1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive-A Wow.dll Missing popup when right clicking

Discussion in 'Malware and Virus Removal Archive' started by lucianvivant, 2013/05/30.

Thread Status:
Not open for further replies.
  1. 2013/05/30
    lucianvivant

    lucianvivant Inactive Thread Starter

    Joined:
    2013/05/30
    Messages:
    28
    Likes Received:
    0
    [Inactive-A] Wow.dll Missing popup when right clicking

    Hello..

    I am VERY new to forums and hope that i do this correctly.
    in the last two days. any time that i right click anything i get a missing wow.dll error popup.
    also the computer stutters and stalls and programs occasionally seem that they are "not responding" and then do finally work. and when hovering over click-able texts or buttons(like the submit and preview buttons at the bottom of this page. the computer stalls . and it is also starting to do it with typing. please help me and be patient with my lack of forum knowledge.

    I have seen other threads of people having the same issue. and it seems that you need logs that are unique to the user.
    could you walk me through this. i have a fear of regedit and combofix, and that i may permanently ruin my computer.
    I use malware bytes and ccleaner normally.
    this is effecting my computer slowing it and causing general annoyance. i want to catch this before it causes more problems if it is indeed a virus.

    Thank you i look forward to your reply. i hope that this does not permanently damage my machine in the interim :)
     
  2. 2013/05/30
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,680
    Likes Received:
    104

  3. to hide this advert.

  4. 2013/05/31
    lucianvivant

    lucianvivant Inactive Thread Starter

    Joined:
    2013/05/30
    Messages:
    28
    Likes Received:
    0
    I will do this and post when i have completed the steps.
    the only rreason i did not is that i haev seen another post on here about this same problem and they did not use these steps.
    there were MANY MANY more
    are you Broni? will get back to you later today wtih the above info
     
  5. 2013/06/03
    lucianvivant

    lucianvivant Inactive Thread Starter

    Joined:
    2013/05/30
    Messages:
    28
    Likes Received:
    0
    Ok.. sorry for the time this took i did not pay my cable bill
    so here are the logs
     
  6. 2013/06/03
    lucianvivant

    lucianvivant Inactive Thread Starter

    Joined:
    2013/05/30
    Messages:
    28
    Likes Received:
    0
    Malwarebytes Anti-Malware (PRO) 1.75.0.1300
    www.malwarebytes.org

    Database version: v2013.05.30.02

    Windows 7 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Algiz :: ALGIZ-PC [administrator]

    Protection: Disabled

    6/3/2013 12:55:36 PM
    mbam-log-2013-06-03 (12-55-36).txt

    Scan type: Full scan (C:\|)
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP |

    PUM
    Scan options disabled: P2P
    Objects scanned: 436915
    Time elapsed: 56 minute(s), 31 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     
  7. 2013/06/03
    lucianvivant

    lucianvivant Inactive Thread Starter

    Joined:
    2013/05/30
    Messages:
    28
    Likes Received:
    0
    DDS (Ver_2012-11-20.01) - NTFS_AMD64
    Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.9.2
    Run by Algiz at 13:54:20 on 2013-06-03
    Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.8174.5761 [GMT -7:00]
    .
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Program Files\Dell\DellDock\DockLogin.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\WLANExt.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Windows\SysWOW64\svchost.exe -k Akamai
    C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe
    C:\Program Files (x86)\CA\PPRT\bin\ITMRTSVC.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    C:\Windows\SysWOW64\PnkBstrA.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    C:\Program Files (x86)\Nero\Update\NASvc.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
    C:\Windows\syswow64\rundll32.exe
    C:\Windows\syswow64\svchost.exe -k netsvcs
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Windows\system32\wuauclt.exe
    C:\Users\Algiz\AppData\Local\RockMelt\Update\1.2.189.1\RockMeltCrashHandler.exe
    C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    C:\Program Files (x86)\BitTorrent\BitTorrent.exe
    C:\Windows\system32\svchost.exe -k SDRSVC
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Windows\notepad.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\System32\cscript.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://proxy.allsearchapp.com/app/start/
    uProxyOverride = <local>
    uURLSearchHooks: YTNavAssist.YTNavAssistPlugin Class: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll
    BHO: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
    BHO: Social Privacy: {09942569-D515-42BE-9F5A-A439B20F91AB} - C:\Program Files (x86)\Social Privacy\sp.dll
    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
    BHO: XFINITY Toolbar: {4b9bcce8-a70b-402a-a7e1-db96831ee26f} - C:\Program Files (x86)\xfin_portal\comcastdx.dll
    BHO: Wondershare Video Converter Ultimate: {65DEE40A-3E93-4cae-9F98-B8E06DCEE2BF} - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRIEPlugin.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
    BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
    BHO: Updater For XFIN_PORTAL: {bb46be07-13eb-4c49-b0f0-fc78b9ea4983} - C:\Program Files (x86)\xfin_portal\auxi\comcastAu.dll
    BHO: {C0114F18-AC58-4188-9C8B-3FE75FAFCA77} - <orphaned>
    BHO: WeCareReminder Class: {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\ProgramData\WeCareReminder\IEHelperv2.5.0.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
    BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
    TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
    TB: XFINITY Toolbar: {4b9bcce8-a70b-402a-a7e1-db96831ee26f} - C:\Program Files (x86)\xfin_portal\comcastdx.dll
    uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
    dRun: [Exetender] "C:\Program Files (x86)\Free Ride Games\GPlayer.exe" /runonstartup
    uPolicies-Explorer: NoDrives = dword:0
    mPolicies-Explorer: NoDrives = dword:0
    mPolicies-Explorer: EnableShellExecuteHooks = dword:1
    mPolicies-Explorer: HideSCAHealth = dword:1
    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
    mPolicies-System: ConsentPromptBehaviorUser = dword:3
    mPolicies-System: EnableUIADesktopToggle = dword:0
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
    IE: Free YouTube Download - C:\Users\Algiz\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
    IE: Free YouTube to MP3 Converter - C:\Users\Algiz\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
    IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
    IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - <orphaned>
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxps://support.dell.com/systemprofiler/SysProExe.CAB
    DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
    TCP: NameServer = 66.228.116.178,66.228.116.179
    TCP: NameServer = 192.168.1.1
    TCP: Interfaces\{39142ED2-76F4-4C33-A7CC-1F089EECE275} : NameServer = 66.228.116.178,66.228.116.179
    TCP: Interfaces\{39142ED2-76F4-4C33-A7CC-1F089EECE275} : DHCPNameServer = 192.168.1.1
    TCP: Interfaces\{39DEC710-C164-4DE1-89B4-7ED0B2F92194} : NameServer = 66.228.116.178,66.228.116.179
    TCP: Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} : NameServer = 66.228.116.178,66.228.116.179
    TCP: Interfaces\{B38C5D08-44C3-4686-9967-58EFBA6FCB72} : NameServer = 66.228.116.178,66.228.116.179
    TCP: Interfaces\{B38C5D08-44C3-4686-9967-58EFBA6FCB72} : DHCPNameServer = 192.168.1.1
    TCP: Interfaces\{B4AD92F9-8E27-425B-8856-4A0DC2A6164C} : NameServer = 66.228.116.178,66.228.116.179
    TCP: Interfaces\{B4AD92F9-8E27-425B-8856-4A0DC2A6164C} : DHCPNameServer = 192.168.1.1
    TCP: Interfaces\{DDB43BBC-3C13-430F-9B48-7099CFAFBD99} : NameServer = 66.228.116.178,66.228.116.179
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    SEH: Directory Opus Shell Execute Hook - {EE761688-C137-4b04-8FAB-3C9CDF0886F0} - C:\Program Files\GPSoftware\Directory Opus\dopuslib32.dll
    mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
    x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
    x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
    x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
    x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
    x64-IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - <orphaned>
    x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    x64-DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
    x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    x64-DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
    x64-Notify: igfxcui - igfxdev.dll
    x64-SEH: Directory Opus Shell Execute Hook - {3CF9ECE0-1A9F-11D2-8C73-00C06C2005DE} - C:\Program Files\GPSoftware\Directory Opus\dopuslib.dll
    .
     
  8. 2013/06/03
    lucianvivant

    lucianvivant Inactive Thread Starter

    Joined:
    2013/05/30
    Messages:
    28
    Likes Received:
    0
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Algiz\AppData\Roaming\Mozilla\Firefox\Profiles\zs33v72y.default\
    FF - prefs.js: browser.search.selectedEngine - IMVU Inc Customized Web Search
    FF - prefs.js: browser.startup.homepage - www.google.com
    FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2612669&SearchSource=2&CUI=UN26468647915944206&UM=&q=
    FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
    FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
    FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
    FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
    FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
    FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll
    FF - plugin: C:\Users\Algiz\AppData\Local\RockMelt\Update\1.2.189.1\npRockMeltOneClick8.dll
    FF - plugin: C:\Users\Algiz\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
    FF - plugin: C:\Windows\npMSDM.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll
    FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
    FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
    FF - ExtSQL: 2013-04-12 08:56; sp@sp.com; C:\Program Files (x86)\Social Privacy\FF
    FF - ExtSQL: 2013-04-23 15:20; {8D150B8F-EFE8-45a3-A4A3-053020F48FAC}; C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt
    FF - ExtSQL: 2013-05-02 14:25; jid1-yZwVFzbsyfMrqQ@jetpack; C:\Users\Algiz\AppData\Roaming\Mozilla\Firefox\Profiles\zs33v72y.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
    FF - ExtSQL: !HIDDEN! 2013-04-23 15:20; {8D150B8F-EFE8-45a3-A4A3-053020F48FAC}; C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: extensions.autoDisableScopes - 0
    FF - user.js: extensions.shownSelectionUI - true
    FF - user.js: extensions.enabledScopes - 15
    user_pref(extensions.newAddons,false);
    FF - user.js: browser.startup.homepage - hxxp://proxy.allsearchapp.com/app/start/
    FF - user.js: browser.search.defaultenginename - All Search
    FF - user.js: browser.search.defaultenginename - All Search
    FF - user.js: browser.newtab.url - hxxp://proxy.allsearchapp.com/app/start/
    FF - user.js: extensions.enabledAddons - sp@sp.com:1.0
    FF - user.js: browser.startup.homepage - www.google.com
    ============= SERVICES / DRIVERS ===============
    .
    R0 gfibto;gfibto;C:\Windows\System32\drivers\gfibto.sys [2013-5-2 14456]
    R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-3-9 55856]
    R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2011-6-14 254528]
    R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
    R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
    R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
    R2 acedrv11;acedrv11;C:\Windows\System32\drivers\acedrv11.sys [2010-2-24 191616]
    R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 27136]
    R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2013-3-28 241152]
    R2 AntiSpywareService;Comcast AntiSpyware;C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe [2009-6-17 616408]
    R2 cpuz135;cpuz135;C:\Windows\System32\drivers\cpuz135_x64.sys [2012-6-28 21992]
    R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648]
    R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-3-9 13336]
    R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-7 418376]
    R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-5-4 503080]
    R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2013-2-14 96768]
    R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-3-9 317440]
    R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2011-3-9 406056]
    R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-12-7 25928]
    R3 PCDSRVC{D3412D80-CF3B4A27-06020200}_0;PCDSRVC{D3412D80-CF3B4A27-06020200}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\My Dell\pcdsrvc_x64.pkms [2013-5-2 25584]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-7 701512]
    S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
    S3 athur;Wireless Network Adapter Service;C:\Windows\System32\drivers\athurx.sys [2011-7-31 1847296]
    S3 gfiark;gfiark;C:\Windows\System32\drivers\gfiark.sys [2013-5-2 38456]
    S3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2011-3-9 158976]
    S3 npggsvc;nProtect GameGuard Service;C:\Windows\System32\GameMon.des -service --> C:\Windows\System32\GameMon.des -service [?]
    S3 OlyCamComm;OLYMPUS USB Communication Device;C:\Windows\System32\drivers\OlyCamComm.sys [2009-9-9 24208]
    S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
    S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
    .
    =============== File Associations ===============
    .
    FileExt: .js: Applications\notepad.exe=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
    ShellExec: switch.exe: open= "C:\Program Files (x86)\NCH Software\Switch\switch" "%L "
    .
    =============== Created Last 30 ================
    .
    2013-05-30 19:38:51 -------- d-----w- C:\Program Files (x86)\Advanced Fix 2013
    2013-05-23 12:28:33 262552 ----a-w- C:\Program Files (x86)\Mozilla Firefox\browser\components\browsercomps.dll
    2013-05-22 00:14:00 -------- d-----w- C:\ProgramData\PC-Doctor for Windows
    2013-05-22 00:13:43 -------- d-----w- C:\Program Files\My Dell
    2013-05-21 02:24:52 -------- d-----w- C:\Users\Algiz\AppData\Local\Two Worlds II
    2013-05-21 02:22:41 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
    2013-05-20 16:44:49 -------- d-----w- C:\Users\Algiz\AppData\Local\DivXNetworks
    2013-05-16 11:31:28 -------- d-----w- C:\Program Files (x86)\Foxy Games
    2013-05-15 01:53:12 17613192 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
    2013-05-14 18:07:19 -------- d-----w- C:\Program Files (x86)\AMD AVT
    2013-05-14 17:54:55 -------- d-----w- C:\Users\Algiz\AppData\Local\4A Games
    2013-05-13 23:25:30 -------- d-----w- C:\Users\Algiz\AppData\Roaming\StarDrive
    2013-05-13 23:21:04 -------- d-----w- C:\Program Files (x86)\StarDrive
    .
    ==================== Find3M ====================
    .
    2013-05-15 02:53:26 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2013-05-15 02:53:26 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2013-05-02 21:24:31 14456 ----a-w- C:\Windows\System32\drivers\gfibto.sys
    2013-04-08 21:56:44 189248 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
    2013-04-08 21:56:43 75136 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
    2013-04-04 21:50:32 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2013-04-01 18:03:46 727952 ----a-w- C:\Windows\SysWow64\WSCM64.dll
    2013-04-01 18:03:42 153088 ----a-w- C:\Windows\SysWow64\WSCM32.dll
    2013-03-29 02:37:10 78432 ----a-w- C:\Windows\System32\atimpc64.dll
    2013-03-29 02:37:10 78432 ----a-w- C:\Windows\System32\amdpcom64.dll
    2013-03-29 02:37:10 71704 ----a-w- C:\Windows\SysWow64\atimpc32.dll
    2013-03-29 02:37:10 71704 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
    2013-03-29 02:37:06 139696 ----a-w- C:\Windows\System32\atiuxp64.dll
    2013-03-29 02:37:04 92304 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
    2013-03-29 02:37:04 118584 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
    2013-03-29 02:37:04 112440 ----a-w- C:\Windows\System32\atiu9p64.dll
    2013-03-29 02:37:02 1155264 ----a-w- C:\Windows\System32\aticfx64.dll
    2013-03-29 02:37:00 970912 ----a-w- C:\Windows\SysWow64\aticfx32.dll
    2013-03-29 02:36:56 8272136 ----a-w- C:\Windows\System32\atidxx64.dll
    2013-03-29 02:36:54 7233336 ----a-w- C:\Windows\SysWow64\atidxx32.dll
    2013-03-29 02:36:50 4450264 ----a-w- C:\Windows\SysWow64\atiumdva.dll
    2013-03-29 02:36:44 5944264 ----a-w- C:\Windows\SysWow64\atiumdag.dll
    2013-03-29 02:36:40 5000320 ----a-w- C:\Windows\System32\atiumd6a.dll
    2013-03-29 02:36:38 6985624 ----a-w- C:\Windows\System32\atiumd64.dll
    2013-03-29 02:35:02 11658752 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
    2013-03-29 02:13:28 222720 ----a-w- C:\Windows\System32\clinfo.exe
    2013-03-29 02:13:14 798734 ----a-w- C:\Windows\SysWow64\amdocl_ld32.exe
    2013-03-29 02:13:14 1187342 ----a-w- C:\Windows\System32\amdocl_as64.exe
    2013-03-29 02:13:14 1061902 ----a-w- C:\Windows\System32\amdocl_ld64.exe
    2013-03-29 02:13:12 995342 ----a-w- C:\Windows\SysWow64\amdocl_as32.exe
    2013-03-29 02:13:08 76288 ----a-w- C:\Windows\System32\OpenVideo64.dll
    2013-03-29 02:13:04 65536 ----a-w- C:\Windows\SysWow64\OpenVideo.dll
    2013-03-29 02:13:00 64000 ----a-w- C:\Windows\System32\OVDecode64.dll
    2013-03-29 02:12:56 56320 ----a-w- C:\Windows\SysWow64\OVDecode.dll
    2013-03-29 02:12:48 29150720 ----a-w- C:\Windows\System32\amdocl64.dll
    2013-03-29 02:10:52 23810560 ----a-w- C:\Windows\SysWow64\amdocl.dll
    2013-03-29 02:09:04 54784 ----a-w- C:\Windows\System32\OpenCL.dll
    2013-03-29 02:09:00 50176 ----a-w- C:\Windows\SysWow64\OpenCL.dll
    2013-03-29 02:04:42 24229376 ----a-w- C:\Windows\System32\atio6axx.dll
    2013-03-29 02:00:54 76800 ----a-w- C:\Windows\System32\coinst_12.104.dll
    2013-03-29 01:57:54 163840 ----a-w- C:\Windows\System32\atiapfxx.exe
    2013-03-29 01:55:36 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
    2013-03-29 01:55:34 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
    2013-03-29 01:55:28 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
    2013-03-29 01:55:28 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
    2013-03-29 01:55:16 16082944 ----a-w- C:\Windows\System32\aticaldd64.dll
    2013-03-29 01:51:04 13703168 ----a-w- C:\Windows\SysWow64\aticaldd.dll
    2013-03-29 01:48:26 19870720 ----a-w- C:\Windows\SysWow64\atioglxx.dll
    2013-03-29 01:35:14 442368 ----a-w- C:\Windows\System32\atidemgy.dll
    2013-03-29 01:35:06 562688 ----a-w- C:\Windows\System32\atieclxx.exe
    2013-03-29 01:34:18 241152 ----a-w- C:\Windows\System32\atiesrxx.exe
    2013-03-29 01:33:00 120320 ----a-w- C:\Windows\System32\atitmm64.dll
    2013-03-29 01:32:46 26112 ----a-w- C:\Windows\System32\atimuixx.dll
    2013-03-29 01:32:42 59392 ----a-w- C:\Windows\System32\atiedu64.dll
    2013-03-29 01:32:36 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
    2013-03-29 01:10:30 636416 ----a-w- C:\Windows\System32\atiadlxx.dll
    2013-03-29 01:10:20 430080 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
    2013-03-29 01:10:08 17920 ----a-w- C:\Windows\System32\atig6pxx.dll
    2013-03-29 01:10:04 14848 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
    2013-03-29 01:10:04 14848 ----a-w- C:\Windows\System32\atiglpxx.dll
    2013-03-29 01:10:00 44032 ----a-w- C:\Windows\System32\atig6txx.dll
    2013-03-29 01:09:52 34816 ----a-w- C:\Windows\SysWow64\atigktxx.dll
    2013-03-29 01:09:44 581120 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
    2013-03-29 01:07:52 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
    .
    ============= FINISH: 13:54:56.46 ===============
     
  9. 2013/06/03
    lucianvivant

    lucianvivant Inactive Thread Starter

    Joined:
    2013/05/30
    Messages:
    28
    Likes Received:
    0
    i have posted all documents but only part 1 of the dds report is showing up.. am i doign somethign wrong?
     
  10. 2013/06/03
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Re-run DDS and see if you'll get 2nd log.

    Then...

    [​IMG] Download RogueKiller for 32bit or Roguekiller for 64bit to your Desktop.
    • Close all the running programs
    • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    [​IMG] Download Malwarebytes Anti-Rootkit (MBAR) from HERE
    • Unzip downloaded file.
    • Open the folder where the contents were unzipped and run mbar.exe
    • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
    • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
    • Wait while the system shuts down and the cleanup process is performed.
    • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
    • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log-xxxxx.txt and system-log.txt
     
  11. 2013/06/03
    lucianvivant

    lucianvivant Inactive Thread Starter

    Joined:
    2013/05/30
    Messages:
    28
    Likes Received:
    0
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2012-11-20.01)
    .
    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume2
    Install Date: 6/13/2011 7:50:51 PM
    System Uptime: 5/31/2013 1:54:02 AM (84 hours ago)
    .
    Motherboard: Dell Inc. | | 0Y2MRG
    Processor: Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz | CPU 1 | 2584/100mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 1385 GiB total, 9.5 GiB free.
    D: is CDROM ()
    E: is Removable
    F: is Removable
    G: is Removable
    H: is Removable
    I: is CDROM ()
    J: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
    Description: X5XSEx
    Device ID: ROOT\LEGACY_X5XSEX\0000
    Manufacturer:
    Name: X5XSEx
    PNP Device ID: ROOT\LEGACY_X5XSEX\0000
    Service: X5XSEx
    .
    ==== System Restore Points ===================
    .
    No restore point in system.
    .
    ==== Installed Programs ======================
    .
    7-Zip 9.20
    Adobe Flash Player 11 ActiveX
    Adobe Flash Player 11 Plugin
    Adobe Reader X (10.1.1)
    Advanced Fix 2013 version 2.0.1.108
    Akamai NetSession Interface
    Akamai NetSession Interface Service
    AMD Accelerated Video Transcoding
    AMD APP SDK Runtime
    AMD Catalyst Install Manager
    AMD Drag and Drop Transcoding
    AMD Media Foundation Decoders
    Angry Birds Seasons
    Anna - Extended Edition (c) Kalypso Media version 1
    Apple Application Support
    Apple Software Update
    Application Profiles
    ASPCA Reminder by We-Care.com v4.0.19.1
    Assassin's Creed Revelations
    Auslogics Duplicate File Finder
    Best Buy pc app
    BitTorrent
    CA Pest Patrol Realtime Protection
    Catalyst Control Center
    Catalyst Control Center - Branding
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center InstallProxy
    Catalyst Control Center Localization All
    ccc-core-static
    ccc-utility64
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help Czech
    CCC Help Danish
    CCC Help Dutch
    CCC Help English
    CCC Help Finnish
    CCC Help French
    CCC Help German
    CCC Help Greek
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Norwegian
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Russian
    CCC Help Spanish
    CCC Help Swedish
    CCC Help Thai
    CCC Help Turkish
    CCleaner
    CDBurnerXP
    Comcast Desktop Software (v1.2.1)
    CPUID HWMonitor 1.19
    D3DX10
    DAEMON Tools Lite
    Damnation
    Dark Tales Edgar Allan Poes The Masque of the Red Death CE 1.00
    Darkness Within 2: The Dark Lineage
    Dead Island Riptide (c) Deep Silver version 1
    Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
    Dell Dock
    Dell Edoc Viewer
    Dell Getting Started Guide
    Dell Product Registration
    DirectX 9 Runtime
    DivX Setup
    DNS Shield
    Driver Sweeper version 3.2.0
    DriverFinder
    DriverIdentifier 3.5
    DW WLAN Card
    Easy DVD Creator 2.4.9
    EuropeMapleStory
    Fallout New Vegas
    FileHippo.com Update Checker
    Frayed Knights 1
    Free Alarm Clock 2.3.3
    Free Audio CD Burner version 1.5.7.504
    Free Studio version 5.5.0
    Geeks3D.com FurMark 1.10.1
    Gemini Rue
    Google Chrome
    Google Update Helper
    GPSoftware Directory Opus
    Grand Theft Auto: Episodes from Liberty City
    Intel(R) Graphics Media Accelerator Driver
    Intel(R) Rapid Storage Technology
    Internet Browser
    Java 7 Update 7 (64-bit)
    Java 7 Update 9
    Java Auto Updater
    Java(TM) 6 Update 30
    Java(TM) 6 Update 31 (64-bit)
    JavaFX 2.1.1
    Junk Mail filter update
    Malwarebytes Anti-Malware version 1.75.0.1300
    Mesh Runtime
    Messenger Companion
    Microsoft .NET Framework 4 Client Profile
    Microsoft .NET Framework 4 Extended
    Microsoft Application Error Reporting
    Microsoft Download Manager
    Microsoft Games for Windows - LIVE Redistributable
    Microsoft Games for Windows Marketplace
    Microsoft Office 2010
    Microsoft Office 2010 Service Pack 1 (SP1)
    Microsoft Office Access MUI (English) 2010
    Microsoft Office Access Setup Metadata MUI (English) 2010
    Microsoft Office Excel MUI (English) 2010
    Microsoft Office Home and Student 2010
    Microsoft Office Office 64-bit Components 2010
    Microsoft Office OneNote MUI (English) 2010
    Microsoft Office Outlook MUI (English) 2010
    Microsoft Office PowerPoint MUI (English) 2010
    Microsoft Office Proof (English) 2010
    Microsoft Office Proof (French) 2010
    Microsoft Office Proof (Spanish) 2010
    Microsoft Office Proofing (English) 2010
    Microsoft Office Publisher MUI (English) 2010
    Microsoft Office Shared 64-bit MUI (English) 2010
    Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
    Microsoft Office Shared MUI (English) 2010
    Microsoft Office Shared Setup Metadata MUI (English) 2010
    Microsoft Office Single Image 2010
    Microsoft Office Word MUI (English) 2010
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2005 Redistributable (x64)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    Microsoft WSE 3.0 Runtime
    Microsoft XNA Framework Redistributable 3.1
    Mozilla Firefox 21.0 (x86 en-US)
    Mozilla Maintenance Service
    MSVCRT
    MSVCRT_amd64
    Multimedia Card Reader
    My Dell
    Nero Burning ROM 10
    Nero BurningROM 10 Help (CHM)
    Nero BurnRights 10
    Nero BurnRights 10 Help (CHM)
    Nero Control Center 10
    Nero ControlCenter 10 Help (CHM)
    Nero Core Components 10
    Nero Toolbar Updater
    Nero Update
    Northmark - Hour of the Wolf
    NVIDIA PhysX
    OLYMPUS ib
    OpenAL
    Pando Media Booster
    PhotoShowExpress
    Pinnacle Studio 16 - Install Manager
    Primordia
    ProtectDisc Driver, Version 11
    PunkBuster Services
    QuickTime
    RBVirtualFolder64Inst
    Realtek High Definition Audio Driver
    Red Faction Guerrilla
    Reset Your Browser
    RockMelt
    Rockstar Games Social Club
    Roxio Activation Module
    Roxio BackOnTrack
    Roxio Burn
    Roxio Creator Starter
    Roxio Express Labeler 3
    Roxio File Backup
    Sam and Max The - Devil's Playhouse
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
    Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
    Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
    Security Update for Microsoft Excel 2010 (KB2597166) 32-Bit Edition
    Security Update for Microsoft InfoPath 2010 (KB2553322) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2553091)
    Security Update for Microsoft Office 2010 (KB2553096)
    Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2598039) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
    Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
    Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)
    Security Update for Microsoft Visio Viewer 2010 (KB2597981) 32-Bit Edition
    SlimDX Redistributable (June 2010)
    Social Privacy
    Sonic CinePlayer Decoder Pack
    SpeedFan (remove only)
    StarDrive
    Steam
    SUPERAntiSpyware
    Switch Sound File Converter
    System Requirements Lab for Intel
    The Dark Eye - Chains of Satinav
    THX TruStudio PC
    TP-LINK Wireless Client Utility
    Trine 2
    Tron: Evolution
    Two Worlds II Epic Edition
    Ubisoft Game Launcher
    Unity Web Player
    Update for Microsoft Office 2010 (KB2553065)
    Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2566458)
    Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
    Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
    Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition
    Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition
    Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
    Uplay
    VC80CRTRedist - 8.0.50727.6195
    Visual Studio 2008 x64 Redistributables
    VLC media player 2.0.5
    WhoCrashed 3.05
    Windows Driver Package - OLYMPUS IMAGING CORP. Camera Communication Driver Package (09/09/2009 1.0.0.0)
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live ID Sign-in Assistant
    Windows Live Installer
    Windows Live Language Selector
    Windows Live Mail
    Windows Live Mesh
    Windows Live Mesh ActiveX Control for Remote Connections
    Windows Live Messenger
    Windows Live Messenger Companion Core
    Windows Live MIME IFilter
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live Remote Client
    Windows Live Remote Client Resources
    Windows Live Remote Service
    Windows Live Remote Service Resources
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    WinRAR 4.01 (32-bit)
    WinRAR 4.01 (64-bit)
    WinX Free MP4 to AVI Converter 4.1.14
    Wondershare Video Converter Ultimate(Build 6.0.4.0)
    XFINITY Toolbar
    Yahoo! Messenger
    Yahoo! Toolbar
    .
    ==== Event Viewer Messages From Past Week ========
    .
    6/3/2013 5:43:55 AM, Error: volsnap [35] - The shadow copies of volume C: were aborted because the shadow copy

    storage failed to grow.
    5/30/2013 6:20:28 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s)

    failed to load: AVGIDSHA
    5/30/2013 6:20:24 AM, Error: Service Control Manager [7000] - The X5XSEx service failed to start due to the

    following error: The system cannot find the path specified.
    5/30/2013 6:20:23 AM, Error: Service Control Manager [7023] - The Windows Defender service terminated with the

    following error: The specified module could not be found.
    5/30/2013 6:18:29 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server

    service which failed to start because of the following error: The dependency service or group failed to start.
    5/30/2013 4:07:00 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start

    the service BITS with arguments " " in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
    5/30/2013 3:55:19 AM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the

    Function Discovery Provider Host service which failed to start because of the following error: The dependency

    service or group failed to start.
    5/30/2013 3:55:19 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start

    the service WSearch with arguments " " in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
    5/30/2013 3:55:18 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start

    the service WSearch with arguments " " in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
    5/30/2013 3:55:17 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start

    the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    5/30/2013 3:55:11 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start

    the service ShellHWDetection with arguments " " in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
    5/30/2013 3:54:12 AM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to

    start. Module Path: C:\Windows\System32\bcmihvsrv64.dll Error Code: 21
    5/30/2013 3:53:54 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s)

    failed to load: AVGIDSHA discache SASDIFSV SASKUTIL spldr Wanarpv6
    .
    ==== End Of File ===========================
     
  12. 2013/06/03
    lucianvivant

    lucianvivant Inactive Thread Starter

    Joined:
    2013/05/30
    Messages:
    28
    Likes Received:
    0
    that was the other log.. i meant it wasent showign up on thiss site.. i jsut saw that it neds to be verififed by moderator.. so i never sent that one in this thread.. thats the attach file from dds

    do yous till want me to run the other programs as stated?
     
  13. 2013/06/03
    lucianvivant

    lucianvivant Inactive Thread Starter

    Joined:
    2013/05/30
    Messages:
    28
    Likes Received:
    0
    also i use cclean but never mess much with register stuff.. and do do torrented games.. but always make sure they are from reputible sources..

    this jsut started and only happens when i right click on anythign and it seems to effect typign in firefox more than IE.. so im using IE to ype in here now.. hope this info helps you as well
     
  14. 2013/06/03
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I just approved your post with Attach.txt log.

    Go on with other scans...
     
  15. 2013/06/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Still with me?
     
  16. 2013/06/10
    lucianvivant

    lucianvivant Inactive Thread Starter

    Joined:
    2013/05/30
    Messages:
    28
    Likes Received:
    0
    i apologize.. my internet connection was out for a few days.. i will post the other scans as soon as i download them.
     
  17. 2013/06/10
    lucianvivant

    lucianvivant Inactive Thread Starter

    Joined:
    2013/05/30
    Messages:
    28
    Likes Received:
    0
    the rogue kilelr keeps freezing on rundll32.exe

    i open rogue killer and dont start anything it does its pre thing.. and then it goes about 14% done and stops and freezes at rundll32.exe..


    ive let it run thinking it may take a while buit its been on that for an hour.. any ideas?
     
  18. 2013/06/10
    lucianvivant

    lucianvivant Inactive Thread Starter

    Joined:
    2013/05/30
    Messages:
    28
    Likes Received:
    0
    did you get my message about the roguekill freezind at the rundll32.exe?
     
  19. 2013/06/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    [​IMG]
     
  20. 2013/06/10
    lucianvivant

    lucianvivant Inactive Thread Starter

    Joined:
    2013/05/30
    Messages:
    28
    Likes Received:
    0
    broni.. there was no message in it.. ive run rogue killer 4 times now.. and it freezes at that file.. and then i have to restartt the computer because i cannot kill the process..
     
  21. 2013/06/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Go ahead with MBAR.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.