Jump to content

"lsm.exe" uses 50% CPU when running


Recommended Posts

Hello!

Im having trouble with my computer: Sometimes a process called "lsm.exe" (With "L", not "capital i") runs all alone. When this happens, the CPU usage goes skyrocket and the temperatures of my components do th same. After forcing it to finish, everything goes back to normal. Sometimes it appears with another names, but the effects are exactly the same. "-12361234.exe" is one of the names. (Notice that the actual name is not this one, is just some numbers with a "-").

Thanks for your time and help!

Here are the logs:
 

DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 10.0.9200.16686  BrowserJavaVersion: 10.25.2
Run by Xalo at 17:01:42 on 2013-09-26
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.34.3082.18.8153.4719 [GMT 2:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\Java\jre7\bin\javaw.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Gaming Mouse\Monitor.EXE
C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Gaming Mouse\OSD.exe
C:\Program Files (x86)\Gaming Mouse\Applets\CpuRam.exe
C:\Program Files (x86)\Gaming Mouse\Applets\EmailPOP3.EXE
C:\Program Files (x86)\Gaming Mouse\Applets\OSDSkype.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Gaming Mouse\Applets\OSDMSN.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe,
BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [LocalSessionManager] "C:\Users\Xalo\AppData\Roaming\lsm.exe"
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [sysXboot] "C:\Program Files\Java\jre7\bin\javaw.exe" -jar "C:\Users\Xalo\AppData\Local\Temp\sysXboot7798110488473582857.jar"
mRun: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Gaming Mouse Driver] "C:\Program Files (x86)\Gaming Mouse\Monitor.EXE"
mRun: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\GIGABY~1.LNK - C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 87.216.1.65 87.216.1.66
TCP: Interfaces\{61365D26-C58D-4EC2-97FC-6A043E5A01A1} : DHCPNameServer = 87.216.1.65 87.216.1.66
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-Run: [Nvtmru] "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Xalo\AppData\Roaming\Mozilla\Firefox\Profiles\tjfjxfqy.default\
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
P2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2013-9-10 9216]
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2013-8-7 82560]
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2013-8-7 42624]
R1 AppleCharger;AppleCharger;C:\Windows\System32\drivers\AppleCharger.sys [2013-8-7 22680]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2013-8-31 283064]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-8-6 361984]
R2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-3-5 53888]
R2 NvStreamSvc;NVIDIA Streamer Service;C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-8-11 14997280]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-9-12 414496]
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2013-8-7 46136]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\Windows\System32\drivers\nvvad64v.sys [2013-9-19 39200]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2013-8-7 565352]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2013-8-7 56448]
S2 BrowserDefendert;BrowserDefendert;C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe --> C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2013-8-29 137336]
S3 GPCIDrv;GPCIDrv;C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [2010-2-4 14376]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-8-10 19456]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\System32\drivers\Synth3dVsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\System32\drivers\terminpt.sys [2013-8-10 29696]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-8-10 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-8-10 30208]
S3 tsusbhub;tsusbhub;C:\Windows\System32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 WatAdminSvc;Servicio de tecnologías de activación de Windows;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-8-7 1255736]
S3 WinRing0_1_2_0;WinRing0_1_2_0;C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [2013-8-10 14544]
.
=============== Created Last 30 ================
.
2013-09-26 14:44:37 76232 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{847E4F5C-F4E9-46B3-977E-1EA2675528E3}\offreg.dll
2013-09-26 14:10:02 -------- d-----w- C:\Users\Xalo\AppData\Local\Mozilla
2013-09-25 16:31:47 1065984 ----a-w- C:\Users\Xalo\AppData\Roaming\lsm.exe
2013-09-25 14:50:01 9694160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{847E4F5C-F4E9-46B3-977E-1EA2675528E3}\mpengine.dll
2013-09-22 01:07:08 -------- d-----w- C:\Users\Xalo\AppData\Roaming\Tropico 4
2013-09-22 00:36:31 -------- d-----w- C:\Users\Xalo\AppData\Roaming\Kalypso Media
2013-09-22 00:31:38 -------- d-----w- C:\Program Files (x86)\Kalypso Media
2013-09-19 15:33:38 -------- d-----w- C:\Users\Xalo\AppData\Local\WinZip
2013-09-19 15:17:31 39200 ----a-w- C:\Windows\System32\drivers\nvvad64v.sys
2013-09-19 15:17:31 28448 ----a-w- C:\Windows\SysWow64\nvaudcap32v.dll
2013-09-15 20:42:34 -------- d-----w- C:\Users\Xalo\AppData\Roaming\OpenOffice.org
2013-09-15 20:40:56 -------- d-----w- C:\Program Files (x86)\OpenOffice.org 3
2013-09-15 20:23:00 -------- d-----w- C:\Users\Xalo\AppData\Local\Adobe
2013-09-15 16:00:37 -------- d-----w- C:\Users\Xalo\AppData\Local\Gas Powered Games
2013-09-15 15:52:20 -------- d--h--w- C:\Windows\msdownld.tmp
2013-09-15 15:52:18 -------- d-----w- C:\Windows\SysWow64\directx
2013-09-15 15:50:33 -------- d-----w- C:\Program Files (x86)\Supreme Commander 2
2013-09-15 08:28:20 -------- d-----w- C:\ProgramData\Rockstar Games
2013-09-15 08:28:20 -------- d-----w- C:\Program Files (x86)\Rockstar Games
2013-09-15 07:42:39 -------- d-----w- C:\Program Files (x86)\Nordic Games
2013-09-12 21:35:40 3968960 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-09-11 23:17:50 571168 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2013-09-10 12:52:36 -------- d-----w- C:\Users\Xalo\AppData\Roaming\SPORE
2013-09-10 11:23:22 -------- d-----w- C:\ProgramData\Steam
2013-09-10 10:31:45 -------- d-----w- C:\Program Files (x86)\Company of Heroes 2
2013-09-10 09:09:30 -------- d-----w- C:\Program Files (x86)\dlc
2013-09-10 07:26:28 -------- d-----w- C:\Users\Xalo\AppData\Local\Chromium
2013-09-09 22:36:50 -------- d-----w- C:\Program Files (x86)\Microsoft Chart Controls
2013-09-09 22:35:07 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-09 22:32:59 -------- d-----w- C:\ProgramData\Hi-Rez Studios
2013-09-09 22:32:48 -------- d-----w- C:\Program Files (x86)\Hi-Rez Studios
2013-09-09 21:57:38 -------- d-----w- C:\Program Files (x86)\Lavalys
2013-09-09 21:57:18 -------- d-----w- C:\ProgramData\DSearchLink
2013-09-09 17:02:36 25640 ----a-w- C:\Windows\gdrv.sys
2013-09-09 16:42:42 -------- d-----w- C:\Program Files\CPUID
2013-09-04 13:31:38 -------- d-----w- C:\Users\Xalo\AppData\Local\ElevatedDiagnostics
2013-09-03 23:17:49 -------- d-----w- C:\Users\Xalo\AppData\Local\FLT
2013-09-03 22:54:33 -------- d-----w- C:\Program Files (x86)\XCOM Enemy Unknown
2013-09-03 13:56:58 503808 ----a-w- C:\Windows\SysWow64\MSVCP71.dll
2013-09-03 13:56:58 40960 ----a-r- C:\Windows\SysWow64\psfind.dll
2013-09-03 13:56:58 1060864 ----a-w- C:\Windows\SysWow64\mfc71.dll
2013-09-03 13:54:10 -------- d-----w- C:\Program Files (x86)\THQ
2013-09-01 20:40:27 -------- d-----w- C:\Users\Xalo\AppData\Local\Introversion
2013-08-31 08:41:24 283064 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys
2013-08-31 08:41:21 -------- d-----w- C:\Users\Xalo\AppData\Roaming\DAEMON Tools Lite
2013-08-31 08:41:20 -------- d-----w- C:\Program Files (x86)\DAEMON Tools Lite
2013-08-31 08:37:55 -------- d-----w- C:\ProgramData\DAEMON Tools Lite
2013-08-30 01:49:00 -------- d-----w- C:\ProgramData\UAB
2013-08-30 01:48:56 -------- d-----w- C:\Users\Xalo\AppData\Local\PC_Drivers_Headquarters
2013-08-30 01:46:32 -------- d-----w- C:\ProgramData\PC Drivers HeadQuarters
2013-08-30 01:44:56 -------- d-----w- C:\ProgramData\APN
2013-08-29 20:46:40 -------- d-----w- C:\Users\Xalo\AppData\Roaming\Natural Selection 2
2013-08-29 16:51:42 -------- d-----w- C:\Program Files (x86)\Bethesda Softworks
2013-08-29 02:02:43 -------- d-----w- C:\Users\Xalo\AppData\Local\Futuremark
2013-08-29 02:02:40 -------- d-----w- C:\Users\Xalo\AppData\Local\IsolatedStorage
2013-08-29 02:01:45 -------- d-----w- C:\Program Files (x86)\Futuremark
2013-08-29 02:00:53 -------- d-----w- C:\Program Files\Futuremark
2013-08-29 01:06:07 -------- d-----w- C:\Program Files (x86)\Gone Home
.
==================== Find3M  ====================
.
2013-09-19 14:37:10 281688 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2013-09-19 14:37:10 281688 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2013-09-18 17:20:33 281688 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2013-09-12 07:25:43 6599968 ----a-w- C:\Windows\System32\nvcpl.dll
2013-09-12 07:25:43 3452192 ----a-w- C:\Windows\System32\nvsvc64.dll
2013-09-12 07:25:40 920864 ----a-w- C:\Windows\System32\nvvsvc.exe
2013-09-12 07:25:40 63776 ----a-w- C:\Windows\System32\nvshext.dll
2013-09-12 07:25:40 2559776 ----a-w- C:\Windows\System32\nvsvcr.dll
2013-09-12 07:25:40 219424 ----a-w- C:\Windows\System32\nvmctray.dll
2013-09-11 22:06:31 3361114 ----a-w- C:\Windows\System32\nvcoproc.bin
2013-08-20 13:32:58 29984 ----a-w- C:\Windows\System32\nvaudcap64v.dll
2013-08-11 08:51:21 76888 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2013-08-10 05:22:18 2241024 ----a-w- C:\Windows\System32\wininet.dll
2013-08-10 05:20:59 3959296 ----a-w- C:\Windows\System32\jscript9.dll
2013-08-10 05:20:55 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-08-10 05:20:55 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-08-10 03:59:10 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-08-10 03:58:09 2876928 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-08-10 03:58:06 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-08-10 03:58:06 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-08-10 03:17:38 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-08-10 03:07:50 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-08-10 02:27:59 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-08-10 02:17:19 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-08-08 19:16:02 108968 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2013-08-08 19:16:01 972712 ----a-w- C:\Windows\System32\deployJava1.dll
2013-08-08 19:16:01 1093032 ----a-w- C:\Windows\System32\npDeployJava1.dll
2013-08-08 01:20:43 3155456 ----a-w- C:\Windows\System32\win32k.sys
2013-08-07 02:22:02 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-08-07 00:43:22 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-08-07 00:43:21 867240 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-08-07 00:43:21 789416 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-08-07 00:30:07 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-02 02:23:53 5550528 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-08-02 02:15:44 1732032 ----a-w- C:\Windows\System32\ntdll.dll
2013-08-02 02:15:03 362496 ----a-w- C:\Windows\System32\wow64win.dll
2013-08-02 02:15:03 243712 ----a-w- C:\Windows\System32\wow64.dll
2013-08-02 02:15:03 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2013-08-02 02:14:57 215040 ----a-w- C:\Windows\System32\winsrv.dll
2013-08-02 02:14:11 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2013-08-02 02:13:34 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2013-08-02 01:59:30 3913664 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-08-02 01:51:23 1292192 ----a-w- C:\Windows\SysWow64\ntdll.dll
2013-08-02 01:50:42 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2013-08-02 01:50:42 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2013-08-02 01:09:17 338432 ----a-w- C:\Windows\System32\conhost.exe
2013-08-02 00:59:09 112640 ----a-w- C:\Windows\System32\smss.exe
2013-08-02 00:45:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2013-08-02 00:45:36 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2013-08-02 00:45:35 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2013-08-02 00:45:34 2048 ----a-w- C:\Windows\SysWow64\user.exe
2013-08-02 00:43:05 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2013-08-02 00:43:05 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 00:43:05 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 00:43:05 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2013-07-25 09:25:54 1888768 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2013-07-25 08:57:27 1620992 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58:42 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-07-19 01:41:01 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-07-09 05:52:52 224256 ----a-w- C:\Windows\System32\wintrust.dll
2013-07-09 05:51:16 1217024 ----a-w- C:\Windows\System32\rpcrt4.dll
2013-07-09 05:46:20 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-07-09 05:46:20 1472512 ----a-w- C:\Windows\System32\crypt32.dll
2013-07-09 05:46:20 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-07-09 04:52:33 663552 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2013-07-09 04:52:10 175104 ----a-w- C:\Windows\SysWow64\wintrust.dll
2013-07-09 04:46:31 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-07-09 04:46:31 1166848 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-07-09 04:46:31 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-07-06 06:03:53 1910208 ----a-w- C:\Windows\System32\drivers\tcpip.sys
.
============= FINISH: 17:01:50,81 ===============

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Ultimate 
Boot Device: \Device\HarddiskVolume1
Install Date: 07/08/2013 0:42:53
System Uptime: 26/09/2013 15:43:49 (2 hours ago)
.
Motherboard: Gigabyte Technology Co., Ltd. |  | 990XA-UD3
Processor: AMD FX-8150 Eight-Core Processor            | CPU 1 | 3600/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 500 GiB total, 70,544 GiB free.
D: is FIXED (NTFS) - 432 GiB total, 431,411 GiB free.
E: is CDROM ()
F: is CDROM (UDF)
G: is FIXED (NTFS) - 466 GiB total, 58,525 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: 
Description: Controladora de bus serie universal(USB)
Device ID: PCI\VEN_1B6F&DEV_7023&SUBSYS_50071458&REV_01\4&22A3F64&0&0050
Manufacturer: 
Name: Controladora de bus serie universal(USB)
PNP Device ID: PCI\VEN_1B6F&DEV_7023&SUBSYS_50071458&REV_01\4&22A3F64&0&0050
Service: 
.
Class GUID: 
Description: Controladora de bus serie universal(USB)
Device ID: PCI\VEN_1B6F&DEV_7023&SUBSYS_50071458&REV_01\4&37E5E774&0&0020
Manufacturer: 
Name: Controladora de bus serie universal(USB)
PNP Device ID: PCI\VEN_1B6F&DEV_7023&SUBSYS_50071458&REV_01\4&37E5E774&0&0020
Service: 
.
==== System Restore Points ===================
.
RP69: 19/09/2013 17:26:38 - Quitado WinZip 17.5
RP70: 19/09/2013 17:31:20 - Installed WinZip 17.0
RP71: 22/09/2013 2:32:32 - Se ha instalado DirectX
RP72: 22/09/2013 3:03:00 - Se ha instalado DirectX
RP73: 23/09/2013 2:58:52 - Windows Update
.
==== Installed Programs ======================
.
@BIOS
1.0 Repack By Mrpiano
3DMark
Actualización de NVIDIA 8.3.14
Adobe Flash Player 10 Plugin
Adobe Reader XI (11.0.04) - Español
AMD APP SDK Runtime
AMD Catalyst Install Manager
AMD Fuel
Call of Juarez Gunslinger © Ubisoft version 1
Catalyst Control Center
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-utility64
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Chivalry: Medieval Warfare
Company of Heroes 2
Company of Heroes Singleplayer Demo
Counter-Strike: Global Offensive
DAEMON Tools Lite
Dishonored
Dolby Home Theater v4
Dota 2
EVEREST Ultimate Edition v4.60
Far Cry 3
Fraps
Futuremark SystemInfo
Gaming Mouse Driver
Garry's Mod
GeForce Experience NvStream Client Components
GIGABYTE OC_GURU II
Gone Home 1.00
Google Chrome
Google Update Helper
Hi-Rez Studios Authenticate and Update Service
Hotline Miami
Java 7 Update 25
Java 7 Update 25 (64-bit)
Java Auto Updater
Java 6 Update 22
Left 4 Dead 2
Malwarebytes Anti-Malware versión 1.75.0.1300
Max Payne 3
Metro: Last Light
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
Mozilla Firefox 24.0 (x86 en-US)
Mozilla Maintenance Service
Natural Selection 2
NVIDIA Controlador de 3D Vision 327.23
NVIDIA Controlador de audio HD 1.3.26.4
NVIDIA Controlador de gráficos 327.23
NVIDIA Controlador de la controladora 3D Vision 326.01
NVIDIA GeForce Experience 1.6.1
NVIDIA Install Application
NVIDIA PhysX
NVIDIA Software del sistema PhysX 9.13.0725
NVIDIA Stereoscopic 3D Driver
NVIDIA Update Components
NVIDIA Virtual Audio 1.2.5
ON_OFF Charge B12.1025.1
OpenOffice.org 3.3
Painkiller Hell and Damnation
Panel de control de NVIDIA 327.23
Papers, Please
Prison Architect
PunkBuster Services
Razer Game Booster
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Reus 1.0
Rockstar Games Social Club
S.T.A.L.K.E.R. - Call of Pripyat
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
SHIELD Streaming
SpeedFan (remove only)
SPORE
Steam
Team Fortress 2
Titan Quest
Titan Quest Immortal Throne
Torchlight II
Tribes: Ascend
Tropico 4 1.00
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2836939)
Uplink
WinZip 17.0
XCOM: Enemy Unknown
Zip Opener Packages
.
==== Event Viewer Messages From Past Week ========
.
26/09/2013 17:01:00, Error: Service Control Manager [7000]  - El servicio BrowserDefendert no pudo iniciarse debido al siguiente error:  El sistema no puede encontrar el archivo especificado.
25/09/2013 7:13:55, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
25/09/2013 23:16:59, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
25/09/2013 18:06:12, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
25/09/2013 0:13:45, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
24/09/2013 15:04:49, Error: Service Control Manager [7009]  - Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio Steam Client Service.
24/09/2013 15:04:49, Error: Service Control Manager [7000]  - El servicio Steam Client Service no pudo iniciarse debido al siguiente error:  El servicio no respondió a tiempo a la solicitud de inicio o de control.
23/09/2013 3:25:50, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
23/09/2013 15:55:16, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
22/09/2013 4:10:40, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
21/09/2013 3:12:07, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
20/09/2013 6:58:30, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
20/09/2013 22:03:29, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
20/09/2013 16:07:28, Error: Service Control Manager [7001]  - El servicio Servicio de lista de redes depende del servicio Reconocimiento de ubicación de red, el cual no pudo iniciarse debido al siguiente error:  No se puede iniciar el servicio o grupo de dependencia.
20/09/2013 16:07:28, Error: Service Control Manager [7001]  - El servicio Servicio de lista de redes depende del servicio Reconocimiento de ubicación de red, el cual no pudo iniciarse debido al siguiente error:  No se puede iniciar el servicio o grupo de dependencia.
20/09/2013 16:07:28, Error: Service Control Manager [7001]  - El servicio Servicio de lista de redes depende del servicio Reconocimiento de ubicación de red, el cual no pudo iniciarse debido al siguiente error:  No se puede iniciar el servicio o grupo de dependencia.
20/09/2013 16:07:28, Error: Service Control Manager [7001]  - El servicio Servicio de lista de redes depende del servicio Reconocimiento de ubicación de red, el cual no pudo iniciarse debido al siguiente error:  No se puede iniciar el servicio o grupo de dependencia.
20/09/2013 16:07:28, Error: Service Control Manager [7001]  - El servicio Servicio de lista de redes depende del servicio Reconocimiento de ubicación de red, el cual no pudo iniciarse debido al siguiente error:  No se puede iniciar el servicio o grupo de dependencia.
20/09/2013 16:07:28, Error: Service Control Manager [7001]  - El servicio Servicio de lista de redes depende del servicio Reconocimiento de ubicación de red, el cual no pudo iniciarse debido al siguiente error:  No se puede iniciar el servicio o grupo de dependencia.
20/09/2013 16:07:28, Error: Microsoft-Windows-DistributedCOM [10005]  - Error de DCOM "1084" al intentar iniciar el servicio WSearch con argumentos "" para ejecutar el servidor: {9E175B6D-F52A-11D8-B9A5-505054503030}
20/09/2013 16:07:28, Error: Microsoft-Windows-DistributedCOM [10005]  - Error de DCOM "1084" al intentar iniciar el servicio WSearch con argumentos "" para ejecutar el servidor: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
20/09/2013 16:07:27, Error: Service Control Manager [7001]  - El servicio Servicio de lista de redes depende del servicio Reconocimiento de ubicación de red, el cual no pudo iniciarse debido al siguiente error:  No se puede iniciar el servicio o grupo de dependencia.
20/09/2013 16:07:27, Error: Service Control Manager [7001]  - El servicio Servicio de lista de redes depende del servicio Reconocimiento de ubicación de red, el cual no pudo iniciarse debido al siguiente error:  No se puede iniciar el servicio o grupo de dependencia.
20/09/2013 16:07:27, Error: Microsoft-Windows-DistributedCOM [10005]  - Error de DCOM "1068" al intentar iniciar el servicio netprofm con argumentos "" para ejecutar el servidor: {A47979D2-C419-11D9-A5B4-001185AD2B89}
20/09/2013 16:07:27, Error: Microsoft-Windows-DistributedCOM [10005]  - Error de DCOM "1068" al intentar iniciar el servicio netman con argumentos "" para ejecutar el servidor: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
20/09/2013 16:07:26, Error: Microsoft-Windows-DistributedCOM [10005]  - Error de DCOM "1084" al intentar iniciar el servicio EventSystem con argumentos "" para ejecutar el servidor: {1BE1F766-5536-11D1-B726-00C04FB926AF}
20/09/2013 16:07:20, Error: Microsoft-Windows-DistributedCOM [10005]  - Error de DCOM "1084" al intentar iniciar el servicio ShellHWDetection con argumentos "" para ejecutar el servidor: {DD522ACC-F821-461A-A407-50B198B896DC}
20/09/2013 16:07:10, Error: Service Control Manager [7026]  - El siguiente controlador de inicio del sistema o de inicio del arranque no se cargó correctamente:  AFD AppleCharger CSC DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr tdx Wanarpv6 WfpLwf
20/09/2013 16:07:10, Error: Service Control Manager [7001]  - El servicio Servicio Interfaz de almacenamiento en red depende del servicio NSI proxy service driver., el cual no pudo iniciarse debido al siguiente error:  Uno de los dispositivos conectados al sistema no funciona.
20/09/2013 16:07:10, Error: Service Control Manager [7001]  - El servicio Reconocimiento de ubicación de red depende del servicio Servicio Interfaz de almacenamiento en red, el cual no pudo iniciarse debido al siguiente error:  No se puede iniciar el servicio o grupo de dependencia.
20/09/2013 16:07:10, Error: Service Control Manager [7001]  - El servicio Minirredirector SMB 2.0 depende del servicio Contenedor y motor de minirredirector SMB, el cual no pudo iniciarse debido al siguiente error:  No se puede iniciar el servicio o grupo de dependencia.
20/09/2013 16:07:10, Error: Service Control Manager [7001]  - El servicio Minirredirector SMB 1.x depende del servicio Contenedor y motor de minirredirector SMB, el cual no pudo iniciarse debido al siguiente error:  No se puede iniciar el servicio o grupo de dependencia.
20/09/2013 16:07:10, Error: Service Control Manager [7001]  - El servicio Estación de trabajo depende del servicio Servicio Interfaz de almacenamiento en red, el cual no pudo iniciarse debido al siguiente error:  No se puede iniciar el servicio o grupo de dependencia.
20/09/2013 16:07:10, Error: Service Control Manager [7001]  - El servicio Contenedor y motor de minirredirector SMB depende del servicio Subsistema de almacenamiento en búfer redirigido, el cual no pudo iniciarse debido al siguiente error:  Uno de los dispositivos conectados al sistema no funciona.
20/09/2013 16:07:10, Error: Service Control Manager [7001]  - El servicio Cliente DNS depende del servicio Controlador de soporte TDI heredado NetIO, el cual no pudo iniciarse debido al siguiente error:  Uno de los dispositivos conectados al sistema no funciona.
20/09/2013 16:07:10, Error: Service Control Manager [7001]  - El servicio Cliente DHCP depende del servicio Ancillary Function Driver for Winsock, el cual no pudo iniciarse debido al siguiente error:  Uno de los dispositivos conectados al sistema no funciona.
20/09/2013 16:07:10, Error: Service Control Manager [7001]  - El servicio Aplicación auxiliar IP depende del servicio Servicio Interfaz de almacenamiento en red, el cual no pudo iniciarse debido al siguiente error:  No se puede iniciar el servicio o grupo de dependencia.
20/09/2013 16:07:10, Error: Service Control Manager [7001]  - El servicio Aplicación auxiliar de NetBIOS sobre TCP/IP depende del servicio Ancillary Function Driver for Winsock, el cual no pudo iniciarse debido al siguiente error:  Uno de los dispositivos conectados al sistema no funciona.
20/09/2013 16:06:13, Error: Service Control Manager [7023]  - El servicio Servidor se cerró con el siguiente error:  No se ha iniciado el servicio.
20/09/2013 16:06:13, Error: Service Control Manager [7023]  - El servicio Examinador de equipos se cerró con el siguiente error:  Se está cerrando el sistema.
20/09/2013 16:06:12, Error: Microsoft-Windows-Directory-Services-SAM [12291]  - SAM no ha podido iniciar el TCP/IP o el subproceso de escucha
20/09/2013 16:06:11, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
20/09/2013 16:05:20, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
20/09/2013 14:27:44, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
20/09/2013 14:21:34, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
19/09/2013 19:22:38, Error: Service Control Manager [7034]  - El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
.
==== End Of File ===========================
 

 

Link to post
Share on other sites

  • Staff

Hello InternetDude

I would like to welcome you to the Malware Removal section of the forum.

Around here they call me Gringo and I will be glad to help you with your malware problems.

Very Important --> Please read this post completely, I have spent my time to put together somethings for you to keep in mind while I am helping you to make things go easier, faster and smoother for both of us!

  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the "Follow This Topic" Button, make sure that the "Receive notification" box is checked and that it is set to "Instantly" - This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.

These are the programs I would like you to run next, if you have any problems with one of these just skip it and move on to the next one.

-AdwCleaner-

Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[s1].txt as well.
-Junkware-Removal-Tool-

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
When they are complete let me have the two reports and let me know how things are running.

Gringo

Link to post
Share on other sites

Done:
 

# AdwCleaner v3.005 - Reporte Creado 26/09/2013 en 17:25:42
# Actualizado 22/09/2013 por Xplode
# Sistema Operativo : Windows 7 Ultimate Service Pack 1 (64 bits)
# Nombre de usuario : Xalo - PC1337KILLER360
# Ejecutado desde : C:\Users\Xalo\Desktop\Anti malware tools\AdwCleaner.exe
# Opción : Limpiar
 
***** [ Servicios ] *****
 
[#] Servicio Borrar : BrowserDefendert
 
***** [ Archivos / Carpetas ] *****
 
Carpeta Borrar : C:\ProgramData\apn
Carpeta Borrar : C:\ProgramData\Babylon
Carpeta Borrar : C:\ProgramData\BrowserDefender
Carpeta Borrar : C:\ProgramData\DSearchLink
Carpeta Borrar : C:\ProgramData\eSafe
Carpeta Borrar : C:\Users\Xalo\AppData\Roaming\digitalsite
Carpeta Borrar : C:\Users\Xalo\AppData\Roaming\eIntaller
Carpeta Borrar : C:\Users\Xalo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
Archivo Borrar : C:\Windows\System32\Tasks\BrowserDefendert
 
***** [ Accesos directos ] *****
 
Acceso directo Desinfectado : C:\Users\Xalo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Acceso directo Desinfectado : C:\Users\Xalo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Acceso directo Desinfectado : C:\Users\Xalo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
 
***** [ Registro ] *****
 
Clave Borrar : HKLM\SOFTWARE\Classes\Prod.cap
Clave Borrar : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Clave Borrar : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Clave Borrar : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Clave Borrar : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Clave Borrar : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Clave Borrar : HKCU\Software\853db8fe73be817
Clave Borrar : HKLM\SOFTWARE\853db8fe73be817
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{0AFD55C8-ADF8-4A33-A6E1-DEDB7A36AEB4}
Clave Borrar : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Clave Borrar : HKCU\Software\dsiteproducts
Clave Borrar : HKCU\Software\Softonic
Clave Borrar : HKLM\Software\DataMngr
Clave Borrar : HKLM\Software\eSafeSecControl
Clave Borrar : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages
Clave Borrar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Clave Borrar : [x64] HKLM\SOFTWARE\Tarma Installer
 
***** [ Navegadores ] *****
 
-\\ Internet Explorer v10.0.9200.16686
 
 
-\\ Mozilla Firefox v24.0 (en-US)
 
[ Archivo : C:\Users\Xalo\AppData\Roaming\Mozilla\Firefox\Profiles\tjfjxfqy.default\prefs.js ]
 
 
-\\ Google Chrome v29.0.1547.76
 
[ Archivo : C:\Users\Xalo\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [4001 octets] - [26/09/2013 17:25:00]
AdwCleaner[s0].txt - [3235 octets] - [26/09/2013 17:25:42]
 
########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [3295 octets] ##########

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.2 (09.22.2013:1)
OS: Windows 7 Ultimate x64
Ran by Xalo on 26/09/2013 at 17:28:51,19
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4077817561-2542389710-4094447064-1000\Software\SweetIM
 
 
 
~~~ Files
 
Successfully deleted: [File] C:\Windows\Tasks\digitalsite.job
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] "C:\Users\Xalo\AppData\Roaming\zip opener packages"
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26/09/2013 at 17:33:17,94
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Link to post
Share on other sites

  • Staff

Hello InternetDude

I Would like you to do the following.

Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links. I want you to save it to the desktop and run it from there.

1. Close any open browsers or any other programs that are open.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.

When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?
Gringo
Link to post
Share on other sites

Damn, I made a mistake and didin't disabled Defender for AdwCleaner and JRT scans. I repeated both and here are the new logs. As you can see there is almost nothing new found, but I prefered to be safe.

 

# AdwCleaner v3.005 - Reporte Creado 26/09/2013 en 18:08:14
# Actualizado 22/09/2013 por Xplode
# Sistema Operativo : Windows 7 Ultimate Service Pack 1 (64 bits)
# Nombre de usuario : Xalo - PC1337KILLER360
# Ejecutado desde : C:\Users\Xalo\Desktop\AdwCleaner.exe
# Opción : Limpiar
 
***** [ Servicios ] *****
 
 
***** [ Archivos / Carpetas ] *****
 
 
***** [ Accesos directos ] *****
 
 
***** [ Registro ] *****
 
 
***** [ Navegadores ] *****
 
-\\ Internet Explorer v10.0.9200.16686
 
 
-\\ Mozilla Firefox v24.0 (en-US)
 
[ Archivo : C:\Users\Xalo\AppData\Roaming\Mozilla\Firefox\Profiles\tjfjxfqy.default\prefs.js ]
 
 
-\\ Google Chrome v29.0.1547.76
 
[ Archivo : C:\Users\Xalo\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [4001 octets] - [26/09/2013 17:25:00]
AdwCleaner[R1].txt - [1057 octets] - [26/09/2013 18:07:46]
AdwCleaner[s0].txt - [3383 octets] - [26/09/2013 17:25:42]
AdwCleaner[s1].txt - [978 octets] - [26/09/2013 18:08:14]
 
########## EOF - C:\AdwCleaner\AdwCleaner[s1].txt - [1037 octets] ##########



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.2 (09.22.2013:1)
OS: Windows 7 Ultimate x64
Ran by Xalo on 26/09/2013 at 18:10:16,79
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26/09/2013 at 18:14:36,90
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


ComboFix 13-09-26.03 - Xalo 26/09/2013  18:18:32.1.8 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.34.3082.18.8153.6630 [GMT 2:00]
Running from: c:\users\Xalo\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Xalo\AppData\Local\Microsoft\Windows\Temporary Internet Files\ApnStub.exe
c:\windows\SysWow64\frapsvid.dll
.
.
(((((((((((((((((((((((((   Files Created from 2013-08-26 to 2013-09-26  )))))))))))))))))))))))))))))))
.
.
2013-09-26 15:28 . 2013-09-26 15:28 -------- d-----w- c:\windows\ERUNT
2013-09-26 15:24 . 2013-09-26 16:08 -------- d-----w- C:\AdwCleaner
2013-09-26 14:10 . 2013-09-26 14:10 -------- d-----w- c:\users\Xalo\AppData\Local\Mozilla
2013-09-26 14:09 . 2013-09-26 14:09 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2013-09-25 14:50 . 2013-09-05 05:32 9694160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{847E4F5C-F4E9-46B3-977E-1EA2675528E3}\mpengine.dll
2013-09-22 01:07 . 2013-09-24 16:50 -------- d-----w- c:\users\Xalo\AppData\Roaming\Tropico 4
2013-09-22 00:36 . 2013-09-22 00:36 -------- d-----w- c:\users\Xalo\AppData\Roaming\Kalypso Media
2013-09-22 00:31 . 2013-09-22 01:01 -------- d-----w- c:\program files (x86)\Kalypso Media
2013-09-19 15:33 . 2013-09-19 15:33 -------- d-----w- c:\users\Xalo\AppData\Local\WinZip
2013-09-19 15:32 . 2013-09-19 15:34 -------- d-----w- c:\programdata\WinZip
2013-09-19 15:32 . 2013-09-19 15:32 -------- d-----w- c:\program files\WinZip
2013-09-19 15:30 . 2013-09-19 15:30 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-09-19 15:17 . 2013-08-20 13:33 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2013-09-19 15:17 . 2013-08-20 13:32 28448 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2013-09-15 20:42 . 2013-09-15 20:42 -------- d-----w- c:\users\Xalo\AppData\Roaming\OpenOffice.org
2013-09-15 20:40 . 2013-09-15 20:41 -------- d-----w- c:\program files (x86)\OpenOffice.org 3
2013-09-15 20:24 . 2013-09-15 20:24 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2013-09-15 20:23 . 2013-09-15 20:26 -------- d-----w- c:\users\Xalo\AppData\Local\Adobe
2013-09-15 16:00 . 2013-09-15 16:00 -------- d-----w- c:\users\Xalo\AppData\Local\Gas Powered Games
2013-09-15 15:52 . 2013-09-15 15:52 -------- d--h--w- c:\windows\msdownld.tmp
2013-09-15 15:50 . 2013-09-15 15:55 -------- d-----w- c:\program files (x86)\Supreme Commander 2
2013-09-15 08:28 . 2013-09-15 08:55 -------- d-----w- c:\program files (x86)\Rockstar Games
2013-09-15 08:28 . 2013-09-15 08:28 -------- d-----w- c:\programdata\Rockstar Games
2013-09-15 07:42 . 2013-09-15 07:42 -------- d-----w- c:\program files (x86)\Nordic Games
2013-09-12 21:35 . 2013-08-02 01:59 3968960 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-09-11 23:17 . 2013-09-11 23:17 571168 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-09-10 12:52 . 2013-09-10 12:52 -------- d-----w- c:\users\Xalo\AppData\Roaming\SPORE
2013-09-10 12:48 . 2013-09-10 12:48 -------- d-----w- c:\program files (x86)\Electronic Arts
2013-09-10 11:23 . 2013-09-10 11:23 -------- d-----w- c:\programdata\Steam
2013-09-10 10:31 . 2013-09-10 10:38 -------- d-----w- c:\program files (x86)\Company of Heroes 2
2013-09-10 09:09 . 2013-09-10 09:10 -------- d-----w- c:\program files (x86)\dlc
2013-09-10 07:26 . 2013-09-10 07:26 -------- d-----w- c:\users\Xalo\AppData\Local\Chromium
2013-09-09 22:36 . 2013-09-09 22:36 -------- d-----w- c:\program files (x86)\Microsoft Chart Controls
2013-09-09 22:35 . 2013-09-09 22:35 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-09 22:35 . 2013-09-09 22:35 -------- d-----w- c:\windows\SysWow64\Macromed
2013-09-09 22:32 . 2013-09-09 22:46 -------- d-----w- c:\programdata\Hi-Rez Studios
2013-09-09 22:32 . 2013-09-09 22:33 -------- d-----w- c:\program files (x86)\Hi-Rez Studios
2013-09-09 21:57 . 2013-09-09 21:57 -------- d-----w- c:\program files (x86)\Lavalys
2013-09-09 17:02 . 2013-09-09 17:17 25640 ----a-w- c:\windows\gdrv.sys
2013-09-09 16:42 . 2013-09-09 16:42 -------- d-----w- c:\program files\CPUID
2013-09-04 13:31 . 2013-09-04 13:31 -------- d-----w- c:\users\Xalo\AppData\Local\ElevatedDiagnostics
2013-09-03 23:17 . 2013-09-03 23:17 -------- d-----w- c:\users\Xalo\AppData\Local\FLT
2013-09-03 22:54 . 2013-09-03 22:54 -------- d-----w- c:\program files (x86)\XCOM Enemy Unknown
2013-09-03 13:56 . 2007-01-01 18:03 40960 ----a-r- c:\windows\SysWow64\psfind.dll
2013-09-03 13:56 . 2006-07-11 16:43 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll
2013-09-03 13:56 . 2006-07-11 16:35 503808 ----a-w- c:\windows\SysWow64\MSVCP71.dll
2013-09-03 13:54 . 2013-09-03 14:00 -------- d-----w- c:\program files (x86)\THQ
2013-09-01 20:40 . 2013-09-01 20:40 -------- d-----w- c:\users\Xalo\AppData\Local\Introversion
2013-08-31 08:41 . 2013-08-31 08:41 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-08-31 08:41 . 2013-09-03 13:48 -------- d-----w- c:\users\Xalo\AppData\Roaming\DAEMON Tools Lite
2013-08-31 08:41 . 2013-08-31 08:41 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2013-08-31 08:37 . 2013-08-31 08:42 -------- d-----w- c:\programdata\DAEMON Tools Lite
2013-08-30 01:49 . 2013-08-30 01:49 -------- d-----w- c:\programdata\UAB
2013-08-30 01:48 . 2013-08-30 01:48 -------- d-----w- c:\users\Xalo\AppData\Local\PC_Drivers_Headquarters
2013-08-30 01:46 . 2013-08-30 01:46 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2013-08-29 20:46 . 2013-08-30 15:27 -------- d-----w- c:\users\Xalo\AppData\Roaming\Natural Selection 2
2013-08-29 16:51 . 2013-08-29 16:51 -------- d-----w- c:\program files (x86)\Bethesda Softworks
2013-08-29 02:02 . 2013-08-29 02:02 -------- d-----w- c:\users\Xalo\AppData\Local\Futuremark
2013-08-29 02:02 . 2013-08-29 02:02 -------- d-----w- c:\users\Xalo\AppData\Local\IsolatedStorage
2013-08-29 02:01 . 2013-08-29 02:01 -------- d-----w- c:\program files (x86)\Futuremark
2013-08-29 02:00 . 2013-08-29 02:00 -------- d-----w- c:\program files\Futuremark
2013-08-29 01:06 . 2013-08-29 01:06 -------- d-----w- c:\program files (x86)\Gone Home
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-19 14:37 . 2013-08-11 08:51 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-09-19 14:37 . 2013-08-09 13:48 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-09-18 17:20 . 2013-08-09 13:44 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-09-13 01:01 . 2013-08-07 01:53 79143768 ----a-w- c:\windows\system32\MRT.exe
2013-09-12 08:58 . 2013-08-11 17:36 15703688 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-09-12 08:58 . 2013-08-11 17:14 1412832 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-09-12 08:58 . 2013-08-11 17:14 2630304 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-09-12 08:58 . 2013-08-11 17:14 12947360 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-09-12 08:58 . 2013-08-11 17:14 2986672 ----a-w- c:\windows\system32\nvapi64.dll
2013-09-12 08:58 . 2013-08-11 17:14 15901448 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-09-12 07:25 . 2013-08-11 17:16 6599968 ----a-w- c:\windows\system32\nvcpl.dll
2013-09-12 07:25 . 2013-08-11 17:16 3452192 ----a-w- c:\windows\system32\nvsvc64.dll
2013-09-12 07:25 . 2013-08-11 17:16 920864 ----a-w- c:\windows\system32\nvvsvc.exe
2013-09-12 07:25 . 2013-08-11 17:16 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-09-12 07:25 . 2013-08-11 17:16 2559776 ----a-w- c:\windows\system32\nvsvcr.dll
2013-09-12 07:25 . 2013-08-11 17:16 219424 ----a-w- c:\windows\system32\nvmctray.dll
2013-09-11 22:06 . 2013-08-11 17:16 3361114 ----a-w- c:\windows\system32\nvcoproc.bin
2013-08-20 13:32 . 2013-08-11 17:27 29984 ----a-w- c:\windows\system32\nvaudcap64v.dll
2013-08-11 08:51 . 2013-08-11 08:51 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-08-08 19:28 . 2013-08-08 19:28 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10144.bin
2013-08-08 19:16 . 2013-08-08 19:16 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-08-08 19:16 . 2013-08-08 19:16 972712 ----a-w- c:\windows\system32\deployJava1.dll
2013-08-08 19:16 . 2013-08-08 19:16 312232 ----a-w- c:\windows\system32\javaws.exe
2013-08-08 19:16 . 2013-08-08 19:16 1093032 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-08-08 19:16 . 2013-08-08 19:16 189352 ----a-w- c:\windows\system32\javaw.exe
2013-08-08 19:16 . 2013-08-08 19:16 188840 ----a-w- c:\windows\system32\java.exe
2013-08-07 02:22 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-08-07 00:43 . 2013-08-07 00:43 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-08-07 00:43 . 2013-08-07 00:43 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-08-07 00:43 . 2013-08-07 00:43 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-08-07 00:31 . 2013-08-07 00:31 97280 ----a-w- c:\windows\system32\mshtmled.dll
2013-08-07 00:31 . 2013-08-07 00:31 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-08-07 00:31 . 2013-08-07 00:31 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-08-07 00:31 . 2013-08-07 00:31 81408 ----a-w- c:\windows\system32\icardie.dll
2013-08-07 00:31 . 2013-08-07 00:31 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-08-07 00:31 . 2013-08-07 00:31 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2013-08-07 00:31 . 2013-08-07 00:31 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-08-07 00:31 . 2013-08-07 00:31 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-08-07 00:31 . 2013-08-07 00:31 62976 ----a-w- c:\windows\system32\pngfilt.dll
2013-08-07 00:31 . 2013-08-07 00:31 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-08-07 00:31 . 2013-08-07 00:31 599552 ----a-w- c:\windows\system32\vbscript.dll
2013-08-07 00:31 . 2013-08-07 00:31 523264 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-08-07 00:31 . 2013-08-07 00:31 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-08-07 00:31 . 2013-08-07 00:31 51200 ----a-w- c:\windows\system32\imgutil.dll
2013-08-07 00:31 . 2013-08-07 00:31 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-08-07 00:31 . 2013-08-07 00:31 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-08-07 00:31 . 2013-08-07 00:31 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2013-08-07 00:31 . 2013-08-07 00:31 441856 ----a-w- c:\windows\system32\html.iec
2013-08-07 00:31 . 2013-08-07 00:31 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-08-07 00:31 . 2013-08-07 00:31 361984 ----a-w- c:\windows\SysWow64\html.iec
2013-08-07 00:31 . 2013-08-07 00:31 281600 ----a-w- c:\windows\system32\dxtrans.dll
2013-08-07 00:31 . 2013-08-07 00:31 27648 ----a-w- c:\windows\system32\licmgr10.dll
2013-08-07 00:31 . 2013-08-07 00:31 270848 ----a-w- c:\windows\system32\iedkcs32.dll
2013-08-07 00:31 . 2013-08-07 00:31 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-08-07 00:31 . 2013-08-07 00:31 235008 ----a-w- c:\windows\system32\url.dll
2013-08-07 00:31 . 2013-08-07 00:31 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-08-07 00:31 . 2013-08-07 00:31 226304 ----a-w- c:\windows\system32\elshyph.dll
2013-08-07 00:31 . 2013-08-07 00:31 216064 ----a-w- c:\windows\system32\msls31.dll
2013-08-07 00:31 . 2013-08-07 00:31 197120 ----a-w- c:\windows\system32\msrating.dll
2013-08-07 00:31 . 2013-08-07 00:31 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-08-07 00:31 . 2013-08-07 00:31 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2013-08-07 00:31 . 2013-08-07 00:31 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-08-07 00:31 . 2013-08-07 00:31 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2013-08-07 00:31 . 2013-08-07 00:31 1509376 ----a-w- c:\windows\system32\inetcpl.cpl
2013-08-07 00:31 . 2013-08-07 00:31 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-08-07 00:31 . 2013-08-07 00:31 149504 ----a-w- c:\windows\system32\occache.dll
2013-08-07 00:31 . 2013-08-07 00:31 144896 ----a-w- c:\windows\system32\wextract.exe
2013-08-07 00:31 . 2013-08-07 00:31 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-08-07 00:31 . 2013-08-07 00:31 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-08-07 00:31 . 2013-08-07 00:31 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2013-08-07 00:31 . 2013-08-07 00:31 13824 ----a-w- c:\windows\system32\mshta.exe
2013-08-07 00:31 . 2013-08-07 00:31 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-08-07 00:31 . 2013-08-07 00:31 136192 ----a-w- c:\windows\system32\iepeers.dll
2013-08-07 00:31 . 2013-08-07 00:31 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-08-07 00:31 . 2013-08-07 00:31 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2013-08-07 00:31 . 2013-08-07 00:31 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2013-08-07 00:31 . 2013-08-07 00:31 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-08-07 00:31 . 2013-08-07 00:31 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-08-07 00:31 . 2013-08-07 00:31 102912 ----a-w- c:\windows\system32\inseng.dll
2013-08-07 00:30 . 2013-08-07 00:30 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2013-08-07 00:30 . 2013-08-07 00:30 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2013-08-07 00:30 . 2013-08-07 00:30 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-08-07 00:30 . 2013-08-07 00:30 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-08-07 00:30 . 2013-08-07 00:30 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-08-07 00:30 . 2013-08-07 00:30 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 3928064 ----a-w- c:\windows\system32\d2d1.dll
2013-08-07 00:30 . 2013-08-07 00:30 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-08-07 00:30 . 2013-08-07 00:30 363008 ----a-w- c:\windows\system32\dxgi.dll
2013-08-07 00:30 . 2013-08-07 00:30 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2013-08-07 00:30 . 2013-08-07 00:30 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-08-07 00:30 . 2013-08-07 00:30 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2013-09-21 1814440]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-08-01 3673696]
"sysXboot"="c:\program files\Java\jre7\bin\javaw.exe" [2013-08-08 189352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-08-06 642216]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"Gaming Mouse Driver"="c:\program files (x86)\Gaming Mouse\Monitor.EXE" [2011-09-09 200704]
"Dolby Home Theater v4"="c:\program files (x86)\Dolby Home Theater v4\pcee4.exe" [2012-04-23 508256]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
GIGABYTE OC_GURU.lnk - c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe [2013-5-22 21946368]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [x]
R3 GPCIDrv;GPCIDrv;c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys;c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Servicio de tecnologías de activación de Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys;c:\program files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-21 18:01 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-06 22:50]
.
2013-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-06 22:50]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-08-27 1028896]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-06-11 12503184]
"RtHDVBg_Dolby"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2012-06-13 1212560]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 87.216.1.65 87.216.1.66
FF - ProfilePath - c:\users\Xalo\AppData\Roaming\Mozilla\Firefox\Profiles\tjfjxfqy.default\
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-LocalSessionManager - c:\users\Xalo\AppData\Roaming\lsm.exe
AddRemove-GOGPACKPAPERSPLEASE_is1 - c:\users\Xalo\Desktop\juegos\papersplease\Papers
AddRemove-Reus 1.0 - c:\users\Xalo\Desktop\juegos\Reus\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-09-26  18:24:48
ComboFix-quarantined-files.txt  2013-09-26 16:24
.
Pre-Run: 83.770.621.952 bytes libres
Post-Run: 84.042.059.776 bytes libres
.
- - End Of File - - 0DBB3592D37AAFBEA1FE46E503B897A0
A36C5E4F47E84449FF07ED3517B43A31
 

No problems during the scans.
The cumputer is running fine, the lsm.exe process is not appearing... but it starts all alone and when he wants, so I can't know if it has been removed yet. Only some time will tell. Oh, and the temperatures are some degrees lower!
Thanks for your help Gringo! Let me know if some other scans are needded, please.
 
Link to post
Share on other sites

  • Staff

Hello InternetDude

At this time I would like you to run this script for me and it is a good time to check out the computer to see if there is anything else that needs to be addressed.

:Run CFScript:

Please start by opening Notepad and copy/paste the text in the box into the window:

ClearJavaCache:: 
Save it to your desktop as CFScript.txt

Referring to the picture above, drag CFScript.txt into ComboFix.exe

CFScriptB-4.gif

This will let ComboFix run again.

Restart if you have to.

Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
    • report from Combofix
    • let me know of any problems you may have had
    • How is the computer doing now after running the script?
Gringo
Link to post
Share on other sites

ComboFix 13-09-26.03 - Xalo 27/09/2013  19:45:25.2.8 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.34.3082.18.8153.6209 [GMT 2:00]
Running from: c:\users\Xalo\Desktop\Anti malware tools\ComboFix.exe
Command switches used :: c:\users\Xalo\Desktop\Anti malware tools\CFScript.txt.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((   Files Created from 2013-08-27 to 2013-09-27  )))))))))))))))))))))))))))))))
.
.
2013-09-27 17:49 . 2013-09-27 17:49 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-09-27 17:49 . 2013-09-27 17:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-09-27 17:44 . 2013-09-27 17:44 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{847E4F5C-F4E9-46B3-977E-1EA2675528E3}\offreg.dll
2013-09-26 15:28 . 2013-09-26 15:28 -------- d-----w- c:\windows\ERUNT
2013-09-26 15:24 . 2013-09-26 16:08 -------- d-----w- C:\AdwCleaner
2013-09-26 14:10 . 2013-09-26 14:10 -------- d-----w- c:\users\Xalo\AppData\Local\Mozilla
2013-09-26 14:09 . 2013-09-26 14:09 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2013-09-25 14:50 . 2013-09-05 05:32 9694160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{847E4F5C-F4E9-46B3-977E-1EA2675528E3}\mpengine.dll
2013-09-22 01:07 . 2013-09-27 14:55 -------- d-----w- c:\users\Xalo\AppData\Roaming\Tropico 4
2013-09-22 00:36 . 2013-09-22 00:36 -------- d-----w- c:\users\Xalo\AppData\Roaming\Kalypso Media
2013-09-22 00:31 . 2013-09-22 01:01 -------- d-----w- c:\program files (x86)\Kalypso Media
2013-09-19 15:33 . 2013-09-19 15:33 -------- d-----w- c:\users\Xalo\AppData\Local\WinZip
2013-09-19 15:32 . 2013-09-19 15:34 -------- d-----w- c:\programdata\WinZip
2013-09-19 15:32 . 2013-09-19 15:32 -------- d-----w- c:\program files\WinZip
2013-09-19 15:30 . 2013-09-19 15:30 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-09-19 15:17 . 2013-08-20 13:33 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2013-09-19 15:17 . 2013-08-20 13:32 28448 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2013-09-15 20:42 . 2013-09-15 20:42 -------- d-----w- c:\users\Xalo\AppData\Roaming\OpenOffice.org
2013-09-15 20:40 . 2013-09-15 20:41 -------- d-----w- c:\program files (x86)\OpenOffice.org 3
2013-09-15 20:24 . 2013-09-15 20:24 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2013-09-15 20:23 . 2013-09-15 20:26 -------- d-----w- c:\users\Xalo\AppData\Local\Adobe
2013-09-15 16:00 . 2013-09-15 16:00 -------- d-----w- c:\users\Xalo\AppData\Local\Gas Powered Games
2013-09-15 15:52 . 2013-09-15 15:52 -------- d--h--w- c:\windows\msdownld.tmp
2013-09-15 15:50 . 2013-09-15 15:55 -------- d-----w- c:\program files (x86)\Supreme Commander 2
2013-09-15 08:28 . 2013-09-15 08:55 -------- d-----w- c:\program files (x86)\Rockstar Games
2013-09-15 08:28 . 2013-09-15 08:28 -------- d-----w- c:\programdata\Rockstar Games
2013-09-15 07:42 . 2013-09-15 07:42 -------- d-----w- c:\program files (x86)\Nordic Games
2013-09-12 21:35 . 2013-08-02 01:59 3968960 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-09-11 23:17 . 2013-09-11 23:17 571168 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-09-10 12:52 . 2013-09-10 12:52 -------- d-----w- c:\users\Xalo\AppData\Roaming\SPORE
2013-09-10 12:48 . 2013-09-10 12:48 -------- d-----w- c:\program files (x86)\Electronic Arts
2013-09-10 11:23 . 2013-09-10 11:23 -------- d-----w- c:\programdata\Steam
2013-09-10 10:31 . 2013-09-10 10:38 -------- d-----w- c:\program files (x86)\Company of Heroes 2
2013-09-10 09:09 . 2013-09-10 09:10 -------- d-----w- c:\program files (x86)\dlc
2013-09-10 07:26 . 2013-09-10 07:26 -------- d-----w- c:\users\Xalo\AppData\Local\Chromium
2013-09-09 22:36 . 2013-09-09 22:36 -------- d-----w- c:\program files (x86)\Microsoft Chart Controls
2013-09-09 22:35 . 2013-09-09 22:35 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-09 22:35 . 2013-09-09 22:35 -------- d-----w- c:\windows\SysWow64\Macromed
2013-09-09 22:32 . 2013-09-09 22:46 -------- d-----w- c:\programdata\Hi-Rez Studios
2013-09-09 22:32 . 2013-09-09 22:33 -------- d-----w- c:\program files (x86)\Hi-Rez Studios
2013-09-09 21:57 . 2013-09-09 21:57 -------- d-----w- c:\program files (x86)\Lavalys
2013-09-09 17:02 . 2013-09-09 17:17 25640 ----a-w- c:\windows\gdrv.sys
2013-09-09 16:42 . 2013-09-09 16:42 -------- d-----w- c:\program files\CPUID
2013-09-04 13:31 . 2013-09-04 13:31 -------- d-----w- c:\users\Xalo\AppData\Local\ElevatedDiagnostics
2013-09-03 23:17 . 2013-09-03 23:17 -------- d-----w- c:\users\Xalo\AppData\Local\FLT
2013-09-03 22:54 . 2013-09-03 22:54 -------- d-----w- c:\program files (x86)\XCOM Enemy Unknown
2013-09-03 13:56 . 2007-01-01 18:03 40960 ----a-r- c:\windows\SysWow64\psfind.dll
2013-09-03 13:56 . 2006-07-11 16:43 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll
2013-09-03 13:56 . 2006-07-11 16:35 503808 ----a-w- c:\windows\SysWow64\MSVCP71.dll
2013-09-03 13:54 . 2013-09-03 14:00 -------- d-----w- c:\program files (x86)\THQ
2013-09-01 20:40 . 2013-09-01 20:40 -------- d-----w- c:\users\Xalo\AppData\Local\Introversion
2013-08-31 08:41 . 2013-08-31 08:41 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-08-31 08:41 . 2013-09-03 13:48 -------- d-----w- c:\users\Xalo\AppData\Roaming\DAEMON Tools Lite
2013-08-31 08:41 . 2013-08-31 08:41 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2013-08-31 08:37 . 2013-08-31 08:42 -------- d-----w- c:\programdata\DAEMON Tools Lite
2013-08-30 01:49 . 2013-08-30 01:49 -------- d-----w- c:\programdata\UAB
2013-08-30 01:48 . 2013-08-30 01:48 -------- d-----w- c:\users\Xalo\AppData\Local\PC_Drivers_Headquarters
2013-08-30 01:46 . 2013-08-30 01:46 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2013-08-29 20:46 . 2013-08-30 15:27 -------- d-----w- c:\users\Xalo\AppData\Roaming\Natural Selection 2
2013-08-29 16:51 . 2013-08-29 16:51 -------- d-----w- c:\program files (x86)\Bethesda Softworks
2013-08-29 02:02 . 2013-08-29 02:02 -------- d-----w- c:\users\Xalo\AppData\Local\Futuremark
2013-08-29 02:02 . 2013-08-29 02:02 -------- d-----w- c:\users\Xalo\AppData\Local\IsolatedStorage
2013-08-29 02:01 . 2013-08-29 02:01 -------- d-----w- c:\program files (x86)\Futuremark
2013-08-29 02:00 . 2013-08-29 02:00 -------- d-----w- c:\program files\Futuremark
2013-08-29 01:06 . 2013-08-29 01:06 -------- d-----w- c:\program files (x86)\Gone Home
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-19 14:37 . 2013-08-11 08:51 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-09-19 14:37 . 2013-08-09 13:48 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-09-18 17:20 . 2013-08-09 13:44 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-09-13 01:01 . 2013-08-07 01:53 79143768 ----a-w- c:\windows\system32\MRT.exe
2013-09-12 08:58 . 2013-08-11 17:36 15703688 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-09-12 08:58 . 2013-08-11 17:14 1412832 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-09-12 08:58 . 2013-08-11 17:14 2630304 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-09-12 08:58 . 2013-08-11 17:14 12947360 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-09-12 08:58 . 2013-08-11 17:14 2986672 ----a-w- c:\windows\system32\nvapi64.dll
2013-09-12 08:58 . 2013-08-11 17:14 15901448 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-09-12 07:25 . 2013-08-11 17:16 6599968 ----a-w- c:\windows\system32\nvcpl.dll
2013-09-12 07:25 . 2013-08-11 17:16 3452192 ----a-w- c:\windows\system32\nvsvc64.dll
2013-09-12 07:25 . 2013-08-11 17:16 920864 ----a-w- c:\windows\system32\nvvsvc.exe
2013-09-12 07:25 . 2013-08-11 17:16 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-09-12 07:25 . 2013-08-11 17:16 2559776 ----a-w- c:\windows\system32\nvsvcr.dll
2013-09-12 07:25 . 2013-08-11 17:16 219424 ----a-w- c:\windows\system32\nvmctray.dll
2013-09-11 22:06 . 2013-08-11 17:16 3361114 ----a-w- c:\windows\system32\nvcoproc.bin
2013-08-20 13:32 . 2013-08-11 17:27 29984 ----a-w- c:\windows\system32\nvaudcap64v.dll
2013-08-11 08:51 . 2013-08-11 08:51 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-08-08 19:28 . 2013-08-08 19:28 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10144.bin
2013-08-08 19:16 . 2013-08-08 19:16 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-08-08 19:16 . 2013-08-08 19:16 972712 ----a-w- c:\windows\system32\deployJava1.dll
2013-08-08 19:16 . 2013-08-08 19:16 312232 ----a-w- c:\windows\system32\javaws.exe
2013-08-08 19:16 . 2013-08-08 19:16 1093032 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-08-08 19:16 . 2013-08-08 19:16 189352 ----a-w- c:\windows\system32\javaw.exe
2013-08-08 19:16 . 2013-08-08 19:16 188840 ----a-w- c:\windows\system32\java.exe
2013-08-07 02:22 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-08-07 00:43 . 2013-08-07 00:43 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-08-07 00:43 . 2013-08-07 00:43 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-08-07 00:43 . 2013-08-07 00:43 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-08-07 00:31 . 2013-08-07 00:31 97280 ----a-w- c:\windows\system32\mshtmled.dll
2013-08-07 00:31 . 2013-08-07 00:31 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-08-07 00:31 . 2013-08-07 00:31 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-08-07 00:31 . 2013-08-07 00:31 81408 ----a-w- c:\windows\system32\icardie.dll
2013-08-07 00:31 . 2013-08-07 00:31 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-08-07 00:31 . 2013-08-07 00:31 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2013-08-07 00:31 . 2013-08-07 00:31 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-08-07 00:31 . 2013-08-07 00:31 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-08-07 00:31 . 2013-08-07 00:31 62976 ----a-w- c:\windows\system32\pngfilt.dll
2013-08-07 00:31 . 2013-08-07 00:31 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-08-07 00:31 . 2013-08-07 00:31 599552 ----a-w- c:\windows\system32\vbscript.dll
2013-08-07 00:31 . 2013-08-07 00:31 523264 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-08-07 00:31 . 2013-08-07 00:31 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-08-07 00:31 . 2013-08-07 00:31 51200 ----a-w- c:\windows\system32\imgutil.dll
2013-08-07 00:31 . 2013-08-07 00:31 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-08-07 00:31 . 2013-08-07 00:31 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-08-07 00:31 . 2013-08-07 00:31 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2013-08-07 00:31 . 2013-08-07 00:31 441856 ----a-w- c:\windows\system32\html.iec
2013-08-07 00:31 . 2013-08-07 00:31 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-08-07 00:31 . 2013-08-07 00:31 361984 ----a-w- c:\windows\SysWow64\html.iec
2013-08-07 00:31 . 2013-08-07 00:31 281600 ----a-w- c:\windows\system32\dxtrans.dll
2013-08-07 00:31 . 2013-08-07 00:31 27648 ----a-w- c:\windows\system32\licmgr10.dll
2013-08-07 00:31 . 2013-08-07 00:31 270848 ----a-w- c:\windows\system32\iedkcs32.dll
2013-08-07 00:31 . 2013-08-07 00:31 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-08-07 00:31 . 2013-08-07 00:31 235008 ----a-w- c:\windows\system32\url.dll
2013-08-07 00:31 . 2013-08-07 00:31 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-08-07 00:31 . 2013-08-07 00:31 226304 ----a-w- c:\windows\system32\elshyph.dll
2013-08-07 00:31 . 2013-08-07 00:31 216064 ----a-w- c:\windows\system32\msls31.dll
2013-08-07 00:31 . 2013-08-07 00:31 197120 ----a-w- c:\windows\system32\msrating.dll
2013-08-07 00:31 . 2013-08-07 00:31 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-08-07 00:31 . 2013-08-07 00:31 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2013-08-07 00:31 . 2013-08-07 00:31 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-08-07 00:31 . 2013-08-07 00:31 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2013-08-07 00:31 . 2013-08-07 00:31 1509376 ----a-w- c:\windows\system32\inetcpl.cpl
2013-08-07 00:31 . 2013-08-07 00:31 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-08-07 00:31 . 2013-08-07 00:31 149504 ----a-w- c:\windows\system32\occache.dll
2013-08-07 00:31 . 2013-08-07 00:31 144896 ----a-w- c:\windows\system32\wextract.exe
2013-08-07 00:31 . 2013-08-07 00:31 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-08-07 00:31 . 2013-08-07 00:31 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-08-07 00:31 . 2013-08-07 00:31 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2013-08-07 00:31 . 2013-08-07 00:31 13824 ----a-w- c:\windows\system32\mshta.exe
2013-08-07 00:31 . 2013-08-07 00:31 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-08-07 00:31 . 2013-08-07 00:31 136192 ----a-w- c:\windows\system32\iepeers.dll
2013-08-07 00:31 . 2013-08-07 00:31 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-08-07 00:31 . 2013-08-07 00:31 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2013-08-07 00:31 . 2013-08-07 00:31 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2013-08-07 00:31 . 2013-08-07 00:31 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-08-07 00:31 . 2013-08-07 00:31 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-08-07 00:31 . 2013-08-07 00:31 102912 ----a-w- c:\windows\system32\inseng.dll
2013-08-07 00:30 . 2013-08-07 00:30 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2013-08-07 00:30 . 2013-08-07 00:30 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2013-08-07 00:30 . 2013-08-07 00:30 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-08-07 00:30 . 2013-08-07 00:30 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-08-07 00:30 . 2013-08-07 00:30 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-08-07 00:30 . 2013-08-07 00:30 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 3928064 ----a-w- c:\windows\system32\d2d1.dll
2013-08-07 00:30 . 2013-08-07 00:30 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-08-07 00:30 . 2013-08-07 00:30 363008 ----a-w- c:\windows\system32\dxgi.dll
2013-08-07 00:30 . 2013-08-07 00:30 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2013-08-07 00:30 . 2013-08-07 00:30 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-08-07 00:30 . 2013-08-07 00:30 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2013-09-21 1814440]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-08-01 3673696]
"sysXboot"="c:\program files\Java\jre7\bin\javaw.exe" [2013-08-08 189352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-08-06 642216]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"Gaming Mouse Driver"="c:\program files (x86)\Gaming Mouse\Monitor.EXE" [2011-09-09 200704]
"Dolby Home Theater v4"="c:\program files (x86)\Dolby Home Theater v4\pcee4.exe" [2012-04-23 508256]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
GIGABYTE OC_GURU.lnk - c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe [2013-5-22 21946368]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [x]
R3 GPCIDrv;GPCIDrv;c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys;c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Servicio de tecnologías de activación de Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys;c:\program files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-21 18:01 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-06 22:50]
.
2013-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-06 22:50]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-08-27 1028896]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-06-11 12503184]
"RtHDVBg_Dolby"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2012-06-13 1212560]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 87.216.1.65 87.216.1.66
FF - ProfilePath - c:\users\Xalo\AppData\Roaming\Mozilla\Firefox\Profiles\tjfjxfqy.default\
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-GOGPACKPAPERSPLEASE_is1 - c:\users\Xalo\Desktop\juegos\papersplease\Papers
AddRemove-Reus 1.0 - c:\users\Xalo\Desktop\juegos\Reus\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-09-27  19:51:12
ComboFix-quarantined-files.txt  2013-09-27 17:51
ComboFix2.txt  2013-09-26 16:24
.
Pre-Run: 81.433.485.312 bytes libres
Post-Run: 81.368.793.088 bytes libres
.
- - End Of File - - 16CC8BFC6C82B95106258FF15687F14C
A36C5E4F47E84449FF07ED3517B43A31


Everything fine. Nothing new.
Link to post
Share on other sites

  • Staff

Hello InternetDude

I would like you to try and run these next.

TDSSKiller

Please download the latest version of TDSSKiller from here and save it to your Desktop.

  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
  • Put a checkmark beside loaded modules.
  • A reboot will be needed to apply the changes. Do it.
  • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
  • Then click on Change parameters in TDSSKiller.
  • Check all boxes then click OK.
  • Click the Start Scan button.
  • The scan should take no longer than 2 minutes.
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
  • If malicious objects are found, they will show in the Scan results
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.

    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

  • more than one report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". The one that I need is the larger one. Please copy and paste the contents of that file here.

    Note** this report can be very long - so if the website gives you an error saying it is to long you may attache it

    If the forum still complains about it being to long send me everything that is at the end of the report after where it says

    ==================

    Scan finished

    ==================

and I will see if I want to see the whole report

--RogueKiller--

Download & SAVE to your Desktop RogueKiller for 32bit or Roguekiller for 64bit

  • Quit all programs that you may have started.
  • Please disconnect any external drives from the computer before you run this scan!
  • For Vista or Windows 7, right-click and select "Run as Administrator to start"
  • For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • Then Click on "Scan" button
  • Wait until the Status box shows "Scan Finished"
  • click on "delete"
  • Wait until the Status box shows "Deleting Finished"
  • Click on "Report" and copy/paste the content of the Notepad into your next reply.
  • the scan will make two reports the one I would like to see is called RKreport[2].txt on your Desktop
  • Exit/Close RogueKiller+
send me the reports made from TDSSKiller and Roguekiller and also let me know how the computer is doing at this time.

Gringo

Link to post
Share on other sites

16:23:00.0018 3736  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
16:23:00.0361 3736  ============================================================
16:23:00.0361 3736  Current date / time: 2013/09/28 16:23:00.0361
16:25:31.0655 4904  ============================================================
16:25:31.0655 4904  Scan finished
16:25:31.0655 4904  ============================================================
16:25:31.0655 4896  Detected object count: 2
16:25:31.0655 4896  Actual detected object count: 2
16:26:54.0008 4896  HiPatchService ( UnsignedFile.Multi.Generic ) - skipped by user
16:26:54.0008 4896  HiPatchService ( UnsignedFile.Multi.Generic ) - User select action: Skip 
16:26:54.0008 4896  IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
16:26:54.0008 4896  IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip 
16:29:16.0048 2960  Deinitialize success












RogueKiller V8.6.12 _x64_ [sep 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
 
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Xalo [Admin rights]
Mode : Remove -- Date : 09/28/2013 16:32:03
| ARK || FAK || MBR |
 
¤¤¤ Bad processes : 0 ¤¤¤
 
¤¤¤ Registry Entries : 8 ¤¤¤
[RUN][HJNAME] HKCU\[...]\Run : LocalSessionManager ("C:\Users\Xalo\AppData\Roaming\lsm.exe" [x]) -> DELETED
[RUN][sUSP PATH] HKCU\[...]\Run : sysXboot ("C:\Program Files\Java\jre7\bin\javaw.exe" -jar "C:\Users\Xalo\AppData\Local\Temp\sysXboot7798110488473582857.jar" [7][-]) -> DELETED
[RUN][HJNAME] HKUS\S-1-5-21-4077817561-2542389710-4094447064-1000\[...]\Run : LocalSessionManager ("C:\Users\Xalo\AppData\Roaming\lsm.exe" [x]) -> [0x2] El sistema no puede encontrar el archivo especificado. 
[RUN][sUSP PATH] HKUS\S-1-5-21-4077817561-2542389710-4094447064-1000\[...]\Run : sysXboot ("C:\Program Files\Java\jre7\bin\javaw.exe" -jar "C:\Users\Xalo\AppData\Local\Temp\sysXboot7798110488473582857.jar" [7][-]) -> [0x2] El sistema no puede encontrar el archivo especificado. 
[HJ POL][PUM] HKLM\[...]\System : DisableRegistryTools (0) -> DELETED
[HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableRegistryTools (0) -> [0x2] El sistema no puede encontrar el archivo especificado. 
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
 
¤¤¤ Scheduled tasks : 1 ¤¤¤
[V2][sUSP PATH] DigitalSite : C:\Users\Xalo\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE - /Check [x] -> DELETED
 
¤¤¤ Startup Entries : 0 ¤¤¤
 
¤¤¤ Web browsers : 0 ¤¤¤
 
¤¤¤ Particular Files / Folders: ¤¤¤
 
¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
 
¤¤¤ External Hives: ¤¤¤
 
¤¤¤ Infection :  ¤¤¤
 
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
 
 
127.0.0.1       localhost
 
 
¤¤¤ MBR Check: ¤¤¤
 
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Unidades de disco estándar) - ST1000DM003-1CH162 ATA Device +++++
--- User ---
[MBR] 0af05c8a0a301c22211ff1c14a2e358f
[bSP] a2b202f804efd4226e8c26fdd387d8d7 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 511899 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1048576000 | Size: 441868 Mo
User = LL1 ... OK!
User = LL2 ... OK!
 
Finished : << RKreport[0]_D_09282013_163203.txt >>
RKreport[0]_S_09282013_163051.txt
 
 


Nothing new for now. If the process pops up again I will notify you.
Link to post
Share on other sites

  • Staff

Hello InternetDude

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
Gringo
Link to post
Share on other sites

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-09-2013 02
Ran by Xalo (administrator) on PC1337KILLER360 on 29-09-2013 22:14:10
Running from C:\Users\Xalo\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: Spanish Modern Sort
Internet Explorer Version 10
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\javaw.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\Gaming Mouse\Monitor.EXE
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
() C:\Program Files (x86)\Gaming Mouse\OSD.exe
() C:\Program Files (x86)\Gaming Mouse\Applets\CpuRam.exe
() C:\Program Files (x86)\Gaming Mouse\Applets\EmailPOP3.EXE
() C:\Program Files (x86)\Gaming Mouse\Applets\OSDSkype.exe
() C:\Program Files (x86)\Gaming Mouse\Applets\OSDMSN.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe
(Almico Software (www.almico.com)) C:\Program Files (x86)\SpeedFan\speedfan.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ==================
 
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation)
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212560 2012-06-13] (Realtek Semiconductor)
