This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Anti-Virus and Firewall keep turning off [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

In last couple of days my Mcafee Anti Virus and Fire wall keep turning off even though Mcafee says everything is on, yet windows keeps notifying me that they are both turned off

I'm currently running windows 8 64bit version. Thank you in advance for your help.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:29:52 PM, on 5/15/2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe
C:\Program Files (x86)\Sony\Content Manager Assistant\CMAWatcher.exe
c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
c:\PROGRA~2\mcafee\SITEAD~1\saui.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\Steven\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK13/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK13/1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSnc.20130401122334.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [mcpltui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ReminderApp_69961952-30DE-4DEB-B6FB-572D30956785] C:\Program Files (x86)\Nova Development\Print Artist Gold 24\ReminderApp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [DelayShred] "c:\PROGRA~1\mcafee\mqs\ShrCL.EXE" /P1 /q "J:\slacker"
O4 - Global Startup: Content Manager Assistant for PlayStation®.lnk = C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: McAfee Home Network (HomeNetSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Connected Remote Service (HPConnectedRemote) - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe
O23 - Service: McAfee Personal Firewall (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Platform Services (mcpltsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Application Statistics Service (MfeASUM) - McAfee, Inc. - C:\Program Files\McAfee\AppStats\MfeASUM.exe
O23 - Service: McAfee Anti-Malware Core (mfecore) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\windows\system32\mfevtps.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 10483 bytes
Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer
  • Press Scan button
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.


NEXT

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well
Thank you for your response!

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-05-2013
Ran by [removed] (administrator) on 28-05-2013 19:20:24
Running from C:\Users\[removed]\Downloads
Windows 8 (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================

