Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

rpcss.dll infection


  • This topic is locked This topic is locked
8 replies to this topic

#1 runntms

runntms

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:05:33 AM

Posted 31 January 2014 - 07:21 PM

I have an annoying trojan Win64/patched that pops up in my AVG every 5 minutes and won't go away. Please help!!!

 

 

Thanks in advance,

Tom

 

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2014 01
Ran by Tom (administrator) on TOM-PC on 31-01-2014 19:16:10
Running from C:\Users\Tom\Desktop
Windows 7 Ultimate (X64) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe
(Conduit) C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe
(Conduit) C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe
(Conduit) C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\loggingserver.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
() C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Samsung Electronics.) C:\Program Files (x86)\Samsung SSD Magician\Samsung Magician.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Malwarebytes Corporation                                    ) C:\Users\Tom\Downloads\mbam-setup.exe
() C:\Users\Tom\AppData\Local\Temp\is-NAIRV.tmp\mbam-setup.tmp
(Malwarebytes Corporation                                    ) C:\Users\Tom\Downloads\mbam-setup.exe
() C:\Users\Tom\AppData\Local\Temp\is-4LUVH.tmp\mbam-setup.tmp
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1100248 2013-12-09] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-09] (NVIDIA Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-27] (Intel Corporation)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2486296 2014-01-05] ()
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-12-11] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKU\S-1-5-21-3281562260-672876486-3167034285-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd)
HKU\S-1-5-21-3281562260-672876486-3167034285-1001\...\Run: [DW7] - "C:\Program Files (x86)\The Weather Channel\The Weather Channel App\TWCApp.exe"
HKU\S-1-5-21-3281562260-672876486-3167034285-1001\...\Run: [AVG-Secure-Search-Update_1113a] - C:\Users\Tom\AppData\Roaming\AVG 1113a Campaign\AVG-Secure-Search-Update-1113a.exe /PROMPT /mid=769e36e9726047d0bf1f5c88787c9e50-ad1491be2ce6c122f6b66faa90e70c2decf7d34c /CMPID=1113a
HKU\S-1-5-21-3281562260-672876486-3167034285-1001\...\Run: [crsscmgr] - C:\Users\Tom\AppData\Roaming\Adobe\crsscmgr\crssc.exe
HKU\S-1-5-21-3281562260-672876486-3167034285-1001\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564528 2013-12-11] (Samsung)
HKU\S-1-5-21-3281562260-672876486-3167034285-1001\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
HKU\S-1-5-21-3281562260-672876486-3167034285-1001\...\MountPoints2: {5f9a1baf-3c63-11e2-aa88-8b8c862dbdc1} - H:\SETUP.EXE
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [1344800 2014-01-29] (Conduit)
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll [1037600 2014-01-29] (Conduit)
Startup: C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Magician.lnk
ShortcutTarget: Samsung Magician.lnk -> C:\Program Files (x86)\Samsung SSD Magician\Samsung Magician.exe (Samsung Electronics.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?ctid=CT3323881&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP1138D3BD-CF0B-4FBF-B84A-CF88DD407B96&SSPV=
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3323881&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP1138D3BD-CF0B-4FBF-B84A-CF88DD407B96&q={searchTerms}&SSPV=
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3323881&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP1138D3BD-CF0B-4FBF-B84A-CF88DD407B96&q={searchTerms}&SSPV=
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={BC8F3CFF-97EA-4850-B6D3-6A44B85CC9D3}&mid=769e36e9726047d0bf1f5c88787c9e50-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=en&ds=AVG&coid=avgtbavg&pr=fr&d=2013-12-11 17:06:40&v=17.1.2.1&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {F06D92E6-B5C8-4C57-A57E-B2255AB3699A} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=714647&p={searchTerms}
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} -  No File
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.3.0.49\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.3.0.49\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.3.0\ViProtocol.dll (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer] 167.206.13.180 167.206.13.181

FireFox:
========
FF ProfilePath: C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\b4xy9ri3.default
FF user.js: detected! => C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\b4xy9ri3.default\user.js
FF NewTab: hxxp://search.conduit.com/?ctid=CT3323881&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=4&UP=SP1138D3BD-CF0B-4FBF-B84A-CF88DD407B96
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Yahoo
FF SearchEngineOrder.user_pref("browser.search.order.2", "");: user_pref("browser.search.order.2", "");
FF SelectedSearchEngine: Google
FF Homepage: hxxp://search.conduit.com/?ctid=CT3323881&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP1138D3BD-CF0B-4FBF-B84A-CF88DD407B96&SSPV=
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.3.0\\npsitesafety.dll (AVG Technologies)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF SearchPlugin: C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\b4xy9ri3.default\searchplugins\conduit-search.xml
FF SearchPlugin: C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\b4xy9ri3.default\searchplugins\safeguard-secure-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml
FF Extension: PSFactoryBuffer - C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\b4xy9ri3.default\Extensions\{0501EAB9-F0A3-990B-B338-15C833E860DF} [2014-01-05]
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49
FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49 [2014-01-05]

==================== Services (Whitelisted) =================

R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.)
R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [2301216 2014-01-29] (Conduit)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-17] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-09] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-09] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-11-10] ()
R2 vToolbarUpdater17.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe [1771544 2014-01-05] (AVG Secure Search)

==================== Drivers (Whitelisted) ====================

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-12-11] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-02] (DT Soft Ltd)
S3 hcwPP2; C:\Windows\System32\DRIVERS\hcwPP2.sys [227328 2007-02-06] (Hauppauge Computer Works, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-12-02] (Duplex Secure Ltd.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-31 19:15 - 2014-01-31 19:15 - 00000000 ____D C:\Users\Tom\Desktop\FRST-OlderVersion
2014-01-31 13:03 - 2014-01-31 13:03 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-31 13:03 - 2014-01-31 13:03 - 00000000 ____D C:\Users\Tom\AppData\Roaming\Malwarebytes
2014-01-31 13:03 - 2014-01-31 13:03 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-31 13:03 - 2014-01-31 13:03 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-31 13:03 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-31 13:02 - 2014-01-31 13:02 - 10284816 _____ (Malwarebytes Corporation                                    ) C:\Users\Tom\Downloads\mbam-setup.exe
2014-01-31 13:02 - 2014-01-31 13:02 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Tom\Downloads\rkill.exe
2014-01-31 13:01 - 2014-01-31 13:01 - 00000000 ____D C:\TDSSKiller_Quarantine
2014-01-31 12:59 - 2014-01-31 12:59 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\Tom\Downloads\tdsskiller.exe
2014-01-31 12:55 - 2014-01-31 12:55 - 00000511 _____ C:\Users\Tom\Downloads\fixlist.txt
2014-01-31 12:49 - 2014-01-31 19:16 - 00019762 _____ C:\Users\Tom\Desktop\FRST.txt
2014-01-31 12:49 - 2014-01-31 12:49 - 00023684 _____ C:\Users\Tom\Desktop\Addition.txt
2014-01-31 12:48 - 2014-01-31 19:16 - 00000000 ____D C:\FRST
2014-01-31 12:48 - 2014-01-31 19:15 - 02080256 _____ (Farbar) C:\Users\Tom\Desktop\FRST64.exe
2014-01-31 12:47 - 2014-01-31 12:47 - 02079744 _____ (Farbar) C:\Users\Tom\Downloads\FRST64.exe
2014-01-29 23:50 - 2014-01-29 23:51 - 00000000 ____D C:\Windows\system32\MRT
2014-01-29 23:50 - 2014-01-06 16:20 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-29 23:42 - 2014-01-29 23:42 - 01069512 _____ (Solid State Networks) C:\Users\Tom\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-29 13:28 - 2014-01-29 13:40 - 00000000 ____D C:\Users\Tom\Documents\SelfMV
2014-01-29 11:31 - 2014-01-29 11:31 - 00000000 ____D C:\Windows\SysWOW64\SearchProtect
2014-01-29 00:46 - 2014-01-29 00:46 - 00000000 ____S C:\Windows\system32\nedcmp.fdf
2014-01-28 23:45 - 2014-01-28 23:45 - 00002002 _____ C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2014-01-28 23:45 - 2014-01-28 23:45 - 00001992 _____ C:\Users\Public\Desktop\Samsung Kies.lnk
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Tom\Documents\samsung
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Tom\AppData\Roaming\Samsung
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Tom\AppData\Local\Samsung
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Program Files (x86)\MyFree Codec
2014-01-28 23:44 - 2014-01-28 23:45 - 00000000 ____D C:\Program Files (x86)\Samsung
2014-01-28 23:44 - 2013-10-30 12:13 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll
2014-01-28 23:44 - 2013-10-30 12:06 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll
2014-01-28 23:36 - 2014-01-28 23:36 - 70015304 _____ (Samsung Electronics Co., Ltd.                                ) C:\Users\Tom\Downloads\KiesSetup.exe
2014-01-28 23:35 - 2014-01-28 23:35 - 38825784 _____ (Samsung Electronics Co., Ltd.                                ) C:\Users\Tom\Downloads\Kies3Setup.exe
2014-01-28 23:34 - 2014-01-28 23:34 - 00615805 _____ (Samsung Kies) C:\Users\Tom\Downloads\kies(1).exe
2014-01-28 23:32 - 2014-01-28 23:41 - 00000000 ____D C:\Users\Tom\AppData\Local\Downloaded Installations
2014-01-28 23:31 - 2014-01-29 11:31 - 00000000 ____D C:\Program Files (x86)\SearchProtect
2014-01-28 23:31 - 2014-01-28 23:31 - 00615805 _____ (Samsung Kies) C:\Users\Tom\Downloads\kies.exe
2014-01-28 23:31 - 2014-01-28 23:31 - 00000000 ____D C:\Users\Tom\AppData\Local\SearchProtect
2014-01-25 21:28 - 2014-01-25 21:29 - 00000000 ____D C:\Program Files (x86)\Samsung SSD Magician
2014-01-25 21:28 - 2013-11-28 22:58 - 15617656 ____R (Samsung Electronics                                         ) C:\Users\Tom\Desktop\Samsung_Magician_v43.exe
2014-01-25 00:32 - 2014-01-25 00:32 - 00000000 ____S C:\Windows\system32\hzdiwxf.aqx
2014-01-22 22:32 - 2014-01-22 22:32 - 00000134 _____ C:\Users\Tom\Desktop\Internet Explorer Troubleshooting.url
2014-01-22 22:31 - 2014-01-22 22:32 - 00001847 _____ C:\Windows\IE9_main.log
2014-01-22 08:52 - 2014-01-22 08:52 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys
2014-01-22 08:52 - 2014-01-22 08:52 - 00108800 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys
2014-01-19 22:38 - 2014-01-19 23:15 - 1861360777 _____ C:\Users\Tom\Downloads\PBS.The.Buddha.720p.x264.AAC.MVGroup.org.mp4
2014-01-16 08:25 - 2014-01-16 08:25 - 00000000 ____S C:\Windows\system32\debrtp.nxi
2014-01-15 21:02 - 2014-01-31 18:23 - 00000093 _____ C:\Windows\system32\tvvcgs.vrq
2014-01-15 21:02 - 2014-01-15 21:02 - 00000064 _____ C:\Windows\system32\hjqc.qca
2014-01-15 21:02 - 2014-01-15 21:02 - 00000000 _____ C:\Windows\system32\zeooxnw.bhl
2014-01-15 19:28 - 2009-09-10 01:28 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-01-15 19:28 - 2009-09-10 00:52 - 00257024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-01-15 19:14 - 2012-12-16 11:52 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-01-15 19:14 - 2012-12-16 09:40 - 00367616 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-01-15 19:14 - 2012-12-16 09:25 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2014-01-15 19:14 - 2012-12-16 09:25 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2014-01-15 19:14 - 2009-10-19 09:46 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-01-15 19:14 - 2009-10-19 09:10 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2014-01-15 19:09 - 2012-03-01 01:54 - 00022896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2014-01-15 19:09 - 2012-03-01 01:40 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-01-15 19:09 - 2012-03-01 01:35 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2014-01-15 19:09 - 2012-03-01 00:45 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-01-15 19:09 - 2012-03-01 00:40 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2014-01-15 19:08 - 2013-03-02 00:49 - 01499648 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-01-15 19:08 - 2013-03-02 00:49 - 01198080 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-01-15 19:08 - 2013-03-02 00:49 - 00134144 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-01-15 19:08 - 2013-03-02 00:44 - 01026560 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2014-01-15 19:08 - 2013-03-02 00:43 - 09377280 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-01-15 19:08 - 2013-03-02 00:43 - 00735744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-01-15 19:08 - 2013-03-02 00:43 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-01-15 19:08 - 2013-03-02 00:43 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-01-15 19:08 - 2013-03-02 00:43 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-01-15 19:08 - 2013-03-02 00:43 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-01-15 19:08 - 2013-03-02 00:42 - 12405760 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-01-15 19:08 - 2013-03-02 00:42 - 02463744 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-01-15 19:08 - 2013-03-02 00:42 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-01-15 19:08 - 2013-03-02 00:42 - 00256000 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-01-15 19:08 - 2013-03-02 00:42 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-01-15 19:08 - 2013-03-02 00:06 - 00981504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-01-15 19:08 - 2013-03-02 00:05 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-01-15 19:08 - 2013-03-02 00:05 - 00132096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-01-15 19:08 - 2013-03-02 00:02 - 06032384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-01-15 19:08 - 2013-03-02 00:02 - 00627200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-01-15 19:08 - 2013-03-02 00:02 - 00606208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2014-01-15 19:08 - 2013-03-02 00:02 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-01-15 19:08 - 2013-03-02 00:02 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-01-15 19:08 - 2013-03-02 00:01 - 11019776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-01-15 19:08 - 2013-03-02 00:01 - 02077184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-01-15 19:08 - 2013-03-02 00:01 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-01-15 19:08 - 2013-03-02 00:01 - 00185856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-01-15 19:08 - 2013-03-02 00:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-01-15 19:08 - 2013-03-02 00:01 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-01-15 19:08 - 2013-03-01 23:38 - 00482816 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-01-15 19:08 - 2013-03-01 23:03 - 00386048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-01-15 19:08 - 2013-03-01 22:56 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-01-15 19:08 - 2013-03-01 22:56 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-01-15 19:08 - 2013-03-01 22:30 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-01-15 19:08 - 2013-03-01 22:29 - 01638912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-01-15 19:08 - 2013-03-01 22:29 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-01-15 19:08 - 2013-02-12 10:42 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-01-15 19:08 - 2013-02-12 10:37 - 03138048 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-01-15 19:08 - 2013-02-12 10:31 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-01-15 19:08 - 2013-02-12 10:13 - 02691072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-01-15 19:08 - 2013-02-12 10:07 - 00131072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-01-15 19:08 - 2013-02-12 08:59 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-01-15 19:08 - 2013-01-04 00:41 - 01893224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-01-15 19:08 - 2013-01-04 00:40 - 00287576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-01-15 19:08 - 2013-01-04 00:37 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-01-15 19:08 - 2013-01-04 00:37 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-01-15 19:08 - 2013-01-04 00:37 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-01-15 19:08 - 2013-01-04 00:36 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-01-15 19:08 - 2013-01-04 00:33 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-01-15 19:08 - 2013-01-04 00:30 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-01-15 19:08 - 2013-01-04 00:30 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:51 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-01-15 19:08 - 2013-01-03 23:51 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-01-15 19:08 - 2013-01-03 23:51 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 22:19 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-01-15 19:08 - 2013-01-03 21:48 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-01-15 19:08 - 2013-01-03 21:48 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-01-15 19:08 - 2013-01-03 21:48 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-01-15 19:08 - 2013-01-03 21:48 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-01-15 19:08 - 2013-01-03 21:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 21:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 21:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 21:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2014-01-15 19:08 - 2012-11-09 00:34 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-01-15 19:08 - 2012-11-09 00:34 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-01-15 19:08 - 2012-11-08 23:49 - 00492032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2014-01-15 19:08 - 2012-11-08 23:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-01-15 19:08 - 2012-06-09 00:30 - 14165504 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-01-15 19:08 - 2012-06-08 23:46 - 12868608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-01-15 19:08 - 2012-03-03 01:29 - 01837568 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-01-15 19:08 - 2012-03-03 01:29 - 01541120 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-01-15 19:08 - 2012-03-03 01:29 - 00902656 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-01-15 19:08 - 2012-03-03 01:29 - 00320512 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-01-15 19:08 - 2012-03-03 01:29 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-01-15 19:08 - 2012-03-03 00:40 - 01170944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-01-15 19:08 - 2012-03-03 00:40 - 01074176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-01-15 19:08 - 2012-03-03 00:40 - 00739840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-01-15 19:08 - 2012-03-03 00:40 - 00218624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-01-15 19:08 - 2012-03-03 00:40 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-01-15 19:08 - 2011-10-26 00:22 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-01-15 19:08 - 2011-10-26 00:22 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-01-15 19:08 - 2011-10-25 23:28 - 01328640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-01-15 19:08 - 2011-10-25 23:28 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-01-15 19:08 - 2011-07-08 21:44 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-01-15 19:08 - 2011-05-03 21:51 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-01-15 19:08 - 2011-05-03 21:51 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-01-15 19:08 - 2009-09-03 02:36 - 01975296 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2014-01-15 19:08 - 2009-09-03 02:04 - 01320960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2014-01-15 19:07 - 2013-04-12 09:36 - 01653096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-01-15 19:07 - 2013-03-19 01:19 - 05497688 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-01-15 19:07 - 2013-03-19 00:54 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-01-15 19:07 - 2013-03-19 00:06 - 03958120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-01-15 19:07 - 2013-03-19 00:06 - 03902312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-01-15 19:07 - 2013-03-18 23:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2014-01-15 19:07 - 2013-03-18 22:19 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-01-15 19:07 - 2013-02-28 22:32 - 03150848 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-15 19:07 - 2013-02-12 09:02 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-01-15 19:07 - 2012-11-20 00:55 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-01-15 19:07 - 2012-11-20 00:10 - 00219136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-01-15 19:07 - 2012-11-02 00:30 - 02001408 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-01-15 19:07 - 2012-11-02 00:30 - 01880064 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-01-15 19:07 - 2012-11-02 00:27 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-01-15 19:07 - 2012-11-01 23:50 - 01388544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-01-15 19:07 - 2012-11-01 23:50 - 01236992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-01-15 19:07 - 2012-11-01 23:48 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2014-01-15 19:07 - 2012-09-25 17:39 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-01-15 19:07 - 2012-09-25 16:55 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2014-01-15 19:07 - 2012-09-06 12:38 - 00295792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2014-01-15 19:07 - 2012-08-24 13:05 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-01-15 19:07 - 2012-08-24 12:10 - 00172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-01-15 19:07 - 2012-08-10 19:53 - 00714752 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-01-15 19:07 - 2012-08-10 18:54 - 00541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-01-15 19:07 - 2012-07-04 17:04 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-01-15 19:07 - 2012-07-04 17:01 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-01-15 19:07 - 2012-07-04 17:01 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-01-15 19:07 - 2012-07-04 16:26 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2014-01-15 19:07 - 2012-07-04 16:23 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2014-01-15 19:07 - 2012-06-16 00:25 - 00850944 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-01-15 19:07 - 2012-06-16 00:25 - 00609792 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-01-15 19:07 - 2012-06-15 23:37 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-01-15 19:07 - 2012-06-15 23:36 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-01-15 19:07 - 2012-06-02 00:38 - 00152432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-01-15 19:07 - 2012-06-02 00:38 - 00095088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-01-15 19:07 - 2012-06-02 00:37 - 00459216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-01-15 19:07 - 2012-06-02 00:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-01-15 19:07 - 2012-06-02 00:25 - 01462784 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-01-15 19:07 - 2012-06-02 00:25 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-01-15 19:07 - 2012-06-02 00:25 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-01-15 19:07 - 2012-06-01 23:48 - 00225280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-01-15 19:07 - 2012-06-01 23:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-01-15 19:07 - 2012-06-01 23:45 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-01-15 19:07 - 2012-06-01 23:45 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-01-15 19:07 - 2012-06-01 23:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2014-01-15 19:07 - 2012-06-01 23:42 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-01-15 19:07 - 2012-05-14 00:20 - 00956416 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-01-15 19:07 - 2012-04-27 22:50 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-01-15 19:07 - 2012-04-26 00:34 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-01-15 19:07 - 2012-04-26 00:34 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-01-15 19:07 - 2012-04-26 00:28 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-01-15 19:07 - 2012-03-17 02:55 - 00075632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-01-15 19:07 - 2012-02-15 01:27 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-01-15 19:07 - 2012-02-15 00:44 - 00826368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2014-01-15 19:07 - 2012-02-14 23:46 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-01-15 19:07 - 2011-12-27 22:59 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-01-15 19:07 - 2011-12-16 03:42 - 00634368 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2014-01-15 19:07 - 2011-12-16 02:59 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2014-01-15 19:07 - 2011-11-17 02:12 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2014-01-15 19:07 - 2011-11-17 02:11 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-01-15 19:07 - 2011-11-17 02:11 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-01-15 19:07 - 2011-11-17 02:11 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-01-15 19:07 - 2011-11-17 02:08 - 01446912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-01-15 19:07 - 2011-11-17 02:05 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-01-15 19:07 - 2011-11-17 00:39 - 00314368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2014-01-15 19:07 - 2011-10-15 01:25 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2014-01-15 19:07 - 2011-10-15 00:48 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2014-01-15 19:07 - 2011-08-27 00:40 - 00861184 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-01-15 19:07 - 2011-08-27 00:40 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2014-01-15 19:07 - 2011-08-26 23:43 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-01-15 19:07 - 2011-08-26 23:43 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2014-01-15 19:07 - 2011-08-17 00:32 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2014-01-15 19:07 - 2011-08-17 00:27 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax
2014-01-15 19:07 - 2011-08-17 00:27 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2014-01-15 19:07 - 2011-08-17 00:27 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax
2014-01-15 19:07 - 2011-08-17 00:27 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax
2014-01-15 19:07 - 2011-08-16 23:26 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2014-01-15 19:07 - 2011-08-16 23:22 - 00204288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSNP.ax
2014-01-15 19:07 - 2011-08-16 23:22 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2014-01-15 19:07 - 2011-08-16 23:22 - 00072704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Mpeg2Data.ax
2014-01-15 19:07 - 2011-08-16 23:22 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSDvbNP.ax
2014-01-15 19:07 - 2011-06-15 04:58 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2014-01-15 19:07 - 2011-06-15 04:58 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2014-01-15 19:07 - 2011-06-15 04:58 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2014-01-15 19:07 - 2011-06-15 04:58 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2014-01-15 19:07 - 2011-06-15 04:04 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
2014-01-15 19:07 - 2011-06-15 04:04 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
2014-01-15 19:07 - 2011-06-15 04:04 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
2014-01-15 19:07 - 2011-06-15 04:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
2014-01-15 19:07 - 2011-06-15 04:04 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
2014-01-15 19:07 - 2011-05-24 06:21 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-01-15 19:07 - 2011-05-24 05:34 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2014-01-15 19:07 - 2011-05-24 05:34 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2014-01-15 19:07 - 2011-05-24 05:34 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2014-01-15 19:07 - 2011-05-24 05:32 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2014-01-15 19:07 - 2011-05-03 00:21 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-01-15 19:07 - 2011-05-02 23:50 - 00740864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2014-01-15 19:07 - 2011-04-28 22:13 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2014-01-15 19:07 - 2011-04-28 22:12 - 00399872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-01-15 19:07 - 2011-04-28 22:12 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-01-15 19:07 - 2011-04-26 21:57 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2014-01-15 19:07 - 2011-03-11 01:19 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2014-01-15 19:07 - 2011-03-11 01:19 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2014-01-15 19:07 - 2011-03-11 00:40 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2014-01-15 19:07 - 2011-03-11 00:40 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2014-01-15 19:07 - 2011-03-03 01:17 - 00356352 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-01-15 19:07 - 2011-03-03 01:17 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-01-15 19:07 - 2011-03-03 01:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2014-01-15 19:07 - 2011-03-03 00:29 - 00269824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2014-01-15 19:07 - 2011-03-03 00:27 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2014-01-15 19:07 - 2011-02-23 00:15 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2014-01-15 19:07 - 2011-02-12 01:14 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2014-01-15 19:07 - 2011-02-05 07:41 - 00640896 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-01-15 19:07 - 2011-02-05 07:41 - 00556928 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-01-15 19:07 - 2011-02-05 07:41 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll
2014-01-15 19:07 - 2011-02-05 07:41 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll
2014-01-15 19:07 - 2011-02-05 07:41 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll
2014-01-15 19:07 - 2011-02-05 07:39 - 00603976 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-01-15 19:07 - 2011-02-05 07:39 - 00518160 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-01-15 19:07 - 2010-12-23 01:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2014-01-15 19:07 - 2010-12-23 01:07 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2014-01-15 19:07 - 2010-12-23 01:02 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2014-01-15 19:07 - 2010-12-23 00:28 - 00850432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2014-01-15 19:07 - 2010-12-23 00:28 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2014-01-15 19:07 - 2010-12-23 00:24 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax
2014-01-15 19:07 - 2010-12-18 01:08 - 01097216 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-01-15 19:07 - 2010-12-18 00:26 - 01034240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-01-15 19:07 - 2010-11-02 00:18 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\wmicmiplugin.dll
2014-01-15 19:07 - 2010-11-02 00:17 - 01169408 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2014-01-15 19:07 - 2010-11-02 00:17 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2014-01-15 19:07 - 2010-11-02 00:16 - 01114624 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-01-15 19:07 - 2010-11-02 00:10 - 00464384 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2014-01-15 19:07 - 2010-11-02 00:10 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe
2014-01-15 19:07 - 2010-11-01 23:40 - 00496128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll
2014-01-15 19:07 - 2010-11-01 23:40 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2014-01-15 19:07 - 2010-11-01 23:34 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2014-01-15 19:07 - 2010-11-01 23:34 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
2014-01-15 19:07 - 2010-10-16 00:23 - 00112000 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-01-15 19:07 - 2010-10-16 00:17 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\odbc32.dll
2014-01-15 19:07 - 2010-10-15 23:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbc32.dll
2014-01-15 19:07 - 2010-09-01 00:21 - 14627840 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-01-15 19:07 - 2010-09-01 00:12 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-01-15 19:07 - 2010-08-31 23:29 - 11406848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-01-15 19:07 - 2010-08-31 23:23 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-01-15 19:07 - 2010-08-30 23:32 - 00954752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc40.dll
2014-01-15 19:07 - 2010-08-30 23:32 - 00954288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc40u.dll
2014-01-15 19:07 - 2010-08-26 00:27 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2014-01-15 19:07 - 2010-08-25 23:39 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2014-01-15 19:07 - 2010-08-21 01:38 - 01024512 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2014-01-15 19:07 - 2010-08-21 01:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-01-15 19:07 - 2010-08-21 01:29 - 00558592 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2014-01-15 19:07 - 2010-08-21 00:36 - 00738816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
2014-01-15 19:07 - 2010-08-21 00:33 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2014-01-15 19:07 - 2010-07-29 01:30 - 00082944 _____ (Radius Inc.) C:\Windows\SysWOW64\iccvid.dll
2014-01-15 19:07 - 2010-06-29 00:39 - 02085376 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2014-01-15 19:07 - 2010-06-29 00:02 - 01413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2014-01-15 19:07 - 2010-06-19 01:53 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\rtutils.dll
2014-01-15 19:07 - 2010-06-19 01:23 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtutils.dll
2014-01-15 19:07 - 2010-05-19 14:48 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-01-15 19:07 - 2010-05-05 02:37 - 00483840 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2014-01-15 19:07 - 2010-05-05 01:46 - 00363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2014-01-15 19:07 - 2010-03-05 02:52 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2014-01-15 19:07 - 2010-03-05 02:42 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2014-01-15 19:07 - 2010-01-09 02:19 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\cabview.dll
2014-01-15 19:07 - 2010-01-09 01:52 - 00132608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cabview.dll
2014-01-15 19:07 - 2009-12-19 04:50 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\tsbyuv.dll
2014-01-15 19:07 - 2009-12-19 04:47 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\msvidc32.dll
2014-01-15 19:07 - 2009-12-19 04:47 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msyuv.dll
2014-01-15 19:07 - 2009-12-19 04:47 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\msrle32.dll
2014-01-15 19:07 - 2009-12-19 04:46 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\iyuv_32.dll
2014-01-15 19:07 - 2009-12-19 04:02 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\avifil32.dll
2014-01-15 19:07 - 2009-12-19 04:02 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mciavi32.dll
2014-01-15 19:07 - 2009-12-19 04:02 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iyuv_32.dll
2014-01-15 19:07 - 2009-12-19 04:02 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvidc32.dll
2014-01-15 19:07 - 2009-12-19 04:02 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msyuv.dll
2014-01-15 19:07 - 2009-12-19 04:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrle32.dll
2014-01-15 19:07 - 2009-12-19 04:02 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsbyuv.dll
2014-01-15 19:07 - 2009-10-31 01:34 - 02870272 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2014-01-15 19:07 - 2009-10-31 00:45 - 02614272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2014-01-15 19:07 - 2009-10-28 01:24 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-01-15 19:07 - 2009-10-01 23:32 - 00982600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-01-15 19:07 - 2009-08-29 02:50 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\msasn1.dll
2014-01-15 19:07 - 2009-08-29 01:57 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msasn1.dll
2014-01-15 19:06 - 2011-11-17 02:14 - 01739160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-01-15 19:06 - 2011-11-17 00:41 - 01292592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-01-15 19:06 - 2010-08-27 01:14 - 00236032 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2014-01-15 19:06 - 2010-08-27 00:46 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
2014-01-15 19:04 - 2011-11-19 10:07 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-01-15 19:04 - 2011-11-19 09:06 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-01-15 18:07 - 2014-01-15 18:07 - 00219314 ____S C:\Windows\system32\pqrdrj.vcc
2014-01-09 12:57 - 2014-01-09 12:57 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2014-01-09 12:56 - 2013-12-19 15:33 - 30372640 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 22960416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 18222008 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 12645664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-01-09 12:56 - 2013-12-19 15:33 - 11605752 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 11554264 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 09700224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 09657464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433221.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433221.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00882464 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00879392 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00852768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00847648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-01-09 12:56 - 2013-11-28 08:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2014-01-09 12:56 - 2013-11-28 08:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2014-01-09 11:40 - 2013-12-05 03:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-01-09 11:40 - 2013-12-05 03:42 - 00032544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-01-05 16:33 - 2014-01-30 00:06 - 00000000 ____D C:\Users\Tom\AppData\Local\Owqnics

==================== One Month Modified Files and Folders =======

2014-01-31 19:16 - 2014-01-31 12:49 - 00019762 _____ C:\Users\Tom\Desktop\FRST.txt
2014-01-31 19:16 - 2014-01-31 12:48 - 00000000 ____D C:\FRST
2014-01-31 19:15 - 2014-01-31 19:15 - 00000000 ____D C:\Users\Tom\Desktop\FRST-OlderVersion
2014-01-31 19:15 - 2014-01-31 12:48 - 02080256 _____ (Farbar) C:\Users\Tom\Desktop\FRST64.exe
2014-01-31 19:09 - 2012-12-02 04:36 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-31 18:23 - 2014-01-15 21:02 - 00000093 _____ C:\Windows\system32\tvvcgs.vrq
2014-01-31 18:18 - 2012-12-02 05:33 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2014-01-31 18:06 - 2009-07-13 23:45 - 00013584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-31 18:06 - 2009-07-13 23:45 - 00013584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-31 17:33 - 2012-12-02 04:24 - 00000000 ____D C:\ProgramData\MFAData
2014-01-31 13:03 - 2014-01-31 13:03 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-31 13:03 - 2014-01-31 13:03 - 00000000 ____D C:\Users\Tom\AppData\Roaming\Malwarebytes
2014-01-31 13:03 - 2014-01-31 13:03 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-31 13:03 - 2014-01-31 13:03 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-31 13:02 - 2014-01-31 13:02 - 10284816 _____ (Malwarebytes Corporation                                    ) C:\Users\Tom\Downloads\mbam-setup.exe
2014-01-31 13:02 - 2014-01-31 13:02 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Tom\Downloads\rkill.exe
2014-01-31 13:01 - 2014-01-31 13:01 - 00000000 ____D C:\TDSSKiller_Quarantine
2014-01-31 12:59 - 2014-01-31 12:59 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\Tom\Downloads\tdsskiller.exe
2014-01-31 12:55 - 2014-01-31 12:55 - 00000511 _____ C:\Users\Tom\Downloads\fixlist.txt
2014-01-31 12:49 - 2014-01-31 12:49 - 00023684 _____ C:\Users\Tom\Desktop\Addition.txt
2014-01-31 12:47 - 2014-01-31 12:47 - 02079744 _____ (Farbar) C:\Users\Tom\Downloads\FRST64.exe
2014-01-31 07:12 - 2012-12-02 04:20 - 01178139 _____ C:\Windows\WindowsUpdate.log
2014-01-31 00:06 - 2013-11-20 14:35 - 00003758 _____ C:\Windows\System32\Tasks\AutoKMS
2014-01-30 07:18 - 2009-07-14 00:13 - 00779266 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-30 07:15 - 2009-07-13 23:51 - 00030943 _____ C:\Windows\setupact.log
2014-01-30 00:06 - 2014-01-05 16:33 - 00000000 ____D C:\Users\Tom\AppData\Local\Owqnics
2014-01-30 00:06 - 2012-12-02 05:33 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-01-30 00:06 - 2012-12-02 04:24 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-30 00:06 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-30 00:00 - 2013-11-14 21:18 - 00000000 ____D C:\ProgramData\AVG2014
2014-01-29 23:57 - 2013-11-20 13:23 - 00772990 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2014-01-29 23:51 - 2014-01-29 23:50 - 00000000 ____D C:\Windows\system32\MRT
2014-01-29 23:42 - 2014-01-29 23:42 - 01069512 _____ (Solid State Networks) C:\Users\Tom\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-29 18:09 - 2013-11-10 12:20 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2014-01-29 18:09 - 2012-12-02 22:05 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2014-01-29 13:40 - 2014-01-29 13:28 - 00000000 ____D C:\Users\Tom\Documents\SelfMV
2014-01-29 11:31 - 2014-01-29 11:31 - 00000000 ____D C:\Windows\SysWOW64\SearchProtect
2014-01-29 11:31 - 2014-01-28 23:31 - 00000000 ____D C:\Program Files (x86)\SearchProtect
2014-01-29 00:46 - 2014-01-29 00:46 - 00000000 ____S C:\Windows\system32\nedcmp.fdf
2014-01-28 23:45 - 2014-01-28 23:45 - 00002002 _____ C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2014-01-28 23:45 - 2014-01-28 23:45 - 00001992 _____ C:\Users\Public\Desktop\Samsung Kies.lnk
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Tom\Documents\samsung
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Tom\AppData\Roaming\Samsung
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Tom\AppData\Local\Samsung
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Program Files (x86)\MyFree Codec
2014-01-28 23:45 - 2014-01-28 23:44 - 00000000 ____D C:\Program Files (x86)\Samsung
2014-01-28 23:45 - 2012-12-02 04:50 - 00000000 ____D C:\ProgramData\Samsung
2014-01-28 23:44 - 2012-12-02 05:28 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2014-01-28 23:41 - 2014-01-28 23:32 - 00000000 ____D C:\Users\Tom\AppData\Local\Downloaded Installations
2014-01-28 23:36 - 2014-01-28 23:36 - 70015304 _____ (Samsung Electronics Co., Ltd.                                ) C:\Users\Tom\Downloads\KiesSetup.exe
2014-01-28 23:35 - 2014-01-28 23:35 - 38825784 _____ (Samsung Electronics Co., Ltd.                                ) C:\Users\Tom\Downloads\Kies3Setup.exe
2014-01-28 23:34 - 2014-01-28 23:34 - 00615805 _____ (Samsung Kies) C:\Users\Tom\Downloads\kies(1).exe
2014-01-28 23:31 - 2014-01-28 23:31 - 00615805 _____ (Samsung Kies) C:\Users\Tom\Downloads\kies.exe
2014-01-28 23:31 - 2014-01-28 23:31 - 00000000 ____D C:\Users\Tom\AppData\Local\SearchProtect
2014-01-28 21:38 - 2012-12-02 04:35 - 00000000 ____D C:\Program Files (x86)\Origin
2014-01-28 17:08 - 2012-12-02 16:23 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2014-01-25 21:29 - 2014-01-25 21:28 - 00000000 ____D C:\Program Files (x86)\Samsung SSD Magician
2014-01-25 21:28 - 2013-11-11 14:02 - 00001131 _____ C:\Users\Public\Desktop\Samsung Magician.lnk
2014-01-25 21:28 - 2012-12-02 04:20 - 00000000 ___RD C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-25 21:21 - 2013-11-20 14:35 - 00000000 ____D C:\Windows\AutoKMS
2014-01-25 21:21 - 2013-11-20 12:48 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-01-25 21:21 - 2012-12-02 04:26 - 00000000 ____D C:\Users\Tom\AppData\Roaming\uTorrent
2014-01-25 21:21 - 2012-12-02 04:23 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2014-01-25 21:21 - 2012-12-02 04:23 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2014-01-25 21:21 - 2012-12-02 04:20 - 00000000 ___RD C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-01-25 21:21 - 2012-12-02 04:20 - 00000000 ____D C:\Users\Tom
2014-01-25 21:21 - 2009-07-14 02:46 - 00000000 ____D C:\Windows\ShellNew
2014-01-25 21:21 - 2009-07-14 02:46 - 00000000 ____D C:\Program Files\Windows Journal
2014-01-25 21:21 - 2009-07-14 00:32 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2014-01-25 21:21 - 2009-07-14 00:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\system32\sysprep
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\system32\NDF
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\servicing
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\security
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\registration
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\Help
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\AppCompat
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\System
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\Services
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2014-01-25 00:32 - 2014-01-25 00:32 - 00000000 ____S C:\Windows\system32\hzdiwxf.aqx
2014-01-22 22:32 - 2014-01-22 22:32 - 00000134 _____ C:\Users\Tom\Desktop\Internet Explorer Troubleshooting.url
2014-01-22 22:32 - 2014-01-22 22:31 - 00001847 _____ C:\Windows\IE9_main.log
2014-01-22 08:52 - 2014-01-22 08:52 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys
2014-01-22 08:52 - 2014-01-22 08:52 - 00108800 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys
2014-01-21 18:49 - 2012-12-02 04:52 - 00000000 ____D C:\Users\Tom\AppData\Roaming\Adobe
2014-01-19 23:15 - 2014-01-19 22:38 - 1861360777 _____ C:\Users\Tom\Downloads\PBS.The.Buddha.720p.x264.AAC.MVGroup.org.mp4
2014-01-16 08:25 - 2014-01-16 08:25 - 00000000 ____S C:\Windows\system32\debrtp.nxi
2014-01-15 21:02 - 2014-01-15 21:02 - 00000064 _____ C:\Windows\system32\hjqc.qca
2014-01-15 21:02 - 2014-01-15 21:02 - 00000000 _____ C:\Windows\system32\zeooxnw.bhl
2014-01-15 21:02 - 2009-07-13 23:45 - 00442248 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-15 18:07 - 2014-01-15 18:07 - 00219314 ____S C:\Windows\system32\pqrdrj.vcc
2014-01-09 12:57 - 2014-01-09 12:57 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2014-01-09 12:57 - 2012-12-02 04:23 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2014-01-06 16:20 - 2014-01-29 23:50 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-05 16:33 - 2013-12-11 17:06 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2014-01-05 11:46 - 2013-12-11 17:06 - 00003744 _____ C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2014-01-05 11:46 - 2013-12-11 17:06 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
ZeroAccess:
C:\Users\Tom\AppData\Local\Google\Desktop\Install

Some content of TEMP:
====================
C:\Users\Tom\AppData\Local\Temp\40740.exe
C:\Users\Tom\AppData\Local\Temp\6_Offer_16.exe
C:\Users\Tom\AppData\Local\Temp\7za.exe
C:\Users\Tom\AppData\Local\Temp\cudart32_50_35.dll
C:\Users\Tom\AppData\Local\Temp\DownloadManager.exe
C:\Users\Tom\AppData\Local\Temp\DTLite4461-0327.exe
C:\Users\Tom\AppData\Local\Temp\facebook.exe
C:\Users\Tom\AppData\Local\Temp\htmlayout.dll
C:\Users\Tom\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Tom\AppData\Local\Temp\jre-7u9-windows-i586-iftw.exe
C:\Users\Tom\AppData\Local\Temp\kpbryvbx.exe
C:\Users\Tom\AppData\Local\Temp\lhxdozzd.exe
C:\Users\Tom\AppData\Local\Temp\libcurl-4.dll
C:\Users\Tom\AppData\Local\Temp\nsi430.exe
C:\Users\Tom\AppData\Local\Temp\nso5D7.exe
C:\Users\Tom\AppData\Local\Temp\nst16BA.exe
C:\Users\Tom\AppData\Local\Temp\nsy1504.exe
C:\Users\Tom\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\Tom\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Tom\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\Tom\AppData\Local\Temp\nvStInst.exe
C:\Users\Tom\AppData\Local\Temp\ose00000.exe
C:\Users\Tom\AppData\Local\Temp\pthreadGC2.dll
C:\Users\Tom\AppData\Local\Temp\pthreadVC2.dll
C:\Users\Tom\AppData\Local\Temp\qlmlignh.exe
C:\Users\Tom\AppData\Local\Temp\SearchProtectINT.exe
C:\Users\Tom\AppData\Local\Temp\sonarinst.exe
C:\Users\Tom\AppData\Local\Temp\SPSetup.exe
C:\Users\Tom\AppData\Local\Temp\The_Weather_Channel_Application.exe
C:\Users\Tom\AppData\Local\Temp\update.exe
C:\Users\Tom\AppData\Local\Temp\uttB64F.tmp.exe
C:\Users\Tom\AppData\Local\Temp\vore.exe
C:\Users\Tom\AppData\Local\Temp\Xvid.exe
C:\Users\Tom\AppData\Local\Temp\zlib1.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2009-07-13 19:00] - [2009-07-13 20:41] - 0510464 ____A (Microsoft Corporation) 0C700C322E1E6ABBEDB2127643A2F80B

 ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected.
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-29 02:25

==================== End Of Log ============================



BC AdBot (Login to Remove)

 


#2 B-boy/StyLe/

B-boy/StyLe/

    Bleepin' Freestyler


  • Malware Response Team
  • 8,307 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:01:33 PM

Posted 31 January 2014 - 08:00 PM

Hello! Welcome to BleepingComputer Forums! :welcome:
My name is Georgi and and I will be helping you with your computer problems.

Before we begin, please note the following:

  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The logs can take some time to research, so please be patient with me.
  • Stay with the topic until I tell you that your system is clean. Missing symptoms does not mean that everything is okay.
  • Instructions that I give are for your system only!
  • Please do not run any tools until requested ! The reason for this is so I know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.
  • Please perform all steps in the order received. If you can't understand something don't hesitate to ask.
  • Again I would like to remind you to make no further changes to your computer unless I direct you to do so. I will not help you if you do not follow my instructions.

 

  • Please re-run FRST again and type the following in the edit box after Search: rpcss.dll
  • Click the Search button
  • It will make a log (Search.txt)- please post the log into your reply to me.
  • Also you forgot to post the log - Addition.txt. Please post that log as well.

 

 

Regards,

Georgi


cXfZ4wS.png


#3 runntms

runntms
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:05:33 AM

Posted 31 January 2014 - 08:22 PM

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2014 01
Ran by Tom (administrator) on TOM-PC on 31-01-2014 20:20:16
Running from C:\Users\Tom\Desktop
Windows 7 Ultimate (X64) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\loggingserver.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
() C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Samsung Electronics.) C:\Program Files (x86)\Samsung SSD Magician\Samsung Magician.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1100248 2013-12-09] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-09] (NVIDIA Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-27] (Intel Corporation)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2486296 2014-01-05] ()
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-12-11] (Samsung Electronics Co., Ltd.)
HKU\S-1-5-21-3281562260-672876486-3167034285-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd)
HKU\S-1-5-21-3281562260-672876486-3167034285-1001\...\Run: [DW7] - "C:\Program Files (x86)\The Weather Channel\The Weather Channel App\TWCApp.exe"
HKU\S-1-5-21-3281562260-672876486-3167034285-1001\...\Run: [AVG-Secure-Search-Update_1113a] - C:\Users\Tom\AppData\Roaming\AVG 1113a Campaign\AVG-Secure-Search-Update-1113a.exe /PROMPT /mid=769e36e9726047d0bf1f5c88787c9e50-ad1491be2ce6c122f6b66faa90e70c2decf7d34c /CMPID=1113a
HKU\S-1-5-21-3281562260-672876486-3167034285-1001\...\Run: [crsscmgr] - C:\Users\Tom\AppData\Roaming\Adobe\crsscmgr\crssc.exe
HKU\S-1-5-21-3281562260-672876486-3167034285-1001\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564528 2013-12-11] (Samsung)
HKU\S-1-5-21-3281562260-672876486-3167034285-1001\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
HKU\S-1-5-21-3281562260-672876486-3167034285-1001\...\MountPoints2: {5f9a1baf-3c63-11e2-aa88-8b8c862dbdc1} - H:\SETUP.EXE
Startup: C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Magician.lnk
ShortcutTarget: Samsung Magician.lnk -> C:\Program Files (x86)\Samsung SSD Magician\Samsung Magician.exe (Samsung Electronics.)

==================== Internet (Whitelisted) ====================

StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3323881&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP1138D3BD-CF0B-4FBF-B84A-CF88DD407B96&q={searchTerms}&SSPV=
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3323881&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP1138D3BD-CF0B-4FBF-B84A-CF88DD407B96&q={searchTerms}&SSPV=
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={BC8F3CFF-97EA-4850-B6D3-6A44B85CC9D3}&mid=769e36e9726047d0bf1f5c88787c9e50-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=en&ds=AVG&coid=avgtbavg&pr=fr&d=2013-12-11 17:06:40&v=17.1.2.1&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {F06D92E6-B5C8-4C57-A57E-B2255AB3699A} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=714647&p={searchTerms}
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} -  No File
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.3.0.49\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.3.0.49\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.3.0\ViProtocol.dll (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer] 167.206.13.180 167.206.13.181

FireFox:
========
FF ProfilePath: C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\b4xy9ri3.default
FF user.js: detected! => C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\b4xy9ri3.default\user.js
FF NewTab: hxxp://search.conduit.com/?ctid=CT3323881&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=4&UP=SP1138D3BD-CF0B-4FBF-B84A-CF88DD407B96
FF SearchEngineOrder.1: Yahoo
FF SearchEngineOrder.user_pref("browser.search.order.2", "");: user_pref("browser.search.order.2", "");
FF SelectedSearchEngine: Google
FF Homepage: hxxp://search.conduit.com/?ctid=CT3323881&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP1138D3BD-CF0B-4FBF-B84A-CF88DD407B96&SSPV=
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.3.0\\npsitesafety.dll (AVG Technologies)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF SearchPlugin: C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\b4xy9ri3.default\searchplugins\conduit-search.xml
FF SearchPlugin: C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\b4xy9ri3.default\searchplugins\safeguard-secure-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml
FF Extension: PSFactoryBuffer - C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\b4xy9ri3.default\Extensions\{0501EAB9-F0A3-990B-B338-15C833E860DF} [2014-01-05]
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49
FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49 [2014-01-05]

==================== Services (Whitelisted) =================

R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-17] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-09] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-09] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-11-10] ()
R2 vToolbarUpdater17.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe [1771544 2014-01-05] (AVG Secure Search)

==================== Drivers (Whitelisted) ====================

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-12-11] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-02] (DT Soft Ltd)
S3 hcwPP2; C:\Windows\System32\DRIVERS\hcwPP2.sys [227328 2007-02-06] (Hauppauge Computer Works, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-12-02] (Duplex Secure Ltd.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-31 20:17 - 2014-01-31 20:17 - 00000604 _____ C:\Users\Tom\Desktop\Search.txt
2014-01-31 19:15 - 2014-01-31 19:15 - 00000000 ____D C:\Users\Tom\Desktop\FRST-OlderVersion
2014-01-31 13:03 - 2014-01-31 19:31 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-31 13:03 - 2014-01-31 13:03 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-31 13:03 - 2014-01-31 13:03 - 00000000 ____D C:\Users\Tom\AppData\Roaming\Malwarebytes
2014-01-31 13:03 - 2014-01-31 13:03 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-31 13:03 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-31 13:02 - 2014-01-31 13:02 - 10284816 _____ (Malwarebytes Corporation                                    ) C:\Users\Tom\Downloads\mbam-setup.exe
2014-01-31 13:02 - 2014-01-31 13:02 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Tom\Downloads\rkill.exe
2014-01-31 13:01 - 2014-01-31 13:01 - 00000000 ____D C:\TDSSKiller_Quarantine
2014-01-31 12:59 - 2014-01-31 12:59 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\Tom\Downloads\tdsskiller.exe
2014-01-31 12:55 - 2014-01-31 12:55 - 00000511 _____ C:\Users\Tom\Downloads\fixlist.txt
2014-01-31 12:49 - 2014-01-31 20:20 - 00018242 _____ C:\Users\Tom\Desktop\FRST.txt
2014-01-31 12:49 - 2014-01-31 12:49 - 00023684 _____ C:\Users\Tom\Desktop\Addition.txt
2014-01-31 12:48 - 2014-01-31 20:20 - 00000000 ____D C:\FRST
2014-01-31 12:48 - 2014-01-31 19:15 - 02080256 _____ (Farbar) C:\Users\Tom\Desktop\FRST64.exe
2014-01-31 12:47 - 2014-01-31 12:47 - 02079744 _____ (Farbar) C:\Users\Tom\Downloads\FRST64.exe
2014-01-29 23:50 - 2014-01-29 23:51 - 00000000 ____D C:\Windows\system32\MRT
2014-01-29 23:50 - 2014-01-06 16:20 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-29 23:42 - 2014-01-29 23:42 - 01069512 _____ (Solid State Networks) C:\Users\Tom\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-29 13:28 - 2014-01-29 13:40 - 00000000 ____D C:\Users\Tom\Documents\SelfMV
2014-01-29 11:31 - 2014-01-29 11:31 - 00000000 ____D C:\Windows\SysWOW64\SearchProtect
2014-01-29 00:46 - 2014-01-29 00:46 - 00000000 ____S C:\Windows\system32\nedcmp.fdf
2014-01-28 23:45 - 2014-01-28 23:45 - 00002002 _____ C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2014-01-28 23:45 - 2014-01-28 23:45 - 00001992 _____ C:\Users\Public\Desktop\Samsung Kies.lnk
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Tom\Documents\samsung
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Tom\AppData\Roaming\Samsung
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Tom\AppData\Local\Samsung
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Program Files (x86)\MyFree Codec
2014-01-28 23:44 - 2014-01-28 23:45 - 00000000 ____D C:\Program Files (x86)\Samsung
2014-01-28 23:44 - 2013-10-30 12:13 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll
2014-01-28 23:44 - 2013-10-30 12:06 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll
2014-01-28 23:36 - 2014-01-28 23:36 - 70015304 _____ (Samsung Electronics Co., Ltd.                                ) C:\Users\Tom\Downloads\KiesSetup.exe
2014-01-28 23:35 - 2014-01-28 23:35 - 38825784 _____ (Samsung Electronics Co., Ltd.                                ) C:\Users\Tom\Downloads\Kies3Setup.exe
2014-01-28 23:32 - 2014-01-28 23:41 - 00000000 ____D C:\Users\Tom\AppData\Local\Downloaded Installations
2014-01-28 23:31 - 2014-01-28 23:31 - 00000000 ____D C:\Users\Tom\AppData\Local\SearchProtect
2014-01-25 21:28 - 2014-01-25 21:29 - 00000000 ____D C:\Program Files (x86)\Samsung SSD Magician
2014-01-25 21:28 - 2013-11-28 22:58 - 15617656 ____R (Samsung Electronics                                         ) C:\Users\Tom\Desktop\Samsung_Magician_v43.exe
2014-01-25 00:32 - 2014-01-25 00:32 - 00000000 ____S C:\Windows\system32\hzdiwxf.aqx
2014-01-22 22:32 - 2014-01-22 22:32 - 00000134 _____ C:\Users\Tom\Desktop\Internet Explorer Troubleshooting.url
2014-01-22 22:31 - 2014-01-22 22:32 - 00001847 _____ C:\Windows\IE9_main.log
2014-01-22 08:52 - 2014-01-22 08:52 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys
2014-01-22 08:52 - 2014-01-22 08:52 - 00108800 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys
2014-01-19 22:38 - 2014-01-19 23:15 - 1861360777 _____ C:\Users\Tom\Downloads\PBS.The.Buddha.720p.x264.AAC.MVGroup.org.mp4
2014-01-16 08:25 - 2014-01-16 08:25 - 00000000 ____S C:\Windows\system32\debrtp.nxi
2014-01-15 21:02 - 2014-01-31 19:23 - 00000081 _____ C:\Windows\system32\tvvcgs.vrq
2014-01-15 21:02 - 2014-01-15 21:02 - 00000064 _____ C:\Windows\system32\hjqc.qca
2014-01-15 21:02 - 2014-01-15 21:02 - 00000000 _____ C:\Windows\system32\zeooxnw.bhl
2014-01-15 19:28 - 2009-09-10 01:28 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-01-15 19:28 - 2009-09-10 00:52 - 00257024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-01-15 19:14 - 2012-12-16 11:52 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-01-15 19:14 - 2012-12-16 09:40 - 00367616 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-01-15 19:14 - 2012-12-16 09:25 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2014-01-15 19:14 - 2012-12-16 09:25 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2014-01-15 19:14 - 2009-10-19 09:46 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-01-15 19:14 - 2009-10-19 09:10 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2014-01-15 19:09 - 2012-03-01 01:54 - 00022896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2014-01-15 19:09 - 2012-03-01 01:40 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-01-15 19:09 - 2012-03-01 01:35 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2014-01-15 19:09 - 2012-03-01 00:45 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-01-15 19:09 - 2012-03-01 00:40 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2014-01-15 19:08 - 2013-03-02 00:49 - 01499648 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-01-15 19:08 - 2013-03-02 00:49 - 01198080 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-01-15 19:08 - 2013-03-02 00:49 - 00134144 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-01-15 19:08 - 2013-03-02 00:44 - 01026560 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2014-01-15 19:08 - 2013-03-02 00:43 - 09377280 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-01-15 19:08 - 2013-03-02 00:43 - 00735744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-01-15 19:08 - 2013-03-02 00:43 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-01-15 19:08 - 2013-03-02 00:43 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-01-15 19:08 - 2013-03-02 00:43 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-01-15 19:08 - 2013-03-02 00:43 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-01-15 19:08 - 2013-03-02 00:42 - 12405760 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-01-15 19:08 - 2013-03-02 00:42 - 02463744 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-01-15 19:08 - 2013-03-02 00:42 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-01-15 19:08 - 2013-03-02 00:42 - 00256000 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-01-15 19:08 - 2013-03-02 00:42 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-01-15 19:08 - 2013-03-02 00:06 - 00981504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-01-15 19:08 - 2013-03-02 00:05 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-01-15 19:08 - 2013-03-02 00:05 - 00132096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-01-15 19:08 - 2013-03-02 00:02 - 06032384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-01-15 19:08 - 2013-03-02 00:02 - 00627200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-01-15 19:08 - 2013-03-02 00:02 - 00606208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2014-01-15 19:08 - 2013-03-02 00:02 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-01-15 19:08 - 2013-03-02 00:02 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-01-15 19:08 - 2013-03-02 00:01 - 11019776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-01-15 19:08 - 2013-03-02 00:01 - 02077184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-01-15 19:08 - 2013-03-02 00:01 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-01-15 19:08 - 2013-03-02 00:01 - 00185856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-01-15 19:08 - 2013-03-02 00:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-01-15 19:08 - 2013-03-02 00:01 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-01-15 19:08 - 2013-03-01 23:38 - 00482816 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-01-15 19:08 - 2013-03-01 23:03 - 00386048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-01-15 19:08 - 2013-03-01 22:56 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-01-15 19:08 - 2013-03-01 22:56 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-01-15 19:08 - 2013-03-01 22:30 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-01-15 19:08 - 2013-03-01 22:29 - 01638912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-01-15 19:08 - 2013-03-01 22:29 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-01-15 19:08 - 2013-02-12 10:42 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-01-15 19:08 - 2013-02-12 10:37 - 03138048 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-01-15 19:08 - 2013-02-12 10:31 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-01-15 19:08 - 2013-02-12 10:13 - 02691072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-01-15 19:08 - 2013-02-12 10:07 - 00131072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-01-15 19:08 - 2013-02-12 08:59 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-01-15 19:08 - 2013-01-04 00:41 - 01893224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-01-15 19:08 - 2013-01-04 00:40 - 00287576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-01-15 19:08 - 2013-01-04 00:37 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-01-15 19:08 - 2013-01-04 00:37 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-01-15 19:08 - 2013-01-04 00:37 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-01-15 19:08 - 2013-01-04 00:36 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-01-15 19:08 - 2013-01-04 00:33 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-01-15 19:08 - 2013-01-04 00:30 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-01-15 19:08 - 2013-01-04 00:30 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-01-15 19:08 - 2013-01-04 00:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:51 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-01-15 19:08 - 2013-01-03 23:51 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-01-15 19:08 - 2013-01-03 23:51 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 22:19 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-01-15 19:08 - 2013-01-03 21:48 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-01-15 19:08 - 2013-01-03 21:48 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-01-15 19:08 - 2013-01-03 21:48 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-01-15 19:08 - 2013-01-03 21:48 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-01-15 19:08 - 2013-01-03 21:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 21:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 21:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-01-15 19:08 - 2013-01-03 21:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2014-01-15 19:08 - 2012-11-09 00:34 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-01-15 19:08 - 2012-11-09 00:34 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-01-15 19:08 - 2012-11-08 23:49 - 00492032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2014-01-15 19:08 - 2012-11-08 23:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-01-15 19:08 - 2012-06-09 00:30 - 14165504 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-01-15 19:08 - 2012-06-08 23:46 - 12868608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-01-15 19:08 - 2012-03-03 01:29 - 01837568 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-01-15 19:08 - 2012-03-03 01:29 - 01541120 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-01-15 19:08 - 2012-03-03 01:29 - 00902656 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-01-15 19:08 - 2012-03-03 01:29 - 00320512 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-01-15 19:08 - 2012-03-03 01:29 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-01-15 19:08 - 2012-03-03 00:40 - 01170944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-01-15 19:08 - 2012-03-03 00:40 - 01074176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-01-15 19:08 - 2012-03-03 00:40 - 00739840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-01-15 19:08 - 2012-03-03 00:40 - 00218624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-01-15 19:08 - 2012-03-03 00:40 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-01-15 19:08 - 2011-10-26 00:22 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-01-15 19:08 - 2011-10-26 00:22 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-01-15 19:08 - 2011-10-25 23:28 - 01328640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-01-15 19:08 - 2011-10-25 23:28 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-01-15 19:08 - 2011-07-08 21:44 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-01-15 19:08 - 2011-05-03 21:51 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-01-15 19:08 - 2011-05-03 21:51 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-01-15 19:08 - 2009-09-03 02:36 - 01975296 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2014-01-15 19:08 - 2009-09-03 02:04 - 01320960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2014-01-15 19:07 - 2013-04-12 09:36 - 01653096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-01-15 19:07 - 2013-03-19 01:19 - 05497688 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-01-15 19:07 - 2013-03-19 00:54 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-01-15 19:07 - 2013-03-19 00:06 - 03958120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-01-15 19:07 - 2013-03-19 00:06 - 03902312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-01-15 19:07 - 2013-03-18 23:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2014-01-15 19:07 - 2013-03-18 22:19 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-01-15 19:07 - 2013-02-28 22:32 - 03150848 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-15 19:07 - 2013-02-12 09:02 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-01-15 19:07 - 2012-11-20 00:55 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-01-15 19:07 - 2012-11-20 00:10 - 00219136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-01-15 19:07 - 2012-11-02 00:30 - 02001408 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-01-15 19:07 - 2012-11-02 00:30 - 01880064 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-01-15 19:07 - 2012-11-02 00:27 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-01-15 19:07 - 2012-11-01 23:50 - 01388544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-01-15 19:07 - 2012-11-01 23:50 - 01236992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-01-15 19:07 - 2012-11-01 23:48 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2014-01-15 19:07 - 2012-09-25 17:39 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-01-15 19:07 - 2012-09-25 16:55 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2014-01-15 19:07 - 2012-09-06 12:38 - 00295792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2014-01-15 19:07 - 2012-08-24 13:05 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-01-15 19:07 - 2012-08-24 12:10 - 00172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-01-15 19:07 - 2012-08-10 19:53 - 00714752 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-01-15 19:07 - 2012-08-10 18:54 - 00541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-01-15 19:07 - 2012-07-04 17:04 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-01-15 19:07 - 2012-07-04 17:01 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-01-15 19:07 - 2012-07-04 17:01 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-01-15 19:07 - 2012-07-04 16:26 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2014-01-15 19:07 - 2012-07-04 16:23 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2014-01-15 19:07 - 2012-06-16 00:25 - 00850944 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-01-15 19:07 - 2012-06-16 00:25 - 00609792 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-01-15 19:07 - 2012-06-15 23:37 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-01-15 19:07 - 2012-06-15 23:36 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-01-15 19:07 - 2012-06-02 00:38 - 00152432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-01-15 19:07 - 2012-06-02 00:38 - 00095088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-01-15 19:07 - 2012-06-02 00:37 - 00459216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-01-15 19:07 - 2012-06-02 00:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-01-15 19:07 - 2012-06-02 00:25 - 01462784 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-01-15 19:07 - 2012-06-02 00:25 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-01-15 19:07 - 2012-06-02 00:25 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-01-15 19:07 - 2012-06-01 23:48 - 00225280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-01-15 19:07 - 2012-06-01 23:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-01-15 19:07 - 2012-06-01 23:45 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-01-15 19:07 - 2012-06-01 23:45 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-01-15 19:07 - 2012-06-01 23:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2014-01-15 19:07 - 2012-06-01 23:42 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-01-15 19:07 - 2012-05-14 00:20 - 00956416 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-01-15 19:07 - 2012-04-27 22:50 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-01-15 19:07 - 2012-04-26 00:34 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-01-15 19:07 - 2012-04-26 00:34 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-01-15 19:07 - 2012-04-26 00:28 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-01-15 19:07 - 2012-03-17 02:55 - 00075632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-01-15 19:07 - 2012-02-15 01:27 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-01-15 19:07 - 2012-02-15 00:44 - 00826368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2014-01-15 19:07 - 2012-02-14 23:46 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-01-15 19:07 - 2011-12-27 22:59 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-01-15 19:07 - 2011-12-16 03:42 - 00634368 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2014-01-15 19:07 - 2011-12-16 02:59 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2014-01-15 19:07 - 2011-11-17 02:12 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2014-01-15 19:07 - 2011-11-17 02:11 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-01-15 19:07 - 2011-11-17 02:11 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-01-15 19:07 - 2011-11-17 02:11 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-01-15 19:07 - 2011-11-17 02:08 - 01446912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-01-15 19:07 - 2011-11-17 02:05 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-01-15 19:07 - 2011-11-17 00:39 - 00314368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2014-01-15 19:07 - 2011-10-15 01:25 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2014-01-15 19:07 - 2011-10-15 00:48 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2014-01-15 19:07 - 2011-08-27 00:40 - 00861184 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-01-15 19:07 - 2011-08-27 00:40 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2014-01-15 19:07 - 2011-08-26 23:43 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-01-15 19:07 - 2011-08-26 23:43 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2014-01-15 19:07 - 2011-08-17 00:32 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2014-01-15 19:07 - 2011-08-17 00:27 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax
2014-01-15 19:07 - 2011-08-17 00:27 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2014-01-15 19:07 - 2011-08-17 00:27 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax
2014-01-15 19:07 - 2011-08-17 00:27 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax
2014-01-15 19:07 - 2011-08-16 23:26 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2014-01-15 19:07 - 2011-08-16 23:22 - 00204288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSNP.ax
2014-01-15 19:07 - 2011-08-16 23:22 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2014-01-15 19:07 - 2011-08-16 23:22 - 00072704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Mpeg2Data.ax
2014-01-15 19:07 - 2011-08-16 23:22 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSDvbNP.ax
2014-01-15 19:07 - 2011-06-15 04:58 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2014-01-15 19:07 - 2011-06-15 04:58 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2014-01-15 19:07 - 2011-06-15 04:58 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2014-01-15 19:07 - 2011-06-15 04:58 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2014-01-15 19:07 - 2011-06-15 04:04 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
2014-01-15 19:07 - 2011-06-15 04:04 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
2014-01-15 19:07 - 2011-06-15 04:04 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
2014-01-15 19:07 - 2011-06-15 04:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
2014-01-15 19:07 - 2011-06-15 04:04 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
2014-01-15 19:07 - 2011-05-24 06:21 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-01-15 19:07 - 2011-05-24 05:34 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2014-01-15 19:07 - 2011-05-24 05:34 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2014-01-15 19:07 - 2011-05-24 05:34 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2014-01-15 19:07 - 2011-05-24 05:32 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2014-01-15 19:07 - 2011-05-03 00:21 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-01-15 19:07 - 2011-05-02 23:50 - 00740864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2014-01-15 19:07 - 2011-04-28 22:13 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2014-01-15 19:07 - 2011-04-28 22:12 - 00399872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-01-15 19:07 - 2011-04-28 22:12 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-01-15 19:07 - 2011-04-26 21:57 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2014-01-15 19:07 - 2011-03-11 01:19 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2014-01-15 19:07 - 2011-03-11 01:19 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2014-01-15 19:07 - 2011-03-11 00:40 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2014-01-15 19:07 - 2011-03-11 00:40 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2014-01-15 19:07 - 2011-03-03 01:17 - 00356352 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-01-15 19:07 - 2011-03-03 01:17 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-01-15 19:07 - 2011-03-03 01:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2014-01-15 19:07 - 2011-03-03 00:29 - 00269824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2014-01-15 19:07 - 2011-03-03 00:27 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2014-01-15 19:07 - 2011-02-23 00:15 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2014-01-15 19:07 - 2011-02-12 01:14 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2014-01-15 19:07 - 2011-02-05 07:41 - 00640896 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-01-15 19:07 - 2011-02-05 07:41 - 00556928 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-01-15 19:07 - 2011-02-05 07:41 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll
2014-01-15 19:07 - 2011-02-05 07:41 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll
2014-01-15 19:07 - 2011-02-05 07:41 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll
2014-01-15 19:07 - 2011-02-05 07:39 - 00603976 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-01-15 19:07 - 2011-02-05 07:39 - 00518160 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-01-15 19:07 - 2010-12-23 01:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2014-01-15 19:07 - 2010-12-23 01:07 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2014-01-15 19:07 - 2010-12-23 01:02 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2014-01-15 19:07 - 2010-12-23 00:28 - 00850432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2014-01-15 19:07 - 2010-12-23 00:28 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2014-01-15 19:07 - 2010-12-23 00:24 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax
2014-01-15 19:07 - 2010-12-18 01:08 - 01097216 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-01-15 19:07 - 2010-12-18 00:26 - 01034240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-01-15 19:07 - 2010-11-02 00:18 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\wmicmiplugin.dll
2014-01-15 19:07 - 2010-11-02 00:17 - 01169408 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2014-01-15 19:07 - 2010-11-02 00:17 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2014-01-15 19:07 - 2010-11-02 00:16 - 01114624 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-01-15 19:07 - 2010-11-02 00:10 - 00464384 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2014-01-15 19:07 - 2010-11-02 00:10 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe
2014-01-15 19:07 - 2010-11-01 23:40 - 00496128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll
2014-01-15 19:07 - 2010-11-01 23:40 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2014-01-15 19:07 - 2010-11-01 23:34 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2014-01-15 19:07 - 2010-11-01 23:34 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
2014-01-15 19:07 - 2010-10-16 00:23 - 00112000 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-01-15 19:07 - 2010-10-16 00:17 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\odbc32.dll
2014-01-15 19:07 - 2010-10-15 23:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbc32.dll
2014-01-15 19:07 - 2010-09-01 00:21 - 14627840 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-01-15 19:07 - 2010-09-01 00:12 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-01-15 19:07 - 2010-08-31 23:29 - 11406848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-01-15 19:07 - 2010-08-31 23:23 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-01-15 19:07 - 2010-08-30 23:32 - 00954752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc40.dll
2014-01-15 19:07 - 2010-08-30 23:32 - 00954288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc40u.dll
2014-01-15 19:07 - 2010-08-26 00:27 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2014-01-15 19:07 - 2010-08-25 23:39 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2014-01-15 19:07 - 2010-08-21 01:38 - 01024512 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2014-01-15 19:07 - 2010-08-21 01:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-01-15 19:07 - 2010-08-21 01:29 - 00558592 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2014-01-15 19:07 - 2010-08-21 00:36 - 00738816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
2014-01-15 19:07 - 2010-08-21 00:33 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2014-01-15 19:07 - 2010-07-29 01:30 - 00082944 _____ (Radius Inc.) C:\Windows\SysWOW64\iccvid.dll
2014-01-15 19:07 - 2010-06-29 00:39 - 02085376 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2014-01-15 19:07 - 2010-06-29 00:02 - 01413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2014-01-15 19:07 - 2010-06-19 01:53 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\rtutils.dll
2014-01-15 19:07 - 2010-06-19 01:23 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtutils.dll
2014-01-15 19:07 - 2010-05-19 14:48 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-01-15 19:07 - 2010-05-05 02:37 - 00483840 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2014-01-15 19:07 - 2010-05-05 01:46 - 00363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2014-01-15 19:07 - 2010-03-05 02:52 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2014-01-15 19:07 - 2010-03-05 02:42 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2014-01-15 19:07 - 2010-01-09 02:19 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\cabview.dll
2014-01-15 19:07 - 2010-01-09 01:52 - 00132608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cabview.dll
2014-01-15 19:07 - 2009-12-19 04:50 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\tsbyuv.dll
2014-01-15 19:07 - 2009-12-19 04:47 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\msvidc32.dll
2014-01-15 19:07 - 2009-12-19 04:47 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msyuv.dll
2014-01-15 19:07 - 2009-12-19 04:47 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\msrle32.dll
2014-01-15 19:07 - 2009-12-19 04:46 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\iyuv_32.dll
2014-01-15 19:07 - 2009-12-19 04:02 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\avifil32.dll
2014-01-15 19:07 - 2009-12-19 04:02 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mciavi32.dll
2014-01-15 19:07 - 2009-12-19 04:02 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iyuv_32.dll
2014-01-15 19:07 - 2009-12-19 04:02 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvidc32.dll
2014-01-15 19:07 - 2009-12-19 04:02 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msyuv.dll
2014-01-15 19:07 - 2009-12-19 04:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrle32.dll
2014-01-15 19:07 - 2009-12-19 04:02 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsbyuv.dll
2014-01-15 19:07 - 2009-10-31 01:34 - 02870272 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2014-01-15 19:07 - 2009-10-31 00:45 - 02614272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2014-01-15 19:07 - 2009-10-28 01:24 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-01-15 19:07 - 2009-10-01 23:32 - 00982600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-01-15 19:07 - 2009-08-29 02:50 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\msasn1.dll
2014-01-15 19:07 - 2009-08-29 01:57 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msasn1.dll
2014-01-15 19:06 - 2011-11-17 02:14 - 01739160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-01-15 19:06 - 2011-11-17 00:41 - 01292592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-01-15 19:06 - 2010-08-27 01:14 - 00236032 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2014-01-15 19:06 - 2010-08-27 00:46 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
2014-01-15 19:04 - 2011-11-19 10:07 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-01-15 19:04 - 2011-11-19 09:06 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-01-15 18:07 - 2014-01-15 18:07 - 00219314 ____S C:\Windows\system32\pqrdrj.vcc
2014-01-09 12:57 - 2014-01-09 12:57 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2014-01-09 12:56 - 2013-12-19 15:33 - 30372640 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 22960416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 18222008 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 12645664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-01-09 12:56 - 2013-12-19 15:33 - 11605752 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 11554264 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 09700224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 09657464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433221.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433221.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00882464 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00879392 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00852768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00847648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-01-09 12:56 - 2013-12-19 15:33 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-01-09 12:56 - 2013-11-28 08:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2014-01-09 12:56 - 2013-11-28 08:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2014-01-09 11:40 - 2013-12-05 03:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-01-09 11:40 - 2013-12-05 03:42 - 00032544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-01-05 16:33 - 2014-01-30 00:06 - 00000000 ____D C:\Users\Tom\AppData\Local\Owqnics

==================== One Month Modified Files and Folders =======

2014-01-31 20:20 - 2014-01-31 12:49 - 00018242 _____ C:\Users\Tom\Desktop\FRST.txt
2014-01-31 20:20 - 2014-01-31 12:48 - 00000000 ____D C:\FRST
2014-01-31 20:17 - 2014-01-31 20:17 - 00000604 _____ C:\Users\Tom\Desktop\Search.txt
2014-01-31 20:09 - 2012-12-02 04:36 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-31 19:35 - 2009-07-14 00:13 - 00779266 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-31 19:34 - 2012-12-02 04:20 - 01194048 _____ C:\Windows\WindowsUpdate.log
2014-01-31 19:31 - 2014-01-31 13:03 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-31 19:31 - 2013-11-20 14:35 - 00003758 _____ C:\Windows\System32\Tasks\AutoKMS
2014-01-31 19:30 - 2012-12-02 05:33 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-01-31 19:30 - 2012-12-02 05:22 - 00052932 _____ C:\Windows\PFRO.log
2014-01-31 19:30 - 2012-12-02 04:24 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-31 19:30 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-31 19:30 - 2009-07-13 23:51 - 00031111 _____ C:\Windows\setupact.log
2014-01-31 19:29 - 2009-07-13 23:45 - 00013584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-31 19:29 - 2009-07-13 23:45 - 00013584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-31 19:28 - 2012-12-02 04:52 - 00000000 ____D C:\Users\Tom\AppData\Roaming\Adobe
2014-01-31 19:23 - 2014-01-15 21:02 - 00000081 _____ C:\Windows\system32\tvvcgs.vrq
2014-01-31 19:15 - 2014-01-31 19:15 - 00000000 ____D C:\Users\Tom\Desktop\FRST-OlderVersion
2014-01-31 19:15 - 2014-01-31 12:48 - 02080256 _____ (Farbar) C:\Users\Tom\Desktop\FRST64.exe
2014-01-31 18:18 - 2012-12-02 05:33 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2014-01-31 17:33 - 2012-12-02 04:24 - 00000000 ____D C:\ProgramData\MFAData
2014-01-31 13:03 - 2014-01-31 13:03 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-31 13:03 - 2014-01-31 13:03 - 00000000 ____D C:\Users\Tom\AppData\Roaming\Malwarebytes
2014-01-31 13:03 - 2014-01-31 13:03 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-31 13:02 - 2014-01-31 13:02 - 10284816 _____ (Malwarebytes Corporation                                    ) C:\Users\Tom\Downloads\mbam-setup.exe
2014-01-31 13:02 - 2014-01-31 13:02 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Tom\Downloads\rkill.exe
2014-01-31 13:01 - 2014-01-31 13:01 - 00000000 ____D C:\TDSSKiller_Quarantine
2014-01-31 12:59 - 2014-01-31 12:59 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\Tom\Downloads\tdsskiller.exe
2014-01-31 12:55 - 2014-01-31 12:55 - 00000511 _____ C:\Users\Tom\Downloads\fixlist.txt
2014-01-31 12:49 - 2014-01-31 12:49 - 00023684 _____ C:\Users\Tom\Desktop\Addition.txt
2014-01-31 12:47 - 2014-01-31 12:47 - 02079744 _____ (Farbar) C:\Users\Tom\Downloads\FRST64.exe
2014-01-30 00:06 - 2014-01-05 16:33 - 00000000 ____D C:\Users\Tom\AppData\Local\Owqnics
2014-01-30 00:00 - 2013-11-14 21:18 - 00000000 ____D C:\ProgramData\AVG2014
2014-01-29 23:57 - 2013-11-20 13:23 - 00772990 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2014-01-29 23:51 - 2014-01-29 23:50 - 00000000 ____D C:\Windows\system32\MRT
2014-01-29 23:42 - 2014-01-29 23:42 - 01069512 _____ (Solid State Networks) C:\Users\Tom\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-29 18:09 - 2013-11-10 12:20 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2014-01-29 18:09 - 2012-12-02 22:05 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2014-01-29 13:40 - 2014-01-29 13:28 - 00000000 ____D C:\Users\Tom\Documents\SelfMV
2014-01-29 11:31 - 2014-01-29 11:31 - 00000000 ____D C:\Windows\SysWOW64\SearchProtect
2014-01-29 00:46 - 2014-01-29 00:46 - 00000000 ____S C:\Windows\system32\nedcmp.fdf
2014-01-28 23:45 - 2014-01-28 23:45 - 00002002 _____ C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2014-01-28 23:45 - 2014-01-28 23:45 - 00001992 _____ C:\Users\Public\Desktop\Samsung Kies.lnk
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Tom\Documents\samsung
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Tom\AppData\Roaming\Samsung
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Tom\AppData\Local\Samsung
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2014-01-28 23:45 - 2014-01-28 23:45 - 00000000 ____D C:\Program Files (x86)\MyFree Codec
2014-01-28 23:45 - 2014-01-28 23:44 - 00000000 ____D C:\Program Files (x86)\Samsung
2014-01-28 23:45 - 2012-12-02 04:50 - 00000000 ____D C:\ProgramData\Samsung
2014-01-28 23:44 - 2012-12-02 05:28 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2014-01-28 23:41 - 2014-01-28 23:32 - 00000000 ____D C:\Users\Tom\AppData\Local\Downloaded Installations
2014-01-28 23:36 - 2014-01-28 23:36 - 70015304 _____ (Samsung Electronics Co., Ltd.                                ) C:\Users\Tom\Downloads\KiesSetup.exe
2014-01-28 23:35 - 2014-01-28 23:35 - 38825784 _____ (Samsung Electronics Co., Ltd.                                ) C:\Users\Tom\Downloads\Kies3Setup.exe
2014-01-28 23:31 - 2014-01-28 23:31 - 00000000 ____D C:\Users\Tom\AppData\Local\SearchProtect
2014-01-28 21:38 - 2012-12-02 04:35 - 00000000 ____D C:\Program Files (x86)\Origin
2014-01-28 17:08 - 2012-12-02 16:23 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2014-01-25 21:29 - 2014-01-25 21:28 - 00000000 ____D C:\Program Files (x86)\Samsung SSD Magician
2014-01-25 21:28 - 2013-11-11 14:02 - 00001131 _____ C:\Users\Public\Desktop\Samsung Magician.lnk
2014-01-25 21:28 - 2012-12-02 04:20 - 00000000 ___RD C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-25 21:21 - 2013-11-20 14:35 - 00000000 ____D C:\Windows\AutoKMS
2014-01-25 21:21 - 2013-11-20 12:48 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-01-25 21:21 - 2012-12-02 04:26 - 00000000 ____D C:\Users\Tom\AppData\Roaming\uTorrent
2014-01-25 21:21 - 2012-12-02 04:23 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2014-01-25 21:21 - 2012-12-02 04:23 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2014-01-25 21:21 - 2012-12-02 04:20 - 00000000 ___RD C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-01-25 21:21 - 2012-12-02 04:20 - 00000000 ____D C:\Users\Tom
2014-01-25 21:21 - 2009-07-14 02:46 - 00000000 ____D C:\Windows\ShellNew
2014-01-25 21:21 - 2009-07-14 02:46 - 00000000 ____D C:\Program Files\Windows Journal
2014-01-25 21:21 - 2009-07-14 00:32 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2014-01-25 21:21 - 2009-07-14 00:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\system32\sysprep
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\system32\NDF
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\servicing
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\security
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\registration
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\Help
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\AppCompat
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\System
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\Services
2014-01-25 21:21 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2014-01-25 00:32 - 2014-01-25 00:32 - 00000000 ____S C:\Windows\system32\hzdiwxf.aqx
2014-01-22 22:32 - 2014-01-22 22:32 - 00000134 _____ C:\Users\Tom\Desktop\Internet Explorer Troubleshooting.url
2014-01-22 22:32 - 2014-01-22 22:31 - 00001847 _____ C:\Windows\IE9_main.log
2014-01-22 08:52 - 2014-01-22 08:52 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys
2014-01-22 08:52 - 2014-01-22 08:52 - 00108800 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys
2014-01-19 23:15 - 2014-01-19 22:38 - 1861360777 _____ C:\Users\Tom\Downloads\PBS.The.Buddha.720p.x264.AAC.MVGroup.org.mp4
2014-01-16 08:25 - 2014-01-16 08:25 - 00000000 ____S C:\Windows\system32\debrtp.nxi
2014-01-15 21:02 - 2014-01-15 21:02 - 00000064 _____ C:\Windows\system32\hjqc.qca
2014-01-15 21:02 - 2014-01-15 21:02 - 00000000 _____ C:\Windows\system32\zeooxnw.bhl
2014-01-15 21:02 - 2009-07-13 23:45 - 00442248 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-15 18:07 - 2014-01-15 18:07 - 00219314 ____S C:\Windows\system32\pqrdrj.vcc
2014-01-09 12:57 - 2014-01-09 12:57 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2014-01-09 12:57 - 2012-12-02 04:23 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2014-01-06 16:20 - 2014-01-29 23:50 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-05 16:33 - 2013-12-11 17:06 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2014-01-05 11:46 - 2013-12-11 17:06 - 00003744 _____ C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2014-01-05 11:46 - 2013-12-11 17:06 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
ZeroAccess:
C:\Users\Tom\AppData\Local\Google\Desktop\Install

Some content of TEMP:
====================
C:\Users\Tom\AppData\Local\Temp\6_Offer_16.exe
C:\Users\Tom\AppData\Local\Temp\7za.exe
C:\Users\Tom\AppData\Local\Temp\cudart32_50_35.dll
C:\Users\Tom\AppData\Local\Temp\htmlayout.dll
C:\Users\Tom\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Tom\AppData\Local\Temp\jre-7u9-windows-i586-iftw.exe
C:\Users\Tom\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\Tom\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Tom\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\Tom\AppData\Local\Temp\nvStInst.exe
C:\Users\Tom\AppData\Local\Temp\ose00000.exe
C:\Users\Tom\AppData\Local\Temp\pthreadGC2.dll
C:\Users\Tom\AppData\Local\Temp\pthreadVC2.dll
C:\Users\Tom\AppData\Local\Temp\sonarinst.exe
C:\Users\Tom\AppData\Local\Temp\The_Weather_Channel_Application.exe
C:\Users\Tom\AppData\Local\Temp\uttB64F.tmp.exe
C:\Users\Tom\AppData\Local\Temp\Xvid.exe
C:\Users\Tom\AppData\Local\Temp\zlib1.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2009-07-13 19:00] - [2009-07-13 20:41] - 0510464 ____A (Microsoft Corporation) 0C700C322E1E6ABBEDB2127643A2F80B

 ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected.
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-29 02:25

==================== End Of Log ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-01-2014 01
Ran by Tom at 2014-01-31 12:49:28
Running from C:\Users\Tom\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}

==================== Installed Programs ======================

µTorrent (HKCU Version: 3.3.2.30303 - BitTorrent Inc.)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader XI (x32 Version: 11.0.00 - Adobe Systems Incorporated)
AVG 2014 (Version: 14.0.3684 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4259 - AVG Technologies) Hidden
AVG 2014 (Version: 2014.0.4259 - AVG Technologies)
AVG SafeGuard toolbar (x32 Version: 17.3.0.49 - AVG Technologies)
Battlefield 1942™ (x32 Version: 1.6.20.0 - Electronic Arts)
Battlefield 3™ (x32 Version: 1.6.0.0 - Electronic Arts)
Battlefield: Bad Company™ 2 (x32 Version: 1.0.0.0 - Electronic Arts)
Battlelog Web Plugins (x32 Version: 2.3.2 - EA Digital Illusions CE AB)
Combined Community Codec Pack 2013-10-17 (x32 Version: 2013.10.17.0 - CCCP Project)
DAEMON Tools Lite (x32 Version: 4.46.1.0327 - DT Soft Ltd)
Definition Update for Microsoft Office 2013 (KB2760587) 64-Bit Edition (Version:  - Microsoft)
ESN Sonar (x32 Version: 0.70.4 - ESN Social Software AB)
Fraps (x32 Version:  - )
GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden
Intel® Control Center (x32 Version: 1.2.1.1007 - Intel Corporation)
Intel® Manageability Engine Firmware Recovery Agent (x32 Version: 1.0.0.36354 - Intel Corporation)
Intel® Management Engine Components (x32 Version: 8.1.0.1252 - Intel Corporation)
Intel® Rapid Storage Technology (x32 Version: 11.0.0.1032 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.3.214 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden
Java 7 Update 45 (x32 Version: 7.0.450 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
JavaFX 2.1.1 (x32 Version: 2.1.1 - Oracle Corporation)
Mass Effect™ 3 Demo (x32 Version: 1.0.0.0 - Electronic Arts)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (Version: 4.0.30320 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320 - Microsoft Corporation) Hidden
Microsoft Access MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Access Setup Metadata MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft DCF MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Excel MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Groove MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft InfoPath MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Lync MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office 32-bit Components 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office OSM MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office OSM UX MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2013 (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2013 - Español (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft OneNote MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Outlook MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft PowerPoint MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Publisher MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Microsoft Word MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Mozilla Firefox 26.0 (x86 en-US) (x32 Version: 26.0 - Mozilla)
Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla)
MyFreeCodec (HKCU Version:  - )
Netflix in Windows Media Center (x32 Version: 3.3.101.0 - Microsoft Corporation)
NVIDIA 3D Vision Controller Driver 332.21 (Version: 332.21 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 332.21 (Version: 332.21 - NVIDIA Corporation)
NVIDIA Control Panel 332.21 (Version: 332.21 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 1.8.1 (Version: 1.8.1 - NVIDIA Corporation)
NVIDIA Graphics Driver 332.21 (Version: 332.21 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.1 (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.142.992 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX System Software 9.13.0725 (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA ShadowPlay 10.11.15 (Version: 10.11.15 - NVIDIA Corporation) Hidden
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3221 - NVIDIA Corporation) Hidden
NVIDIA Update 10.11.15 (Version: 10.11.15 - NVIDIA Corporation) Hidden
NVIDIA Update Core (Version: 10.11.15 - NVIDIA Corporation) Hidden
NVIDIA Virtual Audio 1.2.19 (Version: 1.2.19 - NVIDIA Corporation)
Origin (x32 Version: 8.6.1.39 - Electronic Arts, Inc.)
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
PlayReady PC Runtime amd64 (Version: 1.3.0 - Microsoft Corporation)
PunkBuster Services (x32 Version: 0.991 - Even Balance, Inc.)
Realtek Ethernet Controller Driver (x32 Version: 7.58.411.2012 - Realtek)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6704 - Realtek Semiconductor Corp.)
Samsung Kies (x32 Version: 2.6.1.13105_7 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.6.1.13105_7 - Samsung Electronics Co., Ltd.) Hidden
Samsung Magician (x32 Version: 4.3.0 - Samsung Electronics)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.29.0 - SAMSUNG Electronics Co., Ltd.)
Search Protect (x32 Version: 2.9.62.1 - Conduit) <==== ATTENTION
SHIELD Streaming (Version: 1.6.85 - NVIDIA Corporation) Hidden
TechPowerUp GPU-Z (x32 Version:  - )
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft Access 2013 (KB2768008) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft InfoPath 2013 (KB2752078) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Lync 2013 (KB2817621) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2726954) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2726996) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2737954) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2738038) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760224) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760242) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760257) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760267) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760539) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760553) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760610) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2767845) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2768016) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817309) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817311) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817314) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817316) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817490) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817493) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817624) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817626) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817640) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2827225) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2827228) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2827230) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2827235) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft OneNote 2013 (KB2810016) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Outlook 2013 (KB2825632) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft PowerPoint 2013 (KB2726947) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft PowerPoint 2013 (KB2817625) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Project 2013 (KB2767859) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Publisher 2013 (KB2752097) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft SkyDrive Pro (KB2825633) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Visio 2013 (KB2752018) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2013 (KB2768338) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Word 2013 (KB2817631) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Word 2013 (KB2827218) 64-Bit Edition (Version:  - Microsoft)
Visual Studio 2008 x64 Redistributables (x32 Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (x32 Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WinRAR 4.20 (32-bit) (x32 Version: 4.20.0 - win.rar GmbH)
Xvid MPEG-4 Video Codec (x32 Version:  - )

==================== Restore Points  =========================

30-11-2012 20:07:57 Installed Norton Ghost.
30-11-2012 20:42:17 Installed Acronis True Image Home 2011
02-12-2012 00:40:37 Restore Operation
02-12-2012 04:38:44 Installed Microsoft Primary Interoperability Assemblies 2005
02-12-2012 04:41:19 Installed Nero Multimedia Suite 10.
02-12-2012 07:43:20 Windows Update
23-01-2014 03:30:01 Windows Update
26-01-2014 02:15:58 Restore Operation
29-01-2014 04:44:19 Installed Samsung Kies
30-01-2014 04:50:39 Windows Update

==================== Hosts content: ==========================

2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {088B140D-D1A9-4C32-97C4-8E6A6A972FFC} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {5871AF6E-90A8-4414-B5C3-77088A9D2724} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {63DDC47C-02B8-4E79-A9CE-279D6DD3B3B3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated)
Task: {81F7C2A3-2EED-4D3A-90E5-C6C5DE58F6E7} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel® ME FW Recovery Agent\bin\Bootstrap.exe [2012-04-16] (Intel Corporation)
Task: {A12976FC-280E-4FE9-8386-5E2D040FA4E0} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2013-11-20] ()
Task: {BA97558D-20E3-4591-9696-32EC0D58AC68} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {F9E1E560-0439-4986-B6EB-190B2DBC76C8} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel® ME FW Recovery Agent\bin\Bootstrap.exe [2012-04-16] (Intel Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel® ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel® ME FW Recovery Agent\bin\Bootstrap.exe

==================== Loaded Modules (whitelisted) =============

2013-09-13 06:02 - 2013-09-13 06:02 - 08866472 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-01-05 11:46 - 2014-01-05 11:46 - 00519704 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\log4cplusU.dll
2014-01-25 21:28 - 2013-11-28 12:14 - 00013824 _____ () C:\Program Files (x86)\Samsung SSD Magician\SAMSUNG_SSD.dll
2014-01-25 21:28 - 2013-11-28 18:59 - 00098816 _____ () C:\Program Files (x86)\Samsung SSD Magician\PAL.dll
2014-01-25 21:28 - 2013-11-28 18:59 - 00034304 _____ () C:\Program Files (x86)\Samsung SSD Magician\SATA.dll
2014-01-25 21:28 - 2013-11-28 18:59 - 00032768 _____ () C:\Program Files (x86)\Samsung SSD Magician\SAT.dll
2014-01-25 21:28 - 2013-11-28 19:00 - 00031232 _____ () C:\Program Files (x86)\Samsung SSD Magician\SMINI.dll
2014-01-25 21:28 - 2013-11-28 18:59 - 00029696 _____ () C:\Program Files (x86)\Samsung SSD Magician\SAS.dll
2013-11-15 23:23 - 2013-12-12 17:07 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-09-13 06:02 - 2013-09-13 06:02 - 08866472 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 16242056 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll
2012-12-02 05:39 - 2011-11-29 20:00 - 00059392 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
2012-12-02 05:32 - 2012-06-25 10:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\ACE.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/31/2014 11:51:20 AM) (Source: Software Protection Platform Service) (User: )
Description: License Activation Scheduler (sppuinotify.dll) failed with the following error code:
0x80070005

Error: (01/31/2014 10:51:20 AM) (Source: Software Protection Platform Service) (User: )
Description: License Activation Scheduler (sppuinotify.dll) failed with the following error code:
0x80070005

Error: (01/31/2014 09:51:20 AM) (Source: Software Protection Platform Service) (User: )
Description: License Activation Scheduler (sppuinotify.dll) failed with the following error code:
0x80070005

Error: (01/31/2014 08:51:20 AM) (Source: Software Protection Platform Service) (User: )
Description: License Activation Scheduler (sppuinotify.dll) failed with the following error code:
0x80070005

Error: (01/31/2014 07:51:20 AM) (Source: Software Protection Platform Service) (User: )
Description: License Activation Scheduler (sppuinotify.dll) failed with the following error code:
0x80070005

Error: (01/31/2014 06:51:20 AM) (Source: Software Protection Platform Service) (User: )
Description: License Activation Scheduler (sppuinotify.dll) failed with the following error code:
0x80070005

Error: (01/31/2014 05:51:20 AM) (Source: Software Protection Platform Service) (User: )
Description: License Activation Scheduler (sppuinotify.dll) failed with the following error code:
0x80070005

Error: (01/31/2014 04:51:20 AM) (Source: Software Protection Platform Service) (User: )
Description: License Activation Scheduler (sppuinotify.dll) failed with the following error code:
0x80070005

Error: (01/31/2014 03:51:20 AM) (Source: Software Protection Platform Service) (User: )
Description: License Activation Scheduler (sppuinotify.dll) failed with the following error code:
0x80070005

Error: (01/31/2014 02:51:20 AM) (Source: Software Protection Platform Service) (User: )
Description: License Activation Scheduler (sppuinotify.dll) failed with the following error code:
0x80070005


System errors:
=============
Error: (01/31/2014 00:51:20 AM) (Source: DCOM) (User: )
Description: C:\Windows\System32\slui.exe -Embedding5{F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}

Error: (01/30/2014 00:51:18 AM) (Source: DCOM) (User: )
Description: C:\Windows\System32\slui.exe -Embedding5{F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}

Error: (01/30/2014 00:06:05 AM) (Source: Service Control Manager) (User: )
Description: The Power service terminated with the following error:
%%4203

Error: (01/30/2014 00:01:30 AM) (Source: Service Control Manager) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avgwd service.

Error: (01/29/2014 11:59:09 PM) (Source: VDS Basic Provider) (User: )
Description: Unexpected failure. Error code: D@01010004

Error: (01/29/2014 11:58:12 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070216: Update for Windows 7 for x64-based Systems (KB2387530).

Error: (01/29/2014 11:58:12 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070216: Update for Windows 7 for x64-based Systems (KB2533552).

Error: (01/29/2014 11:56:33 PM) (Source: Disk) (User: )
Description: The device, \Device\Harddisk4\DR5, is not ready for access yet.

Error: (01/29/2014 11:56:33 PM) (Source: Disk) (User: )
Description: The device, \Device\Harddisk4\DR5, is not ready for access yet.

Error: (01/29/2014 11:56:33 PM) (Source: Disk) (User: )
Description: The device, \Device\Harddisk4\DR5, is not ready for access yet.


Microsoft Office Sessions:
=========================
Error: (01/31/2014 11:51:20 AM) (Source: Software Protection Platform Service)(User: )
Description: 0x80070005

Error: (01/31/2014 10:51:20 AM) (Source: Software Protection Platform Service)(User: )
Description: 0x80070005

Error: (01/31/2014 09:51:20 AM) (Source: Software Protection Platform Service)(User: )
Description: 0x80070005

Error: (01/31/2014 08:51:20 AM) (Source: Software Protection Platform Service)(User: )
Description: 0x80070005

Error: (01/31/2014 07:51:20 AM) (Source: Software Protection Platform Service)(User: )
Description: 0x80070005

Error: (01/31/2014 06:51:20 AM) (Source: Software Protection Platform Service)(User: )
Description: 0x80070005

Error: (01/31/2014 05:51:20 AM) (Source: Software Protection Platform Service)(User: )
Description: 0x80070005

Error: (01/31/2014 04:51:20 AM) (Source: Software Protection Platform Service)(User: )
Description: 0x80070005

Error: (01/31/2014 03:51:20 AM) (Source: Software Protection Platform Service)(User: )
Description: 0x80070005

Error: (01/31/2014 02:51:20 AM) (Source: Software Protection Platform Service)(User: )
Description: 0x80070005


==================== Memory info ===========================

Percentage of memory in use: 64%
Total physical RAM: 3565.02 MB
Available physical RAM: 1266.64 MB
Total Pagefile: 7128.18 MB
Available Pagefile: 4685.77 MB
Total Virtual: 8192 MB
Available Virtual: 8191.78 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:209.68 GB) (Free:104.11 GB) NTFS
Drive e: () (Fixed) (Total:596.17 GB) (Free:208.25 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive f: () (Fixed) (Total:233.76 GB) (Free:14.85 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive h: (O2013-PPVL-x64) (CDROM) (Total:1.44 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: 16C4C358)
Partition 1: (Active) - (Size=596 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 234 GB) (Disk ID: 37169345)
Partition 1: (Active) - (Size=234 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 332DBA86)
Partition 1: (Active) - (Size=210 GB) - (Type=07 NTFS)

==================== End Of Log ============================

 

Farbar Recovery Scan Tool (x64) Version: 01-02-2014 01
Ran by Tom at 2014-01-31 20:20:49
Running from C:\Users\Tom\Desktop
Boot Mode: Normal

================== Search: "rpcss.dll" ===================

C:\Windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7600.16385_none_c5bfcda3579104e3\rpcss.dll
[2009-07-13 19:00] - [2009-07-13 20:41] - 0509440 ____A () D41D8CD98F00B204E9800998ECF8427E

C:\Windows\System32\rpcss.dll
[2009-07-13 19:00] - [2009-07-13 20:41] - 0510464 ____A (Microsoft Corporation) 0C700C322E1E6ABBEDB2127643A2F80B

====== End Of Search ======

 

thanx!!



#4 B-boy/StyLe/

B-boy/StyLe/

    Bleepin' Freestyler


  • Malware Response Team
  • 8,307 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:01:33 PM

Posted 01 February 2014 - 05:04 AM

Hello,

 

It seems that you have a newer version of the Zekos (WinNT/Pigeon) trojan and you don't have a clean copy of rpcss.dll that we can use to replace the patched file.

So we should try a different way to work around this.

 

The first method is to update your system to Service Pack 1 (from the frst.txt and search.txt I see that you have Windows 7 without the Service Pack):

 

Your system:

 

Windows 7 Ultimate (X64) OS Language: English(US)

 

but should be:

 

Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)

 

 

 

your version of the rpcss.dll

 

C:\Windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7600.16385_none_c5bfcda3579104e3\rpcss.dll

 

 

but it should be

 

C:\Windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7601.17514_none_c7f0e16b547f887d\rpcss.dll

 

So go ahead and update to SP1. Check the link below:

http://windows.microsoft.com/en-us/windows7/install-windows-7-service-pack-1

 

If that didn't work we will try something else.

 

 

Regards,

Georgi


cXfZ4wS.png


#5 B-boy/StyLe/

B-boy/StyLe/

    Bleepin' Freestyler


  • Malware Response Team
  • 8,307 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:01:33 PM

Posted 04 February 2014 - 07:40 AM

Hi,

 

Are you still there?

 

 

Regards,

Georgi


cXfZ4wS.png


#6 runntms

runntms
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:05:33 AM

Posted 04 February 2014 - 04:44 PM

Hey Georgi,

Yes, I'm still here. unfortunately, i keep getting an error for SP1 that says: ERROR: arithmetic result exceeded 32 bits and ERROR: ERROR_ARITHMETIC_OVERFLOW(0x80070216)

I'm installing from the downloaded disc image which is supposed tp contain both 32 and 64 bit installs



#7 B-boy/StyLe/

B-boy/StyLe/

    Bleepin' Freestyler


  • Malware Response Team
  • 8,307 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:01:33 PM

Posted 05 February 2014 - 12:33 AM

Hi,

 

I don't think that a genuine disk contains both versions. You should try only with the x64 version of SP1 (better use Windows Update to find the appropriate update)

 

http://windows.microsoft.com/en-us/windows7/install-windows-7-service-pack-1

 

 

 

Regards,

Georgi


Edited by B-boy/StyLe/, 05 February 2014 - 12:36 AM.

cXfZ4wS.png


#8 B-boy/StyLe/

B-boy/StyLe/

    Bleepin' Freestyler


  • Malware Response Team
  • 8,307 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:01:33 PM

Posted 12 February 2014 - 04:56 AM

Hi,

 

Are you still there?

 

 

Regards,

Georgi


cXfZ4wS.png


#9 B-boy/StyLe/

B-boy/StyLe/

    Bleepin' Freestyler


  • Malware Response Team
  • 8,307 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:01:33 PM

Posted 20 February 2014 - 03:03 PM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.

cXfZ4wS.png





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users