This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet Connect Suddenly 80-90% slower! Help [Closed]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I can't figure out why it's so dang slow… but I'm pretty sure it happened after I downloaded a file from a bit-torrent site.

I'm sure I'll get the standard you deserve it response… but I've used this site many times and haven't had any problems for a long long time.

Avast quick scan isn't finding anything… but something happened that messed with my dns servers… I'm running Windows 7 64 bit and I got the msg
"You computer seems to be correctly configured, but your dns server is not responding."

thanks for any help… here is my HiJack This Log.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:17:09 AM, on 8/21/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16660)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\XFastUsb\XFastUsb.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
C:\Program Files (x86)\ASRock Utility\InstantBoot\InstantBoot.exe
C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Seven\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: uTorrentControl2 - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Adobe Acrobat Create PDF Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
O3 - Toolbar: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
O3 - Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [TrayServer] C:\Program Files (x86)\MAGIX\Movie_Edit_Pro_17_Plus_Download_Version\TrayServer_en.exe
O4 - HKLM\..\Run: [XFastUsb] "C:\Program Files (x86)\XFastUsb\XFastUsb.exe"
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" update "Software\CyberLink\PowerProducer\5.0"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [AcronisTibMounterMonitor] C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
O4 - HKLM\..\Run: [F5D7050v3] C:\Program Files (x86)\Belkin\F5D7050v3\Belkinwcui.exe
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" –auto-start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Seven\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Device Detector 3.lnk = C:\Program Files (x86)\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office10\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted IP range: http://127.0.0.1
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553542500} - http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2B732425-D1AC-489F-876B-1D9D4B74EF4D}: NameServer = 192.168.1.1
O20 - AppInit_DLLs: C:\Windows\SysWOW64\appinit_dll.dll
O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files (x86)\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Acronis Nonstop Backup Service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: cFosSpeed System Service (cFosSpeedS) - cFos Software GmbH - C:\Program Files\ASRock\XFast LAN\spd.exe
O23 - Service: CyberLink Product - 2011/06/19 08:14:31 (CLKMSVC10_90970B6B) - CyberLink - C:\Program Files (x86)\CyberLink\PowerProducer\BDSDK\NavFilter\kmsvc.exe
O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Acronis OS Selector activator (OS Selector) - Unknown owner - C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Acronis Sync Agent Service (syncagentsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 14745 bytes
Hello, Glitch . Welcome to WTT Forums.

My name is fbfbfb.

I will gladly assist you with your malware concerns. Malware logs may require some time to analyze, and because there is no quick-fix solution, we may need to use various approaches to clean your system. Please be patient.

While working to resolve the issues with your machine, please note the following guidelines:
  • Read and follow my directions carefully, in the sequence they are posted.
  • If you are unsure about anything, please ask for clarification before continuing.
  • To avoid potential problems and setbacks, do not:

  • install or uninstall any applications while your system is being cleaned.
  • use any tools other than those recommended.
  • run any other scans without being directed to do so.

  • Copy and Paste the log files inside your posts. Do not send them as attachments unless otherwise instructed.
  • Stay with this thread until your machine has been deemed all clear. Absence of symptoms does not mean your system is clear.
  • Please reply within 3 days of each posting to avoid closing this topic. If you need more time to complete tasks, or if you will be away, please let me know in advance.
Please run the following scans

1. DDS

Please download DDS from HERE. Click Save File. The file will save to your default location.
  • Disable any script blocking protection. (How to Temporarily Disable Security Programs: Anti-virus/Anti-spyware/Firewall)
  • Double click dds.com > Click Run.
  • At the next prompt, ensure check marks appear next to dds.com and attach.txt > Click Start to begin the scan. When done, click OK to close the DDS window.
  • Two reports will automatically open: dds.txt and Attach.txt. These reports are also saved to your desktop.
Please copy and paste the scan results of DDS.txt.

2. aswMBR

Please download aswMBR from HERE.
  • Double click aswMBR.exe to run it.
  • When asked if you want to download Avast's virus definitions, please select Yes.
  • Click the Scan button to start the scan.
[external image: Posted Image]
  • On completion of the scan, click save log, save it to your desktop, and post in your next reply.
[external image: Posted Image]


Please attach the second file: Attach.txt.

