Not quite sure, help appreciated.

Random pop ups all the time

Laptop has randomly shut down

" A malicious IP address has been blocked " message quite often


Not sure what's going on, I've ran scans and the problem is still there. Thanks.





DDS (Ver_2012-11-20.01) - NTFS_AMD64 

Internet Explorer: 10.0.9200.16537  BrowserJavaVersion: 10.25.2

Run by Devin at 23:01:45 on 2013-07-21

Microsoft Windows 8  6.2.9200.0.1252.1.1033.18.8078.4916 [GMT -7:00]


AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}

AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}


============== Running Processes ===============


C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe

C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe


C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe

C:\Program Files (x86)\Bluetooth Suite\adminservice.exe

C:\Program Files\Intel\iCLS Client\HeciServer.exe


C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe


C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe

C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalServicePeerNet



C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe

C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe

C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe

C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe



C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe

C:\Program Files\ASUS\P4G\BatteryLife.exe

C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe


C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe

C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe


C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe

C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe

C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe

C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe

C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe

C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe

C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe

C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe


C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

C:\Program Files (x86)\Bluetooth Suite\BtTray.exe

C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe

C:\Program Files (x86)\ASUS\Splendid\ACMON.exe

C:\Program Files (x86)\Skype\Phone\Skype.exe

C:\Users\Devin\Local Settings\Apps\F.lux\flux.exe

C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe

C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe

C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe


C:\Program Files\WindowsApps\microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe\LiveComm.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe


C:\Program Files (x86)\Google\Chrome\Application\chrome.exe




============== Pseudo HJT Report ===============


uStart Page = about:blank


mWinlogon: Userinit = userinit.exe

BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

BHO: TopArcadeHits Games: {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Devin\AppData\Local\TopArcadeHits\Toparcadehits.dll

BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

uRun: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

uRun: [F.lux] "C:\Users\Devin\Local Settings\Apps\F.lux\flux.exe" /noshow

uRun: [uTorrent] "C:\Users\Devin\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED

uRun: [Power2GoExpress] "C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe"

uRun: [spybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe

mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"

mRun: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\\AsusWSPanel.exe /S

mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey

mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"

mPolicies-System: DisableCAD = dword:1

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll


TCP: NameServer =

TCP: Interfaces\{87621266-165B-4A9B-B0EF-D5B49875AED2} : DHCPNameServer =

Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

SSODL: WebCheck - <orphaned>

mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

x64-BHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll

x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll

x64-Run: [igfxTray] C:\Windows\System32\igfxtray.exe

x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe

x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s

x64-Run: [btTray] "C:\Program Files (x86)\Bluetooth Suite\BtTray.exe"

x64-Run: [btvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"

x64-Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe

x64-mPolicies-System: DisableCAD = dword:1

x64-IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll

x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll

x64-Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll

x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll

x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>

x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>

x64-Notify: igfxcui - igfxdev.dll

x64-SSODL: WebCheck - <orphaned>


============= SERVICES / DRIVERS ===============


R0 iaStorA;iaStorA;C:\Windows\System32\Drivers\iaStorA.sys [2012-7-5 645952]

R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\System32\Drivers\mfehidk.sys [2012-6-22 771536]

R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\System32\Drivers\mfewfpk.sys [2012-6-22 340216]

R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-9-7 17536]

R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-2 15416]

R2 ASUS InstantOn;ASUS InstantOn Service;C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-4-13 277120]

R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2012-8-10 211584]

R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-12-28 2451456]

R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]

R2 Intel® ME Service;Intel® ME Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [2012-12-28 129856]

R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2012-12-28 166720]

R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-7-18 418376]

R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-7-18 701512]

R2 McShield;McAfee McShield;C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe [2012-11-27 241456]

R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe [2012-11-27 218760]

R2 mfevtp;McAfee Validation Trust Protection Service;C:\Windows\System32\mfevtps.exe [2012-11-27 182752]

R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2013-7-19 1153368]

R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-7-12 3289472]

R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-12-28 365376]

