Paranoidpotato
New member
Please help, my computer GPU is running high, even though nothing is actively running. At the soonest convience please solve this problem.
These are the logs provided:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16476
Run by Ryan Nakai at 20:00:53 on 2013-05-08
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8191.5958 [GMT -6:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Google\Chrome Remote Desktop\25.0.1364.23\remoting_daemon.exe
C:\Users\Ryan Nakai\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
c:\Program Files\Microsoft Security Client\NisSrv.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Program Files (x86)\Google\Chrome Remote Desktop\25.0.1364.23\remoting_host.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Box Sync\BoxSyncHelper.exe
C:\Users\Ryan Nakai\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\Ryan Nakai\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Box Sync\BoxSync.exe
C:\Users\Ryan Nakai\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Ryan Nakai\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Users\Ryan Nakai\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Windows\system32\SearchIndexer.exe
C:\Users\Ryan Nakai\AppData\Roaming\WindowsDriver\vcsrss.exe
C:\Users\Ryan Nakai\AppData\Roaming\WindowsDriver\csrss.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleCrashHandler64.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe,
BHO: Lucky Savings WidgetEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
BHO: DefaultTab Browser Helper: {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Ryan Nakai\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll
BHO: DVDVideoSoft WebPageAdjuster Class: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
uRun: [Google Update] "C:\Users\Ryan Nakai\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [MusicManager] "C:\Users\Ryan Nakai\AppData\Local\Programs\Google\MusicManager\MusicManager.exe"
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [GoogleChromeAutoLaunch_01263A5253C555C4A9D4CAD3ADB95ECB] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
uRun: [WindowsDriver] C:\Users\Ryan Nakai\AppData\Roaming\WindowsDriver\vcsrss.exe
StartupFolder: C:\Users\RYANNA~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
StartupFolder: C:\Users\RYANNA~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Ryan Nakai\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BOXSYN~1.LNK - C:\Program Files\Box Sync\BoxSync.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
IE: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
TCP: NameServer = 10.10.0.1
TCP: Interfaces\{69B9A6F4-8EA2-49CE-9859-B593BB2652A7} : DHCPNameServer = 10.10.0.1
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Lucky Savings WidgetEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
x64-BHO: DVDVideoSoft WebPageAdjuster Class: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll
x64-TB: Lucky Savings Widget: {ae07101b-46d4-4a98-af68-0333ea26e113} -
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [BoxSyncHelper] "C:\Program Files\Box Sync\BoxSyncHelper.exe"
x64-IE: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Ryan Nakai\AppData\Roaming\Mozilla\Firefox\Profiles\7fsthnf9.default\
FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: C:\Users\Ryan Nakai\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll
FF - ExtSQL: 2013-03-26 14:29; {ACAA314B-EEBA-48e4-AD47-84E31C44796C}; C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-1-20 230320]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-4-26 237056]
R2 chromoting;Chrome Remote Desktop Service;C:\Program Files (x86)\Google\Chrome Remote Desktop\25.0.1364.23\remoting_daemon.exe [2013-1-4 357480]
R2 DefaultTabUpdate;DefaultTabUpdate;C:\Users\Ryan Nakai\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe [2013-2-11 107520]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2012-8-31 130008]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2010-7-21 1002848]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-1-27 379360]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-4-21 471144]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-2-12 59392]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-2-11 1255736]
.
=============== Created Last 30 ================
.
2013-04-17 05:27:51 -------- d-----w- C:\Users\Ryan Nakai\AppData\Roaming\Malwarebytes
2013-04-17 05:26:36 -------- d-----w- C:\ProgramData\Malwarebytes
2013-04-17 05:26:34 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-04-17 05:26:34 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-04-17 05:10:53 9311288 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{13DEE44A-FC35-4630-BFE0-1BBDBF974FCB}\mpengine.dll
2013-04-17 04:59:36 -------- d-----w- C:\Users\Ryan Nakai\AppData\Roaming\WindowsDriver
2013-04-16 16:17:56 9311288 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-04-10 22:02:05 -------- d-----w- C:\Program Files (x86)\Lame For Audacity
2013-04-10 15:32:07 3717632 ----a-w- C:\Windows\System32\mstscax.dll
2013-04-10 15:32:07 3217408 ----a-w- C:\Windows\SysWow64\mstscax.dll
2013-04-10 15:32:06 44032 ----a-w- C:\Windows\System32\tsgqec.dll
2013-04-10 15:32:06 36864 ----a-w- C:\Windows\SysWow64\tsgqec.dll
2013-04-10 15:32:06 158720 ----a-w- C:\Windows\System32\aaclient.dll
2013-04-10 15:32:06 131584 ----a-w- C:\Windows\SysWow64\aaclient.dll
2013-04-10 15:32:02 3153408 ----a-w- C:\Windows\System32\win32k.sys
2013-04-10 15:32:01 223752 ----a-w- C:\Windows\System32\drivers\fvevol.sys
2013-04-10 15:32:01 1655656 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2013-04-10 15:31:59 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-04-10 15:31:58 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-04-10 15:31:58 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-04-10 15:31:57 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
2013-04-10 15:31:57 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2013-04-10 15:31:57 112640 ----a-w- C:\Windows\System32\smss.exe
.
==================== Find3M ====================
.
2013-04-13 14:27:33 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-04-13 14:27:33 691592 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-04-02 10:34:28 282744 ------w- C:\Windows\System32\MpSigStub.exe
2013-04-01 19:37:21 109298 ----a-w- C:\Users\Ryan Nakai\AppData\Roaming\MSWINSCK.OCX
2013-02-25 23:59:02 466456 ----a-w- C:\Windows\System32\wrap_oal.dll
2013-02-25 23:59:02 444952 ----a-w- C:\Windows\SysWow64\wrap_oal.dll
2013-02-25 23:59:02 122904 ----a-w- C:\Windows\System32\OpenAL32.dll
2013-02-25 23:59:02 109080 ----a-w- C:\Windows\SysWow64\OpenAL32.dll
2013-02-22 06:27:49 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2013-02-22 06:20:51 1392128 ----a-w- C:\Windows\System32\wininet.dll
2013-02-22 06:19:37 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-02-22 06:15:48 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-02-22 06:15:23 599040 ----a-w- C:\Windows\System32\vbscript.dll
2013-02-22 06:12:41 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2013-02-22 03:46:00 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-02-22 03:38:00 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-02-22 03:37:50 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-02-22 03:34:17 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2013-02-22 03:34:03 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2013-02-22 03:31:46 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-02-12 20:55:22 175616 ----a-w- C:\Windows\System32\msclmd.dll
2013-02-12 20:55:22 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2013-02-12 05:45:24 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45:22 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45:22 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45:22 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48:31 474112 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-02-12 04:48:26 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
2013-02-12 04:12:05 19968 ----a-w- C:\Windows\System32\drivers\usb8023.sys
2013-02-11 23:48:28 0 ----a-w- C:\Windows\ativpsrm.bin
.
============= FINISH: 20:01:08.28 ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-05-08 20:28:21
-----------------------------
20:28:21.341 OS Version: Windows x64 6.1.7601 Service Pack 1
20:28:21.341 Number of processors: 6 586 0xA00
20:28:21.342 ComputerName: LICORICE-PC UserName: Ryan Nakai
20:28:28.653 Initialize success
20:28:42.285 AVAST engine defs: 13050801
20:28:45.143 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005f
20:28:45.144 Disk 0 Vendor: ST1000DM CC4C Size: 953869MB BusType: 11
20:28:45.230 Disk 0 MBR read successfully
20:28:45.232 Disk 0 MBR scan
20:28:45.235 Disk 0 Windows 7 default MBR code
20:28:45.241 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
20:28:45.264 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848
20:28:45.344 Disk 0 scanning C:\Windows\system32\drivers
20:28:57.663 Service scanning
20:29:16.519 Modules scanning
20:29:16.524 Disk 0 trace - called modules:
20:29:16.537 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys
20:29:16.540 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007afb060]
20:29:16.895 3 CLASSPNP.SYS[fffff8800141743f] -> nt!IofCallDriver -> [0xfffffa8006b25040]
20:29:16.899 5 amdxata.sys[fffff8800112f7a8] -> nt!IofCallDriver -> \Device\0000005f[0xfffffa8006b1f230]
20:29:17.980 AVAST engine scan C:\Windows
20:29:20.640 AVAST engine scan C:\Windows\system32
20:32:30.235 AVAST engine scan C:\Windows\system32\drivers
20:32:43.977 AVAST engine scan C:\Users\Ryan Nakai
20:38:59.128 AVAST engine scan C:\ProgramData
20:39:11.692 Scan finished successfully
20:39:48.276 Disk 0 MBR has been saved successfully to "C:\Users\Ryan Nakai\Desktop\MBR.dat"
20:39:48.329 The log file has been saved successfully to "C:\Users\Ryan Nakai\Desktop\aswMBR.txt"
View attachment attach.zip
These are the logs provided:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16476
Run by Ryan Nakai at 20:00:53 on 2013-05-08
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8191.5958 [GMT -6:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Google\Chrome Remote Desktop\25.0.1364.23\remoting_daemon.exe
C:\Users\Ryan Nakai\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
c:\Program Files\Microsoft Security Client\NisSrv.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Program Files (x86)\Google\Chrome Remote Desktop\25.0.1364.23\remoting_host.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Box Sync\BoxSyncHelper.exe
C:\Users\Ryan Nakai\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\Ryan Nakai\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Box Sync\BoxSync.exe
C:\Users\Ryan Nakai\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Ryan Nakai\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Users\Ryan Nakai\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Windows\system32\SearchIndexer.exe
C:\Users\Ryan Nakai\AppData\Roaming\WindowsDriver\vcsrss.exe
C:\Users\Ryan Nakai\AppData\Roaming\WindowsDriver\csrss.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleCrashHandler64.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe,
BHO: Lucky Savings WidgetEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
BHO: DefaultTab Browser Helper: {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Ryan Nakai\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll
BHO: DVDVideoSoft WebPageAdjuster Class: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
uRun: [Google Update] "C:\Users\Ryan Nakai\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [MusicManager] "C:\Users\Ryan Nakai\AppData\Local\Programs\Google\MusicManager\MusicManager.exe"
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [GoogleChromeAutoLaunch_01263A5253C555C4A9D4CAD3ADB95ECB] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
uRun: [WindowsDriver] C:\Users\Ryan Nakai\AppData\Roaming\WindowsDriver\vcsrss.exe
StartupFolder: C:\Users\RYANNA~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
StartupFolder: C:\Users\RYANNA~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Ryan Nakai\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BOXSYN~1.LNK - C:\Program Files\Box Sync\BoxSync.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
IE: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
TCP: NameServer = 10.10.0.1
TCP: Interfaces\{69B9A6F4-8EA2-49CE-9859-B593BB2652A7} : DHCPNameServer = 10.10.0.1
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Lucky Savings WidgetEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
x64-BHO: DVDVideoSoft WebPageAdjuster Class: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll
x64-TB: Lucky Savings Widget: {ae07101b-46d4-4a98-af68-0333ea26e113} -
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [BoxSyncHelper] "C:\Program Files\Box Sync\BoxSyncHelper.exe"
x64-IE: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Ryan Nakai\AppData\Roaming\Mozilla\Firefox\Profiles\7fsthnf9.default\
FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: C:\Users\Ryan Nakai\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll
FF - ExtSQL: 2013-03-26 14:29; {ACAA314B-EEBA-48e4-AD47-84E31C44796C}; C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-1-20 230320]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-4-26 237056]
R2 chromoting;Chrome Remote Desktop Service;C:\Program Files (x86)\Google\Chrome Remote Desktop\25.0.1364.23\remoting_daemon.exe [2013-1-4 357480]
R2 DefaultTabUpdate;DefaultTabUpdate;C:\Users\Ryan Nakai\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe [2013-2-11 107520]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2012-8-31 130008]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2010-7-21 1002848]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-1-27 379360]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-4-21 471144]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-2-12 59392]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-2-11 1255736]
.
=============== Created Last 30 ================
.
2013-04-17 05:27:51 -------- d-----w- C:\Users\Ryan Nakai\AppData\Roaming\Malwarebytes
2013-04-17 05:26:36 -------- d-----w- C:\ProgramData\Malwarebytes
2013-04-17 05:26:34 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-04-17 05:26:34 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-04-17 05:10:53 9311288 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{13DEE44A-FC35-4630-BFE0-1BBDBF974FCB}\mpengine.dll
2013-04-17 04:59:36 -------- d-----w- C:\Users\Ryan Nakai\AppData\Roaming\WindowsDriver
2013-04-16 16:17:56 9311288 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-04-10 22:02:05 -------- d-----w- C:\Program Files (x86)\Lame For Audacity
2013-04-10 15:32:07 3717632 ----a-w- C:\Windows\System32\mstscax.dll
2013-04-10 15:32:07 3217408 ----a-w- C:\Windows\SysWow64\mstscax.dll
2013-04-10 15:32:06 44032 ----a-w- C:\Windows\System32\tsgqec.dll
2013-04-10 15:32:06 36864 ----a-w- C:\Windows\SysWow64\tsgqec.dll
2013-04-10 15:32:06 158720 ----a-w- C:\Windows\System32\aaclient.dll
2013-04-10 15:32:06 131584 ----a-w- C:\Windows\SysWow64\aaclient.dll
2013-04-10 15:32:02 3153408 ----a-w- C:\Windows\System32\win32k.sys
2013-04-10 15:32:01 223752 ----a-w- C:\Windows\System32\drivers\fvevol.sys
2013-04-10 15:32:01 1655656 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2013-04-10 15:31:59 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-04-10 15:31:58 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-04-10 15:31:58 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-04-10 15:31:57 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
2013-04-10 15:31:57 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2013-04-10 15:31:57 112640 ----a-w- C:\Windows\System32\smss.exe
.
==================== Find3M ====================
.
2013-04-13 14:27:33 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-04-13 14:27:33 691592 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-04-02 10:34:28 282744 ------w- C:\Windows\System32\MpSigStub.exe
2013-04-01 19:37:21 109298 ----a-w- C:\Users\Ryan Nakai\AppData\Roaming\MSWINSCK.OCX
2013-02-25 23:59:02 466456 ----a-w- C:\Windows\System32\wrap_oal.dll
2013-02-25 23:59:02 444952 ----a-w- C:\Windows\SysWow64\wrap_oal.dll
2013-02-25 23:59:02 122904 ----a-w- C:\Windows\System32\OpenAL32.dll
2013-02-25 23:59:02 109080 ----a-w- C:\Windows\SysWow64\OpenAL32.dll
2013-02-22 06:27:49 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2013-02-22 06:20:51 1392128 ----a-w- C:\Windows\System32\wininet.dll
2013-02-22 06:19:37 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-02-22 06:15:48 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-02-22 06:15:23 599040 ----a-w- C:\Windows\System32\vbscript.dll
2013-02-22 06:12:41 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2013-02-22 03:46:00 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-02-22 03:38:00 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-02-22 03:37:50 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-02-22 03:34:17 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2013-02-22 03:34:03 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2013-02-22 03:31:46 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-02-12 20:55:22 175616 ----a-w- C:\Windows\System32\msclmd.dll
2013-02-12 20:55:22 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2013-02-12 05:45:24 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45:22 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45:22 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45:22 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48:31 474112 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-02-12 04:48:26 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
2013-02-12 04:12:05 19968 ----a-w- C:\Windows\System32\drivers\usb8023.sys
2013-02-11 23:48:28 0 ----a-w- C:\Windows\ativpsrm.bin
.
============= FINISH: 20:01:08.28 ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-05-08 20:28:21
-----------------------------
20:28:21.341 OS Version: Windows x64 6.1.7601 Service Pack 1
20:28:21.341 Number of processors: 6 586 0xA00
20:28:21.342 ComputerName: LICORICE-PC UserName: Ryan Nakai
20:28:28.653 Initialize success
20:28:42.285 AVAST engine defs: 13050801
20:28:45.143 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005f
20:28:45.144 Disk 0 Vendor: ST1000DM CC4C Size: 953869MB BusType: 11
20:28:45.230 Disk 0 MBR read successfully
20:28:45.232 Disk 0 MBR scan
20:28:45.235 Disk 0 Windows 7 default MBR code
20:28:45.241 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
20:28:45.264 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848
20:28:45.344 Disk 0 scanning C:\Windows\system32\drivers
20:28:57.663 Service scanning
20:29:16.519 Modules scanning
20:29:16.524 Disk 0 trace - called modules:
20:29:16.537 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys
20:29:16.540 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007afb060]
20:29:16.895 3 CLASSPNP.SYS[fffff8800141743f] -> nt!IofCallDriver -> [0xfffffa8006b25040]
20:29:16.899 5 amdxata.sys[fffff8800112f7a8] -> nt!IofCallDriver -> \Device\0000005f[0xfffffa8006b1f230]
20:29:17.980 AVAST engine scan C:\Windows
20:29:20.640 AVAST engine scan C:\Windows\system32
20:32:30.235 AVAST engine scan C:\Windows\system32\drivers
20:32:43.977 AVAST engine scan C:\Users\Ryan Nakai
20:38:59.128 AVAST engine scan C:\ProgramData
20:39:11.692 Scan finished successfully
20:39:48.276 Disk 0 MBR has been saved successfully to "C:\Users\Ryan Nakai\Desktop\MBR.dat"
20:39:48.329 The log file has been saved successfully to "C:\Users\Ryan Nakai\Desktop\aswMBR.txt"
View attachment attach.zip