HKCU\...\Run: [steam] - C:\Program Files (x86)\Steam\steam.exe [1814440 2013-09-21] (Valve Corporation)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673696 2013-08-01] (Disc Soft Ltd)
HKCU\...\Run: [LocalSessionManager] - C:\Users\Xalo\AppData\Roaming\lsm.exe [1065984 2013-09-28] ()
HKCU\...\Run: [sysXboot] - "C:\Program Files\Java\jre7\bin\javaw.exe" -jar "C:\Users\Xalo\AppData\Local\Temp\sysXboot7798110488473582857.jar" <===== ATTENTION
HKLM-x32\...\Run: [startCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [sunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [Gaming Mouse Driver] - C:\Program Files (x86)\Gaming Mouse\Monitor.EXE [200704 2011-09-09] ()
HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [508256 2012-04-23] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
 
==================== Internet (Whitelisted) ====================
 
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 87.216.1.65 87.216.1.66
 
FireFox:
========
FF ProfilePath: C:\Users\Xalo\AppData\Roaming\Mozilla\Firefox\Profiles\tjfjxfqy.default
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll No File
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
 
Chrome: 
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\gcswf32.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Extension: (AdBlock) - C:\Users\Xalo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.8_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Xalo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (Gmail) - C:\Users\Xalo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
 
==================== Services (Whitelisted) =================
 
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-08-11] ()
 
==================== Drivers (Whitelisted) ====================
 
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-08-31] (Disc Soft Ltd)
S3 gdrv; C:\Windows\gdrv.sys [25640 2013-09-09] (Windows ® Server 2003 DDK provider)
S3 gdrv; C:\Windows\gdrv.sys [25640 2013-09-09] (Windows ® Server 2003 DDK provider)
S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] ()
S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] ()
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation)
S3 WinRing0_1_2_0; C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [14544 2012-08-01] (OpenLibSys.org)
S3 WinRing0_1_2_0; C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [14544 2012-08-01] (OpenLibSys.org)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 EtronXHCI; System32\Drivers\EtronXHCI.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
 
==================== NetSvcs (Whitelisted) ===================
 
 
==================== One Month Created Files and Folders ========
 
2013-09-29 22:13 - 2013-09-29 22:13 - 00000000 ____D C:\FRST
2013-09-29 22:11 - 2013-09-29 22:11 - 01953880 _____ (Farbar) C:\Users\Xalo\Downloads\FRST64.exe
2013-09-29 22:11 - 2013-09-29 22:11 - 01953880 _____ (Farbar) C:\Users\Xalo\Desktop\FRST64.exe
2013-09-28 19:47 - 2013-09-28 19:47 - 01065984 _____ C:\Users\Xalo\AppData\Roaming\lsm.exe
2013-09-28 19:40 - 2013-09-28 19:40 - 00000008 _____ C:\Users\Public\instixticus.txt
2013-09-28 16:30 - 2013-09-28 16:30 - 00002596 _____ C:\Users\Xalo\Desktop\RKreport[0]_S_09282013_163051.txt
2013-09-28 16:29 - 2013-09-28 16:32 - 00000000 ____D C:\Users\Xalo\Desktop\RK_Quarantine
2013-09-28 16:28 - 2013-09-28 16:28 - 03812352 _____ C:\Users\Xalo\Downloads\RogueKillerX64 (1).exe
2013-09-28 16:14 - 2013-09-28 16:14 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Xalo\Downloads\tdsskiller.exe
2013-09-28 00:45 - 2013-09-28 00:45 - 00855691 _____ C:\Users\Xalo\Downloads\Essentials (1).zip
2013-09-28 00:42 - 2013-09-28 15:34 - 00000000 ____D C:\Users\Xalo\Desktop\Minecraft server
2013-09-27 19:51 - 2013-09-27 19:51 - 00023059 _____ C:\ComboFix.txt
2013-09-27 18:46 - 2013-09-27 18:46 - 00003347 _____ C:\Users\Xalo\Downloads\server.log
2013-09-27 18:46 - 2013-09-27 18:46 - 00002576 _____ C:\Users\Xalo\Downloads\help.yml
2013-09-27 18:46 - 2013-09-27 18:46 - 00001079 _____ C:\Users\Xalo\Downloads\bukkit.yml
2013-09-27 18:46 - 2013-09-27 18:46 - 00000578 _____ C:\Users\Xalo\Downloads\server.properties
2013-09-27 18:46 - 2013-09-27 18:46 - 00000109 _____ C:\Users\Xalo\Downloads\banned-players.txt
2013-09-27 18:46 - 2013-09-27 18:46 - 00000109 _____ C:\Users\Xalo\Downloads\banned-ips.txt
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 ____D C:\Users\Xalo\Downloads\world_the_end
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 ____D C:\Users\Xalo\Downloads\world_nether
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 ____D C:\Users\Xalo\Downloads\world
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 ____D C:\Users\Xalo\Downloads\plugins
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 _____ C:\Users\Xalo\Downloads\white-list.txt
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 _____ C:\Users\Xalo\Downloads\server.log.lck
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 _____ C:\Users\Xalo\Downloads\permissions.yml
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 _____ C:\Users\Xalo\Downloads\ops.txt
2013-09-27 18:20 - 2013-09-27 18:20 - 00000057 _____ C:\Users\Xalo\Downloads\run.bat
2013-09-27 18:11 - 2013-09-27 18:12 - 15278482 _____ C:\Users\Xalo\Downloads\craftbukkit-1.6.2-R1.0.jar
2013-09-27 18:07 - 2013-09-27 18:07 - 00855691 _____ C:\Users\Xalo\Downloads\Essentials.zip
2013-09-26 18:17 - 2013-09-27 19:51 - 00000000 ____D C:\Qoobox
2013-09-26 18:17 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-09-26 18:17 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-09-26 18:17 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-09-26 18:17 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-09-26 18:17 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-09-26 18:17 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-09-26 18:17 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-09-26 18:17 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-09-26 18:16 - 2013-09-26 18:23 - 00000000 ____D C:\Windows\erdnt
2013-09-26 18:06 - 2013-09-26 18:06 - 05129766 _____ (Swearware) C:\Users\Xalo\Downloads\ComboFix.exe
2013-09-26 17:28 - 2013-09-26 17:28 - 00000000 ____D C:\Windows\ERUNT
2013-09-26 17:24 - 2013-09-26 18:08 - 00000000 ____D C:\AdwCleaner
2013-09-26 17:23 - 2013-09-26 17:23 - 01042066 _____ C:\Users\Xalo\Downloads\AdwCleaner.exe
2013-09-26 17:23 - 2013-09-26 17:23 - 01030038 _____ (Thisisu) C:\Users\Xalo\Downloads\JRT.exe
2013-09-26 17:22 - 2013-09-28 17:08 - 00000000 ____D C:\Users\Xalo\Desktop\Anti malware tools
2013-09-26 16:58 - 2013-09-26 16:58 - 00688992 _____ (Swearware) C:\Users\Xalo\Downloads\dds.com
2013-09-26 16:33 - 2013-09-26 16:33 - 00688992 ____R (Swearware) C:\Users\Xalo\Downloads\dds.scr
2013-09-26 16:10 - 2013-09-26 16:10 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\Mozilla
2013-09-26 16:10 - 2013-09-26 16:10 - 00000000 ____D C:\Users\Xalo\AppData\Local\Mozilla
2013-09-26 16:09 - 2013-09-26 16:09 - 00281824 _____ (Mozilla) C:\Users\Xalo\Downloads\Firefox Setup Stub 24.0.exe
2013-09-26 16:09 - 2013-09-26 16:09 - 00281664 _____ (Mozilla) C:\Users\Xalo\Downloads\Firefox Setup Stub 24.0 (1).exe
2013-09-26 16:09 - 2013-09-26 16:09 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-26 16:09 - 2013-09-26 16:09 - 00000000 ____D C:\ProgramData\Mozilla
2013-09-26 16:09 - 2013-09-26 16:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-26 16:09 - 2013-09-26 16:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-25 20:19 - 2013-09-25 20:20 - 03812352 _____ C:\Users\Xalo\Downloads\RogueKillerX64.exe
2013-09-25 19:50 - 2013-09-25 19:50 - 00301688 _____ (Thesycon GmbH) C:\Users\Xalo\Downloads\dpclat.exe
2013-09-25 18:08 - 2013-09-25 18:08 - 06542715 _____ C:\Users\Xalo\Downloads\minecraft_server.1.6.4 (1).exe
2013-09-25 18:03 - 2013-09-25 18:04 - 06542715 _____ C:\Users\Xalo\Downloads\minecraft_server.1.6.4.exe
2013-09-24 16:29 - 2013-09-24 16:29 - 01577457 _____ C:\Users\Xalo\Downloads\SDT_1_21_1b.swf
2013-09-22 03:07 - 2013-09-28 16:06 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\Tropico 4
2013-09-22 02:59 - 2013-09-22 02:59 - 00012912 _____ C:\Users\Xalo\Desktop\Tropico4 - Acceso directo.lnk
2013-09-22 02:36 - 2013-09-22 02:36 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\Kalypso Media
2013-09-22 02:31 - 2013-09-22 03:01 - 00000000 ____D C:\Program Files (x86)\Kalypso Media
2013-09-20 22:44 - 2013-09-20 22:44 - 01611780 _____ C:\Users\Xalo\Downloads\anally-ripped-whores-scene10-6.mpg
2013-09-20 22:44 - 2013-09-20 22:44 - 01611780 _____ C:\Users\Xalo\Downloads\anally-ripped-whores-scene10-5.mpg
2013-09-19 17:33 - 2013-09-19 17:33 - 00000000 ____D C:\Users\Xalo\AppData\Local\WinZip
2013-09-19 17:32 - 2013-09-19 17:34 - 00000000 ____D C:\ProgramData\WinZip
2013-09-19 17:32 - 2013-09-19 17:32 - 00000000 ____D C:\Program Files\WinZip
2013-09-19 17:30 - 2013-09-19 17:30 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-09-19 17:27 - 2013-09-19 17:27 - 00000000 ____D C:\Users\Xalo\Documents\Add-in Express
2013-09-19 17:24 - 2013-09-12 10:58 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-09-19 17:24 - 2013-09-12 10:58 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 00458528 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 00388384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-09-19 17:24 - 2013-09-12 10:58 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-09-19 17:24 - 2013-06-16 14:38 - 00196384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2013-09-19 17:24 - 2013-06-16 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2013-09-19 17:18 - 2013-09-19 17:18 - 01132770 _____ C:\Users\Xalo\Downloads\mb_bios_ga-990xa-ud3_f13.exe
2013-09-19 17:17 - 2013-08-20 15:33 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2013-09-19 17:17 - 2013-08-20 15:32 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2013-09-19 17:16 - 2013-09-19 17:16 - 01133003 _____ C:\Users\Xalo\Downloads\mb_bios_ga-990xa-ud3_f14b.exe
2013-09-17 16:58 - 2013-09-17 16:58 - 00001758 _____ C:\Users\Xalo\Desktop\SupremeCommander2 - Acceso directo.lnk
2013-09-15 23:31 - 2013-09-15 23:31 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2013-09-15 23:30 - 2013-09-15 23:32 - 00000000 ____D C:\Users\Xalo\Desktop\Gonzalo segon
2013-09-15 22:52 - 2013-09-15 22:52 - 00243469 _____ C:\Users\Xalo\Downloads\Còpia de Horaris_Grau_Quim_13-14_v23.xlsx
2013-09-15 22:52 - 2013-09-15 22:52 - 00243469 _____ C:\Users\Xalo\Downloads\Còpia de Horaris_Grau_Quim_13-14_v23 (2).xlsx
2013-09-15 22:42 - 2013-09-15 22:42 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\OpenOffice.org
2013-09-15 22:40 - 2013-09-15 22:41 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3
2013-09-15 22:38 - 2013-09-15 22:38 - 00000000 ____D C:\Users\Xalo\Desktop\OpenOffice.org 3.3 (ca) Installation Files
2013-09-15 22:35 - 2013-09-15 22:37 - 160119392 _____ C:\Users\Xalo\Downloads\OOo_3.3.0_Win_x86_install-wJRE_ca.exe
2013-09-15 22:27 - 2013-09-15 22:27 - 00243469 _____ C:\Users\Xalo\Downloads\Còpia de Horaris_Grau_Quim_13-14_v23 (1).xlsx
2013-09-15 22:24 - 2013-09-15 22:24 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-09-15 22:23 - 2013-09-15 23:01 - 00000000 ____D C:\ProgramData\Adobe
2013-09-15 22:23 - 2013-09-15 22:26 - 00000000 ____D C:\Users\Xalo\AppData\Local\Adobe
2013-09-15 18:00 - 2013-09-15 18:00 - 00000000 ____D C:\Users\Xalo\Documents\Mis juegos
2013-09-15 18:00 - 2013-09-15 18:00 - 00000000 ____D C:\Users\Xalo\AppData\Local\Gas Powered Games
2013-09-15 17:52 - 2013-09-15 17:52 - 00000000 ___HD C:\Windows\msdownld.tmp
2013-09-15 17:52 - 2013-09-15 17:52 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-09-15 17:52 - 2013-09-15 17:52 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Supreme Commander 2
2013-09-15 17:50 - 2013-09-15 17:55 - 00000000 ____D C:\Program Files (x86)\Supreme Commander 2
2013-09-15 14:37 - 2013-09-15 14:37 - 00001761 _____ C:\Users\Xalo\Desktop\PlayMaxPayne3 - Acceso directo.lnk
2013-09-15 10:28 - 2013-09-15 10:55 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2013-09-15 10:28 - 2013-09-15 10:28 - 00000000 ____D C:\ProgramData\Rockstar Games
2013-09-15 09:45 - 2013-09-15 09:45 - 00002711 _____ C:\Users\Public\Desktop\Painkiller Hell and Damnation.lnk
2013-09-15 09:42 - 2013-09-15 09:42 - 00000000 ____D C:\Program Files (x86)\Nordic Games
2013-09-15 03:38 - 2013-09-15 03:45 - 295142821 _____ C:\Users\Xalo\Downloads\Middens 3.44.zip
2013-09-13 03:02 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-13 03:02 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-13 03:02 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-13 03:02 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-13 03:02 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-13 03:02 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-13 03:02 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-13 03:02 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-13 03:02 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-13 03:02 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-13 03:02 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-13 03:02 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-12 23:35 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-12 23:35 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-12 23:35 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-12 23:35 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-12 23:35 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-12 23:35 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-12 23:35 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-12 23:35 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-12 23:35 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-12 23:35 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-12 23:35 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-12 23:35 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-12 23:35 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-12 23:35 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-12 23:35 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-12 23:35 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-12 23:35 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-12 23:35 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-12 23:35 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-12 23:35 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-12 23:35 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-12 23:35 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-12 23:35 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-12 23:35 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-12 23:35 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-12 23:35 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-09-12 05:50 - 2013-09-12 05:50 - 00000000 ____D C:\Users\Xalo\Downloads\2013GM00212V3
2013-09-12 05:47 - 2013-09-12 05:48 - 43754702 _____ C:\Users\Xalo\Downloads\2013GM00212V3.rar
2013-09-12 01:17 - 2013-09-12 01:17 - 00571168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2013-09-10 14:52 - 2013-09-10 14:52 - 00000000 ____D C:\Users\Xalo\Documents\Mis Creaciones Spore
2013-09-10 14:52 - 2013-09-10 14:52 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\SPORE
2013-09-10 14:48 - 2013-09-10 14:48 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
2013-09-10 13:23 - 2013-09-10 13:23 - 00000000 ____D C:\ProgramData\Steam
2013-09-10 12:37 - 2013-09-10 12:37 - 00000874 _____ C:\Users\Public\Desktop\Company of Heroes 2.lnk
2013-09-10 12:31 - 2013-09-10 12:38 - 00000000 ____D C:\Program Files (x86)\Company of Heroes 2
2013-09-10 11:09 - 2013-09-10 11:10 - 00000000 ____D C:\Program Files (x86)\dlc
2013-09-10 09:26 - 2013-09-15 11:24 - 00000000 ____D C:\Users\Xalo\Documents\Rockstar Games
2013-09-10 09:26 - 2013-09-10 09:26 - 00000000 ____D C:\Users\Xalo\AppData\Local\Chromium
2013-09-10 00:36 - 2013-09-10 00:36 - 00000000 ____D C:\Program Files (x86)\Microsoft Chart Controls
2013-09-10 00:35 - 2013-09-10 00:35 - 00404640 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-10 00:35 - 2013-09-10 00:35 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-09-10 00:32 - 2013-09-10 00:46 - 00000000 ____D C:\ProgramData\Hi-Rez Studios
2013-09-10 00:32 - 2013-09-10 00:33 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2013-09-09 23:57 - 2013-09-09 23:57 - 00001126 _____ C:\Users\Xalo\Desktop\EVEREST Ultimate Edition.lnk
2013-09-09 23:57 - 2013-09-09 23:57 - 00001126 _____ C:\Users\UpdatusUser\Desktop\EVEREST Ultimate Edition.lnk
2013-09-09 23:57 - 2013-09-09 23:57 - 00000000 ____D C:\Program Files (x86)\Lavalys
2013-09-09 19:02 - 2013-09-09 19:17 - 00025640 _____ (Windows ® Server 2003 DDK provider) C:\Windows\gdrv.sys
2013-09-09 19:02 - 2013-09-09 19:02 - 00000000 ____D C:\Users\Xalo\Downloads\atBIOS
2013-09-09 19:01 - 2013-09-09 19:01 - 05385690 _____ C:\Users\Xalo\Downloads\motherboard_utility_gbttools_gbt_atbios.exe
2013-09-09 18:42 - 2013-09-09 18:42 - 01117848 _____ (                                                            ) C:\Users\Xalo\Downloads\hwmonitor_1.23-setup.exe
2013-09-09 18:42 - 2013-09-09 18:42 - 00000000 ____D C:\Program Files\CPUID
2013-09-04 12:54 - 2013-09-04 12:54 - 00000525 _____ C:\Users\Xalo\Desktop\Dispositivos e impresoras - Acceso directo.lnk
2013-09-04 07:47 - 2013-09-22 04:06 - 00000000 ____D C:\Users\Xalo\Desktop\pics
2013-09-04 01:17 - 2013-09-04 01:17 - 00000000 ____D C:\Users\Xalo\AppData\Local\FLT
2013-09-04 01:09 - 2013-09-04 01:09 - 00002208 _____ C:\Users\Public\Desktop\XCOM Enemy Unknown.lnk
2013-09-04 00:54 - 2013-09-04 00:54 - 00000000 ____D C:\Program Files (x86)\XCOM Enemy Unknown
2013-09-03 16:09 - 2013-09-24 15:45 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-09-03 16:02 - 2013-09-03 16:02 - 00002126 _____ C:\Users\Public\Desktop\Titan Quest - Immortal Throne.lnk
2013-09-03 15:56 - 2007-01-01 20:03 - 00040960 ____R C:\Windows\SysWOW64\psfind.dll
2013-09-03 15:56 - 2006-07-11 18:43 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2013-09-03 15:56 - 2006-07-11 18:35 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVCP71.dll
2013-09-03 15:54 - 2013-09-03 16:00 - 00000000 ____D C:\Program Files (x86)\THQ
2013-09-01 22:40 - 2013-09-01 22:40 - 00000000 ____D C:\Users\Xalo\AppData\Local\Introversion
2013-08-31 10:42 - 2013-08-31 10:42 - 00001954 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2013-08-31 10:41 - 2013-09-03 15:48 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\DAEMON Tools Lite
2013-08-31 10:41 - 2013-08-31 10:41 - 00283064 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys
2013-08-31 10:41 - 2013-08-31 10:41 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2013-08-31 10:37 - 2013-08-31 10:42 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2013-08-30 03:49 - 2013-08-30 03:49 - 00000000 ____D C:\Users\Xalo\Downloads\PC Drivers HeadQuarters
2013-08-30 03:49 - 2013-08-30 03:49 - 00000000 ____D C:\ProgramData\UAB
2013-08-30 03:48 - 2013-08-30 03:48 - 00000000 ____D C:\Users\Xalo\AppData\Local\PC_Drivers_Headquarters
2013-08-30 03:46 - 2013-08-30 03:46 - 00000000 ____D C:\ProgramData\PC Drivers HeadQuarters
2013-08-30 03:45 - 2013-08-30 17:59 - 00000000 ____D C:\Users\Xalo\Desktop\DriverDetective
2013-08-30 03:40 - 2013-08-30 03:40 - 02002088 _____ (PC Drivers HeadQuarters) C:\Users\Xalo\Downloads\DriverDetective.exe
2013-08-30 01:36 - 2013-08-30 01:36 - 00000000 ____D C:\Users\Xalo\Desktop\Latency Fix
2013-08-30 01:25 - 2013-08-30 01:25 - 04956875 _____ C:\Users\Xalo\Downloads\Leatrix_Latency_Fix_3.00.zip
 
==================== One Month Modified Files and Folders =======
 
2013-09-29 22:13 - 2013-09-29 22:13 - 00000000 ____D C:\FRST
2013-09-29 22:11 - 2013-09-29 22:11 - 01953880 _____ (Farbar) C:\Users\Xalo\Downloads\FRST64.exe
2013-09-29 22:11 - 2013-09-29 22:11 - 01953880 _____ (Farbar) C:\Users\Xalo\Desktop\FRST64.exe
2013-09-29 22:00 - 2013-08-07 00:50 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-29 17:17 - 2013-08-07 02:30 - 00000000 ____D C:\Program Files (x86)\Steam
2013-09-29 15:55 - 2013-08-07 06:35 - 01715404 _____ C:\Windows\WindowsUpdate.log
2013-09-29 12:35 - 2013-08-07 02:27 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2013-09-29 12:24 - 2009-07-14 06:45 - 00026768 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-29 12:24 - 2009-07-14 06:45 - 00026768 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-29 12:22 - 2010-11-21 09:09 - 00745236 _____ C:\Windows\system32\perfh00A.dat
2013-09-29 12:22 - 2010-11-21 09:09 - 00157736 _____ C:\Windows\system32\perfc00A.dat
2013-09-29 12:22 - 2009-07-14 07:13 - 01670586 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-29 12:17 - 2013-08-10 06:57 - 00017550 _____ C:\autoupdate.log
2013-09-29 12:17 - 2013-08-07 00:50 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-29 12:16 - 2013-08-10 06:18 - 00000000 ____D C:\ProgramData\NVIDIA
2013-09-29 12:16 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-29 12:16 - 2009-07-14 06:51 - 00050305 _____ C:\Windows\setupact.log
