danabear
Posts: 10 +0
Recently I noticed I can't open certain programs up without my computer crashing like clockwork (bsod then restarts). I thought I could negate any of these issues by simply reinstalling windows, so I did that but to no avail. Same problems exist. I checked it with my antivirus (avg) and it came up with 28 rootkit errors and a svchost.exe trojan when scanned with mbam so I figured I'd come here for a final solution... hopefully.
Here are the logs. I think I followed your forum directions accurately, so if you need anything else let me know!
Thanks.
-----------------------------------------------------------------------------------------
Malwarebytes Anti-Malware (Trial) 1.65.1.1000
www.malwarebytes.org
Database version: v2012.11.29.08
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Dana :: BARBOBOT-PC [administrator]
Protection: Enabled
11/29/2012 9:48:36 AM
mbam-log-2012-11-29 (09-48-36).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 219599
Time elapsed: 1 minute(s), 35 second(s)
Memory Processes Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> 4904 -> Delete on reboot.
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 3
C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot.
C:\Program Files\!CheckMinSpec.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\!if.FileExists.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
(end)
-----------------------------------------------------------------------------------
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16455
Run by Dana at 10:10:13 on 2012-11-29
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.9207.7216 [GMT -5:00]
.
AV: AVG Internet Security 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG Internet Security 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
FW: AVG Internet Security 2013 *Enabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LSI SoftModem\agr64svc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Users\Dana\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Users\Dana\AppData\Local\Akamai\netsession_win.exe
C:\Users\Dana\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\AVG\AVG2013\avgcfgex.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe,
uRun: [Spotify] "C:\Users\Dana\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
uRun: [Spotify Web Helper] "C:\Users\Dana\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
uRun: [Akamai NetSession Interface] "C:\Users\Dana\AppData\Local\Akamai\netsession_win.exe"
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
StartupFolder: C:\Users\Dana\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Dana\AppData\Roaming\Dropbox\bin\Dropbox.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: NameServer = 192.168.169.1
TCP: Interfaces\{0961E6E7-5741-49CA-BB5A-3437A2BA979F} : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{6E99B88D-980E-411D-9B96-2665F80DCAED} : DHCPNameServer = 192.168.169.1
SSODL: WebCheck - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-10-15 63328]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2012-9-21 225120]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2012-10-5 111456]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-9-14 40800]
R1 Avgfwfd;AVG network filter service;C:\Windows\System32\drivers\avgfwd6a.sys [2012-9-4 50296]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2012-10-22 154464]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-10-2 185696]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-9-21 200032]
R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2013\avgfws.exe [2012-11-2 1340976]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-6 5814392]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-11-29 399432]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-11-29 676936]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;C:\Windows\System32\drivers\e1y60x64.sys [2009-6-10 281088]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-11-29 25928]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-11-29 1432400]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-11-28 1255736]
.
=============== Created Last 30 ================
.
2012-11-29 14:54:1020480----a-w-C:\Windows\svchost.exe
2012-11-29 14:47:15--------d-----w-C:\Users\Dana\AppData\Roaming\Malwarebytes
2012-11-29 14:46:50--------d-----w-C:\ProgramData\Malwarebytes
2012-11-29 14:46:4925928----a-w-C:\Windows\System32\drivers\mbam.sys
2012-11-29 14:46:49--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-11-29 13:51:45--------d-----w-C:\Users\Dana\AppData\Local\Autodesk
2012-11-29 13:40:31--------d-----w-C:\Program Files (x86)\Autodesk
2012-11-29 13:38:38--------d-----w-C:\Program Files\Common Files\Macrovision Shared
