Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Cannot Kill ZeroAccess Rootkit


  • Please log in to reply
45 replies to this topic

#1 RJswanee

RJswanee

  • Members
  • 31 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:11:59 AM

Posted 19 February 2013 - 08:02 PM

This problem has been upgraded from the "Am I infected?  What do I do?" forum.  My previous topic can be found here:  http://www.bleepingcomputer.com/forums/t/485904/possible-zeroaccess-rootkit-tried-multiple-antimalware-programs-to-no-avail/
I have run a plethora of antimalware programs with nothing to show for it.  I'm running an HP Windows 8 64-bit laptop (at work, so it can only be accessed from 8am-5pm PST), and I was out for two weeks.  When I got back, it was infected.  I had the computer for literally two hours before I left for my vacation - it was brand new; I pulled it out of the box myself.  It was fine when I left.  It appears the virus I have is especially smart and this computer is especially dumb.  The problems (initially) were pop-ups for insurancecomparison.org, ilivid downloads, and make-your-pc-faster (every five minutes with an open browser, every fifteen minutes or so without an open browser).  I've noticed that as of yesterday to open Google Chrome (default browser), I have to right-click the icon and select "New Window" or it won't open.  Also, I had an issue installing an "important" update via Windows Update yesterday.  I have all of the sensitive information stored on a flash drive and NOT on the computer itself (this is a therapist's office).  I am hesitant to do a full system wipe because the computer did not come with any sort of reboot media (no Windows 8 restore disc/flash drive).

My previous topic has copies of a tdsskiller scan log and aswMBR scan log from this morning (2/19); I ran ESETscanner, but it didn't find anything and didn't generate a report.  I ran MWB thorough scan and EmsisoftEmergencyKit in Safe Mode, but they didn't find anything.  I didn't have any pop-ups the entire time, though.  I will be happy to run any/all of these programs again and more.  Any help would be greatly appreciated!

I have tried tdsskiller, HitmanPro, GMER, EmsisoftEmergencyKit, RogueKiller, adwCleaner, ESETscanner, MWB (I installed Spybot S&D out of the box and switched to MWB when I noticed the virus), and Avast! Antivirus Free since I turned it on.

 


DDS.text here:

 

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 10.0.9200.16482  BrowserJavaVersion: 10.13.2
Run by Beccah at 16:39:14 on 2013-02-19
Microsoft Windows 8  6.2.9200.0.1252.1.1033.18.6036.4197 [GMT -8:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\dwm.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Windows\system32\dashost.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\taskhostex.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16455_none_624a7aa150f57306\TiWorker.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - <orphaned>
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
StartupFolder: C:\Users\Beccah\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{608C317E-227A-4475-9934-1D6F7C9F5AD9} : DHCPNameServer = 40.20.1.201 40.20.1.203 40.20.1.202
TCP: Interfaces\{6CB749C8-BDC2-446F-BFC3-69E97F1A69AE} : DHCPNameServer = 192.168.0.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Windows\SysWOW64\skype4com.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-mPolicies-System: PromptOnSecureDesktop = dword:0
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 iaStorA;iaStorA;C:\Windows\System32\Drivers\iaStorA.sys [2012-7-31 645952]
R1 A2DDA;A2 Direct Disk Access Support Driver;C:\Users\Beccah\Desktop\Run\a2ddax64.sys [2013-2-19 23208]
R1 aswnet;avast! AG Firewall Core Driver;C:\Windows\System32\Drivers\aswnet.sys [2013-2-6 468144]
R1 aswSnx;aswSnx;C:\Windows\System32\Drivers\aswSnx.sys [2013-2-6 984144]
R1 aswSP;aswSP;C:\Windows\System32\Drivers\aswSP.sys [2013-2-6 370288]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\Drivers\aswFsBlk.sys [2013-2-6 25232]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\Drivers\aswMonFlt.sys [2013-2-6 71600]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-2-6 44808]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2012-8-10 29600]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-12-26 2451456]
R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 Intel® ME Service;Intel® ME Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [2012-12-26 128896]
R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2012-12-26 165760]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-12-26 364416]
R3 BtAudioBusSrv;IVT Bluetooth Audio Bus Service;C:\Windows\System32\Drivers\BtAudioBus.sys [2012-6-15 23136]
R3 BthL2caScoIfSrv;Bluetooth Profile Interface Driver Service;C:\Windows\System32\Drivers\BtL2caScoIf.sys [2012-7-19 56904]
R3 BthLEEnum;Bluetooth Low Energy Driver;C:\Windows\System32\Drivers\BthLEEnum.sys [2012-7-25 202752]
R3 btUrbFilterDrv;IVT URB Bluetooth Filter Driver Service;C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [2012-8-8 48736]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\Drivers\IntcDAud.sys [2012-6-19 342528]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\Drivers\netr28x.sys [2012-12-26 1958984]
R3 rtbth;RTBTH Bluetooth Device Driver;C:\Windows\System32\Drivers\rtbth.sys [2012-8-9 695392]
R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2012-12-26 690832]
R3 SmbDrvI;SmbDrvI;C:\Windows\System32\Drivers\Smb_driver_Intel.sys [2012-12-26 43832]
R3 WirelessButtonDriver;HP Wireless Button Driver Service;C:\Windows\System32\Drivers\WirelessButtonDriver64.sys [2012-8-3 20288]
S3 RSP2STOR;Realtek PCIE CardReader Driver - P2;C:\Windows\System32\Drivers\RtsP2Stor.sys [2012-12-26 269968]
S3 SmbDrv;SmbDrv;C:\Windows\System32\Drivers\Smb_driver_AMDASF.sys [2012-12-26 41272]
S3 WSDScan;WSD Scan Support;C:\Windows\System32\Drivers\WSDScan.sys [2012-7-25 23552]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2013-02-19 00:47:38    --------    d-----w-    C:\Program Files\HitmanPro
2013-02-19 00:47:28    --------    d-----w-    C:\ProgramData\HitmanPro
2013-02-18 23:40:39    16114176    ----a-w-    C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-02-18 23:40:38    15541248    ----a-w-    C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-02-18 23:38:44    945152    ----a-w-    C:\Windows\System32\resetengmig.dll
2013-02-18 23:38:44    443392    ----a-w-    C:\Windows\System32\ReAgent.dll
2013-02-18 23:38:44    375808    ----a-w-    C:\Windows\SysWow64\ReAgent.dll
2013-02-18 23:38:44    132096    ----a-w-    C:\Windows\System32\sysreset.exe
2013-02-18 23:38:44    1009664    ----a-w-    C:\Windows\System32\reseteng.dll
2013-02-18 23:38:02    26624    ----a-w-    C:\Windows\System32\ReAgentc.exe
2013-02-18 23:38:02    24064    ----a-w-    C:\Windows\SysWow64\ReAgentc.exe
2013-02-18 23:38:01    405504    ----a-w-    C:\Windows\System32\pcasvc.dll
2013-02-18 23:38:01    31232    ----a-w-    C:\Windows\System32\pcadm.dll
2013-02-18 23:38:01    13312    ----a-w-    C:\Windows\System32\pcalua.exe
2013-02-18 23:38:01    11776    ----a-w-    C:\Windows\System32\pcaevts.dll
2013-02-18 20:31:04    --------    d-----w-    C:\Users\Beccah\AppData\Local\ElevatedDiagnostics
2013-02-12 21:37:20    4055552    ----a-w-    C:\Windows\System32\win32k.sys
2013-02-12 21:37:01    6967016    ----a-w-    C:\Windows\System32\ntoskrnl.exe
2013-02-11 19:13:12    861088    ----a-w-    C:\Windows\SysWow64\npDeployJava1.dll
2013-02-11 19:13:12    782240    ----a-w-    C:\Windows\SysWow64\deployJava1.dll
2013-02-11 19:12:57    95648    ----a-w-    C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-02-06 19:47:41    --------    d-----w-    C:\Program Files (x86)\ESET
2013-02-06 17:09:20    468144    ----a-w-    C:\Windows\System32\drivers\aswnet.sys
2013-02-06 17:06:03    54072    ----a-w-    C:\Windows\System32\drivers\aswRdr2.sys
2013-02-06 17:06:02    984144    ----a-w-    C:\Windows\System32\drivers\aswSnx.sys
2013-02-06 17:06:02    71600    ----a-w-    C:\Windows\System32\drivers\aswMonFlt.sys
2013-02-06 17:05:36    41224    ----a-w-    C:\Windows\avastSS.scr
2013-02-06 17:05:27    --------    d-----w-    C:\Program Files\AVAST Software
2013-02-06 16:24:43    --------    d-----w-    C:\Windows\pss
2013-02-04 23:11:17    --------    d-----w-    C:\Users\Beccah\AppData\Local\CrashDumps
2013-02-04 23:10:52    --------    d-----w-    C:\Windows\SysWow64\C2MP
2013-02-04 22:46:50    --------    d-----w-    C:\Users\Beccah\AppData\Roaming\Malwarebytes
2013-02-04 22:46:40    --------    d-----w-    C:\ProgramData\Malwarebytes
2013-02-04 22:46:38    24176    ----a-w-    C:\Windows\System32\drivers\mbam.sys
2013-02-04 22:46:38    --------    d-----w-    C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-01-31 07:08:34    39904    ----a-w-    C:\Windows\SysWow64\dischandler.exe
2013-01-26 20:04:59    816640    ----a-w-    C:\Windows\System32\kerberos.dll
2013-01-26 20:02:52    11459584    ----a-w-    C:\Windows\System32\glcndFilter.dll
2013-01-26 20:01:33    929792    ----a-w-    C:\Windows\SysWow64\mfnetsrc.dll
2013-01-26 20:01:33    1172992    ----a-w-    C:\Windows\System32\mfnetsrc.dll
2013-01-26 20:01:32    677888    ----a-w-    C:\Windows\System32\mfnetcore.dll
2013-01-26 20:01:32    673280    ----a-w-    C:\Windows\System32\mfmpeg2srcsnk.dll
2013-01-26 20:01:31    568832    ----a-w-    C:\Windows\SysWow64\mfnetcore.dll
2013-01-26 20:01:31    513024    ----a-w-    C:\Windows\SysWow64\mfmpeg2srcsnk.dll
2013-01-26 20:01:30    850944    ----a-w-    C:\Windows\SysWow64\mfasfsrcsnk.dll
2013-01-26 20:01:30    1048064    ----a-w-    C:\Windows\System32\mfasfsrcsnk.dll
2013-01-26 20:00:35    618496    ----a-w-    C:\Windows\System32\drivers\srv2.sys
2013-01-26 20:00:34    109568    ----a-w-    C:\Windows\System32\dskquota.dll
2013-01-26 20:00:32    82944    ----a-w-    C:\Windows\SysWow64\dskquota.dll
2013-01-26 19:57:59    6656    ----a-w-    C:\Windows\SysWow64\KBDKURD.DLL
2013-01-26 19:56:01    2367528    ----a-w-    C:\Windows\System32\WSService.dll
2013-01-26 19:56:00    13640704    ----a-w-    C:\Windows\System32\Windows.UI.Xaml.dll
2013-01-26 19:54:59    866304    ----a-w-    C:\Windows\System32\WinTypes.dll
2013-01-26 19:53:59    51200    ----a-w-    C:\Windows\SysWow64\ndptsp.tsp
2013-01-26 19:01:35    641536    ----a-w-    C:\Windows\System32\WSShared.dll
2013-01-26 19:01:35    523776    ----a-w-    C:\Windows\SysWow64\WSShared.dll
2013-01-26 19:01:35    198656    ----a-w-    C:\Windows\System32\Windows.ApplicationModel.Store.dll
2013-01-26 19:01:35    163840    ----a-w-    C:\Windows\System32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-01-26 19:01:35    143872    ----a-w-    C:\Windows\SysWow64\Windows.ApplicationModel.Store.dll
2013-01-26 19:01:35    124928    ----a-w-    C:\Windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-01-26 18:50:50    446976    ----a-w-    C:\Windows\System32\wwansvc.dll
2013-01-26 18:50:49    68608    ----a-w-    C:\Windows\System32\wwanprotdim.dll
2013-01-26 18:50:47    301568    ----a-w-    C:\Windows\System32\newdev.dll
2013-01-26 18:50:46    76288    ----a-w-    C:\Windows\System32\newdev.exe
2013-01-26 18:50:46    275968    ----a-w-    C:\Windows\SysWow64\newdev.dll
2013-01-26 18:50:45    75264    ----a-w-    C:\Windows\System32\ndadmin.exe
2013-01-26 18:50:45    74240    ----a-w-    C:\Windows\SysWow64\newdev.exe
2013-01-26 18:50:45    73728    ----a-w-    C:\Windows\SysWow64\ndadmin.exe
2013-01-25 17:04:08    4012544    ----a-w-    C:\Windows\System32\ffmpeg.dll
2013-01-25 17:03:30    474624    ----a-w-    C:\Windows\System32\ff_kernelDeint.dll
2013-01-25 17:03:16    127488    ----a-w-    C:\Windows\System32\ff_vfw.dll
2013-01-25 17:03:12    4371456    ----a-w-    C:\Windows\System32\ffdshow.ax
2013-01-25 17:02:42    631296    ----a-w-    C:\Windows\System32\TomsMoComp_ff.dll
2013-01-25 17:02:14    114688    ----a-w-    C:\Windows\System32\ff_wmv9.dll
2013-01-25 17:02:12    222720    ----a-w-    C:\Windows\System32\ff_libdts.dll
2013-01-25 17:02:12    156672    ----a-w-    C:\Windows\System32\ff_libmad.dll
2013-01-25 17:02:12    1532928    ----a-w-    C:\Windows\System32\ff_samplerate.dll
2013-01-25 17:02:12    116224    ----a-w-    C:\Windows\System32\ff_liba52.dll
2013-01-25 17:02:10    183296    ----a-w-    C:\Windows\System32\ff_unrar.dll
2013-01-25 16:48:32    3915776    ----a-w-    C:\Windows\SysWow64\ffmpeg.dll
2013-01-25 16:47:32    112640    ----a-w-    C:\Windows\SysWow64\ff_vfw.dll
2013-01-25 16:47:18    3500544    ----a-w-    C:\Windows\SysWow64\ffdshow.ax
2013-01-25 16:46:18    271360    ----a-w-    C:\Windows\SysWow64\TomsMoComp_ff.dll
2013-01-25 16:46:16    99840    ----a-w-    C:\Windows\SysWow64\ff_wmv9.dll
2013-01-25 16:46:16    157184    ----a-w-    C:\Windows\SysWow64\ff_unrar.dll
2013-01-25 16:46:12    211968    ----a-w-    C:\Windows\SysWow64\ff_libdts.dll
2013-01-25 16:46:12    147456    ----a-w-    C:\Windows\SysWow64\ff_libmad.dll
2013-01-25 16:46:08    1525760    ----a-w-    C:\Windows\SysWow64\ff_samplerate.dll
2013-01-25 16:46:08    114688    ----a-w-    C:\Windows\SysWow64\ff_liba52.dll
2013-01-25 16:02:56    7993776    ----a-w-    C:\Windows\System32\avcodec-lav-54.dll
2013-01-25 16:02:56    511656    ----a-w-    C:\Windows\System32\LAVSplitter.ax
2013-01-25 16:02:56    406000    ----a-w-    C:\Windows\System32\swscale-lav-2.dll
2013-01-25 16:02:56    359592    ----a-w-    C:\Windows\System32\IntelQuickSyncDecoder.dll
2013-01-25 16:02:56    278184    ----a-w-    C:\Windows\System32\LAVAudio.ax
2013-01-25 16:02:56    262848    ----a-w-    C:\Windows\System32\avutil-lav-52.dll
2013-01-25 16:02:56    215720    ----a-w-    C:\Windows\System32\libbluray.dll
2013-01-25 16:02:56    185568    ----a-w-    C:\Windows\System32\avresample-lav-1.dll
2013-01-25 16:02:56    180816    ----a-w-    C:\Windows\System32\avfilter-lav-3.dll
2013-01-25 16:02:56    1514152    ----a-w-    C:\Windows\System32\LAVVideo.ax
2013-01-25 16:02:56    1206616    ----a-w-    C:\Windows\System32\avformat-lav-54.dll
2013-01-25 16:00:40    420008    ----a-w-    C:\Windows\SysWow64\LAVSplitter.ax
2013-01-25 16:00:40    384472    ----a-w-    C:\Windows\SysWow64\swscale-lav-2.dll
2013-01-25 16:00:40    279208    ----a-w-    C:\Windows\SysWow64\IntelQuickSyncDecoder.dll
2013-01-25 16:00:40    247920    ----a-w-    C:\Windows\SysWow64\avutil-lav-52.dll
2013-01-25 16:00:40    243880    ----a-w-    C:\Windows\SysWow64\LAVAudio.ax
2013-01-25 16:00:40    183976    ----a-w-    C:\Windows\SysWow64\libbluray.dll
2013-01-25 16:00:40    165160    ----a-w-    C:\Windows\SysWow64\avresample-lav-1.dll
2013-01-25 16:00:40    1186984    ----a-w-    C:\Windows\SysWow64\LAVVideo.ax
2013-01-25 16:00:38    7833552    ----a-w-    C:\Windows\SysWow64\avcodec-lav-54.dll
2013-01-25 16:00:38    169888    ----a-w-    C:\Windows\SysWow64\avfilter-lav-3.dll
2013-01-25 16:00:38    1257464    ----a-w-    C:\Windows\SysWow64\avformat-lav-54.dll
2013-01-23 19:44:07    --------    d-----w-    C:\Users\Beccah\AppData\Roaming\OpenOffice.org
2013-01-22 17:10:11    --------    d-----w-    C:\usr
.
==================== Find3M  ====================
.
2013-02-06 23:06:14    78176    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-02-06 23:06:14    692576    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe
2013-01-31 03:29:52    2226408    ----a-w-    C:\Windows\System32\drivers\tcpip.sys
2013-01-16 00:35:49    44032    ----a-w-    C:\Windows\SysWow64\UXInit.dll
2013-01-16 00:31:26    53760    ----a-w-    C:\Windows\System32\UXInit.dll
2013-01-04 05:32:36    2706432    ----a-w-    C:\Windows\SysWow64\mshtml.tlb
2013-01-04 04:19:53    2706432    ----a-w-    C:\Windows\System32\mshtml.tlb
2012-12-26 17:25:09    29480    ----a-w-    C:\Windows\SysWow64\msxml3a.dll
2012-12-20 00:37:37    1775616    ----a-w-    C:\Windows\SysWow64\wininet.dll
2012-12-20 00:37:04    2881536    ----a-w-    C:\Windows\SysWow64\jscript9.dll
2012-12-20 00:37:02    61440    ----a-w-    C:\Windows\SysWow64\iesetup.dll
2012-12-20 00:37:02    109056    ----a-w-    C:\Windows\SysWow64\iesysprep.dll
2012-12-20 00:36:50    431616    ----a-w-    C:\Windows\apppatch\AcSpecfc.dll
2012-12-20 00:29:16    2246656    ----a-w-    C:\Windows\System32\wininet.dll
2012-12-20 00:29:11    907776    ----a-w-    C:\Windows\System32\uxtheme.dll
2012-12-20 00:28:29    3966464    ----a-w-    C:\Windows\System32\jscript9.dll
2012-12-20 00:28:26    136704    ----a-w-    C:\Windows\System32\iesysprep.dll
2012-12-20 00:28:04    39936    ----a-w-    C:\Windows\apppatch\apppatch64\acspecfc.dll
2012-12-18 01:56:27    534528    ----a-w-    C:\Windows\SysWow64\uxtheme.dll
2012-12-16 08:28:20    46080    ----a-w-    C:\Windows\System32\atmlib.dll
2012-12-16 08:20:01    35328    ----a-w-    C:\Windows\SysWow64\atmlib.dll
2012-12-16 08:08:33    362496    ----a-w-    C:\Windows\System32\atmfd.dll
2012-12-16 07:57:09    300032    ----a-w-    C:\Windows\SysWow64\atmfd.dll
2012-12-06 04:23:00    170496    ----a-w-    C:\Windows\System32\TimeBrokerServer.dll
2012-12-06 04:22:59    178176    ----a-w-    C:\Windows\System32\SystemEventsBrokerServer.dll
2012-12-04 04:21:42    368640    ----a-w-    C:\Windows\System32\sppwinob.dll
2012-11-29 05:05:57    707584    ----a-w-    C:\Windows\System32\AppXDeploymentExtensions.dll
2012-11-29 05:05:57    1131520    ----a-w-    C:\Windows\System32\AppXDeploymentServer.dll
2012-11-27 07:00:32    194280    ----a-w-    C:\Windows\System32\drivers\sdbus.sys
2012-11-27 07:00:29    124648    ----a-w-    C:\Windows\System32\drivers\dumpsd.sys
2012-11-27 06:59:13    329960    ----a-w-    C:\Windows\System32\drivers\storport.sys
2012-11-27 06:39:46    1122768    ----a-w-    C:\Windows\System32\Taskmgr.exe
2012-11-27 04:49:20    1027152    ----a-w-    C:\Windows\SysWow64\Taskmgr.exe
2012-11-27 04:20:50    1048064    ----a-w-    C:\Windows\SysWow64\mstsc.exe
2012-11-27 04:20:42    179200    ----a-w-    C:\Windows\SysWow64\wpnapps.dll
2012-11-27 04:20:35    891904    ----a-w-    C:\Windows\SysWow64\winmde.dll
2012-11-27 04:20:31    798208    ----a-w-    C:\Windows\SysWow64\WebcamUi.dll
2012-11-27 04:20:29    46592    ----a-w-    C:\Windows\SysWow64\vds_ps.dll
2012-11-27 04:20:28    560128    ----a-w-    C:\Windows\SysWow64\UserLanguagesCpl.dll
2012-11-27 04:20:23    1217536    ----a-w-    C:\Windows\SysWow64\storagewmi.dll
2012-11-27 04:20:15    680960    ----a-w-    C:\Windows\System32\vds.exe
2012-11-27 04:20:07    702464    ----a-w-    C:\Windows\SysWow64\nshwfp.dll
2012-11-27 04:20:07    1123840    ----a-w-    C:\Windows\System32\mstsc.exe
2012-11-27 04:18:59    888832    ----a-w-    C:\Windows\System32\nshwfp.dll
2012-11-27 04:18:39    5974528    ----a-w-    C:\Windows\System32\mstscax.dll
2012-11-27 04:18:13    1071104    ----a-w-    C:\Windows\System32\IKEEXT.DLL
2012-11-27 04:18:06    378880    ----a-w-    C:\Windows\System32\FWPUCLNT.DLL
2012-11-27 04:17:32    718848    ----a-w-    C:\Windows\System32\BFE.DLL
2012-11-27 04:17:31    2302464    ----a-w-    C:\Windows\System32\authui.dll
2012-11-27 03:57:32    18432    ----a-w-    C:\Windows\System32\drivers\BtaMPM.sys
2012-11-27 03:56:29    31104    ----a-w-    C:\Windows\System32\drivers\BthAvrcpTg.sys
2012-11-27 03:55:44    29952    ----a-w-    C:\Windows\System32\drivers\BthhfHid.sys
2012-11-26 04:21:18    71168    ----a-w-    C:\Windows\SysWow64\ncryptsslp.dll
2012-11-26 04:20:09    86016    ----a-w-    C:\Windows\System32\ncryptsslp.dll
.
============= FINISH: 16:40:12.52 ===============
 

