jamper
2013-09-01, 04:57
Hello, and Thank You for the help.
A few things have been happening: During a recent windows update, as the computer was booting up and applying updates an error came up saying BitDefender encountered an error .....it said some more but it disappeared before I had the chance to read it all or copy it. I am not sure what to make of this because I do not have BitDefender.
Another problem (I think) is I have 2 partitions C and D and I have yet to use D, but it says there is 1GB being used, I have opened it and there is nothing there.
And the last thing is I keep seeing dllHost.exe COM surrogate showing up and disappearing about every 30 sec or so, every time it does I get the activity indicator on the cursor.
I reformatted the entire computer when I first saw this happen last week, but it is happening again.
Also when I tried to update awsmbr to run a scan for this it says avast engine download error 0.
Thanks Again.
------------------------------------------------------------------------------------------------------------------------------------
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16502
Run by yui at 18:03:26 on 2013-08-31
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.6056.3604 [GMT -7:00]
.
AV: ZoneAlarm Internet Security Suite Antivirus *Enabled/Updated* {DE038A5B-9EDD-18A9-2361-FF7D98D43730}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: ZoneAlarm Internet Security Suite Anti-Spyware *Enabled/Updated* {65626BBF-B8E7-1727-19D1-C40FE3537D8D}
FW: ZoneAlarm Internet Security Suite Firewall *Enabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\FBAgent.exe
C:\Windows\system32\WLANExt.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\P4G\BatteryLife.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Windows\AsScrPro.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\yui\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\taskeng.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Google Update] "C:\Users\yui\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
mRun: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
mRun: [ZoneAlarm] "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe"
StartupFolder: C:\Users\yui\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FANCYS~1.LNK - C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 68.105.28.11 68.105.29.11 68.105.28.12
TCP: Interfaces\{1869CCA2-698C-459D-8CB7-23813A41A346} : DHCPNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3
x64-Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
x64-Run: [ETDCtrl] C:\Program Files (x86)\Elantech\ETDCtrl.exe
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Users\yui\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Users\yui\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\yui\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Users\yui\AppData\Roaming\Mozilla\plugins\npo1d.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
FF - ExtSQL: 2013-08-15 21:29; jid1-xUfzOsOFlzSOXg@jetpack; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\jid1-xUfzOsOFlzSOXg@jetpack.xpi
FF - ExtSQL: 2013-08-15 21:30; jid0-hd39BGK3EuIbK47rGW3fZdR163o@jetpack; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\jid0-hd39BGK3EuIbK47rGW3fZdR163o@jetpack.xpi
FF - ExtSQL: 2013-08-15 21:30; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-08-15 21:31; jid1-ZAdIEUB7XOzOJw@jetpack; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\jid1-ZAdIEUB7XOzOJw@jetpack.xpi
FF - ExtSQL: 2013-08-15 21:31; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
FF - ExtSQL: 2013-08-15 21:31; {73a6fe31-595d-460b-a920-fcc0f8843232}; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF - ExtSQL: 2013-08-15 21:31; support@lastpass.com; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\support@lastpass.com
FF - ExtSQL: 2013-08-15 21:56; jid1-4P0kohSJxU1qGg@jetpack; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\jid1-4P0kohSJxU1qGg@jetpack.xpi
FF - ExtSQL: 2013-08-15 22:03; netflixrandomizer@joshkowarsky.com; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\netflixrandomizer@joshkowarsky.com.xpi
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.zonealarm.tlbrSrchUrl - hxxp://search.zonealarm.com/search?src=tb&tbid=base2013&Lan={dfltLng}&gu=a734bfc817a14665b49769779ebd1f2e&tu=10Go5009n2B000v&sku=&tstsId=&ver=&&q=
FF - user.js: extensions.zonealarm.id - ea8e2377000000000000742f687ae033
FF - user.js: extensions.zonealarm.appId - {C56C48A0-DA4E-46F6-9859-1553DC865F84}
FF - user.js: extensions.zonealarm.instlDay - 15947
FF - user.js: extensions.zonealarm.vrsn - 1.8.11.6
FF - user.js: extensions.zonealarm.vrsni - 1.8.11.6
FF - user.js: extensions.zonealarm.vrsnTs - 1.8.11.613:24:24
FF - user.js: extensions.zonealarm.prtnrId - checkpoint
FF - user.js: extensions.zonealarm.prdct - zonealarm
FF - user.js: extensions.zonealarm.aflt - 1042
FF - user.js: extensions.zonealarm.smplGrp - none
FF - user.js: extensions.zonealarm.tlbrId - base2013
FF - user.js: extensions.zonealarm.instlRef - ZLN119547823771645-1042
FF - user.js: extensions.zonealarm.dfltLng - en
FF - user.js: extensions.zonealarm.excTlbr - false
FF - user.js: extensions.zonealarm.ffxUnstlRst - false
FF - user.js: extensions.zonealarm.admin - false
FF - user.js: extensions.zonealarm.autoRvrt - false
FF - user.js: extensions.zonealarm.rvrt - false
FF - user.js: extensions.zonealarm.newTab - false
.
============= SERVICES / DRIVERS ===============
.
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2010-7-26 17024]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2013-8-31 28504]
R1 kltdi;kltdi;C:\Windows\System32\drivers\kltdi.sys [2013-8-31 54104]
R1 kneps;kneps;C:\Windows\System32\drivers\kneps.sys [2013-8-31 178600]
R2 AFBAgent;AFBAgent;C:\Windows\System32\FBAgent.exe [2013-8-30 379520]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-2 15416]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-8-30 1817560]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-8-30 1033688]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-8-30 171928]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-8-30 2655768]
R2 ZAPrivacyService;ZoneAlarm Privacy Service;C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [2013-6-18 54160]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\System32\drivers\ETD.sys [2013-8-30 138024]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-8-30 317440]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2013-8-30 76912]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2013-8-30 1147232]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\System32\drivers\SiSG664.sys [2009-6-10 56832]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-8-31 1255736]
.
=============== Created Last 30 ================
.
2013-09-01 00:57:42 -------- d-----w- C:\Windows\System32\MRT
2013-09-01 00:09:23 178600 ----a-w- C:\Windows\System32\drivers\kneps.sys
2013-09-01 00:09:22 54104 ----a-w- C:\Windows\System32\drivers\kltdi.sys
2013-09-01 00:09:10 28504 ----a-w- C:\Windows\System32\drivers\klim6.sys
2013-09-01 00:09:07 458584 ----a-w- C:\Windows\System32\drivers\kl1.sys
2013-09-01 00:09:03 89944 ----a-w- C:\Windows\System32\drivers\klflt.sys
2013-09-01 00:08:36 -------- d-----w- C:\Program Files (x86)\CheckPoint
2013-08-31 23:58:35 982912 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-08-31 23:41:42 -------- d-----w- C:\Windows\SysWow64\Wat
2013-08-31 23:41:42 -------- d-----w- C:\Windows\System32\Wat
2013-08-31 23:27:25 311808 ----a-w- C:\Windows\System32\msv1_0.dll
2013-08-31 23:27:25 257024 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2013-08-31 23:21:45 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2013-08-31 23:21:45 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2013-08-31 23:21:45 48960 ----a-w- C:\Windows\System32\netfxperf.dll
2013-08-31 23:21:45 444752 ----a-w- C:\Windows\System32\mscoree.dll
2013-08-31 23:21:45 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2013-08-31 23:21:45 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2013-08-31 23:21:45 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2013-08-31 23:21:45 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2013-08-31 23:21:45 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll
2013-08-31 23:21:44 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2013-08-31 23:15:08 46080 ----a-w- C:\Windows\System32\atmlib.dll
2013-08-31 23:15:08 367616 ----a-w- C:\Windows\System32\atmfd.dll
2013-08-31 23:15:08 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2013-08-31 23:15:08 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2013-08-31 23:12:01 80896 ----a-w- C:\Windows\System32\imagehlp.dll
2013-08-31 23:12:01 22896 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-08-31 23:12:01 158720 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-08-31 23:12:00 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2013-08-31 23:12:00 5120 ----a-w- C:\Windows\System32\wmi.dll
2013-08-31 17:08:01 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll
2013-08-31 17:08:00 751104 ----a-w- C:\Windows\System32\win32spl.dll
2013-08-31 17:06:52 3150848 ----a-w- C:\Windows\System32\win32k.sys
2013-08-31 17:05:58 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2013-08-31 17:04:37 516096 ----a-w- C:\Program Files\Windows Mail\wab.exe
2013-08-31 17:03:47 46592 ----a-w- C:\Windows\System32\msasn1.dll
2013-08-31 17:02:57 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2013-08-31 17:02:57 236032 ----a-w- C:\Windows\System32\srvsvc.dll
2013-08-31 17:02:43 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-08-31 17:02:42 182272 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-08-31 17:02:42 1462784 ----a-w- C:\Windows\System32\crypt32.dll
2013-08-31 17:02:42 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2013-08-31 17:02:42 139264 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-08-31 17:02:42 1157632 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-08-31 17:02:30 77312 ----a-w- C:\Windows\System32\packager.dll
2013-08-31 17:02:30 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2013-08-31 00:45:16 -------- d-----w- C:\Program Files\CCleaner
2013-08-31 00:06:54 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-08-31 00:05:57 17272 ----a-w- C:\Windows\System32\sdnclean64.exe
2013-08-31 00:05:53 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-08-31 00:02:38 -------- d-----w- C:\Users\yui\AppData\Roaming\Malwarebytes
2013-08-31 00:02:30 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-08-31 00:02:30 -------- d-----w- C:\ProgramData\Malwarebytes
2013-08-31 00:02:30 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-31 00:02:15 -------- d-----w- C:\Users\yui\AppData\Local\Programs
2013-08-30 20:50:03 9515512 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3FB6940E-A62C-4ED0-9B97-C443D5B25992}\mpengine.dll
2013-08-30 20:50:02 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-08-30 20:28:33 -------- d-----w- C:\Users\yui\AppData\Roaming\CheckPoint
2013-08-30 20:27:31 374664 ----a-w- C:\Windows\System32\drivers\netio.sys
2013-08-30 20:23:27 -------- d-----w- C:\ProgramData\CheckPoint
2013-08-30 20:17:29 -------- d-----w- C:\Users\yui\AppData\Local\Google
2013-08-30 20:16:56 -------- d-----w- C:\Users\yui\AppData\Local\Macromedia
2013-08-30 20:16:18 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-30 20:16:18 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-08-30 20:15:52 -------- d-----w- C:\Users\yui\AppData\Local\Adobe
2013-08-30 20:10:00 -------- d-----w- C:\Users\yui\AppData\Local\Mozilla
2013-08-30 20:04:27 826368 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2013-08-30 20:04:27 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2013-08-30 20:04:27 139264 ----a-w- C:\Windows\System32\cabview.dll
2013-08-30 20:04:27 132608 ----a-w- C:\Windows\SysWow64\cabview.dll
2013-08-30 20:04:27 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2013-08-30 20:04:26 -------- d-----w- C:\temp
2013-08-30 19:59:05 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2013-08-30 19:58:51 99840 ----a-w- C:\Windows\System32\wudriver.dll
2013-08-30 19:58:42 36864 ----a-w- C:\Windows\System32\wuapp.exe
2013-08-30 19:58:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2013-08-30 19:17:47 5047080 ----a-w- C:\Windows\System32\ETDUI.cpl
2013-08-30 19:17:43 438808 ----a-w- C:\Windows\System32\drivers\iaStor.sys
2013-08-30 19:17:43 15416 ----a-w- C:\Windows\System32\drivers\kbfiltr.sys
2013-08-30 19:17:43 138024 ----a-w- C:\Windows\System32\drivers\ETD.sys
2013-08-30 19:17:39 76912 ----a-w- C:\Windows\System32\drivers\L1C62x64.sys
2013-08-30 19:17:00 317440 ----a-w- C:\Windows\System32\drivers\IntcDAud.sys
2013-08-30 19:17:00 14848 ----a-w- C:\Windows\System32\IntcDAuC.dll
2013-08-30 19:15:58 4368920 ----a-w- C:\Windows\System32\GfxUI.exe
2013-08-30 19:10:12 45056 ----a-w- C:\Windows\System32\acovcnt.exe
2013-08-30 19:08:44 2621440 ---h--r- C:\K73SV.BIN
2013-08-30 19:08:44 2621440 ---h--r- C:\K73E.BIN
2013-08-30 19:08:33 -------- d-----w- C:\eSupport
2013-08-30 19:08:10 -------- d-----w- C:\ProgramData\Trend Micro
2013-08-30 19:05:52 327008 ----a-w- C:\Windows\System32\RaCoInstx.dll
2013-08-30 19:04:51 518896 ----a-w- C:\Windows\System32\SRSTSX64.dll
2013-08-30 19:03:28 -------- d-----w- C:\Program Files\Common Files\Intel
2013-08-30 19:03:28 -------- d-----w- C:\Program Files (x86)\Common Files\Intel
2013-08-30 19:02:03 8192 ----a-w- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
2013-08-30 19:02:03 8192 ----a-w- C:\Windows\System32\drivers\IntelMEFWVer.dll
2013-08-30 19:01:59 -------- d-----w- C:\Program Files (x86)\Common Files\postureAgent
2013-08-30 19:01:54 56344 ----a-w- C:\Windows\System32\drivers\HECIx64.sys
2013-08-30 18:59:35 53248 ----a-w- C:\Windows\SysWow64\CSVer.dll
2013-08-30 18:59:31 -------- d-----w- C:\Intel
2013-08-30 18:57:51 947584 ----a-w- C:\Windows\System32\drivers\ndis.sys
2013-08-30 18:56:04 410504 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2013-08-30 18:56:04 27016 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2013-08-30 18:56:04 166280 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2013-08-30 18:56:04 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2013-08-30 18:56:04 107912 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2013-08-30 18:56:03 2566144 ----a-w- C:\Windows\System32\esent.dll
2013-08-30 18:56:03 187264 ----a-w- C:\Windows\System32\drivers\storport.sys
2013-08-30 18:56:03 1686016 ----a-w- C:\Windows\SysWow64\esent.dll
2013-08-30 18:52:21 51712 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2013-08-30 18:52:21 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
.
==================== Find3M ====================
.
2013-08-31 23:58:35 662528 ----a-w- C:\Windows\System32\XpsPrint.dll
2013-08-30 19:06:51 80512 ----a-w- C:\Windows\AsusScr_K Series_ENG Uninstaller.exe
2013-08-30 19:06:50 3058304 ----a-w- C:\Windows\AsScrPro.exe
2013-06-13 23:34:16 451096 ----a-w- C:\Windows\System32\drivers\vsdatant.sys
.
============= FINISH: 18:03:45.86 ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-08-31 18:12:12
-----------------------------
18:12:12.666 OS Version: Windows x64 6.1.7600
18:12:12.666 Number of processors: 4 586 0x2A07
18:12:12.666 ComputerName: YUI-PC UserName: yui
18:12:13.992 Initialize success
18:12:47.710 AVAST engine download error: 0
18:13:01.485 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:13:01.500 Disk 0 Vendor: Hitachi_ JEDO Size: 610480MB BusType: 3
18:13:01.688 Disk 0 MBR read successfully
18:13:01.688 Disk 0 MBR scan
18:13:01.688 Disk 0 Windows 7 default MBR code
18:13:01.703 Disk 0 Partition 1 00 1C Hidd FAT32 LBA MSDOS5.0 25600 MB offset 2048
18:13:01.703 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 152620 MB offset 52430848
18:13:01.719 Disk 0 Partition - 00 0F Extended LBA 432258 MB offset 364996608
18:13:01.750 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 432257 MB offset 364998656
18:13:01.875 Disk 0 scanning C:\Windows\system32\drivers
18:13:06.243 Service scanning
18:13:24.152 Modules scanning
18:13:24.152 Disk 0 trace - called modules:
18:13:24.713 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
18:13:24.713 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007ebc060]
18:13:24.713 3 CLASSPNP.SYS[fffff8800120143f] -> nt!IofCallDriver -> [0xfffffa800638bd20]
18:13:24.729 5 ACPI.sys[fffff88000eef781] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8006390050]
18:13:24.729 Scan finished successfully
18:13:38.004 Disk 0 MBR has been saved successfully to "C:\Users\yui\Desktop\MBR.dat"
18:13:38.004 The log file has been saved successfully to "C:\Users\yui\Desktop\aswMBR.txt"
A few things have been happening: During a recent windows update, as the computer was booting up and applying updates an error came up saying BitDefender encountered an error .....it said some more but it disappeared before I had the chance to read it all or copy it. I am not sure what to make of this because I do not have BitDefender.
Another problem (I think) is I have 2 partitions C and D and I have yet to use D, but it says there is 1GB being used, I have opened it and there is nothing there.
And the last thing is I keep seeing dllHost.exe COM surrogate showing up and disappearing about every 30 sec or so, every time it does I get the activity indicator on the cursor.
I reformatted the entire computer when I first saw this happen last week, but it is happening again.
Also when I tried to update awsmbr to run a scan for this it says avast engine download error 0.
Thanks Again.
------------------------------------------------------------------------------------------------------------------------------------
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16502
Run by yui at 18:03:26 on 2013-08-31
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.6056.3604 [GMT -7:00]
.
AV: ZoneAlarm Internet Security Suite Antivirus *Enabled/Updated* {DE038A5B-9EDD-18A9-2361-FF7D98D43730}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: ZoneAlarm Internet Security Suite Anti-Spyware *Enabled/Updated* {65626BBF-B8E7-1727-19D1-C40FE3537D8D}
FW: ZoneAlarm Internet Security Suite Firewall *Enabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\FBAgent.exe
C:\Windows\system32\WLANExt.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\P4G\BatteryLife.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Windows\AsScrPro.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\yui\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\taskeng.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Google Update] "C:\Users\yui\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
mRun: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
mRun: [ZoneAlarm] "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe"
StartupFolder: C:\Users\yui\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FANCYS~1.LNK - C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 68.105.28.11 68.105.29.11 68.105.28.12
TCP: Interfaces\{1869CCA2-698C-459D-8CB7-23813A41A346} : DHCPNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3
x64-Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
x64-Run: [ETDCtrl] C:\Program Files (x86)\Elantech\ETDCtrl.exe
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Users\yui\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Users\yui\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\yui\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Users\yui\AppData\Roaming\Mozilla\plugins\npo1d.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
FF - ExtSQL: 2013-08-15 21:29; jid1-xUfzOsOFlzSOXg@jetpack; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\jid1-xUfzOsOFlzSOXg@jetpack.xpi
FF - ExtSQL: 2013-08-15 21:30; jid0-hd39BGK3EuIbK47rGW3fZdR163o@jetpack; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\jid0-hd39BGK3EuIbK47rGW3fZdR163o@jetpack.xpi
FF - ExtSQL: 2013-08-15 21:30; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-08-15 21:31; jid1-ZAdIEUB7XOzOJw@jetpack; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\jid1-ZAdIEUB7XOzOJw@jetpack.xpi
FF - ExtSQL: 2013-08-15 21:31; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
FF - ExtSQL: 2013-08-15 21:31; {73a6fe31-595d-460b-a920-fcc0f8843232}; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF - ExtSQL: 2013-08-15 21:31; support@lastpass.com; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\support@lastpass.com
FF - ExtSQL: 2013-08-15 21:56; jid1-4P0kohSJxU1qGg@jetpack; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\jid1-4P0kohSJxU1qGg@jetpack.xpi
FF - ExtSQL: 2013-08-15 22:03; netflixrandomizer@joshkowarsky.com; C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\extensions\netflixrandomizer@joshkowarsky.com.xpi
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.zonealarm.tlbrSrchUrl - hxxp://search.zonealarm.com/search?src=tb&tbid=base2013&Lan={dfltLng}&gu=a734bfc817a14665b49769779ebd1f2e&tu=10Go5009n2B000v&sku=&tstsId=&ver=&&q=
FF - user.js: extensions.zonealarm.id - ea8e2377000000000000742f687ae033
FF - user.js: extensions.zonealarm.appId - {C56C48A0-DA4E-46F6-9859-1553DC865F84}
FF - user.js: extensions.zonealarm.instlDay - 15947
FF - user.js: extensions.zonealarm.vrsn - 1.8.11.6
FF - user.js: extensions.zonealarm.vrsni - 1.8.11.6
FF - user.js: extensions.zonealarm.vrsnTs - 1.8.11.613:24:24
FF - user.js: extensions.zonealarm.prtnrId - checkpoint
FF - user.js: extensions.zonealarm.prdct - zonealarm
FF - user.js: extensions.zonealarm.aflt - 1042
FF - user.js: extensions.zonealarm.smplGrp - none
FF - user.js: extensions.zonealarm.tlbrId - base2013
FF - user.js: extensions.zonealarm.instlRef - ZLN119547823771645-1042
FF - user.js: extensions.zonealarm.dfltLng - en
FF - user.js: extensions.zonealarm.excTlbr - false
FF - user.js: extensions.zonealarm.ffxUnstlRst - false
FF - user.js: extensions.zonealarm.admin - false
FF - user.js: extensions.zonealarm.autoRvrt - false
FF - user.js: extensions.zonealarm.rvrt - false
FF - user.js: extensions.zonealarm.newTab - false
.
============= SERVICES / DRIVERS ===============
.
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2010-7-26 17024]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2013-8-31 28504]
R1 kltdi;kltdi;C:\Windows\System32\drivers\kltdi.sys [2013-8-31 54104]
R1 kneps;kneps;C:\Windows\System32\drivers\kneps.sys [2013-8-31 178600]
R2 AFBAgent;AFBAgent;C:\Windows\System32\FBAgent.exe [2013-8-30 379520]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-2 15416]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-8-30 1817560]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-8-30 1033688]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-8-30 171928]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-8-30 2655768]
R2 ZAPrivacyService;ZoneAlarm Privacy Service;C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [2013-6-18 54160]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\System32\drivers\ETD.sys [2013-8-30 138024]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-8-30 317440]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2013-8-30 76912]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2013-8-30 1147232]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\System32\drivers\SiSG664.sys [2009-6-10 56832]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-8-31 1255736]
.
=============== Created Last 30 ================
.
2013-09-01 00:57:42 -------- d-----w- C:\Windows\System32\MRT
2013-09-01 00:09:23 178600 ----a-w- C:\Windows\System32\drivers\kneps.sys
2013-09-01 00:09:22 54104 ----a-w- C:\Windows\System32\drivers\kltdi.sys
2013-09-01 00:09:10 28504 ----a-w- C:\Windows\System32\drivers\klim6.sys
2013-09-01 00:09:07 458584 ----a-w- C:\Windows\System32\drivers\kl1.sys
2013-09-01 00:09:03 89944 ----a-w- C:\Windows\System32\drivers\klflt.sys
2013-09-01 00:08:36 -------- d-----w- C:\Program Files (x86)\CheckPoint
2013-08-31 23:58:35 982912 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-08-31 23:41:42 -------- d-----w- C:\Windows\SysWow64\Wat
2013-08-31 23:41:42 -------- d-----w- C:\Windows\System32\Wat
2013-08-31 23:27:25 311808 ----a-w- C:\Windows\System32\msv1_0.dll
2013-08-31 23:27:25 257024 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2013-08-31 23:21:45 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2013-08-31 23:21:45 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2013-08-31 23:21:45 48960 ----a-w- C:\Windows\System32\netfxperf.dll
2013-08-31 23:21:45 444752 ----a-w- C:\Windows\System32\mscoree.dll
2013-08-31 23:21:45 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2013-08-31 23:21:45 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2013-08-31 23:21:45 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2013-08-31 23:21:45 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2013-08-31 23:21:45 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll
2013-08-31 23:21:44 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2013-08-31 23:15:08 46080 ----a-w- C:\Windows\System32\atmlib.dll
2013-08-31 23:15:08 367616 ----a-w- C:\Windows\System32\atmfd.dll
2013-08-31 23:15:08 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2013-08-31 23:15:08 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2013-08-31 23:12:01 80896 ----a-w- C:\Windows\System32\imagehlp.dll
2013-08-31 23:12:01 22896 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-08-31 23:12:01 158720 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-08-31 23:12:00 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2013-08-31 23:12:00 5120 ----a-w- C:\Windows\System32\wmi.dll
2013-08-31 17:08:01 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll
2013-08-31 17:08:00 751104 ----a-w- C:\Windows\System32\win32spl.dll
2013-08-31 17:06:52 3150848 ----a-w- C:\Windows\System32\win32k.sys
2013-08-31 17:05:58 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2013-08-31 17:04:37 516096 ----a-w- C:\Program Files\Windows Mail\wab.exe
2013-08-31 17:03:47 46592 ----a-w- C:\Windows\System32\msasn1.dll
2013-08-31 17:02:57 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2013-08-31 17:02:57 236032 ----a-w- C:\Windows\System32\srvsvc.dll
2013-08-31 17:02:43 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-08-31 17:02:42 182272 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-08-31 17:02:42 1462784 ----a-w- C:\Windows\System32\crypt32.dll
2013-08-31 17:02:42 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2013-08-31 17:02:42 139264 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-08-31 17:02:42 1157632 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-08-31 17:02:30 77312 ----a-w- C:\Windows\System32\packager.dll
2013-08-31 17:02:30 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2013-08-31 00:45:16 -------- d-----w- C:\Program Files\CCleaner
2013-08-31 00:06:54 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-08-31 00:05:57 17272 ----a-w- C:\Windows\System32\sdnclean64.exe
2013-08-31 00:05:53 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-08-31 00:02:38 -------- d-----w- C:\Users\yui\AppData\Roaming\Malwarebytes
2013-08-31 00:02:30 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-08-31 00:02:30 -------- d-----w- C:\ProgramData\Malwarebytes
2013-08-31 00:02:30 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-31 00:02:15 -------- d-----w- C:\Users\yui\AppData\Local\Programs
2013-08-30 20:50:03 9515512 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3FB6940E-A62C-4ED0-9B97-C443D5B25992}\mpengine.dll
2013-08-30 20:50:02 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-08-30 20:28:33 -------- d-----w- C:\Users\yui\AppData\Roaming\CheckPoint
2013-08-30 20:27:31 374664 ----a-w- C:\Windows\System32\drivers\netio.sys
2013-08-30 20:23:27 -------- d-----w- C:\ProgramData\CheckPoint
2013-08-30 20:17:29 -------- d-----w- C:\Users\yui\AppData\Local\Google
2013-08-30 20:16:56 -------- d-----w- C:\Users\yui\AppData\Local\Macromedia
2013-08-30 20:16:18 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-30 20:16:18 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-08-30 20:15:52 -------- d-----w- C:\Users\yui\AppData\Local\Adobe
2013-08-30 20:10:00 -------- d-----w- C:\Users\yui\AppData\Local\Mozilla
2013-08-30 20:04:27 826368 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2013-08-30 20:04:27 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2013-08-30 20:04:27 139264 ----a-w- C:\Windows\System32\cabview.dll
2013-08-30 20:04:27 132608 ----a-w- C:\Windows\SysWow64\cabview.dll
2013-08-30 20:04:27 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2013-08-30 20:04:26 -------- d-----w- C:\temp
2013-08-30 19:59:05 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2013-08-30 19:58:51 99840 ----a-w- C:\Windows\System32\wudriver.dll
2013-08-30 19:58:42 36864 ----a-w- C:\Windows\System32\wuapp.exe
2013-08-30 19:58:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2013-08-30 19:17:47 5047080 ----a-w- C:\Windows\System32\ETDUI.cpl
2013-08-30 19:17:43 438808 ----a-w- C:\Windows\System32\drivers\iaStor.sys
2013-08-30 19:17:43 15416 ----a-w- C:\Windows\System32\drivers\kbfiltr.sys
2013-08-30 19:17:43 138024 ----a-w- C:\Windows\System32\drivers\ETD.sys
2013-08-30 19:17:39 76912 ----a-w- C:\Windows\System32\drivers\L1C62x64.sys
2013-08-30 19:17:00 317440 ----a-w- C:\Windows\System32\drivers\IntcDAud.sys
2013-08-30 19:17:00 14848 ----a-w- C:\Windows\System32\IntcDAuC.dll
2013-08-30 19:15:58 4368920 ----a-w- C:\Windows\System32\GfxUI.exe
2013-08-30 19:10:12 45056 ----a-w- C:\Windows\System32\acovcnt.exe
2013-08-30 19:08:44 2621440 ---h--r- C:\K73SV.BIN
2013-08-30 19:08:44 2621440 ---h--r- C:\K73E.BIN
2013-08-30 19:08:33 -------- d-----w- C:\eSupport
2013-08-30 19:08:10 -------- d-----w- C:\ProgramData\Trend Micro
2013-08-30 19:05:52 327008 ----a-w- C:\Windows\System32\RaCoInstx.dll
2013-08-30 19:04:51 518896 ----a-w- C:\Windows\System32\SRSTSX64.dll
2013-08-30 19:03:28 -------- d-----w- C:\Program Files\Common Files\Intel
2013-08-30 19:03:28 -------- d-----w- C:\Program Files (x86)\Common Files\Intel
2013-08-30 19:02:03 8192 ----a-w- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
2013-08-30 19:02:03 8192 ----a-w- C:\Windows\System32\drivers\IntelMEFWVer.dll
2013-08-30 19:01:59 -------- d-----w- C:\Program Files (x86)\Common Files\postureAgent
2013-08-30 19:01:54 56344 ----a-w- C:\Windows\System32\drivers\HECIx64.sys
2013-08-30 18:59:35 53248 ----a-w- C:\Windows\SysWow64\CSVer.dll
2013-08-30 18:59:31 -------- d-----w- C:\Intel
2013-08-30 18:57:51 947584 ----a-w- C:\Windows\System32\drivers\ndis.sys
2013-08-30 18:56:04 410504 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2013-08-30 18:56:04 27016 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2013-08-30 18:56:04 166280 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2013-08-30 18:56:04 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2013-08-30 18:56:04 107912 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2013-08-30 18:56:03 2566144 ----a-w- C:\Windows\System32\esent.dll
2013-08-30 18:56:03 187264 ----a-w- C:\Windows\System32\drivers\storport.sys
2013-08-30 18:56:03 1686016 ----a-w- C:\Windows\SysWow64\esent.dll
2013-08-30 18:52:21 51712 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2013-08-30 18:52:21 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
.
==================== Find3M ====================
.
2013-08-31 23:58:35 662528 ----a-w- C:\Windows\System32\XpsPrint.dll
2013-08-30 19:06:51 80512 ----a-w- C:\Windows\AsusScr_K Series_ENG Uninstaller.exe
2013-08-30 19:06:50 3058304 ----a-w- C:\Windows\AsScrPro.exe
2013-06-13 23:34:16 451096 ----a-w- C:\Windows\System32\drivers\vsdatant.sys
.
============= FINISH: 18:03:45.86 ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-08-31 18:12:12
-----------------------------
18:12:12.666 OS Version: Windows x64 6.1.7600
18:12:12.666 Number of processors: 4 586 0x2A07
18:12:12.666 ComputerName: YUI-PC UserName: yui
18:12:13.992 Initialize success
18:12:47.710 AVAST engine download error: 0
18:13:01.485 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:13:01.500 Disk 0 Vendor: Hitachi_ JEDO Size: 610480MB BusType: 3
18:13:01.688 Disk 0 MBR read successfully
18:13:01.688 Disk 0 MBR scan
18:13:01.688 Disk 0 Windows 7 default MBR code
18:13:01.703 Disk 0 Partition 1 00 1C Hidd FAT32 LBA MSDOS5.0 25600 MB offset 2048
18:13:01.703 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 152620 MB offset 52430848
18:13:01.719 Disk 0 Partition - 00 0F Extended LBA 432258 MB offset 364996608
18:13:01.750 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 432257 MB offset 364998656
18:13:01.875 Disk 0 scanning C:\Windows\system32\drivers
18:13:06.243 Service scanning
18:13:24.152 Modules scanning
18:13:24.152 Disk 0 trace - called modules:
18:13:24.713 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
18:13:24.713 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007ebc060]
18:13:24.713 3 CLASSPNP.SYS[fffff8800120143f] -> nt!IofCallDriver -> [0xfffffa800638bd20]
18:13:24.729 5 ACPI.sys[fffff88000eef781] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8006390050]
18:13:24.729 Scan finished successfully
18:13:38.004 Disk 0 MBR has been saved successfully to "C:\Users\yui\Desktop\MBR.dat"
18:13:38.004 The log file has been saved successfully to "C:\Users\yui\Desktop\aswMBR.txt"