Hey my ASUS laptop has been acting weird showing event logs stating large ammounts of dll`s have been injected into play from unknown source etc and sometimes hear a song or clip playing in backgroud while on some sites yet nothing showing and there are multiple random clsid`s in places such as HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{8BE4F128-3CAA-44AA-9E0A-6A98F6E1E66C}\Parameters\Tcpip and my flat mates pc is infected and it is as if they are communicating even after I delete network shares folders new ones appear and im unsure as to anything anymore. So any help would be greatly appreciated from a real expert!! I have also added a screen shot of the multple interface clsid`s im jabbering about too.
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16660 BrowserJavaVersion: 10.25.2
Run by Sador27 at 22:42:09 on 2013-08-21
#Option Extended Search is enabled.
Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.12174.11008 [GMT 10:00]
.
AV: AVG Internet Security 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG Internet Security 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
============== Running Processes ===============
.
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\dwm.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Windows\system32\dashost.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\loggingserver.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
C:\Program Files\ASUS\P4G\BatteryLife.exe
C:\Windows\system32\taskhostex.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Windows\system32\taskhost.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files (x86)\AVG\AVG2013\avgcfgex.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.au/
mStart Page = about:blank
mWinlogon: Userinit = userinit.exe,
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: {95B7759C-8C7F-4BF1-B163-73684A933233} - <orphaned>
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\AUTORU~1\ASUSVI~1.LNK - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
mPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
TCP: NameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{8BE4F128-3CAA-44AA-9E0A-6A98F6E1E66C} : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{8BE4F128-3CAA-44AA-9E0A-6A98F6E1E66C}\14E235E294E2F4 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{8BE4F128-3CAA-44AA-9E0A-6A98F6E1E66C}\25E214E205E294E254E225 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{8BE4F128-3CAA-44AA-9E0A-6A98F6E1E66C}\25E214E294E2E4 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{8BE4F128-3CAA-44AA-9E0A-6A98F6E1E66C}\25F4D414E4 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{8BE4F128-3CAA-44AA-9E0A-6A98F6E1E66C}\45548435F5731424244334 : DHCPNameServer = 192.168.1.1
Filter: AutorunsDisabled - <Clsid value has no data>
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.5.0\ViProtocol.dll
SSODL: WebCheck - <orphaned>
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings
x64-mStart Page = about:blank
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-mPolicies-Explorer: NoDriveTypeAutoRun = dword:255
x64-mPolicies-Explorer: NoDriveAutoRun = dword:67108863
x64-Filter: AutorunsDisabled - <Clsid value has no data>
x64-Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - <orphaned>
x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\Drivers\avgidsha.sys [2013-7-20 71480]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\Drivers\avgloga.sys [2013-7-20 311608]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\Drivers\avgmfx64.sys [2013-7-1 116536]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\Drivers\avgrkx64.sys [2013-7-10 45880]
R0 iaStorA;iaStorA;C:\Windows\System32\Drivers\iaStorA.sys [2012-7-6 645952]
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-9-8 17536]
R1 Avgfwfd;AVG network filter service;C:\Windows\System32\Drivers\avgfwd6a.sys [2012-9-4 50296]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\Drivers\avgidsdrivera.sys [2013-7-20 246072]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\Drivers\avgldx64.sys [2013-7-20 206648]
R1 Avgwfpa;AVG Firewall Driver;C:\Windows\System32\Drivers\avgwfpa.sys [2013-7-9 248632]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-23 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-13 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2013-5-8 143088]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-3 15416]
R2 ASUS InstantOn;ASUS InstantOn Service;C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-4-14 277120]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2013-7-23 283136]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-21 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-9-14 166720]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-9-14 365376]
R2 vToolbarUpdater15.5.0;vToolbarUpdater15.5.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [2013-8-15 1643184]
R3 AiCharger;ASUS Charger Driver;C:\Windows\System32\Drivers\AiCharger.sys [2012-7-25 17152]
R3 ATP;ASUS PS/2 Port Input Device;C:\Windows\System32\Drivers\AsusTP.sys [2012-10-31 61824]
R3 HIDSwitch;ASUS Wireless Radio Control;C:\Windows\System32\Drivers\AsHIDSwitch64.sys [2012-8-22 21152]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\Drivers\IntcDAud.sys [2012-8-22 342528]
R3 RSBASTOR;Realtek PCIE CardReader Driver - BA;C:\Windows\System32\Drivers\RtsBaStor.sys [2012-9-14 295056]
R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2012-9-14 683664]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\Windows\System32\Drivers\WUDFRd.sys [2012-7-26 198656]
S0 Avgboota;AVG Early Launch Anti-Malware Driver;C:\Windows\System32\Drivers\avgboota.sys [2012-10-26 20912]
S2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2013\avgfws.exe [2013-7-25 1432080]
S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2013-7-4 4939312]
S2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-8-14 418376]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-8-14 701512]
S3 MBAMProtector;MBAMProtector;C:\Windows\System32\Drivers\mbam.sys [2013-8-14 25928]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 60 ================
.
2013-08-20 13:43:28240304----a-w-C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10214.bin
2013-08-16 17:46:57--------d-----w-C:\Program Files (x86)\Belarc
2013-08-14 06:56:1725928----a-w-C:\Windows\System32\drivers\mbam.sys
2013-08-14 06:56:17--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-14 04:51:572877440----a-w-C:\Windows\SysWow64\jscript9.dll
2013-08-14 04:51:56108032----a-w-C:\Program Files (x86)\Internet Explorer\jsdebuggeride.dll
2013-08-14 04:44:1698304----a-w-C:\Windows\System32\apprepsync.dll
2013-08-14 04:44:1687040----a-w-C:\Windows\SysWow64\apprepapi.dll
2013-08-14 04:44:1674240----a-w-C:\Windows\SysWow64\apprepsync.dll
2013-08-14 04:44:1668096----a-w-C:\Windows\System32\cryptsvc.dll
2013-08-14 04:44:16337408----a-w-C:\Windows\System32\wintrust.dll
2013-08-14 04:44:16261120----a-w-C:\Windows\SysWow64\wintrust.dll
2013-08-14 04:44:161889280----a-w-C:\Windows\System32\crypt32.dll
2013-08-14 04:44:161568256----a-w-C:\Windows\SysWow64\crypt32.dll
2013-08-14 04:44:16124416----a-w-C:\Windows\System32\apprepapi.dll
2013-07-21 12:04:11--------d-----w-C:\Users\Sador\AppData\Roaming\AVG2013
2013-07-21 11:56:27--------d-----w-C:\Users\Sador\AppData\Local\AVG Secure Search
2013-07-21 11:55:49--------d-----w-C:\Users\Sador\AppData\Roaming\TuneUp Software
2013-07-21 11:55:3445856----a-w-C:\Windows\System32\drivers\avgtpx64.sys
2013-07-21 11:55:31--------d-----w-C:\ProgramData\AVG Secure Search
2013-07-21 11:55:30--------d-----w-C:\Program Files (x86)\Common Files\AVG Secure Search
2013-07-21 11:55:30--------d-----w-C:\Program Files (x86)\AVG Secure Search
2013-07-21 11:52:00--------d-----w-C:\ProgramData\AVG2013
2013-07-21 11:52:00--------d-----w-C:\$AVG
2013-07-21 11:51:49--------d-----w-C:\Program Files (x86)\AVG
2013-07-21 10:44:29--------d-----w-C:\Users\Sador\AppData\Local\MFAData
2013-07-21 10:44:29--------d-----w-C:\Users\Sador\AppData\Local\Avg2013
2013-07-21 10:44:29--------d-----w-C:\ProgramData\MFAData
2013-07-21 10:44:29--------d-----w-C:\ProgramData\Common Files
2013-07-20 19:42:38867240----a-w-C:\Windows\SysWow64\npDeployJava1.dll
2013-07-20 19:42:38789416----a-w-C:\Windows\SysWow64\deployJava1.dll
2013-07-20 19:42:3796168----a-w-C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-20 19:32:27972712----a-w-C:\Windows\System32\deployJava1.dll
2013-07-20 19:32:271093032----a-w-C:\Windows\System32\npDeployJava1.dll
2013-07-20 19:32:25108968----a-w-C:\Windows\System32\WindowsAccessBridge-64.dll
2013-07-19 15:51:00311608----a-w-C:\Windows\System32\drivers\avgloga.sys
2013-07-19 15:50:5671480----a-w-C:\Windows\System32\drivers\avgidsha.sys
2013-07-19 15:50:56246072----a-w-C:\Windows\System32\drivers\avgidsdrivera.sys
2013-07-19 15:50:50206648----a-w-C:\Windows\System32\drivers\avgldx64.sys
2013-07-19 05:58:21--------d-----w-C:\Windows\System32\MRT
2013-07-17 05:23:01997632----a-w-C:\Windows\System32\drivers\ndis.sys
2013-07-11 13:14:41--------d-----w-C:\Program Files (x86)\FormatFactory
2013-07-09 22:51:242035200----a-w-C:\Program Files\Common Files\Microsoft Shared\ink\InkObj.dll
2013-07-09 22:51:241617920----a-w-C:\Program Files\Windows Journal\NBDoc.DLL
2013-07-09 22:51:241413632----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\InkObj.dll
2013-07-09 22:51:241318912----a-w-C:\Program Files\Windows Journal\JNWDRV.dll
2013-07-09 22:51:241306112----a-w-C:\Program Files\Windows Journal\JNTFiltr.dll
2013-07-09 22:51:241272320----a-w-C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-07-09 22:51:241029632----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\journal.dll
2013-07-09 22:50:344036096----a-w-C:\Windows\System32\win32k.sys
2013-07-09 22:49:44595968----a-w-C:\Windows\System32\qedit.dll
2013-07-09 22:49:44496640----a-w-C:\Windows\SysWow64\qedit.dll
2013-07-09 22:49:4419187712----a-w-C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-07-09 22:49:4418523648----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-07-09 22:49:291838080----a-w-C:\Windows\System32\DWrite.dll
2013-07-09 22:49:291421312----a-w-C:\Windows\SysWow64\DWrite.dll
2013-07-09 22:45:512842112----a-w-C:\Windows\System32\WMVDECOD.DLL
2013-07-09 22:45:512620928----a-w-C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-09 16:05:08--------d-----w-C:\Windows\ERUNT
2013-07-09 15:32:3845880----a-w-C:\Windows\System32\drivers\avgrkx64.sys
2013-07-08 15:28:50248632----a-w-C:\Windows\System32\drivers\avgwfpa.sys
2013-06-30 15:45:28116536----a-w-C:\Windows\System32\drivers\avgmfx64.sys
2013-06-30 13:16:45--------d-----w-C:\Users\Sador\AppData\Local\CrashDumps
.
==================== Find6M ====================
.
2013-07-26 05:13:372241024----a-w-C:\Windows\System32\wininet.dll
2013-07-26 05:13:28915968----a-w-C:\Windows\System32\uxtheme.dll
2013-07-26 05:13:2853760----a-w-C:\Windows\System32\UXInit.dll
2013-07-26 05:12:083958784----a-w-C:\Windows\System32\jscript9.dll
2013-07-26 05:12:04136704----a-w-C:\Windows\System32\iesysprep.dll
2013-07-26 05:12:0367072----a-w-C:\Windows\System32\iesetup.dll
2013-07-26 03:35:082706432----a-w-C:\Windows\System32\mshtml.tlb
2013-07-26 03:13:241767936----a-w-C:\Windows\SysWow64\wininet.dll
2013-07-26 03:13:1544032----a-w-C:\Windows\SysWow64\UXInit.dll
2013-07-26 03:12:0061440----a-w-C:\Windows\SysWow64\iesetup.dll
2013-07-26 03:12:00109056----a-w-C:\Windows\SysWow64\iesysprep.dll
2013-07-26 02:49:142706432----a-w-C:\Windows\SysWow64\mshtml.tlb
2013-07-26 00:54:34534528----a-w-C:\Windows\SysWow64\uxtheme.dll
2013-07-09 06:07:172233168----a-w-C:\Windows\System32\drivers\tcpip.sys
2013-07-02 00:44:1436288----a-w-C:\Windows\System32\drivers\WdBoot.sys
2013-07-01 22:08:49247216----a-w-C:\Windows\System32\drivers\WdFilter.sys
2013-06-27 22:04:5178200----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-27 22:04:51693112----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
2013-06-14 13:09:55175588----a-w-C:\ProgramData\1371215091.bdinstall.bin
2013-06-01 11:54:16194816----a-w-C:\Windows\System32\drivers\sdbus.sys
2013-06-01 11:54:10125184----a-w-C:\Windows\System32\drivers\dumpsd.sys
2013-06-01 11:34:212391280----a-w-C:\Windows\explorer.exe
2013-06-01 11:29:35337152----a-w-C:\Windows\System32\drivers\USBXHCI.SYS
2013-06-01 11:29:35213248----a-w-C:\Windows\System32\drivers\UCX01000.SYS
2013-06-01 11:26:33327936----a-w-C:\Windows\System32\drivers\volsnap.sys
2013-06-01 11:26:316987008----a-w-C:\Windows\System32\ntoskrnl.exe
2013-06-01 10:24:462106176----a-w-C:\Windows\SysWow64\explorer.exe
2013-06-01 09:25:52364544----a-w-C:\Windows\SysWow64\XpsGdiConverter.dll
2013-06-01 09:25:0567584----a-w-C:\Windows\SysWow64\samlib.dll
2013-06-01 09:24:19493056----a-w-C:\Windows\SysWow64\mscms.dll
2013-06-01 09:24:09850944----a-w-C:\Windows\SysWow64\mfasfsrcsnk.dll
2013-06-01 09:24:091453568----a-w-C:\Windows\SysWow64\mfcore.dll
2013-06-01 09:23:461842176----a-w-C:\Windows\SysWow64\dwmcore.dll
2013-06-01 09:23:06680960----a-w-C:\Windows\System32\vds.exe
2013-06-01 09:22:4780896----a-w-C:\Windows\System32\MbaeParserTask.exe
2013-06-01 09:22:33523264----a-w-C:\Windows\System32\XpsGdiConverter.dll
2013-06-01 09:22:33446976----a-w-C:\Windows\System32\wwansvc.dll
2013-06-01 09:22:09190976----a-w-C:\Windows\System32\vdsutil.dll
2013-06-01 09:21:39729600----a-w-C:\Windows\System32\samsrv.dll
2013-06-01 09:21:39106496----a-w-C:\Windows\System32\samlib.dll
2013-06-01 09:20:45583168----a-w-C:\Windows\System32\mscms.dll
2013-06-01 09:20:341527808----a-w-C:\Windows\System32\mfcore.dll
2013-06-01 09:20:341048576----a-w-C:\Windows\System32\mfasfsrcsnk.dll
2013-06-01 09:20:042219520----a-w-C:\Windows\System32\dwmcore.dll
2013-06-01 09:19:58207872----a-w-C:\Windows\System32\DeviceSetupManager.dll
2013-06-01 09:19:42785408----a-w-C:\Windows\System32\audiosrv.dll
2013-06-01 03:08:5737632----a-w-C:\Windows\System32\drivers\BthAvrcpTg.sys
2013-05-24 22:09:201403296----a-w-C:\Windows\System32\winload.efi
2013-05-24 22:09:201271584----a-w-C:\Windows\System32\winload.exe
2013-05-24 22:09:201217352----a-w-C:\Windows\System32\winresume.efi
2013-05-24 22:09:201093904----a-w-C:\Windows\System32\winresume.exe
2013-05-23 23:02:301314816----a-w-C:\Windows\System32\rpcrt4.dll
2013-05-23 23:01:461300992----a-w-C:\Windows\System32\gdi32.dll
2013-05-23 22:27:051022464----a-w-C:\Windows\SysWow64\gdi32.dll
2013-05-23 22:25:22694272----a-w-C:\Windows\SysWow64\rpcrt4.dll
2013-05-15 22:35:47144384----a-w-C:\Windows\System32\tssdisai.dll
2013-05-15 12:44:42800547----a-w-C:\ProgramData\1368617987.bdinstall.bin
2013-05-15 09:37:07984888----a-w-C:\ProgramData\1368605409.bdinstall.bin
2013-05-15 02:25:59888320----a-w-C:\Windows\System32\autochk.exe
2013-05-15 02:25:44542208----a-w-C:\Windows\System32\untfs.dll
2013-05-15 02:24:10793088----a-w-C:\Windows\SysWow64\autochk.exe
2013-05-15 02:24:01482816----a-w-C:\Windows\SysWow64\untfs.dll
2013-05-04 07:58:17120736----a-w-C:\Windows\System32\AuthHost.exe
2013-05-04 07:34:17446720----a-w-C:\Windows\System32\drivers\USBHUB3.SYS
2013-05-04 07:34:15284416----a-w-C:\Windows\System32\drivers\spaceport.sys
2013-05-04 06:59:5639424----a-w-C:\Windows\System32\wuapp.exe
2013-05-04 06:59:511483776----a-w-C:\Windows\System32\VSSVC.exe
2013-05-04 06:59:36812544----a-w-C:\Windows\System32\Magnify.exe
2013-05-04 06:59:2598304----a-w-C:\Windows\System32\wudriver.dll
2013-05-04 06:59:25251904----a-w-C:\Windows\System32\WUSettingsProvider.dll
2013-05-04 06:59:25141824----a-w-C:\Windows\System32\wuwebv.dll
2013-05-04 06:59:241619968----a-w-C:\Windows\System32\wucltux.dll
2013-05-04 06:59:0813644288----a-w-C:\Windows\System32\Windows.UI.Xaml.dll
2013-05-04 06:58:54328192----a-w-C:\Windows\System32\ubpm.dll
2013-05-04 06:58:5410116096----a-w-C:\Windows\System32\twinui.dll
2013-05-04 06:58:49173568----a-w-C:\Windows\System32\storewuauth.dll
2013-05-04 06:58:491332736----a-w-C:\Windows\System32\sysmain.dll
2013-05-04 06:58:48330240----a-w-C:\Windows\System32\stobject.dll
2013-05-04 06:58:2893696----a-w-C:\Windows\System32\psmsrv.dll
2013-05-04 06:58:02470528----a-w-C:\Windows\System32\netprofmsvc.dll
2013-05-04 06:58:02151552----a-w-C:\Windows\System32\netprofm.dll
2013-05-04 06:58:01169984----a-w-C:\Windows\System32\netplwiz.dll
2013-05-04 06:57:5917408----a-w-C:\Windows\System32\muifontsetup.dll
2013-05-04 06:57:46560640----a-w-C:\Windows\System32\mfmp4srcsnk.dll
2013-05-04 06:57:15501760----a-w-C:\Windows\System32\DevicePairing.dll
2013-05-04 06:57:05179712----a-w-C:\Windows\System32\bisrv.dll
2013-05-04 06:57:05122368----a-w-C:\Windows\System32\biwinrt.dll
2013-05-04 06:57:04389120----a-w-C:\Windows\System32\BCP47Langs.dll
2013-05-04 06:57:042305024----a-w-C:\Windows\System32\authui.dll
2013-05-04 06:57:00708096----a-w-C:\Windows\System32\AppXDeploymentExtensions.dll
2013-05-04 06:57:001131520----a-w-C:\Windows\System32\AppXDeploymentServer.dll
2013-05-04 06:56:53419840----a-w-C:\Windows\System32\intl.cpl
2013-05-04 04:58:3434304----a-w-C:\Windows\SysWow64\wuapp.exe
2013-05-04 04:58:14758784----a-w-C:\Windows\SysWow64\Magnify.exe
2013-05-04 04:58:0283968----a-w-C:\Windows\SysWow64\wudriver.dll
2013-05-04 04:58:02125952----a-w-C:\Windows\SysWow64\wuwebv.dll
2013-05-04 04:57:4910788864----a-w-C:\Windows\SysWow64\Windows.UI.Xaml.dll
2013-05-04 04:57:398857088----a-w-C:\Windows\SysWow64\twinui.dll
2013-05-04 04:57:39247296----a-w-C:\Windows\SysWow64\ubpm.dll
2013-05-04 04:57:35303616----a-w-C:\Windows\SysWow64\stobject.dll
.
============= FINISH: 22:42:34.39 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 8
Boot Device: \Device\HarddiskVolume1
Install Date: 3/29/2013 7:59:27 PM
System Uptime: 8/20/2013 5:25:34 PM (29 hours ago)
.
Motherboard: ASUSTeK COMPUTER INC. | | K55A
Processor: Intel(R) Core(TM) i7-3630QM CPU @ 2.40GHz | SOCKET 0 | 2401/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 279 GiB total, 182.429 GiB free.
D: is FIXED (NTFS) - 398 GiB total, 397.901 GiB free.
E: is CDROM ()
F: is FIXED (FAT32) - 931 GiB total, 35.12 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
888poker
Adobe Reader XI (11.0.03)
ASUS InstantOn
ASUS LifeFrame3
ASUS Live Update
ASUS Power4Gear Hybrid
ASUS Smart Gesture
ASUS Splendid Video Enhancement Technology
ASUS Tutor
ASUS USB Charger Plus
ASUS Virtual Camera
ASUS WebStorage Sync Agent
ASUSDVD
AsusVibe2.0
ATK Package
AVG 2013
Belarc Advisor 8.3
CCleaner
CyberLink LabelPrint 2.5
CyberLink Media Suite
CyberLink Power2Go
DVD Decrypter (Remove Only)
FileASSASSIN
FormatFactory
Google Chrome
ImgBurn
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) SDK for OpenCL - CPU Only Runtime Package
Intel® Trusted Connect Service Client
iWisoft Free Video Downloader 2.1
Java 7 Update 25
Java 7 Update 25 (64-bit)
Java Auto Updater
Java SE Development Kit 7 Update 25 (64-bit)
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft Office
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
PKR
PKRCasino
Qualcomm Atheros Client Installation Program
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek PCIE Card Reader
SceneSwitch
Something Fishy: 3D Desktop Aquarium Screen Saver v1.1DX Trial Version
SUPERAntiSpyware
Visual Studio 2010 x64 Redistributables
VLC media player 2.0.5
Windows Driver Package - ASUS (ATP) Mouse (10/29/2012 1.0.0.148)
WinFlash
Winner Casino
Wisdom-soft AutoScreenRecorder 3.1 Free
.
==== Event Viewer Messages From Past Week ========
.
8/20/2013 5:25:12 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied.
8/20/2013 10:26:52 PM, Error: Service Control Manager [7024] -
8/18/2013 9:21:43 PM, Error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.1.100 with the system having network hardware address 1C-65-9D-0D-DD-FB. Network operations on this system may be disrupted as a result.
8/18/2013 6:31:54 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user SAD0R\Sador27 SID (S-1-5-21-4189086294-1421127706-2605213809-1001) from address LocalHost (Using LRPC) running in the application container CapsuleDigital.PhotoFunia_1.7.0.110_neutral__yede6ekgzbztc SID (S-1-15-2-3490798887-4175610012-4048354168-3993597651-1203629619-1240133896-111838046). This security permission can be modified using the Component Services administrative tool.
8/17/2013 5:58:31 AM, Error: Ntfs [55] - A corruption was discovered in the file system structure on volume F:. The exact nature of the corruption is unknown. The file system structures need to be scanned and fixed offline.
8/17/2013 5:58:31 AM, Error: Microsoft-Windows-Ntfs [98] - Volume F: (\Device\HarddiskVolume8) needs to be taken offline to perform a Full Chkdsk. Please run "CHKDSK /F" locally via the command line, or run "REPAIR-VOLUME <drive:>" locally or remotely via PowerShell.
8/17/2013 5:55:36 AM, Error: Microsoft-Windows-Ntfs [98] - Volume F: (\Device\HarddiskVolume7) needs to be taken offline to perform a Full Chkdsk. Please run "CHKDSK /F" locally via the command line, or run "REPAIR-VOLUME <drive:>" locally or remotely via PowerShell.
.
==== End Of File ===========================
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.08.14.02
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16660
Sador27 :: SAD0R [administrator]
8/14/2013 5:21:20 PM
mbam-log-2013-08-14 (17-21-20).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 213285
Time elapsed: 2 minute(s), 14 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Users\Sador\Desktop\x64tools.zip (PUP.NetworkPasswordTool) -> Quarantined and deleted successfully.
(end)
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16660 BrowserJavaVersion: 10.25.2
Run by Sador27 at 22:42:09 on 2013-08-21
#Option Extended Search is enabled.
Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.12174.11008 [GMT 10:00]
.
AV: AVG Internet Security 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG Internet Security 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
============== Running Processes ===============
.
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\dwm.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Windows\system32\dashost.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\loggingserver.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
C:\Program Files\ASUS\P4G\BatteryLife.exe
C:\Windows\system32\taskhostex.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Windows\system32\taskhost.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files (x86)\AVG\AVG2013\avgcfgex.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.au/
mStart Page = about:blank
mWinlogon: Userinit = userinit.exe,
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: {95B7759C-8C7F-4BF1-B163-73684A933233} - <orphaned>
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\AUTORU~1\ASUSVI~1.LNK - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
mPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
TCP: NameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{8BE4F128-3CAA-44AA-9E0A-6A98F6E1E66C} : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{8BE4F128-3CAA-44AA-9E0A-6A98F6E1E66C}\14E235E294E2F4 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{8BE4F128-3CAA-44AA-9E0A-6A98F6E1E66C}\25E214E205E294E254E225 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{8BE4F128-3CAA-44AA-9E0A-6A98F6E1E66C}\25E214E294E2E4 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{8BE4F128-3CAA-44AA-9E0A-6A98F6E1E66C}\25F4D414E4 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{8BE4F128-3CAA-44AA-9E0A-6A98F6E1E66C}\45548435F5731424244334 : DHCPNameServer = 192.168.1.1
Filter: AutorunsDisabled - <Clsid value has no data>
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.5.0\ViProtocol.dll
SSODL: WebCheck - <orphaned>
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings
x64-mStart Page = about:blank
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-mPolicies-Explorer: NoDriveTypeAutoRun = dword:255
x64-mPolicies-Explorer: NoDriveAutoRun = dword:67108863
x64-Filter: AutorunsDisabled - <Clsid value has no data>
x64-Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - <orphaned>
x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\Drivers\avgidsha.sys [2013-7-20 71480]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\Drivers\avgloga.sys [2013-7-20 311608]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\Drivers\avgmfx64.sys [2013-7-1 116536]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\Drivers\avgrkx64.sys [2013-7-10 45880]
R0 iaStorA;iaStorA;C:\Windows\System32\Drivers\iaStorA.sys [2012-7-6 645952]
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-9-8 17536]
R1 Avgfwfd;AVG network filter service;C:\Windows\System32\Drivers\avgfwd6a.sys [2012-9-4 50296]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\Drivers\avgidsdrivera.sys [2013-7-20 246072]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\Drivers\avgldx64.sys [2013-7-20 206648]
R1 Avgwfpa;AVG Firewall Driver;C:\Windows\System32\Drivers\avgwfpa.sys [2013-7-9 248632]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-23 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-13 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2013-5-8 143088]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-3 15416]
R2 ASUS InstantOn;ASUS InstantOn Service;C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-4-14 277120]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2013-7-23 283136]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-21 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-9-14 166720]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-9-14 365376]
R2 vToolbarUpdater15.5.0;vToolbarUpdater15.5.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [2013-8-15 1643184]
R3 AiCharger;ASUS Charger Driver;C:\Windows\System32\Drivers\AiCharger.sys [2012-7-25 17152]
R3 ATP;ASUS PS/2 Port Input Device;C:\Windows\System32\Drivers\AsusTP.sys [2012-10-31 61824]
R3 HIDSwitch;ASUS Wireless Radio Control;C:\Windows\System32\Drivers\AsHIDSwitch64.sys [2012-8-22 21152]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\Drivers\IntcDAud.sys [2012-8-22 342528]
R3 RSBASTOR;Realtek PCIE CardReader Driver - BA;C:\Windows\System32\Drivers\RtsBaStor.sys [2012-9-14 295056]
R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2012-9-14 683664]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\Windows\System32\Drivers\WUDFRd.sys [2012-7-26 198656]
S0 Avgboota;AVG Early Launch Anti-Malware Driver;C:\Windows\System32\Drivers\avgboota.sys [2012-10-26 20912]
S2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2013\avgfws.exe [2013-7-25 1432080]
S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2013-7-4 4939312]
S2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-8-14 418376]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-8-14 701512]
S3 MBAMProtector;MBAMProtector;C:\Windows\System32\Drivers\mbam.sys [2013-8-14 25928]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 60 ================
.
2013-08-20 13:43:28240304----a-w-C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10214.bin
2013-08-16 17:46:57--------d-----w-C:\Program Files (x86)\Belarc
2013-08-14 06:56:1725928----a-w-C:\Windows\System32\drivers\mbam.sys
2013-08-14 06:56:17--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-14 04:51:572877440----a-w-C:\Windows\SysWow64\jscript9.dll
2013-08-14 04:51:56108032----a-w-C:\Program Files (x86)\Internet Explorer\jsdebuggeride.dll
2013-08-14 04:44:1698304----a-w-C:\Windows\System32\apprepsync.dll
2013-08-14 04:44:1687040----a-w-C:\Windows\SysWow64\apprepapi.dll
2013-08-14 04:44:1674240----a-w-C:\Windows\SysWow64\apprepsync.dll
2013-08-14 04:44:1668096----a-w-C:\Windows\System32\cryptsvc.dll
2013-08-14 04:44:16337408----a-w-C:\Windows\System32\wintrust.dll
2013-08-14 04:44:16261120----a-w-C:\Windows\SysWow64\wintrust.dll
2013-08-14 04:44:161889280----a-w-C:\Windows\System32\crypt32.dll
2013-08-14 04:44:161568256----a-w-C:\Windows\SysWow64\crypt32.dll
2013-08-14 04:44:16124416----a-w-C:\Windows\System32\apprepapi.dll
2013-07-21 12:04:11--------d-----w-C:\Users\Sador\AppData\Roaming\AVG2013
2013-07-21 11:56:27--------d-----w-C:\Users\Sador\AppData\Local\AVG Secure Search
2013-07-21 11:55:49--------d-----w-C:\Users\Sador\AppData\Roaming\TuneUp Software
2013-07-21 11:55:3445856----a-w-C:\Windows\System32\drivers\avgtpx64.sys
2013-07-21 11:55:31--------d-----w-C:\ProgramData\AVG Secure Search
2013-07-21 11:55:30--------d-----w-C:\Program Files (x86)\Common Files\AVG Secure Search
2013-07-21 11:55:30--------d-----w-C:\Program Files (x86)\AVG Secure Search
2013-07-21 11:52:00--------d-----w-C:\ProgramData\AVG2013
2013-07-21 11:52:00--------d-----w-C:\$AVG
2013-07-21 11:51:49--------d-----w-C:\Program Files (x86)\AVG
2013-07-21 10:44:29--------d-----w-C:\Users\Sador\AppData\Local\MFAData
2013-07-21 10:44:29--------d-----w-C:\Users\Sador\AppData\Local\Avg2013
2013-07-21 10:44:29--------d-----w-C:\ProgramData\MFAData
2013-07-21 10:44:29--------d-----w-C:\ProgramData\Common Files
2013-07-20 19:42:38867240----a-w-C:\Windows\SysWow64\npDeployJava1.dll
2013-07-20 19:42:38789416----a-w-C:\Windows\SysWow64\deployJava1.dll
2013-07-20 19:42:3796168----a-w-C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-20 19:32:27972712----a-w-C:\Windows\System32\deployJava1.dll
2013-07-20 19:32:271093032----a-w-C:\Windows\System32\npDeployJava1.dll
2013-07-20 19:32:25108968----a-w-C:\Windows\System32\WindowsAccessBridge-64.dll
2013-07-19 15:51:00311608----a-w-C:\Windows\System32\drivers\avgloga.sys
2013-07-19 15:50:5671480----a-w-C:\Windows\System32\drivers\avgidsha.sys
2013-07-19 15:50:56246072----a-w-C:\Windows\System32\drivers\avgidsdrivera.sys
2013-07-19 15:50:50206648----a-w-C:\Windows\System32\drivers\avgldx64.sys
2013-07-19 05:58:21--------d-----w-C:\Windows\System32\MRT
2013-07-17 05:23:01997632----a-w-C:\Windows\System32\drivers\ndis.sys
2013-07-11 13:14:41--------d-----w-C:\Program Files (x86)\FormatFactory
2013-07-09 22:51:242035200----a-w-C:\Program Files\Common Files\Microsoft Shared\ink\InkObj.dll
2013-07-09 22:51:241617920----a-w-C:\Program Files\Windows Journal\NBDoc.DLL
2013-07-09 22:51:241413632----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\InkObj.dll
2013-07-09 22:51:241318912----a-w-C:\Program Files\Windows Journal\JNWDRV.dll
2013-07-09 22:51:241306112----a-w-C:\Program Files\Windows Journal\JNTFiltr.dll
2013-07-09 22:51:241272320----a-w-C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-07-09 22:51:241029632----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\journal.dll
2013-07-09 22:50:344036096----a-w-C:\Windows\System32\win32k.sys
2013-07-09 22:49:44595968----a-w-C:\Windows\System32\qedit.dll
2013-07-09 22:49:44496640----a-w-C:\Windows\SysWow64\qedit.dll
2013-07-09 22:49:4419187712----a-w-C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-07-09 22:49:4418523648----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-07-09 22:49:291838080----a-w-C:\Windows\System32\DWrite.dll
2013-07-09 22:49:291421312----a-w-C:\Windows\SysWow64\DWrite.dll
2013-07-09 22:45:512842112----a-w-C:\Windows\System32\WMVDECOD.DLL
2013-07-09 22:45:512620928----a-w-C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-09 16:05:08--------d-----w-C:\Windows\ERUNT
2013-07-09 15:32:3845880----a-w-C:\Windows\System32\drivers\avgrkx64.sys
2013-07-08 15:28:50248632----a-w-C:\Windows\System32\drivers\avgwfpa.sys
2013-06-30 15:45:28116536----a-w-C:\Windows\System32\drivers\avgmfx64.sys
2013-06-30 13:16:45--------d-----w-C:\Users\Sador\AppData\Local\CrashDumps
.
==================== Find6M ====================
.
2013-07-26 05:13:372241024----a-w-C:\Windows\System32\wininet.dll
2013-07-26 05:13:28915968----a-w-C:\Windows\System32\uxtheme.dll
2013-07-26 05:13:2853760----a-w-C:\Windows\System32\UXInit.dll
2013-07-26 05:12:083958784----a-w-C:\Windows\System32\jscript9.dll
2013-07-26 05:12:04136704----a-w-C:\Windows\System32\iesysprep.dll
2013-07-26 05:12:0367072----a-w-C:\Windows\System32\iesetup.dll
2013-07-26 03:35:082706432----a-w-C:\Windows\System32\mshtml.tlb
2013-07-26 03:13:241767936----a-w-C:\Windows\SysWow64\wininet.dll
2013-07-26 03:13:1544032----a-w-C:\Windows\SysWow64\UXInit.dll
2013-07-26 03:12:0061440----a-w-C:\Windows\SysWow64\iesetup.dll
2013-07-26 03:12:00109056----a-w-C:\Windows\SysWow64\iesysprep.dll
2013-07-26 02:49:142706432----a-w-C:\Windows\SysWow64\mshtml.tlb
2013-07-26 00:54:34534528----a-w-C:\Windows\SysWow64\uxtheme.dll
2013-07-09 06:07:172233168----a-w-C:\Windows\System32\drivers\tcpip.sys
2013-07-02 00:44:1436288----a-w-C:\Windows\System32\drivers\WdBoot.sys
2013-07-01 22:08:49247216----a-w-C:\Windows\System32\drivers\WdFilter.sys
2013-06-27 22:04:5178200----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-27 22:04:51693112----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
2013-06-14 13:09:55175588----a-w-C:\ProgramData\1371215091.bdinstall.bin
2013-06-01 11:54:16194816----a-w-C:\Windows\System32\drivers\sdbus.sys
2013-06-01 11:54:10125184----a-w-C:\Windows\System32\drivers\dumpsd.sys
2013-06-01 11:34:212391280----a-w-C:\Windows\explorer.exe
2013-06-01 11:29:35337152----a-w-C:\Windows\System32\drivers\USBXHCI.SYS
2013-06-01 11:29:35213248----a-w-C:\Windows\System32\drivers\UCX01000.SYS
2013-06-01 11:26:33327936----a-w-C:\Windows\System32\drivers\volsnap.sys
2013-06-01 11:26:316987008----a-w-C:\Windows\System32\ntoskrnl.exe
2013-06-01 10:24:462106176----a-w-C:\Windows\SysWow64\explorer.exe
2013-06-01 09:25:52364544----a-w-C:\Windows\SysWow64\XpsGdiConverter.dll
2013-06-01 09:25:0567584----a-w-C:\Windows\SysWow64\samlib.dll
2013-06-01 09:24:19493056----a-w-C:\Windows\SysWow64\mscms.dll
2013-06-01 09:24:09850944----a-w-C:\Windows\SysWow64\mfasfsrcsnk.dll
2013-06-01 09:24:091453568----a-w-C:\Windows\SysWow64\mfcore.dll
2013-06-01 09:23:461842176----a-w-C:\Windows\SysWow64\dwmcore.dll
2013-06-01 09:23:06680960----a-w-C:\Windows\System32\vds.exe
2013-06-01 09:22:4780896----a-w-C:\Windows\System32\MbaeParserTask.exe
2013-06-01 09:22:33523264----a-w-C:\Windows\System32\XpsGdiConverter.dll
2013-06-01 09:22:33446976----a-w-C:\Windows\System32\wwansvc.dll
2013-06-01 09:22:09190976----a-w-C:\Windows\System32\vdsutil.dll
2013-06-01 09:21:39729600----a-w-C:\Windows\System32\samsrv.dll
2013-06-01 09:21:39106496----a-w-C:\Windows\System32\samlib.dll
2013-06-01 09:20:45583168----a-w-C:\Windows\System32\mscms.dll
2013-06-01 09:20:341527808----a-w-C:\Windows\System32\mfcore.dll
2013-06-01 09:20:341048576----a-w-C:\Windows\System32\mfasfsrcsnk.dll
2013-06-01 09:20:042219520----a-w-C:\Windows\System32\dwmcore.dll
2013-06-01 09:19:58207872----a-w-C:\Windows\System32\DeviceSetupManager.dll
2013-06-01 09:19:42785408----a-w-C:\Windows\System32\audiosrv.dll
2013-06-01 03:08:5737632----a-w-C:\Windows\System32\drivers\BthAvrcpTg.sys
2013-05-24 22:09:201403296----a-w-C:\Windows\System32\winload.efi
2013-05-24 22:09:201271584----a-w-C:\Windows\System32\winload.exe
2013-05-24 22:09:201217352----a-w-C:\Windows\System32\winresume.efi
2013-05-24 22:09:201093904----a-w-C:\Windows\System32\winresume.exe
2013-05-23 23:02:301314816----a-w-C:\Windows\System32\rpcrt4.dll
2013-05-23 23:01:461300992----a-w-C:\Windows\System32\gdi32.dll
2013-05-23 22:27:051022464----a-w-C:\Windows\SysWow64\gdi32.dll
2013-05-23 22:25:22694272----a-w-C:\Windows\SysWow64\rpcrt4.dll
2013-05-15 22:35:47144384----a-w-C:\Windows\System32\tssdisai.dll
2013-05-15 12:44:42800547----a-w-C:\ProgramData\1368617987.bdinstall.bin
2013-05-15 09:37:07984888----a-w-C:\ProgramData\1368605409.bdinstall.bin
2013-05-15 02:25:59888320----a-w-C:\Windows\System32\autochk.exe
2013-05-15 02:25:44542208----a-w-C:\Windows\System32\untfs.dll
2013-05-15 02:24:10793088----a-w-C:\Windows\SysWow64\autochk.exe
2013-05-15 02:24:01482816----a-w-C:\Windows\SysWow64\untfs.dll
2013-05-04 07:58:17120736----a-w-C:\Windows\System32\AuthHost.exe
2013-05-04 07:34:17446720----a-w-C:\Windows\System32\drivers\USBHUB3.SYS
2013-05-04 07:34:15284416----a-w-C:\Windows\System32\drivers\spaceport.sys
2013-05-04 06:59:5639424----a-w-C:\Windows\System32\wuapp.exe
2013-05-04 06:59:511483776----a-w-C:\Windows\System32\VSSVC.exe
2013-05-04 06:59:36812544----a-w-C:\Windows\System32\Magnify.exe
2013-05-04 06:59:2598304----a-w-C:\Windows\System32\wudriver.dll
2013-05-04 06:59:25251904----a-w-C:\Windows\System32\WUSettingsProvider.dll
2013-05-04 06:59:25141824----a-w-C:\Windows\System32\wuwebv.dll
2013-05-04 06:59:241619968----a-w-C:\Windows\System32\wucltux.dll
2013-05-04 06:59:0813644288----a-w-C:\Windows\System32\Windows.UI.Xaml.dll
2013-05-04 06:58:54328192----a-w-C:\Windows\System32\ubpm.dll
2013-05-04 06:58:5410116096----a-w-C:\Windows\System32\twinui.dll
2013-05-04 06:58:49173568----a-w-C:\Windows\System32\storewuauth.dll
2013-05-04 06:58:491332736----a-w-C:\Windows\System32\sysmain.dll
2013-05-04 06:58:48330240----a-w-C:\Windows\System32\stobject.dll
2013-05-04 06:58:2893696----a-w-C:\Windows\System32\psmsrv.dll
2013-05-04 06:58:02470528----a-w-C:\Windows\System32\netprofmsvc.dll
2013-05-04 06:58:02151552----a-w-C:\Windows\System32\netprofm.dll
2013-05-04 06:58:01169984----a-w-C:\Windows\System32\netplwiz.dll
2013-05-04 06:57:5917408----a-w-C:\Windows\System32\muifontsetup.dll
2013-05-04 06:57:46560640----a-w-C:\Windows\System32\mfmp4srcsnk.dll
2013-05-04 06:57:15501760----a-w-C:\Windows\System32\DevicePairing.dll
2013-05-04 06:57:05179712----a-w-C:\Windows\System32\bisrv.dll
2013-05-04 06:57:05122368----a-w-C:\Windows\System32\biwinrt.dll
2013-05-04 06:57:04389120----a-w-C:\Windows\System32\BCP47Langs.dll
2013-05-04 06:57:042305024----a-w-C:\Windows\System32\authui.dll
2013-05-04 06:57:00708096----a-w-C:\Windows\System32\AppXDeploymentExtensions.dll
2013-05-04 06:57:001131520----a-w-C:\Windows\System32\AppXDeploymentServer.dll
2013-05-04 06:56:53419840----a-w-C:\Windows\System32\intl.cpl
2013-05-04 04:58:3434304----a-w-C:\Windows\SysWow64\wuapp.exe
2013-05-04 04:58:14758784----a-w-C:\Windows\SysWow64\Magnify.exe
2013-05-04 04:58:0283968----a-w-C:\Windows\SysWow64\wudriver.dll
2013-05-04 04:58:02125952----a-w-C:\Windows\SysWow64\wuwebv.dll
2013-05-04 04:57:4910788864----a-w-C:\Windows\SysWow64\Windows.UI.Xaml.dll
2013-05-04 04:57:398857088----a-w-C:\Windows\SysWow64\twinui.dll
2013-05-04 04:57:39247296----a-w-C:\Windows\SysWow64\ubpm.dll
2013-05-04 04:57:35303616----a-w-C:\Windows\SysWow64\stobject.dll
.
============= FINISH: 22:42:34.39 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 8
Boot Device: \Device\HarddiskVolume1
Install Date: 3/29/2013 7:59:27 PM
System Uptime: 8/20/2013 5:25:34 PM (29 hours ago)
.
Motherboard: ASUSTeK COMPUTER INC. | | K55A
Processor: Intel(R) Core(TM) i7-3630QM CPU @ 2.40GHz | SOCKET 0 | 2401/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 279 GiB total, 182.429 GiB free.
D: is FIXED (NTFS) - 398 GiB total, 397.901 GiB free.
E: is CDROM ()
F: is FIXED (FAT32) - 931 GiB total, 35.12 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
888poker
Adobe Reader XI (11.0.03)
ASUS InstantOn
ASUS LifeFrame3
ASUS Live Update
ASUS Power4Gear Hybrid
ASUS Smart Gesture
ASUS Splendid Video Enhancement Technology
ASUS Tutor
ASUS USB Charger Plus
ASUS Virtual Camera
ASUS WebStorage Sync Agent
ASUSDVD
AsusVibe2.0
ATK Package
AVG 2013
Belarc Advisor 8.3
CCleaner
CyberLink LabelPrint 2.5
CyberLink Media Suite
CyberLink Power2Go
DVD Decrypter (Remove Only)
FileASSASSIN
FormatFactory
Google Chrome
ImgBurn
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) SDK for OpenCL - CPU Only Runtime Package
Intel® Trusted Connect Service Client
iWisoft Free Video Downloader 2.1
Java 7 Update 25
Java 7 Update 25 (64-bit)
Java Auto Updater
Java SE Development Kit 7 Update 25 (64-bit)
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft Office
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
PKR
PKRCasino
Qualcomm Atheros Client Installation Program
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek PCIE Card Reader
SceneSwitch
Something Fishy: 3D Desktop Aquarium Screen Saver v1.1DX Trial Version
SUPERAntiSpyware
Visual Studio 2010 x64 Redistributables
VLC media player 2.0.5
Windows Driver Package - ASUS (ATP) Mouse (10/29/2012 1.0.0.148)
WinFlash
Winner Casino
Wisdom-soft AutoScreenRecorder 3.1 Free
.
==== Event Viewer Messages From Past Week ========
.
8/20/2013 5:25:12 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied.
8/20/2013 10:26:52 PM, Error: Service Control Manager [7024] -
8/18/2013 9:21:43 PM, Error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.1.100 with the system having network hardware address 1C-65-9D-0D-DD-FB. Network operations on this system may be disrupted as a result.
8/18/2013 6:31:54 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user SAD0R\Sador27 SID (S-1-5-21-4189086294-1421127706-2605213809-1001) from address LocalHost (Using LRPC) running in the application container CapsuleDigital.PhotoFunia_1.7.0.110_neutral__yede6ekgzbztc SID (S-1-15-2-3490798887-4175610012-4048354168-3993597651-1203629619-1240133896-111838046). This security permission can be modified using the Component Services administrative tool.
8/17/2013 5:58:31 AM, Error: Ntfs [55] - A corruption was discovered in the file system structure on volume F:. The exact nature of the corruption is unknown. The file system structures need to be scanned and fixed offline.
8/17/2013 5:58:31 AM, Error: Microsoft-Windows-Ntfs [98] - Volume F: (\Device\HarddiskVolume8) needs to be taken offline to perform a Full Chkdsk. Please run "CHKDSK /F" locally via the command line, or run "REPAIR-VOLUME <drive:>" locally or remotely via PowerShell.
8/17/2013 5:55:36 AM, Error: Microsoft-Windows-Ntfs [98] - Volume F: (\Device\HarddiskVolume7) needs to be taken offline to perform a Full Chkdsk. Please run "CHKDSK /F" locally via the command line, or run "REPAIR-VOLUME <drive:>" locally or remotely via PowerShell.
.
==== End Of File ===========================
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.08.14.02
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16660
Sador27 :: SAD0R [administrator]
8/14/2013 5:21:20 PM
mbam-log-2013-08-14 (17-21-20).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 213285
Time elapsed: 2 minute(s), 14 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Users\Sador\Desktop\x64tools.zip (PUP.NetworkPasswordTool) -> Quarantined and deleted successfully.
(end)
