Hello TechSpot techsupport guru's.
Got some issues with my notebook.
Specs:
Samsung 300V3A
Core i7 2670QM 2.2ghz
4GB ram
A list of what has has happened so far,
Bluescreen during online gaming,
Difficulty loading Taskmanager
Slow at startup
Slow web browsing
Slow at running scans with either MSE or MBAM and that is only a quick scan, Trying full
scans results in odd pauses and eventually "not responding"
Touch navigation pad becomes unresponsive,
and the big one...the machine runs silly hot, no gaming, just browsing like I am right now.
Temps from speedfan place the gpu at 66 degs C and the cpu varies from 68 to 81 degrees C, not normal under light load conditions. Might explain the BSOD's
There are also several svchost.exe processes running at once, like 13 of em....? Odd?
The MBAM quick scan showed no issues as did the MSE quick scan yet the notebook still behaves like a snail.
ComboFix log
ComboFix 13-12-13.01 - Aidan 14/12/2013 20:26:18.3.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.4010.2752 [GMT 8:00]
Running from: c:\users\Aidan\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
AV: Norton Internet Security *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Norton Internet Security *Disabled/Outdated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2013-11-14 to 2013-12-14 )))))))))))))))))))))))))))))))
.
.
2013-12-14 12:44 . 2013-12-14 12:44--------d-----w-c:\users\UpdatusUser\AppData\Local\temp
2013-12-14 12:44 . 2013-12-14 12:44--------d-----w-c:\users\Default\AppData\Local\temp
2013-12-14 11:12 . 2013-12-14 11:1275888----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6F86C0EB-D67B-40B5-B4DD-DC09FB9EF8B7}\offreg.dll
2013-12-14 10:54 . 2013-11-08 03:1210285968----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6F86C0EB-D67B-40B5-B4DD-DC09FB9EF8B7}\mpengine.dll
2013-12-14 06:49 . 2013-12-14 06:49--------d-----w-C:\AI_RecycleBin
2013-12-14 00:05 . 2013-11-08 03:1210285968----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-12-12 07:39 . 2013-10-25 06:172648576----a-w-c:\windows\system32\iertutil.dll
2013-12-12 07:38 . 2013-10-25 06:1819271168----a-w-c:\windows\system32\mshtml.dll
2013-12-10 10:59 . 2013-12-10 10:59--------d-----w-c:\program files (x86)\Daring Development
2013-12-10 10:52 . 2013-12-12 14:02--------d-----w-c:\users\Aidan\AppData\Roaming\F8fbpsK9
2013-12-10 10:37 . 2013-12-12 14:59--------d-----w-c:\program files (x86)\Optimizer Pro
2013-12-06 14:40 . 2013-12-06 14:4020080----a-w-c:\program files (x86)\Mozilla Firefox\AccessibleMarshal.dll
2013-12-06 14:40 . 2013-12-06 14:402106216----a-w-c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2013-12-06 14:40 . 2013-12-06 14:4075376----a-w-c:\program files (x86)\Mozilla Firefox\breakpadinjector.dll
2013-12-06 14:40 . 2013-12-06 14:40272496----a-w-c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll
2013-12-06 14:40 . 2013-12-06 14:40117360----a-w-c:\program files (x86)\Mozilla Firefox\crashreporter.exe
2013-12-06 14:40 . 2013-12-06 14:40275568----a-w-c:\program files (x86)\Mozilla Firefox\firefox.exe
2013-12-06 14:40 . 2013-12-06 14:4064112----a-w-c:\program files (x86)\Mozilla Firefox\libEGL.dll
2013-12-06 14:40 . 2013-12-06 14:403459696----a-w-c:\program files (x86)\Mozilla Firefox\gkmedias.dll
2013-12-06 14:40 . 2013-12-06 14:40302192----a-w-c:\program files (x86)\Mozilla Firefox\freebl3.dll
2013-12-06 14:40 . 2013-12-06 14:40549488----a-w-c:\program files (x86)\Mozilla Firefox\libGLESv2.dll
2013-12-06 14:40 . 2013-12-06 14:40119408----a-w-c:\program files (x86)\Mozilla Firefox\maintenanceservice.exe
2013-12-06 05:57 . 2013-10-19 00:35965000------w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1718B1E1-3B97-413C-914A-B8BCEA0F4BAA}\gapaengine.dll
2013-11-26 03:51 . 2013-11-26 03:57--------d-----w-c:\program files\Adobe
2013-11-26 03:47 . 2013-11-26 03:53--------d-----w-c:\program files\Common Files\Adobe
2013-11-25 13:53 . 2013-12-12 14:50--------d-----w-c:\users\Aidan\AppData\Roaming\BitTorrent
2013-11-25 13:44 . 2013-12-12 15:09--------d-----w-c:\program files (x86)\TornTV.com
2013-11-23 09:04 . 2013-11-23 09:04--------d-----w-c:\users\Aidan\AppData\Roaming\openvr
2013-11-19 17:50 . 2013-12-13 14:27--------d-----w-C:\coin
2013-11-16 12:45 . 2009-05-29 08:08--------d-----w-C:\NOOBSCAPE RELEASE
2013-11-16 12:43 . 2009-06-04 09:20--------d-----w-C:\Noobscape Client
2013-11-16 09:00 . 2013-11-16 09:00--------d-----w-C:\found.003
2013-11-16 04:03 . 2013-09-04 12:12343040----a-w-c:\windows\system32\drivers\usbhub.sys
2013-11-16 04:03 . 2013-09-04 12:11325120----a-w-c:\windows\system32\drivers\usbport.sys
2013-11-16 04:03 . 2013-09-04 12:1199840----a-w-c:\windows\system32\drivers\usbccgp.sys
2013-11-16 04:03 . 2013-09-04 12:1152736----a-w-c:\windows\system32\drivers\usbehci.sys
2013-11-16 04:03 . 2013-09-04 12:1130720----a-w-c:\windows\system32\drivers\usbuhci.sys
2013-11-16 04:03 . 2013-09-04 12:117808----a-w-c:\windows\system32\drivers\usbd.sys
2013-11-16 04:03 . 2013-09-04 12:1125600----a-w-c:\windows\system32\drivers\usbohci.sys
2013-11-15 12:54 . 2012-02-04 17:09--------d-----w-C:\Insidia 2 Package
2013-11-15 12:50 . 2012-02-17 15:35--------d-----w-C:\InsidiaX.cache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-06 09:43 . 2013-07-20 22:3316152----a-w-c:\windows\system32\drivers\SWDUMon.sys
2013-11-19 10:21 . 2010-11-21 03:27267936------w-c:\windows\system32\MpSigStub.exe
2013-10-19 06:13 . 2013-10-19 06:13108968----a-w-c:\windows\system32\WindowsAccessBridge-64.dll
2013-10-19 06:13 . 2013-10-19 06:14312744----a-w-c:\windows\system32\javaws.exe
2013-10-19 06:13 . 2013-10-19 06:13189352----a-w-c:\windows\system32\javaw.exe
2013-10-19 06:13 . 2013-10-19 06:13189352----a-w-c:\windows\system32\java.exe
2013-10-19 00:35 . 2012-10-02 17:29965000------w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-10-12 02:30 . 2013-11-13 21:03830464----a-w-c:\windows\system32\nshwfp.dll
2013-10-12 02:29 . 2013-11-13 21:03859648----a-w-c:\windows\system32\IKEEXT.DLL
2013-10-12 02:29 . 2013-11-13 21:03324096----a-w-c:\windows\system32\FWPUCLNT.DLL
2013-10-12 02:03 . 2013-11-13 21:03656896----a-w-c:\windows\SysWow64\nshwfp.dll
2013-10-12 02:01 . 2013-11-13 21:03216576----a-w-c:\windows\SysWow64\FWPUCLNT.DLL
2013-10-05 20:25 . 2013-11-13 21:041474048----a-w-c:\windows\system32\crypt32.dll
2013-10-05 19:57 . 2013-11-13 21:041168384----a-w-c:\windows\SysWow64\crypt32.dll
2013-10-04 02:28 . 2013-11-13 21:04190464----a-w-c:\windows\system32\SmartcardCredentialProvider.dll
2013-10-04 02:25 . 2013-11-13 21:04197120----a-w-c:\windows\system32\credui.dll
2013-10-04 02:24 . 2013-11-13 21:041930752----a-w-c:\windows\system32\authui.dll
2013-10-04 01:58 . 2013-11-13 21:04152576----a-w-c:\windows\SysWow64\SmartcardCredentialProvider.dll
2013-10-04 01:56 . 2013-11-13 21:04168960----a-w-c:\windows\SysWow64\credui.dll
2013-10-04 01:56 . 2013-11-13 21:041796096----a-w-c:\windows\SysWow64\authui.dll
2013-10-03 02:23 . 2013-11-13 21:03404480----a-w-c:\windows\system32\gdi32.dll
2013-10-03 02:00 . 2013-11-13 21:03311808----a-w-c:\windows\SysWow64\gdi32.dll
2013-09-28 01:09 . 2013-11-13 21:04497152----a-w-c:\windows\system32\drivers\afd.sys
