I got a virus that turned off Microsoft Essentials and prevented me from starting it. I tried getting other programs to remove it but i believe that the virus also disabled Microsoft installer. My skype wont start properly along with other programs i use daily taking an extremely long time to start then starts to not respond. Any scans I perform come up empty and any attepmt to start microsoft defender says, file not found did you type it in correctly, or something like that despite me opening it from it's specific folder in program files. Renaming the application in a copy paste version of that folder will let me start it but cant do much from there. Thank you for your time anyone that reads this and thank you in advance for any help offered.
Have you tried Malwarebytes? If the installation is blocked you may also need to try Malwarebytes Chameleon.
This sounds like a ZeroAccess infection. Run a scan with RogueKiller and post the log file.
For 32 bit OS - http://www.adlice.com/softs/roguekiller/RogueKiller.exe
For 64 bit OS - http://www.adlice.com/softs/roguekiller/RogueKillerX64.exe
Also post the log from Malwarebytes as suggested in the above post.
"Windows could not find c:.....malwarebyte make sure it is typed in correctly"
And here is the RougeKiller log:
RogueKiller V8.7.13 x64 [Dec 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : 00000000000000000000 [Admin rights]
Mode : Scan -- Date : 12/19/2013 17:23:08
| ARK || FAK || MBR |
¤¤¤ Bad processes : 3 ¤¤¤
[SUSP PATH] msconfig.exe -- C:\ProgramData{$7187-6415-6885-1855$}\msconfig.exe [-] -> KILLED [TermProc]
[SUSP PATH] mseinstall.exe -- C:\Users\00000000000000000000\Desktop\mseinstall.exe [7] -> KILLED [TermProc]
[HIDDEN] msconfig.exe -- C:\ProgramData{$7187-6415-6885-1855$}\msconfig.exe [-] -> KILLED [TermProc]
¤¤¤ Registry Entries : 25 ¤¤¤
[RUN][SUSP PATH] HKCU[...]\Run : Browser Protect (C:\Users\00000000000000000000\AppData\Local\Temp\Browser Protect\Browser Protect.exe [-]) -> FOUND
[SHELL][SUSP PATH] HKCU[...]\Windows : load (C:\ProgramData{$7187-6415-6885-1855$}\msconfig.exe [-]) -> FOUND
[IFEO] HKLM[...]\avcenter.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\avguard.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\avp.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\bdagent.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\ccuac.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\ComboFix.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\egui.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\hijackthis.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\keyscrambler.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\mbam.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\MpCmdRun.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\MSASCui.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\MsMpEng.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\msseces.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\NisSrv.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\spybotsd.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\wireshark.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\zlclient.exe : Debugger (nsjw.exe [x]) -> FOUND
[HJ][PUM] HKLM[...]\Wow6432Node[...]\SystemRestore : DisableSR (1) -> FOUND
[HJ SMENU][PUM] HKCU[...]\Advanced : Start_ShowMyPics (0) -> FOUND
[HJ SMENU][PUM] HKCU[...]\Advanced : Start_ShowMyMusic (0) -> FOUND
[HJ DESK][PUM] HKLM[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKLM[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Scheduled tasks : 0 ¤¤¤
¤¤¤ Startup Entries : 0 ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
¤¤¤ External Hives: ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: (\.\PHYSICALDRIVE0 @ IDE) TOSHIBA DT01ACA100 ATA Device +++++
--- User ---
[MBR] 1d652e16b25a11d5522b2474eb0e1685
[BSP] 817ff837094291983d34add63df2087b : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 953767 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[0]_S_12192013_172308.txt >>
Re-scan with RogueKiller and have it remove everything except:
[HJ SMENU][PUM] HKCU[...]\Advanced : Start_ShowMyPics (0) -> FOUND
[HJ SMENU][PUM] HKCU[...]\Advanced : Start_ShowMyMusic (0) -> FOUND
[HJ DESK][PUM] HKLM[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKLM[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
If you intentionally disabled System Restore, then uncheck:
[HJ][PUM] HKLM[...]\Wow6432Node[...]\SystemRestore : DisableSR (1) -> FOUND
Reboot - MSE + Malwarebytes should be able to run.
Between Rougekiller and malwarebytes I was able to get essentials to reinstal and launch. I am now doing a full scan with it but my skype still has issues starting. Once it is up it seems to run somewhat smoothly until someone calls me. Also, when logging into my League of Legends account I get "did not receive a response from server" and it tells me to make sure windows is up to date and I have no idea where to update it since I cant seem to from my computer.
it tells me to make sure windows is up to date and I have no idea where to update it since I cant seem to from my computer.
Do you mean that Windows Update will not run?
Run Junkware Removal Tool, reboot, then run DDS. Run another scan with RogueKiller, then post the logs from all scans.
Sorry if I was unclear but my skype runs awful and windows update does run but has not helped after I just updated it. Running services, microsoft management console stops responding. I feel like the virus took or shut down something that made these things run smoothly.
Have you run the scans with JRT and DDS?
Running services, microsoft management console stops responding.
I'll look at this once I see your logs.
JRT:
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\dw7
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\{ae07101b-46d4-4a98-af68-0333ea26e113
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\nctaudiocdgrabber2.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID{3C471948-F874-49F5-B338-4F214A2EE0B1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID{FB684D26-01F4-4D9D-87CB-F486BEBA56DC
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\bi
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\visualbee
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\crossrider
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\installiq
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\visualbee
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\s
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\quickshare_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\quickshare_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\webcakedesktop_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\webcakedesktop_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3287806
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3291326
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_free-sound-recorder_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_free-sound-recorder_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ApnSetup_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ApnSetup_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_free-sound-recorder_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_free-sound-recorder_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes{CACA0828-9262-4FDB-B3C9-E0B46C9CACDF
~~~ Files
Successfully deleted: [File] "C:\Users\00000000000000000000\appdata\local\google\chrome\user data\default\local storage\http_app.mam.conduit.com_0.localstorage"
Successfully deleted: [File] "C:\Users\00000000000000000000\appdata\local\google\chrome\user data\default\local storage\http_app.mam.conduit.com_0.localstorage-journal"
Successfully deleted: [File] "C:\end"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\tarma installer"
Successfully deleted: [Folder] "C:\ProgramData\trymedia"
Successfully deleted: [Folder] "C:\Users\00000000000000000000\AppData\Roaming\drivercure"
Successfully deleted: [Folder] "C:\Users\00000000000000000000\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\00000000000000000000\appdata\local\cre"
Successfully deleted: [Folder] "C:\Users\00000000000000000000\appdata\local\webplayer"
Successfully deleted: [Folder] "C:\Users\00000000000000000000\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\bicnnkjibmphdeigoodpjlcklcnaobdj
~~~ Event Viewer Logs were cleared
Scan was completed on Thu 12/19/2013 at 22:10:19.03
End of JRT log
Could not post DDS because of code snippets formated incorrectly in this post.
Just click on the paperclip in the toolbar and attach the DDS logs.
DDS
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16428 BrowserJavaVersion: 10.40.2
Run by 00000000000000000000 at 22:11:52 on 2013-12-19
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8163.5852 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Windows\system32\dlcqcoms.exe
C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
C:\Program Files\Microsoft LifeCam\MSCamS64.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\viakaraokesrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Windows\system32\SearchIndexer.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
C:\Windows\explorer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.msn.com
mStart Page = www.worldplaycity.blogspot.com
mDefault_Page_URL = hxxp://www.worldplaycity.blogspot.com
mDefault_Search_URL = hxxp://www.google.com.pk
uProxyOverride = <local>
mWinlogon: Userinit = userinit.exe,
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_11-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_11-windows-i586.cab
TCP: NameServer = 192.168.0.1 205.171.2.226
TCP: Interfaces\{EBEFFCB0-808D-4F8C-BFDA-79AC516C3B06} : DHCPNameServer = 192.168.0.1 205.171.2.226
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: <No Name>: {ae07101b-46d4-4a98-af68-0333ea26e113} - LocalServer32 - <no file>
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2013-1-10 82560]
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2013-1-10 42624]
R0 iaStorF;iaStorF;C:\Windows\System32\drivers\iaStorF.sys [2012-2-15 23832]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-9-27 248240]
R1 AppleCharger;AppleCharger;C:\Windows\System32\drivers\AppleCharger.sys [2013-1-10 22128]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-8-6 361984]
R2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-3-5 53888]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2013-11-29 2210640]
R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [2013-10-11 377104]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-9-27 134944]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-10-23 414496]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service;C:\Windows\System32\ViakaraokeSrv.exe [2013-1-10 27792]
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2013-1-10 46136]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\System32\drivers\EtronHub3.sys [2013-1-10 65152]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\System32\drivers\EtronXHCI.sys [2013-1-10 88832]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;C:\Windows\System32\drivers\nx6000.sys [2010-1-29 36720]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-10-23 348376]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2013-1-10 565352]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2013-1-10 56448]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\System32\drivers\viahduaa.sys [2013-1-10 2206352]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 ahcix64s;ahcix64s;C:\Windows\System32\drivers\ahcix64s.sys [2012-2-15 290600]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 iaStorA;iaStorA;C:\Windows\System32\drivers\iaStorA.sys [2012-2-15 565528]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2013-12-18 111616]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-12-19 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-12-19 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-12-19 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-3-1 1255736]
S3 WinRing0_1_2_0;WinRing0_1_2_0;C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [2012-11-13 14544]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
ShellExec: wordview.exe: NCHconvertdoc="C:\Program Files (x86)\NCH Software\Prism\prism.exe" -extfind Doxillion "%L"
.
=============== Created Last 30 ================
.
2013-12-20 03:04:16 -------- d-----w- C:\Windows\ERUNT
2013-12-20 02:46:44 -------- d-----w- C:\Windows\Migration
2013-12-2
Otl
O T L l o g f i l e c r e a t e d o n : 1 2 / 2 0 / 2 0 1 3 9 : 3 5 : 5 9 P M - R u n 1
O T L b y O l d T i m e r - V e r s i o n 3 . 2 . 6 9 . 0 F o l d e r = C : \ U s e r s \ 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 \ D o w n l o a d s
6 4 b i t - H o m e P r e m i u m E d i t i o n S e r v i c e P a c k 1 ( V e r s i o n = 6 . 1 . 7 6 0 1 ) - T y p e = N T W o r k s t a t i o n
I n t e r n e t E x p l o r e r ( V e r s i o n = 9 . 1 1 . 9 6 0 0 . 1 6 4 2 8 )
L o c a l e : 0 0 0 0 0 4 0 9 | C o u n t r y : U n i t e d S t a t e s | L a n g u a g e : E N U | D a t e F o r m a t : M / d / y y y y
7 . 9 7 G b T o t a l P h y s i c a l M e m o r y | 4 . 9 5 G b A v a i l a b l e P h y s i c a l M e m o r y | 6 2 . 0 7 % M e m o r y f r e e
1 5 . 9 4 G b P a g i n g F i l e | 1 2 . 5 3 G b A v a i l a b l e i n P a g i n g F i l e | 7 8 . 6 2 % P a g i n g F i l e f r e e
P a g i n g f i l e l o c a t i o n ( s ) : ? : \ p a g e f i l e . s y s [ b i n a r y d a t a ]
% S y s t e m D r i v e % = C : | % S y s t e m R o o t % = C : \ W i n d o w s | % P r o g r a m F i l e s % = C : \ P r o g r a m F i l e s ( x 8 6 )
D r i v e C : | 9 3 1 . 4 1 G b T o t a l S p a c e | 5 1 8 . 9 2 G b F r e e S p a c e | 5 5 . 7 1 % S p a c e F r e e | P a r t i t i o n T y p e : N T F S
C o m p u t e r N a m e : 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 | U s e r N a m e : 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 | L o g g e d i n a s A d m i n i s t r a t o r .
