17:52:35.0578 1512 Detected object count: 16
17:52:35.0578 1512 Actual detected object count: 16
17:53:57.0783 1512 C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe - copied to quarantine
17:53:57.0859 1512 HKLM\SYSTEM\ControlSet001\services\CFSvcs - will be deleted on reboot
17:53:57.0892 1512 HKLM\SYSTEM\ControlSet002\services\CFSvcs - will be deleted on reboot
17:53:57.0934 1512 HKLM\SYSTEM\ControlSet003\services\CFSvcs - will be deleted on reboot
17:53:57.0973 1512 HKLM\SYSTEM\ControlSet004\services\CFSvcs - will be deleted on reboot
17:53:58.0017 1512 HKLM\SYSTEM\ControlSet005\services\CFSvcs - will be deleted on reboot
17:53:58.0057 1512 HKLM\SYSTEM\ControlSet006\services\CFSvcs - will be deleted on reboot
17:53:58.0078 1512 HKLM\SYSTEM\ControlSet007\services\CFSvcs - will be deleted on reboot
17:53:58.0102 1512 HKLM\SYSTEM\ControlSet008\services\CFSvcs - will be deleted on reboot
17:53:58.0122 1512 HKLM\SYSTEM\ControlSet009\services\CFSvcs - will be deleted on reboot
17:53:58.0153 1512 HKLM\SYSTEM\ControlSet010\services\CFSvcs - will be deleted on reboot
17:53:58.0227 1512 HKLM\SYSTEM\ControlSet011\services\CFSvcs - will be deleted on reboot
17:53:58.0267 1512 C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe - will be deleted on reboot
17:53:58.0267 1512 CFSvcs ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:53:58.0443 1512 C:\Program Files\Intel\Wireless\Bin\EvtEng.exe - copied to quarantine
17:53:58.0575 1512 HKLM\SYSTEM\ControlSet001\services\EvtEng - will be deleted on reboot
17:53:58.0598 1512 HKLM\SYSTEM\ControlSet002\services\EvtEng - will be deleted on reboot
17:53:58.0616 1512 HKLM\SYSTEM\ControlSet003\services\EvtEng - will be deleted on reboot
17:53:58.0632 1512 HKLM\SYSTEM\ControlSet004\services\EvtEng - will be deleted on reboot
17:53:58.0644 1512 HKLM\SYSTEM\ControlSet005\services\EvtEng - will be deleted on reboot
17:53:58.0652 1512 HKLM\SYSTEM\ControlSet006\services\EvtEng - will be deleted on reboot
17:53:58.0660 1512 HKLM\SYSTEM\ControlSet007\services\EvtEng - will be deleted on reboot
17:53:58.0669 1512 HKLM\SYSTEM\ControlSet008\services\EvtEng - will be deleted on reboot
17:53:58.0675 1512 HKLM\SYSTEM\ControlSet009\services\EvtEng - will be deleted on reboot
17:53:58.0686 1512 HKLM\SYSTEM\ControlSet010\services\EvtEng - will be deleted on reboot
17:53:58.0699 1512 HKLM\SYSTEM\ControlSet011\services\EvtEng - will be deleted on reboot
17:53:58.0706 1512 C:\Program Files\Intel\Wireless\Bin\EvtEng.exe - will be deleted on reboot
17:53:58.0706 1512 EvtEng ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:53:58.0813 1512 C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe - copied to quarantine
17:53:58.0857 1512 HKLM\SYSTEM\ControlSet001\services\IDriverT - will be deleted on reboot
17:53:58.0858 1512 HKLM\SYSTEM\ControlSet002\services\IDriverT - will be deleted on reboot
17:53:58.0888 1512 HKLM\SYSTEM\ControlSet003\services\IDriverT - will be deleted on reboot
17:53:58.0904 1512 HKLM\SYSTEM\ControlSet004\services\IDriverT - will be deleted on reboot
17:53:58.0916 1512 HKLM\SYSTEM\ControlSet005\services\IDriverT - will be deleted on reboot
17:53:58.0924 1512 HKLM\SYSTEM\ControlSet006\services\IDriverT - will be deleted on reboot
17:53:58.0932 1512 HKLM\SYSTEM\ControlSet007\services\IDriverT - will be deleted on reboot
17:53:58.0941 1512 HKLM\SYSTEM\ControlSet008\services\IDriverT - will be deleted on reboot
17:53:58.0947 1512 HKLM\SYSTEM\ControlSet009\services\IDriverT - will be deleted on reboot
17:53:58.0959 1512 HKLM\SYSTEM\ControlSet010\services\IDriverT - will be deleted on reboot