2013-09-28 19:47 - 2013-09-28 19:47 - 01065984 _____ C:\Users\Xalo\AppData\Roaming\lsm.exe
2013-09-28 19:40 - 2013-09-28 19:40 - 00000008 _____ C:\Users\Public\instixticus.txt
2013-09-28 17:08 - 2013-09-26 17:22 - 00000000 ____D C:\Users\Xalo\Desktop\Anti malware tools
2013-09-28 16:32 - 2013-09-28 16:29 - 00000000 ____D C:\Users\Xalo\Desktop\RK_Quarantine
2013-09-28 16:30 - 2013-09-28 16:30 - 00002596 _____ C:\Users\Xalo\Desktop\RKreport[0]_S_09282013_163051.txt
2013-09-28 16:28 - 2013-09-28 16:28 - 03812352 _____ C:\Users\Xalo\Downloads\RogueKillerX64 (1).exe
2013-09-28 16:17 - 2010-11-21 05:47 - 00044654 _____ C:\Windows\PFRO.log
2013-09-28 16:14 - 2013-09-28 16:14 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Xalo\Downloads\tdsskiller.exe
2013-09-28 16:06 - 2013-09-22 03:07 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\Tropico 4
2013-09-28 15:34 - 2013-09-28 00:42 - 00000000 ____D C:\Users\Xalo\Desktop\Minecraft server
2013-09-28 14:13 - 2013-08-07 03:01 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\.minecraft
2013-09-28 00:45 - 2013-09-28 00:45 - 00855691 _____ C:\Users\Xalo\Downloads\Essentials (1).zip
2013-09-27 19:51 - 2013-09-27 19:51 - 00023059 _____ C:\ComboFix.txt
2013-09-27 19:51 - 2013-09-26 18:17 - 00000000 ____D C:\Qoobox
2013-09-27 19:49 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-09-27 18:46 - 2013-09-27 18:46 - 00003347 _____ C:\Users\Xalo\Downloads\server.log
2013-09-27 18:46 - 2013-09-27 18:46 - 00002576 _____ C:\Users\Xalo\Downloads\help.yml
2013-09-27 18:46 - 2013-09-27 18:46 - 00001079 _____ C:\Users\Xalo\Downloads\bukkit.yml
2013-09-27 18:46 - 2013-09-27 18:46 - 00000578 _____ C:\Users\Xalo\Downloads\server.properties
2013-09-27 18:46 - 2013-09-27 18:46 - 00000109 _____ C:\Users\Xalo\Downloads\banned-players.txt
2013-09-27 18:46 - 2013-09-27 18:46 - 00000109 _____ C:\Users\Xalo\Downloads\banned-ips.txt
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 ____D C:\Users\Xalo\Downloads\world_the_end
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 ____D C:\Users\Xalo\Downloads\world_nether
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 ____D C:\Users\Xalo\Downloads\world
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 ____D C:\Users\Xalo\Downloads\plugins
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 _____ C:\Users\Xalo\Downloads\white-list.txt
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 _____ C:\Users\Xalo\Downloads\server.log.lck
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 _____ C:\Users\Xalo\Downloads\permissions.yml
2013-09-27 18:46 - 2013-09-27 18:46 - 00000000 _____ C:\Users\Xalo\Downloads\ops.txt
2013-09-27 18:20 - 2013-09-27 18:20 - 00000057 _____ C:\Users\Xalo\Downloads\run.bat
2013-09-27 18:12 - 2013-09-27 18:11 - 15278482 _____ C:\Users\Xalo\Downloads\craftbukkit-1.6.2-R1.0.jar
2013-09-27 18:07 - 2013-09-27 18:07 - 00855691 _____ C:\Users\Xalo\Downloads\Essentials.zip
2013-09-26 18:23 - 2013-09-26 18:16 - 00000000 ____D C:\Windows\erdnt
2013-09-26 18:08 - 2013-09-26 17:24 - 00000000 ____D C:\AdwCleaner
2013-09-26 18:06 - 2013-09-26 18:06 - 05129766 _____ (Swearware) C:\Users\Xalo\Downloads\ComboFix.exe
2013-09-26 17:28 - 2013-09-26 17:28 - 00000000 ____D C:\Windows\ERUNT
2013-09-26 17:25 - 2013-08-07 00:43 - 00001158 _____ C:\Users\Xalo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-09-26 17:23 - 2013-09-26 17:23 - 01042066 _____ C:\Users\Xalo\Downloads\AdwCleaner.exe
2013-09-26 17:23 - 2013-09-26 17:23 - 01030038 _____ (Thisisu) C:\Users\Xalo\Downloads\JRT.exe
2013-09-26 16:58 - 2013-09-26 16:58 - 00688992 _____ (Swearware) C:\Users\Xalo\Downloads\dds.com
2013-09-26 16:34 - 2013-08-09 14:07 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\BitTorrent
2013-09-26 16:33 - 2013-09-26 16:33 - 00688992 ____R (Swearware) C:\Users\Xalo\Downloads\dds.scr
2013-09-26 16:10 - 2013-09-26 16:10 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\Mozilla
2013-09-26 16:10 - 2013-09-26 16:10 - 00000000 ____D C:\Users\Xalo\AppData\Local\Mozilla
2013-09-26 16:09 - 2013-09-26 16:09 - 00281824 _____ (Mozilla) C:\Users\Xalo\Downloads\Firefox Setup Stub 24.0.exe
2013-09-26 16:09 - 2013-09-26 16:09 - 00281664 _____ (Mozilla) C:\Users\Xalo\Downloads\Firefox Setup Stub 24.0 (1).exe
2013-09-26 16:09 - 2013-09-26 16:09 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-26 16:09 - 2013-09-26 16:09 - 00000000 ____D C:\ProgramData\Mozilla
2013-09-26 16:09 - 2013-09-26 16:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-26 16:09 - 2013-09-26 16:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-25 20:20 - 2013-09-25 20:19 - 03812352 _____ C:\Users\Xalo\Downloads\RogueKillerX64.exe
2013-09-25 19:50 - 2013-09-25 19:50 - 00301688 _____ (Thesycon GmbH) C:\Users\Xalo\Downloads\dpclat.exe
2013-09-25 18:08 - 2013-09-25 18:08 - 06542715 _____ C:\Users\Xalo\Downloads\minecraft_server.1.6.4 (1).exe
2013-09-25 18:04 - 2013-09-25 18:03 - 06542715 _____ C:\Users\Xalo\Downloads\minecraft_server.1.6.4.exe
2013-09-24 16:29 - 2013-09-24 16:29 - 01577457 _____ C:\Users\Xalo\Downloads\SDT_1_21_1b.swf
2013-09-24 15:45 - 2013-09-03 16:09 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-09-22 04:06 - 2013-09-04 07:47 - 00000000 ____D C:\Users\Xalo\Desktop\pics
2013-09-22 03:08 - 2013-08-09 07:39 - 00000000 ____D C:\Users\Xalo\Desktop\ISOs
2013-09-22 03:01 - 2013-09-22 02:31 - 00000000 ____D C:\Program Files (x86)\Kalypso Media
2013-09-22 02:59 - 2013-09-22 02:59 - 00012912 _____ C:\Users\Xalo\Desktop\Tropico4 - Acceso directo.lnk
2013-09-22 02:36 - 2013-09-22 02:36 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\Kalypso Media
2013-09-20 22:44 - 2013-09-20 22:44 - 01611780 _____ C:\Users\Xalo\Downloads\anally-ripped-whores-scene10-6.mpg
2013-09-20 22:44 - 2013-09-20 22:44 - 01611780 _____ C:\Users\Xalo\Downloads\anally-ripped-whores-scene10-5.mpg
2013-09-19 17:34 - 2013-09-19 17:32 - 00000000 ____D C:\ProgramData\WinZip
2013-09-19 17:33 - 2013-09-19 17:33 - 00000000 ____D C:\Users\Xalo\AppData\Local\WinZip
2013-09-19 17:33 - 2013-08-07 00:42 - 00000000 ____D C:\Users\Xalo
2013-09-19 17:32 - 2013-09-19 17:32 - 00000000 ____D C:\Program Files\WinZip
2013-09-19 17:30 - 2013-09-19 17:30 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-09-19 17:30 - 2013-08-10 06:17 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-09-19 17:27 - 2013-09-19 17:27 - 00000000 ____D C:\Users\Xalo\Documents\Add-in Express
2013-09-19 17:27 - 2013-08-11 19:12 - 00000000 ____D C:\Windows\system32\appmgmt
2013-09-19 17:18 - 2013-09-19 17:18 - 01132770 _____ C:\Users\Xalo\Downloads\mb_bios_ga-990xa-ud3_f13.exe
2013-09-19 17:18 - 2013-08-12 22:17 - 00000000 ____D C:\Users\Xalo\Desktop\drivers motherboard
2013-09-19 17:16 - 2013-09-19 17:16 - 01133003 _____ C:\Users\Xalo\Downloads\mb_bios_ga-990xa-ud3_f14b.exe
2013-09-19 16:37 - 2013-08-11 10:51 - 00281688 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-09-19 16:37 - 2013-08-09 15:48 - 00281688 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2013-09-18 23:27 - 2009-07-14 07:08 - 00032642 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-18 19:20 - 2013-08-09 15:44 - 00281688 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-09-17 16:58 - 2013-09-17 16:58 - 00001758 _____ C:\Users\Xalo\Desktop\SupremeCommander2 - Acceso directo.lnk
2013-09-16 17:23 - 2013-08-07 01:23 - 00064152 _____ C:\Users\Xalo\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-16 17:21 - 2009-07-14 06:45 - 00293936 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-15 23:32 - 2013-09-15 23:30 - 00000000 ____D C:\Users\Xalo\Desktop\Gonzalo segon
2013-09-15 23:31 - 2013-09-15 23:31 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2013-09-15 23:01 - 2013-09-15 22:23 - 00000000 ____D C:\ProgramData\Adobe
2013-09-15 22:52 - 2013-09-15 22:52 - 00243469 _____ C:\Users\Xalo\Downloads\Còpia de Horaris_Grau_Quim_13-14_v23.xlsx
2013-09-15 22:52 - 2013-09-15 22:52 - 00243469 _____ C:\Users\Xalo\Downloads\Còpia de Horaris_Grau_Quim_13-14_v23 (2).xlsx
2013-09-15 22:42 - 2013-09-15 22:42 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\OpenOffice.org
2013-09-15 22:41 - 2013-09-15 22:40 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3
2013-09-15 22:40 - 2013-08-07 02:43 - 00000000 ____D C:\Program Files (x86)\Java
2013-09-15 22:38 - 2013-09-15 22:38 - 00000000 ____D C:\Users\Xalo\Desktop\OpenOffice.org 3.3 (ca) Installation Files
2013-09-15 22:37 - 2013-09-15 22:35 - 160119392 _____ C:\Users\Xalo\Downloads\OOo_3.3.0_Win_x86_install-wJRE_ca.exe
2013-09-15 22:27 - 2013-09-15 22:27 - 00243469 _____ C:\Users\Xalo\Downloads\Còpia de Horaris_Grau_Quim_13-14_v23 (1).xlsx
2013-09-15 22:26 - 2013-09-15 22:23 - 00000000 ____D C:\Users\Xalo\AppData\Local\Adobe
2013-09-15 22:26 - 2013-08-07 01:27 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\Adobe
2013-09-15 22:24 - 2013-09-15 22:24 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-09-15 18:21 - 2013-08-07 03:33 - 00000000 ____D C:\Users\Xalo\Documents\My Games
2013-09-15 18:00 - 2013-09-15 18:00 - 00000000 ____D C:\Users\Xalo\Documents\Mis juegos
2013-09-15 18:00 - 2013-09-15 18:00 - 00000000 ____D C:\Users\Xalo\AppData\Local\Gas Powered Games
2013-09-15 17:55 - 2013-09-15 17:50 - 00000000 ____D C:\Program Files (x86)\Supreme Commander 2
2013-09-15 17:52 - 2013-09-15 17:52 - 00000000 ___HD C:\Windows\msdownld.tmp
2013-09-15 17:52 - 2013-09-15 17:52 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-09-15 17:52 - 2013-09-15 17:52 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Supreme Commander 2
2013-09-15 14:37 - 2013-09-15 14:37 - 00001761 _____ C:\Users\Xalo\Desktop\PlayMaxPayne3 - Acceso directo.lnk
2013-09-15 11:24 - 2013-09-10 09:26 - 00000000 ____D C:\Users\Xalo\Documents\Rockstar Games
2013-09-15 10:55 - 2013-09-15 10:28 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2013-09-15 10:55 - 2013-08-07 03:33 - 00241328 _____ C:\Windows\DirectX.log
2013-09-15 10:28 - 2013-09-15 10:28 - 00000000 ____D C:\ProgramData\Rockstar Games
2013-09-15 10:28 - 2013-08-07 00:56 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-09-15 10:14 - 2013-08-22 19:13 - 00000000 ____D C:\Users\Xalo\Desktop\juegos
2013-09-15 09:47 - 2013-08-24 17:18 - 00000000 ____D C:\Users\Xalo\AppData\Local\SKIDROW
2013-09-15 09:45 - 2013-09-15 09:45 - 00002711 _____ C:\Users\Public\Desktop\Painkiller Hell and Damnation.lnk
2013-09-15 09:42 - 2013-09-15 09:42 - 00000000 ____D C:\Program Files (x86)\Nordic Games
2013-09-15 03:45 - 2013-09-15 03:38 - 295142821 _____ C:\Users\Xalo\Downloads\Middens 3.44.zip
2013-09-13 08:43 - 2013-08-07 00:43 - 00000000 ___RD C:\Users\Xalo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-13 08:43 - 2013-08-07 00:43 - 00000000 ___RD C:\Users\Xalo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-13 03:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-13 03:02 - 2013-08-10 20:21 - 00000000 ____D C:\Windows\system32\MRT
2013-09-13 03:01 - 2013-08-07 03:53 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-12 10:58 - 2013-09-19 17:24 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-09-12 10:58 - 2013-09-19 17:24 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 00458528 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 00388384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-09-12 10:58 - 2013-09-19 17:24 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-09-12 10:58 - 2013-08-11 19:36 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-09-12 10:58 - 2013-08-11 19:15 - 00022814 _____ C:\Windows\system32\nvinfo.pb
2013-09-12 10:58 - 2013-08-11 19:14 - 15901448 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-09-12 10:58 - 2013-08-11 19:14 - 12947360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-09-12 10:58 - 2013-08-11 19:14 - 02986672 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-09-12 10:58 - 2013-08-11 19:14 - 02630304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-09-12 10:58 - 2013-08-11 19:14 - 01412832 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2013-09-12 09:25 - 2013-08-11 19:16 - 06599968 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2013-09-12 09:25 - 2013-08-11 19:16 - 03452192 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2013-09-12 09:25 - 2013-08-11 19:16 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2013-09-12 09:25 - 2013-08-11 19:16 - 00920864 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2013-09-12 09:25 - 2013-08-11 19:16 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2013-09-12 09:25 - 2013-08-11 19:16 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2013-09-12 05:50 - 2013-09-12 05:50 - 00000000 ____D C:\Users\Xalo\Downloads\2013GM00212V3
2013-09-12 05:48 - 2013-09-12 05:47 - 43754702 _____ C:\Users\Xalo\Downloads\2013GM00212V3.rar
2013-09-12 01:17 - 2013-09-12 01:17 - 00571168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2013-09-12 00:06 - 2013-08-11 19:16 - 03361114 _____ C:\Windows\system32\nvcoproc.bin
2013-09-10 14:52 - 2013-09-10 14:52 - 00000000 ____D C:\Users\Xalo\Documents\Mis Creaciones Spore
2013-09-10 14:52 - 2013-09-10 14:52 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\SPORE
2013-09-10 14:48 - 2013-09-10 14:48 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
2013-09-10 13:23 - 2013-09-10 13:23 - 00000000 ____D C:\ProgramData\Steam
2013-09-10 12:38 - 2013-09-10 12:31 - 00000000 ____D C:\Program Files (x86)\Company of Heroes 2
2013-09-10 12:37 - 2013-09-10 12:37 - 00000874 _____ C:\Users\Public\Desktop\Company of Heroes 2.lnk
2013-09-10 11:10 - 2013-09-10 11:09 - 00000000 ____D C:\Program Files (x86)\dlc
2013-09-10 09:26 - 2013-09-10 09:26 - 00000000 ____D C:\Users\Xalo\AppData\Local\Chromium
2013-09-10 00:46 - 2013-09-10 00:32 - 00000000 ____D C:\ProgramData\Hi-Rez Studios
2013-09-10 00:36 - 2013-09-10 00:36 - 00000000 ____D C:\Program Files (x86)\Microsoft Chart Controls
2013-09-10 00:35 - 2013-09-10 00:35 - 00404640 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-10 00:35 - 2013-09-10 00:35 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-09-10 00:33 - 2013-09-10 00:32 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2013-09-09 23:57 - 2013-09-09 23:57 - 00001126 _____ C:\Users\Xalo\Desktop\EVEREST Ultimate Edition.lnk
2013-09-09 23:57 - 2013-09-09 23:57 - 00001126 _____ C:\Users\UpdatusUser\Desktop\EVEREST Ultimate Edition.lnk
2013-09-09 23:57 - 2013-09-09 23:57 - 00000000 ____D C:\Program Files (x86)\Lavalys
2013-09-09 19:17 - 2013-09-09 19:02 - 00025640 _____ (Windows ® Server 2003 DDK provider) C:\Windows\gdrv.sys
2013-09-09 19:02 - 2013-09-09 19:02 - 00000000 ____D C:\Users\Xalo\Downloads\atBIOS
2013-09-09 19:02 - 2013-08-07 01:03 - 00000000 ____D C:\Program Files (x86)\GIGABYTE
2013-09-09 19:01 - 2013-09-09 19:01 - 05385690 _____ C:\Users\Xalo\Downloads\motherboard_utility_gbttools_gbt_atbios.exe
2013-09-09 18:42 - 2013-09-09 18:42 - 01117848 _____ (                                                            ) C:\Users\Xalo\Downloads\hwmonitor_1.23-setup.exe
2013-09-09 18:42 - 2013-09-09 18:42 - 00000000 ____D C:\Program Files\CPUID
2013-09-09 00:22 - 2013-08-10 20:19 - 00000000 ____D C:\Fraps
2013-09-04 12:54 - 2013-09-04 12:54 - 00000525 _____ C:\Users\Xalo\Desktop\Dispositivos e impresoras - Acceso directo.lnk
2013-09-04 01:17 - 2013-09-04 01:17 - 00000000 ____D C:\Users\Xalo\AppData\Local\FLT
2013-09-04 01:09 - 2013-09-04 01:09 - 00002208 _____ C:\Users\Public\Desktop\XCOM Enemy Unknown.lnk
2013-09-04 00:54 - 2013-09-04 00:54 - 00000000 ____D C:\Program Files (x86)\XCOM Enemy Unknown
2013-09-03 16:02 - 2013-09-03 16:02 - 00002126 _____ C:\Users\Public\Desktop\Titan Quest - Immortal Throne.lnk
2013-09-03 16:00 - 2013-09-03 15:54 - 00000000 ____D C:\Program Files (x86)\THQ
2013-09-03 15:48 - 2013-08-31 10:41 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\DAEMON Tools Lite
2013-09-01 22:40 - 2013-09-01 22:40 - 00000000 ____D C:\Users\Xalo\AppData\Local\Introversion
2013-08-31 10:42 - 2013-08-31 10:42 - 00001954 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2013-08-31 10:42 - 2013-08-31 10:37 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2013-08-31 10:41 - 2013-08-31 10:41 - 00283064 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys
2013-08-31 10:41 - 2013-08-31 10:41 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2013-08-31 00:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\LiveKernelReports
2013-08-30 17:59 - 2013-08-30 03:45 - 00000000 ____D C:\Users\Xalo\Desktop\DriverDetective
2013-08-30 17:59 - 2013-08-11 19:15 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-08-30 17:59 - 2010-11-21 09:19 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-08-30 17:59 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-08-30 17:27 - 2013-08-29 22:46 - 00000000 ____D C:\Users\Xalo\AppData\Roaming\Natural Selection 2
2013-08-30 04:16 - 2013-08-29 04:02 - 00000000 ____D C:\Users\Xalo\Documents\3DMark
2013-08-30 03:49 - 2013-08-30 03:49 - 00000000 ____D C:\Users\Xalo\Downloads\PC Drivers HeadQuarters
2013-08-30 03:49 - 2013-08-30 03:49 - 00000000 ____D C:\ProgramData\UAB
2013-08-30 03:48 - 2013-08-30 03:48 - 00000000 ____D C:\Users\Xalo\AppData\Local\PC_Drivers_Headquarters
2013-08-30 03:46 - 2013-08-30 03:46 - 00000000 ____D C:\ProgramData\PC Drivers HeadQuarters
2013-08-30 03:40 - 2013-08-30 03:40 - 02002088 _____ (PC Drivers HeadQuarters) C:\Users\Xalo\Downloads\DriverDetective.exe
2013-08-30 01:36 - 2013-08-30 01:36 - 00000000 ____D C:\Users\Xalo\Desktop\Latency Fix
2013-08-30 01:25 - 2013-08-30 01:25 - 04956875 _____ C:\Users\Xalo\Downloads\Leatrix_Latency_Fix_3.00.zip
 
Some content of TEMP:
====================
C:\Users\Xalo\AppData\Local\Temp\-683089232.exe
C:\Users\Xalo\AppData\Local\Temp\1087115487.exe
C:\Users\Xalo\AppData\Local\Temp\1511248043.exe
C:\Users\Xalo\AppData\Local\Temp\815707762.exe
C:\Users\Xalo\AppData\Local\Temp\cg.exe
C:\Users\Xalo\AppData\Local\Temp\coin.exe
C:\Users\Xalo\AppData\Local\Temp\jansi-64-git-Bukkit-1.6.2-R1.0-3-g9532cb6-b2889jnks.dll
C:\Users\Xalo\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Xalo\AppData\Local\Temp\sfareca00001.dll
 
 
==================== Bamital & volsnap Check =================
 
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
 
LastRegBack: 2013-09-21 00:03
 
==================== End Of Log ============================




Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-09-2013 02
Ran by Xalo at 2013-09-29 22:14:56
Running from C:\Users\Xalo\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
@BIOS (x32 Version: 2.30)
1.0 Repack By Mrpiano (x32)
3DMark (x32 Version: 1.1)
Actualización de NVIDIA 8.3.14 (Version: 8.3.14)
Adobe Flash Player 10 Plugin (x32 Version: 10.3.181.14)
Adobe Reader XI (11.0.04) - Español (x32 Version: 11.0.04)
AMD APP SDK Runtime (Version: 10.0.938.2)
AMD Catalyst Install Manager (Version: 8.0.881.0)
AMD Fuel (Version: 2012.0806.1213.19931)
Call of Juarez Gunslinger © Ubisoft version 1 (x32 Version: 1)
Catalyst Control Center (x32 Version: 2012.0806.1213.19931)
Catalyst Control Center InstallProxy (x32 Version: 2012.0806.1213.19931)
Catalyst Control Center Localization All (x32 Version: 2012.0806.1213.19931)
CCC Help Chinese Standard (x32 Version: 2012.0806.1212.19931)
CCC Help Chinese Traditional (x32 Version: 2012.0806.1212.19931)
CCC Help Czech (x32 Version: 2012.0806.1212.19931)
CCC Help Danish (x32 Version: 2012.0806.1212.19931)
CCC Help Dutch (x32 Version: 2012.0806.1212.19931)
CCC Help English (x32 Version: 2012.0806.1212.19931)
CCC Help Finnish (x32 Version: 2012.0806.1212.19931)
CCC Help French (x32 Version: 2012.0806.1212.19931)
CCC Help German (x32 Version: 2012.0806.1212.19931)
CCC Help Greek (x32 Version: 2012.0806.1212.19931)
CCC Help Hungarian (x32 Version: 2012.0806.1212.19931)
CCC Help Italian (x32 Version: 2012.0806.1212.19931)
CCC Help Japanese (x32 Version: 2012.0806.1212.19931)
CCC Help Korean (x32 Version: 2012.0806.1212.19931)
CCC Help Norwegian (x32 Version: 2012.0806.1212.19931)
CCC Help Polish (x32 Version: 2012.0806.1212.19931)
CCC Help Portuguese (x32 Version: 2012.0806.1212.19931)
CCC Help Russian (x32 Version: 2012.0806.1212.19931)
CCC Help Spanish (x32 Version: 2012.0806.1212.19931)
CCC Help Swedish (x32 Version: 2012.0806.1212.19931)
CCC Help Thai (x32 Version: 2012.0806.1212.19931)
CCC Help Turkish (x32 Version: 2012.0806.1212.19931)
ccc-utility64 (Version: 2012.0806.1213.19931)
Chivalry: Medieval Warfare (x32)
Company of Heroes 2 (x32 Version: 1)
Company of Heroes Singleplayer Demo (x32)
Counter-Strike: Global Offensive (x32)
DAEMON Tools Lite (x32 Version: 4.47.1.0337)
Dishonored (x32)
Dolby Home Theater v4 (x32 Version: 7.2.8000.13)
Dota 2 (x32)
EVEREST Ultimate Edition v4.60 (x32 Version: 4.60)
Far Cry 3 (x32 Version: 1.01)
Fraps (x32)
Futuremark SystemInfo (x32 Version: 4.17.0)
Gaming Mouse Driver (x32)
Garry's Mod (x32)
GeForce Experience NvStream Client Components (Version: 0.1.87)
GIGABYTE OC_GURU II (x32 Version: 1.46.0000)
Gone Home 1.00 (x32)
Google Chrome (x32 Version: 29.0.1547.76)
Hi-Rez Studios Authenticate and Update Service (x32 Version: 3.0.0.0)
Hotline Miami (x32)
Java 7 Update 25 (64-bit) (Version: 7.0.250)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
Java 6 Update 22 (x32 Version: 6.0.220)
Left 4 Dead 2 (x32)
Malwarebytes Anti-Malware versión 1.75.0.1300 (x32 Version: 1.75.0.1300)
Max Payne 3 (x32 Version: 1.0.0.0)
Metro: Last Light (x32)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (x32 Version: 3.5.30730.0)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 24.0 (x86 en-US) (x32 Version: 24.0)
Mozilla Maintenance Service (x32 Version: 24.0)
Natural Selection 2 (x32)
NVIDIA Controlador de 3D Vision 327.23 (Version: 327.23)
NVIDIA Controlador de audio HD 1.3.26.4 (Version: 1.3.26.4)
NVIDIA Controlador de gráficos 327.23 (Version: 327.23)
NVIDIA Controlador de la controladora 3D Vision 326.01 (Version: 326.01)
NVIDIA GeForce Experience 1.6.1 (Version: 1.6.1)
NVIDIA Install Application (Version: 2.1002.133.902)
NVIDIA PhysX (x32 Version: 9.13.0725)
NVIDIA Software del sistema PhysX 9.13.0725 (Version: 9.13.0725)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2723)
NVIDIA Update Components (Version: 8.3.14)
NVIDIA Virtual Audio 1.2.5 (Version: 1.2.5)
ON_OFF Charge B12.1025.1 (x32 Version: 1.00.0001)
OpenOffice.org 3.3 (x32 Version: 3.3.9567)
Painkiller Hell and Damnation (x32)
Panel de control de NVIDIA 327.23 (Version: 327.23)
Papers, Please (x32 Version: 2.0.0.4)
Prison Architect (x32)
PunkBuster Services (x32 Version: 0.993)
Razer Game Booster (x32 Version: 3.7)
Realtek Ethernet Controller Driver (x32 Version: 7.48.823.2011)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6662)
Reus 1.0 (x32 Version: 1.0)
Rockstar Games Social Club (x32 Version: 1.1.0.6)
S.T.A.L.K.E.R. - Call of Pripyat (x32)
SHIELD Streaming (Version: 1.05.28)
SpeedFan (remove only) (x32)
SPORE (x32 Version: 1.00.0000)
Steam (x32 Version: 1.0.0.0)
Team Fortress 2 (x32)
Titan Quest (x32 Version: 1.00.0000)
Titan Quest Immortal Throne (x32 Version: 1.00.0000)
Torchlight II (x32)
Tribes: Ascend (x32)
Tropico 4 1.00 (HKCU Version: 1.00)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Uplink (x32)
WinZip 17.0 (Version: 17.0.10283)
XCOM: Enemy Unknown (x32)
 
==================== Restore Points  =========================
 
26-09-2013 16:17:15 ComboFix created restore point
28-09-2013 18:03:40 Windows Update
 
==================== Hosts content: ==========================
 
2009-07-14 04:34 - 2013-09-26 18:23 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
 
==================== Scheduled Tasks (whitelisted) =============
 
Task: {00098487-9036-4C18-84B7-298D503053FF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-07] (Google Inc.)
Task: {5D857C88-F109-4E20-BAFA-404E64D4E6DA} - \BrowserDefendert No Task File
Task: {748F0F0B-0A50-4E8E-A486-557D520FC2D1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-07] (Google Inc.)
Task: {DDF3E573-AAD4-4BFC-A2A0-61A93C4BF8CF} - System32\Tasks\Razer_Game_Booster_AutoUpdate => C:\Program Files (x86)\Razer\Razer Game Booster\AutoUpdate.exe [2013-06-05] ()
Task: {ECD119A5-4D41-4A58-AF1D-C71710A6855A} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2013-08-07] (Microsoft Corporation)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2013-07-01 08:20 - 2013-08-22 00:18 - 00687104 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2013-07-26 14:46 - 2013-09-21 20:35 - 01121192 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2013-07-15 14:32 - 2013-09-11 00:20 - 20625832 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
2013-06-14 15:49 - 2013-06-15 01:49 - 01100800 _____ () C:\Program Files (x86)\Steam\bin\avcodec-53.dll
2013-06-14 15:49 - 2013-06-15 01:49 - 00124416 _____ () C:\Program Files (x86)\Steam\bin\avutil-51.dll
2013-06-14 15:49 - 2013-06-15 01:49 - 00192000 _____ () C:\Program Files (x86)\Steam\bin\avformat-53.dll
2013-09-10 00:35 - 2013-09-10 00:35 - 06271136 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
2013-08-09 05:16 - 2011-04-06 22:58 - 00057344 _____ () C:\Program Files (x86)\Gaming Mouse\lan.dll
2013-08-09 05:16 - 2011-08-29 22:22 - 00061440 _____ () C:\Program Files (x86)\Gaming Mouse\hiddriver.dll
2013-09-28 21:22 - 2013-09-29 12:35 - 00158720 _____ () C:\Users\Xalo\AppData\Local\Temp\sfareca00001.dll
2013-09-28 00:22 - 2013-09-29 12:35 - 00192512 _____ () C:\Users\Xalo\AppData\Local\Temp\sfamcc00001.dll
2013-09-21 20:03 - 2013-09-17 05:20 - 00709584 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\libglesv2.dll
2013-09-21 20:03 - 2013-09-17 05:20 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\libegl.dll
2013-09-21 20:03 - 2013-09-17 05:21 - 04053456 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\pdf.dll
2013-09-21 20:03 - 2013-09-17 05:21 - 00410576 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll
2013-09-21 20:03 - 2013-09-17 05:20 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\ffmpegsumo.dll
2013-09-21 20:03 - 2013-09-17 05:21 - 13611984 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
 
==================== Safe Mode (whitelisted) ===================
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\85720637.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\85720637.sys => ""="Driver"
 
==================== Faulty Device Manager Devices =============
 
Name: Controladora de bus serie universal(USB)
Description: Controladora de bus serie universal(USB)
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Controladora de bus serie universal(USB)
Description: Controladora de bus serie universal(USB)
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/29/2013 02:44:32 PM) (Source: SideBySide) (User: )
Description: Error al generar el contexto de activación de "1". Error en el manifiesto o el archivo de directiva "2", línea 3.
El elemento de la raíz del archivo de manifiesto debe ser un ensamblado.
 
Error: (09/29/2013 02:32:48 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005
 
Error: (09/29/2013 01:18:56 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005
 
Error: (09/29/2013 00:18:33 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (09/29/2013 00:17:17 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (09/29/2013 00:17:17 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
Error: (09/28/2013 09:29:08 PM) (Source: Application Error) (User: )
Description: Nombre de la aplicación con errores: Fuel.Service.exe, versión: 1.0.0.0, marca de tiempo: 0x501fefb5
Nombre del módulo con errores: Device.dll, versión: 4.1.0.0, marca de tiempo: 0x4f55e10b
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x00000000000033c1
Id. del proceso con errores: 0x6c8
Hora de inicio de la aplicación con errores: 0xFuel.Service.exe0
Ruta de acceso de la aplicación con errores: Fuel.Service.exe1
Ruta de acceso del módulo con errores: Fuel.Service.exe2
Id. del informe: Fuel.Service.exe3
 
Error: (09/28/2013 09:01:12 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (09/28/2013 08:59:58 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (09/28/2013 08:59:58 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
 
System errors:
=============
Error: (09/28/2013 09:29:09 PM) (Source: Service Control Manager) (User: )
Description: El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
 
Error: (09/28/2013 08:04:20 PM) (Source: Service Control Manager) (User: )
Description: El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
 
Error: (09/28/2013 04:16:51 PM) (Source: Service Control Manager) (User: )
Description: El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
 
Error: (09/28/2013 04:26:21 AM) (Source: Service Control Manager) (User: )
Description: El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
 
Error: (09/28/2013 00:22:10 AM) (Source: nvlddmkm) (User: )
Description: \Device\Video7e7e7(214c) 04008f38 10408a10
 
Error: (09/27/2013 07:58:13 PM) (Source: Service Control Manager) (User: )
Description: El servicio Servicio de detección automática de proxy web WinHTTP no pudo iniciarse debido al siguiente error: 
%%1069
 
Error: (09/27/2013 07:58:13 PM) (Source: Service Control Manager) (User: )
Description: El servicio WinHttpAutoProxySvc no se pudo iniciarse como NT AUTHORITY\LocalService con la contraseña configurada actualmente debido al siguiente error: 
%%1352
 
Para asegurarse de que el servicio esté correctamente configurado, use el complemento Servicios en Microsoft Management Console (MMC).
 
Error: (09/27/2013 07:58:13 PM) (Source: Service Control Manager) (User: )
Description: El servicio AMD FUEL Service se terminó de manera inesperada. Esto ha sucedido 1 veces.
 
Error: (09/27/2013 07:49:47 PM) (Source: Service Control Manager) (User: )
Description: El servicio PEVSystemStart ha sido marcado como servicio interactivo. Sin embargo, el sistema está configurado para no permitir servicios interactivos. Este servicio puede tener un funcionamiento incorrecto.
 
Error: (09/27/2013 07:47:36 PM) (Source: Service Control Manager) (User: )
Description: El servicio PEVSystemStart ha sido marcado como servicio interactivo. Sin embargo, el sistema está configurado para no permitir servicios interactivos. Este servicio puede tener un funcionamiento incorrecto.
 
 
Microsoft Office Sessions:
=========================
Error: (09/29/2013 02:44:32 PM) (Source: SideBySide)(User: )
Description: C:\Program Files\WinZip\adxloader.dll.ManifestC:\Program Files\WinZip\adxloader.dll.Manifest2
 
Error: (09/29/2013 02:32:48 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005
 
Error: (09/29/2013 01:18:56 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005
 
Error: (09/29/2013 00:18:33 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (09/29/2013 00:17:17 PM) (Source: NvStreamSvc)(User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (09/29/2013 00:17:17 PM) (Source: NvStreamSvc)(User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
Error: (09/28/2013 09:29:08 PM) (Source: Application Error)(User: )
Description: Fuel.Service.exe1.0.0.0501fefb5Device.dll4.1.0.04f55e10bc000000500000000000033c16c801cebc7cdddfa978C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exeC:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll3e5e191c-2874-11e3-a486-94de807dd5ee
 
Error: (09/28/2013 09:01:12 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (09/28/2013 08:59:58 PM) (Source: NvStreamSvc)(User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (09/28/2013 08:59:58 PM) (Source: NvStreamSvc)(User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
 
CodeIntegrity Errors:
===================================
  Date: 2013-09-26 18:23:03.645
  Description: Windows no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\ComboFix\catchme.sys porque el hash del archivo no se encuentra en el sistema. Puede que un cambio reciente de hardware o software haya instalado un archivo dañado o con una firma incorrecta, o que exista un software malintencionado de origen desconocido.
 
  Date: 2013-09-26 18:23:03.598
  Description: Windows no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\ComboFix\catchme.sys porque el hash del archivo no se encuentra en el sistema. Puede que un cambio reciente de hardware o software haya instalado un archivo dañado o con una firma incorrecta, o que exista un software malintencionado de origen desconocido.
 
 
==================== Memory info =========================== 
 
Percentage of memory in use: 30%
Total physical RAM: 8152.73 MB
Available physical RAM: 5670.64 MB
Total Pagefile: 16303.64 MB
Available Pagefile: 12988.37 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:499.9 GB) (Free:79.14 GB) NTFS
Drive d: (Disco Local 2) (Fixed) (Total:431.51 GB) (Free:431.41 GB) NTFS
Drive f: (TQIT) (CDROM) (Total:2.11 GB) (Free:0 GB) UDF
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 392D172E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=500 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=432 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================

 

 

Link to post
Share on other sites

  • Staff

Hello InternetDude

I need you to download this script I have made for you --> fixlist.txt

It needs to be saved Next to the "Farbar Recovery Scan Tool" (FRST) program (If asked to overwrite existing one please allow)

Run FRST again but this time press the Fix button just once and wait.

When finished, it will make a log (fixlog.txt) next to FRST. Please copy and paste the content of this file to your reply.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Gringo

Link to post
Share on other sites

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 27-09-2013 02
Ran by Xalo at 2013-09-30 15:26:54 Run:1
Running from C:\Users\Xalo\Desktop
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
HKCU\...\Run: [LocalSessionManager] - C:\Users\Xalo\AppData\Roaming\lsm.exe [1065984 2013-09-28] () 
HKCU\...\Run: [sysXboot] - "C:\Program Files\Java\jre7\bin\javaw.exe" -jar "C:\Users\Xalo\AppData\Local\Temp\sysXboot7798110488473582857.jar" <===== ATTENTION
C:\Users\Xalo\AppData\Local\Temp\-683089232.exe 
C:\Users\Xalo\AppData\Local\Temp\1087115487.exe 
C:\Users\Xalo\AppData\Local\Temp\1511248043.exe 
C:\Users\Xalo\AppData\Local\Temp\815707762.exe 
C:\Users\Xalo\AppData\Local\Temp\cg.exe 
C:\Users\Xalo\AppData\Local\Temp\coin.exe 
C:\Users\Xalo\AppData\Local\Temp\jansi-64-git-Bukkit-1.6.2-R1.0-3-g9532cb6-b2889jnks.dll 
C:\Users\Xalo\AppData\Local\Temp\sfamcc00001.dll 
C:\Users\Xalo\AppData\Local\Temp\sfareca00001.dll 
C:\Users\Xalo\AppData\Roaming\lsm.exe
C:\Users\Xalo\AppData\Local\Temp\sysXboot7798110488473582857.jar
 
 
 
 
*****************
 
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\LocalSessionManager => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\sysXboot => Value deleted successfully.
C:\Users\Xalo\AppData\Local\Temp\-683089232.exe  => Moved successfully.
C:\Users\Xalo\AppData\Local\Temp\1087115487.exe  => Moved successfully.
C:\Users\Xalo\AppData\Local\Temp\1511248043.exe  => Moved successfully.
C:\Users\Xalo\AppData\Local\Temp\815707762.exe  => Moved successfully.
C:\Users\Xalo\AppData\Local\Temp\cg.exe  => Moved successfully.
C:\Users\Xalo\AppData\Local\Temp\coin.exe  => Moved successfully.
C:\Users\Xalo\AppData\Local\Temp\jansi-64-git-Bukkit-1.6.2-R1.0-3-g9532cb6-b2889jnks.dll  => Moved successfully.
C:\Users\Xalo\AppData\Local\Temp\sfamcc00001.dll  => Moved successfully.
"C:\Users\Xalo\AppData\Local\Temp\sfareca00001.dll " => File/Directory not found.
C:\Users\Xalo\AppData\Roaming\lsm.exe => Moved successfully.
Could not move "C:\Users\Xalo\AppData\Local\Temp\sysXboot7798110488473582857.jar" => Scheduled to move on reboot.
 
=========== Result of Scheduled Files to move ===========
 
"C:\Users\Xalo\AppData\Local\Temp\sysXboot7798110488473582857.jar" => File could not move.
 
==== End of Fixlog ====



Here we go :D
Link to post
Share on other sites

  • Staff

Blitzblank.

Download BlitzBlank and save it to your desktop. Open Blitzblank.exe

  • Click OK at the warning (and take note of it, this is a VERY powerful tool!).
  • Click the Script tab and copy/paste the following text there:
DeleteFile:"C:\Users\Xalo\AppData\Local\Temp\sysXboot7798110488473582857.jar"
  • Click Execute Now. Your computer will need to reboot in order to replace the files.
  • When done, post me the report created by Blitzblank. you can find it at the root of the drive Normaly C:\
Gringo
Link to post
Share on other sites

  • Staff

Hello InternetDude

I would like you to download an updated version of combofix.

update combofix

  • Delete the version of combofix you have now on your desktop and download a new one from here**Note: It is important that it is saved directly to your desktop**

    1. Close any open browsers.

    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    Double click on combofix.exe & follow the prompts.

    When finished, it will produce a report for you.

    Note:Do not mouseclick combofix's window while it's running. That may cause it to stall

    Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"
  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?
Gringo
Link to post
Share on other sites

ComboFix 13-10-03.03 - Xalo 03/10/2013  15:35:20.3.8 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.34.3082.18.8153.6436 [GMT 2:00]
Running from: c:\users\Xalo\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((   Files Created from 2013-09-03 to 2013-10-03  )))))))))))))))))))))))))))))))
.
.
2013-10-03 13:40 . 2013-10-03 13:40 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-10-03 13:40 . 2013-10-03 13:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-09-26 15:28 . 2013-09-26 15:28 -------- d-----w- c:\windows\ERUNT
2013-09-26 15:24 . 2013-09-26 16:08 -------- d-----w- C:\AdwCleaner
2013-09-26 14:10 . 2013-09-26 14:10 -------- d-----w- c:\users\Xalo\AppData\Local\Mozilla
2013-09-26 14:09 . 2013-09-26 14:09 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2013-09-22 01:07 . 2013-09-28 14:06 -------- d-----w- c:\users\Xalo\AppData\Roaming\Tropico 4
2013-09-22 00:36 . 2013-09-22 00:36 -------- d-----w- c:\users\Xalo\AppData\Roaming\Kalypso Media
2013-09-22 00:31 . 2013-09-22 01:01 -------- d-----w- c:\program files (x86)\Kalypso Media
2013-09-19 15:33 . 2013-09-19 15:33 -------- d-----w- c:\users\Xalo\AppData\Local\WinZip
2013-09-19 15:32 . 2013-09-19 15:34 -------- d-----w- c:\programdata\WinZip
2013-09-19 15:32 . 2013-09-19 15:32 -------- d-----w- c:\program files\WinZip
2013-09-19 15:30 . 2013-09-19 15:30 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-09-19 15:17 . 2013-08-20 13:33 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2013-09-19 15:17 . 2013-08-20 13:32 28448 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2013-09-15 20:42 . 2013-09-15 20:42 -------- d-----w- c:\users\Xalo\AppData\Roaming\OpenOffice.org
2013-09-15 20:40 . 2013-09-15 20:41 -------- d-----w- c:\program files (x86)\OpenOffice.org 3
2013-09-15 20:24 . 2013-09-15 20:24 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2013-09-15 20:23 . 2013-09-15 20:26 -------- d-----w- c:\users\Xalo\AppData\Local\Adobe
2013-09-15 16:00 . 2013-09-15 16:00 -------- d-----w- c:\users\Xalo\AppData\Local\Gas Powered Games
2013-09-15 15:52 . 2013-09-15 15:52 -------- d--h--w- c:\windows\msdownld.tmp
2013-09-15 15:50 . 2013-09-15 15:55 -------- d-----w- c:\program files (x86)\Supreme Commander 2
2013-09-15 08:28 . 2013-09-15 08:55 -------- d-----w- c:\program files (x86)\Rockstar Games
2013-09-15 08:28 . 2013-09-15 08:28 -------- d-----w- c:\programdata\Rockstar Games
2013-09-15 07:42 . 2013-09-15 07:42 -------- d-----w- c:\program files (x86)\Nordic Games
2013-09-12 21:35 . 2013-08-02 01:59 3968960 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-09-11 23:17 . 2013-09-11 23:17 571168 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-09-10 12:52 . 2013-09-10 12:52 -------- d-----w- c:\users\Xalo\AppData\Roaming\SPORE
2013-09-10 12:48 . 2013-09-10 12:48 -------- d-----w- c:\program files (x86)\Electronic Arts
2013-09-10 11:23 . 2013-09-10 11:23 -------- d-----w- c:\programdata\Steam
2013-09-10 10:31 . 2013-09-10 10:38 -------- d-----w- c:\program files (x86)\Company of Heroes 2
2013-09-10 09:09 . 2013-09-10 09:10 -------- d-----w- c:\program files (x86)\dlc
2013-09-10 07:26 . 2013-09-10 07:26 -------- d-----w- c:\users\Xalo\AppData\Local\Chromium
2013-09-09 22:36 . 2013-09-09 22:36 -------- d-----w- c:\program files (x86)\Microsoft Chart Controls
2013-09-09 22:35 . 2013-09-09 22:35 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-09 22:35 . 2013-09-09 22:35 -------- d-----w- c:\windows\SysWow64\Macromed
2013-09-09 22:32 . 2013-09-09 22:46 -------- d-----w- c:\programdata\Hi-Rez Studios
2013-09-09 22:32 . 2013-09-09 22:33 -------- d-----w- c:\program files (x86)\Hi-Rez Studios
2013-09-09 21:57 . 2013-09-09 21:57 -------- d-----w- c:\program files (x86)\Lavalys
2013-09-09 17:02 . 2013-09-09 17:17 25640 ----a-w- c:\windows\gdrv.sys
2013-09-09 16:42 . 2013-09-09 16:42 -------- d-----w- c:\program files\CPUID
2013-09-04 13:31 . 2013-09-04 13:31 -------- d-----w- c:\users\Xalo\AppData\Local\ElevatedDiagnostics
2013-09-03 23:17 . 2013-09-03 23:17 -------- d-----w- c:\users\Xalo\AppData\Local\FLT
2013-09-03 22:54 . 2013-09-03 22:54 -------- d-----w- c:\program files (x86)\XCOM Enemy Unknown
2013-09-03 13:56 . 2007-01-01 18:03 40960 ----a-r- c:\windows\SysWow64\psfind.dll
2013-09-03 13:56 . 2006-07-11 16:43 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll
2013-09-03 13:56 . 2006-07-11 16:35 503808 ----a-w- c:\windows\SysWow64\MSVCP71.dll
2013-09-03 13:54 . 2013-09-03 14:00 -------- d-----w- c:\program files (x86)\THQ
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-19 14:37 . 2013-08-11 08:51 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-09-19 14:37 . 2013-08-09 13:48 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-09-18 17:20 . 2013-08-09 13:44 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-09-13 01:01 . 2013-08-07 01:53 79143768 ----a-w- c:\windows\system32\MRT.exe
2013-09-12 08:58 . 2013-08-11 17:36 15703688 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-09-12 08:58 . 2013-08-11 17:14 1412832 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-09-12 08:58 . 2013-08-11 17:14 2630304 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-09-12 08:58 . 2013-08-11 17:14 12947360 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-09-12 08:58 . 2013-08-11 17:14 2986672 ----a-w- c:\windows\system32\nvapi64.dll
2013-09-12 08:58 . 2013-08-11 17:14 15901448 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-09-12 07:25 . 2013-08-11 17:16 6599968 ----a-w- c:\windows\system32\nvcpl.dll
2013-09-12 07:25 . 2013-08-11 17:16 3452192 ----a-w- c:\windows\system32\nvsvc64.dll
2013-09-12 07:25 . 2013-08-11 17:16 920864 ----a-w- c:\windows\system32\nvvsvc.exe
2013-09-12 07:25 . 2013-08-11 17:16 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-09-12 07:25 . 2013-08-11 17:16 2559776 ----a-w- c:\windows\system32\nvsvcr.dll
2013-09-12 07:25 . 2013-08-11 17:16 219424 ----a-w- c:\windows\system32\nvmctray.dll
2013-09-11 22:06 . 2013-08-11 17:16 3361114 ----a-w- c:\windows\system32\nvcoproc.bin
2013-08-31 08:41 . 2013-08-31 08:41 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-08-20 13:32 . 2013-08-11 17:27 29984 ----a-w- c:\windows\system32\nvaudcap64v.dll
2013-08-11 08:51 . 2013-08-11 08:51 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-08-08 19:28 . 2013-08-08 19:28 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10144.bin
2013-08-08 19:16 . 2013-08-08 19:16 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-08-08 19:16 . 2013-08-08 19:16 972712 ----a-w- c:\windows\system32\deployJava1.dll
2013-08-08 19:16 . 2013-08-08 19:16 312232 ----a-w- c:\windows\system32\javaws.exe
2013-08-08 19:16 . 2013-08-08 19:16 1093032 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-08-08 19:16 . 2013-08-08 19:16 189352 ----a-w- c:\windows\system32\javaw.exe
2013-08-08 19:16 . 2013-08-08 19:16 188840 ----a-w- c:\windows\system32\java.exe
2013-08-07 02:22 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-08-07 00:43 . 2013-08-07 00:43 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-08-07 00:43 . 2013-08-07 00:43 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-08-07 00:43 . 2013-08-07 00:43 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-08-07 00:31 . 2013-08-07 00:31 97280 ----a-w- c:\windows\system32\mshtmled.dll
2013-08-07 00:31 . 2013-08-07 00:31 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-08-07 00:31 . 2013-08-07 00:31 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-08-07 00:31 . 2013-08-07 00:31 81408 ----a-w- c:\windows\system32\icardie.dll
2013-08-07 00:31 . 2013-08-07 00:31 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-08-07 00:31 . 2013-08-07 00:31 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2013-08-07 00:31 . 2013-08-07 00:31 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-08-07 00:31 . 2013-08-07 00:31 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-08-07 00:31 . 2013-08-07 00:31 62976 ----a-w- c:\windows\system32\pngfilt.dll
2013-08-07 00:31 . 2013-08-07 00:31 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-08-07 00:31 . 2013-08-07 00:31 599552 ----a-w- c:\windows\system32\vbscript.dll
2013-08-07 00:31 . 2013-08-07 00:31 523264 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-08-07 00:31 . 2013-08-07 00:31 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-08-07 00:31 . 2013-08-07 00:31 51200 ----a-w- c:\windows\system32\imgutil.dll
2013-08-07 00:31 . 2013-08-07 00:31 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-08-07 00:31 . 2013-08-07 00:31 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-08-07 00:31 . 2013-08-07 00:31 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2013-08-07 00:31 . 2013-08-07 00:31 441856 ----a-w- c:\windows\system32\html.iec
2013-08-07 00:31 . 2013-08-07 00:31 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-08-07 00:31 . 2013-08-07 00:31 361984 ----a-w- c:\windows\SysWow64\html.iec
2013-08-07 00:31 . 2013-08-07 00:31 281600 ----a-w- c:\windows\system32\dxtrans.dll
2013-08-07 00:31 . 2013-08-07 00:31 27648 ----a-w- c:\windows\system32\licmgr10.dll
2013-08-07 00:31 . 2013-08-07 00:31 270848 ----a-w- c:\windows\system32\iedkcs32.dll
2013-08-07 00:31 . 2013-08-07 00:31 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-08-07 00:31 . 2013-08-07 00:31 235008 ----a-w- c:\windows\system32\url.dll
2013-08-07 00:31 . 2013-08-07 00:31 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-08-07 00:31 . 2013-08-07 00:31 226304 ----a-w- c:\windows\system32\elshyph.dll
2013-08-07 00:31 . 2013-08-07 00:31 216064 ----a-w- c:\windows\system32\msls31.dll
2013-08-07 00:31 . 2013-08-07 00:31 197120 ----a-w- c:\windows\system32\msrating.dll
2013-08-07 00:31 . 2013-08-07 00:31 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-08-07 00:31 . 2013-08-07 00:31 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2013-08-07 00:31 . 2013-08-07 00:31 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-08-07 00:31 . 2013-08-07 00:31 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2013-08-07 00:31 . 2013-08-07 00:31 1509376 ----a-w- c:\windows\system32\inetcpl.cpl
2013-08-07 00:31 . 2013-08-07 00:31 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-08-07 00:31 . 2013-08-07 00:31 149504 ----a-w- c:\windows\system32\occache.dll
2013-08-07 00:31 . 2013-08-07 00:31 144896 ----a-w- c:\windows\system32\wextract.exe
2013-08-07 00:31 . 2013-08-07 00:31 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-08-07 00:31 . 2013-08-07 00:31 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-08-07 00:31 . 2013-08-07 00:31 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2013-08-07 00:31 . 2013-08-07 00:31 13824 ----a-w- c:\windows\system32\mshta.exe
2013-08-07 00:31 . 2013-08-07 00:31 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-08-07 00:31 . 2013-08-07 00:31 136192 ----a-w- c:\windows\system32\iepeers.dll
2013-08-07 00:31 . 2013-08-07 00:31 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-08-07 00:31 . 2013-08-07 00:31 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2013-08-07 00:31 . 2013-08-07 00:31 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2013-08-07 00:31 . 2013-08-07 00:31 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-08-07 00:31 . 2013-08-07 00:31 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-08-07 00:31 . 2013-08-07 00:31 102912 ----a-w- c:\windows\system32\inseng.dll
2013-08-07 00:30 . 2013-08-07 00:30 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2013-08-07 00:30 . 2013-08-07 00:30 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2013-08-07 00:30 . 2013-08-07 00:30 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-08-07 00:30 . 2013-08-07 00:30 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-08-07 00:30 . 2013-08-07 00:30 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-08-07 00:30 . 2013-08-07 00:30 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 3928064 ----a-w- c:\windows\system32\d2d1.dll
2013-08-07 00:30 . 2013-08-07 00:30 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-08-07 00:30 . 2013-08-07 00:30 363008 ----a-w- c:\windows\system32\dxgi.dll
2013-08-07 00:30 . 2013-08-07 00:30 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-07 00:30 . 2013-08-07 00:30 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2013-08-07 00:30 . 2013-08-07 00:30 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2013-09-21 1814440]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-08-01 3673696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-08-06 642216]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"Gaming Mouse Driver"="c:\program files (x86)\Gaming Mouse\Monitor.EXE" [2011-09-09 200704]
"Dolby Home Theater v4"="c:\program files (x86)\Dolby Home Theater v4\pcee4.exe" [2012-04-23 508256]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
GIGABYTE OC_GURU.lnk - c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe [2013-5-22 21946368]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [x]
R3 GPCIDrv;GPCIDrv;c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys;c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Servicio de tecnologías de activación de Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys;c:\program files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-21 18:01 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-10-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-06 22:50]
.
2013-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-06 22:50]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-08-27 1028896]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-06-11 12503184]
"RtHDVBg_Dolby"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2012-06-13 1212560]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 87.216.1.65 87.216.1.66
FF - ProfilePath - c:\users\Xalo\AppData\Roaming\Mozilla\Firefox\Profiles\tjfjxfqy.default\
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-85720637.sys
AddRemove-GOGPACKPAPERSPLEASE_is1 - c:\users\Xalo\Desktop\juegos\papersplease\Papers
AddRemove-Reus 1.0 - c:\users\Xalo\Desktop\juegos\Reus\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-10-03  15:42:04
ComboFix-quarantined-files.txt  2013-10-03 13:42
ComboFix2.txt  2013-09-27 17:51
ComboFix3.txt  2013-09-26 16:24
.
Pre-Run: 81.651.011.584 bytes libres
Post-Run: 81.446.297.600 bytes libres
.
- - End Of File - - FD4A91B4726976FAAC695072270C1661
A36C5E4F47E84449FF07ED3517B43A31

No problems. The warning does not trigger, and no lsm.exe around. :D
Link to post
Share on other sites

  • Staff

Hello

These logs are looking allot better. But we still have some work to do.

Please print out these instructions, or copy them to a Notepad file. It will make it easier for you to follow the instructions and complete all of the necessary steps..

uninstall some programs

NOTE** Because of the cleanup process some of the programs I have listed may not be in add/remove anymore this is fine just move to the next item on the list.

You can remove these programs using add/remove or you can use the free uninstaller from Revo (Revo does allot better of a job)

  • Programs to remove
    • Java 7 Update 25

      Java 7 Update 25 (64-bit)

Please download and install Revo Uninstaller Free

  • Double click Revo Uninstaller to run it.
  • From the list of programs double click on The Program to remove
  • When prompted if you want to uninstall click Yes.
  • Be sure the Moderate option is selected then click Next.
  • The program will run, If prompted again click Yes
  • when the built-in uninstaller is finished click on Next.
  • Once the program has searched for leftovers click Next.
  • Check/tick the bolded items only on the list then click Delete
  • when prompted click on Yes and then on next.
  • put a check on any folders that are found and select delete
  • when prompted select yes then on next
  • Once done click Finish.
.

Install Java:

Please go here to install Java

  • click on the Free Java Download Button
  • click on Agree and start Free download
  • click on Run
  • click on run again
  • click on install
  • when install is complete click on close
Clean Out Temp Files
  • This small application you may want to keep and use once a week to keep the computer clean.

    Download CCleaner from here CCleaner

    • Run the installer to install the application.
    • When it gives you the option to install Yahoo toolbar uncheck the box next to it.
    • Run CCleaner. default settings are fine
    • Click Run Cleaner.
    • Close CCleaner.
: Malwarebytes' Anti-Malware :

I see that you have MBAM installed - That is great!! and at this time I would like you to update it and run me a quick scan

  • Double-click mbam icon
  • go to the update tab at the top
  • click on check for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is Checked (ticked) except items in the C:\System Volume Information folder and click on Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
    • If you accidentally close it, the log file is saved here and will be named like this:
    • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.

Click OK to either and let MBAM proceed with the disinfection process.

If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Download HijackThis

  • Go Here to download HijackThis program
  • Save HijackThis to your desktop.
  • Right Click on Hijackthis and select "Run as Admin" (XP users just need to double click to run)
  • Click on "Do A system scan and save a logfile" (if you do not see "Do A system scan and save a logfile" then click on main menu)
  • copy and paste hijackthis report into the topic
"information and logs"
  • In your next post I need the following
    • Log From MBAM
    • report from Hijackthis
    • let me know of any problems you may have had
    • How is the computer doing now?
Gringo
Link to post
Share on other sites

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
 
Versión de la Base de Datos: v2013.10.04.08
 
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16686
Xalo :: PC1337KILLER360 [administrador]
 
04/10/2013 18:50:54
mbam-log-2013-10-04 (18-50-54).txt
 
Tipos de Análisis: Análisis Rápido
Opciones de análisis activado: Memoria | Inicio | Registro | Sistema de archivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM
Opciones de análisis desactivados: P2P
Objetos examinados: 231869
Tiempo transcurrido: 3 minuto(s), 39 segundo(s)
 
Procesos en Memoria Detectados: 0
(No se han detectado elementos maliciosos)
 
Módulos de Memoria Detectados: 0
(No se han detectado elementos maliciosos)
 
Claves del Registro Detectados: 0
(No se han detectado elementos maliciosos)
 
Valores del Registro Detectados: 0
(No se han detectado elementos maliciosos)
 
Elementos de Datos del Registro Detectados: 0
(No se han detectado elementos maliciosos)
 
Carpetas Detectadas: 0
(No se han detectado elementos maliciosos)
 
Archivos Detectados: 0
(No se han detectado elementos maliciosos)
 
fin)
 






Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:00:14, on 04/10/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16686)
Boot mode: Normal
 
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Gaming Mouse\Monitor.EXE
C:\Program Files (x86)\Gaming Mouse\OSD.exe
C:\Program Files (x86)\Gaming Mouse\Applets\CpuRam.exe
C:\Program Files (x86)\Gaming Mouse\Applets\EmailPOP3.EXE
C:\Program Files (x86)\Gaming Mouse\Applets\OSDSkype.exe
C:\Program Files (x86)\Gaming Mouse\Applets\OSDMSN.EXE
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe
C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Xalo\Desktop\HijackThis.exe
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Gaming Mouse Driver] "C:\Program Files (x86)\Gaming Mouse\Monitor.EXE"
O4 - HKLM\..\Run: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-21-4077817561-2542389710-4094447064-1006\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4077817561-2542389710-4094447064-1006\..\Run: [steam] "C:\Program Files (x86)\Steam\steam.exe" -silent (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4077817561-2542389710-4094447064-1006\..\Run: [DAEMON Tools Ultra Agent] "C:\Program Files (x86)\DAEMON Tools Ultra\DTAgent.exe" -autorun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4077817561-2542389710-4094447064-1006\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Global Startup: GIGABYTE OC_GURU.lnk = C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD FUEL Service - Unknown owner - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: @appmgmts.dll,-3250 (AppMgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (AudioSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\bdesvc.dll,-100 (BDESVC) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (bthserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\cscsvc.dll,-200 (CscService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\ehome\ehrecvr.exe,-101 (ehRecvr) - Unknown owner - C:\Windows\ehome\ehRecvr.exe
O23 - Service: @%SystemRoot%\ehome\ehsched.exe,-101 (ehSched) - Unknown owner - C:\Windows\ehome\ehsched.exe
O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (eventlog) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Servicio de Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Servicio de Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-500 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe
O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\netprofm.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\peerdistsvc.dll,-9000 (PeerDistSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - Unknown owner - C:\Windows\SysWow64\perfhost.exe
O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @regsvc.dll,-1 (RemoteRegistry) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\sensrsvc.dll,-1000 (SensrSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\ipnathlp.dll,-106 (SharedAccess) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppuinotify.dll,-103 (sppuinotify) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\umrdp.dll,-1000 (UmRdpService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 (WinDefend) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe
O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner - C:\Windows\system32\svchost.exe
 
--
End of file - 22034 bytes




No problems. Everything is fine. :D
 
Link to post
Share on other sites

  • Staff

Greetings

These logs are looking very good, we are almost done!!! Just one more scan to go.

:Remove unneeded start-up entries:

This part of the fix is purely optional

These are programs that start up when you turn on your computer but don't need to be, any of these programs you can click on their icons (or start from the control panel) and start the program when you need it. By stopping these programs you will boot up faster and your computer will work faster.

  • Run HijackThis (rightclick and run as admin)
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):
    • O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

      O4 - HKLM\..\Run: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart

      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

      O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

      O4 - HKCU\..\Run: [steam] "C:\Program Files (x86)\Steam\steam.exe" -silent

      O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun

      O4 - HKUS\S-1-5-21-4077817561-2542389710-4094447064-1006\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')

      O4 - HKUS\S-1-5-21-4077817561-2542389710-4094447064-1006\..\Run: [steam] "C:\Program Files (x86)\Steam\steam.exe" -silent (User 'UpdatusUser')

      O4 - HKUS\S-1-5-21-4077817561-2542389710-4094447064-1006\..\Run: [DAEMON Tools Ultra Agent] "C:\Program Files (x86)\DAEMON Tools Ultra\DTAgent.exe" -autorun (User 'UpdatusUser')

      O4 - HKUS\S-1-5-21-4077817561-2542389710-4094447064-1006\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')

      O4 - Global Startup: GIGABYTE OC_GURU.lnk = C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe

  • Close all open windows and browsers/email, etc...
  • Click on the "Fix Checked" button
  • When completed, close the application.

    • NOTE**You can research each of those lines >here< and see if you want to keep them or not

      just copy the name between the brackets and paste into the search space

      O4 - HKLM\..\Run: [IntelliPoint]

Eset Online Scanner

**Note** You will need to use Internet explorer for this scan - Vista and win 7 right click on IE shortcut and run as admin

Go Eset web page to run an online scanner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • click on the Run ESET Online Scanner button
  • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
  • When asked, allow the add/on to be installed
    • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings, ensure the options
    • Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • wait for the virus definitions to be downloaded
  • Wait for the scan to finish
When the scan is complete
  • If no threats were found
    • put a checkmark in "Uninstall application on close"
    • close program
    • report to me that nothing was found
  • If threats were found
    • click on "list of threats found"
    • click on "export to text file" and save it as ESET SCAN and save to the desktop
    • Click on back
    • put a checkmark in "Uninstall application on close"
    • click on finish
    • close program
    • copy and paste the report here
Gringo
Link to post
Share on other sites

List of threats found:  :(

C:\AdwCleaner\Quarantine\C\Users\Xalo\AppData\Roaming\eIntaller\FB317711096649a1B39ABFAE910F09ED\eXQ.exe.vir a variant of Win32/ELEX.D application
C:\FRST\Quarantine\1087115487.exe a variant of Win32/CoinMiner.CF trojan
C:\FRST\Quarantine\1511248043.exe a variant of Win32/CoinMiner.CI trojan
C:\FRST\Quarantine\815707762.exe a variant of Win32/CoinMiner.CI trojan
C:\FRST\Quarantine\cg.exe a variant of Win32/Packed.Themida application
C:\FRST\Quarantine\coin.exe a variant of Win32/CoinMiner.CI trojan
C:\FRST\Quarantine\lsm.exe a variant of Win32/CoinMiner.CI trojan
Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.