2013-09-27 01:53 . 2013-09-27 01:53248240----a-w-c:\windows\system32\drivers\MpFilter.sys
2013-09-27 01:53 . 2012-03-21 01:44134944----a-w-c:\windows\system32\drivers\NisDrvWFP.sys
2013-09-25 02:26 . 2013-11-13 21:04154560----a-w-c:\windows\system32\drivers\ksecpkg.sys
2013-09-25 02:26 . 2013-11-13 21:0495680----a-w-c:\windows\system32\drivers\ksecdd.sys
2013-09-25 02:23 . 2013-11-13 21:04135680----a-w-c:\windows\system32\sspicli.dll
2013-09-25 02:23 . 2013-11-13 21:0428672----a-w-c:\windows\system32\sspisrv.dll
2013-09-25 02:23 . 2013-11-13 21:0428160----a-w-c:\windows\system32\secur32.dll
2013-09-25 02:22 . 2013-11-13 21:04340992----a-w-c:\windows\system32\schannel.dll
2013-09-25 02:21 . 2013-11-13 21:04307200----a-w-c:\windows\system32\ncrypt.dll
2013-09-25 02:21 . 2013-11-13 21:041447936----a-w-c:\windows\system32\lsasrv.dll
2013-09-25 01:58 . 2013-11-13 21:0496768----a-w-c:\windows\SysWow64\sspicli.dll
2013-09-25 01:57 . 2013-11-13 21:0422016----a-w-c:\windows\SysWow64\secur32.dll
2013-09-25 01:57 . 2013-11-13 21:04247808----a-w-c:\windows\SysWow64\schannel.dll
2013-09-25 01:56 . 2013-11-13 21:04220160----a-w-c:\windows\SysWow64\ncrypt.dll
2013-09-25 01:03 . 2013-11-13 21:0430720----a-w-c:\windows\system32\lsass.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2013-12-11 1823656]
"Config"="c:\users\Aidan\AppData\Roaming\tasklaunch.exe" [2010-03-18 32592]
"WindowsNetworkClient"="c:\users\Aidan\AppData\Roaming\AppClient\RascalClient.exe" [2013-07-27 11776]
"Windows Compact Framework"="c:\users\Aidan\AppData\Roaming\AppClient\mm.exe" [2013-11-19 12800]
"Windows Miner Client"="c:\coin\xmine.exe" [2013-11-24 12288]
"p8F6lCgBkp"="c:\users\Aidan\AppData\Roaming\F8fbpsK9\TGDvRNf.exe.lnk" [2013-12-10 874]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 tor;Tor Win32 Service;c:\program files (x86)\Tor\tor.exe;c:\program files (x86)\Tor\tor.exe [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 Samsung UPD Service;Samsung UPD Service;c:\windows\System32\SUPDSvc.exe;c:\windows\SYSNATIVE\SUPDSvc.exe [x]
R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys;c:\windows\SYSNATIVE\DRIVERS\SWDUMon.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1207020.003\SYMDS64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1207020.003\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1207020.003\SYMEFA64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1207020.003\SYMEFA64.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20120823.005\BHDrvx64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20120823.005\BHDrvx64.sys [x]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20120828.001\IDSvia64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20120828.001\IDSvia64.sys [x]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys;c:\windows\SYSNATIVE\Drivers\SABI.sys [x]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1207020.003\Ironx64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1207020.003\Ironx64.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1207020.003\SYMNETS.SYS;c:\windows\SYSNATIVE\Drivers\NISx64\1207020.003\SYMNETS.SYS [x]
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [x]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe;c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe [x]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys;c:\windows\SYSNATIVE\Drivers\SSPORT.sys [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-12-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4191367178-1998265054-3350178268-1001Core1ce8564e19f1ad5.job
- c:\users\Aidan\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-25 00:51]
.
2013-12-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4191367178-1998265054-3350178268-1001UA1ce8564e50c3aed.job
- c:\users\Aidan\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-25 00:51]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-25 11895400]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-06-24 168216]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-06-24 418584]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-03-30 10372368]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 1266912]
"IntelTBRunOnce"="wscript.exe" [2013-10-12 168960]
"Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-19 444904]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://home.sweetim.com/?ptr=100&crg=3.1010000.10039&barid={E5362D76-D368-11E2-92A6-B80305750534}
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Aidan\AppData\Roaming\mozilla\firefox\Profiles\l69zelgy.default\
FF - prefs.js: browser.startup.homepage - hxxp://start.search.us.com/v/2/?guid={7B4F761D-914B-4129-80D3-5852CD28A139}&serpv=5
FF - prefs.js: keyword.URL - hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=AU&userid=f00e8de3-0b52-100e-2330-fe2d6c2ccd45&searchtype=ds&installDate=30/09/2013&q=
FF - user.js: browser.startup.homepage - hxxp://start.search.us.com/v/2/?guid={7B4F761D-914B-4129-80D3-5852CD28A139}&serpv=5
FF - user.js: browser.startup.page - 1
FF - user.js: browser.newtab.url - file:///c:\users\Aidan\AppData\Local\TNT2\Common\pinnedSearch.htm
FF - user.js: browser.newtab.url -
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
BHO-{BA3E58F7-60C6-485E-A775-0C1FD9C0E55E} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-4191367178-1998265054-3350178268-1001_Classes\CLSID\{EA2D459F-DE55-EF43-8404-4162A591C937}]
@Denied: (A 4) (Everyone)
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-12-14 20:46:39
ComboFix-quarantined-files.txt 2013-12-14 12:46
ComboFix2.txt 2013-12-13 15:11
.
Pre-Run: 60,890,644,480 bytes free
Post-Run: 60,840,312,832 bytes free
.
- - End Of File - - 186955FCD4829614969CECCA42ED0332
Any help would be greatly appreciated here
Twin
Got some issues with my notebook.
Specs:
Samsung 300V3A
Core i7 2670QM 2.2ghz
4GB ram
A list of what has has happened so far,
Bluescreen during online gaming,
Difficulty loading Taskmanager
Slow at startup
Slow web browsing
Slow at running scans with either MSE or MBAM and that is only a quick scan, Trying full
scans results in odd pauses and eventually "not responding"
Touch navigation pad becomes unresponsive,
and the big one...the machine runs silly hot, no gaming, just browsing like I am right now.
Temps from speedfan place the gpu at 66 degs C and the cpu varies from 68 to 81 degrees C, not normal under light load conditions. Might explain the BSOD's
There are also several svchost.exe processes running at once, like 13 of em....? Odd?
The MBAM quick scan showed no issues as did the MSE quick scan yet the notebook still behaves like a snail.
ComboFix log
ComboFix 13-12-13.01 - Aidan 14/12/2013 20:26:18.3.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.4010.2752 [GMT 8:00]
Running from: c:\users\Aidan\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
AV: Norton Internet Security *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Norton Internet Security *Disabled/Outdated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2013-11-14 to 2013-12-14 )))))))))))))))))))))))))))))))
.
.
2013-12-14 12:44 . 2013-12-14 12:44--------d-----w-c:\users\UpdatusUser\AppData\Local\temp
2013-12-14 12:44 . 2013-12-14 12:44--------d-----w-c:\users\Default\AppData\Local\temp
2013-12-14 11:12 . 2013-12-14 11:1275888----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6F86C0EB-D67B-40B5-B4DD-DC09FB9EF8B7}\offreg.dll
2013-12-14 10:54 . 2013-11-08 03:1210285968----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6F86C0EB-D67B-40B5-B4DD-DC09FB9EF8B7}\mpengine.dll
2013-12-14 06:49 . 2013-12-14 06:49--------d-----w-C:\AI_RecycleBin
2013-12-14 00:05 . 2013-11-08 03:1210285968----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-12-12 07:39 . 2013-10-25 06:172648576----a-w-c:\windows\system32\iertutil.dll
2013-12-12 07:38 . 2013-10-25 06:1819271168----a-w-c:\windows\system32\mshtml.dll
2013-12-10 10:59 . 2013-12-10 10:59--------d-----w-c:\program files (x86)\Daring Development
2013-12-10 10:52 . 2013-12-12 14:02--------d-----w-c:\users\Aidan\AppData\Roaming\F8fbpsK9
2013-12-10 10:37 . 2013-12-12 14:59--------d-----w-c:\program files (x86)\Optimizer Pro
2013-12-06 14:40 . 2013-12-06 14:4020080----a-w-c:\program files (x86)\Mozilla Firefox\AccessibleMarshal.dll
2013-12-06 14:40 . 2013-12-06 14:402106216----a-w-c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2013-12-06 14:40 . 2013-12-06 14:4075376----a-w-c:\program files (x86)\Mozilla Firefox\breakpadinjector.dll
2013-12-06 14:40 . 2013-12-06 14:40272496----a-w-c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll
2013-12-06 14:40 . 2013-12-06 14:40117360----a-w-c:\program files (x86)\Mozilla Firefox\crashreporter.exe
2013-12-06 14:40 . 2013-12-06 14:40275568----a-w-c:\program files (x86)\Mozilla Firefox\firefox.exe
2013-12-06 14:40 . 2013-12-06 14:4064112----a-w-c:\program files (x86)\Mozilla Firefox\libEGL.dll
2013-12-06 14:40 . 2013-12-06 14:403459696----a-w-c:\program files (x86)\Mozilla Firefox\gkmedias.dll
2013-12-06 14:40 . 2013-12-06 14:40302192----a-w-c:\program files (x86)\Mozilla Firefox\freebl3.dll
2013-12-06 14:40 . 2013-12-06 14:40549488----a-w-c:\program files (x86)\Mozilla Firefox\libGLESv2.dll
2013-12-06 14:40 . 2013-12-06 14:40119408----a-w-c:\program files (x86)\Mozilla Firefox\maintenanceservice.exe
2013-12-06 05:57 . 2013-10-19 00:35965000------w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1718B1E1-3B97-413C-914A-B8BCEA0F4BAA}\gapaengine.dll
2013-11-26 03:51 . 2013-11-26 03:57--------d-----w-c:\program files\Adobe
2013-11-26 03:47 . 2013-11-26 03:53--------d-----w-c:\program files\Common Files\Adobe
2013-11-25 13:53 . 2013-12-12 14:50--------d-----w-c:\users\Aidan\AppData\Roaming\BitTorrent
2013-11-25 13:44 . 2013-12-12 15:09--------d-----w-c:\program files (x86)\TornTV.com
2013-11-23 09:04 . 2013-11-23 09:04--------d-----w-c:\users\Aidan\AppData\Roaming\openvr
2013-11-19 17:50 . 2013-12-13 14:27--------d-----w-C:\coin
2013-11-16 12:45 . 2009-05-29 08:08--------d-----w-C:\NOOBSCAPE RELEASE
2013-11-16 12:43 . 2009-06-04 09:20--------d-----w-C:\Noobscape Client
2013-11-16 09:00 . 2013-11-16 09:00--------d-----w-C:\found.003
2013-11-16 04:03 . 2013-09-04 12:12343040----a-w-c:\windows\system32\drivers\usbhub.sys
2013-11-16 04:03 . 2013-09-04 12:11325120----a-w-c:\windows\system32\drivers\usbport.sys
2013-11-16 04:03 . 2013-09-04 12:1199840----a-w-c:\windows\system32\drivers\usbccgp.sys
2013-11-16 04:03 . 2013-09-04 12:1152736----a-w-c:\windows\system32\drivers\usbehci.sys
2013-11-16 04:03 . 2013-09-04 12:1130720----a-w-c:\windows\system32\drivers\usbuhci.sys
2013-11-16 04:03 . 2013-09-04 12:117808----a-w-c:\windows\system32\drivers\usbd.sys
2013-11-16 04:03 . 2013-09-04 12:1125600----a-w-c:\windows\system32\drivers\usbohci.sys
2013-11-15 12:54 . 2012-02-04 17:09--------d-----w-C:\Insidia 2 Package
2013-11-15 12:50 . 2012-02-17 15:35--------d-----w-C:\InsidiaX.cache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-06 09:43 . 2013-07-20 22:3316152----a-w-c:\windows\system32\drivers\SWDUMon.sys
2013-11-19 10:21 . 2010-11-21 03:27267936------w-c:\windows\system32\MpSigStub.exe
2013-10-19 06:13 . 2013-10-19 06:13108968----a-w-c:\windows\system32\WindowsAccessBridge-64.dll
2013-10-19 06:13 . 2013-10-19 06:14312744----a-w-c:\windows\system32\javaws.exe
2013-10-19 06:13 . 2013-10-19 06:13189352----a-w-c:\windows\system32\javaw.exe
2013-10-19 06:13 . 2013-10-19 06:13189352----a-w-c:\windows\system32\java.exe
2013-10-19 00:35 . 2012-10-02 17:29965000------w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-10-12 02:30 . 2013-11-13 21:03830464----a-w-c:\windows\system32\nshwfp.dll
2013-10-12 02:29 . 2013-11-13 21:03859648----a-w-c:\windows\system32\IKEEXT.DLL
2013-10-12 02:29 . 2013-11-13 21:03324096----a-w-c:\windows\system32\FWPUCLNT.DLL
2013-10-12 02:03 . 2013-11-13 21:03656896----a-w-c:\windows\SysWow64\nshwfp.dll
2013-10-12 02:01 . 2013-11-13 21:03216576----a-w-c:\windows\SysWow64\FWPUCLNT.DLL
2013-10-05 20:25 . 2013-11-13 21:041474048----a-w-c:\windows\system32\crypt32.dll
2013-10-05 19:57 . 2013-11-13 21:041168384----a-w-c:\windows\SysWow64\crypt32.dll
2013-10-04 02:28 . 2013-11-13 21:04190464----a-w-c:\windows\system32\SmartcardCredentialProvider.dll
2013-10-04 02:25 . 2013-11-13 21:04197120----a-w-c:\windows\system32\credui.dll
2013-10-04 02:24 . 2013-11-13 21:041930752----a-w-c:\windows\system32\authui.dll
2013-10-04 01:58 . 2013-11-13 21:04152576----a-w-c:\windows\SysWow64\SmartcardCredentialProvider.dll
2013-10-04 01:56 . 2013-11-13 21:04168960----a-w-c:\windows\SysWow64\credui.dll
2013-10-04 01:56 . 2013-11-13 21:041796096----a-w-c:\windows\SysWow64\authui.dll
2013-10-03 02:23 . 2013-11-13 21:03404480----a-w-c:\windows\system32\gdi32.dll
2013-10-03 02:00 . 2013-11-13 21:03311808----a-w-c:\windows\SysWow64\gdi32.dll
2013-09-28 01:09 . 2013-11-13 21:04497152----a-w-c:\windows\system32\drivers\afd.sys
2013-09-27 01:53 . 2013-09-27 01:53248240----a-w-c:\windows\system32\drivers\MpFilter.sys
2013-09-27 01:53 . 2012-03-21 01:44134944----a-w-c:\windows\system32\drivers\NisDrvWFP.sys
2013-09-25 02:26 . 2013-11-13 21:04154560----a-w-c:\windows\system32\drivers\ksecpkg.sys
2013-09-25 02:26 . 2013-11-13 21:0495680----a-w-c:\windows\system32\drivers\ksecdd.sys
2013-09-25 02:23 . 2013-11-13 21:04135680----a-w-c:\windows\system32\sspicli.dll
2013-09-25 02:23 . 2013-11-13 21:0428672----a-w-c:\windows\system32\sspisrv.dll
2013-09-25 02:23 . 2013-11-13 21:0428160----a-w-c:\windows\system32\secur32.dll
2013-09-25 02:22 . 2013-11-13 21:04340992----a-w-c:\windows\system32\schannel.dll
2013-09-25 02:21 . 2013-11-13 21:04307200----a-w-c:\windows\system32\ncrypt.dll
2013-09-25 02:21 . 2013-11-13 21:041447936----a-w-c:\windows\system32\lsasrv.dll
2013-09-25 01:58 . 2013-11-13 21:0496768----a-w-c:\windows\SysWow64\sspicli.dll
2013-09-25 01:57 . 2013-11-13 21:0422016----a-w-c:\windows\SysWow64\secur32.dll
2013-09-25 01:57 . 2013-11-13 21:04247808----a-w-c:\windows\SysWow64\schannel.dll
2013-09-25 01:56 . 2013-11-13 21:04220160----a-w-c:\windows\SysWow64\ncrypt.dll
2013-09-25 01:03 . 2013-11-13 21:0430720----a-w-c:\windows\system32\lsass.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2013-12-11 1823656]
"Config"="c:\users\Aidan\AppData\Roaming\tasklaunch.exe" [2010-03-18 32592]
"WindowsNetworkClient"="c:\users\Aidan\AppData\Roaming\AppClient\RascalClient.exe" [2013-07-27 11776]
"Windows Compact Framework"="c:\users\Aidan\AppData\Roaming\AppClient\mm.exe" [2013-11-19 12800]
"Windows Miner Client"="c:\coin\xmine.exe" [2013-11-24 12288]
"p8F6lCgBkp"="c:\users\Aidan\AppData\Roaming\F8fbpsK9\TGDvRNf.exe.lnk" [2013-12-10 874]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 tor;Tor Win32 Service;c:\program files (x86)\Tor\tor.exe;c:\program files (x86)\Tor\tor.exe [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 Samsung UPD Service;Samsung UPD Service;c:\windows\System32\SUPDSvc.exe;c:\windows\SYSNATIVE\SUPDSvc.exe [x]
R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys;c:\windows\SYSNATIVE\DRIVERS\SWDUMon.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1207020.003\SYMDS64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1207020.003\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1207020.003\SYMEFA64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1207020.003\SYMEFA64.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20120823.005\BHDrvx64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20120823.005\BHDrvx64.sys [x]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20120828.001\IDSvia64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20120828.001\IDSvia64.sys [x]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys;c:\windows\SYSNATIVE\Drivers\SABI.sys [x]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1207020.003\Ironx64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1207020.003\Ironx64.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1207020.003\SYMNETS.SYS;c:\windows\SYSNATIVE\Drivers\NISx64\1207020.003\SYMNETS.SYS [x]
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [x]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe;c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe [x]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys;c:\windows\SYSNATIVE\Drivers\SSPORT.sys [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-12-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4191367178-1998265054-3350178268-1001Core1ce8564e19f1ad5.job
- c:\users\Aidan\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-25 00:51]
.
2013-12-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4191367178-1998265054-3350178268-1001UA1ce8564e50c3aed.job
- c:\users\Aidan\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-25 00:51]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-25 11895400]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-06-24 168216]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-06-24 418584]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-03-30 10372368]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 1266912]
"IntelTBRunOnce"="wscript.exe" [2013-10-12 168960]
"Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-19 444904]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://home.sweetim.com/?ptr=100&crg=3.1010000.10039&barid={E5362D76-D368-11E2-92A6-B80305750534}
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Aidan\AppData\Roaming\mozilla\firefox\Profiles\l69zelgy.default\
FF - prefs.js: browser.startup.homepage - hxxp://start.search.us.com/v/2/?guid={7B4F761D-914B-4129-80D3-5852CD28A139}&serpv=5
FF - prefs.js: keyword.URL - hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=AU&userid=f00e8de3-0b52-100e-2330-fe2d6c2ccd45&searchtype=ds&installDate=30/09/2013&q=
FF - user.js: browser.startup.homepage - hxxp://start.search.us.com/v/2/?guid={7B4F761D-914B-4129-80D3-5852CD28A139}&serpv=5
FF - user.js: browser.startup.page - 1
FF - user.js: browser.newtab.url - file:///c:\users\Aidan\AppData\Local\TNT2\Common\pinnedSearch.htm
FF - user.js: browser.newtab.url -
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
BHO-{BA3E58F7-60C6-485E-A775-0C1FD9C0E55E} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-4191367178-1998265054-3350178268-1001_Classes\CLSID\{EA2D459F-DE55-EF43-8404-4162A591C937}]
@Denied: (A 4) (Everyone)
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-12-14 20:46:39
ComboFix-quarantined-files.txt 2013-12-14 12:46
ComboFix2.txt 2013-12-13 15:11
.
Pre-Run: 60,890,644,480 bytes free
Post-Run: 60,840,312,832 bytes free
.
- - End Of File - - 186955FCD4829614969CECCA42ED0332
Any help would be greatly appreciated here
Twin