This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

svchost using 1.6gb [Solved]

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I have a problem with my computer. It began this morning when my brother turned it on. Windows booted fine but it wasn't possible to open any application so he left it like that. Unfortunately, i arrived about 4 hours later and i don't know if anything happened in the meantime.
After restart, i oppened task menager and watched as the memory ussage continued to grow to about 75% of total memory (I have 4gb but win is 32bit so it's about 3.4gb of total memory). Under processes i saw that one of the svchost exes was using 1.6gb of memory. It didn't freeze the computer, i could still move mouse and open My computer, for example, but i couldn't start any application or even open control panel or do anything in right click menu.
After another restart, i stoped that svchost but another started and started to take more memory until it came to about 1.1gb. I closed it but then the 3rd showed up and when i stopped that one it just stayed there but again, i couldn't do anything.

Then i restarted to safe mode and there it is working like it should. So for 9 hours now i'm checking solutions online and doing various scans and turning off various services but nothing is helping. I found out what services are under that svchost and have disabled them (all but most necessary) but it din't help at all. I can't use any application that can identify which services exactly are under what process because i can't start any application in normal mode.

I scanned with spyware blaster, nod32 and malwarebytes and cleaned anything they found but nothing has changed. I also used RogueKiller.
Other than that, i think that my video card vent starts to spin faster when i try to go to normal mode so i can assume that it's not problem with hardware.
I didn't install anything for awhile and there is no system restore either.

So please, if there is anything that i can do, please tell me because i really don't want to format my disks…

Thanks in advance,
Prcho


Here is log from hijackthis (from safe mode):

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:14:31, on 7.3.2013.
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
M:\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchab.com/?aff=7&uid=c2834b1…91-000129a604ab
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [EvtMgr6] G:\Programi\miš\SetPointP\SetPoint.exe /launchGaming
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [OscarEditor] "C:\Program Files\MOUSE Editor\MouseEditor.exe" Minimum
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = G:\Programi\Ofis\Office12\ONENOTEM.EXE
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\Programi\Ofis\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\Programi\Ofis\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\Programi\Ofis\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9CFE8537-4A71-4787-A171-8D0180B5C3E7}: NameServer = 192.168.1.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - G:\Programi\Machi\hamachi-2.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files\Tunngle\TnglCtrl.exe

–
End of file - 6518 bytes
Welcome to the forum.

Download DDS from one of the links below and save it to your desktop:
http://download.bleepingcomputer.com/sUBs/dds.scr
http://download.bleepingcomputer.com/sUBs/dds.com

Temporarily disable any script blocker if your Anti-Virus/Anti-Malware has it.
Once downloaded you can disconnect from the Internet and disable your Ant-Virus temporarily if needed.
Then double click dds.scr or dds.com to run the tool, on Vista or Win 7 or Win 8 right click and select Run as administrator
Click the Run button if prompted with an Open File - Security Warning dialog box.
A black DOS console should open and run for a moment.
When done, DDS will open two (2) logs: DDS.txt and Attach.txt
Save both reports to your desktop
Please Copy & Paste the contents of the following logs in your next reply
You can ignore the note about zipping the Attach.txt file

Then………

Please remove any usb or external drives from the computer before you run this scan!

Please download and run RogueKiller to your desktop.

http://tigzy.geekstogo.com/Tools/RogueKillerX64.exe <—use this one for 64 bit systems

Quit all running programs.

For Windows XP, double-click to start.
For Vista or Windows 7-8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.


Click Scan to scan the system.
When the scan completes > Close out the program > Don't Fix anything!

Don't run any other options, they're not all bad!!!!!!!

Post back the report which should be located on your desktop.

MrC
Thank you for reply. Here are the reports (all from safe mode):

DDS (Ver_2012-11-20.01) - NTFS_x86 NETWORK
Internet Explorer: 9.0.8112.16464 BrowserJavaVersion: 10.11.2
Run by [removed] at 16:01:48 on 2013-03-08
Microsoft Windows 7 Professional 6.1.7601.1.1250.385.1033.18.3326.2799 [GMT 1:00]
.
AV: ESET NOD32 Antivirus 4.0 *Enabled/Outdated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.0 *Enabled/Outdated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://searchab.com/?aff=7&uid=c2834b1f-71cc-11e2-9291-000129a604ab
uSearch Bar = Preserve
mStart Page = hxxp://www.google.com
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [OscarEditor] "c:\program files\mouse editor\MouseEditor.exe" Minimum
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [CTHelper] CTHELPER.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [EvtMgr6] g:\programi\miš\setpointp\SetPoint.exe /launchGaming
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
dRun: [DevconDefaultDB] c:\windows\system32\READREG /SILENT /FAIL=1
StartupFolder: c:\users\antrax\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenote 2007 screen clipper and launcher.lnk - g:\programi\ofis\office12\ONENOTEM.EXE
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - g:\programi\ofis\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{4C0700BD-7734-4F5B-BDAA-379A2464EDFE} : DHCPNameServer = [removed]
TCP: Interfaces\{9CFE8537-4A71-4787-A171-8D0180B5C3E7} : NameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WebCheck -
SecurityProviders: SecurityProviders = credssp.dll, snapapi32.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\antrax\appdata\roaming\mozilla\firefox\profiles\aq1gjsza.default-1350177323530\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.hr/
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\users\antrax\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_235.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
FF - ExtSQL: 2013-02-08 10:18; [removed]; c:\users\antrax\appdata\roaming\mozilla\firefox\profiles\aq1gjsza.default-1350177323530\extensions\[removed]
FF - ExtSQL: 2013-02-16 22:18; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\antrax\appdata\roaming\mozilla\firefox\profiles\aq1gjsza.default-1350177323530\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-03-07 15:22; {e001c731-5e37-4538-a5cb-8168736a2360}; c:\users\antrax\appdata\roaming\mozilla\firefox\profiles\aq1gjsza.default-1350177323530\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
.
============= SERVICES / DRIVERS ===============
.
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\drivers\tap0901t.sys [2011-1-29 27136]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-9-28 315392]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-2-24 185472]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-2-6 727720]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\drivers\epfwwfpr.sys [2009-2-6 92800]
S2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-3-7 398184]
S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2013-3-7 682344]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-1-8 161536]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2012-12-29 383416]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;g:\programi\machi\hamachi-2.exe -s –> g:\programi\machi\hamachi-2.exe -s [?]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-3-7 21104]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-10-30 14848]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2012-10-30 49664]
S3 TunngleService;TunngleService;c:\program files\tunngle\TnglCtrl.exe [2012-12-23 745368]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-1-28 1343400]
S4 HiPatchService;Hi-Rez Studios Authenticate and Update Service;g:\igre\hi-rez studios\HiPatchService.exe [2012-4-21 8704]
.
=============== File Associations ===============
.
FileExt: .scr: AutoCADScriptFile=c:\windows\system32\notepad.exe "%1"
FileExt: .reg: Applications\notepad.exe=c:\windows\system32\NOTEPAD.EXE %1 [UserChoice]
FileExt: .inf: inffile=c:\windows\system32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2013-03-08 14:04:43 ——– d—–w- c:\program files\CCleaner
2013-03-07 19:22:56 ——– d-sh–w- c:\users\antrax\%APPDATA%
2013-03-07 16:43:50 ——– d—–w- c:\users\antrax\appdata\roaming\Malwarebytes
2013-03-07 16:43:43 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-03-07 16:43:43 ——– d—–w- c:\programdata\Malwarebytes
2013-03-07 16:43:43 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-03-07 15:57:43 ——– d—–w- c:\windows\pss
2013-03-07 15:33:01 ——– d—–w- c:\program files\Microsoft Windows OneCare Live
2013-03-07 14:25:51 ——– d—–w- c:\program files\common files\Bitdefender
2013-03-07 14:22:52 ——– d—–w- c:\users\antrax\appdata\roaming\QuickScan
2013-03-06 11:47:59 ——– d—–w- c:\users\antrax\appdata\local\{091405CF-C0CB-4024-9BE3-A49927A13F91}
2013-03-05 20:52:12 ——– d—–w- c:\users\antrax\appdata\local\{B9D59054-BAC4-49E2-B21A-EE126A275166}
2013-03-05 08:51:37 ——– d—–w- c:\users\antrax\appdata\local\{E646CED3-BB94-425F-9322-BCA3CA6216F5}
2013-03-05 08:49:48 6954968 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{4947cee9-fe18-4798-a051-961c4edf5fc3}\mpengine.dll
2013-03-04 16:54:50 ——– d—–w- c:\users\antrax\appdata\local\{9CFF82BC-A875-4054-A558-BAC696137172}
2013-03-03 20:09:38 74752 —-a-w- c:\windows\ST6UNST.EXE
2013-03-03 20:09:38 290816 ——w- c:\windows\Setup1.exe
2013-03-03 20:03:45 ——– d—–w- c:\users\antrax\appdata\local\{12742D8B-2F31-4420-A72E-45C5A8A8F4C3}
2013-03-01 20:19:49 ——– d—–w- c:\users\antrax\appdata\local\{C64E3F95-A3C9-4E70-9D98-AE4334E7E27E}
2013-02-28 21:13:03 ——– d—–w- c:\users\antrax\appdata\local\{D2BF84CE-BA4C-488E-BDF8-7281AB30D64D}
2013-02-28 09:12:26 ——– d—–w- c:\users\antrax\appdata\local\{58C4799A-28C9-4A4A-ADD0-8D8DCEBF4359}
2013-02-22 11:33:18 ——– d—–w- c:\users\antrax\appdata\local\{70600CB0-643B-4547-9AE2-859CF2D2BBAB}
2013-02-20 21:00:57 ——– d—–w- c:\users\antrax\appdata\local\Rockstar Games
2013-02-19 16:01:32 ——– d—–w- c:\users\antrax\appdata\local\{15045796-BB3A-4FFD-AFCD-27DA9EE3C0F7}
2013-02-18 14:50:02 ——– d—–w- c:\users\antrax\appdata\local\{B23E43D2-9628-48B3-9D8C-0F24A57F414D}
2013-02-18 01:43:57 ——– d—–w- c:\users\antrax\appdata\local\{83F8CB65-BB12-4447-B382-76D8DBBB9A44}
2013-02-17 13:43:19 ——– d—–w- c:\users\antrax\appdata\local\{9A9DE06F-A173-460F-9E61-A321B5A29A55}
2013-02-16 18:36:21 ——– d—–w- c:\users\antrax\appdata\local\Programs
2013-02-16 13:42:18 ——– d—–w- c:\users\antrax\appdata\local\{211F0F07-FDBD-4EA5-87BA-195DB7C2E639}
2013-02-16 01:41:46 ——– d—–w- c:\users\antrax\appdata\local\{B5546443-E3C3-4EF2-81E2-00FCE9CEB0A3}
2013-02-15 13:41:28 ——– d—–w- c:\users\antrax\appdata\local\{190854AB-3F53-4662-A158-F4D6767AACD3}
2013-02-14 13:40:36 ——– d—–w- c:\users\antrax\appdata\local\{CC376FB8-D5EF-44FF-AA36-498EC6328557}
2013-02-14 01:35:05 2347008 —-a-w- c:\windows\system32\win32k.sys
2013-02-14 01:34:55 3967848 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-02-14 01:34:54 3913064 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-02-14 01:34:52 187752 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-14 01:34:52 1293672 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-02-14 01:34:50 169984 —-a-w- c:\windows\system32\winsrv.dll
2013-02-13 12:34:20 ——– d—–w- c:\users\antrax\appdata\local\{1942E724-F62B-4277-9F97-6B60360417FC}
2013-02-12 15:14:57 ——– d—–w- c:\users\antrax\appdata\local\{363F4E4E-A3D0-4A97-8851-20BFD5576422}
2013-02-11 13:23:51 ——– d—–w- c:\users\antrax\appdata\local\{45441A74-A5CB-43C1-826D-FB94484EF802}
2013-02-10 15:50:35 ——– d—–w- c:\users\antrax\appdata\local\{DD5D2BA0-4544-481C-A10D-FB48C399F67A}
2013-02-09 18:31:12 ——– d—–w- c:\users\antrax\appdata\local\{6977BE1E-6D99-42CD-97E4-8451EA93E581}
2013-02-08 15:37:02 ——– d—–w- c:\users\antrax\appdata\local\{AD8034B0-25C5-411F-BE8A-DA69742F3FDE}
2013-02-08 08:52:26 ——– d—–w- c:\programdata\CLSoft LTD
2013-02-08 08:52:13 ——– d—–w- c:\program files\MagniPic
2013-02-08 08:52:05 ——– d—–w- c:\users\antrax\appdata\local\Google
2013-02-07 09:40:08 ——– d—–w- c:\users\antrax\appdata\local\{3338CA44-89CA-43A2-8C13-85BC39097FB8}
2013-02-06 19:31:50 ——– d—–w- c:\users\antrax\appdata\local\{C670A20C-4FE4-4D96-A241-2353D53A0730}
.
==================== Find3M ====================
.
2013-01-17 00:28:58 232336 ——w- c:\windows\system32\MpSigStub.exe
2013-01-14 23:31:03 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-01-14 23:30:59 859552 —-a-w- c:\windows\system32\npdeployJava1.dll
2013-01-14 23:30:58 780192 —-a-w- c:\windows\system32\deployJava1.dll
2013-01-13 21:17:03 9728 —ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 21:17:02 2560 —ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 21:16:42 10752 —ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 21:12:46 3584 —ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 21:11:21 4096 —ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 21:11:08 5632 —ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 21:11:07 5632 —ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 21:11:07 3072 —ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 21:11:07 3072 —ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:31:00 1247744 —-a-w- c:\windows\system32\DWrite.dll
2013-01-13 20:30:34 906240 —-a-w- c:\windows\system32\FntCache.dll
2013-01-13 20:22:22 1988096 —-a-w- c:\windows\system32\d3d10warp.dll
2013-01-13 20:20:31 293376 —-a-w- c:\windows\system32\dxgi.dll
2013-01-13 20:09:00 249856 —-a-w- c:\windows\system32\d3d10_1core.dll
2013-01-13 20:08:43 220160 —-a-w- c:\windows\system32\d3d10core.dll
2013-01-13 20:08:35 1504768 —-a-w- c:\windows\system32\d3d11.dll
2013-01-13 19:54:01 604160 —-a-w- c:\windows\system32\d3d10level9.dll
2013-01-13 19:53:58 207872 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-01-13 19:53:14 187392 —-a-w- c:\windows\system32\UIAnimation.dll
2013-01-13 19:48:47 161792 —-a-w- c:\windows\system32\d3d10_1.dll
2013-01-13 19:46:25 1080832 —-a-w- c:\windows\system32\d3d10.dll
2013-01-13 19:43:21 1230336 —-a-w- c:\windows\system32\WindowsCodecs.dll
2013-01-13 19:37:57 3419136 —-a-w- c:\windows\system32\d2d1.dll
2013-01-13 19:02:06 417792 —-a-w- c:\windows\system32\WMPhoto.dll
2013-01-13 18:34:58 364544 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2013-01-13 17:26:42 1158144 —-a-w- c:\windows\system32\XpsPrint.dll
2013-01-08 22:11:21 1800704 —-a-w- c:\windows\system32\jscript9.dll
2013-01-08 22:03:20 1129472 —-a-w- c:\windows\system32\wininet.dll
2013-01-08 22:03:12 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2013-01-08 21:59:02 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2013-01-08 21:58:29 420864 —-a-w- c:\windows\system32\vbscript.dll
2013-01-08 21:56:23 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2013-01-04 06:11:21 2284544 —-a-w- c:\windows\system32\msmpeg2vdec.dll
2012-12-29 10:26:54 8904632 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-12-29 10:26:54 889784 —-a-w- c:\windows\system32\nvdispgenco32.dll
2012-12-29 10:26:54 7931896 —-a-w- c:\windows\system32\nvcuda.dll
2012-12-29 10:26:54 6263784 —-a-w- c:\windows\system32\nvopencl.dll
2012-12-29 10:26:54 2720696 —-a-w- c:\windows\system32\nvcuvid.dll
2012-12-29 10:26:54 2504248 —-a-w- c:\windows\system32\nvapi.dll
2012-12-29 10:26:54 20450232 —-a-w- c:\windows\system32\nvoglv32.dll
2012-12-29 10:26:54 1985976 —-a-w- c:\windows\system32\nvcuvenc.dll
2012-12-29 10:26:54 17560504 —-a-w- c:\windows\system32\nvcompiler.dll
2012-12-29 10:26:54 15129064 —-a-w- c:\windows\system32\nvd3dum.dll
2012-12-29 10:26:54 12641120 —-a-w- c:\windows\system32\nvwgf2um.dll
2012-12-29 10:26:54 1017272 —-a-w- c:\windows\system32\nvdispco32.dll
2012-12-29 08:26:22 4129720 —-a-w- c:\windows\system32\nvcpl.dll
2012-12-29 08:26:22 3001272 —-a-w- c:\windows\system32\nvsvc.dll
2012-12-29 08:25:57 639928 —-a-w- c:\windows\system32\nvvsvc.exe
2012-12-29 08:25:57 62904 —-a-w- c:\windows\system32\nvshext.dll
2012-12-29 08:25:57 108984 —-a-w- c:\windows\system32\nvmctray.dll
2012-12-29 01:54:24 550328 —-a-w- c:\windows\system32\nvStreaming.exe
2012-12-16 14:13:28 295424 —-a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13:20 34304 —-a-w- c:\windows\system32\atmlib.dll
.
============= FINISH: 16:02:31,84 ===============

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 28.1.2011. 15:13:25
System Uptime: 8.3.2013. 15:55:10 (1 hours ago)
.
Motherboard: DFI Inc. | | LP DK P45-T2R
Processor: Intel® Core™2 Quad CPU Q9400 @ 2.66GHz | Socket 423 | 2667/333mhz
.
==== Disk Partitions =========================
.
A: is Removable
B: is FIXED (NTFS) - 195 GiB total, 70,307 GiB free.
C: is FIXED (NTFS) - 44 GiB total, 8,793 GiB free.
D: is FIXED (NTFS) - 24 GiB total, 5,414 GiB free.
E: is FIXED (NTFS) - 270 GiB total, 83,029 GiB free.
F: is FIXED (NTFS) - 125 GiB total, 79,143 GiB free.
G: is FIXED (NTFS) - 888 GiB total, 307,55 GiB free.
H: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: ehdrv
Device ID: ROOT\LEGACY_EHDRV\0000
Manufacturer:
Name: ehdrv
PNP Device ID: ROOT\LEGACY_EHDRV\0000
Service: ehdrv
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: Security Processor Loader Driver
Device ID: ROOT\LEGACY_SPLDR\0000
Manufacturer:
Name: Security Processor Loader Driver
PNP Device ID: ROOT\LEGACY_SPLDR\0000
Service: spldr
.
Class GUID:
Description: PCI Input Device
Device ID: PCI\VEN_1102&DEV_7003&SUBSYS_00401102&REV_03\4&1EDC1F61&0&11F0
Manufacturer:
Name: PCI Input Device
PNP Device ID: PCI\VEN_1102&DEV_7003&SUBSYS_00401102&REV_03\4&1EDC1F61&0&11F0
Service:
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
7-Zip 9.10 beta
Ace Utilities
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader XI
Adobe Shockwave Player 11.5
AirMech
Anno 1404
Apple Application Support
Apple Software Update
applicationupdater
Ashampoo Burning Studio 9.20
ASIO4ALL
AutoCAD 2011 - English
AutoCAD 2011 Language Pack - English
Autodesk Material Library 2011
Autodesk Material Library 2011 Base Image library
Bentley IEG License Service
Brytenwalda version 1.396
CarrierCommand Uninstall
CCleaner
Community Expansion Pack version 1.01b
Company of Heroes
Company of Heroes: Opposing Fronts
Company of Heroes: Tales of Valor
D3DX10
doPDF 7.2 printer
Dragon Age II
Earth 2160
Empires Dawn of the Modern World
Endless.Space
eReg
ESET NOD32 Antivirus
Europa 1400 - The Guild
Fallen Earth
FARO LS 1.1.406.58
FIFA 13
FIFA 99
FL Studio 10
FMRTE
Football Manager 2013
Free YouTube to MP3 Converter version 3.9.34.305
gamelauncher-ps2-psg
Grand Ages Rome 1.01
Hi-Rez Studios Authenticate and Update Service
IL-2 Sturmovik 1946
IL Download Manager
Installer
Java 7 Update 11
Java Auto Updater
Java™ 6 Update 35
Junk Mail filter update
Logitech SetPoint 6.32
LogMeIn Hamachi
MagniPic
Malwarebytes Anti-Malware version 1.70.0.1100
Mass Effect 2
Mathcad 15 F000
Mathcad PDSi viewable support
MediaCoder 2011
Medieval II Total War
Miasmata
Microsoft .NET Framework 1.1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual J# .NET Redistributable Package 1.1
Microsoft WSE 3.0 Runtime
Microsoft XNA Framework Redistributable 3.1
Morrowind
Mount&Blade Warband
Mount&Blade With Fire and Sword
Mouse Editor
Mozilla Firefox 19.0.2 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Mumble 1.2.3
NBA 2K12
NBA 2K13
Neverwinter Nights 2
NVIDIA 3D Vision Controller Driver 310.90
NVIDIA 3D Vision Driver 310.90
NVIDIA Control Panel 310.90
NVIDIA Graphics Driver 310.90
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX System Software 9.12.1031
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.11.3
NVIDIA Update Components
OKVIRW
OpenAL
Operation Flashpoint ®: Red River
Pando Media Booster
Path of Exile
Patrician IV
Patrician IV - Rise of a Dynasty
PlanetSide 2
Port Royale 3
PowerISO
Pro Evolution Soccer 2013
ProtectDisc Driver, Version 11
PVSonyDll
QuickTime
Race - The WTCC Game
RaiderZ
Rapture3D 2.4.8 Game
Realtek High Definition Audio Driver
S.W.A.T. 4
Saints Row: The Third
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
Skype™ 6.1
SpellForce 2: Faith in Destiny
Spybot - Search & Destroy
SpywareBlaster 4.5
STAAD.Pro 20.07.01.01
Star Wars®: Knights of the Old Republic ™
Steam
Stronghold Kingdoms
SWAT 4 - The Stetchkov Syndicate
SweetIM for Messenger 3.6
SweetIM Toolbar for Internet Explorer 4.2
Team Fortress 2
TES Construction Set
Towns V8
Tribes Ascend
Tunngle beta
Ubisoft Game Launcher
Uninstall 1.0.0.1
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2767848) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Uplay
VLC media player 1.1.7
Warhammer 40,000: Dawn of War - Game of the Year Edition
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinRAR archiver
X-Universe Plugin Manager 1.40
X3 Albio Prelude Bonus Pack [removed]
X3 Albion Prelude
.
==== Event Viewer Messages From Past Week ========
.
8.3.2013. 8:23:25, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the MMCSS service.
8.3.2013. 8:23:25, Error: Service Control Manager [7000] - The Multimedia Class Scheduler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8.3.2013. 7:36:53, Error: Service Control Manager [7022] - The ESET Service service hung on starting.
8.3.2013. 5:28:24, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
8.3.2013. 16:02:05, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
8.3.2013. 15:59:52, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service NVSvc with arguments "" in order to run the server: {DCAB0989-1301-4319-BE5F-ADE89F88581C}
8.3.2013. 15:58:09, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
8.3.2013. 15:56:53, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}
8.3.2013. 15:56:53, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
8.3.2013. 15:56:26, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
8.3.2013. 15:56:25, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
8.3.2013. 15:56:25, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
8.3.2013. 15:56:21, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
8.3.2013. 15:56:13, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
8.3.2013. 15:56:07, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: discache ehdrv SCDEmu spldr Wanarpv6
8.3.2013. 15:45:35, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
8.3.2013. 15:45:35, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
8.3.2013. 15:45:13, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
8.3.2013. 15:44:09, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
8.3.2013. 15:44:09, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-1073473535.
8.3.2013. 15:43:35, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
8.3.2013. 14:28:16, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.
8.3.2013. 14:27:46, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the PlugPlay service.
8.3.2013. 14:27:16, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the MBAMService service.
8.3.2013. 1:01:14, Error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort3.
7.3.2013. 8:24:31, Error: Microsoft-Windows-Bits-Client [16398] - A new BITS job could not be created. The current job count for the user PRCHO\Antrax (6767) is equal to or greater than the job limit (60) specified through group policy. To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
7.3.2013. 20:21:12, Error: Service Control Manager [7001] - The Windows Audio service depends on the Multimedia Class Scheduler service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
7.3.2013. 20:18:35, Error: Service Control Manager [7001] - The Application Information service depends on the User Profile Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
7.3.2013. 19:23:20, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the iphlpsvc service.
7.3.2013. 19:16:35, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Computer Browser service, but this action failed with the following error: An instance of the service is already running.
7.3.2013. 19:16:06, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ProfSvc service.
7.3.2013. 19:16:06, Error: Service Control Manager [7000] - The User Profile Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7.3.2013. 19:15:36, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the IKEEXT service.
7.3.2013. 19:15:36, Error: Service Control Manager [7000] - The IKE and AuthIP IPsec Keying Modules service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7.3.2013. 19:15:06, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
7.3.2013. 19:15:06, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Multimedia Class Scheduler service, but this action failed with the following error: An instance of the service is already running.
7.3.2013. 19:14:06, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Server service, but this action failed with the following error: An instance of the service is already running.
7.3.2013. 19:13:06, Error: Service Control Manager [7034] - The Application Information service terminated unexpectedly. It has done this 1 time(s).
7.3.2013. 19:13:06, Error: Service Control Manager [7031] - The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7.3.2013. 19:13:06, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
7.3.2013. 19:13:06, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
7.3.2013. 19:13:06, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7.3.2013. 19:13:06, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7.3.2013. 19:13:06, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
7.3.2013. 19:13:06, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7.3.2013. 19:13:06, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7.3.2013. 19:13:06, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
7.3.2013. 19:13:06, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
7.3.2013. 19:13:06, Error: Service Control Manager [7031] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
7.3.2013. 19:13:06, Error: Service Control Manager [7031] - The Computer Browser service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
7.3.2013. 19:13:06, Error: Service Control Manager [7031] - The Background Intelligent Transfer Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7.3.2013. 19:13:06, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7.3.2013. 15:19:00, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the wuauserv service.
7.3.2013. 15:19:00, Error: Service Control Manager [7000] - The Windows Update service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7.3.2013. 15:18:00, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Winmgmt service.
7.3.2013. 15:18:00, Error: Service Control Manager [7001] - The Security Center service depends on the Windows Management Instrumentation service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
7.3.2013. 15:16:46, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
7.3.2013. 15:16:46, Error: Service Control Manager [7031] - The Background Intelligent Transfer Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
7.3.2013. 15:06:21, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
7.3.2013. 15:00:35, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
7.3.2013. 15:00:35, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
7.3.2013. 15:00:18, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD CSC DfsC discache ehdrv NetBIOS NetBT nsiproxy Psched rdbss SCDEmu spldr tdx Wanarpv6 WfpLwf
7.3.2013. 15:00:18, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
7.3.2013. 15:00:18, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
7.3.2013. 15:00:18, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
7.3.2013. 15:00:18, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
7.3.2013. 15:00:18, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
7.3.2013. 15:00:18, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
7.3.2013. 15:00:18, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
7.3.2013. 15:00:18, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
7.3.2013. 15:00:18, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
7.3.2013. 15:00:18, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
7.3.2013. 14:47:10, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Background Intelligent Transfer Service service, but this action failed with the following error: An instance of the service is already running.
7.3.2013. 14:47:10, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Themes service.
7.3.2013. 14:47:10, Error: Service Control Manager [7000] - The Themes service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7.3.2013. 14:47:05, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
7.3.2013. 14:46:40, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the LanmanServer service.
7.3.2013. 14:46:10, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Schedule service.
7.3.2013. 14:46:10, Error: Service Control Manager [7000] - The Task Scheduler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7.3.2013. 14:45:08, Error: Service Control Manager [7001] - The Application Information service depends on the User Profile Service service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
7.3.2013. 13:23:24, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service stisvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
7.3.2013. 12:58:33, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AeLookupSvc service.
7.3.2013. 12:58:33, Error: Service Control Manager [7000] - The Application Experience service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7.3.2013. 12:25:31, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
6.3.2013. 12:16:24, Error: Microsoft-Windows-Bits-Client [16398] - A new BITS job could not be created. The current job count for the user PRCHO\Antrax (2962) is equal to or greater than the job limit (60) specified through group policy. To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
5.3.2013. 17:25:41, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
5.3.2013. 12:44:55, Error: Microsoft-Windows-Bits-Client [16398] - A new BITS job could not be created. The current job count for the user PRCHO\Antrax (129) is equal to or greater than the job limit (60) specified through group policy. To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
4.3.2013. 8:13:44, Error: Microsoft-Windows-Bits-Client [16398] - A new BITS job could not be created. The current job count for the user PRCHO\Antrax (128) is equal to or greater than the job limit (60) specified through group policy. To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
2.3.2013. 14:55:15, Error: Microsoft-Windows-Bits-Client [16398] - A new BITS job could not be created. The current job count for the user PRCHO\Antrax (127) is equal to or greater than the job limit (60) specified through group policy. To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
1.3.2013. 9:32:15, Error: Microsoft-Windows-Bits-Client [16398] - A new BITS job could not be created. The current job count for the user PRCHO\Antrax (126) is equal to or greater than the job limit (60) specified through group policy. To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
1.3.2013. 9:32:05, Error: Service Control Manager [7023] - The Server service terminated with the following error: Not enough storage is available to complete this operation.
.
==== End Of File ===========================



RogueKiller V8.5.2 [Feb 23 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Safe mode with network support
User : Antrax [Admin rights]
Mode : Scan – Date : 03/08/2013 16:20:26
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 4 ¤¤¤
[HJ SMENU] HKCU\[…]\Advanced : Start_ShowMyGames (0) -> FOUND
[HJ DESK] HKCU\[…]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ Extern Hives: ¤¤¤
-> D:\windows\system32\config\SOFTWARE
-> D:\windows\system32\config\SYSTEM
-> D:\Users\Default\NTUSER.DAT
-> D:\Users\Default User\NTUSER.DAT
-> D:\Users\Prcho\NTUSER.DAT
-> D:\Documents and Settings\Default\NTUSER.DAT
-> D:\Documents and Settings\Default User\NTUSER.DAT
-> D:\Documents and Settings\UpdatusUser\NTUSER.DAT

¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: SAMSUNG HD502IJ ATA Device +++++
— User —
[MBR] 977d075bd3b9883d80e0332d1bcd463a
[BSP] 6b52f9613f82dc8c2732c1f45fd8a015 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 199996 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 409593240 | Size: 276932 Mo
User = LL1 … OK!
User = LL2 … OK!

+++++ PhysicalDrive1: SAMSUNG HD103SJ ATA Device +++++
— User —
[MBR] b9a63ba4c7e386b2c26a35910954f1fd
[BSP] 8fab17ee0b5407ea36d082427e8f850f : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 45000 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 92162048 | Size: 908867 Mo
User = LL1 … OK!
User = LL2 … OK!

+++++ PhysicalDrive2: ST3160815AS ATA Device +++++
— User —
[MBR] 6bdffa9e67548319a65202d863d1e0ba
[BSP] a46e131688692d7075e5884d3f2da90e : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 24999 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 51199155 | Size: 127617 Mo
User = LL1 … OK!
User = LL2 … OK!

+++++ PhysicalDrive3: StoreJet Transcend +++++
— User —
[MBR] b76c08cd6fe29f348dc12f2543488ea0
[BSP] 438925266526edc7c2eee8a4cb167266 : MBR Code unknown
Partition table:
0 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 63 | Size: 238472 Mo
User = LL1 … OK!
Error reading LL2 MBR!

Finished : << RKreport[11]_S_03082013_02d1620.txt >>
RKreport[10]_S_03082013_02d1616.txt ; RKreport[11]_S_03082013_02d1620.txt ; RKreport[1]_S_03072013_02d2008.txt ; RKreport[2]_H_03072013_02d2009.txt ; RKreport[3]_S_03072013_02d2010.txt ;
RKreport[4]_D_03072013_02d2012.txt ; RKreport[5]_S_03072013_02d2100.txt ; RKreport[6]_S_03082013_02d0501.txt ; RKreport[7]_H_03082013_02d0503.txt ; RKreport[8]_S_03082013_02d1536.txt ;
RKreport[9]_H_03082013_02d1536.txt
Please create a new system restore point before running Malwarebytes Anti-Rootkit if you can.

Download Malwarebytes Anti-Rootkit from HERE
  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder….. mbar-log.txt and system-log.txt

~~~~~~~~~~~~~~~~~~~~~~~

Note:
If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
Internet access
Windows Update
Windows Firewall

If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot.
Verify that your system is now functioning normally.


MrC
Malwarebytes Anty-rootkit didn't find anything. I also ran fixdamage tool, rebooted but nothing has changed. Here are the reports as requested: Malwarebytes Anti-Rootkit BETA 1.01.0.1021 www.malwarebytes.org Database version: v2013.03.08.12 Windows 7 Service Pack 1 x86 NTFS (Safe Mode/Networking) Internet Explorer 9.0.8112.16421 Antrax :: PRCHO [administrator] 8.3.2013. 16:56:23 mbar-log-2013-03-08 (16-56-23).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 30544 Time elapsed: 5 minute(s), 5 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ————————————— Malwarebytes Anti-Rootkit BETA 1.01.0.1021 © Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x86 System is currently in a safe mode Account is Administrative Internet Explorer version: 9.0.8112.16421 Java version: 1.6.0_35 File system is: NTFS Disk drives: B:\ DRIVE_FIXED, C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, E:\ DRIVE_FIXED, F:\ DRIVE_FIXED, G:\ DRIVE_FIXED, M:\ DRIVE_FIXED CPU speed: 2.667000 GHz Memory total: 3487752192, free: 2941198336 ———— Kernel report ———— 03/08/2013 16:49:40 ———— Loaded modules ———– \SystemRoot\system32\ntkrnlpa.exe \SystemRoot\system32\halmacpi.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\ACPI.sys \SystemRoot\system32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\system32\drivers\vdrvroot.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\system32\drivers\pciide.sys \SystemRoot\system32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\system32\drivers\vmbus.sys \SystemRoot\system32\drivers\winhv.sys \SystemRoot\system32\drivers\atapi.sys \SystemRoot\system32\drivers\ataport.SYS \SystemRoot\system32\drivers\amdxata.sys \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\msrpc.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\Drivers\cng.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\drivers\vmstorfl.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\hwpolicy.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\DRIVERS\disk.sys \SystemRoot\system32\DRIVERS\CLASSPNP.SYS \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\DRIVERS\wfplwf.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\system32\drivers\csc.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\usbuhci.sys \SystemRoot\system32\DRIVERS\USBPORT.SYS \SystemRoot\system32\DRIVERS\usbehci.sys \SystemRoot\system32\drivers\HDAudBus.sys \SystemRoot\system32\DRIVERS\cdrom.sys \SystemRoot\system32\DRIVERS\yk62x86.sys \SystemRoot\system32\DRIVERS\fdc.sys \SystemRoot\system32\drivers\i8042prt.sys \SystemRoot\system32\DRIVERS\kbdclass.sys \SystemRoot\system32\DRIVERS\blbdrive.sys \SystemRoot\system32\drivers\CompositeBus.sys \SystemRoot\system32\drivers\mssmbios.sys \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\hamachi.sys \SystemRoot\system32\DRIVERS\tap0901t.sys \SystemRoot\system32\DRIVERS\rdpbus.sys \SystemRoot\system32\drivers\termdd.sys \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\drivers\swenum.sys \SystemRoot\system32\drivers\ks.sys \SystemRoot\system32\drivers\umbus.sys \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\system32\DRIVERS\flpydisk.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\System32\drivers\dxg.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\framebuf.dll \SystemRoot\System32\ATMFD.DLL \SystemRoot\system32\DRIVERS\usbprint.sys \SystemRoot\system32\DRIVERS\usbccgp.sys \SystemRoot\system32\DRIVERS\hidusb.sys \SystemRoot\system32\DRIVERS\HIDCLASS.SYS \SystemRoot\system32\DRIVERS\HIDPARSE.SYS \SystemRoot\system32\DRIVERS\kbdhid.sys \SystemRoot\system32\DRIVERS\mouhid.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\dump_dumpata.sys \SystemRoot\System32\Drivers\dump_atapi.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\Drivers\fastfat.SYS \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\DRIVERS\USBSTOR.SYS \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\mbamswissarmy.sys \Windows\System32\ntdll.dll \Windows\System32\smss.exe \Windows\System32\apisetschema.dll \Windows\System32\autochk.exe ———– End ———– <<<1>>> Upper Device Name: \Device\Harddisk3\DR4 Upper Device Object: 0xffffffffc3dcaac8 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\00000084\ Lower Device Object: 0xffffffffc4a97640 Lower Device Driver Name: \Driver\USBSTOR\ Driver name found: USBSTOR Initialization returned 0x0 Load Function returned 0x0 <<<1>>> Upper Device Name: \Device\Harddisk2\DR2 Upper Device Object: 0xffffffffc35b0030 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IdeDeviceP3T1L0-7\ Lower Device Object: 0xffffffffc27d2908 Lower Device Driver Name: \Driver\atapi\ Driver name found: atapi Initialization returned 0x0 Port sub-driver loaded: \??\C:\Windows\System32\drivers\ataport.sys (0x0) Load Function returned 0x0 <<<1>>> Upper Device Name: \Device\Harddisk1\DR1 Upper Device Object: 0xffffffffc35af950 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IdeDeviceP3T0L0-6\ Lower Device Object: 0xffffffffc3090908 Lower Device Driver Name: \Driver\atapi\ Driver name found: atapi <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xffffffffc35ae2b0 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IdeDeviceP2T0L0-4\ Lower Device Object: 0xffffffffc3096908 Lower Device Driver Name: \Driver\atapi\ Driver name found: atapi Downloaded database version: v2013.03.08.12 Initializing… Done! <<<2>>> Device number: 1, partition: 1 Physical Sector Size: 512 Drive: 1, DevicePointer: 0xffffffffc35af950, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ ——— Disk Stack —— DevicePointer: 0xffffffffc35af588, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffffc35af950, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffffc27d24e8, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xffffffffc3090908, DeviceName: \Device\Ide\IdeDeviceP3T0L0-6\, DriverName: \Driver\atapi\ ———— End ———- Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ Upper DeviceData: 0xffffffffdeb9d038, 0xffffffffc35af950, 0xffffffffc4a26130 Lower DeviceData: 0xffffffffde7ea400, 0xffffffffc3090908, 0xffffffffc42262d0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning directory: C:\Windows\system32\drivers… <<<2>>> Device number: 1, partition: 1 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Done! Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffffffc35ae2b0, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ ——— Disk Stack —— DevicePointer: 0xffffffffc35af020, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffffc35ae2b0, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffffc276e900, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xffffffffc3096908, DeviceName: \Device\Ide\IdeDeviceP2T0L0-4\, DriverName: \Driver\atapi\ ———— End ———- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0xffffffffbc8bd0e0, 0xffffffffc35ae2b0, 0xffffffffc36ed7f8 Lower DeviceData: 0xffffffffde8f29e0, 0xffffffffc3096908, 0xffffffffc41d2048 Drive 0 Scanning MBR on drive 0… Inspecting partition table: MBR Signature: 55AA Disk Signature: A84EA84E Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 63 Numsec = 409593177 Partition file system is NTFS Partition is bootable Partition 1 type is Extended with LBA (0xf) Partition is NOT ACTIVE. Partition starts at LBA: 409593240 Numsec = 567158760 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 500107862016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-62-976753168-976773168)… Drive 1 Scanning MBR on drive 1… Inspecting partition table: MBR Signature: 55AA Disk Signature: 8B5029E3 Partition information: Partition 0 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 2048 Numsec = 92160000 Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 92162048 Numsec = 1861359616 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 1000204886016 bytes Sector size: 512 bytes Physical Sector Size: 512 Drive: 2, DevicePointer: 0xffffffffc35b0030, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\ ——— Disk Stack —— DevicePointer: 0xffffffffc35b0cb0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffffc35b0030, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffffc2749918, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xffffffffc27d2908, DeviceName: \Device\Ide\IdeDeviceP3T1L0-7\, DriverName: \Driver\atapi\ ———— End ———- Alternate DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\ Upper DeviceData: 0xffffffffbc9cc4e0, 0xffffffffc35b0030, 0xffffffffc3cda608 Lower DeviceData: 0xffffffffde62a070, 0xffffffffc27d2908, 0xffffffffc4247700 Drive 2 Scanning MBR on drive 2… Inspecting partition table: MBR Signature: 55AA Disk Signature: 7B707B7 Partition information: Partition 0 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 63 Numsec = 51199092 Partition 1 type is Extended with LBA (0xf) Partition is NOT ACTIVE. Partition starts at LBA: 51199155 Numsec = 261361485 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 160041885696 bytes Sector size: 512 bytes Physical Sector Size: 512 Drive: 3, DevicePointer: 0xffffffffc3dcaac8, DeviceName: \Device\Harddisk3\DR4\, DriverName: \Driver\Disk\ ——— Disk Stack —— DevicePointer: 0xffffffffc4aa6ba8, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffffc3dcaac8, DeviceName: \Device\Harddisk3\DR4\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffffc4a97640, DeviceName: \Device\00000084\, DriverName: \Driver\USBSTOR\ ———— End ———- Alternate DeviceName: \Device\Harddisk3\DR4\, DriverName: \Driver\Disk\ Upper DeviceData: 0xffffffffde8424d8, 0xffffffffc3dcaac8, 0xffffffffc4afdac8 Lower DeviceData: 0xffffffffe04c2d08, 0xffffffffc4a97640, 0xffffffffc4037048 Drive 3 Scanning MBR on drive 3… Inspecting partition table: MBR Signature: 55AA Disk Signature: E6D6DEC5 Partition information: Partition 0 type is Other (0xc) Partition is NOT ACTIVE. Partition starts at LBA: 63 Numsec = 488392002 Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 250059350016 bytes Sector size: 512 bytes Done! Performing system, memory and registry scan… Done! Scan finished ======================================= ————————————— Malwarebytes Anti-Rootkit BETA 1.01.0.1021 © Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x86 System is currently in a safe mode Account is Administrative Internet Explorer version: 9.0.8112.16421 Java version: 1.6.0_35 File system is: NTFS Disk drives: B:\ DRIVE_FIXED, C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, E:\ DRIVE_FIXED, F:\ DRIVE_FIXED, G:\ DRIVE_FIXED, M:\ DRIVE_FIXED CPU speed: 2.667000 GHz Memory total: 3487752192, free: 2968088576 ———— Kernel report ———— 03/08/2013 16:56:47 ———— Loaded modules ———– \SystemRoot\system32\ntkrnlpa.exe \SystemRoot\system32\halmacpi.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\ACPI.sys \SystemRoot\system32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\system32\drivers\vdrvroot.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\system32\drivers\pciide.sys \SystemRoot\system32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\system32\drivers\vmbus.sys \SystemRoot\system32\drivers\winhv.sys \SystemRoot\system32\drivers\atapi.sys \SystemRoot\system32\drivers\ataport.SYS \SystemRoot\system32\drivers\amdxata.sys \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\msrpc.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\Drivers\cng.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\drivers\vmstorfl.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\hwpolicy.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\DRIVERS\disk.sys \SystemRoot\system32\DRIVERS\CLASSPNP.SYS \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\DRIVERS\wfplwf.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\system32\drivers\csc.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\usbuhci.sys \SystemRoot\system32\DRIVERS\USBPORT.SYS \SystemRoot\system32\DRIVERS\usbehci.sys \SystemRoot\system32\drivers\HDAudBus.sys \SystemRoot\system32\DRIVERS\cdrom.sys \SystemRoot\system32\DRIVERS\yk62x86.sys \SystemRoot\system32\DRIVERS\fdc.sys \SystemRoot\system32\drivers\i8042prt.sys \SystemRoot\system32\DRIVERS\kbdclass.sys \SystemRoot\system32\DRIVERS\blbdrive.sys \SystemRoot\system32\drivers\CompositeBus.sys \SystemRoot\system32\drivers\mssmbios.sys \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\hamachi.sys \SystemRoot\system32\DRIVERS\tap0901t.sys \SystemRoot\system32\DRIVERS\rdpbus.sys \SystemRoot\system32\drivers\termdd.sys \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\drivers\swenum.sys \SystemRoot\system32\drivers\ks.sys \SystemRoot\system32\drivers\umbus.sys \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\system32\DRIVERS\flpydisk.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\System32\drivers\dxg.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\framebuf.dll \SystemRoot\System32\ATMFD.DLL \SystemRoot\system32\DRIVERS\usbprint.sys \SystemRoot\system32\DRIVERS\usbccgp.sys \SystemRoot\system32\DRIVERS\hidusb.sys \SystemRoot\system32\DRIVERS\HIDCLASS.SYS \SystemRoot\system32\DRIVERS\HIDPARSE.SYS \SystemRoot\system32\DRIVERS\kbdhid.sys \SystemRoot\system32\DRIVERS\mouhid.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\dump_dumpata.sys \SystemRoot\System32\Drivers\dump_atapi.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\Drivers\fastfat.SYS \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\DRIVERS\USBSTOR.SYS \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\mbamswissarmy.sys \Windows\System32\ntdll.dll \Windows\System32\smss.exe \Windows\System32\apisetschema.dll \Windows\System32\autochk.exe ———– End ———– <<<1>>> Upper Device Name: \Device\Harddisk3\DR4 Upper Device Object: 0xffffffffc3dcaac8 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\00000084\ Lower Device Object: 0xffffffffc4a97640 Lower Device Driver Name: \Driver\USBSTOR\ Device already Exists: 0xffffffffc4037048 <<<1>>> Upper Device Name: \Device\Harddisk2\DR2 Upper Device Object: 0xffffffffc35b0030 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IdeDeviceP3T1L0-7\ Lower Device Object: 0xffffffffc27d2908 Lower Device Driver Name: \Driver\atapi\ Device already Exists: 0xffffffffc4247700 <<<1>>> Upper Device Name: \Device\Harddisk1\DR1 Upper Device Object: 0xffffffffc35af950 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IdeDeviceP3T0L0-6\ Lower Device Object: 0xffffffffc3090908 Lower Device Driver Name: \Driver\atapi\ Device already Exists: 0xffffffffc42262d0 <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xffffffffc35ae2b0 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IdeDeviceP2T0L0-4\ Lower Device Object: 0xffffffffc3096908 Lower Device Driver Name: \Driver\atapi\ Device already Exists: 0xffffffffc41d2048 =======================================
Please download and run ComboFix.

The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

Please visit this webpage for download links, and instructions for running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Information on disabling your malware programs can be found Here.

Make sure you run ComboFix from your desktop.

Give it at least 30-45 minutes to finish if needed.

Please include the C:\ComboFix.txt in your next reply for further review.

———->NOTE<———-

If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix….please reboot the computer, this should resolve the problem. You may have to do this several times if needed.

MrC
ComboFix said that i should turn of nod32 but it is already turned off. There is no icon in system tray and i checked under services. Also, when i try to run nod manually, it doesn't want to start in safe mode so i started ComboFix anyway. I hope that's ok.
Here is ComboFix report: ComboFix 13-03-07.03 - Antrax 8.03.2013. 17:32:38.1.4 - x86 NETWORK Microsoft Windows 7 Professional 6.1.7601.1.1250.385.1033.18.3326.2820 [GMT 1:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 4.0 *Enabled/Outdated* {CB0F8167-5331-BA19-698E-64816B6801A5} SP: ESET NOD32 Antivirus 4.0 *Enabled/Outdated* {706E6083-750B-B597-533E-5FF310EF4B18} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\ST6UNST.000 c:\windows\system32\URTTemp c:\windows\system32\URTTemp\regtlib.exe G:\install.exe . . ((((((((((((((((((((((((( Files Created from 2013-02-08 to 2013-03-08 ))))))))))))))))))))))))))))))) . . 2013-03-08 14:04 . 2013-03-08 14:04 ——– d—–w- c:\program files\CCleaner 2013-03-07 19:22 . 2013-03-07 19:22 ——– d-sh–w- c:\users\Antrax\%APPDATA% 2013-03-07 16:43 . 2013-03-07 16:43 ——– d—–w- c:\users\Antrax\AppData\Roaming\Malwarebytes 2013-03-07 16:43 . 2013-03-07 19:26 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2013-03-07 16:43 . 2013-03-07 16:43 ——– d—–w- c:\programdata\Malwarebytes 2013-03-07 16:43 . 2012-12-14 15:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-03-07 15:33 . 2013-03-07 15:33 ——– d—–w- c:\program files\Microsoft Windows OneCare Live 2013-03-07 14:25 . 2013-03-07 14:25 ——– d—–w- c:\program files\Common Files\Bitdefender 2013-03-07 14:22 . 2013-03-08 14:00 ——– d—–w- c:\users\Antrax\AppData\Roaming\QuickScan 2013-03-05 08:49 . 2013-02-08 00:45 6954968 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4947CEE9-FE18-4798-A051-961C4EDF5FC3}\mpengine.dll 2013-03-03 20:09 . 2013-03-03 20:11 74752 —-a-w- c:\windows\ST6UNST.EXE 2013-03-03 20:09 . 2013-03-03 20:11 290816 ——w- c:\windows\Setup1.exe 2013-02-20 21:00 . 2013-02-20 21:00 ——– d—–w- c:\users\Antrax\AppData\Local\Rockstar Games 2013-02-16 18:36 . 2013-02-16 18:36 ——– d—–w- c:\users\Antrax\AppData\Local\Programs 2013-02-14 01:35 . 2013-01-04 03:00 2347008 —-a-w- c:\windows\system32\win32k.sys 2013-02-14 01:34 . 2013-01-05 05:00 3967848 —-a-w- c:\windows\system32\ntkrnlpa.exe 2013-02-14 01:34 . 2013-01-05 05:00 3913064 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-02-14 01:34 . 2013-01-03 05:05 1293672 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-02-14 01:34 . 2013-01-03 05:04 187752 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2013-02-14 01:34 . 2013-01-04 04:50 169984 —-a-w- c:\windows\system32\winsrv.dll 2013-02-08 08:52 . 2013-02-08 08:52 ——– d—–w- c:\programdata\CLSoft LTD 2013-02-08 08:52 . 2013-02-08 08:52 ——– d—–w- c:\program files\MagniPic 2013-02-08 08:52 . 2013-02-08 08:52 ——– d—–w- c:\users\Antrax\AppData\Local\Google . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-17 00:28 . 2011-01-28 14:49 232336 ——w- c:\windows\system32\MpSigStub.exe 2013-01-14 23:31 . 2013-01-14 23:31 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll 2013-01-14 23:30 . 2012-07-15 06:46 859552 —-a-w- c:\windows\system32\npdeployJava1.dll 2013-01-14 23:30 . 2011-02-01 15:24 780192 —-a-w- c:\windows\system32\deployJava1.dll 2012-12-29 10:26 . 2013-01-05 23:10 8904632 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys 2012-12-29 10:26 . 2013-01-05 23:10 6263784 —-a-w- c:\windows\system32\nvopencl.dll 2012-12-29 10:26 . 2013-01-05 23:10 2720696 —-a-w- c:\windows\system32\nvcuvid.dll 2012-12-29 10:26 . 2013-01-05 23:10 20450232 —-a-w- c:\windows\system32\nvoglv32.dll 2012-12-29 10:26 . 2013-01-05 23:10 15129064 —-a-w- c:\windows\system32\nvd3dum.dll 2012-12-29 10:26 . 2013-01-05 23:10 7931896 —-a-w- c:\windows\system32\nvcuda.dll 2012-12-29 10:26 . 2013-01-05 23:10 1985976 —-a-w- c:\windows\system32\nvcuvenc.dll 2012-12-29 10:26 . 2013-01-05 23:10 17560504 —-a-w- c:\windows\system32\nvcompiler.dll 2012-12-29 10:26 . 2012-10-10 20:14 889784 —-a-w- c:\windows\system32\nvdispgenco32.dll 2012-12-29 10:26 . 2011-11-17 20:55 1017272 —-a-w- c:\windows\system32\nvdispco32.dll 2012-12-29 10:26 . 2010-07-10 04:37 2504248 —-a-w- c:\windows\system32\nvapi.dll 2012-12-29 10:26 . 2009-07-13 22:09 12641120 —-a-w- c:\windows\system32\nvwgf2um.dll 2012-12-29 08:26 . 2011-01-07 20:06 4129720 —-a-w- c:\windows\system32\nvcpl.dll 2012-12-29 08:26 . 2011-01-07 20:06 3001272 —-a-w- c:\windows\system32\nvsvc.dll 2012-12-29 08:25 . 2011-01-07 20:06 639928 —-a-w- c:\windows\system32\nvvsvc.exe 2012-12-29 08:25 . 2011-01-07 20:06 108984 —-a-w- c:\windows\system32\nvmctray.dll 2012-12-29 08:25 . 2010-07-09 15:37 62904 —-a-w- c:\windows\system32\nvshext.dll 2012-12-29 01:54 . 2012-12-29 01:54 550328 —-a-w- c:\windows\system32\nvStreaming.exe 2012-12-16 14:13 . 2012-12-21 02:00 295424 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 02:00 34304 —-a-w- c:\windows\system32\atmlib.dll 2013-03-08 14:08 . 2013-03-08 14:08 263064 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OscarEditor"="c:\program files\MOUSE Editor\MouseEditor.exe" [2010-12-23 3344384] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-02-24 10025576] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400] "CTxfiHlp"="CTXFIHLP.EXE" [2007-04-09 19968] "CTHelper"="CTHELPER.EXE" [2007-04-09 19456] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "EvtMgr6"="g:\programi\miš\SetPointP\SetPoint.exe" [2011-10-07 1387288] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-23 926896] "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-10-01 640376] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DevconDefaultDB"="c:\windows\system32\READREG" [X] . c:\users\Antrax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - g:\programi\Ofis\Office12\ONENOTEM.EXE [2011-1-28 97680] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2011-09-27 19:03 66328 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] SecurityProviders credssp.dll, snapapi32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent] 2012-05-26 13:23 399736 —-a-w- c:\program files\uTorrent\uTorrent.exe . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Steam"="c:\program files\Steam\Steam.exe" -silent "msnmsgr"=~"c:\program files\Windows Live\Messenger\msnmsgr.exe" /background "RGSC"=g:\igre\gta4\Rockstar Games Social Club\RGSCLauncher.exe /silent "Pando Media Booster"=c:\program files\Pando Networks\Media Booster\PMB.exe . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" ""= "PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE "LogMeIn Hamachi Ui"="g:\programi\Machi\hamachi-2-ui.exe" –auto-start . R1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x] R2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x] R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [x] R2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x] R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] R3 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;g:\programi\Machi\hamachi-2.exe [x] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 HiPatchService;Hi-Rez Studios Authenticate and Update Service;g:\igre\Hi-Rez Studios\HiPatchService.exe [x] S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [x] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [x] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc GPSvcGroup REG_MULTI_SZ GPSvc . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . . . ——- Supplementary Scan ——- . uStart Page = hxxp://searchab.com/?aff=7&uid=c2834b1f-71cc-11e2-9291-000129a604ab mStart Page = hxxp://www.google.com Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com TCP: Interfaces\{9CFE8537-4A71-4787-A171-8D0180B5C3E7}: NameServer = 192.168.1.1 FF - ProfilePath - c:\users\Antrax\AppData\Roaming\Mozilla\Firefox\Profiles\aq1gjsza.default-1350177323530\ FF - prefs.js: browser.startup.homepage - hxxps://www.google.hr/ FF - ExtSQL: 2013-02-08 10:18; [removed]; c:\users\Antrax\AppData\Roaming\Mozilla\Firefox\Profiles\aq1gjsza.default-1350177323530\extensions\[removed] FF - ExtSQL: 2013-02-16 22:18; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Antrax\AppData\Roaming\Mozilla\Firefox\Profiles\aq1gjsza.default-1350177323530\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF - ExtSQL: 2013-03-07 15:22; {e001c731-5e37-4538-a5cb-8168736a2360}; c:\users\Antrax\AppData\Roaming\Mozilla\Firefox\Profiles\aq1gjsza.default-1350177323530\extensions\{e001c731-5e37-4538-a5cb-8168736a2360} . . ——- File Associations ——- . .scr=AutoCADScriptFile . - - - - ORPHANS REMOVED - - - - . AddRemove-FIFA 99 - e:\igre\fifa99\DeIsL1.isu . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-2875100996-1120981469-1397374340-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-2875100996-1120981469-1397374340-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\S-1-5-21-2875100996-1120981469-1397374340-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] @Allowed: (Read) (RestrictedCode) "??"=hex:be,14,6f,98,c4,86,57,bf,f6,14,d1,69,e7,56,0a,ae,9c,10,bd,95,35,5c,05, 22,0e,1e,09,03,72,a0,5e,f8,c4,23,be,b1,ba,4c,f4,08,3d,42,0d,bb,61,e0,1f,92,\ "??"=hex:31,3e,27,2e,04,30,51,eb,56,de,9f,40,dd,f4,98,e6 . [HKEY_USERS\S-1-5-21-2875100996-1120981469-1397374340-1001\Software\SecuROM\License information*] "datasecu"=hex:7c,19,98,44,da,1e,f7,76,fa,7a,76,bc,d4,59,35,d9,65,07,4d,f9,e3, 02,70,19,1b,3b,36,dc,32,f3,8a,87,45,96,ad,c4,51,26,99,91,66,88,de,92,28,aa,\ "rkeysecu"=hex:29,fa,cd,71,58,99,a7,fc,b1,e4,02,73,f1,75,a3,da . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-03-08 17:39:45 ComboFix-quarantined-files.txt 2013-03-08 16:39 . Pre-Run: 9.257.013.248 bytes free Post-Run: 9.176.866.816 bytes free . - - End Of File - - 8016D1F3D1C411087CDA0DA9E73D0625
Please read the directions carefully so you don't end up deleting something that is good!!

If in doubt about an entry….please ask or choose Skip!!!!

Don't Delete anything unless instructed to!

If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
Skip and click on Continue

If a suspicious object is detected, the default action will be Skip, click on Continue

Please note that TDSSKiller can be run in safe mode if needed.

Here's a video that explains how to run it if needed:
How To Run TDSSKiller

Please download the latest version of TDSSKiller from here and save it to your Desktop.
  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.

    [external image: Posted Image]
  • Put a checkmark beside loaded modules.

    [external image: Posted Image]
  • A reboot will be needed to apply the changes. Do it.
  • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
  • Then click on Change parameters in TDSSKiller.
  • Check all boxes then click OK.

    [external image: Posted Image]
  • Click the Start Scan button.

    [external image: Posted Image]
  • The scan should take no longer than 2 minutes.
  • If a suspicious object is detected, the default action will be Skip, click on Continue.

    [external image: Posted Image]

    Any entries like this: \Device\Harddisk0\DR0 ( TDSS File System ) - please choose Skip.

    If in doubt about an entry….please ask or choose Skip
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.

    [external image: Posted Image]

    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
  • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here. There may be 3 logs > so post or attach all of them.
  • Sometimes these logs can be very large, in that case please attach it or zip it up and attach it.

Here's a summary of what to do if you would like to print it out:


If in doubt about an entry….please ask or choose Skip

Don't Delete anything unless instructed to!

If a suspicious object is detected, the default action will be Skip, click on Continue

If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
Skip and click on Continue

Any entries like this: \Device\Harddisk0\DR0 ( TDSS File System ) - please choose Skip.

If malicious objects are found, they will show in the Scan results and offer three (3) options.

Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.


MrC
When i go to normal mode it just stalls on the Welcome screen. I tried the startup recovery but it says that it can't fix anything. I guess that only option left is to reinstall windows, right? Safe mode is still working.
No we're not giving up yet……please do this:

  • Please download Farbar Recovery Scan Tool and save it to a flash drive.

    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

    Plug the flash drive into the infected PC.
  • If you are using Windows 8 consult How to use the Windows 8 System Recovery Environment Command Prompt to enter System Recovery Command prompt.

    If you are using Vista or Windows 7 enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    Note: In case you can not enter System Recovery Options by using F8 method, you can use Windows installation disc, or make a repair disc. Any Windows installation disc or a repair disc made on another computer can be used.
    To make a repair disk on Windows 7 consult: http://www.sevenforums.com/tutorials/2083-…isc-create.html


    To enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
  • On the System Recovery Options menu you will get the following options:Startup Repair
    System Restore
    Windows Complete PC Restore
    Windows Memory Diagnostic Tool
    Command Prompt


    Select Command Prompt

    Once in the Command Prompt:
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

MrC
Here is the log from Frst: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-03-2013 Ran by [removed] at 08-03-2013 21:17:10 Running from J:\ Windows 7 Professional (X86) OS Language: English(US) The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\…\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.) HKLM\…\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [10025576 2011-02-24] (Realtek Semiconductor) HKLM\…\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [2021400 2009-02-06] (ESET) HKLM\…\Run: [CTxfiHlp] CTXFIHLP.EXE [x] HKLM\…\Run: [CTHelper] CTHELPER.EXE [x] HKLM\…\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2010-11-29] (Apple Inc.) HKLM\…\Run: [EvtMgr6] G:\Programi\miš\SetPointP\SetPoint.exe /launchGaming [x] HKLM\…\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [926896 2012-09-23] (Adobe Systems Incorporated) HKLM\…\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [640376 2008-10-01] (Adobe Systems Inc.) HKU\Antrax\…\Run: [OscarEditor] "C:\Program Files\MOUSE Editor\MouseEditor.exe" Minimum [3344384 2010-12-23] () HKLM\…\Runonce: [B53A6FE9-9D53-4A07-B7C3-70343758C910] cmd.exe /C start /D "C:\Users\Antrax\AppData\Local\Temp" /B B53A6FE9-9D53-4A07-B7C3-70343758C910.exe -activeimages -postboot [x] HKLM\…\Runonce: [23A6BFED-8798-4432-AFDF-17DE6D64679E] cmd.exe /C start /D "C:\Users\Antrax\AppData\Local\Temp" /B 23A6BFED-8798-4432-AFDF-17DE6D64679E.exe -activeimages -postboot [x] Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [X] Tcpip\..\Interfaces\{9CFE8537-4A71-4787-A171-8D0180B5C3E7}: [NameServer]192.168.1.1 Startup: C:\Users\Antrax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> G:\Programi\Ofis\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Services (Whitelisted) =================== 3 COMMONFX.DLL; C:\Windows\System32\COMMONFX.DLL [98600 2007-04-17] (Creative Technology Ltd) 3 CT20XUT.DLL; C:\Windows\System32\CT20XUT.DLL [164608 2007-04-11] (Creative Technology Ltd.) 3 CTAUDFX.DLL; C:\Windows\System32\CTAUDFX.DLL [546048 2007-04-11] (Creative Technology Ltd) 3 CTEAPSFX.DLL; C:\Windows\System32\CTEAPSFX.DLL [168192 2007-04-11] (Creative Technology Ltd) 3 CTEDSPFX.DLL; C:\Windows\System32\CTEDSPFX.DLL [280320 2007-04-11] (Creative Technology Ltd) 3 CTEDSPIO.DLL; C:\Windows\System32\CTEDSPIO.DLL [128768 2007-04-11] (Creative Technology Ltd) 3 CTEDSPSY.DLL; C:\Windows\System32\CTEDSPSY.DLL [323328 2007-04-11] (Creative Technology Ltd) 3 CTERFXFX.DLL; C:\Windows\System32\CTERFXFX.DLL [94976 2007-04-11] (Creative Technology Ltd) 3 CTEXFIFX.DLL; C:\Windows\System32\CTEXFIFX.DLL [1317632 2007-04-11] (Creative Technology Ltd.) 3 CTHWIUT.DLL; C:\Windows\System32\CTHWIUT.DLL [66816 2007-04-11] (Creative Technology Ltd.) 3 CTSBLFX.DLL; C:\Windows\System32\CTSBLFX.DLL [560384 2007-04-11] (Creative Technology Ltd) 3 EhttpSrv; "C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe" [20680 2009-02-06] (ESET) 2 ekrn; "C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe" [727720 2009-02-06] (ESET) 2 MBAMScheduler; "C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe" [398184 2012-12-14] (Malwarebytes Corporation) 2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [682344 2012-12-14] (Malwarebytes Corporation) 3 npggsvc; C:\Windows\system32\GameMon.des -service [4622336 2012-07-25] (INCA Internet Co., Ltd.) 3 TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [745368 2012-11-26] (Tunngle.net GmbH) 3 Hamachi2Svc; C:\Programi\Machi\hamachi-2.exe -s [x] 4 HiPatchService; C:\Igre\Hi-Rez Studios\HiPatchService.exe [x] ==================== Drivers (Whitelisted) ==================== 2 acedrv11; \??\C:\Windows\system32\drivers\acedrv11.sys [185472 2010-02-24] (Protect Software GmbH) 2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2012-08-31] () 3 ctdvda2k; C:\Windows\System32\drivers\ctdvda2k.sys [347128 2007-04-09] (Creative Technology Ltd) 2 eamon; C:\Windows\System32\DRIVERS\eamon.sys [113448 2009-02-06] (ESET) 1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [106208 2009-02-06] (ESET) 2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [92800 2009-02-06] (ESET) 3 ha10kx2k; C:\Windows\System32\drivers\ha10kx2k.sys [797992 2007-04-09] (Creative Technology Ltd) 3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) 3 hap16v2k; C:\Windows\System32\drivers\hap16v2k.sys [163112 2007-04-09] (Creative Technology Ltd) 3 hap17v2k; C:\Windows\System32\drivers\hap17v2k.sys [189736 2007-04-09] (Creative Technology Ltd) 2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2012-08-31] () 3 LMouFilt; C:\Windows\System32\DRIVERS\LMouFilt.Sys [39192 2011-09-01] (Logitech, Inc.) 3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [30360 2011-09-01] (Logitech, Inc.) 3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [21104 2012-12-14] (Malwarebytes Corporation) 3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [27136 2009-09-15] (Tunngle.net) 3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] () 3 catchme; \??\C:\Users\Antrax\AppData\Local\Temp\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-03-08 11:21 - 2013-03-08 11:39 - 00000112 ____A C:\Windows\setupact.log 2013-03-08 11:21 - 2013-03-08 11:21 - 00000000 ____A C:\Windows\setuperr.log 2013-03-08 10:02 - 2013-03-08 10:02 - 00045964 ____A C:\TDSSKiller.2.8.16.0_08.03.2013_18.48.49_log.rar 2013-03-08 09:10 - 2013-03-08 09:08 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\Antrax\Desktop\tdsskiller.exe 2013-03-08 08:39 - 2013-03-08 08:39 - 00012993 ____A C:\ComboFix.txt 2013-03-08 08:31 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe 2013-03-08 08:31 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe 2013-03-08 08:31 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-03-08 08:31 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-03-08 08:31 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-03-08 08:31 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe 2013-03-08 08:31 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe 2013-03-08 08:31 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe 2013-03-08 08:26 - 2013-03-08 08:39 - 00000000 ___AD C:\Qoobox 2013-03-08 08:26 - 2013-03-08 08:38 - 00000000 ____D C:\Windows\erdnt 2013-03-08 08:22 - 2013-03-08 08:20 - 05037067 ____R (Swearware) C:\Users\Antrax\Desktop\ComboFix.exe 2013-03-08 07:20 - 2013-03-08 07:20 - 00003393 ____A C:\Users\Antrax\Desktop\RKreport[11]_S_03082013_02d1620.txt 2013-03-08 07:16 - 2013-03-08 07:16 - 00003233 ____A C:\Users\Antrax\Desktop\RKreport[10]_S_03082013_02d1616.txt 2013-03-08 07:13 - 2013-03-08 07:13 - 00000000 ____D C:\Users\Antrax\AppData\Local\{587535FC-2ED7-4C46-B552-4DDC220BD739} 2013-03-08 07:02 - 2013-03-08 07:14 - 00034045 ____A C:\Users\Antrax\Desktop\attach.txt 2013-03-08 07:02 - 2013-03-08 07:14 - 00017686 ____A C:\Users\Antrax\Desktop\dds.txt 2013-03-08 06:59 - 2013-03-08 06:54 - 00688992 ____R (Swearware) C:\Users\Antrax\Desktop\dds.com 2013-03-08 06:36 - 2013-03-08 06:36 - 00003471 ____A C:\Users\Antrax\Desktop\RKreport[8]_S_03082013_02d1536.txt 2013-03-08 06:36 - 2013-03-08 06:36 - 00001979 ____A C:\Users\Antrax\Desktop\RKreport[9]_H_03082013_02d1536.txt 2013-03-08 06:21 - 2013-03-08 06:21 - 00008543 ____A C:\Users\Antrax\Documents\Uninstall Mass Effect.log 2013-03-08 06:08 - 2013-03-08 06:30 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-03-08 06:04 - 2013-03-08 06:04 - 00000969 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-03-08 06:04 - 2013-03-08 06:04 - 00000000 ____D C:\Program Files\CCleaner 2013-03-08 05:41 - 2013-03-07 20:03 - 00001016 ____A C:\Windows\System32\Drivers\etc\hosts.20130308-144136.backup 2013-03-07 20:03 - 2013-03-07 20:03 - 00001905 ____A C:\Users\Antrax\Desktop\RKreport[7]_H_03082013_02d0503.txt 2013-03-07 20:01 - 2013-03-07 20:01 - 00003397 ____A C:\Users\Antrax\Desktop\RKreport[6]_S_03082013_02d0501.txt 2013-03-07 19:22 - 2013-03-07 11:09 - 00001016 ____A C:\Windows\System32\Drivers\etc\hosts.20130308-042221.backup 2013-03-07 18:46 - 2013-03-07 18:46 - 00625664 ____A C:\Users\Antrax\Desktop\dds.scr 2013-03-07 18:13 - 2013-03-07 18:13 - 00001441 ____A C:\scu.dat 2013-03-07 12:00 - 2013-03-07 12:00 - 00002858 ____A C:\Users\Antrax\Desktop\RKreport[5]_S_03072013_02d2100.txt 2013-03-07 11:22 - 2013-03-07 11:22 - 00000000 __SHD C:\Users\Antrax\%APPDATA% 2013-03-07 11:12 - 2013-03-07 11:12 - 00003059 ____A C:\Users\Antrax\Desktop\RKreport[4]_D_03072013_02d2012.txt 2013-03-07 11:10 - 2013-03-07 11:10 - 00002990 ____A C:\Users\Antrax\Desktop\RKreport[3]_S_03072013_02d2010.txt 2013-03-07 11:09 - 2013-03-07 11:09 - 00001718 ____A C:\Users\Antrax\Desktop\RKreport[2]_H_03072013_02d2009.txt 2013-03-07 11:08 - 2013-03-07 11:08 - 00003416 ____A C:\Users\Antrax\Desktop\RKreport[1]_S_03072013_02d2008.txt 2013-03-07 11:07 - 2013-03-08 07:20 - 00000000 ____D C:\Users\Antrax\Desktop\RK_Quarantine 2013-03-07 11:05 - 2013-03-07 11:02 - 00816640 ____A C:\Users\Antrax\Desktop\RogueKiller.exe 2013-03-07 10:20 - 2013-03-07 10:20 - 00000033 ____A C:\Users\Antrax\AppData\Roaming\mbam.context.scan 2013-03-07 08:43 - 2013-03-07 11:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-03-07 08:43 - 2013-03-07 08:43 - 00001089 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2013-03-07 08:43 - 2013-03-07 08:43 - 00000000 ____D C:\Users\Antrax\AppData\Roaming\Malwarebytes 2013-03-07 08:43 - 2013-03-07 08:43 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-03-07 08:43 - 2012-12-14 07:49 - 00021104 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2013-03-07 07:57 - 2013-03-07 12:01 - 00000000 ____D C:\Windows\pss 2013-03-07 07:40 - 2013-03-07 07:40 - 00002243 ____A C:\Windows\epplauncher.mif 2013-03-07 07:33 - 2013-03-07 07:33 - 00000000 ____D C:\Program Files\Microsoft Windows OneCare Live 2013-03-07 06:40 - 2013-03-07 06:38 - 01752992 ____A (Bleeping Computer, LLC) C:\Users\Antrax\Desktop\rkill.com 2013-03-07 06:38 - 2013-03-08 06:42 - 00002816 ____A C:\Users\Antrax\Desktop\Rkill.txt 2013-03-07 06:25 - 2013-03-07 06:25 - 00000000 ____D C:\Program Files\Common Files\Bitdefender 2013-03-07 06:22 - 2013-03-08 06:00 - 00000000 ____D C:\Users\Antrax\AppData\Roaming\QuickScan 2013-03-06 03:47 - 2013-03-06 15:48 - 00000000 ____D C:\Users\Antrax\AppData\Local\{091405CF-C0CB-4024-9BE3-A49927A13F91} 2013-03-05 12:52 - 2013-03-05 12:52 - 00000000 ____D C:\Users\Antrax\AppData\Local\{B9D59054-BAC4-49E2-B21A-EE126A275166} 2013-03-05 00:51 - 2013-03-05 00:51 - 00000000 ____D C:\Users\Antrax\AppData\Local\{E646CED3-BB94-425F-9322-BCA3CA6216F5} 2013-03-04 08:54 - 2013-03-04 08:55 - 00000000 ____D C:\Users\Antrax\AppData\Local\{9CFF82BC-A875-4054-A558-BAC696137172} 2013-03-03 12:09 - 2013-03-03 12:11 - 00290816 ____N (Microsoft Corporation) C:\Windows\Setup1.exe 2013-03-03 12:09 - 2013-03-03 12:11 - 00074752 ____A (Microsoft Corporation) C:\Windows\ST6UNST.EXE 2013-03-03 12:03 - 2013-03-03 12:04 - 00000000 ____D C:\Users\Antrax\AppData\Local\{12742D8B-2F31-4420-A72E-45C5A8A8F4C3} 2013-03-01 12:19 - 2013-03-01 12:20 - 00000000 ____D C:\Users\Antrax\AppData\Local\{C64E3F95-A3C9-4E70-9D98-AE4334E7E27E} 2013-02-28 13:13 - 2013-02-28 13:13 - 00000000 ____D C:\Users\Antrax\AppData\Local\{D2BF84CE-BA4C-488E-BDF8-7281AB30D64D} 2013-02-28 01:12 - 2013-02-28 01:12 - 00000000 ____D C:\Users\Antrax\AppData\Local\{58C4799A-28C9-4A4A-ADD0-8D8DCEBF4359} 2013-02-27 15:21 - 2013-01-13 13:17 - 00009728 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-02-27 15:21 - 2013-01-13 13:17 - 00002560 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-02-27 15:21 - 2013-01-13 13:16 - 00010752 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-02-27 15:21 - 2013-01-13 13:12 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-02-27 15:21 - 2013-01-13 13:11 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-02-27 15:21 - 2013-01-13 13:11 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-02-27 15:21 - 2013-01-13 13:11 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-02-27 15:21 - 2013-01-13 13:11 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll 2013-02-27 15:21 - 2013-01-13 13:11 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-02-27 15:21 - 2013-01-13 12:31 - 01247744 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2013-02-27 15:21 - 2013-01-13 12:30 - 00906240 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll 2013-02-27 15:21 - 2013-01-13 12:22 - 01988096 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2013-02-27 15:21 - 2013-01-13 12:20 - 00293376 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll 2013-02-27 15:21 - 2013-01-13 12:09 - 00249856 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll 2013-02-27 15:21 - 2013-01-13 12:08 - 01504768 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-02-27 15:21 - 2013-01-13 12:08 - 00220160 ____A (Microsoft Corporation) C:\Windows\System32\d3d10core.dll 2013-02-27 15:21 - 2013-01-13 11:54 - 00604160 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2013-02-27 15:21 - 2013-01-13 11:53 - 00207872 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecsExt.dll 2013-02-27 15:21 - 2013-01-13 11:53 - 00187392 ____A (Microsoft Corporation) C:\Windows\System32\UIAnimation.dll 2013-02-27 15:21 - 2013-01-13 11:48 - 00161792 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll 2013-02-27 15:21 - 2013-01-13 11:46 - 01080832 ____A (Microsoft Corporation) C:\Windows\System32\d3d10.dll 2013-02-27 15:21 - 2013-01-13 11:43 - 01230336 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-02-27 15:21 - 2013-01-13 11:37 - 03419136 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll 2013-02-27 15:21 - 2013-01-13 11:02 - 00417792 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll 2013-02-27 15:21 - 2013-01-13 10:34 - 00364544 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll 2013-02-27 15:21 - 2013-01-13 09:26 - 01158144 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll 2013-02-27 15:21 - 2013-01-03 22:11 - 02284544 ____A (Microsoft Corporation) C:\Windows\System32\msmpeg2vdec.dll 2013-02-22 03:33 - 2013-02-22 03:33 - 00000000 ____D C:\Users\Antrax\AppData\Local\{70600CB0-643B-4547-9AE2-859CF2D2BBAB} 2013-02-20 13:00 - 2013-02-20 13:00 - 00000000 ____D C:\Users\Antrax\AppData\Local\Rockstar Games 2013-02-19 08:01 - 2013-02-19 08:01 - 00000000 ____D C:\Users\Antrax\AppData\Local\{15045796-BB3A-4FFD-AFCD-27DA9EE3C0F7} 2013-02-18 06:50 - 2013-02-18 06:50 - 00000000 ____D C:\Users\Antrax\AppData\Local\{B23E43D2-9628-48B3-9D8C-0F24A57F414D} 2013-02-17 17:43 - 2013-02-17 17:44 - 00000000 ____D C:\Users\Antrax\AppData\Local\{83F8CB65-BB12-4447-B382-76D8DBBB9A44} 2013-02-17 07:00 - 2013-02-17 07:00 - 00743349 ____A C:\Users\Antrax\Desktop\PoDgOrA letak.pptx 2013-02-17 05:43 - 2013-02-17 05:43 - 00000000 ____D C:\Users\Antrax\AppData\Local\{9A9DE06F-A173-460F-9E61-A321B5A29A55} 2013-02-16 20:01 - 2013-03-06 16:15 - 00000360 ____A C:\Users\Antrax\Desktop\pantera.txt 2013-02-16 10:39 - 2013-02-16 10:40 - 00000000 ____D C:\Users\Antrax\Documents\SpellForce2 2013-02-16 09:58 - 2013-02-16 09:58 - 00000825 ____A C:\Users\Public\Desktop\SpellForce 2 Faith in Destiny.lnk 2013-02-16 05:42 - 2013-02-16 17:43 - 00000000 ____D C:\Users\Antrax\AppData\Local\{211F0F07-FDBD-4EA5-87BA-195DB7C2E639} 2013-02-15 17:41 - 2013-02-15 17:42 - 00000000 ____D C:\Users\Antrax\AppData\Local\{B5546443-E3C3-4EF2-81E2-00FCE9CEB0A3} 2013-02-15 05:41 - 2013-02-15 05:41 - 00000000 ____D C:\Users\Antrax\AppData\Local\{190854AB-3F53-4662-A158-F4D6767AACD3} 2013-02-14 05:40 - 2013-02-14 17:41 - 00000000 ____D C:\Users\Antrax\AppData\Local\{CC376FB8-D5EF-44FF-AA36-498EC6328557} 2013-02-13 18:06 - 2013-01-08 14:23 - 12321280 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-02-13 18:06 - 2013-01-08 14:11 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-02-13 18:06 - 2013-01-08 14:09 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-02-13 18:06 - 2013-01-08 14:03 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-02-13 18:06 - 2013-01-08 14:03 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-02-13 18:06 - 2013-01-08 14:03 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-02-13 18:06 - 2013-01-08 14:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-02-13 18:06 - 2013-01-08 14:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-02-13 18:06 - 2013-01-08 13:59 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-02-13 18:06 - 2013-01-08 13:58 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-02-13 18:06 - 2013-01-08 13:58 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-02-13 18:06 - 2013-01-08 13:57 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-02-13 18:06 - 2013-01-08 13:56 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-02-13 18:06 - 2013-01-08 13:56 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-02-13 18:06 - 2013-01-08 13:56 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-02-13 18:06 - 2013-01-08 13:53 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-02-13 17:35 - 2013-01-03 19:00 - 02347008 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-02-13 17:34 - 2013-01-04 21:00 - 03967848 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe 2013-02-13 17:34 - 2013-01-04 21:00 - 03913064 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-02-13 17:34 - 2013-01-03 20:50 - 00169984 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll 2013-02-13 17:34 - 2013-01-02 21:05 - 01293672 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-02-13 17:34 - 2013-01-02 21:04 - 00187752 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS 2013-02-13 04:34 - 2013-02-13 16:35 - 00000000 ____D C:\Users\Antrax\AppData\Local\{1942E724-F62B-4277-9F97-6B60360417FC} 2013-02-12 07:14 - 2013-02-12 07:15 - 00000000 ____D C:\Users\Antrax\AppData\Local\{363F4E4E-A3D0-4A97-8851-20BFD5576422} 2013-02-11 05:23 - 2013-02-11 17:24 - 00000000 ____D C:\Users\Antrax\AppData\Local\{45441A74-A5CB-43C1-826D-FB94484EF802} 2013-02-10 07:50 - 2013-02-10 07:50 - 00000000 ____D C:\Users\Antrax\AppData\Local\{DD5D2BA0-4544-481C-A10D-FB48C399F67A} 2013-02-09 10:31 - 2013-02-09 10:31 - 00000000 ____D C:\Users\Antrax\AppData\Local\{6977BE1E-6D99-42CD-97E4-8451EA93E581} 2013-02-08 07:37 - 2013-02-08 07:37 - 00000000 ____D C:\Users\Antrax\AppData\Local\{AD8034B0-25C5-411F-BE8A-DA69742F3FDE} 2013-02-08 00:52 - 2013-02-08 00:52 - 00000000 ____D C:\Users\Antrax\AppData\Local\Google 2013-02-08 00:52 - 2013-02-08 00:52 - 00000000 ____D C:\ProgramData\CLSoft LTD 2013-02-08 00:52 - 2013-02-08 00:52 - 00000000 ____D C:\Program Files\MagniPic 2013-02-07 01:40 - 2013-02-07 13:40 - 00000000 ____D C:\Users\Antrax\AppData\Local\{3338CA44-89CA-43A2-8C13-85BC39097FB8} 2013-02-06 11:31 - 2013-02-06 11:32 - 00000000 ____D C:\Users\Antrax\AppData\Local\{C670A20C-4FE4-4D96-A241-2353D53A0730} ==================== One Month Modified Files and Folders ======== 2013-03-08 21:17 - 2013-03-08 21:17 - 00000000 ____D C:\FRST 2013-03-08 12:11 - 2011-01-28 06:17 - 00792914 ____A C:\Windows\System32\PerfStringBackup.INI 2013-03-08 11:39 - 2013-03-08 11:21 - 00000112 ____A C:\Windows\setupact.log 2013-03-08 11:39 - 2011-01-28 08:48 - 00000000 ____D C:\ProgramData\NVIDIA 2013-03-08 11:39 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-03-08 11:21 - 2013-03-08 11:21 - 00000000 ____A C:\Windows\setuperr.log 2013-03-08 10:02 - 2013-03-08 10:02 - 00045964 ____A C:\TDSSKiller.2.8.16.0_08.03.2013_18.48.49_log.rar 2013-03-08 09:08 - 2013-03-08 09:10 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\Antrax\Desktop\tdsskiller.exe 2013-03-08 08:39 - 2013-03-08 08:39 - 00012993 ____A C:\ComboFix.txt 2013-03-08 08:39 - 2013-03-08 08:26 - 00000000 ___AD C:\Qoobox 2013-03-08 08:39 - 2009-07-13 18:37 - 00000000 ___RD C:\users\Public 2013-03-08 08:38 - 2013-03-08 08:26 - 00000000 ____D C:\Windows\erdnt 2013-03-08 08:38 - 2009-07-13 18:04 - 00000215 ____A C:\Windows\system.ini 2013-03-08 08:20 - 2013-03-08 08:22 - 05037067 ____R (Swearware) C:\Users\Antrax\Desktop\ComboFix.exe 2013-03-08 07:44 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\LogFiles 2013-03-08 07:20 - 2013-03-08 07:20 - 00003393 ____A C:\Users\Antrax\Desktop\RKreport[11]_S_03082013_02d1620.txt 2013-03-08 07:20 - 2013-03-07 11:07 - 00000000 ____D C:\Users\Antrax\Desktop\RK_Quarantine 2013-03-08 07:16 - 2013-03-08 07:16 - 00003233 ____A C:\Users\Antrax\Desktop\RKreport[10]_S_03082013_02d1616.txt 2013-03-08 07:14 - 2013-03-08 07:02 - 00034045 ____A C:\Users\Antrax\Desktop\attach.txt 2013-03-08 07:14 - 2013-03-08 07:02 - 00017686 ____A C:\Users\Antrax\Desktop\dds.txt 2013-03-08 07:13 - 2013-03-08 07:13 - 00000000 ____D C:\Users\Antrax\AppData\Local\{587535FC-2ED7-4C46-B552-4DDC220BD739} 2013-03-08 06:54 - 2013-03-08 06:59 - 00688992 ____R (Swearware) C:\Users\Antrax\Desktop\dds.com 2013-03-08 06:43 - 2012-04-24 14:57 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-03-08 06:42 - 2013-03-07 06:38 - 00002816 ____A C:\Users\Antrax\Desktop\Rkill.txt 2013-03-08 06:38 - 2011-01-28 11:14 - 00000000 ____D C:\Users\Antrax\Documents\Ace Utilities Backups 2013-03-08 06:36 - 2013-03-08 06:36 - 00003471 ____A C:\Users\Antrax\Desktop\RKreport[8]_S_03082013_02d1536.txt 2013-03-08 06:36 - 2013-03-08 06:36 - 00001979 ____A C:\Users\Antrax\Desktop\RKreport[9]_H_03082013_02d1536.txt 2013-03-08 06:31 - 2011-09-20 13:40 - 00000000 ____D C:\Users\Antrax\AppData\Local\Unity 2013-03-08 06:30 - 2013-03-08 06:08 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-03-08 06:29 - 2012-10-06 14:43 - 00000000 ____D C:\Users\Public\Documents\The Witcher 2013-03-08 06:29 - 2011-03-12 14:25 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-03-08 06:26 - 2011-03-08 06:48 - 00000000 ____D C:\Program Files\Electronic Arts 2013-03-08 06:22 - 2011-12-02 09:25 - 00000000 ____D C:\Users\Antrax\Documents\Might & Magic Heroes VI 2013-03-08 06:21 - 2013-03-08 06:21 - 00008543 ____A C:\Users\Antrax\Documents\Uninstall Mass Effect.log 2013-03-08 06:21 - 2011-03-04 09:52 - 00000000 ____D C:\Program Files\Common Files\BioWare 2013-03-08 06:19 - 2011-03-12 15:49 - 00000000 ____D C:\Program Files\DVDVideoSoft 2013-03-08 06:19 - 2011-03-12 15:49 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-03-08 06:16 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\DriverStore 2013-03-08 06:13 - 2012-06-24 05:32 - 00000000 ____D C:\Users\Antrax\AppData\Roaming\Ubisoft 2013-03-08 06:11 - 2011-07-22 00:18 - 00000000 ____D C:\Windows\Minidump 2013-03-08 06:11 - 2011-01-29 10:20 - 00000000 ____D C:\Program Files\Steam 2013-03-08 06:11 - 2011-01-28 15:05 - 00000000 ____D C:\Windows\Panther 2013-03-08 06:11 - 2011-01-28 09:26 - 00000000 ____D C:\Users\Antrax\Tracing 2013-03-08 06:11 - 2011-01-28 09:26 - 00000000 ____D C:\Users\Antrax\AppData\Roaming\DAEMON Tools Lite 2013-03-08 06:11 - 2011-01-28 07:23 - 00000000 ____D C:\Users\Antrax\AppData\Roaming\Skype 2013-03-08 06:11 - 2011-01-28 07:13 - 00000000 ____D C:\Users\Antrax\AppData\Local\LogMeIn Hamachi 2013-03-08 06:04 - 2013-03-08 06:04 - 00000969 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-03-08 06:04 - 2013-03-08 06:04 - 00000000 ____D C:\Program Files\CCleaner 2013-03-08 06:00 - 2013-03-07 06:22 - 00000000 ____D C:\Users\Antrax\AppData\Roaming\QuickScan 2013-03-08 04:29 - 2009-07-13 20:34 - 00014976 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-03-08 04:29 - 2009-07-13 20:34 - 00014976 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-03-07 22:35 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\Cursors 2013-03-07 20:03 - 2013-03-08 05:41 - 00001016 ____A C:\Windows\System32\Drivers\etc\hosts.20130308-144136.backup 2013-03-07 20:03 - 2013-03-07 20:03 - 00001905 ____A C:\Users\Antrax\Desktop\RKreport[7]_H_03082013_02d0503.txt 2013-03-07 20:01 - 2013-03-07 20:01 - 00003397 ____A C:\Users\Antrax\Desktop\RKreport[6]_S_03082013_02d0501.txt 2013-03-07 19:59 - 2011-01-28 08:11 - 00000000 ____D C:\Users\Antrax\AppData\Roaming\uTorrent 2013-03-07 19:18 - 2011-01-28 10:58 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2013-03-07 18:46 - 2013-03-07 18:46 - 00625664 ____A C:\Users\Antrax\Desktop\dds.scr 2013-03-07 18:13 - 2013-03-07 18:13 - 00001441 ____A C:\scu.dat 2013-03-07 12:01 - 2013-03-07 07:57 - 00000000 ____D C:\Windows\pss 2013-03-07 12:00 - 2013-03-07 12:00 - 00002858 ____A C:\Users\Antrax\Desktop\RKreport[5]_S_03072013_02d2100.txt 2013-03-07 11:26 - 2013-03-07 08:43 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-03-07 11:22 - 2013-03-07 11:22 - 00000000 __SHD C:\Users\Antrax\%APPDATA% 2013-03-07 11:22 - 2011-01-28 06:13 - 00000000 ____D C:\users\Antrax 2013-03-07 11:12 - 2013-03-07 11:12 - 00003059 ____A C:\Users\Antrax\Desktop\RKreport[4]_D_03072013_02d2012.txt 2013-03-07 11:10 - 2013-03-07 11:10 - 00002990 ____A C:\Users\Antrax\Desktop\RKreport[3]_S_03072013_02d2010.txt 2013-03-07 11:09 - 2013-03-07 19:22 - 00001016 ____A C:\Windows\System32\Drivers\etc\hosts.20130308-042221.backup 2013-03-07 11:09 - 2013-03-07 11:09 - 00001718 ____A C:\Users\Antrax\Desktop\RKreport[2]_H_03072013_02d2009.txt 2013-03-07 11:08 - 2013-03-07 11:08 - 00003416 ____A C:\Users\Antrax\Desktop\RKreport[1]_S_03072013_02d2008.txt 2013-03-07 11:02 - 2013-03-07 11:05 - 00816640 ____A C:\Users\Antrax\Desktop\RogueKiller.exe 2013-03-07 10:20 - 2013-03-07 10:20 - 00000033 ____A C:\Users\Antrax\AppData\Roaming\mbam.context.scan 2013-03-07 10:13 - 2009-07-13 20:53 - 00032648 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-03-07 08:43 - 2013-03-07 08:43 - 00001089 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2013-03-07 08:43 - 2013-03-07 08:43 - 00000000 ____D C:\Users\Antrax\AppData\Roaming\Malwarebytes 2013-03-07 08:43 - 2013-03-07 08:43 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-03-07 08:14 - 2011-11-29 12:28 - 00000000 ____D C:\Program Files\SpywareBlaster 2013-03-07 07:40 - 2013-03-07 07:40 - 00002243 ____A C:\Windows\epplauncher.mif 2013-03-07 07:33 - 2013-03-07 07:33 - 00000000 ____D C:\Program Files\Microsoft Windows OneCare Live 2013-03-07 06:43 - 2011-02-06 14:00 - 00007654 ____A C:\Users\Antrax\AppData\Local\Resmon.ResmonCfg 2013-03-07 06:38 - 2013-03-07 06:40 - 01752992 ____A (Bleeping Computer, LLC) C:\Users\Antrax\Desktop\rkill.com 2013-03-07 06:25 - 2013-03-07 06:25 - 00000000 ____D C:\Program Files\Common Files\Bitdefender 2013-03-07 04:07 - 2012-11-21 08:23 - 00000000 ____D C:\Users\Antrax\AppData\Local\PMB Files 2013-03-06 16:15 - 2013-02-16 20:01 - 00000360 ____A C:\Users\Antrax\Desktop\pantera.txt 2013-03-06 15:48 - 2013-03-06 03:47 - 00000000 ____D C:\Users\Antrax\AppData\Local\{091405CF-C0CB-4024-9BE3-A49927A13F91} 2013-03-05 12:52 - 2013-03-05 12:52 - 00000000 ____D C:\Users\Antrax\AppData\Local\{B9D59054-BAC4-49E2-B21A-EE126A275166} 2013-03-05 00:51 - 2013-03-05 00:51 - 00000000 ____D C:\Users\Antrax\AppData\Local\{E646CED3-BB94-425F-9322-BCA3CA6216F5} 2013-03-04 09:07 - 2013-01-20 15:22 - 00000000 ____D C:\Users\Antrax\Desktop\server 2013-03-04 08:57 - 2011-02-02 09:14 - 00000000 ____D C:\Users\Antrax\AppData\Roaming\.minecraft 2013-03-04 08:55 - 2013-03-04 08:54 - 00000000 ____D C:\Users\Antrax\AppData\Local\{9CFF82BC-A875-4054-A558-BAC696137172} 2013-03-03 12:11 - 2013-03-03 12:09 - 00290816 ____N (Microsoft Corporation) C:\Windows\Setup1.exe 2013-03-03 12:11 - 2013-03-03 12:09 - 00074752 ____A (Microsoft Corporation) C:\Windows\ST6UNST.EXE 2013-03-03 12:04 - 2013-03-03 12:03 - 00000000 ____D C:\Users\Antrax\AppData\Local\{12742D8B-2F31-4420-A72E-45C5A8A8F4C3} 2013-03-01 12:20 - 2013-03-01 12:19 - 00000000 ____D C:\Users\Antrax\AppData\Local\{C64E3F95-A3C9-4E70-9D98-AE4334E7E27E} 2013-02-28 13:13 - 2013-02-28 13:13 - 00000000 ____D C:\Users\Antrax\AppData\Local\{D2BF84CE-BA4C-488E-BDF8-7281AB30D64D} 2013-02-28 03:56 - 2012-11-16 04:43 - 00000000 ____D C:\Windows\rescache 2013-02-28 01:12 - 2013-02-28 01:12 - 00000000 ____D C:\Users\Antrax\AppData\Local\{58C4799A-28C9-4A4A-ADD0-8D8DCEBF4359} 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\zh-TW 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\zh-HK 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\zh-CN 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\tr-TR 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\sv-SE 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\ru-RU 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\pt-PT 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\pt-BR 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\pl-PL 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\nl-NL 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\nb-NO 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\ko-KR 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\ja-JP 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\it-IT 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\hu-HU 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\fr-FR 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\fi-FI 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\el-GR 2013-02-28 00:57 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\de-DE 2013-02-22 03:33 - 2013-02-22 03:33 - 00000000 ____D C:\Users\Antrax\AppData\Local\{70600CB0-643B-4547-9AE2-859CF2D2BBAB} 2013-02-20 13:00 - 2013-02-20 13:00 - 00000000 ____D C:\Users\Antrax\AppData\Local\Rockstar Games 2013-02-19 08:01 - 2013-02-19 08:01 - 00000000 ____D C:\Users\Antrax\AppData\Local\{15045796-BB3A-4FFD-AFCD-27DA9EE3C0F7} 2013-02-18 06:50 - 2013-02-18 06:50 - 00000000 ____D C:\Users\Antrax\AppData\Local\{B23E43D2-9628-48B3-9D8C-0F24A57F414D} 2013-02-17 17:44 - 2013-02-17 17:43 - 00000000 ____D C:\Users\Antrax\AppData\Local\{83F8CB65-BB12-4447-B382-76D8DBBB9A44} 2013-02-17 07:00 - 2013-02-17 07:00 - 00743349 ____A C:\Users\Antrax\Desktop\PoDgOrA letak.pptx 2013-02-17 05:43 - 2013-02-17 05:43 - 00000000 ____D C:\Users\Antrax\AppData\Local\{9A9DE06F-A173-460F-9E61-A321B5A29A55} 2013-02-16 17:43 - 2013-02-16 05:42 - 00000000 ____D C:\Users\Antrax\AppData\Local\{211F0F07-FDBD-4EA5-87BA-195DB7C2E639} 2013-02-16 10:40 - 2013-02-16 10:39 - 00000000 ____D C:\Users\Antrax\Documents\SpellForce2 2013-02-16 09:58 - 2013-02-16 09:58 - 00000825 ____A C:\Users\Public\Desktop\SpellForce 2 Faith in Destiny.lnk 2013-02-16 09:55 - 2012-05-26 09:03 - 00000000 ____D C:\Users\Antrax\Desktop\glupo 2013-02-15 17:42 - 2013-02-15 17:41 - 00000000 ____D C:\Users\Antrax\AppData\Local\{B5546443-E3C3-4EF2-81E2-00FCE9CEB0A3} 2013-02-15 05:41 - 2013-02-15 05:41 - 00000000 ____D C:\Users\Antrax\AppData\Local\{190854AB-3F53-4662-A158-F4D6767AACD3} 2013-02-14 17:41 - 2013-02-14 05:40 - 00000000 ____D C:\Users\Antrax\AppData\Local\{CC376FB8-D5EF-44FF-AA36-498EC6328557} 2013-02-14 02:06 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-02-14 01:52 - 2009-07-13 20:33 - 00426752 ____A C:\Windows\System32\FNTCACHE.DAT 2013-02-13 18:08 - 2011-01-28 07:02 - 67823584 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-02-13 18:07 - 2011-01-28 09:37 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-02-13 16:35 - 2013-02-13 04:34 - 00000000 ____D C:\Users\Antrax\AppData\Local\{1942E724-F62B-4277-9F97-6B60360417FC} 2013-02-12 07:15 - 2013-02-12 07:14 - 00000000 ____D C:\Users\Antrax\AppData\Local\{363F4E4E-A3D0-4A97-8851-20BFD5576422} 2013-02-11 17:24 - 2013-02-11 05:23 - 00000000 ____D C:\Users\Antrax\AppData\Local\{45441A74-A5CB-43C1-826D-FB94484EF802} 2013-02-10 07:50 - 2013-02-10 07:50 - 00000000 ____D C:\Users\Antrax\AppData\Local\{DD5D2BA0-4544-481C-A10D-FB48C399F67A} 2013-02-09 10:31 - 2013-02-09 10:31 - 00000000 ____D C:\Users\Antrax\AppData\Local\{6977BE1E-6D99-42CD-97E4-8451EA93E581} 2013-02-08 08:11 - 2011-01-28 07:26 - 00000000 ____D C:\Users\Antrax\Documents\My Received Files 2013-02-08 07:37 - 2013-02-08 07:37 - 00000000 ____D C:\Users\Antrax\AppData\Local\{AD8034B0-25C5-411F-BE8A-DA69742F3FDE} 2013-02-08 00:52 - 2013-02-08 00:52 - 00000000 ____D C:\Users\Antrax\AppData\Local\Google 2013-02-08 00:52 - 2013-02-08 00:52 - 00000000 ____D C:\ProgramData\CLSoft LTD 2013-02-08 00:52 - 2013-02-08 00:52 - 00000000 ____D C:\Program Files\MagniPic 2013-02-08 00:52 - 2011-10-26 12:50 - 00000000 ____D C:\ProgramData\Premium 2013-02-08 00:52 - 2011-10-26 12:50 - 00000000 ____D C:\ProgramData\InstallMate 2013-02-07 13:40 - 2013-02-07 01:40 - 00000000 ____D C:\Users\Antrax\AppData\Local\{3338CA44-89CA-43A2-8C13-85BC39097FB8} 2013-02-06 11:32 - 2013-02-06 11:31 - 00000000 ____D C:\Users\Antrax\AppData\Local\{C670A20C-4FE4-4D96-A241-2353D53A0730} ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 12% Total physical RAM: 4094.18 MB Available physical RAM: 3563.73 MB Total Pagefile: 4092.46 MB Available Pagefile: 3569.48 MB Total Virtual: 2047.88 MB Available Virtual: 1960.7 MB ==================== Partitions ============================= 2 Drive c: () (Fixed) (Total:43.95 GB) (Free:8.47 GB) NTFS 3 Drive e: () (Fixed) (Total:24.41 GB) (Free:5.41 GB) NTFS 4 Drive f: () (Fixed) (Total:270.44 GB) (Free:83.03 GB) NTFS 5 Drive g: () (Fixed) (Total:124.63 GB) (Free:79.14 GB) NTFS 6 Drive h: () (Fixed) (Total:887.57 GB) (Free:355.29 GB) NTFS 8 Drive j: (Transcend) (Fixed) (Total:232.83 GB) (Free:61.27 GB) FAT32 9 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS 10 Drive y: () (Fixed) (Total:195.31 GB) (Free:70.87 GB) NTFS ==>[System with boot components (obtained from reading drive)] Disk ### Status Size Free Dyn Gpt ——– ————- ——- ——- — — Disk 0 Online 465 GB 9 MB Disk 1 Online 931 GB 0 B Disk 2 Online 149 GB 8 MB Disk 3 Online 232 GB 1024 KB Partitions of Disk 0: =============== Disk ID: A84EA84E Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 195 GB 31 KB Partition 0 Extended 270 GB 195 GB Partition 2 Logical 270 GB 195 GB ========================================================= Disk: 0 Partition 1 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 Y NTFS Partition 195 GB Healthy ========================================================= Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 F NTFS Partition 270 GB Healthy ========================================================= Partitions of Disk 1: =============== Disk ID: 8B5029E3 Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 43 GB 1024 KB Partition 2 Primary 887 GB 43 GB ========================================================= Disk: 1 Partition 1 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 C NTFS Partition 43 GB Healthy ========================================================= Disk: 1 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 4 H NTFS Partition 887 GB Healthy ========================================================= Partitions of Disk 2: =============== Disk ID: 07B707B7 Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 24 GB 31 KB Partition 0 Extended 124 GB 24 GB Partition 2 Logical 124 GB 24 GB ========================================================= Disk: 2 Partition 1 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 5 E NTFS Partition 24 GB Healthy ========================================================= Disk: 2 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 6 G NTFS Partition 124 GB Healthy ========================================================= Partitions of Disk 3: =============== Disk ID: E6D6DEC5 Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 232 GB 31 KB ========================================================= Disk: 3 Partition 1 Type : 0C Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 7 J Transcend FAT32 Partition 232 GB Healthy ========================================================= Last Boot: 2013-02-23 06:44 ==================== End Of Log ============================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI