NasuButt
Posts: 11 +0
Hi! As the title says, I am having a couple BSoD issues [No specific error included] and other crashing issues as well as a couple issues with some programs I use.
Here are my logs:
Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org
Database version: v2013.01.14.10
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
Josh :: FAG-PC [administrator]
1/14/2013 5:48:41 PM
mbam-log-2013-01-14 (17-48-41).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 232607
Time elapsed: 12 minute(s), 21 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 19
HKLM\SOFTWARE\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk (PUP.GamesPlayLab) -> No action taken.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk (PUP.GamesPlayLab) -> No action taken.
HKCR\CLSID\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKCR\TypeLib\{44444444-4444-4444-4444-440044224458} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKCR\Interface\{55555555-5555-5555-5555-550055225558} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0002258.BHO.1 (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKCR\CLSID\{22222222-2222-2222-2222-220022222258} (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0002258.Sandbox.1 (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0002258.Sandbox (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKCR\CLSID\{33333333-3333-3333-3333-330033223358} (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0002258.FBApi.1 (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0002258.FBApi (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0002258.BHO (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\I Want This (Adware.GamePlayLab) -> Quarantined and deleted successfully.
Registry Values Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\I Want This|Publisher (Adware.GamePlayLab) -> Data: 215 Apps -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 5
C:\Program Files\I Want This (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Users\FAG\Local Settings\Application Data\I Want This (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Users\FAG\Local Settings\Application Data\I Want This\Chrome (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Users\FAG\AppData\Local\I Want This (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Users\FAG\AppData\Local\I Want This\Chrome (Adware.GamePlayLab) -> Quarantined and deleted successfully.
Files Detected: 11
C:\Program Files\I Want This\I Want This.dll (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
C:\Users\FAG\AppData\Local\temp\IWantThis.exe (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
C:\Users\FAG\AppData\Local\temp\.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\I Want This\I Want This.ini (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Program Files\I Want This\I Want This.exe (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Program Files\I Want This\I Want This.ico (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Program Files\I Want This\I Want ThisGui.exe (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Program Files\I Want This\I Want ThisInstaller.log (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Program Files\I Want This\Uninstall.exe (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Users\FAG\Local Settings\Application Data\I Want This\Chrome\I Want This.crx (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Users\FAG\AppData\Local\I Want This\Chrome\I Want This.crx (Adware.GamePlayLab) -> Quarantined and deleted successfully.
(end)
_________________________________________________
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_29
Run by Josh at 18:13:02 on 2013-01-14
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3062.1920 [GMT -5:00]
.
AV: AVG Internet Security *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Internet Security *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Tablet\Pen\WacomHost.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Bamboo Dock\BambooCore.exe
C:\Program Files\Steam\Steam.exe
C:\Users\Josh\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\svchost.exe -k WindowsMobile
.
============== Pseudo HJT Report ===============
.
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [BambooCore] c:\program files\bamboo dock\BambooCore.exe
StartupFolder: c:\users\josh\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\josh\appdata\roaming\dropbox\bin\Dropbox.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
DPF: {7623BE59-D4CF-4379-ABC4-B39E11854D66} - hxxp://avatar.mabinogi.jp/3drender/renderer/mabiweb.2010.05.24.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 75.75.76.76 75.75.75.75
TCP: Interfaces\{04A64E48-5D43-43F3-BA7D-CACE7172D049} : DHCPNameServer = 75.75.76.76 75.75.75.75
TCP: Interfaces\{04A64E48-5D43-43F3-BA7D-CACE7172D049}\2627F636B6 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{04A64E48-5D43-43F3-BA7D-CACE7172D049}\6657C6D65627 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{04A64E48-5D43-43F3-BA7D-CACE7172D049}\7516E6E616027716473686 : DHCPNameServer = 75.75.76.76 75.75.75.75
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\24.0.1312.52\installer\setup.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\josh\appdata\roaming\mozilla\firefox\profiles\ep0qw4jw.default\
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npBFPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\tabletplugins\npWacomTabletPlugin.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\nexon\ngm\npnxgame.dll
FF - plugin: c:\programdata\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_135.dll
FF - plugin: c:\windows\system32\npmproxy.dll
FF - plugin: c:\windows\system32\npOGPPlugin.dll
FF - ExtSQL: 2012-12-26 20:43; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-10-25 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-10-25 337880]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-3-25 242240]
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\rsdrv.sys [2012-1-21 22312]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2012-7-11 116608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-10-25 20696]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-10-25 57688]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-4-6 44768]
R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [2009-7-13 20992]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\skype\toolbars\skype c2c service\c2c_service.exe [2012-12-13 3290896]
R2 WTabletServiceCon;Wacom Consumer Service;c:\program files\tablet\pen\WTabletServiceCon.exe [2012-12-24 526208]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-9-28 315392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 FreemakeVideoCapture;FreemakeVideoCapture;c:\program files\freemake\capturelib\CaptureLibService.exe [2011-11-27 8704]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-11-9 160944]
S3 apf003;apf003;c:\windows\system32\apf003.sys [2012-5-13 13232]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 hidkmdf;KMDF Driver;c:\windows\system32\drivers\hidkmdf.sys [2012-12-24 11680]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-10-26 15872]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-10-26 52224]
S3 WacHidRouter;Wacom Hid Router;c:\windows\system32\drivers\wachidrouter.sys [2012-12-24 69024]
S3 wacomrouterfilter;Wacom Router Filter Driver;c:\windows\system32\drivers\wacomrouterfilter.sys [2012-12-24 13728]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-11-10 1343400]
S3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files\razer\razer game booster\driver\WinRing0.sys [2012-11-13 14416]
S4 atashost;WebEx Service Host for Support Center;c:\windows\system32\atashost.exe [2012-1-25 133944]
.
=============== Created Last 30 ================
.
2013-01-14 22:47:25--------d-----w-c:\users\josh\appdata\roaming\Malwarebytes
2013-01-14 22:46:29--------d-----w-c:\users\josh\appdata\local\Programs
2013-01-14 21:24:46--------d-----w-c:\users\josh\appdata\local\SecondLife
2013-01-14 21:23:55--------d-----w-c:\program files\SecondLifeViewer2
2013-01-14 06:08:07--------d-----w-c:\users\josh\appdata\roaming\Auslogics
2013-01-14 06:05:19--------d-----w-c:\program files\Portable
2013-01-14 02:52:09--------d-----w-c:\program files\Auslogics
2013-01-14 02:26:43--------d-----w-c:\program files\ESET
2013-01-13 22:24:08--------d-----w-c:\users\josh\appdata\roaming\enchant
2013-01-13 22:17:32--------d-----w-c:\users\josh\AbiSuite
2013-01-13 22:15:17--------d-----w-c:\program files\AbiWord
2013-01-13 05:08:46--------d-----w-c:\users\josh\appdata\roaming\DAEMON Tools Lite
2013-01-09 04:25:292345984----a-w-c:\windows\system32\win32k.sys
2013-01-09 04:25:051389568----a-w-c:\windows\system32\msxml6.dll
2013-01-09 04:24:53293376----a-w-c:\windows\system32\KernelBase.dll
2013-01-09 04:24:51271360----a-w-c:\windows\system32\conhost.exe
2013-01-09 04:24:51169984----a-w-c:\windows\system32\winsrv.dll
2013-01-09 04:24:18492032----a-w-c:\windows\system32\win32spl.dll
2013-01-09 04:24:15626688----a-w-c:\windows\system32\usp10.dll
2013-01-09 04:24:11220160----a-w-c:\windows\system32\ncrypt.dll
2013-01-09 04:24:0949152----a-w-c:\windows\system32\taskhost.exe
2013-01-09 02:25:50--------d-----w-c:\program files\common files\Steam
2013-01-09 02:25:46--------d-----w-c:\program files\Steam
2013-01-08 23:28:02--------d-----w-c:\program files\Super Meat Boy
2013-01-08 18:03:28--------d-----w-c:\users\josh\appdata\local\SKIDROW
2013-01-08 17:57:10452440----a-w-c:\windows\system32\d3dx10_40.dll
2013-01-08 17:57:102036576----a-w-c:\windows\system32\D3DCompiler_40.dll
2013-01-08 17:57:094379984----a-w-c:\windows\system32\D3DX9_40.dll
2013-01-08 14:52:16--------d-----w-c:\users\josh\.swt
2013-01-08 09:38:10--------d-----w-c:\users\josh\appdata\roaming\SUPERAntiSpyware.com
2013-01-08 09:37:42--------d-----w-c:\programdata\SUPERAntiSpyware.com
2013-01-08 09:37:42--------d-----w-c:\program files\SUPERAntiSpyware
2013-01-08 09:23:27--------d-----w-c:\users\josh\appdata\roaming\BitTorrent
2013-01-05 15:21:46--------d-----w-c:\users\josh\appdata\local\CyberLink
2013-01-05 15:21:05--------d-----w-c:\users\josh\appdata\local\CrashRpt
2013-01-05 15:20:45--------d-----w-c:\users\josh\appdata\local\Producer
2013-01-05 15:20:45--------d-----w-c:\program files\Livestream for Producers
2013-01-05 15:09:00--------d-----w-c:\users\josh\appdata\roaming\Livestream
2013-01-05 13:42:44--------d-----w-c:\users\josh\appdata\roaming\fltk.org
2013-01-05 13:42:44--------d-----w-c:\programdata\fltk.org
2013-01-05 13:32:27--------d-----w-c:\program files\Amnesia - The Dark Descent
2013-01-05 12:56:10--------d-----w-c:\program files\uTorrent
2013-01-05 12:55:17--------d-----w-c:\users\josh\appdata\roaming\uTorrent
2013-01-05 05:39:03--------d-----r-c:\users\josh\Dropbox
2013-01-05 05:36:20--------d-----w-c:\users\josh\appdata\roaming\Dropbox
2012-12-25 18:41:05295424----a-w-c:\windows\system32\atmfd.dll
2012-12-25 18:41:0434304----a-w-c:\windows\system32\atmlib.dll
2012-12-25 18:27:04--------d-----w-c:\users\josh\appdata\local\Apple Computer
2012-12-25 02:09:24--------d-----r-c:\program files\Skype
2012-12-24 21:47:09--------d-----w-c:\users\josh\appdata\roaming\SYSTEMAX Software Development
2012-12-24 21:40:54--------d-----w-c:\users\josh\appdata\roaming\WTablet
2012-12-24 21:40:52--------d-----w-c:\program files\TabletPlugins
2012-12-24 21:40:4869024----a-w-c:\windows\system32\drivers\wachidrouter.sys
2012-12-24 21:40:481461992----a-w-c:\windows\system32\wdfcoinstaller01009.dll
2012-12-24 21:40:4811680----a-w-c:\windows\system32\drivers\hidkmdf.sys
2012-12-24 21:40:381629056----a-w-c:\windows\system32\Pen_Tablet.dll
2012-12-24 21:40:381621888----a-w-c:\windows\system32\Pen_Touch_Tablet.dll
2012-12-24 21:40:381510272----a-w-c:\windows\system32\Wintab32.dll
2012-12-24 21:40:381506176----a-w-c:\windows\system32\WacomMT.dll
2012-12-24 21:40:36--------d-----w-c:\program files\Tablet
2012-12-24 21:31:49--------d-----w-c:\users\josh\appdata\local\join.me
2012-12-24 21:31:27--------d-----w-c:\users\josh\appdata\roaming\Wacom
2012-12-24 21:31:19--------d-----w-c:\programdata\Wacom
2012-12-24 21:30:50--------d-----w-c:\users\josh\appdata\local\Adobe
2012-12-24 21:30:38--------d-----w-c:\program files\Bamboo Dock
2012-12-24 21:24:4913728----a-w-c:\windows\system32\drivers\wacomrouterfilter.sys
2012-12-24 06:59:01--------d-----w-c:\users\josh\appdata\local\Razer
2012-12-24 02:27:32--------d-----w-c:\users\josh\appdata\local\PMB Files
2012-12-24 02:21:20--------d-----w-c:\users\josh\appdata\local\Google
2012-12-24 02:20:42--------d-----w-c:\users\josh\appdata\local\Apple
2012-12-24 02:19:25--------d-----w-c:\users\josh\appdata\local\Mozilla
2012-12-24 02:17:00--------d-----w-c:\users\josh\appdata\local\VirtualStore
2012-12-18 18:20:22376832----a-w-c:\windows\system32\dpnet.dll
2012-12-18 18:20:182048----a-w-c:\windows\system32\tzres.dll
.
==================== Find3M ====================
.
2013-01-13 05:22:1856320----a-w-c:\windows\system32\vsstrace.dll
2012-12-14 21:49:2821104----a-w-c:\windows\system32\drivers\mbam.sys
2012-12-12 03:51:1973656----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-12 03:51:19697272----a-w-c:\windows\system32\FlashPlayerApp.exe
2010-09-17 00:01:062608640----a-w-c:\program files\STEINSGATE.exe
.
============= FINISH: 18:15:12.53 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 5/24/2010 9:50:54 PM
System Uptime: 1/14/2013 6:08:34 PM (0 hours ago)
.
Motherboard: Wistron | | 30CD
Processor: Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz | U2E1 | 1833/667mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 233 GiB total, 61.293 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is CDROM ()
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP809: 1/14/2013 3:01:16 AM - Windows Update
RP811: 1/14/2013 4:24:33 AM - Windows Update
.
==== Installed Programs ======================
.
µTorrent
7-Zip 9.21
AbiWord 2.8.6
Adobe AIR
Adobe Download Assistant
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Amnesia - The Dark Descent
ƒOƒŠ[ƒtƒVƒ“ƒhƒ[ƒ€ Ver1.10
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
Auslogics Registry Cleaner
avast! Free Antivirus
Bamboo
Bamboo Dock
Bandisoft MPEG-1 Decoder
BitTorrent
Blacklight Retribution
Bonjour
CCleaner
Conexant HD Audio
CyberLink YouCam
D3DX10
DAEMON Tools Lite
Dark Eternal- Dissolution
Derpys Lamp
DivX Setup
Dragon Nest
Dropbox
DS4 Default Content
Elsword version 1.17
ESET Online Scanner v3
Facebook Video Calling 1.0.0.8714
Facebook Video Calling 1.2.0.287
File Shredder 2.0
Fraps (remove only)
Google Chrome
Google Update Helper
Grand Chase version 092412
HDAUDIO Soft Data Fax Modem with SmartCP
Intel(R) Graphics Media Accelerator Driver
Intel(R) TV Wizard
iTunes
Java Auto Updater
Java(TM) 6 Update 22
Java(TM) 6 Update 29
join.me
League of Legends
Lernout & Hauspie TruVoice American English TTS Engine
Livestream for Producers
Mabinogi
Malwarebytes Anti-Malware version 1.70.0.1100
MapleStory
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Mozilla Firefox 15.0.1 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
Nexon Game Manager
NVIDIA PhysX
OGPlanet Game Launcher
ooVoo
OpenOffice.org 3.3
Pando Media Booster
Portal 2
Project64 1.6
PunkBuster Services
QuickTime
Razer Game Booster
Rumble Fighter
RuneScape Launcher 1.0.4
Rusty Hearts
SecondLifeViewer (remove only)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Skype Click to Call
Skype™ 6.0
Steam
StepMania v5.0 alpha 1a (remove only)
STOnline
SUPERAntiSpyware
Trickster
TuneUp Companion 2.2.7
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
VC80CRTRedist - 8.0.50727.6195
Vindictus
Voobly Game Data
WebTablet FB Plugin 32 bit
WIDI Recognition System Pro 3.3 (remove only)
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Mobile Device Center
WinPcap 4.1.2
WinRAR 4.01 (32-bit)
.
==== End Of File ===========================
Here are my logs:
Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org
Database version: v2013.01.14.10
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
Josh :: FAG-PC [administrator]
1/14/2013 5:48:41 PM
mbam-log-2013-01-14 (17-48-41).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 232607
Time elapsed: 12 minute(s), 21 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 19
HKLM\SOFTWARE\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk (PUP.GamesPlayLab) -> No action taken.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk (PUP.GamesPlayLab) -> No action taken.
HKCR\CLSID\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKCR\TypeLib\{44444444-4444-4444-4444-440044224458} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKCR\Interface\{55555555-5555-5555-5555-550055225558} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0002258.BHO.1 (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
HKCR\CLSID\{22222222-2222-2222-2222-220022222258} (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0002258.Sandbox.1 (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0002258.Sandbox (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKCR\CLSID\{33333333-3333-3333-3333-330033223358} (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0002258.FBApi.1 (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0002258.FBApi (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0002258.BHO (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\I Want This (Adware.GamePlayLab) -> Quarantined and deleted successfully.
Registry Values Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\I Want This|Publisher (Adware.GamePlayLab) -> Data: 215 Apps -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 5
C:\Program Files\I Want This (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Users\FAG\Local Settings\Application Data\I Want This (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Users\FAG\Local Settings\Application Data\I Want This\Chrome (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Users\FAG\AppData\Local\I Want This (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Users\FAG\AppData\Local\I Want This\Chrome (Adware.GamePlayLab) -> Quarantined and deleted successfully.
Files Detected: 11
C:\Program Files\I Want This\I Want This.dll (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
C:\Users\FAG\AppData\Local\temp\IWantThis.exe (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
C:\Users\FAG\AppData\Local\temp\.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\I Want This\I Want This.ini (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Program Files\I Want This\I Want This.exe (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Program Files\I Want This\I Want This.ico (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Program Files\I Want This\I Want ThisGui.exe (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Program Files\I Want This\I Want ThisInstaller.log (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Program Files\I Want This\Uninstall.exe (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Users\FAG\Local Settings\Application Data\I Want This\Chrome\I Want This.crx (Adware.GamePlayLab) -> Quarantined and deleted successfully.
C:\Users\FAG\AppData\Local\I Want This\Chrome\I Want This.crx (Adware.GamePlayLab) -> Quarantined and deleted successfully.
(end)
_________________________________________________
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_29
Run by Josh at 18:13:02 on 2013-01-14
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3062.1920 [GMT -5:00]
.
AV: AVG Internet Security *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Internet Security *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Tablet\Pen\WacomHost.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Bamboo Dock\BambooCore.exe
C:\Program Files\Steam\Steam.exe
C:\Users\Josh\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\svchost.exe -k WindowsMobile
.
============== Pseudo HJT Report ===============
.
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [BambooCore] c:\program files\bamboo dock\BambooCore.exe
StartupFolder: c:\users\josh\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\josh\appdata\roaming\dropbox\bin\Dropbox.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
DPF: {7623BE59-D4CF-4379-ABC4-B39E11854D66} - hxxp://avatar.mabinogi.jp/3drender/renderer/mabiweb.2010.05.24.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 75.75.76.76 75.75.75.75
TCP: Interfaces\{04A64E48-5D43-43F3-BA7D-CACE7172D049} : DHCPNameServer = 75.75.76.76 75.75.75.75
TCP: Interfaces\{04A64E48-5D43-43F3-BA7D-CACE7172D049}\2627F636B6 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{04A64E48-5D43-43F3-BA7D-CACE7172D049}\6657C6D65627 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{04A64E48-5D43-43F3-BA7D-CACE7172D049}\7516E6E616027716473686 : DHCPNameServer = 75.75.76.76 75.75.75.75
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\24.0.1312.52\installer\setup.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\josh\appdata\roaming\mozilla\firefox\profiles\ep0qw4jw.default\
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npBFPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\tabletplugins\npWacomTabletPlugin.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\nexon\ngm\npnxgame.dll
FF - plugin: c:\programdata\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_135.dll
FF - plugin: c:\windows\system32\npmproxy.dll
FF - plugin: c:\windows\system32\npOGPPlugin.dll
FF - ExtSQL: 2012-12-26 20:43; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-10-25 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-10-25 337880]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-3-25 242240]
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\rsdrv.sys [2012-1-21 22312]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2012-7-11 116608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-10-25 20696]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-10-25 57688]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-4-6 44768]
R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [2009-7-13 20992]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\skype\toolbars\skype c2c service\c2c_service.exe [2012-12-13 3290896]
R2 WTabletServiceCon;Wacom Consumer Service;c:\program files\tablet\pen\WTabletServiceCon.exe [2012-12-24 526208]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-9-28 315392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 FreemakeVideoCapture;FreemakeVideoCapture;c:\program files\freemake\capturelib\CaptureLibService.exe [2011-11-27 8704]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-11-9 160944]
S3 apf003;apf003;c:\windows\system32\apf003.sys [2012-5-13 13232]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 hidkmdf;KMDF Driver;c:\windows\system32\drivers\hidkmdf.sys [2012-12-24 11680]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-10-26 15872]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-10-26 52224]
S3 WacHidRouter;Wacom Hid Router;c:\windows\system32\drivers\wachidrouter.sys [2012-12-24 69024]
S3 wacomrouterfilter;Wacom Router Filter Driver;c:\windows\system32\drivers\wacomrouterfilter.sys [2012-12-24 13728]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-11-10 1343400]
S3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files\razer\razer game booster\driver\WinRing0.sys [2012-11-13 14416]
S4 atashost;WebEx Service Host for Support Center;c:\windows\system32\atashost.exe [2012-1-25 133944]
.
=============== Created Last 30 ================
.
2013-01-14 22:47:25--------d-----w-c:\users\josh\appdata\roaming\Malwarebytes
2013-01-14 22:46:29--------d-----w-c:\users\josh\appdata\local\Programs
2013-01-14 21:24:46--------d-----w-c:\users\josh\appdata\local\SecondLife
2013-01-14 21:23:55--------d-----w-c:\program files\SecondLifeViewer2
2013-01-14 06:08:07--------d-----w-c:\users\josh\appdata\roaming\Auslogics
2013-01-14 06:05:19--------d-----w-c:\program files\Portable
2013-01-14 02:52:09--------d-----w-c:\program files\Auslogics
2013-01-14 02:26:43--------d-----w-c:\program files\ESET
2013-01-13 22:24:08--------d-----w-c:\users\josh\appdata\roaming\enchant
2013-01-13 22:17:32--------d-----w-c:\users\josh\AbiSuite
2013-01-13 22:15:17--------d-----w-c:\program files\AbiWord
2013-01-13 05:08:46--------d-----w-c:\users\josh\appdata\roaming\DAEMON Tools Lite
2013-01-09 04:25:292345984----a-w-c:\windows\system32\win32k.sys
2013-01-09 04:25:051389568----a-w-c:\windows\system32\msxml6.dll
2013-01-09 04:24:53293376----a-w-c:\windows\system32\KernelBase.dll
2013-01-09 04:24:51271360----a-w-c:\windows\system32\conhost.exe
2013-01-09 04:24:51169984----a-w-c:\windows\system32\winsrv.dll
2013-01-09 04:24:18492032----a-w-c:\windows\system32\win32spl.dll
2013-01-09 04:24:15626688----a-w-c:\windows\system32\usp10.dll
2013-01-09 04:24:11220160----a-w-c:\windows\system32\ncrypt.dll
2013-01-09 04:24:0949152----a-w-c:\windows\system32\taskhost.exe
2013-01-09 02:25:50--------d-----w-c:\program files\common files\Steam
2013-01-09 02:25:46--------d-----w-c:\program files\Steam
2013-01-08 23:28:02--------d-----w-c:\program files\Super Meat Boy
2013-01-08 18:03:28--------d-----w-c:\users\josh\appdata\local\SKIDROW
2013-01-08 17:57:10452440----a-w-c:\windows\system32\d3dx10_40.dll
2013-01-08 17:57:102036576----a-w-c:\windows\system32\D3DCompiler_40.dll
2013-01-08 17:57:094379984----a-w-c:\windows\system32\D3DX9_40.dll
2013-01-08 14:52:16--------d-----w-c:\users\josh\.swt
2013-01-08 09:38:10--------d-----w-c:\users\josh\appdata\roaming\SUPERAntiSpyware.com
2013-01-08 09:37:42--------d-----w-c:\programdata\SUPERAntiSpyware.com
2013-01-08 09:37:42--------d-----w-c:\program files\SUPERAntiSpyware
2013-01-08 09:23:27--------d-----w-c:\users\josh\appdata\roaming\BitTorrent
2013-01-05 15:21:46--------d-----w-c:\users\josh\appdata\local\CyberLink
2013-01-05 15:21:05--------d-----w-c:\users\josh\appdata\local\CrashRpt
2013-01-05 15:20:45--------d-----w-c:\users\josh\appdata\local\Producer
2013-01-05 15:20:45--------d-----w-c:\program files\Livestream for Producers
2013-01-05 15:09:00--------d-----w-c:\users\josh\appdata\roaming\Livestream
2013-01-05 13:42:44--------d-----w-c:\users\josh\appdata\roaming\fltk.org
2013-01-05 13:42:44--------d-----w-c:\programdata\fltk.org
2013-01-05 13:32:27--------d-----w-c:\program files\Amnesia - The Dark Descent
2013-01-05 12:56:10--------d-----w-c:\program files\uTorrent
2013-01-05 12:55:17--------d-----w-c:\users\josh\appdata\roaming\uTorrent
2013-01-05 05:39:03--------d-----r-c:\users\josh\Dropbox
2013-01-05 05:36:20--------d-----w-c:\users\josh\appdata\roaming\Dropbox
2012-12-25 18:41:05295424----a-w-c:\windows\system32\atmfd.dll
2012-12-25 18:41:0434304----a-w-c:\windows\system32\atmlib.dll
2012-12-25 18:27:04--------d-----w-c:\users\josh\appdata\local\Apple Computer
2012-12-25 02:09:24--------d-----r-c:\program files\Skype
2012-12-24 21:47:09--------d-----w-c:\users\josh\appdata\roaming\SYSTEMAX Software Development
2012-12-24 21:40:54--------d-----w-c:\users\josh\appdata\roaming\WTablet
2012-12-24 21:40:52--------d-----w-c:\program files\TabletPlugins
2012-12-24 21:40:4869024----a-w-c:\windows\system32\drivers\wachidrouter.sys
2012-12-24 21:40:481461992----a-w-c:\windows\system32\wdfcoinstaller01009.dll
2012-12-24 21:40:4811680----a-w-c:\windows\system32\drivers\hidkmdf.sys
2012-12-24 21:40:381629056----a-w-c:\windows\system32\Pen_Tablet.dll
2012-12-24 21:40:381621888----a-w-c:\windows\system32\Pen_Touch_Tablet.dll
2012-12-24 21:40:381510272----a-w-c:\windows\system32\Wintab32.dll
2012-12-24 21:40:381506176----a-w-c:\windows\system32\WacomMT.dll
2012-12-24 21:40:36--------d-----w-c:\program files\Tablet
2012-12-24 21:31:49--------d-----w-c:\users\josh\appdata\local\join.me
2012-12-24 21:31:27--------d-----w-c:\users\josh\appdata\roaming\Wacom
2012-12-24 21:31:19--------d-----w-c:\programdata\Wacom
2012-12-24 21:30:50--------d-----w-c:\users\josh\appdata\local\Adobe
2012-12-24 21:30:38--------d-----w-c:\program files\Bamboo Dock
2012-12-24 21:24:4913728----a-w-c:\windows\system32\drivers\wacomrouterfilter.sys
2012-12-24 06:59:01--------d-----w-c:\users\josh\appdata\local\Razer
2012-12-24 02:27:32--------d-----w-c:\users\josh\appdata\local\PMB Files
2012-12-24 02:21:20--------d-----w-c:\users\josh\appdata\local\Google
2012-12-24 02:20:42--------d-----w-c:\users\josh\appdata\local\Apple
2012-12-24 02:19:25--------d-----w-c:\users\josh\appdata\local\Mozilla
2012-12-24 02:17:00--------d-----w-c:\users\josh\appdata\local\VirtualStore
2012-12-18 18:20:22376832----a-w-c:\windows\system32\dpnet.dll
2012-12-18 18:20:182048----a-w-c:\windows\system32\tzres.dll
.
==================== Find3M ====================
.
2013-01-13 05:22:1856320----a-w-c:\windows\system32\vsstrace.dll
2012-12-14 21:49:2821104----a-w-c:\windows\system32\drivers\mbam.sys
2012-12-12 03:51:1973656----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-12 03:51:19697272----a-w-c:\windows\system32\FlashPlayerApp.exe
2010-09-17 00:01:062608640----a-w-c:\program files\STEINSGATE.exe
.
============= FINISH: 18:15:12.53 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 5/24/2010 9:50:54 PM
System Uptime: 1/14/2013 6:08:34 PM (0 hours ago)
.
Motherboard: Wistron | | 30CD
Processor: Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz | U2E1 | 1833/667mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 233 GiB total, 61.293 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is CDROM ()
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP809: 1/14/2013 3:01:16 AM - Windows Update
RP811: 1/14/2013 4:24:33 AM - Windows Update
.
==== Installed Programs ======================
.
µTorrent
7-Zip 9.21
AbiWord 2.8.6
Adobe AIR
Adobe Download Assistant
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Amnesia - The Dark Descent
ƒOƒŠ[ƒtƒVƒ“ƒhƒ[ƒ€ Ver1.10
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
Auslogics Registry Cleaner
avast! Free Antivirus
Bamboo
Bamboo Dock
Bandisoft MPEG-1 Decoder
BitTorrent
Blacklight Retribution
Bonjour
CCleaner
Conexant HD Audio
CyberLink YouCam
D3DX10
DAEMON Tools Lite
Dark Eternal- Dissolution
Derpys Lamp
DivX Setup
Dragon Nest
Dropbox
DS4 Default Content
Elsword version 1.17
ESET Online Scanner v3
Facebook Video Calling 1.0.0.8714
Facebook Video Calling 1.2.0.287
File Shredder 2.0
Fraps (remove only)
Google Chrome
Google Update Helper
Grand Chase version 092412
HDAUDIO Soft Data Fax Modem with SmartCP
Intel(R) Graphics Media Accelerator Driver
Intel(R) TV Wizard
iTunes
Java Auto Updater
Java(TM) 6 Update 22
Java(TM) 6 Update 29
join.me
League of Legends
Lernout & Hauspie TruVoice American English TTS Engine
Livestream for Producers
Mabinogi
Malwarebytes Anti-Malware version 1.70.0.1100
MapleStory
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Mozilla Firefox 15.0.1 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
Nexon Game Manager
NVIDIA PhysX
OGPlanet Game Launcher
ooVoo
OpenOffice.org 3.3
Pando Media Booster
Portal 2
Project64 1.6
PunkBuster Services
QuickTime
Razer Game Booster
Rumble Fighter
RuneScape Launcher 1.0.4
Rusty Hearts
SecondLifeViewer (remove only)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Skype Click to Call
Skype™ 6.0
Steam
StepMania v5.0 alpha 1a (remove only)
STOnline
SUPERAntiSpyware
Trickster
TuneUp Companion 2.2.7
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
VC80CRTRedist - 8.0.50727.6195
Vindictus
Voobly Game Data
WebTablet FB Plugin 32 bit
WIDI Recognition System Pro 3.3 (remove only)
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Mobile Device Center
WinPcap 4.1.2
WinRAR 4.01 (32-bit)
.
==== End Of File ===========================