EvilRev
2012-11-07, 05:47
I keep hearing the windows usb disconnect sound twice in a row once every hour or so. It will not stop even when i reinstall windows. The computer was not doing this when i first got it. Here are the logs...
:oreo: DDS Log
DDS (Ver_2012-10-19.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16421
Run by Brandon at 22:30:44 on 2012-11-06
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8143.5996 [GMT -5:00]
.
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Windows\System32\TiltWheelMouse.exe
C:\Games\Steam\Steam.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorIcon.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\SymcPCCULaunchSvc.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\ccSvcHst.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\ccSvcHst.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.msn.com
uDefault_Page_URL = hxxp://www.msn.com
mStart Page = hxxp://www.msn.com
mDefault_Page_URL = hxxp://www.msn.com
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coieplg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ips\ipsbho.dll
BHO: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll
BHO: Windows Live Toolbar Helper: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coieplg.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [Steam] "C:\Games\Steam\steam.exe" -silent
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorIcon.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
StartupFolder: C:\Users\Brandon\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{AEB50B75-BCF4-46A5-B126-1F19924C3192} : DHCPNameServer = 192.168.1.1
SSODL: WebCheck - <orphaned>
x64-mStart Page = hxxp://www.msn.com
x64-mDefault_Page_URL = hxxp://www.msn.com
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [MouseDriver] TiltWheelMouse.exe
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 asahci64;asahci64;C:\Windows\System32\drivers\asahci64.sys [2012-1-6 49760]
R0 iaStorA;iaStorA;C:\Windows\System32\drivers\iaStorA.sys [2011-12-2 565528]
R0 iaStorF;iaStorF;C:\Windows\System32\drivers\iaStorF.sys [2012-10-30 23832]
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NISx64\1309000.009\symds64.sys [2012-10-31 451192]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1309000.009\symefa64.sys [2012-10-31 1129120]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20121030.002\BHDrvx64.sys [2012-11-5 1385632]
R1 ccSet_NIS;Norton Internet Security Settings Manager;C:\Windows\System32\drivers\NISx64\1309000.009\ccsetx64.sys [2012-10-31 167072]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20121106.001\IDSviA64.sys [2012-11-6 513184]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NISx64\1309000.009\ironx64.sys [2012-10-31 190072]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\NISx64\1309000.009\symnets.sys [2012-10-31 405624]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-9-23 65192]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccsvchst.exe [2012-10-31 138272]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\SymcPCCULaunchSvc.exe [2012-10-30 123320]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-30 1258856]
R2 PCCUJobMgr;Common Client Job Manager Service;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\ccSvcHst.exe [2012-10-30 126392]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2011-11-3 130536]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2011-11-3 395752]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-10-30 138912]
R3 MEIx64;Intel(R) Management Engine Interface ;C:\Windows\System32\drivers\HECIx64.sys [2012-10-30 56600]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-10-30 677480]
R3 t_mouse.sys;iBall Advanced Mouse;C:\Windows\System32\drivers\t_mouse.sys [2009-4-16 25088]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-30 136176]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-30 136176]
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe [2012-9-5 234776]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-3-1 1255736]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120]
.
=============== Created Last 30 ================
.
2012-11-05 17:52:53 -------- d-----w- C:\TDSSKiller_Quarantine
2012-11-01 05:47:16 902656 ----a-w- C:\Windows\System32\d2d1.dll
2012-11-01 05:47:16 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
2012-11-01 05:47:16 1139200 ----a-w- C:\Windows\System32\FntCache.dll
2012-11-01 02:18:00 737952 ----a-w- C:\Windows\System32\drivers\NISx64\1309000.009\srtsp64.sys
2012-11-01 02:18:00 451192 ----a-r- C:\Windows\System32\drivers\NISx64\1309000.009\symds64.sys
2012-11-01 02:18:00 405624 ----a-w- C:\Windows\System32\drivers\NISx64\1309000.009\symnets.sys
2012-11-01 02:18:00 37536 ----a-w- C:\Windows\System32\drivers\NISx64\1309000.009\srtspx64.sys
2012-11-01 02:18:00 190072 ----a-w- C:\Windows\System32\drivers\NISx64\1309000.009\ironx64.sys
2012-11-01 02:18:00 167072 ----a-w- C:\Windows\System32\drivers\NISx64\1309000.009\ccsetx64.sys
2012-11-01 02:18:00 1129120 ----a-w- C:\Windows\System32\drivers\NISx64\1309000.009\symefa64.sys
2012-11-01 02:17:54 -------- d-----w- C:\Windows\System32\drivers\NISx64\1309000.009
2012-10-31 17:29:06 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-10-31 17:29:06 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-10-31 17:29:06 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-10-31 17:29:05 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-10-31 17:29:05 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-10-31 07:50:48 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-10-31 07:49:59 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-10-31 07:48:35 245760 ----a-w- C:\Windows\System32\OxpsConverter.exe
2012-10-31 07:48:10 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
2012-10-31 07:48:10 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys
2012-10-31 07:48:10 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2012-10-31 07:48:07 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2012-10-31 07:48:07 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2012-10-31 07:48:07 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2012-10-31 07:48:07 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2012-10-31 07:48:01 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-10-31 07:46:56 503808 ----a-w- C:\Windows\System32\srcore.dll
2012-10-31 07:46:55 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
2012-10-31 07:46:36 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2012-10-31 07:46:28 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2012-10-31 07:46:28 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2012-10-31 07:46:20 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll
2012-10-31 07:46:20 634880 ----a-w- C:\Windows\System32\msvcrt.dll
2012-10-31 07:45:57 956928 ----a-w- C:\Windows\System32\localspl.dll
2012-10-31 07:45:50 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2012-10-31 07:45:39 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2012-10-31 07:45:39 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2012-10-31 07:45:39 331776 ----a-w- C:\Windows\System32\oleacc.dll
2012-10-31 07:45:39 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2012-10-31 07:45:32 723456 ----a-w- C:\Windows\System32\EncDec.dll
2012-10-31 07:45:32 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2012-10-31 07:44:07 751104 ----a-w- C:\Windows\System32\win32spl.dll
2012-10-31 07:44:07 67072 ----a-w- C:\Windows\splwow64.exe
2012-10-31 07:44:07 559104 ----a-w- C:\Windows\System32\spoolsv.exe
2012-10-31 07:44:07 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll
2012-10-31 07:43:38 77312 ----a-w- C:\Windows\System32\packager.dll
2012-10-31 07:43:38 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2012-10-31 01:05:17 -------- d-----w- C:\Program Files (x86)\Datel
2012-10-31 00:40:26 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2012-10-31 00:39:58 54200 ----a-w- C:\Windows\System32\drivers\dsiarhwprog_x64.sys
2012-10-30 23:40:50 -------- d-----w- C:\ProgramData\Blizzard Entertainment
2012-10-30 23:40:50 -------- d-----w- C:\Program Files (x86)\Common Files\Blizzard Entertainment
2012-10-30 23:39:13 -------- d-----w- C:\ProgramData\Battle.net
2012-10-30 23:07:42 -------- d-----w- C:\Users\Brandon\AppData\Local\CrashDumps
2012-10-30 22:37:39 77656 ----a-w- C:\Windows\System32\XAPOFX1_5.dll
2012-10-30 22:36:30 111960 ----a-w- C:\Windows\dxsdkuninst.exe
2012-10-30 22:36:30 -------- d-----w- C:\Program Files (x86)\Microsoft DirectX SDK (June 2010)
2012-10-30 21:53:10 -------- d-----w- C:\Users\Brandon\AppData\Local\Adobe
2012-10-30 21:52:28 -------- d-----w- C:\Program Files (x86)\Common Files\Intel Corporation
2012-10-30 21:48:56 -------- d-----w- C:\ProgramData\McAfee Security Scan
2012-10-30 21:48:53 -------- d-----w- C:\Program Files (x86)\McAfee Security Scan
2012-10-30 21:10:43 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2012-10-30 20:12:49 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2012-10-30 20:09:15 -------- d-----r- C:\Games
2012-10-30 19:26:53 891240 ----a-w- C:\Windows\System32\nvvsvc.exe
2012-10-30 19:26:53 63336 ----a-w- C:\Windows\System32\nvshext.dll
2012-10-30 19:26:53 6200680 ----a-w- C:\Windows\System32\nvcpl.dll
2012-10-30 19:26:53 3536817 ----a-w- C:\Windows\System32\nvcoproc.bin
2012-10-30 19:26:53 3293544 ----a-w- C:\Windows\System32\nvsvc64.dll
2012-10-30 19:26:53 2557800 ----a-w- C:\Windows\System32\nvsvcr.dll
2012-10-30 19:26:53 118120 ----a-w- C:\Windows\System32\nvmctray.dll
2012-10-30 19:25:43 60776 ----a-w- C:\Windows\System32\OpenCL.dll
2012-10-30 19:25:43 52584 ----a-w- C:\Windows\SysWow64\OpenCL.dll
2012-10-30 19:24:34 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2012-10-30 19:24:29 -------- d-----w- C:\Program Files\NVIDIA Corporation
2012-10-30 19:24:29 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2012-10-30 19:17:49 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-10-30 19:17:49 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-10-30 19:17:49 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-10-30 19:14:37 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-10-30 19:14:25 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-10-30 19:14:05 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-10-30 19:14:05 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-10-30 19:08:15 -------- d-----w- C:\Program Files (x86)\ASUS
2012-10-30 19:07:13 -------- d-----w- C:\Program Files (x86)\ASM104xUSB3
2012-10-30 19:06:11 74344 ----a-w- C:\Windows\System32\RtNicProp64.dll
2012-10-30 19:06:11 677480 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys
2012-10-30 19:06:11 107552 ----a-w- C:\Windows\System32\RTNUninst64.dll
2012-10-30 19:05:21 -------- d-----w- C:\Program Files (x86)\ASM106xSATA
2012-10-30 19:05:08 8192 ----a-w- C:\Windows\System32\drivers\IntelMEFWVer.dll
2012-10-30 19:04:58 56600 ----a-w- C:\Windows\System32\drivers\HECIx64.sys
2012-10-30 19:02:58 -------- d-----w- C:\Users\Brandon\AppData\Roaming\Intel Corporation
2012-10-30 18:59:59 81248 ----a-w- C:\Windows\System32\SFCOM64.dll
2012-10-30 18:54:19 23832 ----a-w- C:\Windows\System32\drivers\iaStorF.sys
2012-10-30 18:51:19 -------- d-----w- C:\Windows\AsusInstAll
2012-10-30 18:49:24 53248 ----a-r- C:\Windows\SysWow64\CSVer.dll
2012-10-30 18:47:59 296320 ----a-w- C:\Windows\System32\drivers\volsnap.sys
2012-10-30 18:43:53 -------- d-----w- C:\Users\Brandon\AppData\Local\Google
2012-10-30 18:42:23 175736 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2012-10-30 18:42:23 -------- d-----w- C:\Program Files\Symantec
2012-10-30 18:42:23 -------- d-----w- C:\Program Files\Common Files\Symantec Shared
2012-10-30 18:41:25 -------- d-----w- C:\Windows\System32\drivers\NISx64
2012-10-30 18:41:24 -------- d-----w- C:\Program Files (x86)\Norton Internet Security
2012-10-30 18:39:09 -------- d-----w- C:\Windows\System32\drivers\NortonPCCheckupx64\02000F0.060
2012-10-30 18:39:09 -------- d-----w- C:\Windows\System32\drivers\NortonPCCheckupx64
2012-10-30 18:39:08 -------- d-----w- C:\ProgramData\Norton
2012-10-30 18:39:08 -------- d-----w- C:\Program Files (x86)\Norton PC Checkup
2012-10-30 18:39:04 -------- d-----w- C:\ProgramData\NortonInstaller
2012-10-30 18:39:04 -------- d-----w- C:\Program Files (x86)\NortonInstaller
2012-10-30 18:27:18 -------- d-----w- C:\Users\Brandon\AppData\Local\Diagnostics
2012-10-30 18:26:55 -------- d-----w- C:\Users\Brandon\AppData\Local\ElevatedDiagnostics
2012-10-30 18:19:04 -------- d-----w- C:\Users\Brandon\AppData\Local\VirtualStore
2012-10-16 23:03:05 -------- d-sh--w- C:\Recovery
2012-10-11 01:22:54 2428776 ----a-w- C:\Windows\SysWow64\nvapi.dll
2012-10-11 01:22:52 26331496 ----a-w- C:\Windows\System32\nvoglv64.dll
2012-10-11 01:22:52 1760104 ----a-w- C:\Windows\System32\nvdispco64.dll
2012-10-11 01:22:32 15309160 ----a-w- C:\Windows\SysWow64\nvd3dum.dll
2012-10-11 01:22:26 2747240 ----a-w- C:\Windows\System32\nvcuvid.dll
2012-10-11 01:22:24 364904 ----a-w- C:\Windows\System32\nvEncodeAPI64.dll
2012-10-11 01:22:24 19906920 ----a-w- C:\Windows\SysWow64\nvoglv32.dll
2012-10-11 01:22:18 13443944 ----a-w- C:\Windows\System32\drivers\nvlddmkm.sys
2012-10-11 01:22:14 17559912 ----a-w- C:\Windows\SysWow64\nvcompiler.dll
.
==================== Find3M ====================
.
2012-10-11 01:23:48 247144 ----a-w- C:\Windows\System32\nvinitx.dll
2012-10-02 17:15:52 430952 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2012-09-14 19:19:29 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-09-14 18:28:53 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-08-31 18:19:35 1659760 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2012-08-30 17:12:02 3968880 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12:02 3914096 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-08-24 18:05:07 220160 ----a-w- C:\Windows\System32\wintrust.dll
2012-08-24 16:57:48 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-08-22 18:12:50 1913200 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-08-22 18:12:40 950128 ----a-w- C:\Windows\System32\drivers\ndis.sys
2012-08-22 18:12:40 376688 ----a-w- C:\Windows\System32\drivers\netio.sys
2012-08-22 18:12:33 288624 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2012-08-20 18:48:44 362496 ----a-w- C:\Windows\System32\wow64win.dll
2012-08-20 18:48:44 243200 ----a-w- C:\Windows\System32\wow64.dll
2012-08-20 18:48:44 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2012-08-20 18:48:43 215040 ----a-w- C:\Windows\System32\winsrv.dll
2012-08-20 18:48:37 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2012-08-20 18:48:35 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2012-08-20 18:46:22 338432 ----a-w- C:\Windows\System32\conhost.exe
2012-08-20 17:40:21 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-08-20 17:38:44 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2012-08-20 17:38:26 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2012-08-20 17:37:19 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2012-08-20 17:37:18 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2012-08-20 15:38:21 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2012-08-20 15:38:20 2048 ----a-w- C:\Windows\SysWow64\user.exe
2012-08-20 15:33:28 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-08-20 15:33:28 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-08-20 15:33:28 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-08-20 15:33:28 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-08-11 00:56:03 715776 ----a-w- C:\Windows\System32\kerberos.dll
2012-08-10 23:56:14 542208 ----a-w- C:\Windows\SysWow64\kerberos.dll
.
============= FINISH: 22:31:06.65 ===============
:oreo: aswMBR Log
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-11-06 22:34:48
-----------------------------
22:34:48.980 OS Version: Windows x64 6.1.7601 Service Pack 1
22:34:48.980 Number of processors: 8 586 0x2D07
22:34:48.980 ComputerName: BLACKPEARL UserName: Brandon
22:34:50.241 Initialize success
22:36:48.678 AVAST engine defs: 12110602
22:36:57.946 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000006a
22:36:57.947 Disk 0 Vendor: ATA_____ A610 Size: 953869MB BusType: 11
22:36:57.955 Disk 0 MBR read successfully
22:36:57.957 Disk 0 MBR scan
22:36:57.959 Disk 0 Windows 7 default MBR code
22:36:57.974 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
22:36:57.992 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848
22:36:58.002 Disk 0 scanning C:\Windows\system32\drivers
22:37:03.934 Service scanning
22:37:18.151 Modules scanning
22:37:18.154 Disk 0 trace - called modules:
22:37:18.254 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorF.sys ACPI.sys storport.sys hal.dll iaStorA.sys
22:37:18.256 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007f1c790]
22:37:18.259 3 CLASSPNP.SYS[fffff8800465143f] -> nt!IofCallDriver -> [0xfffffa8007e24c50]
22:37:18.262 5 iaStorF.sys[fffff880048652fa] -> nt!IofCallDriver -> [0xfffffa8007b26040]
22:37:18.265 7 ACPI.sys[fffff88000f887a1] -> nt!IofCallDriver -> \Device\0000006a[0xfffffa8007b17430]
22:37:19.516 AVAST engine scan C:\Windows
22:37:20.908 AVAST engine scan C:\Windows\system32
22:38:58.878 AVAST engine scan C:\Windows\system32\drivers
22:39:06.710 AVAST engine scan C:\Users\Brandon
22:39:38.500 AVAST engine scan C:\ProgramData
22:39:55.033 Scan finished successfully
22:40:09.349 Disk 0 MBR has been saved successfully to "C:\Users\Brandon\Desktop\MBR.dat"
22:40:09.352 The log file has been saved successfully to "C:\Users\Brandon\Desktop\aswMBR.txt"
:oreo: DDS Log
DDS (Ver_2012-10-19.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16421
Run by Brandon at 22:30:44 on 2012-11-06
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8143.5996 [GMT -5:00]
.
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Windows\System32\TiltWheelMouse.exe
C:\Games\Steam\Steam.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorIcon.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\SymcPCCULaunchSvc.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\ccSvcHst.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\ccSvcHst.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.msn.com
uDefault_Page_URL = hxxp://www.msn.com
mStart Page = hxxp://www.msn.com
mDefault_Page_URL = hxxp://www.msn.com
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coieplg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ips\ipsbho.dll
BHO: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll
BHO: Windows Live Toolbar Helper: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coieplg.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [Steam] "C:\Games\Steam\steam.exe" -silent
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorIcon.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
StartupFolder: C:\Users\Brandon\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{AEB50B75-BCF4-46A5-B126-1F19924C3192} : DHCPNameServer = 192.168.1.1
SSODL: WebCheck - <orphaned>
x64-mStart Page = hxxp://www.msn.com
x64-mDefault_Page_URL = hxxp://www.msn.com
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [MouseDriver] TiltWheelMouse.exe
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 asahci64;asahci64;C:\Windows\System32\drivers\asahci64.sys [2012-1-6 49760]
R0 iaStorA;iaStorA;C:\Windows\System32\drivers\iaStorA.sys [2011-12-2 565528]
R0 iaStorF;iaStorF;C:\Windows\System32\drivers\iaStorF.sys [2012-10-30 23832]
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NISx64\1309000.009\symds64.sys [2012-10-31 451192]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1309000.009\symefa64.sys [2012-10-31 1129120]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20121030.002\BHDrvx64.sys [2012-11-5 1385632]
R1 ccSet_NIS;Norton Internet Security Settings Manager;C:\Windows\System32\drivers\NISx64\1309000.009\ccsetx64.sys [2012-10-31 167072]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20121106.001\IDSviA64.sys [2012-11-6 513184]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NISx64\1309000.009\ironx64.sys [2012-10-31 190072]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\NISx64\1309000.009\symnets.sys [2012-10-31 405624]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-9-23 65192]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccsvchst.exe [2012-10-31 138272]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\SymcPCCULaunchSvc.exe [2012-10-30 123320]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-30 1258856]
R2 PCCUJobMgr;Common Client Job Manager Service;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\ccSvcHst.exe [2012-10-30 126392]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2011-11-3 130536]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2011-11-3 395752]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-10-30 138912]
R3 MEIx64;Intel(R) Management Engine Interface ;C:\Windows\System32\drivers\HECIx64.sys [2012-10-30 56600]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-10-30 677480]
R3 t_mouse.sys;iBall Advanced Mouse;C:\Windows\System32\drivers\t_mouse.sys [2009-4-16 25088]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-30 136176]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-30 136176]
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe [2012-9-5 234776]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-3-1 1255736]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120]
.
=============== Created Last 30 ================
.
2012-11-05 17:52:53 -------- d-----w- C:\TDSSKiller_Quarantine
2012-11-01 05:47:16 902656 ----a-w- C:\Windows\System32\d2d1.dll
2012-11-01 05:47:16 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
2012-11-01 05:47:16 1139200 ----a-w- C:\Windows\System32\FntCache.dll
2012-11-01 02:18:00 737952 ----a-w- C:\Windows\System32\drivers\NISx64\1309000.009\srtsp64.sys
2012-11-01 02:18:00 451192 ----a-r- C:\Windows\System32\drivers\NISx64\1309000.009\symds64.sys
2012-11-01 02:18:00 405624 ----a-w- C:\Windows\System32\drivers\NISx64\1309000.009\symnets.sys
2012-11-01 02:18:00 37536 ----a-w- C:\Windows\System32\drivers\NISx64\1309000.009\srtspx64.sys
2012-11-01 02:18:00 190072 ----a-w- C:\Windows\System32\drivers\NISx64\1309000.009\ironx64.sys
2012-11-01 02:18:00 167072 ----a-w- C:\Windows\System32\drivers\NISx64\1309000.009\ccsetx64.sys
2012-11-01 02:18:00 1129120 ----a-w- C:\Windows\System32\drivers\NISx64\1309000.009\symefa64.sys
2012-11-01 02:17:54 -------- d-----w- C:\Windows\System32\drivers\NISx64\1309000.009
2012-10-31 17:29:06 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-10-31 17:29:06 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-10-31 17:29:06 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-10-31 17:29:05 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-10-31 17:29:05 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-10-31 07:50:48 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-10-31 07:49:59 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-10-31 07:48:35 245760 ----a-w- C:\Windows\System32\OxpsConverter.exe
2012-10-31 07:48:10 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
2012-10-31 07:48:10 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys
2012-10-31 07:48:10 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2012-10-31 07:48:07 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2012-10-31 07:48:07 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2012-10-31 07:48:07 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2012-10-31 07:48:07 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2012-10-31 07:48:01 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-10-31 07:46:56 503808 ----a-w- C:\Windows\System32\srcore.dll
2012-10-31 07:46:55 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
2012-10-31 07:46:36 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2012-10-31 07:46:28 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2012-10-31 07:46:28 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2012-10-31 07:46:20 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll
2012-10-31 07:46:20 634880 ----a-w- C:\Windows\System32\msvcrt.dll
2012-10-31 07:45:57 956928 ----a-w- C:\Windows\System32\localspl.dll
2012-10-31 07:45:50 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2012-10-31 07:45:39 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2012-10-31 07:45:39 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2012-10-31 07:45:39 331776 ----a-w- C:\Windows\System32\oleacc.dll
2012-10-31 07:45:39 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2012-10-31 07:45:32 723456 ----a-w- C:\Windows\System32\EncDec.dll
2012-10-31 07:45:32 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2012-10-31 07:44:07 751104 ----a-w- C:\Windows\System32\win32spl.dll
2012-10-31 07:44:07 67072 ----a-w- C:\Windows\splwow64.exe
2012-10-31 07:44:07 559104 ----a-w- C:\Windows\System32\spoolsv.exe
2012-10-31 07:44:07 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll
2012-10-31 07:43:38 77312 ----a-w- C:\Windows\System32\packager.dll
2012-10-31 07:43:38 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2012-10-31 01:05:17 -------- d-----w- C:\Program Files (x86)\Datel
2012-10-31 00:40:26 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2012-10-31 00:39:58 54200 ----a-w- C:\Windows\System32\drivers\dsiarhwprog_x64.sys
2012-10-30 23:40:50 -------- d-----w- C:\ProgramData\Blizzard Entertainment
2012-10-30 23:40:50 -------- d-----w- C:\Program Files (x86)\Common Files\Blizzard Entertainment
2012-10-30 23:39:13 -------- d-----w- C:\ProgramData\Battle.net
2012-10-30 23:07:42 -------- d-----w- C:\Users\Brandon\AppData\Local\CrashDumps
2012-10-30 22:37:39 77656 ----a-w- C:\Windows\System32\XAPOFX1_5.dll
2012-10-30 22:36:30 111960 ----a-w- C:\Windows\dxsdkuninst.exe
2012-10-30 22:36:30 -------- d-----w- C:\Program Files (x86)\Microsoft DirectX SDK (June 2010)
2012-10-30 21:53:10 -------- d-----w- C:\Users\Brandon\AppData\Local\Adobe
2012-10-30 21:52:28 -------- d-----w- C:\Program Files (x86)\Common Files\Intel Corporation
2012-10-30 21:48:56 -------- d-----w- C:\ProgramData\McAfee Security Scan
2012-10-30 21:48:53 -------- d-----w- C:\Program Files (x86)\McAfee Security Scan
2012-10-30 21:10:43 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2012-10-30 20:12:49 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2012-10-30 20:09:15 -------- d-----r- C:\Games
2012-10-30 19:26:53 891240 ----a-w- C:\Windows\System32\nvvsvc.exe
2012-10-30 19:26:53 63336 ----a-w- C:\Windows\System32\nvshext.dll
2012-10-30 19:26:53 6200680 ----a-w- C:\Windows\System32\nvcpl.dll
2012-10-30 19:26:53 3536817 ----a-w- C:\Windows\System32\nvcoproc.bin
2012-10-30 19:26:53 3293544 ----a-w- C:\Windows\System32\nvsvc64.dll
2012-10-30 19:26:53 2557800 ----a-w- C:\Windows\System32\nvsvcr.dll
2012-10-30 19:26:53 118120 ----a-w- C:\Windows\System32\nvmctray.dll
2012-10-30 19:25:43 60776 ----a-w- C:\Windows\System32\OpenCL.dll
2012-10-30 19:25:43 52584 ----a-w- C:\Windows\SysWow64\OpenCL.dll
2012-10-30 19:24:34 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2012-10-30 19:24:29 -------- d-----w- C:\Program Files\NVIDIA Corporation
2012-10-30 19:24:29 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2012-10-30 19:17:49 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-10-30 19:17:49 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-10-30 19:17:49 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-10-30 19:14:37 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-10-30 19:14:25 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-10-30 19:14:05 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-10-30 19:14:05 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-10-30 19:08:15 -------- d-----w- C:\Program Files (x86)\ASUS
2012-10-30 19:07:13 -------- d-----w- C:\Program Files (x86)\ASM104xUSB3
2012-10-30 19:06:11 74344 ----a-w- C:\Windows\System32\RtNicProp64.dll
2012-10-30 19:06:11 677480 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys
2012-10-30 19:06:11 107552 ----a-w- C:\Windows\System32\RTNUninst64.dll
2012-10-30 19:05:21 -------- d-----w- C:\Program Files (x86)\ASM106xSATA
2012-10-30 19:05:08 8192 ----a-w- C:\Windows\System32\drivers\IntelMEFWVer.dll
2012-10-30 19:04:58 56600 ----a-w- C:\Windows\System32\drivers\HECIx64.sys
2012-10-30 19:02:58 -------- d-----w- C:\Users\Brandon\AppData\Roaming\Intel Corporation
2012-10-30 18:59:59 81248 ----a-w- C:\Windows\System32\SFCOM64.dll
2012-10-30 18:54:19 23832 ----a-w- C:\Windows\System32\drivers\iaStorF.sys
2012-10-30 18:51:19 -------- d-----w- C:\Windows\AsusInstAll
2012-10-30 18:49:24 53248 ----a-r- C:\Windows\SysWow64\CSVer.dll
2012-10-30 18:47:59 296320 ----a-w- C:\Windows\System32\drivers\volsnap.sys
2012-10-30 18:43:53 -------- d-----w- C:\Users\Brandon\AppData\Local\Google
2012-10-30 18:42:23 175736 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2012-10-30 18:42:23 -------- d-----w- C:\Program Files\Symantec
2012-10-30 18:42:23 -------- d-----w- C:\Program Files\Common Files\Symantec Shared
2012-10-30 18:41:25 -------- d-----w- C:\Windows\System32\drivers\NISx64
2012-10-30 18:41:24 -------- d-----w- C:\Program Files (x86)\Norton Internet Security
2012-10-30 18:39:09 -------- d-----w- C:\Windows\System32\drivers\NortonPCCheckupx64\02000F0.060
2012-10-30 18:39:09 -------- d-----w- C:\Windows\System32\drivers\NortonPCCheckupx64
2012-10-30 18:39:08 -------- d-----w- C:\ProgramData\Norton
2012-10-30 18:39:08 -------- d-----w- C:\Program Files (x86)\Norton PC Checkup
2012-10-30 18:39:04 -------- d-----w- C:\ProgramData\NortonInstaller
2012-10-30 18:39:04 -------- d-----w- C:\Program Files (x86)\NortonInstaller
2012-10-30 18:27:18 -------- d-----w- C:\Users\Brandon\AppData\Local\Diagnostics
2012-10-30 18:26:55 -------- d-----w- C:\Users\Brandon\AppData\Local\ElevatedDiagnostics
2012-10-30 18:19:04 -------- d-----w- C:\Users\Brandon\AppData\Local\VirtualStore
2012-10-16 23:03:05 -------- d-sh--w- C:\Recovery
2012-10-11 01:22:54 2428776 ----a-w- C:\Windows\SysWow64\nvapi.dll
2012-10-11 01:22:52 26331496 ----a-w- C:\Windows\System32\nvoglv64.dll
2012-10-11 01:22:52 1760104 ----a-w- C:\Windows\System32\nvdispco64.dll
2012-10-11 01:22:32 15309160 ----a-w- C:\Windows\SysWow64\nvd3dum.dll
2012-10-11 01:22:26 2747240 ----a-w- C:\Windows\System32\nvcuvid.dll
2012-10-11 01:22:24 364904 ----a-w- C:\Windows\System32\nvEncodeAPI64.dll
2012-10-11 01:22:24 19906920 ----a-w- C:\Windows\SysWow64\nvoglv32.dll
2012-10-11 01:22:18 13443944 ----a-w- C:\Windows\System32\drivers\nvlddmkm.sys
2012-10-11 01:22:14 17559912 ----a-w- C:\Windows\SysWow64\nvcompiler.dll
.
==================== Find3M ====================
.
2012-10-11 01:23:48 247144 ----a-w- C:\Windows\System32\nvinitx.dll
2012-10-02 17:15:52 430952 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2012-09-14 19:19:29 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-09-14 18:28:53 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-08-31 18:19:35 1659760 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2012-08-30 17:12:02 3968880 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12:02 3914096 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-08-24 18:05:07 220160 ----a-w- C:\Windows\System32\wintrust.dll
2012-08-24 16:57:48 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-08-22 18:12:50 1913200 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-08-22 18:12:40 950128 ----a-w- C:\Windows\System32\drivers\ndis.sys
2012-08-22 18:12:40 376688 ----a-w- C:\Windows\System32\drivers\netio.sys
2012-08-22 18:12:33 288624 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2012-08-20 18:48:44 362496 ----a-w- C:\Windows\System32\wow64win.dll
2012-08-20 18:48:44 243200 ----a-w- C:\Windows\System32\wow64.dll
2012-08-20 18:48:44 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2012-08-20 18:48:43 215040 ----a-w- C:\Windows\System32\winsrv.dll
2012-08-20 18:48:37 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2012-08-20 18:48:35 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2012-08-20 18:46:22 338432 ----a-w- C:\Windows\System32\conhost.exe
2012-08-20 17:40:21 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-08-20 17:38:44 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2012-08-20 17:38:26 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2012-08-20 17:37:19 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2012-08-20 17:37:18 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2012-08-20 15:38:21 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2012-08-20 15:38:20 2048 ----a-w- C:\Windows\SysWow64\user.exe
2012-08-20 15:33:28 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-08-20 15:33:28 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-08-20 15:33:28 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-08-20 15:33:28 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-08-11 00:56:03 715776 ----a-w- C:\Windows\System32\kerberos.dll
2012-08-10 23:56:14 542208 ----a-w- C:\Windows\SysWow64\kerberos.dll
.
============= FINISH: 22:31:06.65 ===============
:oreo: aswMBR Log
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-11-06 22:34:48
-----------------------------
22:34:48.980 OS Version: Windows x64 6.1.7601 Service Pack 1
22:34:48.980 Number of processors: 8 586 0x2D07
22:34:48.980 ComputerName: BLACKPEARL UserName: Brandon
22:34:50.241 Initialize success
22:36:48.678 AVAST engine defs: 12110602
22:36:57.946 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000006a
22:36:57.947 Disk 0 Vendor: ATA_____ A610 Size: 953869MB BusType: 11
22:36:57.955 Disk 0 MBR read successfully
22:36:57.957 Disk 0 MBR scan
22:36:57.959 Disk 0 Windows 7 default MBR code
22:36:57.974 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
22:36:57.992 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848
22:36:58.002 Disk 0 scanning C:\Windows\system32\drivers
22:37:03.934 Service scanning
22:37:18.151 Modules scanning
22:37:18.154 Disk 0 trace - called modules:
22:37:18.254 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorF.sys ACPI.sys storport.sys hal.dll iaStorA.sys
22:37:18.256 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007f1c790]
22:37:18.259 3 CLASSPNP.SYS[fffff8800465143f] -> nt!IofCallDriver -> [0xfffffa8007e24c50]
22:37:18.262 5 iaStorF.sys[fffff880048652fa] -> nt!IofCallDriver -> [0xfffffa8007b26040]
22:37:18.265 7 ACPI.sys[fffff88000f887a1] -> nt!IofCallDriver -> \Device\0000006a[0xfffffa8007b17430]
22:37:19.516 AVAST engine scan C:\Windows
22:37:20.908 AVAST engine scan C:\Windows\system32
22:38:58.878 AVAST engine scan C:\Windows\system32\drivers
22:39:06.710 AVAST engine scan C:\Users\Brandon
22:39:38.500 AVAST engine scan C:\ProgramData
22:39:55.033 Scan finished successfully
22:40:09.349 Disk 0 MBR has been saved successfully to "C:\Users\Brandon\Desktop\MBR.dat"
22:40:09.352 The log file has been saved successfully to "C:\Users\Brandon\Desktop\aswMBR.txt"