2012-11-29 13:36:09--------d-----w-C:\Program Files\Common Files\Autodesk Shared
2012-11-29 13:36:09--------d-----w-C:\Program Files\Autodesk
2012-11-29 13:34:59540688----a-w-C:\Windows\System32\d3dx10_39.dll
2012-11-29 13:16:33--------d-----w-C:\Users\Dana\AppData\Roaming\Autodesk
2012-11-29 13:16:24--------d-----w-C:\Program Files\eula
2012-11-29 13:16:20500136----a-w-C:\Program Files\Setup.exe
2012-11-29 13:16:20--------d-----w-C:\Program Files\NLSDL
2012-11-29 13:16:14--------d-----w-C:\Program Files\zh-CN
2012-11-29 13:16:14--------d-----w-C:\Program Files\Setup
2012-11-29 13:16:14--------d-----w-C:\Program Files\ja-JP
2012-11-29 13:16:14--------d-----w-C:\Program Files\en-US
2012-11-29 13:16:14--------d-----w-C:\Program Files\CER
2012-11-29 13:15:38--------d-----w-C:\Program Files\3rdParty
2012-11-29 13:15:34--------d-----w-C:\Program Files\x64
2012-11-29 13:15:34--------d-----w-C:\Program Files\SetupRes
2012-11-29 13:14:36--------d-----w-C:\Program Files\Resources
2012-11-29 13:14:36--------d-----w-C:\Program Files\Locale
2012-11-29 13:14:35--------d-----w-C:\Program Files\GraphicsData
2012-11-29 13:12:06--------d-----w-C:\Program Files\CommonData
2012-11-29 13:05:43314784----a-w-C:\Program Files\Uninstaller.exe
2012-11-29 13:00:53--------d-----w-C:\Users\Dana\AppData\Local\Akamai
2012-11-29 04:59:31--------d-----w-C:\Program Files (x86)\Steam
2012-11-29 04:59:31--------d-----w-C:\Program Files (x86)\Common Files\Steam
2012-11-29 04:53:14--------d-----w-C:\Users\Dana\AppData\Roaming\Dropbox
2012-11-29 04:51:22--------d-----w-C:\Users\Dana\AppData\Local\Spotify
2012-11-29 04:50:54--------d-----w-C:\Users\Dana\AppData\Roaming\Spotify
2012-11-29 04:48:53--------d-----w-C:\Users\Dana\AppData\Roaming\NVIDIA
2012-11-29 04:48:36--------d-----w-C:\Program Files\Speccy
2012-11-29 04:47:29--------d-----w-C:\Program Files (x86)\VideoLAN
2012-11-29 04:33:25--------d-----w-C:\Users\Dana\AppData\Local\ElevatedDiagnostics
2012-11-29 02:49:11--------d-----w-C:\Users\Dana\AppData\Local\Apple Computer
2012-11-29 02:49:0133240----a-w-C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-11-29 02:47:30--------d-----w-C:\Program Files\iPod
2012-11-29 02:47:29--------d-----w-C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-11-29 02:47:29--------d-----w-C:\Program Files (x86)\iTunes
2012-11-29 02:47:28--------d-----w-C:\Program Files\iTunes
2012-11-29 02:45:57--------d-----w-C:\Users\Dana\AppData\Local\Apple
2012-11-29 02:44:33--------d-----w-C:\Program Files\Bonjour
2012-11-29 02:44:33--------d-----w-C:\Program Files (x86)\Bonjour
2012-11-29 02:36:03--------d-----w-C:\Users\Dana\AppData\Roaming\LolClient
2012-11-29 02:21:4568616----a-w-C:\Windows\SysWow64\XAPOFX1_1.dll
2012-11-29 02:21:45509448----a-w-C:\Windows\SysWow64\XAudio2_2.dll
2012-11-29 02:21:45467984----a-w-C:\Windows\SysWow64\d3dx10_39.dll
2012-11-29 02:21:453851784----a-w-C:\Windows\SysWow64\D3DX9_39.dll
2012-11-29 02:21:451493528----a-w-C:\Windows\SysWow64\D3DCompiler_39.dll
2012-11-29 02:16:22--------d-----w-C:\Riot Games
2012-11-29 01:42:38--------d-----w-C:\Program Files\CCleaner
2012-11-29 01:20:48--------d-----w-C:\Users\Dana\AppData\Roaming\AVG2013
2012-11-29 01:17:48--------d-----w-C:\Users\Dana\AppData\Roaming\TuneUp Software
2012-11-29 01:16:03--------d--h--w-C:\$AVG
2012-11-29 01:16:03--------d-----w-C:\ProgramData\AVG2013
2012-11-29 01:14:54--------d-----w-C:\Program Files (x86)\AVG
2012-11-29 01:06:51--------d--h--w-C:\ProgramData\Common Files
2012-11-29 01:06:50--------d-----w-C:\Users\Dana\AppData\Local\Avg2013
2012-11-29 01:06:49--------d-----w-C:\Users\Dana\AppData\Local\MFAData
2012-11-29 01:06:48--------d-----w-C:\ProgramData\MFAData
2012-11-29 01:01:31--------d-----w-C:\Program Files\LSI SoftModem
2012-11-29 00:55:55--------d-----w-C:\Users\Dana\AppData\Local\PMB Files
2012-11-29 00:55:54--------d-----w-C:\ProgramData\PMB Files
2012-11-29 00:55:45--------d-----w-C:\Program Files (x86)\Pando Networks
2012-11-29 00:52:00--------d-sh--w-C:\Windows\Installer
2012-11-29 00:47:51--------d-----w-C:\Users\Dana\AppData\Local\Google
2012-11-29 00:47:30--------d-----w-C:\Users\Dana\AppData\Local\Apps
2012-11-29 00:47:29--------d-----w-C:\Users\Dana\AppData\Local\Deployment
2012-11-29 00:39:01--------d-----w-C:\Windows\SysWow64\Wat
2012-11-29 00:39:00--------d-----w-C:\Windows\System32\Wat
2012-11-29 00:24:018199504----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-11-29 00:23:569125352----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{90A7E907-D83E-47A3-BCB1-1C16AF602FA3}\mpengine.dll
2012-11-29 00:13:439728----a-w-C:\Windows\System32\Wdfres.dll
2012-11-29 00:13:43785512----a-w-C:\Windows\System32\drivers\Wdf01000.sys
