Hi thanks so much for this service - I accidentally downloaded an apparently pretty malicious program called xVidly onto my computer. Usually I steer clear of these things pretty well, but it was very late and I was tired and it was set up to resemble something like a routine update to Flash...
Anyway, while I was looking around online for ways to remove it I found the remarkably thorough threads in this forum and thought I should probably try to get some help here; thanks again for such a selfless service!
Below are the log files.
(1) MalwareBytes Log
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
Database version: v2013.06.11.05
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16580
Tyler :: TYLERROSSLAPTOP [administrator]
Protection: Enabled
6/11/2013 11:24:49 AM
mbam-log-2013-06-11 (11-24-49).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 207417
Time elapsed: 5 minute(s), 31 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
(2) DDS
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.11.2
Run by Tyler at 12:04:21 on 2013-06-11
Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.6003.2949 [GMT -4:00]
.
AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\AECLSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe
C:\Windows\system32\dashost.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe
C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Cirrus Logic Audio Panel\CirrusAudioPanel_Dell.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Users\Tyler\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Tyler\AppData\Roaming\uTorrent\uTorrent.exe
C:\Users\Tyler\AppData\Roaming\SearchProtect\bin\cltmng.exe
C:\Users\Tyler\AppData\Local\Smartbar\Application\QuickShare.exe
C:\Program Files (x86)\Free Download Manager\fdm.exe
C:\Users\Tyler\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Ask.com\Updater\Updater.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Dell Backup and Recovery\TOASTER.EXE
C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\DBRUpd.exe
C:\Windows\system32\taskhostex.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\taskeng.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com/?ctid=CT3300236&octid=CT3300236&SearchSource=61&CUI=UN37230123991995811&UM=2&UP=SPC3543338-F85E-499D-8AC0-5391061E1ECF
uDefault_Page_URL = hxxp://dell13.msn.com
uURLSearchHooks: UrlSearchHook Class: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
uURLSearchHooks: uTorrentControl_v6 Toolbar: {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll
uURLSearchHooks: xVidly1 Toolbar: {8c58b088-1159-4ad9-a411-c7d3ae7edb28} -
mURLSearchHooks: uTorrentControl_v6 Toolbar: {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll
mURLSearchHooks: xVidly1 Toolbar: {8c58b088-1159-4ad9-a411-c7d3ae7edb28} -
mWinlogon: Userinit = userinit.exe
BHO: QuickShare WidgetEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: xVidly1 Toolbar: {8c58b088-1159-4ad9-a411-c7d3ae7edb28} -
BHO: uTorrentControl_v6 Toolbar: {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll
BHO: Wajam: {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll
BHO: Get Lyrics: {AF5B5C22-498A-4239-9A51-82BDD99C6A44} - C:\Program Files (x86)\GetLyrics\getlrcs.dll
BHO: Free Download Manager: {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: uTorrentControl_v6 Toolbar: {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll
TB: xVidly1 Toolbar: {8c58b088-1159-4ad9-a411-c7d3ae7edb28} -
TB: QuickShare Widget: {ae07101b-46d4-4a98-af68-0333ea26e113} -
uRun: [Spotify Web Helper] "C:\Users\Tyler\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
uRun: [Spotify] "C:\Users\Tyler\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [uTorrent] "C:\Users\Tyler\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
uRun: [SearchProtect] C:\Users\Tyler\AppData\Roaming\SearchProtect\bin\cltmng.exe
uRun: [Browser Infrastructure Helper] C:\Users\Tyler\AppData\Local\Smartbar\Application\QuickShare.exe startup
uRun: [Free Download Manager] "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
mRun: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe
mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\Users\Tyler\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Tyler\AppData\Roaming\Dropbox\bin\Dropbox.exe
IE: Download all with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dllink.htm
IE: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{974647D6-7B1D-4BAB-A65E-8A72B683979B} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{974647D6-7B1D-4BAB-A65E-8A72B683979B}\07F6C6964797 : DHCPNameServer = 172.24.10.10 205.171.2.65
TCP: Interfaces\{974647D6-7B1D-4BAB-A65E-8A72B683979B}\246574 : DHCPNameServer = 204.117.214.10 199.2.252.10
TCP: Interfaces\{974647D6-7B1D-4BAB-A65E-8A72B683979B}\36F6E666562756E63656 : DHCPNameServer = 204.117.214.10 199.2.252.10
TCP: Interfaces\{974647D6-7B1D-4BAB-A65E-8A72B683979B}\37B6976696 : DHCPNameServer = 8.8.8.8
TCP: Interfaces\{974647D6-7B1D-4BAB-A65E-8A72B683979B}\C6563647572756 : DHCPNameServer = 204.117.214.10 199.2.252.10
TCP: Interfaces\{974647D6-7B1D-4BAB-A65E-8A72B683979B}\E4544574541425F5745756374713 : DHCPNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: QuickShare WidgetEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
x64-TB: QuickShare Widget: {ae07101b-46d4-4a98-af68-0333ea26e113} -
x64-Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
x64-Run: [QuickSet] c:\Program Files\Dell\QuickSet\QuickSet.exe
x64-Run: [Dell Audio] C:\Program Files\Cirrus Logic Audio Panel\CirrusAudioPanel_Dell.exe
x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 iaStorA;iaStorA;C:\Windows\System32\Drivers\iaStorA.sys [2012-10-27 651832]
R2 AECLFilters;Andrea Cirrus Logic Filters Service;C:\Windows\System32\AECLSr64.exe [2012-10-7 99696]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2012-7-17 731688]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-10-7 1091520]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2012-10-7 1112000]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-5-2 135952]
R2 CltMngSvc;Search Protect by Conduit Updater;C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe [2013-5-8 97056]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-10-7 7168]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2012-10-7 2451456]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-10-7 166720]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-6-11 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-6-11 701512]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [2013-2-21 1914728]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-10-7 365376]