To attach a file, do the following:
  • Under the reply panel is the Attachments Panel.
  • Browse for the attachment file you want to upload, then click the green Upload button.
  • Once it has uploaded, click the Manage Current Attachments drop down box.
  • Click on [external image: Posted Image] to insert the attachment into your post.
Hmmm… OK thx.

I kinda figured the HJT Log would help… I thought you guys still use that… oh well.

Here is the info you asked for.

DDS.txt

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16660 BrowserJavaVersion: 10.25.2
Run by [removed] at 20:17:08 on 2013-08-22
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.15849.13342 [GMT -10:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ASRock\XFast LAN\cfosspeed.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Eraser\Eraser.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files (x86)\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\XFastUsb\XFastUsb.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Program Files\ASRock\XFast LAN\spd.exe
C:\Program Files (x86)\ASRock Utility\InstantBoot\InstantBoot.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\CyberLink\Shared files\RichVideo64.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\AUDIODG.EXE
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
mURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 : {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Adobe Acrobat Create PDF Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: Adobe Acrobat Create PDF from Selection: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
TB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
TB: uTorrentControl2 Toolbar: {687578B9-7132-4A7A-80E4-30EE31099E03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
TB: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
TB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
uRun: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide
uRun: [ASRockXTU]
mRun: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
mRun: [TrayServer] C:\Program Files (x86)\MAGIX\Movie_Edit_Pro_17_Plus_Download_Version\TrayServer_en.exe
mRun: [XFastUsb] "C:\Program Files (x86)\XFastUsb\XFastUsb.exe"
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" update "Software\CyberLink\PowerProducer\5.0"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe" /r
mRun: [UpdReg] C:\Windows\UpdReg.EXE
mRun: [TrueImageMonitor.exe] "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe"
mRun: [AcronisTibMounterMonitor] C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
mRun: [F5D7050v3] C:\Program Files (x86)\Belkin\F5D7050v3\Belkinwcui.exe
mRun: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" –auto-start
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
mRun: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe"
StartupFolder: C:\Users\Seven\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\DEVICE~1.LNK - C:\Program Files (x86)\Olympus\DeviceDetector\DevDtct2.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MICROS~1.LNK - C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE
uPolicies-Explorer: HideSCAHealth = dword:1
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office10\EXCEL.EXE/3000
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553542500} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 207.69.188.186 207.69.188.187
TCP: Interfaces\{2B732425-D1AC-489F-876B-1D9D4B74EF4D} : NameServer = 192.168.1.1
TCP: Interfaces\{2B732425-D1AC-489F-876B-1D9D4B74EF4D} : DHCPNameServer = [removed] [removed]
TCP: Interfaces\{5DB94730-52E9-4CC4-9A29-E05933C826A8} : DHCPNameServer = [removed] [removed]
TCP: Interfaces\{64695011-CCC3-4D9B-A6B8-6F93A6833A2D} : DHCPNameServer = [removed] [removed]
TCP: Interfaces\{90457221-519E-450B-BC72-D25623377D8B} : DHCPNameServer = [removed] [removed]
TCP: Interfaces\{A2C325CE-90B5-4CD1-AA0E-A7AA83AC1E87} : DHCPNameServer = [removed] [removed]
TCP: Interfaces\{BE254A87-FF09-4169-B7C5-E42000285EC0} : DHCPNameServer = [removed] [removed]
TCP: Interfaces\{F25F42B7-27CE-41D5-B50F-BAFA2F7930E5} : DHCPNameServer = [removed] [removed]
