Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Random Sounds (Name Not Available on Sound Mixer)


  • Please log in to reply
18 replies to this topic

#1 thegreatneedshelp

thegreatneedshelp

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Philippines
  • Local time:02:00 PM

Posted 25 September 2013 - 07:13 AM

Hello. I need some help on my computer because it plays random sounds and ads that I don't even understand. I need some help in removing this virus because it is very irritating. I know that it is adware but please help me solve it. I've tried MBAM, Avast Free Antivirus, Kaspersky Pure 3.0, Norton 360, Super AntiSpyware, AdwCleaner, Rogue Cleaner and even Bit Defender Total Security 2014. Now I am currently trying Avira Free Antivirus because I am desperate to lose this virus. Please help me, although I am not sure whether I can log in daily to this forum and I don't understand the Log Thingy .. :( And also may I just ask, upto how many antivirus(es) can I install because I already have BitDefender Total Security 2014 :(


Edited by thegreatneedshelp, 25 September 2013 - 07:16 AM.


BC AdBot (Login to Remove)

 


#2 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,725 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:11:00 PM

Posted 25 September 2013 - 10:46 PM

Welcome aboard p22002758.gif

 

p22002970.gif Download Security Check from here or here and save it to your Desktop.

  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
NOTE 2 SecurityCheck may produce some false warning(s), so leave the results reading to me.

p22002970.gif Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


p22002970.gif Please download MiniToolBox and run it.

Checkmark following boxes:
  • Report IE Proxy Settings
  • Report FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices (do NOT change any settings here)
  • List Users, Partitions and Memory size

Click Go and post the result.

p22002970.gif Download Malwarebytes' Anti-Malware (aka MBAM): https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/ to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Be sure to restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

p22002970.gifDownload Malwarebytes Anti-Rootkit from HERE to your Desktop.
  • Unzip downloaded file.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • DO NOT click on the Cleanup button. Simply exit the program.
  • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log-xxxxx.txt and system-log.txt


p22002970.gif Please download Rkill (courtesy of BleepingComputer.com) to your desktop.
There are 2 different versions. If one of them won't run then download and try to run the other one.
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.


If normal mode still doesn't work, run the tool from safe mode.

When the scan is done Notepad will open with rKill log.
Post it in your next reply.

NOTE. rKill.txt log will also be present on your desktop.

NOTE Do NOT wrap your logs in "quote" or "code" brackets.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#3 kdblup

kdblup

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:11:00 PM

Posted 26 September 2013 - 12:58 AM

Hi Broni, I am having the same issues as the original poster as well.  The problem is that I can't download ANYTHING as I get an error saying the download contained a virus.  No way to override it. From researching it seems like this is the malware as well. Any suggestions to a work around without a 2nd computer?



#4 thegreatneedshelp

thegreatneedshelp
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Philippines
  • Local time:02:00 PM

Posted 26 September 2013 - 03:17 AM

Hello. Thanks for replying.. So here's the logs 
Security Check Log
 Results of screen317's Security Check version 0.99.73  
   x64 (UAC is enabled)  
 Internet Explorer 10  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Security Center service is not running! This report may not be accurate! 
 Windows Firewall Disabled!  
Windows Defender        
Bitdefender Antivirus   
 Antivirus out of date! (On Access scanning disabled!) 
`````````Anti-malware/Other Utilities Check:````````` 
 Java™ SE Runtime Environment 6 Update 1 
 Java version out of Date! 
 Adobe Flash Player 11.8.800.168  
 Adobe Reader XI  
 Mozilla Firefox 21.0 Firefox out of Date!  
 Google Chrome 29.0.1547.66  
 Google Chrome 29.0.1547.76  
````````Process Check: objlist.exe by Laurent````````  
 Bitdefender Bitdefender vsserv.exe  
 Bitdefender Bitdefender updatesrv.exe  
 Bitdefender Bitdefender SafeBox safeboxservice.exe  
 Bitdefender Bitdefender bdagent.exe  
 Bitdefender Bitdefender pmbxag.exe  
 Bitdefender Bitdefender antispam32 bdapppassmgr.exe 
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  % 
````````````````````End of Log`````````````````````` 
 

FSS Log

Farbar Service Scanner Version: 13-09-2013
Ran by Windows 8 (administrator) on 26-09-2013 at 16:05:58
Running from "C:\Users\noreen quilario\Downloads"
Microsoft Windows 8 Single Language  (X64)
Boot Mode: Normal
****************************************************************
 
Internet Services:
============
 
Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is offline
Google.com is accessible.
Yahoo.com is accessible.
 
 
Windows Firewall:
=============
 
Firewall Disabled Policy: 
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0
 
 
System Restore:
============
 
System Restore Disabled Policy: 
========================
 
 
Action Center:
============
 
 
Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is set to Demand. The default start type is Auto.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.
 
 
Windows Autoupdate Disabled Policy: 
============================
 
 
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend: ""%ProgramFiles%\Windows Defender\MsMpEng.exe"".
 
 
Windows Defender Disabled Policy: 
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
 
 
Other Services:
==============
 
 
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll
[2013-09-12 14:23] - [2013-06-11 03:15] - 0723968 ____A (Microsoft Corporation) 73133A0C0CA63817BFF2CB9DE65B64E7
 
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll
[2013-09-12 14:26] - [2013-08-16 13:21] - 3275776 ____A (Microsoft Corporation) 9DEC60D4783377097014DFCCA31E69F8
 
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MsMpEng.exe => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
 
 
**** End of log ****
 

MiniToolBox Log
 

MiniToolBox by Farbar  Version: 13-07-2013
Ran by Windows 8 (administrator) on 26-09-2013 at 16:08:26
Running from "C:\Users\noreen quilario\Downloads"
Microsoft Windows 8 Single Language  (X64)
Boot Mode: Normal
***************************************************************************
 
========================= IE Proxy Settings: ============================== 
 
Proxy is not enabled.
No Proxy Server is set.
 
========================= FF Proxy Settings: ============================== 
 
========================= Hosts content: =================================
#74.208.105.171 gs.apple.com
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com
127.0.0.1 adobe.activate.com
127.0.0.1 hl2rcv.adobe.com
127.0.0.1 209.34.83.73:443
127.0.0.1 209.34.83.73:43
127.0.0.1 209.34.83.73
 
There are 10 more lines starting with "127.0.0.1"
 
========================= IP Configuration: ================================
 
Realtek PCIe GBE Family Controller = Ethernet (Connected)
Qualcomm Atheros AR9285 Wireless Network Adapter = Wi-Fi (Media disconnected)
 
 
# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
 
reset
set global icmpredirects=enabled
set interface interface="Local Area Connection* 9" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Wi-Fi" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Ethernet" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 11" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 12" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="other_0" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 13" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
 
 
popd
# End of IPv4 configuration
 
 
 
Windows IP Configuration
 
   Host Name . . . . . . . . . . . . : noreen
   Primary Dns Suffix  . . . . . . . : 
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
 
Wireless LAN adapter Local Area Connection* 13:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft Hosted Network Virtual Adapter
   Physical Address. . . . . . . . . : 52-B7-C3-ED-2F-D3
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Wireless LAN adapter Local Area Connection* 11:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter
   Physical Address. . . . . . . . . : 12-B7-C3-ED-2F-D3
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Ethernet adapter Ethernet:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
   Physical Address. . . . . . . . . : 50-B7-C3-0A-43-28
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::d5d7:633a:5396:59a6%13(Preferred) 
   IPv4 Address. . . . . . . . . . . : 192.168.0.103(Preferred) 
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Thursday, September 26, 2013 4:02:13 PM
   Lease Expires . . . . . . . . . . : Thursday, September 26, 2013 6:02:12 PM
   Default Gateway . . . . . . . . . : 192.168.0.1
   DHCP Server . . . . . . . . . . . : 192.168.0.1
   DHCPv6 IAID . . . . . . . . . . . : 352321776
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-19-17-54-50-50-B7-C3-0A-43-28
   DNS Servers . . . . . . . . . . . : 192.168.0.1
   NetBIOS over Tcpip. . . . . . . . : Enabled
 
Wireless LAN adapter Wi-Fi:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Qualcomm Atheros AR9285 Wireless Network Adapter
   Physical Address. . . . . . . . . : 50-B7-C3-ED-2F-D3
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter isatap.{96396D24-C908-418F-B6A9-8E1C5B11E0B7}:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter Teredo Tunneling Pseudo-Interface:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2001:0:4137:9e76:2428:2bb0:8f2f:b00c(Preferred) 
   Link-local IPv6 Address . . . . . : fe80::2428:2bb0:8f2f:b00c%17(Preferred) 
   Default Gateway . . . . . . . . . : ::
   NetBIOS over Tcpip. . . . . . . . : Disabled
Server:  UnKnown
Address:  192.168.0.1
 
Name:    google.com
Addresses:  2404:6800:4005:c00::65
 173.194.127.103
 173.194.127.104
 173.194.127.105
 173.194.127.110
 173.194.127.96
 173.194.127.97
 173.194.127.98
 173.194.127.99
 173.194.127.100
 173.194.127.101
 173.194.127.102
 
 
Pinging google.com [173.194.127.198] with 32 bytes of data:
Request timed out.
Reply from 173.194.127.198: bytes=32 time=25ms TTL=55
 
Ping statistics for 173.194.127.198:
    Packets: Sent = 2, Received = 1, Lost = 1 (50% loss),
Approximate round trip times in milli-seconds:
    Minimum = 25ms, Maximum = 25ms, Average = 25ms
Server:  UnKnown
Address:  192.168.0.1
 
Name:    yahoo.com
Addresses:  98.139.183.24
 206.190.36.45
 98.138.253.109
 
 
Pinging yahoo.com [206.190.36.45] with 32 bytes of data:
Reply from 206.190.36.45: bytes=32 time=203ms TTL=47
Reply from 206.190.36.45: bytes=32 time=245ms TTL=47
 
Ping statistics for 206.190.36.45:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 203ms, Maximum = 245ms, Average = 224ms
 
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
 
Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 21...52 b7 c3 ed 2f d3 ......Microsoft Hosted Network Virtual Adapter
 14...12 b7 c3 ed 2f d3 ......Microsoft Wi-Fi Direct Virtual Adapter
 13...50 b7 c3 0a 43 28 ......Realtek PCIe GBE Family Controller
 12...50 b7 c3 ed 2f d3 ......Qualcomm Atheros AR9285 Wireless Network Adapter
  1...........................Software Loopback Interface 1
 16...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
 17...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================
 
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.0.1    192.168.0.103     20
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.0.0    255.255.255.0         On-link     192.168.0.103    276
    192.168.0.103  255.255.255.255         On-link     192.168.0.103    276
    192.168.0.255  255.255.255.255         On-link     192.168.0.103    276
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link     192.168.0.103    276
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link     192.168.0.103    276
===========================================================================
Persistent Routes:
  None
 
IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
 17    306 ::/0                     On-link
  1    306 ::1/128                  On-link
 17    306 2001::/32                On-link
 17    306 2001:0:4137:9e76:2428:2bb0:8f2f:b00c/128
                                    On-link
 13    276 fe80::/64                On-link
 17    306 fe80::/64                On-link
 17    306 fe80::2428:2bb0:8f2f:b00c/128
                                    On-link
 13    276 fe80::d5d7:633a:5396:59a6/128
                                    On-link
  1    306 ff00::/8                 On-link
 17    306 ff00::/8                 On-link
 13    276 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================
 
Catalog5 01 C:\windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\windows\SysWOW64\pnrpnsp.dll [67584] (Microsoft Corporation)
Catalog5 03 C:\windows\SysWOW64\pnrpnsp.dll [67584] (Microsoft Corporation)
Catalog5 04 C:\windows\SysWOW64\NLAapi.dll [55296] (Microsoft Corporation)
Catalog5 05 C:\windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog5 06 C:\windows\SysWOW64\winrnr.dll [21504] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 C:\windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 02 C:\windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 03 C:\windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 04 C:\windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 05 C:\windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 06 C:\windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 07 C:\windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 08 C:\windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 09 C:\windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
Catalog9 10 C:\windows\SysWOW64\mswsock.dll [289280] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\napinsp.dll [66560] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\pnrpnsp.dll [85504] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [85504] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\NLAapi.dll [72192] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [53760] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation)
 
========================= Event log errors: ===============================
 
Application errors:
==================
Error: (09/25/2013 07:53:48 PM) (Source: Application Error) (User: )
Description: Faulting application name: Quick Starter.exe, version: 1.0.0.19, time stamp: 0x5049b514
Faulting module name: Quick Starter.exe, version: 1.0.0.19, time stamp: 0x5049b514
Exception code: 0xc0000005
Fault offset: 0x000000000004ca2c
Faulting process id: 0x1220
Faulting application start time: 0xQuick Starter.exe0
Faulting application path: Quick Starter.exe1
Faulting module path: Quick Starter.exe2
Report Id: Quick Starter.exe3
Faulting package full name: Quick Starter.exe4
Faulting package-relative application ID: Quick Starter.exe5
 
Error: (09/23/2013 05:40:59 PM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe, version: 6.2.9200.16420, time stamp: 0x505a9a4e
Faulting module name: AppXDeploymentClient.dll, version: 6.2.9200.16384, time stamp: 0x501086e3
Exception code: 0xc0000005
Fault offset: 0x000000000001644f
Faulting process id: 0x53c
Faulting application start time: 0xsvchost.exe0
Faulting application path: svchost.exe1
Faulting module path: svchost.exe2
Report Id: svchost.exe3
Faulting package full name: svchost.exe4
Faulting package-relative application ID: svchost.exe5
 
Error: (09/23/2013 10:36:57 AM) (Source: Application Error) (User: )
Description: Faulting application name: Photoshop.exe, version: 13.0.1.0, time stamp: 0x5022da9d
Faulting module name: ntdll.dll, version: 6.2.9200.16579, time stamp: 0x51637f77
Exception code: 0xc0000374
Fault offset: 0x00000000000ebd59
Faulting process id: 0x1404
Faulting application start time: 0xPhotoshop.exe0
Faulting application path: Photoshop.exe1
Faulting module path: Photoshop.exe2
Report Id: Photoshop.exe3
Faulting package full name: Photoshop.exe4
Faulting package-relative application ID: Photoshop.exe5
 
Error: (09/19/2013 07:46:20 PM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {66681f8a-ed16-4b56-b7a1-ad58915a3ee0}
 
Error: (09/18/2013 06:40:21 PM) (Source: Application Error) (User: )
Description: Faulting application name: chrome.exe, version: 29.0.1547.66, time stamp: 0x5224d150
Faulting module name: webplayer_win.dll, version: 4.2.1.11687, time stamp: 0x521c68ef
Exception code: 0xc0000005
Fault offset: 0x00229371
Faulting process id: 0x78c
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
Faulting package full name: chrome.exe4
Faulting package-relative application ID: chrome.exe5
 
Error: (09/18/2013 04:44:45 PM) (Source: Application Error) (User: )
Description: Faulting application name: chrome.exe, version: 29.0.1547.66, time stamp: 0x5224d150
Faulting module name: webplayer_win.dll, version: 4.2.1.11687, time stamp: 0x521c68ef
Exception code: 0xc0000005
Fault offset: 0x00229371
Faulting process id: 0x1088
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
Faulting package full name: chrome.exe4
Faulting package-relative application ID: chrome.exe5
 
Error: (09/17/2013 07:47:13 AM) (Source: Application Error) (User: )
Description: Faulting application name: N360.exe, version: 12.10.0.42, time stamp: 0x5202e8a2
Faulting module name: msvcrt.dll, version: 7.0.9200.16384, time stamp: 0x5010ae12
Exception code: 0xc0000005
Fault offset: 0x0000b22e
Faulting process id: 0x920
Faulting application start time: 0xN360.exe0
Faulting application path: N360.exe1
Faulting module path: N360.exe2
Report Id: N360.exe3
Faulting package full name: N360.exe4
Faulting package-relative application ID: N360.exe5
 
Error: (09/16/2013 08:11:31 PM) (Source: Application Hang) (User: )
Description: The program javaw.exe version 6.0.10.6 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 13b4
 
Start Time: 01ceb2d312c8d38f
 
Termination Time: 10
 
Application Path: C:\Program Files (x86)\Java\jre1.6.0_01\bin\javaw.exe
 
Report Id: 113a5f27-1ec9-11e3-bfdf-50b7c30a4328
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (09/16/2013 05:06:05 PM) (Source: Application Hang) (User: )
Description: The program AvastUI.exe version 8.0.1497.376 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1270
 
Start Time: 01ceb2b65b2dc354
 
Termination Time: 38261
 
Application Path: C:\Program Files\AVAST Software\Avast\AvastUI.exe
 
Report Id: 1df07ab8-1eaf-11e3-bfdc-50b7c30a4328
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (09/13/2013 01:53:33 PM) (Source: .NET Runtime) (User: )
Description: Application: CCC.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.ObjectDisposedException
Stack:
   at System.Windows.Forms.Control.MarshaledInvoke(System.Windows.Forms.Control, System.Delegate, System.Object[], Boolean)
   at System.Windows.Forms.Control.Invoke(System.Delegate, System.Object[])
   at ATI.ACE.AEM.Plugin.Source.Kit.Server.Common.WindowBasedFeeler.Close()
   at ATI.ACE.AEM.Plugin.Source.Kit.Server.EEU.PI_EEUPlugin.Stop()
   at ATI.ACE.AEM.Server.ACEEventManager.Stop()
   at ATI.ACE.CLI.Component.Runtime.Runtime.Cleanup()
   at ATI.ACE.CLI.Component.Runtime.Shared.Private.RTComponent.Destroy()
   at ATI.ACE.CCC.Implementation.CCC_Main.CCCNewThreadBegin(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Threading.ThreadHelper.ThreadStart(System.Object)
 
 
System errors:
=============
Error: (09/26/2013 06:39:39 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
 
Error: (09/26/2013 06:39:38 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
 
Error: (09/25/2013 07:56:38 PM) (Source: Service Control Manager) (User: )
Description: The Toolbar Updater service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (09/23/2013 06:03:51 PM) (Source: DCOM) (User: noreen)
Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (09/23/2013 06:03:44 PM) (Source: DCOM) (User: noreen)
Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (09/23/2013 06:03:38 PM) (Source: DCOM) (User: noreen)
Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (09/23/2013 06:03:32 PM) (Source: DCOM) (User: noreen)
Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (09/23/2013 06:03:26 PM) (Source: DCOM) (User: noreen)
Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (09/23/2013 06:03:16 PM) (Source: DCOM) (User: noreen)
Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (09/23/2013 06:03:13 PM) (Source: DCOM) (User: noreen)
Description: 1084WSearchUnavailable{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
 
 
Microsoft Office Sessions:
=========================
Error: (09/25/2013 07:53:48 PM) (Source: Application Error)(User: )
Description: Quick Starter.exe1.0.0.195049b514Quick Starter.exe1.0.0.195049b514c0000005000000000004ca2c122001ceb9d12cec9357C:\Program Files (x86)\Samsung\Quick Starter\Quick Starter.exeC:\Program Files (x86)\Samsung\Quick Starter\Quick Starter.exe22d80415-25d9-11e3-bffb-50b7c30a4328
 
Error: (09/23/2013 05:40:59 PM) (Source: Application Error)(User: )
Description: svchost.exe6.2.9200.16420505a9a4eAppXDeploymentClient.dll6.2.9200.16384501086e3c0000005000000000001644f53c01ceb8345644a148C:\windows\system32\svchost.exeC:\Windows\System32\AppXDeploymentClient.dll4056a7cb-2434-11e3-bff1-50b7c30a4328
 
Error: (09/23/2013 10:36:57 AM) (Source: Application Error)(User: )
Description: Photoshop.exe13.0.1.05022da9dntdll.dll6.2.9200.1657951637f77c000037400000000000ebd59140401ceb7f90d5bdc5cC:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\Photoshop.exeC:\windows\SYSTEM32\ntdll.dll03c340a2-23f9-11e3-bfef-50b7c30a4328
 
Error: (09/19/2013 07:46:20 PM) (Source: VSS)(User: )
Description: 0x80070005, Access is denied.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {66681f8a-ed16-4b56-b7a1-ad58915a3ee0}
 
Error: (09/18/2013 06:40:21 PM) (Source: Application Error)(User: )
Description: chrome.exe29.0.1547.665224d150webplayer_win.dll4.2.1.11687521c68efc00000050022937178c01ceb45a59e9a1d1C:\Program Files (x86)\Google\Chrome\Application\chrome.exeC:\Users\noreen quilario\AppData\LocalLow\Unity\WebPlayer\player\Release3.x.x\webplayer_win.dllb72d247f-204e-11e3-bfe5-50b7c30a4328
 
Error: (09/18/2013 04:44:45 PM) (Source: Application Error)(User: )
Description: chrome.exe29.0.1547.665224d150webplayer_win.dll4.2.1.11687521c68efc000000500229371108801ceb44aca3e6596C:\Program Files (x86)\Google\Chrome\Application\chrome.exeC:\Users\noreen quilario\AppData\LocalLow\Unity\WebPlayer\player\Release3.x.x\webplayer_win.dll911225f3-203e-11e3-bfe5-50b7c30a4328
 
Error: (09/17/2013 07:47:13 AM) (Source: Application Error)(User: )
Description: N360.exe12.10.0.425202e8a2msvcrt.dll7.0.9200.163845010ae12c00000050000b22e92001ceb32da1805a54C:\Program Files (x86)\Norton 360\Engine\21.0.1.3\N360.exeC:\windows\SYSTEM32\msvcrt.dll4f0a7a5e-1f2a-11e3-bfe0-50b7c30a4328
 
Error: (09/16/2013 08:11:31 PM) (Source: Application Hang)(User: )
Description: javaw.exe6.0.10.613b401ceb2d312c8d38f10C:\Program Files (x86)\Java\jre1.6.0_01\bin\javaw.exe113a5f27-1ec9-11e3-bfdf-50b7c30a4328
 
Error: (09/16/2013 05:06:05 PM) (Source: Application Hang)(User: )
Description: AvastUI.exe8.0.1497.376127001ceb2b65b2dc35438261C:\Program Files\AVAST Software\Avast\AvastUI.exe1df07ab8-1eaf-11e3-bfdc-50b7c30a4328
 
Error: (09/13/2013 01:53:33 PM) (Source: .NET Runtime)(User: )
Description: Application: CCC.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.ObjectDisposedException
Stack:
   at System.Windows.Forms.Control.MarshaledInvoke(System.Windows.Forms.Control, System.Delegate, System.Object[], Boolean)
   at System.Windows.Forms.Control.Invoke(System.Delegate, System.Object[])
   at ATI.ACE.AEM.Plugin.Source.Kit.Server.Common.WindowBasedFeeler.Close()
   at ATI.ACE.AEM.Plugin.Source.Kit.Server.EEU.PI_EEUPlugin.Stop()
   at ATI.ACE.AEM.Server.ACEEventManager.Stop()
   at ATI.ACE.CLI.Component.Runtime.Runtime.Cleanup()
   at ATI.ACE.CLI.Component.Runtime.Shared.Private.RTComponent.Destroy()
   at ATI.ACE.CCC.Implementation.CCC_Main.CCCNewThreadBegin(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Threading.ThreadHelper.ThreadStart(System.Object)
 
 
=========================== Installed Programs ============================
 
???? ????? (Version: 16.4.3503.0728)
µTorrent (Version: 3.3.0.29625)
ABBYY FineReader 9.0 Sprint (Version: 9.01.506.5829)
Adobe After Effects CS6 (Version: 11)
Adobe AIR (Version: 3.1.0.4880)
Adobe Audition CS6 (Version: 5.0)
Adobe Dreamweaver CS6 (Version: 12)
Adobe Flash Player 11 Plugin (Version: 11.8.800.168)
Adobe Flash Professional CS6 (Version: 12.0)
Adobe Help Manager (Version: 4.0.244)
Adobe Illustrator CS6 (Version: 16.0)
Adobe Photoshop CS6 (Version: 13.0)
Adobe Premiere Pro CS6 (Version: 6.0)
Adobe Reader XI (11.0.02) (Version: 11.0.02)
Adobe Widget Browser (Version: 2.0 Build 348)
Adobe Widget Browser (Version: 2.0.348)
AMD APP SDK Runtime (Version: 10.0.938.2)
AMD Catalyst Install Manager (Version: 8.0.881.0)
Apple Application Support (Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (Version: 2.1.3.127)
Audacity 2.0.3 (Version: 2.0.3)
Avira SearchFree Toolbar (Version: 12.5.1.1249)
Bitcasa version 0.9.20.4133 (Version: 0.9.20.4133)
Bitdefender Total Security (Version: 17.15.0.682)
bl (Version: 1.0.0)
Bonjour (Version: 3.0.0.10)
BufferChm (Version: 90.0.146.000)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center (Version: 2012.0806.1156.19437)
Catalyst Control Center InstallProxy (Version: 2012.0806.1156.19437)
Catalyst Control Center Localization All (Version: 2012.0806.1156.19437)
CCC Help Chinese Standard (Version: 2012.0806.1155.19437)
CCC Help Chinese Traditional (Version: 2012.0806.1155.19437)
CCC Help Czech (Version: 2012.0806.1155.19437)
CCC Help Danish (Version: 2012.0806.1155.19437)
CCC Help Dutch (Version: 2012.0806.1155.19437)
CCC Help English (Version: 2012.0806.1155.19437)
CCC Help Finnish (Version: 2012.0806.1155.19437)
CCC Help French (Version: 2012.0806.1155.19437)
CCC Help German (Version: 2012.0806.1155.19437)
CCC Help Greek (Version: 2012.0806.1155.19437)
CCC Help Hungarian (Version: 2012.0806.1155.19437)
CCC Help Italian (Version: 2012.0806.1155.19437)
CCC Help Japanese (Version: 2012.0806.1155.19437)
CCC Help Korean (Version: 2012.0806.1155.19437)
CCC Help Norwegian (Version: 2012.0806.1155.19437)
CCC Help Polish (Version: 2012.0806.1155.19437)
CCC Help Portuguese (Version: 2012.0806.1155.19437)
CCC Help Russian (Version: 2012.0806.1155.19437)
CCC Help Spanish (Version: 2012.0806.1155.19437)
CCC Help Swedish (Version: 2012.0806.1155.19437)
CCC Help Thai (Version: 2012.0806.1155.19437)
CCC Help Turkish (Version: 2012.0806.1155.19437)
ccc-utility64 (Version: 2012.0806.1156.19437)
CustomerResearchQFolder (Version: 1.00.0000)
CyberLink Power2Go 8 (Version: 8.0.0.1912)
CyberLink PowerDVD 10 (Version: 10.0.4421.02)
D2400 (Version: 90.0.200.000)
D2400_Help (Version: 90.0.200.000)
D3DX10 (Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
DeviceDiscovery (Version: 90.0.146.000)
DeviceManagementQFolder (Version: 1.00.0000)
dj_sf_ProductContext (Version: 90.0.200.000)
dj_sf_software (Version: 90.0.200.000)
dj_sf_software_req (Version: 90.0.200.000)
Easy File Share (Version: 1.3.6)
E-POP (Version: 1.0.1)
Epson Easy Photo Print 2 (Version: 2.2.0.0)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (Version: 1.00.0000)
Epson Event Manager (Version: 2.40.0001)
EPSON ME 320 Series Manual
EPSON ME 320 Series Printer Uninstall
EPSON Scan
eSupportQFolder (Version: 1.00.0000)
Euro Truck Simulator 2 (Version: 1.2.5)
Free YouTube Downloader 3.5.136
GlassFish Server Open Source Edition 3.1
Google Chrome (Version: 29.0.1547.76)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.5.4413.1752)
Graphmatica
HangARoo v2.052
Help Desk (Version: 1.0.8)
HP Customer Participation Program 9.0 (Version: 9.0)
HP Deskjet Printer Driver Software 9.0 (Version: 9.0)
HP Imaging Device Functions 9.0 (Version: 9.0)
HP Photosmart Essential 2.01 (Version: 2.01)
HP Photosmart Essential2.01 (Version: 1.01.0000)
HP Solution Center 9.0 (Version: 9.0)
HP Update (Version: 4.000.006.002)
HPProductAssistant (Version: 90.0.146.000)
HPSSupply (Version: 2.2.0.0000)
Intel AppUp(SM) center (Version: 3.6.1.33070.11)
Intel® Management Engine Components (Version: 8.1.0.1252)
Intel® Trusted Connect Service Client (Version: 1.24.388.1)
iTunes (Version: 11.0.2.26)
Java 7 Update 25 (64-bit) (Version: 7.0.250)
Java SE Development Kit 7 Update 25 (64-bit) (Version: 1.7.0.250)
Java™ SE Runtime Environment 6 Update 1 (Version: 1.6.0.10)
K-Lite Mega Codec Pack 8.4.0 (Version: 8.4.0)
LAME v3.99.3 (for Windows)
MarketResearch (Version: 90.0.146.000)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office (Version: 14.0.6120.5004)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Home and Student 2010 (Version: 14.0.6029.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Single Image 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft_VC80_CRT_x86 (Version: 8.0.50727.4053)
Microsoft_VC90_CRT_x86 (Version: 1.00.0000)
Movie Maker (Version: 16.4.3503.0728)
Mozilla Firefox 21.0 (x86 en-US) (Version: 21.0)
MP3 Rocket
MSVCRT (Version: 15.4.2862.0708)
MSVCRT Redists (Version: 1.0)
MSVCRT110 (Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1108.0727)
NetBeans IDE 7.0 (Version: 7.0)
Opera 12.15 (Version: 12.15.1748)
PanoStandAlone (Version: 90.0.146.000)
PDF Settings CS6 (Version: 11.0)
ph (Version: 1.0.0)
PHASE 3 VASP
Photo Common (Version: 16.4.3503.0728)
Photo Gallery (Version: 16.4.3503.0728)
PSSWCORE (Version: 2.01.0000)
Qualcomm Atheros Client Installation Program (Version: 10.0)
Quick Starter (Version: 1.0.0)
QuickTime (Version: 7.74.80.86)
Realtek Ethernet Controller Driver (Version: 8.4.907.2012)
Recovery (Version: 6.0.7.2)
S Agent (Version: 1.0.9)
Settings (Version: 2.0.1)
Skype™ 6.3 (Version: 6.3.107)
SolutionCenter (Version: 90.0.146.000)
Status (Version: 90.0.146.000)
Support Center (Version: 2.1.10)
Support Center FAQ (Version: 1.0.6)
SW Update (Version: 2.1.6)
Toolbox (Version: 90.0.146.000)
TrayApp (Version: 90.0.146.000)
Unity Web Player (Version: )
UnloadSupport (Version: 9.0.0)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553157) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589370) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760758) 32-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition
USB Disk Security
User Guide (Version: 1.4.00)
Vegas Pro 12.0 (64-bit) (Version: 12.0.367)
VideoToolkit01 (Version: 90.0.146.000)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1)
WebReg (Version: 90.0.146.000)
Windows Live Communications Platform (Version: 16.4.3503.0728)
Windows Live Essentials (Version: 16.4.3503.0728)
Windows Live Installer (Version: 16.4.3503.0728)
Windows Live Photo Common (Version: 16.4.3503.0728)
Windows Live PIMT Platform (Version: 16.4.3503.0728)
Windows Live SOXE (Version: 16.4.3503.0728)
Windows Live SOXE Definitions (Version: 16.4.3503.0728)
Windows Live UX Platform (Version: 16.4.3503.0728)
Windows Live UX Platform Language Pack (Version: 16.4.3503.0728)
Windows Movie Maker 2.6 (Version: 2.6.4037.0)
WinRAR 4.11 (64-bit) (Version: 4.11.0)
Yahoo! Messenger
 
========================= Devices: ================================
 
 
========================= Memory info: ===================================
 
Percentage of memory in use: 37%
Total physical RAM: 4055.48 MB
Available physical RAM: 2525.23 MB
Total Pagefile: 4759.48 MB
Available Pagefile: 2652.77 MB
Total Virtual: 4095.88 MB
Available Virtual: 3949.91 MB
 
========================= Partitions: =====================================
 
1 Drive c: () (Fixed) (Total:453.58 GB) (Free:372.8 GB) NTFS
3 Drive f: (New Volume) (Fixed) (Total:452.49 GB) (Free:447.55 GB) NTFS
 
========================= Users: ========================================
 
User accounts for \\NOREEN
 
Administrator            Guest                    Windows 8                
 
 
**** End of log ****
 

MBAM Log 

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
 
Database version: v2013.09.26.02
 
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16688
Windows 8 :: NOREEN [limited]
 
9/26/2013 4:11:37 PM
mbam-log-2013-09-26 (16-11-37).txt
 
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 225726
Time elapsed: 4 minute(s), 27 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
(end)
.. this is all logs requested .. now im going to restart my computer 


#5 thegreatneedshelp

thegreatneedshelp
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Philippines
  • Local time:02:00 PM

Posted 26 September 2013 - 03:51 AM

Just Finished MBAR Scan :
MBAR Log: (mbar-log-2013-09-26 (16-27-08))

Malwarebytes Anti-Rootkit BETA 1.07.0.1005
www.malwarebytes.org
 
Database version: v2013.09.26.02
 
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16688
Windows 8 :: NOREEN [limited]
 
9/26/2013 4:27:08 PM
mbar-log-2013-09-26 (16-27-08).txt
 
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 259041
Time elapsed: 14 minute(s), 31 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
Physical Sectors Detected: 0
(No malicious items detected)
 
(end)
 

MBAR Log: (system-log)

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1005
 
© Malwarebytes Corporation 2011-2012
 
OS version: 6.2.9200 Windows 8 x64
 
Account is Non-administrative
 
Internet Explorer version: 10.0.9200.16688
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, F:\ DRIVE_FIXED
CPU speed: 2.794000 GHz
Memory total: 4252479488, free: 2654932992
 
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1005
 
© Malwarebytes Corporation 2011-2012
 
OS version: 6.2.9200 Windows 8 x64
 
Account is Non-administrative
 
Internet Explorer version: 10.0.9200.16688
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, F:\ DRIVE_FIXED
CPU speed: 2.794000 GHz
Memory total: 4252479488, free: 2624589824
 
=======================================
 
 
Downloaded database version: v2013.09.26.02
Downloaded database version: v2013.09.23.01
=======================================
Initializing...
------------ Kernel report ------------
     09/26/2013 16:27:04
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kd.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\System32\drivers\CLFS.SYS
\SystemRoot\System32\drivers\tm.sys
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\system32\CI.dll
\SystemRoot\System32\drivers\msrpc.sys
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\System32\Drivers\acpiex.sys
\SystemRoot\System32\Drivers\WppRecorder.sys
\SystemRoot\System32\drivers\ACPI.sys
\SystemRoot\System32\drivers\WMILIB.SYS
\SystemRoot\System32\drivers\msisadrv.sys
\SystemRoot\System32\drivers\pci.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\system32\drivers\tpm.sys
\SystemRoot\System32\drivers\vdrvroot.sys
\SystemRoot\system32\DRIVERS\trufos.sys
\SystemRoot\system32\DRIVERS\FLTMGR.SYS
\SystemRoot\system32\drivers\pdc.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\gfibto.sys
\SystemRoot\System32\drivers\spaceport.sys
\SystemRoot\System32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\System32\drivers\storahci.sys
\SystemRoot\System32\drivers\storport.sys
\SystemRoot\System32\drivers\EhStorClass.sys
\SystemRoot\System32\drivers\fileinfo.sys
\SystemRoot\system32\DRIVERS\avc3.sys
\SystemRoot\system32\DRIVERS\gzflt.sys
\SystemRoot\System32\Drivers\PxHlpa64.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\DRIVERS\wfplwfs.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\System32\drivers\volsnap.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\disk.sys
\SystemRoot\System32\drivers\CLASSPNP.SYS
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\drivers\cdrom.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\BasicRender.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\System32\drivers\BasicDisplay.sys
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\Drivers\Msfs.SYS
\??\C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys
\??\C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\System32\drivers\npsvctrig.sys
\SystemRoot\System32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\CLVirtualDrive.sys
\??\C:\windows\system32\drivers\cbfs3.sys
\SystemRoot\system32\DRIVERS\bdvedisk.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\System32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\kdnic.sys
\SystemRoot\System32\drivers\umbus.sys
\SystemRoot\system32\DRIVERS\atikmpag.sys
\SystemRoot\system32\DRIVERS\atikmdag.sys
\SystemRoot\System32\drivers\HECIx64.sys
\SystemRoot\System32\drivers\usbehci.sys
\SystemRoot\System32\drivers\USBPORT.SYS
\SystemRoot\System32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\Rt630x64.sys
\SystemRoot\system32\DRIVERS\athw8x.sys
\SystemRoot\System32\drivers\vwifibus.sys
\SystemRoot\System32\drivers\i8042prt.sys
\SystemRoot\System32\drivers\kbdclass.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\System32\drivers\wmiacpi.sys
\SystemRoot\System32\drivers\intelppm.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\System32\drivers\swenum.sys
\SystemRoot\System32\drivers\ks.sys
\SystemRoot\system32\DRIVERS\avchv.sys
\SystemRoot\System32\drivers\rdpbus.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\System32\drivers\usbhub.sys
\SystemRoot\System32\drivers\USBD.SYS
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\System32\drivers\hidusb.sys
\SystemRoot\System32\drivers\HIDCLASS.SYS
\SystemRoot\System32\drivers\HIDPARSE.SYS
\SystemRoot\System32\drivers\mouhid.sys
\SystemRoot\System32\drivers\mouclass.sys
\SystemRoot\System32\drivers\usbccgp.sys
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\System32\Drivers\dump_diskdump.sys
\SystemRoot\System32\Drivers\dump_storahci.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\DRIVERS\avckf.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\drivers\Ndu.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\drivers\condrv.sys
\SystemRoot\System32\DRIVERS\srv.sys
\??\C:\windows\system32\drivers\mbam.sys
\??\C:\windows\system32\drivers\mbamchameleon.sys
\??\C:\windows\system32\drivers\MBAMSwissArmy.sys
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa8004de2060
Upper Device Driver Name: \Driver\disk\
Lower Device Name: \Device\00000037\
Lower Device Object: 0xfffffa80042fa250
Lower Device Driver Name: \Driver\storahci\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa8004de2060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8004de2b10, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8004de2060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
DevicePointer: 0xfffffa80042fc330, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xfffffa80042fa250, DeviceName: \Device\00000037\, DriverName: \Driver\storahci\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Read File: File "C:\Windows\System32\Drivers\vwifibus.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\SYSTEM32\drivers\vwifibus.sys" is compressed (flags = 1)
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
This drive is a GPT Drive.
MBR Signature: 55AA
Disk Signature: F416CB57
 
GPT Protective MBR Partition information:
 
    Partition 0 type is EFI-GPT (0xee)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 1  Numsec = 4294967295
 
    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
GPT Partition information:
 
    GPT Header Signature 4546492050415254
    GPT Header Revision 65536 Size 92 CRC 1732876667
    GPT Header CurrentLba = 1 BackupLba 1953525167
    GPT Header FirstUsableLba 34  LastUsableLba 1953525134
    GPT Header Guid f38527ee-4e65-4e34-8b96-c975b6df04f
    GPT Header Contains 128 partition entries starting at LBA 2
    GPT Header Partition entry size = 128
 
    Backup GPT header Signature 4546492050415254
    Backup GPT header Revision 65536 Size 92 CRC 1732876667
    Backup GPT header CurrentLba = 1953525167 BackupLba 1
    Backup GPT header FirstUsableLba 34  LastUsableLba 1953525134
    Backup GPT header Guid f38527ee-4e65-4e34-8b96-c975b6df04f
    Backup GPT header Contains 128 partition entries starting at LBA 1953525135
    Backup GPT header Partition entry size = 128
 
    Partition 0 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
    Partition ID 3510387d-dc4f-48fc-a3b6-fbb3b3968036
    FirstLBA 2048  Last LBA 1023999
    Attributes 1
    Partition Name                 Basic data partition
 
    Partition 1 Type c12a7328-f81f-11d2-ba4b-0a0c93ec93b
    Partition ID 395e5993-4b98-4275-aa2b-8e46c91330c8
    FirstLBA 1024000  Last LBA 1638399
    Attributes 0
    Partition Name                 EFI system partition
 
    GPT Partition 1 is bootable
    Partition 2 Type e3c9e316-b5c-4db8-817d-f92df0215ae
    Partition ID d718acd4-60ac-4e5f-8034-c3e525ef935e
    FirstLBA 1638400  Last LBA 1900543
    Attributes 0
    Partition Name         Microsoft reserved partition
 
    Partition 3 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
    Partition ID a6319ed4-8b70-4778-a02c-73eafb1ea252
    FirstLBA 1900544  Last LBA 953137152
    Attributes 0
    Partition Name                 Basic data partition
 
    Partition 4 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
    Partition ID fecaf2e4-3300-4df4-a398-7afcf26806f
    FirstLBA 953139200  Last LBA 1902069759
    Attributes 0
    Partition Name                 Basic data partition
 
    Partition 5 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
    Partition ID acf90617-4e41-482c-aa64-8e2459b8c63
    FirstLBA 1902069761  Last LBA 1951426560
    Attributes 1
    Partition Name                 Basic data partition
 
    Partition 6 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
    Partition ID 60fbcf6a-e5f3-4665-4173-636c65706975
    FirstLBA 1951426561  Last LBA 1953523712
    Attributes 1
    Partition Name                 Basic data partition
 
Disk Size: 1000204886016 bytes
Sector size: 512 bytes
 
Done!
Scan finished
=======================================
 
 
Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_r.mbam...
Removal finished
 

Rkill Log

Rkill 2.6.1 by Lawrence Abrams (Grinler)
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
 
Program started at: 09/26/2013 04:45:28 PM in x64 mode.
Windows Version: Windows 8 Single Language 
 
Checking for Windows services to stop:
 
 * No malware services found to stop.
 
Checking for processes to terminate:
 
 * C:\Users\noreen quilario\AppData\Local\Temp\ToolbarUpdater.exe (PID: 2176) [UP-HEUR]
 
1 proccess terminated!
 
Checking Registry for malware related settings:
 
 * Explorer Policy Removed:  NoActiveDesktopChanges [HKLM]
 
Backup Registry file created at:
 C:\Users\noreen quilario\Contacts\Desktop\rkill\rkill-09-26-2013-04-45-33.reg
 
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
  * HKLM\Software\Classes\.exe\shell found and deleted!
 
 
Performing miscellaneous checks:
 
 * Windows Defender Disabled
 
   [HKLM\SOFTWARE\Microsoft\Windows Defender]
   "DisableAntiSpyware" = dword:00000001
 
 * Windows Firewall Disabled
 
   [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
   "EnableFirewall" = dword:00000000
 
Checking Windows Service Integrity: 
 
 * AppMgmt [Missing Service]
 * CSC [Missing Service]
 * CscService [Missing Service]
 * PeerDistSvc [Missing Service]
 
Searching for Missing Digital Signatures: 
 
 * No issues found.
 
Checking HOSTS File: 
 
 * HOSTS file entries found: 
 
  127.0.0.1 activate.adobe.com
  127.0.0.1 practivate.adobe.com
  127.0.0.1 ereg.adobe.com
  127.0.0.1 activate.wip3.adobe.com
  127.0.0.1 wip3.adobe.com
  127.0.0.1 3dns-3.adobe.com
  127.0.0.1 3dns-2.adobe.com
  127.0.0.1 adobe-dns.adobe.com
  127.0.0.1 adobe-dns-2.adobe.com
  127.0.0.1 adobe-dns-3.adobe.com
  127.0.0.1 ereg.wip3.adobe.com
  127.0.0.1 activate-sea.adobe.com
  127.0.0.1 wwis-dubc1-vip60.adobe.com
  127.0.0.1 activate-sjc0.adobe.com
  127.0.0.1 adobe.activate.com
  127.0.0.1 hl2rcv.adobe.com
  127.0.0.1 209.34.83.73:443
  127.0.0.1 209.34.83.73:43
  127.0.0.1 209.34.83.73
  127.0.0.1 209.34.83.67:443
 
  20 out of 30 HOSTS entries shown.
  Please review HOSTS file for further entries.
 
Program finished at: 09/26/2013 04:46:02 PM
Execution time: 0 hours(s), 0 minute(s), and 33 seconds(s)
 

Please Reply :) 



#6 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,725 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:11:00 PM

Posted 26 September 2013 - 09:34 AM

Looks clean so far....

 

p22002970.gif Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
Double click on TFC.exe to run the program.
Click on Start button to begin cleaning process.
TFC will close all running programs, and it may ask you to restart computer.

=============================================================================

p22002970.gif Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Scan button.
  • When the scan has finished click on Clean button.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.


=============================================================================

p22002970.gif Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


=======================================

p22002970.gif Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click on List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    NOTE. If Eset doesn't find any threats it'll NOT produce any log.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#7 thegreatneedshelp

thegreatneedshelp
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Philippines
  • Local time:02:00 PM

Posted 27 September 2013 - 02:59 AM

Clean?? But Why Do I Get Random Sounds Popping Up Even Without Any Window Open??
BTW.. HERE ARE THE LOGS AS REQUESTED..
AdwCleaner Log:

# AdwCleaner v3.005 - Report created 27/09/2013 at 15:42:24
# Updated 22/09/2013 by Xplode
# Operating System : Windows 8 Single Language  (64 bits)
# Username : Windows 8 - NOREEN
# Running from : C:\Users\noreen quilario\Downloads\adwcleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
Service Deleted : APNMCP
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\AskPartnerNetwork
Folder Deleted : C:\ProgramData\blekko toolbars
Folder Deleted : C:\Program Files (x86)\AskPartnerNetwork
Folder Deleted : C:\Users\noreen quilario\AppData\LocalLow\adawaretb
Folder Deleted : C:\Users\noreen quilario\AppData\Roaming\Mozilla\Firefox\Profiles\jkew9ahh.default\adawaretb
Folder Deleted : C:\Users\noreen quilario\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Key Deleted : HKCU\Software\AskPartnerNetwork
Key Deleted : HKLM\Software\adawaretb
Key Deleted : HKLM\Software\AskPartnerNetwork
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v10.0.9200.16688
 
 
-\\ Mozilla Firefox v21.0 (en-US)
 
[ File : C:\Users\noreen quilario\AppData\Roaming\Mozilla\Firefox\Profiles\jkew9ahh.default\prefs.js ]
 
 
[ File : C:\Users\noreen quilario\AppData\Roaming\Mozilla\Firefox\Profiles\jkew9ahh.default\prefs.js ]
 
 
-\\ Google Chrome v29.0.1547.76
 
[ File : C:\Users\noreen quilario\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [1574 octets] - [25/09/2013 17:16:18]
AdwCleaner[R1].txt - [1147 octets] - [25/09/2013 17:20:42]
AdwCleaner[R2].txt - [2223 octets] - [27/09/2013 15:42:15]
AdwCleaner[S0].txt - [1571 octets] - [25/09/2013 17:16:59]
AdwCleaner[S1].txt - [1209 octets] - [25/09/2013 17:21:09]
AdwCleaner[S2].txt - [2024 octets] - [27/09/2013 15:42:24]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2084 octets] ##########

JRT Log:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.3 (09.27.2013:1)
OS: Windows 8 Single Language x64
Ran by Windows 8 on Fri 09/27/2013 at 15:48:41.29
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho.1
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Failed to delete: [Registry Key] "hkey_local_machine\software\classes\clsid\{44cbc005-6243-4502-8a02-3a096a282664}"
Failed to delete: [Registry Key] "hkey_local_machine\software\classes\clsid\{80703783-e415-4ee3-ab60-d36981c5a6f1}"
Failed to delete: [Registry Key] "hkey_local_machine\software\classes\clsid\{d8278076-bc68-4484-9233-6e7f1628b56c}"
Failed to delete: [Registry Key] "hkey_local_machine\software\classes\clsid\{f297534d-7b06-459d-bc19-2dd8ef69297b}"
Failed to delete: [Registry Key] "hkey_local_machine\software\classes\typelib\{9945959c-aad8-4312-8b57-2de11927e770}"
Failed to delete: [Registry Key] "hkey_local_machine\software\microsoft\internet explorer\low rights\elevationpolicy\{6978f29a-3493-40b2-8cdc-9c13a02f85a4}"
Failed to delete: [Registry Key] "hkey_local_machine\software\microsoft\internet explorer\low rights\elevationpolicy\{d7949a66-d936-4028-9552-14f7dc50f38d}"
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] "C:\Users\noreen quilario\appdata\local\adawarebp"
Failed to delete: [Folder] "C:\Program Files (x86)\free youtube downloader"
 
 
 
~~~ FireFox
 
Successfully deleted: [File] C:\Users\noreen quilario\AppData\Roaming\mozilla\firefox\profiles\jkew9ahh.default\extensions\toolbar_avira-v7@apn.ask.com.xpi
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 09/27/2013 at 15:52:02.33
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


#8 thegreatneedshelp

thegreatneedshelp
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Philippines
  • Local time:02:00 PM

Posted 27 September 2013 - 03:16 AM

HEY BRONI... CAN I JUST ASK.. UPTO HOW MANY ANTIVIRUS PROGRAMS AN WHAT WOULD YOU RECOMMEND FOR ME TO INSTALL? AND WHEN I READ MY PREVIOUS LOGS .. I FOUND THIS IN THE "INSTALLED PROGRAMS" LIST "???? ????? (Version: 16.4.3503.0728)" AND THE SCAN OF ESET IS STILL ONGOING .... WHAT IS THAT PROGRAM? AND IS THAT THE VIRUS ?
"
???? ????? (Version: 16.4.3503.0728)"  WHAT THE HELL IS IT??



#9 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,725 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:11:00 PM

Posted 27 September 2013 - 03:45 PM

Your BitDefender says it's out of date.

Why?

 

"???? ????? (Version: 16.4.3503.0728)" usually means some program with a name using non-Latin characters.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#10 thegreatneedshelp

thegreatneedshelp
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Philippines
  • Local time:02:00 PM

Posted 28 September 2013 - 04:56 AM

HEY BRONI .. MY COMPUTER FAILED TO BOOT A WHILE AGO AND WE WENT TO A TECHNICIAN TO CHECK IT OUT AND HE SAID THAT THE VIRUS WAS BLOCKING THE OS TO LOG IN SO WHEN WE WERE ABLE TO START IT UP, WE SAVE ALL OUR IMPORTANT FILES TO A USB AND WE USED THE RECOVERY FUNCTION OF MY PC TO RESET THE PC TO MAKE IT BACK TO ZERO.. SO NOW IT IS OK AND NO MORE PROBLEMS BUT THANKS FOR THE HELP ANYWAYS :) ... BUT JUST TWO MORE QUESTIONS: UPTO HOW MANY ANTIVIRUS PROGRAMS WOULD YOU RECOMMEND FOR ME TO INSTALL AND IF POSSIBLE WHAT ANTIVIRUS(ES)?? THANKS :)



#11 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,725 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:11:00 PM

Posted 28 September 2013 - 09:10 PM

Thank you for letting me know :)

 

You can run only one AV program.

 

Install ONE of these:

- Avast! free antivirus: http://www.avast.com/eng/download-avast-home.html

- free Microsoft Security Essentials: http://windows.microsoft.com/en-GB/windows/products/security-essentials
Note for Windows 8 users: Microsoft Security Essentials comes preinstalled and renamed as Windows Defender.
You can keep it or you have to disable it before installing another AV program.  How to...

- free Comodo Antivirus: http://www.comodo.com/home/internet-security/antivirus.php
 


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#12 thegreatneedshelp

thegreatneedshelp
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Philippines
  • Local time:02:00 PM

Posted 01 October 2013 - 03:04 AM

HEY BRONI THANKS FOR THE REPLY ... SEE, MY SAMSUNG PC HAS A FREE 60 DAYS TRIAL OF NORTON INTERNET SECURITY 2013 WHEN IT WAS RECOVERED BUT IF THE TRIAL FINISHES CAN I JUST INSTALL BIT DEFENDER AGAIN?? BECAUSE FROM WHAT I HAVE RESEARCHED.. IT IS THE BEST AV PROGRAM :)



#13 thegreatneedshelp

thegreatneedshelp
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Philippines
  • Local time:02:00 PM

Posted 01 October 2013 - 03:08 AM

AND BRONI.. I HAVE A NEW PROBLEM.. AFTER RECOVERING MY PC ALL THE FILES WERE DELETED SO I DOWNLOADED FREE YOUTUBE DOWNLOADER BUT THERE WAS A QV06 MALWARE.. AND IT CANT BE DETECTED BY NORTON I. S. SO I SEARCHED THE NET AND I HAVE FOUND SPYHUNTER AND IT SCANNED MY PC AND IT SHOWED 92 THREATS ALL MALWARES AND ADWARES BUT I CAN'T REMOVE THESE THREATS BECAUSE I HAVE TO BUY THE PRODUCT :) SO NOW I WILL TRY ADWCLEANER TO REMOVE THESE AND I HOPE IT WON'T DEVELOP AGAIN TO THE FORMER VIRUS I HAD :)



#14 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,725 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:11:00 PM

Posted 01 October 2013 - 07:42 PM

Please turn caps off.

 

IF THE TRIAL FINISHES CAN I JUST INSTALL BIT DEFENDER AGAIN??

 

Sure.

 

p22002970.gif Download Security Check from here or here and save it to your Desktop.

  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
NOTE 2 SecurityCheck may produce some false warning(s), so leave the results reading to me.

p22002970.gif Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


p22002970.gif Please download MiniToolBox and run it.

Checkmark following boxes:
  • Report IE Proxy Settings
  • Report FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices (do NOT change any settings here)
  • List Users, Partitions and Memory size

Click Go and post the result.

p22002970.gif Download Malwarebytes' Anti-Malware (aka MBAM): https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/ to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Be sure to restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

p22002970.gifDownload Malwarebytes Anti-Rootkit from HERE to your Desktop.
  • Unzip downloaded file.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • DO NOT click on the Cleanup button. Simply exit the program.
  • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log-xxxxx.txt and system-log.txt


p22002970.gif Please download Rkill (courtesy of BleepingComputer.com) to your desktop.
There are 2 different versions. If one of them won't run then download and try to run the other one.
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.


If normal mode still doesn't work, run the tool from safe mode.

When the scan is done Notepad will open with rKill log.
Post it in your next reply.

NOTE. rKill.txt log will also be present on your desktop.

NOTE Do NOT wrap your logs in "quote" or "code" brackets.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#15 thegreatneedshelp

thegreatneedshelp
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Philippines
  • Local time:02:00 PM

Posted 17 October 2013 - 06:32 AM

Hello Broni.. so my pc is now running like new ..  I have a new problem... i bought a new a SanDisk Cruzer Edge 8gb Flash Drive .. and it is showing up as Local Disk . I want to put it as removable disk .. What To Do?? Another question: Will it be ok if I often scan for Malwares/Adwares using AdwCleaner because I don't want any Virus to develop again . :) thanks






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users