Open Side Menu Go to the Top
Register
help with Virus/Spyware/Malware(OS:win7 SP:1) help with Virus/Spyware/Malware(OS:win7 SP:1)

12-22-2016 , 07:46 PM
I think I have contracted some Virus/Spyware/Malware, please help me check if my pc is safe and secure. I've noticed my pc become drastically slower since i reformatted a couple months ago. Thanks in advance for any help.

DDS logs:

#1
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 8.0.7601.17514
Run by Gedis at 17:27:35 on 2016-12-22
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4094.1281 [GMT -6:00]
.
AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\Antivirus\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Avira\Antivirus\avguard.exe
C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe
C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater. ServiceHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Gedis\AppData\Local\FluxSoftware\Flux\flu x.exe
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.ex e
C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64. exe
C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
c:\postgreSQL\bin\pg_ctl.exe
c:\postgreSQL\bin\postgres.exe
c:\postgreSQL\bin\postgres.exe
c:\postgreSQL\bin\postgres.exe
c:\postgreSQL\bin\postgres.exe
c:\postgreSQL\bin\postgres.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files (x86)\Avira\Antivirus\avcenter.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [f.lux] "C:\Users\Gedis\AppData\Local\FluxSoftware\Flux\fl ux.exe" /noshow
mRun: [Avira SystrayStartTrigger] "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe "
mRun: [avgnt] "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{3BCC58F8-F8C2-4187-BB03-3E71EB310DD4} : DHCPNameServer = 75.75.75.75 75.75.76.76
SSODL: WebCheck - <orphaned>
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll
x64-Run: [ShadowPlay] "C:\Windows\System32\rundll32.exe" C:\Windows\System32\nvspcap64.dll,ShadowPlayOnSyst emStart
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\Insta ller\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
============= SERVICES / DRIVERS ===============
.
R0 avusbflt;avusbflt;C:\Windows\System32\drivers\avus bflt.sys [2016-10-22 35864]
R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.s ys [2016-10-22 28600]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\Antivirus\sched.exe [2016-10-22 476736]
R2 AntiVirService;Avira Real-Time Protection;C:\Program Files (x86)\Avira\Antivirus\avguard.exe [2016-10-22 476736]
R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgn tflt.sys [2016-10-22 176464]
R2 Avira.ServiceHost;Avira Service Host;C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [2016-11-24 350528]
R2 AviraPhantomVPN;Avira Phantom VPN;C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [2016-12-15 300424]
R2 AviraUpdaterService;Avira Updater Service;C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater. ServiceHost.exe [2016-12-9 25232]
R2 avnetflt;avnetflt;C:\Windows\System32\drivers\avne tflt.sys [2016-10-22 79696]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container;C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-10-22 462784]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe [2016-10-22 459832]
R2 NVIDIA Wireless Controller Service;NVIDIA Wireless Controller Service;C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [2016-10-22 1163712]
R2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4;C:\postgreSQL\bin\pg_ctl.exe [2016-10-22 66048]
R2 TeamViewer;TeamViewer 11;C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2016-10-24 7500048]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\Windows\System32\drivers\nvvad64v.sys [2016-11-28 46016]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-6-10 187392]
S2 AntiVirMailService;Avira Mail Protection;C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [2016-10-22 1089592]
S2 AntiVirWebService;Avira Web Protection;C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [2016-10-22 1490296]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\ v4.0.30319\mscorsvw.exe [2016-7-14 107192]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework6 4\v4.0.30319\mscorsvw.exe [2016-7-14 128696]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-9-20 324224]
S3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\dr ivers\MBAMSwissArmy.sys [2016-11-30 192216]
S3 NvContainerNetworkService;NVIDIA NetworkService Container;C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-10-22 462784]
S3 NvStreamKms;NVIDIA KMS;C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-11-28 27584]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUs bFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
.
=============== Created Last 30 ================
.
2016-12-12 22:31:45 -------- d-----w- C:\Users\Gedis\AppData\Local\Chromium
2016-12-04 20:48:53 -------- d-----w- C:\Users\Gedis\AppData\Local\Equilab
2016-12-04 20:48:26 -------- d-----w- C:\Program Files (x86)\PokerStrategy.com
2016-12-04 20:47:41 -------- d-----w- C:\Users\Gedis\AppData\Local\Downloaded Installations
2016-12-02 20:08:20 -------- d-----w- C:\Users\Gedis\AppData\Local\Adobe
2016-12-01 04:15:05 192216 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2016-12-01 04:14:16 64896 ----a-w- C:\Windows\System32\drivers\mwac.sys
2016-12-01 04:14:16 27008 ----a-w- C:\Windows\System32\drivers\mbam.sys
2016-12-01 04:14:16 140672 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2016-12-01 04:14:16 -------- d-----w- C:\ProgramData\Malwarebytes
2016-12-01 04:14:16 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-11-30 08:25:57 -------- d-----w- C:\Users\Gedis\AppData\Local\Microsoft Games
2016-11-28 21:14:53 91584 ----a-w- C:\Windows\SysWow64\nvaudcap32v.dll
2016-11-28 21:14:53 46016 ----a-w- C:\Windows\System32\drivers\nvvad64v.sys
2016-11-28 21:14:53 101824 ----a-w- C:\Windows\System32\nvaudcap64v.dll
.
==================== Find3M ====================
.
2016-12-15 21:49:06 35864 ----a-w- C:\Windows\System32\drivers\avusbflt.sys
2016-12-15 21:49:06 176464 ----a-w- C:\Windows\System32\drivers\avgntflt.sys
2016-11-17 13:45:32 1854400 ----a-w- C:\Windows\System32\nvspcap64.dll
2016-11-17 13:45:32 1755072 ----a-w- C:\Windows\System32\nvspbridge64.dll
2016-11-17 13:45:32 1452480 ----a-w- C:\Windows\SysWow64\nvspcap.dll
2016-11-17 13:45:32 1317312 ----a-w- C:\Windows\SysWow64\nvspbridge.dll
2016-11-17 13:45:32 120256 ----a-w- C:\Windows\System32\NvRtmpStreamer64.dll
2016-11-16 16:42:27 1951 ----a-w- C:\Windows\NvContainerRecovery.bat
2016-10-22 18:55:02 110144 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2016-10-19 22:48:22 46024 ----a-w- C:\Windows\System32\nvhdap64.dll
2016-10-19 22:48:22 212936 ----a-w- C:\Windows\System32\drivers\nvhda64v.sys
2016-10-19 22:48:22 1595456 ----a-w- C:\Windows\System32\nvhdagenco6420103.dll
2016-10-18 19:52:12 2477624 ----a-w- C:\Windows\System32\nvsvc64.dll
2016-10-18 19:52:11 6386232 ----a-w- C:\Windows\System32\nvcpl.dll
2016-10-18 19:52:10 83512 ----a-w- C:\Windows\System32\nv3dappshextr.dll
2016-10-18 19:52:10 71224 ----a-w- C:\Windows\System32\nvshext.dll
2016-10-18 19:52:10 546752 ----a-w- C:\Windows\System32\nv3dappshext.dll
2016-10-18 19:52:10 392128 ----a-w- C:\Windows\System32\nvmctray.dll
2016-10-18 19:52:10 1762752 ----a-w- C:\Windows\System32\nvsvcr.dll
2016-10-18 19:52:02 7471705 ----a-w- C:\Windows\System32\nvcoproc.bin
2016-10-18 19:31:52 134712 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2016-10-06 13:03:58 35784 ----a-w- C:\Windows\System32\drivers\tap0901.sys
2016-09-27 19:19:44 79696 ----a-w- C:\Windows\System32\drivers\avnetflt.sys
2016-09-27 19:19:44 28600 ----a-w- C:\Windows\System32\drivers\avkmgr.sys
.
============= FINISH: 17:27:42.11 ===============

#2
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 10/22/2016 1:43:58 PM
System Uptime: 12/22/2016 3:37:37 PM (2 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | P7P55D-E LX
Processor: Intel(R) Core(TM) i5 CPU 760 @ 2.80GHz | LGA1156 | 2801/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 931 GiB total, 858.272 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer:
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:
.
Class GUID:
Description: Universal Serial Bus (USB) Controller
Device ID: PCI\VEN_1033&DEV_0194&SUBSYS_84131043&REV_03\4&18A 226F2&0&00E3
Manufacturer:
Name: Universal Serial Bus (USB) Controller
PNP Device ID: PCI\VEN_1033&DEV_0194&SUBSYS_84131043&REV_03\4&18A 226F2&0&00E3
Service:
.
==== System Restore Points ===================
.
RP9: 12/4/2016 2:48:05 PM - Installed PokerStrategy.com Equilab.
.
==== Installed Programs ======================
.
µTorrent
Adobe Acrobat Reader DC
Adobe Refresh Manager
Ansel
Avira Antivirus
Avira Connect
Avira Phantom VPN
Avira Software Updater
Dota 2
Dota 2 Test
f.lux
Flopzilla
Google Chrome
Google Update Helper
Holdem Indicator 2.8.2
Holdem Manager 2
Ignition Casino
Ignition Hand Converter
Java 8 Update 111 (64-bit)
Java Auto Updater
Malwarebytes Anti-Malware version 2.2.1.1043
Microsoft .NET Framework 4.6.2
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
NVIDIA 3D Vision Controller Driver 369.04
NVIDIA 3D Vision Driver 375.57
NVIDIA Backend
NVIDIA Container
NVIDIA Control Panel 375.57
NVIDIA Display Container
NVIDIA Display Container LS
NVIDIA Elevated User Container
NVIDIA GeForce Experience 3.1.2.31
NVIDIA Graphics Driver 375.57
NVIDIA HD Audio Driver 1.3.34.17
NVIDIA Install Application
NVIDIA LocalSystem Container
NVIDIA Message Bus for NvContainer
NVIDIA NetworkService Container
NVIDIA Optimus Update 2.13.0.21
NVIDIA PhysX System Software 9.16.0318
NVIDIA ShadowPlay 2.13.0.21
Nvidia Share
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 2.13.0.21
NVIDIA Update Core
NVIDIA User Container
NVIDIA Virtual Audio 3.40.1
NVIDIA Watchdog Plugin for NvContainer
NVIDIA Wireless Controller Service
NvNodejs
NvTelemetry
PokerStrategy.com Equilab
PostgreSQL 8.4
SHIELD Streaming
SHIELD Wireless Controller Driver
Skype™ 7.29
Steam
TeamViewer 11
VLC media player
Vulkan Run Time Libraries 1.0.26.0
.
==== Event Viewer Messages From Past Week ========
.
12/22/2016 4:43:37 PM, Error: Schannel [36887] - The following fatal alert was received: 40.
12/21/2016 10:36:13 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Avira Updater Service service to connect.
.
==== End Of File ===========================


Malwarebytes log:

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 12/22/2016
Scan Time: 5:33 PM
Logfile:
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.12.22.17
Rootkit Database: v2016.11.20.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Gedis

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 309004
Time Elapsed: 6 min, 58 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

HJT log:

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 5:34:40 PM, on 12/22/2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Gedis\AppData\Local\FluxSoftware\Flux\flu x.exe
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Users\Gedis\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [Avira SystrayStartTrigger] "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe "
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [f.lux] "C:\Users\Gedis\AppData\Local\FluxSoftware\Flux\fl ux.exe" /noshow
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?')
O4 - HKUS\S-1-5-21-643460721-3641889158-1229835903-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun (User '?')
O4 - HKUS\S-1-5-21-643460721-3641889158-1229835903-1005\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'postgres')
O4 - HKUS\S-1-5-21-643460721-3641889158-1229835903-1005\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'postgres')
O4 - HKUS\S-1-5-21-643460721-3641889158-1229835903-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-21-643460721-3641889158-1229835903-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?')
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: Avira Phantom VPN (AviraPhantomVPN) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe
O23 - Service: Avira Updater Service (AviraUpdaterService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater. ServiceHost.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe
O23 - Service: NVIDIA Wireless Controller Service - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
O23 - Service: postgresql-8.4 - PostgreSQL Server 8.4 (postgresql-8.4) - PostgreSQL Global Development Group - c:\postgreSQL\bin\pg_ctl.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8990 bytes
help with Virus/Spyware/Malware(OS:win7 SP:1) Quote
12-22-2016 , 08:23 PM
Perhaps Gabe or someone can help you determine if there's any malware. I'm pretty rusty when it comes to logs.

Having said that, here's some common sense (I hope) in the meantime:

1. Why is Avira disabled? Turn it on, keep it on, keep it updated. Have you run a full scan with it?

2. Why is Internet Explorer at version 8? It doesn't matter if you only use Chrome, if you have IE installed you MUST keep it up to date. Update it.

3. While you're at it, run Windows update and install all critical updates, since if IE is that out of date you're probably not updating Windows either.

4. Download and install the free version of Secunia PSI. Use that to make sure all of your other software is up to date.
help with Virus/Spyware/Malware(OS:win7 SP:1) Quote
12-22-2016 , 09:17 PM
Quote:
Originally Posted by thunderbolts
Perhaps Gabe or someone can help you determine if there's any malware. I'm pretty rusty when it comes to logs.

Having said that, here's some common sense (I hope) in the meantime:

1. Why is Avira disabled? Turn it on, keep it on, keep it updated. Have you run a full scan with it?

2. Why is Internet Explorer at version 8? It doesn't matter if you only use Chrome, if you have IE installed you MUST keep it up to date. Update it.

3. While you're at it, run Windows update and install all critical updates, since if IE is that out of date you're probably not updating Windows either.

4. Download and install the free version of Secunia PSI. Use that to make sure all of your other software is up to date.
Thanks for the input, I disabled it for the logs as instructed in the sticky. As far as keeping software up to date, I will do that after the logs have been examined. I do need to delete IE since i never use it.
help with Virus/Spyware/Malware(OS:win7 SP:1) Quote
12-23-2016 , 12:36 PM
DDS and HijackThis! oh wow, nice to see you back again

logs seem clean

Slow computers can also mean that some software isn't properly working together with other software, you could e.g. try and put another AV and see if that helps. Having 12 chrome windows open and ****ing bloatware Skype isn't affecting speed positively either.
help with Virus/Spyware/Malware(OS:win7 SP:1) Quote
12-25-2016 , 07:13 PM
Quote:
Originally Posted by Gabethebabe
DDS and HijackThis! oh wow, nice to see you back again

logs seem clean

Slow computers can also mean that some software isn't properly working together with other software, you could e.g. try and put another AV and see if that helps. Having 12 chrome windows open and ****ing bloatware Skype isn't affecting speed positively either.
Thanks for the help, is there an AV you could recommend?
help with Virus/Spyware/Malware(OS:win7 SP:1) Quote
01-02-2017 , 03:58 AM
Bitdefender
Panda
Sophos now has a free AV as well, should be good, since it has always been a reputable company.
help with Virus/Spyware/Malware(OS:win7 SP:1) Quote

      
m