IndenturedSmile
Posts: 16 +0
I'm having the exact problem as outlined in this thread: https://www.techspot.com/community/topics/audio-ads-playing-on-windows-7-background.199113/. Was using Steam, Skype, and Chrome when my computer "crashed" by immediately powering off and then rebooting. I now have random audio playing in the background.
The infection first appeared last night (though I'm not sure if that was the time of infection). I tried following a few instructions found via Google last night, but they were all quite old and didn't work.
I also would have followed the steps in the linked thread, but I don't know enough about reading the logs to fix it myself, and I noticed that there are some generated infected files that will probably be different on my computer.
The logs from the four steps are below. Thanks for your help!
Malwarebytes:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2014.01.06.01
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Will :: DESKTOP [administrator]
1/5/2014 10:16:20 PM
mbam-log-2014-01-05 (22-16-20).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 238444
Time elapsed: 3 minute(s), 10 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 10.25.2
Run by Will at 22:46:10 on 2014-01-05
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.8173.5426 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\WizMouse\WizMouse.exe
C:\Program Files\pia_manager\pia_manager.exe
C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe
C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe
C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\SysWOW64\vmnat.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
C:\Windows\SysWOW64\vmnetdhcp.exe
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\TortoiseHg\TortoiseHgOverlayServer.exe
C:\Program Files (x86)\Switcher\Switcher.exe
C:\Users\Will\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
C:\Users\Will\AppData\Local\Temp\ocr3311.tmp\bin\rubyw.exe
C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
C:\Program Files\pia_manager\pia_manager.exe
C:\Users\Will\AppData\Local\Temp\ocr69CA.tmp\bin\rubyw.exe
C:\Program Files\pia_manager\pia_tray\pia_tray.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://www.google.com/
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: Microsoft Web Test Recorder 10.0 Helper: {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
TB: avast! Online Security: {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
EB: Web Test Recorder 10.0: {5802D092-1784-4908-8CDB-99B6842D353D} -
uRun: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
uRun: [Switcher] "C:\Program Files (x86)\Switcher\Switcher.exe" /quiet
uRun: [Spotify Web Helper] "C:\Users\Will\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
LSP: %windir%\system32\vsocklib.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{365E5A01-07A6-44F9-9347-8CFC6200C67F} : DHCPNameServer = 209.222.18.222 209.222.18.218
TCP: Interfaces\{50B74618-57B8-4D79-B72D-DAB0982974CB} : DHCPNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll
x64-TB: avast! Online Security: {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORDTSUPTBT
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [TortoiseHgOverlayIconServer] C:\Program Files\TortoiseHg\TortoiseHgOverlayServer.exe
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
x64-DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\e18g8f3h.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: browser.search.selectedEngine - Google
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Users\Will\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: C:\Users\Will\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll
FF - plugin: C:\Users\Will\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll
FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2014-1-5 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2014-1-5 207904]
R0 vsock;vSockets Driver;C:\Windows\System32\drivers\vsock.sys [2013-6-6 70296]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2014-1-5 1034464]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2014-1-5 422216]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-1-22 283200]
R2 asComSvc;ASUS Com Service;C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe [2011-6-13 922240]
R2 asHmComSvc;ASUS HM Com Service;C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-1 915584]
R2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2012-1-27 586880]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2014-1-5 78648]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-1-5 50344]
R2 DTSAudioService;DTSAudioService;C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe [2012-1-22 210024]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-2-9 383264]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2012-10-11 918680]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2011-6-2 128488]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2011-6-2 401896]
R3 aswStm;aswStm;C:\Windows\System32\drivers\aswstm.sys [2014-1-5 79672]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-1-22 539240]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);C:\Windows\System32\drivers\tap0901t.sys [2012-12-9 31232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 dualshock3;SIXAXIS/DUALSHOCK3 DX (USB) Beta;C:\Windows\System32\drivers\dualshock3_x64.sys [2012-11-1 26752]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-9-5 171680]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;C:\Windows\System32\drivers\MijXfilt.sys [2012-10-31 115272]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TunngleService;TunngleService;C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2012-12-9 745368]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-8-2 51712]
S3 VSPerfDrv100;Performance Tools Driver 10.0;C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-3-17 68440]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-3-2 1255736]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2009-7-22 61976]
S4 RsFx0103;RsFx0103 Driver;C:\Windows\System32\drivers\RsFx0103.sys [2009-3-30 311656]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-3-30 427880]
.
=============== Created Last 30 ================
.
2014-01-06 03:14:07 -------- d-----w- C:\Users\Will\AppData\Roaming\AVAST Software
2014-01-06 03:13:30 79672 ----a-w- C:\Windows\System32\drivers\aswstm.sys
2014-01-06 03:13:28 207904 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2014-01-06 03:13:25 65776 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2014-01-06 03:13:23 1034464 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2014-01-06 03:13:21 78648 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2014-01-06 03:13:20 92544 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2014-01-06 03:13:08 43152 ----a-w- C:\Windows\avastSS.scr
2014-01-06 03:12:56 -------- d-----w- C:\Program Files\AVAST Software
2014-01-06 03:12:33 -------- d-----w- C:\ProgramData\AVAST Software
2014-01-04 07:44:33 -------- d-sh--w- C:\$RECYCLE.BIN
2014-01-04 07:28:19 98816 ----a-w- C:\Windows\sed.exe
2014-01-04 07:28:19 256000 ----a-w- C:\Windows\PEV.exe
2014-01-04 07:28:19 208896 ----a-w- C:\Windows\MBR.exe
2014-01-04 07:11:34 -------- d-----w- C:\Users\Will\AppData\Roaming\Malwarebytes
2014-01-04 07:11:30 -------- d-----w- C:\ProgramData\Malwarebytes
2014-01-04 07:11:29 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-01-04 07:11:29 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-04 07:08:59 82944 ----a-w- C:\Windows\System32\drivers\ipfltdrv.sys.bak
2014-01-04 06:34:58 -------- d-----w- C:\Users\Will\AppData\Roaming\TuneUp Software
2014-01-04 06:31:30 -------- d--h--w- C:\ProgramData\Common Files
2014-01-04 06:31:29 -------- d-----w- C:\Users\Will\AppData\Local\MFAData
2014-01-04 06:31:29 -------- d-----w- C:\ProgramData\MFAData
2013-12-30 09:58:04 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{43F8743F-A2B4-4EC1-84C3-4B6E5A8BEDA2}\offreg.dll
2013-12-07 04:34:28 -------- d-----w- C:\Users\Will\AppData\Roaming\Cycling '74
.
==================== Find3M ====================
.
2013-12-11 08:52:08 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-11 08:52:08 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
.
============= FINISH: 22:46:37.40 ===============
Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume3
Install Date: 1/19/2012 5:40:01 PM
System Uptime: 1/5/2014 10:26:33 PM (0 hours ago)
.
Motherboard: ASUSTeK COMPUTER INC. | | P8P67-M PRO
Processor: Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz | LGA1155 | 3301/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 200 GiB total, 22.391 GiB free.
D: is FIXED (NTFS) - 75 GiB total, 15.697 GiB free.
E: is FIXED (NTFS) - 400 GiB total, 111.46 GiB free.
F: is FIXED (NTFS) - 1102 GiB total, 54.077 GiB free.
H: is CDROM ()
I: is CDROM ()
J: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP278: 1/4/2014 1:33:20 AM - Installed AVG 2014
RP279: 1/4/2014 1:33:49 AM - Installed AVG 2014
RP280: 1/4/2014 1:55:14 AM - Removed AVG 2014
RP281: 1/4/2014 1:56:02 AM - Removed AVG 2014
RP282: 1/4/2014 2:18:04 AM - OTL Restore Point - 1/4/2014 2:18:02 AM
RP283: 1/5/2014 10:12:44 PM - avast! antivirus system restore point
.
==== Installed Programs ======================
.
µTorrent
Ableton Live 8
Adobe AIR
Adobe Community Help
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Photoshop CS5.1
Age of Empires II: HD Edition
AI Suite II
Amazon MP3 Downloader 1.0.18
Amnesia: The Dark Descent
Android SDK Tools
Antichamber
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Aptana Studio 3
Aquaria
Arma 2
Arma 2: Operation Arrowhead
Asmedia ASM104x USB 3.0 Host Controller Driver
Assassin's Creed
Atom Zombie Smasher
avast! Free Antivirus
Baldur's Gate - The Original Saga
Bastion
Batman: Arkham City GOTY
Beneath a Steel Sky
BioShock Infinite
Bonjour
Borderlands 2
Cave Story+
Construct 2 r90
Crayon Physics Deluxe
Crystal Reports for Visual Studio
DAEMON Tools Lite
Dark Souls: Prepare to Die Edition
Darksiders
Darwinia
dBpoweramp Music Converter
Deadlight
DEFCON
Deus Ex: Human Revolution
Don't Starve
Dotfuscator Software Services - Community Edition
Dual-Core Optimizer
Dungeon Defenders
Dungeons of Dredmor
Dustforce
EasyBCD 2.1.2
EVE Online (remove only)
EVEMon
Fallout: New Vegas
Far Cry 3
FarCry 3 version 5.1
FEZ
FileZilla Client 3.5.3
From Dust
GameRanger
Garpa Topographical Survey
Git version 1.7.9-preview20120201
GOG.com Downloader version 3.5.6
Google Chrome
Grand Theft Auto
Grand Theft Auto IV
Guild Wars 2
Havij 1.15 Free
Hector: Ep 1
HFSExplorer 0.21
Home
Hotline Miami
Indiana Jones and the Fate of Atlantis
IntelliJ IDEA Community Edition 12.1.4
iTunes
Java 7 Update 25
Java Auto Updater
Java(TM) 6 Update 32
Java(TM) 7 Update 3 (64-bit)
Java(TM) SE Development Kit 7 Update 2 (64-bit)
Java(TM) SE Development Kit 7 Update 3 (64-bit)
JavaFX 2.0.3 (64-bit)
JavaFX 2.0.3 SDK (64-bit)
join.me
Just Cause 2
KatMouse (remove only)
Kerbal Space Program
L.A. Noire
LibreOffice 3.5
LIMBO
Little Inferno
Lone Survivor
Loom
Machinarium
Magicka
Malwarebytes Anti-Malware version 1.75.0.1300
Manhole
Max 5.1.9
Metro 2033
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft .NET Framework 4 Multi-Targeting Pack
Microsoft Application Error Reporting
Microsoft ASP.NET MVC 2
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Help Viewer 1.0
Microsoft Silverlight
Microsoft Silverlight 3 SDK
Microsoft SQL Server 2008 (64-bit)
Microsoft SQL Server 2008 Browser
Microsoft SQL Server 2008 Common Files
Microsoft SQL Server 2008 Database Engine Services
Microsoft SQL Server 2008 Database Engine Shared
Microsoft SQL Server 2008 Native Client
Microsoft SQL Server 2008 R2 Data-Tier Application Framework
Microsoft SQL Server 2008 R2 Data-Tier Application Project
Microsoft SQL Server 2008 R2 Management Objects
Microsoft SQL Server 2008 R2 Management Objects (x64)
Microsoft SQL Server 2008 R2 Transact-SQL Language Service
Microsoft SQL Server 2008 RsFx Driver
Microsoft SQL Server 2008 Setup Support Files
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft SQL Server Compact 3.5 SP2 x64 ENU
Microsoft SQL Server Database Publishing Wizard 1.4
Microsoft SQL Server System CLR Types
Microsoft SQL Server System CLR Types (x64)
Microsoft SQL Server VSS Writer
Microsoft Sync Framework Runtime v1.0 SP1 (x64)
Microsoft Sync Framework SDK v1.0 SP1
Microsoft Sync Framework Services v1.0 SP1 (x64)
Microsoft Sync Services for ADO.NET v2.0 SP1 (x64)
Microsoft Team Foundation Server 2010 Object Model - ENU
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610
Microsoft Visual F# 2.0 Runtime
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
Microsoft Visual Studio 2010 IntelliTrace Collection (x64)
Microsoft Visual Studio 2010 Office Developer Tools (x64)
Microsoft Visual Studio 2010 Performance Collection Tools - ENU
Microsoft Visual Studio 2010 SharePoint Developer Tools
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
Microsoft Visual Studio 2010 Ultimate - ENU
Microsoft Visual Studio Macro Tools
Microsoft WSE 3.0 Runtime
Microsoft XNA Framework Redistributable 3.1
Microsoft XNA Framework Redistributable 4.0
Microsoft XNA Framework Redistributable 4.0 Refresh
Microsoft XNA Game Studio 4.0 (XnaLiveProxy)
Microsoft XNA Game Studio 4.0 Refresh
Microsoft XNA Game Studio 4.0 Refresh (ARP entry)
Microsoft XNA Game Studio 4.0 Refresh (Redists)
Microsoft XNA Game Studio 4.0 Refresh (Shared Components)
Microsoft XNA Game Studio 4.0 Refresh (Visual Studio)
Microsoft XNA Game Studio Platform Tools
Microsoft_VC80_ATL_x86_x64
Microsoft_VC80_CRT_x86
Microsoft_VC80_CRT_x86_x64
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFC_x86_x64
Microsoft_VC80_MFCLOC_x86
Microsoft_VC80_MFCLOC_x86_x64
Microsoft_VC90_ATL_x86
Microsoft_VC90_ATL_x86_x64
Microsoft_VC90_CRT_x86
Microsoft_VC90_CRT_x86_x64
Microsoft_VC90_MFC_x86
Microsoft_VC90_MFC_x86_x64
Microsoft_VC90_MFCLOC_x86
Microsoft_VC90_MFCLOC_x86_x64
MotioninJoy DS3 driver version 0.6.0005
Mozilla Firefox 19.0.2 (x86 en-US)
Mozilla Maintenance Service
Mudlet (remove only)
Multiwinia
Mumble 1.2.3
MUSHclient (remove only)
My Game Long Name
Myst: Masterpiece Edition
NCsoft Launcher
Neverwinter
Neverwinter Nights Diamond Edition
Nexus Mod Manager
Notepad++
NVIDIA 3D Vision Controller Driver 314.07
NVIDIA 3D Vision Driver 314.07
NVIDIA Control Panel 314.07
NVIDIA Graphics Driver 314.07
NVIDIA HD Audio Driver 1.3.23.1
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX System Software 9.12.1031
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.12.12
NVIDIA Update Components
OpenAL
OpenVPN 2.2.1
Oracle VM VirtualBox 4.1.22
Osmos
Pando Media Booster
PCSX2 - Playstation 2 Emulator
PDF Settings CS5
PhotoME Beta-Release
Pidgin
Portal
Portal 2
Portal 2 Publishing Tool
Prison Architect
Private Internet Access Support Files
Project 64 version 2.0.0.14
Project64 1.6
Proteus
PS3 Media Server
Psychonauts
QuickTime
RailsInstaller 2.1.0
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Recettear: An Item Shop's Tale
Riven
Riven The sequel to Myst
Rockstar Games Social Club
Rogue Legacy
Ruby 1.9.3-p194
Saints Row: The Third
Service Pack 1 for SQL Server 2008 (KB968369) (64-bit)
Shadowgrounds
Shelter
Sid Meier's Civilization IV
Sid Meier's Civilization V
SimCity 4 Deluxe
Skype™ 6.11
Source SDK
Source SDK Base 2007
Space Engineers
SpaceChem
Spirits
Spotify
Sql Server Customer Experience Improvement Program
Starbound
Starseed Pilgrim
Steam
Sublime Text 2.0.2
Super Meat Boy
Superbrothers: Sword & Sworcery EP
Switcher 2.0.0
Sword of the Stars: The Pit
Team Fortress 2
Terraria
TES Construction Set
The Binding of Isaac
The Book Of Unwritten Tales version 1.03
The Dig
The Elder Scrolls Online Beta
The Elder Scrolls V: Skyrim
The Secret of Monkey Island: Special Edition
The Stanley Parable
The Swapper
The Testament of Sherlock Holmes
The Walking Dead
The Witcher: Enhanced Edition
Thirty Flights of Loving
Thomas Was Alone
Tiled - Tiled Map Editor
Titan Quest
Tixati
TortoiseHg 2.3.2 (x64)
Trine
Tropico 4
Tunngle beta
Ubisoft Game Launcher
UDPixel.exe
Unepic
Unity
Uplay
Uplink
Vagrant
Vessel
Viscera Cleanup Detail - ALPHA
Visual Studio 2010 Prerequisites - English
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
Visual Studio 2012 x64 Redistributables
Visual Studio 2012 x86 Redistributables
VLC media player 2.0.7
VMware Player
VVVVVV
WampServer 2.2
War Thunder
War Thunder Launcher 1.0.1.269
Warhammer 40,000: Dawn of War - Game of the Year Edition
Web Deployment Tool
WinDirStat 1.1.2
Windows Live ID Sign-in Assistant
WinRAR 4.10 (64-bit)
WinSCP 4.3.7
WizMouse v1.6.0.2
Wizorb
.
==== Event Viewer Messages From Past Week ========
.
1/5/2014 10:44:24 PM, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
1/5/2014 10:44:24 PM, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
1/5/2014 10:42:09 PM, Error: Service Control Manager [7023] - The Power service terminated with the following error: The WMI request could not be completed and should be retried.
1/5/2014 10:42:05 PM, Error: Service Control Manager [7000] - The SIXAXIS/DUALSHOCK3 DX (USB) Beta service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
1/4/2014 2:43:04 AM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
1/4/2014 2:33:12 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Reboot the machine) after the unexpected termination of the Power service, but this action failed with the following error: A system shutdown has already been scheduled.
1/4/2014 2:33:12 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Reboot the machine) after the unexpected termination of the Plug and Play service, but this action failed with the following error: A system shutdown has already been scheduled.
1/4/2014 2:33:12 AM, Error: Service Control Manager [7031] - The Power service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
1/4/2014 2:33:12 AM, Error: Service Control Manager [7031] - The Plug and Play service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
1/4/2014 2:33:12 AM, Error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
1/4/2014 2:01:58 AM, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
1/4/2014 1:35:51 AM, Error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
1/4/2014 1:35:32 AM, Error: Service Control Manager [7034] - The PnkBstrA service terminated unexpectedly. It has done this 1 time(s).
1/4/2014 1:24:06 AM, Error: Service Control Manager [7034] - The ASUS Com Service service terminated unexpectedly. It has done this 1 time(s).
1/4/2014 1:23:46 AM, Error: Service Control Manager [7034] - The DTSAudioService service terminated unexpectedly. It has done this 1 time(s).
.
==== End Of File ===========================
The infection first appeared last night (though I'm not sure if that was the time of infection). I tried following a few instructions found via Google last night, but they were all quite old and didn't work.
I also would have followed the steps in the linked thread, but I don't know enough about reading the logs to fix it myself, and I noticed that there are some generated infected files that will probably be different on my computer.
The logs from the four steps are below. Thanks for your help!
Malwarebytes:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2014.01.06.01
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Will :: DESKTOP [administrator]
1/5/2014 10:16:20 PM
mbam-log-2014-01-05 (22-16-20).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 238444
Time elapsed: 3 minute(s), 10 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 10.25.2
Run by Will at 22:46:10 on 2014-01-05
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.8173.5426 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\WizMouse\WizMouse.exe
C:\Program Files\pia_manager\pia_manager.exe
C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe
C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe
C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\SysWOW64\vmnat.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
C:\Windows\SysWOW64\vmnetdhcp.exe
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\TortoiseHg\TortoiseHgOverlayServer.exe
C:\Program Files (x86)\Switcher\Switcher.exe
C:\Users\Will\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
C:\Users\Will\AppData\Local\Temp\ocr3311.tmp\bin\rubyw.exe
C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
C:\Program Files\pia_manager\pia_manager.exe
C:\Users\Will\AppData\Local\Temp\ocr69CA.tmp\bin\rubyw.exe
C:\Program Files\pia_manager\pia_tray\pia_tray.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Will\AppData\Local\Google\Chrome\Application\chrome.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://www.google.com/
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: Microsoft Web Test Recorder 10.0 Helper: {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
TB: avast! Online Security: {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
EB: Web Test Recorder 10.0: {5802D092-1784-4908-8CDB-99B6842D353D} -
uRun: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
uRun: [Switcher] "C:\Program Files (x86)\Switcher\Switcher.exe" /quiet
uRun: [Spotify Web Helper] "C:\Users\Will\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
LSP: %windir%\system32\vsocklib.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{365E5A01-07A6-44F9-9347-8CFC6200C67F} : DHCPNameServer = 209.222.18.222 209.222.18.218
TCP: Interfaces\{50B74618-57B8-4D79-B72D-DAB0982974CB} : DHCPNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll
x64-TB: avast! Online Security: {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORDTSUPTBT
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [TortoiseHgOverlayIconServer] C:\Program Files\TortoiseHg\TortoiseHgOverlayServer.exe
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
x64-DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\e18g8f3h.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: browser.search.selectedEngine - Google
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Users\Will\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: C:\Users\Will\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll
FF - plugin: C:\Users\Will\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll
FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2014-1-5 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2014-1-5 207904]
R0 vsock;vSockets Driver;C:\Windows\System32\drivers\vsock.sys [2013-6-6 70296]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2014-1-5 1034464]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2014-1-5 422216]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-1-22 283200]
R2 asComSvc;ASUS Com Service;C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe [2011-6-13 922240]
R2 asHmComSvc;ASUS HM Com Service;C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-1 915584]
R2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2012-1-27 586880]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2014-1-5 78648]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-1-5 50344]
R2 DTSAudioService;DTSAudioService;C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe [2012-1-22 210024]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-2-9 383264]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2012-10-11 918680]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2011-6-2 128488]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2011-6-2 401896]
R3 aswStm;aswStm;C:\Windows\System32\drivers\aswstm.sys [2014-1-5 79672]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-1-22 539240]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);C:\Windows\System32\drivers\tap0901t.sys [2012-12-9 31232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 dualshock3;SIXAXIS/DUALSHOCK3 DX (USB) Beta;C:\Windows\System32\drivers\dualshock3_x64.sys [2012-11-1 26752]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-9-5 171680]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;C:\Windows\System32\drivers\MijXfilt.sys [2012-10-31 115272]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TunngleService;TunngleService;C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2012-12-9 745368]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-8-2 51712]
S3 VSPerfDrv100;Performance Tools Driver 10.0;C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-3-17 68440]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-3-2 1255736]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2009-7-22 61976]
S4 RsFx0103;RsFx0103 Driver;C:\Windows\System32\drivers\RsFx0103.sys [2009-3-30 311656]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-3-30 427880]
.
=============== Created Last 30 ================
.
2014-01-06 03:14:07 -------- d-----w- C:\Users\Will\AppData\Roaming\AVAST Software
2014-01-06 03:13:30 79672 ----a-w- C:\Windows\System32\drivers\aswstm.sys
2014-01-06 03:13:28 207904 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2014-01-06 03:13:25 65776 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2014-01-06 03:13:23 1034464 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2014-01-06 03:13:21 78648 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2014-01-06 03:13:20 92544 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2014-01-06 03:13:08 43152 ----a-w- C:\Windows\avastSS.scr
2014-01-06 03:12:56 -------- d-----w- C:\Program Files\AVAST Software
2014-01-06 03:12:33 -------- d-----w- C:\ProgramData\AVAST Software
2014-01-04 07:44:33 -------- d-sh--w- C:\$RECYCLE.BIN
2014-01-04 07:28:19 98816 ----a-w- C:\Windows\sed.exe
2014-01-04 07:28:19 256000 ----a-w- C:\Windows\PEV.exe
2014-01-04 07:28:19 208896 ----a-w- C:\Windows\MBR.exe
2014-01-04 07:11:34 -------- d-----w- C:\Users\Will\AppData\Roaming\Malwarebytes
2014-01-04 07:11:30 -------- d-----w- C:\ProgramData\Malwarebytes
2014-01-04 07:11:29 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-01-04 07:11:29 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-04 07:08:59 82944 ----a-w- C:\Windows\System32\drivers\ipfltdrv.sys.bak
2014-01-04 06:34:58 -------- d-----w- C:\Users\Will\AppData\Roaming\TuneUp Software
2014-01-04 06:31:30 -------- d--h--w- C:\ProgramData\Common Files
2014-01-04 06:31:29 -------- d-----w- C:\Users\Will\AppData\Local\MFAData
2014-01-04 06:31:29 -------- d-----w- C:\ProgramData\MFAData
2013-12-30 09:58:04 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{43F8743F-A2B4-4EC1-84C3-4B6E5A8BEDA2}\offreg.dll
2013-12-07 04:34:28 -------- d-----w- C:\Users\Will\AppData\Roaming\Cycling '74
.
==================== Find3M ====================
.
2013-12-11 08:52:08 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-11 08:52:08 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
.
============= FINISH: 22:46:37.40 ===============
Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume3
Install Date: 1/19/2012 5:40:01 PM
System Uptime: 1/5/2014 10:26:33 PM (0 hours ago)
.
Motherboard: ASUSTeK COMPUTER INC. | | P8P67-M PRO
Processor: Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz | LGA1155 | 3301/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 200 GiB total, 22.391 GiB free.
D: is FIXED (NTFS) - 75 GiB total, 15.697 GiB free.
E: is FIXED (NTFS) - 400 GiB total, 111.46 GiB free.
F: is FIXED (NTFS) - 1102 GiB total, 54.077 GiB free.
H: is CDROM ()
I: is CDROM ()
J: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP278: 1/4/2014 1:33:20 AM - Installed AVG 2014
RP279: 1/4/2014 1:33:49 AM - Installed AVG 2014
RP280: 1/4/2014 1:55:14 AM - Removed AVG 2014
RP281: 1/4/2014 1:56:02 AM - Removed AVG 2014
RP282: 1/4/2014 2:18:04 AM - OTL Restore Point - 1/4/2014 2:18:02 AM
RP283: 1/5/2014 10:12:44 PM - avast! antivirus system restore point
.
==== Installed Programs ======================
.
µTorrent
Ableton Live 8
Adobe AIR
Adobe Community Help
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Photoshop CS5.1
Age of Empires II: HD Edition
AI Suite II
Amazon MP3 Downloader 1.0.18
Amnesia: The Dark Descent
Android SDK Tools
Antichamber
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Aptana Studio 3
Aquaria
Arma 2
Arma 2: Operation Arrowhead
Asmedia ASM104x USB 3.0 Host Controller Driver
Assassin's Creed
Atom Zombie Smasher
avast! Free Antivirus
Baldur's Gate - The Original Saga
Bastion
Batman: Arkham City GOTY
Beneath a Steel Sky
BioShock Infinite
Bonjour
Borderlands 2
Cave Story+
Construct 2 r90
Crayon Physics Deluxe
Crystal Reports for Visual Studio
DAEMON Tools Lite
Dark Souls: Prepare to Die Edition
Darksiders
Darwinia
dBpoweramp Music Converter
Deadlight
DEFCON
Deus Ex: Human Revolution
Don't Starve
Dotfuscator Software Services - Community Edition
Dual-Core Optimizer
Dungeon Defenders
Dungeons of Dredmor
Dustforce
EasyBCD 2.1.2
EVE Online (remove only)
EVEMon
Fallout: New Vegas
Far Cry 3
FarCry 3 version 5.1
FEZ
FileZilla Client 3.5.3
From Dust
GameRanger
Garpa Topographical Survey
Git version 1.7.9-preview20120201
GOG.com Downloader version 3.5.6
Google Chrome
Grand Theft Auto
Grand Theft Auto IV
Guild Wars 2
Havij 1.15 Free
Hector: Ep 1
HFSExplorer 0.21
Home
Hotline Miami
Indiana Jones and the Fate of Atlantis
IntelliJ IDEA Community Edition 12.1.4
iTunes
Java 7 Update 25
Java Auto Updater
Java(TM) 6 Update 32
Java(TM) 7 Update 3 (64-bit)
Java(TM) SE Development Kit 7 Update 2 (64-bit)
Java(TM) SE Development Kit 7 Update 3 (64-bit)
JavaFX 2.0.3 (64-bit)
JavaFX 2.0.3 SDK (64-bit)
join.me
Just Cause 2
KatMouse (remove only)
Kerbal Space Program
L.A. Noire
LibreOffice 3.5
LIMBO
Little Inferno
Lone Survivor
Loom
Machinarium
Magicka
Malwarebytes Anti-Malware version 1.75.0.1300
Manhole
Max 5.1.9
Metro 2033
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft .NET Framework 4 Multi-Targeting Pack
Microsoft Application Error Reporting
Microsoft ASP.NET MVC 2
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Help Viewer 1.0
Microsoft Silverlight
Microsoft Silverlight 3 SDK
Microsoft SQL Server 2008 (64-bit)
Microsoft SQL Server 2008 Browser
Microsoft SQL Server 2008 Common Files
Microsoft SQL Server 2008 Database Engine Services
Microsoft SQL Server 2008 Database Engine Shared
Microsoft SQL Server 2008 Native Client
Microsoft SQL Server 2008 R2 Data-Tier Application Framework
Microsoft SQL Server 2008 R2 Data-Tier Application Project
Microsoft SQL Server 2008 R2 Management Objects
Microsoft SQL Server 2008 R2 Management Objects (x64)
Microsoft SQL Server 2008 R2 Transact-SQL Language Service
Microsoft SQL Server 2008 RsFx Driver
Microsoft SQL Server 2008 Setup Support Files
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft SQL Server Compact 3.5 SP2 x64 ENU
Microsoft SQL Server Database Publishing Wizard 1.4
Microsoft SQL Server System CLR Types
Microsoft SQL Server System CLR Types (x64)
Microsoft SQL Server VSS Writer
Microsoft Sync Framework Runtime v1.0 SP1 (x64)
Microsoft Sync Framework SDK v1.0 SP1
Microsoft Sync Framework Services v1.0 SP1 (x64)
Microsoft Sync Services for ADO.NET v2.0 SP1 (x64)
Microsoft Team Foundation Server 2010 Object Model - ENU
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610
Microsoft Visual F# 2.0 Runtime
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
Microsoft Visual Studio 2010 IntelliTrace Collection (x64)
Microsoft Visual Studio 2010 Office Developer Tools (x64)
Microsoft Visual Studio 2010 Performance Collection Tools - ENU
Microsoft Visual Studio 2010 SharePoint Developer Tools
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
Microsoft Visual Studio 2010 Ultimate - ENU
Microsoft Visual Studio Macro Tools
Microsoft WSE 3.0 Runtime
Microsoft XNA Framework Redistributable 3.1
Microsoft XNA Framework Redistributable 4.0
Microsoft XNA Framework Redistributable 4.0 Refresh
Microsoft XNA Game Studio 4.0 (XnaLiveProxy)
Microsoft XNA Game Studio 4.0 Refresh
Microsoft XNA Game Studio 4.0 Refresh (ARP entry)
Microsoft XNA Game Studio 4.0 Refresh (Redists)
Microsoft XNA Game Studio 4.0 Refresh (Shared Components)
Microsoft XNA Game Studio 4.0 Refresh (Visual Studio)
Microsoft XNA Game Studio Platform Tools
Microsoft_VC80_ATL_x86_x64
Microsoft_VC80_CRT_x86
Microsoft_VC80_CRT_x86_x64
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFC_x86_x64
Microsoft_VC80_MFCLOC_x86
Microsoft_VC80_MFCLOC_x86_x64
Microsoft_VC90_ATL_x86
Microsoft_VC90_ATL_x86_x64
Microsoft_VC90_CRT_x86
Microsoft_VC90_CRT_x86_x64
Microsoft_VC90_MFC_x86
Microsoft_VC90_MFC_x86_x64
Microsoft_VC90_MFCLOC_x86
Microsoft_VC90_MFCLOC_x86_x64
MotioninJoy DS3 driver version 0.6.0005
Mozilla Firefox 19.0.2 (x86 en-US)
Mozilla Maintenance Service
Mudlet (remove only)
Multiwinia
Mumble 1.2.3
MUSHclient (remove only)
My Game Long Name
Myst: Masterpiece Edition
NCsoft Launcher
Neverwinter
Neverwinter Nights Diamond Edition
Nexus Mod Manager
Notepad++
NVIDIA 3D Vision Controller Driver 314.07
NVIDIA 3D Vision Driver 314.07
NVIDIA Control Panel 314.07
NVIDIA Graphics Driver 314.07
NVIDIA HD Audio Driver 1.3.23.1
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX System Software 9.12.1031
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.12.12
NVIDIA Update Components
OpenAL
OpenVPN 2.2.1
Oracle VM VirtualBox 4.1.22
Osmos
Pando Media Booster
PCSX2 - Playstation 2 Emulator
PDF Settings CS5
PhotoME Beta-Release
Pidgin
Portal
Portal 2
Portal 2 Publishing Tool
Prison Architect
Private Internet Access Support Files
Project 64 version 2.0.0.14
Project64 1.6
Proteus
PS3 Media Server
Psychonauts
QuickTime
RailsInstaller 2.1.0
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Recettear: An Item Shop's Tale
Riven
Riven The sequel to Myst
Rockstar Games Social Club
Rogue Legacy
Ruby 1.9.3-p194
Saints Row: The Third
Service Pack 1 for SQL Server 2008 (KB968369) (64-bit)
Shadowgrounds
Shelter
Sid Meier's Civilization IV
Sid Meier's Civilization V
SimCity 4 Deluxe
Skype™ 6.11
Source SDK
Source SDK Base 2007
Space Engineers
SpaceChem
Spirits
Spotify
Sql Server Customer Experience Improvement Program
Starbound
Starseed Pilgrim
Steam
Sublime Text 2.0.2
Super Meat Boy
Superbrothers: Sword & Sworcery EP
Switcher 2.0.0
Sword of the Stars: The Pit
Team Fortress 2
Terraria
TES Construction Set
The Binding of Isaac
The Book Of Unwritten Tales version 1.03
The Dig
The Elder Scrolls Online Beta
The Elder Scrolls V: Skyrim
The Secret of Monkey Island: Special Edition
The Stanley Parable
The Swapper
The Testament of Sherlock Holmes
The Walking Dead
The Witcher: Enhanced Edition
Thirty Flights of Loving
Thomas Was Alone
Tiled - Tiled Map Editor
Titan Quest
Tixati
TortoiseHg 2.3.2 (x64)
Trine
Tropico 4
Tunngle beta
Ubisoft Game Launcher
UDPixel.exe
Unepic
Unity
Uplay
Uplink
Vagrant
Vessel
Viscera Cleanup Detail - ALPHA
Visual Studio 2010 Prerequisites - English
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
Visual Studio 2012 x64 Redistributables
Visual Studio 2012 x86 Redistributables
VLC media player 2.0.7
VMware Player
VVVVVV
WampServer 2.2
War Thunder
War Thunder Launcher 1.0.1.269
Warhammer 40,000: Dawn of War - Game of the Year Edition
Web Deployment Tool
WinDirStat 1.1.2
Windows Live ID Sign-in Assistant
WinRAR 4.10 (64-bit)
WinSCP 4.3.7
WizMouse v1.6.0.2
Wizorb
.
==== Event Viewer Messages From Past Week ========
.
1/5/2014 10:44:24 PM, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
1/5/2014 10:44:24 PM, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
1/5/2014 10:42:09 PM, Error: Service Control Manager [7023] - The Power service terminated with the following error: The WMI request could not be completed and should be retried.
1/5/2014 10:42:05 PM, Error: Service Control Manager [7000] - The SIXAXIS/DUALSHOCK3 DX (USB) Beta service failed to start due to the following error: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
1/4/2014 2:43:04 AM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
1/4/2014 2:33:12 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Reboot the machine) after the unexpected termination of the Power service, but this action failed with the following error: A system shutdown has already been scheduled.
1/4/2014 2:33:12 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Reboot the machine) after the unexpected termination of the Plug and Play service, but this action failed with the following error: A system shutdown has already been scheduled.
1/4/2014 2:33:12 AM, Error: Service Control Manager [7031] - The Power service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
1/4/2014 2:33:12 AM, Error: Service Control Manager [7031] - The Plug and Play service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
1/4/2014 2:33:12 AM, Error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
1/4/2014 2:01:58 AM, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
1/4/2014 1:35:51 AM, Error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
1/4/2014 1:35:32 AM, Error: Service Control Manager [7034] - The PnkBstrA service terminated unexpectedly. It has done this 1 time(s).
1/4/2014 1:24:06 AM, Error: Service Control Manager [7034] - The ASUS Com Service service terminated unexpectedly. It has done this 1 time(s).
1/4/2014 1:23:46 AM, Error: Service Control Manager [7034] - The DTSAudioService service terminated unexpectedly. It has done this 1 time(s).
.
==== End Of File ===========================