Attached Files



BC AdBot (Login to Remove)

 


#2 The Dark Knight

The Dark Knight

    Malware Vigilante


  • Members
  • 651 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:59 AM

Posted 20 February 2013 - 03:42 PM

Hello and welcome to BleepingComputer. I am The Dark Knight and will be assisting you. Please ask questions if anything is unclear. welcome.gif
 
For x32 (x86) bit systems please download the Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
For x64 bit systems please download the Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
To enter System Recovery Options by using the Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
  • Select Command Prompt.
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select Computer, find your flash drive letter and close the notepad.
  • In the command window type e:\frst.exe (for x64 bit version type e:\frst64)  and press Enter.
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to the disclaimer.
  • Press the Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it in your reply.

Edited by The Dark Knight, 20 February 2013 - 03:42 PM.

If you make yourself more than just a man, if you devote yourself to an ideal...you become something else entirely. A legend, Mr. Wayne, a legend!


If I have helped you please consider donating to the Neuroscience Research Institute.


Posted Image
Posted Image


#3 RJswanee

RJswanee
  • Topic Starter

  • Members
  • 31 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:11:59 AM

Posted 20 February 2013 - 04:57 PM

Ugh, I'm an idiot.  OK, got it.  Also, I couldn't get the Advanced Boot Options to come up with F8, so I held down SHIFT and clicked "Restart" from the Power Menu.  It worked!

 



Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-02-2013 01
Ran by SYSTEM at 20-02-2013 14:16:18
Running from E:\
Windows 8   (X64) OS Language: English(US) 
The current controlset is ControlSet001
 
==================== Registry (Whitelisted) ===================
 
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-07-21] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-24] (Synaptics Incorporated)
HKLM-x32\...\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey [1342008 2011-08-26] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4297136 2012-10-30] (AVAST Software)
HKLM\...\Runonce: [MSPCLOCK] rundll32.exe streamci,StreamingDeviceSetup {97ebaacc-95bd-11d0-a3ea-00a0c9223196},{53172480-4791-11D0-A5D6-28DB04C10000},{53172480-4791-11D0-A5D6-28DB04C10000} [x]
HKLM\...\Runonce: [MSPQM] rundll32.exe streamci,StreamingDeviceSetup {DDF4358E-BB2C-11D0-A42F-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196} [x]
HKLM\...\Runonce: [MSKSSRV] rundll32.exe streamci,StreamingDeviceSetup {96E080C7-143C-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196} [x]
HKLM\...\Runonce: [MSTEE.CxTransform] rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},C:\Windows\inf\ksfilter.inf,MSTEE.Interface.Install [x]
HKLM\...\Runonce: [MSTEE.Splitter] rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},C:\Windows\inf\ksfilter.inf,MSTEE.Interface.Install [x]
HKLM\...\Runonce: [WDM_DRMKAUD] rundll32.exe streamci,StreamingDeviceSetup {EEC12DB6-AD9C-4168-8658-B03DAEF417FE},{ABD61E00-9350-47e2-A632-4438B90C6641},{FFBB6E3F-CCFE-4D84-90D9-421418B03A8E},C:\Windows\inf\WDMAUDIO.inf,WDM_DRMKAUD.Interface.Install [x]
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\Beccah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> X:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (No File)
 
==================== Services (Whitelisted) ===================
 
3 AllUserInstallAgent; C:\Windows\System32\AUInstallAgent.dll [122368 2012-07-25] (Microsoft Corporation)
2 AudioEndpointBuilder; C:\Windows\System32\AudioEndpointBuilder.dll [169472 2012-11-05] (Microsoft Corporation)
2 avast! Antivirus; "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [44808 2012-10-30] (AVAST Software)
2 BlueSoleilCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe [1544192 2012-08-02] (IVT Corporation)
2 BrokerInfrastructure; C:\Windows\System32\bisrv.dll [179712 2012-09-19] (Microsoft Corporation)
3 BsHelpCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe [138752 2012-07-10] (IVT Corporation)
2 DeviceAssociationService; C:\Windows\System32\das.dll [342016 2012-07-25] (Microsoft Corporation)
3 DeviceInstall; C:\Windows\System32\umpnpmgr.dll [107008 2012-09-19] (Microsoft Corporation)
3 DsmSvc; C:\Windows\System32\DeviceSetupManager.dll [207872 2012-07-25] (Microsoft Corporation)
3 EFS; C:\Windows\System32\efssvc.dll [37376 2012-07-25] (Microsoft Corporation)
3 fhsvc; C:\Windows\System32\fhsvc.dll [116736 2012-09-19] (Microsoft Corporation)
2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-17] (Intel Corporation)
2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
3 KeyIso; C:\Windows\System32\keyiso.dll [59904 2012-07-25] (Microsoft Corporation)
3 KeyIso; C:\Windows\SysWow64\keyiso.dll [43520 2012-07-25] (Microsoft Corporation)
2 LSM; C:\Windows\System32\lsm.dll [438272 2013-01-09] (Microsoft Corporation)
3 NcaSvc; C:\Windows\System32\ncasvc.dll [161792 2012-07-25] (Microsoft Corporation)
3 NcdAutoSetup; C:\Windows\System32\NcdAutoSetup.dll [73728 2012-07-25] (Microsoft Corporation)
3 Netlogon; C:\Windows\System32\netlogon.dll [743936 2012-07-25] (Microsoft Corporation)
3 Netlogon; C:\Windows\SysWow64\netlogon.dll [634368 2012-07-25] (Microsoft Corporation)
3 netprofm; C:\Windows\System32\netprofmsvc.dll [464384 2013-01-09] (Microsoft Corporation)
3 PrintNotify; C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll [2675712 2012-11-05] (Microsoft Corporation)
3 StorSvc; C:\Windows\SysWow64\storsvc.dll [18432 2012-07-25] (Microsoft Corporation)
3 svsvc; C:\Windows\System32\svsvc.dll [12800 2012-07-25] (Microsoft Corporation)
3 SystemEventsBroker; C:\Windows\System32\SystemEventsBrokerServer.dll [178176 2012-12-05] (Microsoft Corporation)
3 TimeBroker; C:\Windows\System32\TimeBrokerServer.dll [170496 2012-12-05] (Microsoft Corporation)
3 VaultSvc; C:\Windows\System32\vaultsvc.dll [283648 2012-07-25] (Microsoft Corporation)
3 vmicheartbeat; C:\Windows\System32\ICSvc.dll [336384 2012-07-25] (Microsoft Corporation)
3 vmickvpexchange; C:\Windows\System32\ICSvc.dll [336384 2012-07-25] (Microsoft Corporation)
3 vmicrdv; C:\Windows\System32\ICSvc.dll [336384 2012-07-25] (Microsoft Corporation)
3 vmicshutdown; C:\Windows\System32\ICSvc.dll [336384 2012-07-25] (Microsoft Corporation)
3 vmictimesync; C:\Windows\System32\ICSvc.dll [336384 2012-07-25] (Microsoft Corporation)
3 vmicvss; C:\Windows\System32\ICSvc.dll [336384 2012-07-25] (Microsoft Corporation)
2 Wcmsvc; C:\Windows\System32\wcmsvc.dll [263680 2012-07-25] (Microsoft Corporation)
3 WiaRpc; C:\Windows\System32\wiarpc.dll [65536 2012-07-25] (Microsoft Corporation)
3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [15440 2012-07-25] (Microsoft Corporation)
3 WinHttpAutoProxySvc; C:\Windows\SysWow64\winhttp.dll [516608 2012-11-05] (Microsoft Corporation)
2 wlidsvc; C:\Windows\System32\wlidsvc.dll [1964544 2013-01-09] (Microsoft Corporation)
3 WSService; C:\Windows\System32\WSService.dll [2367528 2012-09-20] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) =====================
 
0 3ware; C:\Windows\System32\Drivers\3ware.sys [106736 2012-07-25] (LSI)
0 acpiex; C:\Windows\System32\Drivers\acpiex.sys [77040 2012-07-25] (Microsoft Corporation)
3 acpipagr; C:\Windows\System32\Drivers\acpipagr.sys [10240 2012-07-25] (Microsoft Corporation)
3 acpitime; C:\Windows\System32\Drivers\acpitime.sys [10752 2012-07-25] (Microsoft Corporation)
0 arc; C:\Windows\System32\Drivers\arc.sys [104688 2012-07-25] (PMC-Sierra, Inc.)
0 arcsas; C:\Windows\System32\Drivers\arcsas.sys [108272 2012-07-25] (PMC-Sierra, Inc.)
2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [25232 2012-10-30] (AVAST Software)
2 aswMonFlt; C:\Windows\System32\Drivers\aswMonFlt.sys [71600 2012-10-30] (AVAST Software)
1 aswnet; C:\Windows\System32\Drivers\aswnet.sys [468144 2013-02-06] (AVAST Software)
1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [54072 2012-10-15] (AVAST Software)
1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [984144 2012-10-30] (AVAST Software)
1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [370288 2012-10-30] (AVAST Software)
1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [59728 2012-07-03] (AVAST Software)
1 BasicDisplay; C:\Windows\System32\Drivers\BasicDisplay.sys [48640 2012-07-25] (Microsoft Corporation)
1 BasicRender; C:\Windows\System32\Drivers\BasicRender.sys [29696 2012-07-25] (Microsoft Corporation)
3 BtAudioBusSrv; C:\Windows\System32\Drivers\BtAudioBus.sys [23136 2012-06-15] (IVT Corporation)
4 BthAvrcpTg; C:\Windows\System32\Drivers\BthAvrcpTg.sys [31104 2012-11-26] (Microsoft Corporation)
4 BthHFEnum; C:\Windows\System32\Drivers\BthHFEnum.sys [51200 2012-07-25] (Microsoft Corporation)
4 bthhfhid; C:\Windows\System32\Drivers\bthhfhid.sys [29952 2012-11-26] (Microsoft Corporation)
3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [56904 2012-07-19] (Ralink Corporation)
3 BthLEEnum; C:\Windows\System32\Drivers\BthLEEnum.sys [202752 2012-07-25] (Microsoft Corporation)
3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [48736 2012-08-08] (Ralink Corporation)
0 CLFS; C:\Windows\System32\Drivers\CLFS.sys [361200 2012-07-25] (Microsoft Corporation)
3 condrv; C:\Windows\System32\Drivers\condrv.sys [33792 2012-07-25] (Microsoft Corporation)
1 dam; C:\Windows\System32\Drivers\dam.sys [58088 2012-10-10] (Microsoft Corporation)
0 EhStorClass; C:\Windows\System32\Drivers\EhStorClass.sys [81136 2012-07-25] (Microsoft Corporation)
0 EhStorTcgDrv; C:\Windows\System32\Drivers\EhStorTcgDrv.sys [113904 2012-07-25] (Microsoft Corporation)
3 FxPPM; C:\Windows\System32\Drivers\FxPPM.sys [22528 2012-11-05] (Microsoft Corporation)
3 gencounter; C:\Windows\System32\drivers\vmgencounter.sys [12288 2012-07-25] (Microsoft Corporation)
3 GPIOClx0101; C:\Windows\System32\Drivers\msgpioclx.sys [120040 2012-09-19] (Microsoft Corporation)
3 hidi2c; C:\Windows\System32\Drivers\hidi2c.sys [39936 2012-11-19] (Microsoft Corporation)
3 hyperkbd; C:\Windows\System32\Drivers\hyperkbd.sys [11776 2012-07-25] (Microsoft Corporation)
3 HyperVideo; C:\Windows\System32\Drivers\HyperVideo.sys [24576 2012-07-25] (Microsoft Corporation)
0 iaStorA; C:\Windows\System32\Drivers\iaStorA.sys [645952 2012-07-31] (Intel Corporation)
3 kdnic; C:\Windows\System32\Drivers\kdnic.sys [18432 2012-07-25] (Microsoft Corporation)
0 LSI_SSS; C:\Windows\System32\Drivers\LSI_SSS.sys [81136 2012-07-25] (LSI Corporation)
3 MsBridge; C:\Windows\system32\DRIVERS\bridge.sys [129536 2012-07-25] (Microsoft Corporation)
3 msgpiowin32; C:\Windows\System32\Drivers\msgpiowin32.sys [28904 2013-01-09] (Microsoft Corporation)
3 mshidumdf; C:\Windows\System32\Drivers\mshidumdf.sys [10752 2012-07-25] (Microsoft Corporation)
3 MsLldp; C:\Windows\System32\Drivers\MsLldp.sys [68608 2012-07-25] (Microsoft Corporation)
0 mvumis; C:\Windows\System32\Drivers\mvumis.sys [64240 2012-07-25] (Marvell Semiconductor, Inc.)
3 NdisImPlatform; C:\Windows\System32\Drivers\NdisImPlatform.sys [126464 2012-07-25] (Microsoft Corporation)
3 NDISWANLEGACY; C:\Windows\system32\DRIVERS\ndiswan.sys [174080 2012-07-25] (Microsoft Corporation)
2 Ndu; C:\Windows\System32\Drivers\Ndu.sys [97792 2012-07-25] (Microsoft Corporation)
1 npsvctrig; C:\Windows\System32\Drivers\npsvctrig.sys [23552 2012-07-25] (Microsoft Corporation)
0 pdc; C:\Windows\System32\Drivers\pdc.sys [69864 2012-11-05] (Microsoft Corporation)
3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.)
3 rtbth; C:\Windows\System32\Drivers\rtbth.sys [695392 2012-08-09] (Ralink Technology, Corp.)
3 RTL8168; C:\Windows\system32\DRIVERS\Rt630x64.sys [690832 2012-07-31] (Realtek                                            )
3 sdstor; C:\Windows\System32\Drivers\sdstor.sys [56552 2012-10-10] (Microsoft Corporation)
3 SerCx; C:\Windows\System32\Drivers\SerCx.sys [62976 2012-07-25] (Microsoft Corporation)
3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-24] (Synaptics Incorporated)
3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-24] (Synaptics Incorporated)
0 spaceport; C:\Windows\System32\Drivers\spaceport.sys [283888 2012-07-25] (Microsoft Corporation)
3 SpbCx; C:\Windows\System32\Drivers\SpbCx.sys [59392 2012-07-25] (Microsoft Corporation)
0 storahci; C:\Windows\System32\Drivers\storahci.sys [77552 2012-07-25] (Microsoft Corporation)
3 UASPStor; C:\Windows\System32\Drivers\UASPStor.sys [97008 2012-07-25] (Microsoft Corporation)
3 UCX01000; C:\Windows\System32\Drivers\UCX01000.sys [212200 2012-09-19] (Microsoft Corporation)
3 USBHUB3; C:\Windows\System32\Drivers\USBHUB3.sys [445160 2012-11-05] (Microsoft Corporation)
3 USBXHCI; C:\Windows\System32\Drivers\USBXHCI.sys [337128 2012-09-19] (Microsoft Corporation)
3 VerifierExt; C:\Windows\System32\Drivers\VerifierExt.sys [106224 2012-07-25] (Microsoft Corporation)
3 vpci; C:\Windows\System32\Drivers\vpci.sys [67824 2012-07-25] (Microsoft Corporation)
0 VSTXRAID; C:\Windows\System32\Drivers\VSTXRAID.sys [322800 2012-07-25] (VIA Corporation)
3 WdBoot; C:\Windows\System32\Drivers\WdBoot.sys [34216 2012-07-25] (Microsoft Corporation)
3 WdFilter; C:\Windows\System32\Drivers\WdFilter.sys [258288 2012-07-25] (Microsoft Corporation)
0 WFPLWFS; C:\Windows\System32\Drivers\WFPLWFS.sys [96496 2012-07-25] (Microsoft Corporation)
3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20288 2012-08-03] (Hewlett-Packard Development Company, L.P.)
3 wpcfltr; C:\Windows\System32\Drivers\wpcfltr.sys [45056 2012-07-25] (Microsoft Corporation)
3 WpdUpFltr; C:\Windows\System32\Drivers\WpdUpFltr.sys [19968 2012-07-25] (Microsoft Corporation)
3 WUDFWpdFs; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-25] (Microsoft Corporation)
1 A2DDA; \??\C:\Users\Beccah\Desktop\Run\a2ddax64.sys [x]
 
==================== NetSvcs (Whitelisted) ====================
 
 
==================== One Month Created Files and Folders ========
 
2013-02-20 14:16 - 2013-02-20 14:16 - 00000000 ____D C:\FRST
2013-02-20 14:01 - 2013-02-20 14:01 - 00001739 ____A C:\Users\Beccah\Documents\Farbar Recovery Instructions.txt
2013-02-20 13:59 - 2013-02-20 13:59 - 01464401 ____A (Farbar) C:\Users\Beccah\Downloads\FRST64.exe
2013-02-19 16:38 - 2013-02-19 16:38 - 00688992 ____A (Swearware) C:\Users\Beccah\Downloads\dds.com
2013-02-19 15:18 - 2013-02-19 15:18 - 349184023 ____A C:\Windows\MEMORY.DMP
2013-02-19 15:18 - 2013-02-19 15:18 - 00280408 ____A C:\Windows\Minidump\021913-18890-01.dmp
2013-02-19 15:18 - 2013-02-19 15:18 - 00000000 ____D C:\Windows\Minidump
2013-02-19 15:16 - 2013-02-19 15:16 - 00000947 ____A C:\AdwCleaner[S2].txt
2013-02-19 15:16 - 2013-02-19 15:16 - 00000888 ____A C:\AdwCleaner[R2].txt
2013-02-19 14:22 - 2013-02-19 14:22 - 00000000 ____D C:\Windows\Sun
2013-02-19 13:19 - 2013-02-19 13:20 - 02347384 ____A (ESET) C:\Users\Beccah\Downloads\esetsmartinstaller_enu.exe
2013-02-19 08:18 - 2013-02-19 08:19 - 04732416 ____A (AVAST Software) C:\Users\Beccah\Downloads\aswMBR.exe
2013-02-19 08:14 - 2013-02-19 08:14 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\Beccah\Downloads\tdsskiller.exe
2013-02-18 16:47 - 2013-02-18 16:54 - 00000000 ____D C:\ProgramData\HitmanPro
2013-02-18 16:47 - 2013-02-18 16:47 - 00000000 ____D C:\Program Files\HitmanPro
2013-02-18 16:38 - 2013-02-18 16:39 - 09754024 ____A (SurfRight B.V.) C:\Users\Beccah\Downloads\HitmanPro_x64.exe
2013-02-18 16:35 - 2013-01-15 16:25 - 01437696 ____A (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2013-02-18 16:35 - 2013-01-15 16:23 - 01690624 ____A (Microsoft Corporation) C:\Windows\System32\GdiPlus.dll
2013-02-18 16:32 - 2013-01-09 17:53 - 00028904 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\msgpiowin32.sys
2013-02-18 16:32 - 2013-01-09 17:40 - 01448168 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-02-18 16:32 - 2013-01-09 17:40 - 00303848 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2013-02-18 16:32 - 2013-01-09 17:39 - 00194280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\sdbus.sys
2013-02-18 16:32 - 2013-01-09 17:39 - 00124648 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dumpsd.sys
2013-02-18 16:32 - 2013-01-09 17:29 - 01934056 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
2013-02-18 16:32 - 2013-01-09 17:29 - 00785504 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\Wdf01000.sys
2013-02-18 16:32 - 2013-01-09 17:29 - 00091880 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys
2013-02-18 16:32 - 2013-01-09 15:26 - 17560576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-02-18 16:32 - 2013-01-09 15:26 - 01752064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setupapi.dll
2013-02-18 16:32 - 2013-01-09 15:26 - 01611776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe
2013-02-18 16:32 - 2013-01-09 15:26 - 00890880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2013-02-18 16:32 - 2013-01-09 15:26 - 00436736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL
2013-02-18 16:32 - 2013-01-09 15:26 - 00410624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2013-02-18 16:32 - 2013-01-09 15:26 - 00261120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2013-02-18 16:32 - 2013-01-09 15:26 - 00115712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netprofm.dll
2013-02-18 16:32 - 2013-01-09 15:26 - 00083968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wiaacmgr.exe
2013-02-18 16:32 - 2013-01-09 15:26 - 00067584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2013-02-18 16:32 - 2013-01-09 15:23 - 19791360 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-02-18 16:32 - 2013-01-09 15:23 - 02094592 ____A (Microsoft Corporation) C:\Windows\System32\mmc.exe
2013-02-18 16:32 - 2013-01-09 15:23 - 01964544 ____A (Microsoft Corporation) C:\Windows\System32\wlidsvc.dll
2013-02-18 16:32 - 2013-01-09 15:23 - 01886208 ____A (Microsoft Corporation) C:\Windows\System32\setupapi.dll
2013-02-18 16:32 - 2013-01-09 15:23 - 00728064 ____A (Microsoft Corporation) C:\Windows\System32\samsrv.dll
2013-02-18 16:32 - 2013-01-09 15:23 - 00594944 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.dll
2013-02-18 16:32 - 2013-01-09 15:23 - 00406016 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Media.dll
2013-02-18 16:32 - 2013-01-09 15:23 - 00256000 ____A (Microsoft Corporation) C:\Windows\System32\WSDMon.dll
2013-02-18 16:32 - 2013-01-09 15:23 - 00240640 ____A (Microsoft Corporation) C:\Windows\System32\fsquirt.exe
2013-02-18 16:32 - 2013-01-09 15:23 - 00095232 ____A (Microsoft Corporation) C:\Windows\System32\wiaacmgr.exe
2013-02-18 16:32 - 2013-01-09 15:22 - 01120768 ____A (Microsoft Corporation) C:\Windows\System32\msctf.dll
2013-02-18 16:32 - 2013-01-09 15:22 - 00894464 ____A (Microsoft Corporation) C:\Windows\System32\iphlpsvc.dll
2013-02-18 16:32 - 2013-01-09 15:22 - 00666112 ____A (Microsoft Corporation) C:\Windows\System32\MP4SDECD.DLL
2013-02-18 16:32 - 2013-01-09 15:22 - 00464384 ____A (Microsoft Corporation) C:\Windows\System32\netprofmsvc.dll
2013-02-18 16:32 - 2013-01-09 15:22 - 00438272 ____A (Microsoft Corporation) C:\Windows\System32\lsm.dll
2013-02-18 16:32 - 2013-01-09 15:22 - 00159232 ____A (Microsoft Corporation) C:\Windows\System32\inetpp.dll
2013-02-18 16:32 - 2013-01-09 15:22 - 00151040 ____A (Microsoft Corporation) C:\Windows\System32\netprofm.dll
2013-02-18 16:32 - 2013-01-08 19:59 - 00341504 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\HdAudio.sys
2013-02-18 16:32 - 2013-01-08 19:59 - 00074752 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\BTHUSB.SYS
2013-02-18 16:32 - 2013-01-08 19:58 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bthenum.sys
2013-02-18 16:32 - 2013-01-08 19:57 - 01175040 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bthport.sys
2013-02-18 16:32 - 2013-01-04 16:08 - 00386577 ____A C:\Windows\System32\ApnDatabase.xml
2013-02-18 16:32 - 2012-11-01 21:19 - 00171520 ____A (Microsoft Corporation) C:\Windows\System32\ncbservice.dll
2013-02-18 16:32 - 2012-11-01 21:18 - 00107520 ____A (Microsoft Corporation) C:\Windows\System32\httpprxm.dll
2013-02-18 16:32 - 2012-11-01 21:18 - 00062464 ____A (Microsoft Corporation) C:\Windows\System32\adhsvc.dll
2013-02-18 16:32 - 2012-11-01 21:18 - 00022528 ____A (Microsoft Corporation) C:\Windows\System32\adhapi.dll
2013-02-18 16:32 - 2012-11-01 21:18 - 00017920 ____A (Microsoft Corporation) C:\Windows\System32\httpprxp.dll
2013-02-18 16:32 - 2012-11-01 21:18 - 00015872 ____A (Microsoft Corporation) C:\Windows\System32\keepaliveprovider.dll
2013-02-18 15:38 - 2012-11-02 21:26 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\sysreset.exe
2013-02-18 15:38 - 2012-11-02 21:25 - 01009664 ____A (Microsoft Corporation) C:\Windows\System32\reseteng.dll
2013-02-18 15:38 - 2012-11-02 21:25 - 00945152 ____A (Microsoft Corporation) C:\Windows\System32\resetengmig.dll
2013-02-18 15:38 - 2012-11-02 21:25 - 00443392 ____A (Microsoft Corporation) C:\Windows\System32\ReAgent.dll
2013-02-18 15:38 - 2012-11-02 21:25 - 00375808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2013-02-18 15:38 - 2012-10-23 19:25 - 00026624 ____A (Microsoft Corporation) C:\Windows\System32\ReAgentc.exe
2013-02-18 15:38 - 2012-10-23 19:25 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\pcalua.exe
2013-02-18 15:38 - 2012-10-23 19:24 - 00405504 ____A (Microsoft Corporation) C:\Windows\System32\pcasvc.dll
2013-02-18 15:38 - 2012-10-23 19:24 - 00031232 ____A (Microsoft Corporation) C:\Windows\System32\pcadm.dll
2013-02-18 15:38 - 2012-10-23 19:05 - 00011776 ____A (Microsoft Corporation) C:\Windows\System32\pcaevts.dll
2013-02-18 15:38 - 2012-10-23 18:48 - 00024064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ReAgentc.exe
2013-02-18 12:36 - 2013-02-18 12:36 - 00374784 ____A C:\Users\Beccah\Downloads\5uvyczm3.exe
2013-02-18 12:26 - 2013-02-18 12:26 - 05034457 ____A (Swearware) C:\Users\Beccah\Downloads\ComboFix.exe
2013-02-18 12:20 - 2013-02-18 12:20 - 00001166 ____A C:\AdwCleaner[S1].txt
2013-02-18 12:19 - 2013-02-18 12:19 - 00587671 ____A C:\Users\Beccah\Downloads\adwcleaner0.exe
2013-02-18 12:19 - 2013-02-18 12:19 - 00001252 ____A C:\AdwCleaner[R1].txt
2013-02-18 12:01 - 2013-02-18 12:01 - 00388608 ____A (Trend Micro Inc.) C:\Users\Beccah\Downloads\HijackThis.exe
2013-02-18 11:54 - 2013-02-18 11:54 - 00798208 ____A C:\Users\Beccah\Downloads\RogueKiller.exe
2013-02-18 10:46 - 2013-02-18 10:46 - 00000000 ____D C:\Users\Beccah\Downloads\Set-ups
2013-02-18 10:45 - 2013-02-18 10:57 - 00000000 ____D C:\Users\Beccah\Downloads\Suspicious Crap
2013-02-14 10:24 - 2013-02-14 09:17 - 00010858 ____A C:\Users\Beccah\Documents\Periodic Report Blank.odt
2013-02-14 08:16 - 2013-02-14 08:16 - 00427552 ____A C:\Windows\System32\FNTCACHE.DAT
2013-02-13 14:57 - 2013-02-13 16:31 - 00010996 ____A C:\Users\Beccah\Documents\Update Evaluation Blank.odt
2013-02-13 14:51 - 2013-02-13 16:31 - 00011692 ____A C:\Users\Beccah\Documents\Unemployability Blank.odt
2013-02-13 14:45 - 2013-02-13 16:30 - 00010994 ____A C:\Users\Beccah\Documents\Update Assessment Blank.odt
2013-02-12 13:37 - 2013-01-16 20:04 - 04055552 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-02-12 13:37 - 2013-01-13 19:56 - 06967016 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-02-12 13:35 - 2013-01-30 19:29 - 02226408 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-02-12 13:35 - 2013-01-15 16:35 - 01689600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-02-12 13:35 - 2013-01-15 16:35 - 01137664 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-02-12 13:35 - 2013-01-15 16:35 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-02-12 13:35 - 2013-01-15 16:31 - 01351168 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-02-12 13:35 - 2013-01-15 16:31 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\UXInit.dll
2013-02-12 13:35 - 2013-01-15 16:30 - 02165760 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-02-12 13:35 - 2013-01-04 17:40 - 14326784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-02-12 13:35 - 2013-01-04 17:27 - 19442688 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-02-12 13:35 - 2013-01-03 21:32 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-02-12 13:35 - 2013-01-03 20:19 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-02-12 13:35 - 2012-12-19 16:37 - 13740032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-02-12 13:35 - 2012-12-19 16:37 - 02881536 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-02-12 13:35 - 2012-12-19 16:37 - 01775616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-02-12 13:35 - 2012-12-19 16:37 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-02-12 13:35 - 2012-12-19 16:37 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-02-12 13:35 - 2012-12-19 16:37 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-02-12 13:35 - 2012-12-19 16:37 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-02-12 13:35 - 2012-12-19 16:37 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-02-12 13:35 - 2012-12-19 16:29 - 02246656 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-02-12 13:35 - 2012-12-19 16:29 - 00907776 ____A (Microsoft Corporation) C:\Windows\System32\uxtheme.dll
2013-02-12 13:35 - 2012-12-19 16:29 - 00050688 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-02-12 13:35 - 2012-12-19 16:28 - 15417856 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-02-12 13:35 - 2012-12-19 16:28 - 03966464 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-02-12 13:35 - 2012-12-19 16:28 - 00854528 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-02-12 13:35 - 2012-12-19 16:28 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-02-12 13:35 - 2012-12-19 16:28 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-02-12 13:35 - 2012-12-17 17:56 - 00534528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2013-02-11 11:13 - 2013-02-11 11:13 - 00000000 ____D C:\ProgramData\Sun
2013-02-11 11:13 - 2013-02-11 11:12 - 00861088 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-02-11 11:13 - 2013-02-11 11:12 - 00782240 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-02-11 11:13 - 2013-02-11 11:12 - 00262560 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-02-11 11:12 - 2013-02-11 11:12 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-02-11 11:12 - 2013-02-11 11:12 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-02-11 11:12 - 2013-02-11 11:12 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-02-11 11:12 - 2013-02-11 11:12 - 00000000 ____D C:\Program Files (x86)\Java
2013-02-06 11:47 - 2013-02-06 11:47 - 00000000 ____D C:\Program Files (x86)\ESET
2013-02-06 09:09 - 2013-02-06 09:10 - 00468144 ____A (AVAST Software) C:\Windows\System32\Drivers\aswnet.sys
2013-02-06 09:06 - 2013-02-06 09:06 - 00001922 ____A C:\Users\Public\Desktop\avast!.lnk
2013-02-06 09:06 - 2012-10-30 15:51 - 00984144 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2013-02-06 09:06 - 2012-10-30 15:51 - 00370288 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2013-02-06 09:06 - 2012-10-30 15:51 - 00071600 ____A (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
2013-02-06 09:06 - 2012-10-30 15:51 - 00025232 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys
2013-02-06 09:06 - 2012-10-15 08:59 - 00054072 ____A (AVAST Software) C:\Windows\System32\Drivers\aswRdr2.sys
2013-02-06 09:06 - 2012-07-03 09:21 - 00059728 ____A (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys
2013-02-06 09:05 - 2013-02-06 09:05 - 00000000 ____D C:\Program Files\AVAST Software
2013-02-06 09:05 - 2012-10-30 15:51 - 00041224 ____A (AVAST Software) C:\Windows\avastSS.scr
2013-02-06 09:05 - 2012-10-30 15:50 - 00227648 ____A (AVAST Software) C:\Windows\SysWOW64\aswBoot.exe
2013-02-06 08:25 - 2013-02-18 16:20 - 00000796 ____A C:\Windows\setupact.log
2013-02-06 08:24 - 2013-02-06 08:24 - 00000000 ____D C:\Windows\pss
2013-02-05 17:21 - 2013-02-05 17:21 - 00000000 ____D C:\Users\Beccah\AppData\LocalGoogle
2013-02-04 15:11 - 2013-02-06 11:22 - 00000000 ____D C:\Users\Beccah\AppData\Local\CrashDumps
2013-02-04 15:10 - 2013-02-04 15:11 - 00000000 ____D C:\Windows\SysWOW64\C2MP
2013-02-04 14:46 - 2013-02-04 14:46 - 00001069 ____A C:\Users\Public\Desktop\Mb.lnk
2013-02-04 14:46 - 2013-02-04 14:46 - 00000000 ____D C:\Users\Beccah\AppData\Roaming\Malwarebytes
2013-02-04 14:46 - 2013-02-04 14:46 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-02-04 14:46 - 2013-02-04 14:46 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-02-04 14:46 - 2012-12-14 16:49 - 00024176 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-02-04 14:03 - 2013-02-04 14:03 - 00000000 ____D C:\Users\Beccah\Documents\ProcAlyzer Dumps
2013-01-30 23:08 - 2013-01-30 23:08 - 00039904 ____A C:\Windows\SysWOW64\dischandler.exe
2013-01-28 08:41 - 2013-01-28 08:41 - 00000117 ____A C:\Windows\System32\netcfg-408817609.txt
2013-01-28 08:41 - 2013-01-28 08:41 - 00000117 ____A C:\Windows\System32\netcfg-408815781.txt
2013-01-26 12:05 - 2012-10-10 23:47 - 00793200 ____A (Microsoft Corporation) C:\Windows\System32\mfplat.dll
2013-01-26 12:05 - 2012-10-10 23:35 - 02380944 ____A (Microsoft Corporation) C:\Windows\explorer.exe
2013-01-26 12:05 - 2012-10-10 23:16 - 01403784 ____A (Microsoft Corporation) C:\Windows\System32\winload.efi
2013-01-26 12:05 - 2012-10-10 23:16 - 01267424 ____A (Microsoft Corporation) C:\Windows\System32\winload.exe
2013-01-26 12:05 - 2012-10-10 23:16 - 01217328 ____A (Microsoft Corporation) C:\Windows\System32\winresume.efi
2013-01-26 12:05 - 2012-10-10 23:16 - 01093880 ____A (Microsoft Corporation) C:\Windows\System32\winresume.exe
2013-01-26 12:05 - 2012-10-10 21:56 - 02115952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2013-01-26 12:05 - 2012-10-10 21:46 - 01395712 ____A (Microsoft Corporation) C:\Windows\System32\Windows.UI.Immersive.dll
2013-01-26 12:05 - 2012-10-10 21:46 - 00816128 ____A (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe
2013-01-26 12:05 - 2012-10-10 21:46 - 00373760 ____A (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe
2013-01-26 12:05 - 2012-10-10 21:45 - 03554304 ____A (Microsoft Corporation) C:\Windows\System32\tquery.dll
2013-01-26 12:05 - 2012-10-10 21:45 - 00590848 ____A (Microsoft Corporation) C:\Windows\System32\SHCore.dll
2013-01-26 12:05 - 2012-10-10 21:45 - 00579584 ____A (Microsoft Corporation) C:\Windows\System32\StructuredQuery.dll
2013-01-26 12:05 - 2012-10-10 21:44 - 02116096 ____A (Microsoft Corporation) C:\Windows\System32\mssrch.dll
2013-01-26 12:05 - 2012-10-10 21:44 - 01265152 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2013-01-26 12:05 - 2012-10-10 21:44 - 00904192 ____A (Microsoft Corporation) C:\Windows\System32\MPSSVC.dll
2013-01-26 12:05 - 2012-10-10 21:44 - 00435712 ____A (Microsoft Corporation) C:\Windows\System32\mssph.dll
2013-01-26 12:05 - 2012-10-10 21:43 - 02206208 ____A (Microsoft Corporation) C:\Windows\System32\dwmcore.dll
2013-01-26 12:05 - 2012-10-10 21:07 - 02764288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2013-01-26 12:05 - 2012-10-10 21:07 - 01226752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2013-01-26 12:05 - 2012-10-10 21:07 - 00414720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2013-01-26 12:05 - 2012-10-10 21:06 - 01841152 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2013-01-26 12:05 - 2012-10-10 21:06 - 01610240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2013-01-26 12:05 - 2012-10-10 16:45 - 00478424 ____A C:\Windows\SysWOW64\locale.nls
2013-01-26 12:05 - 2012-10-10 16:44 - 00478424 ____A C:\Windows\System32\locale.nls
2013-01-26 12:04 - 2012-10-10 23:26 - 00336104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\Classpnp.sys
2013-01-26 12:04 - 2012-10-10 23:25 - 00056552 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\sdstor.sys
2013-01-26 12:04 - 2012-10-10 23:23 - 01001192 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2013-01-26 12:04 - 2012-10-10 23:23 - 00441576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2013-01-26 12:04 - 2012-10-10 23:18 - 00172264 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2013-01-26 12:04 - 2012-10-10 23:13 - 00058088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dam.sys
2013-01-26 12:04 - 2012-10-10 23:13 - 00033512 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\battc.sys
2013-01-26 12:04 - 2012-10-10 23:08 - 00562392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2013-01-26 12:04 - 2012-10-10 23:02 - 01636672 ____A (Microsoft Corporation) C:\Windows\System32\WMALFXGFXDSP.dll
2013-01-26 12:04 - 2012-10-10 23:01 - 00503080 ____A (Microsoft Corporation) C:\Windows\System32\ci.dll
2013-01-26 12:04 - 2012-10-10 21:46 - 00517120 ____A (Microsoft Corporation) C:\Windows\System32\winlogon.exe
2013-01-26 12:04 - 2012-10-10 21:46 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe
2013-01-26 12:04 - 2012-10-10 21:46 - 00154112 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Storage.Compression.dll
2013-01-26 12:04 - 2012-10-10 21:46 - 00049664 ____A (Microsoft Corporation) C:\Windows\System32\BdeUISrv.exe
2013-01-26 12:04 - 2012-10-10 21:46 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\wfapigp.dll
2013-01-26 12:04 - 2012-10-10 21:45 - 01045504 ____A (Microsoft Corporation) C:\Windows\System32\usercpl.dll
2013-01-26 12:04 - 2012-10-10 21:45 - 00505344 ____A (Microsoft Corporation) C:\Windows\System32\SpaceControl.dll
2013-01-26 12:04 - 2012-10-10 21:45 - 00370176 ____A (Microsoft Corporation) C:\Windows\System32\SysFxUI.dll
2013-01-26 12:04 - 2012-10-10 21:45 - 00055808 ____A (Microsoft Corporation) C:\Windows\System32\PCPKsp.dll
2013-01-26 12:04 - 2012-10-10 21:44 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2013-01-26 12:04 - 2012-10-10 21:44 - 00745984 ____A (Microsoft Corporation) C:\Windows\System32\mssvp.dll
2013-01-26 12:04 - 2012-10-10 21:44 - 00561152 ____A (Microsoft Corporation) C:\Windows\System32\mfmp4srcsnk.dll
2013-01-26 12:04 - 2012-10-10 21:44 - 00355328 ____A (Microsoft Corporation) C:\Windows\System32\mswsock.dll
2013-01-26 12:04 - 2012-10-10 21:44 - 00264704 ____A (Microsoft Corporation) C:\Windows\System32\ListSvc.dll
2013-01-26 12:04 - 2012-10-10 21:44 - 00259584 ____A (Microsoft Corporation) C:\Windows\System32\input.dll
2013-01-26 12:04 - 2012-10-10 21:44 - 00246272 ____A (Microsoft Corporation) C:\Windows\System32\mssphtb.dll
2013-01-26 12:04 - 2012-10-10 21:44 - 00105984 ____A (Microsoft Corporation) C:\Windows\System32\icfupgd.dll
2013-01-26 12:04 - 2012-10-10 21:44 - 00102400 ____A (Microsoft Corporation) C:\Windows\System32\mssitlb.dll
2013-01-26 12:04 - 2012-10-10 21:44 - 00096256 ____A (Microsoft Corporation) C:\Windows\System32\mssprxy.dll
2013-01-26 12:04 - 2012-10-10 21:44 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\msscntrs.dll
2013-01-26 12:04 - 2012-10-10 21:44 - 00014336 ____A (Microsoft Corporation) C:\Windows\System32\msshooks.dll
2013-01-26 12:04 - 2012-10-10 21:43 - 01836032 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2013-01-26 12:04 - 2012-10-10 21:43 - 01294336 ____A (Microsoft Corporation) C:\Windows\System32\gdi32.dll
2013-01-26 12:04 - 2012-10-10 21:43 - 01280000 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll
2013-01-26 12:04 - 2012-10-10 21:43 - 00757760 ____A (Microsoft Corporation) C:\Windows\System32\FirewallAPI.dll
2013-01-26 12:04 - 2012-10-10 21:43 - 00331776 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcore.dll
2013-01-26 12:04 - 2012-10-10 21:43 - 00244224 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcore6.dll
2013-01-26 12:04 - 2012-10-10 21:43 - 00190976 ____A (Microsoft Corporation) C:\Windows\System32\bdesvc.dll
2013-01-26 12:04 - 2012-10-10 21:43 - 00118784 ____A (Microsoft Corporation) C:\Windows\System32\AppxSip.dll
2013-01-26 12:04 - 2012-10-10 21:43 - 00081920 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcsvc.dll
2013-01-26 12:04 - 2012-10-10 21:43 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcsvc6.dll
2013-01-26 12:04 - 2012-10-10 21:42 - 00612416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2013-01-26 12:04 - 2012-10-10 21:23 - 00034816 ____A (Microsoft Corporation) C:\Windows\System32\microsoft-windows-pdc.dll
2013-01-26 12:04 - 2012-10-10 21:23 - 00007680 ____A (Microsoft Corporation) C:\Windows\System32\kbdhebl3.dll
2013-01-26 12:04 - 2012-10-10 21:19 - 00005632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\drmkaud.sys
2013-01-26 12:04 - 2012-10-10 21:18 - 00111616 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\drmk.sys
2013-01-26 12:04 - 2012-10-10 21:16 - 00286208 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\portcls.sys
2013-01-26 12:04 - 2012-10-10 21:15 - 00074752 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mpsdrv.sys
2013-01-26 12:04 - 2012-10-10 21:08 - 00671232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2013-01-26 12:04 - 2012-10-10 21:08 - 00303104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2013-01-26 12:04 - 2012-10-10 21:08 - 00170496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2013-01-26 12:04 - 2012-10-10 21:07 - 00962560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll
2013-01-26 12:04 - 2012-10-10 21:07 - 00460800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2013-01-26 12:04 - 2012-10-10 21:07 - 00116224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.Compression.dll
2013-01-26 12:04 - 2012-10-10 21:07 - 00047616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PCPKsp.dll
2013-01-26 12:04 - 2012-10-10 21:07 - 00019968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 01420800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00658432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00653824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00550912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00411136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00408064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00289280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00270336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00219648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00186880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00094208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00060416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00051712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00035328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2013-01-26 12:04 - 2012-10-10 21:06 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2013-01-26 12:04 - 2012-10-10 21:05 - 00099840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AppxSip.dll
2013-01-26 12:04 - 2012-10-10 20:42 - 00007168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kbdhebl3.dll
2013-01-26 12:04 - 2012-10-10 19:11 - 01022464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-01-26 12:02 - 2012-11-05 23:52 - 00445160 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\USBHUB3.SYS
2013-01-26 12:02 - 2012-11-05 23:52 - 00277736 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\msiscsi.sys
2013-01-26 12:02 - 2012-11-05 23:36 - 00069864 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\pdc.sys
2013-01-26 12:02 - 2012-11-05 23:33 - 01566432 ____A (Microsoft Corporation) C:\Windows\System32\ole32.dll
2013-01-26 12:02 - 2012-11-05 23:33 - 00522640 ____A (Microsoft Corporation) C:\Windows\System32\AUDIOKSE.dll
2013-01-26 12:02 - 2012-11-05 23:33 - 00490064 ____A (Microsoft Corporation) C:\Windows\System32\AudioEng.dll
2013-01-26 12:02 - 2012-11-05 23:33 - 00447792 ____A (Microsoft Corporation) C:\Windows\System32\AudioSes.dll
2013-01-26 12:02 - 2012-11-05 23:33 - 00253512 ____A (Microsoft Corporation) C:\Windows\System32\audiodg.exe
2013-01-26 12:02 - 2012-11-05 21:00 - 00463768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2013-01-26 12:02 - 2012-11-05 21:00 - 00427568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2013-01-26 12:02 - 2012-11-05 21:00 - 00324344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2013-01-26 12:02 - 2012-11-05 20:48 - 01150160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 08856576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 01619968 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00883712 ____A (Microsoft Corporation) C:\Windows\HelpPane.exe
2013-01-26 12:02 - 2012-11-05 20:20 - 00767488 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00621056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00516608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00386560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00375296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00314880 ____A (Microsoft Corporation) C:\Windows\System32\rdpclip.exe
2013-01-26 12:02 - 2012-11-05 20:20 - 00251904 ____A (Microsoft Corporation) C:\Windows\System32\WUSettingsProvider.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00246784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00202240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00195072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00141824 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00125952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00093696 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WcnApi.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00083968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00077824 ____A (Microsoft Corporation) C:\Windows\System32\taskhost.exe
2013-01-26 12:02 - 2012-11-05 20:20 - 00072192 ____A (Microsoft Corporation) C:\Windows\System32\taskhostex.exe
2013-01-26 12:02 - 2012-11-05 20:20 - 00043008 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00039424 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2013-01-26 12:02 - 2012-11-05 20:20 - 00034304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2013-01-26 12:02 - 2012-11-05 20:20 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wfdprov.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00018432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2013-01-26 12:02 - 2012-11-05 20:20 - 00017408 ____A (Microsoft Corporation) C:\Windows\System32\wuaext.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 10096640 ____A (Microsoft Corporation) C:\Windows\System32\twinui.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 08552448 ____A (Microsoft Corporation) C:\Windows\SysWOW64\glcndFilter.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 01451520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 01386496 ____A (Microsoft Corporation) C:\Windows\System32\wlansvc.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 00710656 ____A (Microsoft Corporation) C:\Windows\System32\winhttp.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 00470016 ____A (Microsoft Corporation) C:\Windows\System32\wlanmsm.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 00466944 ____A (Microsoft Corporation) C:\Windows\System32\wcncsvc.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 00446464 ____A (Microsoft Corporation) C:\Windows\System32\wlansec.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 00318464 ____A (Microsoft Corporation) C:\Windows\System32\ubpm.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 00291328 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.Connectivity.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 00273408 ____A (Microsoft Corporation) C:\Windows\System32\wlanapi.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 00214528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 00126976 ____A (Microsoft Corporation) C:\Windows\System32\WcnApi.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 00126464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFCaptureEngine.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\wfdprov.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 00027136 ____A (Microsoft Corporation) C:\Windows\System32\WcnEapPeerProxy.dll
2013-01-26 12:02 - 2012-11-05 20:19 - 00026624 ____A (Microsoft Corporation) C:\Windows\System32\WcnEapAuthProxy.dll
2013-01-26 12:02 - 2012-11-05 20:18 - 11459584 ____A (Microsoft Corporation) C:\Windows\System32\glcndFilter.dll
2013-01-26 12:02 - 2012-11-05 20:18 - 01526784 ____A (Microsoft Corporation) C:\Windows\System32\mfcore.dll
2013-01-26 12:02 - 2012-11-05 20:18 - 01037312 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2013-01-26 12:02 - 2012-11-05 20:18 - 00976384 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2013-01-26 12:02 - 2012-11-05 20:18 - 00753664 ____A (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2013-01-26 12:02 - 2012-11-05 20:18 - 00703488 ____A (Microsoft Corporation) C:\Windows\System32\drvstore.dll
2013-01-26 12:02 - 2012-11-05 20:18 - 00549376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\drvstore.dll
2013-01-26 12:02 - 2012-11-05 20:18 - 00501760 ____A (Microsoft Corporation) C:\Windows\System32\DevicePairing.dll
2013-01-26 12:02 - 2012-11-05 20:18 - 00449536 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DevicePairing.dll
2013-01-26 12:02 - 2012-11-05 20:18 - 00281088 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll
2013-01-26 12:02 - 2012-11-05 20:18 - 00267264 ____A (Microsoft Corporation) C:\Windows\System32\EncDump.dll
2013-01-26 12:02 - 2012-11-05 20:18 - 00189440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\bthprops.cpl
2013-01-26 12:02 - 2012-11-05 20:18 - 00172032 ____A (Microsoft Corporation) C:\Windows\System32\MFCaptureEngine.dll
2013-01-26 12:02 - 2012-11-05 20:18 - 00102400 ____A (Microsoft Corporation) C:\Windows\System32\fdWCN.dll
2013-01-26 12:02 - 2012-11-05 20:18 - 00084992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fdWCN.dll
2013-01-26 12:02 - 2012-11-05 20:17 - 02146816 ____A (Microsoft Corporation) C:\Windows\System32\actxprxy.dll
2013-01-26 12:02 - 2012-11-05 20:17 - 00785920 ____A (Microsoft Corporation) C:\Windows\System32\audiosrv.dll
2013-01-26 12:02 - 2012-11-05 20:17 - 00212992 ____A (Microsoft Corporation) C:\Windows\System32\bthprops.cpl
2013-01-26 12:02 - 2012-11-05 20:17 - 00169472 ____A (Microsoft Corporation) C:\Windows\System32\AudioEndpointBuilder.dll
2013-01-26 12:02 - 2012-11-05 20:17 - 00110080 ____A (Microsoft Corporation) C:\Windows\System32\dafWCN.dll
2013-01-26 12:02 - 2012-11-05 20:00 - 00099328 ____A (Microsoft Corporation) C:\Windows\System32\wushareduxresources.dll
2013-01-26 12:02 - 2012-11-05 20:00 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\iscsilog.dll
2013-01-26 12:02 - 2012-11-05 19:58 - 00009728 ____A (Microsoft Corporation) C:\Windows\System32\wlanhlp.dll
2013-01-26 12:02 - 2012-11-05 19:56 - 00009728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll
2013-01-26 12:02 - 2012-11-05 19:55 - 00212992 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys
2013-01-26 12:02 - 2012-11-05 19:55 - 00090624 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\amdk8.sys
2013-01-26 12:02 - 2012-11-05 19:55 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\intelppm.sys
2013-01-26 12:02 - 2012-11-05 19:55 - 00088064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\amdppm.sys
2013-01-26 12:02 - 2012-11-05 19:55 - 00087552 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\processr.sys
2013-01-26 12:02 - 2012-11-05 19:55 - 00022528 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fxppm.sys
2013-01-26 12:02 - 2012-11-05 19:54 - 00859136 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys
2013-01-26 12:02 - 2012-11-05 19:53 - 00560640 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\afd.sys
2013-01-26 12:02 - 2012-11-05 19:52 - 00366080 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys
2013-01-26 12:02 - 2012-11-05 19:51 - 00665600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-01-26 12:01 - 2012-10-16 20:32 - 01172992 ____A (Microsoft Corporation) C:\Windows\System32\mfnetsrc.dll
2013-01-26 12:01 - 2012-10-16 20:32 - 01048064 ____A (Microsoft Corporation) C:\Windows\System32\mfasfsrcsnk.dll
2013-01-26 12:01 - 2012-10-16 20:32 - 00677888 ____A (Microsoft Corporation) C:\Windows\System32\mfnetcore.dll
2013-01-26 12:01 - 2012-10-16 20:32 - 00673280 ____A (Microsoft Corporation) C:\Windows\System32\mfmpeg2srcsnk.dll
2013-01-26 12:01 - 2012-10-16 19:57 - 00929792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2013-01-26 12:01 - 2012-10-16 19:57 - 00850944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2013-01-26 12:01 - 2012-10-16 19:57 - 00568832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2013-01-26 12:01 - 2012-10-16 19:57 - 00513024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2013-01-26 12:00 - 2012-10-23 20:54 - 00396008 ____A (Microsoft Corporation) C:\Windows\System32\hal.dll
2013-01-26 12:00 - 2012-10-11 22:13 - 00109568 ____A (Microsoft Corporation) C:\Windows\System32\dskquota.dll
2013-01-26 12:00 - 2012-10-11 21:46 - 00618496 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
2013-01-26 12:00 - 2012-10-11 21:39 - 00082944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dskquota.dll
2013-01-26 11:58 - 2012-11-19 21:24 - 01164800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Display.dll
2013-01-26 11:58 - 2012-11-19 21:24 - 00036352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DevDispItemProvider.dll
2013-01-26 11:58 - 2012-11-19 21:17 - 01184256 ____A (Microsoft Corporation) C:\Windows\System32\Display.dll
2013-01-26 11:58 - 2012-11-19 21:17 - 00049152 ____A (Microsoft Corporation) C:\Windows\System32\DevDispItemProvider.dll
2013-01-26 11:58 - 2012-11-19 20:59 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\KBDKURD.DLL
2013-01-26 11:58 - 2012-11-19 20:56 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2013-01-26 11:58 - 2012-11-19 20:56 - 00027136 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbohci.sys
2013-01-26 11:58 - 2012-11-19 20:54 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidi2c.sys
2013-01-26 11:58 - 2012-09-19 23:55 - 00496872 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbhub.sys
2013-01-26 11:58 - 2012-09-19 23:55 - 00488168 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbport.sys
2013-01-26 11:58 - 2012-09-19 23:55 - 00079080 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbehci.sys
2013-01-26 11:58 - 2012-09-19 23:55 - 00021736 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbd.sys
2013-01-26 11:57 - 2012-12-05 20:23 - 00170496 ____A (Microsoft Corporation) C:\Windows\System32\TimeBrokerServer.dll
2013-01-26 11:57 - 2012-12-05 20:22 - 00178176 ____A (Microsoft Corporation) C:\Windows\System32\SystemEventsBrokerServer.dll
2013-01-26 11:57 - 2012-12-03 20:21 - 00368640 ____A (Microsoft Corporation) C:\Windows\System32\sppwinob.dll
2013-01-26 11:57 - 2012-11-28 21:05 - 01131520 ____A (Microsoft Corporation) C:\Windows\System32\AppXDeploymentServer.dll
2013-01-26 11:57 - 2012-11-28 21:05 - 00707584 ____A (Microsoft Corporation) C:\Windows\System32\AppXDeploymentExtensions.dll
2013-01-26 11:57 - 2012-11-26 22:59 - 00329960 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\storport.sys
2013-01-26 11:57 - 2012-11-26 22:39 - 01122768 ____A (Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
2013-01-26 11:57 - 2012-11-26 22:27 - 00058288 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2013-01-26 11:57 - 2012-11-26 20:49 - 01027152 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Taskmgr.exe
2013-01-26 11:57 - 2012-11-26 20:20 - 01217536 ____A (Microsoft Corporation) C:\Windows\SysWOW64\storagewmi.dll
2013-01-26 11:57 - 2012-11-26 20:20 - 01123840 ____A (Microsoft Corporation) C:\Windows\System32\mstsc.exe
2013-01-26 11:57 - 2012-11-26 20:20 - 01048064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-01-26 11:57 - 2012-11-26 20:20 - 00891904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2013-01-26 11:57 - 2012-11-26 20:20 - 00798208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WebcamUi.dll
2013-01-26 11:57 - 2012-11-26 20:20 - 00702464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-01-26 11:57 - 2012-11-26 20:20 - 00680960 ____A (Microsoft Corporation) C:\Windows\System32\vds.exe
2013-01-26 11:57 - 2012-11-26 20:20 - 00560128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UserLanguagesCpl.dll
2013-01-26 11:57 - 2012-11-26 20:20 - 00179200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2013-01-26 11:57 - 2012-11-26 20:20 - 00046592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vds_ps.dll
2013-01-26 11:57 - 2012-11-26 20:19 - 05088256 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-01-26 11:57 - 2012-11-26 20:19 - 03345920 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2013-01-26 11:57 - 2012-11-26 20:19 - 03245568 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2013-01-26 11:57 - 2012-11-26 20:19 - 02033664 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-01-26 11:57 - 2012-11-26 20:19 - 01536512 ____A (Microsoft Corporation) C:\Windows\System32\storagewmi.dll
2013-01-26 11:57 - 2012-11-26 20:19 - 01145856 ____A (Microsoft Corporation) C:\Windows\System32\winmde.dll
2013-01-26 11:57 - 2012-11-26 20:19 - 01096704 ____A (Microsoft Corporation) C:\Windows\System32\wmpmde.dll
2013-01-26 11:57 - 2012-11-26 20:19 - 00955904 ____A (Microsoft Corporation) C:\Windows\System32\WebcamUi.dll
2013-01-26 11:57 - 2012-11-26 20:19 - 00631808 ____A (Microsoft Corporation) C:\Windows\System32\UserLanguagesCpl.dll
2013-01-26 11:57 - 2012-11-26 20:19 - 00245248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-01-26 11:57 - 2012-11-26 20:19 - 00245248 ____A (Microsoft Corporation) C:\Windows\System32\usbmon.dll
2013-01-26 11:57 - 2012-11-26 20:19 - 00244736 ____A (Microsoft Corporation) C:\Windows\System32\wpnapps.dll
2013-01-26 11:57 - 2012-11-26 20:19 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\storewuauth.dll
2013-01-26 11:57 - 2012-11-26 20:18 - 05974528 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2013-01-26 11:57 - 2012-11-26 20:18 - 01071104 ____A (Microsoft Corporation) C:\Windows\System32\IKEEXT.DLL
2013-01-26 11:57 - 2012-11-26 20:18 - 00888832 ____A (Microsoft Corporation) C:\Windows\System32\nshwfp.dll
2013-01-26 11:57 - 2012-11-26 20:18 - 00378880 ____A (Microsoft Corporation) C:\Windows\System32\FWPUCLNT.DLL
2013-01-26 11:57 - 2012-11-26 20:17 - 02302464 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-01-26 11:57 - 2012-11-26 20:17 - 00718848 ____A (Microsoft Corporation) C:\Windows\System32\BFE.DLL
2013-01-26 11:57 - 2012-11-26 19:57 - 00018432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\BtaMPM.sys
2013-01-26 11:57 - 2012-11-26 19:56 - 00031104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\BthAvrcpTg.sys
2013-01-26 11:57 - 2012-11-26 19:55 - 00029952 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\BthhfHid.sys
2013-01-26 11:57 - 2012-11-19 21:02 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KBDKURD.DLL
2013-01-26 11:57 - 2012-11-01 21:20 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2013-01-26 11:57 - 2012-10-12 00:08 - 00027880 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpvideominiport.sys
2013-01-26 11:57 - 2012-10-11 22:14 - 00036352 ____A (Microsoft Corporation) C:\Windows\System32\rfxvmt.dll
2013-01-26 11:57 - 2012-10-11 21:50 - 00235520 ____A (Microsoft Corporation) C:\Windows\System32\rdpudd.dll
2013-01-26 11:57 - 2012-09-19 22:09 - 00032256 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbuhci.sys
2013-01-26 11:57 - 2012-09-10 21:28 - 00023552 ____A (Microsoft Corporation) C:\Windows\System32\vdsldr.exe
2013-01-26 11:57 - 2012-09-10 21:27 - 00190976 ____A (Microsoft Corporation) C:\Windows\System32\vdsutil.dll
2013-01-26 11:57 - 2012-09-10 21:27 - 00120832 ____A (Microsoft Corporation) C:\Windows\System32\vds_ps.dll
2013-01-26 11:56 - 2012-09-20 01:10 - 02367528 ____A (Microsoft Corporation) C:\Windows\System32\WSService.dll
2013-01-26 11:56 - 2012-09-19 22:33 - 13640704 ____A (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll
2013-01-26 11:55 - 2012-09-20 00:40 - 00389360 ____A (Microsoft Corporation) C:\Windows\System32\MMDevAPI.dll
2013-01-26 11:55 - 2012-09-20 00:28 - 01825208 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2013-01-26 11:55 - 2012-09-19 23:55 - 03265256 ____A (Broadcom Corporation) C:\Windows\System32\Drivers\evbda.sys
2013-01-26 11:55 - 2012-09-19 23:55 - 00533224 ____A (Broadcom Corporation) C:\Windows\System32\Drivers\bxvbda.sys
2013-01-26 11:55 - 2012-09-19 22:47 - 00307192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MMDevAPI.dll
2013-01-26 11:55 - 2012-09-19 22:33 - 14259712 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll
2013-01-26 11:55 - 2012-09-19 22:33 - 03964416 ____A (Microsoft Corporation) C:\Windows\System32\WinSAT.exe
2013-01-26 11:55 - 2012-09-19 22:33 - 02397184 ____A (Microsoft Corporation) C:\Windows\System32\WpcMon.exe
2013-01-26 11:55 - 2012-09-19 22:33 - 01590272 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-01-26 11:55 - 2012-09-19 22:33 - 01513984 ____A (Microsoft Corporation) C:\Windows\System32\vssapi.dll
2013-01-26 11:55 - 2012-09-19 22:33 - 01304064 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Media.Streaming.dll
2013-01-26 11:55 - 2012-09-19 22:33 - 00757248 ____A (Microsoft Corporation) C:\Windows\System32\uDWM.dll
2013-01-26 11:55 - 2012-09-19 22:33 - 00573440 ____A (Microsoft Corporation) C:\Windows\System32\WinSATAPI.dll
2013-01-26 11:55 - 2012-09-19 22:33 - 00543232 ____A (Microsoft Corporation) C:\Windows\System32\wlroamextension.dll
2013-01-26 11:55 - 2012-09-19 22:33 - 00420352 ____A (Microsoft Corporation) C:\Windows\System32\WWAHost.exe
2013-01-26 11:55 - 2012-09-19 22:32 - 01739264 ____A (Microsoft Corporation) C:\Windows\System32\RacEngn.dll
2013-01-26 11:55 - 2012-09-19 22:32 - 01019392 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.dll
2013-01-26 11:55 - 2012-09-19 22:32 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\provcore.dll
2013-01-26 11:55 - 2012-09-19 22:32 - 00416256 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-01-26 11:55 - 2012-09-19 22:32 - 00385024 ____A (Microsoft Corporation) C:\Windows\System32\ncsi.dll
2013-01-26 11:55 - 2012-09-19 22:31 - 00604672 ____A (Microsoft Corporation) C:\Windows\System32\dnsapi.dll
2013-01-26 11:55 - 2012-09-19 22:31 - 00468992 ____A (Microsoft Corporation) C:\Windows\System32\MFMediaEngine.dll
2013-01-26 11:55 - 2012-09-19 22:31 - 00236544 ____A (Microsoft Corporation) C:\Windows\System32\MFPlay.dll
2013-01-26 11:55 - 2012-09-19 22:31 - 00155136 ____A (Microsoft Corporation) C:\Windows\System32\IPHLPAPI.DLL
2013-01-26 11:55 - 2012-09-19 22:30 - 03847168 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll
2013-01-26 11:55 - 2012-09-19 22:30 - 02219008 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll
2013-01-26 11:55 - 2012-09-19 22:30 - 01743872 ____A (Microsoft Corporation) C:\Windows\System32\combase.dll
2013-01-26 11:55 - 2012-09-19 22:30 - 00634880 ____A (Microsoft Corporation) C:\Windows\System32\apphelp.dll
2013-01-26 11:55 - 2012-09-19 22:26 - 01409376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-01-26 11:55 - 2012-09-19 21:55 - 11875328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-01-26 11:55 - 2012-09-19 21:55 - 10791936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2013-01-26 11:55 - 2012-09-19 21:55 - 01319424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-01-26 11:55 - 2012-09-19 21:55 - 00995328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2013-01-26 11:55 - 2012-09-19 21:54 - 01196032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vssapi.dll
2013-01-26 11:55 - 2012-09-19 21:54 - 00709632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MsSpellCheckingFacility.dll
2013-01-26 11:55 - 2012-09-19 21:54 - 00325632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-01-26 11:55 - 2012-09-19 21:53 - 03296256 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-01-26 11:55 - 2012-09-19 21:53 - 02033664 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-01-26 11:55 - 2012-09-19 21:53 - 00675840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2013-01-26 11:55 - 2012-09-19 21:53 - 00119808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IPHLPAPI.DLL
2013-01-26 11:54 - 2012-09-20 01:08 - 00027280 ____A (Microsoft Corporation) C:\Windows\System32\avrt.dll
2013-01-26 11:54 - 2012-09-20 00:31 - 00425192 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\acpi.sys
2013-01-26 11:54 - 2012-09-20 00:04 - 00411880 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2013-01-26 11:54 - 2012-09-20 00:04 - 00100072 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2013-01-26 11:54 - 2012-09-19 23:55 - 00337128 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\USBXHCI.SYS
2013-01-26 11:54 - 2012-09-19 23:55 - 00212200 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\UCX01000.SYS
2013-01-26 11:54 - 2012-09-19 23:55 - 00120040 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\msgpioclx.sys
2013-01-26 11:54 - 2012-09-19 23:03 - 00465128 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fvevol.sys
2013-01-26 11:54 - 2012-09-19 23:03 - 00148712 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tpm.sys
2013-01-26 11:54 - 2012-09-19 22:48 - 00062488 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dumpfve.sys
2013-01-26 11:54 - 2012-09-19 22:33 - 01342464 ____A (Microsoft Corporation) C:\Windows\System32\user32.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00866304 ____A (Microsoft Corporation) C:\Windows\System32\WinTypes.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00699392 ____A (Microsoft Corporation) C:\Windows\System32\twinapi.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00627712 ____A (Microsoft Corporation) C:\Windows\System32\lpksetup.exe
2013-01-26 11:54 - 2012-09-19 22:33 - 00588800 ____A (Microsoft Corporation) C:\Windows\System32\webio.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00545280 ____A (Microsoft Corporation) C:\Windows\System32\taskeng.exe
2013-01-26 11:54 - 2012-09-19 22:33 - 00541184 ____A (Microsoft Corporation) C:\Windows\System32\VAN.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00457216 ____A (Microsoft Corporation) C:\Windows\System32\wpncore.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00410624 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2013-01-26 11:54 - 2012-09-19 22:33 - 00390144 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00344064 ____A (Microsoft Corporation) C:\Windows\System32\wlidcredprov.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00332800 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00249344 ____A (Microsoft Corporation) C:\Windows\System32\wpnprv.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00203776 ____A (Microsoft Corporation) C:\Windows\System32\WSClient.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00194048 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00177152 ____A (Microsoft Corporation) C:\Windows\System32\WSSync.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\fhmanagew.exe
2013-01-26 11:54 - 2012-09-19 22:33 - 00117760 ____A (Microsoft Corporation) C:\Windows\System32\dwm.exe
2013-01-26 11:54 - 2012-09-19 22:33 - 00110592 ____A C:\Windows\System32\OEMLicense.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00107008 ____A (Microsoft Corporation) C:\Windows\System32\umpnpmgr.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00101888 ____A (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
2013-01-26 11:54 - 2012-09-19 22:33 - 00092672 ____A (Microsoft Corporation) C:\Windows\System32\drvinst.exe
2013-01-26 11:54 - 2012-09-19 22:33 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\lpremove.exe
2013-01-26 11:54 - 2012-09-19 22:33 - 00090624 ____A (Microsoft Corporation) C:\Windows\System32\TpmTasks.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\umpo.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00069632 ____A (Microsoft Corporation) C:\Windows\System32\vsstrace.dll
2013-01-26 11:54 - 2012-09-19 22:33 - 00035840 ____A (Microsoft Corporation) C:\Windows\System32\lsass.exe
2013-01-26 11:54 - 2012-09-19 22:33 - 00029696 ____A (Microsoft Corporation) C:\Windows\System32\svchost.exe
2013-01-26 11:54 - 2012-09-19 22:33 - 00025088 ____A (Microsoft Corporation) C:\Windows\System32\sdbinst.exe
2013-01-26 11:54 - 2012-09-19 22:32 - 01400832 ____A (Microsoft Corporation) C:\Windows\System32\propsys.dll
2013-01-26 11:54 - 2012-09-19 22:32 - 00356352 ____A (Microsoft Corporation) C:\Windows\System32\nlasvc.dll
2013-01-26 11:54 - 2012-09-19 22:32 - 00256512 ____A (Microsoft Corporation) C:\Windows\System32\msvproc.dll
2013-01-26 11:54 - 2012-09-19 22:32 - 00228352 ____A (Microsoft Corporation) C:\Windows\System32\ProximityService.dll
2013-01-26 11:54 - 2012-09-19 22:32 - 00189952 ____A (Microsoft Corporation) C:\Windows\System32\perfos.dll
2013-01-26 11:54 - 2012-09-19 22:32 - 00163328 ____A (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2013-01-26 11:54 - 2012-09-19 22:32 - 00121856 ____A (Microsoft Corporation) C:\Windows\System32\rascfg.dll
2013-01-26 11:54 - 2012-09-19 22:32 - 00112128 ____A (Microsoft Corporation) C:\Windows\System32\PackageStateRoaming.dll
2013-01-26 11:54 - 2012-09-19 22:32 - 00093696 ____A (Microsoft Corporation) C:\Windows\System32\psmsrv.dll
2013-01-26 11:54 - 2012-09-19 22:32 - 00076288 ____A (Microsoft Corporation) C:\Windows\System32\RpcEpMap.dll
2013-01-26 11:54 - 2012-09-19 22:32 - 00075264 ____A (Microsoft Corporation) C:\Windows\System32\rasdiag.dll
2013-01-26 11:54 - 2012-09-19 22:32 - 00072192 ____A (Microsoft Corporation) C:\Windows\System32\nlaapi.dll
2013-01-26 11:54 - 2012-09-19 22:32 - 00065536 ____A (Microsoft Corporation) C:\Windows\System32\setbcdlocale.dll
2013-01-26 11:54 - 2012-09-19 22:32 - 00034816 ____A (Microsoft Corporation) C:\Windows\System32\perfdisk.dll
2013-01-26 11:54 - 2012-09-19 22:32 - 00023552 ____A (Microsoft Corporation) C:\Windows\System32\perfnet.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00755200 ____A (Microsoft Corporation) C:\Windows\System32\fveapi.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00617984 ____A (Microsoft Corporation) C:\Windows\System32\mfsrcsnk.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00459776 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00437760 ____A (Microsoft Corporation) C:\Windows\System32\mfh264enc.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00355328 ____A (Microsoft Corporation) C:\Windows\System32\mfsvr.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00315392 ____A (Microsoft Corporation) C:\Windows\System32\fhcfg.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00280576 ____A (Microsoft Corporation) C:\Windows\System32\fhcat.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00240640 ____A (Microsoft Corporation) C:\Windows\System32\fveapibase.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\fhengine.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00210432 ____A (Microsoft Corporation) C:\Windows\System32\dnsrslvr.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\dwmredir.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00137728 ____A (Microsoft Corporation) C:\Windows\System32\fhshl.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00118272 ____A (Microsoft Corporation) C:\Windows\System32\DevPropMgr.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00116736 ____A (Microsoft Corporation) C:\Windows\System32\fhsvc.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00080896 ____A (Microsoft Corporation) C:\Windows\System32\mmcss.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00080896 ____A (Microsoft Corporation) C:\Windows\System32\fhsrchapi.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\fhevents.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00067584 ____A (Microsoft Corporation) C:\Windows\System32\fhsrchph.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00064000 ____A (Microsoft Corporation) C:\Windows\System32\fhlisten.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\fhcleanup.dll
2013-01-26 11:54 - 2012-09-19 22:31 - 00038400 ____A (Microsoft Corporation) C:\Windows\System32\fhtask.dll
2013-01-26 11:54 - 2012-09-19 22:30 - 02066432 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-01-26 11:54 - 2012-09-19 22:30 - 02016256 ____A (Microsoft Corporation) C:\Windows\System32\batmeter.dll
2013-01-26 11:54 - 2012-09-19 22:30 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\appwiz.cpl
2013-01-26 11:54 - 2012-09-19 22:30 - 00190976 ____A (Microsoft Corporation) C:\Windows\System32\aelupsvc.dll
2013-01-26 11:54 - 2012-09-19 22:30 - 00180736 ____A (Microsoft Corporation) C:\Windows\System32\bcdsrv.dll
2013-01-26 11:54 - 2012-09-19 22:30 - 00179712 ____A (Microsoft Corporation) C:\Windows\System32\bisrv.dll
2013-01-26 11:54 - 2012-09-19 22:30 - 00156672 ____A (Microsoft Corporation) C:\Windows\System32\DAFWSD.dll
2013-01-26 11:54 - 2012-09-19 22:30 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-01-26 11:54 - 2012-09-19 22:13 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\microsoft-windows-kernel-power-events.dll
2013-01-26 11:54 - 2012-09-19 22:13 - 00023656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\avrt.dll
2013-01-26 11:54 - 2012-09-19 22:09 - 00022528 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ws2ifsl.sys
2013-01-26 11:54 - 2012-09-19 21:55 - 00465920 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2013-01-26 11:54 - 2012-09-19 21:55 - 00417280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2013-01-26 11:54 - 2012-09-19 21:55 - 00410624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wlroamextension.dll
2013-01-26 11:54 - 2012-09-19 21:55 - 00333824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2013-01-26 11:54 - 2012-09-19 21:55 - 00303616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WinSATAPI.dll
2013-01-26 11:54 - 2012-09-19 21:55 - 00267776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-01-26 11:54 - 2012-09-19 21:55 - 00265216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-01-26 11:54 - 2012-09-19 21:55 - 00263168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wlidcredprov.dll
2013-01-26 11:54 - 2012-09-19 21:55 - 00239616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2013-01-26 11:54 - 2012-09-19 21:55 - 00166912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll
2013-01-26 11:54 - 2012-09-19 21:55 - 00154624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WSSync.dll
2013-01-26 11:54 - 2012-09-19 21:55 - 00083968 ____A C:\Windows\SysWOW64\OEMLicense.dll
2013-01-26 11:54 - 2012-09-19 21:55 - 00080896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe
2013-01-26 11:54 - 2012-09-19 21:55 - 00080384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2013-01-26 11:54 - 2012-09-19 21:55 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
2013-01-26 11:54 - 2012-09-19 21:55 - 00021504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2013-01-26 11:54 - 2012-09-19 21:54 - 01369600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RacEngn.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 01137152 ____A (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00533504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\provcore.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00509952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00480768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\VAN.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00449024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00413184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfh264enc.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00270336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00214528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvproc.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFPlay.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00108544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rascfg.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00089088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PackageStateRoaming.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00059392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rasdiag.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00055296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00052224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vsstrace.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00031232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\perfdisk.dll
2013-01-26 11:54 - 2012-09-19 21:54 - 00021504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\perfnet.dll
2013-01-26 11:54 - 2012-09-19 21:53 - 02007040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\batmeter.dll
2013-01-26 11:54 - 2012-09-19 21:53 - 01701376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-01-26 11:54 - 2012-09-19 21:53 - 01247232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2013-01-26 11:54 - 2012-09-19 21:53 - 00670208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\appwiz.cpl
2013-01-26 11:54 - 2012-09-19 21:53 - 00461824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2013-01-26 11:54 - 2012-09-19 21:53 - 00366080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-01-26 11:54 - 2012-09-19 21:53 - 00025088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-01-26 11:53 - 2012-09-19 22:33 - 00060928 ____A (Microsoft Corporation) C:\Windows\System32\ndptsp.tsp
2013-01-26 11:53 - 2012-09-19 22:33 - 00047104 ____A (Microsoft Corporation) C:\Windows\System32\kmddsp.tsp
2013-01-26 11:53 - 2012-09-19 22:32 - 00044544 ____A (Microsoft Corporation) C:\Windows\System32\perfctrs.dll
2013-01-26 11:53 - 2012-09-19 22:32 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\rasmxs.dll
2013-01-26 11:53 - 2012-09-19 22:32 - 00037888 ____A (Microsoft Corporation) C:\Windows\System32\perfproc.dll
2013-01-26 11:53 - 2012-09-19 22:32 - 00029696 ____A (Microsoft Corporation) C:\Windows\System32\rasser.dll
2013-01-26 11:53 - 2012-09-19 22:32 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2013-01-26 11:53 - 2012-09-19 22:32 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\MUILanguageCleanup.dll
2013-01-26 11:53 - 2012-09-19 22:32 - 00009728 ____A (Microsoft Corporation) C:\Windows\System32\spwmp.dll
2013-01-26 11:53 - 2012-09-19 22:32 - 00006656 ____A (Microsoft Corporation) C:\Windows\System32\shimeng.dll
2013-01-26 11:53 - 2012-09-19 22:32 - 00006144 ____A (Microsoft Corporation) C:\Windows\System32\msdxm.ocx
2013-01-26 11:53 - 2012-09-19 22:32 - 00006144 ____A (Microsoft Corporation) C:\Windows\System32\dxmasf.dll
2013-01-26 11:53 - 2012-09-19 22:31 - 00064000 ____A (Microsoft Corporation) C:\Windows\System32\fhautoplay.dll
2013-01-26 11:53 - 2012-09-19 22:31 - 00037888 ____A (Microsoft Corporation) C:\Windows\System32\LangCleanupSysprepAction.dll
2013-01-26 11:53 - 2012-09-19 22:31 - 00020480 ____A (Microsoft Corporation) C:\Windows\System32\fhsvcctl.dll
2013-01-26 11:53 - 2012-09-19 22:31 - 00017408 ____A (Microsoft Corporation) C:\Windows\System32\eventcls.dll
2013-01-26 11:53 - 2012-09-19 22:31 - 00008704 ____A (Microsoft Corporation) C:\Windows\System32\lpksetupproxyserv.dll
2013-01-26 11:53 - 2012-09-19 22:12 - 09374208 ____A (Microsoft Corporation) C:\Windows\System32\wmploc.DLL
2013-01-26 11:53 - 2012-09-19 22:09 - 00025088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndistapi.sys
2013-01-26 11:53 - 2012-09-19 22:08 - 00071168 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hdaudbus.sys
2013-01-26 11:53 - 2012-09-19 22:08 - 00060416 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndproxy.sys
2013-01-26 11:53 - 2012-09-19 22:07 - 00210304 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbvideo.sys
2013-01-26 11:53 - 2012-09-19 22:05 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\wanarp.sys
2013-01-26 11:53 - 2012-09-19 21:55 - 00051200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ndptsp.tsp
2013-01-26 11:53 - 2012-09-19 21:55 - 00038912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kmddsp.tsp
2013-01-26 11:53 - 2012-09-19 21:54 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\perfctrs.dll
2013-01-26 11:53 - 2012-09-19 21:54 - 00034816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\perfproc.dll
2013-01-26 11:53 - 2012-09-19 21:54 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\perfos.dll
2013-01-26 11:53 - 2012-09-19 21:54 - 00032768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rasmxs.dll
2013-01-26 11:53 - 2012-09-19 21:54 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rasser.dll
2013-01-26 11:53 - 2012-09-19 21:54 - 00009216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2013-01-26 11:53 - 2012-09-19 21:54 - 00005632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2013-01-26 11:53 - 2012-09-19 21:54 - 00004608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2013-01-26 11:53 - 2012-09-19 21:54 - 00004608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2013-01-26 11:53 - 2012-09-19 21:53 - 00015360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\eventcls.dll
2013-01-26 11:53 - 2012-09-19 21:32 - 09374208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-01-26 11:53 - 2012-09-19 20:13 - 00098816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-01-26 11:53 - 2012-09-19 20:10 - 01126912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2013-01-26 11:01 - 2012-11-07 20:25 - 00523776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2013-01-26 11:01 - 2012-11-07 20:25 - 00143872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2013-01-26 11:01 - 2012-11-07 20:25 - 00124928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-01-26 11:01 - 2012-11-07 20:22 - 00641536 ____A (Microsoft Corporation) C:\Windows\System32\WSShared.dll
2013-01-26 11:01 - 2012-11-07 20:22 - 00198656 ____A (Microsoft Corporation) C:\Windows\System32\Windows.ApplicationModel.Store.dll
2013-01-26 11:01 - 2012-11-07 20:22 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-01-26 10:50 - 2012-10-01 23:34 - 00446976 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2013-01-26 10:50 - 2012-10-01 23:34 - 00068608 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
2013-01-26 10:50 - 2012-09-26 23:17 - 00076288 ____A (Microsoft Corporation) C:\Windows\System32\newdev.exe
2013-01-26 10:50 - 2012-09-26 23:17 - 00075264 ____A (Microsoft Corporation) C:\Windows\System32\ndadmin.exe
2013-01-26 10:50 - 2012-09-26 23:15 - 00301568 ____A (Microsoft Corporation) C:\Windows\System32\newdev.dll
2013-01-26 10:50 - 2012-09-26 22:35 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\newdev.exe
2013-01-26 10:50 - 2012-09-26 22:35 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ndadmin.exe
2013-01-26 10:50 - 2012-09-26 22:34 - 00275968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\newdev.dll
2013-01-26 10:18 - 2013-01-26 10:18 - 00000117 ____A C:\Windows\System32\netcfg-241856015.txt
2013-01-26 10:18 - 2013-01-26 10:18 - 00000117 ____A C:\Windows\System32\netcfg-241855750.txt
2013-01-25 09:04 - 2013-01-25 09:04 - 04012544 ____A C:\Windows\System32\ffmpeg.dll
2013-01-25 09:03 - 2013-01-25 09:03 - 04371456 ____A C:\Windows\System32\ffdshow.ax
2013-01-25 09:03 - 2013-01-25 09:03 - 00474624 ____A C:\Windows\System32\ff_kernelDeint.dll
2013-01-25 09:03 - 2013-01-25 09:03 - 00127488 ____A C:\Windows\System32\ff_vfw.dll
2013-01-25 09:02 - 2013-01-25 09:02 - 01532928 ____A C:\Windows\System32\ff_samplerate.dll
2013-01-25 09:02 - 2013-01-25 09:02 - 00631296 ____A C:\Windows\System32\TomsMoComp_ff.dll
2013-01-25 09:02 - 2013-01-25 09:02 - 00222720 ____A C:\Windows\System32\ff_libdts.dll
2013-01-25 09:02 - 2013-01-25 09:02 - 00183296 ____A C:\Windows\System32\ff_unrar.dll
2013-01-25 09:02 - 2013-01-25 09:02 - 00156672 ____A C:\Windows\System32\ff_libmad.dll
2013-01-25 09:02 - 2013-01-25 09:02 - 00116224 ____A C:\Windows\System32\ff_liba52.dll
2013-01-25 09:02 - 2013-01-25 09:02 - 00114688 ____A C:\Windows\System32\ff_wmv9.dll
2013-01-25 08:48 - 2013-01-25 08:48 - 03915776 ____A C:\Windows\SysWOW64\ffmpeg.dll
2013-01-25 08:47 - 2013-01-25 08:47 - 03500544 ____A C:\Windows\SysWOW64\ffdshow.ax
2013-01-25 08:47 - 2013-01-25 08:47 - 00112640 ____A C:\Windows\SysWOW64\ff_vfw.dll
2013-01-25 08:46 - 2013-01-25 08:46 - 01525760 ____A C:\Windows\SysWOW64\ff_samplerate.dll
2013-01-25 08:46 - 2013-01-25 08:46 - 00271360 ____A C:\Windows\SysWOW64\TomsMoComp_ff.dll
2013-01-25 08:46 - 2013-01-25 08:46 - 00211968 ____A C:\Windows\SysWOW64\ff_libdts.dll
2013-01-25 08:46 - 2013-01-25 08:46 - 00157184 ____A C:\Windows\SysWOW64\ff_unrar.dll
2013-01-25 08:46 - 2013-01-25 08:46 - 00147456 ____A C:\Windows\SysWOW64\ff_libmad.dll
2013-01-25 08:46 - 2013-01-25 08:46 - 00114688 ____A C:\Windows\SysWOW64\ff_liba52.dll
2013-01-25 08:46 - 2013-01-25 08:46 - 00099840 ____A C:\Windows\SysWOW64\ff_wmv9.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 07993776 ____A C:\Windows\System32\avcodec-lav-54.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 01514152 ____A (1f0.de - Hendrik Leppkes) C:\Windows\System32\LAVVideo.ax
2013-01-25 08:02 - 2013-01-25 08:02 - 01206616 ____A C:\Windows\System32\avformat-lav-54.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 00511656 ____A (1f0.de - Hendrik Leppkes) C:\Windows\System32\LAVSplitter.ax
2013-01-25 08:02 - 2013-01-25 08:02 - 00406000 ____A C:\Windows\System32\swscale-lav-2.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 00359592 ____A (Intel Corp.) C:\Windows\System32\IntelQuickSyncDecoder.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 00278184 ____A (1f0.de - Hendrik Leppkes) C:\Windows\System32\LAVAudio.ax
2013-01-25 08:02 - 2013-01-25 08:02 - 00262848 ____A C:\Windows\System32\avutil-lav-52.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 00215720 ____A C:\Windows\System32\libbluray.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 00185568 ____A C:\Windows\System32\avresample-lav-1.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 00180816 ____A C:\Windows\System32\avfilter-lav-3.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 07833552 ____A C:\Windows\SysWOW64\avcodec-lav-54.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 01257464 ____A C:\Windows\SysWOW64\avformat-lav-54.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 01186984 ____A (1f0.de - Hendrik Leppkes) C:\Windows\SysWOW64\LAVVideo.ax
2013-01-25 08:00 - 2013-01-25 08:00 - 00420008 ____A (1f0.de - Hendrik Leppkes) C:\Windows\SysWOW64\LAVSplitter.ax
2013-01-25 08:00 - 2013-01-25 08:00 - 00384472 ____A C:\Windows\SysWOW64\swscale-lav-2.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 00279208 ____A (Intel Corp.) C:\Windows\SysWOW64\IntelQuickSyncDecoder.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 00247920 ____A C:\Windows\SysWOW64\avutil-lav-52.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 00243880 ____A (1f0.de - Hendrik Leppkes) C:\Windows\SysWOW64\LAVAudio.ax
2013-01-25 08:00 - 2013-01-25 08:00 - 00183976 ____A C:\Windows\SysWOW64\libbluray.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 00169888 ____A C:\Windows\SysWOW64\avfilter-lav-3.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 00165160 ____A C:\Windows\SysWOW64\avresample-lav-1.dll
2013-01-23 15:00 - 2013-01-23 15:00 - 00000117 ____A C:\Windows\System32\netcfg-24903843.txt
2013-01-23 15:00 - 2013-01-23 15:00 - 00000117 ____A C:\Windows\System32\netcfg-24902000.txt
2013-01-23 11:44 - 2013-01-23 11:44 - 00000000 ____D C:\Users\Beccah\AppData\Roaming\OpenOffice.org
2013-01-23 11:24 - 2013-01-23 11:24 - 00000117 ____A C:\Windows\System32\netcfg-11939375.txt
2013-01-23 11:24 - 2013-01-23 11:24 - 00000117 ____A C:\Windows\System32\netcfg-11939234.txt
2013-01-22 14:19 - 2013-01-22 14:19 - 00000117 ____A C:\Windows\System32\netcfg-2099937.txt
2013-01-22 14:19 - 2013-01-22 14:19 - 00000117 ____A C:\Windows\System32\netcfg-2099875.txt
2013-01-22 12:01 - 2013-01-22 12:01 - 00000117 ____A C:\Windows\System32\netcfg-412584500.txt
2013-01-22 12:01 - 2013-01-22 12:01 - 00000117 ____A C:\Windows\System32\netcfg-412584437.txt
2013-01-22 09:10 - 2013-01-22 09:10 - 00000000 ____D C:\usr
2013-01-22 09:09 - 2013-01-22 09:09 - 00000117 ____A C:\Windows\System32\netcfg-402251265.txt
2013-01-22 09:09 - 2013-01-22 09:09 - 00000117 ____A C:\Windows\System32\netcfg-402250781.txt
 
==================== One Month Modified Files and Folders =======
 
2013-02-20 14:16 - 2013-02-20 14:16 - 00000000 ____D C:\FRST
2013-02-20 14:13 - 2013-01-16 16:03 - 00000924 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-02-20 14:13 - 2013-01-16 16:03 - 00000920 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-02-20 14:12 - 2013-01-16 15:54 - 02013513 ____A C:\Windows\WindowsUpdate.log
2013-02-20 14:11 - 2013-01-16 16:21 - 00000664 ____A C:\Windows\System32\config\afw_hm.conf
2013-02-20 14:11 - 2013-01-16 16:21 - 00000004 ____A C:\Windows\System32\config\afw_db.conf
2013-02-20 14:11 - 2012-12-26 09:09 - 00004524 ____A C:\Windows\SysWOW64\LOCALSERVICE.INI
2013-02-20 14:11 - 2012-12-26 09:09 - 00000043 ____A C:\Windows\SysWOW64\LOCALDEVICE.INI
2013-02-20 14:11 - 2012-08-10 17:45 - 00000821 ____A C:\Windows\SysWOW64\bscs.ini
2013-02-20 14:11 - 2012-07-25 23:22 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-02-20 14:09 - 2012-07-25 21:26 - 00262144 __ASH C:\Windows\System32\config\BBI
2013-02-20 14:06 - 2012-07-26 00:12 - 00000000 ___RD C:\Windows\ToastData
2013-02-20 14:02 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\System32\sru
2013-02-20 14:01 - 2013-02-20 14:01 - 00001739 ____A C:\Users\Beccah\Documents\Farbar Recovery Instructions.txt
2013-02-20 14:00 - 2012-07-25 23:28 - 00941050 ____A C:\Windows\System32\PerfStringBackup.INI
2013-02-20 13:59 - 2013-02-20 13:59 - 01464401 ____A (Farbar) C:\Users\Beccah\Downloads\FRST64.exe
2013-02-20 08:44 - 2013-01-16 17:01 - 00000000 ____D C:\Users\Beccah\AppData\Roaming\tixati
2013-02-19 16:38 - 2013-02-19 16:38 - 00688992 ____A (Swearware) C:\Users\Beccah\Downloads\dds.com
2013-02-19 15:18 - 2013-02-19 15:18 - 349184023 ____A C:\Windows\MEMORY.DMP
2013-02-19 15:18 - 2013-02-19 15:18 - 00280408 ____A C:\Windows\Minidump\021913-18890-01.dmp
2013-02-19 15:18 - 2013-02-19 15:18 - 00000000 ____D C:\Windows\Minidump
2013-02-19 15:16 - 2013-02-19 15:16 - 00000947 ____A C:\AdwCleaner[S2].txt
2013-02-19 15:16 - 2013-02-19 15:16 - 00000888 ____A C:\AdwCleaner[R2].txt
2013-02-19 14:22 - 2013-02-19 14:22 - 00000000 ____D C:\Windows\Sun
2013-02-19 13:20 - 2013-02-19 13:19 - 02347384 ____A (ESET) C:\Users\Beccah\Downloads\esetsmartinstaller_enu.exe
2013-02-19 08:19 - 2013-02-19 08:18 - 04732416 ____A (AVAST Software) C:\Users\Beccah\Downloads\aswMBR.exe
2013-02-19 08:14 - 2013-02-19 08:14 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\Beccah\Downloads\tdsskiller.exe
2013-02-18 16:54 - 2013-02-18 16:47 - 00000000 ____D C:\ProgramData\HitmanPro
2013-02-18 16:47 - 2013-02-18 16:47 - 00000000 ____D C:\Program Files\HitmanPro
2013-02-18 16:39 - 2013-02-18 16:38 - 09754024 ____A (SurfRight B.V.) C:\Users\Beccah\Downloads\HitmanPro_x64.exe
2013-02-18 16:27 - 2012-07-26 00:12 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-02-18 16:20 - 2013-02-06 08:25 - 00000796 ____A C:\Windows\setupact.log
2013-02-18 15:40 - 2012-12-26 09:03 - 00002720 ____A C:\Windows\System32\RaCoInst.log
2013-02-18 12:45 - 2013-01-16 15:56 - 00000000 ____D C:\Users\Beccah\AppData\Local\VirtualStore
2013-02-18 12:36 - 2013-02-18 12:36 - 00374784 ____A C:\Users\Beccah\Downloads\5uvyczm3.exe
2013-02-18 12:26 - 2013-02-18 12:26 - 05034457 ____A (Swearware) C:\Users\Beccah\Downloads\ComboFix.exe
2013-02-18 12:20 - 2013-02-18 12:20 - 00001166 ____A C:\AdwCleaner[S1].txt
2013-02-18 12:19 - 2013-02-18 12:19 - 00587671 ____A C:\Users\Beccah\Downloads\adwcleaner0.exe
2013-02-18 12:19 - 2013-02-18 12:19 - 00001252 ____A C:\AdwCleaner[R1].txt
2013-02-18 12:01 - 2013-02-18 12:01 - 00388608 ____A (Trend Micro Inc.) C:\Users\Beccah\Downloads\HijackThis.exe
2013-02-18 11:54 - 2013-02-18 11:54 - 00798208 ____A C:\Users\Beccah\Downloads\RogueKiller.exe
2013-02-18 10:57 - 2013-02-18 10:45 - 00000000 ____D C:\Users\Beccah\Downloads\Suspicious Crap
2013-02-18 10:46 - 2013-02-18 10:46 - 00000000 ____D C:\Users\Beccah\Downloads\Set-ups
2013-02-18 10:46 - 2013-01-17 16:00 - 00000000 ____D C:\Users\Beccah\Downloads\Kyocera KX 6.0.2212
2013-02-14 09:17 - 2013-02-14 10:24 - 00010858 ____A C:\Users\Beccah\Documents\Periodic Report Blank.odt
2013-02-14 08:16 - 2013-02-14 08:16 - 00427552 ____A C:\Windows\System32\FNTCACHE.DAT
2013-02-13 16:31 - 2013-02-13 14:57 - 00010996 ____A C:\Users\Beccah\Documents\Update Evaluation Blank.odt
2013-02-13 16:31 - 2013-02-13 14:51 - 00011692 ____A C:\Users\Beccah\Documents\Unemployability Blank.odt
2013-02-13 16:30 - 2013-02-13 14:45 - 00010994 ____A C:\Users\Beccah\Documents\Update Assessment Blank.odt
2013-02-12 13:41 - 2013-01-17 17:19 - 70004024 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-02-12 13:37 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-02-11 12:45 - 2013-01-16 16:03 - 00000000 ____D C:\Users\Beccah\AppData\Local\Google
2013-02-11 12:45 - 2013-01-16 16:03 - 00000000 ____D C:\Program Files (x86)\Google
2013-02-11 12:44 - 2012-09-11 18:02 - 00000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2013-02-11 12:37 - 2012-09-11 18:04 - 00000000 ____D C:\ProgramData\CyberLink
2013-02-11 11:13 - 2013-02-11 11:13 - 00000000 ____D C:\ProgramData\Sun
2013-02-11 11:12 - 2013-02-11 11:13 - 00861088 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-02-11 11:12 - 2013-02-11 11:13 - 00782240 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-02-11 11:12 - 2013-02-11 11:13 - 00262560 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-02-11 11:12 - 2013-02-11 11:12 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-02-11 11:12 - 2013-02-11 11:12 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-02-11 11:12 - 2013-02-11 11:12 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-02-11 11:12 - 2013-02-11 11:12 - 00000000 ____D C:\Program Files (x86)\Java
2013-02-06 15:06 - 2012-07-26 00:14 - 00692576 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-02-06 15:06 - 2012-07-26 00:14 - 00078176 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-02-06 13:02 - 2012-08-03 14:23 - 00742520 ____A C:\Windows\PFRO.log
2013-02-06 11:56 - 2013-01-16 17:17 - 00000000 ____D C:\Users\Beccah\AppData\Roaming\Real
2013-02-06 11:56 - 2013-01-16 17:17 - 00000000 ____D C:\Program Files (x86)\Real
2013-02-06 11:56 - 2013-01-16 17:14 - 00000000 ____D C:\ProgramData\Real
2013-02-06 11:47 - 2013-02-06 11:47 - 00000000 ____D C:\Program Files (x86)\ESET
2013-02-06 11:22 - 2013-02-04 15:11 - 00000000 ____D C:\Users\Beccah\AppData\Local\CrashDumps
2013-02-06 11:22 - 2012-08-03 15:21 - 00000000 ____D C:\Windows\Panther
2013-02-06 09:10 - 2013-02-06 09:09 - 00468144 ____A (AVAST Software) C:\Windows\System32\Drivers\aswnet.sys
2013-02-06 09:10 - 2013-01-17 08:54 - 00000175 ____A C:\Windows\System32\Drivers\aswnet.sys.sum
2013-02-06 09:09 - 2013-01-16 16:20 - 00000000 ____A C:\Windows\SysWOW64\config.nt
2013-02-06 09:06 - 2013-02-06 09:06 - 00001922 ____A C:\Users\Public\Desktop\avast!.lnk
2013-02-06 09:05 - 2013-02-06 09:05 - 00000000 ____D C:\Program Files\AVAST Software
2013-02-06 09:05 - 2013-01-16 16:20 - 00000000 ____D C:\ProgramData\AVAST Software
2013-02-06 08:24 - 2013-02-06 08:24 - 00000000 ____D C:\Windows\pss
2013-02-05 17:21 - 2013-02-05 17:21 - 00000000 ____D C:\Users\Beccah\AppData\LocalGoogle
2013-02-05 08:11 - 2013-01-16 16:55 - 00000000 ____D C:\Program Files (x86)\Glary Utilities
2013-02-05 08:11 - 2013-01-16 16:24 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-02-05 08:10 - 2013-01-16 16:55 - 00001026 ____A C:\Users\Beccah\Desktop\Glary Utilities.lnk
2013-02-05 08:10 - 2013-01-16 16:55 - 00000352 ____A C:\Windows\Tasks\GlaryInitialize.job
2013-02-04 15:11 - 2013-02-04 15:10 - 00000000 ____D C:\Windows\SysWOW64\C2MP
2013-02-04 15:03 - 2013-01-16 17:00 - 00000784 ____A C:\Users\Beccah\Desktop\Tixati.lnk
2013-02-04 15:03 - 2013-01-16 17:00 - 00000000 ____D C:\Program Files\tixati
2013-02-04 14:46 - 2013-02-04 14:46 - 00001069 ____A C:\Users\Public\Desktop\Mb.lnk
2013-02-04 14:46 - 2013-02-04 14:46 - 00000000 ____D C:\Users\Beccah\AppData\Roaming\Malwarebytes
2013-02-04 14:46 - 2013-02-04 14:46 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-02-04 14:46 - 2013-02-04 14:46 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-02-04 14:03 - 2013-02-04 14:03 - 00000000 ____D C:\Users\Beccah\Documents\ProcAlyzer Dumps
2013-02-04 14:03 - 2013-01-16 16:24 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-01-30 23:08 - 2013-01-30 23:08 - 00039904 ____A C:\Windows\SysWOW64\dischandler.exe
2013-01-30 19:29 - 2013-02-12 13:35 - 02226408 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-01-29 10:42 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\rescache
2013-01-28 14:53 - 2012-07-26 00:12 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2013-01-28 14:53 - 2012-07-25 21:38 - 00000000 ____D C:\Windows\System32\oobe
2013-01-28 14:52 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\WinStore
2013-01-28 08:41 - 2013-01-28 08:41 - 00000117 ____A C:\Windows\System32\netcfg-408817609.txt
2013-01-28 08:41 - 2013-01-28 08:41 - 00000117 ____A C:\Windows\System32\netcfg-408815781.txt
2013-01-26 10:18 - 2013-01-26 10:18 - 00000117 ____A C:\Windows\System32\netcfg-241856015.txt
2013-01-26 10:18 - 2013-01-26 10:18 - 00000117 ____A C:\Windows\System32\netcfg-241855750.txt
2013-01-25 09:04 - 2013-01-25 09:04 - 04012544 ____A C:\Windows\System32\ffmpeg.dll
2013-01-25 09:03 - 2013-01-25 09:03 - 04371456 ____A C:\Windows\System32\ffdshow.ax
2013-01-25 09:03 - 2013-01-25 09:03 - 00474624 ____A C:\Windows\System32\ff_kernelDeint.dll
2013-01-25 09:03 - 2013-01-25 09:03 - 00127488 ____A C:\Windows\System32\ff_vfw.dll
2013-01-25 09:02 - 2013-01-25 09:02 - 01532928 ____A C:\Windows\System32\ff_samplerate.dll
2013-01-25 09:02 - 2013-01-25 09:02 - 00631296 ____A C:\Windows\System32\TomsMoComp_ff.dll
2013-01-25 09:02 - 2013-01-25 09:02 - 00222720 ____A C:\Windows\System32\ff_libdts.dll
2013-01-25 09:02 - 2013-01-25 09:02 - 00183296 ____A C:\Windows\System32\ff_unrar.dll
2013-01-25 09:02 - 2013-01-25 09:02 - 00156672 ____A C:\Windows\System32\ff_libmad.dll
2013-01-25 09:02 - 2013-01-25 09:02 - 00116224 ____A C:\Windows\System32\ff_liba52.dll
2013-01-25 09:02 - 2013-01-25 09:02 - 00114688 ____A C:\Windows\System32\ff_wmv9.dll
2013-01-25 08:48 - 2013-01-25 08:48 - 03915776 ____A C:\Windows\SysWOW64\ffmpeg.dll
2013-01-25 08:47 - 2013-01-25 08:47 - 03500544 ____A C:\Windows\SysWOW64\ffdshow.ax
2013-01-25 08:47 - 2013-01-25 08:47 - 00112640 ____A C:\Windows\SysWOW64\ff_vfw.dll
2013-01-25 08:46 - 2013-01-25 08:46 - 01525760 ____A C:\Windows\SysWOW64\ff_samplerate.dll
2013-01-25 08:46 - 2013-01-25 08:46 - 00271360 ____A C:\Windows\SysWOW64\TomsMoComp_ff.dll
2013-01-25 08:46 - 2013-01-25 08:46 - 00211968 ____A C:\Windows\SysWOW64\ff_libdts.dll
2013-01-25 08:46 - 2013-01-25 08:46 - 00157184 ____A C:\Windows\SysWOW64\ff_unrar.dll
2013-01-25 08:46 - 2013-01-25 08:46 - 00147456 ____A C:\Windows\SysWOW64\ff_libmad.dll
2013-01-25 08:46 - 2013-01-25 08:46 - 00114688 ____A C:\Windows\SysWOW64\ff_liba52.dll
2013-01-25 08:46 - 2013-01-25 08:46 - 00099840 ____A C:\Windows\SysWOW64\ff_wmv9.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 07993776 ____A C:\Windows\System32\avcodec-lav-54.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 01514152 ____A (1f0.de - Hendrik Leppkes) C:\Windows\System32\LAVVideo.ax
2013-01-25 08:02 - 2013-01-25 08:02 - 01206616 ____A C:\Windows\System32\avformat-lav-54.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 00511656 ____A (1f0.de - Hendrik Leppkes) C:\Windows\System32\LAVSplitter.ax
2013-01-25 08:02 - 2013-01-25 08:02 - 00406000 ____A C:\Windows\System32\swscale-lav-2.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 00359592 ____A (Intel Corp.) C:\Windows\System32\IntelQuickSyncDecoder.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 00278184 ____A (1f0.de - Hendrik Leppkes) C:\Windows\System32\LAVAudio.ax
2013-01-25 08:02 - 2013-01-25 08:02 - 00262848 ____A C:\Windows\System32\avutil-lav-52.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 00215720 ____A C:\Windows\System32\libbluray.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 00185568 ____A C:\Windows\System32\avresample-lav-1.dll
2013-01-25 08:02 - 2013-01-25 08:02 - 00180816 ____A C:\Windows\System32\avfilter-lav-3.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 07833552 ____A C:\Windows\SysWOW64\avcodec-lav-54.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 01257464 ____A C:\Windows\SysWOW64\avformat-lav-54.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 01186984 ____A (1f0.de - Hendrik Leppkes) C:\Windows\SysWOW64\LAVVideo.ax
2013-01-25 08:00 - 2013-01-25 08:00 - 00420008 ____A (1f0.de - Hendrik Leppkes) C:\Windows\SysWOW64\LAVSplitter.ax
2013-01-25 08:00 - 2013-01-25 08:00 - 00384472 ____A C:\Windows\SysWOW64\swscale-lav-2.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 00279208 ____A (Intel Corp.) C:\Windows\SysWOW64\IntelQuickSyncDecoder.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 00247920 ____A C:\Windows\SysWOW64\avutil-lav-52.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 00243880 ____A (1f0.de - Hendrik Leppkes) C:\Windows\SysWOW64\LAVAudio.ax
2013-01-25 08:00 - 2013-01-25 08:00 - 00183976 ____A C:\Windows\SysWOW64\libbluray.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 00169888 ____A C:\Windows\SysWOW64\avfilter-lav-3.dll
2013-01-25 08:00 - 2013-01-25 08:00 - 00165160 ____A C:\Windows\SysWOW64\avresample-lav-1.dll
2013-01-23 15:00 - 2013-01-23 15:00 - 00000117 ____A C:\Windows\System32\netcfg-24903843.txt
2013-01-23 15:00 - 2013-01-23 15:00 - 00000117 ____A C:\Windows\System32\netcfg-24902000.txt
2013-01-23 11:44 - 2013-01-23 11:44 - 00000000 ____D C:\Users\Beccah\AppData\Roaming\OpenOffice.org
2013-01-23 11:24 - 2013-01-23 11:24 - 00000117 ____A C:\Windows\System32\netcfg-11939375.txt
2013-01-23 11:24 - 2013-01-23 11:24 - 00000117 ____A C:\Windows\System32\netcfg-11939234.txt
2013-01-22 14:19 - 2013-01-22 14:19 - 00000117 ____A C:\Windows\System32\netcfg-2099937.txt
2013-01-22 14:19 - 2013-01-22 14:19 - 00000117 ____A C:\Windows\System32\netcfg-2099875.txt
2013-01-22 12:01 - 2013-01-22 12:01 - 00000117 ____A C:\Windows\System32\netcfg-412584500.txt
2013-01-22 12:01 - 2013-01-22 12:01 - 00000117 ____A C:\Windows\System32\netcfg-412584437.txt
2013-01-22 09:10 - 2013-01-22 09:10 - 00000000 ____D C:\usr
2013-01-22 09:09 - 2013-01-22 09:09 - 00000117 ____A C:\Windows\System32\netcfg-402251265.txt
2013-01-22 09:09 - 2013-01-22 09:09 - 00000117 ____A C:\Windows\System32\netcfg-402250781.txt
 
==================== Known DLLs (Whitelisted) =================
 
 
==================== Bamital & volsnap Check =================
 
C:\Windows\System32\winlogon.exe
[2013-01-26 12:04] - [2012-10-10 21:46] - 0517120 ____A (Microsoft Corporation) BCF2036A0DD579E47C008C133550283E
 
C:\Windows\System32\wininit.exe
[2012-07-25 16:03] - [2012-07-25 19:08] - 0132608 ____A (Microsoft Corporation) FE9AB232B56A12224E8A3F3F9878C9A3
 
C:\Windows\explorer.exe
[2013-01-26 12:05] - [2012-10-10 23:35] - 2380944 ____A (Microsoft Corporation) E13A31D5254C25406A7946BDD9B06364
 
C:\Windows\SysWOW64\explorer.exe
[2013-01-26 12:05] - [2012-10-10 21:56] - 2115952 ____A (Microsoft Corporation) 953ADECFF08202A01EFC6110214FDE02
 
C:\Windows\System32\svchost.exe
[2013-01-26 11:54] - [2012-09-19 22:33] - 0029696 ____A (Microsoft Corporation) EDE27EACE742EE2888C5DD36400A2EC0
 
C:\Windows\SysWOW64\svchost.exe
[2013-01-26 11:54] - [2012-09-19 21:55] - 0023040 ____A (Microsoft Corporation) A46DC432F81473F526E3994AA483E366
 
C:\Windows\System32\services.exe
[2013-01-26 11:54] - [2012-09-19 22:33] - 0410624 ____A (Microsoft Corporation) 8F226143046435C75C033B0C52E90FFE
 
C:\Windows\System32\User32.dll
[2013-01-26 11:54] - [2012-09-19 22:33] - 1342464 ____A (Microsoft Corporation) A99AD14F26BDA7D7F27F76BC91B7EED7
 
C:\Windows\SysWOW64\User32.dll
[2013-01-26 11:53] - [2012-09-19 20:10] - 1126912 ____A (Microsoft Corporation) BA1C3ACD929A71E88B49C2B6E38F92B3
 
C:\Windows\System32\userinit.exe
[2012-07-25 16:06] - [2012-07-25 19:08] - 0025088 ____A (Microsoft Corporation) 0E925F7BA032920D58DD284B6181A247
 
C:\Windows\SysWOW64\userinit.exe
[2012-07-25 16:08] - [2012-07-25 19:21] - 0021504 ____A (Microsoft Corporation) 9F6289D194A04A09671FEED4B6CB6EF7
 
C:\Windows\System32\Drivers\volsnap.sys
[2012-07-25 18:30] - [2012-07-25 20:57] - 0332016 ____A (Microsoft Corporation) 2FB3CDFD5EAF4CD9D4AFAF96877D13AE
 
 
==================== EXE ASSOCIATION =====================
 
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
 
==================== Restore Points  =========================
 
Restore point made on: 2013-01-26 10:36:36
Restore point made on: 2013-02-05 08:47:45
Restore point made on: 2013-02-06 09:05:22
Restore point made on: 2013-02-11 11:12:04
Restore point made on: 2013-02-18 15:39:32
 
==================== Memory info =========================== 
 
Percentage of memory in use: 12%
Total physical RAM: 6036.27 MB
Available physical RAM: 5289.41 MB
Total Pagefile: 6036.27 MB
Available Pagefile: 5297.79 MB
Total Virtual: 8192 MB
Available Virtual: 8191.87 MB
 
==================== Partitions =============================
 
1 Drive a: (WINRE) (Fixed) (Total:0.39 GB) (Free:0.16 GB) NTFS
2 Drive c: () (Fixed) (Total:672.21 GB) (Free:620.29 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive d: (RECOVERY) (Fixed) (Total:25.66 GB) (Free:3.05 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive e: () (Removable) (Total:14.9 GB) (Free:14.85 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.25 GB) (Free:0.24 GB) NTFS
 
 
  Disk ###  Status         Size     Free     Dyn  Gpt
  --------  -------------  -------  -------  ---  ---
  Disk 0    Online          698 GB      0 B        *
  Disk 1    Online           14 GB      0 B         
 
Partitions of Disk 0:
===============
 
Disk ID: {91612880-A4D2-44C4-88FE-D5D179314181}
 
  Partition ###  Type              Size     Offset
  -------------  ----------------  -------  -------
  Partition 1    Recovery           400 MB  1024 KB
  Partition 2    System (partition with boot components)             260 MB   401 MB
  Partition 3    Reserved           128 MB   661 MB
  Partition 4    Primary            672 GB   789 MB
  Partition 5    Primary             25 GB   672 GB
 
==================================================================================
 
Disk: 0
Partition 1
Type    : de94bba4-06d1-4d40-a16a-bfd50179d6ac
Hidden  : Yes
Required: Yes
Attrib  : 0X8000000000000001
 
  Volume ###  Ltr  Label        Fs     Type        Size     Status     Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 3     A   WINRE        NTFS   Partition    400 MB  Healthy    Hidden  
 
=========================================================
 
Disk: 0
Partition 2
Type    : c12a7328-f81f-11d2-ba4b-00a0c93ec93b
Hidden  : Yes
Required: No
Attrib  : 0X8000000000000000
 
  Volume ###  Ltr  Label        Fs     Type        Size     Status     Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 4                      FAT32  Partition    260 MB  Healthy    Hidden  
 
=========================================================
 
Disk: 0
Partition 3
Type    : e3c9e316-0b5c-4db8-817d-f92df00215ae
Hidden  : Yes
Required: No
Attrib  : 0X8000000000000000
 
There is no volume associated with this partition.
 
=========================================================
 
Disk: 0
Partition 4
Type    : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden  : No
Required: No
Attrib  : 0000000000000000
 
  Volume ###  Ltr  Label        Fs     Type        Size     Status     Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 1     C                NTFS   Partition    672 GB  Healthy            
 
=========================================================
 
Disk: 0
Partition 5
Type    : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden  : No
Required: Yes
Attrib  : 0X0000000000000001
 
  Volume ###  Ltr  Label        Fs     Type        Size     Status     Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 6     D   RECOVERY     NTFS   Partition     25 GB  Healthy    Hidden  
 
=========================================================
 
Partitions of Disk 1:
===============
 
Disk ID: 00000000
 
  Partition ###  Type              Size     Offset
  -------------  ----------------  -------  -------
  Partition 1    Primary             14 GB    16 KB
 
==================================================================================
 
Disk: 1
Partition 1
Type  : 0C
Hidden: No
Active: No
 
  Volume ###  Ltr  Label        Fs     Type        Size     Status     Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 5     E                FAT32  Removable     14 GB  Healthy            
 
=========================================================
 
Last Boot: 2013-02-20 13:40
 
==================== End Of Log =============================

Edited by RJswanee, 20 February 2013 - 05:25 PM.


#4 RJswanee

RJswanee
  • Topic Starter

  • Members
  • 31 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:11:59 AM

Posted 20 February 2013 - 08:00 PM

The computer will be unavailable from Thursday, Feb 21 to Monday, Feb 25.  I will be back in the office Feb 25.  Just letting you know - I can't remove it from the office.



#5 The Dark Knight

The Dark Knight

    Malware Vigilante


  • Members
  • 651 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:59 AM

Posted 21 February 2013 - 06:10 AM

Good evening RJswanee,

I will be away from Sunday until Tuesday.

Please download the attached fixlist.txt.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.
On Windows XP: Now please boot into the BartPE CD.
Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt). Please post it in your reply.

Attached Files


Edited by The Dark Knight, 21 February 2013 - 06:11 AM.

If you make yourself more than just a man, if you devote yourself to an ideal...you become something else entirely. A legend, Mr. Wayne, a legend!


If I have helped you please consider donating to the Neuroscience Research Institute.


Posted Image
Posted Image


#6 The Dark Knight

The Dark Knight

    Malware Vigilante


  • Members
  • 651 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:59 AM

Posted 23 February 2013 - 04:25 PM

Just a side note: I am away until Tuesday.


If you make yourself more than just a man, if you devote yourself to an ideal...you become something else entirely. A legend, Mr. Wayne, a legend!


If I have helped you please consider donating to the Neuroscience Research Institute.


Posted Image
Posted Image


#7 RJswanee

RJswanee
  • Topic Starter

  • Members
  • 31 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:11:59 AM

Posted 25 February 2013 - 11:17 AM

Downloaded and noted.  Thank you.



#8 The Dark Knight

The Dark Knight

    Malware Vigilante


  • Members
  • 651 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:59 AM

Posted 26 February 2013 - 05:14 AM

Hello RJswanee,

 

Please post the new log.


If you make yourself more than just a man, if you devote yourself to an ideal...you become something else entirely. A legend, Mr. Wayne, a legend!


If I have helped you please consider donating to the Neuroscience Research Institute.


Posted Image
Posted Image


#9 RJswanee

RJswanee
  • Topic Starter

  • Members
  • 31 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:11:59 AM

Posted 26 February 2013 - 11:37 AM

Here it is - the fix was the GMER Scan tool, I believe.



Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-02-2013 01
Ran by SYSTEM at 2013-02-26 08:34:54 Run:1
Running from E:\
 
==============================================
 
C:\Users\Beccah\Downloads\5uvyczm3.exe moved successfully.
 
==== End of Fixlog ====


#10 The Dark Knight

The Dark Knight

    Malware Vigilante


  • Members
  • 651 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:59 AM

Posted 26 February 2013 - 03:42 PM

Good morning RJswanee,

 

Please download Malwarebytes Anti-Rootkit here.

  • Unzip the contents to a folder on the Desktop.
  • Open the folder where the contents were unzipped and run mbar.exe ( right-click and select Run as administrator for Vista and Windows 7).
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Please post the two logs produced.


Please note: This tool is still in BETA mode, so please ensure you have backed up any important files.


If you make yourself more than just a man, if you devote yourself to an ideal...you become something else entirely. A legend, Mr. Wayne, a legend!


If I have helped you please consider donating to the Neuroscience Research Institute.


Posted Image
Posted Image


#11 RJswanee

RJswanee
  • Topic Starter

  • Members
  • 31 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:11:59 AM

Posted 26 February 2013 - 06:31 PM

It said, "Congratulations!  No Malware found!"  I noticed I haven't had a pop-up all day.  I have no idea what happened.  When I left at 5pm yesterday, there were pop-ups.  I came into work this morning at 8am with no issues.  The only problem I've experienced today is the Avast! WebRep plug-in keeps crashing.



#12 RJswanee

RJswanee
  • Topic Starter

  • Members
  • 31 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:11:59 AM

Posted 26 February 2013 - 06:33 PM

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.01.0.1020
 
© Malwarebytes Corporation 2011-2012
 
OS version: 6.2.9200 Windows 8 x64
 
Account is Administrative
 
Internet Explorer version: 10.0.9200.16484
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
CPU speed: 2.395000 GHz
Memory total: 6329491456, free: 5103407104
 
------------ Kernel report ------------
     02/26/2013 15:20:08
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kd.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\System32\drivers\CLFS.SYS
\SystemRoot\System32\drivers\tm.sys
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\system32\CI.dll
\SystemRoot\System32\drivers\msrpc.sys
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\System32\Drivers\acpiex.sys
\SystemRoot\System32\Drivers\WppRecorder.sys
\SystemRoot\System32\drivers\ACPI.sys
\SystemRoot\System32\drivers\WMILIB.SYS
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\msisadrv.sys
\SystemRoot\System32\drivers\pci.sys
\SystemRoot\System32\drivers\vdrvroot.sys
\SystemRoot\system32\drivers\pdc.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\System32\drivers\spaceport.sys
\SystemRoot\System32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\System32\drivers\iaStorA.sys
\SystemRoot\System32\drivers\storport.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\System32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\DRIVERS\wfplwfs.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\hpdskflt.sys
\SystemRoot\System32\drivers\wd.sys
\SystemRoot\System32\drivers\volsnap.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\disk.sys
\SystemRoot\System32\drivers\CLASSPNP.SYS
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\drivers\cdrom.sys
\SystemRoot\System32\Drivers\aswSnx.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\BasicRender.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\System32\drivers\BasicDisplay.sys
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\System32\Drivers\aswTdi.SYS
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\System32\Drivers\aswrdr2.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\System32\drivers\npsvctrig.sys
\SystemRoot\System32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\System32\Drivers\aswSP.SYS
\SystemRoot\System32\Drivers\aswnet.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\System32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\kdnic.sys
\SystemRoot\System32\drivers\umbus.sys
\SystemRoot\System32\drivers\CmBatt.sys
\SystemRoot\System32\drivers\BATTC.SYS
\SystemRoot\system32\DRIVERS\igdkmd64.sys
\SystemRoot\System32\drivers\USBXHCI.SYS
\SystemRoot\System32\drivers\ucx01000.sys
\SystemRoot\System32\drivers\HECIx64.sys
\SystemRoot\System32\drivers\usbehci.sys
\SystemRoot\System32\drivers\USBPORT.SYS
\SystemRoot\System32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\netr28x.sys
\SystemRoot\System32\drivers\vwifibus.sys
\SystemRoot\System32\drivers\rtbth.sys
\SystemRoot\system32\DRIVERS\Rt630x64.sys
\SystemRoot\System32\drivers\i8042prt.sys
\SystemRoot\system32\DRIVERS\SynTP.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\System32\drivers\kbdclass.sys
\SystemRoot\System32\drivers\mouclass.sys
\SystemRoot\system32\DRIVERS\Smb_driver_Intel.sys
\SystemRoot\system32\DRIVERS\Accelerometer.sys
\SystemRoot\System32\drivers\WirelessButtonDriver64.sys
\SystemRoot\System32\drivers\HIDCLASS.SYS
\SystemRoot\System32\drivers\HIDPARSE.SYS
\SystemRoot\System32\drivers\wmiacpi.sys
\SystemRoot\System32\drivers\intelppm.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\System32\Drivers\BtAudioBus.sys
\SystemRoot\System32\drivers\swenum.sys
\SystemRoot\System32\drivers\ks.sys
\SystemRoot\System32\drivers\rdpbus.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\System32\drivers\usbhub.sys
\SystemRoot\System32\drivers\UsbHub3.sys
\SystemRoot\system32\DRIVERS\stwrt64.sys
\SystemRoot\system32\DRIVERS\portcls.sys
\SystemRoot\system32\DRIVERS\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\DRIVERS\IntcDAud.sys
\SystemRoot\System32\Drivers\IvtUrbBtFlt.sys
\SystemRoot\System32\Drivers\BTHUSB.sys
\SystemRoot\System32\Drivers\bthport.sys
\SystemRoot\system32\DRIVERS\BthLEEnum.sys
\SystemRoot\system32\DRIVERS\rfcomm.sys
\SystemRoot\System32\drivers\BthEnum.sys
\SystemRoot\system32\DRIVERS\bthpan.sys
\SystemRoot\System32\Drivers\BtL2caScoIf.sys
\SystemRoot\System32\drivers\usbccgp.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\System32\Drivers\dump_diskdump.sys
\SystemRoot\System32\Drivers\dump_iaStorA.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\??\C:\Windows\system32\drivers\aswMonFlt.sys
\SystemRoot\System32\Drivers\aswFsBlk.SYS
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\drivers\Ndu.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\System32\drivers\condrv.sys
\SystemRoot\System32\drivers\hidusb.sys
\SystemRoot\System32\drivers\mouhid.sys
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\DRIVERS\monitor.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\mbamswissarmy.sys
----------- End -----------
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa80085f8060
Upper Device Driver Name: \Driver\disk\
Lower Device Name: \Device\00000038\
Lower Device Object: 0xfffffa8007913060
Lower Device Driver Name: \Driver\iaStorA\
Driver name found: iaStorA
Initialization returned 0x0
Port sub-driver loaded: \??\C:\Windows\System32\Drivers\storport.sys (0x0)
Load Function returned 0x0
Downloaded database version: v2013.02.26.11
Initializing...
Done!
<<<2>>>
Device number: 0, partition: 4
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa80085f8060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa80085f8b10, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa80085f8060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
DevicePointer: 0xfffffa8008344b10, DeviceName: Unknown, DriverName: \Driver\hpdskflt\
DevicePointer: 0xfffffa8007913060, DeviceName: \Device\00000038\, DriverName: \Driver\iaStorA\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
Upper DeviceData: 0xfffff8a00b9127b0, 0xfffffa80085f8060, 0xfffffa8009290740
Lower DeviceData: 0xfffff8a009de0760, 0xfffffa8007913060, 0xfffffa800ce22920
Partition type: GUID
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning directory: C:\Windows\system32\drivers...
<<<2>>>
Device number: 0, partition: 4
Partition type: GUID
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
This drive is a GPT Drive.
MBR Signature: 55AA
Disk Signature: 151C1871
 
GPT Protective MBR Partition information:
 
    Partition 0 type is EFI-GPT (0xee)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 1  Numsec = 1465149167
 
    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
GPT Partition information:
 
    GPT Header Signature 4546492050415254
    GPT Header Revision 65536 Size 92 CRC 3182797606
    GPT Header CurrentLba = 1 BackupLba 1465149167
    GPT Header FirstUsableLba 34  LastUsableLba 1465149134
    GPT Header Guid 91612880-a4d2-44c4-88fe-d5d179314181
    GPT Header Contains 128 partition entries starting at LBA 2
    GPT Header Partition entry size = 128
 
    Backup GPT header Signature 4546492050415254
    Backup GPT header Revision 65536 Size 92 CRC 3182797606
    Backup GPT header CurrentLba = 1465149167 BackupLba 1
    Backup GPT header FirstUsableLba 34  LastUsableLba 1465149134
    Backup GPT header Guid 91612880-a4d2-44c4-88fe-d5d179314181
    Backup GPT header Contains 128 partition entries starting at LBA 1465149135
    Backup GPT header Partition entry size = 128
 
    Partition 0 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
    Partition ID 5762bb3e-c36e-4110-a786-8a79a8e9bee9
    FirstLBA 2048  Last LBA 821247
    Attributes 1
    Partition Name                 Basic data partition
 
    Partition 1 Type c12a7328-f81f-11d2-ba4b-0a0c93ec93b
    Partition ID 9628442-25d4-49e3-8bed-1129336791b2
    FirstLBA 821248  Last LBA 1353727
    Attributes 0
    Partition Name                 EFI system partition
 
    GPT Partition 1 is bootable
    Partition 2 Type e3c9e316-b5c-4db8-817d-f92df0215ae
    Partition ID 46f35399-c450-4196-a9f6-a3fce2ab1242
    FirstLBA 1353728  Last LBA 1615871
    Attributes 0
    Partition Name         Microsoft reserved partition
 
    Partition 3 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
    Partition ID 5f4c07c2-417d-408c-9af6-1841ae127ab1
    FirstLBA 1615872  Last LBA 1411340287
    Attributes 0
    Partition Name                 Basic data partition
 
    Partition 4 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
    Partition ID c1f510e4-5aa9-4690-aac0-e515a4b7c5a3
    FirstLBA 1411340288  Last LBA 1465147391
    Attributes 1
    Partition Name                 Basic data partition
 
Disk Size: 750156374016 bytes
Sector size: 512 bytes
 
Done!
Performing system, memory and registry scan...
Done!
Scan finished
=======================================


#13 The Dark Knight

The Dark Knight

    Malware Vigilante


  • Members
  • 651 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:59 AM

Posted 27 February 2013 - 03:56 AM

Hello RJswanee,

 

When I left at 5pm yesterday, there were pop-ups.

What sort of popups?


If you make yourself more than just a man, if you devote yourself to an ideal...you become something else entirely. A legend, Mr. Wayne, a legend!


If I have helped you please consider donating to the Neuroscience Research Institute.


Posted Image
Posted Image


#14 RJswanee

RJswanee
  • Topic Starter

  • Members
  • 31 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:11:59 AM

Posted 27 February 2013 - 06:17 PM

The pop-ups were for insurancecomparison.org, ilivid downloads, and make-your-pc-faster.  They haven't shown up since Monday night.  They were the tip-off that I hadn't rid the computer of the viruses.



#15 The Dark Knight

The Dark Knight

    Malware Vigilante


  • Members
  • 651 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:59 AM

Posted 27 February 2013 - 08:02 PM

Hey RJswanee,

 

Please download to the Desktop RogueKiller (by tigzy).

  • Please quit all programs.
  • Start RogueKiller.exe.
  • Wait until Prescan has finished.
  • Click on Scan.
  • Click on Report and copy/paste the contents of the report in your next reply.

 

=====

 

Also, please download AdwCleaner by Xplode onto your Desktop.

  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search.
  • A logfile will automatically open after the scan has finished.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[Rn].txt as well - n is the order number.

 

=====

 

Please provide both logs in your reply.


If you make yourself more than just a man, if you devote yourself to an ideal...you become something else entirely. A legend, Mr. Wayne, a legend!


If I have helped you please consider donating to the Neuroscience Research Institute.


Posted Image
Posted Image





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users