Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

So my HDD is always at 100 percent, please help. :c


  • This topic is locked This topic is locked
2 replies to this topic

#1 ProeyJoey

ProeyJoey

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:08:28 PM

Posted 28 September 2013 - 07:43 PM

DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 10.0.9200.16688  BrowserJavaVersion: 10.40.2
Run by Anonymous-Wind at 20:24:37 on 2013-09-28
Microsoft Windows 8 Pro with Media Center  6.2.9200.0.1252.1.2057.18.8155.5449 [GMT -4:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\dwm.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
C:\Program Files (x86)\Stardock\Start8\Start8_64.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\dashost.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\sppsvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhostex.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Windows\system32\taskmgr.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\BitComet\BitComet.exe
C:\Users\Anonymous-Wind\AppData\Local\Skillbrains\lightshot\4.4.2.0\LightShot.exe
C:\Program Files\BitComet\tools\BitCometService.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
BHO: BitComet Helper: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Microsoft Web Test Recorder 10.0 Helper: {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
EB: Web Test Recorder 10.0: {3142c289-f319-47f5-a594-a827028714c9} - 
uRun: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
uRun: [LightShot] C:\Users\Anonymous-Wind\AppData\Local\Skillbrains\lightshot\LightShot.exe Flags: uninsdeletevalue
uRun: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mPolicies-System: PromptOnSecureDesktop = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
IE: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
IE: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll/206
TCP: Interfaces\{9EA530DA-D33B-41A0-81EE-9FFFAA70D023} : DHCPNameServer = 192.168.1.254
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-mPolicies-System: PromptOnSecureDesktop = dword:0
x64-mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\Drivers\dtsoftbus01.sys [2013-9-15 283200]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2013-6-28 2470736]
R2 IDMWFP;IDMWFP;C:\Windows\System32\Drivers\idmwfp.sys [2013-6-28 172920]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-9-2 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-9-2 701512]
R2 Start8;Stardock Start8;C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [2013-3-19 142960]
R2 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-9-2 4308320]
R3 AVPolDIR;AVerMedia USB Polaris Series DIR Service;C:\Windows\System32\Drivers\AVPolDIR.sys [2013-3-5 7168]
R3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;C:\Program Files\BitComet\tools\BitCometService.exe -service --> C:\Program Files\BitComet\tools\BitCometService.exe -service [?]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\Drivers\mbam.sys [2013-9-2 25928]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\Drivers\netr28x.sys [2013-4-15 2482960]
R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2012-6-2 589824]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\Windows\System32\Drivers\WUDFRd.sys [2012-7-25 198656]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-7-25 162672]
S3 Te.Service;Te.Service;C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [2012-7-25 126976]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 vmbusr;Virtual Machine Bus Provider;C:\Windows\System32\Drivers\vmbusr.sys [2012-7-25 117248]
S3 WSDScan;WSD Scan Support;C:\Windows\System32\Drivers\WSDScan.sys [2013-9-8 23552]
.
=============== File Associations ===============
.
FileExt: .vbs: VBSFile="C:\Windows\System32\WScript.exe" "%1" %* [UserChoice]
.
=============== Created Last 30 ================
.
2013-09-29 00:18:42 76232 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F86C0D77-F45D-40C7-B521-0CEDD0FDC479}\offreg.dll
2013-09-28 23:36:53 9694160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F86C0D77-F45D-40C7-B521-0CEDD0FDC479}\mpengine.dll
2013-09-27 08:50:08 304816 ----a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10218.bin
2013-09-23 22:34:31 -------- d-----w- C:\ProgramData\Oracle
2013-09-23 22:34:10 868264 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-09-23 22:34:10 790440 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-09-23 22:34:08 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-22 05:35:17 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Roaming\iFunbox_UserCache
2013-09-22 05:34:08 -------- d-----w- C:\Program Files (x86)\i-Funbox DevTeam
2013-09-21 21:15:04 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Local\LogMeIn Hamachi
2013-09-21 21:14:29 -------- d-----w- C:\Program Files (x86)\LogMeIn Hamachi
2013-09-21 07:00:08 9515512 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-09-20 23:15:00 -------- d-----w- C:\Program Files (x86)\Winamp Detect
2013-09-20 23:14:57 -------- d-----w- C:\Program Files (x86)\Common Files\PX Storage Engine
2013-09-20 23:04:37 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Local\S4LResource_3
2013-09-17 22:48:48 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Roaming\EurekaLog
2013-09-17 22:46:57 -------- d-----w- C:\Program Files (x86)\eSupport.com
2013-09-16 23:02:27 -------- d-----w- C:\Program Files (x86)\Microsoft Synchronization Services
2013-09-16 23:01:49 -------- d-----w- C:\Windows\PCHEALTH
2013-09-16 22:59:55 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
2013-09-16 22:59:28 -------- d-----w- C:\Program Files (x86)\Microsoft Analysis Services
2013-09-16 22:59:13 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Local\Microsoft Help
2013-09-15 23:01:17 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Local\Howei
2013-09-15 19:56:09 2562208 ----a-w- C:\ProgramData\Microsoft\VisualStudio\11.0\1033\ResourceCache.dll
2013-09-15 19:51:40 -------- d-----w- C:\Program Files\Microsoft SQL Server Compact Edition
2013-09-15 19:51:38 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-09-15 19:51:17 -------- d-----w- C:\Program Files\Application Verifier
2013-09-15 19:51:17 -------- d-----w- C:\Program Files (x86)\Application Verifier
2013-09-15 19:51:14 -------- d-----w- C:\ProgramData\Windows App Certification Kit
2013-09-15 19:50:45 -------- d-----w- C:\Program Files (x86)\Common Files\Microsoft
2013-09-15 19:50:34 -------- d-----w- C:\ProgramData\PreEmptive Solutions
2013-09-15 19:49:21 -------- d-----w- C:\Program Files (x86)\Microsoft ASP.NET
2013-09-15 19:49:06 -------- d-----w- C:\Program Files (x86)\Microsoft Web Tools
2013-09-15 19:48:55 -------- d-----w- C:\Program Files\Microsoft
2013-09-15 19:48:42 -------- d-----w- C:\Program Files\IIS Express
2013-09-15 19:48:42 -------- d-----w- C:\Program Files (x86)\IIS Express
2013-09-15 19:48:05 -------- d-----w- C:\Program Files (x86)\NuGet
2013-09-15 19:47:58 -------- d-----w- C:\Program Files (x86)\Microsoft WCF Data Services
2013-09-15 19:47:52 -------- d-----w- C:\Program Files\IIS
2013-09-15 19:47:52 -------- d-----w- C:\Program Files (x86)\IIS
2013-09-15 19:46:53 -------- d-----w- C:\Program Files (x86)\Windows Kits
2013-09-15 19:43:39 -------- d-----w- C:\Program Files (x86)\HTML Help Workshop
2013-09-15 19:43:30 -------- d-----w- C:\Program Files (x86)\Microsoft Help Viewer
2013-09-15 19:42:56 -------- d-----w- C:\Windows\SysWow64\1033
2013-09-15 19:42:48 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server
2013-09-15 19:42:47 -------- d-----w- C:\Program Files\Microsoft SQL Server
2013-09-15 19:40:02 -------- d-----w- C:\Program Files (x86)\Common Files\Merge Modules
2013-09-15 19:39:18 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 11.0
2013-09-15 19:39:14 -------- d-----w- C:\Windows\System32\1033
2013-09-15 19:38:59 -------- d-----w- C:\Program Files\Microsoft Visual Studio 11.0
2013-09-15 19:31:39 283200 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys
2013-09-15 19:31:34 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Roaming\DAEMON Tools Pro
2013-09-15 19:31:32 -------- d-----w- C:\Program Files (x86)\DAEMON Tools Pro
2013-09-15 19:30:53 -------- d-----w- C:\ProgramData\DAEMON Tools Pro
2013-09-14 17:53:53 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Local\Apple Computer
2013-09-14 17:53:40 33240 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2013-09-14 17:53:11 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-09-14 17:53:11 -------- d-----w- C:\Program Files\iTunes
2013-09-14 17:53:11 -------- d-----w- C:\Program Files\iPod
2013-09-14 17:53:11 -------- d-----w- C:\Program Files (x86)\iTunes
2013-09-14 17:52:38 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Local\Apple
2013-09-14 17:52:11 -------- d-----w- C:\Program Files\Bonjour
2013-09-14 17:52:11 -------- d-----w- C:\Program Files (x86)\Bonjour
2013-09-14 02:41:39 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2013-09-14 02:41:36 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-09-14 02:36:39 -------- d-----w- C:\GunZ2
2013-09-12 17:34:38 144896 ----a-w- C:\Windows\System32\tssdisai.dll
2013-09-12 07:05:07 3959296 ----a-w- C:\Windows\System32\jscript9.dll
2013-09-08 23:44:36 -------- d-----w- C:\Program Files (x86)\Kill3rCombo
2013-09-08 13:48:18 68608 ----a-w- C:\Windows\System32\wwanprotdim.dll
2013-09-08 13:48:07 1184256 ----a-w- C:\Windows\System32\Display.dll
2013-09-08 13:48:06 1164800 ----a-w- C:\Windows\SysWow64\Display.dll
2013-09-08 13:48:05 7168 ----a-w- C:\Windows\System32\KBDKURD.DLL
2013-09-08 13:48:05 6656 ----a-w- C:\Windows\SysWow64\KBDKURD.DLL
2013-09-08 13:46:27 82944 ----a-w- C:\Windows\SysWow64\dskquota.dll
2013-09-08 13:46:27 115712 ----a-w- C:\Windows\System32\wbem\PolicMan.dll
2013-09-08 13:46:27 109568 ----a-w- C:\Windows\System32\dskquota.dll
2013-09-08 13:46:26 84992 ----a-w- C:\Windows\SysWow64\wbem\PolicMan.dll
2013-09-08 13:46:11 929792 ----a-w- C:\Windows\SysWow64\mfnetsrc.dll
2013-09-08 13:46:11 1172992 ----a-w- C:\Windows\System32\mfnetsrc.dll
2013-09-08 13:46:10 677888 ----a-w- C:\Windows\System32\mfnetcore.dll
2013-09-08 13:46:10 673280 ----a-w- C:\Windows\System32\mfmpeg2srcsnk.dll
2013-09-08 13:46:10 568832 ----a-w- C:\Windows\SysWow64\mfnetcore.dll
2013-09-08 13:46:10 513024 ----a-w- C:\Windows\SysWow64\mfmpeg2srcsnk.dll
2013-09-08 13:44:51 3245568 ----a-w- C:\Windows\System32\rdpcorets.dll
2013-09-08 13:43:59 997632 ----a-w- C:\Windows\System32\drivers\ndis.sys
2013-09-08 13:42:59 236544 ----a-w- C:\Windows\System32\MFPlay.dll
2013-09-08 13:34:30 301568 ----a-w- C:\Windows\System32\newdev.dll
2013-09-08 13:34:29 275968 ----a-w- C:\Windows\SysWow64\newdev.dll
2013-09-08 13:34:28 76288 ----a-w- C:\Windows\System32\newdev.exe
2013-09-08 13:34:28 75264 ----a-w- C:\Windows\System32\ndadmin.exe
2013-09-08 13:34:28 74240 ----a-w- C:\Windows\SysWow64\newdev.exe
2013-09-08 13:34:28 73728 ----a-w- C:\Windows\SysWow64\ndadmin.exe
2013-09-08 11:56:02 78296 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-08 11:56:02 694232 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-09-05 13:40:25 19187712 ----a-w- C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-09-05 13:40:23 18523648 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-09-05 11:01:15 -------- d-----w- C:\Windows\System32\MRT
2013-09-03 21:26:29 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Local\ElevatedDiagnostics
2013-09-03 21:15:18 79256 ----a-w- C:\Windows\SysWow64\npOGPPlugin.dll
2013-09-03 21:15:16 271768 ----a-w- C:\Windows\SysWow64\OGPIEPlugin.ocx
2013-09-03 21:15:12 -------- d-----w- C:\Program Files (x86)\OGPlanet
2013-09-03 21:13:59 83736 ----a-w- C:\Windows\System32\xinput1_2.dll
2013-09-03 21:06:53 -------- d--h--w- C:\Windows\msdownld.tmp
2013-09-03 21:06:48 -------- d-----w- C:\Windows\SysWow64\directx
2013-09-03 04:23:16 888320 ----a-w- C:\Windows\System32\autochk.exe
2013-09-03 04:23:16 542208 ----a-w- C:\Windows\System32\untfs.dll
2013-09-03 04:23:16 482816 ----a-w- C:\Windows\SysWow64\untfs.dll
2013-09-03 04:23:15 793088 ----a-w- C:\Windows\SysWow64\autochk.exe
2013-09-03 04:21:59 71168 ----a-w- C:\Windows\System32\WSDPrintProxy.DLL
2013-09-03 04:21:59 36352 ----a-w- C:\Windows\SysWow64\DevDispItemProvider.dll
2013-09-03 04:21:59 128512 ----a-w- C:\Windows\System32\SettingSyncInfo.dll
2013-09-03 04:21:59 100864 ----a-w- C:\Windows\SysWow64\SettingSyncInfo.dll
2013-09-03 04:21:58 30720 ----a-w- C:\Windows\System32\drivers\monitor.sys
2013-09-03 04:21:58 26112 ----a-w- C:\Windows\System32\drivers\mouhid.sys
2013-09-03 04:21:58 235008 ----a-w- C:\Program Files\Windows NT\Accessories\WordpadFilter.dll
2013-09-03 04:21:58 195072 ----a-w- C:\Program Files (x86)\Windows NT\Accessories\WordpadFilter.dll
2013-09-03 04:19:18 17888 ----a-w- C:\Windows\System32\msvcr100_clr0400.dll
2013-09-03 04:19:16 17888 ----a-w- C:\Windows\SysWow64\msvcr100_clr0400.dll
2013-09-03 04:16:56 694272 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2013-09-03 04:15:59 94208 ----a-w- C:\Windows\SysWow64\mssitlb.dll
2013-09-03 04:14:54 830464 ----a-w- C:\Windows\System32\wbem\WmiPrvSD.dll
2013-09-03 04:13:46 2893824 ----a-w- C:\Windows\System32\msmpeg2vdec.dll
2013-09-03 04:12:57 1558912 ----a-w- C:\Program Files\Windows Defender\DbgHelp.dll
2013-09-03 04:11:54 1889280 ----a-w- C:\Windows\System32\crypt32.dll
2013-09-03 04:10:52 2382336 ----a-w- C:\Windows\SysWow64\esent.dll
2013-09-03 04:10:51 2851840 ----a-w- C:\Windows\System32\esent.dll
2013-09-03 04:05:44 2361344 ----a-w- C:\Windows\System32\msxml6.dll
2013-09-03 04:05:44 1836032 ----a-w- C:\Windows\System32\msxml3.dll
2013-09-03 04:05:44 1802240 ----a-w- C:\Windows\SysWow64\msxml6.dll
2013-09-03 04:05:43 2048 ----a-w- C:\Windows\SysWow64\msxml6r.dll
2013-09-03 04:05:43 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2013-09-03 04:05:43 2048 ----a-w- C:\Windows\System32\msxml6r.dll
2013-09-03 04:05:43 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2013-09-03 04:05:43 1438720 ----a-w- C:\Windows\SysWow64\msxml3.dll
2013-09-03 02:48:55 -------- d-----w- C:\Program Files (x86)\Skillbrains
2013-09-03 02:48:50 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Local\Skillbrains
2013-09-02 19:00:02 50784 ----a-w- C:\ProgramData\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin
2013-09-02 19:00:01 17536 ----a-w- C:\ProgramData\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-09-02 17:42:57 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Roaming\TeamViewer
2013-09-02 17:42:15 -------- d-----w- C:\Program Files (x86)\TeamViewer
2013-09-02 08:04:08 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Roaming\Malwarebytes
2013-09-02 08:03:55 -------- d-----w- C:\ProgramData\Malwarebytes
2013-09-02 08:03:53 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-09-02 08:03:53 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-02 06:35:59 -------- d-----w- C:\Program Files (x86)\alaplaya
2013-09-02 06:20:53 106496 ----a-w- C:\Windows\System32\SLCHook.dll
2013-09-02 06:07:11 -------- d-----w- C:\Windows\System32\tokens
2013-09-02 06:07:00 10240 ----a-w- C:\Windows\sppsvc.exe
2013-09-02 06:07:00 10240 ----a-w- C:\Windows\slsvc.exe
2013-09-02 05:58:22 -------- d-----w- C:\ProgramData\Stardock
2013-09-02 05:58:19 -------- d-----w- C:\Program Files (x86)\Stardock
2013-09-02 05:54:29 -------- d-----w- C:\ProgramData\Package Cache
2013-09-02 05:53:00 -------- d-----r- C:\Program Files (x86)\Skype
2013-09-02 05:52:35 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Roaming\BitComet
2013-09-02 05:52:33 -------- d-----w- C:\Program Files\BitComet
2013-09-02 05:47:09 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Local\Google
2013-09-02 05:46:56 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Local\Deployment
2013-09-02 05:46:56 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Local\Apps
2013-09-02 05:45:39 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Roaming\IDM
2013-09-02 05:45:39 -------- d-----w- C:\Users\Anonymous-Wind\AppData\Roaming\DMCache
2013-09-02 05:45:39 -------- d-----w- C:\ProgramData\IDM
2013-09-02 05:45:30 -------- d-----w- C:\Program Files (x86)\Internet Download Manager
2013-09-02 04:38:25 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-09-02 03:52:35 -------- d-----r- C:\Users\Anonymous-Wind\Searches
2013-09-02 03:52:17 -------- d-----r- C:\Users\Anonymous-Wind\Contacts
2013-09-01 23:27:29 -------- d-----w- C:\Windows\Panther
.
==================== Find3M  ====================
.
2013-08-21 04:12:06 2241024 ----a-w- C:\Windows\System32\wininet.dll
2013-08-21 04:11:59 915968 ----a-w- C:\Windows\System32\uxtheme.dll
2013-08-21 04:11:59 53760 ----a-w- C:\Windows\System32\UXInit.dll
2013-08-21 04:11:04 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-08-21 04:11:04 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-08-21 02:34:51 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-08-21 02:06:11 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-08-21 02:06:06 44032 ----a-w- C:\Windows\SysWow64\UXInit.dll
2013-08-21 02:05:28 2876928 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-08-21 02:05:25 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-08-21 02:05:25 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-08-21 01:43:54 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-08-20 23:52:56 534528 ----a-w- C:\Windows\SysWow64\uxtheme.dll
2013-08-16 05:41:13 58200 ----a-w- C:\Windows\System32\drivers\dam.sys
2013-08-16 05:39:26 2371728 ----a-w- C:\Windows\System32\WSService.dll
2013-08-16 05:32:48 209200 ----a-w- C:\Windows\System32\NotificationUI.exe
2013-08-16 05:22:22 40448 ----a-w- C:\Windows\System32\wuapp.exe
2013-08-16 05:22:11 4917760 ----a-w- C:\Windows\System32\sppsvc.exe
2013-08-16 05:20:30 105984 ----a-w- C:\Windows\System32\WinSetupUI.dll
2013-08-15 22:43:21 35328 ----a-w- C:\Windows\SysWow64\wuapp.exe
2013-08-15 22:43:07 84992 ----a-w- C:\Windows\SysWow64\wudriver.dll
2013-08-15 22:43:07 126976 ----a-w- C:\Windows\SysWow64\wuwebv.dll
2013-08-15 22:43:03 562688 ----a-w- C:\Windows\SysWow64\WSShared.dll
2013-08-15 22:43:03 159232 ----a-w- C:\Windows\SysWow64\WSSync.dll
2013-08-15 22:43:02 83968 ----a-w- C:\Windows\SysWow64\OEMLicense.dll
2013-08-15 22:43:02 167424 ----a-w- C:\Windows\SysWow64\WSClient.dll
2013-08-15 22:43:02 143872 ----a-w- C:\Windows\SysWow64\Windows.ApplicationModel.Store.dll
2013-08-15 22:43:02 124928 ----a-w- C:\Windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-08-15 22:42:52 76800 ----a-w- C:\Windows\SysWow64\setupcln.dll
2013-08-15 22:42:47 91648 ----a-w- C:\Windows\SysWow64\sppc.dll
2013-08-03 04:30:14 4038144 ----a-w- C:\Windows\System32\win32k.sys
2013-07-13 06:18:21 337408 ----a-w- C:\Windows\System32\wintrust.dll
2013-07-13 06:16:06 68096 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-07-13 06:15:53 98304 ----a-w- C:\Windows\System32\apprepsync.dll
2013-07-13 06:15:53 124416 ----a-w- C:\Windows\System32\apprepapi.dll
2013-07-13 04:24:58 261120 ----a-w- C:\Windows\SysWow64\wintrust.dll
2013-07-13 04:23:11 1568256 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-07-13 04:23:03 87040 ----a-w- C:\Windows\SysWow64\apprepapi.dll
2013-07-13 04:23:03 74240 ----a-w- C:\Windows\SysWow64\apprepsync.dll
2013-07-09 08:04:07 120144 ----a-w- C:\Windows\System32\drivers\msgpioclx.sys
2013-07-09 06:18:21 439488 ----a-w- C:\Windows\System32\WerFault.exe
2013-07-09 06:07:17 2233168 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-07-09 04:25:45 385768 ----a-w- C:\Windows\SysWow64\WerFault.exe
2013-07-09 03:57:19 245760 ----a-w- C:\Windows\SysWow64\LocationApi.dll
2013-07-08 22:46:00 543744 ----a-w- C:\Windows\System32\wwanmm.dll
2013-07-08 22:46:00 414208 ----a-w- C:\Windows\System32\wwanconn.dll
2013-07-08 22:46:00 370688 ----a-w- C:\Windows\System32\Wwanadvui.dll
2013-07-08 22:45:16 312832 ----a-w- C:\Windows\System32\LocationApi.dll
2013-07-06 00:16:17 1025024 ----a-w- C:\Windows\System32\localspl.dll
2013-07-03 00:23:43 391168 ----a-w- C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-07-03 00:23:12 778752 ----a-w- C:\Windows\System32\oleaut32.dll
2013-07-03 00:22:26 1300480 ----a-w- C:\Windows\System32\gdi32.dll
2013-07-03 00:11:23 268800 ----a-w- C:\Windows\SysWow64\Windows.Networking.BackgroundTransfer.dll
2013-07-03 00:11:02 551424 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2013-07-02 00:44:14 36288 ----a-w- C:\Windows\System32\drivers\WdBoot.sys
2013-07-01 22:08:49 247216 ----a-w- C:\Windows\System32\drivers\WdFilter.sys
.
============= FINISH: 20:27:09.92 ===============
 
There's that, and here's an SS of what the fahk is going on, any help would be appreciated.
http://prntscr.com/1u3e3f
For starters, I disabled windows defender, so I don't know why it's there. And I'm not even scanning with malware bytes atm. :/ 
Attached File  attach.txt   16.52KB   0 downloads
 


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 40,447 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:28 PM

Posted 02 October 2013 - 10:03 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.
===

Search and delete the AdWare, PUP (Potentially Unwanted Program) installed on your computer.

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.

  • IMPORTANT

  • If you click the Clean button all items listed in the report will be removed.

  • If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.

  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number).
  • ===

    thisisujrt.gif Please download
    Junkware Removal Tool to your Desktop.
  • Please close your security software to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete, depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
  • Please post the contents of JRT.txt into your reply.
  • ===

    --RogueKiller--
  • Download & SAVE to your Desktop RogueKiller for 32bit or Roguekiller for 64bit

  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7, right-click and select "Run as Administrator to start"
  • For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • Then Click on "Scan" button
  • Wait until the Status box shows "Scan Finished"
  • click on "delete"
  • Wait until the Status box shows "Deleting Finished"
  • Click on "Report" and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
  • Exit/Close RogueKiller+
  • Third party programs if not up to date can be the cause of infiltration an infection.
    ===

    Please run this security check for my review.

    Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
  • p.s.
    If the SecurityCheck program fails to run for any reason, run it as an Administrator.
    ===

    Please paste the logs in your next reply DO NOT ATTACH THEM.
    Let me know what problem persists.


#3 nasdaq

nasdaq

  • Malware Response Team
  • 40,447 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:28 PM

Posted 08 October 2013 - 09:12 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users