Remove the TrojanDownloader:Win32/Adload.DA virus from your computer
Windows has detected TrojanDownloader:Win32/Adload.DA, a known computer virus, on your computer.
To remove the virus from your computer, follow these instructions:
Go to the following website:
Microsoft Safety Scanner
Click Download Now, and then follow the instructions on the screen.
I downloaded Microsoft Safety Scanner and ran a full system scan and it found nothing infected.
I then ran a full system scan using Microsoft security essentials and found nothing again.
Does this mean that malware is gone?
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
Run by at 22:15:32 on 2012-07-24
Microsoft Windows 7 Professional 6.1.7601.1.1252.64.1033.18.3838.1522 [GMT 12:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\PROGRA~2\PHAROS~1\Core\CTskMstr.exe
C:\Windows\SysWOW64\rpcnet.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Users\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Users\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskhost.exe
C:\Users\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Users\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Users\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.xtra.co.nz/
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
BHO: Face recognition web login for FastAccess: {da5bce70-d057-4d63-943d-5f3927ec59f1} - C:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
uRun: [Google Update] "C:\Users\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
mRun: [FAStartup]
mRun: [FATrayAlert] C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\BHAVIS~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{CB1EB85E-9FB9-4DC1-A2CF-DBF58C6B7084} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{CB1EB85E-9FB9-4DC1-A2CF-DBF58C6B7084}\84F4D454 : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{EB36A299-2DC1-4BDD-B2E7-CC85CC63C3EF} : DhcpNameServer = 192.168.222.251
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Notify: FastAccess - C:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli FAPassSync
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Face recognition web login for FastAccess: {DA5BCE70-D057-4D63-943D-5F3927EC59F1} - C:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
BHO-X64: SSOIEAddonBHO - No File
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
mRun-x64: [FAStartup]
mRun-x64: [FATrayAlert] C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-4 63928]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe [2012-2-7 89600]
R2 FAService;FAService;C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe [2011-4-23 2412728]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
R3 FACAP;facap, FastAccess Video Capture;C:\Windows\system32\DRIVERS\facap.sys --> C:\Windows\system32\DRIVERS\facap.sys [?]
R3 itecir;ITECIR Infrared Receiver;C:\Windows\system32\DRIVERS\itecir.sys --> C:\Windows\system32\DRIVERS\itecir.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;C:\Windows\system32\DRIVERS\OA001Ufd.sys --> C:\Windows\system32\DRIVERS\OA001Ufd.sys [?]
R3 OA001Vid;Creative Camera OA001 Function Driver;C:\Windows\system32\DRIVERS\OA001Vid.sys --> C:\Windows\system32\DRIVERS\OA001Vid.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 NetLogin Helper;NetLogin Helper;C:\Program Files (x86)\NetLogin\NetLoginService.exe [2008-2-18 69632]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-1-31 158856]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\system32\DRIVERS\wdcsam64.sys --> C:\Windows\system32\DRIVERS\wdcsam64.sys [?]
.
=============== Created Last 30 ================
.