17:53:58.0977 1512 HKLM\SYSTEM\ControlSet011\services\IDriverT - will be deleted on reboot
17:53:58.0984 1512 C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe - will be deleted on reboot
17:53:58.0984 1512 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:53:59.0117 1512 C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE - copied to quarantine
17:53:59.0176 1512 HKLM\SYSTEM\ControlSet001\services\IJPLMSVC - will be deleted on reboot
17:53:59.0179 1512 HKLM\SYSTEM\ControlSet010\services\IJPLMSVC - will be deleted on reboot
17:53:59.0181 1512 HKLM\SYSTEM\ControlSet011\services\IJPLMSVC - will be deleted on reboot
17:53:59.0188 1512 C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE - will be deleted on reboot
17:53:59.0188 1512 IJPLMSVC ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:53:59.0809 1512 C:\Windows\system32\drivers\kr10i.sys - copied to quarantine
17:54:00.0041 1512 HKLM\SYSTEM\ControlSet001\services\KR10I - will be deleted on reboot
17:54:00.0071 1512 HKLM\SYSTEM\ControlSet002\services\KR10I - will be deleted on reboot
17:54:00.0072 1512 HKLM\SYSTEM\ControlSet003\services\KR10I - will be deleted on reboot
17:54:00.0072 1512 HKLM\SYSTEM\ControlSet004\services\KR10I - will be deleted on reboot
17:54:00.0073 1512 HKLM\SYSTEM\ControlSet005\services\KR10I - will be deleted on reboot
17:54:00.0073 1512 HKLM\SYSTEM\ControlSet006\services\KR10I - will be deleted on reboot
17:54:00.0074 1512 HKLM\SYSTEM\ControlSet007\services\KR10I - will be deleted on reboot
17:54:00.0074 1512 HKLM\SYSTEM\ControlSet008\services\KR10I - will be deleted on reboot
17:54:00.0075 1512 HKLM\SYSTEM\ControlSet009\services\KR10I - will be deleted on reboot
17:54:00.0088 1512 HKLM\SYSTEM\ControlSet010\services\KR10I - will be deleted on reboot
17:54:00.0090 1512 HKLM\SYSTEM\ControlSet011\services\KR10I - will be deleted on reboot
17:54:00.0097 1512 C:\Windows\system32\drivers\kr10i.sys - will be deleted on reboot
17:54:00.0097 1512 KR10I ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:54:00.0179 1512 C:\Windows\system32\drivers\kr10n.sys - copied to quarantine
17:54:00.0283 1512 HKLM\SYSTEM\ControlSet001\services\KR10N - will be deleted on reboot
17:54:00.0284 1512 HKLM\SYSTEM\ControlSet002\services\KR10N - will be deleted on reboot
17:54:00.0284 1512 HKLM\SYSTEM\ControlSet003\services\KR10N - will be deleted on reboot
17:54:00.0285 1512 HKLM\SYSTEM\ControlSet004\services\KR10N - will be deleted on reboot
17:54:00.0285 1512 HKLM\SYSTEM\ControlSet005\services\KR10N - will be deleted on reboot
17:54:00.0286 1512 HKLM\SYSTEM\ControlSet006\services\KR10N - will be deleted on reboot
17:54:00.0286 1512 HKLM\SYSTEM\ControlSet007\services\KR10N - will be deleted on reboot
17:54:00.0287 1512 HKLM\SYSTEM\ControlSet008\services\KR10N - will be deleted on reboot
17:54:00.0287 1512 HKLM\SYSTEM\ControlSet009\services\KR10N - will be deleted on reboot
17:54:00.0288 1512 HKLM\SYSTEM\ControlSet010\services\KR10N - will be deleted on reboot
17:54:00.0289 1512 HKLM\SYSTEM\ControlSet011\services\KR10N - will be deleted on reboot
17:54:00.0296 1512 C:\Windows\system32\drivers\kr10n.sys - will be deleted on reboot
17:54:00.0296 1512 KR10N ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:54:00.0437 1512 C:\Windows\system32\drivers\kr3npxp.sys - copied to quarantine
17:54:00.0522 1512 HKLM\SYSTEM\ControlSet001\services\KR3NPXP - will be deleted on reboot
17:54:00.0524 1512 HKLM\SYSTEM\ControlSet002\services\KR3NPXP - will be deleted on reboot