2012-11-29 00:13:4354376----a-w-C:\Windows\System32\drivers\WdfLdr.sys
2012-11-29 00:13:432560----a-w-C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2012-11-29 00:02:1587040----a-w-C:\Windows\System32\drivers\WUDFPf.sys
2012-11-29 00:02:1584992----a-w-C:\Windows\System32\WUDFSvc.dll
2012-11-29 00:02:15744448----a-w-C:\Windows\System32\WUDFx.dll
2012-11-29 00:02:1545056----a-w-C:\Windows\System32\WUDFCoinstaller.dll
2012-11-29 00:02:15229888----a-w-C:\Windows\System32\WUDFHost.exe
2012-11-29 00:02:15198656----a-w-C:\Windows\System32\drivers\WUDFRd.sys
2012-11-29 00:02:15194048----a-w-C:\Windows\System32\WUDFPlatform.dll
2012-11-29 00:01:0681408----a-w-C:\Windows\System32\imagehlp.dll
2012-11-29 00:01:065120----a-w-C:\Windows\SysWow64\wmi.dll
2012-11-29 00:01:065120----a-w-C:\Windows\System32\wmi.dll
2012-11-29 00:01:0623408----a-w-C:\Windows\System32\drivers\fs_rec.sys
2012-11-29 00:01:06159232----a-w-C:\Windows\SysWow64\imagehlp.dll
2012-11-28 23:59:10--------d-----w-C:\Program Files (x86)\NVIDIA Corporation
2012-11-28 23:58:53891240----a-w-C:\Windows\System32\nvvsvc.exe
2012-11-28 23:58:5363336----a-w-C:\Windows\System32\nvshext.dll
2012-11-28 23:58:536200680----a-w-C:\Windows\System32\nvcpl.dll
2012-11-28 23:58:533293544----a-w-C:\Windows\System32\nvsvc64.dll
2012-11-28 23:58:532557800----a-w-C:\Windows\System32\nvsvcr.dll
2012-11-28 23:58:53118120----a-w-C:\Windows\System32\nvmctray.dll
2012-11-28 23:58:2660776----a-w-C:\Windows\System32\OpenCL.dll
2012-11-28 23:58:2652584----a-w-C:\Windows\SysWow64\OpenCL.dll
2012-11-28 23:57:53--------d-----w-C:\ProgramData\NVIDIA Corporation
2012-11-28 23:57:31--------d-----w-C:\Program Files\NVIDIA Corporation
2012-11-28 23:54:5931232----a-w-C:\Windows\SysWow64\prevhost.exe
2012-11-28 23:53:59514560----a-w-C:\Windows\SysWow64\qdvd.dll
2012-11-28 23:51:43184320----a-w-C:\Windows\System32\cryptsvc.dll
2012-11-28 23:51:431464320----a-w-C:\Windows\System32\crypt32.dll
2012-11-28 23:51:43140288----a-w-C:\Windows\SysWow64\cryptsvc.dll
2012-11-28 23:51:43140288----a-w-C:\Windows\System32\cryptnet.dll
2012-11-28 23:51:431159680----a-w-C:\Windows\SysWow64\crypt32.dll
2012-11-28 23:51:43103936----a-w-C:\Windows\SysWow64\cryptnet.dll
2012-11-28 23:45:5377312----a-w-C:\Windows\System32\packager.dll
2012-11-28 23:45:5367072----a-w-C:\Windows\SysWow64\packager.dll
2012-11-28 23:44:10--------d-----w-C:\Windows\Panther
2012-11-28 23:33:352622464----a-w-C:\Windows\System32\wucltux.dll
2012-11-28 23:33:2899840----a-w-C:\Windows\System32\wudriver.dll
2012-11-28 23:33:1136864----a-w-C:\Windows\System32\wuapp.exe
2012-11-28 23:33:11186752----a-w-C:\Windows\System32\wuwebv.dll
2012-11-28 23:02:10--------d-----w-C:\Users\Dana\AppData\Local\Diagnostics
2012-11-28 22:13:08--------d-----w-C:\Users\Dana\.swt
2012-11-28 22:06:05--------d-----w-C:\Users\Dana\AppData\Local\VirtualStore
2012-11-20 23:37:13--------d-----w-C:\Crash
2012-11-20 13:42:08960968----a-w-C:\Program Files\LaunchPad.exe
2012-11-13 00:40:05--------d-----w-C:\AdobeTemp
.
==================== Find3M ====================
.
2012-10-22 18:02:44154464----a-w-C:\Windows\System32\drivers\avgidsdrivera.sys
2012-10-18 18:25:583149824----a-w-C:\Windows\System32\win32k.sys
2012-10-16 08:38:37135168----a-w-C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38:34350208----a-w-C:\Windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39:52561664----a-w-C:\Windows\apppatch\AcLayers.dll
2012-10-15 08:48:5063328----a-w-C:\Windows\System32\drivers\avgidsha.sys
2012-10-11 02:22:542428776----a-w-C:\Windows\SysWow64\nvapi.dll
2012-10-11 02:22:5226331496----a-w-C:\Windows\System32\nvoglv64.dll
2012-10-11 02:22:521760104----a-w-C:\Windows\System32\nvdispco64.dll
2012-10-11 02:22:3215309160----a-w-C:\Windows\SysWow64\nvd3dum.dll
2012-10-11 02:22:262747240----a-w-C:\Windows\System32\nvcuvid.dll
2012-10-11 02:22:2419906920----a-w-C:\Windows\SysWow64\nvoglv32.dll
2012-10-11 02:22:1813443944----a-w-C:\Windows\System32\drivers\nvlddmkm.sys
2012-10-11 02:22:1417559912----a-w-C:\Windows\SysWow64\nvcompiler.dll
2012-10-09 18:17:1355296----a-w-C:\Windows\System32\dhcpcsvc6.dll
2012-10-09 18:17:13226816----a-w-C:\Windows\System32\dhcpcore6.dll
2012-10-09 17:40:3144032----a-w-C:\Windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40:31193536----a-w-C:\Windows\SysWow64\dhcpcore6.dll
2012-10-05 08:32:50111456----a-w-C:\Windows\System32\drivers\avgmfx64.sys
2012-10-03 17:56:541914248----a-w-C:\Windows\System32\drivers\tcpip.sys
2012-10-03 17:44:2170656----a-w-C:\Windows\System32\nlaapi.dll
2012-10-03 17:44:21303104----a-w-C:\Windows\System32\nlasvc.dll
2012-10-03 17:44:17246272----a-w-C:\Windows\System32\netcorehc.dll
2012-10-03 17:44:1718944----a-w-C:\Windows\System32\netevent.dll
2012-10-03 17:44:16216576----a-w-C:\Windows\System32\ncsi.dll
2012-10-03 17:42:16569344----a-w-C:\Windows\System32\iphlpsvc.dll
2012-10-03 16:42:2418944----a-w-C:\Windows\SysWow64\netevent.dll
2012-10-03 16:42:24175104----a-w-C:\Windows\SysWow64\netcorehc.dll
2012-10-03 16:42:23156672----a-w-C:\Windows\SysWow64\ncsi.dll
2012-10-03 16:07:2645568----a-w-C:\Windows\System32\drivers\tcpipreg.sys
2012-10-02 18:15:52430952----a-w-C:\Windows\SysWow64\nvStreaming.exe
2012-10-02 08:30:38185696----a-w-C:\Windows\System32\drivers\avgldx64.sys
2012-09-25 22:47:4378336----a-w-C:\Windows\SysWow64\synceng.dll
2012-09-25 22:46:1795744----a-w-C:\Windows\System32\synceng.dll
2012-09-21 08:46:04200032----a-w-C:\Windows\System32\drivers\avgtdia.sys
2012-09-21 08:46:00225120----a-w-C:\Windows\System32\drivers\avgloga.sys
2012-09-14 19:19:292048----a-w-C:\Windows\System32\tzres.dll
2012-09-14 18:28:532048----a-w-C:\Windows\SysWow64\tzres.dll
2012-09-14 08:05:1840800----a-w-C:\Windows\System32\drivers\avgrkx64.sys
2012-09-04 15:39:3250296----a-w-C:\Windows\System32\drivers\avgfwd6a.sys
2012-08-31 18:19:351659760----a-w-C:\Windows\System32\drivers\ntfs.sys
.
============= FINISH: 10:10:34.49 ===============
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 11/28/2012 5:05:52 PM
System Uptime: 11/29/2012 9:52:34 AM (1 hours ago)
.
Motherboard: Gateway | | TBGM01
Processor: Intel(R) Core(TM) i7 CPU 950 @ 3.07GHz | CPU 1 | 3037/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 917 GiB total, 821.693 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
G: is Removable
H: is Removable
I: is FIXED (NTFS) - 466 GiB total, 357.108 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
Description: Microsoft PS/2 Mouse
Device ID: ACPI\PNP0F03\4&6730480&0
Manufacturer: Microsoft
Name: Microsoft PS/2 Mouse
PNP Device ID: ACPI\PNP0F03\4&6730480&0
Service: i8042prt
.
==== System Restore Points ===================
.
RP7: 11/28/2012 8:13:13 PM - Installed AVG 2013
RP8: 11/28/2012 8:14:59 PM - Installed AVG 2013
RP9: 11/28/2012 8:23:40 PM - Windows Update
RP10: 11/28/2012 9:16:10 PM - Installed League of Legends
RP11: 11/28/2012 9:46:03 PM - Installed iTunes
RP12: 11/28/2012 11:58:00 PM - Installed 7-Zip 9.20 (x64 edition)
RP13: 11/28/2012 11:58:44 PM - Installed Steam
RP14: 11/29/2012 8:05:50 AM - Installed DirectX
RP15: 11/29/2012 8:33:47 AM - Installed DirectX
.
==== Installed Programs ======================
.
7-Zip 9.20 (x64 edition)
Akamai NetSession Interface
Apple Application Support
Apple Mobile Device Support
Apple Software Update
applicationupdater
Autodesk Backburner 2013.0.0
Autodesk DirectConnect 2013 64-bit
Autodesk FBX Plug-in 2013.1 - Maya 2013 64-bit
Autodesk MatchMover 2013 64-bit
Autodesk Maya 2013 64-bit
AVG 2013
Bonjour
CCleaner
Composite 2013 64-bit
Dropbox
gamelauncher-ps2-live
Google Chrome
Google Update Helper
iTunes
League of Legends
LSI PCI-SV92EX Soft Modem
Malwarebytes Anti-Malware version 1.65.1.1000
Microsoft .NET Framework 4 Client Profile
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
NVIDIA 3D Vision Driver 306.97
NVIDIA Control Panel 306.97
NVIDIA Graphics Driver 306.97
NVIDIA Install Application
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.10.8
NVIDIA Update Components
Pando Media Booster
PlanetSide 2
Speccy
Spotify
Steam
Visual Studio 2010 x64 Redistributables
VLC media player 2.0.4
.
==== Event Viewer Messages From Past Week ========
.
11/29/2012 9:53:14 AM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied.
11/29/2012 8:53:54 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff880ea0e6bb0, 0x0000000000000001, 0xfffffa80093ed2e6, 0x0000000000000005). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 112912-41059-01.
11/29/2012 12:00:22 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
11/29/2012 12:00:22 AM, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
11/28/2012 8:12:46 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk5\DR5.
11/28/2012 8:12:36 PM, Error: volsnap [25] - The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time. Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.
11/28/2012 7:34:15 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Update for Internet Explorer 8 Compatibility View List for Windows 7 for x64-based Systems (KB2598845).
11/28/2012 7:34:15 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Security Update for Internet Explorer 8 for Windows 7 for x64-based Systems (KB2544521).
11/28/2012 7:32:23 PM, Error: Service Control Manager [7023] -
11/28/2012 7:28:53 PM, Error: Service Control Manager [7034] - The NVIDIA Stereoscopic 3D Driver Service service terminated unexpectedly. It has done this 1 time(s).