(AMD) C:\windows\system32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
(Microsoft Corporation) C:\windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\windows\system32\dashost.exe
(McAfee, Inc.) C:\Program Files\McAfee\AppStats\MfeASUM.exe
(McAfee, Inc.) C:\windows\system32\mfevtps.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Hewlett-Packard) c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
(McAfee, Inc.) C:\PROGRA~1\McAfee\MSC\McAPExe.exe
(McAfee, Inc.) c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
(McAfee, Inc.) c:\PROGRA~1\mcafee\msc\mcupdmgr.exe
(McAfee, Inc.) c:\PROGRA~1\mcafee\mqs\qcshm.exe
(Microsoft Corporation) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(McAfee, Inc.) C:\PROGRA~1\McAfee\MSC\McInfo.exe
(AMD) C:\windows\system32\atieclxx.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe\LiveComm.exe
(Sony Computer Entertainment Inc.) C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe
(Sony Computer Entertainment Inc.) C:\Program Files (x86)\Sony\Content Manager Assistant\CMAWatcher.exe
(CyberLink) c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Farbar) C:\Users\Steven\Downloads\FRST64.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [BeatsOSDApp] C:\Program Files\IDT\WDM\beats64.exe [41664 2013-03-29] (Hewlett-Packard )
HKLM\…\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [1702912 2013-03-29] (IDT, Inc.)
HKCU\…\Run: [DelayShred] "c:\PROGRA~1\mcafee\mqs\ShrCL.EXE" /P1 /q "J:\slacker" [67856 2013-02-01] ()
MountPoints2: {daf2b115-a9f2-11e2-be8b-78e3b5ba207a} - "J:\CMADownloader.exe"
HKLM-x32\…\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [642216 2012-11-14] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [mcpltui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey [454600 2013-02-28] (McAfee, Inc.)
HKLM-x32\…\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM-x32\…\Run: [] [x]
HKLM-x32\…\Run: [ReminderApp_69961952-30DE-4DEB-B6FB-572D30956785] C:\Program Files (x86)\Nova Development\Print Artist Gold 24\ReminderApp.exe [144728 2011-03-09] ()
HKLM-x32\…\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot [295512 2013-05-16] (RealNetworks, Inc.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Content Manager Assistant for PlayStation®.lnk
ShortcutTarget: Content Manager Assistant for PlayStation®.lnk -> C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK13/1
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK13/1
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK13/1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
SearchScopes: HKLM - {609B3C92-2746-4672-A74B-B25433917B3A} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
SearchScopes: HKLM-x32 - {609B3C92-2746-4672-A74B-B25433917B3A} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
SearchScopes: HKCU - {609B3C92-2746-4672-A74B-B25433917B3A} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
SearchScopes: HKCU - {7645B951-4348-42AF-AA7E-37E493E59887} URL = http://search.yahoo.com/search?fr=mcafee&p;={SearchTerms}
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSnc.20130401122333.dll (McAfee, Inc.)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSnc.20130401122334.dll (McAfee, Inc.)
BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\PROGRA~1\mcafee\msc\MCSNIE~1.DLL (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\PROGRA~2\mcafee\msc\mcsniepl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF ProfilePath: C:\Users\Steven\AppData\Roaming\Mozilla\Firefox\Profiles\irbmtnh0.default
FF SelectedSearchEngine: Google
FF Homepage: https://sellercentral.amazon.com/gp/homepage.html
FF Keyword.URL: hxxp://search.yahoo.com/search?fr=mcafee&p;=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll ()
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @mcafee.com/MVT - C:\Program Files (x86)\McAfee\Supportability\MVT\NPMVTPlugin.dll (McAfee, Inc.)
FF Plugin-x32: @mcafee.com/SAFFPlugin - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.2.32 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.2.32 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: hxxp://thebaconstation.com/
CHR RestoreOnStartup: "hxxp://thebaconstation.com/"
CHR DefaultSearchURL: (McAfee) - http://search.yahoo.com/search?fr=mcafee&p;={searchTerms}
CHR DefaultSuggestURL: (McAfee) - "suggest_url": ""
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll ()
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.60.126.1_0\McChPlg.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll No File
CHR Plugin: (McAfee SecurityCenter) - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
CHR Extension: (Google Docs) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (SiteAdvisor) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.61.113.2_0
CHR Extension: (RealDownloader) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.2_0
CHR Extension: (Gmail) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [221296 2013-03-05] (McAfee, Inc.)
R2 HPConnectedRemote; c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [35744 2012-10-12] (Hewlett-Packard)
R2 HPSLPSVC; C:\Users\Steven\AppData\Local\Temp\7zS37F2\hpslpsvc64.dll [1039360 2013-02-06] (Hewlett-Packard Co.)
R2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [120592 2013-03-04] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [221296 2013-03-05] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [221296 2013-03-05] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [388680 2013-03-01] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [221296 2013-03-05] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [221296 2013-03-05] (McAfee, Inc.)
R2 MfeASUM; C:\Program Files\McAfee\AppStats\MfeASUM.exe [335216 2013-05-05] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1007288 2012-10-06] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [218320 2012-12-26] (McAfee, Inc.)
R2 mfevtp; C:\windows\system32\mfevtps.exe [182312 2012-12-26] (McAfee, Inc.)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-28] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98472 2012-07-17] (Advanced Micro Devices)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [69672 2012-12-26] (McAfee, Inc.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows ® Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows ® Win 7 DDK provider)
R3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197264 2012-05-28] (McAfee, Inc.)
R3 L1C; C:\Windows\system32\DRIVERS\L1C63x64.sys [110744 2012-07-30] (Qualcomm Atheros Co., Ltd.)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [178840 2012-12-26] (McAfee, Inc.)
R1 MfeASKM; C:\Program Files\McAfee\AppStats\MfeASKM.sys [31408 2013-05-05] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [309400 2012-12-26] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69168 2012-12-26] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [515528 2012-12-26] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [771096 2012-12-26] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [328976 2012-11-02] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [97208 2012-11-02] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [339776 2012-12-26] (McAfee, Inc.)
S3 WUDFSensorLP; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-25] (Microsoft Corporation)
S3 WUDFWpdMtp; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-25] (Microsoft Corporation)
S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [89088 2012-07-25] (Microsoft Corporation)
S3 CpqDfw; system32\drivers\CpqDfw.sys [x]
U3 mfeavfk01; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-05-28 19:19 - 2013-05-28 19:19 - 00000000 ____D C:\FRST
2013-05-28 19:18 - 2013-05-28 19:18 - 01915774 ____A (Farbar) C:\Users\Steven\Downloads\FRST64.exe
2013-05-25 22:18 - 2013-05-25 22:18 - 00000360 ____A C:\Windows\PFRO.log
2013-05-25 21:07 - 2013-05-25 21:07 - 00000000 ____D C:\Users\Steven\Documents\CyberLink
2013-05-25 21:07 - 2013-05-25 21:07 - 00000000 ____D C:\Users\Steven\AppData\Roaming\WebApp
2013-05-16 15:00 - 2013-05-16 15:00 - 00355744 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-16 13:18 - 2013-05-16 13:18 - 00000000 ____D C:\ProgramData\RealNetworks
2013-05-16 13:18 - 2013-05-16 13:18 - 00000000 ____D C:\Program Files (x86)\RealNetworks
2013-05-16 13:10 - 2013-05-16 13:10 - 00001113 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-05-16 12:43 - 2013-04-08 22:33 - 00489576 ____A (Microsoft Corporation) C:\Windows\System32\AudioEng.dll
2013-05-16 12:43 - 2013-04-08 22:33 - 00446792 ____A (Microsoft Corporation) C:\Windows\System32\AudioSes.dll
2013-05-16 12:43 - 2013-04-08 22:33 - 00253544 ____A (Microsoft Corporation) C:\Windows\System32\audiodg.exe
2013-05-16 12:43 - 2013-04-08 22:27 - 00284424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys
2013-05-16 12:43 - 2013-04-08 22:20 - 00306952 ____A (Microsoft Corporation) C:\Windows\System32\kd_02_10ec.dll
2013-05-16 12:43 - 2013-04-08 22:20 - 00086280 ____A (Microsoft Corporation) C:\Windows\System32\kdnet.dll
2013-05-16 12:43 - 2013-04-08 22:18 - 00077960 ____A (Microsoft Corporation) C:\Windows\System32\kdvm.dll
2013-05-16 12:43 - 2013-04-08 22:17 - 01829408 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2013-05-16 12:43 - 2013-04-08 21:52 - 00816128 ____A (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe
2013-05-16 12:43 - 2013-04-08 21:52 - 00804352 ____A (Microsoft Corporation) C:\Windows\System32\RecoveryDrive.exe
2013-05-16 12:43 - 2013-04-08 21:52 - 00373760 ____A (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe
2013-05-16 12:43 - 2013-04-08 21:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe
2013-05-16 12:43 - 2013-04-08 21:52 - 00126464 ____A (Microsoft Corporation) C:\Windows\System32\Robocopy.exe
2013-05-16 12:43 - 2013-04-08 21:51 - 14267904 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll
2013-05-16 12:43 - 2013-04-08 21:51 - 13648384 ____A (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll
2013-05-16 12:43 - 2013-04-08 21:51 - 10116096 ____A (Microsoft Corporation) C:\Windows\System32\twinui.dll
2013-05-16 12:43 - 2013-04-08 21:51 - 03552768 ____A (Microsoft Corporation) C:\Windows\System32\tquery.dll
2013-05-16 12:43 - 2013-04-08 21:51 - 00595456 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.dll
2013-05-16 12:43 - 2013-04-08 21:51 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll
2013-05-16 12:43 - 2013-04-08 21:51 - 00456704 ____A (Microsoft Corporation) C:\Windows\System32\wpncore.dll
2013-05-16 12:43 - 2013-04-08 21:51 - 00391168 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-05-16 12:43 - 2013-04-08 21:51 - 00367616 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-05-16 12:43 - 2013-04-08 21:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wscsvc.dll
2013-05-16 12:43 - 2013-04-08 21:50 - 02107904 ____A (Microsoft Corporation) C:\Windows\System32\mssrch.dll
2013-05-16 12:43 - 2013-04-08 21:50 - 01285632 ____A (Microsoft Corporation) C:\Windows\System32\schedsvc.dll
2013-05-16 12:43 - 2013-04-08 21:50 - 00745984 ____A (Microsoft Corporation) C:\Windows\System32\mssvp.dll
2013-05-16 12:43 - 2013-04-08 21:50 - 00435200 ____A (Microsoft Corporation) C:\Windows\System32\mssph.dll
2013-05-16 12:43 - 2013-04-08 21:50 - 00422400 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-05-16 12:43 - 2013-04-08 21:50 - 00414720 ____A (Microsoft Corporation) C:\Windows\System32\GenuineCenter.dll
2013-05-16 12:43 - 2013-04-08 21:50 - 00096256 ____A (Microsoft Corporation) C:\Windows\System32\mssprxy.dll
2013-05-16 12:43 - 2013-04-08 21:50 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\msscntrs.dll
2013-05-16 12:43 - 2013-04-08 21:50 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\msshooks.dll
2013-05-16 12:43 - 2013-04-08 21:49 - 01444864 ____A (Microsoft Corporation) C:\Windows\System32\MSAudDecMFT.dll
2013-05-16 12:43 - 2013-04-08 21:49 - 00817152 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2013-05-16 12:43 - 2013-04-08 21:49 - 00468992 ____A (Microsoft Corporation) C:\Windows\System32\MFMediaEngine.dll
2013-05-16 12:43 - 2013-04-08 21:49 - 00281088 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll
2013-05-16 12:43 - 2013-04-08 21:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\fhengine.dll
2013-05-16 12:43 - 2013-04-08 21:49 - 00210432 ____A (Microsoft Corporation) C:\Windows\System32\iuilp.dll
2013-05-16 12:43 - 2013-04-08 21:49 - 00196096 ____A (Microsoft Corporation) C:\Windows\System32\dmvdsitf.dll
2013-05-16 12:43 - 2013-04-08 21:49 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\dwmredir.dll
2013-05-16 12:43 - 2013-04-08 21:49 - 00050176 ____A (Microsoft Corporation) C:\Windows\System32\fmifs.dll
2013-05-16 12:43 - 2013-04-08 21:48 - 02303488 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-05-16 12:43 - 2013-04-08 21:48 - 00785408 ____A (Microsoft Corporation) C:\Windows\System32\audiosrv.dll
2013-05-16 12:43 - 2013-04-08 21:48 - 00419840 ____A (Microsoft Corporation) C:\Windows\System32\intl.cpl
2013-05-16 12:43 - 2013-04-08 21:48 - 00169472 ____A (Microsoft Corporation) C:\Windows\System32\AudioEndpointBuilder.dll
2013-05-16 12:43 - 2013-04-08 19:35 - 04038144 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-05-16 12:43 - 2013-04-08 19:34 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys
2013-05-16 12:43 - 2013-04-08 19:34 - 00083968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2013-05-16 12:43 - 2013-04-08 19:34 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys
2013-05-16 12:43 - 2013-04-08 19:33 - 00623104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
2013-05-16 12:43 - 2013-04-08 19:33 - 00060416 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndproxy.sys
2013-05-16 12:43 - 2013-04-08 19:32 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\PEAuth.sys
2013-05-16 12:43 - 2013-04-08 19:31 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
2013-05-16 12:43 - 2013-04-08 19:31 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\wanarp.sys
2013-05-16 12:43 - 2013-04-08 16:44 - 00123880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2013-05-16 12:43 - 2013-04-08 16:39 - 01408896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-05-16 12:43 - 2013-04-08 16:37 - 00426024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2013-05-16 12:43 - 2013-04-08 16:37 - 00324368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2013-05-16 12:43 - 2013-04-08 14:52 - 11878912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-05-16 12:43 - 2013-04-08 14:52 - 00670208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2013-05-16 12:43 - 2013-04-08 14:52 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-05-16 12:43 - 2013-04-08 14:52 - 00302592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2013-05-16 12:43 - 2013-04-08 14:52 - 00171008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2013-05-16 12:43 - 2013-04-08 14:52 - 00106496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe
2013-05-16 12:43 - 2013-04-08 14:51 - 10789888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 08857088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 02767360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 02035200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 01593344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 01113600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 00659456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 00656896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 00411136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 00403968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 00389632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2013-05-16 12:43 - 2013-04-08 14:51 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 00324096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 00268800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 00214528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 00186880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 00155648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fmifs.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 00035328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2013-05-16 12:43 - 2013-04-08 14:51 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2013-05-16 12:43 - 2013-04-04 16:30 - 00503080 ____A (Microsoft Corporation) C:\Windows\System32\ci.dll
2013-05-16 12:43 - 2013-04-02 15:08 - 00387688 ____A C:\Windows\System32\ApnDatabase.xml
2013-05-16 12:43 - 2013-03-30 11:16 - 01403784 ____A (Microsoft Corporation) C:\Windows\System32\winload.efi
2013-05-16 12:43 - 2013-03-30 11:16 - 01267424 ____A (Microsoft Corporation) C:\Windows\System32\winload.exe
2013-05-16 12:43 - 2013-03-28 15:09 - 01217328 ____A (Microsoft Corporation) C:\Windows\System32\winresume.efi
2013-05-16 12:43 - 2013-03-28 15:09 - 01093880 ____A (Microsoft Corporation) C:\Windows\System32\winresume.exe
2013-05-16 12:43 - 2013-03-15 15:05 - 00298456 ____A (Microsoft Corporation) C:\Windows\System32\rsaenh.dll
2013-05-16 12:43 - 2013-03-15 15:05 - 00252928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll
2013-05-16 12:43 - 2012-12-12 21:00 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2013-05-16 12:43 - 2012-12-12 20:59 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-05-15 23:29 - 2013-05-15 23:29 - 00010485 ____A C:\Users\Steven\Desktop\hijackthis.log
2013-05-15 23:25 - 2013-05-15 23:25 - 00388608 ____A (Trend Micro Inc.) C:\Users\Steven\Desktop\HiJackThis.exe
2013-05-14 20:30 - 2013-05-14 20:30 - 09195912 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-05-14 20:21 - 2013-04-15 19:34 - 01455368 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-14 20:21 - 2013-04-09 16:17 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-05-14 20:21 - 2013-04-09 16:17 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-05-14 20:21 - 2013-04-09 16:17 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-05-14 20:21 - 2013-04-09 16:17 - 00915968 ____A (Microsoft Corporation) C:\Windows\System32\uxtheme.dll
2013-05-14 20:21 - 2013-04-09 16:17 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-05-14 20:21 - 2013-04-09 16:17 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-05-14 20:21 - 2013-04-09 16:16 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-05-14 20:21 - 2013-04-09 16:16 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-05-14 20:21 - 2013-04-09 16:16 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-05-14 20:21 - 2013-04-09 16:16 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-05-14 20:21 - 2013-04-09 15:30 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-05-14 20:21 - 2013-04-09 15:30 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-05-14 20:21 - 2013-04-09 15:29 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-05-14 20:21 - 2013-04-09 15:29 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-05-14 20:21 - 2013-04-09 15:29 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-05-14 20:21 - 2013-04-09 15:29 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-05-14 20:21 - 2013-04-09 15:29 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-05-14 20:21 - 2013-04-09 15:29 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-05-14 20:20 - 2013-03-14 17:17 - 00861184 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys
2013-05-14 20:19 - 2013-04-10 23:40 - 06987528 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-05-14 20:19 - 2013-03-21 20:49 - 02382336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2013-05-14 20:19 - 2013-03-21 15:47 - 02851840 ____A (Microsoft Corporation) C:\Windows\System32\esent.dll
2013-05-14 20:19 - 2013-03-06 00:10 - 00112872 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-14 20:19 - 2013-03-05 23:31 - 19758592 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-14 20:19 - 2013-03-05 23:31 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-14 20:19 - 2013-03-05 23:29 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-14 20:19 - 2013-03-05 22:03 - 17561600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-05-14 20:19 - 2013-03-05 22:03 - 00199168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-05-11 11:21 - 2013-05-11 11:21 - 00001075 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-05-11 11:21 - 2013-05-11 11:21 - 00000000 ____D C:\Users\Steven\AppData\Roaming\Malwarebytes
2013-05-11 11:21 - 2013-05-11 11:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-05-11 11:20 - 2013-05-11 11:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-05-11 11:20 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-05-03 16:11 - 2013-05-03 16:11 - 00000000 ____D C:\Program Files (x86)\PCPitstop
2013-05-01 14:48 - 2013-05-01 14:48 - 00000000 ____D C:\Users\Steven\Desktop\FPR Real World 2012 (PS3)
2013-05-01 14:46 - 2013-05-01 14:46 - 00000000 ____D C:\Program Files (x86)\Free RAR Extract Frog
2013-05-01 14:42 - 2013-05-01 14:42 - 01221780 ____A C:\Users\Steven\Downloads\FPR Real World 2012 (PS3).rar
2013-05-01 00:22 - 2013-05-01 00:22 - 01114502 ____A C:\Users\Steven\Desktop\DJKM-WWE-2013-03.18.13.zip