R2 WajamUpdater;WajamUpdater;C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe [2013-5-2 109064]
R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2012-7-18 2699568]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;C:\Windows\System32\Drivers\AmpPal.sys [2012-7-17 162344]
R3 BthLEEnum;Bluetooth Low Energy Driver;C:\Windows\System32\Drivers\BthLEEnum.sys [2012-7-25 202752]
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\Drivers\btmaux.sys [2012-10-7 110592]
R3 btmhsf;btmhsf;C:\Windows\System32\Drivers\btmhsf.sys [2012-10-7 825344]
R3 CirrusLFD;CS42xxLowerFilter;C:\Windows\System32\Drivers\CSLFDx64.sys [2012-10-7 41328]
R3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\Drivers\iBtFltCoex.sys [2012-10-7 55848]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\Drivers\IntcDAud.sys [2012-10-7 342528]
R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\Drivers\iwdbus.sys [2012-8-9 25568]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\Drivers\L1C63x64.sys [2012-6-2 100864]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\Drivers\mbam.sys [2013-6-11 25928]
R3 NETwNe64;@oem3.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit;C:\Windows\System32\Drivers\NETwew00.sys [2012-10-7 4273192]
S2 CirrusAudioService;Cirrus Audio Service;C:\Program Files\Cirrus Logic Audio Panel\Cirrvus.exe [2012-8-6 7168]
S2 DellDigitalDelivery;Dell Digital Delivery Service;C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [2012-6-19 173056]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-4-19 161384]
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;C:\Windows\System32\Drivers\AmpPal.sys [2012-7-17 162344]
S3 DellRbtn;Airplane Mode Switch;C:\Windows\System32\Drivers\DellRbtn.sys [2012-10-7 10752]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\Drivers\intelaud.sys [2012-8-9 35296]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2012-7-18 272176]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\Windows\System32\Drivers\RtsUVStor.sys [2012-10-7 315536]
S3 usb3Hub;USB-IF USB 3.0 Hub;C:\Windows\System32\Drivers\usb3Hub.sys [2012-8-9 48096]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\Drivers\usbaapl64.sys [2012-9-28 53760]
S3 XHCIPort;USB-IF xHCI USB Host Controller;C:\Windows\System32\Drivers\xHCIPort.sys [2012-8-9 188384]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2013-06-11 15:23:53--------d-----w-C:\Users\Tyler\AppData\Roaming\Malwarebytes
2013-06-11 15:23:38--------d-----w-C:\ProgramData\Malwarebytes
2013-06-11 15:23:3425928----a-w-C:\Windows\System32\drivers\mbam.sys
2013-06-11 15:23:34--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-11 15:22:47--------d-----w-C:\Downloads
2013-06-11 03:59:40--------d-----w-C:\Users\Tyler\AppData\Roaming\Free Download Manager
2013-06-11 03:07:03--------d-----w-C:\Program Files (x86)\Free Download Manager
2013-06-11 03:06:41--------d-----w-C:\Program Files (x86)\GetLyrics
2013-06-11 03:06:24--------d-----w-C:\Users\Tyler\AppData\Local\Smartbar
2013-06-11 03:05:16--------d-----w-C:\Users\Tyler\AppData\Local\Wajam
2013-06-11 03:05:14--------d-----w-C:\Program Files (x86)\Wajam
2013-06-11 02:29:599460464----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D60D954C-C3BF-4BE2-B561-34271B40F9C0}\mpengine.dll
2013-06-09 17:27:149460464----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-06-05 22:21:41--------d-----r-C:\Users\Tyler\Dropbox
2013-06-05 22:18:22--------d-----w-C:\Users\Tyler\AppData\Roaming\Dropbox
2013-06-05 18:07:07--------d-----w-C:\Users\Tyler\AppData\Local\Wondershare
2013-06-05 18:07:06--------d-----w-C:\Program Files (x86)\Common Files\Wondershare
2013-06-05 18:06:53--------d-----w-C:\ProgramData\PDFEditor
2013-06-05 18:06:50--------d-----w-C:\Users\Tyler\AppData\Roaming\Wondershare
2013-06-05 18:06:31--------d-----w-C:\Program Files (x86)\Wondershare
2013-06-02 02:08:25--------d-----w-C:\Program Files (x86)\Common Files\Avid
2013-06-02 01:41:57--------d-----w-C:\Program Files (x86)\Sibelius Software
2013-06-02 01:34:33--------d-----w-C:\Program Files (x86)\Neuratron AudioScore Lite
2013-06-02 01:34:10--------d-----w-C:\Program Files (x86)\Neuratron PhotoScore Lite
2013-06-02 01:22:02--------d-----w-C:\Users\Tyler\AppData\Roaming\Avid
2013-06-02 01:22:02--------d-----w-C:\ProgramData\Avid
2013-06-02 01:22:02--------d-----w-C:\Program Files\Avid
2013-06-02 01:22:02--------d-----w-C:\Program Files (x86)\Avid
2013-06-02 01:21:16--------d-----w-C:\Users\Tyler\AppData\Local\start
2013-06-01 18:58:14--------d-----w-C:\Program Files (x86)\SearchProtect
2013-06-01 18:57:56--------d-----w-C:\Program Files (x86)\Conduit
2013-06-01 18:57:53--------d-----w-C:\Users\Tyler\AppData\Local\Conduit
2013-06-01 18:57:53--------d-----w-C:\Program Files (x86)\uTorrentControl_v6
2013-06-01 18:56:45--------d-----w-C:\Users\Tyler\AppData\Roaming\uTorrent
2013-06-01 18:17:09--------d-----w-C:\Program Files (x86)\MyPC Backup
2013-06-01 18:16:13--------d-----w-C:\Program Files (x86)\LessTabs
2013-06-01 18:15:35--------d-----w-C:\Program Files (x86)\InternetHelper3.1
2013-06-01 18:15:07--------d-----w-C:\Users\Tyler\AppData\Roaming\SearchProtect
2013-06-01 18:14:53--------d-----w-C:\Users\Tyler\AppData\Roaming\DownLite
2013-06-01 18:14:50--------d-----w-C:\Users\Tyler\AppData\Local\CRE
2013-06-01 18:14:25--------d-----w-C:\Program Files (x86)\Flash Player Pro
2013-06-01 18:09:54--------d-----w-C:\Program Files (x86)\GRETECH
2013-06-01 18:09:25--------d-----w-C:\Program Files (x86)\Industriya
2013-06-01 01:16:44--------d-----w-C:\Program Files (x86)\lg_fwupdate
2013-05-22 20:28:54--------d-----w-C:\Users\Tyler\AppData\Local\Macroplant,_LLC
2013-05-22 20:28:43--------d-----w-C:\Program Files (x86)\Sharepod
2013-05-22 20:28:03--------d-----w-C:\Users\Tyler\AppData\Local\Programs
2013-05-22 02:42:32--------d-----w-C:\ProgramData\PC-Doctor for Windows
2013-05-22 02:42:03--------d-----w-C:\Program Files\My Dell
2013-05-20 17:23:272382336----a-w-C:\Windows\SysWow64\esent.dll
2013-05-20 17:23:262851840----a-w-C:\Windows\System32\esent.dll
2013-05-18 21:41:33--------d-----r-C:\Program Files (x86)\Skype
2013-05-17 20:59:592035200----a-w-C:\Windows\SysWow64\authui.dll
2013-05-15 15:36:406987528----a-w-C:\Windows\System32\ntoskrnl.exe
2013-05-15 15:36:39861184----a-w-C:\Windows\System32\drivers\http.sys
2013-05-15 15:36:2870144----a-w-C:\Windows\System32\appinfo.dll
2013-05-15 15:36:28112872----a-w-C:\Windows\System32\consent.exe
.