11/28/2012 7:28:52 PM, Error: Service Control Manager [7034] - The NVIDIA Update Service Daemon service terminated unexpectedly. It has done this 1 time(s).
11/28/2012 6:34:05 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024d00e: Windows Update Core.
.
==== End Of File ===========================
Here are the logs. I think I followed your forum directions accurately, so if you need anything else let me know!
Thanks.
-----------------------------------------------------------------------------------------
Malwarebytes Anti-Malware (Trial) 1.65.1.1000
www.malwarebytes.org
Database version: v2012.11.29.08
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Dana :: BARBOBOT-PC [administrator]
Protection: Enabled
11/29/2012 9:48:36 AM
mbam-log-2012-11-29 (09-48-36).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 219599
Time elapsed: 1 minute(s), 35 second(s)
Memory Processes Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> 4904 -> Delete on reboot.
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 3
C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot.
C:\Program Files\!CheckMinSpec.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\!if.FileExists.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
(end)
-----------------------------------------------------------------------------------
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16455
Run by Dana at 10:10:13 on 2012-11-29
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.9207.7216 [GMT -5:00]
.
AV: AVG Internet Security 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG Internet Security 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
FW: AVG Internet Security 2013 *Enabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LSI SoftModem\agr64svc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Users\Dana\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Users\Dana\AppData\Local\Akamai\netsession_win.exe
C:\Users\Dana\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\AVG\AVG2013\avgcfgex.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe,
uRun: [Spotify] "C:\Users\Dana\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
uRun: [Spotify Web Helper] "C:\Users\Dana\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
uRun: [Akamai NetSession Interface] "C:\Users\Dana\AppData\Local\Akamai\netsession_win.exe"
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
StartupFolder: C:\Users\Dana\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Dana\AppData\Roaming\Dropbox\bin\Dropbox.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: NameServer = 192.168.169.1
TCP: Interfaces\{0961E6E7-5741-49CA-BB5A-3437A2BA979F} : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{6E99B88D-980E-411D-9B96-2665F80DCAED} : DHCPNameServer = 192.168.169.1
SSODL: WebCheck - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-10-15 63328]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2012-9-21 225120]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2012-10-5 111456]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-9-14 40800]
R1 Avgfwfd;AVG network filter service;C:\Windows\System32\drivers\avgfwd6a.sys [2012-9-4 50296]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2012-10-22 154464]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-10-2 185696]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-9-21 200032]
R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2013\avgfws.exe [2012-11-2 1340976]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-6 5814392]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-11-29 399432]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-11-29 676936]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;C:\Windows\System32\drivers\e1y60x64.sys [2009-6-10 281088]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-11-29 25928]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-11-29 1432400]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-11-28 1255736]
.
=============== Created Last 30 ================
.
2012-11-29 14:54:1020480----a-w-C:\Windows\svchost.exe
2012-11-29 14:47:15--------d-----w-C:\Users\Dana\AppData\Roaming\Malwarebytes
2012-11-29 14:46:50--------d-----w-C:\ProgramData\Malwarebytes
2012-11-29 14:46:4925928----a-w-C:\Windows\System32\drivers\mbam.sys
2012-11-29 14:46:49--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-11-29 13:51:45--------d-----w-C:\Users\Dana\AppData\Local\Autodesk
2012-11-29 13:40:31--------d-----w-C:\Program Files (x86)\Autodesk
2012-11-29 13:38:38--------d-----w-C:\Program Files\Common Files\Macrovision Shared
2012-11-29 13:36:09--------d-----w-C:\Program Files\Common Files\Autodesk Shared
2012-11-29 13:36:09--------d-----w-C:\Program Files\Autodesk
2012-11-29 13:34:59540688----a-w-C:\Windows\System32\d3dx10_39.dll
2012-11-29 13:16:33--------d-----w-C:\Users\Dana\AppData\Roaming\Autodesk
2012-11-29 13:16:24--------d-----w-C:\Program Files\eula
2012-11-29 13:16:20500136----a-w-C:\Program Files\Setup.exe
2012-11-29 13:16:20--------d-----w-C:\Program Files\NLSDL