==================== One Month Modified Files and Folders =======

2013-05-28 19:19 - 2013-05-28 19:19 - 00000000 ____D C:\FRST
2013-05-28 19:18 - 2013-05-28 19:18 - 01915774 ____A (Farbar) C:\Users\Steven\Downloads\FRST64.exe
2013-05-28 19:11 - 2013-03-16 23:22 - 00000902 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-05-28 19:11 - 2012-07-26 01:12 - 00000000 ____D C:\Windows\System32\sru
2013-05-28 17:54 - 2013-04-26 20:36 - 01818747 ____A C:\Windows\WindowsUpdate.log
2013-05-28 17:48 - 2013-03-14 20:59 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2013-05-28 17:48 - 2013-03-14 20:59 - 00000000 ____A C:\Windows\System32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-05-28 17:47 - 2013-03-15 15:46 - 00000000 ____D C:\Users\Steven\AppData\Roaming\HpUpdate
2013-05-27 18:29 - 2013-03-16 23:36 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-05-27 15:32 - 2013-03-16 23:22 - 00000906 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-05-27 00:43 - 2013-03-14 15:57 - 00000000 ____D C:\Users\Steven\Desktop\Joy's secrets
2013-05-26 21:08 - 2012-07-26 01:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-05-25 22:23 - 2012-07-26 00:28 - 00876558 ____A C:\Windows\System32\PerfStringBackup.INI
2013-05-25 22:22 - 2013-03-15 15:31 - 01907200 __ASH C:\Users\Steven\Desktop\Thumbs.db
2013-05-25 22:18 - 2013-05-25 22:18 - 00000360 ____A C:\Windows\PFRO.log
2013-05-25 22:18 - 2013-03-14 18:07 - 00000000 ____D C:\Program Files (x86)\McAfee
2013-05-25 22:18 - 2012-07-26 00:22 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-05-25 22:10 - 2012-07-25 22:26 - 00262144 __ASH C:\Windows\System32\config\BBI
2013-05-25 21:07 - 2013-05-25 21:07 - 00000000 ____D C:\Users\Steven\Documents\CyberLink
2013-05-25 21:07 - 2013-05-25 21:07 - 00000000 ____D C:\Users\Steven\AppData\Roaming\WebApp
2013-05-25 21:07 - 2013-03-22 20:09 - 00000000 ____D C:\Users\Steven\AppData\Roaming\CyberLink
2013-05-25 21:07 - 2013-03-22 20:09 - 00000000 ____D C:\Users\Public\CyberLink
2013-05-25 21:07 - 2013-03-07 14:40 - 00000000 ____D C:\ProgramData\CyberLink
2013-05-24 20:17 - 2013-03-14 17:27 - 00000000 ____D C:\users\Steven
2013-05-23 19:21 - 2012-07-25 22:26 - 00262144 __ASH C:\Windows\System32\config\ELAM
2013-05-21 19:12 - 2013-03-17 11:56 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2013-05-19 21:44 - 2013-03-22 20:19 - 00000344 ____A C:\Windows\Tasks\HPCeeScheduleForSteven.job
2013-05-18 00:09 - 2012-07-26 01:12 - 00000000 ____D C:\Windows\rescache
2013-05-16 15:00 - 2013-05-16 15:00 - 00355744 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-16 15:00 - 2013-03-14 22:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-05-16 13:18 - 2013-05-16 13:18 - 00000000 ____D C:\ProgramData\RealNetworks
2013-05-16 13:18 - 2013-05-16 13:18 - 00000000 ____D C:\Program Files (x86)\RealNetworks
2013-05-16 13:16 - 2013-04-04 12:48 - 00201872 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2013-05-16 13:16 - 2013-04-04 12:47 - 00272896 ____A (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
2013-05-16 13:16 - 2013-04-04 12:47 - 00006656 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll
2013-05-16 13:16 - 2013-04-04 12:47 - 00005632 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll
2013-05-16 13:16 - 2013-04-04 12:42 - 00000000 ____D C:\ProgramData\Real
2013-05-16 13:15 - 2013-03-07 14:54 - 00499712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2013-05-16 13:15 - 2013-03-07 14:54 - 00348160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2013-05-16 13:10 - 2013-05-16 13:10 - 00001113 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-05-16 13:10 - 2013-04-19 13:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-05-16 12:46 - 2012-07-26 01:12 - 00000000 ___RD C:\Windows\ToastData
2013-05-16 12:46 - 2012-07-26 01:12 - 00000000 ____D C:\Windows\WinStore
2013-05-16 12:35 - 2013-03-15 12:20 - 00000000 ____D C:\Program Files (x86)\Diablo III
2013-05-15 23:29 - 2013-05-15 23:29 - 00010485 ____A C:\Users\Steven\Desktop\hijackthis.log
2013-05-15 23:26 - 2013-03-14 17:27 - 00000000 ____D C:\Users\Steven\AppData\Local\VirtualStore
2013-05-15 23:25 - 2013-05-15 23:25 - 00388608 ____A (Trend Micro Inc.) C:\Users\Steven\Desktop\HiJackThis.exe
2013-05-15 21:33 - 2012-07-26 01:12 - 00000000 ____D C:\Windows\System32\NDF
2013-05-15 21:31 - 2013-03-07 14:35 - 00004230 ____A C:\Windows\System32\RaCoInst.log
2013-05-14 20:30 - 2013-05-14 20:30 - 09195912 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-05-14 20:28 - 2013-03-14 18:21 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-05-12 17:45 - 2013-03-22 13:24 - 00000000 ____D C:\Users\Steven\AppData\Local\Nova Development
2013-05-11 11:21 - 2013-05-11 11:21 - 00001075 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-05-11 11:21 - 2013-05-11 11:21 - 00000000 ____D C:\Users\Steven\AppData\Roaming\Malwarebytes
2013-05-11 11:21 - 2013-05-11 11:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-05-11 11:21 - 2013-05-11 11:20 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-05-09 18:05 - 2013-03-14 17:27 - 00000000 ____D C:\Users\Steven\AppData\Local\Packages
2013-05-09 01:03 - 2013-03-21 15:08 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2013-05-07 13:07 - 2012-07-26 01:14 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-05-07 13:07 - 2012-07-26 01:14 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-05-03 16:11 - 2013-05-03 16:11 - 00000000 ____D C:\Program Files (x86)\PCPitstop
2013-05-02 08:29 - 2013-04-04 16:06 - 00278800 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2013-05-01 14:48 - 2013-05-01 14:48 - 00000000 ____D C:\Users\Steven\Desktop\FPR Real World 2012 (PS3)
2013-05-01 14:47 - 2013-04-25 17:42 - 00000000 ____D C:\Users\Steven\AppData\Roaming\Philipp Winterberg
2013-05-01 14:46 - 2013-05-01 14:46 - 00000000 ____D C:\Program Files (x86)\Free RAR Extract Frog
2013-05-01 14:42 - 2013-05-01 14:42 - 01221780 ____A C:\Users\Steven\Downloads\FPR Real World 2012 (PS3).rar
2013-05-01 00:22 - 2013-05-01 00:22 - 01114502 ____A C:\Users\Steven\Desktop\DJKM-WWE-2013-03.18.13.zip
2013-04-30 19:44 - 2013-03-14 21:52 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-04-30 19:44 - 2013-03-14 21:52 - 00000000 ____D C:\Program Files\CCleaner
2013-04-28 18:18 - 2013-04-16 14:02 - 00000000 ____D C:\ProgramData\Recovery

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


Last Boot: 2013-05-23 19:31

==================== End Of Log ============================







Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-05-2013
Ran by [removed] at 2013-05-28 19:22:13 Run:
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

64 Bit HP CIO Components Installer (Version: 7.2.8)
Adobe Flash Player 11 Plugin (Version: 11.7.700.202)
Adobe Reader XI (11.0.03) (Version: 11.0.03)
AIO_CDA_ProductContext (Version: 140.0.425.000)
AIO_CDA_Software (Version: 140.0.428.000)
AIO_Scan (Version: 130.0.421.000)
AMD Accelerated Video Transcoding (Version: 12.5.100.21114)
AMD APP SDK Runtime (Version: 10.0.938.2)
AMD Catalyst Install Manager (Version: 8.0.881.0)
AMD VISION Engine Control Center (Version: 2012.1114.401.6988)
Back to the Future The Game (Version: 2.0.0.0)
BoneCraft (Version: 1.0.4)
BufferChm (Version: 140.0.298.000)
C5100 (Version: 140.0.425.000)
c5100_Help (Version: 82.0.256.000)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (Version: 2012.1114.401.6988)
Catalyst Control Center InstallProxy (Version: 2012.0704.2139.36919)
Catalyst Control Center Localization All (Version: 2012.1114.401.6988)
Catalyst Control Center Profiles Desktop (Version: 2012.1114.401.6988)
CCC Help Chinese Standard (Version: 2012.1114.0400.6988)
CCC Help Chinese Traditional (Version: 2012.1114.0400.6988)
CCC Help Czech (Version: 2012.1114.0400.6988)
CCC Help Danish (Version: 2012.1114.0400.6988)
CCC Help Dutch (Version: 2012.1114.0400.6988)
CCC Help English (Version: 2012.1114.0400.6988)
CCC Help Finnish (Version: 2012.1114.0400.6988)
CCC Help French (Version: 2012.1114.0400.6988)
CCC Help German (Version: 2012.1114.0400.6988)
CCC Help Greek (Version: 2012.1114.0400.6988)
CCC Help Hungarian (Version: 2012.1114.0400.6988)
CCC Help Italian (Version: 2012.1114.0400.6988)
CCC Help Japanese (Version: 2012.1114.0400.6988)
CCC Help Korean (Version: 2012.1114.0400.6988)
CCC Help Norwegian (Version: 2012.1114.0400.6988)
CCC Help Polish (Version: 2012.1114.0400.6988)
CCC Help Portuguese (Version: 2012.1114.0400.6988)
CCC Help Russian (Version: 2012.1114.0400.6988)
CCC Help Spanish (Version: 2012.1114.0400.6988)
CCC Help Swedish (Version: 2012.1114.0400.6988)
CCC Help Thai (Version: 2012.1114.0400.6988)
CCC Help Turkish (Version: 2012.1114.0400.6988)
ccc-utility64 (Version: 2012.1114.401.6988)
CCleaner (Version: 4.01)
Content Manager Assistant for PlayStation® (Version: 2.10.6402.20)
Copy (Version: 140.0.298.000)
CyberLink Media Suite 10 (Version: 10.0.2.2114)
CyberLink Power2Go 8 (Version: 8.0.2.2126)
CyberLink PowerDirector 10 (Version: 10.0.2.2126)
CyberLink PowerDVD (Version: 10.0.7.4605)
D3DX10 (Version: 15.4.2368.0902)
Destinations (Version: 140.0.253.000)
DeviceDiscovery (Version: 140.0.298.000)
Diablo III (Version: 1.0.8.16603)
doPDF 7.3 printer
Fax (Version: 140.0.307.000)
FileHippo.com Update Checker
Free RAR Extract Frog (Version: 4.70)
Google Chrome (Version: 27.0.1453.94)
Google Update Helper (Version: 1.3.21.145)
Hewlett-Packard ACLM.NET v1.2.1.1 (Version: 1.00.0000)
HP Connected Remote (Version: 1.0.1218)
HP Customer Experience Enhancements (Version: 6.0.1.7)
HP Imaging Device Functions 14.0 (Version: 14.0)
HP Photosmart All-In-One Driver Software (Version: 14.0)
HP Postscript Converter (Version: 3.1.3591)
HP Support Assistant (Version: 7.0.39.15)
HP Support Information (Version: 12.00.0000)
HP Update (Version: 5.002.006.003)
HPPhotoGadget (Version: 140.0.524.000)
HydraVision (Version: 4.2.236.0)
IDT Audio (Version: 1.0.6418.0)
Jurassic Park The Game (Version: 1.0.0.15)
Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
McAfee AntiVirus Plus (Version: 12.1.323)
McAfee Virtual Technician (Version: 7.1.0.2483)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Movie Maker (Version: 16.4.3503.0728)
Mozilla Firefox 21.0 (x86 en-US) (Version: 21.0)
Mozilla Maintenance Service (Version: 21.0)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT110 (Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1108.0727)
Network64 (Version: 140.0.306.000)
Next Generation Visualisations (Version: 1.0.0)
Photo Common (Version: 16.4.3503.0728)
Photo Gallery (Version: 16.4.3503.0728)
Print Artist Gold (Version: 24.0.1.2)
Ralink RT5390R 802.11bgn Wi-Fi Adapter (Version: 5.0.5.0)
RealDownloader (Version: 1.3.2)
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0)
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0)
RealPlayer (Version: 16.0.2)
RealUpgrade 1.1 (Version: 1.1.0)
Recovery Manager (Version: 5.5.0.5826)
Scan (Version: 140.0.253.000)
Shared C Run-time for x64 (Version: 10.0.0)
SpywareBlaster 5.0 (Version: 5.0.0)
Status (Version: 140.0.342.000)
The Walking Dead (Version: 1.0.0.15)
Toolbox (Version: 140.0.596.000)
TrayApp (Version: 140.0.297.000)
WebReg (Version: 140.0.297.017)
Windows Live Communications Platform (Version: 16.4.3503.0728)
Windows Live Essentials (Version: 16.4.3503.0728)
Windows Live Installer (Version: 16.4.3503.0728)
Windows Live Photo Common (Version: 16.4.3503.0728)
Windows Live PIMT Platform (Version: 16.4.3503.0728)
Windows Live SOXE (Version: 16.4.3503.0728)
Windows Live SOXE Definitions (Version: 16.4.3503.0728)
Windows Live UX Platform (Version: 16.4.3503.0728)
Windows Live UX Platform Language Pack (Version: 16.4.3503.0728)
World of Warcraft (Version: 5.2.0.16826)

==================== Restore Points =========================

15-05-2013 03:27:20 Windows Update
16-05-2013 20:00:56 McAfee Vulnerability Scanner
24-05-2013 02:40:53 Scheduled Checkpoint

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/27/2013 06:09:38 PM) (Source: Application Error) (User: )
Description: Faulting application name: McSmtFwk.exe, version: 4.1.185.0, time stamp: 0x50c7b310
Faulting module name: McSmtFwk.exe, version: 4.1.185.0, time stamp: 0x50c7b310
Exception code: 0xc0000005
Fault offset: 0x00000000000030a5
Faulting process id: 0x1b10
Faulting application start time: 0xMcSmtFwk.exe0
Faulting application path: McSmtFwk.exe1
Faulting module path: McSmtFwk.exe2
Report Id: McSmtFwk.exe3
Faulting package full name: McSmtFwk.exe4
Faulting package-relative application ID: McSmtFwk.exe5

Error: (05/27/2013 06:03:36 PM) (Source: Application Error) (User: )
Description: Faulting application name: McUICnt.exe, version: 5.1.169.0, time stamp: 0x50712b57
Faulting module name: McSmtStr.dll, version: 4.1.185.0, time stamp: 0x50c7b31e
Exception code: 0xc0000005
Fault offset: 0x000000000001db5c
Faulting process id: 0xc68
Faulting application start time: 0xMcUICnt.exe0
Faulting application path: McUICnt.exe1
Faulting module path: McUICnt.exe2
Report Id: McUICnt.exe3
Faulting package full name: McUICnt.exe4
Faulting package-relative application ID: McUICnt.exe5

Error: (05/27/2013 05:49:52 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/25/2013 05:57:59 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/25/2013 05:56:46 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/25/2013 05:45:06 PM) (Source: Application Error) (User: )
Description: Faulting application name: mcsacore.exe, version: 3.6.1.106, time stamp: 0x5134ca77
Faulting module name: ntdll.dll, version: 6.2.9200.16579, time stamp: 0x51637f77
Exception code: 0xc0000005
Fault offset: 0x000000000005ab00
Faulting process id: 0xe54
Faulting application start time: 0xmcsacore.exe0
Faulting application path: mcsacore.exe1
Faulting module path: mcsacore.exe2
Report Id: mcsacore.exe3
Faulting package full name: mcsacore.exe4
Faulting package-relative application ID: mcsacore.exe5

Error: (05/24/2013 06:25:54 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/23/2013 07:32:34 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/23/2013 07:30:11 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/21/2013 07:23:18 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.


System errors:
=============
Error: (05/28/2013 07:16:59 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 07:16:59 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 07:16:56 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 07:16:56 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 07:12:32 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 07:12:32 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 07:12:29 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 07:12:29 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 05:58:03 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 05:57:33 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.


Microsoft Office Sessions:
=========================
Error: (05/27/2013 06:09:38 PM) (Source: Application Error)(User: )
Description: McSmtFwk.exe4.1.185.050c7b310McSmtFwk.exe4.1.185.050c7b310c000000500000000000030
a51b1001ce5a907840644aC:\PROGRA~1\COMMON~1\McAfee\Platform\MSM\McSmtFwk.exeC:\PROGRA~1\COMMON~1\McAfee\Platform\MSM\McSmtFwk.exe44169ca0-c733-11e2-be98-78e3b5ba207a

Error: (05/27/2013 06:03:36 PM) (Source: Application Error)(User: )
Description: McUICnt.exe5.1.169.050712b57McSmtStr.dll4.1.185.050c7b31ec0000005000000000001db5
cc6801ce5b3f2e7b416eC:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exeC:\PROGRA~1\COMMON~1\McAfee\Platform\MSM\McSmtStr.dll6c908930-c732-11e2-be98-78e3b5ba207a

Error: (05/27/2013 05:49:52 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe

Error: (05/25/2013 05:57:59 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe

Error: (05/25/2013 05:56:46 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe

Error: (05/25/2013 05:45:06 PM) (Source: Application Error)(User: )
Description: mcsacore.exe3.6.1.1065134ca77ntdll.dll6.2.9200.1657951637f77c0000005000000000005
ab00e5401ce58f5ce9aed01c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exeC:\windows\SYSTEM32\ntdll.dll81dd79fa-c59d-11e2-be97-78e3b5ba207a

Error: (05/24/2013 06:25:54 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe

Error: (05/23/2013 07:32:34 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe

Error: (05/23/2013 07:30:11 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe

Error: (05/21/2013 07:23:18 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe


==================== Memory info ===========================

Percentage of memory in use: 40%
Total physical RAM: 3991.29 MB
Available physical RAM: 2376.66 MB
Total Pagefile: 4695.29 MB
Available Pagefile: 2868.15 MB
Total Virtual: 8192 MB
Available Virtual: 8191.76 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:445.84 GB) (Free:329.33 GB) NTFS (Disk=0 Partition=4) ==>[System with boot components (obtained from reading drive)]
Drive d: (Recovery Image) (Fixed) (Total:18.44 GB) (Free:2.31 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 466 GB) (Disk ID: ABD9DDBB)

Partition: GPT Partition Type
==================== End Of Log ============================






Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-05-2013
Ran by [removed] at 2013-05-28 19:22:13 Run:
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

