\AppData\Local\Microsoft\Windows\WebCache\V0100019.log.

 

1201 - Time                     : 7/11/2013 6:00:18 AM

1202 - Source                   : SideBySide

1203 - Description              : Activation context generation failed for "C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe". Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis.

 

1201 - Time                     : 7/11/2013 2:15:22 AM

1202 - Source                   : WinMgmt

1203 - Description              : Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

 

1201 - Time                     : 7/9/2013 4:59:42 AM

1202 - Source                   : SideBySide

1203 - Description              : Activation context generation failed for "C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe". Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis.

 

1201 - Time                     : 7/9/2013 3:04:05 AM

1202 - Source                   : SideBySide

1203 - Description              : Activation context generation failed for "C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe". Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis.

 

1201 - Time                     : 7/9/2013 1:38:42 AM

1202 - Source                   : WinMgmt

1203 - Description              : Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

 

1201 - Time                     : 7/11/2013 1:17:29 PM

1202 - Source                   : Service Control Manager

1203 - Description              : The Windows Update service hung on starting.

 

1201 - Time                     : 7/11/2013 1:12:29 PM

1202 - Source                   : Service Control Manager

1203 - Description              : A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.

 

1201 - Time                     : 7/11/2013 1:11:59 PM

1202 - Source                   : Service Control Manager

1203 - Description              : A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SysMain service.

 

1201 - Time                     : 7/11/2013 1:11:26 PM

1202 - Source                   : Service Control Manager

1203 - Description              : A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.

 

1201 - Time                     : 7/11/2013 1:08:45 PM

1202 - Source                   : EventLog

1203 - Description              : The previous system shutdown at 6:35:01 PM on ‎7/‎10/‎2013 was unexpected.

 

1201 - Time                     : 7/11/2013 2:20:01 AM

1202 - Source                   : Service Control Manager

1203 - Description              : A timeout (30000 milliseconds) was reached while waiting for a transaction response from the eventlog service.

 

1201 - Time                     : 7/11/2013 2:18:58 AM

1202 - Source                   : Service Control Manager

1203 - Description              : The Windows Defender service hung on starting.

 

1201 - Time                     : 7/9/2013 1:22:32 PM

1202 - Source                   : Service Control Manager

1203 - Description              : The Steam Client Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.

 

1201 - Time                     : 7/9/2013 1:22:32 PM

1202 - Source                   : Service Control Manager

1203 - Description              : A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.

 

1201 - Time                     : 7/9/2013 6:37:55 AM

1202 - Source                   : yukonw7

1203 - Description              : Driver status 1

 

----------------------------------

End of file - 27304 Bytes

Link to post
Share on other sites

I was going to do a Before an after but i kinda delete the Before so here is the After Report

 

# AdwCleaner v2.305 - Logfile created 07/12/2013 at 11:28:18
# Updated 11/07/2013 by Xplode
# Operating system : Windows 7 Professional Service Pack 1 (64 bits)
# User : Anthony - ANTHONY-PC
# Boot Mode : Normal
# Running from : C:\Users\Anthony\Downloads\adwcleaner.exe
# Option [search]
 
 
***** [services] *****
 
 
***** [Files / Folders] *****
 
 
***** [Registry] *****
 
 
***** [internet Browsers] *****
 
-\\ Internet Explorer v10.0.9200.16635
 
[OK] Registry is clean.
 
-\\ Google Chrome v28.0.1500.71
 
File : C:\Users\Anthony\AppData\Local\Google\Chrome\User Data\Default\Preferences
 
[OK] File is clean.
 
*************************
 
AdwCleaner[R4].txt - [667 octets] - [12/07/2013 11:28:18]
 
########## EOF - C:\AdwCleaner[R4].txt - [726 octets] ##########
Link to post
Share on other sites

Combofix


Combofix should only be run when adviced by a team member!

Link


Important - Save the file to your desktop!


  • Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
  • Run Combofix.exe



When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.

Link to post
Share on other sites

Looks good!

 

 

Please go to here to run the online scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth Technology

[*]Click Scan[*]Wait for the scan to finish[*]If any threats were found, click the 'List of found threats' , then click Export to text file.... [*]Save it to your desktop, then please copy and paste that log as a reply to this topic.

Link to post
Share on other sites

Delete this file.

 

Then we can do the cleanup - if you are facing any issues, report that immediately.

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[s1].txt also.


SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.

Link to post
Share on other sites

AdwCleaner

 

# AdwCleaner v2.305 - Logfile created 07/15/2013 at 13:36:16

# Updated 11/07/2013 by Xplode

# Operating system : Windows 7 Professional Service Pack 1 (64 bits)

# User : Anthony - ANTHONY-PC

# Boot Mode : Normal

# Running from : C:\Users\Anthony\Downloads\IT Stuff\adwcleaner.exe

# Option [search]

 

 

***** [services] *****

 

 

***** [Files / Folders] *****

 

 

***** [Registry] *****

 

 

***** [internet Browsers] *****

 

-\\ Internet Explorer v10.0.9200.16635

 

[OK] Registry is clean.

 

-\\ Google Chrome v28.0.1500.72

 

File : C:\Users\Anthony\AppData\Local\Google\Chrome\User Data\Default\Preferences

 

[OK] File is clean.

 

*************************

 

AdwCleaner[R4].txt - [794 octets] - [12/07/2013 11:28:18]

AdwCleaner[R5].txt - [862 octets] - [15/07/2013 13:34:31]

AdwCleaner[R6].txt - [794 octets] - [15/07/2013 13:36:16]

 

########## EOF - C:\AdwCleaner[R6].txt - [853 octets] ##########

 

SecurityCheck

 


Results of screen317's Security Check version 0.99.69  

 Windows 7 Service Pack 1 x64 (UAC is enabled)  

 Internet Explorer 10  

``````````````Antivirus/Firewall Check:`````````````` 

 Windows Firewall Enabled!  

avast! Antivirus   

 Antivirus up to date!   

`````````Anti-malware/Other Utilities Check:````````` 

 SpywareBlaster 5.0    

 Spybot - Search & Destroy 

 Malwarebytes Anti-Malware version 1.75.0.1300  

 Java 7 Update 25  

 Google Chrome 28.0.1500.71  

 Google Chrome 28.0.1500.72  

````````Process Check: objlist.exe by Laurent````````  

 Spybot Teatimer.exe is disabled! 

 IObit IObit Malware Fighter IMFsrv.exe  

 AVAST Software Avast AvastSvc.exe  

 AVAST Software Avast AvastUI.exe  

`````````````````System Health check````````````````` 

 Total Fragmentation on Drive C: 0% 

````````````````````End of Log`````````````````````` 

Link to post
Share on other sites

Your system is all clean now! :)

 

 

Please uninstall IObit Malware Fighter - use Malwarebytes Antimalware instead.

 

 

Uninstall our tools using delfix

Please follow these steps in order:

  1. In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button.
  2. In the case we used Combofix. Deactivate your antivirus software once more, then rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed.
  3. In any case please download delfix to your desktop.
    • Close all other programms and start delfix.
    • Please check all the boxes and run the tool.
    • delfix will now delete all found traces of our removal process

[*] If there is still something left please delete it manualy.

 

 

 

 

How to protect yourself

  • System Updates
    Beeing up to date is very important. Please be sure to activate automatic updates in your control panel.
    Windows XP | Windows Vista |
    Windows 7 | windows 8
  • Protection
    What you need is one (not more) good virus scanner with backgroud protection. Additionally I recommend a special malwarescanner that you run from time to time.
    Personally I am using the avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer you good protection for free use. But please remember: You get only the full protection if you use the payed versions of your security software.
  • Up to date Software
    Stay up to date with all the programs you use. Some of those really have to have an eye on are: your browser(s) including add-ons and plug-ins, Java, Flash Player, your virus scanner, and basically every software you use often. These link may help you to check:

    [*] Backups
    There are chances for an emergency every day. So be prepared. Back up your data on a regular basis. If you burn it to DVDs from time to time, use a cloud-drive or a professional network backup system is your choice. [*] Brains
    It's no joke! You really need one of those things. :) It is very important not just to click anywhere it is colored or flashing while you surfing on the web. Do not click an OK button on any popping window without reading what it says. While installing software always choose the custom mode, read what those windows says and uncheck adware that will be installed along the software you want.

Link to post
Share on other sites

The Final TOSHIBA Advanced SystemCare Diagnose Report v1.0

 

Advanced SystemCare Diagnose Report v1.0

Date: 2013/07/16 17:56:28

 

----------------------------------

01 - Operating System

----------------------------------

 

0101 - Operating System         : Windows 7 Professional 64-bit (6.1, Build 7601) Service Pack 1 (7601.win7sp1_gdr.130318-1533)

0102 - Language                 : English (Regional Setting: English)

0103 - BIOS                     : BIOS Version 1.80   

0104 - Processor                : Intel® Pentium® Dual  CPU  T2330  @ 1.60GHz (2 CPUs), ~1.6GHz

0105 - Memory                   : 1024MB RAM

0106 - Available OS Memory      : 1014MB RAM

0107 - Page File                : 1896MB used, 708MB available

0108 - Windows Dir              : C:\Windows

0109 - DirectX Version          : DirectX 11

0110 - DX Setup Parameters      : Not found

0111 - User DPI Setting         : Using System DPI

0112 - System DPI Setting       : 96 DPI (100 percent)

0113 - DWM DPI Scaling          : Disabled

0114 - DxDiag Version           : 6.01.7601.17514

 

----------------------------------

02 - Processor

----------------------------------

 

0201 - Caption                  : Intel® Pentium® Dual  CPU  T2330  @ 1.60GHz x2 ~1600MHz

0202 - Current Clock Speed      : 1600MHz

0203 - L1 Cache                 : 64.00 KB

0204 - L2 Cache                 : 1.00 MB

 

----------------------------------

03 - Video Adapter

----------------------------------

 

0301 - Card Name                : Mobile Intel® 965 Express Chipset Family

0302 - Manufacturer             : Intel Corporation

0303 - Chip Type                : Mobile Intel® 965 Express Chipset Family

0304 - DAC Type                 : Internal

0305 - Device Key               : Enum\PCI\VEN_8086&DEV_2A02&SUBSYS_FF101179&REV_03

0306 - Display Memory           : 251 MB

0307 - AdapterRAM               : 256.00 MB

0308 - Current Mode             : 1280 x 800 (32 bit) (60Hz)

0309 - Monitor Name             : Generic PnP Monitor

0310 - Driver Name              : igdumd64.dll,igd10umd64.dll,igdumdx32,igd10umd32

0311 - Driver Version           : 8.14.0010.1930

0312 - Driver Language          : English

0313 - DDI Version              : 10

0314 - Driver Model             : WDDM 1.1

0315 - Driver Beta              : False

0316 - Driver Debug             : False

0317 - Driver Date              : 9/23/2009 19:22:58

0318 - Driver Size              : 5472256

0319 - VDD                      : n/a

0320 - Mini VDD                 : n/a

0321 - Mini VDD Date            : n/a

0322 - Mini VDD Size            : 0

0323 - Device Identifier        : {D7B78E66-6942-11CF-4375-1ADFA2C2C535}

0324 - Vendor ID                : 0x8086

0325 - Device ID                : 0x2A02

0326 - SubSys ID                : 0xFF101179

0327 - Revision ID              : 0x0003

0328 - Driver Strong Name       : oem2.inf:Intel.Mfg.NTamd64:i965GM0:8.15.10.1930:pci\ven_8086&dev_2a02

0329 - Rank Of Driver           : 00EC2001

0330 - Video Accel              : ModeMPEG2_A ModeMPEG2_C ModeWMV9_B ModeVC1_B

0331 - Deinterlace Caps         : {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

                                  {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

                                  {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

                                  {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

                                  {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

                                  {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

                                  {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

                                  {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering

 

                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch

                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend

0332 - D3D9 Overlay             : Not Supported

0333 - DXVA-HD                  : Not Supported

0334 - DDraw Status             : Enabled

0335 - D3D Status               : Enabled

0336 - AGP Status               : Enabled

0337 - Notes                    : No problems found.

 

0338 - OpenGL                   : 6.1.7600.16385 (win7_rtm.090713-1255)

 

----------------------------------

04 - Memory

----------------------------------

 

0401 - Total Memory             : 1014.40 MB

0402 - Free Memory              : 86.36 MB

0403 - Total Pagefile           : 2.54 GB

0404 - Free Pagefile            : 702.45 MB

 

0405 - Bank Label               : Bank 0

0406 - Speed                    : 667 MHz

0407 - Total Width              : 64 Bits

0408 - Capacity                 : 512.00 MB

 

0405 - Bank Label               : Bank 1

0406 - Speed                    : 667 MHz

0407 - Total Width              : 64 Bits

0408 - Capacity                 : 512.00 MB

 

----------------------------------

05 - Network

----------------------------------

 

0501 - Description              : Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter

0502 - Driver Date              : 3-31-2010

0503 - Driver Version           : 62.1182.331.2010

 

----------------------------------

06 - Motherboard

----------------------------------

 

0601 - Model                    : SANTA ROSA CRB

0602 - Manufacturer             : Intel Corporation

 

----------------------------------

07 - Sound Device

----------------------------------

 

0701 - Description              : Speakers (High Definition Audio Device)

0702 - Default Sound Playback   : True

0703 - Default Voice Playback   : True

0704 - Hardware ID              : HDAUDIO\FUNC_01&VEN_10EC&DEV_0268&SUBSYS_1179FF14&REV_1000

0705 - Manufacturer ID          : 1

0706 - Product ID               : 65535

0707 - Type                     : WDM

0708 - Driver Name              : HdAudio.sys

0709 - Driver Version           : 6.01.7601.17514

0710 - Driver attributes        : Final Retail

0711 - Date and Size            : 11/20/2010 20:23:47

0713 - Driver Provider          : Microsoft

0714 - Min/Max Sample Rate      : 4316782, 4316782

0715 - Static/Strm HW Mix Bufs  : 4316782, 4316782

0716 - Static/Strm HW 3D Bufs   : 4316782, 4316782

0717 - HW Memory                : 4316790

0718 - Voice Management         : False

0719 - EAX 2.0 Listen/Src   : False, False

0720 - I3DL2 Listen/Src     : False, False

0721 - Notes                    : No problems found.

 

 

----------------------------------

08 - Hard Disk

----------------------------------

 

0801 - Model                    : FUJITSU MHY2120BH ATA Device

0802 - Media Type               : Fixed hard disk media

0803 - Size                     : 111.79 GB

0805 - Driver Date              : 6-21-2006

0806 - Driver Version           : 6.1.7600.16385

 

0807 - Caption                  : C:\

0808 - Capacity                 : 111.69 GB

0809 - Free Space               : 85.69 GB

0810 - Drive Type               : 3-Fixed

0811 - File System              : NTFS

 

----------------------------------

09 - Process

----------------------------------

 

0901 - 0000 Idle                   0 0    0               

0901 - 0004 System                 0 0    0               

0901 - 0110 smss.exe               0 0    0   normal      

0901 - 0170 csrss.exe              0 0    0   normal      

0901 - 019c wininit.exe            0 0    0   high        

0901 - 01b0 csrss.exe              1 174  88  normal      

0901 - 01dc services.exe           0 0    0   normal      

0901 - 01ec lsass.exe              0 0    0   normal      

0901 - 01f4 lsm.exe                0 0    0   normal      

0901 - 022c winlogon.exe           1 6    0   high        

0901 - 028c svchost.exe            0 0    0   normal      

0901 - 02c4 ASCService.exe         0 0    0   high         C:\Program Files (x86)\IObit\Advanced SystemCare 6

0901 - 030c svchost.exe            0 0    0   normal      

0901 - 0360 svchost.exe            0 0    0   normal       

0901 - 0394 svchost.exe            0 0    0   normal      

0901 - 03c0 svchost.exe            0 0    0   normal      

0901 - 03e0 svchost.exe            0 0    0   normal      

0901 - 0138 svchost.exe            0 0    0   normal      

0901 - 0250 svchost.exe            0 0    0   normal      

0901 - 0458 AvastSvc.exe           0 0    0   normal       C:\Program Files\AVAST Software\Avast

0901 - 0530 dwm.exe                1 17   2   high        

0901 - 0548 explorer.exe           1 432  260 normal       

0901 - 05e4 Suo10_SmartRAM.exe     1 213  44  normal       C:\Program Files (x86)\IObit\Advanced SystemCare 6

0901 - 0658 AvastUI.exe            1 159  50  normal       C:\Program Files\AVAST Software\Avast

0901 - 06f0 taskhost.exe           1 23   21  normal      

0901 - 04f8 spoolsv.exe            0 0    0   normal      

0901 - 0140 svchost.exe            0 0    0   normal      

0901 - 067c SASCore64.exe          0 0    0   normal      

0901 - 05d0 svchost.exe            0 0    0   normal      

0901 - 08a8 taskeng.exe            0 0    0   below normal

0901 - 08d0 taskeng.exe            1 9    3   normal      

0901 - 0910 Monitor.exe            1 216  43  below normal C:\Program Files (x86)\IObit\Advanced SystemCare 6

0901 - 04c0 rndlresolversvc.exe    0 0    0   normal       C:\Program Files (x86)\RealNetworks\RealDownloader

0901 - 09c4 SDFSSvc.exe            0 0    0   normal       C:\Program Files (x86)\Spybot - Search & Destroy 2

0901 - 0bbc SynTPEnh.exe           1 64   34  above normal

0901 - 0984 igfxpers.exe           1 9    5   normal      

0901 - 0b58 igfxsrvc.exe           1 9    3   normal      

0901 - 05c0 hkcmd.exe              1 9    16  normal      

0901 - 0994 igfxtray.exe           1 11   6   normal      

0901 - 0480 REALSCHED.EXE          1 9    10  normal       C:\PROGRAM FILES (X86)\REAL\REALPLAYER\UPDATE

0901 - 08bc JUSCHED.EXE            1 9    2   normal       C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE

0901 - 0528 svchost.exe            0 0    0   normal      

0901 - 0a18 TeamViewer_Service.exe 0 0    0   normal       C:\Program Files (x86)\TeamViewer\Version8

0901 - 0a24 svchost.exe            0 0    0   normal      

0901 - 0768 SDUpdSvc.exe           0 0    0   normal       C:\Program Files (x86)\Spybot - Search & Destroy 2

0901 - 0e2c SDWSCSvc.exe           0 0    0   normal       C:\Program Files (x86)\Spybot - Search & Destroy 2

0901 - 0f60 SearchIndexer.exe      0 0    0   normal      

0901 - 0fb4 wmpnetwk.exe           0 0    0   normal      

0901 - 0f6c svchost.exe            0 0    0   normal      

0901 - 11e8 SynTPHelper.exe        1 9    3   above normal

0901 - 0ff8 mbamservice.exe        0 0    0   normal       C:\Program Files (x86)\Malwarebytes' Anti-Malware

0901 - 0c80 mbamgui.exe            1 28   25  normal       C:\Program Files (x86)\Malwarebytes' Anti-Malware

0901 - 100c taskhost.exe           1 9    4   normal      

0901 - 089c ctfmon.exe             1 19   8   normal       C:\Windows\SysWOW64

0901 - 117c svchost.exe            0 0    0   below normal

0901 - 0c78 chrome.exe             1 130  70  normal       C:\Program Files (x86)\Google\Chrome\Application

0901 - 0c10 chrome.exe             1 13   2   normal       C:\Program Files (x86)\Google\Chrome\Application

0901 - 0a1c chrome.exe             1 483  1   below normal C:\Program Files (x86)\Google\Chrome\Application

0901 - 1118 chrome.exe             1 9    1   normal       C:\Program Files (x86)\Google\Chrome\Application

0901 - 0ee4 chrome.exe             1 10   1   normal       C:\Program Files (x86)\Google\Chrome\Application

0901 - 0f00 chrome.exe             1 10   1   normal       C:\Program Files (x86)\Google\Chrome\Application

0901 - 10ac chrome.exe             1 10   1   normal       C:\Program Files (x86)\Google\Chrome\Application

0901 - 0c48 chrome.exe             1 21   19  normal       C:\Program Files (x86)\Google\Chrome\Application

0901 - 1268 audiodg.exe            0 0    0               

0901 - 124c ASC.exe                1 2672 143 normal       C:\Program Files (x86)\IObit\Advanced SystemCare 6

0901 - 0e18 WmiPrvSE.exe           0 0    0   normal      

0901 - 1274 ASCTray.exe            1 59   27  normal       C:\Program Files (x86)\IObit\Advanced SystemCare 6

0901 - 13d4 Sus10_SysExplorer.exe  1 102  47  normal       C:\Program Files (x86)\IObit\Advanced SystemCare 6

 

 

----------------------------------

10 - Service

----------------------------------

 

1001 - SAS Core Service - ["C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"]

1001 - Advanced SystemCare Service 6 - [C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe]

1001 - Application Experience - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - Application Information - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - Windows Audio Endpoint Builder - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - Windows Audio - [C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted]

1001 - avast! Antivirus - ["C:\Program Files\AVAST Software\Avast\AvastSvc.exe"]

1001 - Base Filtering Engine - [C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork]

1001 - Background Intelligent Transfer Service - [C:\Windows\System32\svchost.exe -k netsvcs]

1001 - Computer Browser - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - Cryptographic Services - [C:\Windows\system32\svchost.exe -k NetworkService]

1001 - DHCP Client - [C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted]

1001 - DNS Client - [C:\Windows\system32\svchost.exe -k NetworkService]

1001 - Extensible Authentication Protocol - [C:\Windows\System32\svchost.exe -k netsvcs]

1001 - Windows Event Log - [C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted]

1001 - COM+ Event System - [C:\Windows\system32\svchost.exe -k LocalService]

1001 - Function Discovery Provider Host - [C:\Windows\system32\svchost.exe -k LocalService]

1001 - Function Discovery Resource Publication - [C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation]

1001 - Windows Font Cache Service - [C:\Windows\system32\svchost.exe -k LocalService]

1001 - HomeGroup Listener - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - HomeGroup Provider - [C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted]

1001 - CNG Key Isolation - [C:\Windows\system32\lsass.exe]

1001 - Server - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - Workstation - [C:\Windows\System32\svchost.exe -k NetworkService]

1001 - TCP/IP NetBIOS Helper - [C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted]

1001 - MBAMService - ["C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe"]

1001 - Multimedia Class Scheduler - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - Windows Firewall - [C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork]

1001 - Network Connections - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - Network List Service - [C:\Windows\System32\svchost.exe -k LocalService]

1001 - Network Location Awareness - [C:\Windows\System32\svchost.exe -k NetworkService]

1001 - Network Store Interface Service - [C:\Windows\system32\svchost.exe -k LocalService]

1001 - Peer Networking Identity Manager - [C:\Windows\System32\svchost.exe -k LocalServicePeerNet]

1001 - Peer Networking Grouping - [C:\Windows\System32\svchost.exe -k LocalServicePeerNet]

1001 - Program Compatibility Assistant Service - [C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - Plug and Play - [C:\Windows\system32\svchost.exe -k DcomLaunch]

1001 - Peer Name Resolution Protocol - [C:\Windows\System32\svchost.exe -k LocalServicePeerNet]

1001 - Power - [C:\Windows\system32\svchost.exe -k DcomLaunch]

1001 - User Profile Service - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - Remote Access Connection Manager - [C:\Windows\System32\svchost.exe -k netsvcs]

1001 - RealNetworks Downloader Resolver Service - ["C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe"]

1001 - Security Accounts Manager - [C:\Windows\system32\lsass.exe]

1001 - Windows Backup - [C:\Windows\system32\svchost.exe -k SDRSVC]

1001 - Spybot-S&D 2 Scanner Service - ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"]

1001 - Spybot-S&D 2 Updating Service - ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe"]

1001 - Spybot-S&D 2 Security Center Service - [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe]

1001 - Secondary Logon - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - System Event Notification Service - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - Shell Hardware Detection - [C:\Windows\System32\svchost.exe -k netsvcs]

1001 - Print Spooler - [C:\Windows\System32\spoolsv.exe]

1001 - SSDP Discovery - [C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation]

1001 - Secure Socket Tunneling Protocol Service - [C:\Windows\system32\svchost.exe -k LocalService]

1001 - Windows Image Acquisition (WIA) - [C:\Windows\system32\svchost.exe -k imgsvc]

1001 - Superfetch - [C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - Telephony - [C:\Windows\System32\svchost.exe -k NetworkService]

1001 - TeamViewer 8 - ["C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"]

1001 - Themes - [C:\Windows\System32\svchost.exe -k netsvcs]

1001 - Distributed Link Tracking Client - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - Desktop Window Manager Session Manager - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - Windows Defender - [C:\Windows\System32\svchost.exe -k secsvcs]

1001 - Windows Management Instrumentation - [C:\Windows\system32\svchost.exe -k netsvcs]

1001 - WLAN AutoConfig - [C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted]

1001 - Windows Media Player Network Sharing Service - ["C:\Program Files\Windows Media Player\wmpnetwk.exe"]

1001 - Security Center - [C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted]

1001 - Windows Search - [C:\Windows\system32\SearchIndexer.exe /Embedding]

1001 - Windows Update - [C:\Windows\system32\svchost.exe -k netsvcs]

 

----------------------------------

11 - Windows Express

----------------------------------

 

1101 - System Score             : 3

1102 - Memory Score             : 4.5

1103 - CPU Score                : 4.5

1104 - Graphics Score           : 3.1

1105 - Gaming Score             : 3

1106 - Disk Score               : 5

 

----------------------------------

12 - Event Log

----------------------------------

 

1201 - Time                     : 7/17/2013 1:56:14 AM

1202 - Source                   : Application Error

1203 - Description              : Faulting application name: TWCApp.exe, version: 7.5.3.0, time stamp: 0x51c84ddd Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015, time stamp: 0x50b83c8a Exception code: 0xe0434352 Fault offset: 0x0000c41f Faulting process id: 0xc84 Faulting application start time: 0x01ce824db65c7667 Faulting application path: C:\Program Files (x86)\The Weather Channel\The Weather Channel App\TWCApp.exe Faulting module path: C:\Windows\syswow64\KERNELBASE.dll Report Id: 010d87c6-ee41-11e2-ae27-00a0d19736d0

 

1201 - Time                     : 7/16/2013 5:14:48 PM

1202 - Source                   : WinMgmt

1203 - Description              : Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

 

1201 - Time                     : 7/16/2013 4:48:27 PM

1202 - Source                   : WinMgmt

1203 - Description              : Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

 

1201 - Time                     : 7/16/2013 4:33:00 PM

1202 - Source                   : WinMgmt

1203 - Description              : Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

 

1201 - Time                     : 7/16/2013 4:26:42 PM

1202 - Source                   : WinMgmt

1203 - Description              : Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

 

1201 - Time                     : 7/16/2013 3:20:00 PM

1202 - Source                   : WinMgmt

1203 - Description              : Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

 

1201 - Time                     : 7/16/2013 1:00:11 PM

1202 - Source                   : WinMgmt

1203 - Description              : Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

 

1201 - Time                     : 7/16/2013 4:23:01 AM

1202 - Source                   : WinMgmt

1203 - Description              : Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

 

1201 - Time                     : 7/16/2013 3:29:32 AM

1202 - Source                   : SideBySide

1203 - Description              : Activation context generation failed for "c:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

 

1201 - Time                     : 7/16/2013 2:59:05 AM

1202 - Source                   : WinMgmt

1203 - Description              : Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

 

1201 - Time                     : 7/16/2013 5:20:30 PM

1202 - Source                   : yukonw7

1203 - Description              : Driver status 1

 

1201 - Time                     : 7/16/2013 5:20:30 PM

1202 - Source                   : yukonw7

1203 - Description              : Driver status 1

 

1201 - Time                     : 7/16/2013 5:20:30 PM

1202 - Source                   : yukonw7

1203 - Description              : Driver status 1

 

1201 - Time                     : 7/16/2013 5:13:14 PM

1202 - Source                   : Service Control Manager

1203 - Description              : The MBAMService service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.

 

1201 - Time                     : 7/16/2013 5:13:14 PM

1202 - Source                   : Service Control Manager

1203 - Description              : A timeout was reached (30000 milliseconds) while waiting for the MBAMService service to connect.

 

1201 - Time                     : 7/16/2013 5:12:30 PM

1202 - Source                   : Service Control Manager

1203 - Description              : The MBAMScheduler service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.

 

1201 - Time                     : 7/16/2013 5:12:30 PM

1202 - Source                   : Service Control Manager

1203 - Description              : A timeout was reached (30000 milliseconds) while waiting for the MBAMScheduler service to connect.

 

1201 - Time                     : 7/16/2013 4:47:22 PM

1202 - Source                   : EventLog

1203 - Description              : The previous system shutdown at 1:44:54 AM on ‎7/‎16/‎2013 was unexpected.

 

1201 - Time                     : 7/16/2013 4:26:44 PM

1202 - Source                   : Service Control Manager

1203 - Description              : The Security Center service terminated with the following error:  The authentication service is unknown.

 

1201 - Time                     : 7/16/2013 4:26:44 PM

1202 - Source                   : Service Control Manager

1203 - Description              : The Background Intelligent Transfer Service service terminated with service-specific error %%-2147024846.

 

----------------------------------

End of file - 31298 Bytes

Link to post
Share on other sites

Im FREE!!!!!!!!!!!!!!!!!!!!!!!! LOL

 

My Mother In-Lawns pc HP

 

Advanced SystemCare Diagnose Report v1.0
Date: 2013/07/17 12:35:41
 
----------------------------------
01 - Operating System
----------------------------------
 
0101 - Operating System         : Windows 7 Home Premium 64-bit (6.1, Build 7601) Service Pack 1 (7601.win7sp1_gdr.130318-1533)
0102 - Language                 : English (Regional Setting: English)
0103 - BIOS                     : InsydeH2O Version CCB.03.61.09F.1A
0104 - Processor                : AMD A4-3305M APU with Radeon HD Graphics (2 CPUs), ~1.9GHz
0105 - Memory                   : 4096MB RAM
0106 - Available OS Memory      : 3562MB RAM
0107 - Page File                : 1888MB used, 5233MB available
0108 - Windows Dir              : C:\Windows
0109 - DirectX Version          : DirectX 11
0110 - DX Setup Parameters      : Not found
0111 - User DPI Setting         : Using System DPI
0112 - System DPI Setting       : 96 DPI (100 percent)
0113 - DWM DPI Scaling          : Disabled
0114 - DxDiag Version           : 6.01.7601.17514
 
----------------------------------
02 - Processor
----------------------------------
 
0201 - Caption                  : AMD A4-3305M APU with Radeon HD Graphics x2 ~1900MHz
0202 - Current Clock Speed      : 1900MHz
0203 - L1 Cache                 : 256.00 KB
0204 - L2 Cache                 : 1.00 MB
 
----------------------------------
03 - Video Adapter
----------------------------------
 
0301 - Card Name                : AMD Radeon HD 6480G
0302 - Manufacturer             : Advanced Micro Devices, Inc.
0303 - Chip Type                : ATI display adapter (0x9649)
0304 - DAC Type                 : Internal DAC(400MHz)
0305 - Device Key               : Enum\PCI\VEN_1002&DEV_9649&SUBSYS_358B103C&REV_00
0306 - Display Memory           : 2022 MB
0307 - AdapterRAM               : 512.00 MB
0308 - Current Mode             : 1366 x 768 (32 bit) (60Hz)
0309 - Monitor Name             : Generic PnP Monitor
0310 - Driver Name              : aticfx64.dll,aticfx64.dll,aticfx64.dll,aticfx32,aticfx32,aticfx32,atiumd64.dll,atidxx64.dll,atidxx64.dll,atiumdag,atidxx32,atidxx32,atiumdva,atiumd6a.cap,atitmm64.dll
0311 - Driver Version           : 8.17.0010.1099
0312 - Driver Language          : English
0313 - DDI Version              : 11
0314 - Driver Model             : WDDM 1.1
0315 - Driver Beta              : False
0316 - Driver Debug             : False
0317 - Driver Date              : 9/28/2011 22:15:26
0318 - Driver Size              : 867328
0319 - VDD                      : n/a
0320 - Mini VDD                 : n/a
0321 - Mini VDD Date            : n/a
0322 - Mini VDD Size            : 0
0323 - Device Identifier        : {D7B71EE2-D509-11CF-C777-8115BEC2C535}
0324 - Vendor ID                : 0x1002
0325 - Device ID                : 0x9649
0326 - SubSys ID                : 0x358B103C
0327 - Revision ID              : 0x0000
0328 - Driver Strong Name       : oem2.inf:ATI.Mfg.NTamd64.6.1:ati2mtag_Sumo_Mobile:8.900.7.1000:pci\ven_1002&dev_9649&subsys_358b103c
0329 - Rank Of Driver           : 00E60001
0330 - Video Accel              : ModeMPEG2_A ModeMPEG2_C 
0331 - Deinterlace Caps         : {6E8329FF-B642-418B-BCF0-BCB6591E255F}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_PixelAdaptive 
                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_BOBVerticalStretch 
                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY 
                                  {6E8329FF-B642-418B-BCF0-BCB6591E255F}: Format(In/Out)=(UYVY,UYVY) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_PixelAdaptive 
                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(UYVY,UYVY) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_BOBVerticalStretch 
                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(UYVY,UYVY) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY 
                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YV12,0x32315659) Frames(Prev/Fwd/Back)=(0,0,0) Caps=
                                  {3C5323C1-6FB7-44F5-9081-056BF2EE449D}: Format(In/Out)=(NV12,0x3231564e) Frames(Prev/Fwd/Back)=(0,0,2) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_PixelAdaptive 
                                  {552C0DAD-CCBC-420B-83C8-74943CF9F1A6}: Format(In/Out)=(NV12,0x3231564e) Frames(Prev/Fwd/Back)=(0,0,2) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_PixelAdaptive 
                                  {6E8329FF-B642-418B-BCF0-BCB6591E255F}: Format(In/Out)=(NV12,0x3231564e) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_PixelAdaptive 
                                  {335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(NV12,0x3231564e) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_BOBVerticalStretch 
                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(NV12,0x3231564e) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY 
                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC1,UNKNOWN) Frames(Prev/Fwd/Back)=(0,0,0) Caps=
                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC2,UNKNOWN) Frames(Prev/Fwd/Back)=(0,0,0) Caps=
                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC3,UNKNOWN) Frames(Prev/Fwd/Back)=(0,0,0) Caps=
                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC4,UNKNOWN) Frames(Prev/Fwd/Back)=(0,0,0) Caps=
                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(S340,UNKNOWN) Frames(Prev/Fwd/Back)=(0,0,0) Caps=
                                  {5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(S342,UNKNOWN) Frames(Prev/Fwd/Back)=(0,0,0) Caps=
0332 - D3D9 Overlay             : Not Supported
0333 - DXVA-HD                  : Not Supported
0334 - DDraw Status             : Enabled
0335 - D3D Status               : Enabled
0336 - AGP Status               : Enabled
0337 - Notes                    : No problems found.
 
0338 - OpenGL                   : 6.1.7600.16385 (win7_rtm.090713-1255)
 
----------------------------------
04 - Memory
----------------------------------
 
0401 - Total Memory             : 3.48 GB
0402 - Free Memory              : 2.04 GB
0403 - Total Pagefile           : 6.96 GB
0404 - Free Pagefile            : 5.11 GB
 
0405 - Bank Label               : BANK0
0406 - Speed                    : 1333 MHz
0407 - Total Width              : 64 Bits
0408 - Capacity                 : 4.00 GB
 
----------------------------------
05 - Network
----------------------------------
 
0501 - Description              : Realtek RTL8188CE 802.11b/g/n WiFi Adapter
0502 - Driver Date              : 7-12-2011
0503 - Driver Version           : 1005.24.712.2011
 
----------------------------------
06 - Motherboard
----------------------------------
 
0601 - Model                    : 1805
0602 - Manufacturer             : Hewlett-Packard
 
----------------------------------
07 - Sound Device
----------------------------------
 
0701 - Description              : Speakers and Headphones (IDT High Definition Audio CODEC)
0702 - Default Sound Playback   : True
0703 - Default Voice Playback   : False
0704 - Hardware ID              : HDAUDIO\FUNC_01&VEN_111D&DEV_7605&SUBSYS_103C358B&REV_1001
0705 - Manufacturer ID          : 1
0706 - Product ID               : 100
0707 - Type                     : WDM
0708 - Driver Name              : stwrt64.sys
0709 - Driver Version           : 6.10.6345.0000
0710 - Driver attributes        : Final Retail
0711 - Date and Size            : 6/2/2011 09:11:26
0713 - Driver Provider          : IDT
0714 - Min/Max Sample Rate      : 4316782, 4316782
0715 - Static/Strm HW Mix Bufs  : 4316782, 4316782
0716 - Static/Strm HW 3D Bufs   : 4316782, 4316782
0717 - HW Memory                : 4316790
0718 - Voice Management         : False
0719 - EAX 2.0 Listen/Src   : False, False
0720 - I3DL2 Listen/Src     : False, False
0721 - Notes                    : No problems found.
 
0701 - Description              : Communications Headphones (IDT High Definition Audio CODEC)
0702 - Default Sound Playback   : False
0703 - Default Voice Playback   : True
0704 - Hardware ID              : HDAUDIO\FUNC_01&VEN_111D&DEV_7605&SUBSYS_103C358B&REV_1001
0705 - Manufacturer ID          : 1
0706 - Product ID               : 100
0707 - Type                     : WDM
0708 - Driver Name              : stwrt64.sys
0709 - Driver Version           : 6.10.6345.0000
0710 - Driver attributes        : Final Retail
0711 - Date and Size            : 6/2/2011 09:11:26
0713 - Driver Provider          : IDT
0714 - Min/Max Sample Rate      : 4316782, 4316782
0715 - Static/Strm HW Mix Bufs  : 4316782, 4316782
0716 - Static/Strm HW 3D Bufs   : 4316782, 4316782
0717 - HW Memory                : 4316790
0718 - Voice Management         : False
0719 - EAX 2.0 Listen/Src   : False, False
0720 - I3DL2 Listen/Src     : False, False
0721 - Notes                    : No problems found.
 
 
----------------------------------
08 - Hard Disk
----------------------------------
 
0801 - Model                    : WDC WD50 00BPVT-22HXZT3 SATA Disk Device(Western Digital)
0802 - Media Type               : Fixed hard disk media
0803 - Size                     : 465.76 GB
0805 - Driver Date              : 6-21-2006
0806 - Driver Version           : 6.1.7600.16385
 
0807 - Caption                  : C:\
0808 - Capacity                 : 440.01 GB
0809 - Free Space               : 398.60 GB
0810 - Drive Type               : 3-Fixed
0811 - File System              : NTFS
 
0807 - Caption                  : D:\
0808 - Capacity                 : 21.58 GB
0809 - Free Space               : 2.32 GB
0810 - Drive Type               : 3-Fixed
0811 - File System              : NTFS
 
0807 - Caption                  : E:\
0808 - Capacity                 : 3.96 GB
0809 - Free Space               : 1.08 GB
0810 - Drive Type               : 3-Fixed
0811 - File System              : FAT32
 
----------------------------------
09 - Process
----------------------------------
 
0901 - 0000 Idle                      0 0    0                
0901 - 0004 System                    0 0    0                
0901 - 0134 smss.exe                  0 0    0   normal       
0901 - 01e4 csrss.exe                 0 0    0   normal       
0901 - 022c wininit.exe               0 0    0   high         
0901 - 026c services.exe              0 0    0   normal       
0901 - 027c lsass.exe                 0 0    0   normal       
0901 - 0284 lsm.exe                   0 0    0   normal       
0901 - 02f8 svchost.exe               0 0    0   normal       
0901 - 0330 ASCService.exe            0 0    0   high         C:\Program Files (x86)\IObit\Advanced SystemCare 6
0901 - 036c TrueSuiteService.exe      0 0    0   normal       C:\Program Files (x86)\HP SimplePass 2012
0901 - 03a8 svchost.exe               0 0    0   normal       
0901 - 03f4 atiesrxx.exe              0 0    0   normal       
0901 - 01dc svchost.exe               0 0    0   normal       
0901 - 01e8 svchost.exe               0 0    0   normal       
0901 - 0428 svchost.exe               0 0    0   normal       
0901 - 044c svchost.exe               0 0    0   normal       
0901 - 0484 audiodg.exe               0 0    0                
0901 - 04a4 svchost.exe               0 0    0   normal       
0901 - 04f8 hpservice.exe             0 0    0   normal       
0901 - 05b0 WUDFHost.exe              0 0    0   normal       
0901 - 0650 svchost.exe               0 0    0   normal       
0901 - 06a0 AvastSvc.exe              0 0    0   normal       C:\Program Files\AVAST Software\Avast
0901 - 0710 spoolsv.exe               0 0    0   normal       
0901 - 0764 svchost.exe               0 0    0   normal       
0901 - 077c IMFsrv.exe                0 0    0   normal       C:\Program Files (x86)\IObit\IObit Malware Fighter
0901 - 047c armsvc.exe                0 0    0   normal       C:\Program Files (x86)\Common Files\Adobe\ARM\1.0
0901 - 0544 Fuel.Service.exe          0 0    0   normal       
0901 - 06bc svchost.exe               0 0    0   normal       
0901 - 05fc HPClientServices.exe      0 0    0   normal       
0901 - 0820 HPDrvMntSvc.exe           0 0    0   normal       C:\Program Files (x86)\Hewlett-Packard\Shared
0901 - 0838 HPWMISVC.exe              0 0    0   normal       C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch
0901 - 0850 RIconMan.exe              0 0    0   normal       
0901 - 0878 rndlresolversvc.exe       0 0    0   normal       C:\Program Files (x86)\RealNetworks\RealDownloader
0901 - 0934 svchost.exe               0 0    0   normal       
0901 - 0990 TeamViewer_Service.exe    0 0    0   normal       C:\Program Files (x86)\TeamViewer\Version8
0901 - 0a18 taskeng.exe               0 0    0   below normal 
0901 - 0a98 GoogleCrashHandler.exe    0 0    0   idle         C:\Program Files (x86)\Google\Update\1.3.21.153
0901 - 0aa0 GoogleCrashHandler64.exe  0 0    0   idle         
0901 - 0a24 ToolbarUpdater.exe        0 0    0   normal       C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0
0901 - 0874 WLIDSVC.EXE               0 0    0   normal       
0901 - 0c50 WLIDSVCM.EXE              0 0    0   normal       
0901 - 0c88 WmiPrvSE.exe              0 0    0   normal       
0901 - 0cf4 YahooAUService.exe        0 0    0   normal       C:\Program Files (x86)\Yahoo!\SoftwareUpdate
0901 - 0ec8 svchost.exe               0 0    0   normal       
0901 - 1014 SearchIndexer.exe         0 0    0   normal       
0901 - 10c0 wmpnetwk.exe              0 0    0   normal       
0901 - 131c svchost.exe               0 0    0   normal       
0901 - 102c dllhost.exe               0 0    0   normal       
0901 - 1608 HPSA_Service.exe          0 0    0   normal       
0901 - 16b4 svchost.exe               0 0    0   normal       
0901 - 0984 PresentationFontCache.exe 0 0    0   normal       
0901 - 1088 TrustedInstaller.exe      0 0    0   normal       
0901 - 1530 WUDFHost.exe              0 0    0   normal       
0901 - 0b28 svchost.exe               0 0    0   normal       
0901 - 1214 csrss.exe                 2 174  85  normal       
0901 - 1670 winlogon.exe              2 6    0   high         
0901 - 05a0 atieclxx.exe              2 9    5   normal       
0901 - 0718 taskhost.exe              2 22   26  normal       
0901 - 1650 taskeng.exe               2 10   3   normal       
0901 - 1604 dwm.exe                   2 16   2   high         
0901 - 0f00 explorer.exe              2 283  193 normal       
0901 - 13a4 taskeng.exe               2 9    3   normal       
0901 - 02e0 TouchControl.exe          2 17   14  normal       C:\Program Files (x86)\HP SimplePass 2012
0901 - 11f4 BioMonitor.exe            2 9    5   normal       C:\Program Files (x86)\HP SimplePass 2012
0901 - 11f8 ASCTray.exe               2 59   27  normal       C:\Program Files (x86)\IObit\Advanced SystemCare 6
0901 - 1728 WebCakeDesktop.exe        2 4    1   normal       C:\Users\Aarons\AppData\Roaming\WebCake
0901 - 0f04 unsecapp.exe              2 9    3   normal       
0901 - 14c4 SearchProtection.exe      2 20   14  normal       C:\Users\Aarons\AppData\Roaming\Search Protection
0901 - 0c40 hpqwutils.exe             2 13   7   normal       C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb
0901 - 0e34 AvastUI.exe               2 134  35  normal       C:\Program Files\AVAST Software\Avast
0901 - 1544 jusched.exe               2 9    2   normal       C:\Program Files (x86)\Common Files\Java\Java Update
0901 - 0e58 realsched.exe             2 9    10  normal       C:\Program Files (x86)\Real\RealPlayer\Update
0901 - 03d8 WmiPrvSE.exe              0 0    0   normal       
0901 - 0e70 IELowutil.exe             2 9    3   normal       C:\Program Files (x86)\Internet Explorer
0901 - 0980 YCMMirage.exe             2 18   9   below normal C:\Program Files (x86)\CyberLink\YouCam
0901 - 11c0 chrome.exe                2 107  60  normal       C:\Program Files (x86)\Google\Chrome\Application
0901 - 10a4 MOM.exe                   2 9    9   normal       
0901 - 0a94 chrome.exe                2 13   3   normal       C:\Program Files (x86)\Google\Chrome\Application
0901 - 07f8 chrome.exe                2 10   1   normal       C:\Program Files (x86)\Google\Chrome\Application
0901 - 129c chrome.exe                2 21   19  normal       C:\Program Files (x86)\Google\Chrome\Application
0901 - 1704 CCC.exe                   2 36   31  normal       
0901 - 17a4 chrome.exe                2 369  1   below normal C:\Program Files (x86)\Google\Chrome\Application
0901 - 04dc ASC.exe                   2 2755 143 normal       C:\Program Files (x86)\IObit\Advanced SystemCare 6
0901 - 0c44 Sus10_SysExplorer.exe     2 102  46  normal       C:\Program Files (x86)\IObit\Advanced SystemCare 6
 
 
----------------------------------
10 - Service
----------------------------------
 
1001 - Adobe Acrobat Update Service - ["C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"]
1001 - Advanced SystemCare Service 6 - [C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe]
1001 - Application Experience - [C:\Windows\system32\svchost.exe -k netsvcs]
1001 - AMD External Events Utility - [C:\Windows\system32\atiesrxx.exe]
1001 - AMD FUEL Service - [C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe /launchService]
1001 - Application Information - [C:\Windows\system32\svchost.exe -k netsvcs]
1001 - Windows Audio Endpoint Builder - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]
1001 - Windows Audio - [C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted]
1001 - avast! Antivirus - ["C:\Program Files\AVAST Software\Avast\AvastSvc.exe"]
1001 - Base Filtering Engine - [C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork]
1001 - Background Intelligent Transfer Service - [C:\Windows\System32\svchost.exe -k netsvcs]
1001 - Computer Browser - [C:\Windows\System32\svchost.exe -k netsvcs]
1001 - Cryptographic Services - [C:\Windows\system32\svchost.exe -k NetworkService]
1001 - DHCP Client - [C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted]
1001 - DNS Client - [C:\Windows\system32\svchost.exe -k NetworkService]
1001 - Extensible Authentication Protocol - [C:\Windows\System32\svchost.exe -k netsvcs]
1001 - Windows Event Log - [C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted]
1001 - COM+ Event System - [C:\Windows\system32\svchost.exe -k LocalService]
1001 - Function Discovery Provider Host - [C:\Windows\system32\svchost.exe -k LocalService]
1001 - Function Discovery Resource Publication - [C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation]
1001 - Windows Font Cache Service - [C:\Windows\system32\svchost.exe -k LocalService]
1001 - Windows Presentation Foundation Font Cache 3.0.0.0 - [C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe]
1001 - TrueSuiteService - ["C:\Program Files (x86)\HP SimplePass 2012\TrueSuiteService.exe"]
1001 - Human Interface Device Access - [C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted]
1001 - HomeGroup Listener - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]
1001 - HomeGroup Provider - [C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted]
1001 - HP Support Assistant Service - ["C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"]
1001 - HP Client Services - ["C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe"]
1001 - HP Quick Synchronization Service - ["C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"]
1001 - HP Service - [C:\Windows\system32\Hpservice.exe]
1001 - HPWMISVC - [C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe]
1001 - IconMan_R - ["C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"]
1001 - IKE and AuthIP IPsec Keying Modules - [C:\Windows\system32\svchost.exe -k netsvcs]
1001 - IMF Service - [C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe]
1001 - CNG Key Isolation - [C:\Windows\system32\lsass.exe]
1001 - Server - [C:\Windows\system32\svchost.exe -k netsvcs]
1001 - Workstation - [C:\Windows\System32\svchost.exe -k NetworkService]
1001 - TCP/IP NetBIOS Helper - [C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted]
1001 - Multimedia Class Scheduler - [C:\Windows\system32\svchost.exe -k netsvcs]
1001 - Windows Firewall - [C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork]
1001 - Network Connections - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]
1001 - Network List Service - [C:\Windows\System32\svchost.exe -k LocalService]
1001 - Network Location Awareness - [C:\Windows\System32\svchost.exe -k NetworkService]
1001 - Network Store Interface Service - [C:\Windows\system32\svchost.exe -k LocalService]
1001 - Peer Networking Identity Manager - [C:\Windows\System32\svchost.exe -k LocalServicePeerNet]
1001 - Peer Networking Grouping - [C:\Windows\System32\svchost.exe -k LocalServicePeerNet]
1001 - Program Compatibility Assistant Service - [C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted]
1001 - Plug and Play - [C:\Windows\system32\svchost.exe -k DcomLaunch]
1001 - Peer Name Resolution Protocol - [C:\Windows\System32\svchost.exe -k LocalServicePeerNet]
1001 - IPsec Policy Agent - [C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted]
1001 - Power - [C:\Windows\system32\svchost.exe -k DcomLaunch]
1001 - User Profile Service - [C:\Windows\system32\svchost.exe -k netsvcs]
1001 - RealNetworks Downloader Resolver Service - ["C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe"]
1001 - Security Accounts Manager - [C:\Windows\system32\lsass.exe]
1001 - System Event Notification Service - [C:\Windows\system32\svchost.exe -k netsvcs]
1001 - Shell Hardware Detection - [C:\Windows\System32\svchost.exe -k netsvcs]
1001 - Print Spooler - [C:\Windows\System32\spoolsv.exe]
1001 - SSDP Discovery - [C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation]
1001 - Windows Image Acquisition (WIA) - [C:\Windows\system32\svchost.exe -k imgsvc]
1001 - Superfetch - [C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted]
1001 - Tablet PC Input Service - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]
1001 - TeamViewer 8 - ["C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"]
1001 - Themes - [C:\Windows\System32\svchost.exe -k netsvcs]
1001 - Distributed Link Tracking Client - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]
1001 - UPnP Device Host - [C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation]
1001 - Desktop Window Manager Session Manager - [C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted]
1001 - Credential Manager - [C:\Windows\system32\lsass.exe]
1001 - vToolbarUpdater15.3.0 - [C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe]
1001 - Windows Biometric Service - [C:\Windows\system32\svchost.exe -k WbioSvcGroup]
1001 - Windows Defender - [C:\Windows\System32\svchost.exe -k secsvcs]
1001 - WinHTTP Web Proxy Auto-Discovery Service - [C:\Windows\system32\svchost.exe -k LocalService]
1001 - Windows Management Instrumentation - [C:\Windows\system32\svchost.exe -k netsvcs]
1001 - WLAN AutoConfig - [C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted]
1001 - Windows Live ID Sign-in Assistant - ["C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"]
1001 - Windows Media Player Network Sharing Service - ["C:\Program Files\Windows Media Player\wmpnetwk.exe"]
1001 - Security Center - [C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted]
1001 - Windows Search - [C:\Windows\system32\SearchIndexer.exe /Embedding]
1001 - Windows Update - [C:\Windows\system32\svchost.exe -k netsvcs]
1001 - Windows Driver Foundation - User-mode Driver Framework - [C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted]
1001 - Yahoo! Updater - ["C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe"]
 
----------------------------------
11 - Windows Express
----------------------------------
 
1101 - System Score             : 4.5
1102 - Memory Score             : 5.9
1103 - CPU Score                : 5.7
1104 - Graphics Score           : 4.5
1105 - Gaming Score             : 6
1106 - Disk Score               : 5.8
 
----------------------------------
12 - Event Log
----------------------------------
 
1201 - Time                     : 7/18/2013 12:24:39 AM
1202 - Source                   : WinMgmt
1203 - Description              : Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. 
 
1201 - Time                     : 7/17/2013 5:31:58 AM
1202 - Source                   : SideBySide
1203 - Description              : Activation context generation failed for "C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe". Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. 
 
1201 - Time                     : 7/17/2013 2:16:48 AM
1202 - Source                   : WinMgmt
1203 - Description              : Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. 
 
1201 - Time                     : 7/17/2013 2:14:36 AM
1202 - Source                   : WinMgmt
1203 - Description              : Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. 
 
1201 - Time                     : 7/16/2013 3:00:19 PM
1202 - Source                   : Microsoft-Windows-CAPI2
1203 - Description              : Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.  Details: AddWin32ServiceFiles: Unable to back up image of service WebCake Desktop Updater since QueryServiceConfig API failed  System Error: The system cannot find the file specified. . 
 
1201 - Time                     : 7/16/2013 3:01:00 PM
1202 - Source                   : Microsoft-Windows-WindowsUpdateClient
1203 - Description              : Installation Failure: Windows failed to install the following update with error 0x800f020b: Western Digital Technologies - Other hardware - WD SES Device. 
 
----------------------------------
End of file - 28405 Bytes
Link to post
Share on other sites

I don´t need to see an IObit log - you should uninstall it.

 

Scan with DDS

Download DDS and save it to your desktop from here or here or
here.

Disable any script blocker, and then double click dds.scr to run the tool.

When done, DDS will open two (2) logs
DDS.txt
Attach.txt
Save both reports to your desktop.

 

 

 

Scan with Gmer rootkit scanner

Please download Gmer from here by clicking on the "Download EXE" Button.

  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )

    [*]Leave everything else as it is. [*]Close all other running programs as well as your Browser. [*]Click the Scan button & wait for it to finish. [*]Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post. [*]Save it where you can easily find it, such as your desktop. [*]Please post the content of the ark.txt here.


**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.