B o o t M o d e : N o r m a l | S c a n M o d e : C u r r e n t u s e r | I n c l u d e 6 4 b i t S c a n s
C o m p a n y N a m e W h i t e l i s t : O f f | S k i p M i c r o s o f t F i l e s : O f f | N o C o m p a n y N a m e W h i t e l i s t : O n | F i l e A g e = 3 0 D a y s
[ c o l o r = # E 5 6 7 1 7 ] = = = = = = = = = = P r o c e s s e s ( A l l ) = = = = = = = = = = [ / c o l o r ]
P R C - [ 2 0 1 3 / 1 2 / 2 0 2 1 : 3 5 : 3 3 | 0 0 0 , 6 0 2 , 1 1 2 | - - - - | M ] ( O l d T i m e r T o o l s ) - - C : \ U s e r s \ 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 \ D o w n l o a d s \ O T L . e x e
P R C - [ 2 0 1 3 / 1 2 / 1 1 1 4 : 4 0 : 3 6 | 0 0 1 , 8 2 3 , 6 5 6 | - - - - | M ] ( V a l v e C o r p o r a t i o n ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ S t e a m \ S t e a m . e x e
P R C - [ 2 0 1 3 / 1 2 / 1 1 1 4 : 4 0 : 3 6 | 0 0 0 , 5 6 9 , 7 6 8 | - - - - | M ] ( V a l v e C o r p o r a t i o n ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ C o m m o n F i l e s \ S t e a m \ S t e a m S e r v i c e . e x e
P R C - [ 2 0 1 3 / 1 2 / 0 3 2 1 : 4 8 : 0 6 | 0 0 0 , 8 6 3 , 1 8 4 | - - - - | M ] ( G o o g l e I n c . ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ G o o g l e \ C h r o m e \ A p p l i c a t i o n \ c h r o m e . e x e
P R C - [ 2 0 1 3 / 1 1 / 1 5 1 0 : 5 8 : 3 4 | 0 2 0 , 5 8 8 , 7 0 4 | R - - - | M ] ( S k y p e T e c h n o l o g i e s S . A . ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ S k y p e \ P h o n e \ S k y p e . e x e
P R C - [ 2 0 1 3 / 1 0 / 2 7 0 9 : 1 2 : 2 6 | 0 0 1 , 3 6 4 , 2 5 6 | - - - - | M ] ( N V I D I A C o r p o r a t i o n ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ N V I D I A C o r p o r a t i o n \ N V I D I A U p d a t e C o r e \ d a e m o n u . e x e
P R C - [ 2 0 1 3 / 1 0 / 2 3 0 3 : 0 2 : 3 2 | 0 0 0 , 4 1 4 , 4 9 6 | - - - - | M ] ( N V I D I A C o r p o r a t i o n ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ N V I D I A C o r p o r a t i o n \ 3 D V i s i o n \ n v S C P A P I S v r . e x e
P R C - [ 2 0 1 3 / 1 0 / 1 8 1 1 : 2 4 : 3 3 | 0 0 0 , 0 6 6 , 8 7 2 | - - - - | M ] ( ) - - C : \ W i n d o w s \ S y s W O W 6 4 \ P n k B s t r A . e x e
P R C - [ 2 0 1 3 / 0 1 / 1 0 1 8 : 1 6 : 5 6 | 0 0 0 , 1 3 6 , 1 7 6 | - - - - | M ] ( G o o g l e I n c . ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ G o o g l e \ U p d a t e \ G o o g l e U p d a t e . e x e
[ c o l o r = # E 5 6 7 1 7 ] = = = = = = = = = = M o d u l e s ( A l l ) = = = = = = = = = = [ / c o l o r ]
M O D - [ 2 0 1 3 / 1 2 / 2 0 2 1 : 3 5 : 3 3 | 0 0 0 , 6 0 2 , 1 1 2 | - - - - | M ] ( O l d T i m e r T o o l s ) - - C : \ U s e r s \ 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 \ D o w n l o a d s \ O T L . e x e
M O D - [ 2 0 1 3 / 1 2 / 1 8 0 4 : 4 5 : 5 3 | 0 0 0 , 1 8 2 , 2 7 2 | - - - - | M ] ( M i c r o s o f t C o r p o r a t i o n ) - - C : \ W i n d o w s \ S y s W O W 6 4 \ m s l s 3 1 . d l l
M O D - [ 2 0 1 3 / 1 2 / 1 1 1 4 : 4 1 : 0 0 | 0 0 0 , 2 3 6 , 4 5 6 | - - - - | M ] ( V a l v e C o r p o r a t i o n ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ S t e a m \ v s t d l i b _ s . d l l
M O D - [ 2 0 1 3 / 1 2 / 1 1 1 4 : 4 0 : 5 0 | 0 0 0 , 2 6 1 , 0 3 2 | - - - - | M ] ( V a l v e C o r p o r a t i o n ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ S t e a m \ t i e r 0 _ s . d l l
M O D - [ 2 0 1 3 / 1 2 / 1 1 1 4 : 4 0 : 4 8 | 0 0 8 , 7 8 2 , 2 4 8 | - - - - | M ] ( V a l v e C o r p o r a t i o n ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ S t e a m \ s t e a m c l i e n t . d l l
M O D - [ 2 0 1 3 / 1 2 / 1 1 1 4 : 4 0 : 3 8 | 0 0 2 , 4 8 9 , 7 6 8 | - - - - | M ] ( V a l v e C o r p o r a t i o n ) - - c : \ P r o g r a m F i l e s ( x 8 6 ) \ S t e a m \ b i n \ f r i e n d s u i . d l l
M O D - [ 2 0 1 3 / 1 2 / 1 1 1 4 : 4 0 : 3 8 | 0 0 1 , 1 3 5 , 0 1 6 | - - - - | M ] ( ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ S t e a m \ b i n \ c h r o m e h t m l . d l l
M O D - [ 2 0 1 3 / 1 2 / 1 1 1 4 : 4 0 : 3 8 | 0 0 0 , 6 9 6 , 7 4 4 | - - - - | M ] ( V a l v e C o r p o r a t i o n ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ S t e a m \ b i n \ v g u i 2 _ s . d l l
M O D - [ 2 0 1 3 / 1 2 / 1 1 1 4 : 4 0 : 3 8 | 0 0 0 , 2 8 9 , 7 0 4 | - - - - | M ] ( V a l v e C o r p o r a t i o n ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ S t e a m \ c r a s h h a n d l e r . d l l
M O D - [ 2 0 1 3 / 1 2 / 1 1 1 4 : 4 0 : 3 8 | 0 0 0 , 1 6 9 , 3 8 4 | - - - - | M ] ( V a l v e C o r p o r a t i o n ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ S t e a m \ b i n \ f i l e s y s t e m _ s t d i o . d l l
M O D - [ 2 0 1 3 / 1 2 / 1 1 1 4 : 4 0 : 3 6 | 0 1 1 , 2 8 0 , 2 9 6 | - - - - | M ] ( V a l v e C o r p o r a t i o n ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ S t e a m \ S t e a m U I . d l l
M O D - [ 2 0 1 3 / 1 2 / 1 1 1 4 : 4 0 : 3 6 | 0 0 1 , 8 2 3 , 6 5 6 | - - - - | M ] ( V a l v e C o r p o r a t i o n ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ S t e a m \ S t e a m . e x e
M O D - [ 2 0 1 3 / 1 2 / 1 1 1 4 : 4 0 : 3 6 | 0 0 1 , 8 1 0 , 8 5 6 | - - - - | M ] ( V a l v e C o r p o r a t i o n ) - - c : \ P r o g r a m F i l e s ( x 8 6 ) \ S t e a m \ b i n \ s e r v e r b r o w s e r . d l l
M O D - [ 2 0 1 3 / 1 2 / 0 6 1 4 : 4 2 : 4 4 | 0 0 2 , 8 8 2 , 9 8 4 | - - - - | M ] ( V a l v e C o r p o r a t i o n ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ S t e a m \ S t e a m . d l l
M O D - [ 2 0 1 3 / 1 2 / 0 3 2 1 : 4 8 : 0 6 | 0 0 0 , 8 6 3 , 1 8 4 | - - - - | M ] ( G o o g l e I n c . ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ G o o g l e \ C h r o m e \ A p p l i c a t i o n \ c h r o m e . e x e
M O D - [ 2 0 1 3 / 1 2 / 0 3 2 1 : 4 8 : 0 4 | 0 0 0 , 3 9 9 , 3 1 2 | - - - - | M ] ( ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ G o o g l e \ C h r o m e \ A p p l i c a t i o n \ 3 1 . 0 . 1 6 5 0 . 6 3 \ p p g o o g l e n a c l p l u g i n c h r o m e . d l l
M O D - [ 2 0 1 3 / 1 2 / 0 3 2 1 : 4 8 : 0 3 | 0 1 3 , 5 8 6 , 8 9 6 | - - - - | M ] ( ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ G o o g l e \ C h r o m e \ A p p l i c a t i o n \ 3 1 . 0 . 1 6 5 0 . 6 3 \ P e p p e r F l a s h \ p e p f l a s h p l a y e r . d l l
M O D - [ 2 0 1 3 / 1 2 / 0 3 2 1 : 4 8 : 0 2 | 0 0 4 , 0 5 5 , 5 0 4 | - - - - | M ] ( ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ G o o g l e \ C h r o m e \ A p p l i c a t i o n \ 3 1 . 0 . 1 6 5 0 . 6 3 \ p d f . d l l
M O D - [ 2 0 1 3 / 1 2 / 0 3 2 1 : 4 7 : 1 2 | 0 0 2 , 1 3 4 , 4 8 0 | - - - - | M ] ( G o o g l e I n c . ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ G o o g l e \ C h r o m e \ A p p l i c a t i o n \ 3 1 . 0 . 1 6 5 0 . 6 3 \ l i b p e e r c o n n e c t i o n . d l l
M O D - [ 2 0 1 3 / 1 2 / 0 3 2 1 : 4 7 : 1 1 | 0 0 0 , 7 0 2 , 4 1 6 | - - - - | M ] ( ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ G o o g l e \ C h r o m e \ A p p l i c a t i o n \ 3 1 . 0 . 1 6 5 0 . 6 3 \ l i b g l e s v 2 . d l l
M O D - [ 2 0 1 3 / 1 2 / 0 3 2 1 : 4 7 : 1 1 | 0 0 0 , 0 9 9 , 7 9 2 | - - - - | M ] ( ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ G o o g l e \ C h r o m e \ A p p l i c a t i o n \ 3 1 . 0 . 1 6 5 0 . 6 3 \ l i b e g l . d l l
M O D - [ 2 0 1 3 / 1 2 / 0 3 2 1 : 4 7 : 1 0 | 0 0 9 , 9 6 2 , 9 6 0 | - - - - | M ] ( T h e I C U P r o j e c t ) - - C : \ P r o g r a m F i l e s ( x 8 6 ) \ G o o g l e
O T L E x t r a s l o g f i l e c r e a t e d o n : 1 2 / 2 0 / 2 0 1 3 9 : 3 5 : 5 9 P M - R u n 1
O T L b y O l d T i m e r - V e r s i o n 3 . 2 . 6 9 . 0 F o l d e r = C : \ U s e r s \ 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 \ D o w n l o a d s
6 4 b i t - H o m e P r e m i u m E d i t i o n S e r v i c e P a c k 1 ( V e r s i o n = 6 . 1 . 7 6 0 1 ) - T y p e = N T W o r k s t a t i o n
I n t e r n e t E x p l o r e r ( V e r s i o n = 9 . 1 1 . 9 6 0 0 . 1 6 4 2 8 )
L o c a l e : 0 0 0 0 0 4 0 9 | C o u n t r y : U n i t e d S t a t e s | L a n g u a g e : E N U | D a t e F o r m a t : M / d / y y y y
7 . 9 7 G b T o t a l P h y s i c a l M e m o r y | 4 . 9 5 G b A v a i l a b l e P h y s i c a l M e m o r y | 6 2 . 0 7 % M e m o r y f r e e
1 5 . 9 4 G b P a g i n g F i l e | 1 2 . 5 3 G b A v a i l a b l e i n P a g i n g F i l e | 7 8 . 6 2 % P a g i n g F i l e f r e e
P a g i n g f i l e l o c a t i o n ( s ) : ? : \ p a g e f i l e . s y s [ b i n a r y d a t a ]
% S y s t e m D r i v e % = C : | % S y s t e m R o o t % = C : \ W i n d o w s | % P r o g r a m F i l e s % = C : \ P r o g r a m F i l e s ( x 8 6 )
D r i v e C : | 9 3 1 . 4 1 G b T o t a l S p a c e | 5 1 8 . 9 2 G b F r e e S p a c e | 5 5 . 7 1 % S p a c e F r e e | P a r t i t i o n T y p e : N T F S
C o m p u t e r N a m e : 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 | U s e r N a m e : 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 | L o g g e d i n a s A d m i n i s t r a t o r .
B o o t M o d e : N o r m a l | S c a n M o d e : C u r r e n t u s e r | I n c l u d e 6 4 b i t S c a n s
C o m p a n y N a m e W h i t e l i s t : O f f | S k i p M i c r o s o f t F i l e s : O f f | N o C o m p a n y N a m e W h i t e l i s t : O n | F i l e A g e = 3 0 D a y s
[ c o l o r = # E 5 6 7 1 7 ] = = = = = = = = = = E x t r a R e g i s t r y ( A l l ) = = = = = = = = = = [ / c o l o r ]
[ c o l o r = # E 5 6 7 1 7 ] = = = = = = = = = = F i l e A s s o c i a t i o n s = = = = = = = = = = [ / c o l o r ]
[ b ] 6 4 b i t : [ / b ] [ H K E Y _ L O C A L _ M A C H I N E \ S O F T W A R E \ C l a s s e s \ <