AppInit_DLLs= C:\Windows\SysWOW64\appinit_dll.dll
SSODL: WebCheck -
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [THXCfg64] C:\Windows\System32\RunDLL32.exe C:\Windows\System32\THXCfg64.dll,RunDLLEntry THXCfg64
x64-Run: [XFast LAN] C:\Program Files\ASRock\XFast LAN\cFosSpeed.exe
x64-Run: [VIRTU] C:\Program Files\Lucidlogix Technologies\VIRTU\VirtuControlPanel.Exe /hide
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [Acronis Scheduler2 Service] "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck -
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Seven\AppData\Roaming\Mozilla\Firefox\Profiles\xlrz96d1.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
FF - plugin: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Users\Seven\AppData\Local\Citrix\Plugins\104\npappdetector.dll
FF - plugin: C:\Users\Seven\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Users\Seven\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Seven\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Users\Seven\AppData\Roaming\Mozilla\plugins\npo1d.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-08-18 18:16; [removed]; C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
.
—- FIREFOX POLICIES —-
FF - user.js: general.useragent.extra.brc -
.
============= SERVICES / DRIVERS ===============
.
R0 AsrRamDisk;AsrRamDisk;C:\Windows\System32\drivers\AsrRamDisk.sys [2012-4-11 31016]
R0 fltsrv;Acronis Storage Filter Management;C:\Windows\System32\drivers\fltsrv.sys [2013-6-30 108832]
R0 mrdd;Marvell Removable Disk Control Driver;C:\Windows\System32\drivers\mrdd.sys [2010-2-28 22568]
R0 mv61xx;mv61xx;C:\Windows\System32\drivers\mv61xx.sys [2009-5-11 178728]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2013-7-29 56208]
R0 Si3124r5;SiI-3124 SoftRaid 5 Controller;C:\Windows\System32\drivers\Si3124r5.sys [2010-4-13 340008]
R0 tib;Acronis TIB Manager;C:\Windows\System32\drivers\tib.sys [2013-6-30 1120032]
R0 tib_mounter;Acronis TIB Mounter;C:\Windows\System32\drivers\tib_mounter.sys [2013-6-30 183224]
R0 vididr;Acronis Virtual Disk;C:\Windows\System32\drivers\vididr.sys [2013-6-30 161568]
R0 vidsflt;Acronis Disk Storage Filter;C:\Windows\System32\drivers\vidsflt.sys [2013-6-30 117024]
R1 AsrAppCharger;AsrAppCharger;C:\Windows\System32\drivers\AsrAppCharger.sys [2011-6-8 15368]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2011-7-3 591192]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2010-3-1 304472]
R1 FNETURPX;FNETURPX;C:\Windows\System32\drivers\FNETURPX.SYS [2011-6-8 15936]
R1 xlkfs;xlkfs;C:\Windows\System32\drivers\xlkfs.sys [2012-5-4 30456]
R2 afcdpsrv;Acronis Nonstop Backup Service;C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2013-6-30 3783672]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2010-3-1 24408]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2010-3-1 66904]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2012-1-12 44768]
R2 cpuz135;cpuz135;C:\Windows\System32\drivers\cpuz135_x64.sys [2011-6-8 21992]
R2 Fabs;FABS - Helping agent for MAGIX media database;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2011-5-24 1840128]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2013-6-28 2470736]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-6-11 13592]
R2 OS Selector;Acronis OS Selector activator;C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe [2010-9-29 2139400]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS);C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2011-6-19 386344]
R2 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-1-18 383264]
R2 syncagentsrv;Acronis Sync Agent Service;C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [2013-3-20 7084672]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-6-8 2656280]
R3 afcdp;afcdp;C:\Windows\System32\drivers\afcdp.sys [2013-6-30 367200]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-6-8 317440]
R3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\System32\drivers\lvrs64.sys [2012-9-21 351520]
R3 LVUVC64;Logitech HD Pro Webcam C920(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2012-9-21 4763680]