2012-07-24 08:17:50 69000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{166AA005-B8E7-425C-9F9B-ACE91F18F0F2}\offreg.dll
2012-07-24 05:43:13 -------- d-----w- C:\Program Files (x86)\ESET
2012-07-24 05:34:56 -------- d-----w- C:\Program Files (x86)\Oracle
2012-07-24 05:34:01 772544 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-07-24 05:28:42 9133488 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{166AA005-B8E7-425C-9F9B-ACE91F18F0F2}\mpengine.dll
2012-07-24 04:54:17 -------- d-----w- C:\Users\AppData\Local\{36775749-DEE1-4C72-843C-C00A9DEB558E}
2012-07-24 04:54:06 -------- d-----w- C:\Users\AppData\Local\{05840721-86A6-4B68-855F-442D055ACAD0}
2012-07-23 05:14:37 9133488 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-23 05:09:21 -------- d-----w- C:\Users\AppData\Local\{C4017BF1-836A-4AB2-B61C-FB3BC090AC3E}
2012-07-23 05:09:09 -------- d-----w- C:\Users\AppData\Local\{FE398526-6AB7-40E3-B952-9EDF7BE6C168}
2012-07-22 12:11:15 -------- d-----w- C:\Users\AppData\Local\{4C62D2F6-219B-461C-A5B3-2CB90ED674BA}
2012-07-22 12:11:04 -------- d-----w- C:\Users\AppData\Local\{C9A59A81-B23D-4BF6-A6BF-EC4EFD280722}
2012-07-22 00:10:52 -------- d-----w- C:\Users\AppData\Local\{B17B6171-603B-4B59-A4F3-F05F5D3B4BCF}
2012-07-22 00:10:41 -------- d-----w- C:\Users\AppData\Local\{A5C2490C-F2BD-4AF2-8065-3D6FEFBE675E}
2012-07-21 11:04:03 -------- d-----w- C:\Users\AppData\Local\{67255771-105D-47FE-9533-907353411B2C}
2012-07-21 11:02:57 -------- d-----w- C:\Users\AppData\Local\{7D8B36FC-DCCB-4C8E-800B-344D8844C66F}
2012-07-20 21:53:55 -------- d-----w- C:\Users\AppData\Local\{4C72620D-5DA7-4BCA-8285-B73CC47076A4}
2012-07-20 21:53:38 -------- d-----w- C:\Users\AppData\Local\{8F8C1638-C216-44CA-8347-BAB9731854DE}
2012-07-20 06:02:20 -------- d-----w- C:\Users\AppData\Local\{1B0D8976-871D-4997-9EE6-6A7ADCE75CD3}
2012-07-20 06:02:08 -------- d-----w- C:\Users\AppData\Local\{939FC512-2F13-4F7A-96CC-CDB7268565C7}
2012-07-19 05:18:48 -------- d-----w- C:\Users\AppData\Local\{4F24AA34-9E7E-4D21-9C81-EBC62B933F6E}
2012-07-19 05:18:36 -------- d-----w- C:\Users\AppData\Local\{874B5AF8-7F31-4785-B1F3-56DEC7CDD948}
2012-07-18 06:58:11 -------- d-----w- C:\Users\AppData\Local\{580EDEB3-101E-4B75-ACEE-738DBF9034B4}
2012-07-18 06:57:55 -------- d-----w- C:\Users\AppData\Local\{6081F24D-8B03-4747-B46E-21BE5B060DFB}
2012-07-17 04:39:16 -------- d-----w- C:\Users\AppData\Local\{6B21085B-652C-44ED-B83B-314D27B482ED}
2012-07-17 04:39:06 -------- d-----w- C:\Users\AppData\Local\{8D8C4C48-9341-4C0A-96E0-2EE6C2CBE23C}
2012-07-16 04:14:24 -------- d-----w- C:\Users\AppData\Local\{E3774062-E74F-4B73-9457-0F3F1CE616DE}
2012-07-16 04:14:13 -------- d-----w- C:\Users\AppData\Local\{C3B81022-CC50-4FBF-B933-D56F6C93805C}
2012-07-15 01:33:59 -------- d-----w- C:\Users\AppData\Local\{C37E7D16-3203-4C06-9107-D8E54DA4818D}
2012-07-15 01:33:48 -------- d-----w- C:\Users\AppData\Local\{E7822E2B-55FF-40F9-B842-91A1ED8A4BC4}
2012-07-13 04:18:59 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2012-07-12 22:21:54 -------- d-----w- C:\Users\AppData\Local\{DADA1FCF-DC67-4909-A135-7B6C763C5178}
2012-07-12 22:21:49 -------- d-----w- C:\Users\AppData\Local\{77A0A129-A3D0-4580-874A-B3C56BAA687D}
2012-07-12 10:19:03 -------- d-----w- C:\Users\AppData\Local\{96E23002-B869-4C02-98FF-19D9ECBF9715}
2012-07-12 10:17:18 -------- d-----w- C:\Users\AppData\Local\{A3D587E2-E531-42A2-8CB3-3BEB41B4CBD8}
2012-07-11 22:23:23 -------- d-----w- C:\Program Files\Pharos
2012-07-11 22:23:21 -------- d-----w- C:\ProgramData\Ricoh
2012-07-11 22:22:36 716800 ----atw- C:\Windows\System32\PSR6D105.DLL
2012-07-11 22:22:35 82432 ----a-w- C:\Windows\SysWow64\msxml4r.dll
2012-07-11 22:22:31 -------- d-----w- C:\Program Files (x86)\PharosSystems
2012-07-11 22:22:22 -------- d-----w- C:\Program Files (x86)\Pharos
2012-07-11 22:16:59 -------- d-----w- C:\Users\AppData\Local\{6A0B981C-E891-4A5F-9B6F-FE2143467B40}
2012-07-11 22:16:57 -------- d-----w- C:\Users\AppData\Local\{8E5D6C35-CCE4-42EB-ACEE-01D3B1FEC96C}
2012-07-11 04:39:27 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-11 02:59:11 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-07-11 00:36:56 -------- d-----w- C:\Users\AppData\Local\{BD811741-F443-45C9-A286-F21600A22E95}
2012-07-11 00:36:53 -------- d-----w- C:\Users\AppData\Local\{97344E5E-3587-40FD-9FDD-EA625FEABB0B}
2012-07-10 12:36:28 -------- d-----w- C:\Users\AppData\Local\{3764493C-8B0B-40BC-A206-7BA5AFAF8927}
2012-07-10 12:36:17 -------- d-----w- C:\Users\AppData\Local\{12CC3B2A-E1D9-49D7-A020-A4AE0EE633D1}
2012-07-10 00:36:01 -------- d-----w- C:\Users\AppData\Local\{59EB9165-D0A3-4D2F-8574-411D4AA869A6}
2012-07-10 00:35:59 -------- d-----w- C:\Users\AppData\Local\{A62A93C2-2739-4D45-A45D-2DC378A2E402}
2012-07-09 12:35:34 -------- d-----w- C:\Users\AppData\Local\{FBEF997E-A3B3-491D-9CEC-49F130DBC883}
2012-07-09 12:35:22 -------- d-----w- C:\Users\AppData\Local\{8B3E65A9-C514-48B8-81CC-76300B2E549E}
2012-07-09 00:35:06 -------- d-----w- C:\Users\AppData\Local\{C1F7D643-D38D-4409-B1A5-BFBFABAD73A9}
2012-07-09 00:35:04 -------- d-----w- C:\Users\AppData\Local\{657BCE57-B951-4534-9288-3C4D00EC89AA}
2012-07-08 12:34:39 -------- d-----w- C:\Users\AppData\Local\{5CC8B1EA-4EAD-4FA7-9C9F-8381195DA7C0}
2012-07-08 12:34:28 -------- d-----w- C:\Users\AppData\Local\{1DD0636B-E7BD-4925-B881-91F72B4A0EDD}
2012-07-08 00:34:16 -------- d-----w- C:\Users\AppData\Local\{F16623B5-58C4-43F8-8D29-43B2583452BD}
2012-07-08 00:34:05 -------- d-----w- C:\Users\AppData\Local\{53E59054-4516-4559-9379-92EBD2DD6B76}
2012-07-07 12:33:40 -------- d-----w- C:\Users\AppData\Local\{3E078BF3-FA87-4822-B17F-C461C3AE92E2}
2012-07-07 12:33:28 -------- d-----w- C:\Users\AppData\Local\{ECC386D1-C805-471E-B8F2-161DA19ACE8B}
2012-07-07 00:33:16 -------- d-----w- C:\Users\AppData\Local\{E2A67537-CA29-4DD2-BBA2-BF22CCF009EE}
2012-07-07 00:33:04 -------- d-----w- C:\Users\AppData\Local\{0A0EC1FD-094C-4D47-BC0D-933EE6F6CD3E}
2012-07-06 10:04:59 -------- d-----w- C:\Users\AppData\Local\{09C7678E-8860-492E-986C-AA84367714CC}
2012-07-06 10:04:48 -------- d-----w- C:\Users\AppData\Local\{45FF6E9A-4593-4CD5-9E31-897ACF54583B}
2012-07-05 22:04:28 -------- d-----w- C:\Users\AppData\Local\{E7485CE8-19F8-449D-B1E5-EC9738D3EB5B}
2012-07-05 22:04:23 -------- d-----w- C:\Users\AppData\Local\{6D7D90AB-E133-4436-9D60-1F99BA3DCAF3}
2012-07-05 00:00:07 -------- d-----w- C:\Users\AppData\Local\{2E67E848-3678-4E2D-80CB-69F4A19ABB14}
2012-07-04 23:58:21 -------- d-----w- C:\Users\AppData\Local\{800B2DE0-87F3-449F-B914-4B38079F960E}
2012-07-04 12:05:03 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{25F43044-C360-4C52-9B95-2A9C62EB5E05}\gapaengine.dll
2012-07-04 11:56:22 -------- d-----w- C:\Users\AppData\Local\{2A314897-D0EF-4E17-9BC1-60F639B19919}
2012-07-04 11:54:38 -------- d-----w- C:\Users\AppData\Local\{494D4BF5-C01D-451D-846E-4B6C01D25591}
2012-07-03 22:43:05 -------- d-----w- C:\Program Files (x86)\NetLogin
2012-07-03 22:06:39 -------- d-----w- C:\Users\AppData\Local\{E4BB8796-8F61-4FB9-9618-B2B898BB57F8}
2012-07-03 22:05:03 -------- d-----w- C:\Users\AppData\Local\{C9170ACA-AE76-4062-927B-7514302469A1}
2012-07-03 08:05:18 -------- d-----w- C:\Users\AppData\Local\{AD540725-8DF3-4CAD-8B8A-8F21A57E38EC}
2012-07-03 08:05:08 -------- d-----w- C:\Users\AppData\Local\{118250A7-6487-418A-853E-FABD13B94DDA}
2012-07-02 22:12:49 -------- d-----w- C:\Users\AppData\Local\{8E35724C-F7FB-4A4E-9A6D-BDB442B10645}
2012-07-02 05:19:10 -------- d-----w- C:\Users\AppData\Local\{88D42262-371E-4780-9E96-2AD8D47F93CF}
2012-07-02 05:18:59 -------- d-----w- C:\Users\AppData\Local\{E176054A-E8E4-4C67-A7F1-E9392C0E9962}
2012-07-01 22:27:36 -------- d-----w- C:\Users\AppData\Local\{714FE6C5-18E1-42C7-91F4-E365E9A5FA71}
2012-07-01 00:52:36 -------- d-----w- C:\Users\AppData\Local\{50CB4371-0FFD-4FC9-A54C-788C57EBBC15}
2012-07-01 00:52:25 -------- d-----w- C:\Users\AppData\Local\{3780A9F1-90AD-4975-B26F-3468FAA02341}
2012-06-30 00:12:58 -------- d-----w- C:\Users\AppData\Local\{A3C8EC9E-6B75-4514-9685-F0B456D5B74D}
2012-06-30 00:12:46 -------- d-----w- C:\Users\AppData\Local\{98B46A0E-2298-4888-8BBC-CA105E665644}
2012-06-29 11:13:56 -------- d-----w- C:\Users\AppData\Local\{51663657-21F9-4F49-890F-D4FFCE07D2BE}
2012-06-29 11:13:41 -------- d-----w- C:\Users\AppData\Local\{207952F7-268F-4441-8496-01B3BCB368E7}
2012-06-28 21:28:16 -------- d-----w- C:\Users\AppData\Local\{899C937C-7A4A-4A64-8907-00B5921DB06E}
2012-06-28 21:28:02 -------- d-----w- C:\Users\AppData\Local\{BE96704D-73E9-4E95-85E6-A535BF10DD6D}
2012-06-27 22:20:31 -------- d-----w- C:\Users\AppData\Local\{8B65E01E-1318-4379-B88B-39A5F52379CD}
2012-06-27 22:19:59 -------- d-----w- C:\Users\AppData\Local\{493F6422-DCC3-4651-B37D-D8FA59331553}
2012-06-27 00:03:32 -------- d-----w- C:\Users\AppData\Local\{5CF43FDF-0129-45A1-BE79-A5634EC19BA2}
2012-06-27 00:03:29 -------- d-----w- C:\Users\AppData\Local\{973BC8E7-B930-4FBD-AE7B-7EC97A629593}
2012-06-26 12:03:04 -------- d-----w- C:\Users\AppData\Local\{AC4B6A6F-061A-47E5-89D7-724A246B9813}
2012-06-26 00:02:39 -------- d-----w- C:\Users\AppData\Local\{1E00DF8F-DF14-478A-8F0C-33D44061B8D5}
2012-06-26 00:02:25 -------- d-----w- C:\Users\AppData\Local\{2A7FB4FD-D512-4F42-85D9-F5AD7C5127BE}
2012-06-25 02:08:13 -------- d-----w- C:\Users\AppData\Local\{5D7E612C-F752-4726-B2F2-5C2C9619288C}
2012-06-25 02:08:03 -------- d-----w- C:\Users\AppData\Local\{509A349E-41C0-4CC0-9DDB-4FBC5F6ECC04}
2012-06-24 14:07:38 -------- d-----w- C:\Users\AppData\Local\{0C8AC597-1BA5-458F-B95A-D512EED247AC}
.
==================== Find3M ====================
.
2012-07-24 05:16:39 17408 ----a-w- C:\Windows\System32\rpcnetp.exe
2012-07-24 05:16:36 58288 ----a-w- C:\Windows\SysWow64\rpcnet.dll
2012-07-05 10:06:20 687544 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-02 12:12:17 2311680 ----a-w- C:\Windows\System32\jscript9.dll
2012-06-02 12:05:28 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-06-02 12:04:50 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-06-02 12:01:40 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-06-02 11:57:08 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-02 08:33:25 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-02 08:25:08 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-02 08:25:03 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-02 08:20:33 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-02 08:16:52 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-06-02 03:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 03:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-05-04 11:06:22 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll
2012-04-28 03:55:21 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-26 05:34:27 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
.
============= FINISH: 22:16:11.78 ===============


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top











