Jump to content

PWS:Win32/Fareit.gen!J caught by Windows Defender; not sure if clean


Recommended Posts


On Friday, I made the mistake of clicking a link in an email which I thought was from DHL, which automatically ran the attached malware instead. Upon doing this, I immediately pulled out the Ethernet plug, and I saw that Windows Defender immediately flagged the file as "PWS:Win32/Fareit.gen!J". It was then able to remove it without any noticeable difficulty.

Since then, I have done the following:

- Checked the AppData folders for suspicious content - I found some randomised folders (not GUIDs) without any EXEs in, but I removed them anyway using Eraser.

- Erased some EXEs and DLLs in the root of AppData - their names matched certain Windows components, but they had no business being in that folder...

- Deleted some randomised registry entries in HKEY_CURRENT_USER\Software\ (in retrospect, maybe I shouldn't have done this)

- Ran both parts of CCleaner (in retrospect, I probably should have left the registry alone, but the things this found didn't look related)

- Ran a full scan in MalwareBytes both in & out of Safe Mode - nothing detected

- Ran a full scan in SUPERAntiSpyware both in & out of Safe Mode - nothing detected

- Ran a full scan in Windows Defender - nothing detected

- Ran a full scan in Kaspersky PURE 2 - nothing detected

All my software is suggesting that I had a lucky break, but I'd like a professional opinion before I put the Ethernet plug back in. What do you guys think?

Thanks in advance; DDS log and Attach file are below:


DDS (Ver_2012-11-20.01) - NTFS_AMD64

Internet Explorer: 10.0.9200.16736 BrowserJavaVersion: 10.9.2

Run by Joe at 23:30:00 on 2013-11-25

Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.8190.5637 [GMT 0:00]


AV: Kaspersky PURE 2.0 *Enabled/Outdated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}

SP: Kaspersky PURE 2.0 *Enabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

FW: Kaspersky PURE 2.0 *Enabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}


============== Running Processes ===============



C:\Windows\system32\svchost.exe -k DcomLaunch


C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe



C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe

C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe

C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe

C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe

C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt

C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe

C:\Windows\System32\svchost.exe -k HPZ12

C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe

C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

C:\Windows\System32\svchost.exe -k HPZ12


C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe

C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted





C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe


C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe

C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe

C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe

C:\Program Files\Eraser\Eraser.exe

C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe

C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe

C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe


C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe

C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe

C:\Program Files\Logitech\GamePanel Software\Applets\LCDClock.exe

C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe


C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted



C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe

C:\Windows\System32\svchost.exe -k secsvcs

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files\NVIDIA Corporation\Display\nvtray.exe



C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe



C:\Windows\System32\svchost.exe -k WerSvcGroup







============== Pseudo HJT Report ===============


uStart Page = about:blank

BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ievkbd.dll

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\klwtbbho.dll

EB: : {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 -

EB: : {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 -

mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r

mRun: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe"

mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe

mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe"

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

mPolicies-Explorer: NoActiveDesktop = dword:1

mPolicies-Explorer: NoActiveDesktopChanges = dword:1

mPolicies-Explorer: NoDriveTypeAutoRun = dword:28

mPolicies-System: ConsentPromptBehaviorAdmin = dword:5

mPolicies-System: ConsentPromptBehaviorUser = dword:3

mPolicies-System: EnableUIADesktopToggle = dword:0

IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ie_banner_deny.htm

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000

IE: Kaspersky PURE - C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\MODULE~1\spIEBho.dll/616

IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ievkbd.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\klwtbbho.dll

TCP: NameServer =

TCP: Interfaces\{0ADB2B3E-54AC-4450-BE08-FF2E9F35F280} : DHCPNameServer =

TCP: Interfaces\{0ADB2B3E-54AC-4450-BE08-FF2E9F35F280}\0525E453638393 : DHCPNameServer =

TCP: Interfaces\{0ADB2B3E-54AC-4450-BE08-FF2E9F35F280}\0525E4D2465667F6C6F6 : DHCPNameServer =

TCP: Interfaces\{0ADB2B3E-54AC-4450-BE08-FF2E9F35F280}\0525E4F5F423 : DHCPNameServer =

TCP: Interfaces\{0ADB2B3E-54AC-4450-BE08-FF2E9F35F280}\244584572633D283A43453 : DHCPNameServer =

TCP: Interfaces\{0ADB2B3E-54AC-4450-BE08-FF2E9F35F280}\F423D4F62696C65675966696D2542354141473 : DHCPNameServer =

TCP: Interfaces\{4B56870D-04D8-447F-983C-B8C4F41572FF} : DHCPNameServer =

TCP: Interfaces\{8D8CC0D1-97F7-4D1A-A37B-8C257099F965} : DHCPNameServer =

TCP: Interfaces\{8D8CC0D1-97F7-4D1A-A37B-8C257099F965}\0525E453638393 : DHCPNameServer =

TCP: Interfaces\{90F5A8DA-FA64-4DD2-9DF7-7BAA36228E97} : DHCPNameServer =

TCP: Interfaces\{90F5A8DA-FA64-4DD2-9DF7-7BAA36228E97}\0525E453638393 : DHCPNameServer =

TCP: Interfaces\{90F5A8DA-FA64-4DD2-9DF7-7BAA36228E97}\465667F6C6F6D2030303243324343454535403 : DHCPNameServer =