R2 ZAtheros Bt&Wlan Coex Agent;ZAtheros Bt&Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2012-8-10 323584]

R3 AiCharger;ASUS Charger Driver;C:\Windows\System32\Drivers\AiCharger.sys [2012-9-18 17152]

R3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;C:\Windows\System32\Drivers\btath_flt.sys [2012-12-28 88728]

R3 ATP;ASUS PS/2 Port Input Device;C:\Windows\System32\Drivers\AsusTP.sys [2012-10-31 61824]

R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\Drivers\btath_a2dp.sys [2012-12-28 344216]

R3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;C:\Windows\System32\Drivers\btath_avdt.sys [2012-12-28 114840]

R3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;C:\Windows\System32\Drivers\btath_bus.sys [2012-12-28 33944]

R3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\Drivers\btath_hcrp.sys [2012-12-28 178840]

R3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\Drivers\btath_lwflt.sys [2012-12-28 76952]

R3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\Drivers\btath_rcp.sys [2012-12-28 135832]

R3 BtFilter;BtFilter;C:\Windows\System32\Drivers\btfilter.sys [2012-12-28 567808]

R3 BthLEEnum;Bluetooth Low Energy Driver;C:\Windows\System32\Drivers\BthLEEnum.sys [2012-7-25 202752]

R3 HIDSwitch;ASUS Wireless Radio Control;C:\Windows\System32\Drivers\AsHIDSwitch64.sys [2013-1-16 21152]

R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\Drivers\IntcDAud.sys [2013-1-16 342528]

R3 MBAMProtector;MBAMProtector;C:\Windows\System32\Drivers\mbam.sys [2013-7-18 25928]

R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\System32\Drivers\mfeavfk.sys [2012-6-22 309840]

R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\System32\Drivers\mfefirek.sys [2012-6-22 515968]

R3 RSBASTOR;Realtek PCIE CardReader Driver - BA;C:\Windows\System32\Drivers\RtsBaStor.sys [2012-12-28 295056]

R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2012-12-28 683664]

S0 mfeelamk;McAfee Inc. mfeelamk;C:\Windows\System32\Drivers\mfeelamk.sys [2012-6-18 69168]

S2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2013-7-12 201304]

S2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2013-7-12 201304]

S2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2013-7-12 201304]

S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-6-21 162408]

S3 ASUSProcObsrv;ASUS Process Creation/Termination Observer;C:\eSupport\eDriver\I386\AsPrOb64.sys [2012-12-28 12416]

S3 cfwids;McAfee Inc. cfwids;C:\Windows\System32\Drivers\cfwids.sys [2012-6-22 70112]

S3 HipShieldK;McAfee Inc. HipShieldK;C:\Windows\System32\Drivers\HipShieldK.sys [2013-7-12 196440]

S3 McAWFwk;McAfee Activation Service;C:\PROGRA~1\mcafee\msc\mcawfwk.exe [2012-11-27 332080]

S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\System32\Drivers\mferkdet.sys [2012-6-22 106552]

S4 McOobeSv;McAfee OOBE Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2013-7-12 201304]


=============== Created Last 30 ================


2013-07-22 03:08:23 -------- d-----w- C:\ProgramData\Malwarebytes' Anti-Malware (portable)

2013-07-20 02:56:05 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy

2013-07-20 02:56:05 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy

2013-07-19 04:14:07 -------- d-----w- C:\Users\Devin\AppData\Local\Cyberlink

2013-07-18 17:24:00 -------- d-----w- C:\Users\Devin\AppData\Roaming\Malwarebytes

2013-07-18 17:23:50 -------- d-----w- C:\ProgramData\Malwarebytes

2013-07-18 17:23:49 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys

2013-07-18 17:23:49 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2013-07-18 17:23:22 -------- d-----w- C:\Users\Devin\AppData\Local\Programs

2013-07-18 06:00:01 21 ----a-w- C:\Users\Devin\AppData\Roaming\my_intel.sys

2013-07-18 05:58:35 -------- d-----w- C:\Users\Devin\AppData\Roaming\ASUS

2013-07-18 05:20:15 -------- d-----w- C:\aws

2013-07-18 05:20:11 -------- d-----w- C:\Asus WebStorage

2013-07-18 05:11:42 -------- d-----w- C:\Users\Devin\AppData\Local\Power2Go

2013-07-18 05:09:07 -------- d-----w- C:\Program Files (x86)\Common Files\SceneSwitch

2013-07-18 05:07:32 -------- d-----w- C:\Users\Devin\AppData\Local\Adobe

2013-07-18 05:03:10 -------- d-----w- C:\Users\Devin\AppData\Local\WinZip

2013-07-18 05:01:44 -------- d-----w- C:\Users\Devin\AppData\Roaming\uTorrent

2013-07-17 18:50:09 -------- d-----w- C:\Windows\System32\MRT

2013-07-17 03:02:27 252080 ----a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10210.bin

2013-07-16 02:43:28 3236864 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\tipskins.dll

2013-07-16 02:42:59 7680 ----a-w- C:\Windows\System32\kbdhebl3.dll

2013-07-16 02:40:33 11459584 ----a-w- C:\Windows\System32\glcndFilter.dll

2013-07-16 02:32:23 144384 ----a-w- C:\Windows\System32\tssdisai.dll

2013-07-15 02:01:15 -------- d-----w- C:\Program Files\CCleaner

2013-07-15 00:54:38 78200 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2013-07-15 00:54:38 693112 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2013-07-15 00:43:00 -------- d-----w- C:\sources

2013-07-14 16:49:50 17888 ----a-w- C:\Windows\System32\msvcr100_clr0400.dll

2013-07-14 16:49:09 17888 ----a-w- C:\Windows\SysWow64\msvcr100_clr0400.dll

2013-07-14 16:43:53 1161728 ----a-w- C:\Windows\System32\sppobjs.dll

2013-07-14 16:42:54 3552768 ----a-w- C:\Windows\System32\tquery.dll

2013-07-14 06:05:34 19187712 ----a-w- C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll

2013-07-14 06:05:33 18523648 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll

2013-07-13 20:07:22 2035200 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\InkObj.dll

2013-07-13 20:07:22 1617920 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL

2013-07-13 20:07:22 1306112 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll

2013-07-13 20:07:22 1272320 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll

2013-07-13 20:07:21 1413632 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\InkObj.dll

2013-07-13 20:07:21 1318912 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll

2013-07-13 20:07:21 1029632 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\journal.dll

2013-07-13 20:07:19 303848 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys

2013-07-13 20:07:19 1455368 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys

2013-07-13 20:07:01 135680 ----a-w- C:\Windows\System32\appserverai.dll

2013-07-13 20:07:01 126976 ----a-w- C:\Windows\System32\RDWebAI.dll

2013-07-13 20:07:01 122880 ----a-w- C:\Windows\System32\VmHostAI.dll

2013-07-13 20:06:58 148480 ----a-w- C:\Windows\System32\poqexec.exe

2013-07-13 20:06:58 132608 ----a-w- C:\Windows\SysWow64\poqexec.exe

2013-07-13 20:06:42 94208 ----a-w- C:\Windows\System32\synceng.dll

2013-07-13 20:06:42 72192 ----a-w- C:\Windows\SysWow64\synceng.dll

2013-07-13 20:06:42 4036096 ----a-w- C:\Windows\System32\win32k.sys

2013-07-13 20:06:37 86016 ----a-w- C:\Windows\System32\ncryptsslp.dll

2013-07-13 20:06:37 71168 ----a-w- C:\Windows\SysWow64\ncryptsslp.dll

2013-07-13 20:04:56 1690624 ----a-w- C:\Windows\System32\GdiPlus.dll

2013-07-13 20:03:54 405504 ----a-w- C:\Windows\System32\pcasvc.dll

2013-07-13 18:36:06 -------- d-----w- C:\Users\Devin\AppData\Local\TopArcadeHits

2013-07-13 15:51:05 50784 ----a-w- C:\ProgramData\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin

2013-07-13 15:50:59 17536 ----a-w- C:\ProgramData\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin

2013-07-13 03:04:11 867240 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll

2013-07-13 03:04:11 789416 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2013-07-13 03:04:09 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

2013-07-13 02:50:06 -------- d-----w- C:\Program Files (x86)\SystemRequirementsLab

2013-07-13 02:20:58 -------- d-----r- C:\Program Files (x86)\Skype

2013-07-12 21:20:57 -------- d-----w- C:\ProgramData\Blizzard Entertainment

2013-07-12 21:20:57 -------- d-----w- C:\Program Files (x86)\World of Warcraft

2013-07-12 21:20:57 -------- d-----w- C:\Program Files (x86)\Common Files\Blizzard Entertainment

2013-07-12 21:19:56 -------- d-----w- C:\ProgramData\Battle.net

2013-07-12 20:11:04 196440 ----a-w- C:\Windows\System32\drivers\HipShieldK.sys

2013-07-12 19:58:11 -------- d-----w- C:\Users\Devin\AppData\Local\Google

2013-07-12 19:57:58 -------- d-----w- C:\Users\Devin\AppData\Local\Apps

2013-07-12 19:57:57 -------- d-----w- C:\Users\Devin\AppData\Local\Deployment

2013-07-12 19:55:14 -------- d-----w- C:\Users\Devin\AppData\Local\BMExplorer

2013-07-12 19:55:13 -------- d-----w- C:\Users\Devin\AppData\Roaming\ASUS WebStorage

2013-07-12 19:55:07 -------- d-----w- C:\Users\Devin\AppData\Roaming\Atheros

2013-07-12 19:55:05 416 ----a-w- C:\Users\Devin\AppData\Roaming\sp_data.sys

2013-07-12 19:54:40 -------- d-----r- C:\Users\Devin\Searches

2013-07-12 19:54:32 -------- d-----w- C:\ProgramData\FolderView

2013-07-12 19:53:42 -------- d-----r- C:\Users\Devin\Contacts

2013-07-12 19:53:06 -------- d-----w- C:\Users\Devin\AppData\Local\VirtualStore


==================== Find3M  ====================


2013-06-16 22:41:31 997632 ----a-w- C:\Windows\System32\drivers\ndis.sys

2013-06-11 23:43:37 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll

2013-06-11 23:43:00 2877440 ----a-w- C:\Windows\SysWow64\jscript9.dll

2013-06-11 23:26:20 2241024 ----a-w- C:\Windows\System32\wininet.dll

2013-06-11 23:25:16 3958784 ----a-w- C:\Windows\System32\jscript9.dll

2013-06-01 11:54:16 194816 ----a-w- C:\Windows\System32\drivers\sdbus.sys

2013-06-01 11:54:10 125184 ----a-w- C:\Windows\System32\drivers\dumpsd.sys

2013-06-01 11:34:21 2391280 ----a-w- C:\Windows\explorer.exe

2013-06-01 11:33:13 2233600 ----a-w- C:\Windows\System32\drivers\tcpip.sys

2013-06-01 11:29:35 337152 ----a-w- C:\Windows\System32\drivers\USBXHCI.SYS

2013-06-01 11:29:35 213248 ----a-w- C:\Windows\System32\drivers\UCX01000.SYS

2013-06-01 11:26:33 327936 ----a-w- C:\Windows\System32\drivers\volsnap.sys

2013-06-01 11:26:31 6987008 ----a-w- C:\Windows\System32\ntoskrnl.exe

2013-06-01 10:24:46 2106176 ----a-w- C:\Windows\SysWow64\explorer.exe

2013-06-01 09:25:52 364544 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll

2013-06-01 09:25:05 67584 ----a-w- C:\Windows\SysWow64\samlib.dll

2013-06-01 09:25:03 496640 ----a-w- C:\Windows\SysWow64\qedit.dll

2013-06-01 09:24:19 493056 ----a-w- C:\Windows\SysWow64\mscms.dll

2013-06-01 09:24:09 850944 ----a-w- C:\Windows\SysWow64\mfasfsrcsnk.dll

2013-06-01 09:24:09 1453568 ----a-w- C:\Windows\SysWow64\mfcore.dll

2013-06-01 09:23:46 1842176 ----a-w- C:\Windows\SysWow64\dwmcore.dll

2013-06-01 09:23:06 680960 ----a-w- C:\Windows\System32\vds.exe

2013-06-01 09:22:47 80896 ----a-w- C:\Windows\System32\MbaeParserTask.exe

2013-06-01 09:22:33 523264 ----a-w- C:\Windows\System32\XpsGdiConverter.dll

2013-06-01 09:22:33 446976 ----a-w- C:\Windows\System32\wwansvc.dll

2013-06-01 09:22:09 190976 ----a-w- C:\Windows\System32\vdsutil.dll

2013-06-01 09:21:39 729600 ----a-w- C:\Windows\System32\samsrv.dll

2013-06-01 09:21:39 106496 ----a-w- C:\Windows\System32\samlib.dll

2013-06-01 09:21:34 595968 ----a-w- C:\Windows\System32\qedit.dll

2013-06-01 09:20:45 583168 ----a-w- C:\Windows\System32\mscms.dll

2013-06-01 09:20:34 1527808 ----a-w- C:\Windows\System32\mfcore.dll

2013-06-01 09:20:34 1048576 ----a-w- C:\Windows\System32\mfasfsrcsnk.dll

2013-06-01 09:20:04 2219520 ----a-w- C:\Windows\System32\dwmcore.dll

2013-06-01 09:19:58 207872 ----a-w- C:\Windows\System32\DeviceSetupManager.dll

2013-06-01 09:19:42 785408 ----a-w- C:\Windows\System32\audiosrv.dll

2013-06-01 03:08:57 37632 ----a-w- C:\Windows\System32\drivers\BthAvrcpTg.sys

2013-05-24 22:09:20 1403296 ----a-w- C:\Windows\System32\winload.efi

2013-05-24 22:09:20 1271584 ----a-w- C:\Windows\System32\winload.exe

2013-05-24 22:09:20 1217352 ----a-w- C:\Windows\System32\winresume.efi

2013-05-24 22:09:20 1093904 ----a-w- C:\Windows\System32\winresume.exe

2013-05-23 23:01:46 1300992 ----a-w- C:\Windows\System32\gdi32.dll

2013-05-23 22:27:05 1022464 ----a-w- C:\Windows\SysWow64\gdi32.dll

2013-05-15 22:37:03 44032 ----a-w- C:\Windows\SysWow64\UXInit.dll

2013-05-15 22:35:49 53760 ----a-w- C:\Windows\System32\UXInit.dll

2013-05-15 02:25:59 888320 ----a-w- C:\Windows\System32\autochk.exe

2013-05-15 02:25:44 542208 ----a-w- C:\Windows\System32\untfs.dll

2013-05-15 02:24:10 793088 ----a-w- C:\Windows\SysWow64\autochk.exe

2013-05-15 02:24:01 482816 ----a-w- C:\Windows\SysWow64\untfs.dll

2013-05-14 13:14:01 2706432 ----a-w- C:\Windows\System32\mshtml.tlb

2013-05-14 09:23:31 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2013-05-04 07:58:17 120736 ----a-w- C:\Windows\System32\AuthHost.exe

2013-05-04 07:34:17 446720 ----a-w- C:\Windows\System32\drivers\USBHUB3.SYS

2013-05-04 07:34:15 284416 ----a-w- C:\Windows\System32\drivers\spaceport.sys

2013-05-04 06:59:56 39424 ----a-w- C:\Windows\System32\wuapp.exe

2013-05-04 06:59:51 1483776 ----a-w- C:\Windows\System32\VSSVC.exe

2013-05-04 06:59:36 812544 ----a-w- C:\Windows\System32\Magnify.exe

2013-05-04 06:59:25 98304 ----a-w- C:\Windows\System32\wudriver.dll

2013-05-04 06:59:25 251904 ----a-w- C:\Windows\System32\WUSettingsProvider.dll

2013-05-04 06:59:25 141824 ----a-w- C:\Windows\System32\wuwebv.dll

2013-05-04 06:59:24 1619968 ----a-w- C:\Windows\System32\wucltux.dll

2013-05-04 06:59:21 2842112 ----a-w- C:\Windows\System32\WMVDECOD.DLL

2013-05-04 06:59:08 13644288 ----a-w- C:\Windows\System32\Windows.UI.Xaml.dll

2013-05-04 06:58:54 328192 ----a-w- C:\Windows\System32\ubpm.dll

2013-05-04 06:58:54 10116096 ----a-w- C:\Windows\System32\twinui.dll

2013-05-04 06:58:49 173568 ----a-w- C:\Windows\System32\storewuauth.dll

2013-05-04 06:58:49 1332736 ----a-w- C:\Windows\System32\sysmain.dll

2013-05-04 06:58:48 330240 ----a-w- C:\Windows\System32\stobject.dll

2013-05-04 06:58:28 93696 ----a-w- C:\Windows\System32\psmsrv.dll

2013-05-04 06:58:02 470528 ----a-w- C:\Windows\System32\netprofmsvc.dll

2013-05-04 06:58:02 151552 ----a-w- C:\Windows\System32\netprofm.dll

2013-05-04 06:58:01 169984 ----a-w- C:\Windows\System32\netplwiz.dll

2013-05-04 06:57:59 17408 ----a-w- C:\Windows\System32\muifontsetup.dll

2013-05-04 06:57:46 560640 ----a-w- C:\Windows\System32\mfmp4srcsnk.dll

2013-05-04 06:57:15 501760 ----a-w- C:\Windows\System32\DevicePairing.dll

2013-05-04 06:57:05 179712 ----a-w- C:\Windows\System32\bisrv.dll

2013-05-04 06:57:05 122368 ----a-w- C:\Windows\System32\biwinrt.dll

2013-05-04 06:57:04 389120 ----a-w- C:\Windows\System32\BCP47Langs.dll

2013-05-04 06:57:04 2305024 ----a-w- C:\Windows\System32\authui.dll

2013-05-04 06:57:00 708096 ----a-w- C:\Windows\System32\AppXDeploymentExtensions.dll

2013-05-04 06:57:00 1131520 ----a-w- C:\Windows\System32\AppXDeploymentServer.dll

2013-05-04 06:56:53 419840 ----a-w- C:\Windows\System32\intl.cpl

2013-05-04 04:58:34 34304 ----a-w- C:\Windows\SysWow64\wuapp.exe

2013-05-04 04:58:14 758784 ----a-w- C:\Windows\SysWow64\Magnify.exe

2013-05-04 04:58:02 83968 ----a-w- C:\Windows\SysWow64\wudriver.dll

2013-05-04 04:58:02 125952 ----a-w- C:\Windows\SysWow64\wuwebv.dll

2013-05-04 04:57:58 2620928 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL

2013-05-04 04:57:49 10788864 ----a-w- C:\Windows\SysWow64\Windows.UI.Xaml.dll

2013-05-04 04:57:39 8857088 ----a-w- C:\Windows\SysWow64\twinui.dll

2013-05-04 04:57:39 247296 ----a-w- C:\Windows\SysWow64\ubpm.dll

2013-05-04 04:57:35 303616 ----a-w- C:\Windows\SysWow64\stobject.dll

2013-05-04 04:57:16 18432 ----a-w- C:\Windows\SysWow64\npmproxy.dll

2013-05-04 04:57:04 151040 ----a-w- C:\Windows\SysWow64\netplwiz.dll

2013-05-04 04:57:04 115712 ----a-w- C:\Windows\SysWow64\netprofm.dll

2013-05-04 04:57:02 14336 ----a-w- C:\Windows\SysWow64\muifontsetup.dll

2013-05-04 04:56:48 411136 ----a-w- C:\Windows\SysWow64\mfmp4srcsnk.dll

2013-05-04 04:56:14 449536 ----a-w- C:\Windows\SysWow64\DevicePairing.dll

2013-05-04 04:56:06 92160 ----a-w- C:\Windows\SysWow64\biwinrt.dll

2013-05-04 04:56:05 309760 ----a-w- C:\Windows\SysWow64\BCP47Langs.dll

2013-05-04 04:56:05 2035712 ----a-w- C:\Windows\SysWow64\authui.dll

2013-05-04 04:55:58 389632 ----a-w- C:\Windows\SysWow64\intl.cpl


============= FINISH: 23:02:06.98 ===============










DDS (Ver_2012-11-20.01)


Microsoft Windows 8

Boot Device: \Device\HarddiskVolume1

Install Date: 7/12/2013 12:52:44 PM

System Uptime: 7/21/2013 6:23:26 AM (17 hours ago)


Motherboard: ASUSTeK COMPUTER INC. |  | K55A

Processor: Intel® Core i7-3630QM CPU @ 2.40GHz | SOCKET 0 | 2401/100mhz


==== Disk Partitions =========================


C: is FIXED (NTFS) - 373 GiB total, 288.499 GiB free.

D: is FIXED (NTFS) - 538 GiB total, 537.444 GiB free.

E: is CDROM ()


==== Disabled Device Manager Items =============


==== System Restore Points ===================


RP2: 7/12/2013 8:03:39 PM - Installed Java 7 Update 25

RP3: 7/13/2013 11:00:15 PM - Language Pack Removal

RP4: 7/16/2013 10:32:03 PM - Language Pack Removal


==== Installed Programs ======================





Adobe Reader X MUI

ASUS Instant Connect

ASUS InstantOn

ASUS LifeFrame3

ASUS Live Update

ASUS Power4Gear Hybrid

ASUS Screen Saver

ASUS Smart Gesture

ASUS Splendid Video Enhancement Technology

ASUS Tutor

ASUS USB Charger Plus

ASUS Virtual Camera

ASUS WebStorage Sync Agent


ATK Package


CyberLink LabelPrint 2.5

CyberLink Power2Go



Galerie de photos

Galería de fotos

Google Chrome

Google Update Helper

Intel® Management Engine Components

Intel® Processor Graphics

Intel® SDK for OpenCL - CPU Only Runtime Package

Intel® Trusted Connect Service Client

Java 7 Update 25

Java Auto Updater

Malwarebytes Anti-Malware version

McAfee Internet Security

Microsoft Application Error Reporting

Microsoft Office

Microsoft Silverlight

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219

Movie Maker




MyBitCast 2.0

Photo Common

Photo Gallery

Qualcomm Atheros Bluetooth Suite (64)

Qualcomm Atheros Client Installation Program

Realtek Ethernet Controller Driver

Realtek High Definition Audio Driver

Realtek PCIE Card Reader


Shared C Run-time for x64

Skype Click to Call

Skype™ 6.6

Spybot - Search & Destroy

System Requirements Lab for Intel


Windows Driver Package - ASUS (ATP) Mouse  (10/29/2012

Windows Live

Windows Live ???

Windows Live Communications Platform

Windows Live Essentials

Windows Live Installer

Windows Live Photo Common

Windows Live PIMT Platform

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live UX Platform

Windows Live UX Platform Language Pack


WinZip 17.0

World of Warcraft


==== Event Viewer Messages From Past Week ========


7/21/2013 7:27:31 PM, Error: Service Control Manager [7023]  - The Interactive Services Detection service terminated with the following error:  Incorrect function.

7/21/2013 11:01:45 PM, Error: Service Control Manager [7031]  - The McAfee VirusScan Announcer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

7/21/2013 11:01:45 PM, Error: Service Control Manager [7031]  - The McAfee Services service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

7/21/2013 11:01:45 PM, Error: Service Control Manager [7031]  - The McAfee Proxy Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

7/21/2013 11:01:45 PM, Error: Service Control Manager [7031]  - The McAfee Personal Firewall Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

7/21/2013 11:01:45 PM, Error: Service Control Manager [7031]  - The McAfee Network Agent service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

7/21/2013 11:01:45 PM, Error: Service Control Manager [7031]  - The McAfee Anti-Spam Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

7/15/2013 10:35:57 PM, Error: Service Control Manager [7034]  - The Computer Backup (MyPC Backup) service terminated unexpectedly.  It has done this 1 time(s).

7/15/2013 10:19:43 PM, Error: Service Control Manager [7023]  - The Windows Modules Installer service terminated with the following error:  The process cannot access the file because it is being used by another process.

7/15/2013 10:17:10 PM, Error: Service Control Manager [7031]  - The Print Spooler service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.

7/15/2013 10:16:49 PM, Error: Service Control Manager [7001]  - The Windows Media Player Network Sharing Service service depends on the Windows Search service which failed to start because of the following error:  The process cannot access the file because it is being used by another process.

7/15/2013 10:16:49 PM, Error: Service Control Manager [7000]  - The Windows Search service failed to start due to the following error:  The process cannot access the file because it is being used by another process.

7/15/2013 10:16:23 PM, Error: Service Control Manager [7023]  - The Security Center service terminated with the following error:  The process cannot access the file because it is being used by another process.

7/15/2013 10:14:57 PM, Error: Service Control Manager [7031]  - The Print Spooler service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.

7/14/2013 7:35:01 PM, Error: Service Control Manager [7043]  - The Windows Update service did not shut down properly after receiving a preshutdown control.

7/14/2013 5:50:59 PM, Error: Microsoft-Windows-WMPNSS-Service [14346]  - A new media server was not initialized because RegisterRunningDevice() encountered error '0x8007045a'. Restart your computer, and then restart the WMPNetworkSvc service.

7/14/2013 5:47:58 PM, Error: Service Control Manager [7022]  - The McAfee McShield service hung on starting.

7/14/2013 5:44:25 PM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Computer Backup (MyPC Backup) service to connect.

7/14/2013 5:44:25 PM, Error: Service Control Manager [7000]  - The Computer Backup (MyPC Backup) service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.

7/14/2013 5:43:20 PM, Error: Service Control Manager [7023]  - The Application Information service terminated with the following error:  The process cannot access the file because it is being used by another process.

7/14/2013 5:43:08 PM, Error: Application Popup [877]  - 

7/14/2013 2:32:24 PM, Error: Microsoft-Windows-WindowsUpdateClient [20]  - Installation Failure: Windows failed to install the following update with error 0x80070490: Update for Windows 8 for x64-based Systems (KB2795944).

7/14/2013 2:31:31 PM, Error: Microsoft-Windows-WindowsUpdateClient [20]  - Installation Failure: Windows failed to install the following update with error 0x80246007: Update for Windows 8 for x64-based Systems (KB2771431).

7/14/2013 2:29:09 PM, Error: Microsoft-Windows-WindowsUpdateClient [20]  - Installation Failure: Windows failed to install the following update with error 0x80070490: Update for Windows 8 for x64-based Systems (KB2822241).

7/14/2013 2:23:22 PM, Error: Microsoft-Windows-WindowsUpdateClient [20]  - Installation Failure: Windows failed to install the following update with error 0x80070490: Update for Windows 8 for x64-based Systems (KB2845533).

7/14/2013 2:22:16 PM, Error: Microsoft-Windows-WindowsUpdateClient [20]  - Installation Failure: Windows failed to install the following update with error 0x80070490: Update for Windows 8 for x64-based Systems (KB2836988).


==== End Of File ===========================

Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.

  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

Scan with Malwarebytes Anti-Rootkit

Please download Malwarebytes Anti-Rootkit from here Malwarebytes : Malwarebytes Anti-Rootkit and save it to your desktop.

Be sure to print out and follow the instructions provided on that same page.

Caution: This is a beta version so please be sure to read the disclaimer and back up any important data before using.

  • Double click the mbar.zip file to open it, then 'Extract all files'.
  • Double click the mbar folder to open it, then double click mbar.exe to start the tool.

Check for Updates, then Scan your system for malware

If malware is found, do NOT press the Cleanup button yet. Click EXIT.

I'd like to see the log first so I can see what it sees. You'll find the log in that mbar folder as MBAR-log-[date and time]***.txt . Please attach that to your next reply.

  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