R3 netr7364;Belkin Wireless 54G USB Network Adapter Driver;C:\Windows\System32\drivers\netr7364.sys [2013-6-30 716800]
R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2010-2-3 134760]
R3 VirtuWDDM;VirtuWDDM;C:\Windows\System32\drivers\VirtuWDDM.sys [2013-3-25 66336]
S2 CLKMSVC10_90970B6B;CyberLink Product - 2011/06/19 08:14:31;C:\Program Files (x86)\CyberLink\PowerProducer\BDSDK\NavFilter\kmsvc.exe [2010-11-9 246256]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2011-4-26 2702848]
S3 FNETTBOH_305;FNETTBOH_305;C:\Windows\System32\drivers\FNETTBOH_305.SYS [2011-6-9 32320]
S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2011-2-14 412712]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2011-4-6 20992]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-4-6 59392]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-6-8 1255736]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-5-19 393728]
.
=============== File Associations ===============
.
FileExt: .exe: wa="%1" %*
FileExt: .ini: Applications\SciTE.exe="D:\Program Files\Scintilla Text Editor\SciTE.exe" "%1" [UserChoice]
FileExt: .js: jsfile="C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"
ShellExec: dreamweaver.exe: Open="C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\dreamweaver.exe", "%1"
.
=============== Created Last 30 ================
.
2050-07-29 01:07:22 ——– d—–w- C:\Users\Seven\AppData\Roaming\TechSmith
2050-07-29 01:04:43 ——– d—–w- C:\Users\Seven\AppData\Roaming\iZotope
2050-07-29 01:03:12 ——– d—–w- C:\Program Files\Common Files\VST3
2050-07-29 01:03:11 ——– d—–w- C:\Program Files (x86)\Common Files\VST3
2050-07-29 01:03:10 ——– d—–w- C:\Program Files\Vstplugins
2050-07-29 01:03:09 ——– d—–w- C:\Program Files (x86)\Vstplugins
2050-07-29 01:03:08 ——– d—–w- C:\Program Files (x86)\iZotope
2050-07-29 01:03:08 ——– d—–w- C:\Program Files (x86)\Common Files\Digidesign
2013-08-21 09:43:14 ——– d—–w- C:\Program Files (x86)\Compact Wireless-G USB Adapter Wireless Network Monitor
2013-08-21 08:09:08 ——– d—–w- C:\Users\Seven\AppData\Local\ElevatedDiagnostics
2013-08-21 07:59:09 ——– d—–w- C:\Program Files\CCleaner
2013-08-21 07:23:01 ——– d—–w- C:\Program Files\SAMSUNG
2013-08-21 07:22:46 ——– d—–w- C:\ProgramData\Samsung
2013-08-21 07:08:52 ——– d—–w- C:\Program Files (x86)\Intel Android Device USB driver
2013-08-20 16:53:22 ——– d—–w- C:\Program Files (x86)\DGMPG
2013-08-19 04:13:39 ——– d—–w- C:\Users\Seven\AppData\Roaming\com.adobe.formscentral.FormsCentralForAcrobat
2013-08-15 07:02:08 ——– d—–w- C:\Users\Seven\AppData\Local\Logitech® Webcam Software
2013-08-15 06:58:06 53248 —-a-r- C:\Users\Seven\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2013-08-15 04:36:39 ——– d—–w- C:\Windows\64F6748976BB4CDDA236F954BE774B35.TMP
2013-08-15 04:36:38 ——– d—–w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-08-15 04:22:37 ——– d—–w- C:\Program Files (x86)\Activision
2013-08-15 04:21:43 ——– d-sh–w- C:\Windows\ftpcache
2013-08-14 16:33:53 224256 —-a-w- C:\Windows\System32\wintrust.dll
2013-07-30 07:03:50 ——– d—–w- C:\Users\Seven\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-07-30 06:55:32 ——– d—–w- C:\ProgramData\regid.1986-12.com.adobe
2013-07-30 06:50:33 ——– d—–w- C:\Users\Seven\AppData\Roaming\PACE Anti-Piracy
2013-07-30 06:50:33 ——– d—–w- C:\Users\Seven\AppData\Local\PACE Anti-Piracy
2013-07-30 06:50:33 ——– d—–w- C:\ProgramData\PACE Anti-Piracy
2013-07-30 06:50:33 ——– d—–w- C:\Program Files\Common Files\PACE Anti-Piracy
2013-07-30 06:15:38 ——– d—–w- C:\ProgramData\ALM
2013-07-30 06:13:12 ——– d—–w- C:\Users\Seven\Adobe Flash Builder 4.6
2013-07-30 06:07:33 56208 ——w- C:\Windows\System32\drivers\PxHlpa64.sys
2013-07-30 06:07:33 10224 ——w- C:\Windows\System32\drivers\cdralw2k.sys
2013-07-30 06:07:33 10224 ——w- C:\Windows\System32\drivers\cdr4_xp.sys
2013-07-29 07:36:38 ——– d—–w- C:\Program Files (x86)\Prezi Desktop 4
2013-07-29 07:32:51 ——– d—–w- C:\Users\Seven\AppData\Roaming\com.prezi.PreziDesktop
2013-07-29 03:31:33 ——– d—–w- C:\Windows\System32\MRT
2013-07-29 00:51:24 ——– d—–w- C:\Program Files (x86)\Common Files\TechSmith Shared
.
==================== Find3M ====================
.