17:54:00.0524 1512 HKLM\SYSTEM\ControlSet003\services\KR3NPXP - will be deleted on reboot
17:54:00.0525 1512 HKLM\SYSTEM\ControlSet004\services\KR3NPXP - will be deleted on reboot
17:54:00.0525 1512 HKLM\SYSTEM\ControlSet005\services\KR3NPXP - will be deleted on reboot
17:54:00.0526 1512 HKLM\SYSTEM\ControlSet006\services\KR3NPXP - will be deleted on reboot
17:54:00.0526 1512 HKLM\SYSTEM\ControlSet007\services\KR3NPXP - will be deleted on reboot
17:54:00.0526 1512 HKLM\SYSTEM\ControlSet008\services\KR3NPXP - will be deleted on reboot
17:54:00.0527 1512 HKLM\SYSTEM\ControlSet009\services\KR3NPXP - will be deleted on reboot
17:54:00.0527 1512 HKLM\SYSTEM\ControlSet010\services\KR3NPXP - will be deleted on reboot
17:54:00.0529 1512 HKLM\SYSTEM\ControlSet011\services\KR3NPXP - will be deleted on reboot
17:54:00.0536 1512 C:\Windows\system32\drivers\kr3npxp.sys - will be deleted on reboot
17:54:00.0536 1512 KR3NPXP ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:54:00.0703 1512 C:\Program Files\Common Files\Motive\McciCMService.exe - copied to quarantine
17:54:00.0802 1512 HKLM\SYSTEM\ControlSet001\services\McciCMService - will be deleted on reboot
17:54:00.0805 1512 HKLM\SYSTEM\ControlSet010\services\McciCMService - will be deleted on reboot
17:54:00.0869 1512 HKLM\SYSTEM\ControlSet011\services\McciCMService - will be deleted on reboot
17:54:00.0879 1512 C:\Program Files\Common Files\Motive\McciCMService.exe - will be deleted on reboot
17:54:00.0879 1512 McciCMService ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:54:00.0940 1512 C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS - copied to quarantine
17:54:00.0981 1512 HKLM\SYSTEM\ControlSet001\services\MREMP50 - will be deleted on reboot
17:54:01.0003 1512 HKLM\SYSTEM\ControlSet010\services\MREMP50 - will be deleted on reboot
17:54:01.0006 1512 HKLM\SYSTEM\ControlSet011\services\MREMP50 - will be deleted on reboot
17:54:01.0013 1512 C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS - will be deleted on reboot
17:54:01.0013 1512 MREMP50 ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:54:01.0072 1512 C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS - copied to quarantine
17:54:01.0087 1512 HKLM\SYSTEM\ControlSet001\services\MRESP50 - will be deleted on reboot
17:54:01.0090 1512 HKLM\SYSTEM\ControlSet010\services\MRESP50 - will be deleted on reboot
17:54:01.0091 1512 HKLM\SYSTEM\ControlSet011\services\MRESP50 - will be deleted on reboot
17:54:01.0099 1512 C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS - will be deleted on reboot
17:54:01.0099 1512 MRESP50 ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:54:01.0241 1512 C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe - copied to quarantine
17:54:01.0327 1512 HKLM\SYSTEM\ControlSet001\services\RegSrvc - will be deleted on reboot
17:54:01.0347 1512 HKLM\SYSTEM\ControlSet002\services\RegSrvc - will be deleted on reboot
17:54:01.0354 1512 HKLM\SYSTEM\ControlSet003\services\RegSrvc - will be deleted on reboot
17:54:01.0367 1512 HKLM\SYSTEM\ControlSet004\services\RegSrvc - will be deleted on reboot
17:54:01.0377 1512 HKLM\SYSTEM\ControlSet005\services\RegSrvc - will be deleted on reboot
17:54:01.0386 1512 HKLM\SYSTEM\ControlSet006\services\RegSrvc - will be deleted on reboot
17:54:01.0395 1512 HKLM\SYSTEM\ControlSet007\services\RegSrvc - will be deleted on reboot
17:54:01.0402 1512 HKLM\SYSTEM\ControlSet008\services\RegSrvc - will be deleted on reboot
17:54:01.0408 1512 HKLM\SYSTEM\ControlSet009\services\RegSrvc - will be deleted on reboot
17:54:01.0425 1512 HKLM\SYSTEM\ControlSet010\services\RegSrvc - will be deleted on reboot
17:54:01.0428 1512 HKLM\SYSTEM\ControlSet011\services\RegSrvc - will be deleted on reboot
17:54:01.0435 1512 C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe - will be deleted on reboot
17:54:01.0435 1512 RegSrvc ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:54:01.0819 1512 C:\Windows\system32\Drivers\sptd.sys - copied to quarantine
17:54:01.0903 1512 HKLM\SYSTEM\ControlSet001\services\sptd - will be deleted on reboot
17:54:01.0929 1512 HKLM\SYSTEM\ControlSet002\services\sptd - will be deleted on reboot
17:54:01.0930 1512 HKLM\SYSTEM\ControlSet003\services\sptd - will be deleted on reboot
17:54:01.0930 1512 HKLM\SYSTEM\ControlSet004\services\sptd - will be deleted on reboot
17:54:01.0931 1512 HKLM\SYSTEM\ControlSet005\services\sptd - will be deleted on reboot
17:54:01.0931 1512 HKLM\SYSTEM\ControlSet006\services\sptd - will be deleted on reboot
17:54:01.0932 1512 HKLM\SYSTEM\ControlSet007\services\sptd - will be deleted on reboot
17:54:01.0932 1512 HKLM\SYSTEM\ControlSet008\services\sptd - will be deleted on reboot
17:54:01.0933 1512 HKLM\SYSTEM\ControlSet009\services\sptd - will be deleted on reboot
17:54:01.0999 1512 HKLM\SYSTEM\ControlSet010\services\sptd - will be deleted on reboot
17:54:02.0007 1512 HKLM\SYSTEM\ControlSet011\services\sptd - will be deleted on reboot
17:54:02.0015 1512 C:\Windows\system32\Drivers\sptd.sys - will be deleted on reboot
17:54:02.0015 1512 sptd ( LockedFile.Multi.Generic ) - User select action: Delete
17:54:02.0106 1512 C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe - copied to quarantine
17:54:02.0165 1512 HKLM\SYSTEM\ControlSet001\services\TNaviSrv - will be deleted on reboot
17:54:02.0166 1512 HKLM\SYSTEM\ControlSet002\services\TNaviSrv - will be deleted on reboot
17:54:02.0183 1512 HKLM\SYSTEM\ControlSet003\services\TNaviSrv - will be deleted on reboot
17:54:02.0267 1512 HKLM\SYSTEM\ControlSet004\services\TNaviSrv - will be deleted on reboot
17:54:02.0277 1512 HKLM\SYSTEM\ControlSet005\services\TNaviSrv - will be deleted on reboot
17:54:02.0285 1512 HKLM\SYSTEM\ControlSet006\services\TNaviSrv - will be deleted on reboot
17:54:02.0295 1512 HKLM\SYSTEM\ControlSet007\services\TNaviSrv - will be deleted on reboot
17:54:02.0302 1512 HKLM\SYSTEM\ControlSet008\services\TNaviSrv - will be deleted on reboot
17:54:02.0308 1512 HKLM\SYSTEM\ControlSet009\services\TNaviSrv - will be deleted on reboot
17:54:02.0315 1512 HKLM\SYSTEM\ControlSet010\services\TNaviSrv - will be deleted on reboot
17:54:02.0319 1512 HKLM\SYSTEM\ControlSet011\services\TNaviSrv - will be deleted on reboot
17:54:02.0326 1512 C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe - will be deleted on reboot
17:54:02.0326 1512 TNaviSrv ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:54:02.0403 1512 C:\Windows\system32\TODDSrv.exe - copied to quarantine
17:54:02.0465 1512 HKLM\SYSTEM\ControlSet001\services\TODDSrv - will be deleted on reboot
17:54:02.0466 1512 HKLM\SYSTEM\ControlSet002\services\TODDSrv - will be deleted on reboot
17:54:02.0467 1512 HKLM\SYSTEM\ControlSet003\services\TODDSrv - will be deleted on reboot
17:54:02.0467 1512 HKLM\SYSTEM\ControlSet004\services\TODDSrv - will be deleted on reboot
17:54:02.0468 1512 HKLM\SYSTEM\ControlSet005\services\TODDSrv - will be deleted on reboot
17:54:02.0468 1512 HKLM\SYSTEM\ControlSet006\services\TODDSrv - will be deleted on reboot
17:54:02.0469 1512 HKLM\SYSTEM\ControlSet007\services\TODDSrv - will be deleted on reboot
17:54:02.0469 1512 HKLM\SYSTEM\ControlSet008\services\TODDSrv - will be deleted on reboot
17:54:02.0470 1512 HKLM\SYSTEM\ControlSet009\services\TODDSrv - will be deleted on reboot
17:54:02.0470 1512 HKLM\SYSTEM\ControlSet010\services\TODDSrv - will be deleted on reboot
17:54:02.0472 1512 HKLM\SYSTEM\ControlSet011\services\TODDSrv - will be deleted on reboot
17:54:02.0479 1512 C:\Windows\system32\TODDSrv.exe - will be deleted on reboot
17:54:02.0479 1512 TODDSrv ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:54:02.0612 1512 C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe - copied to quarantine
17:54:02.0679 1512 HKLM\SYSTEM\ControlSet001\services\UleadBurningHelper - will be deleted on reboot
17:54:02.0707 1512 HKLM\SYSTEM\ControlSet002\services\UleadBurningHelper - will be deleted on reboot
17:54:02.0708 1512 HKLM\SYSTEM\ControlSet003\services\UleadBurningHelper - will be deleted on reboot
17:54:02.0708 1512 HKLM\SYSTEM\ControlSet004\services\UleadBurningHelper - will be deleted on reboot
17:54:02.0709 1512 HKLM\SYSTEM\ControlSet005\services\UleadBurningHelper - will be deleted on reboot
17:54:02.0709 1512 HKLM\SYSTEM\ControlSet006\services\UleadBurningHelper - will be deleted on reboot
17:54:02.0709 1512 HKLM\SYSTEM\ControlSet007\services\UleadBurningHelper - will be deleted on reboot
17:54:02.0710 1512 HKLM\SYSTEM\ControlSet008\services\UleadBurningHelper - will be deleted on reboot
17:54:02.0710 1512 HKLM\SYSTEM\ControlSet009\services\UleadBurningHelper - will be deleted on reboot
17:54:02.0711 1512 HKLM\SYSTEM\ControlSet010\services\UleadBurningHelper - will be deleted on reboot
17:54:02.0712 1512 HKLM\SYSTEM\ControlSet011\services\UleadBurningHelper - will be deleted on reboot
17:54:02.0720 1512 C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe - will be deleted on reboot
17:54:02.0720 1512 UleadBurningHelper ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:54:02.0806 1512 C:\Program Files\Viewpoint\Common\ViewpointService.exe - copied to quarantine
17:54:02.0846 1512 HKLM\SYSTEM\ControlSet001\services\Viewpoint Manager Service - will be deleted on reboot
17:54:02.0848 1512 HKLM\SYSTEM\ControlSet002\services\Viewpoint Manager Service - will be deleted on reboot
17:54:02.0883 1512 HKLM\SYSTEM\ControlSet003\services\Viewpoint Manager Service - will be deleted on reboot
17:54:02.0897 1512 HKLM\SYSTEM\ControlSet004\services\Viewpoint Manager Service - will be deleted on reboot
17:54:02.0907 1512 HKLM\SYSTEM\ControlSet005\services\Viewpoint Manager Service - will be deleted on reboot
17:54:02.0915 1512 HKLM\SYSTEM\ControlSet006\services\Viewpoint Manager Service - will be deleted on reboot
17:54:02.0925 1512 HKLM\SYSTEM\ControlSet007\services\Viewpoint Manager Service - will be deleted on reboot
17:54:02.0932 1512 HKLM\SYSTEM\ControlSet008\services\Viewpoint Manager Service - will be deleted on reboot
17:54:02.0938 1512 HKLM\SYSTEM\ControlSet009\services\Viewpoint Manager Service - will be deleted on reboot
17:54:02.0946 1512 HKLM\SYSTEM\ControlSet010\services\Viewpoint Manager Service - will be deleted on reboot
17:54:02.0950 1512 HKLM\SYSTEM\ControlSet011\services\Viewpoint Manager Service - will be deleted on reboot
17:54:02.0957 1512 C:\Program Files\Viewpoint\Common\ViewpointService.exe - will be deleted on reboot
17:54:02.0958 1512 Viewpoint Manager Service ( UnsignedFile.Multi.Generic ) - User select action: Delete
17:54:08.0932 4184 Deinitialize success
And Malwarebytes found this:
Files Detected: 3
C:\Users\Brooke\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001ff (PUP.ToolbarDownloader) -> Quarantined and deleted successfully.
C:\Users\Brooke\AppData\Local\Temp\is1598539481\IWantThis.exe (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
C:\Users\Brooke\Desktop\.junk\SoftonicDownloader_for_kaspersky-tdsskiller.exe (PUP.ToolbarDownloader) -> Quarantined and deleted successfully.
(end)
However I am still having CPU issues but Malwarebytes and other scans have found nothing. Here are the logs from DDS and GMER:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.19222 BrowserJavaVersion: 1.6.0_29
Run by Brooke at 0:54:19 on 2012-05-21
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2038.873 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\locator.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\wbem\WmiApSrv.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\Brooke\Desktop\Defogger.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://centurylink.net
mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
uInternet Settings,ProxyOverride = *.local
mURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTor.dll
BHO: AutorunsDisabled - No File
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTor.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\alwil software\avast5\aswWebRepIE.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\alwil software\avast5\aswWebRepIE.dll
TB: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTor.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [avast] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: intuit.com\ttlc
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 192.168.2.1 75.75.75.75 75.75.76.76
TCP: Interfaces\{1D3A962B-2713-4DFF-BC38-3B4EF66CDBE4} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{A350C129-D04E-4AF1-B585-FEEC3633BD74} : DhcpNameServer = 192.168.2.1 75.75.75.75 75.75.76.76
Handler: AutorunsDisabled\skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\brooke\appdata\roaming\mozilla\firefox\profiles\ba3krz0f.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.centurylink.net/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3072253&SearchSource=2&q=
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\canon\easy-photoprint ex\NPEZFFPI.DLL
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nptgeqplugin.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_235.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-5-18 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-10-3 337880]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-10-3 20696]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-10-3 57688]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-10-3 44768]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2012-5-17 1153368]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2007-6-12 7168]
S3 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-7-25 22344]
S3 SystemExplorerHelpService;System Explorer Service;c:\program files\system explorer\service\SystemExplorerService.exe [2012-5-20 535000]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-23 257696]
S4 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-7-5 21504]
S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-6-16 136176]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-6-16 136176]
S4 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-7-25 654408]
S4 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2012-1-23 92592]
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2012-05-04 23:32:51 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-04 23:32:51 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-04 19:56:40 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-03 08:16:12 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-03 08:16:11 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-02 13:36:21 2044928 ----a-w- c:\windows\system32\win32k.sys
2012-03-30 12:39:11 905600 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-20 23:28:50 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-03-06 23:15:19 41184 ----a-w- c:\windows\avastSS.scr
2012-03-06 23:03:51 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-03-06 23:01:48 57688 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-03-01 14:46:01 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-03-01 14:46:01 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2012-02-29 15:11:45 5120 ----a-w- c:\windows\system32\wmi.dll
2012-02-29 15:11:42 172032 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 15:09:53 157696 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 14:08:47 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2012-02-29 13:44:50 683008 ----a-w- c:\windows\system32\d2d1.dll
2012-02-29 13:41:40 1069056 ----a-w- c:\windows\system32\DWrite.dll
2012-02-29 13:32:37 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-02-28 11:30:48 916992 ----a-w- c:\windows\system32\wininet.dll
2012-02-28 11:25:41 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-02-28 11:25:17 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-02-28 11:25:03 71680 ----a-w- c:\windows\system32\iesetup.dll
2012-02-28 11:25:03 109056 ----a-w- c:\windows\system32\iesysprep.dll
2012-02-28 10:07:57 385024 ----a-w- c:\windows\system32\html.iec
2012-02-28 08:12:52 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2012-02-28 08:08:30 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2012-02-23 14:18:36 237072 ------w- c:\windows\system32\MpSigStub.exe
.
============= FINISH: 0:56:48.35 ===============
I have also been using System Explorer and Process Explorer to look for what is taking up all that space occasionally. And usually it is an svchost.exe process or taskeng.exe process, other times it is explorer.exe or other Toshiba related processes. I feel like I have tried just about every rootkit, virus, or malware remover there is but they all find nothing and I am still having very high CPU spikes and very high CPU usage in general, averaging about 50-60%. Help please
PS. When I first noticed this was happened, I disabled a lot of my startup processes for fear that they were the cause of the issue, or at least contributing to it


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top











