Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all articles
Browse latest Browse all 2798

Reposting logs-!st logs I dont think I ran scan properly

$
0
0
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537
Run by Me at 13:15:36 on 2015-03-08
Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.3986.2145 [GMT -4:00]
.
AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16384_none_622908ad510eb05b\TiWorker.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\dashost.exe
C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Windows Defender\MpCmdRun.exe
C:\Program Files\Windows Defender\MpCmdRun.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16384_none_622908ad510eb05b\TiWorker.exe
C:\Windows\System32\dwm.exe
C:\Windows\system32\taskhostex.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
C:\Windows\system32\msiexec.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Windows Defender\MpCmdRun.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{7C77261A-B209-448F-84D0-BE95872F97CF} : DHCPNameServer = 192.168.1.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 iaStorA;iaStorA;C:\Windows\System32\Drivers\iaStorA.sys [2012-9-28 650808]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-9-27 86528]
R2 HPConnectedRemote;HP Connected Remote Service;C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [2012-10-12 35744]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2012-8-23 29600]
R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [2014-12-11 89864]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-9-7 35232]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2013-6-7 2451456]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-6-7 128896]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-6-7 165760]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\Drivers\IntcDAud.sys [2012-6-19 342528]
R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2013-6-7 690832]
R3 SmbDrvI;SmbDrvI;C:\Windows\System32\Drivers\Smb_driver_Intel.sys [2012-8-24 43832]
R3 WirelessButtonDriver;HP Wireless Button Driver Service;C:\Windows\System32\Drivers\WirelessButtonDriver64.sys [2012-8-31 20800]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 RSP2STOR;Realtek PCIE CardReader Driver - P2;C:\Windows\System32\Drivers\RtsP2Stor.sys [2013-6-7 269968]
S3 SmbDrv;SmbDrv;C:\Windows\System32\Drivers\Smb_driver_AMDASF.sys [2012-8-24 41272]
S3 WSDScan;WSD Scan Support;C:\Windows\System32\Drivers\WSDScan.sys [2013-6-7 23552]
.
=============== Created Last 30 ================
.
2015-03-08 17:13:15 17536 ----a-w- C:\ProgramData\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2015-03-08 05:25:16 35480 ----a-w- C:\Windows\SysWow64\TsWpfWrp.exe
2015-03-08 05:25:16 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe
2015-03-08 05:22:37 6973248 ----a-w- C:\Windows\System32\ntoskrnl.exe
2015-03-08 05:20:01 3248640 ----a-w- C:\Windows\System32\rdpcorets.dll
2015-03-08 05:19:58 235520 ----a-w- C:\Windows\System32\rdpudd.dll
2015-03-08 05:19:31 79872 ----a-w- C:\Windows\System32\packager.dll
2015-03-08 05:19:31 68096 ----a-w- C:\Windows\SysWow64\packager.dll
2015-03-08 05:19:25 1312768 ----a-w- C:\Windows\System32\rpcrt4.dll
2015-03-08 05:19:24 694272 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2015-03-08 05:19:18 1627648 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2015-03-08 05:19:18 1338880 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2015-03-08 05:19:02 2842112 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2015-03-08 05:19:02 2620928 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2015-03-08 05:18:51 238080 ----a-w- C:\Windows\System32\pku2u.dll
2015-03-08 05:18:51 187904 ----a-w- C:\Windows\SysWow64\pku2u.dll
2015-03-08 05:18:35 3842560 ----a-w- C:\Windows\System32\d2d1.dll
2015-03-08 05:18:34 2238976 ----a-w- C:\Windows\System32\d3d10warp.dll
2015-03-08 05:18:33 3288576 ----a-w- C:\Windows\SysWow64\d2d1.dll
2015-03-08 05:18:31 2032640 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2015-03-08 05:17:01 124112 ----a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2015-03-08 05:17:01 102608 ----a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-03-08 05:14:33 411880 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2015-03-08 05:13:24 222720 ----a-w- C:\Windows\System32\scrobj.dll
2015-03-08 05:13:24 143872 ----a-w- C:\Windows\System32\wshom.ocx
2015-03-08 05:13:23 861184 ----a-w- C:\Windows\System32\drivers\http.sys
2015-03-08 05:13:23 194048 ----a-w- C:\Windows\System32\scrrun.dll
2015-03-08 05:13:23 162304 ----a-w- C:\Windows\SysWow64\scrobj.dll
2015-03-08 05:13:23 156160 ----a-w- C:\Windows\SysWow64\scrrun.dll
2015-03-08 05:13:23 146944 ----a-w- C:\Windows\System32\cscript.exe
2015-03-08 05:13:23 115712 ----a-w- C:\Windows\SysWow64\cscript.exe
2015-03-08 05:11:49 142336 ----a-w- C:\Windows\System32\drivers\mrxdav.sys
2015-03-08 05:10:14 4036096 ----a-w- C:\Windows\System32\win32k.sys
2015-03-08 05:10:13 1300992 ----a-w- C:\Windows\System32\gdi32.dll
2015-03-08 05:10:12 1023488 ----a-w- C:\Windows\SysWow64\gdi32.dll
2015-03-07 09:47:38 75888 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{26627039-9E53-490F-9D46-81114B897E87}\offreg.dll
2015-03-07 09:43:19 -------- d-----w- C:\Program Files (x86)\Hp
2015-03-07 09:10:15 -------- d-----w- C:\AdwCleaner
2015-03-07 07:35:25 -------- d-----w- C:\Windows\Microsoft Antimalware
2015-03-07 04:00:08 11910896 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{26627039-9E53-490F-9D46-81114B897E87}\mpengine.dll
2015-03-07 03:57:45 -------- d-----w- C:\MAL
2015-03-06 07:16:58 -------- d-----w- C:\Windows\pss
2015-03-06 00:15:55 -------- d-----w- C:\Users\Me\AppData\Roaming\hpqlog
2015-03-04 13:12:10 -------- d-----w- C:\Users\Me\AppData\Local\Hewlett-Packard
2015-03-04 13:11:42 -------- d-----r- C:\Users\Me\Searches
2015-03-04 13:11:42 -------- d-----r- C:\Users\Me\Contacts
2015-03-04 13:09:59 -------- d-----w- C:\Users\Me\AppData\Local\assembly
2015-03-04 13:09:36 -------- d-----w- C:\Users\Me\AppData\Roaming\Synaptics
2015-03-04 13:09:23 -------- d-----w- C:\Users\Me\AppData\Local\VirtualStore
2015-03-04 13:09:06 -------- d-----w- C:\Users\Me\AppData\Local\Packages
.
==================== Find3M ====================
.
2014-12-18 06:52:38 1043968 ----a-w- C:\Windows\System32\usercpl.dll
2014-12-18 06:52:23 588800 ----a-w- C:\Windows\System32\SHCore.dll
2014-12-18 06:51:31 1282560 ----a-w- C:\Windows\System32\lsasrv.dll
2014-12-18 06:20:27 961536 ----a-w- C:\Windows\SysWow64\usercpl.dll
2014-12-18 06:20:18 452608 ----a-w- C:\Windows\SysWow64\SHCore.dll
2014-12-18 04:47:30 717824 ----a-w- C:\Windows\System32\adtschema.dll
2014-12-18 04:15:36 717824 ----a-w- C:\Windows\SysWow64\adtschema.dll
2014-12-09 23:14:50 569720 ----a-w- C:\Windows\System32\drivers\cng.sys
.
============= FINISH: 13:17:30.25 ===============

Attached Files
File Type: zip ark.zip (1.2 KB)
File Type: zip attach.zip (2.3 KB)

Viewing all articles
Browse latest Browse all 2798

Trending Articles