2013-08-21 01:25:02 71048 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-21 01:25:02 692104 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-07-26 05:13:37 2241024 —-a-w- C:\Windows\System32\wininet.dll
2013-07-26 05:12:08 3958784 —-a-w- C:\Windows\System32\jscript9.dll
2013-07-26 05:12:04 136704 —-a-w- C:\Windows\System32\iesysprep.dll
2013-07-26 05:12:03 67072 —-a-w- C:\Windows\System32\iesetup.dll
2013-07-26 03:35:08 2706432 —-a-w- C:\Windows\System32\mshtml.tlb
2013-07-26 03:13:24 1767936 —-a-w- C:\Windows\SysWow64\wininet.dll
2013-07-26 03:12:04 2877440 —-a-w- C:\Windows\SysWow64\jscript9.dll
2013-07-26 03:12:00 61440 —-a-w- C:\Windows\SysWow64\iesetup.dll
2013-07-26 03:12:00 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll
2013-07-26 02:49:14 2706432 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2013-07-26 02:39:38 89600 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-07-26 01:59:38 71680 —-a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-07-25 09:25:54 1888768 —-a-w- C:\Windows\System32\WMVDECOD.DLL
2013-07-25 08:57:27 1620992 —-a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58:42 2048 —-a-w- C:\Windows\System32\tzres.dll
2013-07-19 01:41:01 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2013-07-10 20:15:28 96168 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-10 20:15:28 867240 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-07-10 20:15:28 789416 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2013-07-09 06:03:30 5550528 —-a-w- C:\Windows\System32\ntoskrnl.exe
2013-07-09 05:54:22 1732032 —-a-w- C:\Windows\System32\ntdll.dll
2013-07-09 05:53:12 243712 —-a-w- C:\Windows\System32\wow64.dll
2013-07-09 05:51:16 1217024 —-a-w- C:\Windows\System32\rpcrt4.dll
2013-07-09 05:46:20 184320 —-a-w- C:\Windows\System32\cryptsvc.dll
2013-07-09 05:46:20 1472512 —-a-w- C:\Windows\System32\crypt32.dll
2013-07-09 05:46:20 139776 —-a-w- C:\Windows\System32\cryptnet.dll
2013-07-09 05:03:34 3968960 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-07-09 05:03:34 3913664 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-07-09 04:53:47 1292192 —-a-w- C:\Windows\SysWow64\ntdll.dll
2013-07-09 04:52:33 663552 —-a-w- C:\Windows\SysWow64\rpcrt4.dll
2013-07-09 04:52:33 5120 —-a-w- C:\Windows\SysWow64\wow32.dll
2013-07-09 04:52:10 175104 —-a-w- C:\Windows\SysWow64\wintrust.dll
2013-07-09 04:46:31 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-07-09 04:46:31 1166848 —-a-w- C:\Windows\SysWow64\crypt32.dll
2013-07-09 04:46:31 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll
2013-07-09 04:45:07 44032 —-a-w- C:\Windows\apppatch\acwow64.dll
2013-07-09 02:49:42 25600 —-a-w- C:\Windows\SysWow64\setup16.exe
2013-07-09 02:49:41 7680 —-a-w- C:\Windows\SysWow64\instnm.exe
2013-07-09 02:49:39 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll
2013-07-09 02:49:38 2048 —-a-w- C:\Windows\SysWow64\user.exe
2013-07-06 06:03:53 1910208 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2013-07-01 05:29:34 716800 —-a-w- C:\Windows\System32\drivers\netr7364.sys
2013-06-30 20:33:58 367200 —-a-w- C:\Windows\System32\drivers\afcdp.sys
2013-06-30 20:33:55 1462560 —-a-w- C:\Windows\System32\drivers\tdrpman.sys
2013-06-30 20:33:54 183224 —-a-w- C:\Windows\System32\drivers\tib_mounter.sys
2013-06-30 20:33:54 161568 —-a-w- C:\Windows\System32\drivers\vididr.sys
2013-06-30 20:33:54 1120032 —-a-w- C:\Windows\System32\drivers\tib.sys
2013-06-30 20:33:53 117024 —-a-w- C:\Windows\System32\drivers\vidsflt.sys
2013-06-30 20:33:50 233760 —-a-w- C:\Windows\System32\drivers\snapman.sys
2013-06-30 20:33:50 108832 —-a-w- C:\Windows\System32\drivers\fltsrv.sys
2013-06-30 01:31:03 971360 —-a-w- C:\Windows\System32\drivers\timntr.sys
2013-06-15 04:35:40 1111552 —-a-w- C:\Windows\System32\rdpcorets.dll
2013-06-15 04:32:16 39936 —-a-w- C:\Windows\System32\drivers\tssecsrv.sys
2013-06-05 03:34:27 3153920 —-a-w- C:\Windows\System32\win32k.sys
2013-06-04 06:00:13 624128 —-a-w- C:\Windows\System32\qedit.dll
2013-06-04 04:53:07 509440 —-a-w- C:\Windows\SysWow64\qedit.dll
2008-12-11 02:14:40 4411392 —-a-w- C:\Program Files (x86)\mplayerc.exe
.
============= FINISH: 20:17:18.28 ===============