64 Bit HP CIO Components Installer (Version: 7.2.8)
Adobe Flash Player 11 Plugin (Version: 11.7.700.202)
Adobe Reader XI (11.0.03) (Version: 11.0.03)
AIO_CDA_ProductContext (Version: 140.0.425.000)
AIO_CDA_Software (Version: 140.0.428.000)
AIO_Scan (Version: 130.0.421.000)
AMD Accelerated Video Transcoding (Version: 12.5.100.21114)
AMD APP SDK Runtime (Version: 10.0.938.2)
AMD Catalyst Install Manager (Version: 8.0.881.0)
AMD VISION Engine Control Center (Version: 2012.1114.401.6988)
Back to the Future The Game (Version: 2.0.0.0)
BoneCraft (Version: 1.0.4)
BufferChm (Version: 140.0.298.000)
C5100 (Version: 140.0.425.000)
c5100_Help (Version: 82.0.256.000)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (Version: 2012.1114.401.6988)
Catalyst Control Center InstallProxy (Version: 2012.0704.2139.36919)
Catalyst Control Center Localization All (Version: 2012.1114.401.6988)
Catalyst Control Center Profiles Desktop (Version: 2012.1114.401.6988)
CCC Help Chinese Standard (Version: 2012.1114.0400.6988)
CCC Help Chinese Traditional (Version: 2012.1114.0400.6988)
CCC Help Czech (Version: 2012.1114.0400.6988)
CCC Help Danish (Version: 2012.1114.0400.6988)
CCC Help Dutch (Version: 2012.1114.0400.6988)
CCC Help English (Version: 2012.1114.0400.6988)
CCC Help Finnish (Version: 2012.1114.0400.6988)
CCC Help French (Version: 2012.1114.0400.6988)
CCC Help German (Version: 2012.1114.0400.6988)
CCC Help Greek (Version: 2012.1114.0400.6988)
CCC Help Hungarian (Version: 2012.1114.0400.6988)
CCC Help Italian (Version: 2012.1114.0400.6988)
CCC Help Japanese (Version: 2012.1114.0400.6988)
CCC Help Korean (Version: 2012.1114.0400.6988)
CCC Help Norwegian (Version: 2012.1114.0400.6988)
CCC Help Polish (Version: 2012.1114.0400.6988)
CCC Help Portuguese (Version: 2012.1114.0400.6988)
CCC Help Russian (Version: 2012.1114.0400.6988)
CCC Help Spanish (Version: 2012.1114.0400.6988)
CCC Help Swedish (Version: 2012.1114.0400.6988)
CCC Help Thai (Version: 2012.1114.0400.6988)
CCC Help Turkish (Version: 2012.1114.0400.6988)
ccc-utility64 (Version: 2012.1114.401.6988)
CCleaner (Version: 4.01)
Content Manager Assistant for PlayStation® (Version: 2.10.6402.20)
Copy (Version: 140.0.298.000)
CyberLink Media Suite 10 (Version: 10.0.2.2114)
CyberLink Power2Go 8 (Version: 8.0.2.2126)
CyberLink PowerDirector 10 (Version: 10.0.2.2126)
CyberLink PowerDVD (Version: 10.0.7.4605)
D3DX10 (Version: 15.4.2368.0902)
Destinations (Version: 140.0.253.000)
DeviceDiscovery (Version: 140.0.298.000)
Diablo III (Version: 1.0.8.16603)
doPDF 7.3 printer
Fax (Version: 140.0.307.000)
FileHippo.com Update Checker
Free RAR Extract Frog (Version: 4.70)
Google Chrome (Version: 27.0.1453.94)
Google Update Helper (Version: 1.3.21.145)
Hewlett-Packard ACLM.NET v1.2.1.1 (Version: 1.00.0000)
HP Connected Remote (Version: 1.0.1218)
HP Customer Experience Enhancements (Version: 6.0.1.7)
HP Imaging Device Functions 14.0 (Version: 14.0)
HP Photosmart All-In-One Driver Software (Version: 14.0)
HP Postscript Converter (Version: 3.1.3591)
HP Support Assistant (Version: 7.0.39.15)
HP Support Information (Version: 12.00.0000)
HP Update (Version: 5.002.006.003)
HPPhotoGadget (Version: 140.0.524.000)
HydraVision (Version: 4.2.236.0)
IDT Audio (Version: 1.0.6418.0)
Jurassic Park The Game (Version: 1.0.0.15)
Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
McAfee AntiVirus Plus (Version: 12.1.323)
McAfee Virtual Technician (Version: 7.1.0.2483)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Movie Maker (Version: 16.4.3503.0728)
Mozilla Firefox 21.0 (x86 en-US) (Version: 21.0)
Mozilla Maintenance Service (Version: 21.0)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT110 (Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1108.0727)
Network64 (Version: 140.0.306.000)
Next Generation Visualisations (Version: 1.0.0)
Photo Common (Version: 16.4.3503.0728)
Photo Gallery (Version: 16.4.3503.0728)
Print Artist Gold (Version: 24.0.1.2)
Ralink RT5390R 802.11bgn Wi-Fi Adapter (Version: 5.0.5.0)
RealDownloader (Version: 1.3.2)
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0)
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0)
RealPlayer (Version: 16.0.2)
RealUpgrade 1.1 (Version: 1.1.0)
Recovery Manager (Version: 5.5.0.5826)
Scan (Version: 140.0.253.000)
Shared C Run-time for x64 (Version: 10.0.0)
SpywareBlaster 5.0 (Version: 5.0.0)
Status (Version: 140.0.342.000)
The Walking Dead (Version: 1.0.0.15)
Toolbox (Version: 140.0.596.000)
TrayApp (Version: 140.0.297.000)
WebReg (Version: 140.0.297.017)
Windows Live Communications Platform (Version: 16.4.3503.0728)
Windows Live Essentials (Version: 16.4.3503.0728)
Windows Live Installer (Version: 16.4.3503.0728)
Windows Live Photo Common (Version: 16.4.3503.0728)
Windows Live PIMT Platform (Version: 16.4.3503.0728)
Windows Live SOXE (Version: 16.4.3503.0728)
Windows Live SOXE Definitions (Version: 16.4.3503.0728)
Windows Live UX Platform (Version: 16.4.3503.0728)
Windows Live UX Platform Language Pack (Version: 16.4.3503.0728)
World of Warcraft (Version: 5.2.0.16826)

==================== Restore Points =========================

15-05-2013 03:27:20 Windows Update
16-05-2013 20:00:56 McAfee Vulnerability Scanner
24-05-2013 02:40:53 Scheduled Checkpoint

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/27/2013 06:09:38 PM) (Source: Application Error) (User: )
Description: Faulting application name: McSmtFwk.exe, version: 4.1.185.0, time stamp: 0x50c7b310
Faulting module name: McSmtFwk.exe, version: 4.1.185.0, time stamp: 0x50c7b310
Exception code: 0xc0000005
Fault offset: 0x00000000000030a5
Faulting process id: 0x1b10
Faulting application start time: 0xMcSmtFwk.exe0
Faulting application path: McSmtFwk.exe1
Faulting module path: McSmtFwk.exe2
Report Id: McSmtFwk.exe3
Faulting package full name: McSmtFwk.exe4
Faulting package-relative application ID: McSmtFwk.exe5

Error: (05/27/2013 06:03:36 PM) (Source: Application Error) (User: )
Description: Faulting application name: McUICnt.exe, version: 5.1.169.0, time stamp: 0x50712b57
Faulting module name: McSmtStr.dll, version: 4.1.185.0, time stamp: 0x50c7b31e
Exception code: 0xc0000005
Fault offset: 0x000000000001db5c
Faulting process id: 0xc68
Faulting application start time: 0xMcUICnt.exe0
Faulting application path: McUICnt.exe1
Faulting module path: McUICnt.exe2
Report Id: McUICnt.exe3
Faulting package full name: McUICnt.exe4
Faulting package-relative application ID: McUICnt.exe5

Error: (05/27/2013 05:49:52 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/25/2013 05:57:59 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/25/2013 05:56:46 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/25/2013 05:45:06 PM) (Source: Application Error) (User: )
Description: Faulting application name: mcsacore.exe, version: 3.6.1.106, time stamp: 0x5134ca77
Faulting module name: ntdll.dll, version: 6.2.9200.16579, time stamp: 0x51637f77
Exception code: 0xc0000005
Fault offset: 0x000000000005ab00
Faulting process id: 0xe54
Faulting application start time: 0xmcsacore.exe0
Faulting application path: mcsacore.exe1
Faulting module path: mcsacore.exe2
Report Id: mcsacore.exe3
Faulting package full name: mcsacore.exe4
Faulting package-relative application ID: mcsacore.exe5

Error: (05/24/2013 06:25:54 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/23/2013 07:32:34 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/23/2013 07:30:11 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/21/2013 07:23:18 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.


System errors:
=============
Error: (05/28/2013 07:16:59 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 07:16:59 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 07:16:56 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 07:16:56 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 07:12:32 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 07:12:32 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 07:12:29 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 07:12:29 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 05:58:03 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

Error: (05/28/2013 05:57:33 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.