==================== Find3M ====================
.
2013-05-07 20:07:5078200----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-07 20:07:50693112----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
2013-05-02 15:29:56278800------w-C:\Windows\System32\MpSigStub.exe
2013-04-16 02:34:441455368----a-w-C:\Windows\System32\drivers\dxgkrnl.sys
2013-04-13 05:56:35444416----a-w-C:\Windows\apppatch\AcSpecfc.dll
2013-04-09 23:17:442242048----a-w-C:\Windows\System32\wininet.dll
2013-04-09 23:17:36915968----a-w-C:\Windows\System32\uxtheme.dll
2013-04-09 23:16:583958784----a-w-C:\Windows\System32\jscript9.dll
2013-04-09 22:30:261767424----a-w-C:\Windows\SysWow64\wininet.dll
2013-04-09 22:29:442877440----a-w-C:\Windows\SysWow64\jscript9.dll
2013-04-09 05:33:02489576----a-w-C:\Windows\System32\AudioEng.dll
2013-04-09 05:33:02446792----a-w-C:\Windows\System32\AudioSes.dll
2013-04-09 05:33:02253544----a-w-C:\Windows\System32\audiodg.exe
2013-04-09 05:27:43284424----a-w-C:\Windows\System32\drivers\spaceport.sys
2013-04-09 05:20:0286280----a-w-C:\Windows\System32\kdnet.dll
2013-04-09 05:20:02306952----a-w-C:\Windows\System32\kd_02_10ec.dll
2013-04-09 05:18:0577960----a-w-C:\Windows\System32\kdvm.dll
2013-04-09 05:17:571829408----a-w-C:\Windows\System32\ntdll.dll
2013-04-09 04:52:07816128----a-w-C:\Windows\System32\SearchIndexer.exe
2013-04-09 04:52:07373760----a-w-C:\Windows\System32\SearchProtocolHost.exe
2013-04-09 04:52:07197120----a-w-C:\Windows\System32\SearchFilterHost.exe
2013-04-09 04:52:07126464----a-w-C:\Windows\System32\Robocopy.exe
2013-04-09 04:52:06804352----a-w-C:\Windows\System32\RecoveryDrive.exe
2013-04-09 04:51:51367616----a-w-C:\Windows\System32\conhost.exe
2013-04-09 04:51:45523264----a-w-C:\Windows\System32\XpsGdiConverter.dll
2013-04-09 04:51:4199840----a-w-C:\Windows\System32\wscsvc.dll
2013-04-09 04:51:41456704----a-w-C:\Windows\System32\wpncore.dll
2013-04-09 04:51:2013648384----a-w-C:\Windows\System32\Windows.UI.Xaml.dll
2013-04-09 04:51:17595456----a-w-C:\Windows\System32\Windows.Networking.dll
2013-04-09 04:51:17391168----a-w-C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-04-09 04:51:0510116096----a-w-C:\Windows\System32\twinui.dll
2013-04-09 04:51:033552768----a-w-C:\Windows\System32\tquery.dll
2013-04-09 04:50:53414720----a-w-C:\Windows\System32\GenuineCenter.dll
2013-04-09 04:50:39422400----a-w-C:\Windows\System32\schannel.dll
2013-04-09 04:50:391285632----a-w-C:\Windows\System32\schedsvc.dll
2013-04-09 04:50:0396256----a-w-C:\Windows\System32\mssprxy.dll
2013-04-09 04:50:03745984----a-w-C:\Windows\System32\mssvp.dll
2013-04-09 04:50:032107904----a-w-C:\Windows\System32\mssrch.dll
2013-04-09 04:50:0265024----a-w-C:\Windows\System32\msscntrs.dll
2013-04-09 04:50:02435200----a-w-C:\Windows\System32\mssph.dll
2013-04-09 04:50:0213824----a-w-C:\Windows\System32\msshooks.dll
2013-04-09 04:49:541444864----a-w-C:\Windows\System32\MSAudDecMFT.dll
2013-04-09 04:49:45468992----a-w-C:\Windows\System32\MFMediaEngine.dll
2013-04-09 04:49:45281088----a-w-C:\Windows\System32\mfreadwrite.dll
2013-04-09 04:49:36817152----a-w-C:\Windows\System32\kerberos.dll
2013-04-09 04:49:33210432----a-w-C:\Windows\System32\iuilp.dll
2013-04-09 04:49:1650176----a-w-C:\Windows\System32\fmifs.dll
2013-04-09 04:49:16231936----a-w-C:\Windows\System32\fhengine.dll
2013-04-09 04:49:09172544----a-w-C:\Windows\System32\dwmredir.dll
2013-04-09 04:49:06196096----a-w-C:\Windows\System32\dmvdsitf.dll
2013-04-09 04:48:432303488----a-w-C:\Windows\System32\authui.dll
2013-04-09 04:48:42785408----a-w-C:\Windows\System32\audiosrv.dll
2013-04-09 04:48:42169472----a-w-C:\Windows\System32\AudioEndpointBuilder.dll
2013-04-09 04:48:34419840----a-w-C:\Windows\System32\intl.cpl
2013-04-09 02:35:134038144----a-w-C:\Windows\System32\win32k.sys
2013-04-09 02:34:4983968----a-w-C:\Windows\System32\drivers\hidclass.sys
2013-04-09 02:34:4227648----a-w-C:\Windows\System32\drivers\hidusb.sys
2013-04-09 02:34:3095744----a-w-C:\Windows\System32\drivers\hidbth.sys
2013-04-09 02:33:4160416----a-w-C:\Windows\System32\drivers\ndproxy.sys
2013-04-09 02:33:05623104----a-w-C:\Windows\System32\drivers\srv2.sys
2013-04-09 02:32:02805376----a-w-C:\Windows\System32\drivers\PEAuth.sys
2013-04-09 02:31:14247808----a-w-C:\Windows\System32\drivers\srvnet.sys
2013-04-09 02:31:0183456----a-w-C:\Windows\System32\drivers\wanarp.sys
2013-04-08 23:44:25123880----a-w-C:\Windows\SysWow64\wscapi.dll
2013-04-08 23:39:141408896----a-w-C:\Windows\SysWow64\ntdll.dll
2013-04-08 23:37:29426024----a-w-C:\Windows\SysWow64\AudioEng.dll
2013-04-08 23:37:29324368----a-w-C:\Windows\SysWow64\AudioSes.dll