aswMBR.txt

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-08-22 20:30:32
—————————–
20:30:32.348 OS Version: Windows x64 6.1.7601 Service Pack 1
20:30:32.348 Number of processors: 8 586 0x2A07
20:30:32.348 ComputerName: SEVEN64-PC UserName: Seven
20:30:32.535 Initialize success
20:30:32.723 AVAST engine defs: 13082201
20:30:35.671 Disk 0 \Device\Harddisk0\DR0 -> \Device\00000083
20:30:35.671 Disk 0 Vendor: ST4000DM CC52 Size: 3815447MB BusType: 11
20:30:35.687 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\00000084
20:30:35.687 Disk 1 Vendor: OCZ-VECT 2.0_ Size: 122104MB BusType: 11
20:30:35.687 Disk 1 MBR read successfully
20:30:35.687 Disk 1 MBR scan
20:30:35.687 Disk 1 Windows XP default MBR code
20:30:35.702 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 55 MB offset 2048
20:30:35.702 Disk 1 Partition 2 00 07 HPFS/NTFS NTFS 122048 MB offset 114688
20:30:35.702 Disk 1 scanning C:\Windows\system32\drivers
20:30:37.169 Service scanning
20:30:40.788 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
20:30:42.083 Modules scanning
20:30:42.083 Disk 1 trace - called modules:
20:30:42.098 ntoskrnl.exe CLASSPNP.SYS disk.sys vidsflt.sys >>UNKNOWN [0xfffffa800d9672c0]< 20:30:42.098 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xfffffa8011692790]
20:30:42.114 3 CLASSPNP.SYS[fffff88000faa43f] -> nt!IofCallDriver -> [0xfffffa800e128e00]
20:30:42.114 5 vidsflt.sys[fffff88000f385f1] -> nt!IofCallDriver -> \Device\00000084[0xfffffa800dc397a0]
20:30:42.114 \Driver\mvs91xx[0xfffffa800dc36060] -> IRP_MJ_CREATE -> 0xfffffa800d9672c0
20:30:42.223 AVAST engine scan C:\Windows
20:30:42.410 AVAST engine scan C:\Windows\system32
20:31:12.284 AVAST engine scan C:\Windows\system32\drivers
20:31:13.813 AVAST engine scan C:\Users\Seven
20:31:27.057 File: C:\Users\Seven\Pictures\3dmark\kgn_pcmark.exe **INFECTED** Win32:Malware-gen
20:31:28.025 AVAST engine scan C:\ProgramData
20:31:37.712 Scan finished successfully
20:35:21.029 Disk 1 MBR has been saved successfully to "C:\Users\Seven\Desktop\MBR.dat"
20:35:21.032 The log file has been saved successfully to "C:\Users\Seven\Desktop\aswMBR.txt"


attach.txt is attached.

thanks for the help

Attachments:

Quick Note… I have a large file on my server that I download to test my speeds… I was getting like 10-20 KB/s but after running the aswMBR I'm now getting 200+KB/s. I used to get 700+KB/s… so it's not a complete fix.. but I think aswMBR stopped a service or something, it's noticable faster now.
Hello, Glitch.

Thank you for your DDS and aswMBR logs. The HJT log that you submitted was a good starting point, but we ask for additional logs as they provide greater details of your system, and therefore, we can apply the best solution to address the problem(s).

You stated that you downloaded a cracked version of Adobe Master Suite from a bit-torrent site. Before we continue, I need to make you aware that it is the policy of WhattheTech not to support the use of illegal Pirated/Warez/Cracked software. Helping a person who insists on using such software, could be construed in the eyes of the law to be aiding and abetting a crime.

I will be happy to continue helping you rid your computer of malware, but you will first need to remove any cracked programs.

When you are ready to move forward, please post back.
Hello, Glitch.

Thank you for removing the cracked software. Let’s work on cleaning your system first and see if that resolves your computer’s speed.

P2P Program

I see you have P2P software (uTorrent) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P file sharing as a major conduit to spread their wares.

Please see this topic for more information: Perils of P2P File Sharing.

I would strongly recommend that you uninstall this now. You can do so via Control Panel:
  • Click Start and select Control Panel.
  • When the Control Panel window opens, click on Uninstall a program found under the Programs category.
  • If you are using the Classic View of the Control Panel, then you would double-click on the Programs and Features icon instead.
  • Look through the list of programs for the one that you would like to uninstall, and then left-click on it once to highlight it.
  • Click on the Uninstall button.
  • When asked if you are sure you want to uninstall, click Yes.
  • The program will uninstall, and when completed you will be back at the list of programs installed on your computer.
  • When finished, close the Programs and Features screen.
Please run the following scan

OTL
  • Please download OTL to your desktop from HERE or HERE.
  • Close all other applications and windows so that you have nothing open.
  • Double click on the [external image: Posted Image]icon on your desktop.

Note: Vista and Windows 7 users right-click and select Run As Administrator. If you receive a UAC prompt asking if you would like to continue running the program, you should press the Continue button.

  • Under Output, click Minimal Output to select it.
  • Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.
  • Then click the Run Fix button at the top.
:OTL
uURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
mURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
BHO: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
TB: uTorrentControl2 Toolbar: {687578B9-7132-4A7A-80E4-30EE31099E03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
TB: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
2013-08-15 04:36:39 ——– d—–w- C:\Windows\64F6748976BB4CDDA236F954BE774B35.TMP

:Commands
[emptytemp]
[resethosts]
  • Let the program run unhindered; it will reboot when it is done. If it does not, please reboot your system.
  • Post the new log in your next reply.

Hello, Glitch.

Are you still there? Do you still need help?


Hi, thx for the follow up…. ya know.. I"m not sure why entirely

but after running DDS and aswMBR my computer has been acting fine…

which is odd because they don't really fix anything, but scan correct?

I did run OTL and remove the items you listed… and I ran several other malware removal tools… but to be honest, my download speeds were fine before that.

I'm downloading at speeds of 200KB/s to 1MB/s now…. so problem solved.

strange that my other computers on my home network never slowed down, so it wasn't the ISP….

I think what this issue was, was my DNS server was having connections problems… so I disabled IPv6 and reset my DNS server and after that it's been fine.

thanks for the help.
Hello, Glitch. Thank you for responding. I'm glad to hear that your computer appears to be working well. As it is not unusual for malware to resurface, I am asking that you stay with this topic a bit longer while we run a few more tools. This will ensure that your system is clean and safe. As well, we need to remove some applications and update others – outdated programs can compromise the security of your system. If you are interested in continuing the clean up process, please send me the results of your last OTL scan.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI