Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Possibly infected. Strange events. Norton detects nothing.


  • This topic is locked This topic is locked
34 replies to this topic

#1 newt123

newt123

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:08:48 AM

Posted 20 November 2013 - 10:05 PM

A few days ago i did a full system reboot, cause i thought i got a virus. So i did the reboot, installed norton internet security, malwarebytes, superantispyware and hitman pro. I did a full system scan with each of the listed programs and no virus etc was detected. However yesterday i got a high cpu usage alert from norton, saying bluetooth obex service was 100% of at least one cpu. As i open up norton to check it, suddenly the performance monitoring was turned off. I then turned it on again, but it then turned off. After that i wasnt able to turn it on again, so i restarted the computer and after that everything seemed fine. Seems very strange as i never use or open any bluetooth services. I did a full system scan with all mentioned programs again, and no infections were found. I checked the norton performance calendar to see if any other suspicious activities had gone on. Turned out the bluetooth obex service (obexsrv.exe) had used the same amount of cpu on another occasion and also bluetooth mediasrv.exe had been using alot of cpu on the occasions. Another thing i noticed was: in the performance calendar where the bluetooth obex service was using up alot of cpu, two processes of ccsvchst.exe show, running simultaneously. When i then want to get more info on it by clicking on it, norton tells me: File not found or file not accesible. Please try again later. I am really worrying about whats going on. Am i infected or is this harmless?? The dds log is below. Thanks in advance! :)

 

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16428
Run by 1 at 4:31:05 on 2013-11-21
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.45.1033.18.6092.3984 [GMT 1:00]
.
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\AUDIODG.EXE
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Users\1\Desktop\Virus Detection\HijackThis.exe
C:\Windows\SysWOW64\notepad.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.bing.com?pc=HPNTDF
mWinlogon: Userinit = userinit.exe,
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ips\ipsbho.dll
BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [HPQuickWebProxy] "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{280F13DA-E4AF-4520-96EA-003BFA090D10} : DHCPNameServer = 192.168.0.1
SSODL: WebCheck - <orphaned>
x64-BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\18ghfms5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3306061&CUI=UN21434502115176265&UM=2&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - google.dk
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3306061&SearchSource=2&CUI=UN21434502115176265&UM=2&q=
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll
FF - ExtSQL: 2013-11-18 02:58; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn
FF - ExtSQL: 2013-11-18 03:03; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFF
FF - ExtSQL: 2013-11-18 05:22; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\18ghfms5.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-11-18 20:32; {b9db16a4-6edc-47ec-a1f4-b86292ed211d}; C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\18ghfms5.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-10-15 55856]
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NISx64\1309010.00E\symds64.sys [2013-11-19 451192]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1309010.00E\symefa64.sys [2013-11-19 1129120]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20131114.001\BHDrvx64.sys [2013-11-19 1524824]
R1 ccSet_NIS;Norton Internet Security Settings Manager;C:\Windows\System32\drivers\NISx64\1309010.00E\ccsetx64.sys [2013-11-19 167072]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20131119.001\IDSviA64.sys [2013-11-20 521816]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NISx64\1309010.00E\ironx64.sys [2013-11-19 190072]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\NISx64\1309010.00E\symnets.sys [2013-11-19 405624]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2013-10-10 144152]
R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-9-30 169408]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2011-10-20 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-5-8 203776]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-6-21 85560]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-5-22 103992]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2011-5-27 30520]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-4-8 26680]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-10-20 13592]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-10-20 2375168]
R2 jhi_service;Intel® Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-2-24 212944]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-11-18 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-11-18 701512]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe [2013-11-19 138272]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-10-20 2656280]
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2011-3-8 51712]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys [2010-7-28 31088]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-11-18 140376]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-10-15 317440]
R3 intelkmd;intelkmd;C:\Windows\System32\drivers\igdpmd64.sys [2011-4-15 12228128]
R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\drivers\iwdbus.sys [2011-5-17 25496]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-3-23 77936]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-11-18 25928]
R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2011-5-17 42392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-5-6 263496]
S3 AMPPAL;Intel® Centrino® Bluetooth 3.0 + High Speed Virtual Adapter;C:\Windows\System32\drivers\AmpPal.sys [2011-4-21 294912]
S3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2011-3-8 274944]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2011-3-23 59904]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2013-11-18 111616]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\drivers\intelaud.sys [2011-5-17 34200]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-5-2 340240]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2011-10-20 337512]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-11-18 1255736]
.
=============== Created Last 30 ================
.
2013-11-20 13:56:42    --------    d-----w-    C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-11-20 13:56:41    116440    ----a-w-    C:\Windows\System32\drivers\MBAMSwissArmy.sys
2013-11-20 13:55:40    91352    ----a-w-    C:\Windows\System32\drivers\mbamchameleon.sys
2013-11-20 10:36:26    --------    d-----w-    C:\ProgramData\Sophos
2013-11-20 10:36:15    73728    ----a-r-    C:\Users\1\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe1_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2013-11-20 10:36:15    73728    ----a-r-    C:\Users\1\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2013-11-20 10:36:02    73728    ----a-r-    C:\Users\1\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\ARPPRODUCTICON.exe
2013-11-20 10:35:51    --------    d-----w-    C:\Program Files (x86)\Sophos
2013-11-19 05:09:50    737952    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\srtsp64.sys
2013-11-19 05:09:50    451192    ----a-r-    C:\Windows\System32\drivers\NISx64\1309010.00E\symds64.sys
2013-11-19 05:09:50    405624    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\symnets.sys
2013-11-19 05:09:50    37536    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\srtspx64.sys
2013-11-19 05:09:50    190072    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\ironx64.sys
2013-11-19 05:09:50    1129120    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\symefa64.sys
2013-11-19 05:09:49    167072    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\ccsetx64.sys
2013-11-19 05:09:44    --------    d-----w-    C:\Windows\System32\drivers\NISx64\1309010.00E
2013-11-18 23:10:50    --------    d-----w-    C:\Users\1\AppData\Local\NPE
2013-11-18 21:13:03    99840    ----a-w-    C:\Windows\System32\drivers\usbccgp.sys
2013-11-18 21:13:03    7808    ----a-w-    C:\Windows\System32\drivers\usbd.sys
2013-11-18 21:13:03    52736    ----a-w-    C:\Windows\System32\drivers\usbehci.sys
2013-11-18 21:13:03    343040    ----a-w-    C:\Windows\System32\drivers\usbhub.sys
2013-11-18 21:13:03    325120    ----a-w-    C:\Windows\System32\drivers\usbport.sys
2013-11-18 21:13:03    30720    ----a-w-    C:\Windows\System32\drivers\usbuhci.sys
2013-11-18 21:13:03    25600    ----a-w-    C:\Windows\System32\drivers\usbohci.sys
2013-11-18 21:13:01    1424384    ----a-w-    C:\Windows\System32\WindowsCodecs.dll
2013-11-18 21:13:01    1230336    ----a-w-    C:\Windows\SysWow64\WindowsCodecs.dll
2013-11-18 21:12:48    67072    ----a-w-    C:\Windows\splwow64.exe
2013-11-18 21:12:48    559104    ----a-w-    C:\Windows\System32\spoolsv.exe
2013-11-18 20:22:28    --------    d-----w-    C:\Users\1\AppData\Roaming\IDT
2013-11-18 20:21:56    --------    d-----w-    C:\Users\1\AppData\Local\CrashDumps
2013-11-18 19:32:56    --------    d-----w-    C:\Users\1\dwhelper
2013-11-18 05:27:21    --------    d-----w-    C:\Users\1\AppData\Local\Macromedia
2013-11-18 05:27:02    692616    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe
2013-11-18 04:37:33    --------    d-----w-    C:\Program Files\CCleaner
2013-11-18 04:33:38    --------    d-----w-    C:\Program Files\HitmanPro
2013-11-18 04:32:36    --------    d-----w-    C:\ProgramData\HitmanPro
2013-11-18 04:28:28    --------    d-----w-    C:\Users\1\AppData\Roaming\SUPERAntiSpyware.com
2013-11-18 04:28:02    --------    d-----w-    C:\ProgramData\SUPERAntiSpyware.com
2013-11-18 04:28:02    --------    d-----w-    C:\Program Files\SUPERAntiSpyware
2013-11-18 04:25:39    --------    d-----w-    C:\Users\1\AppData\Roaming\Malwarebytes
2013-11-18 04:25:30    --------    d-----w-    C:\ProgramData\Malwarebytes
2013-11-18 04:25:27    25928    ----a-w-    C:\Windows\System32\drivers\mbam.sys
2013-11-18 04:25:27    --------    d-----w-    C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-18 04:25:02    --------    d-----w-    C:\Users\1\AppData\Local\Programs
2013-11-18 04:01:57    --------    d-----w-    C:\Windows\SysWow64\Wat
2013-11-18 04:01:57    --------    d-----w-    C:\Windows\System32\Wat
2013-11-18 03:21:31    2560    ----a-w-    C:\Windows\System32\drivers\nb-NO\wdf01000.sys.mui
2013-11-18 03:21:31    2560    ----a-w-    C:\Windows\System32\drivers\fi-FI\wdf01000.sys.mui
2013-11-18 03:21:31    2560    ----a-w-    C:\Windows\System32\drivers\da-DK\wdf01000.sys.mui
2013-11-18 03:21:30    2560    ----a-w-    C:\Windows\System32\drivers\sv-SE\wdf01000.sys.mui
2013-11-18 03:21:30    2560    ----a-w-    C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2013-11-18 02:59:35    --------    d-----w-    C:\Program Files (x86)\Common Files\Symantec Shared
2013-11-18 02:46:57    294912    ----a-w-    C:\Windows\System32\browserchoice.exe
2013-11-18 02:37:21    87040    ----a-w-    C:\Windows\System32\drivers\WUDFPf.sys
2013-11-18 02:37:21    84992    ----a-w-    C:\Windows\System32\WUDFSvc.dll
2013-11-18 02:37:21    744448    ----a-w-    C:\Windows\System32\WUDFx.dll
2013-11-18 02:37:21    45056    ----a-w-    C:\Windows\System32\WUDFCoinstaller.dll
2013-11-18 02:37:21    229888    ----a-w-    C:\Windows\System32\WUDFHost.exe
2013-11-18 02:37:21    198656    ----a-w-    C:\Windows\System32\drivers\WUDFRd.sys
2013-11-18 02:37:21    194048    ----a-w-    C:\Windows\System32\WUDFPlatform.dll
2013-11-18 02:33:36    --------    d-----w-    C:\Windows\System32\MRT
2013-11-18 02:31:58    81408    ----a-w-    C:\Windows\System32\imagehlp.dll
2013-11-18 02:31:58    5120    ----a-w-    C:\Windows\SysWow64\wmi.dll
2013-11-18 02:31:58    5120    ----a-w-    C:\Windows\System32\wmi.dll
2013-11-18 02:31:58    23408    ----a-w-    C:\Windows\System32\drivers\fs_rec.sys
2013-11-18 02:31:58    159232    ----a-w-    C:\Windows\SysWow64\imagehlp.dll
2013-11-18 02:27:59    224256    ----a-w-    C:\Windows\System32\wintrust.dll
2013-11-18 02:25:56    245760    ----a-w-    C:\Windows\System32\OxpsConverter.exe
2013-11-18 02:21:04    751104    ----a-w-    C:\Windows\System32\win32spl.dll
2013-11-18 02:21:04    492544    ----a-w-    C:\Windows\SysWow64\win32spl.dll
2013-11-18 02:21:04    404480    ----a-w-    C:\Windows\System32\gdi32.dll
2013-11-18 02:21:04    311808    ----a-w-    C:\Windows\SysWow64\gdi32.dll
2013-11-18 02:21:02    936448    ----a-w-    C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-11-18 02:21:02    1367040    ----a-w-    C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-11-18 02:21:00    5549504    ----a-w-    C:\Windows\System32\ntoskrnl.exe
2013-11-18 02:21:00    3969472    ----a-w-    C:\Windows\SysWow64\ntkrnlpa.exe
2013-11-18 02:21:00    3914176    ----a-w-    C:\Windows\SysWow64\ntoskrnl.exe
2013-11-18 02:19:26    903168    ----a-w-    C:\Windows\SysWow64\certutil.exe
2013-11-18 02:19:26    1192448    ----a-w-    C:\Windows\System32\certutil.exe
2013-11-18 02:19:25    52224    ----a-w-    C:\Windows\System32\certenc.dll
2013-11-18 02:19:25    43008    ----a-w-    C:\Windows\SysWow64\certenc.dll
2013-11-18 02:19:17    690688    ----a-w-    C:\Windows\SysWow64\msvcrt.dll
2013-11-18 02:19:17    634880    ----a-w-    C:\Windows\System32\msvcrt.dll
2013-11-18 02:10:46    --------    d-----w-    C:\Users\1\AppData\Local\Microsoft Games
2013-11-18 02:06:21    461312    ----a-w-    C:\Windows\System32\scavengeui.dll
2013-11-18 02:06:11    859648    ----a-w-    C:\Windows\System32\IKEEXT.DLL
2013-11-18 02:06:11    830464    ----a-w-    C:\Windows\System32\nshwfp.dll
2013-11-18 02:06:11    656896    ----a-w-    C:\Windows\SysWow64\nshwfp.dll
2013-11-18 02:06:11    324096    ----a-w-    C:\Windows\System32\FWPUCLNT.DLL
2013-11-18 02:06:11    216576    ----a-w-    C:\Windows\SysWow64\FWPUCLNT.DLL
2013-11-18 02:04:47    956928    ----a-w-    C:\Windows\System32\localspl.dll
2013-11-18 02:03:39    826880    ----a-w-    C:\Windows\SysWow64\rdpcore.dll
2013-11-18 02:03:39    23552    ----a-w-    C:\Windows\System32\drivers\tdtcp.sys
2013-11-18 02:03:39    1031680    ----a-w-    C:\Windows\System32\rdpcore.dll
2013-11-18 02:00:54    --------    d-----w-    C:\Users\1\AppData\Local\ATI
2013-11-18 01:59:47    --------    d-----w-    C:\Users\1\AppData\Roaming\hpqLog
2013-11-18 01:59:44    --------    d-----w-    C:\Users\1\AppData\Local\Adobe
2013-11-18 01:58:09    --------    d-----w-    C:\Users\1\AppData\Local\RemEngine
2013-11-18 01:57:46    --------    d-----w-    C:\Users\1\AppData\Local\Hewlett-Packard
2013-11-18 01:57:37    --------    d-----w-    C:\Users\1\AppData\Local\Hewlett-Packard_Company
2013-11-18 01:57:23    --------    d-----w-    C:\Users\1\AppData\Local\AuthenTec
2013-11-18 01:56:41    --------    d-----w-    C:\Users\1\AppData\Local\VirtualStore
2013-11-18 01:56:17    2622464    ----a-w-    C:\Windows\System32\wucltux.dll
2013-11-18 01:56:08    99840    ----a-w-    C:\Windows\System32\wudriver.dll
2013-11-18 01:56:08    --------    d-----w-    C:\Users\1\AppData\Roaming\Intel
2013-11-18 01:56:01    36864    ----a-w-    C:\Windows\System32\wuapp.exe
2013-11-18 01:56:01    186752    ----a-w-    C:\Windows\System32\wuwebv.dll
.
==================== Find3M  ====================
.
2013-11-18 15:23:13    175736    ----a-w-    C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2013-11-18 05:27:02    71048    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-18 02:55:35    9728    ---ha-w-    C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-10-05 20:25:35    1474048    ----a-w-    C:\Windows\System32\crypt32.dll
2013-10-05 19:57:25    1168384    ----a-w-    C:\Windows\SysWow64\crypt32.dll
2013-10-04 02:28:31    190464    ----a-w-    C:\Windows\System32\SmartcardCredentialProvider.dll
2013-10-04 02:25:17    197120    ----a-w-    C:\Windows\System32\credui.dll
2013-10-04 02:24:49    1930752    ----a-w-    C:\Windows\System32\authui.dll
2013-10-04 01:58:50    152576    ----a-w-    C:\Windows\SysWow64\SmartcardCredentialProvider.dll
2013-10-04 01:56:25    168960    ----a-w-    C:\Windows\SysWow64\credui.dll
2013-10-04 01:56:00    1796096    ----a-w-    C:\Windows\SysWow64\authui.dll
2013-09-28 01:09:10    497152    ----a-w-    C:\Windows\System32\drivers\afd.sys
2013-09-25 02:26:40    95680    ----a-w-    C:\Windows\System32\drivers\ksecdd.sys
2013-09-25 02:26:40    154560    ----a-w-    C:\Windows\System32\drivers\ksecpkg.sys
2013-09-25 02:23:33    28672    ----a-w-    C:\Windows\System32\sspisrv.dll
2013-09-25 02:23:33    135680    ----a-w-    C:\Windows\System32\sspicli.dll
2013-09-25 02:23:01    28160    ----a-w-    C:\Windows\System32\secur32.dll
2013-09-25 02:22:59    340992    ----a-w-    C:\Windows\System32\schannel.dll
2013-09-25 02:21:50    307200    ----a-w-    C:\Windows\System32\ncrypt.dll
2013-09-25 02:21:07    1447936    ----a-w-    C:\Windows\System32\lsasrv.dll
2013-09-25 01:58:17    96768    ----a-w-    C:\Windows\SysWow64\sspicli.dll
2013-09-25 01:57:26    22016    ----a-w-    C:\Windows\SysWow64\secur32.dll
2013-09-25 01:57:24    247808    ----a-w-    C:\Windows\SysWow64\schannel.dll
2013-09-25 01:56:42    220160    ----a-w-    C:\Windows\SysWow64\ncrypt.dll
2013-09-25 01:03:24    30720    ----a-w-    C:\Windows\System32\lsass.exe
2013-09-08 02:30:37    1903552    ----a-w-    C:\Windows\System32\drivers\tcpip.sys
2013-09-08 02:27:14    327168    ----a-w-    C:\Windows\System32\mswsock.dll
2013-09-08 02:03:58    231424    ----a-w-    C:\Windows\SysWow64\mswsock.dll
2013-08-29 02:16:35    1732032    ----a-w-    C:\Windows\System32\ntdll.dll
2013-08-29 02:16:28    243712    ----a-w-    C:\Windows\System32\wow64.dll
2013-08-29 02:16:14    859648    ----a-w-    C:\Windows\System32\tdh.dll
2013-08-29 02:13:28    878080    ----a-w-    C:\Windows\System32\advapi32.dll
2013-08-29 01:50:31    5120    ----a-w-    C:\Windows\SysWow64\wow32.dll
2013-08-29 01:50:30    1292192    ----a-w-    C:\Windows\SysWow64\ntdll.dll
2013-08-29 01:50:16    619520    ----a-w-    C:\Windows\SysWow64\tdh.dll
2013-08-29 01:48:17    640512    ----a-w-    C:\Windows\SysWow64\advapi32.dll
2013-08-29 01:48:15    44032    ----a-w-    C:\Windows\apppatch\acwow64.dll
2013-08-29 00:49:53    25600    ----a-w-    C:\Windows\SysWow64\setup16.exe
2013-08-29 00:49:52    7680    ----a-w-    C:\Windows\SysWow64\instnm.exe
2013-08-29 00:49:52    14336    ----a-w-    C:\Windows\SysWow64\ntvdm64.dll
2013-08-29 00:49:49    2048    ----a-w-    C:\Windows\SysWow64\user.exe
2013-08-28 01:21:06    3155968    ----a-w-    C:\Windows\System32\win32k.sys
.
============= FINISH:  4:31:42,07 ===============
 

Attached Files


Edited by newt123, 20 November 2013 - 10:38 PM.


BC AdBot (Login to Remove)

 


#2 newt123

newt123
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:08:48 AM

Posted 25 November 2013 - 04:46 AM

Can i get some help please? Anyone? thx :)



#3 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,669 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:48 AM

Posted 25 November 2013 - 10:10 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/514887 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#4 newt123

newt123
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:08:48 AM

Posted 26 November 2013 - 02:27 AM

Im still not sure whether or not i am infected. So getting to the bottom of things would be nice :)
 
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16428
Run by 1 at 8:25:32 on 2013-11-26
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.45.1033.18.6092.3893 [GMT 1:00]
.
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k WbioSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.bing.com?pc=HPNTDF
mWinlogon: Userinit = userinit.exe,
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ips\ipsbho.dll
BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [HPQuickWebProxy] "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{280F13DA-E4AF-4520-96EA-003BFA090D10} : DHCPNameServer = 192.168.0.1
SSODL: WebCheck - <orphaned>
x64-BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\18ghfms5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3306061&CUI=UN21434502115176265&UM=2&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - google.dk
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3306061&SearchSource=2&CUI=UN21434502115176265&UM=2&q=
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll
FF - ExtSQL: 2013-11-18 02:58; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn
FF - ExtSQL: 2013-11-18 03:03; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFF
FF - ExtSQL: 2013-11-18 05:22; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\18ghfms5.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-11-18 20:32; {b9db16a4-6edc-47ec-a1f4-b86292ed211d}; C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\18ghfms5.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-10-15 55856]
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NISx64\1309010.00E\symds64.sys [2013-11-19 451192]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1309010.00E\symefa64.sys [2013-11-19 1129120]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20131114.001\BHDrvx64.sys [2013-11-19 1524824]
R1 ccSet_NIS;Norton Internet Security Settings Manager;C:\Windows\System32\drivers\NISx64\1309010.00E\ccsetx64.sys [2013-11-19 167072]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20131122.001\IDSviA64.sys [2013-11-25 521816]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NISx64\1309010.00E\ironx64.sys [2013-11-19 190072]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\NISx64\1309010.00E\symnets.sys [2013-11-19 405624]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2013-10-10 144152]
R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-9-30 169408]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2011-10-20 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-5-8 203776]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-6-21 85560]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-5-22 103992]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2011-5-27 30520]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-4-8 26680]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-10-20 13592]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-10-20 2375168]
R2 jhi_service;Intel® Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-2-24 212944]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-11-18 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-11-18 701512]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe [2013-11-19 138272]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-10-20 2656280]
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2011-3-8 51712]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys [2010-7-28 31088]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-11-21 137648]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-10-15 317440]
R3 intelkmd;intelkmd;C:\Windows\System32\drivers\igdpmd64.sys [2011-4-15 12228128]
R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\drivers\iwdbus.sys [2011-5-17 25496]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-3-23 77936]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-11-18 25928]
R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2011-5-17 42392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-5-6 263496]
S3 AMPPAL;Intel® Centrino® Bluetooth 3.0 + High Speed Virtual Adapter;C:\Windows\System32\drivers\AmpPal.sys [2011-4-21 294912]
S3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2011-3-8 274944]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2011-3-23 59904]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2013-11-18 111616]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\drivers\intelaud.sys [2011-5-17 34200]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-5-2 340240]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2011-10-20 337512]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-11-18 1255736]
.
=============== Created Last 30 ================
.
2013-11-20 13:56:42    --------    d-----w-    C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-11-20 13:55:40    91352    ----a-w-    C:\Windows\System32\drivers\mbamchameleon.sys
2013-11-20 10:36:26    --------    d-----w-    C:\ProgramData\Sophos
2013-11-20 10:36:15    73728    ----a-r-    C:\Users\1\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe1_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2013-11-20 10:36:15    73728    ----a-r-    C:\Users\1\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2013-11-20 10:36:02    73728    ----a-r-    C:\Users\1\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\ARPPRODUCTICON.exe
2013-11-20 10:35:51    --------    d-----w-    C:\Program Files (x86)\Sophos
2013-11-19 05:09:50    737952    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\srtsp64.sys
2013-11-19 05:09:50    451192    ----a-r-    C:\Windows\System32\drivers\NISx64\1309010.00E\symds64.sys
2013-11-19 05:09:50    405624    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\symnets.sys
2013-11-19 05:09:50    37536    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\srtspx64.sys
2013-11-19 05:09:50    190072    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\ironx64.sys
2013-11-19 05:09:50    1129120    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\symefa64.sys
2013-11-19 05:09:49    167072    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\ccsetx64.sys
2013-11-19 05:09:44    --------    d-----w-    C:\Windows\System32\drivers\NISx64\1309010.00E
2013-11-18 23:10:50    --------    d-----w-    C:\Users\1\AppData\Local\NPE
2013-11-18 21:13:03    99840    ----a-w-    C:\Windows\System32\drivers\usbccgp.sys
2013-11-18 21:13:03    7808    ----a-w-    C:\Windows\System32\drivers\usbd.sys
2013-11-18 21:13:03    52736    ----a-w-    C:\Windows\System32\drivers\usbehci.sys
2013-11-18 21:13:03    343040    ----a-w-    C:\Windows\System32\drivers\usbhub.sys
2013-11-18 21:13:03    325120    ----a-w-    C:\Windows\System32\drivers\usbport.sys
2013-11-18 21:13:03    30720    ----a-w-    C:\Windows\System32\drivers\usbuhci.sys
2013-11-18 21:13:03    25600    ----a-w-    C:\Windows\System32\drivers\usbohci.sys
2013-11-18 21:13:01    1424384    ----a-w-    C:\Windows\System32\WindowsCodecs.dll
2013-11-18 21:13:01    1230336    ----a-w-    C:\Windows\SysWow64\WindowsCodecs.dll
2013-11-18 21:12:48    67072    ----a-w-    C:\Windows\splwow64.exe
2013-11-18 21:12:48    559104    ----a-w-    C:\Windows\System32\spoolsv.exe
2013-11-18 20:22:28    --------    d-----w-    C:\Users\1\AppData\Roaming\IDT
2013-11-18 20:21:56    --------    d-----w-    C:\Users\1\AppData\Local\CrashDumps
2013-11-18 19:32:56    --------    d-----w-    C:\Users\1\dwhelper
2013-11-18 05:27:21    --------    d-----w-    C:\Users\1\AppData\Local\Macromedia
2013-11-18 05:27:02    692616    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe
2013-11-18 04:37:33    --------    d-----w-    C:\Program Files\CCleaner
2013-11-18 04:33:38    --------    d-----w-    C:\Program Files\HitmanPro
2013-11-18 04:32:36    --------    d-----w-    C:\ProgramData\HitmanPro
2013-11-18 04:28:28    --------    d-----w-    C:\Users\1\AppData\Roaming\SUPERAntiSpyware.com
2013-11-18 04:28:02    --------    d-----w-    C:\ProgramData\SUPERAntiSpyware.com
2013-11-18 04:28:02    --------    d-----w-    C:\Program Files\SUPERAntiSpyware
2013-11-18 04:25:39    --------    d-----w-    C:\Users\1\AppData\Roaming\Malwarebytes
2013-11-18 04:25:30    --------    d-----w-    C:\ProgramData\Malwarebytes
2013-11-18 04:25:27    25928    ----a-w-    C:\Windows\System32\drivers\mbam.sys
2013-11-18 04:25:27    --------    d-----w-    C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-18 04:25:02    --------    d-----w-    C:\Users\1\AppData\Local\Programs
2013-11-18 04:01:57    --------    d-----w-    C:\Windows\SysWow64\Wat
2013-11-18 04:01:57    --------    d-----w-    C:\Windows\System32\Wat
2013-11-18 03:21:31    2560    ----a-w-    C:\Windows\System32\drivers\nb-NO\wdf01000.sys.mui
2013-11-18 03:21:31    2560    ----a-w-    C:\Windows\System32\drivers\fi-FI\wdf01000.sys.mui
2013-11-18 03:21:31    2560    ----a-w-    C:\Windows\System32\drivers\da-DK\wdf01000.sys.mui
2013-11-18 03:21:30    2560    ----a-w-    C:\Windows\System32\drivers\sv-SE\wdf01000.sys.mui
2013-11-18 03:21:30    2560    ----a-w-    C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2013-11-18 02:59:35    --------    d-----w-    C:\Program Files (x86)\Common Files\Symantec Shared
2013-11-18 02:46:57    294912    ----a-w-    C:\Windows\System32\browserchoice.exe
2013-11-18 02:37:21    87040    ----a-w-    C:\Windows\System32\drivers\WUDFPf.sys
2013-11-18 02:37:21    84992    ----a-w-    C:\Windows\System32\WUDFSvc.dll
2013-11-18 02:37:21    744448    ----a-w-    C:\Windows\System32\WUDFx.dll
2013-11-18 02:37:21    45056    ----a-w-    C:\Windows\System32\WUDFCoinstaller.dll
2013-11-18 02:37:21    229888    ----a-w-    C:\Windows\System32\WUDFHost.exe
2013-11-18 02:37:21    198656    ----a-w-    C:\Windows\System32\drivers\WUDFRd.sys
2013-11-18 02:37:21    194048    ----a-w-    C:\Windows\System32\WUDFPlatform.dll
2013-11-18 02:33:36    --------    d-----w-    C:\Windows\System32\MRT
2013-11-18 02:31:58    81408    ----a-w-    C:\Windows\System32\imagehlp.dll
2013-11-18 02:31:58    5120    ----a-w-    C:\Windows\SysWow64\wmi.dll
2013-11-18 02:31:58    5120    ----a-w-    C:\Windows\System32\wmi.dll
2013-11-18 02:31:58    23408    ----a-w-    C:\Windows\System32\drivers\fs_rec.sys
2013-11-18 02:31:58    159232    ----a-w-    C:\Windows\SysWow64\imagehlp.dll
2013-11-18 02:27:59    224256    ----a-w-    C:\Windows\System32\wintrust.dll
2013-11-18 02:25:56    245760    ----a-w-    C:\Windows\System32\OxpsConverter.exe
2013-11-18 02:21:04    751104    ----a-w-    C:\Windows\System32\win32spl.dll
2013-11-18 02:21:04    492544    ----a-w-    C:\Windows\SysWow64\win32spl.dll
2013-11-18 02:21:04    404480    ----a-w-    C:\Windows\System32\gdi32.dll
2013-11-18 02:21:04    311808    ----a-w-    C:\Windows\SysWow64\gdi32.dll
2013-11-18 02:21:02    936448    ----a-w-    C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-11-18 02:21:02    1367040    ----a-w-    C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-11-18 02:21:00    5549504    ----a-w-    C:\Windows\System32\ntoskrnl.exe
2013-11-18 02:21:00    3969472    ----a-w-    C:\Windows\SysWow64\ntkrnlpa.exe
2013-11-18 02:21:00    3914176    ----a-w-    C:\Windows\SysWow64\ntoskrnl.exe
2013-11-18 02:19:26    903168    ----a-w-    C:\Windows\SysWow64\certutil.exe
2013-11-18 02:19:26    1192448    ----a-w-    C:\Windows\System32\certutil.exe
2013-11-18 02:19:25    52224    ----a-w-    C:\Windows\System32\certenc.dll
2013-11-18 02:19:25    43008    ----a-w-    C:\Windows\SysWow64\certenc.dll
2013-11-18 02:19:17    690688    ----a-w-    C:\Windows\SysWow64\msvcrt.dll
2013-11-18 02:19:17    634880    ----a-w-    C:\Windows\System32\msvcrt.dll
2013-11-18 02:10:46    --------    d-----w-    C:\Users\1\AppData\Local\Microsoft Games
2013-11-18 02:06:21    461312    ----a-w-    C:\Windows\System32\scavengeui.dll
2013-11-18 02:06:11    859648    ----a-w-    C:\Windows\System32\IKEEXT.DLL
2013-11-18 02:06:11    830464    ----a-w-    C:\Windows\System32\nshwfp.dll
2013-11-18 02:06:11    656896    ----a-w-    C:\Windows\SysWow64\nshwfp.dll
2013-11-18 02:06:11    324096    ----a-w-    C:\Windows\System32\FWPUCLNT.DLL
2013-11-18 02:06:11    216576    ----a-w-    C:\Windows\SysWow64\FWPUCLNT.DLL
2013-11-18 02:04:47    956928    ----a-w-    C:\Windows\System32\localspl.dll
2013-11-18 02:03:39    826880    ----a-w-    C:\Windows\SysWow64\rdpcore.dll
2013-11-18 02:03:39    23552    ----a-w-    C:\Windows\System32\drivers\tdtcp.sys
2013-11-18 02:03:39    1031680    ----a-w-    C:\Windows\System32\rdpcore.dll
2013-11-18 02:00:54    --------    d-----w-    C:\Users\1\AppData\Local\ATI
2013-11-18 01:59:47    --------    d-----w-    C:\Users\1\AppData\Roaming\hpqLog
2013-11-18 01:59:44    --------    d-----w-    C:\Users\1\AppData\Local\Adobe
2013-11-18 01:58:09    --------    d-----w-    C:\Users\1\AppData\Local\RemEngine
2013-11-18 01:57:46    --------    d-----w-    C:\Users\1\AppData\Local\Hewlett-Packard
2013-11-18 01:57:37    --------    d-----w-    C:\Users\1\AppData\Local\Hewlett-Packard_Company
2013-11-18 01:57:23    --------    d-----w-    C:\Users\1\AppData\Local\AuthenTec
2013-11-18 01:56:41    --------    d-----w-    C:\Users\1\AppData\Local\VirtualStore
2013-11-18 01:56:17    2622464    ----a-w-    C:\Windows\System32\wucltux.dll
2013-11-18 01:56:08    99840    ----a-w-    C:\Windows\System32\wudriver.dll
2013-11-18 01:56:08    --------    d-----w-    C:\Users\1\AppData\Roaming\Intel
2013-11-18 01:56:01    36864    ----a-w-    C:\Windows\System32\wuapp.exe
2013-11-18 01:56:01    186752    ----a-w-    C:\Windows\System32\wuwebv.dll
.
==================== Find3M  ====================
.
2013-11-18 15:23:13    175736    ----a-w-    C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2013-11-18 05:27:02    71048    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-18 02:55:35    9728    ---ha-w-    C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-10-05 20:25:35    1474048    ----a-w-    C:\Windows\System32\crypt32.dll
2013-10-05 19:57:25    1168384    ----a-w-    C:\Windows\SysWow64\crypt32.dll
2013-10-04 02:28:31    190464    ----a-w-    C:\Windows\System32\SmartcardCredentialProvider.dll
2013-10-04 02:25:17    197120    ----a-w-    C:\Windows\System32\credui.dll
2013-10-04 02:24:49    1930752    ----a-w-    C:\Windows\System32\authui.dll
2013-10-04 01:58:50    152576    ----a-w-    C:\Windows\SysWow64\SmartcardCredentialProvider.dll
2013-10-04 01:56:25    168960    ----a-w-    C:\Windows\SysWow64\credui.dll
2013-10-04 01:56:00    1796096    ----a-w-    C:\Windows\SysWow64\authui.dll
2013-09-28 01:09:10    497152    ----a-w-    C:\Windows\System32\drivers\afd.sys
2013-09-25 02:26:40    95680    ----a-w-    C:\Windows\System32\drivers\ksecdd.sys
2013-09-25 02:26:40    154560    ----a-w-    C:\Windows\System32\drivers\ksecpkg.sys
2013-09-25 02:23:33    28672    ----a-w-    C:\Windows\System32\sspisrv.dll
2013-09-25 02:23:33    135680    ----a-w-    C:\Windows\System32\sspicli.dll
2013-09-25 02:23:01    28160    ----a-w-    C:\Windows\System32\secur32.dll
2013-09-25 02:22:59    340992    ----a-w-    C:\Windows\System32\schannel.dll
2013-09-25 02:21:50    307200    ----a-w-    C:\Windows\System32\ncrypt.dll
2013-09-25 02:21:07    1447936    ----a-w-    C:\Windows\System32\lsasrv.dll
2013-09-25 01:58:17    96768    ----a-w-    C:\Windows\SysWow64\sspicli.dll
2013-09-25 01:57:26    22016    ----a-w-    C:\Windows\SysWow64\secur32.dll
2013-09-25 01:57:24    247808    ----a-w-    C:\Windows\SysWow64\schannel.dll
2013-09-25 01:56:42    220160    ----a-w-    C:\Windows\SysWow64\ncrypt.dll
2013-09-25 01:03:24    30720    ----a-w-    C:\Windows\System32\lsass.exe
2013-09-08 02:30:37    1903552    ----a-w-    C:\Windows\System32\drivers\tcpip.sys
2013-09-08 02:27:14    327168    ----a-w-    C:\Windows\System32\mswsock.dll
2013-09-08 02:03:58    231424    ----a-w-    C:\Windows\SysWow64\mswsock.dll
2013-08-29 02:16:35    1732032    ----a-w-    C:\Windows\System32\ntdll.dll
2013-08-29 02:16:28    243712    ----a-w-    C:\Windows\System32\wow64.dll
2013-08-29 02:16:14    859648    ----a-w-    C:\Windows\System32\tdh.dll
2013-08-29 02:13:28    878080    ----a-w-    C:\Windows\System32\advapi32.dll
2013-08-29 01:50:31    5120    ----a-w-    C:\Windows\SysWow64\wow32.dll
2013-08-29 01:50:30    1292192    ----a-w-    C:\Windows\SysWow64\ntdll.dll
2013-08-29 01:50:16    619520    ----a-w-    C:\Windows\SysWow64\tdh.dll
2013-08-29 01:48:17    640512    ----a-w-    C:\Windows\SysWow64\advapi32.dll
2013-08-29 01:48:15    44032    ----a-w-    C:\Windows\apppatch\acwow64.dll
2013-08-29 00:49:53    25600    ----a-w-    C:\Windows\SysWow64\setup16.exe
2013-08-29 00:49:52    7680    ----a-w-    C:\Windows\SysWow64\instnm.exe
2013-08-29 00:49:52    14336    ----a-w-    C:\Windows\SysWow64\ntvdm64.dll
2013-08-29 00:49:49    2048    ----a-w-    C:\Windows\SysWow64\user.exe
.
============= FINISH:  8:26:05,85 ===============

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 18-11-2013 02:55:38
System Uptime: 26-11-2013 08:04:28 (0 hours ago)
.
Motherboard: Hewlett-Packard | | 1651
Processor: Intel® Core™ i5-2430M CPU @ 2.40GHz | CPU1 | 2401/1333mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 670 GiB total, 607,533 GiB free.
D: is FIXED (NTFS) - 24 GiB total, 2,544 GiB free.
E: is FIXED (FAT32) - 4 GiB total, 1,082 GiB free.
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP3: 18-11-2013 03:05:33 - Removed Evernote v. 4.2.3
RP4: 18-11-2013 03:08:02 - Windows Live Essentials
RP5: 18-11-2013 03:09:15 - WLSetup
RP6: 18-11-2013 03:14:48 - Removed HP Launch Box
RP7: 18-11-2013 03:29:18 - Windows Update
RP8: 18-11-2013 05:15:06 - Windows Update
RP9: 18-11-2013 05:23:09 - Windows Update
RP10: 18-11-2013 22:15:32 - Windows Update
RP11: 19-11-2013 21:50:04 - Windows Update
RP12: 19-11-2013 22:50:24 - Installed Microsoft Fix it 50123
RP13: 20-11-2013 08:05:55 - Removed Intel® PROSet/Wireless for Bluetooth® 3.0 + High Speed
RP14: 20-11-2013 08:24:00 - Removed Intel® PROSet/Wireless Software for Bluetooth® Technology
RP15: 20-11-2013 11:35:18 - Installed Sophos Virus Removal Tool.
.
==== Installed Programs ======================
.
ActiveX-kontroll för fjärranslutningar för Windows Live Mesh
Adobe AIR
Adobe Community Help
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Adobe Photoshop Elements 9
Adobe Premiere Elements 9
Adobe Reader X MUI
Adobe Shockwave Player 11.5
Agatha Christie - Peril at End House
ALPS Touch Pad Driver
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
ATI Catalyst Install Manager
AuthenTec TrueAPI
Bejeweled 3
Blackhawk Striker 2
Blasterball 3
Bounce Symphony
Cake Mania
Catalyst Control Center
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
Catalyst Control Center Profiles Mobile
ccc-utility64
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
Chronicles of Albian
Chuzzle Deluxe
Cradle of Rome 2
CyberLink YouCam
Elements 9 Organizer
Elements STI Installer
ESU for Microsoft Windows 7 SP1
Farm Frenzy
FATE
Final Drive: Nitro
Governor of Poker 2 Premium Edition
Hewlett-Packard ACLM.NET v1.1.1.0
HitmanPro 3.7
HP 3D DriveGuard
HP Client Services
HP CoolSense
HP Customer Experience Enhancements
HP Documentation
HP Games
HP On Screen Display
HP Power Manager
HP Quick Launch
HP QuickWeb
HP Setup
HP Setup Manager
HP SimplePass 2011
HP Software Framework
HP Support Assistant
IDT Audio
Intel PROSet Wireless
Intel® Control Center
Intel® Display Audio Driver
Intel® Identity Protection Technology 1.1.2.0
Intel® Management Engine Components
Intel® PROSet/Wireless Software for Bluetooth® Technology
Intel® PROSet/Wireless WiFi Software
Intel® Rapid Storage Technology
Intel® WiDi
Intel® Wireless Display
Jewel Quest: The Sleepless Star - Collector's Edition
Mah Jong Medley
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office 2010
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_CRT_x86
Mozilla Firefox 25.0.1 (x86 da)
Mozilla Maintenance Service
Mystery of Mortlake Mansion
Namco All-Stars: PAC-MAN
Norton Internet Security
Penguins!
Plants vs. Zombies - Game of the Year
Poker Superstars III
Polar Bowler
Polar Golfer
PX Profile Update
Realtek PCIE Card Reader
Recovery Manager
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)
Slingo Supreme
SmartSound Quicktracks for Premiere Elements 9.0
Sophos Virus Removal Tool
SUPERAntiSpyware
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3)
Update Installer for WildTangent Games App
Vacation Quest - The Hawaiian Islands
Validity WBF DDK
VIP Access SDK (1.0.1.2)
Virtual Villagers 5 - New Believers
WildTangent Games App (HP Games)
Windows Live Fotogalleri
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger
Windows Live Mesh ActiveX-objekt til fjernforbindelser
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Meshin etäyhteyksien ActiveX-komponentti
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live Remote Client Resources
Windows Live Remote Service Resources
Windows Live Writer
Windows Live Writer Resources
Windows Liven sähköposti
Windows Liven valokuvavalikoima
Zuma Deluxe
.
==== Event Viewer Messages From Past Week ========
.
26-11-2013 08:05:32, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
26-11-2013 08:05:32, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-1073473535.
26-11-2013 08:05:09, Error: Service Control Manager [7034] - The TrueSuiteService service terminated unexpectedly. It has done this 1 time(s).
20-11-2013 06:43:10, Error: Service Control Manager [7034] - The Bluetooth OBEX Service service terminated unexpectedly. It has done this 1 time(s).
20-11-2013 06:05:30, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
20-11-2013 06:05:30, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
20-11-2013 06:05:30, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
.
==== End Of File ===========================

Attached Files


Edited by Oh My, 01 December 2013 - 10:52 PM.
Reopened at member's request. ~ OB


#5 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,801 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:48 PM

Posted 01 December 2013 - 10:59 PM

Greetings newt123 and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that. :thumbup2:

===================================================

Ground Rules:

  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met. :)
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
  • Now let's get started :thumbup2:

===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far.
 

A few days ago i did a full system reboot

Can you explain exactly what this means.

 

Please run these programs for me.

===================================================

AdwCleaner by Xplode - Delete Adware

-------------------

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browser
  • Double click on AdwCleaner.exe, select OK, then Run
  • Click on Delete
  • Confirm each time with OK
  • Your computer will be rebooted automatically. A text file will open after the restart
  • Copy and paste the contents in your reply
  • You can find the logfile at C:\AdwCleaner[S1].txt

===================================================

Junkware Removal Tool by thisisu

-------------------

  • Please download Junkware Removal Tool and save it to your desktop.
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Right-mouse click JRT.exe and select Run as administrator (Windows XP double click the icon)
  • Please allow the program time to run
  • Once completed a Notepad document will open on your desktop
  • Copy and paste the contents in your reply

===================================================

Farbar Recovery Scan Tool (FRST)

--------------------

  • Download Farbar Recover Scan Tool for either 32 bit or 64 bit systems and save it to your desktop
  • If you are unsure if you have 32 bit or 64 bit simply download and try one. If that doesn't run properly the other one should
  • Double click the icon
  • Click Yes to the disclaimer
  • Click Scan and allow the program to run
  • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
  • 2 Notepad documents should now be open on your desktop.
  • Please copy and paste the contents of both in your reply

===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:

  • AdwCleaner log
  • Junkware log
  • Farbar logs (2)

Edited by Oh My, 01 December 2013 - 11:00 PM.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#6 newt123

newt123
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:08:48 AM

Posted 02 December 2013 - 06:17 AM

Sorry i didnt mean system reboot. I mean, i re-installed windows completely so everything on my pc was clean. I ran the programs like you said. When i ran JRT the first time i ran it without administrator and the log showed something. I then ran it again as an administrator and it showed like below. Eversince i've had the bluetooth issue i removed it. I want to point out that bluetooth was set to run on start up, if that should be of any importance to you :) the logs are below.

 

 

# AdwCleaner v3.014 - Report created 02/12/2013 at 11:11:03
# Updated 01/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : 1 - 1-HP
# Running from : C:\Users\1\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\boost_interprocess

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428


-\\ Mozilla Firefox v25.0.1 (da)

[ File : C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\18ghfms5.default\prefs.js ]

Line Deleted : user_pref("CT3306061.FF19Solved", "true");
Line Deleted : user_pref("CT3306061.UserID", "UN21434502115176265");
Line Deleted : user_pref("CT3306061.browser.search.defaultthis.engineName", "true");
Line Deleted : user_pref("CT3306061.fullUserID", "UN21434502115176265.IN.20131120083409");
Line Deleted : user_pref("CT3306061.installDate", "20/11/2013 08:34:12");
Line Deleted : user_pref("CT3306061.installSessionId", "{FBA54419-59CA-4C66-A294-661293158E6F}");
Line Deleted : user_pref("CT3306061.installSp", "TRUE");
Line Deleted : user_pref("CT3306061.installerVersion", "1.8.1.4");
Line Deleted : user_pref("CT3306061.keyword", "true");
Line Deleted : user_pref("CT3306061.originalHomepage", "hxxp://www.ethjerteforalle.dk/");
Line Deleted : user_pref("CT3306061.originalSearchAddressUrl", "");
Line Deleted : user_pref("CT3306061.originalSearchEngine", "");
Line Deleted : user_pref("CT3306061.originalSearchEngineName", "");
Line Deleted : user_pref("CT3306061.searchRevert", "true");
Line Deleted : user_pref("CT3306061.searchUninstallUserMode", "2");
Line Deleted : user_pref("CT3306061.searchUserMode", "2");
Line Deleted : user_pref("CT3306061.smartbar.homepage", "true");
Line Deleted : user_pref("CT3306061.toolbarInstallDate", "20-11-2013 08:34:09");
Line Deleted : user_pref("CT3306061.versionFromInstaller", "10.22.3.18");
Line Deleted : user_pref("CT3306061.xpeMode", "0");
Line Deleted : user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3306061&octid=CT3306061&SearchSource=61&CUI=UN21434502115176265&UM=2&UP=SPD1B9B4F9-F960-4895-AF2C-ACEF923DF994");
Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
Line Deleted : user_pref("browser.search.defaultthis.engineName", "Connect DLC 5 Customized Web Search");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3306061&CUI=UN21434502115176265&UM=2&SearchSource=3&q={searchTerms}");
Line Deleted : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3306061&SearchSource=2&CUI=UN21434502115176265&UM=2&q=");
Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3306061");
Line Deleted : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3306061&CUI=UN21434502115176265&UM=2&SearchSource=13,hxxp://search.conduit.com/?ctid=CT3306061&octid=CT3306061&SearchSource[...]
Line Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3306061&SearchSource=2&CUI=UN21434502115176265&UM=2&q=");
Line Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT3306061");
Line Deleted : user_pref("smartbar.homePageOwnerCTID", "CT3306061");
Line Deleted : user_pref("smartbar.machineId", "CGFYU8I+CN1UTS35CGEZPR+G37VMCE3SJ0MFQODVABZDLUU7RJRVVVQD4UV7LSQOQ62PU+/HABFUARIDALJWJG");
Line Deleted : user_pref("smartbar.originalHomepage", "hxxp://search.conduit.com/?ctid=CT3306061&CUI=UN21434502115176265&UM=2&SearchSource=13");

[ File : C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\18ghfms5.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [8156 octets] - [02/12/2013 11:08:57]
AdwCleaner[S0].txt - [4843 octets] - [02/12/2013 11:11:03]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4903 octets] ##########
 

 

 

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by 1 on 02-12-2013 at 11:58:53,50
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 02-12-2013 at 12:04:47,14
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-12-2013
Ran by 1 (administrator) on 1-HP on 02-12-2013 12:07:34
Running from C:\Users\1\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [IntelPAN] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel® Corporation)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-05-27] (IDT, Inc.)
HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [569200 2011-02-19] (Alps Electric Co., Ltd.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [497648 2010-07-29] (Adobe Systems Incorporated)
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\sysWOW64\userinit.exe [26624 2010-11-21] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6604568 2013-11-05] (SUPERAntiSpyware)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-05-08] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [HPQuickWebProxy] - C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [168504 2011-06-28] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586808 2011-04-08] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HPOSD] - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [336440 2011-06-14] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP CoolSense] - C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1342008 2011-05-31] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDF
SearchScopes: HKLM - {3DA3F049-FA75-4EC7-A65E-77435B9FF82D} URL = http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ips\ipsbho.dll (Symantec Corporation)
BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll (Symantec Corporation)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\18ghfms5.default
FF Homepage: google.dk
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazon-co-uk.xml
FF Extension: DownloadHelper - C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\18ghfms5.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: Adblock Plus - C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\18ghfms5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFF
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn\

==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe [138272 2012-06-16] (Symantec Corporation)

==================== Drivers (Whitelisted) ====================

R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20131114.001\BHDrvx64.sys [1524824 2013-11-01] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1309010.00E\ccSetx64.sys [167072 2012-06-07] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-21] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-21] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20131128.001\IDSvia64.sys [521816 2013-11-15] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20131201.021\ENG64.SYS [126040 2013-11-28] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20131201.021\EX64.SYS [2099288 2013-11-28] (Symantec Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1309010.00E\SRTSP64.SYS [737952 2012-07-06] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1309010.00E\SRTSPX64.SYS [37536 2012-07-06] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1309010.00E\SYMDS64.SYS [451192 2011-05-16] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1309010.00E\SYMEFA64.SYS [1129120 2012-05-22] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [175736 2013-11-18] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1309010.00E\Ironx64.SYS [190072 2012-04-18] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1309010.00E\SYMNETS.SYS [405624 2012-04-18] (Symantec Corporation)
S3 clwvd; system32\DRIVERS\clwvd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-02 12:07 - 2013-12-02 12:08 - 00013021 _____ C:\Users\1\Desktop\FRST.txt
2013-12-02 12:07 - 2013-12-02 12:07 - 00000000 ____D C:\FRST
2013-12-02 12:04 - 2013-12-02 12:04 - 00000621 _____ C:\Users\1\Desktop\JRT.txt
2013-12-02 11:19 - 2013-12-02 11:19 - 00000000 ____D C:\Windows\ERUNT
2013-12-02 11:08 - 2013-12-02 11:15 - 00000000 ____D C:\AdwCleaner
2013-12-02 11:06 - 2013-12-02 11:06 - 01959184 _____ (Farbar) C:\Users\1\Desktop\FRST64.exe
2013-12-02 11:05 - 2013-12-02 11:05 - 01110034 _____ C:\Users\1\Desktop\AdwCleaner.exe
2013-12-02 11:05 - 2013-12-02 11:05 - 01034531 _____ (Thisisu) C:\Users\1\Desktop\JRT.exe
2013-12-01 16:26 - 2013-12-02 11:26 - 00000224 _____ C:\Windows\setupact.log
2013-12-01 16:26 - 2013-12-01 16:26 - 00000000 _____ C:\Windows\setuperr.log
2013-12-01 16:21 - 2013-12-01 16:21 - 00000000 ____D C:\Users\1\AppData\Local\HP
2013-12-01 10:28 - 2013-12-01 10:28 - 00000000 ____D C:\Users\1\AppData\Roaming\Symantec
2013-11-28 13:04 - 2013-12-01 23:26 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-28 13:04 - 2013-11-28 13:04 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-11-28 13:04 - 2013-11-28 13:04 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-28 13:04 - 2013-11-28 13:04 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-11-28 12:43 - 2013-11-28 12:43 - 00000000 ____D C:\ProgramData\F-Secure
2013-11-27 12:33 - 2013-11-27 12:33 - 00059096 _____ C:\Users\1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-26 21:46 - 2013-11-26 21:46 - 00762252 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-11-26 20:47 - 2013-11-26 20:47 - 00001155 _____ C:\Users\1\Desktop\Free M4a to MP3 Converter.lnk
2013-11-26 20:47 - 2013-11-26 20:47 - 00000000 ____D C:\Program Files (x86)\Free M4a to MP3 Converter
2013-11-26 20:30 - 2013-11-26 20:30 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2013-11-26 20:28 - 2013-12-02 11:50 - 00000000 ____D C:\Users\1\Desktop\Nature Sounds
2013-11-26 13:06 - 2013-11-26 13:06 - 00000000 ____D C:\Users\1\.oces2
2013-11-26 13:05 - 2013-11-26 13:05 - 00000000 ____D C:\ProgramData\Sun
2013-11-26 13:04 - 2013-11-26 13:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-11-26 13:04 - 2013-11-26 13:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-11-26 13:04 - 2013-11-26 13:04 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-11-26 13:04 - 2013-11-26 13:04 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-26 13:04 - 2013-11-26 13:04 - 00000000 ____D C:\Program Files (x86)\Java
2013-11-26 13:04 - 2013-11-26 13:03 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-11-26 13:04 - 2013-11-26 13:03 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-11-26 13:04 - 2013-11-26 13:03 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-11-26 13:04 - 2013-11-26 13:03 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-11-26 13:03 - 2013-11-26 13:03 - 00000000 ____D C:\Program Files\Java
2013-11-26 11:31 - 2013-11-26 11:31 - 00000000 ____D C:\edudata
2013-11-20 14:56 - 2013-11-20 15:38 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-11-20 14:55 - 2013-11-20 14:56 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-11-20 11:36 - 2013-11-20 11:36 - 00000000 ____D C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sophos
2013-11-20 11:36 - 2013-11-20 11:36 - 00000000 ____D C:\ProgramData\Sophos
2013-11-20 11:35 - 2013-11-20 11:35 - 00000000 ____D C:\Program Files (x86)\Sophos
2013-11-19 22:30 - 2013-11-21 09:25 - 00000000 ___RD C:\Users\1\Desktop\Virus Detection
2013-11-19 21:46 - 2013-11-26 20:56 - 00000166 _____ C:\Windows\SysWOW64\DOErrors.log
2013-11-19 21:41 - 2013-11-19 21:41 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security
2013-11-19 12:45 - 2013-11-19 12:45 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-11-19 12:45 - 2013-11-19 12:45 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-11-19 00:10 - 2013-11-20 12:38 - 00000000 ____D C:\Users\1\AppData\Local\NPE
2013-11-18 22:22 - 2013-11-18 22:41 - 00000000 ____D C:\Users\1\Desktop\Wallpapers
2013-11-18 22:13 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-11-18 22:13 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-11-18 22:13 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-11-18 22:13 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-11-18 22:13 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-11-18 22:13 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-11-18 22:13 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-11-18 22:13 - 2013-04-17 08:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-11-18 22:13 - 2013-04-17 07:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2013-11-18 22:12 - 2012-02-11 07:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2013-11-18 22:12 - 2012-02-11 07:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
2013-11-18 21:22 - 2013-11-18 21:22 - 00000000 ____D C:\Users\1\AppData\Roaming\IDT
2013-11-18 21:21 - 2013-11-26 11:33 - 00000000 ____D C:\Users\1\AppData\Local\CrashDumps
2013-11-18 20:32 - 2013-11-18 20:32 - 00000000 ____D C:\Users\1\dwhelper
2013-11-18 18:49 - 2013-11-27 18:19 - 00000008 _____ C:\Users\1\Desktop\Kcal.txt
2013-11-18 06:27 - 2013-11-18 06:27 - 00000000 ____D C:\Users\1\AppData\Local\Macromedia
2013-11-18 06:26 - 2013-11-18 06:26 - 00000000 ____D C:\Windows\system32\Macromed
2013-11-18 05:37 - 2013-11-18 05:37 - 00002764 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-11-18 05:37 - 2013-11-18 05:37 - 00000000 ____D C:\Program Files\CCleaner
2013-11-18 05:35 - 2013-11-18 05:35 - 00000000 ____D C:\Users\1\Desktop\Uni
2013-11-18 05:33 - 2013-11-18 05:33 - 00000000 ____D C:\Program Files\HitmanPro
2013-11-18 05:32 - 2013-11-20 10:47 - 00000000 ____D C:\ProgramData\HitmanPro
2013-11-18 05:28 - 2013-12-01 21:28 - 00000502 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 625d7d2f-53de-47a7-9e83-3bc3be1f86b5.job
2013-11-18 05:28 - 2013-11-18 05:38 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-11-18 05:28 - 2013-11-18 05:28 - 00003486 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 625d7d2f-53de-47a7-9e83-3bc3be1f86b5
2013-11-18 05:28 - 2013-11-18 05:28 - 00000000 ____D C:\Users\1\AppData\Roaming\SUPERAntiSpyware.com
2013-11-18 05:28 - 2013-11-18 05:28 - 00000000 ____D C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2013-11-18 05:28 - 2013-11-18 05:28 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-11-18 05:26 - 2013-11-18 05:26 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-18 05:26 - 2013-11-18 05:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-18 05:26 - 2013-11-18 05:26 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-18 05:26 - 2013-11-18 05:26 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-18 05:26 - 2013-11-18 05:26 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-18 05:26 - 2013-11-18 05:26 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-18 05:26 - 2013-11-18 05:26 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-18 05:26 - 2013-11-18 05:26 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-18 05:26 - 2013-11-18 05:26 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-18 05:26 - 2013-11-18 05:26 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-18 05:26 - 2013-11-18 05:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-18 05:25 - 2013-11-18 05:25 - 00000000 ____D C:\Users\1\AppData\Roaming\Malwarebytes
2013-11-18 05:25 - 2013-11-18 05:25 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-18 05:25 - 2013-11-18 05:25 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-18 05:25 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-18 05:21 - 2013-11-18 18:01 - 00000000 ____D C:\Users\1\AppData\Local\Mozilla
2013-11-18 05:21 - 2013-11-18 05:21 - 00000000 ____D C:\Users\1\AppData\Roaming\Mozilla
2013-11-18 05:21 - 2013-11-18 05:21 - 00000000 ____D C:\ProgramData\Mozilla
2013-11-18 05:21 - 2013-11-18 05:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-18 05:21 - 2013-11-18 05:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-18 05:12 - 2013-11-25 11:14 - 00000000 ____D C:\Users\1\AppData\Roaming\Adobe
2013-11-18 05:12 - 2013-11-18 05:12 - 00003520 _____ C:\Windows\System32\Tasks\CreateChoiceProcessTask
2013-11-18 03:55 - 2013-11-18 03:55 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-11-18 03:46 - 2010-02-23 09:16 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe
2013-11-18 03:37 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2013-11-18 03:37 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2013-11-18 03:37 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2013-11-18 03:37 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2013-11-18 03:37 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2013-11-18 03:37 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2013-11-18 03:37 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2013-11-18 03:37 - 2012-06-02 15:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2013-11-18 03:33 - 2013-11-18 03:34 - 00000000 ____D C:\Windows\system32\MRT
2013-11-18 03:33 - 2013-11-07 16:00 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-18 03:31 - 2012-03-01 07:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2013-11-18 03:31 - 2012-03-01 07:33 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-11-18 03:31 - 2012-03-01 07:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2013-11-18 03:31 - 2012-03-01 06:33 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-11-18 03:31 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2013-11-18 03:28 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-18 03:28 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-18 03:28 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-18 03:28 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-18 03:28 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-18 03:28 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-18 03:28 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-18 03:28 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-18 03:28 - 2013-07-19 02:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-11-18 03:28 - 2013-07-19 02:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-11-18 03:28 - 2013-07-09 06:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-11-18 03:28 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-11-18 03:28 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-11-18 03:28 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-11-18 03:28 - 2013-04-12 15:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2013-11-18 03:28 - 2013-02-27 07:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2013-11-18 03:28 - 2013-02-27 06:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2013-11-18 03:28 - 2013-02-15 07:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2013-11-18 03:28 - 2013-02-15 07:06 - 03717632 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-11-18 03:28 - 2013-02-15 07:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2013-11-18 03:28 - 2013-02-15 05:37 - 03217408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-11-18 03:28 - 2013-02-15 05:34 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-11-18 03:28 - 2013-02-15 04:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-11-18 03:28 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2013-11-18 03:28 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2013-11-18 03:28 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2013-11-18 03:28 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2013-11-18 03:28 - 2011-04-09 07:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2013-11-18 03:28 - 2011-04-09 06:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2013-11-18 03:27 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-18 03:27 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-11-18 03:27 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-11-18 03:27 - 2013-08-02 03:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-11-18 03:27 - 2013-08-02 03:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-11-18 03:27 - 2013-08-02 02:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-11-18 03:27 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-11-18 03:27 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-11-18 03:27 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-11-18 03:27 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-11-18 03:27 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-11-18 03:27 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-11-18 03:27 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-11-18 03:27 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-11-18 03:27 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-11-18 03:27 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-11-18 03:27 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-11-18 03:27 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-11-18 03:27 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-11-18 03:27 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-11-18 03:27 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-11-18 03:27 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-11-18 03:27 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-11-18 03:27 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-11-18 03:27 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-11-18 03:27 - 2013-04-26 00:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-11-18 03:27 - 2013-03-31 23:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-11-18 03:27 - 2013-03-19 06:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-11-18 03:27 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2013-11-18 03:27 - 2013-02-12 05:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2013-11-18 03:27 - 2012-11-30 06:45 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-11-18 03:27 - 2012-11-30 06:45 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-11-18 03:27 - 2012-11-30 06:43 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-11-18 03:27 - 2012-11-30 00:17 - 00420064 _____ C:\Windows\SysWOW64\locale.nls
2013-11-18 03:27 - 2012-11-30 00:15 - 00420064 _____ C:\Windows\system32\locale.nls
2013-11-18 03:27 - 2012-10-03 18:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2013-11-18 03:27 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2013-11-18 03:27 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2013-11-18 03:27 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2013-11-18 03:27 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2013-11-18 03:27 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2013-11-18 03:27 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2013-11-18 03:27 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2013-11-18 03:27 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2013-11-18 03:27 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2013-11-18 03:27 - 2012-04-26 06:41 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2013-11-18 03:27 - 2012-04-26 06:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2013-11-18 03:27 - 2012-04-26 06:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2013-11-18 03:27 - 2012-01-13 08:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2013-11-18 03:27 - 2012-01-04 11:44 - 00509952 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2013-11-18 03:27 - 2012-01-04 09:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2013-11-18 03:27 - 2011-12-30 07:26 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2013-11-18 03:27 - 2011-12-30 06:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
2013-11-18 03:27 - 2011-11-17 07:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2013-11-18 03:27 - 2011-11-17 06:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2013-11-18 03:27 - 2011-10-26 06:25 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2013-11-18 03:27 - 2011-10-26 06:25 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2013-11-18 03:27 - 2011-10-26 05:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2013-11-18 03:27 - 2011-10-26 05:32 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2013-11-18 03:26 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-18 03:26 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-18 03:26 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-18 03:26 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-18 03:26 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-18 03:26 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-18 03:26 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-18 03:26 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-18 03:26 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-18 03:26 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-18 03:26 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-18 03:26 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-18 03:26 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-18 03:26 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-11-18 03:26 - 2013-07-26 03:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-11-18 03:26 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-11-18 03:26 - 2013-07-26 02:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-11-18 03:26 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-11-18 03:26 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-18 03:26 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-11-18 03:26 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2013-11-18 03:26 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2013-11-18 03:26 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2013-11-18 03:26 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2013-11-18 03:26 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2013-11-18 03:26 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2013-11-18 03:26 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2013-11-18 03:26 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2013-11-18 03:26 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2013-11-18 03:26 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2013-11-18 03:26 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2013-11-18 03:26 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2013-11-18 03:26 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2013-11-18 03:26 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2013-11-18 03:26 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2013-11-18 03:26 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2013-11-18 03:26 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2013-11-18 03:26 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2013-11-18 03:26 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
2013-11-18 03:26 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
2013-11-18 03:26 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
2013-11-18 03:26 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2013-11-18 03:26 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2013-11-18 03:26 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
2013-11-18 03:26 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2013-11-18 03:26 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
2013-11-18 03:26 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
2013-11-18 03:26 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
2013-11-18 03:26 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2013-11-18 03:26 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2013-11-18 03:26 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
2013-11-18 03:26 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
2013-11-18 03:26 - 2012-11-28 23:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2013-11-18 03:26 - 2012-11-28 23:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2013-11-18 03:26 - 2012-11-28 23:56 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2013-11-18 03:26 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2013-11-18 03:26 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2013-11-18 03:25 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-11-18 03:25 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-11-18 03:25 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-11-18 03:25 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-11-18 03:25 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-11-18 03:25 - 2013-07-09 06:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-11-18 03:25 - 2013-07-09 05:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-11-18 03:25 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2013-11-18 03:25 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2013-11-18 03:25 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2013-11-18 03:25 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2013-11-18 03:25 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2013-11-18 03:25 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-11-18 03:25 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-11-18 03:25 - 2013-06-15 05:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-11-18 03:25 - 2013-06-04 07:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-11-18 03:25 - 2013-06-04 05:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-11-18 03:25 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-11-18 03:25 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-11-18 03:25 - 2012-11-22 06:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2013-11-18 03:25 - 2012-11-22 05:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2013-11-18 03:25 - 2012-11-02 06:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2013-11-18 03:25 - 2012-11-02 06:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2013-11-18 03:25 - 2012-11-01 06:43 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2013-11-18 03:25 - 2012-11-01 06:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2013-11-18 03:25 - 2012-11-01 05:47 - 01389568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2013-11-18 03:25 - 2012-11-01 05:47 - 01236992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2013-11-18 03:25 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2013-11-18 03:25 - 2012-05-01 06:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2013-11-18 03:25 - 2012-04-28 04:55 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2013-11-18 03:25 - 2011-08-17 06:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2013-11-18 03:25 - 2011-08-17 06:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2013-11-18 03:25 - 2011-08-17 05:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2013-11-18 03:25 - 2011-08-17 05:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2013-11-18 03:25 - 2010-06-26 04:55 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2013-11-18 03:25 - 2010-06-26 04:24 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2013-11-18 03:21 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-18 03:21 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-18 03:21 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-11-18 03:21 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-11-18 03:21 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-11-18 03:21 - 2013-04-26 06:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-11-18 03:21 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-11-18 03:20 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-11-18 03:20 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-11-18 03:20 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-11-18 03:20 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-11-18 03:20 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-11-18 03:20 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-11-18 03:20 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-11-18 03:20 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-11-18 03:20 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-11-18 03:20 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-11-18 03:20 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-11-18 03:20 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-11-18 03:20 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-11-18 03:20 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-11-18 03:20 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2013-11-18 03:20 - 2013-01-03 07:00 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2013-11-18 03:20 - 2012-11-23 04:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2013-11-18 03:20 - 2012-09-25 23:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2013-11-18 03:20 - 2012-09-25 23:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2013-11-18 03:20 - 2012-08-22 19:12 - 00376688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2013-11-18 03:20 - 2012-08-11 01:56 - 00715776 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2013-11-18 03:20 - 2012-08-11 00:56 - 00542208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2013-11-18 03:20 - 2012-07-06 21:07 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2013-11-18 03:20 - 2012-07-04 23:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2013-11-18 03:20 - 2012-07-04 23:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2013-11-18 03:20 - 2012-07-04 23:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2013-11-18 03:20 - 2012-07-04 22:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2013-11-18 03:20 - 2012-07-04 22:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2013-11-18 03:20 - 2012-05-05 09:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2013-11-18 03:20 - 2012-05-05 08:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2013-11-18 03:20 - 2012-04-07 13:31 - 03216384 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2013-11-18 03:20 - 2012-04-07 12:26 - 02342400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2013-11-18 03:20 - 2012-03-17 08:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2013-11-18 03:19 - 2013-05-13 06:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-11-18 03:19 - 2013-05-13 04:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-11-18 03:19 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-11-18 03:19 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-11-18 03:19 - 2011-12-16 09:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2013-11-18 03:19 - 2011-12-16 08:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2013-11-18 03:10 - 2013-11-18 03:11 - 00000000 ____D C:\Users\1\AppData\Local\Microsoft Games
2013-11-18 03:06 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-18 03:06 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-18 03:06 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-18 03:06 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-18 03:06 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-18 03:06 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2013-11-18 03:05 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-11-18 03:05 - 2013-04-10 07:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2013-11-18 03:05 - 2012-06-06 07:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2013-11-18 03:05 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2013-11-18 03:05 - 2011-11-19 15:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2013-11-18 03:05 - 2011-11-19 15:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2013-11-18 03:05 - 2011-10-15 07:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2013-11-18 03:05 - 2011-10-15 06:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2013-11-18 03:05 - 2011-08-27 06:37 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2013-11-18 03:05 - 2011-08-27 06:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2013-11-18 03:05 - 2011-08-27 05:26 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2013-11-18 03:05 - 2011-08-27 05:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2013-11-18 03:05 - 2011-02-03 12:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-11-18 03:04 - 2012-05-14 06:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2013-11-18 03:03 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2013-11-18 03:03 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2013-11-18 03:03 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2013-11-18 03:02 - 2013-11-28 08:47 - 00000000 ____D C:\Users\1\AppData\Roaming\hewlett-packard
2013-11-18 03:02 - 2013-11-18 03:02 - 00003804 _____ C:\Windows\System32\Tasks\SetupManager
2013-11-18 03:00 - 2013-11-18 03:00 - 00000000 ____D C:\Users\1\AppData\Roaming\ATI
2013-11-18 03:00 - 2013-11-18 03:00 - 00000000 ____D C:\Users\1\AppData\Local\ATI
2013-11-18 02:59 - 2013-11-28 13:03 - 00000000 ____D C:\Users\1\AppData\Local\Adobe
2013-11-18 02:59 - 2013-11-18 02:59 - 00000000 ____D C:\Users\1\AppData\Roaming\hpqLog
2013-11-18 02:58 - 2013-12-02 11:46 - 00003894 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{987991BD-132D-4F5C-A990-25A162D30BB7}
2013-11-18 02:58 - 2013-11-28 08:48 - 00003692 _____ C:\Windows\System32\Tasks\Registration
2013-11-18 02:58 - 2013-11-20 09:01 - 00000000 ___RD C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-18 02:58 - 2013-11-18 05:48 - 00001417 _____ C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-18 02:58 - 2013-11-18 05:12 - 00000000 ___RD C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-18 02:58 - 2013-11-18 02:58 - 00000000 ____D C:\Users\1\AppData\Local\RemEngine
2013-11-18 02:57 - 2013-11-28 08:47 - 00000000 ____D C:\Users\1\AppData\Local\Hewlett-Packard
2013-11-18 02:57 - 2013-11-18 03:02 - 00000000 ____D C:\Users\1\AppData\Local\Hewlett-Packard_Company
2013-11-18 02:57 - 2013-11-18 02:57 - 00000000 ____D C:\Users\1\AppData\Local\AuthenTec
2013-11-18 02:56 - 2013-11-19 22:14 - 00000000 ____D C:\Users\1\AppData\Local\VirtualStore
2013-11-18 02:56 - 2013-11-18 02:56 - 00000000 ____D C:\Users\1\AppData\Roaming\Intel
2013-11-18 02:56 - 2012-06-02 23:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2013-11-18 02:56 - 2012-06-02 23:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2013-11-18 02:56 - 2012-06-02 23:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2013-11-18 02:56 - 2012-06-02 23:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2013-11-18 02:56 - 2012-06-02 23:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2013-11-18 02:56 - 2012-06-02 23:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2013-11-18 02:56 - 2012-06-02 23:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2013-11-18 02:56 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2013-11-18 02:56 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2013-11-18 02:55 - 2013-11-30 13:34 - 00000000 ____D C:\Users\1
2013-11-18 02:55 - 2013-11-18 02:55 - 00000020 ___SH C:\Users\1\ntuser.ini
2013-11-18 02:55 - 2011-10-15 06:19 - 00000000 ____D C:\Users\1\AppData\Roaming\Macromedia
2013-11-18 02:55 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-18 02:55 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

==================== One Month Modified Files and Folders =======

2013-12-02 12:08 - 2013-12-02 12:07 - 00013021 _____ C:\Users\1\Desktop\FRST.txt
2013-12-02 12:07 - 2013-12-02 12:07 - 00000000 ____D C:\FRST
2013-12-02 12:04 - 2013-12-02 12:04 - 00000621 _____ C:\Users\1\Desktop\JRT.txt
2013-12-02 11:50 - 2013-11-26 20:28 - 00000000 ____D C:\Users\1\Desktop\Nature Sounds
2013-12-02 11:46 - 2013-11-18 02:58 - 00003894 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{987991BD-132D-4F5C-A990-25A162D30BB7}
2013-12-02 11:33 - 2009-07-14 05:45 - 00032064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-02 11:33 - 2009-07-14 05:45 - 00032064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-02 11:31 - 2009-07-14 06:13 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-02 11:29 - 2011-10-20 21:16 - 01834829 _____ C:\Windows\WindowsUpdate.log
2013-12-02 11:26 - 2013-12-01 16:26 - 00000224 _____ C:\Windows\setupact.log
2013-12-02 11:26 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-02 11:19 - 2013-12-02 11:19 - 00000000 ____D C:\Windows\ERUNT
2013-12-02 11:15 - 2013-12-02 11:08 - 00000000 ____D C:\AdwCleaner
2013-12-02 11:06 - 2013-12-02 11:06 - 01959184 _____ (Farbar) C:\Users\1\Desktop\FRST64.exe
2013-12-02 11:05 - 2013-12-02 11:05 - 01110034 _____ C:\Users\1\Desktop\AdwCleaner.exe
2013-12-02 11:05 - 2013-12-02 11:05 - 01034531 _____ (Thisisu) C:\Users\1\Desktop\JRT.exe
2013-12-01 23:26 - 2013-11-28 13:04 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-01 21:28 - 2013-11-18 05:28 - 00000502 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 625d7d2f-53de-47a7-9e83-3bc3be1f86b5.job
2013-12-01 16:26 - 2013-12-01 16:26 - 00000000 _____ C:\Windows\setuperr.log
2013-12-01 16:25 - 2011-10-20 21:32 - 00000000 ____D C:\Program Files (x86)\HP SimplePass 2011
2013-12-01 16:21 - 2013-12-01 16:21 - 00000000 ____D C:\Users\1\AppData\Local\HP
2013-12-01 10:28 - 2013-12-01 10:28 - 00000000 ____D C:\Users\1\AppData\Roaming\Symantec
2013-11-30 13:34 - 2013-11-18 02:55 - 00000000 ____D C:\Users\1
2013-11-28 13:04 - 2013-11-28 13:04 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-11-28 13:04 - 2013-11-28 13:04 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-28 13:04 - 2013-11-28 13:04 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-11-28 13:03 - 2013-11-18 02:59 - 00000000 ____D C:\Users\1\AppData\Local\Adobe
2013-11-28 12:59 - 2011-10-15 06:16 - 00000000 ____D C:\ProgramData\Adobe
2013-11-28 12:59 - 2011-10-15 06:16 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-11-28 12:43 - 2013-11-28 12:43 - 00000000 ____D C:\ProgramData\F-Secure
2013-11-28 08:48 - 2013-11-18 02:58 - 00003692 _____ C:\Windows\System32\Tasks\Registration
2013-11-28 08:47 - 2013-11-18 03:02 - 00000000 ____D C:\Users\1\AppData\Roaming\hewlett-packard
2013-11-28 08:47 - 2013-11-18 02:57 - 00000000 ____D C:\Users\1\AppData\Local\Hewlett-Packard
2013-11-27 18:19 - 2013-11-18 18:49 - 00000008 _____ C:\Users\1\Desktop\Kcal.txt
2013-11-27 12:33 - 2013-11-27 12:33 - 00059096 _____ C:\Users\1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-26 21:46 - 2013-11-26 21:46 - 00762252 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-11-26 21:31 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-11-26 21:25 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2013-11-26 21:25 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
2013-11-26 21:25 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2013-11-26 21:25 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-11-26 21:24 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\winrm
2013-11-26 21:24 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\WCN
2013-11-26 21:24 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\slmgr
2013-11-26 21:24 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2013-11-26 21:24 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-11-26 21:24 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-11-26 21:24 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\DVD Maker
2013-11-26 21:24 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\MUI
2013-11-26 21:24 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
2013-11-26 21:24 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2013-11-26 21:24 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\servicing
2013-11-26 21:24 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\System
2013-11-26 21:23 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\winrm
2013-11-26 21:23 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\WCN
2013-11-26 21:23 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\slmgr
2013-11-26 21:23 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts
2013-11-26 21:23 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\com
2013-11-26 21:23 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sysprep
2013-11-26 21:23 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\oobe
2013-11-26 21:23 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\MUI
2013-11-26 21:23 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\migwiz
2013-11-26 21:23 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Dism
2013-11-26 21:23 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\IME
2013-11-26 21:22 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\com
2013-11-26 20:56 - 2013-11-19 21:46 - 00000166 _____ C:\Windows\SysWOW64\DOErrors.log
2013-11-26 20:47 - 2013-11-26 20:47 - 00001155 _____ C:\Users\1\Desktop\Free M4a to MP3 Converter.lnk
2013-11-26 20:47 - 2013-11-26 20:47 - 00000000 ____D C:\Program Files (x86)\Free M4a to MP3 Converter
2013-11-26 20:30 - 2013-11-26 20:30 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2013-11-26 13:06 - 2013-11-26 13:06 - 00000000 ____D C:\Users\1\.oces2
2013-11-26 13:05 - 2013-11-26 13:05 - 00000000 ____D C:\ProgramData\Sun
2013-11-26 13:04 - 2013-11-26 13:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-11-26 13:04 - 2013-11-26 13:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-11-26 13:04 - 2013-11-26 13:04 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-11-26 13:04 - 2013-11-26 13:04 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-26 13:04 - 2013-11-26 13:04 - 00000000 ____D C:\Program Files (x86)\Java
2013-11-26 13:03 - 2013-11-26 13:04 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-11-26 13:03 - 2013-11-26 13:04 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-11-26 13:03 - 2013-11-26 13:04 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-11-26 13:03 - 2013-11-26 13:04 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-11-26 13:03 - 2013-11-26 13:03 - 00000000 ____D C:\Program Files\Java
2013-11-26 13:02 - 2009-07-14 05:54 - 00000749 ___RH C:\Windows\WindowsShell.Manifest
2013-11-26 13:02 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries
2013-11-26 11:33 - 2013-11-18 21:21 - 00000000 ____D C:\Users\1\AppData\Local\CrashDumps
2013-11-26 11:31 - 2013-11-26 11:31 - 00000000 ____D C:\edudata
2013-11-25 11:14 - 2013-11-18 05:12 - 00000000 ____D C:\Users\1\AppData\Roaming\Adobe
2013-11-21 09:25 - 2013-11-19 22:30 - 00000000 ___RD C:\Users\1\Desktop\Virus Detection
2013-11-20 15:38 - 2013-11-20 14:56 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-11-20 14:56 - 2013-11-20 14:55 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-11-20 12:38 - 2013-11-19 00:10 - 00000000 ____D C:\Users\1\AppData\Local\NPE
2013-11-20 11:36 - 2013-11-20 11:36 - 00000000 ____D C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sophos
2013-11-20 11:36 - 2013-11-20 11:36 - 00000000 ____D C:\ProgramData\Sophos
2013-11-20 11:35 - 2013-11-20 11:35 - 00000000 ____D C:\Program Files (x86)\Sophos
2013-11-20 10:47 - 2013-11-18 05:32 - 00000000 ____D C:\ProgramData\HitmanPro
2013-11-20 09:01 - 2013-11-18 02:58 - 00000000 ___RD C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-20 08:07 - 2011-10-20 21:19 - 00000000 ____D C:\Program Files\Intel
2013-11-19 22:14 - 2013-11-18 02:56 - 00000000 ____D C:\Users\1\AppData\Local\VirtualStore
2013-11-19 21:41 - 2013-11-19 21:41 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security
2013-11-19 21:35 - 2011-10-20 21:30 - 00003234 _____ C:\Windows\System32\Tasks\Norton WSC Integration
2013-11-19 21:35 - 2011-10-20 21:30 - 00000000 ____D C:\Windows\system32\Drivers\NISx64
2013-11-19 12:45 - 2013-11-19 12:45 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-11-19 12:45 - 2013-11-19 12:45 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-11-19 00:10 - 2011-10-20 21:30 - 00000000 ____D C:\ProgramData\Norton
2013-11-18 22:41 - 2013-11-18 22:22 - 00000000 ____D C:\Users\1\Desktop\Wallpapers
2013-11-18 21:22 - 2013-11-18 21:22 - 00000000 ____D C:\Users\1\AppData\Roaming\IDT
2013-11-18 20:32 - 2013-11-18 20:32 - 00000000 ____D C:\Users\1\dwhelper
2013-11-18 18:01 - 2013-11-18 05:21 - 00000000 ____D C:\Users\1\AppData\Local\Mozilla
2013-11-18 16:23 - 2011-10-20 21:30 - 00175736 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
2013-11-18 16:23 - 2011-10-20 21:30 - 00007488 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT
2013-11-18 16:23 - 2011-10-20 21:25 - 00000000 ____D C:\Program Files\Symantec
2013-11-18 11:51 - 2009-07-14 06:38 - 00029696 ___SH C:\Windows\system32\config\BCD-Template.LOG
2013-11-18 11:51 - 2009-07-14 06:32 - 00032768 _____ C:\Windows\system32\config\BCD-Template
2013-11-18 06:27 - 2013-11-18 06:27 - 00000000 ____D C:\Users\1\AppData\Local\Macromedia
2013-11-18 06:26 - 2013-11-18 06:26 - 00000000 ____D C:\Windows\system32\Macromed
2013-11-18 05:58 - 2007-01-02 02:25 - 00000000 ____D C:\Windows\Panther
2013-11-18 05:48 - 2013-11-18 02:58 - 00001417 _____ C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-18 05:43 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-11-18 05:38 - 2013-11-18 05:28 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-11-18 05:37 - 2013-11-18 05:37 - 00002764 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-11-18 05:37 - 2013-11-18 05:37 - 00000000 ____D C:\Program Files\CCleaner
2013-11-18 05:35 - 2013-11-18 05:35 - 00000000 ____D C:\Users\1\Desktop\Uni
2013-11-18 05:33 - 2013-11-18 05:33 - 00000000 ____D C:\Program Files\HitmanPro
2013-11-18 05:28 - 2013-11-18 05:28 - 00003486 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 625d7d2f-53de-47a7-9e83-3bc3be1f86b5
2013-11-18 05:28 - 2013-11-18 05:28 - 00000000 ____D C:\Users\1\AppData\Roaming\SUPERAntiSpyware.com
2013-11-18 05:28 - 2013-11-18 05:28 - 00000000 ____D C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2013-11-18 05:28 - 2013-11-18 05:28 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-11-18 05:26 - 2013-11-18 05:26 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-18 05:26 - 2013-11-18 05:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-18 05:26 - 2013-11-18 05:26 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-18 05:26 - 2013-11-18 05:26 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-18 05:26 - 2013-11-18 05:26 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-18 05:26 - 2013-11-18 05:26 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-18 05:26 - 2013-11-18 05:26 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-18 05:26 - 2013-11-18 05:26 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-18 05:26 - 2013-11-18 05:26 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-18 05:26 - 2013-11-18 05:26 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-18 05:26 - 2013-11-18 05:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-18 05:26 - 2013-11-18 05:26 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-18 05:26 - 2013-11-18 05:26 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-18 05:25 - 2013-11-18 05:25 - 00000000 ____D C:\Users\1\AppData\Roaming\Malwarebytes
2013-11-18 05:25 - 2013-11-18 05:25 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-18 05:25 - 2013-11-18 05:25 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-18 05:21 - 2013-11-18 05:21 - 00000000 ____D C:\Users\1\AppData\Roaming\Mozilla
2013-11-18 05:21 - 2013-11-18 05:21 - 00000000 ____D C:\ProgramData\Mozilla
2013-11-18 05:21 - 2013-11-18 05:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-18 05:21 - 2013-11-18 05:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-18 05:12 - 2013-11-18 05:12 - 00003520 _____ C:\Windows\System32\Tasks\CreateChoiceProcessTask
2013-11-18 05:12 - 2013-11-18 02:58 - 00000000 ___RD C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-18 05:12 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-11-18 05:09 - 2009-07-14 05:45 - 00274976 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-18 05:03 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
2013-11-18 05:03 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
2013-11-18 05:02 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\zh-HK
2013-11-18 05:02 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\tr-TR
2013-11-18 03:55 - 2013-11-18 03:55 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-11-18 03:55 - 2013-11-18 03:55 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-11-18 03:34 - 2013-11-18 03:33 - 00000000 ____D C:\Windows\system32\MRT
2013-11-18 03:15 - 2011-06-14 05:09 - 00000000 ____D C:\Program Files\Hewlett-Packard
2013-11-18 03:14 - 2011-10-15 06:09 - 00000000 ____D C:\Program Files (x86)\Windows Live
2013-11-18 03:11 - 2013-11-18 03:10 - 00000000 ____D C:\Users\1\AppData\Local\Microsoft Games
2013-11-18 03:08 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-11-18 03:05 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\restore
2013-11-18 03:02 - 2013-11-18 03:02 - 00003804 _____ C:\Windows\System32\Tasks\SetupManager
2013-11-18 03:02 - 2013-11-18 02:57 - 00000000 ____D C:\Users\1\AppData\Local\Hewlett-Packard_Company
2013-11-18 03:00 - 2013-11-18 03:00 - 00000000 ____D C:\Users\1\AppData\Roaming\ATI
2013-11-18 03:00 - 2013-11-18 03:00 - 00000000 ____D C:\Users\1\AppData\Local\ATI
2013-11-18 02:59 - 2013-11-18 02:59 - 00000000 ____D C:\Users\1\AppData\Roaming\hpqLog
2013-11-18 02:58 - 2013-11-18 02:58 - 00000000 ____D C:\Users\1\AppData\Local\RemEngine
2013-11-18 02:57 - 2013-11-18 02:57 - 00000000 ____D C:\Users\1\AppData\Local\AuthenTec
2013-11-18 02:57 - 2011-10-15 05:59 - 00000000 ___RD C:\Program Files (x86)\Online Services
2013-11-18 02:57 - 2011-02-10 20:23 - 00000000 ___HD C:\SYSTEM.SAV
2013-11-18 02:57 - 2011-02-10 20:23 - 00000000 ____D C:\SWSetup
2013-11-18 02:56 - 2013-11-18 02:56 - 00000000 ____D C:\Users\1\AppData\Roaming\Intel
2013-11-18 02:55 - 2013-11-18 02:55 - 00000020 ___SH C:\Users\1\ntuser.ini
2013-11-18 02:55 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Recovery
2013-11-18 02:55 - 2007-01-02 02:32 - 00000000 __SHD C:\Recovery
2013-11-07 16:00 - 2013-11-18 03:33 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Some content of TEMP:
====================
C:\Users\1\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-30 14:48

==================== End Of Log ============================

 

 

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-12-2013
Ran by 1 at 2013-12-02 12:08:37
Running from C:\Users\1\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Norton Internet Security (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

==================== Installed Programs ======================

ActiveX-kontroll för fjärranslutningar för Windows Live Mesh (x32 Version: 15.4.5722.2)
Adobe AIR (x32 Version: 1.5.3.9130)
Adobe Community Help (x32 Version: 3.2.1)
Adobe Community Help (x32 Version: 3.2.1.650)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.152)
Adobe Photoshop Elements 9 (x32 Version: 9.0)
Adobe Premiere Elements 9 (x32 Version: 9.0)
Adobe Reader XI (11.0.05) (x32 Version: 11.0.05)
Adobe Shockwave Player 11.5 (x32 Version: 11.5.9.620)
Agatha Christie - Peril at End House (x32 Version: 2.2.0.95)
ALPS Touch Pad Driver (Version: 7.206.1717.117)
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 1.0.2.43)
ATI Catalyst Install Manager (Version: 3.0.816.0)
AuthenTec TrueAPI (Version: 1.3.0.111)
Bejeweled 3 (x32 Version: 2.2.0.97)
Blackhawk Striker 2 (x32 Version: 2.2.0.95)
Blasterball 3 (x32 Version: 2.2.0.97)
Bounce Symphony (x32 Version: 2.2.0.97)
Cake Mania (x32 Version: 2.2.0.95)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center (x32 Version: 2011.0508.224.2391)
Catalyst Control Center Graphics Previews Common (x32 Version: 2011.0508.224.2391)
Catalyst Control Center InstallProxy (x32 Version: 2011.0508.224.2391)
Catalyst Control Center Localization All (x32 Version: 2011.0508.224.2391)
Catalyst Control Center Profiles Mobile (x32 Version: 2011.0508.224.2391)
CCC Help Chinese Standard (x32 Version: 2011.0508.0223.2391)
CCC Help Chinese Traditional (x32 Version: 2011.0508.0223.2391)
CCC Help Czech (x32 Version: 2011.0508.0223.2391)
CCC Help Danish (x32 Version: 2011.0508.0223.2391)
CCC Help Dutch (x32 Version: 2011.0508.0223.2391)
CCC Help English (x32 Version: 2011.0508.0223.2391)
CCC Help Finnish (x32 Version: 2011.0508.0223.2391)
CCC Help French (x32 Version: 2011.0508.0223.2391)
CCC Help German (x32 Version: 2011.0508.0223.2391)
CCC Help Greek (x32 Version: 2011.0508.0223.2391)
CCC Help Hungarian (x32 Version: 2011.0508.0223.2391)
CCC Help Italian (x32 Version: 2011.0508.0223.2391)
CCC Help Japanese (x32 Version: 2011.0508.0223.2391)
CCC Help Korean (x32 Version: 2011.0508.0223.2391)
CCC Help Norwegian (x32 Version: 2011.0508.0223.2391)
CCC Help Polish (x32 Version: 2011.0508.0223.2391)
CCC Help Portuguese (x32 Version: 2011.0508.0223.2391)
CCC Help Russian (x32 Version: 2011.0508.0223.2391)
CCC Help Spanish (x32 Version: 2011.0508.0223.2391)
CCC Help Swedish (x32 Version: 2011.0508.0223.2391)
CCC Help Thai (x32 Version: 2011.0508.0223.2391)
CCC Help Turkish (x32 Version: 2011.0508.0223.2391)
ccc-utility64 (Version: 2011.0508.224.2391)
CCleaner (Version: 4.07)
Chronicles of Albian (x32 Version: 2.2.0.95)
Chuzzle Deluxe (x32 Version: 2.2.0.95)
Cradle of Rome 2 (x32 Version: 2.2.0.95)
Elements 9 Organizer (x32 Version: 9.0)
Elements STI Installer (x32 Version: 1.0)
ESU for Microsoft Windows 7 SP1 (x32 Version: 2.1.1)
Farm Frenzy (x32 Version: 2.2.0.95)
FATE (x32 Version: 2.2.0.97)
Final Drive: Nitro (x32 Version: 2.2.0.95)
Free M4a to MP3 Converter 8.1 (x32)
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.95)
Hewlett-Packard ACLM.NET v1.1.1.0 (x32 Version: 1.00.0000)
HitmanPro 3.7 (Version: 3.7.8.208)
HP 3D DriveGuard (Version: 4.1.9.1)
HP Client Services (Version: 1.1.12938.3539)
HP CoolSense (x32 Version: 2.1.0)
HP Customer Experience Enhancements (x32 Version: 6.0.1.7)
HP Documentation (x32 Version: 1.1.0.0)
HP Games (x32 Version: 1.0.2.5)
HP On Screen Display (x32 Version: 1.2.2)
HP Power Manager (x32 Version: 1.2.3)
HP Quick Launch (x32 Version: 2.4.3)
HP QuickWeb (x32 Version: 3.1.0.9742)
HP Setup (x32 Version: 8.7.4751.3798)
HP Setup Manager (x32 Version: 1.1.13476.3753)
HP SimplePass 2011 (x32 Version: 5.3.0.163)
HP Software Framework (x32 Version: 4.1.6.1)
HP Support Assistant (x32 Version: 6.0.5.4)
IDT Audio (x32 Version: 1.0.6341.0)
Intel PROSet Wireless
Intel PROSet Wireless (x32)
Intel® Control Center (x32 Version: 1.2.1.1007)
Intel® Display Audio Driver (x32 Version: 6.14.00.3074)
Intel® Identity Protection Technology 1.1.2.0 (x32 Version: 1.1.2.0)
Intel® Management Engine Components (x32 Version: 7.0.0.1144)
Intel® PROSet/Wireless Software for Bluetooth® Technology (Version: 1.1.0.0537)
Intel® PROSet/Wireless WiFi Software (Version: 14.01.1000)
Intel® Rapid Storage Technology (x32 Version: 10.5.0.1026)
Intel® WiDi (x32 Version: 2.1.39.0)
Intel® Wireless Display
Java 7 Update 45 (64-bit) (Version: 7.0.450)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
Jewel Quest: The Sleepless Star - Collector's Edition (x32 Version: 2.2.0.95)
Mah Jong Medley (x32 Version: 2.2.0.95)
Malwarebytes Anti-Malware version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2010 (x32 Version: 14.0.4763.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000)
Mozilla Firefox 25.0.1 (x86 da) (x32 Version: 25.0.1)
Mozilla Maintenance Service (x32 Version: 25.0.1)
Mystery of Mortlake Mansion (x32 Version: 2.2.0.97)
Namco All-Stars: PAC-MAN (x32 Version: 2.2.0.95)
Norton Internet Security (x32 Version: 19.9.1.14)
Penguins! (x32 Version: 2.2.0.95)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95)
Poker Superstars III (x32 Version: 2.2.0.95)
Polar Bowler (x32 Version: 2.2.0.97)
Polar Golfer (x32 Version: 2.2.0.95)
PX Profile Update (x32 Version: 1.00.1.)
Realtek PCIE Card Reader (x32 Version: 6.1.7600.80)
Recovery Manager (x32 Version: 2.0.0)
Slingo Supreme (x32 Version: 2.2.0.97)
SmartSound Quicktracks for Premiere Elements 9.0 (x32 Version: 3.12.3090)
Sophos Virus Removal Tool (x32 Version: 2.4)
SUPERAntiSpyware (Version: 5.6.1042)
Update Installer for WildTangent Games App (x32)
Vacation Quest - The Hawaiian Islands (x32 Version: 2.2.0.97)
Validity WBF DDK (Version: 4.3.205.0)
VIP Access SDK (1.0.1.2)  (x32 Version: 1.0.1.2)
Virtual Villagers 5 - New Believers (x32 Version: 2.2.0.97)
WildTangent Games App (HP Games) (x32 Version: 4.0.5.2)
Windows Live Fotogalleri (x32 Version: 15.4.3502.0922)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (x32 Version: 15.4.5722.2)
Windows Live Meshin etäyhteyksien ActiveX-komponentti (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
Windows Liven sähköposti (x32 Version: 15.4.3502.0922)
Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922)
Zuma Deluxe (x32 Version: 2.2.0.95)

==================== Restore Points  =========================

20-11-2013 07:24:00 Removed Intel® PROSet/Wireless Software for Bluetooth® Technology
20-11-2013 10:35:18 Installed Sophos Virus Removal Tool.
26-11-2013 08:44:29 Konfigureret YouCam
26-11-2013 15:51:33 Language Pack Removal
26-11-2013 20:40:04 Windows Update
28-11-2013 11:49:57 Removed Adobe Reader X (10.1.8) MUI.
28-11-2013 11:59:09 Installed Adobe Reader XI.

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {30DF5089-1E86-4FBF-9F7B-FF3BE7BD1C15} - System32\Tasks\SetupManager => C:\Program Files (x86)\Hewlett-Packard\Setup Manager\Toaster.exe [2011-05-13] (Microsoft)
Task: {37CBD217-E128-4480-B28F-73BB8DE0024B} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\symerr.exe [2012-02-04] (Symantec Corporation)
Task: {6160DDBC-CA35-460D-B7A0-F7614A0D4E32} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-28] (Adobe Systems Incorporated)
Task: {6CCBABC1-4247-47E8-B998-0ADF89D98E4E} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\wscstub.exe [2013-02-02] (Symantec Corporation)
Task: {85A03B72-0BB8-424E-9E7C-1385C5B9E7FF} - System32\Tasks\SUPERAntiSpyware Scheduled Task 625d7d2f-53de-47a7-9e83-3bc3be1f86b5 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-10-10] (SUPERAdBlocker.com)
Task: {946234A9-D54A-412D-B7D8-4D3684FC9350} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2011-06-21] (Hewlett-Packard Company)
Task: {AD62A5A5-1D65-4230-9CA1-D9DB96A3D383} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2011-06-21] (Hewlett-Packard Company)
Task: {BA75E8D3-7C5C-48E5-A2DD-B7A0EA64E0B2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe [2011-06-21] (Hewlett-Packard Company)
Task: {E65EA320-97CC-46DD-A378-7A9A60D203CD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater\HPSFUpdater.exe [2011-06-14] (Hewlett-Packard)
Task: {E66E2AF3-4A70-46E6-BC17-C6D17543D4B8} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\symerr.exe [2012-02-04] (Symantec Corporation)
Task: {EF7CD86A-F513-472A-93D4-B1FA2CCB9C4D} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2011-06-28] ()
Task: {F6CD192D-5447-4432-8E3E-44A21546B161} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-22] (Piriform Ltd)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 625d7d2f-53de-47a7-9e83-3bc3be1f86b5.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

==================== Loaded Modules (whitelisted) =============

2011-04-15 19:16 - 2011-04-15 19:16 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-05-02 21:41 - 2011-05-02 21:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-05-08 10:23 - 2011-05-08 10:23 - 00243712 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2011-05-12 22:13 - 2011-05-12 22:13 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2011-10-20 21:19 - 2011-04-30 09:28 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================

System errors:
=============

Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Percentage of memory in use: 25%
Total physical RAM: 6091.86 MB
Available physical RAM: 4514.13 MB
Total Pagefile: 12181.9 MB
Available Pagefile: 10440.22 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:670.02 GB) (Free:607.47 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Recovery) (Fixed) (Total:24.45 GB) (Free:2.54 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:3.96 GB) (Free:1.08 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 699 GB) (Disk ID: E41BE8D3)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=670 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=24 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=4 GB) - (Type=0C)

==================== End Of Log ============================



#7 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,801 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:48 PM

Posted 02 December 2013 - 09:43 AM

Thank you for posting all the information. I am not seeing anything suspicious. The ccsvchst.exe file is related to Norton.

Are you currently experiencing any problems?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#8 newt123

newt123
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:08:48 AM

Posted 02 December 2013 - 09:48 AM

Eversince the incident nothing unusual has happened. Everything is working fine. Guess the bluetooth had difficulties starting up and it used up alot of cpu. Probably just me being paranoid :) Thanks for the help Gary! The service you guys provide is amazing :) Thanks again.



#9 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,801 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:48 PM

Posted 02 December 2013 - 10:36 AM

Excellent. It is always good to be overcautious. Anytime we can assist you I hope you would not hesitate to stop in and say "Hi".

Now that your computer is running well it is my great pleasure to proclaim to you the Good News!

===================================================

All Clean

--------------

Your machine appears to be clean. You can remove any of the programs or logs on your system as a result of our efforts together. Please take the time to read below on how to secure the machine and take the necessary steps to keep it clean :thumbsup:

Lawrence Abrams, the founder of BleepingComputer.com, has developed an excellent tutorial which will provide you with the information you need to know to keep your computer secure and clean. Please take the time to read:In addition, here are some more links you might find of interest:I will leave this topic open for just a couple of days in case you have any further issues then it will be closed shortly thereafter.

Thank you for placing your trust in BleepingComputer. It was a pleasure serving you. OhMy_done.gif
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#10 newt123

newt123
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:08:48 AM

Posted 04 December 2013 - 08:09 AM

So im experiencing further suspicious activity on my pc. Two days ago everytime i went onto my pc after it had been a sleep (i often only sleep the computer rather than turning it off) the fingerprint device started blinking for a while so i eventualy removed hp's simple pass and it stopped. The other thing is, that my wireless internet connection get disrupted. On the internet access icon on the taskbar my pc is searching for my router then finds it and it says unidentified network, and it wont connect. So i simply disconnect and reconnect and everything is fine again. Lastly when i turned on my pc this morning (again after id had been asleep, it wasnt shut completely down), and wanted to remove the temporary internet files i noticed the show hidden folders setting had been changed to do not show hidden folders. I always have it set to show hidden folders. Im thinking this is because of some registry modifications? None of my malware, firewall, virus detections programs etc show any signs of intrusion or infection. Would you please be so kind to check my newly added logs one last time? Im going crazy over all the small strange things happening on my pc. I would be very thankful :)

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16428  BrowserJavaVersion: 10.45.2
Run by 1 at 14:07:34 on 2013-12-04
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.45.1033.18.6092.3784 [GMT 1:00]
.
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files\File Association Helper\FAHWindow.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.bing.com?pc=HPNTDF
mWinlogon: Userinit = userinit.exe,
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ips\ipsbho.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [HPQuickWebProxy] "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{280F13DA-E4AF-4520-96EA-003BFA090D10} : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{280F13DA-E4AF-4520-96EA-003BFA090D10}\145575C414E4 : DHCPNameServer = 8.8.8.8
TCP: Interfaces\{280F13DA-E4AF-4520-96EA-003BFA090D10}\56465727F616D6 : DHCPNameServer = 10.88.0.5 10.88.0.6
SSODL: WebCheck - <orphaned>
x64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [FAHConsole] C:\Program Files\File Association Helper\FAHConsole.exe
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\18ghfms5.default\
FF - prefs.js: browser.startup.homepage - google.dk
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll
FF - ExtSQL: 2013-11-18 02:58; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn
FF - ExtSQL: 2013-11-18 03:03; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFF
FF - ExtSQL: 2013-11-18 05:22; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\18ghfms5.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-11-18 20:32; {b9db16a4-6edc-47ec-a1f4-b86292ed211d}; C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\18ghfms5.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-10-15 55856]
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NISx64\1309010.00E\symds64.sys [2013-11-19 451192]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1309010.00E\symefa64.sys [2013-11-19 1129120]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20131203.001\BHDrvx64.sys [2013-12-3 1526488]
R1 ccSet_NIS;Norton Internet Security Settings Manager;C:\Windows\System32\drivers\NISx64\1309010.00E\ccsetx64.sys [2013-11-19 167072]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20131203.002\IDSviA64.sys [2013-12-4 521816]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NISx64\1309010.00E\ironx64.sys [2013-11-19 190072]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\NISx64\1309010.00E\symnets.sys [2013-11-19 405624]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2013-10-10 144152]
R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-9-30 169408]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2011-10-20 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-5-8 203776]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-6-21 85560]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-5-22 103992]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2011-5-27 30520]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-4-8 26680]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-10-20 13592]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-10-20 2375168]
R2 jhi_service;Intel® Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-2-24 212944]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe [2013-11-19 138272]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-10-20 2656280]
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2011-3-8 51712]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-11-21 137648]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-10-15 317440]
R3 intelkmd;intelkmd;C:\Windows\System32\drivers\igdpmd64.sys [2011-4-15 12228128]
R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\drivers\iwdbus.sys [2011-5-17 25496]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-3-23 77936]
R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2011-5-17 42392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-5-6 263496]
S3 AMPPAL;Intel® Centrino® Bluetooth 3.0 + High Speed Virtual Adapter;C:\Windows\System32\drivers\AmpPal.sys [2011-4-21 294912]
S3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2011-3-8 274944]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2011-3-23 59904]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2013-11-18 111616]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\drivers\intelaud.sys [2011-5-17 34200]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-5-2 340240]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2011-10-20 337512]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-11-18 1255736]
.
=============== Created Last 30 ================
.
2013-12-04 11:07:23    --------    d-----w-    C:\Users\1\AppData\Local\WinZip
2013-12-04 11:06:05    --------    d-----w-    C:\Program Files\File Association Helper
2013-12-03 21:06:24    --------    d-----w-    C:\Users\1\AppData\Local\ElevatedDiagnostics
2013-12-03 21:04:47    --------    d-----w-    C:\Users\1\AppData\Local\Diagnostics
2013-12-02 10:19:18    --------    d-----w-    C:\Windows\ERUNT
2013-12-01 15:21:58    --------    d-----w-    C:\Users\1\AppData\Local\HP
2013-12-01 09:28:10    --------    d-----w-    C:\Users\1\AppData\Roaming\Symantec
2013-11-28 12:04:19    71048    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-28 12:04:19    692616    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe
2013-11-26 20:42:12    --------    d-----w-    C:\Windows\Migration
2013-11-26 19:47:38    --------    d-----w-    C:\Program Files (x86)\Free M4a to MP3 Converter
2013-11-26 12:06:23    --------    d-----w-    C:\Users\1\.oces2
2013-11-26 12:04:50    96168    ----a-w-    C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-11-26 12:04:03    108968    ----a-w-    C:\Windows\System32\WindowsAccessBridge-64.dll
2013-11-26 10:31:04    --------    d-----w-    C:\edudata
2013-11-20 13:56:42    --------    d-----w-    C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-11-20 13:55:40    91352    ----a-w-    C:\Windows\System32\drivers\mbamchameleon.sys
2013-11-20 10:36:26    --------    d-----w-    C:\ProgramData\Sophos
2013-11-20 10:36:15    73728    ----a-r-    C:\Users\1\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe1_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2013-11-20 10:36:15    73728    ----a-r-    C:\Users\1\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2013-11-20 10:36:02    73728    ----a-r-    C:\Users\1\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\ARPPRODUCTICON.exe
2013-11-20 10:35:51    --------    d-----w-    C:\Program Files (x86)\Sophos
2013-11-19 05:09:50    737952    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\srtsp64.sys
2013-11-19 05:09:50    451192    ----a-r-    C:\Windows\System32\drivers\NISx64\1309010.00E\symds64.sys
2013-11-19 05:09:50    405624    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\symnets.sys
2013-11-19 05:09:50    37536    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\srtspx64.sys
2013-11-19 05:09:50    190072    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\ironx64.sys
2013-11-19 05:09:50    1129120    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\symefa64.sys
2013-11-19 05:09:49    167072    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\ccsetx64.sys
2013-11-19 05:09:44    --------    d-----w-    C:\Windows\System32\drivers\NISx64\1309010.00E
2013-11-18 23:10:50    --------    d-----w-    C:\Users\1\AppData\Local\NPE
2013-11-18 21:13:03    99840    ----a-w-    C:\Windows\System32\drivers\usbccgp.sys
2013-11-18 21:13:03    7808    ----a-w-    C:\Windows\System32\drivers\usbd.sys
2013-11-18 21:13:03    52736    ----a-w-    C:\Windows\System32\drivers\usbehci.sys
2013-11-18 21:13:03    343040    ----a-w-    C:\Windows\System32\drivers\usbhub.sys
2013-11-18 21:13:03    325120    ----a-w-    C:\Windows\System32\drivers\usbport.sys
2013-11-18 21:13:03    30720    ----a-w-    C:\Windows\System32\drivers\usbuhci.sys
2013-11-18 21:13:03    25600    ----a-w-    C:\Windows\System32\drivers\usbohci.sys
2013-11-18 21:13:01    1424384    ----a-w-    C:\Windows\System32\WindowsCodecs.dll
2013-11-18 21:13:01    1230336    ----a-w-    C:\Windows\SysWow64\WindowsCodecs.dll
2013-11-18 21:12:48    67072    ----a-w-    C:\Windows\splwow64.exe
2013-11-18 21:12:48    559104    ----a-w-    C:\Windows\System32\spoolsv.exe
2013-11-18 20:22:28    --------    d-----w-    C:\Users\1\AppData\Roaming\IDT
2013-11-18 20:21:56    --------    d-----w-    C:\Users\1\AppData\Local\CrashDumps
2013-11-18 19:32:56    --------    d-----w-    C:\Users\1\dwhelper
2013-11-18 05:27:21    --------    d-----w-    C:\Users\1\AppData\Local\Macromedia
2013-11-18 04:37:33    --------    d-----w-    C:\Program Files\CCleaner
2013-11-18 04:33:38    --------    d-----w-    C:\Program Files\HitmanPro
2013-11-18 04:32:36    --------    d-----w-    C:\ProgramData\HitmanPro
2013-11-18 04:28:28    --------    d-----w-    C:\Users\1\AppData\Roaming\SUPERAntiSpyware.com
2013-11-18 04:28:02    --------    d-----w-    C:\ProgramData\SUPERAntiSpyware.com
2013-11-18 04:28:02    --------    d-----w-    C:\Program Files\SUPERAntiSpyware
2013-11-18 04:25:39    --------    d-----w-    C:\Users\1\AppData\Roaming\Malwarebytes
2013-11-18 04:25:30    --------    d-----w-    C:\ProgramData\Malwarebytes
2013-11-18 04:25:27    25928    ----a-w-    C:\Windows\System32\drivers\mbam.sys
2013-11-18 04:25:27    --------    d-----w-    C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-18 04:25:02    --------    d-----w-    C:\Users\1\AppData\Local\Programs
2013-11-18 04:01:57    --------    d-----w-    C:\Windows\SysWow64\Wat
2013-11-18 04:01:57    --------    d-----w-    C:\Windows\System32\Wat
2013-11-18 03:21:30    2560    ----a-w-    C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2013-11-18 02:59:35    --------    d-----w-    C:\Program Files (x86)\Common Files\Symantec Shared
2013-11-18 02:46:57    294912    ----a-w-    C:\Windows\System32\browserchoice.exe
2013-11-18 02:37:21    87040    ----a-w-    C:\Windows\System32\drivers\WUDFPf.sys
2013-11-18 02:37:21    84992    ----a-w-    C:\Windows\System32\WUDFSvc.dll
2013-11-18 02:37:21    744448    ----a-w-    C:\Windows\System32\WUDFx.dll
2013-11-18 02:37:21    45056    ----a-w-    C:\Windows\System32\WUDFCoinstaller.dll
2013-11-18 02:37:21    229888    ----a-w-    C:\Windows\System32\WUDFHost.exe
2013-11-18 02:37:21    198656    ----a-w-    C:\Windows\System32\drivers\WUDFRd.sys
2013-11-18 02:37:21    194048    ----a-w-    C:\Windows\System32\WUDFPlatform.dll
2013-11-18 02:33:36    --------    d-----w-    C:\Windows\System32\MRT
2013-11-18 02:31:58    81408    ----a-w-    C:\Windows\System32\imagehlp.dll
2013-11-18 02:31:58    5120    ----a-w-    C:\Windows\SysWow64\wmi.dll
2013-11-18 02:31:58    5120    ----a-w-    C:\Windows\System32\wmi.dll
2013-11-18 02:31:58    23408    ----a-w-    C:\Windows\System32\drivers\fs_rec.sys
2013-11-18 02:31:58    159232    ----a-w-    C:\Windows\SysWow64\imagehlp.dll
2013-11-18 02:27:59    224256    ----a-w-    C:\Windows\System32\wintrust.dll
2013-11-18 02:25:56    245760    ----a-w-    C:\Windows\System32\OxpsConverter.exe
2013-11-18 02:21:04    751104    ----a-w-    C:\Windows\System32\win32spl.dll
2013-11-18 02:21:04    492544    ----a-w-    C:\Windows\SysWow64\win32spl.dll
2013-11-18 02:21:04    404480    ----a-w-    C:\Windows\System32\gdi32.dll
2013-11-18 02:21:04    311808    ----a-w-    C:\Windows\SysWow64\gdi32.dll
2013-11-18 02:21:02    936448    ----a-w-    C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-11-18 02:21:02    1367040    ----a-w-    C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-11-18 02:21:00    5549504    ----a-w-    C:\Windows\System32\ntoskrnl.exe
2013-11-18 02:21:00    3969472    ----a-w-    C:\Windows\SysWow64\ntkrnlpa.exe
2013-11-18 02:21:00    3914176    ----a-w-    C:\Windows\SysWow64\ntoskrnl.exe
2013-11-18 02:19:26    903168    ----a-w-    C:\Windows\SysWow64\certutil.exe
2013-11-18 02:19:26    1192448    ----a-w-    C:\Windows\System32\certutil.exe
2013-11-18 02:19:25    52224    ----a-w-    C:\Windows\System32\certenc.dll
2013-11-18 02:19:25    43008    ----a-w-    C:\Windows\SysWow64\certenc.dll
2013-11-18 02:19:17    690688    ----a-w-    C:\Windows\SysWow64\msvcrt.dll
2013-11-18 02:19:17    634880    ----a-w-    C:\Windows\System32\msvcrt.dll
2013-11-18 02:10:46    --------    d-----w-    C:\Users\1\AppData\Local\Microsoft Games
2013-11-18 02:06:21    461312    ----a-w-    C:\Windows\System32\scavengeui.dll
2013-11-18 02:06:11    859648    ----a-w-    C:\Windows\System32\IKEEXT.DLL
2013-11-18 02:06:11    830464    ----a-w-    C:\Windows\System32\nshwfp.dll
2013-11-18 02:06:11    656896    ----a-w-    C:\Windows\SysWow64\nshwfp.dll
2013-11-18 02:06:11    324096    ----a-w-    C:\Windows\System32\FWPUCLNT.DLL
2013-11-18 02:06:11    216576    ----a-w-    C:\Windows\SysWow64\FWPUCLNT.DLL
2013-11-18 02:04:47    956928    ----a-w-    C:\Windows\System32\localspl.dll
2013-11-18 02:03:39    826880    ----a-w-    C:\Windows\SysWow64\rdpcore.dll
2013-11-18 02:03:39    23552    ----a-w-    C:\Windows\System32\drivers\tdtcp.sys
2013-11-18 02:03:39    1031680    ----a-w-    C:\Windows\System32\rdpcore.dll
2013-11-18 02:00:54    --------    d-----w-    C:\Users\1\AppData\Local\ATI
2013-11-18 01:59:47    --------    d-----w-    C:\Users\1\AppData\Roaming\hpqLog
2013-11-18 01:59:44    --------    d-----w-    C:\Users\1\AppData\Local\Adobe
2013-11-18 01:58:09    --------    d-----w-    C:\Users\1\AppData\Local\RemEngine
2013-11-18 01:57:46    --------    d-----w-    C:\Users\1\AppData\Local\Hewlett-Packard
2013-11-18 01:57:37    --------    d-----w-    C:\Users\1\AppData\Local\Hewlett-Packard_Company
2013-11-18 01:57:23    --------    d-----w-    C:\Users\1\AppData\Local\AuthenTec
2013-11-18 01:56:41    --------    d-----w-    C:\Users\1\AppData\Local\VirtualStore
2013-11-18 01:56:17    2622464    ----a-w-    C:\Windows\System32\wucltux.dll
2013-11-18 01:56:08    99840    ----a-w-    C:\Windows\System32\wudriver.dll
2013-11-18 01:56:08    --------    d-----w-    C:\Users\1\AppData\Roaming\Intel
2013-11-18 01:56:01    36864    ----a-w-    C:\Windows\System32\wuapp.exe
2013-11-18 01:56:01    186752    ----a-w-    C:\Windows\System32\wuwebv.dll
.
==================== Find3M  ====================
.
2013-11-18 15:23:13    175736    ----a-w-    C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2013-11-18 02:55:35    9728    ---ha-w-    C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-10-05 20:25:35    1474048    ----a-w-    C:\Windows\System32\crypt32.dll
2013-10-05 19:57:25    1168384    ----a-w-    C:\Windows\SysWow64\crypt32.dll
2013-10-04 02:28:31    190464    ----a-w-    C:\Windows\System32\SmartcardCredentialProvider.dll
2013-10-04 02:25:17    197120    ----a-w-    C:\Windows\System32\credui.dll
2013-10-04 02:24:49    1930752    ----a-w-    C:\Windows\System32\authui.dll
2013-10-04 01:58:50    152576    ----a-w-    C:\Windows\SysWow64\SmartcardCredentialProvider.dll
2013-10-04 01:56:25    168960    ----a-w-    C:\Windows\SysWow64\credui.dll
2013-10-04 01:56:00    1796096    ----a-w-    C:\Windows\SysWow64\authui.dll
2013-09-28 01:09:10    497152    ----a-w-    C:\Windows\System32\drivers\afd.sys
2013-09-25 02:26:40    95680    ----a-w-    C:\Windows\System32\drivers\ksecdd.sys
2013-09-25 02:26:40    154560    ----a-w-    C:\Windows\System32\drivers\ksecpkg.sys
2013-09-25 02:23:33    28672    ----a-w-    C:\Windows\System32\sspisrv.dll
2013-09-25 02:23:33    135680    ----a-w-    C:\Windows\System32\sspicli.dll
2013-09-25 02:23:01    28160    ----a-w-    C:\Windows\System32\secur32.dll
2013-09-25 02:22:59    340992    ----a-w-    C:\Windows\System32\schannel.dll
2013-09-25 02:21:50    307200    ----a-w-    C:\Windows\System32\ncrypt.dll
2013-09-25 02:21:07    1447936    ----a-w-    C:\Windows\System32\lsasrv.dll
2013-09-25 01:58:17    96768    ----a-w-    C:\Windows\SysWow64\sspicli.dll
2013-09-25 01:57:26    22016    ----a-w-    C:\Windows\SysWow64\secur32.dll
2013-09-25 01:57:24    247808    ----a-w-    C:\Windows\SysWow64\schannel.dll
2013-09-25 01:56:42    220160    ----a-w-    C:\Windows\SysWow64\ncrypt.dll
2013-09-25 01:03:24    30720    ----a-w-    C:\Windows\System32\lsass.exe
2013-09-11 20:21:54    863344    ----a-w-    C:\Windows\SysWow64\msvcr110_clr0400.dll
2013-09-11 20:21:54    501872    ----a-w-    C:\Windows\SysWow64\msvcp110_clr0400.dll
2013-09-11 20:21:54    28776    ----a-w-    C:\Windows\SysWow64\aspnet_counters.dll
2013-09-11 20:21:54    18000    ----a-w-    C:\Windows\SysWow64\msvcr100_clr0400.dll
2013-09-11 18:39:06    855664    ----a-w-    C:\Windows\System32\msvcr110_clr0400.dll
2013-09-11 18:39:06    614000    ----a-w-    C:\Windows\System32\msvcp110_clr0400.dll
2013-09-11 18:39:06    30312    ----a-w-    C:\Windows\System32\aspnet_counters.dll
2013-09-11 18:39:06    18000    ----a-w-    C:\Windows\System32\msvcr100_clr0400.dll
2013-09-08 02:30:37    1903552    ----a-w-    C:\Windows\System32\drivers\tcpip.sys
2013-09-08 02:27:14    327168    ----a-w-    C:\Windows\System32\mswsock.dll
2013-09-08 02:03:58    231424    ----a-w-    C:\Windows\SysWow64\mswsock.dll
.
============= FINISH: 14:07:51,60 ===============
 

Attached Files



#11 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,801 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:48 PM

Posted 04 December 2013 - 10:21 AM

Let's take a look at the contents of an uncommon folder. Please do this.

===================================================

SystemLook by jpshortstuff

--------------------
  • Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2
Download Mirror #3 For 64-bit users

  • Double-click SystemLook.exe to run it.
  • Vista\Windows 7 users:: Right click on SystemLook.exe, click Run As Administrator
  • Copy the content of the following codebox into the main textfield:
:dir
C:\Users\1\.oces2 /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. If necessary please zip and attach the file.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • SystemLook log

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#12 newt123

newt123
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:08:48 AM

Posted 04 December 2013 - 05:00 PM

SystemLook 30.07.11 by jpshortstuff
Log created at 22:59 on 04/12/2013 by 1
Administrator - Elevation successful

========== dir ==========

C:\Users\1\.oces2 - Parameters: "/s"

---Files---
None found.

C:\Users\1\.oces2\danid    d------    [12:06 26/11/2013]

C:\Users\1\.oces2\danid\plugins    d------    [12:06 26/11/2013]
DanID_Applet-attachments.jar    --a---- 36156 bytes    [12:06 26/11/2013]    [12:06 26/11/2013]
DanID_Applet-bouncycastle.jar    --a---- 68503 bytes    [12:06 26/11/2013]    [12:06 26/11/2013]
DanID_Applet-crypto.jar    --a---- 210321 bytes    [12:06 26/11/2013]    [12:06 26/11/2013]
DanID_Applet-nanoxml.jar    --a---- 26985 bytes    [12:06 26/11/2013]    [12:06 26/11/2013]
DanID_Applet-shortterm.jar    --a---- 29938 bytes    [12:06 26/11/2013]    [12:06 26/11/2013]
DanID_Applet.jar    --a---- 753555 bytes    [12:06 26/11/2013]    [12:06 26/11/2013]

-= EOF =-



#13 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,801 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:48 PM

Posted 04 December 2013 - 05:16 PM

Does this sound reasonable to you for the referenced file?
 

The file 'DanID_Applet.jar' is associated with a company that all Danish citizens use when accessing stuff such as their bank account or tax papers online.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#14 newt123

newt123
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:08:48 AM

Posted 04 December 2013 - 05:20 PM

yes, that folder is completely harmless :) I've been using ccleaners registry cleaner alot lately without backing up the regestry maybe that could be the reason the show hidden folders setting changed? When trustedinstaller is making modifications to windows updates or installing stuff, could registry changes maybe affect the hidden folders settings? Just trying to figure out how it changed, as i find it suspicious



#15 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,801 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:48 PM

Posted 04 December 2013 - 05:32 PM

I don't know but it is very possible CCleaner resets the hidden file setting to its default, namely hiding those file. It is not a good idea to use any kind of registry cleaners. Much inadvertent damage is done in doing so. It is far better to target known bad registry entries than to do a sweep through your system.

Personally I disabled my fingerprint reader because it was experiencing issues. I am not sure about the internet issue. Run these for me.

===================================================

Farbar's MiniToolBox

--------------------
  • Please download MiniToolBox, save it to your desktop
  • Please close any Firefox browsers you may have open
  • Double click the icon to launch the program
  • Make sure the following options are checked:

Flush DNS
Report IE Proxy Settings
Reset IE Proxy Settings
Report FF Proxy Settings
Reset FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List devices >>(Problem only)<<

  • Click Go and once the scan is completed a Result.txt Notepad document will open on your desktop
  • Please copy and paste the contents in your reply
===================================================

Farbar's Service Scanner

--------------------
  • Please download Farbar Service Scanner, save it to your desktop, and run it.
  • Make sure the following options are checked:

Internet Services
Windows Firewall
System Restore
Security Center/Action Center
Windows Update
Windows Defender
Other Services

  • Press Scan
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Result log
  • FSS log

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users