Jump to content

Malwarebytes

strange things going on

- - - - - hijacked

2 replies to this topic

#1
lepeiam69

    New Member

  • Members
  • Pip
  • 2 posts
I know things are being changed on my computer, please help me analyze this



.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Mel at 3:41:34 on 2012-02-26
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3561.1380 [GMT -8:00]
.
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\System32\atwtusb.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\atwtusb.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\IO3O LLC\Who Is On My Wifi\mywifi.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe
C:\ProgramData\Macrovision\FLEXnet Connect\11\ISUSPM.exe
C:\Program Files (x86)\MAGIX\Music_Maker_MX_Production_Suite_Download_Version\MusicMaker.exe
C:\Program Files (x86)\MAGIX\Music_Maker_MX_Production_Suite_Download_Version\Online\magixofa.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mel\Downloads\HijackThis (1).exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\RUBotted\RUBotSrv.exe
C:\Program Files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
BHO: SteadyVideoBHO Class: {6c680bae-655c-4e3d-8fc4-e6a520c3d928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
uRun: [ISUSPM] "C:\ProgramData\Macrovision\FLEXnet Connect\11\ISUSPM.exe" -scheduler
uRun: [HijackThis startup scan] C:\Users\Mel\Downloads\HijackThis.exe /startupscan
mRun: [HPQuickWebProxy] "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [Trend Micro RUBotted V2.0 Beta] C:\Program Files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AUTORU~1.LNK - C:\Windows\Installer\{33D427F9-FB5E-4E1A-A83E-E9E1E6B060AD}\_60ECD5E5FD618826B11700.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
TCP: DhcpNameServer = 192.168.15.1
TCP: Interfaces\{6D2453D7-B8E4-42CC-84A2-13CAA854231D} : DhcpNameServer = 20.20.1.1
TCP: Interfaces\{810E3034-92B0-479B-99D9-6B7C478B12F2} : DhcpNameServer = 192.168.15.1
TCP: Interfaces\{810E3034-92B0-479B-99D9-6B7C478B12F2}\075736B6 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{810E3034-92B0-479B-99D9-6B7C478B12F2}\34C6561627023507F64702435683 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{810E3034-92B0-479B-99D9-6B7C478B12F2}\36865656471686E6564777F627B6 : DhcpNameServer = 64.250.243.37 64.250.243.42
TCP: Interfaces\{810E3034-92B0-479B-99D9-6B7C478B12F2}\97E616D6569647 : DhcpNameServer = 192.168.15.1
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
mASetup: {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} - msiexec /fu {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} /qn
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
BHO-X64: Norton Identity Protection - No File
BHO-X64: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
BHO-X64: AMD SteadyVideo BHO - No File
BHO-X64: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.DLL
BHO-X64: Norton Vulnerability Protection - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
mRun-x64: [HPQuickWebProxy] "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
mRun-x64: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun-x64: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [Trend Micro RUBotted V2.0 Beta] C:\Program Files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe
IE-X64: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\Windows\system32\DRIVERS\amd_sata.sys --> C:\Windows\system32\DRIVERS\amd_sata.sys [?]
R0 amd_xata;amd_xata;C:\Windows\system32\DRIVERS\amd_xata.sys --> C:\Windows\system32\DRIVERS\amd_xata.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-9-28 361984]
R2 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-7-20 249648]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-9 86072]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-9-12 227896]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-7-11 26680]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-1-8 2413056]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-2-22 652360]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccsvchst.exe [2012-2-7 138248]
R2 RUBotSrv;Trend Micro RUBotted Service;C:\Program Files (x86)\Trend Micro\RUBotted\RUBotSrv.exe [2012-2-26 439632]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]
R2 WTService;WTService;C:\Windows\System32\atwtusb.exe -s --> C:\Windows\System32\atwtusb.exe -s [?]
R3 amdiox64;AMD IO Driver;C:\Windows\system32\DRIVERS\amdiox64.sys --> C:\Windows\system32\DRIVERS\amdiox64.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120215.001\BHDrvx64.sys [2012-2-18 1157240]
R3 ccSet_NIS;Norton Internet Security Settings Manager;C:\Windows\system32\drivers\NISx64\1305000.091\ccSetx64.sys --> C:\Windows\system32\drivers\NISx64\1305000.091\ccSetx64.sys [?]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\system32\DRIVERS\clwvd.sys --> C:\Windows\system32\DRIVERS\clwvd.sys [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-2-4 138360]
R3 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120224.002\IDSviA64.sys [2012-2-24 488568]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\system32\DRIVERS\RtsPStor.sys --> C:\Windows\system32\DRIVERS\RtsPStor.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\Windows\system32\DRIVERS\rtl8192Ce.sys --> C:\Windows\system32\DRIVERS\rtl8192Ce.sys [?]
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --> C:\Windows\system32\DRIVERS\Sftfslh.sys [?]
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --> C:\Windows\system32\DRIVERS\Sftvollh.sys [?]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]
R3 SymDS;Symantec Data Store;C:\Windows\system32\drivers\NISx64\1305000.091\SYMDS64.SYS --> C:\Windows\system32\drivers\NISx64\1305000.091\SYMDS64.SYS [?]
R3 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\NISx64\1305000.091\SYMEFA64.SYS --> C:\Windows\system32\drivers\NISx64\1305000.091\SYMEFA64.SYS [?]
R3 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\NISx64\1305000.091\Ironx64.SYS --> C:\Windows\system32\drivers\NISx64\1305000.091\Ironx64.SYS [?]
R3 SymNetS;Symantec Network Security WFP Driver;C:\Windows\system32\Drivers\NISx64\1305000.091\SYMNETS.SYS --> C:\Windows\system32\Drivers\NISx64\1305000.091\SYMNETS.SYS [?]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys --> C:\Windows\system32\DRIVERS\usbfilter.sys [?]
S2 Fabs;FABS - Helping agent for MAGIX media database;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe /DisableUI --> C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [?]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;C:\Windows\system32\Drivers\ssadadb.sys --> C:\Windows\system32\Drivers\ssadadb.sys [?]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-8-1 195320]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2011-4-26 2702848]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\system32\DRIVERS\ssadbus.sys --> C:\Windows\system32\DRIVERS\ssadbus.sys [?]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\system32\DRIVERS\ssadmdfl.sys --> C:\Windows\system32\DRIVERS\ssadmdfl.sys [?]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\system32\DRIVERS\ssadmdm.sys --> C:\Windows\system32\DRIVERS\ssadmdm.sys [?]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);C:\Windows\system32\DRIVERS\ssadserd.sys --> C:\Windows\system32\DRIVERS\ssadserd.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-02-26 11:33:04 -------- d-----w- C:\Program Files (x86)\WinPcap
2012-02-26 11:32:35 -------- d-----w- C:\Program Files (x86)\Trend Micro
2012-02-26 08:50:08 -------- d-----w- C:\Users\Mel\AppData\Roaming\Macrovision
2012-02-25 16:43:46 367104 ----a-w- C:\Windows\System32\CNC360L.dll
2012-02-25 16:43:46 315392 ----a-w- C:\Windows\SysWow64\CNC360L.dll
2012-02-25 16:43:46 17920 ----a-w- C:\Windows\System32\CNHMCA6.dll
2012-02-25 16:43:46 15872 ----a-w- C:\Windows\SysWow64\CNHMCA.dll
2012-02-25 16:43:46 1368064 ----a-w- C:\Windows\System32\CNC360C.dll
2012-02-25 16:43:46 112128 ----a-w- C:\Windows\System32\CNC360I.dll
2012-02-25 16:43:46 106496 ----a-w- C:\Windows\SysWow64\CNC360U.dll
2012-02-25 16:43:40 -------- d--h--w- C:\ProgramData\CanonIJFAX
2012-02-25 16:43:35 302080 ----a-w- C:\Windows\System32\CNCALAK.DLL
2012-02-25 16:42:42 -------- d-----w- C:\Users\Mel\AppData\Local\MediaMonkey
2012-02-25 16:42:24 -------- d-----w- C:\Users\Mel\AppData\Roaming\MediaMonkey
2012-02-25 16:42:11 -------- d-----w- C:\ProgramData\MediaMonkey
2012-02-25 16:42:01 -------- d-----w- C:\Program Files (x86)\MediaMonkey
2012-02-25 16:32:26 88576 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPPAK.DLL
2012-02-25 16:32:26 29696 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPDAK.DLL
2012-02-25 16:31:49 374784 ----a-w- C:\Windows\System32\CNMLMAK.DLL
2012-02-25 16:12:01 -------- d-----w- C:\Users\Mel\all beat
2012-02-25 16:09:15 -------- d-----w- C:\Users\Mel\AppData\Local\Windows Live
2012-02-25 16:09:15 -------- d-----w- C:\Users\Mel\AppData\Local\{50F760D7-CA11-4D36-A0FE-86DAE2A33CC6}
2012-02-25 16:09:03 -------- d-----w- C:\Users\Mel\AppData\Local\{5EFD042A-DAEF-46D0-A676-B0C2FB721C27}
2012-02-22 11:31:12 -------- d-----w- C:\Users\Mel\AppData\Roaming\Malwarebytes
2012-02-22 11:31:06 -------- d-----w- C:\ProgramData\Malwarebytes
2012-02-22 11:31:05 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-02-22 11:31:05 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-02-22 05:50:30 -------- d-----w- C:\Program Files (x86)\IO3O LLC
2012-02-21 23:22:54 43640 ----a-r- C:\Windows\System32\drivers\SymIMV.sys
2012-02-21 19:34:31 -------- d-----w- C:\Users\Mel\AppData\Local\ElevatedDiagnostics
2012-02-20 04:03:24 -------- d-----w- C:\Users\Mel\AppData\Roaming\NetMedia Providers
2012-02-20 03:06:07 -------- d-----w- C:\Users\Mel\AppData\Local\Sony
2012-02-20 02:58:13 -------- d-----w- C:\Program Files (x86)\Sony
2012-02-19 23:29:28 -------- d-----w- C:\temp
2012-02-19 22:56:46 -------- d-----w- C:\Program Files\CCleaner
2012-02-19 22:01:11 -------- d-----w- C:\Users\Mel\AppData\Roaming\Get from YouTube
2012-02-19 21:55:30 -------- d-----w- C:\Users\Mel\AppData\Roaming\Import Audio from Video
2012-02-19 11:27:44 -------- d-----w- C:\Program Files (x86)\NCH Swift Sound
2012-02-19 11:26:30 -------- d-----w- C:\Program Files (x86)\NCH Software
2012-02-19 11:26:26 -------- d-----w- C:\Users\Mel\AppData\Roaming\NCH Software
2012-02-19 11:17:55 -------- d-----w- C:\Program Files (x86)\K-Lite Codec Pack
2012-02-19 08:07:16 -------- d-----w- C:\Users\Mel\AppData\Roaming\Free Audio Editor
2012-02-19 07:46:52 602112 ----a-w- C:\Windows\SysWow64\NCTAudioTransform2.dll
2012-02-19 07:46:52 479232 ----a-w- C:\Windows\SysWow64\NCTAudioVisualization2.dll
2012-02-19 07:46:52 458752 ----a-w- C:\Windows\SysWow64\NCTAudioRecord2.dll
2012-02-19 07:46:52 458752 ----a-w- C:\Windows\SysWow64\NCTAudioPlayer2.dll
2012-02-19 07:46:52 417792 ----a-w- C:\Windows\SysWow64\NCTTextToAudio2.dll
2012-02-19 07:46:52 348160 ----a-w- C:\Windows\SysWow64\NCTWMAFile2.dll
2012-02-19 07:46:52 1986560 ----a-w- C:\Windows\SysWow64\NCTAudioFile2.dll
2012-02-19 07:46:52 1212416 ----a-w- C:\Windows\SysWow64\NCTAudioInformation2.dll
2012-02-19 07:46:51 880640 ----a-w- C:\Windows\SysWow64\NCTAudioEditor2.dll
2012-02-19 07:46:51 835584 ----a-w- C:\Windows\SysWow64\NCTAudioCDGrabber2.dll
2012-02-19 07:46:51 344064 ----a-w- C:\Windows\SysWow64\msvcr70.dll
2012-02-19 07:46:49 -------- d-----w- C:\Program Files (x86)\Free Audio Editor
2012-02-18 15:37:54 -------- d-----w- C:\Users\Mel\AppData\Roaming\DigitalDJ17
2012-02-18 15:37:46 -------- d-----w- C:\Users\Mel\AppData\Roaming\SongManager
2012-02-18 15:37:32 -------- d-----w- C:\Program Files (x86)\ASIO4ALL v2
2012-02-18 14:40:53 509952 ----a-w- C:\Windows\System32\ntshrui.dll
2012-02-18 14:40:53 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
2012-02-18 14:40:21 515584 ----a-w- C:\Windows\System32\timedate.cpl
2012-02-18 14:40:20 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl
2012-02-18 14:39:16 498688 ----a-w- C:\Windows\System32\drivers\afd.sys
2012-02-18 14:39:13 3145728 ----a-w- C:\Windows\System32\win32k.sys
2012-02-18 14:39:05 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll
2012-02-18 14:39:05 634880 ----a-w- C:\Windows\System32\msvcrt.dll
2012-02-17 07:57:19 -------- d-----w- C:\Users\Mel\AppData\Local\Mozilla
2012-02-17 06:18:20 -------- d-----w- C:\Users\Mel\AppData\Local\{E994AFBE-EFFB-400D-AB57-73CA87AF7319}
2012-02-17 04:28:17 -------- d-----w- C:\ProgramData\PopCap Games
2012-02-17 02:23:25 -------- d-----w- C:\Users\Mel\AppData\Local\{C872B5EF-5C0D-49CD-B892-1509A7CF1418}
2012-02-17 02:23:25 -------- d-----w- C:\Users\Mel\AppData\Local\{4F83C0B4-0A47-44F5-908A-B04342A5E181}
2012-02-11 20:28:04 -------- d-----w- C:\Users\Mel\AppData\Local\CrashDumps
2012-02-11 19:22:26 -------- d-----w- C:\Users\Mel\AppData\Roaming\SynthMaker
2012-02-11 19:22:14 -------- d-----w- C:\Users\Mel\AppData\Roaming\Acoustica
2012-02-11 07:37:04 -------- d-----w- C:\ProgramData\VirtualizedApplications
2012-02-10 07:03:47 -------- d-----w- C:\Users\Mel\AppData\Roaming\SoftGrid Client
2012-02-10 07:03:47 -------- d-----w- C:\Users\Mel\AppData\Local\SoftGrid Client
2012-02-09 22:36:54 -------- d-----w- C:\Users\Mel\AppData\Roaming\com.adobe.example.DubTurbo2.2C5EA5ABC1DEB308D2835FE19E22900BCCA96951.1
2012-02-09 22:35:21 -------- d-----w- C:\Program Files (x86)\DubTurbo2
2012-02-08 19:53:58 -------- d-----w- C:\Users\Mel\AppData\Roaming\Windows Live Writer
2012-02-08 19:53:58 -------- d-----w- C:\Users\Mel\AppData\Local\Windows Live Writer
2012-02-08 10:50:05 -------- d-----w- C:\Program Files (x86)\Microsoft Application Virtualization Client
2012-02-08 10:49:43 -------- d-----w- C:\Users\Mel\AppData\Roaming\TP
2012-02-08 09:16:39 -------- d-----w- C:\Windows\Msagent
2012-02-08 03:23:45 738936 ----a-w- C:\Windows\System32\drivers\NISx64\1305000.091\srtsp64.sys
2012-02-08 03:23:45 451192 ----a-r- C:\Windows\System32\drivers\NISx64\1305000.091\symds64.sys
2012-02-08 03:23:45 405624 ----a-w- C:\Windows\System32\drivers\NISx64\1305000.091\symnets.sys
2012-02-08 03:23:45 37496 ----a-w- C:\Windows\System32\drivers\NISx64\1305000.091\srtspx64.sys
2012-02-08 03:23:45 190072 ----a-w- C:\Windows\System32\drivers\NISx64\1305000.091\ironx64.sys
2012-02-08 03:23:45 167048 ----a-w- C:\Windows\System32\drivers\NISx64\1305000.091\ccsetx64.sys
2012-02-08 03:23:45 1092728 ----a-w- C:\Windows\System32\drivers\NISx64\1305000.091\symefa64.sys
2012-02-08 03:23:29 -------- d-----w- C:\Windows\System32\drivers\NISx64\1305000.091
2012-02-06 04:11:56 -------- d-----w- C:\Users\Mel\AppData\Roaming\Artweaver
2012-02-06 04:00:11 -------- d-----w- C:\Users\Mel\AppData\Local\PDF Annotator
2012-02-06 04:00:01 -------- d-----w- C:\Program Files (x86)\PDF Annotator
2012-02-06 03:59:20 -------- d-----w- C:\Program Files (x86)\Power Presenter RE II
2012-02-06 03:57:28 -------- d-----w- C:\ProgramData\Artweaver
2012-02-06 03:57:28 -------- d-----w- C:\Program Files (x86)\Artweaver 1.0
2012-02-06 03:55:12 7680 ----a-w- C:\Windows\System32\drivers\moufiltr.sys
2012-02-06 03:54:55 7808 ----a-w- C:\Windows\System32\drivers\walvhid.sys
2012-02-06 03:54:53 -------- d-----w- C:\Windows\vhid
2012-02-06 03:54:39 -------- d-----w- C:\Windows\udtablet
2012-02-06 03:54:14 -------- d-----w- C:\Windows\calib_da
2012-02-06 03:54:14 -------- d-----w- C:\ProgramData\Tablet
2012-02-05 16:54:42 1347344 ----a-w- C:\Windows\SysWow64\msvbvm50.dll
2012-02-05 16:10:58 -------- d-----w- C:\Program Files (x86)\Acoustica Shared Effects
2012-02-05 16:10:50 -------- d-----w- C:\Program Files (x86)\Acoustica Beatcraft
2012-02-05 16:05:02 -------- d-----w- C:\ProgramData\Acoustica
2012-02-05 14:44:41 -------- d-----w- C:\Program Files (x86)\uTorrent
2012-02-05 14:39:38 -------- d-----w- C:\Users\Mel\AppData\Roaming\uTorrent
2012-02-04 11:56:50 -------- d-----w- C:\Windows\SysWow64\Wat
2012-02-04 11:56:50 -------- d-----w- C:\Windows\System32\Wat
2012-02-04 11:32:40 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2012-02-04 08:03:50 -------- d-----w- C:\Users\Mel\AppData\Local\Diagnostics
2012-02-04 07:11:43 -------- d-----w- C:\Users\Mel\AppData\Roaming\Zya
2012-02-04 07:11:01 -------- d-----w- C:\Users\Mel\AppData\Local\Google
2012-02-04 06:52:16 -------- d-----w- C:\Users\Mel\AppData\Local\Music Mastermind
2012-02-04 06:52:04 -------- d-----w- C:\ProgramData\Zya
2012-02-04 06:52:04 -------- d-----w- C:\Program Files (x86)\Zya
2012-02-04 05:09:29 -------- d-----w- C:\Users\Mel\AppData\Roaming\MAGIX
2012-02-04 05:07:42 -------- d-----w- C:\Program Files (x86)\MAGIX
2012-02-04 05:07:17 -------- d-----w- C:\ProgramData\MAGIX
2012-02-04 05:07:14 -------- d-----w- C:\Program Files (x86)\Common Files\MAGIX Services
2012-02-04 04:57:12 -------- d-----w- C:\Users\Mel\AppData\Roaming\REAPER
2012-02-04 04:56:31 -------- d-----w- C:\Program Files\Common Files\Propellerhead Software
2012-02-04 04:56:23 -------- d-----w- C:\Program Files\REAPER (x64)
2012-02-04 01:30:55 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2012-02-03 17:50:42 -------- d-----w- C:\Users\Mel\AppData\Local\Apple Computer
2012-02-03 17:50:10 34152 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-02-03 17:50:10 126312 ----a-w- C:\Windows\System32\GEARAspi64.dll
2012-02-03 17:50:10 107368 ----a-w- C:\Windows\SysWow64\GEARAspi.dll
2012-02-03 17:49:48 -------- d-----w- C:\Program Files\iPod
2012-02-03 17:49:47 -------- d-----w- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2012-02-03 17:49:47 -------- d-----w- C:\Program Files\iTunes
2012-02-03 17:49:47 -------- d-----w- C:\Program Files (x86)\iTunes
2012-02-03 17:48:40 -------- d-----w- C:\Users\Mel\AppData\Local\Apple
2012-02-03 17:47:46 -------- d-----w- C:\Program Files\Bonjour
2012-02-03 17:47:46 -------- d-----w- C:\Program Files (x86)\Bonjour
2012-02-03 17:47:02 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2012-02-03 17:47:02 366592 ----a-w- C:\Windows\System32\qdvd.dll
2012-02-03 17:47:02 1572864 ----a-w- C:\Windows\System32\quartz.dll
2012-02-03 17:47:02 1328128 ----a-w- C:\Windows\SysWow64\quartz.dll
2012-02-03 17:44:49 1923952 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-02-03 17:07:32 886784 ----a-w- C:\Program Files\Common Files\System\wab32.dll
2012-02-03 17:07:32 708608 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2012-02-03 17:07:27 142336 ----a-w- C:\Windows\System32\poqexec.exe
2012-02-03 17:07:27 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2012-02-03 16:58:41 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2012-02-03 16:47:09 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2012-02-03 16:47:09 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2012-02-03 16:38:49 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2012-02-03 16:38:49 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2012-02-03 16:38:49 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2012-02-03 16:38:48 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2012-02-03 16:26:14 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2012-02-03 16:26:14 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2012-02-03 16:26:14 331776 ----a-w- C:\Windows\System32\oleacc.dll
2012-02-03 16:26:14 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2012-02-03 16:26:12 723456 ----a-w- C:\Windows\System32\EncDec.dll
2012-02-03 16:26:12 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2012-02-03 16:25:02 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-02-03 16:25:02 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-02-03 16:24:34 1731920 ----a-w- C:\Windows\System32\ntdll.dll
2012-02-03 16:24:34 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
2012-02-03 16:24:19 77312 ----a-w- C:\Windows\System32\packager.dll
2012-02-03 16:24:19 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2012-02-02 06:41:57 -------- d-----w- C:\Users\Mel\AppData\Local\Adobe
2012-02-02 06:29:32 -------- d-----w- C:\Users\Mel\AppData\Roaming\Hoyle FaceCreator
2012-02-02 06:29:32 -------- d-----w- C:\Users\Mel\AppData\Roaming\Hoyle Card Games
2012-02-01 21:20:40 -------- d-----w- C:\Users\Mel\AppData\Local\AMD
2012-02-01 21:20:31 -------- d-----w- C:\Users\Mel\AppData\Local\ATI
2012-02-01 21:19:26 -------- d-----w- C:\Users\Mel\AppData\Roaming\Synaptics
2012-02-01 21:14:51 -------- d-----w- C:\Users\Mel\AppData\Roaming\hpqlog
2012-02-01 21:14:49 -------- d-----w- C:\Users\Mel\AppData\Local\Hewlett-Packard
2012-02-01 21:13:56 -------- d-----w- C:\Users\Mel\AppData\Local\RemEngine
2012-02-01 21:13:51 -------- d-----w- C:\Users\Mel\AppData\Local\Hewlett-Packard_Company
2012-02-01 21:12:37 -------- d-----w- C:\Users\Mel\AppData\Local\VirtualStore
.
==================== Find3M ====================
.
2012-02-22 10:42:39 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-08 03:24:51 175736 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2012-01-08 13:58:27 0 ----a-w- C:\Windows\ativpsrm.bin
2011-12-14 07:11:03 2308096 ----a-w- C:\Windows\System32\jscript9.dll
2011-12-14 07:04:30 1390080 ----a-w- C:\Windows\System32\wininet.dll
2011-12-14 07:03:38 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl
2011-12-14 06:57:28 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-12-14 03:04:54 1798656 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-12-14 02:57:18 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-12-14 02:56:58 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2011-12-14 02:50:04 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
.
============= FINISH: 3:42:30.06 ===============

Attached Files



#2
LDTate

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 20,118 posts
  • Gender:Male
  • Location:Missouri, USA
Posted Image

Logs will be closed if you haven't replied within 3 days


Please don't attach the scans / logs for these tools, use "copy/paste".


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Please run a new MBAM scan being sure to update before scanning.

Post the scan results

Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
Larry Tate
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
LDTate

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 20,118 posts
  • Gender:Male
  • Location:Missouri, USA
Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!
Larry Tate
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us