Im infested with a virus or malware. Sound(ads) play out of my speakers at random times. Even if there isn't 1 program open. there is still sound

Please Help. Im pretty sure Im Infected with Malware or Virus





I have these radio advertisments coming thru my speakers on the pc.  There can be nothing open at all and it will just start playing advertisments.  I work from home and speak to people thru a headset all day.  And the sound comes thru the headset.  I am at my wits end with this thing.  I googled the problem and saw that Im not the only one. So I have ran Malwarebytes on my pc, as well as cccleaner and norton.  But nothing seems to work.  Still to this min there is a advertisment in spanish playing thru my speakers and then a Tablet advertisment.



I thought after running Malwarebytes that it would have fixed the problem.  The Full scan did pick up 3 things. I saved the log and removed the what the scan found. Restarted the pc.  and here we are....



Can you please help me 



Below are the copy & paste of the DDS and Attatch.



DDS (Ver_2012-11-20.01) - NTFS_AMD64 

Internet Explorer: 9.0.8112.16526  BrowserJavaVersion: 10.45.2

Run by Marshall Kline at 16:00:07 on 2014-01-01

Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.8189.2725 [GMT -7:00]


AV: Norton 360 Online *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Norton 360 Online *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

FW: Norton 360 Online *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}


============== Running Processes ===============



C:\Windows\system32\svchost.exe -k DcomLaunch


C:\Windows\system32\svchost.exe -k rpcss

C:\Windows\System32\svchost.exe -k secsvcs


C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup


C:\Windows\system32\svchost.exe -k LocalService

C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe


C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe

C:\Windows\system32\svchost.exe -k NetworkService


C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork




C:\Users\Marshall Kline\AppData\Local\GCC\Controller.exe

C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe


C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Program Files (x86)\Norton 360\Engine\\ccSvcHst.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Users\Marshall Kline\Desktop\UTILITY CLEAN UP FOLDER\Spybot - Search & Destroy 2\SDFSSvc.exe

C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Users\Marshall Kline\Desktop\UTILITY CLEAN UP FOLDER\Spybot - Search & Destroy 2\SDUpdSvc.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe


C:\Program Files\Windows Media Player\wmpnscfg.exe


C:\Program Files (x86)\Norton 360\Engine\\ccSvcHst.exe


C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\system32\svchost.exe -k SDRSVC

C:\Windows\System32\svchost.exe -k WerSvcGroup


C:\Program Files (x86)\Hewlett-Packard\KBD\kbd.exe


C:\Users\Marshall Kline\AppData\Local\GCC\Controller.exe

C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe

C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVC.exe

C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVC.exe

C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVC.exe

C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVC.exe

C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVC.exe

C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVC.exe


C:\Program Files\Windows Media Player\wmpnetwk.exe


C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Users\Marshall Kline\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe








============== Pseudo HJT Report ===============


BHO: Disabled:{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - <orphaned>

BHO: Disabled:{9030D464-4C02-4ABF-8ECC-5164760863C6} - <orphaned>

BHO: Disabled:{DBC80044-A445-435b-BC74-9C25C1C588A9} - <orphaned>

BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360



BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360



BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7



BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet 



BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7



TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\



TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\



uRun: [862E6F2ABDB27F704018BF5A059E623CAA598183._service_run] "C:\Program Files (x86)


\Google\Chrome\Application\chrome.exe" --type=service

uRun: [DAEMON Tools Lite] "C:\Users\Marshall Kline\DVD Program FOLDER\DAEMON Tools Lite\DTLite.exe" -autorun

uRun: [Google Update] "C:\Users\Marshall Kline\AppData\Local\Google\Update\GoogleUpdate.exe" /c

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [sDTray] "C:\Users\Marshall Kline\Desktop\UTILITY CLEAN UP FOLDER\Spybot - Search & Destroy 2\SDTray.exe"

uPolicies-Explorer: NoDrives = dword:0

uPolicies-Explorer: NoDriveTypeAutoRun = dword:221

mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0

mPolicies-Explorer: NoDrives = dword:0

mPolicies-System: EnableLUA = dword:0

mPolicies-System: EnableUIADesktopToggle = dword:0

IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\OFFICE11\EXCEL.EXE/3000

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files 


(x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} - 

DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - 


DPF: {7C9C5968-FA32-4724-AA58-7BF98B40005D} - 


DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - 


DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - 






TCP: NameServer =

TCP: Interfaces\{0A43F2B8-30E9-473F-A491-096CB0336207} : DHCPNameServer =

TCP: Interfaces\{C4226BEC-969C-4E62-A4A3-A0427B7AE12D} : DHCPNameServer =

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)


\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common 



Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo 



Notify: SDWinLogon - SDWinLogon.dll

LSA: Security Packages =  kerberos msv1_0 schannel wdigest tspkg

mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)


\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level 


--multi-install --chrome

x64-mWinlogon: Userinit = C:\Windows\System32\userinit.exe,C:\Program Files (x86)\iSafe\wpk.exe

x64-BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - <orphaned>

x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common 


Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)


\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll

x64-BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - <orphaned>

x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s

x64-mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0

x64-mPolicies-Explorer: NoDrives = dword:0

x64-mPolicies-System: EnableLUA = dword:0

x64-mPolicies-System: EnableUIADesktopToggle = dword:0

x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files 


(x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll

x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)


\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll

x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>

x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>


================= FIREFOX ===================


FF - ProfilePath - C:\Users\Marshall Kline\AppData\Roaming\Mozilla\Firefox\Profiles\hr5yc6gq.default\

FF - prefs.js: browser.startup.homepage - 




FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll

FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll

FF - plugin: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll

FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

FF - plugin: C:\Program Files (x86)\Zoiper Web\npZoiper.dll

FF - plugin: C:\Users\Marshall Kline\AppData\Local\Google\Update\\npGoogleUpdate3.dll

FF - plugin: C:\Users\Marshall Kline\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll

FF - plugin: C:\Users\Marshall Kline\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll

FF - plugin: C:\Users\Marshall Kline\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll

FF - plugin: C:\Users\Marshall Kline\AppData\Roaming\Mozilla\plugins\npo1d.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll

FF - ExtSQL: 2013-11-14 11:25; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; C:\ProgramData\Norton\{0C55C096-0F1D-



FF - ExtSQL: 2013-11-14 21:15; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; C:\ProgramData\Norton\{0C55C096-0F1D-



FF - ExtSQL: 2013-11-15 11:43; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; C:\Program Files (x86)\Mozilla 



FF - ExtSQL: 2013-12-06 20:02; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\Marshall 





FF - user.js: extensions.autoDisableScopes - 0

FF - user.js: extensions.shownSelectionUI - true


============= SERVICES / DRIVERS ===============


R0 gfibto;gfibto;C:\Windows\System32\drivers\gfibto.sys [2013-5-11 14456]

R0 MxEFUF;Matrox Extio Upper Function Filter;C:\Windows\System32\drivers\MxEFUF64.sys [2013-4-24 157696]

R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2009-4-15 55856]

R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\N360x64\0604010.00E\symds64.sys [2013-2-5 451192]

R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\N360x64\0604010.00E\symefa64.sys [2013-


2-5 1129120]

R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145


\Definitions\BASHDefs\20131203.001\BHDrvx64.sys [2013-12-3 1526488]

R1 ccSet_N360;Norton 360 Settings Manager;C:\Windows\System32\drivers\N360x64\0604010.00E\ccsetx64.sys [2013-2-5 



R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2013-5-6 283200]

R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145


\Definitions\IPSDefs\20131231.001\IDSviA64.sys [2013-12-31 521944]

R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\N360x64\0604010.00E\ironx64.sys [2013-2-5 190072]

R1 SYMTDIv;Symantec Vista Network Dispatch Driver;C:\Windows\System32\drivers\N360x64\0604010.00E\symtdiv.sys 


[2013-2-5 445560]

R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-4-20 203776]

R2 FontCache;Windows Font Cache Service;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1


-20 27648]

R2 Freemake Improver;Freemake Improver;C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [2013-9


-12 101888]

R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2011-6-6 72216]

R2 N360;Norton 360;C:\Program Files (x86)\Norton 360\Engine\\ccsvchst.exe [2013-2-5 138272]

R2 npf;NetGroup Packet Filter Driver;C:\Windows\System32\drivers\npf.sys [2011-2-11 35344]

R2 RtkAudioService;Realtek Audio Service;C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2013-11-23 289496]

R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Users\Marshall Kline\Desktop\UTILITY CLEAN UP FOLDER\Spybot - 


Search & Destroy 2\SDFSSvc.exe [2013-12-13 3921880]

R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Users\Marshall Kline\Desktop\UTILITY CLEAN UP FOLDER\Spybot - 


Search & Destroy 2\SDUpdSvc.exe [2013-12-13 1042272]

R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-10-9 



R2 ubsbm;Unibrain 1394 SBM Driver;C:\Windows\System32\drivers\UBSBM.sys [2013-4-28 24064]

R2 ubumapi;Unibrain 1394 FireAPI Driver;C:\Windows\System32\drivers\UBUMAPI.sys [2013-4-28 92160]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec 


Shared\EENGINE\EraserUtilRebootDrv.sys [2013-11-23 137648]

R3 netr7364;USB Wireless 802.11 b/g Adaptor Driver for Vista;C:\Windows\System32\drivers\netr7364.sys [2013-4-22 



R3 PCD5SRVC{8AAF211B-043E02A9-05040000};PCD5SRVC{8AAF211B-043E02A9-05040000} - PCDR Kernel Mode Service 


Helper Driver;C:\PROGRA~1\PC-DOC~1\PCD5SRVC_x64.pkms [2008-9-9 25888]

R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2013-4-30 258784]

R3 ubohci;Unibrain 1394 OHCI Driver;C:\Windows\System32\drivers\ubohci.sys [2013-4-28 132608]

R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache;C:\Windows\Microsoft.NET\Framework64


\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-9-11 1012344]

R3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);C:\Windows\System32\drivers\WsAudio_DeviceS(1).sys [2013-6-19 29288]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN 


v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN 


v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]

S2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Users\Marshall Kline\Desktop\UTILITY CLEAN UP FOLDER\Spybot 


- Search & Destroy 2\SDWSCSvc.exe [2013-12-13 171416]

S3 androidusb;ADB Interface Driver;C:\Windows\System32\drivers\smhwadb.sys [2011-8-24 31744]

S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN 


v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-8-28 89920]

S3 DigiartyVirtualCDBus;Digiarty Virtual Driver;C:\Windows\System32\drivers\DigiartyVirtualCDBus.sys [2013-6-10 276256]

S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]

S3 pimou;Pluralinput Mouse;C:\Windows\System32\drivers\pimou.sys [2013-4-30 22856]

S3 smhwdev;SmartPhone dummy USB PNP Device (Normal);C:\Windows\System32\drivers\smhwdev.sys [2011-8-24 114432]

S3 smhwser;USB Device for Legacy Serial Communication (Normal);C:\Windows\System32\drivers\smhwser.sys [2011-8-24 



S3 SRS_HDAL_Service;HD Audio Lab;C:\Windows\System32\drivers\SRS_HDAL_amd64.sys [2013-5-9 533280]

S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\System32\drivers\ssadbus.sys [2011-5-13 



S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\System32\drivers\ssadmdfl.sys [2011-5-13 16872]

S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\System32\drivers\ssadmdm.sys [2011-5-13 177640]

S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);C:\Windows\System32\drivers\ssadserd.sys [2011-5-13 



S3 SWDUMon;SWDUMon;C:\Windows\System32\drivers\SWDUMon.sys [2013-8-31 16152]

S4 SecStore;Secure Storage;C:\Windows\SysWOW64\secpro.exe [2013-5-9 61440]


=============== File Associations ===============


FileExt: .txt: txtfile=C:\Windows\SysWow64\NOTEPAD.EXE %1

FileExt: .jse: JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*


=============== Created Last 30 ================



==================== Find3M  ====================


2014-01-01 19:59:31 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2014-01-01 19:59:31 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2013-12-29 10:00:03 16152 ----a-w- C:\Windows\System32\drivers\SWDUMon.sys

2013-12-13 05:34:57 90708896 ----a-w- C:\Windows\System32\mrt.exe

2013-11-26 04:39:08 276256 ----a-w- C:\Windows\System32\drivers\DigiartyVirtualCDBus.sys

2013-11-24 03:27:41 525792 ----a-w- C:\Windows\DIFxAPI.dll

2013-11-19 10:33:38 267936 ------w- C:\Windows\System32\MpSigStub.exe

2013-11-15 02:09:03 17847296 ----a-w- C:\Windows\System32\mshtml.dll

2013-11-15 01:42:57 10926080 ----a-w- C:\Windows\System32\ieframe.dll

2013-11-15 01:37:29 2334720 ----a-w- C:\Windows\System32\jscript9.dll

2013-11-15 01:29:33 1347072 ----a-w- C:\Windows\System32\urlmon.dll

2013-11-15 01:29:03 1392128 ----a-w- C:\Windows\System32\wininet.dll

2013-11-15 01:28:41 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl

2013-11-15 01:28:00 237056 ----a-w- C:\Windows\System32\url.dll

2013-11-15 01:25:24 85504 ----a-w- C:\Windows\System32\jsproxy.dll

2013-11-15 01:22:21 173056 ----a-w- C:\Windows\System32\ieUnatt.exe

2013-11-15 01:20:47 599040 ----a-w- C:\Windows\System32\vbscript.dll

2013-11-15 01:20:45 816640 ----a-w- C:\Windows\System32\jscript.dll

2013-11-15 01:19:54 2147840 ----a-w- C:\Windows\System32\iertutil.dll

2013-11-15 01:19:47 729088 ----a-w- C:\Windows\System32\msfeeds.dll

2013-11-15 01:18:24 96768 ----a-w- C:\Windows\System32\mshtmled.dll

2013-11-15 01:18:03 2382848 ----a-w- C:\Windows\System32\mshtml.tlb

2013-11-15 01:12:57 248320 ----a-w- C:\Windows\System32\ieui.dll

2013-11-14 23:13:33 12344320 ----a-w- C:\Windows\SysWow64\mshtml.dll

2013-11-14 22:50:50 1806848 ----a-w- C:\Windows\SysWow64\jscript9.dll

2013-11-14 22:50:06 9739264 ----a-w- C:\Windows\SysWow64\ieframe.dll

2013-11-14 22:43:24 1105408 ----a-w- C:\Windows\SysWow64\urlmon.dll

2013-11-14 22:42:41 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll

2013-11-14 22:42:32 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl

2013-11-14 22:41:18 231936 ----a-w- C:\Windows\SysWow64\url.dll

2013-11-14 22:40:04 65024 ----a-w- C:\Windows\SysWow64\jsproxy.dll

2013-11-14 22:38:54 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe

2013-11-14 22:38:35 717824 ----a-w- C:\Windows\SysWow64\jscript.dll

2013-11-14 22:38:16 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll

2013-11-14 22:37:32 607744 ----a-w- C:\Windows\SysWow64\msfeeds.dll

2013-11-14 22:36:16 1796096 ----a-w- C:\Windows\SysWow64\iertutil.dll

2013-11-14 22:36:08 73216 ----a-w- C:\Windows\SysWow64\mshtmled.dll

2013-11-14 22:35:52 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2013-11-14 22:32:56 176640 ----a-w- C:\Windows\SysWow64\ieui.dll

2013-11-09 23:38:11 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

2013-11-09 23:38:10 264616 ----a-w- C:\Windows\SysWow64\javaws.exe

2013-11-09 23:38:10 175016 ----a-w- C:\Windows\SysWow64\javaw.exe

2013-11-09 23:38:10 174504 ----a-w- C:\Windows\SysWow64\java.exe

2013-10-30 04:34:52 1386496 ----a-w- C:\Windows\System32\WMALFXGFXDSP.dll

2013-10-30 04:34:21 374784 ----a-w- C:\Windows\System32\SysFxUI.dll

2013-10-30 03:55:25 122368 ----a-w- C:\Windows\System32\drivers\drmk.sys

2013-10-30 02:33:31 218112 ----a-w- C:\Windows\System32\drivers\portcls.sys

2013-10-30 02:10:03 2776064 ----a-w- C:\Windows\System32\win32k.sys

2013-10-22 09:31:05 79360 ----a-w- C:\Windows\System32\imagehlp.dll

2013-10-22 07:19:59 158208 ----a-w- C:\Windows\SysWow64\imagehlp.dll

2013-10-14 02:13:07 0 ----a-w- C:\Windows\ativpsrm.bin

2013-10-11 04:27:20 144384 ----a-w- C:\Windows\System32\wshom.ocx

2013-10-11 04:26:04 198656 ----a-w- C:\Windows\System32\scrrun.dll

2013-10-11 04:23:42 462848 ----a-w- C:\Windows\System32\IKEEXT.DLL

2013-10-11 04:23:21 781824 ----a-w- C:\Windows\System32\FWPUCLNT.DLL

2013-10-11 02:19:13 166912 ----a-w- C:\Windows\System32\wscript.exe

2013-10-11 02:19:11 147968 ----a-w- C:\Windows\System32\cscript.exe

2013-10-11 02:08:55 36864 ----a-w- C:\Windows\SysWow64\wshcon.dll

2013-10-11 02:08:55 131072 ----a-w- C:\Windows\SysWow64\wshom.ocx

2013-10-11 02:08:35 172032 ----a-w- C:\Windows\SysWow64\scrrun.dll

2013-10-11 02:07:57 596480 ----a-w- C:\Windows\SysWow64\FWPUCLNT.DLL

2013-10-11 00:35:42 135168 ----a-w- C:\Windows\SysWow64\cscript.exe

2013-10-11 00:35:41 155648 ----a-w- C:\Windows\SysWow64\wscript.exe


============= FINISH: 16:01:39.99 ===============










DDS (Ver_2012-11-20.01)


Microsoft® Windows Vista™ Home Premium 

Boot Device: \Device\HarddiskVolume1

Install Date: 1/26/2009 7:03:28 PM

System Uptime: 12/27/2013 10:38:39 PM (114 hours ago)


Motherboard: ECS  |  | Nettle3

Processor: AMD Phenom 9150e Quad-Core Processor | Socket AM2  | 1800/201mhz


==== Disk Partitions =========================


C: is FIXED (NTFS) - 453 GiB total, 30.827 GiB free.

D: is FIXED (NTFS) - 13 GiB total, 1.354 GiB free.

E: is CDROM ()

F: is CDROM ()

G: is CDROM ()

H: is CDROM ()

I: is CDROM ()

K: is FIXED (NTFS) - 932 GiB total, 74.381 GiB free.

L: is CDROM ()


==== Disabled Device Manager Items =============


Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}

Description: Microsoft 6to4 Adapter

Device ID: ROOT\*6TO4MP\0001

Manufacturer: Microsoft

Name: Microsoft 6to4 Adapter

PNP Device ID: ROOT\*6TO4MP\0001

Service: tunnel


Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}

Description: Microsoft 6to4 Adapter

Device ID: ROOT\*6TO4MP\0004

Manufacturer: Microsoft

Name: Microsoft 6to4 Adapter #2

PNP Device ID: ROOT\*6TO4MP\0004

Service: tunnel


Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}

Description: Microsoft 6to4 Adapter

Device ID: ROOT\*6TO4MP\0015

Manufacturer: Microsoft

Name: Microsoft 6to4 Adapter #3

PNP Device ID: ROOT\*6TO4MP\0015

Service: tunnel


Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}

Description: Microsoft 6to4 Adapter

Device ID: ROOT\*6TO4MP\0029

Manufacturer: Microsoft

Name: Microsoft 6to4 Adapter #6

PNP Device ID: ROOT\*6TO4MP\0029

Service: tunnel


==== System Restore Points ===================


RP1750: 12/28/2013 10:15:31 AM - Scheduled Checkpoint

RP1752: 12/31/2013 4:05:53 PM - Windows Update


==== Installed Programs ======================



7-Zip 9.22beta

AC3Filter 2.5b

Adobe AIR

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Reader XI (11.0.05)

Apple Application Support

Apple Software Update

Astroburn Lite

Auto Gordian Knot 2.40

AviSynth 2.5

AVS Video Converter 8

BDlot DVD ISO Master 3.0.2

Canon MG2100 series MP Drivers

Canon MG2100 series On-screen Manual

Canon MG2100 series User Registration

Canon MP Navigator EX 5.0

Canon My Printer

Canon Solution Menu EX


Compatibility Pack for the 2007 Office system

CyberLink DVD Suite Deluxe


DAEMON Tools Lite

DivX Setup

Download App

DVD Decrypter (Remove Only)

DVD Rebuilder

DVD Shrink 3.2

Enhanced Multimedia Keyboard Solution

ffdshow v1.1.3476 [2010-06-15]

Free Video Cutter 1.1

Freemake Audio Converter version 1.1.0

Freemake Music Box

Freemake Video Converter version 4.1.0

GOM Player

Google Chrome

Google Drive

Google Earth

Google Talk Plugin

Google Update Helper

Hardware Diagnostic Tools

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)

HP MediaSmart DVD

HP Picasso Media Center Add-In

HP Recovery Manager RSS

HPAsset component for HP Active Support Library




Itibiti RTC

Java 7 Update 45

Java Auto Updater



Malwarebytes Anti-Malware version

Microsoft .NET Framework 3.5 SP1

Microsoft .NET Framework 4.5.1

Microsoft .NET Framework 4.5.1 (ITA)

Microsoft .NET Framework 4.5.1 (Italiano)

Microsoft Application Error Reporting

Microsoft Default Manager

Microsoft Office File Validation Add-In

Microsoft Office Professional Edition 2003

Microsoft Silverlight

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft VC9 runtime libraries

Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2005 Redistributable (x64)

Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175

Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570

Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219

Microsoft Works

Microsoft Works 6-9 Converter

Motorola Phone Tools

Mozilla Firefox 26.0 (x86 en-US)

Mozilla Maintenance Service


MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

Norton 360

NVIDIA Control Panel 307.83

NVIDIA Display Control Panel

NVIDIA Drivers

NVIDIA ForceWare Network Access Manager

NVIDIA Graphics Driver 307.83

NVIDIA Install Application

NVIDIA Update 1.10.8

NVIDIA Update Components

Picasa 3


Prism Video File Converter

Python 2.5.2


Realtek High Definition Audio Driver

Security Update for CAPICOM (KB931906)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2861697)

Segoe UI

Skype Click to Call

Skype™ 6.9




Sothink Movie DVD Maker

Spybot - Search & Destroy


Unity Web Player

Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

VC80CRTRedist - 8.0.50727.6195

VLC media player 2.1.2

VobSub v2.23 (Remove Only)

Windows Live Communications Platform

Windows Live Essentials

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Language Selector

Windows Live Movie Maker

Windows Live Photo Common

Windows Live Photo Gallery

Windows Live PIMT Platform

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live UX Platform

Windows Live UX Platform Language Pack

WinPcap 4.1.2

WinRAR 5.01 (64-bit)

Wise Registry Cleaner 7.91

X-Lite 3.0

XviD MPEG4 Video Codec (remove only)

Xvid Video Codec


Zoiper Web


==== Event Viewer Messages From Past Week ========


12/27/2013 11:53:48 AM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while 


waiting for the Freemake Improver service to connect.

12/27/2013 11:53:48 AM, Error: Service Control Manager [7000]  - The Freemake Improver service failed to start due to 


the following error:  The service did not respond to the start or control request in a timely fashion.

12/27/2013 11:51:58 AM, Error: EventLog [6008]  - The previous system shutdown at 6:41:52 AM on 12/27/2013 was 



12/27/2013 10:44:19 PM, Error: Microsoft-Windows-SharedAccess_NAT [30005]  - The DHCP allocator has detected a 


DHCP server with IP address on the same network as the interface with IP address The allocator 


has disabled itself on the interface to avoid confusing DHCP clients.

12/27/2013 10:40:59 PM, Error: Microsoft-Windows-SharedAccess_NAT [34001]  - The ICS_IPV6 failed to configure IPv6 



12/27/2013 10:40:45 PM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) 


failed to load:  Beep

12/27/2013 10:40:44 PM, Error: Service Control Manager [7000]  - The Spybot-S&D 2 Security Center Service service 


failed to start due to the following error:  Spybot-S&D 2 Security Center Service is not a valid Win32 application.

12/27/2013 1:59:41 AM, Error: Microsoft-Windows-PrintSpooler [19]  - The print spooler failed to share printer Canon 


MG2100 series Printer XPS (Copy 2) with shared resource name Canon MG2100 series Printer XPS (Copy 2). Error 2114. 


The printer cannot be used by others on the network.

12/25/2013 2:17:49 PM, Error: Microsoft-Windows-SharedAccess_NAT [31004]  - The DNS proxy agent was unable to 


allocate 0 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager 


has encountered an internal error.

12/25/2013 12:51:42 AM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) 


failed to load:  Beep i8042prt

12/25/2013 12:50:18 AM, Error: EventLog [6008]  - The previous system shutdown at 12:44:31 AM on 12/25/2013 was 



12/25/2013 1:00:44 AM, Error: Microsoft-Windows-SharedAccess_NAT [30013]  - The DHCP allocator has disabled itself 


on IP address, since the IP address is outside the scope from which 


addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to 


include the IP address, or change the IP address to fall within the scope.

1/1/2014 8:25:23 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while 


waiting for a transaction response from the SysMain service.

1/1/2014 11:22:21 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while 


waiting for a transaction response from the TrkWks service.

1/1/2014 1:17:23 PM, Error: Service Control Manager [7031]  - The Windows Media Player Network Sharing Service service 


terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 


milliseconds: Restart the service.


==== End Of File ===========================



Thank you

Marshall Kline

Welcome to the forum.

Please download and run RogueKiller 32 Bit to your desktop.

RogueKiller 64 Bit <---use this one for 64 bit systems

Which system am I using?

Quit all running programs.

For Windows XP, double-click to start.

For Vista or Windows 7-8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.

Click Scan to scan the system.

When the scan completes > Close out the program > Don't Fix anything!

Don't run any other options, they're not all bad!!!!!!!

Post back the report which should be located on your desktop.

(please don't put logs in code or quotes and use the default font)

General P2P/Piracy Warning:

1. If you're using Peer 2 Peer software such uTorrent, BitTorrent or similar you must either fully uninstall it or completely disable it from running while being assisted here.

Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.

2. If you have illegal/cracked software, cracks, keygens, custom (Adobe) host file, etc. on the system, please remove or uninstall them now and read the policy on Piracy.

Failure to remove such software will result in your topic being closed and no further assistance being provided.



Please read all of my instructions completely including these.

Make sure system restore is turned on and running

Make sure you're subscribed to this topic: Click on the Follow This Topic Button (at the top right of this page), make sure that the Receive notification box is checked and that it is set to Instantly

Removing malware can be unpredictable...unlikely but things can go very wrong! Backup any files that cannot be replaced. You can copy them to a CD/DVD, external drive or a pen drive

<+>Please don't run any other scans, download, install or uninstall any programs while I'm working with you.

<+>The removal of malware isn't instantaneous, please be patient.

<+>When we are done, I'll give to instructions on how to cleanup all the tools and logs

<+>Please stick with me until I give you the "all clear" and Please don't waste my time by leaving before that.

------->Your topic will be closed if you haven't replied within 3 days!<--------

(If I don't respond within 24 hours, please send me a PM)

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