TCP: Interfaces\{D3E4C2A8-28E1-47BA-BBA6-A69C53E3EDDB} : DHCPNameServer =

TCP: Interfaces\{D3E4C2A8-28E1-47BA-BBA6-A69C53E3EDDB}\0525E453638393 : DHCPNameServer =

TCP: Interfaces\{D3E4C2A8-28E1-47BA-BBA6-A69C53E3EDDB}\33027627164747F6E602374727565647 : DHCPNameServer =

TCP: Interfaces\{D3E4C2A8-28E1-47BA-BBA6-A69C53E3EDDB}\337427164747F6E63747 : DHCPNameServer =

TCP: Interfaces\{D3E4C2A8-28E1-47BA-BBA6-A69C53E3EDDB}\6796277696E6022627F616462616E646 : DHCPNameServer =

Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

SSODL: WebCheck -

x64-BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\ievkbd.dll

x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll

x64-BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll

x64-BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\klwtbbho.dll

x64-BHO: {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} -

x64-Run: [Launch LgDeviceAgent] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"

x64-Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"

x64-Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE

x64-Run: [Eraser] "C:\PROGRA~1\Eraser\Eraser.exe" --atRestart

x64-Run: [Nvtmru] "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"

x64-Run: [shadowPlay] C:\Windows\System32\rundll32.exe C:\Windows\System32\nvspcap64.dll,ShadowPlayOnSystemStart

x64-IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\ievkbd.dll

x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll

x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\klwtbbho.dll

x64-Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\amd64\puresp4.dll

x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll

x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -

x64-Notify: klogon - C:\Windows\System32\klogon.dll

x64-SSODL: WebCheck -


================= FIREFOX ===================


FF - ProfilePath - C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\6jemve3h.default\

FF - prefs.js: browser.search.selectedEngine - Google UK SSL

FF - prefs.js: browser.startup.homepage - about:newtab

FF - component: C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\6jemve3h.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc_fireftp.dll

FF - component: C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\6jemve3h.default\extensions\lazarus@interclue.com\platform\WINNT_x86-msvc\components\WeaveCrypto.dll

FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

FF - plugin: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll

FF - plugin: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypchub.dll

FF - plugin: C:\SumatraPDF\npPdfViewer.dll

FF - plugin: C:\Users\Joe\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll

FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll

FF - plugin: C:\Windows\SysWOW64\npmproxy.dll


============= SERVICES / DRIVERS ===============


R0 CSCrySec;InfoWatch Encrypt Sector Library driver;C:\Windows\System32\drivers\CSCrySec.sys [2013-2-13 85048]

R1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;C:\Windows\System32\drivers\CSVirtualDiskDrv.sys [2013-2-13 66104]

R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2011-10-20 13616]

R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2011-3-10 29488]

R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]

R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]

R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-8-11 140672]

R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe [2012-8-30 202328]

R2 CSObjectsSrv;CryptoStorage control service;C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [2009-12-21 743992]

R2 DevoloNetworkService;devolo Network Service;C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [2012-2-28 3128856]

R2 NvStreamSvc;NVIDIA Streamer Service;C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-10-5 15125280]

R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-11-11 414496]

R2 USBDLM;USBDLM;C:\Users\Joe\Software\USBDLM\USBDLM.EXE [2009-9-17 223232]

R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544]

R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;C:\Windows\System32\drivers\LGBusEnum.sys [2009-7-14 22408]

R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\Windows\System32\drivers\nvvad64v.sys [2013-10-5 39200]

R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-10 539240]

R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\System32\drivers\viahduaa.sys [2009-10-22 1207808]

S1 aiptektp;Pen Pad;C:\Windows\System32\drivers\aiptektp.sys [2009-10-22 29184]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-6-21 162408]

S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;C:\Windows\System32\drivers\bcmwlhigh664.sys [2011-4-19 1254464]

S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2010-1-15 35104]

S3 libusb0;LibUsb-Win32 - Kernel Driver 03/20/2007,;C:\Windows\System32\drivers\libusb0.sys [2010-10-2 43456]

S3 massfilter;ZTE Mass Storage Filter Driver;C:\Windows\System32\drivers\massfilter.sys [2009-12-23 9216]

S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;C:\Windows\System32\drivers\MijXfilt.sys [2010-10-23 121416]

S3 pspdisp;pspdisp;C:\Windows\System32\drivers\pspdisp_x64.sys [2011-1-18 4608]

S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-10-25 19456]

S3 Revoflt;Revoflt;C:\Windows\System32\drivers\revoflt.sys [2009-12-28 31800]

S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-11-12 56832]

S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]

S4 sprtsvc_O2DA;SupportSoft Sprocket Service (O2DA);C:\Program Files (x86)\O2 Assistant\bin\sprtsvc.exe [2010-4-23 206120]

S4 tgsrvc_O2DA;SupportSoft Repair Service (O2DA);C:\Program Files (x86)\O2 Assistant\bin\tgsrvc.exe [2010-4-23 185640]


=============== File Associations ===============


FileExt: .txt: txtfile=C:\Windows\System32\NOTEPAD.EXE %1 [userChoice]

FileExt: .inf: inffile=C:\Windows\System32\NOTEPAD.EXE %1 [userChoice]



