Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help Me With Malware/Slow Problems?


  • Please log in to reply
33 replies to this topic

Poll: What Kinds Of Viruses Do You Get? (2 member(s) have cast votes)

Which Type of Virus Do You Get The Most?

  1. Malware (2 votes [100.00%] - View)

    Percentage of vote: 100.00%

  2. Trojans (0 votes [0.00%])

    Percentage of vote: 0.00%

  3. Ransomware (0 votes [0.00%])

    Percentage of vote: 0.00%

  4. Adware (0 votes [0.00%])

    Percentage of vote: 0.00%

  5. Worms (0 votes [0.00%])

    Percentage of vote: 0.00%

  6. Spyware (0 votes [0.00%])

    Percentage of vote: 0.00%

Vote Guests cannot vote

#1 Gizmo770

Gizmo770

  • Members
  • 52 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Somewhere.
  • Local time:11:51 PM

Posted 22 July 2013 - 06:15 PM

Hi guys, recently I removed some unwanted Malware, Trojans, and Tracking Cookies with Spybot S&D, Hitman Pro, and Malwarebytes. After the removal/quarantine, my laptop has been acting slow, some applications open, but crash after opening. Honestly, most of the pirated games I had had these problems, but one or two legit programs I owned also had the problems, like League of Legends. Malwarebytes quarantined seven "Stolen.Data", One "Rouge.RegClean", and removed Registry Data to disable Microsoft Security Center Notifications. Spybot removed Win32.Downloader.Gen. Hitman's Logs are below.
------------------------------------------------------------------------------------------------------------------------------------
Suspicious files ____________________________________________________________
 
   C:\Users\Giancarlo Garnica\AppData\Local\PunkBuster\BFP4F\pb\dll\wc002304.dll -> Quarantined
      Size . . . . . . . : 954,496 bytes
      Age  . . . . . . . : 251.9 days (2012-11-11 18:15:05)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : EEBDAC091729B0B80A21E14B2CE0392E4584205BA06F5ED1B846C51D034A2177
      Fuzzy  . . . . . . : 29.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
 
   C:\Users\Giancarlo Garnica\AppData\Local\PunkBuster\BFP4F\pb\pbcl.dll -> Quarantined
      Size . . . . . . . : 954,496 bytes
      Age  . . . . . . . : 243.9 days (2012-11-19 19:44:53)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : EEBDAC091729B0B80A21E14B2CE0392E4584205BA06F5ED1B846C51D034A2177
      Fuzzy  . . . . . . : 29.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
 
   C:\Users\Giancarlo Garnica\AppData\Local\PunkBuster\BFP4F\pb\pbclold.dll -> Quarantined
      Size . . . . . . . : 954,496 bytes
      Age  . . . . . . . : 469.6 days (2012-04-08 02:42:07)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : EEBDAC091729B0B80A21E14B2CE0392E4584205BA06F5ED1B846C51D034A2177
      Fuzzy  . . . . . . : 29.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
 
   C:\Users\Giancarlo Garnica\AppData\Local\PunkBuster\BFP4F\pb\PnkBstrK.sys -> PendingDelete
      Size . . . . . . . : 139,424 bytes
      Age  . . . . . . . : 251.9 days (2012-11-11 18:12:13)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : 2A97BC40220EE7B5383991EDB238A70B2D6A7881E54E465999E2EADD6A396029
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
         The file is a device driver. Device drivers run as trusted (highly privileged) code.
         Program is code signed with a valid Authenticode certificate.
 
   C:\Users\Giancarlo Garnica\AppData\Local\PunkBuster\WAW\pb\pbcl.dll -> Quarantined
      Size . . . . . . . : 733,004 bytes
      Age  . . . . . . . : 54.9 days (2013-05-27 18:33:13)
      Entropy  . . . . . : 7.5
      SHA-256  . . . . . : 8715126E77E8E6F98B4487C11B4656ADAC59145A86D56A0370F2FAE86E40FDC7
      Fuzzy  . . . . . . : 25.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
 
 
Potential Unwanted Programs _________________________________________________
 
   C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo) -> Deleted
   C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll (Yontoo) -> Deleted
   C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll (Yontoo) -> Deleted
      Size . . . . . . . : 354,304 bytes
      Age  . . . . . . . : 595.1 days (2011-12-04 13:57:06)
      Entropy  . . . . . : 6.5
      SHA-256  . . . . . : 4755C57C2870090A4871C7ADBA06AB82369443F778517569A87426DD77EB9572
      Fuzzy  . . . . . . : -2.0
 
   C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat (Yontoo) -> Deleted
   C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe (Yontoo) -> Deleted
      Size . . . . . . . : 227,984 bytes
      Age  . . . . . . . : 595.1 days (2011-12-04 13:57:06)
      Entropy  . . . . . : 6.4
      SHA-256  . . . . . : 17936188EFAC05A0EF9FD87A79B268445CE307DD37A6F9206D116F195AB049C9
      Product  . . . . . : Tarma® Installer
      Publisher  . . . . : Tarma Software Research Pty Ltd
      Description  . . . : Tarma® Installer
      Version  . . . . . : 2011.03.11.1355U
      Copyright  . . . . : © 1990-2011 Tarma Software Research Pty Ltd
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -15.0
 
   C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico (Yontoo) -> Deleted
   HKLM\SOFTWARE\Tarma Installer\Components\{9307081B-7444-494C-8CF6-2FA7C0E92BFB}\ (Yontoo) -> Deleted
   HKLM\SOFTWARE\Tarma Installer\Components\{9D9785E5-3424-40B6-A287-BA143AD53109}\ (Yontoo) -> Deleted
   HKLM\SOFTWARE\Tarma Installer\Components\{A8F0AD53-1AEE-447E-89CD-71C325796F84}\ (Yontoo) -> Deleted
   HKLM\SOFTWARE\Tarma Installer\Components\{B6783DFA-B8C8-4CB6-AB9F-EF1A1F7F7AE8}\ (Yontoo) -> Deleted
   HKLM\SOFTWARE\Tarma Installer\Components\{F5F971A9-DBF8-4EEC-81E3-5F1660573E6C}\ (Yontoo) -> Deleted
   HKLM\SOFTWARE\Tarma Installer\Products\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo) -> Deleted
   HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc\ (Yontoo) -> Deleted
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo) -> Deleted
   HKU\S-1-5-21-823395916-568712339-3280133799-1001\Software\Softonic\ (Softonic) -> Deleted
 
Cookies _____________________________________________________________________
 
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:dmtracker.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:fastclick.net
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.freewebs.com
 
 
[/code]
-------------------------------------------------------------------------------------------------
Here's another log below by Hitman a day later.
 

 
HitmanPro 3.7.6.201
www.hitmanpro.com
 
   Computer name . . . . : GIAN
   Windows . . . . . . . : 6.1.1.7601.X64/2
   User name . . . . . . : Gian\Giancarlo Garnica
   UAC . . . . . . . . . : Disabled
   License . . . . . . . : Trial (31 days left)
 
   Scan date . . . . . . : 2013-07-19 19:30:42
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 41m 14s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No
 
   Threats . . . . . . . : 98
   Traces  . . . . . . . : 1976
 
   Objects scanned . . . : 1,954,348
   Files scanned . . . . : 64,257
   Remnants scanned  . . : 620,764 files / 1,269,327 keys
 
Malware _____________________________________________________________________
 
   C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\bin\MenuSystem.dll -> Quarantined
      Size . . . . . . . : 1,658,112 bytes
      Age  . . . . . . . : 1.1 days (2013-07-18 16:13:22)
      Entropy  . . . . . : 7.9
      SHA-256  . . . . . : 479D25D5E4D6DCBDCCC306404257711107F39D07270391FDD426CB9EE5A0858F
      Product  . . . . . : Garry's Mod
      Copyright  . . . . : Facepunch Studios Ltd 2012
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
    > G Data . . . . . . : Gen:Trojan.Heur.LP.LH9aa4U0Fhii
      Fuzzy  . . . . . . : 99.0
      Forensic Cluster
         -9.0s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\1100268990253532387\
         -8.9s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\1100268990253532387\uploads\addons\
         -8.9s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\1100268990253532387\data.vdf
         -8.9s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\1100268990253532387\uploads\
         -8.9s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\1100268990253532387\uploads\addons\1ajybksqfqtiyabtaf1xtdtstf85dh2l.gm
         -1.2s C:\Program Files (x86)\Steam\depotcache\4002_8994349685710801403.manifest
         -1.1s C:\Program Files (x86)\Steam\depotcache\4001_2630004081422662025.manifest
         -0.4s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\base.fgd
         -0.4s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\dxsupport.cfg
         -0.3s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\dxsupport_sp.cfg
         -0.3s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\garrysmod_002.vpk
         -0.3s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\garrysmod_dir.vpk
         -0.3s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\AdminServer.dll
         -0.3s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\bsppack.dll
         -0.3s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\engine.dll
         -0.2s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\FileSystem_Stdio.dll
         -0.2s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\GameUI.dll
         -0.2s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\materialsystem.dll
         -0.2s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\ServerBrowser.dll
         -0.2s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\shaderapidx9.dll
         -0.2s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\shadercompile_dll.dll
         -0.2s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\stdshader_dx8.dll
         -0.2s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\studiorender.dll
         -0.2s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\stdshader_dx9.dll
         -0.1s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\tools\commedit.dll
         -0.1s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\tools\pet.dll
         -0.1s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\tools\vmt.dll
         -0.1s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\vgui2.dll
         -0.0s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\vguimatsurface.dll
         -0.0s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\vtex_dll.dll
         -0.0s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\bin\client.dll
          0.0s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\bin\server.dll
          0.0s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\bin\lua_shared.dll
          0.0s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\bin\lua_shared.dll
          0.0s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\bin\MenuSystem.dll
          0.0s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\bin\resources.dll
          0.3s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\921244714560333447\
          0.3s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\921244714560333447\data.vdf
          0.5s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\921244714560333447\creation\
          0.5s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\921244714560333447\creation\jxtkbjutpvddecpy.main
          1.9s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\vidcfg.bin
          2.4s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\basehaptics.txt
          2.8s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\gamemodes\terrortown\gamemode\shared.lua
          5.2s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\lua\menu\loading.lua
          7.5s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\html\css\menu\PageOptions.css
          7.5s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\html\css\menu\PageOptions.css
          9.1s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\gamemodes\sandbox\gamemode\cl_search_models.lua
          9.1s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\garrysmod.ver
          9.1s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\steam.inf
          9.1s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\gamemodes\sandbox\gamemode\persistence.lua
          9.1s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\gamemodes\sandbox\gamemode\editor_player.lua
          9.3s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\html\css\menu\NavBar.css
          9.3s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\lua\postprocess\bokeh_dof.lua
          9.4s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\halflife2.fgd
          9.7s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\resource\LoadingDialogNoBanner.res
          9.7s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\resource\LoadingDialogNoBannerSingle.res
          9.7s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\dxsupport_episodic.cfg
          9.7s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\dxsupport.csv
          9.8s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\gamemodes\sandbox\gamemode\spawnmenu\creationmenu\content\contentsearch.lua
          9.8s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\gamemodes\terrortown\gamemode\crcs.lua
          9.8s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\lua\vgui\dimage.lua
          9.8s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\resource\LoadingDialogVAC.res
          9.8s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\gamemodes\terrortown\gamemode\init.lua
         10.1s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\html\js\menu\control.Menu.js
         10.2s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\garrysmod\lua\skins\default.lua
         25.4s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\datacache.dll
         42.3s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\542943467842315221\
         42.3s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\542943467842315221\data.vdf
         42.3s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\542943467842315221\creation\
         42.3s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\542943467842315221\creation\ommqehucgqepagat.main
         42.5s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\560966114351025301\
         42.5s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\560966114351025301\data.vdf
         42.5s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\560966114351025301\creation\
         42.5s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\560966114351025301\creation\twrebqndegtfnqjc.main
         43.8s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\576728807178959839\
         43.8s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\576728807178959839\data.vdf
         43.9s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\576728807178959839\uploads\addons\
         43.9s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\576728807178959839\uploads\addons\g26iahojghbqlqvq1a2pfjvudpeaprav.gm
         43.9s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\576728807178959839\uploads\
         71.4s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\901001920661839275\
         71.4s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\901001920661839275\data.vdf
         71.4s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\901001920661839275\uploads\addons\
         71.4s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\901001920661839275\uploads\
         71.4s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\901001920661839275\uploads\addons\vebntlaeetvkb45vi2xwqy2rtpv65sru.gm
         71.8s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\633037019374736869\
         71.8s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\633037019374736869\data.vdf
         71.8s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\633037019374736869\uploads\addons\
         71.8s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\633037019374736869\uploads\addons\dear_sister_swep_v2.gm
         71.8s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\633037019374736869\uploads\
         72.9s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\576728713085087789\
         72.9s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\576728713085087789\data.vdf
         73.0s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\576728713085087789\uploads\
         73.0s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\576728713085087789\uploads\addons\
         73.1s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\866090369318486597\
         73.1s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\866090369318486597\data.vdf
         73.1s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\866090369318486597\data.vdf
         73.1s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\576728713085087789\uploads\addons\yxrdm5raoppphqspuwiogsxdg2kc8wdn.gm
         73.1s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\866090369318486597\uploads\addons\
         73.1s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\866090369318486597\uploads\
         73.2s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\866090369318486597\uploads\addons\a.gm
         73.2s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\866090369318486597\uploads\addons\a.gm
         73.3s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\gmad.exe
         73.5s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\920129449259803548\
         73.6s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\920129449259803548\data.vdf
         73.6s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\558716941409826625\
         73.6s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\558716941409826625\data.vdf
         73.7s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\920129449259803548\uploads\
         73.8s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\920129449259803548\uploads\addons\
         73.8s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\558716941409826625\uploads\addons\
         73.8s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\558716941409826625\uploads\addons\
         73.8s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\920129449259803548\uploads\addons\jcxvhsv8kov5yxbkaykc0heamqijuhvr.gm
         73.8s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\558716941409826625\uploads\addons\bqmkygv4dtwpryjmxkosdkq8o5po2eeq.gm
         73.8s C:\Program Files (x86)\Steam\userdata\91600446\ugc\referenced\558716941409826625\uploads\
         74.5s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\gmod_audio.dll
         75.4s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\gmpublish.exe
         77.0s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\haptics.dll
         78.7s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\inputsystem.dll
         80.4s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\launcher.dll
         80.4s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\launcher.dll
         87.6s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\scenefilecache.dll
         96.2s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\shaderapiempty.dll
         96.7s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\shadercompile.exe
         99.9s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\soundemittersystem.dll
         100.8s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\stdshader_dbg.dll
         101.7s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\stdshader_dx6.dll
         101.7s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\stdshader_dx6.dll
         104.0s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\stdshader_dx7.dll
         104.0s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\stdshader_dx7.dll
         111.2s C:\Program Files (x86)\Steam\steamapps\halopwner770\garrysmod\bin\tier0.dll
 
   C:\Users\Giancarlo Garnica\Desktop\Misc. Apps\Hack-Vision CSS Public 1.1\Hack-Vision CSS Public.dll -> Quarantined
      Size . . . . . . . : 278,528 bytes
      Age  . . . . . . . : 108.9 days (2013-04-01 21:14:08)
      Entropy  . . . . . : 6.6
      SHA-256  . . . . . : 893EF9C3478EDCE902E2920F49828D3BD567926924AD67865D1E4958AFA94739
    > Ikarus . . . . . . : Trojan-Downloader.Win32.Delf!IK
      Fuzzy  . . . . . . : 106.0
 
   C:\Users\Giancarlo Garnica\Desktop\Misc. Apps\Hack-Vision CSS Public 1.1\Hack-Vision CSS Public.exe -> Deleted
      Size . . . . . . . : 67,072 bytes
      Age  . . . . . . . : 108.9 days (2013-04-01 21:14:09)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : A813327485C8CA61CB166095B7BECD7CFA331313BE061EC43F9531621665FB39
    > G Data . . . . . . : Trojan.Generic.1109384 (Engine A)
    > Ikarus . . . . . . : Trojan.Generic!IK
      Fuzzy  . . . . . . : 114.0
 
   C:\Users\Giancarlo Garnica\Desktop\Other Games\The Elder Scrolls V - Skyrim\The Elder Scrolls V Skyrim\steam_api.dll -> Quarantined
      Size . . . . . . . : 178,688 bytes
      Age  . . . . . . . : 63.2 days (2013-05-17 15:45:16)
      Entropy  . . . . . : 6.5
      SHA-256  . . . . . : 5FD5A9DFA514609A2BD6764D04A119A245EAF4B991B0A8DB437FD75C80EFAF9A
    > Ikarus . . . . . . : Win32.Malware!IK
      Fuzzy  . . . . . . : 106.0
 
 
Suspicious files ____________________________________________________________
 
   C:\Users\Giancarlo Garnica\AppData\Local\PunkBuster\BFP4F\pb\dll\wc002304.dll
      Size . . . . . . . : 954,496 bytes
      Age  . . . . . . . : 250.1 days (2012-11-11 18:15:05)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : EEBDAC091729B0B80A21E14B2CE0392E4584205BA06F5ED1B846C51D034A2177
      Fuzzy  . . . . . . : 29.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
 
   C:\Users\Giancarlo Garnica\AppData\Local\PunkBuster\BFP4F\pb\pbcl.dll
      Size . . . . . . . : 954,496 bytes
      Age  . . . . . . . : 242.0 days (2012-11-19 19:44:53)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : EEBDAC091729B0B80A21E14B2CE0392E4584205BA06F5ED1B846C51D034A2177
      Fuzzy  . . . . . . : 29.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
 
   C:\Users\Giancarlo Garnica\AppData\Local\PunkBuster\BFP4F\pb\pbclold.dll
      Size . . . . . . . : 954,496 bytes
      Age  . . . . . . . : 467.7 days (2012-04-08 02:42:07)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : EEBDAC091729B0B80A21E14B2CE0392E4584205BA06F5ED1B846C51D034A2177
      Fuzzy  . . . . . . : 29.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
 
   C:\Users\Giancarlo Garnica\AppData\Local\PunkBuster\BFP4F\pb\PnkBstrK.sys
      Size . . . . . . . : 139,424 bytes
      Age  . . . . . . . : 250.1 days (2012-11-11 18:12:13)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : 2A97BC40220EE7B5383991EDB238A70B2D6A7881E54E465999E2EADD6A396029
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
         The file is a device driver. Device drivers run as trusted (highly privileged) code.
         Program is code signed with a valid Authenticode certificate.
 
   C:\Users\Giancarlo Garnica\AppData\Local\PunkBuster\WAW\pb\pbcl.dll
      Size . . . . . . . : 733,004 bytes
      Age  . . . . . . . : 53.0 days (2013-05-27 18:33:13)
      Entropy  . . . . . : 7.5
      SHA-256  . . . . . : 8715126E77E8E6F98B4487C11B4656ADAC59145A86D56A0370F2FAE86E40FDC7
      Fuzzy  . . . . . . : 25.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Program contains PE structure anomalies. This is not typical for most programs.
 
 
Potential Unwanted Programs _________________________________________________
 
   C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
   C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll (Yontoo)
   C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll (Yontoo)
      Size . . . . . . . : 354,304 bytes
      Age  . . . . . . . : 593.2 days (2011-12-04 13:57:06)
      Entropy  . . . . . : 6.5
      SHA-256  . . . . . : 4755C57C2870090A4871C7ADBA06AB82369443F778517569A87426DD77EB9572
      Fuzzy  . . . . . . : -2.0
 
   C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat (Yontoo)
   C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe (Yontoo)
      Size . . . . . . . : 227,984 bytes
      Age  . . . . . . . : 593.2 days (2011-12-04 13:57:06)
      Entropy  . . . . . : 6.4
      SHA-256  . . . . . : 17936188EFAC05A0EF9FD87A79B268445CE307DD37A6F9206D116F195AB049C9
      Product  . . . . . : Tarma® Installer
      Publisher  . . . . : Tarma Software Research Pty Ltd
      Description  . . . : Tarma® Installer
      Version  . . . . . : 2011.03.11.1355U
      Copyright  . . . . : © 1990-2011 Tarma Software Research Pty Ltd
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -15.0
 
   C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico (Yontoo)
   HKLM\SOFTWARE\Tarma Installer\Components\{9307081B-7444-494C-8CF6-2FA7C0E92BFB}\ (Yontoo)
   HKLM\SOFTWARE\Tarma Installer\Components\{9D9785E5-3424-40B6-A287-BA143AD53109}\ (Yontoo)
   HKLM\SOFTWARE\Tarma Installer\Components\{A8F0AD53-1AEE-447E-89CD-71C325796F84}\ (Yontoo)
   HKLM\SOFTWARE\Tarma Installer\Components\{B6783DFA-B8C8-4CB6-AB9F-EF1A1F7F7AE8}\ (Yontoo)
   HKLM\SOFTWARE\Tarma Installer\Components\{F5F971A9-DBF8-4EEC-81E3-5F1660573E6C}\ (Yontoo)
   HKLM\SOFTWARE\Tarma Installer\Products\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
   HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc\ (Yontoo)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
   HKU\S-1-5-21-823395916-568712339-3280133799-1001\Software\Softonic\ (Softonic)
 
Cookies _____________________________________________________________________
 
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:247realmedia.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:2o7.net
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:a1.interclick.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.intergi.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pointroll.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:adserver.adtechus.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtechus.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:amazonlocal.122.2o7.net
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:apmebf.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:at.atwola.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:atwola.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:collective-media.net
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:dmtracker.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:getclicky.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:in.getclicky.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:interclick.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:invitemedia.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:kontera.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:logoworks.112.2o7.net
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:media6degrees.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:mediaplex.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:microsoftsto.112.2o7.net
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:microsoftwindows.112.2o7.net
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:msnbc.112.2o7.net
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:mswmwpapolloprod.122.2o7.net
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:pcworldcommunication.122.2o7.net
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:pointroll.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:questionmarket.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:realmedia.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:ru4.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:stat.4u.pl
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:statcounter.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:tacoda.at.atwola.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:xiti.com
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:yadro.ru
   C:\Users\Giancarlo Garnica\AppData\Local\Google\Chrome\User Data\Default\Cookies:yieldmanager.net
 
 

 
I have already removed the pirated games due to crashes. Thanks in advance. :)

Edit: Moved topic from Windows 7 to the more appropriate forum. ~ Animal

When the internet actually comes to a close, whenever that happens, just think, how will we live?

~(Myself) Gizmo770


BC AdBot (Login to Remove)

 


#2 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,738 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:09:51 PM

Posted 22 July 2013 - 08:17 PM

p22002970.gif Download Security Check from here or here and save it to your Desktop.

  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
NOTE 2 SecurityCheck may produce some false warning(s), so leave the results reading to me.

p22002970.gif Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


p22002970.gif Please download MiniToolBox and run it.

Checkmark following boxes:
  • Report IE Proxy Settings
  • Report FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices (do NOT change any settings here)
  • List Users, Partitions and Memory size

Click Go and post the result.

p22002970.gif Download Malwarebytes' Anti-Malware (aka MBAM): https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/ to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Be sure to restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

p22002970.gifDownload Malwarebytes Anti-Rootkit from HERE to your Desktop.
  • Unzip downloaded file.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • DO NOT click on the Cleanup button. Simply exit the program.
  • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log-xxxxx.txt and system-log.txt


p22002970.gif Please download Rkill (courtesy of BleepingComputer.com) to your desktop.
There are 2 different versions. If one of them won't run then download and try to run the other one.
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.


If normal mode still doesn't work, run the tool from safe mode.

When the scan is done Notepad will open with rKill log.
Post it in your next reply.

NOTE. rKill.txt log will also be present on your desktop.

NOTE Do NOT wrap your logs in "quote" or "code" brackets.


My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#3 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:12:51 AM

Posted 22 July 2013 - 08:34 PM

Just wanted to add that Hitman removed. Hitman has a lot of false Positives.

The Tarma Installer is a tool for developers to distribute their software. So this is a False Positive. And specifically, it is the _Setupx.dll file that is being detected. This file is accessing privileged areas of the system to perform the install, so that's why it is being flagged as a "Potentially dangerous object".

 

 

And Punkbuster.. PunkBuster is a computer program that is designed to detect software used for cheating in online games. It does this by scanning the memory contents of the local machine. A computer identified as using cheats may be banned from connecting to protected servers. The aim of the program is to isolate cheaters and prevent them from disrupting legitimate games. PunkBuster is developed and published by Even Balance, Inc.

 

http://en.wikipedia.org/wiki/PunkBuster

 

These are legitimate apps to some games. Their remoaval will make some games slow or even unusable.


How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#4 Gizmo770

Gizmo770
  • Topic Starter

  • Members
  • 52 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Somewhere.
  • Local time:11:51 PM

Posted 22 July 2013 - 08:45 PM

Just wanted to add that Hitman removed. Hitman has a lot of false Positives.

The Tarma Installer is a tool for developers to distribute their software. So this is a False Positive. And specifically, it is the _Setupx.dll file that is being detected. This file is accessing privileged areas of the system to perform the install, so that's why it is being flagged as a "Potentially dangerous object".

 

 

And Punkbuster.. PunkBuster is a computer program that is designed to detect software used for cheating in online games. It does this by scanning the memory contents of the local machine. A computer identified as using cheats may be banned from connecting to protected servers. The aim of the program is to isolate cheaters and prevent them from disrupting legitimate games. PunkBuster is developed and published by Even Balance, Inc.

 

http://en.wikipedia.org/wiki/PunkBuster

 

These are legitimate apps to some games. Their remoaval will make some games slow or even unusable.

So, if these files are quarantined, is it okay to put them back?


When the internet actually comes to a close, whenever that happens, just think, how will we live?

~(Myself) Gizmo770


#5 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:12:51 AM

Posted 22 July 2013 - 08:54 PM

If they were originally installed thru legitimate games. If not they can contain malware.
Also do Broni's steps regardless.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#6 Gizmo770

Gizmo770
  • Topic Starter

  • Members
  • 52 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Somewhere.
  • Local time:11:51 PM

Posted 22 July 2013 - 08:56 PM

If they were originally installed thru legitimate games. If not they can contain malware.
Also do Broni's steps regardless.

What games are installed with Tarma Tool, if you know. Thanks. :)

Edit: Nevermind, I already deleted them. If any of my legit games use Tarma, I'll know. Also, CoD W@W also used Punkbuster, and I don't have it anymore. So, yeah...


Edited by Gizmo770, 22 July 2013 - 09:02 PM.

When the internet actually comes to a close, whenever that happens, just think, how will we live?

~(Myself) Gizmo770


#7 Gizmo770

Gizmo770
  • Topic Starter

  • Members
  • 52 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Somewhere.
  • Local time:11:51 PM

Posted 22 July 2013 - 09:24 PM

@Broni,

Is it normal for Security Check to stay on preparing for a while?


When the internet actually comes to a close, whenever that happens, just think, how will we live?

~(Myself) Gizmo770


#8 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,738 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:09:51 PM

Posted 22 July 2013 - 09:53 PM

Try to re-run it.


My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#9 Gizmo770

Gizmo770
  • Topic Starter

  • Members
  • 52 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Somewhere.
  • Local time:11:51 PM

Posted 23 July 2013 - 03:14 PM

 Results of screen317's Security Check version 0.99.70  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 10  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
avast! Antivirus                     
Lavasoft Ad-Aware                    
AVG Internet Security 2012           
Bitdefender Antivirus Free Edition   
Webroot SecureAnywhere               
 Antivirus up to date!  (On Access scanning disabled!) 
`````````Anti-malware/Other Utilities Check:````````` 
 Ad-Aware 
 Spybot - Search & Destroy 
 Malwarebytes Anti-Malware version 1.75.0.1300  
 TuneUp Utilities 2013   
 TuneUp Utilities Language Pack (en-US) 
 TuneUp Utilities 2013   
 Java™ 6 Update 31  
 Java 7 Update 21  
 Java version out of Date! 
 Adobe Flash Player 11.7.700.224  
 Adobe Reader XI  
 Google Chrome 28.0.1500.71  
 Google Chrome 28.0.1500.72  
 Google Chrome plugins...  
````````Process Check: objlist.exe by Laurent````````  
 Ad-Aware AAWService.exe is disabled! 
 Ad-Aware AAWTray.exe is disabled! 
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 0% 
````````````````````End of Log`````````````````````` 
 

 

 

 

Farbar Service Scanner Version: 13-07-2013
Ran by Giancarlo Garnica (administrator) on 23-07-2013 at 12:39:00
Running from "C:\Users\Giancarlo Garnica\Desktop"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
 
Internet Services:
============
 
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
 
 
Windows Firewall:
=============
 
Firewall Disabled Policy: 
==================
 
 
System Restore:
============
 
System Restore Disabled Policy: 
========================
 
 
Action Center:
============
 
 
Windows Update:
============
 
Windows Autoupdate Disabled Policy: 
============================
 
 
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.
 
 
Windows Defender Disabled Policy: 
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
 
 
Other Services:
==============
 
 
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
 
 
**** End of log ****
 
 
 

 

MiniToolBox by Farbar  Version: 13-07-2013
Ran by Giancarlo Garnica (administrator) on 23-07-2013 at 13:21:04
Running from "C:\Users\Giancarlo Garnica\Desktop"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************
 
========================= IE Proxy Settings: ============================== 
 
Proxy is not enabled.
No Proxy Server is set.
 
========================= FF Proxy Settings: ============================== 
 
"network.proxy.type", 0
========================= Hosts content: =================================
 
 
 
========================= IP Configuration: ================================
 
Realtek RTL8188CE 802.11b/g/n WiFi Adapter = Wireless Network Connection (Connected)
Hamachi Network Interface = Local Area Connection 2 (Connected)
Realtek PCIe FE Family Controller = Local Area Connection (Media disconnected)
Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 2 (Media disconnected)
 
 
# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
 
reset
set global icmpredirects=enabled
add route prefix=0.0.0.0/0 interface="ethernet_13" nexthop=5.0.0.1 publish=Yes
add route prefix=0.0.0.0/0 interface="Local Area Connection 2" nexthop=25.0.0.1 publish=Yes
set interface interface="ethernet_13" forwarding=disabled advertise=disabled metric=9000 siteprefixlength=0 nud=disabled routerdiscovery=disabled managedaddress=disabled otherstateful=disabled weakhostsend=disabled weakhostreceive=disabled ignoredefaultroutes=disabled advertisedrouterlifetime=0 advertisedefaultroute=disabled currenthoplimit=0 forcearpndwolpattern=disabled enabledirectedmacwolpattern=disabled
set interface interface="Local Area Connection 2" forwarding=disabled advertise=disabled metric=9000 siteprefixlength=0 nud=disabled routerdiscovery=disabled managedaddress=disabled otherstateful=disabled weakhostsend=disabled weakhostreceive=disabled ignoredefaultroutes=disabled advertisedrouterlifetime=0 advertisedefaultroute=disabled currenthoplimit=0 forcearpndwolpattern=disabled enabledirectedmacwolpattern=disabled
 
 
popd
# End of IPv4 configuration
 
 
 
Windows IP Configuration
 
   Host Name . . . . . . . . . . . . : Gian
   Primary Dns Suffix  . . . . . . . : 
   Node Type . . . . . . . . . . . . : Broadcast
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
 
Ethernet adapter Local Area Connection 2:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Hamachi Network Interface
   Physical Address. . . . . . . . . : 7A-79-19-D0-01-32
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2620:9b::19d0:132(Preferred) 
   Link-local IPv6 Address . . . . . : fe80::4d54:c70e:93e4:6695%19(Preferred) 
   IPv4 Address. . . . . . . . . . . : 25.208.1.50(Preferred) 
   Subnet Mask . . . . . . . . . . . : 255.0.0.0
   Lease Obtained. . . . . . . . . . : Monday, July 22, 2013 10:24:01 PM
   Lease Expires . . . . . . . . . . : Tuesday, July 22, 2014 10:26:16 PM
   Default Gateway . . . . . . . . . : 2620:9b::1900:1
                                       25.0.0.1
   DHCP Server . . . . . . . . . . . : 25.0.0.1
   DHCPv6 IAID . . . . . . . . . . . : 360348005
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-16-0F-5F-E7-D0-DF-9A-AE-74-28
   DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
                                       fec0:0:0:ffff::2%1
                                       fec0:0:0:ffff::3%1
   NetBIOS over Tcpip. . . . . . . . : Enabled
 
Wireless LAN adapter Wireless Network Connection 2:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter
   Physical Address. . . . . . . . . : D0-DF-9A-AE-74-28
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Ethernet adapter Local Area Connection:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Realtek PCIe FE Family Controller
   Physical Address. . . . . . . . . : 2C-76-8A-DB-22-F2
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Wireless LAN adapter Wireless Network Connection:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Realtek RTL8188CE 802.11b/g/n WiFi Adapter
   Physical Address. . . . . . . . . : D0-DF-9A-AE-74-28
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2602:304:b39d:11f9:8c2d:7b1a:ae0d:c6af(Preferred) 
   Temporary IPv6 Address. . . . . . : 2602:304:b39d:11f9:455c:d33e:8864:94c4(Preferred) 
   Link-local IPv6 Address . . . . . : fe80::8c2d:7b1a:ae0d:c6af%11(Preferred) 
   IPv4 Address. . . . . . . . . . . : 192.168.1.109(Preferred) 
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Monday, July 22, 2013 10:24:23 PM
   Lease Expires . . . . . . . . . . : Wednesday, July 24, 2013 10:24:30 AM
   Default Gateway . . . . . . . . . : fe80::22e5:2aff:fe85:2cda%11
                                       192.168.1.254
   DHCP Server . . . . . . . . . . . : 192.168.1.254
   DHCPv6 IAID . . . . . . . . . . . : 248569754
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-16-0F-5F-E7-D0-DF-9A-AE-74-28
   DNS Servers . . . . . . . . . . . : 208.67.222.222
                                       208.67.220.220
   NetBIOS over Tcpip. . . . . . . . : Enabled
 
Tunnel adapter isatap.{ADD5C23D-D0FD-4377-B886-C06C6B2D73DA}:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #3
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter isatap.{99CB48CC-7C08-4A59-8469-27E38902A503}:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #5
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter Local Area Connection* 23:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #6
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter isatap.{75802A72-D719-4B1D-8DC7-9450F482ECC3}:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #8
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter Local Area Connection* 24:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2001:0:4137:9e76:846:2262:b4c6:2ee0(Preferred) 
   Link-local IPv6 Address . . . . . : fe80::846:2262:b4c6:2ee0%35(Preferred) 
   Default Gateway . . . . . . . . . : 
   NetBIOS over Tcpip. . . . . . . . : Disabled
 
Tunnel adapter isatap.{52498BC1-2C43-40FF-B77D-DEE71D30DA1F}:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #9
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
Server:  resolver1.opendns.com
Address:  208.67.222.222
 
Name:    google.com
Addresses:  2607:f8b0:4009:804::1005
 173.194.46.36
 173.194.46.38
 173.194.46.37
 173.194.46.41
 173.194.46.39
 173.194.46.40
 173.194.46.33
 173.194.46.35
 173.194.46.34
 173.194.46.46
 173.194.46.32
 
 
Pinging google.com [2607:f8b0:4009:801::1000] with 32 bytes of data:
Reply from 2607:f8b0:4009:801::1000: time=50ms 
Reply from 2607:f8b0:4009:801::1000: time=30ms 
 
Ping statistics for 2607:f8b0:4009:801::1000:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 30ms, Maximum = 50ms, Average = 40ms
Server:  resolver1.opendns.com
Address:  208.67.222.222
 
Name:    yahoo.com
Addresses:  98.138.253.109
 98.139.183.24
 206.190.36.45
 
 
Pinging yahoo.com [206.190.36.45] with 32 bytes of data:
Reply from 206.190.36.45: bytes=32 time=167ms TTL=45
Reply from 206.190.36.45: bytes=32 time=105ms TTL=45
 
Ping statistics for 206.190.36.45:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 105ms, Maximum = 167ms, Average = 136ms
 
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
 
Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 19...7a 79 19 d0 01 32 ......Hamachi Network Interface
 13...d0 df 9a ae 74 28 ......Microsoft Virtual WiFi Miniport Adapter
 12...2c 76 8a db 22 f2 ......Realtek PCIe FE Family Controller
 11...d0 df 9a ae 74 28 ......Realtek RTL8188CE 802.11b/g/n WiFi Adapter
  1...........................Software Loopback Interface 1
 37...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #3
 34...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #5
 38...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #6
 30...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #8
 35...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
 39...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #9
===========================================================================
 
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0         25.0.0.1      25.208.1.50   9256
          0.0.0.0          0.0.0.0    192.168.1.254    192.168.1.109     30
         25.0.0.0        255.0.0.0         On-link       25.208.1.50   9256
      25.208.1.50  255.255.255.255         On-link       25.208.1.50   9256
   25.255.255.255  255.255.255.255         On-link       25.208.1.50   9256
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.1.0    255.255.255.0         On-link     192.168.1.109    286
    192.168.1.109  255.255.255.255         On-link     192.168.1.109    286
    192.168.1.255  255.255.255.255         On-link     192.168.1.109    286
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link       25.208.1.50   9256
        224.0.0.0        240.0.0.0         On-link     192.168.1.109    286
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link       25.208.1.50   9256
  255.255.255.255  255.255.255.255         On-link     192.168.1.109    286
===========================================================================
Persistent Routes:
  Network Address          Netmask  Gateway Address  Metric
          0.0.0.0          0.0.0.0          5.0.0.1  Default 
          0.0.0.0          0.0.0.0         25.0.0.1  Default 
===========================================================================
 
IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
 19   9020 ::/0                     2620:9b::1900:1
 11    286 ::/0                     fe80::22e5:2aff:fe85:2cda
  1    306 ::1/128                  On-link
 35     58 2001::/32                On-link
 35    306 2001:0:4137:9e76:846:2262:b4c6:2ee0/128
                                    On-link
 11     38 2602:304:b39d:11f9::/64  On-link
 11    286 2602:304:b39d:11f9:455c:d33e:8864:94c4/128
                                    On-link
 11    286 2602:304:b39d:11f9:8c2d:7b1a:ae0d:c6af/128
                                    On-link
 19    276 2620:9b::/96             On-link
 19    276 2620:9b::19d0:132/128    On-link
 19    276 fe80::/64                On-link
 11    286 fe80::/64                On-link
 35    306 fe80::/64                On-link
 35    306 fe80::846:2262:b4c6:2ee0/128
                                    On-link
 19    276 fe80::4d54:c70e:93e4:6695/128
                                    On-link
 11    286 fe80::8c2d:7b1a:ae0d:c6af/128
                                    On-link
  1    306 ff00::/8                 On-link
 35    306 ff00::/8                 On-link
 19    276 ff00::/8                 On-link
 11    286 ff00::/8                 On-link
===========================================================================
Persistent Routes:
 If Metric Network Destination      Gateway
  0 4294967295 2620:9b::/96             On-link
  0   9000 ::/0                     2620:9b::1900:1
===========================================================================
========================= Winsock entries =====================================
 
Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648] (Microsoft Corp.)
Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648] (Microsoft Corp.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760] (Microsoft Corp.)
x64-Catalog5 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760] (Microsoft Corp.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
 
========================= Event log errors: ===============================
 
Application errors:
==================
Error: (07/23/2013 00:37:58 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005
 
Error: (07/23/2013 11:37:09 AM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005
 
Error: (07/23/2013 10:00:58 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "*" of attribute "language" in element "assemblyIdentity" is invalid.
 
Error: (07/22/2013 10:26:24 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/22/2013 09:45:39 PM) (Source: Application Error) (User: )
Description: Faulting application name: csgo.exe, version: 0.0.0.0, time stamp: 0x519a76be
Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec49b8f
Exception code: 0xc0000374
Fault offset: 0x000ce6c3
Faulting process id: 0x1ae0
Faulting application start time: 0xcsgo.exe0
Faulting application path: csgo.exe1
Faulting module path: csgo.exe2
Report Id: csgo.exe3
 
Error: (07/22/2013 09:43:49 PM) (Source: Application Error) (User: )
Description: Faulting application name: csgo.exe, version: 0.0.0.0, time stamp: 0x519a76be
Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec49b8f
Exception code: 0xc0000374
Fault offset: 0x000ce6c3
Faulting process id: 0x18e0
Faulting application start time: 0xcsgo.exe0
Faulting application path: csgo.exe1
Faulting module path: csgo.exe2
Report Id: csgo.exe3
 
Error: (07/22/2013 08:11:28 PM) (Source: Application Error) (User: )
Description: Faulting application name: LoLLauncher.exe, version: 0.0.0.0, time stamp: 0x4f15f44a
Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec49b8f
Exception code: 0xc0000005
Fault offset: 0x000332a0
Faulting process id: 0xd4c
Faulting application start time: 0xLoLLauncher.exe0
Faulting application path: LoLLauncher.exe1
Faulting module path: LoLLauncher.exe2
Report Id: LoLLauncher.exe3
 
Error: (07/22/2013 07:48:35 PM) (Source: Application Error) (User: )
Description: Faulting application name: Steam.exe, version: 1.82.67.49, time stamp: 0x51dcaeb7
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x111efd98
Faulting process id: 0x1bfc
Faulting application start time: 0xSteam.exe0
Faulting application path: Steam.exe1
Faulting module path: Steam.exe2
Report Id: Steam.exe3
 
Error: (07/22/2013 06:51:26 PM) (Source: Application Error) (User: )
Description: Faulting application name: DllHost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bca54
Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e
Exception code: 0xc0000374
Fault offset: 0x00000000000c40f2
Faulting process id: 0x1238
Faulting application start time: 0xDllHost.exe0
Faulting application path: DllHost.exe1
Faulting module path: DllHost.exe2
Report Id: DllHost.exe3
 
Error: (07/22/2013 06:05:32 PM) (Source: Application Error) (User: )
Description: Faulting application name: HitmanPro_x64.exe, version: 3.7.6.201, time stamp: 0x51a8b9ba
Faulting module name: RPCRT4.dll, version: 6.1.7601.17514, time stamp: 0x4ce7c96e
Exception code: 0xc0000005
Fault offset: 0x000000000004818a
Faulting process id: 0x17f4
Faulting application start time: 0xHitmanPro_x64.exe0
Faulting application path: HitmanPro_x64.exe1
Faulting module path: HitmanPro_x64.exe2
Report Id: HitmanPro_x64.exe3
 
 
System errors:
=============
Error: (07/23/2013 01:16:46 PM) (Source: Service Control Manager) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error: 
%%-2140993535
 
Error: (07/23/2013 01:16:46 PM) (Source: Service Control Manager) (User: )
Description: The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: 
%%-2140993535
 
Error: (07/23/2013 01:16:46 PM) (Source: PNRPSvc) (User: )
Description: 0x80630801
 
Error: (07/23/2013 01:16:37 PM) (Source: Service Control Manager) (User: )
Description: The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: 
%%-2140993535
 
Error: (07/23/2013 01:16:37 PM) (Source: Service Control Manager) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error: 
%%-2140993535
 
Error: (07/23/2013 01:16:37 PM) (Source: PNRPSvc) (User: )
Description: 0x80630801
 
Error: (07/23/2013 01:16:36 PM) (Source: Service Control Manager) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error: 
%%-2140993535
 
Error: (07/23/2013 01:16:36 PM) (Source: Service Control Manager) (User: )
Description: The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: 
%%-2140993535
 
Error: (07/23/2013 01:16:36 PM) (Source: PNRPSvc) (User: )
Description: 0x80630801
 
Error: (07/23/2013 01:16:07 PM) (Source: Service Control Manager) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error: 
%%-2140993535
 
 
Microsoft Office Sessions:
=========================
Error: (07/23/2013 00:37:58 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005
 
Error: (07/23/2013 11:37:09 AM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005
 
Error: (07/23/2013 10:00:58 AM) (Source: SideBySide)(User: )
Description: assemblyIdentitylanguage*c:\program files (x86)\spybot - search & destroy\DelZip179.dllc:\program files (x86)\spybot - search & destroy\DelZip179.dll8
 
Error: (07/22/2013 10:26:24 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/22/2013 09:45:39 PM) (Source: Application Error)(User: )
Description: csgo.exe0.0.0.0519a76bentdll.dll6.1.7601.177254ec49b8fc0000374000ce6c31ae001ce874eb3e47361C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exeC:\Windows\SysWOW64\ntdll.dllf4ef0293-f341-11e2-908e-2c768adb22f2
 
Error: (07/22/2013 09:43:49 PM) (Source: Application Error)(User: )
Description: csgo.exe0.0.0.0519a76bentdll.dll6.1.7601.177254ec49b8fc0000374000ce6c318e001ce874e6e5596e5C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exeC:\Windows\SysWOW64\ntdll.dllb3abc7f1-f341-11e2-908e-2c768adb22f2
 
Error: (07/22/2013 08:11:28 PM) (Source: Application Error)(User: )
Description: LoLLauncher.exe0.0.0.04f15f44antdll.dll6.1.7601.177254ec49b8fc0000005000332a0d4c01ce87418954316cC:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.175\deploy\LoLLauncher.exeC:\Windows\SysWOW64\ntdll.dllcca0dcd1-f334-11e2-908e-2c768adb22f2
 
Error: (07/22/2013 07:48:35 PM) (Source: Application Error)(User: )
Description: Steam.exe1.82.67.4951dcaeb7unknown0.0.0.000000000c0000005111efd981bfc01ce8725794aac32C:\Program Files (x86)\Steam\Steam.exeunknown9a6752d5-f331-11e2-908e-2c768adb22f2
 
Error: (07/22/2013 06:51:26 PM) (Source: Application Error)(User: )
Description: DllHost.exe6.1.7600.163854a5bca54ntdll.dll6.1.7601.177254ec4aa8ec000037400000000000c40f2123801ce8736585992f9C:\Windows\system32\DllHost.exeC:\Windows\SYSTEM32\ntdll.dll9ea2cd47-f329-11e2-908e-2c768adb22f2
 
Error: (07/22/2013 06:05:32 PM) (Source: Application Error)(User: )
Description: HitmanPro_x64.exe3.7.6.20151a8b9baRPCRT4.dll6.1.7601.175144ce7c96ec0000005000000000004818a17f401ce872feed4bd1cC:\Users\Giancarlo Garnica\Desktop\Virus Wipers\HitmanPro_x64.exeC:\Windows\system32\RPCRT4.dll34f836df-f323-11e2-908e-2c768adb22f2
 
 
CodeIntegrity Errors:
===================================
  Date: 2013-04-01 15:52:40.091
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\GIANCA~1\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2013-04-01 15:52:39.697
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\GIANCA~1\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2013-04-01 15:52:38.585
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2013-04-01 15:52:38.184
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2013-03-03 21:16:58.391
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\GIANCA~1\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2013-03-03 21:16:58.079
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\GIANCA~1\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2013-03-03 21:16:57.330
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2013-03-03 21:16:57.034
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2013-03-02 14:01:39.377
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\GIANCA~1\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2013-03-02 14:01:39.080
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\GIANCA~1\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
=========================== Installed Programs ============================
 
µTorrent (Version: 3.3.0.29625)
64 Bit HP CIO Components Installer (Version: 7.2.8)
ActiveCheck component for HP Active Support Library (Version: 3.0.0.3)
Ad-Aware Security Add-on (Version: 3.1.0.2)
Adobe AIR (Version: 3.7.0.2090)
Adobe Flash Player 11 ActiveX (Version: 11.7.700.224)
Adobe Flash Player 11 Plugin (Version: 11.7.700.224)
Adobe Reader XI (11.0.03) (Version: 11.0.03)
Adobe Shockwave Player 11.5 (Version: 11.5.8.612)
AMD Accelerated Video Transcoding (Version: 12.10.100.30328)
AMD APP SDK Runtime (Version: 10.0.1084.4)
AMD Catalyst Install Manager (Version: 8.0.911.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Fuel (Version: 2013.0328.2218.38225)
AMD Media Foundation Decoders (Version: 1.0.80328.2204)
AMD Steady Video Plug-In  (Version: 2.06.0000)
AMD VISION Engine Control Center (Version: 2013.0328.2218.38225)
Apple Application Support (Version: 2.3.2)
Apple Mobile Device Support (Version: 6.0.1.3)
Apple Software Update (Version: 2.1.3.127)
avast! Free Antivirus (Version: 8.0.1489.0)
AVG 2012 (Version: 12.0.1873)
AVG 2012 (Version: 12.0.1890)
Bandisoft MPEG-1 Decoder
BioShock (Version: 1.1)
Bitdefender Antivirus Free Edition (Version: 1.0.18.1047)
BitTorrent (Version: 7.8.0.29112)
Bonjour (Version: 3.0.0.10)
BufferChm (Version: 140.0.212.000)
C4700 (Version: 140.0.690.000)
Call of Duty® 4 - Modern Warfare™ 1.6 Patch
Call of Duty® 4 - Modern Warfare™ 1.6 Patch (Version: 1.6)
Call of Duty® 4 - Modern Warfare™ 1.7 Patch
Call of Duty® 4 - Modern Warfare™ 1.7 Patch (Version: 1.7)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (Version: 2013.0328.2218.38225)
Catalyst Control Center InstallProxy (Version: 2013.0328.2218.38225)
Catalyst Control Center Localization All (Version: 2013.0328.2218.38225)
CCC Help Chinese Standard (Version: 2013.0328.2217.38225)
CCC Help Chinese Traditional (Version: 2013.0328.2217.38225)
CCC Help Czech (Version: 2013.0328.2217.38225)
CCC Help Danish (Version: 2013.0328.2217.38225)
CCC Help Dutch (Version: 2013.0328.2217.38225)
CCC Help English (Version: 2013.0328.2217.38225)
CCC Help Finnish (Version: 2013.0328.2217.38225)
CCC Help French (Version: 2013.0328.2217.38225)
CCC Help German (Version: 2013.0328.2217.38225)
CCC Help Greek (Version: 2013.0328.2217.38225)
CCC Help Hungarian (Version: 2013.0328.2217.38225)
CCC Help Italian (Version: 2013.0328.2217.38225)
CCC Help Japanese (Version: 2013.0328.2217.38225)
CCC Help Korean (Version: 2013.0328.2217.38225)
CCC Help Norwegian (Version: 2013.0328.2217.38225)
CCC Help Polish (Version: 2013.0328.2217.38225)
CCC Help Portuguese (Version: 2013.0328.2217.38225)
CCC Help Russian (Version: 2013.0328.2217.38225)
CCC Help Spanish (Version: 2013.0328.2217.38225)
CCC Help Swedish (Version: 2013.0328.2217.38225)
CCC Help Thai (Version: 2013.0328.2217.38225)
CCC Help Turkish (Version: 2013.0328.2217.38225)
ccc-utility64 (Version: 2013.0328.2218.38225)
CCleaner (Version: 3.27)
Cisco EAP-FAST Module (Version: 2.2.14)
Cisco LEAP Module (Version: 1.0.19)
Cisco PEAP Module (Version: 1.1.6)
Counter-Strike: Global Offensive
CyberLink YouCam (Version: 3.2.1.3726)
D3DX10 (Version: 15.4.2368.0902)
DAEMON Tools Lite (Version: 4.47.1.0333)
Destinations (Version: 140.0.77.000)
DeviceDiscovery (Version: 140.0.212.000)
DirectX for Managed Code Update (Summer 2004) (Version: 9.02.2904)
Energy Star Digital Logo (Version: 1.0.1)
ESU for Microsoft Windows 7 (Version: 1.0.0)
Game Booster 3 (Version: 3.4)
Garry's Mod
Glary Utilities 3 (v3.3.0.112) (Version: 3.3.0.112)
Google Chrome (Version: 28.0.1500.72)
GPBaseService2 (Version: 140.0.211.000)
Half-Life 2
Halo Combat Evolved
HP Auto (Version: 1.0.12935.3667)
HP Client Services (Version: 1.0.12656.3472)
HP CloudDrive
HP Customer Experience Enhancements (Version: 6.0.1.7)
HP Customer Participation Program 14.0 (Version: 14.0)
HP Documentation (Version: 1.1.0.0)
HP Imaging Device Functions 14.0 (Version: 14.0)
HP On Screen Display (Version: 1.0.7)
HP Photo Creations (Version: 1.0.0.2024)
HP Photosmart C4700 All-in-One Driver Software 14.0 Rel. 6 (Version: 14.0)
HP Power Manager (Version: 1.2.1)
HP Product Detection (Version: 11.15.0007)
HP Quick Launch (Version: 2.3.6)
HP Setup (Version: 8.6.4516.3597)
HP Setup Manager (Version: 1.1.13155.3599)
HP Smart Web Printing 4.60 (Version: 4.60)
HP Software Framework (Version: 4.0.108.1)
HP Solution Center 14.0 (Version: 14.0)
HP Support Assistant (Version: 5.1.11.1)
HP Update (Version: 5.005.000.002)
HP Wireless Assistant (Version: 4.0.10.0)
HPAsset component for HP Active Support Library (Version: 3.0.2.2)
HPDiagnosticAlert (Version: 1.00.0000)
HPPhotoGadget (Version: 140.0.524.000)
HPProductAssistant (Version: 140.0.212.000)
HPSSupply (Version: 140.0.211.000)
iExplorer 3.2.1.5
iTunes (Version: 11.0.1.12)
Java 7 Update 21 (Version: 7.0.210)
Java Auto Updater (Version: 2.1.9.5)
Java™ 6 Update 22 (64-bit) (Version: 6.0.220)
Java™ 6 Update 31 (Version: 6.0.310)
Junk Mail filter update (Version: 16.4.3505.0912)
League of Legends (Version: 3.0.0)
Left 4 Dead 2
Left 4 Dead 2 Add-on Support
Left 4 Dead 2 Dedicated Server
LogMeIn Hamachi (Version: 2.1.0.374)
Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
MarketResearch (Version: 140.0.212.000)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft AppLocale (Version: 1.0.0)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SkyDrive (Version: 16.4.6013.0910)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Windows Application Compatibility Database
Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0)
Microsoft XNA Framework Redistributable 4.0 (Version: 4.0.20823.0)
MotioninJoy Gamepad tool 0.7.1001 (Version: 0.7.1001)
Movie Maker (Version: 16.4.3505.0912)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT_amd64 (Version: 15.4.2862.0708)
MSVCRT110 (Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 4.0 SP2 Parser and SDK (Version: 4.20.9818.0)
MX-900 Editor (Version: 1.10.044)
Network64 (Version: 140.0.215.000)
Network64 (Version: 140.0.221.000)
OpenAL
Origin (Version: 8.3.7.3619)
Paint.NET v3.5.10 (Version: 3.60.0)
Pando Media Booster (Version: 2.3.6.0)
Photo Gallery (Version: 16.4.3505.0912)
PictureMover (Version: 3.5.0.35)
PlayReady PC Runtime x86 (Version: 1.3.0)
Portal 2
PS_AIO_06_C4700_SW_Min (Version: 140.0.690.000)
QuickTime (Version: 7.71.80.42)
QuickTransfer (Version: 140.0.98.000)
Realtek Ethernet Controller Driver (Version: 7.42.304.2011)
Realtek High Definition Audio Driver (Version: 6.0.1.6287)
Realtek PCIE Card Reader (Version: 6.1.7600.77)
REALTEK Wireless LAN Driver (Version: 1.00.10.0416)
Recovery Manager (Version: 1.0.22)
Registry Repair 4.1.0.388 (Version: 4.1.0.388)
ROBLOX Player
ROBLOX Studio 2013
RPG Maker VX Ace (Version: 1.01)
RPG MAKER VX Ace RTP (Version: 1.00)
Scan (Version: 140.0.80.000)
Shop for HP Supplies (Version: 14.0)
Skype™ 6.3 (Version: 6.3.107)
SmartWebPrinting (Version: 140.0.186.000)
SolutionCenter (Version: 140.0.213.000)
Source Filmmaker
Source SDK Base 2007
Spybot - Search & Destroy (Version: 1.6.2)
Status (Version: 140.0.212.000)
Steam (Version: 1.0.0.0)
Synaptics Pointing Device Driver (Version: 15.2.4.3)
System Requirements Lab Detection (Version: 1.0.5.0)
Team Fortress 2
TeamViewer 8 (Version: 8.0.16642)
Terraria
TexMex
The Sims 2 Open For Business
The Sims 2 University
Toolbox (Version: 140.0.428.000)
TrayApp (Version: 140.0.212.000)
TuneUp Utilities 2013 (Version: 13.0.3020.7)
TuneUp Utilities Language Pack (en-US) (Version: 13.0.3020.7)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1)
Visual Studio 2008 x64 Redistributables (Version: 10.0.0.2)
VLC media player 2.0.7 (Version: 2.0.7)
Warframe
WebReg (Version: 140.0.212.017)
Webroot SecureAnywhere (Version: 8.0.2.155)
Windows Driver Package - CDC Driver (usbser) Ports  (10/15/2009 1.0.0.0) (Version: 10/15/2009 1.0.0.0)
Windows Driver Package - FTDI CDM Driver Package (10/22/2009 2.06.00) (Version: 10/22/2009 2.06.00)
Windows Live Communications Platform (Version: 16.4.3505.0912)
Windows Live Essentials (Version: 16.4.3505.0912)
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0)
Windows Live Installer (Version: 16.4.3505.0912)
Windows Live Mail (Version: 16.4.3505.0912)
Windows Live Messenger (Version: 16.4.3505.0912)
Windows Live MIME IFilter (Version: 16.4.3505.0912)
Windows Live Photo Common (Version: 16.4.3505.0912)
Windows Live PIMT Platform (Version: 16.4.3505.0912)
Windows Live SOXE (Version: 16.4.3505.0912)
Windows Live SOXE Definitions (Version: 16.4.3505.0912)
Windows Live UX Platform (Version: 16.4.3505.0912)
Windows Live UX Platform Language Pack (Version: 16.4.3505.0912)
Windows Live Writer (Version: 16.4.3505.0912)
Windows Live Writer Resources (Version: 16.4.3505.0912)
WinRAR 4.01 (32-bit) (Version: 4.01.0)
Xfire 2.0 (Version: 2.0)
Xfire Codec (remove only)
 
========================= Devices: ================================
 
Name: Photosmart C6300 series
Description: Photosmart C6300 series
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service: 
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: Photosmart 5510d series
Description: Photosmart 5510d series
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service: 
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: Photosmart C4700 series
Description: Photosmart C4700 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Deskjet 3050 J610 series
Description: Deskjet 3050 J610 series
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service: 
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
========================= Memory info: ===================================
 
Percentage of memory in use: 77%
Total physical RAM: 2666.91 MB
Available physical RAM: 590.61 MB
Total Pagefile: 5332 MB
Available Pagefile: 2272.89 MB
Total Virtual: 4095.88 MB
Available Virtual: 3953.7 MB
 
========================= Partitions: =====================================
 
1 Drive c: () (Fixed) (Total:284.06 GB) (Free:82.81 GB) NTFS
2 Drive d: (RECOVERY) (Fixed) (Total:13.73 GB) (Free:1.7 GB) NTFS
3 Drive e: (Sims2DoubleDeluxe) (CDROM) (Total:5.55 GB) (Free:0 GB) UDF
 
========================= Users: ========================================
 
User accounts for \\GIAN
 
Administrator            Giancarlo Garnica        Guest                    
 
 
**** End of log ****
 

 

 

 

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
 
Database version: v2013.07.23.06
 
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16635
Giancarlo Garnica :: GIAN [administrator]
 
7/23/2013 1:28:50 PM
mbam-log-2013-07-23 (13-28-50).txt
 
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 264525
Time elapsed: 18 minute(s), 30 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
(end)
 

 

 

 

Malwarebytes Anti-Rootkit BETA 1.06.0.1004
www.malwarebytes.org
 
Database version: v2013.07.23.07
 
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16635
Giancarlo Garnica :: GIAN [administrator]
 
7/23/2013 1:59:02 PM
mbar-log-2013-07-23 (13-59-02).txt
 
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P
Scan options disabled: PUP
Objects scanned: 294270
Time elapsed: 39 minute(s), 24 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
Physical Sectors Detected: 0
(No malicious items detected)
 
(end)
 

 

 

 

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.06.0.1004
 
© Malwarebytes Corporation 2011-2012
 
OS version: 6.1.7601 Windows 7 Service Pack 1 x64
 
Account is Administrative
 
Internet Explorer version: 10.0.9200.16635
 
Java version: 1.6.0_31
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
CPU speed: 1.596000 GHz
Memory total: 2796453888, free: 709668864
 
Downloaded database version: v2013.07.23.07
Downloaded database version: v2013.07.15.01
Initializing...
------------ Kernel report ------------
     07/23/2013 13:58:28
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_AuthenticAMD.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\system32\drivers\gfibto.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\DRIVERS\trufos.sys
\SystemRoot\system32\DRIVERS\FLTMGR.SYS
\SystemRoot\system32\drivers\compbatt.sys
\SystemRoot\system32\drivers\BATTC.SYS
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\msahci.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\system32\DRIVERS\amd_sata.sys
\SystemRoot\system32\DRIVERS\storport.sys
\SystemRoot\system32\DRIVERS\amd_xata.sys
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\system32\DRIVERS\avc3.sys
\SystemRoot\System32\drivers\WRkrn.sys
\SystemRoot\System32\drivers\msrpc.sys
\SystemRoot\System32\drivers\NETIO.SYS
\SystemRoot\System32\drivers\NDIS.SYS
\SystemRoot\System32\drivers\TDI.SYS
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\System32\Drivers\aswVmm.sys
\SystemRoot\System32\Drivers\aswRvrt.sys
\SystemRoot\system32\DRIVERS\dtsoftbus01.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\System32\Drivers\aswSnx.SYS
\SystemRoot\system32\DRIVERS\gzflt.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\??\C:\Windows\system32\drivers\avgtpx64.sys
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\??\C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\System32\Drivers\aswTdi.SYS
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\Drivers\aswrdr2.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\drivers\blbdrive.sys
\SystemRoot\System32\Drivers\aswSP.SYS
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\amdppm.sys
\SystemRoot\system32\DRIVERS\atikmpag.sys
\SystemRoot\system32\DRIVERS\atikmdag.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\DRIVERS\usbohci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbfilter.sys
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\drivers\CmBatt.sys
\SystemRoot\system32\drivers\i8042prt.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\SynTP.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\RtsPStor.sys
\SystemRoot\system32\DRIVERS\Rt64win7.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\system32\DRIVERS\rtl8192Ce.sys
\SystemRoot\system32\DRIVERS\vwifibus.sys
\SystemRoot\system32\drivers\wmiacpi.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\clwvd.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\hamachi.sys
\SystemRoot\system32\DRIVERS\cbfs3.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\udfs.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_diskdump.sys
\SystemRoot\System32\Drivers\dump_amd_sata.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\??\C:\Windows\system32\drivers\aswMonFlt.sys
\??\C:\Windows\system32\drivers\mbam.sys
\SystemRoot\System32\Drivers\aswFsBlk.SYS
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\avckf.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\??\C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys
\SystemRoot\system32\DRIVERS\cdfs.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\mbamswissarmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\rpcrt4.dll
\Windows\System32\user32.dll
\Windows\System32\sechost.dll
\Windows\System32\urlmon.dll
\Windows\System32\kernel32.dll
\Windows\System32\Wldap32.dll
\Windows\System32\msctf.dll
\Windows\System32\msvcrt.dll
\Windows\System32\ws2_32.dll
\Windows\System32\ole32.dll
\Windows\System32\gdi32.dll
\Windows\System32\psapi.dll
\Windows\System32\setupapi.dll
\Windows\System32\imm32.dll
\Windows\System32\iertutil.dll
\Windows\System32\lpk.dll
\Windows\System32\wininet.dll
\Windows\System32\shlwapi.dll
\Windows\System32\nsi.dll
\Windows\System32\clbcatq.dll
\Windows\System32\oleaut32.dll
\Windows\System32\shell32.dll
\Windows\System32\comdlg32.dll
\Windows\System32\usp10.dll
\Windows\System32\normaliz.dll
\Windows\System32\difxapi.dll
\Windows\System32\imagehlp.dll
\Windows\System32\advapi32.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\wintrust.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\KernelBase.dll
\Windows\System32\devobj.dll
\Windows\System32\crypt32.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\comctl32.dll
\Windows\System32\msasn1.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa80030bb060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\0000007a\
Lower Device Object: 0xfffffa8002e356d0
Lower Device Driver Name: \Driver\amd_sata\
<<<2>>>
Device number: 0, partition: 2
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa80030bb060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa80030bbb90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa80030bb060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8002f97040, DeviceName: Unknown, DriverName: \Driver\amd_xata\
DevicePointer: 0xfffffa8002e356d0, DeviceName: \Device\0000007a\, DriverName: \Driver\amd_sata\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
Device number: 0, partition: 2
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\Windows\system32\drivers...
<<<2>>>
Device number: 0, partition: 2
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 20ED0ABE
 
Partition information:
 
    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 2048  Numsec = 407552
    Partition file system is NTFS
    Partition is bootable
 
    Partition 1 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 409600  Numsec = 595718144
 
    Partition 2 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 596127744  Numsec = 28801024
 
    Partition 3 type is Other (0xc)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 624928768  Numsec = 211632
 
Disk Size: 320072933376 bytes
Sector size: 512 bytes
 
Scanning physical sectors of unpartitioned space on drive 0 (1-2047-625122448-625142448)...
Done!
Scan finished
=======================================
 
 
Removal queue found; removal started
Removing c:\programdata\malwarebytes' anti-malware (portable)\mbr_0_i.mbam...
Removing c:\programdata\malwarebytes' anti-malware (portable)\bootstrap_0_0_2048_i.mbam...
Removing c:\programdata\malwarebytes' anti-malware (portable)\mbr_0_r.mbam...
Removal finished
 

 

 

 

Rkill 2.5.7 by Lawrence Abrams (Grinler)
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
 
Program started at: 07/23/2013 02:56:49 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1
 
Checking for Windows services to stop:
 
 * No malware services found to stop.
 
Checking for processes to terminate:
 
 * No malware processes found to kill.
 
Checking Registry for malware related settings:
 
 * No issues found in the Registry.
 
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
 
Performing miscellaneous checks:
 
 * Windows Defender Disabled
 
   [HKLM\SOFTWARE\Microsoft\Windows Defender]
   "DisableAntiSpyware" = dword:00000001
 
Checking Windows Service Integrity: 
 
 * Windows Defender (WinDefend) is not Running.
   Startup Type set to: Manual
 
Searching for Missing Digital Signatures: 
 
 * No issues found.
 
Checking HOSTS File: 
 
 * No issues found.
 
Program finished at: 07/23/2013 03:03:15 PM
Execution time: 0 hours(s), 6 minute(s), and 26 seconds(s)

When the internet actually comes to a close, whenever that happens, just think, how will we live?

~(Myself) Gizmo770


#10 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,738 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:09:51 PM

Posted 23 July 2013 - 07:50 PM

p22002970.gif You're running FIVE AV programs!

That's the most I've ever seen :)

 

avast! Antivirus                     
Lavasoft Ad-Aware                    
AVG Internet Security 2012           
Bitdefender Antivirus Free Edition   
Webroot SecureAnywhere          

 

You must uninstall FOUR of them.

If AVG is one of them use AVG Remover: http://www.avg.com/us-en/utilities

 

When done....

 

p22002970.gif Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
Double click on TFC.exe to run the program.
Click on Start button to begin cleaning process.
TFC will close all running programs, and it may ask you to restart computer.

=============================================================================

p22002970.gif Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.


=============================================================================

p22002970.gif Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


=======================================

p22002970.gif Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click on List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    NOTE. If Eset doesn't find any threats it'll NOT produce any log.


My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#11 Gizmo770

Gizmo770
  • Topic Starter

  • Members
  • 52 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Somewhere.
  • Local time:11:51 PM

Posted 23 July 2013 - 11:09 PM

p22002970.gif You're running FIVE AV programs!

That's the most I've ever seen :)

 

avast! Antivirus                     
Lavasoft Ad-Aware                    
AVG Internet Security 2012           
Bitdefender Antivirus Free Edition   
Webroot SecureAnywhere          

 

You must uninstall FOUR of them.

If AVG is one of them use AVG Remover: http://www.avg.com/us-en/utilities

Yeah, sorry about that, I got paranoid after a couple attacks. Webroot, I can't uninstall for some reason. Probably a corrupted install. I'm too lazy to uninstall it, and really, I never have it open, and I already found a complicated uninstall forum with a guy who had the same problem... Is it okay if I leave that on and Bitdefender too? I feel that avast! isn't enough...


When the internet actually comes to a close, whenever that happens, just think, how will we live?

~(Myself) Gizmo770


#12 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,738 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:09:51 PM

Posted 23 July 2013 - 11:21 PM

No. We can't proceed until I see only one AV running.


My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#13 Gizmo770

Gizmo770
  • Topic Starter

  • Members
  • 52 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Somewhere.
  • Local time:11:51 PM

Posted 23 July 2013 - 11:42 PM

No. We can't proceed until I see only one AV running.

Sorry, >.< even Webroot?


When the internet actually comes to a close, whenever that happens, just think, how will we live?

~(Myself) Gizmo770


#14 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,738 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:09:51 PM

Posted 23 July 2013 - 11:47 PM

You can have only one AV program running.

 

When done with uninstalling four of them post new Security Check log.


My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#15 Gizmo770

Gizmo770
  • Topic Starter

  • Members
  • 52 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Somewhere.
  • Local time:11:51 PM

Posted 24 July 2013 - 04:32 PM

p22002970.gif You're running FIVE AV programs!

That's the most I've ever seen :)

 

avast! Antivirus                     
Lavasoft Ad-Aware                    
AVG Internet Security 2012           
Bitdefender Antivirus Free Edition   
Webroot SecureAnywhere          

 

You must uninstall FOUR of them.

If AVG is one of them use AVG Remover: http://www.avg.com/us-en/utilities

 

When done....

 

p22002970.gif Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
Double click on TFC.exe to run the program.
Click on Start button to begin cleaning process.
TFC will close all running programs, and it may ask you to restart computer.

=============================================================================

p22002970.gif Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.


=============================================================================

p22002970.gif Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


=======================================

p22002970.gif Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click on List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    NOTE. If Eset doesn't find any threats it'll NOT produce any log.

 

Should I remove the threats found by ESETScan?


When the internet actually comes to a close, whenever that happens, just think, how will we live?

~(Myself) Gizmo770





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users