2013-04-08 21:52:16670208----a-w-C:\Windows\SysWow64\SearchIndexer.exe
2013-04-08 21:52:16302592----a-w-C:\Windows\SysWow64\SearchProtocolHost.exe
2013-04-08 21:52:16171008----a-w-C:\Windows\SysWow64\SearchFilterHost.exe
2013-04-08 21:52:16106496----a-w-C:\Windows\SysWow64\Robocopy.exe
2013-04-08 21:52:06364544----a-w-C:\Windows\SysWow64\XpsGdiConverter.dll
2013-04-04 23:30:17503080----a-w-C:\Windows\System32\ci.dll
2013-03-30 18:16:051403784----a-w-C:\Windows\System32\winload.efi
2013-03-30 18:16:051267424----a-w-C:\Windows\System32\winload.exe
2013-03-28 22:09:091093880----a-w-C:\Windows\System32\winresume.exe
2013-03-28 22:09:041217328----a-w-C:\Windows\System32\winresume.efi
2013-03-15 22:05:34298456----a-w-C:\Windows\System32\rsaenh.dll
2013-03-15 22:05:16252928----a-w-C:\Windows\SysWow64\rsaenh.dll
.
============= FINISH: 12:04:41.47 ===============
(3) Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 8
Boot Device: \Device\HarddiskVolume1
Install Date: 12/26/2012 12:05:17 AM
System Uptime: 6/11/2013 12:13:28 AM (12 hours ago)
.
Motherboard: Dell Inc. | | 0J4MPR
Processor: Intel(R) Core(TM) i3-3217U CPU @ 1.80GHz | CPU Socket - U3E1 | 1801/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 452 GiB total, 346.34 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {8a2edc79-c759-46f2-88af-9d4efe3b5eee}
Description: USB-IF xHCI USB Host Controller
Device ID: ROOT\UOIP_BUS_DRIVER\0000
Manufacturer: Intel Corporation
Name: USB-IF xHCI USB Host Controller
PNP Device ID: ROOT\UOIP_BUS_DRIVER\0000
Service: XHCIPort
.
==== System Restore Points ===================
.
RP25: 5/27/2013 8:50:16 PM - Scheduled Checkpoint
RP26: 5/31/2013 9:10:20 PM - Installed Suite
RP27: 6/1/2013 2:22:09 PM - Restore Operation
RP28: 6/10/2013 10:28:04 PM - Scheduled Checkpoint
RP29: 6/10/2013 11:57:05 PM - Restore Operation
.
==== Installed Programs ======================
.
µTorrent
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
Ask Toolbar Updater
Avid License Control
Bonjour
Cirrus Logic Audio Panel
D3DX10
Dell Audio
Dell Backup and Recovery
Dell Backup and Recovery - Support Software
Dell Digital Delivery
Dell Touchpad
Dropbox
Free Download Manager 3.9.2
Get Lyrics
Google Chrome
Google Update Helper
Intel PROSet Wireless
Intel(R) Control Center
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
Intel(R) Rapid Storage Technology
Intel(R) WiDi
Intel® PROSet/Wireless WiFi Software
Intel® Trusted Connect Service Client
iTunes
Java 7 Update 11
Java Auto Updater
LibreOffice 3.6
LibreOffice 3.6 Help Pack (English)
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft Application Error Reporting
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Movie Maker
MSVCRT
MSVCRT110
MSVCRT110_amd64
My Dell
Neuratron AudioScore Lite
Neuratron PhotoScore Lite
Photo Common
Photo Gallery
Python 3.3.0
Quickset64
QuickShare
QuickTime
Realtek USB 2.0 Card Reader
Search Protect by conduit
Shared C Run-time for x64
Sharepod 4.0.0.3
Sibelius 7 OpenType Fonts
Sibelius 7.1.0.54
Sibelius Scorch (all browsers)
Skype™ 6.3
Spotify
uTorrentControl_v6 Toolbar
Wajam
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
xVidly
xVidly1 Toolbar
.
==== Event Viewer Messages From Past Week ========
.
6/9/2013 1:57:47 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000139 (0x0000000000000003, 0xfffff801ae4875a0, 0xfffff801ae4874f8, 0x0000000000000000). A dump was saved in: C:\Windows\Minidump\060913-56484-01.dmp. Report Id: 060913-56484-01.
6/11/2013 12:15:59 AM, Error: Service Control Manager [7034] - The Dell Digital Delivery Service service terminated unexpectedly. It has done this 1 time(s).
6/11/2013 12:13:18 AM, Error: Ntfs [55] - A corruption was discovered in the file system structure on volume OS. The Master File Table (MFT) contains a corrupted file record. The file reference number is 0x800000002c787. The name of the file is "<unable to determine file name>".
6/11/2013 11:24:06 AM, Error: Service Control Manager [7046] - The following service has repeatedly stopped responding to service control requests: SoftThinks Agent Service Contact the service vendor or the system administrator about whether to disable this service until the problem is identified. You may have to restart the computer in safe mode before you can disable the service.
6/11/2013 11:23:36 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
6/10/2013 11:58:02 PM, Error: Ntfs [55] - A corruption was discovered in the file system structure on volume OS. The exact nature of the corruption is unknown. The file system structures need to be scanned online.
.
==== End Of File ===========================
Anyway, while I was looking around online for ways to remove it I found the remarkably thorough threads in this forum and thought I should probably try to get some help here; thanks again for such a selfless service!
Below are the log files.
(1) MalwareBytes Log
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
Database version: v2013.06.11.05
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16580
Tyler :: TYLERROSSLAPTOP [administrator]
Protection: Enabled
6/11/2013 11:24:49 AM
mbam-log-2013-06-11 (11-24-49).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 207417
Time elapsed: 5 minute(s), 31 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
(2) DDS
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.11.2
Run by Tyler at 12:04:21 on 2013-06-11
Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.6003.2949 [GMT -4:00]
.
AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\AECLSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe
C:\Windows\system32\dashost.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe
C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Cirrus Logic Audio Panel\CirrusAudioPanel_Dell.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Users\Tyler\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Tyler\AppData\Roaming\uTorrent\uTorrent.exe
C:\Users\Tyler\AppData\Roaming\SearchProtect\bin\cltmng.exe
C:\Users\Tyler\AppData\Local\Smartbar\Application\QuickShare.exe
C:\Program Files (x86)\Free Download Manager\fdm.exe
C:\Users\Tyler\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Ask.com\Updater\Updater.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Dell Backup and Recovery\TOASTER.EXE
C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\DBRUpd.exe
C:\Windows\system32\taskhostex.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\taskeng.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com/?ctid=CT3300236&octid=CT3300236&SearchSource=61&CUI=UN37230123991995811&UM=2&UP=SPC3543338-F85E-499D-8AC0-5391061E1ECF
uDefault_Page_URL = hxxp://dell13.msn.com
uURLSearchHooks: UrlSearchHook Class: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
uURLSearchHooks: uTorrentControl_v6 Toolbar: {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll
uURLSearchHooks: xVidly1 Toolbar: {8c58b088-1159-4ad9-a411-c7d3ae7edb28} -
mURLSearchHooks: uTorrentControl_v6 Toolbar: {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll
mURLSearchHooks: xVidly1 Toolbar: {8c58b088-1159-4ad9-a411-c7d3ae7edb28} -
mWinlogon: Userinit = userinit.exe
BHO: QuickShare WidgetEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: xVidly1 Toolbar: {8c58b088-1159-4ad9-a411-c7d3ae7edb28} -
BHO: uTorrentControl_v6 Toolbar: {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll
BHO: Wajam: {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll
BHO: Get Lyrics: {AF5B5C22-498A-4239-9A51-82BDD99C6A44} - C:\Program Files (x86)\GetLyrics\getlrcs.dll
BHO: Free Download Manager: {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: uTorrentControl_v6 Toolbar: {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll
TB: xVidly1 Toolbar: {8c58b088-1159-4ad9-a411-c7d3ae7edb28} -
TB: QuickShare Widget: {ae07101b-46d4-4a98-af68-0333ea26e113} -
uRun: [Spotify Web Helper] "C:\Users\Tyler\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
uRun: [Spotify] "C:\Users\Tyler\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [uTorrent] "C:\Users\Tyler\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
uRun: [SearchProtect] C:\Users\Tyler\AppData\Roaming\SearchProtect\bin\cltmng.exe
uRun: [Browser Infrastructure Helper] C:\Users\Tyler\AppData\Local\Smartbar\Application\QuickShare.exe startup
uRun: [Free Download Manager] "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
mRun: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe
mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\Users\Tyler\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Tyler\AppData\Roaming\Dropbox\bin\Dropbox.exe
IE: Download all with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dllink.htm
IE: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{974647D6-7B1D-4BAB-A65E-8A72B683979B} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{974647D6-7B1D-4BAB-A65E-8A72B683979B}\07F6C6964797 : DHCPNameServer = 172.24.10.10 205.171.2.65
TCP: Interfaces\{974647D6-7B1D-4BAB-A65E-8A72B683979B}\246574 : DHCPNameServer = 204.117.214.10 199.2.252.10
TCP: Interfaces\{974647D6-7B1D-4BAB-A65E-8A72B683979B}\36F6E666562756E63656 : DHCPNameServer = 204.117.214.10 199.2.252.10
TCP: Interfaces\{974647D6-7B1D-4BAB-A65E-8A72B683979B}\37B6976696 : DHCPNameServer = 8.8.8.8
TCP: Interfaces\{974647D6-7B1D-4BAB-A65E-8A72B683979B}\C6563647572756 : DHCPNameServer = 204.117.214.10 199.2.252.10
TCP: Interfaces\{974647D6-7B1D-4BAB-A65E-8A72B683979B}\E4544574541425F5745756374713 : DHCPNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: QuickShare WidgetEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
x64-TB: QuickShare Widget: {ae07101b-46d4-4a98-af68-0333ea26e113} -
x64-Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
x64-Run: [QuickSet] c:\Program Files\Dell\QuickSet\QuickSet.exe
x64-Run: [Dell Audio] C:\Program Files\Cirrus Logic Audio Panel\CirrusAudioPanel_Dell.exe
x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 iaStorA;iaStorA;C:\Windows\System32\Drivers\iaStorA.sys [2012-10-27 651832]
R2 AECLFilters;Andrea Cirrus Logic Filters Service;C:\Windows\System32\AECLSr64.exe [2012-10-7 99696]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2012-7-17 731688]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-10-7 1091520]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2012-10-7 1112000]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-5-2 135952]
R2 CltMngSvc;Search Protect by Conduit Updater;C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe [2013-5-8 97056]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-10-7 7168]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2012-10-7 2451456]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-10-7 166720]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-6-11 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-6-11 701512]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [2013-2-21 1914728]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-10-7 365376]
R2 WajamUpdater;WajamUpdater;C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe [2013-5-2 109064]
R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2012-7-18 2699568]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;C:\Windows\System32\Drivers\AmpPal.sys [2012-7-17 162344]
R3 BthLEEnum;Bluetooth Low Energy Driver;C:\Windows\System32\Drivers\BthLEEnum.sys [2012-7-25 202752]
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\Drivers\btmaux.sys [2012-10-7 110592]
R3 btmhsf;btmhsf;C:\Windows\System32\Drivers\btmhsf.sys [2012-10-7 825344]
R3 CirrusLFD;CS42xxLowerFilter;C:\Windows\System32\Drivers\CSLFDx64.sys [2012-10-7 41328]
R3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\Drivers\iBtFltCoex.sys [2012-10-7 55848]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\Drivers\IntcDAud.sys [2012-10-7 342528]
R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\Drivers\iwdbus.sys [2012-8-9 25568]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\Drivers\L1C63x64.sys [2012-6-2 100864]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\Drivers\mbam.sys [2013-6-11 25928]
R3 NETwNe64;@oem3.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit;C:\Windows\System32\Drivers\NETwew00.sys [2012-10-7 4273192]
S2 CirrusAudioService;Cirrus Audio Service;C:\Program Files\Cirrus Logic Audio Panel\Cirrvus.exe [2012-8-6 7168]
S2 DellDigitalDelivery;Dell Digital Delivery Service;C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [2012-6-19 173056]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-4-19 161384]
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;C:\Windows\System32\Drivers\AmpPal.sys [2012-7-17 162344]
S3 DellRbtn;Airplane Mode Switch;C:\Windows\System32\Drivers\DellRbtn.sys [2012-10-7 10752]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\Drivers\intelaud.sys [2012-8-9 35296]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2012-7-18 272176]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\Windows\System32\Drivers\RtsUVStor.sys [2012-10-7 315536]
S3 usb3Hub;USB-IF USB 3.0 Hub;C:\Windows\System32\Drivers\usb3Hub.sys [2012-8-9 48096]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\Drivers\usbaapl64.sys [2012-9-28 53760]
S3 XHCIPort;USB-IF xHCI USB Host Controller;C:\Windows\System32\Drivers\xHCIPort.sys [2012-8-9 188384]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2013-06-11 15:23:53--------d-----w-C:\Users\Tyler\AppData\Roaming\Malwarebytes
2013-06-11 15:23:38--------d-----w-C:\ProgramData\Malwarebytes
2013-06-11 15:23:3425928----a-w-C:\Windows\System32\drivers\mbam.sys
2013-06-11 15:23:34--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-11 15:22:47--------d-----w-C:\Downloads
2013-06-11 03:59:40--------d-----w-C:\Users\Tyler\AppData\Roaming\Free Download Manager
2013-06-11 03:07:03--------d-----w-C:\Program Files (x86)\Free Download Manager
2013-06-11 03:06:41--------d-----w-C:\Program Files (x86)\GetLyrics
2013-06-11 03:06:24--------d-----w-C:\Users\Tyler\AppData\Local\Smartbar
2013-06-11 03:05:16--------d-----w-C:\Users\Tyler\AppData\Local\Wajam
2013-06-11 03:05:14--------d-----w-C:\Program Files (x86)\Wajam
2013-06-11 02:29:599460464----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D60D954C-C3BF-4BE2-B561-34271B40F9C0}\mpengine.dll
2013-06-09 17:27:149460464----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-06-05 22:21:41--------d-----r-C:\Users\Tyler\Dropbox
2013-06-05 22:18:22--------d-----w-C:\Users\Tyler\AppData\Roaming\Dropbox
2013-06-05 18:07:07--------d-----w-C:\Users\Tyler\AppData\Local\Wondershare
2013-06-05 18:07:06--------d-----w-C:\Program Files (x86)\Common Files\Wondershare
2013-06-05 18:06:53--------d-----w-C:\ProgramData\PDFEditor
2013-06-05 18:06:50--------d-----w-C:\Users\Tyler\AppData\Roaming\Wondershare
2013-06-05 18:06:31--------d-----w-C:\Program Files (x86)\Wondershare
2013-06-02 02:08:25--------d-----w-C:\Program Files (x86)\Common Files\Avid
2013-06-02 01:41:57--------d-----w-C:\Program Files (x86)\Sibelius Software
2013-06-02 01:34:33--------d-----w-C:\Program Files (x86)\Neuratron AudioScore Lite
2013-06-02 01:34:10--------d-----w-C:\Program Files (x86)\Neuratron PhotoScore Lite
2013-06-02 01:22:02--------d-----w-C:\Users\Tyler\AppData\Roaming\Avid
2013-06-02 01:22:02--------d-----w-C:\ProgramData\Avid
2013-06-02 01:22:02--------d-----w-C:\Program Files\Avid
2013-06-02 01:22:02--------d-----w-C:\Program Files (x86)\Avid
2013-06-02 01:21:16--------d-----w-C:\Users\Tyler\AppData\Local\start
2013-06-01 18:58:14--------d-----w-C:\Program Files (x86)\SearchProtect
2013-06-01 18:57:56--------d-----w-C:\Program Files (x86)\Conduit
2013-06-01 18:57:53--------d-----w-C:\Users\Tyler\AppData\Local\Conduit
2013-06-01 18:57:53--------d-----w-C:\Program Files (x86)\uTorrentControl_v6
2013-06-01 18:56:45--------d-----w-C:\Users\Tyler\AppData\Roaming\uTorrent
2013-06-01 18:17:09--------d-----w-C:\Program Files (x86)\MyPC Backup
2013-06-01 18:16:13--------d-----w-C:\Program Files (x86)\LessTabs
2013-06-01 18:15:35--------d-----w-C:\Program Files (x86)\InternetHelper3.1
2013-06-01 18:15:07--------d-----w-C:\Users\Tyler\AppData\Roaming\SearchProtect
2013-06-01 18:14:53--------d-----w-C:\Users\Tyler\AppData\Roaming\DownLite
2013-06-01 18:14:50--------d-----w-C:\Users\Tyler\AppData\Local\CRE
2013-06-01 18:14:25--------d-----w-C:\Program Files (x86)\Flash Player Pro
2013-06-01 18:09:54--------d-----w-C:\Program Files (x86)\GRETECH
2013-06-01 18:09:25--------d-----w-C:\Program Files (x86)\Industriya
2013-06-01 01:16:44--------d-----w-C:\Program Files (x86)\lg_fwupdate
2013-05-22 20:28:54--------d-----w-C:\Users\Tyler\AppData\Local\Macroplant,_LLC
2013-05-22 20:28:43--------d-----w-C:\Program Files (x86)\Sharepod
2013-05-22 20:28:03--------d-----w-C:\Users\Tyler\AppData\Local\Programs
2013-05-22 02:42:32--------d-----w-C:\ProgramData\PC-Doctor for Windows
2013-05-22 02:42:03--------d-----w-C:\Program Files\My Dell
2013-05-20 17:23:272382336----a-w-C:\Windows\SysWow64\esent.dll
2013-05-20 17:23:262851840----a-w-C:\Windows\System32\esent.dll
2013-05-18 21:41:33--------d-----r-C:\Program Files (x86)\Skype
2013-05-17 20:59:592035200----a-w-C:\Windows\SysWow64\authui.dll
2013-05-15 15:36:406987528----a-w-C:\Windows\System32\ntoskrnl.exe
2013-05-15 15:36:39861184----a-w-C:\Windows\System32\drivers\http.sys
2013-05-15 15:36:2870144----a-w-C:\Windows\System32\appinfo.dll
2013-05-15 15:36:28112872----a-w-C:\Windows\System32\consent.exe
.
==================== Find3M ====================
.
2013-05-07 20:07:5078200----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-07 20:07:50693112----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
2013-05-02 15:29:56278800------w-C:\Windows\System32\MpSigStub.exe
2013-04-16 02:34:441455368----a-w-C:\Windows\System32\drivers\dxgkrnl.sys
2013-04-13 05:56:35444416----a-w-C:\Windows\apppatch\AcSpecfc.dll
2013-04-09 23:17:442242048----a-w-C:\Windows\System32\wininet.dll
2013-04-09 23:17:36915968----a-w-C:\Windows\System32\uxtheme.dll
2013-04-09 23:16:583958784----a-w-C:\Windows\System32\jscript9.dll
2013-04-09 22:30:261767424----a-w-C:\Windows\SysWow64\wininet.dll
2013-04-09 22:29:442877440----a-w-C:\Windows\SysWow64\jscript9.dll
2013-04-09 05:33:02489576----a-w-C:\Windows\System32\AudioEng.dll
2013-04-09 05:33:02446792----a-w-C:\Windows\System32\AudioSes.dll
2013-04-09 05:33:02253544----a-w-C:\Windows\System32\audiodg.exe
2013-04-09 05:27:43284424----a-w-C:\Windows\System32\drivers\spaceport.sys
2013-04-09 05:20:0286280----a-w-C:\Windows\System32\kdnet.dll
2013-04-09 05:20:02306952----a-w-C:\Windows\System32\kd_02_10ec.dll
2013-04-09 05:18:0577960----a-w-C:\Windows\System32\kdvm.dll
2013-04-09 05:17:571829408----a-w-C:\Windows\System32\ntdll.dll
2013-04-09 04:52:07816128----a-w-C:\Windows\System32\SearchIndexer.exe
2013-04-09 04:52:07373760----a-w-C:\Windows\System32\SearchProtocolHost.exe
2013-04-09 04:52:07197120----a-w-C:\Windows\System32\SearchFilterHost.exe
2013-04-09 04:52:07126464----a-w-C:\Windows\System32\Robocopy.exe
2013-04-09 04:52:06804352----a-w-C:\Windows\System32\RecoveryDrive.exe
2013-04-09 04:51:51367616----a-w-C:\Windows\System32\conhost.exe
2013-04-09 04:51:45523264----a-w-C:\Windows\System32\XpsGdiConverter.dll
2013-04-09 04:51:4199840----a-w-C:\Windows\System32\wscsvc.dll
2013-04-09 04:51:41456704----a-w-C:\Windows\System32\wpncore.dll
2013-04-09 04:51:2013648384----a-w-C:\Windows\System32\Windows.UI.Xaml.dll
2013-04-09 04:51:17595456----a-w-C:\Windows\System32\Windows.Networking.dll
2013-04-09 04:51:17391168----a-w-C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-04-09 04:51:0510116096----a-w-C:\Windows\System32\twinui.dll
2013-04-09 04:51:033552768----a-w-C:\Windows\System32\tquery.dll
2013-04-09 04:50:53414720----a-w-C:\Windows\System32\GenuineCenter.dll
2013-04-09 04:50:39422400----a-w-C:\Windows\System32\schannel.dll
2013-04-09 04:50:391285632----a-w-C:\Windows\System32\schedsvc.dll
2013-04-09 04:50:0396256----a-w-C:\Windows\System32\mssprxy.dll
2013-04-09 04:50:03745984----a-w-C:\Windows\System32\mssvp.dll
2013-04-09 04:50:032107904----a-w-C:\Windows\System32\mssrch.dll
2013-04-09 04:50:0265024----a-w-C:\Windows\System32\msscntrs.dll
2013-04-09 04:50:02435200----a-w-C:\Windows\System32\mssph.dll
2013-04-09 04:50:0213824----a-w-C:\Windows\System32\msshooks.dll
2013-04-09 04:49:541444864----a-w-C:\Windows\System32\MSAudDecMFT.dll
2013-04-09 04:49:45468992----a-w-C:\Windows\System32\MFMediaEngine.dll
2013-04-09 04:49:45281088----a-w-C:\Windows\System32\mfreadwrite.dll
2013-04-09 04:49:36817152----a-w-C:\Windows\System32\kerberos.dll
2013-04-09 04:49:33210432----a-w-C:\Windows\System32\iuilp.dll
2013-04-09 04:49:1650176----a-w-C:\Windows\System32\fmifs.dll
2013-04-09 04:49:16231936----a-w-C:\Windows\System32\fhengine.dll
2013-04-09 04:49:09172544----a-w-C:\Windows\System32\dwmredir.dll
2013-04-09 04:49:06196096----a-w-C:\Windows\System32\dmvdsitf.dll
2013-04-09 04:48:432303488----a-w-C:\Windows\System32\authui.dll
2013-04-09 04:48:42785408----a-w-C:\Windows\System32\audiosrv.dll
2013-04-09 04:48:42169472----a-w-C:\Windows\System32\AudioEndpointBuilder.dll
2013-04-09 04:48:34419840----a-w-C:\Windows\System32\intl.cpl
2013-04-09 02:35:134038144----a-w-C:\Windows\System32\win32k.sys
2013-04-09 02:34:4983968----a-w-C:\Windows\System32\drivers\hidclass.sys
2013-04-09 02:34:4227648----a-w-C:\Windows\System32\drivers\hidusb.sys
2013-04-09 02:34:3095744----a-w-C:\Windows\System32\drivers\hidbth.sys
2013-04-09 02:33:4160416----a-w-C:\Windows\System32\drivers\ndproxy.sys
2013-04-09 02:33:05623104----a-w-C:\Windows\System32\drivers\srv2.sys
2013-04-09 02:32:02805376----a-w-C:\Windows\System32\drivers\PEAuth.sys
2013-04-09 02:31:14247808----a-w-C:\Windows\System32\drivers\srvnet.sys
2013-04-09 02:31:0183456----a-w-C:\Windows\System32\drivers\wanarp.sys
2013-04-08 23:44:25123880----a-w-C:\Windows\SysWow64\wscapi.dll
2013-04-08 23:39:141408896----a-w-C:\Windows\SysWow64\ntdll.dll
2013-04-08 23:37:29426024----a-w-C:\Windows\SysWow64\AudioEng.dll
2013-04-08 23:37:29324368----a-w-C:\Windows\SysWow64\AudioSes.dll
2013-04-08 21:52:16670208----a-w-C:\Windows\SysWow64\SearchIndexer.exe
2013-04-08 21:52:16302592----a-w-C:\Windows\SysWow64\SearchProtocolHost.exe
2013-04-08 21:52:16171008----a-w-C:\Windows\SysWow64\SearchFilterHost.exe
2013-04-08 21:52:16106496----a-w-C:\Windows\SysWow64\Robocopy.exe
2013-04-08 21:52:06364544----a-w-C:\Windows\SysWow64\XpsGdiConverter.dll
2013-04-04 23:30:17503080----a-w-C:\Windows\System32\ci.dll
2013-03-30 18:16:051403784----a-w-C:\Windows\System32\winload.efi
2013-03-30 18:16:051267424----a-w-C:\Windows\System32\winload.exe
2013-03-28 22:09:091093880----a-w-C:\Windows\System32\winresume.exe
2013-03-28 22:09:041217328----a-w-C:\Windows\System32\winresume.efi
2013-03-15 22:05:34298456----a-w-C:\Windows\System32\rsaenh.dll
2013-03-15 22:05:16252928----a-w-C:\Windows\SysWow64\rsaenh.dll
.
============= FINISH: 12:04:41.47 ===============
(3) Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 8
Boot Device: \Device\HarddiskVolume1
Install Date: 12/26/2012 12:05:17 AM
System Uptime: 6/11/2013 12:13:28 AM (12 hours ago)
.
Motherboard: Dell Inc. | | 0J4MPR
Processor: Intel(R) Core(TM) i3-3217U CPU @ 1.80GHz | CPU Socket - U3E1 | 1801/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 452 GiB total, 346.34 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {8a2edc79-c759-46f2-88af-9d4efe3b5eee}
Description: USB-IF xHCI USB Host Controller
Device ID: ROOT\UOIP_BUS_DRIVER\0000
Manufacturer: Intel Corporation
Name: USB-IF xHCI USB Host Controller
PNP Device ID: ROOT\UOIP_BUS_DRIVER\0000
Service: XHCIPort
.
==== System Restore Points ===================
.
RP25: 5/27/2013 8:50:16 PM - Scheduled Checkpoint
RP26: 5/31/2013 9:10:20 PM - Installed Suite
RP27: 6/1/2013 2:22:09 PM - Restore Operation
RP28: 6/10/2013 10:28:04 PM - Scheduled Checkpoint
RP29: 6/10/2013 11:57:05 PM - Restore Operation
.
==== Installed Programs ======================
.
µTorrent
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
Ask Toolbar Updater
Avid License Control
Bonjour
Cirrus Logic Audio Panel
D3DX10
Dell Audio
Dell Backup and Recovery
Dell Backup and Recovery - Support Software
Dell Digital Delivery
Dell Touchpad
Dropbox
Free Download Manager 3.9.2
Get Lyrics
Google Chrome
Google Update Helper
Intel PROSet Wireless
Intel(R) Control Center
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
Intel(R) Rapid Storage Technology
Intel(R) WiDi
Intel® PROSet/Wireless WiFi Software
Intel® Trusted Connect Service Client
iTunes
Java 7 Update 11
Java Auto Updater
LibreOffice 3.6
LibreOffice 3.6 Help Pack (English)
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft Application Error Reporting
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Movie Maker
MSVCRT
MSVCRT110
MSVCRT110_amd64
My Dell
Neuratron AudioScore Lite
Neuratron PhotoScore Lite
Photo Common
Photo Gallery
Python 3.3.0
Quickset64
QuickShare
QuickTime
Realtek USB 2.0 Card Reader
Search Protect by conduit
Shared C Run-time for x64
Sharepod 4.0.0.3
Sibelius 7 OpenType Fonts
Sibelius 7.1.0.54
Sibelius Scorch (all browsers)
Skype™ 6.3
Spotify
uTorrentControl_v6 Toolbar
Wajam
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
xVidly
xVidly1 Toolbar
.
==== Event Viewer Messages From Past Week ========
.
6/9/2013 1:57:47 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000139 (0x0000000000000003, 0xfffff801ae4875a0, 0xfffff801ae4874f8, 0x0000000000000000). A dump was saved in: C:\Windows\Minidump\060913-56484-01.dmp. Report Id: 060913-56484-01.
6/11/2013 12:15:59 AM, Error: Service Control Manager [7034] - The Dell Digital Delivery Service service terminated unexpectedly. It has done this 1 time(s).
6/11/2013 12:13:18 AM, Error: Ntfs [55] - A corruption was discovered in the file system structure on volume OS. The Master File Table (MFT) contains a corrupted file record. The file reference number is 0x800000002c787. The name of the file is "<unable to determine file name>".
6/11/2013 11:24:06 AM, Error: Service Control Manager [7046] - The following service has repeatedly stopped responding to service control requests: SoftThinks Agent Service Contact the service vendor or the system administrator about whether to disable this service until the problem is identified. You may have to restart the computer in safe mode before you can disable the service.
6/11/2013 11:23:36 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
6/10/2013 11:58:02 PM, Error: Ntfs [55] - A corruption was discovered in the file system structure on volume OS. The exact nature of the corruption is unknown. The file system structures need to be scanned online.
.
==== End Of File ===========================