Microsoft Office Sessions:
=========================
Error: (05/27/2013 06:09:38 PM) (Source: Application Error)(User: )
Description: McSmtFwk.exe4.1.185.050c7b310McSmtFwk.exe4.1.185.050c7b310c000000500000000000030
a51b1001ce5a907840644aC:\PROGRA~1\COMMON~1\McAfee\Platform\MSM\McSmtFwk.exeC:\PROGRA~1\COMMON~1\McAfee\Platform\MSM\McSmtFwk.exe44169ca0-c733-11e2-be98-78e3b5ba207a

Error: (05/27/2013 06:03:36 PM) (Source: Application Error)(User: )
Description: McUICnt.exe5.1.169.050712b57McSmtStr.dll4.1.185.050c7b31ec0000005000000000001db5
cc6801ce5b3f2e7b416eC:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exeC:\PROGRA~1\COMMON~1\McAfee\Platform\MSM\McSmtStr.dll6c908930-c732-11e2-be98-78e3b5ba207a

Error: (05/27/2013 05:49:52 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe

Error: (05/25/2013 05:57:59 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe

Error: (05/25/2013 05:56:46 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe

Error: (05/25/2013 05:45:06 PM) (Source: Application Error)(User: )
Description: mcsacore.exe3.6.1.1065134ca77ntdll.dll6.2.9200.1657951637f77c0000005000000000005
ab00e5401ce58f5ce9aed01c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exeC:\windows\SYSTEM32\ntdll.dll81dd79fa-c59d-11e2-be97-78e3b5ba207a

Error: (05/24/2013 06:25:54 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe

Error: (05/23/2013 07:32:34 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe

Error: (05/23/2013 07:30:11 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe

Error: (05/21/2013 07:23:18 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe


==================== Memory info ===========================

Percentage of memory in use: 40%
Total physical RAM: 3991.29 MB
Available physical RAM: 2376.66 MB
Total Pagefile: 4695.29 MB
Available Pagefile: 2868.15 MB
Total Virtual: 8192 MB
Available Virtual: 8191.76 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:445.84 GB) (Free:329.33 GB) NTFS (Disk=0 Partition=4) ==>[System with boot components (obtained from reading drive)]
Drive d: (Recovery Image) (Fixed) (Total:18.44 GB) (Free:2.31 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 466 GB) (Disk ID: ABD9DDBB)

Partition: GPT Partition Type
==================== End Of Log ============================aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-05-28 19:40:18
—————————–
19:40:18.214 OS Version: Windows x64 6.2.9200
19:40:18.214 Number of processors: 4 586 0x1001
19:40:18.214 ComputerName: NWO UserName:
19:40:18.230 Initialze error 1
19:40:32.161 AVAST engine defs: 13052801
19:40:43.346 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000030
19:40:43.362 Disk 0 Vendor: ST500DM002-1BD142 HP73 Size: 476940MB BusType: 11
19:40:43.377 Disk 0 MBR read successfully
19:40:43.393 Disk 0 MBR scan
19:40:43.440 Disk 0 unknown MBR code
19:40:43.440 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
19:40:43.502 Disk 0 scanning C:\windows\system32\drivers
19:40:43.502 Service scanning
19:40:44.267 Modules scanning
19:40:44.267 Disk 0 trace - called modules:
19:40:44.267 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
19:40:44.267 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8005053060]
19:40:44.267 3 CLASSPNP.SYS[fffff8800143cfea] -> nt!IofCallDriver -> [0xfffffa8004671040]
19:40:44.282 5 amd_xata.sys[fffff88000edc634] -> nt!IofCallDriver -> \Device\00000030[0xfffffa8004676280]
19:40:44.282 AVAST engine scan C:\windows
19:40:44.298 AVAST engine scan C:\windows\system32
19:40:44.298 AVAST engine scan C:\windows\system32\drivers
19:40:44.298 AVAST engine scan C:\Users\Steven
19:40:44.313 AVAST engine scan C:\ProgramData
19:40:44.313 Scan finished successfully
19:41:43.095 Disk 0 MBR has been saved successfully to "C:\Users\Steven\Downloads\MBR.dat"
19:41:43.142 The log file has been saved successfully to "C:\Users\Steven\Downloads\Addition.txt"

Attachments:

Please run the following:

Please create a new system restore point before running Malwarebytes Anti-Rootkit if you can.

MBAR tutorial

Download Malwarebytes Anti-Rootkit from HERE
  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder….. mbar-log.txt and system-log.txt

~~~~~~~~~~~~~~~~~~~~~~~

Note:
If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
Internet access
Windows Update
Windows Firewall

If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot.
Verify that your system is now functioning normally.
No threats found. Malwarebytes Anti-Rootkit BETA 1.06.0.1003 www.malwarebytes.org Database version: v2013.05.29.01 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16580 Steven :: NWO [administrator] 5/28/2013 8:10:18 PM mbar-log-2013-05-28 (20-10-18).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P Scan options disabled: Deep Anti-Rootkit Scan | PUP Objects scanned: 231745 Time elapsed: 15 minute(s), 28 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) ————————————— Malwarebytes Anti-Rootkit BETA 1.06.0.1003 © Malwarebytes Corporation 2011-2012 OS version: 6.2.9200 Windows 8 x64 Account is Administrative Internet Explorer version: 10.0.9200.16580 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED CPU speed: 3.194000 GHz Memory total: 4185169920, free: 2267426816 Downloaded database version: v2013.05.29.01 Downloaded database version: v2013.05.22.01 Initializing… ———— Kernel report ———— 05/28/2013 20:10:14 ———— Loaded modules ———– \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_AuthenticAMD.dll \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\Drivers\cng.sys \SystemRoot\system32\drivers\tpm.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\amd_sata.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\amd_xata.sys \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\system32\drivers\mfehidk.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\DRIVERS\wfplwfs.sys \SystemRoot\system32\drivers\mfewfpk.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgmms1.sys \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\vwififlt.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \??\C:\Program Files\McAfee\AppStats\MfeASKM.sys \SystemRoot\System32\drivers\discache.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\CLVirtualDrive.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\System32\drivers\CompositeBus.sys \SystemRoot\system32\DRIVERS\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \SystemRoot\system32\DRIVERS\atikmpag.sys \SystemRoot\system32\DRIVERS\atikmdag.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\system32\DRIVERS\L1C63x64.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\System32\drivers\ucx01000.sys \SystemRoot\System32\Drivers\fastfat.SYS \SystemRoot\System32\drivers\usbohci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\drivers\usbfilter.sys \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\system32\DRIVERS\netr28x.sys \SystemRoot\System32\drivers\vwifibus.sys \SystemRoot\System32\drivers\amdppm.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\system32\DRIVERS\stwrt64.sys \SystemRoot\system32\DRIVERS\portcls.sys \SystemRoot\system32\DRIVERS\drmk.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\system32\drivers\AtihdW86.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\USBSTOR.SYS \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\drivers\kbdhid.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\system32\drivers\mfeavfk.sys \SystemRoot\system32\drivers\mfefirek.sys \SystemRoot\system32\DRIVERS\mfencbdc.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_amd_sata.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\drivers\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \SystemRoot\system32\DRIVERS\vwifimp.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\system32\drivers\WudfPf.sys \SystemRoot\system32\drivers\cfwids.sys \SystemRoot\system32\drivers\HipShieldK.sys \SystemRoot\system32\DRIVERS\cdfs.sys \SystemRoot\System32\drivers\condrv.sys \SystemRoot\system32\drivers\mfeapfk.sys \SystemRoot\System32\drivers\rdpvideominiport.sys \SystemRoot\System32\cdd.dll \??\C:\Users\Steven\AppData\Local\Temp\aswMBR.sys \??\C:\windows\system32\drivers\mbamchameleon.sys \??\C:\windows\system32\drivers\mbamswissarmy.sys ———– End ———– Done! <<<1>>> Upper Device Name: \Device\Harddisk4\DR4 Upper Device Object: 0xfffffa80066ed740 Upper Device Driver Name: \Driver\disk\ Lower Device Name: \Device\0000004f\ Lower Device Object: 0xfffffa80066f6b00 Lower Device Driver Name: \Driver\USBSTOR\ <<<1>>> Upper Device Name: \Device\Harddisk3\DR3 Upper Device Object: 0xfffffa80066f1740 Upper Device Driver Name: \Driver\disk\ Lower Device Name: \Device\0000004e\ Lower Device Object: 0xfffffa80066f0060 Lower Device Driver Name: \Driver\USBSTOR\ <<<1>>> Upper Device Name: \Device\Harddisk2\DR2 Upper Device Object: 0xfffffa80066ef740 Upper Device Driver Name: \Driver\disk\ Lower Device Name: \Device\0000004d\ Lower Device Object: 0xfffffa80066f6060 Lower Device Driver Name: \Driver\USBSTOR\ <<<1>>> Upper Device Name: \Device\Harddisk1\DR1 Upper Device Object: 0xfffffa80066f0740 Upper Device Driver Name: \Driver\disk\ Lower Device Name: \Device\0000004c\ Lower Device Object: 0xfffffa80066f2060 Lower Device Driver Name: \Driver\USBSTOR\ <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xfffffa8005053060 Upper Device Driver Name: \Driver\disk\ Lower Device Name: \Device\00000030\ Lower Device Object: 0xfffffa8004676280 Lower Device Driver Name: \Driver\amd_sata\ <<<2>>> Device number: 0, partition: 4 Physical Sector Size: 512 Drive: 0, DevicePointer: 0xfffffa8005053060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ ——— Disk Stack —— DevicePointer: 0xfffffa8004f8c980, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa8005053060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ DevicePointer: 0xfffffa8004671040, DeviceName: Unknown, DriverName: \Driver\amd_xata\ DevicePointer: 0xfffffa8004676280, DeviceName: \Device\00000030\, DriverName: \Driver\amd_sata\ ———— End ———- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 Partition type: GUID <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> Device number: 0, partition: 4 Partition type: GUID <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\windows\system32\drivers… <<<2>>> Device number: 0, partition: 4 Partition type: GUID <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Done! Drive 0 Scanning MBR on drive 0… Inspecting partition table: This drive is a GPT Drive. MBR Signature: 55AA Disk Signature: ABD9DDBB GPT Protective MBR Partition information: Partition 0 type is EFI-GPT (0xee) Partition is NOT ACTIVE. Partition starts at LBA: 1 Numsec = 4294967295 Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 GPT Partition information: GPT Header Signature 4546492050415254 GPT Header Revision 65536 Size 92 CRC 3097122270 GPT Header CurrentLba = 1 BackupLba 976773167 GPT Header FirstUsableLba 34 LastUsableLba 976773134 GPT Header Guid 92d7739a-7db4-4e75-86d1-8de02b9c2fbd GPT Header Contains 128 partition entries starting at LBA 2 GPT Header Partition entry size = 128 Backup GPT header Signature 4546492050415254 Backup GPT header Revision 65536 Size 92 CRC 3097122270 Backup GPT header CurrentLba = 976773167 BackupLba 1 Backup GPT header FirstUsableLba 34 LastUsableLba 976773134 Backup GPT header Guid 92d7739a-7db4-4e75-86d1-8de02b9c2fbd Backup GPT header Contains 128 partition entries starting at LBA 976773135 Backup GPT header Partition entry size = 128 Partition 0 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac Partition ID e29e510a-b962-4886-bc63-3b5942ae2bf3 FirstLBA 2048 Last LBA 2097151 Attributes 1 Partition Name Basic data partition Partition 1 Type c12a7328-f81f-11d2-ba4b-0a0c93ec93b Partition ID 4a56b14e-bd47-49db-bd2c-6c4bbaca4f5b FirstLBA 2097152 Last LBA 2834431 Attributes 0 Partition Name EFI system partition GPT Partition 1 is bootable Partition 2 Type e3c9e316-b5c-4db8-817d-f92df0215ae Partition ID 675d07dd-7f57-42a3-b5c7-36d20c92b96 FirstLBA 2834432 Last LBA 3096575 Attributes 0 Partition Name Microsoft reserved partition Partition 3 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7 Partition ID 3bfbf56d-b39c-4c45-a7e2-da93d4aabee FirstLBA 3096576 Last LBA 938098687 Attributes 0 Partition Name Basic data partition Partition 4 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7 Partition ID 312b29e1-28d0-4a28-8be8-f3ed75275ff4 FirstLBA 938098688 Last LBA 976773119 Attributes 1 Partition Name Basic data partition Disk Size: 500107862016 bytes Sector size: 512 bytes Done! Physical Sector Size: 0 Drive: 1, DevicePointer: 0xfffffa80066f0740, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\ ——— Disk Stack —— DevicePointer: 0xfffffa80066f65b0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa80066f0740, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\ DevicePointer: 0xfffffa80066f2060, DeviceName: \Device\0000004c\, DriverName: \Driver\USBSTOR\ ———— End ———- Physical Sector Size: 0 Drive: 2, DevicePointer: 0xfffffa80066ef740, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\disk\ ——— Disk Stack —— DevicePointer: 0xfffffa80066ee290, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa80066ef740, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\disk\ DevicePointer: 0xfffffa80066f6060, DeviceName: \Device\0000004d\, DriverName: \Driver\USBSTOR\ ———— End ———- Physical Sector Size: 0 Drive: 3, DevicePointer: 0xfffffa80066f1740, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\disk\ ——— Disk Stack —— DevicePointer: 0xfffffa80066ed040, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa80066f1740, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\disk\ DevicePointer: 0xfffffa80066f0060, DeviceName: \Device\0000004e\, DriverName: \Driver\USBSTOR\ ———— End ———- Physical Sector Size: 0 Drive: 4, DevicePointer: 0xfffffa80066ed740, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\disk\ ——— Disk Stack —— DevicePointer: 0xfffffa80066eeb10, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa80066ed740, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\disk\ DevicePointer: 0xfffffa80066f6b00, DeviceName: \Device\0000004f\, DriverName: \Driver\USBSTOR\ ———— End ———- Scan finished ======================================= Removal queue found; removal started Removing c:\programdata\malwarebytes' anti-malware (portable)\mbr_0_i.mbam… Removing c:\programdata\malwarebytes' anti-malware (portable)\mbr_0_r.mbam… Removal finished
Did you check if your AV and Firewall were now running?

If not did you run the fix damage tool as per the instructions

(it is located in the Malwarebytes Anti-Rootkit folder > Locate fixdamage.exe within the \mbar\Plugins folder )

If you have already run fixdamage.exe and it did not resolve the issue, then please run the following:


  • Please download MiniToolBox and save it to your desktop and run it.

    Checkmark following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Report FF Proxy Settings
  • List content of Hosts
  • List installed programs.

Click Go and post the result (Result.txt) that pops up. A copy of result.txt will be saved in the same directory the tool is run.


NEXT


Please download Farbar Service Scanner to your desktop and run it.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
Yes everything seems to be running normally now, not sure if anything was removed during these scans but it seems to have done the trick.
Good,

The fix damage tool likely rectified the issue.
There are a couple more scans I'd like you to run to make certain there are no leftovers:

please do the following:


Please download Junkware Removal Tool to your desktop.
  • Shutdown your antivirus to avoid any conflicts.
  • Right-mouse click JRT.exe and select Run as administrator
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message


NEXT


Download AdwCleaner from here and save it to your desktop.
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply


NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Here are my reports, for the ESET Scanner nothing was found so no report was made. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows 8 x64 Ran by [removed] on Sat 06/01/2013 at 12:49:19.12 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{609B3C92-2746-4672-A74B-B25433917B3A} Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{609B3C92-2746-4672-A74B-B25433917B3A} Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\microsoft\Internet Explorer\SearchScopes\{609B3C92-2746-4672-A74B-B25433917B3A} ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Steven\AppData\Roaming\mozilla\firefox\profiles\irbmtnh0.default\minidumps [2 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Sat 06/01/2013 at 12:53:23.48 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ # AdwCleaner v2.301 - Logfile created 06/01/2013 at 12:57:11 # Updated 16/05/2013 by Xplode # Operating system : Windows 8 (64 bits) # User : Steven - NWO # Boot Mode : Normal # Running from : C:\Users\Steven\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** ***** [Registry] ***** ***** [Internet Browsers] ***** -\\ Internet Explorer v10.0.9200.16537 [OK] Registry is clean. -\\ Mozilla Firefox v21.0 (en-US) File : C:\Users\Steven\AppData\Roaming\Mozilla\Firefox\Profiles\irbmtnh0.default\prefs.js [OK] File is clean. -\\ Google Chrome v27.0.1453.94 File : C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [781 octets] - [01/06/2013 12:57:11] ########## EOF - C:\AdwCleaner[S1].txt - [840 octets] ########## Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.06.01.04 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16580 Steven :: NWO [administrator] 6/1/2013 1:01:30 PM mbam-log-2013-06-01 (13-01-30).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 213380 Time elapsed: 4 minute(s), 10 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Everything is looking good, firewall and antivirus is staying on. Seems everything is looking great, knock on wood. Thank you for your patience and help with this matter.
We just have some housekeeping to do now,

Please do the following:


You can delete the FRST, JRT, MBAR and aswMBR logs and programs from your desktop.



NEXT

  • Double click on adwcleaner.exe to run the tool.
  • Click on Uninstall.
  • Confirm with yes.


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    PC Safety and Security–What Do I Need?.
  • Simple and easy ways to keep your computer safe and secure on the Internet

Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
I have run the cleanup and everything is still looking good. I will follow those helpful tips to prevent future infections. Thank you again for your help.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI