Nick443
2014-03-15, 07:21
I just got a new Laptop off Ebay and its running really slow. IE and google Chrome are always locking up and I tried to install MBAM but it saying cant find user32.dll but I looked in the system 32 file and the file is there. So I was wondering if anyone could help me to determine if I am effected. I am kinda suspicious being I got the laptop online. Thank you
Sorry I didn't see the read this before you post forum. So here is the logs you guys want. Sorry about that and thanks for the help.
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16521 BrowserJavaVersion: 10.51.2
Run by Precision M6300 at 0:42:02 on 2014-03-15
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.4094.2353 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
FW: avast! Internet Security *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
.
============== Running Processes ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-03-15 00:44:08
-----------------------------
00:44:08.295 OS Version: Windows x64 6.1.7601 Service Pack 1
00:44:08.295 Number of processors: 2 586 0xF0B
00:44:08.295 ComputerName: PRECISIONM6300 UserName:
00:44:09.855 Initialize success
00:44:13.973 AVAST engine defs: 14031401
00:44:30.883 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
00:44:30.883 Disk 0 Vendor: ST9160823ASG 3.ADD Size: 152627MB BusType: 3
00:44:31.008 Disk 0 MBR read successfully
00:44:31.008 Disk 0 MBR scan
00:44:31.008 Disk 0 Windows 7 default MBR code
00:44:31.024 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
00:44:31.039 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 152525 MB offset 206848
00:44:31.164 Disk 0 scanning C:\Windows\system32\drivers
00:44:38.949 Service scanning
00:44:55.921 Modules scanning
00:44:55.921 Disk 0 trace - called modules:
00:44:55.968 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS intelide.sys PCIIDEX.SYS hal.dll atapi.sys
00:44:55.968 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80042d9060]
00:44:56.499 3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0xfffffa80040e9060]
00:44:56.998 AVAST engine scan C:\Windows
00:44:58.183 AVAST engine scan C:\Windows\system32
00:47:51.291 AVAST engine scan C:\Windows\system32\drivers
00:48:00.838 AVAST engine scan C:\Users\Precision M6300
00:50:13.412 AVAST engine scan C:\ProgramData
00:50:44.536 Scan finished successfully
00:51:29.714 Disk 0 MBR has been saved successfully to "C:\Users\Precision M6300\Desktop\MBR.dat"
00:51:29.745 The log file has been saved successfully to "C:\Users\Precision M6300\Desktop\aswMBR.txt"
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
C:\Windows\system32\taskhost.exe
C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.202\deploy\LoLLauncher.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\System32\MsSpellCheckingFacility.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.dell.com
uDefault_Page_URL = hxxp://www.dell.com
mWinlogon: Userinit = userinit.exe
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: avast! Online Security: {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
mRun: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
mRun: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
StartupFolder: C:\Users\PRECIS~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{68BB8804-2288-49BF-93D1-4652893DB5D7} : DHCPNameServer = 192.168.1.254
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.149\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: avast! Online Security: {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1 www.spywareinfo.com (http://www.spywareinfo.com)
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2014-3-13 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2014-3-13 207904]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-9-27 248240]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2013-8-24 55856]
R1 aswKbd;aswKbd;C:\Windows\System32\drivers\aswKbd.sys [2014-3-13 28184]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2014-3-13 1038072]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2014-3-13 421704]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2014-3-13 78648]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-3-13 50344]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2013-4-22 822504]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-6-18 134944]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2013-6-26 523944]
R3 aswStm;aswStm;C:\Windows\System32\drivers\aswStm.sys [2014-3-13 80184]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-10-23 348376]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2013-6-26 767144]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2013-6-26 273576]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2013-6-26 28840]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2013-6-26 23208]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2013-6-26 207528]
R3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
R3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
R3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S2 avast! Firewall;avast! Firewall;"C:\Program Files\AVAST Software\Avast\afwServ.exe" --> C:\Program Files\AVAST Software\Avast\afwServ.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2014-3-14 1153368]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-3-14 111616]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2011-2-15 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2011-2-15 180736]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-8-31 19456]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-3-14 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-8-31 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-8-31 1255736]
.
=============== Created Last 30 ================
.
2014-03-14 13:49:15 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2014-03-14 13:49:15 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2014-03-14 13:14:57 10536864 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{3F32A48A-A026-419A-989E-8DCFC4B8C164}\mpengine.dll
2014-03-14 13:14:17 548864 ----a-w- C:\Windows\System32\vbscript.dll
2014-03-14 13:14:17 454656 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-03-14 13:09:29 6574592 ----a-w- C:\Windows\System32\mstscax.dll
2014-03-14 13:09:29 5694464 ----a-w- C:\Windows\SysWow64\mstscax.dll
2014-03-14 12:30:27 1008128 ----a-w- C:\Windows\System32\USER32 (2).dll
2014-03-14 12:28:26 -------- d-----w- C:\Windows\Migration
2014-03-14 12:20:47 44544 ----a-w- C:\Windows\System32\TsUsbGDCoInstaller.dll
2014-03-14 12:15:57 -------- d-----w- C:\Users\Precision M6300\AppData\Local\Google
2014-03-14 12:15:19 -------- d-----w- C:\Users\Precision M6300\AppData\Local\Apps
2014-03-14 12:15:18 -------- d-----w- C:\Users\Precision M6300\AppData\Local\Deployment
2014-03-14 12:10:44 1008128 ----a-w- C:\Windows\system\USER32.dll
2014-03-14 12:01:02 792576 ----a-w- C:\Windows\SysWow64\TSWorkspace.dll
2014-03-14 12:01:02 1030144 ----a-w- C:\Windows\System32\TSWorkspace.dll
2014-03-14 11:37:07 -------- d-----w- C:\ProgramData\Malwarebytes
2014-03-14 09:07:27 1031560 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BD793EB2-C0A1-4C92-B473-C0824A59F933}\gapaengine.dll
2014-03-14 09:07:11 10536864 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-03-14 07:02:11 467984 ----a-w- C:\Windows\SysWow64\d3dx10_39.dll
2014-03-14 07:02:11 1493528 ----a-w- C:\Windows\SysWow64\D3DCompiler_39.dll
2014-03-14 07:02:07 3851784 ----a-w- C:\Windows\SysWow64\D3DX9_39.dll
2014-03-14 07:01:34 -------- d-sh--w- C:\Windows\SysWow64\AI_RecycleBin
2014-03-14 07:01:30 -------- d-----w- C:\Riot Games
2014-03-14 06:57:33 -------- d-----w- C:\Users\Precision M6300\AppData\Local\PMB Files
2014-03-14 06:57:30 -------- d-----w- C:\ProgramData\PMB Files
2014-03-14 06:57:21 -------- d-----w- C:\Program Files (x86)\Pando Networks
2014-03-14 06:52:54 -------- d-----w- C:\Users\Precision M6300\AppData\Roaming\Riot Games
2014-03-14 06:50:22 108968 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2014-03-13 21:54:42 99840 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2014-03-13 21:54:42 53248 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2014-03-13 21:54:42 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2014-03-13 21:54:41 7808 ----a-w- C:\Windows\System32\drivers\usbd.sys
2014-03-13 21:54:41 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2014-03-13 21:54:41 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2014-03-13 21:54:41 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2014-03-13 13:50:23 -------- d-----w- C:\ProgramData\Oracle
2014-03-13 13:45:20 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-03-13 13:36:48 -------- d-----w- C:\NVIDIA
2014-03-13 08:54:06 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2014-03-13 08:54:06 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2014-03-13 08:54:04 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2014-03-13 08:54:03 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2014-03-13 06:36:06 -------- d-----w- C:\Users\Precision M6300\AppData\Roaming\AVAST Software
2014-03-13 06:35:19 440672 ----a-w- C:\Windows\System32\drivers\aswndisflt.sys
2014-03-13 06:34:54 80184 ----a-w- C:\Windows\System32\drivers\aswStm.sys
2014-03-13 06:34:54 207904 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2014-03-13 06:34:53 65776 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2014-03-13 06:34:52 1038072 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2014-03-13 06:34:50 92544 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2014-03-13 06:34:50 78648 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2014-03-13 06:34:49 28184 ----a-w- C:\Windows\System32\drivers\aswKbd.sys
2014-03-13 06:34:43 43152 ----a-w- C:\Windows\avastSS.scr
2014-03-13 06:15:20 -------- d-----w- C:\Program Files\AVAST Software
2014-03-13 06:06:01 -------- d-----w- C:\ProgramData\AVAST Software
2014-03-13 01:55:05 1031560 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-03-13 01:55:00 484864 ----a-w- C:\Windows\System32\wer.dll
2014-03-13 01:55:00 228864 ----a-w- C:\Windows\System32\wwansvc.dll
2014-03-13 01:53:59 497152 ----a-w- C:\Windows\System32\drivers\afd.sys
2014-03-13 01:52:31 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2014-03-13 01:49:55 81920 ----a-w- C:\Windows\SysWow64\davclnt.dll
2014-03-13 01:44:16 461312 ----a-w- C:\Windows\System32\scavengeui.dll
2014-03-13 01:41:44 -------- d-----w- C:\Users\Precision M6300\AppData\Roaming\NVIDIA
2014-03-13 01:39:59 25936 ----a-w- C:\Windows\System32\X3DAudio1_5.dll
2014-03-13 01:16:44 -------- d-----w- C:\Program Files (x86)\SystemRequirementsLab
2014-03-13 01:12:45 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2014-03-13 01:12:42 -------- d-----w- C:\Program Files (x86)\Steam
2014-03-10 14:37:57 -------- d-----w- C:\Users\Precision M6300\AppData\Local\Diagnostics
.
==================== Find3M ====================
.
2014-03-13 01:23:37 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-03-13 01:23:37 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-03-01 05:17:02 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-03-01 05:16:26 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-03-01 04:52:55 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-03-01 04:51:59 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-03-01 04:33:52 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-03-01 04:33:34 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-03-01 04:32:59 708608 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-03-01 04:23:49 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-03-01 04:11:20 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-03-01 03:54:33 5768704 ----a-w- C:\Windows\System32\jscript9.dll
2014-03-01 03:52:43 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-03-01 03:51:53 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-03-01 03:38:26 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-03-01 03:37:35 553472 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-03-01 03:35:11 2041856 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-03-01 03:14:15 4244480 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-03-01 03:10:28 2334208 ----a-w- C:\Windows\System32\wininet.dll
2014-03-01 03:00:08 1964032 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-03-01 02:32:16 1820160 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-02-07 01:23:30 3156480 ----a-w- C:\Windows\System32\win32k.sys
2014-02-04 02:32:22 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2014-02-04 02:32:12 624128 ----a-w- C:\Windows\System32\qedit.dll
2014-02-04 02:04:22 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2014-02-04 02:04:11 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2014-01-29 02:06:47 381440 ----a-w- C:\Windows\SysWow64\wer.dll
2014-01-24 06:27:12 6676768 ----a-w- C:\Windows\System32\nvcpl.dll
2014-01-24 06:27:12 3496224 ----a-w- C:\Windows\System32\nvsvc64.dll
2014-01-24 06:27:08 922912 ----a-w- C:\Windows\System32\nvvsvc.exe
2014-01-24 06:27:08 67072 ----a-w- C:\Windows\System32\nv3dappshextr.dll
2014-01-24 06:27:08 63776 ----a-w- C:\Windows\System32\nvshext.dll
2014-01-24 06:27:08 386336 ----a-w- C:\Windows\System32\nvmctray.dll
2014-01-24 06:27:08 2559776 ----a-w- C:\Windows\System32\nvsvcr.dll
2014-01-24 06:27:08 1070368 ----a-w- C:\Windows\System32\nv3dappshext.dll
2014-01-19 07:33:29 270496 ------w- C:\Windows\System32\MpSigStub.exe
2013-12-24 23:09:41 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2013-12-24 22:48:32 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
.
============= FINISH: 0:43:03.63 ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-03-15 00:44:08
-----------------------------
00:44:08.295 OS Version: Windows x64 6.1.7601 Service Pack 1
00:44:08.295 Number of processors: 2 586 0xF0B
00:44:08.295 ComputerName: PRECISIONM6300 UserName:
00:44:09.855 Initialize success
00:44:13.973 AVAST engine defs: 14031401
00:44:30.883 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
00:44:30.883 Disk 0 Vendor: ST9160823ASG 3.ADD Size: 152627MB BusType: 3
00:44:31.008 Disk 0 MBR read successfully
00:44:31.008 Disk 0 MBR scan
00:44:31.008 Disk 0 Windows 7 default MBR code
00:44:31.024 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
00:44:31.039 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 152525 MB offset 206848
00:44:31.164 Disk 0 scanning C:\Windows\system32\drivers
00:44:38.949 Service scanning
00:44:55.921 Modules scanning
00:44:55.921 Disk 0 trace - called modules:
00:44:55.968 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS intelide.sys PCIIDEX.SYS hal.dll atapi.sys
00:44:55.968 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80042d9060]
00:44:56.499 3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0xfffffa80040e9060]
00:44:56.998 AVAST engine scan C:\Windows
00:44:58.183 AVAST engine scan C:\Windows\system32
00:47:51.291 AVAST engine scan C:\Windows\system32\drivers
00:48:00.838 AVAST engine scan C:\Users\Precision M6300
00:50:13.412 AVAST engine scan C:\ProgramData
00:50:44.536 Scan finished successfully
00:51:29.714 Disk 0 MBR has been saved successfully to "C:\Users\Precision M6300\Desktop\MBR.dat"
00:51:29.745 The log file has been saved successfully to "C:\Users\Precision M6300\Desktop\aswMBR.txt"
Sorry I didn't see the read this before you post forum. So here is the logs you guys want. Sorry about that and thanks for the help.
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16521 BrowserJavaVersion: 10.51.2
Run by Precision M6300 at 0:42:02 on 2014-03-15
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.4094.2353 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
FW: avast! Internet Security *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
.
============== Running Processes ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-03-15 00:44:08
-----------------------------
00:44:08.295 OS Version: Windows x64 6.1.7601 Service Pack 1
00:44:08.295 Number of processors: 2 586 0xF0B
00:44:08.295 ComputerName: PRECISIONM6300 UserName:
00:44:09.855 Initialize success
00:44:13.973 AVAST engine defs: 14031401
00:44:30.883 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
00:44:30.883 Disk 0 Vendor: ST9160823ASG 3.ADD Size: 152627MB BusType: 3
00:44:31.008 Disk 0 MBR read successfully
00:44:31.008 Disk 0 MBR scan
00:44:31.008 Disk 0 Windows 7 default MBR code
00:44:31.024 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
00:44:31.039 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 152525 MB offset 206848
00:44:31.164 Disk 0 scanning C:\Windows\system32\drivers
00:44:38.949 Service scanning
00:44:55.921 Modules scanning
00:44:55.921 Disk 0 trace - called modules:
00:44:55.968 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS intelide.sys PCIIDEX.SYS hal.dll atapi.sys
00:44:55.968 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80042d9060]
00:44:56.499 3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0xfffffa80040e9060]
00:44:56.998 AVAST engine scan C:\Windows
00:44:58.183 AVAST engine scan C:\Windows\system32
00:47:51.291 AVAST engine scan C:\Windows\system32\drivers
00:48:00.838 AVAST engine scan C:\Users\Precision M6300
00:50:13.412 AVAST engine scan C:\ProgramData
00:50:44.536 Scan finished successfully
00:51:29.714 Disk 0 MBR has been saved successfully to "C:\Users\Precision M6300\Desktop\MBR.dat"
00:51:29.745 The log file has been saved successfully to "C:\Users\Precision M6300\Desktop\aswMBR.txt"
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
C:\Windows\system32\taskhost.exe
C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.202\deploy\LoLLauncher.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\System32\MsSpellCheckingFacility.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.dell.com
uDefault_Page_URL = hxxp://www.dell.com
mWinlogon: Userinit = userinit.exe
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: avast! Online Security: {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
mRun: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
mRun: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
StartupFolder: C:\Users\PRECIS~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{68BB8804-2288-49BF-93D1-4652893DB5D7} : DHCPNameServer = 192.168.1.254
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.149\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: avast! Online Security: {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1 www.spywareinfo.com (http://www.spywareinfo.com)
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2014-3-13 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2014-3-13 207904]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-9-27 248240]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2013-8-24 55856]
R1 aswKbd;aswKbd;C:\Windows\System32\drivers\aswKbd.sys [2014-3-13 28184]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2014-3-13 1038072]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2014-3-13 421704]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2014-3-13 78648]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-3-13 50344]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2013-4-22 822504]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-6-18 134944]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2013-6-26 523944]
R3 aswStm;aswStm;C:\Windows\System32\drivers\aswStm.sys [2014-3-13 80184]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-10-23 348376]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2013-6-26 767144]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2013-6-26 273576]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2013-6-26 28840]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2013-6-26 23208]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2013-6-26 207528]
R3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
R3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
R3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S2 avast! Firewall;avast! Firewall;"C:\Program Files\AVAST Software\Avast\afwServ.exe" --> C:\Program Files\AVAST Software\Avast\afwServ.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2014-3-14 1153368]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-3-14 111616]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2011-2-15 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2011-2-15 180736]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-8-31 19456]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-3-14 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-8-31 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-8-31 1255736]
.
=============== Created Last 30 ================
.
2014-03-14 13:49:15 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2014-03-14 13:49:15 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2014-03-14 13:14:57 10536864 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{3F32A48A-A026-419A-989E-8DCFC4B8C164}\mpengine.dll
2014-03-14 13:14:17 548864 ----a-w- C:\Windows\System32\vbscript.dll
2014-03-14 13:14:17 454656 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-03-14 13:09:29 6574592 ----a-w- C:\Windows\System32\mstscax.dll
2014-03-14 13:09:29 5694464 ----a-w- C:\Windows\SysWow64\mstscax.dll
2014-03-14 12:30:27 1008128 ----a-w- C:\Windows\System32\USER32 (2).dll
2014-03-14 12:28:26 -------- d-----w- C:\Windows\Migration
2014-03-14 12:20:47 44544 ----a-w- C:\Windows\System32\TsUsbGDCoInstaller.dll
2014-03-14 12:15:57 -------- d-----w- C:\Users\Precision M6300\AppData\Local\Google
2014-03-14 12:15:19 -------- d-----w- C:\Users\Precision M6300\AppData\Local\Apps
2014-03-14 12:15:18 -------- d-----w- C:\Users\Precision M6300\AppData\Local\Deployment
2014-03-14 12:10:44 1008128 ----a-w- C:\Windows\system\USER32.dll
2014-03-14 12:01:02 792576 ----a-w- C:\Windows\SysWow64\TSWorkspace.dll
2014-03-14 12:01:02 1030144 ----a-w- C:\Windows\System32\TSWorkspace.dll
2014-03-14 11:37:07 -------- d-----w- C:\ProgramData\Malwarebytes
2014-03-14 09:07:27 1031560 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BD793EB2-C0A1-4C92-B473-C0824A59F933}\gapaengine.dll
2014-03-14 09:07:11 10536864 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-03-14 07:02:11 467984 ----a-w- C:\Windows\SysWow64\d3dx10_39.dll
2014-03-14 07:02:11 1493528 ----a-w- C:\Windows\SysWow64\D3DCompiler_39.dll
2014-03-14 07:02:07 3851784 ----a-w- C:\Windows\SysWow64\D3DX9_39.dll
2014-03-14 07:01:34 -------- d-sh--w- C:\Windows\SysWow64\AI_RecycleBin
2014-03-14 07:01:30 -------- d-----w- C:\Riot Games
2014-03-14 06:57:33 -------- d-----w- C:\Users\Precision M6300\AppData\Local\PMB Files
2014-03-14 06:57:30 -------- d-----w- C:\ProgramData\PMB Files
2014-03-14 06:57:21 -------- d-----w- C:\Program Files (x86)\Pando Networks
2014-03-14 06:52:54 -------- d-----w- C:\Users\Precision M6300\AppData\Roaming\Riot Games
2014-03-14 06:50:22 108968 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2014-03-13 21:54:42 99840 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2014-03-13 21:54:42 53248 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2014-03-13 21:54:42 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2014-03-13 21:54:41 7808 ----a-w- C:\Windows\System32\drivers\usbd.sys
2014-03-13 21:54:41 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2014-03-13 21:54:41 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2014-03-13 21:54:41 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2014-03-13 13:50:23 -------- d-----w- C:\ProgramData\Oracle
2014-03-13 13:45:20 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-03-13 13:36:48 -------- d-----w- C:\NVIDIA
2014-03-13 08:54:06 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2014-03-13 08:54:06 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2014-03-13 08:54:04 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2014-03-13 08:54:03 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2014-03-13 06:36:06 -------- d-----w- C:\Users\Precision M6300\AppData\Roaming\AVAST Software
2014-03-13 06:35:19 440672 ----a-w- C:\Windows\System32\drivers\aswndisflt.sys
2014-03-13 06:34:54 80184 ----a-w- C:\Windows\System32\drivers\aswStm.sys
2014-03-13 06:34:54 207904 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2014-03-13 06:34:53 65776 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2014-03-13 06:34:52 1038072 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2014-03-13 06:34:50 92544 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2014-03-13 06:34:50 78648 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2014-03-13 06:34:49 28184 ----a-w- C:\Windows\System32\drivers\aswKbd.sys
2014-03-13 06:34:43 43152 ----a-w- C:\Windows\avastSS.scr
2014-03-13 06:15:20 -------- d-----w- C:\Program Files\AVAST Software
2014-03-13 06:06:01 -------- d-----w- C:\ProgramData\AVAST Software
2014-03-13 01:55:05 1031560 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-03-13 01:55:00 484864 ----a-w- C:\Windows\System32\wer.dll
2014-03-13 01:55:00 228864 ----a-w- C:\Windows\System32\wwansvc.dll
2014-03-13 01:53:59 497152 ----a-w- C:\Windows\System32\drivers\afd.sys
2014-03-13 01:52:31 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2014-03-13 01:49:55 81920 ----a-w- C:\Windows\SysWow64\davclnt.dll
2014-03-13 01:44:16 461312 ----a-w- C:\Windows\System32\scavengeui.dll
2014-03-13 01:41:44 -------- d-----w- C:\Users\Precision M6300\AppData\Roaming\NVIDIA
2014-03-13 01:39:59 25936 ----a-w- C:\Windows\System32\X3DAudio1_5.dll
2014-03-13 01:16:44 -------- d-----w- C:\Program Files (x86)\SystemRequirementsLab
2014-03-13 01:12:45 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2014-03-13 01:12:42 -------- d-----w- C:\Program Files (x86)\Steam
2014-03-10 14:37:57 -------- d-----w- C:\Users\Precision M6300\AppData\Local\Diagnostics
.
==================== Find3M ====================
.
2014-03-13 01:23:37 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-03-13 01:23:37 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-03-01 05:17:02 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-03-01 05:16:26 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-03-01 04:52:55 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-03-01 04:51:59 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-03-01 04:33:52 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-03-01 04:33:34 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-03-01 04:32:59 708608 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-03-01 04:23:49 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-03-01 04:11:20 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-03-01 03:54:33 5768704 ----a-w- C:\Windows\System32\jscript9.dll
2014-03-01 03:52:43 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-03-01 03:51:53 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-03-01 03:38:26 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-03-01 03:37:35 553472 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-03-01 03:35:11 2041856 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-03-01 03:14:15 4244480 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-03-01 03:10:28 2334208 ----a-w- C:\Windows\System32\wininet.dll
2014-03-01 03:00:08 1964032 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-03-01 02:32:16 1820160 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-02-07 01:23:30 3156480 ----a-w- C:\Windows\System32\win32k.sys
2014-02-04 02:32:22 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2014-02-04 02:32:12 624128 ----a-w- C:\Windows\System32\qedit.dll
2014-02-04 02:04:22 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2014-02-04 02:04:11 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2014-01-29 02:06:47 381440 ----a-w- C:\Windows\SysWow64\wer.dll
2014-01-24 06:27:12 6676768 ----a-w- C:\Windows\System32\nvcpl.dll
2014-01-24 06:27:12 3496224 ----a-w- C:\Windows\System32\nvsvc64.dll
2014-01-24 06:27:08 922912 ----a-w- C:\Windows\System32\nvvsvc.exe
2014-01-24 06:27:08 67072 ----a-w- C:\Windows\System32\nv3dappshextr.dll
2014-01-24 06:27:08 63776 ----a-w- C:\Windows\System32\nvshext.dll
2014-01-24 06:27:08 386336 ----a-w- C:\Windows\System32\nvmctray.dll
2014-01-24 06:27:08 2559776 ----a-w- C:\Windows\System32\nvsvcr.dll
2014-01-24 06:27:08 1070368 ----a-w- C:\Windows\System32\nv3dappshext.dll
2014-01-19 07:33:29 270496 ------w- C:\Windows\System32\MpSigStub.exe
2013-12-24 23:09:41 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2013-12-24 22:48:32 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
.
============= FINISH: 0:43:03.63 ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-03-15 00:44:08
-----------------------------
00:44:08.295 OS Version: Windows x64 6.1.7601 Service Pack 1
00:44:08.295 Number of processors: 2 586 0xF0B
00:44:08.295 ComputerName: PRECISIONM6300 UserName:
00:44:09.855 Initialize success
00:44:13.973 AVAST engine defs: 14031401
00:44:30.883 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
00:44:30.883 Disk 0 Vendor: ST9160823ASG 3.ADD Size: 152627MB BusType: 3
00:44:31.008 Disk 0 MBR read successfully
00:44:31.008 Disk 0 MBR scan
00:44:31.008 Disk 0 Windows 7 default MBR code
00:44:31.024 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
00:44:31.039 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 152525 MB offset 206848
00:44:31.164 Disk 0 scanning C:\Windows\system32\drivers
00:44:38.949 Service scanning
00:44:55.921 Modules scanning
00:44:55.921 Disk 0 trace - called modules:
00:44:55.968 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS intelide.sys PCIIDEX.SYS hal.dll atapi.sys
00:44:55.968 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80042d9060]
00:44:56.499 3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0xfffffa80040e9060]
00:44:56.998 AVAST engine scan C:\Windows
00:44:58.183 AVAST engine scan C:\Windows\system32
00:47:51.291 AVAST engine scan C:\Windows\system32\drivers
00:48:00.838 AVAST engine scan C:\Users\Precision M6300
00:50:13.412 AVAST engine scan C:\ProgramData
00:50:44.536 Scan finished successfully
00:51:29.714 Disk 0 MBR has been saved successfully to "C:\Users\Precision M6300\Desktop\MBR.dat"
00:51:29.745 The log file has been saved successfully to "C:\Users\Precision M6300\Desktop\aswMBR.txt"