=============== Created Last 30 ================


2013-11-24 18:20:09 1990493 ----a-w- C:\MGtools.exe

2013-11-22 12:44:13 10285968 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4AFD208C-16EA-40F4-BD6A-8BBA40E5DF96}\mpengine.dll

2013-11-21 22:04:41 -------- d-----w- C:\Users\Joe\AppData\Local\NVIDIA Corporation

2013-11-12 18:25:53 44544 ----a-w- C:\Windows\System32\TsUsbGDCoInstaller.dll

2013-11-12 18:20:22 1930752 ----a-w- C:\Windows\System32\authui.dll

2013-11-12 18:18:26 859648 ----a-w- C:\Windows\System32\IKEEXT.DLL

2013-11-12 18:18:26 830464 ----a-w- C:\Windows\System32\nshwfp.dll

2013-11-12 18:18:26 656896 ----a-w- C:\Windows\SysWow64\nshwfp.dll

2013-11-12 18:18:26 324096 ----a-w- C:\Windows\System32\FWPUCLNT.DLL

2013-11-12 18:18:26 216576 ----a-w- C:\Windows\SysWow64\FWPUCLNT.DLL

2013-11-11 08:59:28 590112 ----a-w- C:\Windows\SysWow64\nvStreaming.exe

2013-11-02 14:12:40 -------- d-----w- C:\Users\Joe\AppData\Roaming\Sega

2013-10-29 18:11:57 1884448 ----a-w- C:\Windows\System32\nvdispco6433165.dll

2013-10-29 18:11:57 1511712 ----a-w- C:\Windows\System32\nvdispgenco6433165.dll

2013-10-29 18:11:57 1510176 ----a-w- C:\Windows\System32\nvhdagenco64.dll

2013-10-29 17:40:40 1064224 ----a-w- C:\Windows\System32\nvspcap64.dll

2013-10-29 17:40:39 955168 ----a-w- C:\Windows\SysWow64\nvspcap.dll

2013-10-29 17:38:48 28960 ----a-w- C:\Windows\SysWow64\nvaudcap32v.dll

2013-10-28 22:07:48 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69

2013-10-28 22:07:48 -------- d-----w- C:\Program Files\iTunes

2013-10-28 22:07:48 -------- d-----w- C:\Program Files\iPod

2013-10-28 22:07:48 -------- d-----w- C:\Program Files (x86)\iTunes


==================== Find3M ====================


2013-11-11 15:02:02 6674208 ----a-w- C:\Windows\System32\nvcpl.dll

2013-11-11 15:02:02 3490080 ----a-w- C:\Windows\System32\nvsvc64.dll

2013-11-11 15:01:59 922912 ----a-w- C:\Windows\System32\nvvsvc.exe

2013-11-11 15:01:59 63776 ----a-w- C:\Windows\System32\nvshext.dll

2013-11-11 15:01:59 219424 ----a-w- C:\Windows\System32\nvmctray.dll

2013-11-11 15:01:58 3467927 ----a-w- C:\Windows\System32\nvcoproc.bin

2013-11-11 05:50:16 267936 ------w- C:\Windows\System32\MpSigStub.exe

2013-10-25 18:00:00 127488 ----a-w- C:\Windows\System32\ff_vfw.dll

2013-10-25 18:00:00 112640 ----a-w- C:\Windows\SysWow64\ff_vfw.dll

2013-10-16 00:48:05 1884448 ----a-w- C:\Windows\System32\nvdispco6433158.dll

2013-10-16 00:48:05 1511712 ----a-w- C:\Windows\System32\nvdispgenco6433158.dll

2013-10-15 11:15:31 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2013-10-15 11:15:31 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2013-10-12 08:45:20 2241536 ----a-w- C:\Windows\System32\wininet.dll

2013-10-12 08:43:37 3959808 ----a-w- C:\Windows\System32\jscript9.dll

2013-10-12 08:43:32 67072 ----a-w- C:\Windows\System32\iesetup.dll

2013-10-12 08:43:32 136704 ----a-w- C:\Windows\System32\iesysprep.dll

2013-10-12 07:03:50 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll

2013-10-12 07:02:33 2877952 ----a-w- C:\Windows\SysWow64\jscript9.dll

2013-10-12 07:02:29 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll

2013-10-12 07:02:29 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll

2013-10-12 06:35:26 2706432 ----a-w- C:\Windows\System32\mshtml.tlb

2013-10-12 06:08:58 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2013-10-12 05:44:38 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe

2013-10-12 05:15:39 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe

2013-10-05 20:25:35 1474048 ----a-w- C:\Windows\System32\crypt32.dll

2013-10-05 19:57:25 1168384 ----a-w- C:\Windows\SysWow64\crypt32.dll

2013-10-04 02:28:31 190464 ----a-w- C:\Windows\System32\SmartcardCredentialProvider.dll

2013-10-04 02:25:17 197120 ----a-w- C:\Windows\System32\credui.dll

2013-10-04 01:58:50 152576 ----a-w- C:\Windows\SysWow64\SmartcardCredentialProvider.dll

2013-10-04 01:56:25 168960 ----a-w- C:\Windows\SysWow64\credui.dll

2013-10-04 01:56:00 1796096 ----a-w- C:\Windows\SysWow64\authui.dll

2013-10-03 02:23:48 404480 ----a-w- C:\Windows\System32\gdi32.dll

2013-10-03 02:00:44 311808 ----a-w- C:\Windows\SysWow64\gdi32.dll

2013-10-02 02:22:20 56832 ----a-w- C:\Windows\System32\drivers\TsUsbFlt.sys

2013-10-02 02:11:13 13824 ----a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe

2013-10-02 02:08:53 12800 ----a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll

2013-10-02 01:48:59 56832 ----a-w- C:\Windows\System32\MsRdpWebAccess.dll

2013-10-02 01:48:08 18944 ----a-w- C:\Windows\System32\wksprtPS.dll

2013-10-02 01:29:05 62976 ----a-w- C:\Windows\System32\tsgqec.dll

2013-10-02 00:15:45 1057280 ----a-w- C:\Windows\System32\rdvidcrl.dll

2013-10-02 00:14:58 50176 ----a-w- C:\Windows\SysWow64\MsRdpWebAccess.dll

2013-10-02 00:14:20 17920 ----a-w- C:\Windows\SysWow64\wksprtPS.dll

2013-10-02 00:08:30 83968 ----a-w- C:\Windows\System32\TSWbPrxy.exe

2013-10-02 00:01:16 420864 ----a-w- C:\Windows\System32\wksprt.exe

2013-10-01 23:58:48 53248 ----a-w- C:\Windows\SysWow64\tsgqec.dll

2013-10-01 23:31:09 1147392 ----a-w- C:\Windows\System32\mstsc.exe

2013-10-01 23:08:10 855552 ----a-w- C:\Windows\SysWow64\rdvidcrl.dll

2013-10-01 22:34:12 1068544 ----a-w- C:\Windows\SysWow64\mstsc.exe

2013-10-01 20:57:46 6578176 ----a-w- C:\Windows\System32\mstscax.dll

2013-10-01 20:55:10 5698048 ----a-w- C:\Windows\SysWow64\mstscax.dll

2013-09-28 01:09:10 497152 ----a-w- C:\Windows\System32\drivers\afd.sys

2013-09-27 23:01:44 39200 ----a-w- C:\Windows\System32\drivers\nvvad64v.sys

2013-09-27 23:01:38 29984 ----a-w- C:\Windows\System32\nvaudcap64v.dll

2013-09-25 02:26:40 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys

2013-09-25 02:26:40 154560 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys

2013-09-25 02:23:41 1030144 ----a-w- C:\Windows\System32\TSWorkspace.dll

2013-09-25 02:23:33 28672 ----a-w- C:\Windows\System32\sspisrv.dll

2013-09-25 02:23:33 135680 ----a-w- C:\Windows\System32\sspicli.dll

2013-09-25 02:23:01 28160 ----a-w- C:\Windows\System32\secur32.dll

2013-09-25 02:22:59 340992 ----a-w- C:\Windows\System32\schannel.dll

2013-09-25 02:21:50 307200 ----a-w- C:\Windows\System32\ncrypt.dll

2013-09-25 02:21:07 1447936 ----a-w- C:\Windows\System32\lsasrv.dll

2013-09-25 01:58:17 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll

2013-09-25 01:57:53 792576 ----a-w- C:\Windows\SysWow64\TSWorkspace.dll

2013-09-25 01:57:26 22016 ----a-w- C:\Windows\SysWow64\secur32.dll

2013-09-25 01:57:24 247808 ----a-w- C:\Windows\SysWow64\schannel.dll

2013-09-25 01:56:42 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll

2013-09-25 01:03:24 30720 ----a-w- C:\Windows\System32\lsass.exe

2013-09-12 08:58:10 1884448 ----a-w- C:\Windows\System32\nvdispco6432723.dll

2013-09-12 08:58:10 1511712 ----a-w- C:\Windows\System32\nvdispgenco6432723.dll

2013-09-12 07:25:40 2559776 ----a-w- C:\Windows\System32\nvsvcr.dll

2013-09-08 02:30:37 1903552 ----a-w- C:\Windows\System32\drivers\tcpip.sys

2013-09-08 02:27:14 327168 ----a-w- C:\Windows\System32\mswsock.dll

2013-09-08 02:03:58 231424 ----a-w- C:\Windows\SysWow64\mswsock.dll

2013-09-04 12:12:11 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys

2013-09-04 12:11:51 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys

2013-09-04 12:11:49 99840 ----a-w- C:\Windows\System32\drivers\usbccgp.sys

2013-09-04 12:11:43 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys

2013-09-04 12:11:43 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys

2013-09-04 12:11:42 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys

2013-09-04 12:11:40 7808 ----a-w- C:\Windows\System32\drivers\usbd.sys

2013-08-31 10:53:37 189248 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe

2013-08-31 10:53:35 75136 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe

2013-08-29 02:17:48 5549504 ----a-w- C:\Windows\System32\ntoskrnl.exe

2013-08-29 02:16:35 1732032 ----a-w- C:\Windows\System32\ntdll.dll

2013-08-29 02:16:28 243712 ----a-w- C:\Windows\System32\wow64.dll

2013-08-29 02:16:14 859648 ----a-w- C:\Windows\System32\tdh.dll

2013-08-29 02:13:28 878080 ----a-w- C:\Windows\System32\advapi32.dll

2013-08-29 01:51:45 3969472 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe

2013-08-29 01:51:45 3914176 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe

2013-08-29 01:50:31 5120 ----a-w- C:\Windows\SysWow64\wow32.dll

2013-08-29 01:50:30 1292192 ----a-w- C:\Windows\SysWow64\ntdll.dll

2013-08-29 01:50:16 619520 ----a-w- C:\Windows\SysWow64\tdh.dll

2013-08-29 01:48:17 640512 ----a-w- C:\Windows\SysWow64\advapi32.dll

2013-08-29 01:48:15 44032 ----a-w- C:\Windows\apppatch\acwow64.dll

2013-08-29 00:49:53 25600 ----a-w- C:\Windows\SysWow64\setup16.exe

2013-08-29 00:49:52 7680 ----a-w- C:\Windows\SysWow64\instnm.exe

2013-08-29 00:49:52 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll

2013-08-29 00:49:49 2048 ----a-w- C:\Windows\SysWow64\user.exe

2006-05-03 11:06:54 163328 --sha-r- C:\Windows\SysWOW64\flvDX.dll

2007-02-21 12:47:16 31232 --sha-r- C:\Windows\SysWOW64\msfDX.dll

2008-03-16 14:30:52 216064 --sha-r- C:\Windows\SysWOW64\nbDX.dll

2010-01-06 23:00:00 107520 --sha-r- C:\Windows\SysWOW64\TAKDSDecoder.dll


============= FINISH: 23:30:50.22 ===============





DDS (Ver_2012-11-20.01)


Microsoft Windows 7 Professional

Boot Device: \Device\HarddiskVolume1

Install Date: 22/10/2009 14:32:26

System Uptime: 25/11/2013 22:24:55 (1 hours ago)


Motherboard: ASUSTeK Computer INC. | | M4A77TD PRO

Processor: AMD Phenom II X3 720 Processor | AM3 | 2800/200mhz


==== Disk Partitions =========================


C: is FIXED (NTFS) - 298 GiB total, 92.363 GiB free.

D: is FIXED (NTFS) - 1397 GiB total, 1252.637 GiB free.

E: is CDROM ()

S: is FIXED (NTFS) - 1863 GiB total, 1477.292 GiB free.


==== Disabled Device Manager Items =============


Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}

Description: MS/MS-Pro


Manufacturer: Generic-

Name: I:\


Service: WUDFRd


Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}

Description: SD/MMC


Manufacturer: Generic-

Name: H:\


Service: WUDFRd


Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}

Description: SM/xD-Picture


Manufacturer: Generic-

Name: G:\


Service: WUDFRd


Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}

Description: Compact Flash


Manufacturer: Generic-

Name: F:\


Service: WUDFRd


==== System Restore Points ===================


RP625: 24/11/2013 17:52:26 - Windows Defender Checkpoint


==== Installed Programs ======================


Update for Microsoft Office 2007 (KB2508958)

12noon Display Changer


64 Bit HP CIO Components Installer

7-Zip 9.20 (x64 edition)

A.F.5 Rename your files 1.1

AaaaaAAaaaAAAaaAAAAaAAAAA!!! for the Awesome

Adobe AIR

Adobe Creative Suite 4 Master Collection

Adobe Download Assistant

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Setup

Adobe Shockwave Player 11.5




Alan Wake

Alien Breed: Impact

Amazon Kindle

Amazon MP3 Downloader 1.0.9

Anomaly Warzone Earth

Apple Application Support

Apple Mobile Device Support


AsfTools 3.1 (remove only)

Assassin's Creed Revelations

Assassin抯 Creed III

ASUS PC Diagnostics

ATI Catalyst Install Manager

Atom Zombie Smasher

Audacity 1.2.6

Auslogics DiskDefrag

Avidemux 2.5



Battlefield 3


Broken Sword: Shadow of the Templars - Director's Cut




Cave Story+


CDex extraction audio


Crystal Reports Basic for Visual Studio 2008

Crystal Reports Basic Runtime for Visual Studio 2008 (x64)

Dead Island

Dead Island Riptide

Dead Space 2

Dead Space 3


DesignPro SE eMedia


Deus Ex: Human Revolution


devolo dLAN Cockpit

dLAN Cockpit

DLC Quest


Dragon's Lair


Duke Nukem 3D

Duke Nukem 3D: Megaton Edition

Dungeons of Dredmor


EndItAll 2.0

English Country Tune

EPU-4 Engine




FileZilla Client 3.7.3

FlashDevelop 4.0.1

Fractal: Make Blooms Not War

FreeFileSync v3.6

GameSave Manager v3

GCFScape 1.7.3

GeForce Experience NvStream Client Components


Gratuitous Space Battles

Half Minute Hero: Super Mega Neo Climax Ultimate Boy


HijackThis 2.0.2

Hotfix for Microsoft Visual C++ 2010 Express - ENU (KB2542054)

Hotfix for Microsoft Visual C++ 2010 Express - ENU (KB2635973)

Hotfix for Microsoft Visual Studio 2008 Professional Edition - ENU (KB971091)

Hotfix for Microsoft Visual Studio 2008 Professional Edition - ENU (KB973674)

Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2280741)

Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2284668)

Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2295689)

Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2420513)

Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2452649)

Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2455033)

Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2485545)

Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB982517)

Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB982721)

Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB983233)

Hotline Miami

HP Imaging Device Functions 13.0

HP Photosmart C4200 All-In-One Driver Software 13.0 Rel. 1

HP Solution Center 13.0

HP Update




Indiana Jones and the Fate of Atlantis

InfraRecorder 0.50 (x64 edition)

Intrusion 2



Java 7 Update 9

Java 6 Update 31

Java 7 Update 3 (64-bit)

Java SE Development Kit 7 Update 3 (64-bit)

JavaFX 2.0.3 (64-bit)

JavaFX 2.0.3 SDK (64-bit)

K-Lite Mega Codec Pack 10.1.3

Kaspersky PURE 2.0

Legend of Grimrock


Linksys Wireless Manager

Little Inferno

Logitech GamePanel Software 3.03.133

Malwarebytes Anti-Malware version


MediaCoder x64

MediaMonkey 3.2

Microsoft .NET Compact Framework 2.0 SP2

Microsoft .NET Compact Framework 3.5

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Extended

Microsoft .NET Framework 4 Multi-Targeting Pack

Microsoft Application Error Reporting

Microsoft Device Emulator (64 bit) version 3.0 - ENU

Microsoft Document Explorer 2008

Microsoft Help Viewer 1.1

Microsoft Office 2007 Service Pack 3 (SP3)

Microsoft Office Access MUI (English) 2007

Microsoft Office Access Setup Metadata MUI (English) 2007

Microsoft Office Excel MUI (English) 2007

Microsoft Office File Validation Add-In

Microsoft Office Groove MUI (English) 2007

Microsoft Office Groove Setup Metadata MUI (English) 2007

Microsoft Office InfoPath MUI (English) 2007

Microsoft Office Office 64-bit Components 2007

Microsoft Office OneNote MUI (English) 2007

Microsoft Office Outlook MUI (English) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

Microsoft Office Publisher MUI (English) 2007

Microsoft Office Shared 64-bit MUI (English) 2007

Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3)

Microsoft Office Ultimate 2007

Microsoft Office Visual Web Developer 2007

Microsoft Office Visual Web Developer MUI (English) 2007

Microsoft Office Word MUI (English) 2007

Microsoft SQL Server 2005

Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)

Microsoft SQL Server 2005 Tools Express Edition

Microsoft SQL Server Compact 3.5 Design Tools ENU

Microsoft SQL Server Compact 3.5 for Devices ENU

Microsoft SQL Server Compact 3.5 SP2 ENU

Microsoft SQL Server Compact 3.5 SP2 x64 ENU

Microsoft SQL Server Database Publishing Wizard 1.2

Microsoft SQL Server Native Client

Microsoft SQL Server Setup Support Files (English)

Microsoft SQL Server VSS Writer

Microsoft Visual C++ Compilers 2010 Standard - enu - x86

Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2005 Redistributable (x64)

Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175

Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570

Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219

Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219

Microsoft Visual C++ 2010 Express - ENU

Microsoft Visual J# 2.0 Redistributable Package

Microsoft Visual Studio 2005 Tools for Office Runtime

Microsoft Visual Studio 2008 Professional Edition - ENU

Microsoft Visual Studio 2008 Remote Debugger - ENU

Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU

Microsoft Visual Studio 2010 Service Pack 1

Microsoft Visual Studio 2010 Tools for Office Runtime (x64)

Microsoft Visual Studio Web Authoring Component

Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools

Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries

Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense

Microsoft Windows SDK for Visual Studio 2008 Tools

Microsoft Windows SDK for Visual Studio 2008 Win32 Tools

Microsoft XNA Framework Redistributable 4.0 Refresh

MotioninJoy DS3 driver version 0.6.0005

MozBackup 1.4.9

Mozilla Firefox 25.0.1 (x86 en-GB)

Mozilla Maintenance Service

Mozilla Thunderbird 24.1.1 (x86 en-GB)

Mp3tag v2.57

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

My O2


NVIDIA 3D Vision Controller Driver

NVIDIA 3D Vision Controller Driver 331.82

NVIDIA 3D Vision Driver 331.82

NVIDIA Control Panel 331.82

NVIDIA GeForce Experience 1.7.1

NVIDIA Graphics Driver 331.82

NVIDIA HD Audio Driver

NVIDIA Install Application

NVIDIA LED Visualizer 1.0


NVIDIA PhysX System Software 9.13.0725

NVIDIA ShadowPlay 9.3.21

NVIDIA Stereoscopic 3D Driver

NVIDIA Update 9.3.21

NVIDIA Update Components

NVIDIA Virtual Audio 1.2.9

OCR Software by I.R.I.S. 13.0

Offspring Fling!

OGRE Demos 1.7.0


Opera 12.16

Organ Trail: Director's Cut



PeerBlock 1.1 (r518)


Poker Night at the Inventory




PunkBuster Services

Pure Networks Platform

Puzzle Agent 2


QT Lite 4.1.0

Ralink RT2870 Wireless LAN Card

Real Alternative 2.0.2

Realtek 8136 8168 8169 Ethernet Driver


Revenge of the Titans

Revo Uninstaller Pro 2.4.1


Saints Row: The Third


Security Update for 2007 Microsoft Office System (KB2288621)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)

Security Update for Microsoft .NET Framework 4 Extended (KB2416472)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Security Update for Microsoft .NET Framework 4 Extended (KB2736428)

Security Update for Microsoft .NET Framework 4 Extended (KB2742595)

Security Update for Microsoft .NET Framework 4 Extended (KB2858302v2)

Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2687309) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2760415) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2827326) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2827329) 32-Bit Edition

Security Update for Microsoft Office Excel 2007 (KB2827324) 32-Bit Edition

Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition

Security Update for Microsoft Office Outlook 2007 (KB2825644) 32-Bit Edition

Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition

Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition

Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition

Security Update for Microsoft Office system 2007 (KB974234)

Security Update for Microsoft Office Word 2007 (KB2827330) 32-Bit Edition

SEGA Genesis & Mega Drive Classics

Serious Sam HD: The First Encounter

Shadow Warrior Classic Redux


Shank 2

SHIELD Streaming

Skype Click to Call

Skype 6.6

SmartFoxServer 2X 2.0.1



Sonic Adventure DX

Sonic CD




SQLite ADO.NET 2.0/3.5 Provider

Star Wars: The Old Republic


Stealth Bastard Deluxe



SUPER v2012.build.51 (April 7, 2012) version v2012.build.51

Super Hexagon


Surgeon Simulator 2013

TeamSpeak 3 Client

TeraCopy 2.27

The Basement Collection

The Binding Of Isaac

The Elder Scrolls V: Skyrim

The Sims 3

The Sims 3 High-End Loft Stuff

The Sims 3 Late Night

The Typing of The Dead: Overkill

The Walking Dead

Thomas Was Alone



Trine 2


Ubisoft Game Launcher


Unity Web Player


Update for 2007 Microsoft Office System (KB967642)

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Client Profile (KB2836939)

Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2836939)

Update for Microsoft .NET Framework 4 Extended (KB2836939v3)

Update for Microsoft Office 2007 Help for Common Features (KB963673)

Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition

Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition

Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition

Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition

Update for Microsoft Office 2007 System (KB2539530)

Update for Microsoft Office Access 2007 Help (KB963663)

Update for Microsoft Office Excel 2007 Help (KB963678)

Update for Microsoft Office Infopath 2007 Help (KB963662)

Update for Microsoft Office OneNote 2007 Help (KB963670)

Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition

Update for Microsoft Office Outlook 2007 Help (KB963677)

Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2825642) 32-Bit Edition

Update for Microsoft Office Powerpoint 2007 Help (KB963669)

Update for Microsoft Office Publisher 2007 Help (KB963667)

Update for Microsoft Office Script Editor Help (KB963671)

Update for Microsoft Office Word 2007 Help (KB963665)

Update for Microsoft Visual Studio 2008 Professional Edition - ENU (KB972221)

VC Runtimes MSI

VIA Platform Device Manager

Visual Studio .NET Prerequisites - English

Visual Studio 2005 Tools for Office Second Edition Runtime

Visual Studio Tools for the Office system 3.0 Runtime

VLC media player 2.1.0

VLC Streamer 4.21


WIDCOMM Bluetooth Software


Windows Driver Package - Broadcom Bluetooth (06/15/2009

Windows Driver Package - Broadcom Bluetooth (07/30/2009

Windows Driver Package - Broadcom HIDClass (07/28/2009

Windows Mobile 5.0 SDK R2 for Pocket PC

Windows Mobile 5.0 SDK R2 for Smartphone

WinMerge 2.12.4

Worms Revolution

XCOM: Enemy Unknown

XML Notepad 2007


Zinio Reader 4



==== Event Viewer Messages From Past Week ========


25/11/2013 22:26:19, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: aiptektp

25/11/2013 22:26:03, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the btwdins service.

23/11/2013 20:24:39, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.

23/11/2013 20:21:53, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.

23/11/2013 15:27:00, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}

23/11/2013 15:26:59, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}

23/11/2013 15:20:17, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}

23/11/2013 15:20:17, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

23/11/2013 15:20:08, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

23/11/2013 15:20:02, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}

23/11/2013 15:19:51, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: aiptektp AsIO CSVirtualDiskDrv discache KLIF SASDIFSV SASKUTIL spldr Wanarpv6

22/11/2013 16:10:29, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.

22/11/2013 12:41:16, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80070420'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.

21/11/2013 17:11:18, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Schedule service.

20/11/2013 12:19:38, Error: Microsoft-Windows-WHEA-Logger [20] - A fatal hardware error has occurred. Component: AMD Northbridge Error Source: Machine Check Exception Error Type: HyperTransport Watchdog Timeout Error Processor ID: 0 The details view of this entry contains further information.

20/11/2013 12:19:25, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the nmservice service.

20/11/2013 12:18:01, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xfffffa8007d8f8f8, 0x0000000000000000, 0x0000000000000000). A dump was saved in: C:\Windows\Minidump\112013-27331-01.dmp. Report Id: 112013-27331-01.

19/11/2013 17:15:10, Error: Service Control Manager [7034] - The Pure Networks Platform Service service terminated unexpectedly. It has done this 1 time(s).

19/11/2013 13:08:08, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the SQL Server (SQLEXPRESS) service to connect.

19/11/2013 13:08:08, Error: Service Control Manager [7000] - The SQL Server (SQLEXPRESS) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

18/11/2013 13:26:11, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xfffffa8007eb0538, 0x0000000000000000, 0x0000000000000000). A dump was saved in: C:\Windows\Minidump\111813-24648-01.dmp. Report Id: 111813-24648-01.

18/11/2013 13:18:07, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Pure Networks Platform Service service to connect.

18/11/2013 13:18:07, Error: Service Control Manager [7000] - The Pure Networks Platform Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.


==== End Of File ===========================

Link to post
Share on other sites

Welcome to the forum.

Please download and run RogueKiller 32 Bit to your desktop.

RogueKiller 64 Bit <---use this one for 64 bit systems

Which system am I using?

Quit all running programs.

For Windows XP, double-click to start.

For Vista or Windows 7-8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.

Click Scan to scan the system.

When the scan completes > Close out the program > Don't Fix anything!

Don't run any other options, they're not all bad!!!!!!!

Post back the report which should be located on your desktop.

(please don't put logs in code or quotes and use the default font)

General P2P/Piracy Warning:

1. If you're using Peer 2 Peer software such as uTorrent, BitTorrent or similar you must either fully uninstall it or completely disable it from running while being assisted here.

Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.

2. If you have illegal/cracked software, cracks, keygens, custom (Adobe) host file, etc. on the system, please remove or uninstall them now and read the policy on Piracy.

Failure to remove such software will result in your topic being closed and no further assistance being provided.



Please read all of my instructions completely including these.

Make sure system restore is turned on and running

Make sure you're subscribed to this topic: Click on the Follow This Topic Button (at the top right of this page), make sure that the Receive notification box is checked and that it is set to Instantly

Removing malware can be unpredictable...unlikely but things can go very wrong! Backup any files that cannot be replaced. You can copy them to a CD/DVD, external drive or a pen drive

<+>Please don't run any other scans, download, install or uninstall any programs while I'm working with you.

<+>The removal of malware isn't instantaneous, please be patient.

<+>When we are done, I'll give to instructions on how to cleanup all the tools and logs

<+>Please stick with me until I give you the "all clear" and Please don't waste my time by leaving before that.

------->Your topic will be closed if you haven't replied within 3 days!<--------

(If I don't respond within 24 hours, please send me a PM)

Link to post
Share on other sites

Thanks very much for your quick response. I will need to turn in soon, but my report is below:

RogueKiller V8.7.9 _x64_ [Nov 25 2013] by Tigzy

mail : tigzyRK<at>gmail<dot>com

Feedback : http://www.adlice.com/forum/

Website : http://www.adlice.com/softwares/roguekiller/

Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version

Started in : Normal mode

User : Joe [Admin rights]

Mode : Scan -- Date : 11/26/2013 00:15:54

| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 3 ¤¤¤

[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND

[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND

[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤

--> %SystemRoot%\System32\drivers\etc\hosts

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) WDC WD3200AAKS-00L9A0 ATA Device +++++

--- User ---

[MBR] 7be44f4ab8b4aa6db3ab33bee2ce9b62

[bSP] 2339d25d60d261478caa50e8fbdd029c : Windows 7/8 MBR Code

Partition table:

0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 305243 Mo

User = LL1 ... OK!

User = LL2 ... OK!

+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) WDC WD15EADS-00P8B0 ATA Device +++++

--- User ---

[MBR] 3a9798d4c48324f0a7e9a6082c9297c5

[bSP] 9191afbcd19dcbe26b182566aa1126de : Legit.A MBR Code

Partition table:

0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 1430796 Mo

User = LL1 ... OK!

User = LL2 ... OK!

+++++ PhysicalDrive2: (\\.\PHYSICALDRIVE2 @ IDE) WDC WD20EARS-00J99B0 ATA Device +++++

--- User ---

[MBR] 007b10bdd336cf1d7cc117f45026bb31

[bSP] dcb81d85259663de424150b0b5e7c9cd : Windows 7/8 MBR Code

Partition table:

0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 1907727 Mo

User = LL1 ... OK!

User = LL2 ... OK!

+++++ PhysicalDrive3: (\\.\PHYSICALDRIVE3 @ USB) Generic- Compact Flash USB Device +++++

Error reading User MBR! ([0x15] The device is not ready. )

User = LL1 ... OK!

Error reading LL2 MBR! ([0x32] The request is not supported. )

+++++ PhysicalDrive4: (\\.\PHYSICALDRIVE4 @ USB) Generic- SM/xD-Picture USB Device +++++

Error reading User MBR! ([0x15] The device is not ready. )

User = LL1 ... OK!

Error reading LL2 MBR! ([0x32] The request is not supported. )

Finished : << RKreport[0]_S_11262013_001554.txt >>

Link to post
Share on other sites

It looks OK, we can run some scans if you want.

I would suggest you disable Windows Defender and update Kaspersky:

Please disable Windows Defender, you have Kaspersky running and having two anti-virus programs running on a system only causes poor performance, conflicts and spotty protection.

How to Disable Defender

Dangers of running 2 anti-virus programs


AV: Kaspersky PURE 2.0 *Enabled/Outdated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
SP: Kaspersky PURE 2.0 *Enabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky PURE 2.0 *Enabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}


Let me know...MrC

Link to post
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.