2012-11-29 13:16:14--------d-----w-C:\Program Files\zh-CN
2012-11-29 13:16:14--------d-----w-C:\Program Files\Setup
2012-11-29 13:16:14--------d-----w-C:\Program Files\ja-JP
2012-11-29 13:16:14--------d-----w-C:\Program Files\en-US
2012-11-29 13:16:14--------d-----w-C:\Program Files\CER
2012-11-29 13:15:38--------d-----w-C:\Program Files\3rdParty
2012-11-29 13:15:34--------d-----w-C:\Program Files\x64
2012-11-29 13:15:34--------d-----w-C:\Program Files\SetupRes
2012-11-29 13:14:36--------d-----w-C:\Program Files\Resources
2012-11-29 13:14:36--------d-----w-C:\Program Files\Locale
2012-11-29 13:14:35--------d-----w-C:\Program Files\GraphicsData
2012-11-29 13:12:06--------d-----w-C:\Program Files\CommonData
2012-11-29 13:05:43314784----a-w-C:\Program Files\Uninstaller.exe
2012-11-29 13:00:53--------d-----w-C:\Users\Dana\AppData\Local\Akamai
2012-11-29 04:59:31--------d-----w-C:\Program Files (x86)\Steam
2012-11-29 04:59:31--------d-----w-C:\Program Files (x86)\Common Files\Steam
2012-11-29 04:53:14--------d-----w-C:\Users\Dana\AppData\Roaming\Dropbox
2012-11-29 04:51:22--------d-----w-C:\Users\Dana\AppData\Local\Spotify
2012-11-29 04:50:54--------d-----w-C:\Users\Dana\AppData\Roaming\Spotify
2012-11-29 04:48:53--------d-----w-C:\Users\Dana\AppData\Roaming\NVIDIA
2012-11-29 04:48:36--------d-----w-C:\Program Files\Speccy
2012-11-29 04:47:29--------d-----w-C:\Program Files (x86)\VideoLAN
2012-11-29 04:33:25--------d-----w-C:\Users\Dana\AppData\Local\ElevatedDiagnostics
2012-11-29 02:49:11--------d-----w-C:\Users\Dana\AppData\Local\Apple Computer
2012-11-29 02:49:0133240----a-w-C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-11-29 02:47:30--------d-----w-C:\Program Files\iPod
2012-11-29 02:47:29--------d-----w-C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-11-29 02:47:29--------d-----w-C:\Program Files (x86)\iTunes
2012-11-29 02:47:28--------d-----w-C:\Program Files\iTunes
2012-11-29 02:45:57--------d-----w-C:\Users\Dana\AppData\Local\Apple
2012-11-29 02:44:33--------d-----w-C:\Program Files\Bonjour
2012-11-29 02:44:33--------d-----w-C:\Program Files (x86)\Bonjour
2012-11-29 02:36:03--------d-----w-C:\Users\Dana\AppData\Roaming\LolClient
2012-11-29 02:21:4568616----a-w-C:\Windows\SysWow64\XAPOFX1_1.dll
2012-11-29 02:21:45509448----a-w-C:\Windows\SysWow64\XAudio2_2.dll
2012-11-29 02:21:45467984----a-w-C:\Windows\SysWow64\d3dx10_39.dll
2012-11-29 02:21:453851784----a-w-C:\Windows\SysWow64\D3DX9_39.dll
2012-11-29 02:21:451493528----a-w-C:\Windows\SysWow64\D3DCompiler_39.dll
2012-11-29 02:16:22--------d-----w-C:\Riot Games
2012-11-29 01:42:38--------d-----w-C:\Program Files\CCleaner
2012-11-29 01:20:48--------d-----w-C:\Users\Dana\AppData\Roaming\AVG2013
2012-11-29 01:17:48--------d-----w-C:\Users\Dana\AppData\Roaming\TuneUp Software
2012-11-29 01:16:03--------d--h--w-C:\$AVG
2012-11-29 01:16:03--------d-----w-C:\ProgramData\AVG2013
2012-11-29 01:14:54--------d-----w-C:\Program Files (x86)\AVG
2012-11-29 01:06:51--------d--h--w-C:\ProgramData\Common Files
2012-11-29 01:06:50--------d-----w-C:\Users\Dana\AppData\Local\Avg2013
2012-11-29 01:06:49--------d-----w-C:\Users\Dana\AppData\Local\MFAData
2012-11-29 01:06:48--------d-----w-C:\ProgramData\MFAData
2012-11-29 01:01:31--------d-----w-C:\Program Files\LSI SoftModem
2012-11-29 00:55:55--------d-----w-C:\Users\Dana\AppData\Local\PMB Files
2012-11-29 00:55:54--------d-----w-C:\ProgramData\PMB Files
2012-11-29 00:55:45--------d-----w-C:\Program Files (x86)\Pando Networks
2012-11-29 00:52:00--------d-sh--w-C:\Windows\Installer
2012-11-29 00:47:51--------d-----w-C:\Users\Dana\AppData\Local\Google
2012-11-29 00:47:30--------d-----w-C:\Users\Dana\AppData\Local\Apps
2012-11-29 00:47:29--------d-----w-C:\Users\Dana\AppData\Local\Deployment
2012-11-29 00:39:01--------d-----w-C:\Windows\SysWow64\Wat
2012-11-29 00:39:00--------d-----w-C:\Windows\System32\Wat
2012-11-29 00:24:018199504----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-11-29 00:23:569125352----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{90A7E907-D83E-47A3-BCB1-1C16AF602FA3}\mpengine.dll
2012-11-29 00:13:439728----a-w-C:\Windows\System32\Wdfres.dll
2012-11-29 00:13:43785512----a-w-C:\Windows\System32\drivers\Wdf01000.sys
2012-11-29 00:13:4354376----a-w-C:\Windows\System32\drivers\WdfLdr.sys
2012-11-29 00:13:432560----a-w-C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2012-11-29 00:02:1587040----a-w-C:\Windows\System32\drivers\WUDFPf.sys
2012-11-29 00:02:1584992----a-w-C:\Windows\System32\WUDFSvc.dll
2012-11-29 00:02:15744448----a-w-C:\Windows\System32\WUDFx.dll
2012-11-29 00:02:1545056----a-w-C:\Windows\System32\WUDFCoinstaller.dll
2012-11-29 00:02:15229888----a-w-C:\Windows\System32\WUDFHost.exe
2012-11-29 00:02:15198656----a-w-C:\Windows\System32\drivers\WUDFRd.sys
2012-11-29 00:02:15194048----a-w-C:\Windows\System32\WUDFPlatform.dll
2012-11-29 00:01:0681408----a-w-C:\Windows\System32\imagehlp.dll
2012-11-29 00:01:065120----a-w-C:\Windows\SysWow64\wmi.dll
2012-11-29 00:01:065120----a-w-C:\Windows\System32\wmi.dll
2012-11-29 00:01:0623408----a-w-C:\Windows\System32\drivers\fs_rec.sys
2012-11-29 00:01:06159232----a-w-C:\Windows\SysWow64\imagehlp.dll
2012-11-28 23:59:10--------d-----w-C:\Program Files (x86)\NVIDIA Corporation
2012-11-28 23:58:53891240----a-w-C:\Windows\System32\nvvsvc.exe
2012-11-28 23:58:5363336----a-w-C:\Windows\System32\nvshext.dll
2012-11-28 23:58:536200680----a-w-C:\Windows\System32\nvcpl.dll
2012-11-28 23:58:533293544----a-w-C:\Windows\System32\nvsvc64.dll
2012-11-28 23:58:532557800----a-w-C:\Windows\System32\nvsvcr.dll
2012-11-28 23:58:53118120----a-w-C:\Windows\System32\nvmctray.dll
2012-11-28 23:58:2660776----a-w-C:\Windows\System32\OpenCL.dll
2012-11-28 23:58:2652584----a-w-C:\Windows\SysWow64\OpenCL.dll
2012-11-28 23:57:53--------d-----w-C:\ProgramData\NVIDIA Corporation
2012-11-28 23:57:31--------d-----w-C:\Program Files\NVIDIA Corporation
2012-11-28 23:54:5931232----a-w-C:\Windows\SysWow64\prevhost.exe
2012-11-28 23:53:59514560----a-w-C:\Windows\SysWow64\qdvd.dll
2012-11-28 23:51:43184320----a-w-C:\Windows\System32\cryptsvc.dll
2012-11-28 23:51:431464320----a-w-C:\Windows\System32\crypt32.dll
2012-11-28 23:51:43140288----a-w-C:\Windows\SysWow64\cryptsvc.dll
2012-11-28 23:51:43140288----a-w-C:\Windows\System32\cryptnet.dll
2012-11-28 23:51:431159680----a-w-C:\Windows\SysWow64\crypt32.dll
2012-11-28 23:51:43103936----a-w-C:\Windows\SysWow64\cryptnet.dll
2012-11-28 23:45:5377312----a-w-C:\Windows\System32\packager.dll
2012-11-28 23:45:5367072----a-w-C:\Windows\SysWow64\packager.dll
2012-11-28 23:44:10--------d-----w-C:\Windows\Panther
2012-11-28 23:33:352622464----a-w-C:\Windows\System32\wucltux.dll
2012-11-28 23:33:2899840----a-w-C:\Windows\System32\wudriver.dll
2012-11-28 23:33:1136864----a-w-C:\Windows\System32\wuapp.exe
2012-11-28 23:33:11186752----a-w-C:\Windows\System32\wuwebv.dll
2012-11-28 23:02:10--------d-----w-C:\Users\Dana\AppData\Local\Diagnostics
2012-11-28 22:13:08--------d-----w-C:\Users\Dana\.swt
2012-11-28 22:06:05--------d-----w-C:\Users\Dana\AppData\Local\VirtualStore
2012-11-20 23:37:13--------d-----w-C:\Crash
2012-11-20 13:42:08960968----a-w-C:\Program Files\LaunchPad.exe
2012-11-13 00:40:05--------d-----w-C:\AdobeTemp
.
==================== Find3M ====================
.
2012-10-22 18:02:44154464----a-w-C:\Windows\System32\drivers\avgidsdrivera.sys
2012-10-18 18:25:583149824----a-w-C:\Windows\System32\win32k.sys
2012-10-16 08:38:37135168----a-w-C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38:34350208----a-w-C:\Windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39:52561664----a-w-C:\Windows\apppatch\AcLayers.dll
2012-10-15 08:48:5063328----a-w-C:\Windows\System32\drivers\avgidsha.sys
2012-10-11 02:22:542428776----a-w-C:\Windows\SysWow64\nvapi.dll
2012-10-11 02:22:5226331496----a-w-C:\Windows\System32\nvoglv64.dll
2012-10-11 02:22:521760104----a-w-C:\Windows\System32\nvdispco64.dll
2012-10-11 02:22:3215309160----a-w-C:\Windows\SysWow64\nvd3dum.dll
2012-10-11 02:22:262747240----a-w-C:\Windows\System32\nvcuvid.dll
2012-10-11 02:22:2419906920----a-w-C:\Windows\SysWow64\nvoglv32.dll
2012-10-11 02:22:1813443944----a-w-C:\Windows\System32\drivers\nvlddmkm.sys
2012-10-11 02:22:1417559912----a-w-C:\Windows\SysWow64\nvcompiler.dll
2012-10-09 18:17:1355296----a-w-C:\Windows\System32\dhcpcsvc6.dll
2012-10-09 18:17:13226816----a-w-C:\Windows\System32\dhcpcore6.dll
2012-10-09 17:40:3144032----a-w-C:\Windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40:31193536----a-w-C:\Windows\SysWow64\dhcpcore6.dll
2012-10-05 08:32:50111456----a-w-C:\Windows\System32\drivers\avgmfx64.sys
2012-10-03 17:56:541914248----a-w-C:\Windows\System32\drivers\tcpip.sys
2012-10-03 17:44:2170656----a-w-C:\Windows\System32\nlaapi.dll
2012-10-03 17:44:21303104----a-w-C:\Windows\System32\nlasvc.dll
2012-10-03 17:44:17246272----a-w-C:\Windows\System32\netcorehc.dll
2012-10-03 17:44:1718944----a-w-C:\Windows\System32\netevent.dll
2012-10-03 17:44:16216576----a-w-C:\Windows\System32\ncsi.dll
2012-10-03 17:42:16569344----a-w-C:\Windows\System32\iphlpsvc.dll
2012-10-03 16:42:2418944----a-w-C:\Windows\SysWow64\netevent.dll
2012-10-03 16:42:24175104----a-w-C:\Windows\SysWow64\netcorehc.dll
2012-10-03 16:42:23156672----a-w-C:\Windows\SysWow64\ncsi.dll
2012-10-03 16:07:2645568----a-w-C:\Windows\System32\drivers\tcpipreg.sys
2012-10-02 18:15:52430952----a-w-C:\Windows\SysWow64\nvStreaming.exe
2012-10-02 08:30:38185696----a-w-C:\Windows\System32\drivers\avgldx64.sys
2012-09-25 22:47:4378336----a-w-C:\Windows\SysWow64\synceng.dll
2012-09-25 22:46:1795744----a-w-C:\Windows\System32\synceng.dll
2012-09-21 08:46:04200032----a-w-C:\Windows\System32\drivers\avgtdia.sys
2012-09-21 08:46:00225120----a-w-C:\Windows\System32\drivers\avgloga.sys
2012-09-14 19:19:292048----a-w-C:\Windows\System32\tzres.dll
2012-09-14 18:28:532048----a-w-C:\Windows\SysWow64\tzres.dll
2012-09-14 08:05:1840800----a-w-C:\Windows\System32\drivers\avgrkx64.sys
2012-09-04 15:39:3250296----a-w-C:\Windows\System32\drivers\avgfwd6a.sys
2012-08-31 18:19:351659760----a-w-C:\Windows\System32\drivers\ntfs.sys
.
============= FINISH: 10:10:34.49 ===============
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 11/28/2012 5:05:52 PM
System Uptime: 11/29/2012 9:52:34 AM (1 hours ago)
.
Motherboard: Gateway | | TBGM01
Processor: Intel(R) Core(TM) i7 CPU 950 @ 3.07GHz | CPU 1 | 3037/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 917 GiB total, 821.693 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
G: is Removable
H: is Removable
I: is FIXED (NTFS) - 466 GiB total, 357.108 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
Description: Microsoft PS/2 Mouse
Device ID: ACPI\PNP0F03\4&6730480&0
Manufacturer: Microsoft
Name: Microsoft PS/2 Mouse
PNP Device ID: ACPI\PNP0F03\4&6730480&0
Service: i8042prt
.
==== System Restore Points ===================
.
RP7: 11/28/2012 8:13:13 PM - Installed AVG 2013
RP8: 11/28/2012 8:14:59 PM - Installed AVG 2013
RP9: 11/28/2012 8:23:40 PM - Windows Update
RP10: 11/28/2012 9:16:10 PM - Installed League of Legends
RP11: 11/28/2012 9:46:03 PM - Installed iTunes
RP12: 11/28/2012 11:58:00 PM - Installed 7-Zip 9.20 (x64 edition)
RP13: 11/28/2012 11:58:44 PM - Installed Steam
RP14: 11/29/2012 8:05:50 AM - Installed DirectX
RP15: 11/29/2012 8:33:47 AM - Installed DirectX
.
==== Installed Programs ======================
.
7-Zip 9.20 (x64 edition)
Akamai NetSession Interface
Apple Application Support
Apple Mobile Device Support
Apple Software Update
applicationupdater
Autodesk Backburner 2013.0.0
Autodesk DirectConnect 2013 64-bit
Autodesk FBX Plug-in 2013.1 - Maya 2013 64-bit
Autodesk MatchMover 2013 64-bit
Autodesk Maya 2013 64-bit
AVG 2013
Bonjour
CCleaner
Composite 2013 64-bit
Dropbox
gamelauncher-ps2-live
Google Chrome
Google Update Helper
iTunes
League of Legends
LSI PCI-SV92EX Soft Modem
Malwarebytes Anti-Malware version 1.65.1.1000
Microsoft .NET Framework 4 Client Profile
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
NVIDIA 3D Vision Driver 306.97
NVIDIA Control Panel 306.97
NVIDIA Graphics Driver 306.97
NVIDIA Install Application
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.10.8
NVIDIA Update Components
Pando Media Booster
PlanetSide 2
Speccy
Spotify
Steam
Visual Studio 2010 x64 Redistributables
VLC media player 2.0.4
.
==== Event Viewer Messages From Past Week ========
.
11/29/2012 9:53:14 AM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied.
11/29/2012 8:53:54 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff880ea0e6bb0, 0x0000000000000001, 0xfffffa80093ed2e6, 0x0000000000000005). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 112912-41059-01.
11/29/2012 12:00:22 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
11/29/2012 12:00:22 AM, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
11/28/2012 8:12:46 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk5\DR5.
11/28/2012 8:12:36 PM, Error: volsnap [25] - The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time. Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.
11/28/2012 7:34:15 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Update for Internet Explorer 8 Compatibility View List for Windows 7 for x64-based Systems (KB2598845).
11/28/2012 7:34:15 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Security Update for Internet Explorer 8 for Windows 7 for x64-based Systems (KB2544521).
11/28/2012 7:32:23 PM, Error: Service Control Manager [7023] -
11/28/2012 7:28:53 PM, Error: Service Control Manager [7034] - The NVIDIA Stereoscopic 3D Driver Service service terminated unexpectedly. It has done this 1 time(s).
11/28/2012 7:28:52 PM, Error: Service Control Manager [7034] - The NVIDIA Update Service Daemon service terminated unexpectedly. It has done this 1 time(s).
11/28/2012 6:34:05 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024d00e: Windows Update Core.
.
==== End Of File ===========================