Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help, My browsers dont work anymore


  • This topic is locked This topic is locked
16 replies to this topic

#1 Aurifex

Aurifex

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:12:34 PM

Posted 14 March 2014 - 12:46 AM

I been getting some help from another forum user on the 'Am I infected' pages and have been directed to post my problem here.

 

Basically, an official looking Australia Post email was sent to me notifying of a parcel to be collected at the local post office and I needed to get a consignment doc to pick it up. As we receive many parcels, we did not think anything of it.

 

So realising it was potentially a virus, I posted in 'Am I infected' to be find out and remove. There did not seem to be any issues, but a week later a whole heap of warning windows suddenly popped up and since then I have been unable to use firefox and ie.

 

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.16521  BrowserJavaVersion: 10.51.2
Run by unknown at 16:31:54 on 2014-03-14
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.1.1033.18.1790.622 [GMT 11:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\NetComm\Common\RegistryWriter.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\explorer.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Samsung\Kies\Kies.exe
C:\Program Files\NetComm\Common\RaUI.exe
C:\Program Files\Caplio Software\RGateLXP.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\Speccy\Speccy.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\WmiApSrv.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
mCustomizeSearch = hxxp://www.google.com
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [KiesPDLR] c:\program files\samsung\kies\external\firmwareupdate\KiesPDLR.exe
uRun: [KiesPreload] c:\program files\samsung\kies\Kies.exe /preload
uRun: [News.net] c:\program files\news.net\breakingnews\DesktopContainer.exe
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [NBAgent] "c:\program files\nero\nero 10\nero backitup\NBAgent.exe" /WinStart
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [KiesTrayAgent] c:\program files\samsung\kies\KiesTrayAgent.exe
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [lkebutoh] "c:\programdata\ofjz\ecuwofez.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\netcom~1.lnk - c:\program files\netcomm\common\RaUI.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\ricohg~1.lnk - c:\program files\caplio software\RGateLXP.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office10\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
Trusted Zone: alipay.com
Trusted Zone: alipay.com
Trusted Zone: alisoft.com
Trusted Zone: alisoft.com
Trusted Zone: taobao.com
Trusted Zone: taobao.com
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{1C009DDA-39C5-42BB-9ED4-B4AA02C2094A} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{1C009DDA-39C5-42BB-9ED4-B4AA02C2094A}\44C494E4B4 : DHCPNameServer = 10.1.1.1
TCP: Interfaces\{78B4CEE9-F16C-44DF-923A-A668D96E9611} : DHCPNameServer = 192.168.1.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs= c:\progra~1\searchprotect\searchprotect\bin\SPVC32Loader.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\unknown\appdata\roaming\mozilla\firefox\profiles\cr4c0zm7.default-1394486327657\
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.22.5\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.30214.0\npctrlui.dll
FF - plugin: c:\program files\trademanager\npalissologin.dll
FF - plugin: c:\program files\trademanager\nptrademanager.dll
FF - plugin: c:\program files\trademanager\npwangwang.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\unknown\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_12_0_0_77.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2013-9-27 214696]
R1 MpKsldff1a976;MpKsldff1a976;c:\programdata\microsoft\microsoft antimalware\definition updates\{75783977-8eb0-4949-91cf-29e83014da71}\MpKsldff1a976.sys [2014-3-14 39464]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2014-3-11 418376]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2014-3-11 701512]
R2 NAUpdate;Nero Update;c:\program files\nero\update\NASvc.exe [2010-3-25 490280]
R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 104768]
R2 RalinkRegistryWriter;Ralink Registry Writer;c:\program files\netcomm\common\RegistryWriter.exe [2011-10-7 69632]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-3-11 22856]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2013-10-23 280288]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [2012-1-16 30312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 bqusbser;WCDMA USB Device for Legacy Serial Communication;c:\windows\system32\drivers\Mousbser.sys [2008-5-22 103936]
S3 BrSerIb;Brother MFC Serial Interface Driver(WDM);c:\windows\system32\drivers\BrSerIb.sys [2009-7-14 265088]
S3 BrUsbSIb;Brother MFC Serial USB Driver(WDM);c:\windows\system32\drivers\BrUsbSIb.sys [2009-7-14 11904]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [2013-6-4 84248]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2012-6-20 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2014-3-13 108032]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2011-8-2 18432]
S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\drivers\netr28u.sys [2009-6-11 657408]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2014-3-12 14848]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2012-1-16 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2012-1-16 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2012-1-16 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [2012-1-16 114280]
S3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [2013-6-4 181912]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2014-3-12 49152]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-3-17 1343400]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-23 51040]
.
=============== File Associations ===============
.
ShellExec: DigitalTheatre.exe: open="c:\program files\arcsoft\totalmedia extreme\digital theatre\uDTStart.exe" "%1"
.
=============== Created Last 30 ================
.
2014-03-14 05:28:28    39464    ----a-w-    c:\programdata\microsoft\microsoft antimalware\definition updates\{75783977-8eb0-4949-91cf-29e83014da71}\MpKsldff1a976.sys
2014-03-14 05:10:05    --------    d-----w-    c:\users\unknown\appdata\local\{22417392-7AD2-419B-9A6E-E56B23C6F117}
2014-03-13 16:00:38    --------    d-----w-    c:\users\unknown\appdata\local\{B831E33C-181D-4798-99D1-47DC39FA776B}
2014-03-13 16:00:32    --------    d-----w-    c:\programdata\ofjz
2014-03-13 04:09:53    7947048    ------w-    c:\programdata\microsoft\microsoft antimalware\definition updates\{75783977-8eb0-4949-91cf-29e83014da71}\mpengine.dll
2014-03-13 00:20:25    185344    ----a-w-    c:\windows\system32\wwansvc.dll
2014-03-13 00:20:22    2349056    ----a-w-    c:\windows\system32\win32k.sys
2014-03-13 00:20:21    1230336    ----a-w-    c:\windows\system32\WindowsCodecs.dll
2014-03-13 00:20:19    5694464    ----a-w-    c:\windows\system32\mstscax.dll
2014-03-13 00:20:14    381440    ----a-w-    c:\windows\system32\wer.dll
2014-03-12 21:19:30    --------    d-----w-    c:\users\unknown\appdata\local\{58513ECF-F5D2-44E5-9F4C-9A0CBDF45CC6}
2014-03-12 04:00:31    7947048    ------w-    c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2014-03-11 22:26:37    14848    ----a-w-    c:\windows\system32\drivers\rdpvideominiport.sys
2014-03-11 22:26:37    12800    ----a-w-    c:\windows\system32\RdpGroupPolicyExtension.dll
2014-03-11 22:26:34    221184    ----a-w-    c:\windows\system32\rdpudd.dll
2014-03-11 22:26:34    192000    ----a-w-    c:\windows\system32\rdpendp_winip.dll
2014-03-11 22:26:33    2739712    ----a-w-    c:\windows\system32\rdpcorets.dll
2014-03-11 22:26:03    32256    ----a-w-    c:\windows\system32\TsUsbGDCoInstaller.dll
2014-03-11 22:26:01    12800    ----a-w-    c:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-03-11 22:26:00    49152    ----a-w-    c:\windows\system32\drivers\TsUsbFlt.sys
2014-03-11 22:25:59    53248    ----a-w-    c:\windows\system32\tsgqec.dll
2014-03-11 22:25:59    50176    ----a-w-    c:\windows\system32\MsRdpWebAccess.dll
2014-03-11 22:25:59    17920    ----a-w-    c:\windows\system32\wksprtPS.dll
2014-03-11 22:25:59    14336    ----a-w-    c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-03-11 22:25:58    855552    ----a-w-    c:\windows\system32\rdvidcrl.dll
2014-03-11 22:25:58    76288    ----a-w-    c:\windows\system32\TSWbPrxy.exe
2014-03-11 22:25:58    350208    ----a-w-    c:\windows\system32\wksprt.exe
2014-03-11 22:25:58    1068544    ----a-w-    c:\windows\system32\mstsc.exe
2014-03-11 22:24:08    792576    ----a-w-    c:\windows\system32\TSWorkspace.dll
2014-03-11 22:24:05    514560    ----a-w-    c:\windows\system32\qdvd.dll
2014-03-11 22:19:13    --------    d-----w-    c:\users\unknown\appdata\local\{F96658A8-FAF7-4C1D-86ED-1C0CEFDA33BE}
2014-03-11 09:57:26    --------    d-----w-    c:\users\unknown\appdata\local\{3CBA1460-F382-4ECA-BC06-C439939ADE7C}
2014-03-11 05:45:42    --------    d-----w-    c:\program files\Speccy
2014-03-11 00:45:56    --------    d-----w-    c:\program files\ESET
2014-03-10 21:27:44    22856    ----a-w-    c:\windows\system32\drivers\mbam.sys
2014-03-10 21:27:44    --------    d-----w-    c:\program files\Malwarebytes' Anti-Malware
2014-03-10 20:46:43    --------    d-----w-    c:\users\unknown\appdata\local\{824DB67E-2AF1-4AB3-B831-9599F9BFBA69}
2014-03-10 08:46:14    --------    d-----w-    c:\users\unknown\appdata\local\{480D26A8-315E-4F8A-99F9-64C14003FA5E}
2014-03-10 05:37:32    --------    d-----w-    c:\programdata\ebdc
2014-03-09 20:43:15    --------    d-----w-    c:\users\unknown\appdata\local\{CBF052D1-D3A3-4F18-BAE7-9B7CD75C2A6C}
2014-03-09 04:16:47    765968    ------w-    c:\programdata\microsoft\microsoft antimalware\definition updates\{e38f04a1-a12e-487a-bde4-3534beba21f7}\gapaengine.dll
2014-03-08 08:30:31    --------    d-----w-    c:\users\unknown\appdata\local\CrashDumps
2014-03-08 08:30:22    --------    d-----w-    c:\users\unknown\appdata\local\{A88AE5B2-ABEB-4965-B22F-71157B3D3010}
2014-03-07 20:14:55    --------    d-----w-    c:\programdata\iflr
2014-03-07 20:06:26    --------    d-----w-    c:\users\unknown\appdata\local\{D96128E7-775A-4D37-96E2-8E5A5750BEC2}
2014-03-06 23:13:47    --------    d-----w-    c:\users\unknown\appdata\local\{F9AAEE8B-864D-4ACD-9F94-7F0FCF0559E7}
2014-03-05 22:02:14    --------    d-----w-    c:\users\unknown\appdata\local\{DE030B0A-6BE1-4FDF-A1FF-1B6262C897A8}
2014-03-05 08:44:08    --------    d-----w-    c:\users\unknown\appdata\local\{E56DB46F-396F-4167-85EE-422A02FE158C}
2014-03-04 20:43:40    --------    d-----w-    c:\users\unknown\appdata\local\{937EBBB1-75AC-416B-8518-6FFDD411C514}
2014-03-04 01:44:00    --------    d-----w-    c:\programdata\ilin
2014-03-03 19:53:00    --------    d-----w-    c:\programdata\Oracle
2014-03-03 19:52:30    94632    ----a-w-    c:\windows\system32\WindowsAccessBridge.dll
2014-03-03 19:43:01    --------    d-----w-    c:\users\unknown\appdata\local\{8445ED36-709F-489C-8A19-08FA29853D50}
2014-03-03 05:19:32    --------    d-----w-    c:\users\unknown\appdata\local\{CE1B8D22-0818-46C6-B5C6-5ABD7F0F53A1}
2014-03-03 03:04:33    --------    d-----w-    c:\programdata\inyv
2014-03-03 02:18:58    --------    d-----w-    c:\programdata\yqyc
2014-03-03 02:18:56    --------    d-----w-    c:\programdata\amepugyf
2014-03-02 17:19:04    --------    d-----w-    c:\users\unknown\appdata\local\{C8553F1C-DCC3-4186-81AC-D59DC80B7754}
2014-03-01 21:22:10    --------    d-----w-    c:\users\unknown\appdata\local\{7988F25E-42D5-483F-8C31-AA7B00BB8350}
2014-02-28 21:53:54    --------    d-----w-    c:\users\unknown\appdata\local\{76D4D32B-9E1E-4329-9BDD-16DD7866C0E9}
2014-02-27 19:52:47    --------    d-----w-    c:\users\unknown\appdata\local\{12C0B45D-95EB-4F40-8055-5988414D1F2A}
2014-02-26 20:35:08    --------    d-----w-    c:\users\unknown\appdata\local\{D95EA739-1005-4962-8FE2-6DC10B269C6C}
2014-02-25 21:11:47    --------    d-----w-    c:\users\unknown\appdata\local\{4A52383B-9DA4-4D77-8997-3635B681EF21}
2014-02-25 07:25:18    --------    d-----w-    c:\users\unknown\appdata\local\{D6B27FDB-5D94-4B77-929F-CD800B3BBD30}
2014-02-24 19:22:42    --------    d-----w-    c:\users\unknown\appdata\local\{E5CAC627-E354-4FFA-B81B-40B990A40CF8}
2014-02-24 06:49:22    --------    d-----w-    c:\users\unknown\appdata\local\{414E4E6C-C6CE-42E7-8CF4-26CF6F52FE1A}
2014-02-23 18:49:06    --------    d-----w-    c:\users\unknown\appdata\local\{A0A0B8AF-CB9C-44E5-B043-D982A1548B56}
2014-02-22 18:52:50    --------    d-----w-    c:\users\unknown\appdata\local\{A2C20AE5-2970-4901-8E5F-28854CF0719C}
2014-02-22 05:30:54    --------    d-----w-    c:\users\unknown\appdata\local\{3B0DA881-2B59-4EC3-B6FE-7A4AE0C68BAF}
2014-02-21 00:46:07    --------    d-----w-    c:\users\unknown\appdata\local\{18F099C4-3CE5-4516-806F-E73F1F33770E}
2014-02-20 09:39:35    --------    d-----w-    c:\users\unknown\appdata\local\{B2E264EE-87EE-479E-88C8-D3AFA709CA5A}
2014-02-19 21:13:17    --------    d-----w-    c:\users\unknown\appdata\local\{FE58155E-F2DB-4206-94D2-C076D381045C}
2014-02-19 07:42:36    --------    d-----w-    c:\users\unknown\appdata\local\{78E0DC29-60A3-4BDC-B96D-7589151BC609}
2014-02-18 18:51:09    --------    d-----w-    c:\users\unknown\appdata\local\{6F44F1E2-F261-4814-A0D5-0D559FB63055}
2014-02-17 20:19:38    --------    d-----w-    c:\users\unknown\appdata\local\{DCD5934F-9564-4666-AD95-8BDC02E6BE98}
2014-02-17 08:19:25    --------    d-----w-    c:\users\unknown\appdata\local\{86C8749A-58DF-4C3A-BD14-E688182BDF44}
2014-02-16 20:19:12    --------    d-----w-    c:\users\unknown\appdata\local\{A9E9283D-0593-43EF-9943-D1F3E42C9CD8}
2014-02-15 22:56:20    --------    d-----w-    c:\users\unknown\appdata\local\{0026EF2A-4381-4248-971F-F281B13CD76A}
2014-02-14 20:21:59    --------    d-----w-    c:\users\unknown\appdata\local\{FD2DB3B0-C157-432F-BE58-343311AAECEA}
2014-02-13 20:59:14    --------    d-----w-    c:\users\unknown\appdata\local\{C804A8BE-2355-45AD-BEFF-CAD9EE7AEAF9}
2014-02-13 07:11:14    --------    d-----w-    c:\users\unknown\appdata\local\{0E04FBCB-84F9-45D0-B3AD-2D504D6037A2}
2014-02-12 16:04:43    454656    ----a-w-    c:\windows\system32\vbscript.dll
2014-02-12 16:00:40    --------    d-----w-    c:\users\unknown\appdata\local\{4A221742-2C67-489A-B75D-91BC250DC791}
.
==================== Find3M  ====================
.
2014-03-11 22:56:38    71048    ----a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl
2014-03-11 22:56:38    692616    ----a-w-    c:\windows\system32\FlashPlayerApp.exe
2014-03-01 04:11:20    2724864    ----a-w-    c:\windows\system32\mshtml.tlb
2014-03-01 04:10:48    4096    ----a-w-    c:\windows\system32\ieetwcollectorres.dll
2014-03-01 03:52:43    61952    ----a-w-    c:\windows\system32\iesetup.dll
2014-03-01 03:51:53    51200    ----a-w-    c:\windows\system32\ieetwproxystub.dll
2014-03-01 03:38:26    112128    ----a-w-    c:\windows\system32\ieUnatt.exe
2014-03-01 03:38:23    108032    ----a-w-    c:\windows\system32\ieetwcollector.exe
2014-03-01 03:37:35    553472    ----a-w-    c:\windows\system32\jscript9diag.dll
2014-03-01 03:31:30    646144    ----a-w-    c:\windows\system32\MsSpellCheckingFacility.exe
2014-03-01 03:14:15    4244480    ----a-w-    c:\windows\system32\jscript9.dll
2014-03-01 03:00:08    1964032    ----a-w-    c:\windows\system32\inetcpl.cpl
2014-03-01 02:32:16    1820160    ----a-w-    c:\windows\system32\wininet.dll
2014-02-04 02:04:11    509440    ----a-w-    c:\windows\system32\qedit.dll
2014-01-19 07:32:23    231584    ------w-    c:\windows\system32\MpSigStub.exe
2014-01-16 00:40:14    487016    ----a-w-    C:\SecurityScanner.dll
2013-12-24 23:09:41    1987584    ----a-w-    c:\windows\system32\d3d10warp.dll
.
============= FINISH: 16:33:49.84 ===============
 

Attached Files



BC AdBot (Login to Remove)

 


#2 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:34 AM

Posted 14 March 2014 - 03:02 AM

Hi there,

yeah your computer is still infected!
Please run the following scans:


Step 1

Please download TDSSKiller and save it to your Desktop.

  • Start tdsskiller.exe with administrator privileges.
  • Accept the EULA and the KSN Statement.
  • Click on Change parameters.
  • Make sure that all available options (except "Loaded modules") are checked and click OK.
  • Click on Start scan.
  • If any threats are found don't delete them but choose the Skip option for all of them.
  • Click on Report to open the log file. (It is also saved at C:\TDSSKiller.<version_date_time>_log.txt).
    Copy and paste its contents in your next reply.

 

 

 

Step 2

Please download Farbar Recovery Scan Tool and save it to your Desktop.

  • Start FRST with administator privileges.
  • Make sure the option Addition.txt is checked and press the Scan button.
  • When finished, FRST will produce two logs (FRST.txt and Addition.txt) in the same directory the tool was run from.
  • Please copy and paste these logs in your next reply.


#3 Aurifex

Aurifex
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:12:34 PM

Posted 15 March 2014 - 02:09 PM

06:05:00.0559 0x095c  TDSS rootkit removing tool 3.0.0.25 Feb 27 2014 15:23:02
06:05:05.0874 0x095c  ============================================================
06:05:05.0874 0x095c  Current date / time: 2014/03/16 06:05:05.0874
06:05:05.0874 0x095c  SystemInfo:
06:05:05.0874 0x095c  
06:05:05.0874 0x095c  OS Version: 6.1.7601 ServicePack: 1.0
06:05:05.0874 0x095c  Product type: Workstation
06:05:05.0874 0x095c  ComputerName: UNKNOWN-PC
06:05:05.0875 0x095c  UserName: unknown
06:05:05.0875 0x095c  Windows directory: C:\Windows
06:05:05.0875 0x095c  System windows directory: C:\Windows
06:05:05.0875 0x095c  Processor architecture: Intel x86
06:05:05.0875 0x095c  Number of processors: 2
06:05:05.0875 0x095c  Page size: 0x1000
06:05:05.0875 0x095c  Boot type: Normal boot
06:05:05.0875 0x095c  ============================================================
06:05:07.0245 0x095c  KLMD registered as C:\Windows\system32\drivers\08647932.sys
06:05:07.0684 0x095c  System UUID: {C08F7665-EA5C-6DEF-7D72-DADC39B8E5AB}
06:05:08.0502 0x095c  Drive \Device\Harddisk0\DR0 - Size: 0x7470AFDE00 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
06:05:08.0516 0x095c  Drive \Device\Harddisk1\DR1 - Size: 0x4A85C4DE00 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
06:05:08.0518 0x095c  ============================================================
06:05:08.0518 0x095c  \Device\Harddisk0\DR0:
06:05:08.0519 0x095c  MBR partitions:
06:05:08.0519 0x095c  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384405
06:05:08.0519 0x095c  \Device\Harddisk1\DR1:
06:05:08.0519 0x095c  MBR partitions:
06:05:08.0519 0x095c  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2542D682
06:05:08.0519 0x095c  ============================================================
06:05:08.0539 0x095c  C: <-> \Device\Harddisk1\DR1\Partition1
06:05:08.0546 0x095c  E: <-> \Device\Harddisk0\DR0\Partition1
06:05:08.0589 0x095c  ============================================================
06:05:08.0590 0x095c  Initialize success
06:05:08.0590 0x095c  ============================================================
06:06:07.0944 0x17fc  ============================================================
06:06:07.0944 0x17fc  Scan started
06:06:07.0944 0x17fc  Mode: Manual; SigCheck; TDLFS;
06:06:07.0944 0x17fc  ============================================================
06:06:07.0944 0x17fc  KSN ping started
06:06:10.0814 0x17fc  KSN ping finished: true
06:06:11.0048 0x17fc  ================ Scan system memory ========================
06:06:11.0048 0x17fc  System memory - ok
06:06:11.0048 0x17fc  ================ Scan services =============================
06:06:11.0236 0x17fc  [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
06:06:11.0314 0x17fc  1394ohci - ok
06:06:11.0392 0x17fc  [ BEB5E6A8C17C3C7485563281E0F9E77E, D04ACF4833370AC1BFA5365B7D23DB0F6BD5067102B4AD523D74DBE89EDDABBA ] 61883           C:\Windows\system32\DRIVERS\61883.sys
06:06:11.0454 0x17fc  61883 - ok
06:06:11.0532 0x17fc  [ ADC420616C501B45D26C0FD3EF1E54E4, 29FC41D40A35AC5476E2A673CE5B12684E0CFA12A1AEBEEBE5883FBA5CA68B67 ] ACDaemon        C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
06:06:11.0548 0x17fc  ACDaemon - ok
06:06:11.0594 0x17fc  [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI            C:\Windows\system32\drivers\ACPI.sys
06:06:11.0610 0x17fc  ACPI - ok
06:06:11.0641 0x17fc  [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
06:06:11.0704 0x17fc  AcpiPmi - ok
06:06:11.0813 0x17fc  [ B362181ED3771DC03B4141927C80F801, 69514E5177A0AEA89C27C2234712F9F82E8D8F99E1FD4273898C9324C6FF7472 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
06:06:11.0828 0x17fc  AdobeARMservice - ok
06:06:11.0938 0x17fc  [ 9D96B0D5855FD1B98023B3EEC9F06786, E4C79233158BE8AA4E9C6DD71585E5D2703A5156531EB3D692D7D81BC443E844 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
06:06:11.0953 0x17fc  AdobeFlashPlayerUpdateSvc - ok
06:06:12.0000 0x17fc  [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx         C:\Windows\system32\DRIVERS\adp94xx.sys
06:06:12.0031 0x17fc  adp94xx - ok
06:06:12.0062 0x17fc  [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci         C:\Windows\system32\DRIVERS\adpahci.sys
06:06:12.0078 0x17fc  adpahci - ok
06:06:12.0140 0x17fc  [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320         C:\Windows\system32\DRIVERS\adpu320.sys
06:06:12.0156 0x17fc  adpu320 - ok
06:06:12.0203 0x17fc  [ 8B5EEFEEC1E6D1A72A06C526628AD161, 026CDF4C96F4D493E7BABF79A14C4B0B5ADCCEF0B081FFFA2E3B243B2414167F ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
06:06:12.0250 0x17fc  AeLookupSvc - ok
06:06:12.0296 0x17fc  [ F81BB7E487EDCEAB630A7EE66CF23913, 7D1638FD7E388EF670FA0A421762E0413351058A20DDF0F9988A383F05395A68 ] AFD             C:\Windows\system32\drivers\afd.sys
06:06:12.0359 0x17fc  AFD - ok
06:06:12.0406 0x17fc  [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440          C:\Windows\system32\drivers\agp440.sys
06:06:12.0406 0x17fc  agp440 - ok
06:06:12.0437 0x17fc  [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx         C:\Windows\system32\DRIVERS\djsvs.sys
06:06:12.0452 0x17fc  aic78xx - ok
06:06:12.0484 0x17fc  [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG             C:\Windows\System32\alg.exe
06:06:12.0546 0x17fc  ALG - ok
06:06:12.0577 0x17fc  [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide          C:\Windows\system32\drivers\aliide.sys
06:06:12.0593 0x17fc  aliide - ok
06:06:12.0624 0x17fc  [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
06:06:12.0640 0x17fc  amdagp - ok
06:06:12.0702 0x17fc  [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide          C:\Windows\system32\drivers\amdide.sys
06:06:12.0718 0x17fc  amdide - ok
06:06:12.0764 0x17fc  [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8           C:\Windows\system32\DRIVERS\amdk8.sys
06:06:12.0811 0x17fc  AmdK8 - ok
06:06:12.0827 0x17fc  [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
06:06:12.0874 0x17fc  AmdPPM - ok
06:06:12.0920 0x17fc  [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
06:06:12.0936 0x17fc  amdsata - ok
06:06:12.0952 0x17fc  [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
06:06:12.0967 0x17fc  amdsbs - ok
06:06:12.0983 0x17fc  [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
06:06:12.0998 0x17fc  amdxata - ok
06:06:13.0030 0x17fc  [ DD8D9C597AF7CD2F6B70A3D6A4A1ACEA, 834B397F365D930DA01D5189DDF06195CFE4C0F9249223C5A9004643F41BA6E4 ] androidusb      C:\Windows\system32\Drivers\ssadadb.sys
06:06:13.0108 0x17fc  androidusb - ok
06:06:13.0154 0x17fc  [ AEA177F783E20150ACE5383EE368DA19, 8FA9EE27AA1F22E8B8FE33A21028CA1E0062BAA95CB132C20D55B98C03B4254F ] AppID           C:\Windows\system32\drivers\appid.sys
06:06:13.0279 0x17fc  AppID - ok
06:06:13.0342 0x17fc  [ 62A9C86CB6085E20DB4823E4E97826F5, E0F840B49710022C4FB437002AD06F64B0F6B5D628B32D00F2B66765E6B97E4B ] AppIDSvc        C:\Windows\System32\appidsvc.dll
06:06:13.0388 0x17fc  AppIDSvc - ok
06:06:13.0420 0x17fc  [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] Appinfo         C:\Windows\System32\appinfo.dll
06:06:13.0466 0x17fc  Appinfo - ok
06:06:13.0544 0x17fc  [ A5299D04ED225D64CF07A568A3E1BF8C, 6F7E73893127BADC8C9815E9BCC0EB5F6584E254D0D09A0B6A680704C71E0A90 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
06:06:13.0560 0x17fc  Apple Mobile Device - ok
06:06:13.0591 0x17fc  [ A45D184DF6A8803DA13A0B329517A64A, C1D16B60A6D69689AE951DC3D6884ED2E233D144B3FC0B86BC1C50AAAAA01ED2 ] AppMgmt         C:\Windows\System32\appmgmts.dll
06:06:13.0638 0x17fc  AppMgmt - ok
06:06:13.0669 0x17fc  [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc             C:\Windows\system32\DRIVERS\arc.sys
06:06:13.0685 0x17fc  arc - ok
06:06:13.0716 0x17fc  [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
06:06:13.0732 0x17fc  arcsas - ok
06:06:13.0841 0x17fc  [ 9D768C43FEF254DD50B1DBF8AD5C4C0B, A50854EA5C08605133B8BB4DFDC6090357C5665314AA72E0BFA1E07D4E451F09 ] aspnet_state    C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
06:06:13.0856 0x17fc  aspnet_state - ok
06:06:13.0872 0x17fc  [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
06:06:13.0981 0x17fc  AsyncMac - ok
06:06:14.0012 0x17fc  [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi           C:\Windows\system32\drivers\atapi.sys
06:06:14.0028 0x17fc  atapi - ok
06:06:14.0215 0x17fc  [ 712D8A95E45B070114C5309ADA7358FF, 1F0285CFB9982637186531489743798511BA75B612B202231E9BC1CF5372C0BB ] atikmdag        C:\Windows\system32\drivers\atikmdag.sys
06:06:14.0418 0x17fc  atikmdag - ok
06:06:14.0480 0x17fc  [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E141BA11471666E7D9EB3C93CC ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
06:06:14.0527 0x17fc  AudioEndpointBuilder - ok
06:06:14.0558 0x17fc  [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E141BA11471666E7D9EB3C93CC ] Audiosrv        C:\Windows\System32\Audiosrv.dll
06:06:14.0590 0x17fc  Audiosrv - ok
06:06:14.0636 0x17fc  [ C44BDD77E06053CF5AFE046F3A47C16B, FB0EF5AEDD5F8760765A3AB890B32867C0A38397B6423D5291BCFF6FC38346D9 ] Avc             C:\Windows\system32\DRIVERS\avc.sys
06:06:14.0668 0x17fc  Avc - ok
06:06:14.0699 0x17fc  [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV        C:\Windows\System32\AxInstSV.dll
06:06:14.0746 0x17fc  AxInstSV - ok
06:06:14.0777 0x17fc  [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv         C:\Windows\system32\DRIVERS\bxvbdx.sys
06:06:14.0808 0x17fc  b06bdrv - ok
06:06:14.0855 0x17fc  [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x        C:\Windows\system32\DRIVERS\b57nd60x.sys
06:06:14.0886 0x17fc  b57nd60x - ok
06:06:14.0933 0x17fc  [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC          C:\Windows\System32\bdesvc.dll
06:06:14.0980 0x17fc  BDESVC - ok
06:06:14.0995 0x17fc  [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep            C:\Windows\system32\drivers\Beep.sys
06:06:15.0026 0x17fc  Beep - ok
06:06:15.0089 0x17fc  [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE             C:\Windows\System32\bfe.dll
06:06:15.0167 0x17fc  BFE - ok
06:06:15.0214 0x17fc  [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS            C:\Windows\system32\qmgr.dll
06:06:15.0260 0x17fc  BITS - ok
06:06:15.0276 0x17fc  [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
06:06:15.0307 0x17fc  blbdrive - ok
06:06:15.0401 0x17fc  [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A, 10F21999FF6B1D410EBF280F7F27DEACA5289739CF12F4293B614B8FC6C88DCC ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
06:06:15.0416 0x17fc  Bonjour Service - ok
06:06:15.0463 0x17fc  [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
06:06:15.0479 0x17fc  bowser - ok
06:06:15.0510 0x17fc  [ 92AFD281E9169EEE644636DEA975F320, D00C20C3F86EF6F26F2B8488E16F11C03450D6170B935FB9EE226D0A6A83AABA ] bqusbser        C:\Windows\system32\DRIVERS\Mousbser.sys
06:06:15.0557 0x17fc  bqusbser - ok
06:06:15.0572 0x17fc  [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
06:06:15.0604 0x17fc  BrFiltLo - ok
06:06:15.0619 0x17fc  [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
06:06:15.0650 0x17fc  BrFiltUp - ok
06:06:15.0697 0x17fc  [ 77361D72A04F18809D0EFB6CCEB74D4B, 55E7DB65BB29FF421F138CDFF05E5ECFFC7C8862FAA68F6179A3BA9D6B69AE64 ] BridgeMP        C:\Windows\system32\DRIVERS\bridge.sys
06:06:15.0760 0x17fc  BridgeMP - ok
06:06:15.0822 0x17fc  [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser         C:\Windows\System32\browser.dll
06:06:15.0884 0x17fc  Browser - ok
06:06:15.0916 0x17fc  [ 08C7E41FF10F56E83B4F10B5E8B1E8B6, AF75E3EDFECC145B8389E4AA6EB8A7456CD60B4462BED7EE7C2C70C534697A9F ] BrSerIb         C:\Windows\system32\DRIVERS\BrSerIb.sys
06:06:15.0962 0x17fc  BrSerIb - ok
06:06:15.0994 0x17fc  [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
06:06:16.0040 0x17fc  Brserid - ok
06:06:16.0103 0x17fc  [ 56F59A4011F503149AE4DE826982CA4F, C89142939D576D33FC4B130F529A02DC15B1247C76419111DF450AF4191CE23B ] BrSerIf         C:\Windows\system32\Drivers\BrSerIf.sys
06:06:16.0150 0x17fc  BrSerIf - ok
06:06:16.0165 0x17fc  [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
06:06:16.0196 0x17fc  BrSerWdm - ok
06:06:16.0228 0x17fc  [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
06:06:16.0274 0x17fc  BrUsbMdm - ok
06:06:16.0290 0x17fc  [ A24C7B39602218F8DBDB2B6704325FC7, B90A1BA412A33AD041A2CE47FBB73AE296AF07A2F3DF1F56D9FEE5B3B1E0BBD5 ] BrUsbSer        C:\Windows\system32\Drivers\BrUsbSer.sys
06:06:16.0321 0x17fc  BrUsbSer - ok
06:06:16.0337 0x17fc  [ 2132A117160F2A96A13C044AE9BCED91, 97ADC66B6FEFA369237E989027C57A0DF28DE031DD2E885325DDB2F54F17745A ] BrUsbSIb        C:\Windows\system32\DRIVERS\BrUsbSIb.sys
06:06:16.0368 0x17fc  BrUsbSIb - ok
06:06:16.0399 0x17fc  [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
06:06:16.0430 0x17fc  BTHMODEM - ok
06:06:16.0477 0x17fc  [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv         C:\Windows\system32\bthserv.dll
06:06:16.0524 0x17fc  bthserv - ok
06:06:16.0680 0x17fc  catchme - ok
06:06:16.0789 0x17fc  [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
06:06:16.0836 0x17fc  cdfs - ok
06:06:16.0883 0x17fc  [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
06:06:16.0898 0x17fc  cdrom - ok
06:06:16.0930 0x17fc  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc     C:\Windows\System32\certprop.dll
06:06:16.0976 0x17fc  CertPropSvc - ok
06:06:17.0008 0x17fc  [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
06:06:17.0023 0x17fc  circlass - ok
06:06:17.0039 0x17fc  [ 635181E0E9BBF16871BF5380D71DB02D, 58D5150C6F3B9F1730FFDF3A8A2ABF5FF207F9785BD66C0C1E03A0F1C223A26A ] CLFS            C:\Windows\system32\CLFS.sys
06:06:17.0070 0x17fc  CLFS - ok
06:06:17.0132 0x17fc  [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
06:06:17.0148 0x17fc  clr_optimization_v2.0.50727_32 - ok
06:06:17.0195 0x17fc  [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
06:06:17.0210 0x17fc  clr_optimization_v4.0.30319_32 - ok
06:06:17.0242 0x17fc  [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
06:06:17.0273 0x17fc  CmBatt - ok
06:06:17.0304 0x17fc  [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
06:06:17.0320 0x17fc  cmdide - ok
06:06:17.0366 0x17fc  [ 85449EEBE8F8EBD6481EFBF0F352B4EB, E6FF04970C5A5BFDE7297A86C1C7B9BFE2E0F976A1A1AFB874CEB488DC6151CC ] CNG             C:\Windows\system32\Drivers\cng.sys
06:06:17.0398 0x17fc  CNG - ok
06:06:17.0413 0x17fc  [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
06:06:17.0429 0x17fc  Compbatt - ok
06:06:17.0460 0x17fc  [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
06:06:17.0491 0x17fc  CompositeBus - ok
06:06:17.0507 0x17fc  COMSysApp - ok
06:06:17.0522 0x17fc  [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk         C:\Windows\system32\DRIVERS\crcdisk.sys
06:06:17.0538 0x17fc  crcdisk - ok
06:06:17.0585 0x17fc  [ 7CA1BECEA5DE2643ADDAD32670E7A4C9, E3AB4CC52A97E3855D7EAB87363F807FDD2162ED8C76A036CD71549ED64E7797 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
06:06:17.0647 0x17fc  CryptSvc - ok
06:06:17.0678 0x17fc  [ 3C2177A897B4CA2788C6FB0C3FD81D4B, 98575CBD0664586E6211D02E71BDD52CBAA149A1658573550E29E74E5F7B1553 ] CSC             C:\Windows\system32\drivers\csc.sys
06:06:17.0741 0x17fc  CSC - ok
06:06:17.0772 0x17fc  [ 15F93B37F6801943360D9EB42485D5D3, DD6838C6496CB15F8BB57A6596F6A64ADD9C36B09F062295699131232712B558 ] CscService      C:\Windows\System32\cscsvc.dll
06:06:17.0819 0x17fc  CscService - ok
06:06:17.0866 0x17fc  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch      C:\Windows\system32\rpcss.dll
06:06:17.0897 0x17fc  DcomLaunch - ok
06:06:17.0928 0x17fc  [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc       C:\Windows\System32\defragsvc.dll
06:06:17.0990 0x17fc  defragsvc - ok
06:06:18.0037 0x17fc  [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
06:06:18.0084 0x17fc  DfsC - ok
06:06:18.0131 0x17fc  [ 54D0B8343CE8C22412A5F29D32EFD211, D78BF09680FF19523C84E862593B45637D91A079C79CAB63A13726E7ACA8ABBF ] dg_ssudbus      C:\Windows\system32\DRIVERS\ssudbus.sys
06:06:18.0146 0x17fc  dg_ssudbus - ok
06:06:18.0193 0x17fc  [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp            C:\Windows\system32\dhcpcore.dll
06:06:18.0287 0x17fc  Dhcp - ok
06:06:18.0318 0x17fc  [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache        C:\Windows\system32\drivers\discache.sys
06:06:18.0349 0x17fc  discache - ok
06:06:18.0396 0x17fc  [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk            C:\Windows\system32\DRIVERS\disk.sys
06:06:18.0412 0x17fc  Disk - ok
06:06:18.0443 0x17fc  [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache        C:\Windows\System32\dnsrslvr.dll
06:06:18.0490 0x17fc  Dnscache - ok
06:06:18.0552 0x17fc  [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc         C:\Windows\System32\dot3svc.dll
06:06:18.0599 0x17fc  dot3svc - ok
06:06:18.0661 0x17fc  [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS             C:\Windows\system32\dps.dll
06:06:18.0708 0x17fc  DPS - ok
06:06:18.0755 0x17fc  [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
06:06:18.0802 0x17fc  drmkaud - ok
06:06:18.0864 0x17fc  [ 71BC35067CABC02C9453AEAA42B2E43E, 713B19F2C08EA5E4C087F7A74A8856932CF33E19D63384823DD4E02ED8798619 ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
06:06:18.0895 0x17fc  DXGKrnl - ok
06:06:18.0926 0x17fc  [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost         C:\Windows\System32\eapsvc.dll
06:06:18.0973 0x17fc  EapHost - ok
06:06:19.0098 0x17fc  [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv           C:\Windows\system32\DRIVERS\evbdx.sys
06:06:19.0254 0x17fc  ebdrv - ok
06:06:19.0301 0x17fc  [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] EFS             C:\Windows\System32\lsass.exe
06:06:19.0316 0x17fc  EFS - ok
06:06:19.0379 0x17fc  [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
06:06:19.0472 0x17fc  ehRecvr - ok
06:06:19.0488 0x17fc  [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched         C:\Windows\ehome\ehsched.exe
06:06:19.0535 0x17fc  ehSched - ok
06:06:19.0582 0x17fc  [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor         C:\Windows\system32\DRIVERS\elxstor.sys
06:06:19.0613 0x17fc  elxstor - ok
06:06:19.0644 0x17fc  [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
06:06:19.0675 0x17fc  ErrDev - ok
06:06:19.0753 0x17fc  esgiguard - ok
06:06:19.0784 0x17fc  [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem     C:\Windows\system32\es.dll
06:06:19.0816 0x17fc  EventSystem - ok
06:06:19.0831 0x17fc  [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat           C:\Windows\system32\drivers\exfat.sys
06:06:19.0862 0x17fc  exfat - ok
06:06:19.0878 0x17fc  [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
06:06:19.0940 0x17fc  fastfat - ok
06:06:20.0003 0x17fc  [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax             C:\Windows\system32\fxssvc.exe
06:06:20.0065 0x17fc  Fax - ok
06:06:20.0096 0x17fc  [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc             C:\Windows\system32\DRIVERS\fdc.sys
06:06:20.0128 0x17fc  fdc - ok
06:06:20.0159 0x17fc  [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost         C:\Windows\system32\fdPHost.dll
06:06:20.0206 0x17fc  fdPHost - ok
06:06:20.0221 0x17fc  [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub        C:\Windows\system32\fdrespub.dll
06:06:20.0268 0x17fc  FDResPub - ok
06:06:20.0299 0x17fc  [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
06:06:20.0315 0x17fc  FileInfo - ok
06:06:20.0330 0x17fc  [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
06:06:20.0362 0x17fc  Filetrace - ok
06:06:20.0377 0x17fc  [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
06:06:20.0408 0x17fc  flpydisk - ok
06:06:20.0440 0x17fc  [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
06:06:20.0455 0x17fc  FltMgr - ok
06:06:20.0533 0x17fc  [ E12C4928B32ACE04610259647F072635, B71B9C2DF45F33C4DAC88435129B08B0BCDBBE82E8C3AD0A95F00137CC8B619F ] FontCache       C:\Windows\system32\FntCache.dll
06:06:20.0627 0x17fc  FontCache - ok
06:06:20.0674 0x17fc  [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
06:06:20.0689 0x17fc  FontCache3.0.0.0 - ok
06:06:20.0720 0x17fc  [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
06:06:20.0736 0x17fc  FsDepends - ok
06:06:20.0767 0x17fc  [ B0082808A6856A252F7CDD939892CE50, 3A069239629C4F54049A2CFC6642AC5102ECEAA74470BAA9DDB1AB108D1060EE ] fssfltr         C:\Windows\system32\DRIVERS\fssfltr.sys
06:06:20.0783 0x17fc  fssfltr - ok
06:06:20.0892 0x17fc  [ 28DDEEEC44E988657B732CF404D504CB, 47F83018E5449CDCED3DD447991788EBAAC92C418D4513FBA9408C45E9AB8E7E ] fsssvc          C:\Program Files\Windows Live\Family Safety\fsssvc.exe
06:06:20.0954 0x17fc  fsssvc - ok
06:06:20.0986 0x17fc  [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
06:06:21.0001 0x17fc  Fs_Rec - ok
06:06:21.0032 0x17fc  [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
06:06:21.0064 0x17fc  fvevol - ok
06:06:21.0079 0x17fc  [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
06:06:21.0095 0x17fc  gagp30kx - ok
06:06:21.0126 0x17fc  [ 185ADA973B5020655CEE342059A86CBB, D3E352DFAF30761505480A4C557D980083F65EC5BD46E2656B2114D47B272A89 ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
06:06:21.0142 0x17fc  GEARAspiWDM - ok
06:06:21.0188 0x17fc  [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc           C:\Windows\System32\gpsvc.dll
06:06:21.0298 0x17fc  gpsvc - ok
06:06:21.0516 0x17fc  [ F02A533F517EB38333CB12A9E8963773, 1F72CD1CF660766FA8F912E40B7323A0192A300B376186C10F6803DC5EFE28DF ] gupdate         C:\Program Files\Google\Update\GoogleUpdate.exe
06:06:21.0532 0x17fc  gupdate - ok
06:06:21.0563 0x17fc  [ F02A533F517EB38333CB12A9E8963773, 1F72CD1CF660766FA8F912E40B7323A0192A300B376186C10F6803DC5EFE28DF ] gupdatem        C:\Program Files\Google\Update\GoogleUpdate.exe
06:06:21.0578 0x17fc  gupdatem - ok
06:06:21.0656 0x17fc  [ C1CC0C9742B881C42F1CC628E6F9EBD1, 0F63B84B36E25BA208DFA6AD467EEAA20575519EFF1ED62F3A35010CB7CDB9D8 ] Hardlock        C:\Windows\system32\drivers\hardlock.sys
06:06:21.0734 0x17fc  Hardlock - ok
06:06:21.0766 0x17fc  [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
06:06:21.0812 0x17fc  hcw85cir - ok
06:06:21.0859 0x17fc  [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
06:06:21.0890 0x17fc  HdAudAddService - ok
06:06:21.0953 0x17fc  [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus        C:\Windows\system32\drivers\HDAudBus.sys
06:06:21.0984 0x17fc  HDAudBus - ok
06:06:22.0015 0x17fc  [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt         C:\Windows\system32\DRIVERS\HidBatt.sys
06:06:22.0031 0x17fc  HidBatt - ok
06:06:22.0046 0x17fc  [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
06:06:22.0078 0x17fc  HidBth - ok
06:06:22.0109 0x17fc  [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr           C:\Windows\system32\DRIVERS\hidir.sys
06:06:22.0156 0x17fc  HidIr - ok
06:06:22.0187 0x17fc  [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv         C:\Windows\System32\hidserv.dll
06:06:22.0234 0x17fc  hidserv - ok
06:06:22.0265 0x17fc  [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb          C:\Windows\system32\drivers\hidusb.sys
06:06:22.0327 0x17fc  HidUsb - ok
06:06:22.0405 0x17fc  [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc          C:\Windows\system32\kmsvc.dll
06:06:22.0436 0x17fc  hkmsvc - ok
06:06:22.0483 0x17fc  [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
06:06:22.0546 0x17fc  HomeGroupListener - ok
06:06:22.0577 0x17fc  [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
06:06:22.0624 0x17fc  HomeGroupProvider - ok
06:06:22.0670 0x17fc  [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
06:06:22.0686 0x17fc  HpSAMD - ok
06:06:22.0733 0x17fc  [ 871917B07A141BFF43D76D8844D48106, 30C702008D0EE57D63F74864967DD19A55A268E77E42B5B3CC73037AD51D2987 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
06:06:22.0780 0x17fc  HTTP - ok
06:06:22.0811 0x17fc  [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
06:06:22.0826 0x17fc  hwpolicy - ok
06:06:22.0858 0x17fc  [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
06:06:22.0889 0x17fc  i8042prt - ok
06:06:22.0936 0x17fc  [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
06:06:22.0967 0x17fc  iaStorV - ok
06:06:23.0045 0x17fc  [ C521D7EB6497BB1AF6AFA89E322FB43C, BDDCFCBB5B76A9295669B5AC9F732D6127199ED5C300770B554C4E4794F66BB7 ] idsvc           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
06:06:23.0092 0x17fc  idsvc - ok
06:06:23.0123 0x17fc  IEEtwCollectorService - ok
06:06:23.0138 0x17fc  [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp           C:\Windows\system32\DRIVERS\iirsp.sys
06:06:23.0154 0x17fc  iirsp - ok
06:06:23.0216 0x17fc  [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] IKEEXT          C:\Windows\System32\ikeext.dll
06:06:23.0279 0x17fc  IKEEXT - ok
06:06:23.0310 0x17fc  [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide        C:\Windows\system32\drivers\intelide.sys
06:06:23.0326 0x17fc  intelide - ok
06:06:23.0341 0x17fc  [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
06:06:23.0372 0x17fc  intelppm - ok
06:06:23.0419 0x17fc  [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
06:06:23.0466 0x17fc  IPBusEnum - ok
06:06:23.0482 0x17fc  [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
06:06:23.0528 0x17fc  IpFilterDriver - ok
06:06:23.0575 0x17fc  [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
06:06:23.0638 0x17fc  iphlpsvc - ok
06:06:23.0669 0x17fc  [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
06:06:23.0700 0x17fc  IPMIDRV - ok
06:06:23.0731 0x17fc  [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
06:06:23.0778 0x17fc  IPNAT - ok
06:06:23.0872 0x17fc  [ BC0EA61246F8D940FBC5F652D337D6BD, BF018317631937EED13136608831F526BE34AF7E59FEF4863E3EDD205C02E1A7 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
06:06:23.0918 0x17fc  iPod Service - ok
06:06:23.0934 0x17fc  [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM          C:\Windows\system32\drivers\irenum.sys
06:06:23.0981 0x17fc  IRENUM - ok
06:06:24.0012 0x17fc  [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp          C:\Windows\system32\drivers\isapnp.sys
06:06:24.0028 0x17fc  isapnp - ok
06:06:24.0043 0x17fc  [ CB7A9ABB12B8415BCE5D74994C7BA3AE, 464BFF3F5EEE985BE075E23E1813F5CB82A9A0771A92C6D889B13B867BCDF647 ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
06:06:24.0059 0x17fc  iScsiPrt - ok
06:06:24.0106 0x17fc  [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass        C:\Windows\system32\drivers\kbdclass.sys
06:06:24.0121 0x17fc  kbdclass - ok
06:06:24.0137 0x17fc  [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid          C:\Windows\system32\drivers\kbdhid.sys
06:06:24.0168 0x17fc  kbdhid - ok
06:06:24.0200 0x17fc  [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] KeyIso          C:\Windows\system32\lsass.exe
06:06:24.0216 0x17fc  KeyIso - ok
06:06:24.0247 0x17fc  [ F286830298323272260332D6ABC905C1, FF4CD182A95CA53119B228690D682EE9214BE131A0DBCB09B6189FBEBBFF902C ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
06:06:24.0247 0x17fc  KSecDD - ok
06:06:24.0263 0x17fc  [ D7C760D57B1656DD748B9E4AB6CB5A51, F8AE4185A6A9F7005DEFF1FDC03F395C6189825B482B8C650637FD29DE93AB68 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
06:06:24.0278 0x17fc  KSecPkg - ok
06:06:24.0309 0x17fc  [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm           C:\Windows\system32\msdtckrm.dll
06:06:24.0372 0x17fc  KtmRm - ok
06:06:24.0403 0x17fc  [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer    C:\Windows\System32\srvsvc.dll
06:06:24.0465 0x17fc  LanmanServer - ok
06:06:24.0497 0x17fc  [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
06:06:24.0528 0x17fc  LanmanWorkstation - ok
06:06:24.0621 0x17fc  [ 83D8BE94E1CBCBE2EA8372DB1A95A159, 28D18C7B93EFB6C83023D39A54489DDE98DE578AFCC06DD0712D00DE7CD48968 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
06:06:24.0637 0x17fc  LightScribeService - detected UnsignedFile.Multi.Generic ( 1 )
06:06:27.0679 0x17fc  Detect skipped due to KSN trusted
06:06:27.0679 0x17fc  LightScribeService - ok
06:06:27.0726 0x17fc  [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
06:06:27.0773 0x17fc  lltdio - ok
06:06:27.0960 0x17fc  [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc         C:\Windows\System32\lltdsvc.dll
06:06:28.0022 0x17fc  lltdsvc - ok
06:06:28.0038 0x17fc  [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts         C:\Windows\System32\lmhsvc.dll
06:06:28.0069 0x17fc  lmhosts - ok
06:06:28.0116 0x17fc  [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
06:06:28.0131 0x17fc  LSI_FC - ok
06:06:28.0163 0x17fc  [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS         C:\Windows\system32\DRIVERS\lsi_sas.sys
06:06:28.0178 0x17fc  LSI_SAS - ok
06:06:28.0194 0x17fc  [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
06:06:28.0209 0x17fc  LSI_SAS2 - ok
06:06:28.0225 0x17fc  [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
06:06:28.0241 0x17fc  LSI_SCSI - ok
06:06:28.0256 0x17fc  [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv           C:\Windows\system32\drivers\luafv.sys
06:06:28.0303 0x17fc  luafv - ok
06:06:28.0365 0x17fc  [ 4470E3C1E0C3378E4CAB137893C12C3A, CA8E66356F0E671D5454E561E7EAD74DE25DCF53BE452369F96ECACFA8709489 ] MBAMProtector   C:\Windows\system32\drivers\mbam.sys
06:06:28.0381 0x17fc  MBAMProtector - ok
06:06:28.0443 0x17fc  [ 65085456FD9A74D7F1A999520C299ECB, EA564BC913EF1B8A4CAA9242FC70F525B68CF1F3CA462F63B0B7215B93FE8530 ] MBAMScheduler   C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
06:06:28.0475 0x17fc  MBAMScheduler - ok
06:06:28.0553 0x17fc  [ E0D7732F2D2E24B2DB3F67B6750295B8, AA5CA86AF1ACEC900F60339016B3DC55472DB40ADB99186005A7ABE67B7D66FC ] MBAMService     C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
06:06:28.0584 0x17fc  MBAMService - ok
06:06:28.0615 0x17fc  [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
06:06:28.0631 0x17fc  Mcx2Svc - ok
06:06:28.0646 0x17fc  [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas         C:\Windows\system32\DRIVERS\megasas.sys
06:06:28.0662 0x17fc  megasas - ok
06:06:28.0693 0x17fc  [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
06:06:28.0709 0x17fc  MegaSR - ok
06:06:28.0740 0x17fc  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS           C:\Windows\system32\mmcss.dll
06:06:28.0787 0x17fc  MMCSS - ok
06:06:28.0818 0x17fc  [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem           C:\Windows\system32\drivers\modem.sys
06:06:28.0849 0x17fc  Modem - ok
06:06:28.0880 0x17fc  [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
06:06:28.0896 0x17fc  monitor - ok
06:06:28.0911 0x17fc  [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
06:06:28.0927 0x17fc  mouclass - ok
06:06:28.0958 0x17fc  [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
06:06:28.0974 0x17fc  mouhid - ok
06:06:29.0005 0x17fc  [ FC8771F45ECCCFD89684E38842539B9B, 806DDF2B4830CA866582FE74A521BB7DF26CA0E19013DAF584D3677FB48CC77A ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
06:06:29.0021 0x17fc  mountmgr - ok
06:06:29.0067 0x17fc  [ 338037EFA0E8E8699B2667D57B751574, 59E0D39806D0C4EB57913AA013242837FD39AD378726AEE42D250CBA87C1C3BF ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
06:06:29.0083 0x17fc  MozillaMaintenance - ok
06:06:29.0145 0x17fc  [ E77DC03DD3C8E5A388BF9EED2A28F3D1, ED0DAA975D1EC35CE036F02596218E15CC6A054167628D12A0A5AD91B841F422 ] MpFilter        C:\Windows\system32\DRIVERS\MpFilter.sys
06:06:29.0177 0x17fc  MpFilter - ok
06:06:29.0192 0x17fc  [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 ] mpio            C:\Windows\system32\drivers\mpio.sys
06:06:29.0208 0x17fc  mpio - ok
06:06:29.0317 0x17fc  [ 65C34426C83EFA32D48380A97717997B, CD7EB6BFBB0BE382BA21055460D9A72323F09AF3194A22D8EDB28D5DB3BAE8E7 ] MpKsldff1a976   C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{75783977-8EB0-4949-91CF-29E83014DA71}\MpKsldff1a976.sys
06:06:29.0333 0x17fc  MpKsldff1a976 - ok
06:06:29.0364 0x17fc  [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
06:06:29.0411 0x17fc  mpsdrv - ok
06:06:29.0457 0x17fc  [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc          C:\Windows\system32\mpssvc.dll
06:06:29.0520 0x17fc  MpsSvc - ok
06:06:29.0551 0x17fc  [ 21F4B24ACFC79A483515BD986DD9043F, 22681907E02E0B723ABE2CEF0602D36C8EF862E7E2B62A9B40A5EF582E58D7BA ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
06:06:29.0598 0x17fc  MRxDAV - ok
06:06:29.0645 0x17fc  [ 5D16C921E3671636C0EBA3BBAAC5FD25, 5BC107B95CAFC88F51FBB9F657B99944B20627A2B618F263093D7045E4FFD65C ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
06:06:29.0691 0x17fc  mrxsmb - ok
06:06:29.0738 0x17fc  [ 6D17A4791ACA19328C685D256349FEFC, 012AA3D84EEAAF53780D06D2D11B9727DFC3441F3FAD75BC9E751FB814403668 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
06:06:29.0769 0x17fc  mrxsmb10 - ok
06:06:29.0801 0x17fc  [ B81F204D146000BE76651A50670A5E9E, 78193D0F967BE9829E53F9B500342934B4B1E1F4CEFC444382959E2061BC3B17 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
06:06:29.0832 0x17fc  mrxsmb20 - ok
06:06:29.0863 0x17fc  [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci          C:\Windows\system32\drivers\msahci.sys
06:06:29.0879 0x17fc  msahci - ok
06:06:29.0894 0x17fc  [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
06:06:29.0910 0x17fc  msdsm - ok
06:06:29.0941 0x17fc  [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC           C:\Windows\System32\msdtc.exe
06:06:29.0988 0x17fc  MSDTC - ok
06:06:30.0081 0x17fc  [ 114B67C324D64C8195FD3BF93B4DF02A, EF9349BD28578D3BE57946125AA909DFF902D8CB0BFCD9902F690C70F78E3EEB ] MSDV            C:\Windows\system32\DRIVERS\msdv.sys
06:06:30.0097 0x17fc  MSDV - ok
06:06:30.0144 0x17fc  [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs            C:\Windows\system32\drivers\Msfs.sys
06:06:30.0159 0x17fc  Msfs - ok
06:06:30.0175 0x17fc  [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
06:06:30.0222 0x17fc  mshidkmdf - ok
06:06:30.0237 0x17fc  [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
06:06:30.0253 0x17fc  msisadrv - ok
06:06:30.0284 0x17fc  [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
06:06:30.0331 0x17fc  MSiSCSI - ok
06:06:30.0331 0x17fc  msiserver - ok
06:06:30.0378 0x17fc  [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
06:06:30.0393 0x17fc  MSKSSRV - ok
06:06:30.0503 0x17fc  [ B0F49DA36F30922F5DDC3B623B778FCE, EE025AEFA4A2095AFEABFB3A49639DA77D78068A3F5EEDA6C15D34853AFD5609 ] MsMpSvc         c:\Program Files\Microsoft Security Client\MsMpEng.exe
06:06:30.0518 0x17fc  MsMpSvc - ok
06:06:30.0518 0x17fc  [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
06:06:30.0565 0x17fc  MSPCLOCK - ok
06:06:30.0596 0x17fc  [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
06:06:30.0643 0x17fc  MSPQM - ok
06:06:30.0674 0x17fc  [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
06:06:30.0690 0x17fc  MsRPC - ok
06:06:30.0721 0x17fc  [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
06:06:30.0737 0x17fc  mssmbios - ok
06:06:30.0752 0x17fc  [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
06:06:30.0768 0x17fc  MSTEE - ok
06:06:30.0783 0x17fc  [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
06:06:30.0815 0x17fc  MTConfig - ok
06:06:30.0846 0x17fc  [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup             C:\Windows\system32\Drivers\mup.sys
06:06:30.0846 0x17fc  Mup - ok
06:06:30.0893 0x17fc  [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent        C:\Windows\system32\qagentRT.dll
06:06:30.0924 0x17fc  napagent - ok
06:06:30.0971 0x17fc  [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
06:06:31.0017 0x17fc  NativeWifiP - ok
06:06:31.0111 0x17fc  [ E4534BCCDD1EA7A7A256BB9D6688A5FC, 68AFEDC17BF449DF7FC9CC9D7F020C1D82ABE91C40C7E6419DF87FAFDA700A0E ] NAUpdate        C:\Program Files\Nero\Update\NASvc.exe
06:06:31.0127 0x17fc  NAUpdate - ok
06:06:31.0189 0x17fc  [ 8C9C922D71F1CD4DEF73F186416B7896, 15FF43CD90C7913F83B35F2E7986561584588E8A45196EBD965C3A355836A9C7 ] NDIS            C:\Windows\system32\drivers\ndis.sys
06:06:31.0220 0x17fc  NDIS - ok
06:06:31.0251 0x17fc  [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
06:06:31.0298 0x17fc  NdisCap - ok
06:06:31.0314 0x17fc  [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
06:06:31.0361 0x17fc  NdisTapi - ok
06:06:31.0407 0x17fc  [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
06:06:31.0439 0x17fc  Ndisuio - ok
06:06:31.0470 0x17fc  [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
06:06:31.0501 0x17fc  NdisWan - ok
06:06:31.0548 0x17fc  [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
06:06:31.0595 0x17fc  NDProxy - ok
06:06:31.0641 0x17fc  [ 1352E1648213551923A0A822E441553C, F9BCA299249D8E1ADF88F54554F72428E267E39911143F4C99DFF562F0EE4E70 ] Netaapl         C:\Windows\system32\DRIVERS\netaapl.sys
06:06:31.0688 0x17fc  Netaapl - ok
06:06:31.0735 0x17fc  [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
06:06:31.0813 0x17fc  NetBIOS - ok
06:06:31.0860 0x17fc  [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
06:06:31.0891 0x17fc  NetBT - ok
06:06:31.0907 0x17fc  [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] Netlogon        C:\Windows\system32\lsass.exe
06:06:31.0922 0x17fc  Netlogon - ok
06:06:31.0953 0x17fc  [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman          C:\Windows\System32\netman.dll
06:06:32.0000 0x17fc  Netman - ok
06:06:32.0063 0x17fc  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
06:06:32.0078 0x17fc  NetMsmqActivator - ok
06:06:32.0094 0x17fc  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
06:06:32.0109 0x17fc  NetPipeActivator - ok
06:06:32.0141 0x17fc  [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm        C:\Windows\System32\netprofm.dll
06:06:32.0203 0x17fc  netprofm - ok
06:06:32.0281 0x17fc  [ 27EE4B406E2F26F6117A9A420BD4CB65, D4EB07F56A1D1F0DA2197AB80917036A057A543F837CE5B102EE4F4ACA4606A7 ] netr28u         C:\Windows\system32\DRIVERS\netr28u.sys
06:06:32.0343 0x17fc  netr28u - ok
06:06:32.0359 0x17fc  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
06:06:32.0375 0x17fc  NetTcpActivator - ok
06:06:32.0390 0x17fc  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
06:06:32.0406 0x17fc  NetTcpPortSharing - ok
06:06:32.0437 0x17fc  [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960         C:\Windows\system32\DRIVERS\nfrd960.sys
06:06:32.0437 0x17fc  nfrd960 - ok
06:06:32.0484 0x17fc  [ 32FF06EC6D946EF791D98D6C838A3090, 319BDD491CB22D0CCCCE76A2854CF469D7AF046289F9C56CD03AE3D3CBC0275E ] NisDrv          C:\Windows\system32\DRIVERS\NisDrvWFP.sys
06:06:32.0499 0x17fc  NisDrv - ok
06:06:32.0515 0x17fc  [ 42D33042371BFB1A7D40834590CAFD30, 53DA3618EC10293B2DF686E291A4EF6ACBBD41D116EC762D54106D201A784E87 ] NisSrv          c:\Program Files\Microsoft Security Client\NisSrv.exe
06:06:32.0546 0x17fc  NisSrv - ok
06:06:32.0593 0x17fc  [ 374071043F9E4231EE43BE2BB48DD36D, C4FA3FC40CC49DBBB91901D14210A55D3831FAC9F9B3FF45FCA7F5CF242C9E92 ] NlaSvc          C:\Windows\System32\nlasvc.dll
06:06:32.0624 0x17fc  NlaSvc - ok
06:06:32.0624 0x17fc  [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
06:06:32.0671 0x17fc  Npfs - ok
06:06:32.0702 0x17fc  [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi             C:\Windows\system32\nsisvc.dll
06:06:32.0749 0x17fc  nsi - ok
06:06:32.0780 0x17fc  [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
06:06:32.0796 0x17fc  nsiproxy - ok
06:06:32.0874 0x17fc  [ 5E43D2B0EE64123D4880DFA6626DEFDE, 164413A22DE58B19EA2B4120034B46D6BE1F424B80C3421E10BE5C81153D049F ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
06:06:32.0936 0x17fc  Ntfs - ok
06:06:32.0952 0x17fc  [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null            C:\Windows\system32\drivers\Null.sys
06:06:32.0999 0x17fc  Null - ok
06:06:33.0014 0x17fc  [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid          C:\Windows\system32\drivers\nvraid.sys
06:06:33.0030 0x17fc  nvraid - ok
06:06:33.0061 0x17fc  [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
06:06:33.0077 0x17fc  nvstor - ok
06:06:33.0123 0x17fc  [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
06:06:33.0139 0x17fc  nv_agp - ok
06:06:33.0155 0x17fc  [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
06:06:33.0186 0x17fc  ohci1394 - ok
06:06:33.0217 0x17fc  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
06:06:33.0248 0x17fc  p2pimsvc - ok
06:06:33.0264 0x17fc  [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc          C:\Windows\system32\p2psvc.dll
06:06:33.0311 0x17fc  p2psvc - ok
06:06:33.0342 0x17fc  [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport         C:\Windows\system32\DRIVERS\parport.sys
06:06:33.0373 0x17fc  Parport - ok
06:06:33.0420 0x17fc  [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr         C:\Windows\system32\drivers\partmgr.sys
06:06:33.0435 0x17fc  partmgr - ok
06:06:33.0435 0x17fc  [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm          C:\Windows\system32\DRIVERS\parvdm.sys
06:06:33.0451 0x17fc  Parvdm - ok
06:06:33.0467 0x17fc  [ 358AB7956D3160000726574083DFC8A6, 6CAFD4D1B8AB8C1D167ADC018985DDAB5AC2CBFFB3434FE6390F14AF50C19025 ] PcaSvc          C:\Windows\System32\pcasvc.dll
06:06:33.0482 0x17fc  PcaSvc - ok
06:06:33.0498 0x17fc  [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci             C:\Windows\system32\drivers\pci.sys
06:06:33.0513 0x17fc  pci - ok
06:06:33.0560 0x17fc  [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide          C:\Windows\system32\drivers\pciide.sys
06:06:33.0560 0x17fc  pciide - ok
06:06:33.0591 0x17fc  [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
06:06:33.0607 0x17fc  pcmcia - ok
06:06:33.0654 0x17fc  [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw             C:\Windows\system32\drivers\pcw.sys
06:06:33.0654 0x17fc  pcw - ok
06:06:33.0701 0x17fc  [ 9E0104BA49F4E6973749A02BF41344ED, B32F39F38DB48D77FBA884DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
06:06:33.0763 0x17fc  PEAUTH - ok
06:06:33.0825 0x17fc  [ AF4D64D2A57B9772CF3801950B8058A6, C9C493A3775E6E1660CE5DF75DA574D0C04245FB88CF41B96217A725359C350D ] PeerDistSvc     C:\Windows\system32\peerdistsvc.dll
06:06:33.0888 0x17fc  PeerDistSvc - ok
06:06:33.0966 0x17fc  [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla             C:\Windows\system32\pla.dll
06:06:34.0059 0x17fc  pla - ok
06:06:34.0106 0x17fc  [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
06:06:34.0153 0x17fc  PlugPlay - ok
06:06:34.0169 0x17fc  [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
06:06:34.0200 0x17fc  PNRPAutoReg - ok
06:06:34.0231 0x17fc  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
06:06:34.0247 0x17fc  PNRPsvc - ok
06:06:34.0278 0x17fc  [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
06:06:34.0340 0x17fc  PolicyAgent - ok
06:06:34.0371 0x17fc  [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power           C:\Windows\system32\umpo.dll
06:06:34.0418 0x17fc  Power - ok
06:06:34.0465 0x17fc  [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
06:06:34.0512 0x17fc  PptpMiniport - ok
06:06:34.0527 0x17fc  [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor       C:\Windows\system32\DRIVERS\processr.sys
06:06:34.0543 0x17fc  Processor - ok
06:06:34.0574 0x17fc  [ CADEFAC453040E370A1BDFF3973BE00D, 2E3DD8DA702468D8AB0F3CE27188B1991D4CB015FB36BAE4C6E7996B61CF49B8 ] ProfSvc         C:\Windows\system32\profsvc.dll
06:06:34.0637 0x17fc  ProfSvc - ok
06:06:34.0652 0x17fc  [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] ProtectedStorage C:\Windows\system32\lsass.exe
06:06:34.0652 0x17fc  ProtectedStorage - ok
06:06:34.0683 0x17fc  [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
06:06:34.0730 0x17fc  Psched - ok
06:06:34.0793 0x17fc  [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
06:06:34.0855 0x17fc  ql2300 - ok
06:06:34.0871 0x17fc  [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
06:06:34.0886 0x17fc  ql40xx - ok
06:06:34.0902 0x17fc  [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE           C:\Windows\system32\qwave.dll
06:06:34.0949 0x17fc  QWAVE - ok
06:06:34.0964 0x17fc  [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
06:06:34.0995 0x17fc  QWAVEdrv - ok
06:06:35.0089 0x17fc  [ 432F5B15E21A54B48072593F03570326, BF58D0423DDAA05A70A56F0E2ED6388C5C5E48641ABCE47E99930D5CFE942291 ] RalinkRegistryWriter C:\Program Files\NetComm\Common\RegistryWriter.exe
06:06:35.0120 0x17fc  RalinkRegistryWriter - detected UnsignedFile.Multi.Generic ( 1 )
06:06:38.0147 0x17fc  Detect skipped due to KSN trusted
06:06:38.0147 0x17fc  RalinkRegistryWriter - ok
06:06:38.0162 0x17fc  [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
06:06:38.0178 0x17fc  RasAcd - ok
06:06:38.0209 0x17fc  [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
06:06:38.0256 0x17fc  RasAgileVpn - ok
06:06:38.0303 0x17fc  [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto         C:\Windows\System32\rasauto.dll
06:06:38.0334 0x17fc  RasAuto - ok
06:06:38.0350 0x17fc  [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
06:06:38.0396 0x17fc  Rasl2tp - ok
06:06:38.0443 0x17fc  [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan          C:\Windows\System32\rasmans.dll
06:06:38.0474 0x17fc  RasMan - ok
06:06:38.0506 0x17fc  [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
06:06:38.0521 0x17fc  RasPppoe - ok
06:06:38.0568 0x17fc  [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
06:06:38.0615 0x17fc  RasSstp - ok
06:06:38.0646 0x17fc  [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
06:06:38.0708 0x17fc  rdbss - ok
06:06:38.0724 0x17fc  [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
06:06:38.0740 0x17fc  rdpbus - ok
06:06:38.0786 0x17fc  [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
06:06:38.0818 0x17fc  RDPCDD - ok
06:06:38.0864 0x17fc  [ B973FCFC50DC1434E1970A146F7E3885, BE797E5F5AE34D37F8DA1134CE94DD14DBE36D2BC405B97E992E2257848B7CA9 ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
06:06:38.0880 0x17fc  RDPDR - ok
06:06:38.0896 0x17fc  [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
06:06:38.0942 0x17fc  RDPENCDD - ok
06:06:38.0989 0x17fc  [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
06:06:39.0005 0x17fc  RDPREFMP - ok
06:06:39.0067 0x17fc  [ 65375DF758CA1872AB7EBBBA457FD5E6, 8AC7681F51277E799C22FF95FA0B833E9E260D37C0416319FF05B66FB3948005 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
06:06:39.0114 0x17fc  RdpVideoMiniport - ok
06:06:39.0145 0x17fc  [ F031683E6D1FEA157ABB2FF260B51E61, 83B552819A5964152882C527E1421DBCEAACC74DEB897E3C4B53F52F1467FED3 ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
06:06:39.0192 0x17fc  RDPWD - ok
06:06:39.0239 0x17fc  [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
06:06:39.0254 0x17fc  rdyboost - ok
06:06:39.0286 0x17fc  [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess    C:\Windows\System32\mprdim.dll
06:06:39.0317 0x17fc  RemoteAccess - ok
06:06:39.0332 0x17fc  [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry  C:\Windows\system32\regsvc.dll
06:06:39.0379 0x17fc  RemoteRegistry - ok
06:06:39.0410 0x17fc  [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
06:06:39.0442 0x17fc  RpcEptMapper - ok
06:06:39.0473 0x17fc  [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator      C:\Windows\system32\locator.exe
06:06:39.0488 0x17fc  RpcLocator - ok
06:06:39.0535 0x17fc  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs           C:\Windows\System32\rpcss.dll
06:06:39.0566 0x17fc  RpcSs - ok
06:06:39.0613 0x17fc  [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
06:06:39.0629 0x17fc  rspndr - ok
06:06:39.0676 0x17fc  [ 3983CEA05BB855351D75F5482B6C42CE, E995E712B7929DA88618DCF8C64616CF25380694A13BEA53F4F3D8CA3E73E120 ] RTL8167         C:\Windows\system32\DRIVERS\Rt86win7.sys
06:06:39.0722 0x17fc  RTL8167 - ok
06:06:39.0754 0x17fc  [ 7FA7F2E249A5DCBB7970630E15E1F482, 9633B193F3FDA67BC551C6DCA4788AB83E9F45F77763EE579D02FE5D6B80DEDF ] s3cap           C:\Windows\system32\drivers\vms3cap.sys
06:06:39.0800 0x17fc  s3cap - ok
06:06:39.0816 0x17fc  [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] SamSs           C:\Windows\system32\lsass.exe
06:06:39.0816 0x17fc  SamSs - ok
06:06:39.0847 0x17fc  [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
06:06:39.0847 0x17fc  sbp2port - ok
06:06:39.0878 0x17fc  [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
06:06:39.0910 0x17fc  SCardSvr - ok
06:06:39.0910 0x17fc  [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
06:06:39.0941 0x17fc  scfilter - ok
06:06:40.0003 0x17fc  [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule        C:\Windows\system32\schedsvc.dll
06:06:40.0081 0x17fc  Schedule - ok
06:06:40.0112 0x17fc  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc     C:\Windows\System32\certprop.dll
06:06:40.0144 0x17fc  SCPolicySvc - ok
06:06:40.0175 0x17fc  [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
06:06:40.0222 0x17fc  SDRSVC - ok
06:06:40.0253 0x17fc  [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
06:06:40.0284 0x17fc  secdrv - ok
06:06:40.0300 0x17fc  [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon        C:\Windows\system32\seclogon.dll
06:06:40.0346 0x17fc  seclogon - ok
06:06:40.0362 0x17fc  [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS            C:\Windows\system32\sens.dll
06:06:40.0409 0x17fc  SENS - ok
06:06:40.0424 0x17fc  [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
06:06:40.0549 0x17fc  SensrSvc - ok
06:06:40.0580 0x17fc  [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
06:06:40.0596 0x17fc  Serenum - ok
06:06:40.0612 0x17fc  [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial          C:\Windows\system32\DRIVERS\serial.sys
06:06:40.0643 0x17fc  Serial - ok
06:06:40.0705 0x17fc  [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
06:06:40.0721 0x17fc  sermouse - ok
06:06:40.0799 0x17fc  [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv      C:\Windows\system32\sessenv.dll
06:06:40.0830 0x17fc  SessionEnv - ok
06:06:40.0861 0x17fc  [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
06:06:40.0877 0x17fc  sffdisk - ok
06:06:40.0892 0x17fc  [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
06:06:40.0908 0x17fc  sffp_mmc - ok
06:06:40.0924 0x17fc  [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
06:06:40.0939 0x17fc  sffp_sd - ok
06:06:40.0970 0x17fc  [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy         C:\Windows\system32\DRIVERS\sfloppy.sys
06:06:41.0002 0x17fc  sfloppy - ok
06:06:41.0048 0x17fc  [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess    C:\Windows\System32\ipnathlp.dll
06:06:41.0111 0x17fc  SharedAccess - ok
06:06:41.0142 0x17fc  [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
06:06:41.0204 0x17fc  ShellHWDetection - ok
06:06:41.0220 0x17fc  [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp          C:\Windows\system32\drivers\sisagp.sys
06:06:41.0236 0x17fc  sisagp - ok
06:06:41.0267 0x17fc  [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
06:06:41.0282 0x17fc  SiSRaid2 - ok
06:06:41.0298 0x17fc  [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
06:06:41.0314 0x17fc  SiSRaid4 - ok
06:06:41.0329 0x17fc  [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
06:06:41.0360 0x17fc  Smb - ok
06:06:41.0392 0x17fc  [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
06:06:41.0407 0x17fc  SNMPTRAP - ok
06:06:41.0423 0x17fc  [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr           C:\Windows\system32\drivers\spldr.sys
06:06:41.0423 0x17fc  spldr - ok
06:06:41.0470 0x17fc  [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler         C:\Windows\System32\spoolsv.exe
06:06:41.0532 0x17fc  Spooler - ok
06:06:41.0641 0x17fc  [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc          C:\Windows\system32\sppsvc.exe
06:06:41.0797 0x17fc  sppsvc - ok
06:06:41.0844 0x17fc  [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify     C:\Windows\system32\sppuinotify.dll
06:06:41.0891 0x17fc  sppuinotify - ok
06:06:41.0938 0x17fc  [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv             C:\Windows\system32\DRIVERS\srv.sys
06:06:41.0969 0x17fc  srv - ok
06:06:42.0016 0x17fc  [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
06:06:42.0062 0x17fc  srv2 - ok
06:06:42.0078 0x17fc  [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
06:06:42.0094 0x17fc  srvnet - ok
06:06:42.0156 0x17fc  [ 64E44ACD8C238FCBBB78F0BA4BDC4B05, 59D015DD86EA35AC8F667C063AE76FAFA9497F04225D256DF5A37EB1461F15D4 ] ssadbus         C:\Windows\system32\DRIVERS\ssadbus.sys
06:06:42.0203 0x17fc  ssadbus - ok
06:06:42.0218 0x17fc  [ BB2C84A15C765DA89FD832B0E73F26CE, BAE3E7726F075340B8CC7BCA18869DFEA304A03B0A0429B4C3D186B1149E9A9A ] ssadmdfl        C:\Windows\system32\DRIVERS\ssadmdfl.sys
06:06:42.0265 0x17fc  ssadmdfl - ok
06:06:42.0281 0x17fc  [ 6D0D132DDC6F43EDA00DCED6D8B1CA31, 0A37081D95A56861C3E48592048DFCFAE6FB38510D21AB41C9C73744743E7646 ] ssadmdm         C:\Windows\system32\DRIVERS\ssadmdm.sys
06:06:42.0312 0x17fc  ssadmdm - ok
06:06:42.0343 0x17fc  [ 1A5A397BC459F346AB56492B61EF79F6, 9CB7BE4E4A7B145D97BA0C72EE7ECB844DA6EB0282FBC3BE92A1CC5AD80FA6C4 ] ssadserd        C:\Windows\system32\DRIVERS\ssadserd.sys
06:06:42.0390 0x17fc  ssadserd - ok
06:06:42.0437 0x17fc  [ 069351A1D7D291013177A90AE6EDCCBC, 9AAC7DAEAD7ABF593FB3F7B959BB1F9310C46DBF86395FF4117DDCE4B74E849B ] sscdbus         C:\Windows\system32\DRIVERS\sscdbus.sys
06:06:42.0452 0x17fc  sscdbus - ok
06:06:42.0468 0x17fc  [ 1C925BE223A5C0F9F469252292A48DF6, 0A3F59040B0B856D7888F4AA2EC229F506B82C4DB62470E1D1B76B34EB49AF3F ] sscdmdfl        C:\Windows\system32\DRIVERS\sscdmdfl.sys
06:06:42.0484 0x17fc  sscdmdfl - ok
06:06:42.0499 0x17fc  [ AE3E77AE0FBDB07EB1AC3FED74A0695E, E491A8610AA82D612314C336FDED109D66F7306291798218CBB154D389375096 ] sscdmdm         C:\Windows\system32\DRIVERS\sscdmdm.sys
06:06:42.0515 0x17fc  sscdmdm - ok
06:06:42.0546 0x17fc  [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
06:06:42.0593 0x17fc  SSDPSRV - ok
06:06:42.0624 0x17fc  [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc         C:\Windows\system32\sstpsvc.dll
06:06:42.0640 0x17fc  SstpSvc - ok
06:06:42.0686 0x17fc  [ D2C02234E3E87EA5FE420F045068099B, A5BFB342FFF50E6EAF5586A72BCBE56E9DA4F7AE612EDE7D20D77DB59472D3FE ] ssudmdm         C:\Windows\system32\DRIVERS\ssudmdm.sys
06:06:42.0702 0x17fc  ssudmdm - ok
06:06:42.0733 0x17fc  [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
06:06:42.0733 0x17fc  stexstor - ok
06:06:42.0780 0x17fc  [ EDB05BD63148796F23EA78506404A538, 8EBF623D3DEB6CCAC75AAFCF8B23271029A28BE29D459088E40FBF109E80AA17 ] StillCam        C:\Windows\system32\DRIVERS\serscan.sys
06:06:42.0827 0x17fc  StillCam - ok
06:06:42.0874 0x17fc  [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc          C:\Windows\System32\wiaservc.dll
06:06:42.0920 0x17fc  StiSvc - ok
06:06:42.0952 0x17fc  [ 472AF0311073DCECEAA8FA18BA2BDF89, 089414057EB2047E42C96C1ACE79D509967461DC5A4D2836F63C04268637A3FC ] storflt         C:\Windows\system32\drivers\vmstorfl.sys
06:06:42.0952 0x17fc  storflt - ok
06:06:42.0998 0x17fc  [ DCAFFD62259E0BDB433DD67B5BB37619, CBD12FF9BBF33D18B0F3D322B12EC62E7DF3BF45C6AD43D2E91FF4C4762E05D0 ] storvsc         C:\Windows\system32\drivers\storvsc.sys
06:06:42.0998 0x17fc  storvsc - ok
06:06:43.0030 0x17fc  [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum          C:\Windows\system32\drivers\swenum.sys
06:06:43.0045 0x17fc  swenum - ok
06:06:43.0076 0x17fc  [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv           C:\Windows\System32\swprv.dll
06:06:43.0123 0x17fc  swprv - ok
06:06:43.0154 0x17fc  Synth3dVsc - ok
06:06:43.0217 0x17fc  [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain         C:\Windows\system32\sysmain.dll
06:06:43.0279 0x17fc  SysMain - ok
06:06:43.0310 0x17fc  [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
06:06:43.0326 0x17fc  TabletInputService - ok
06:06:43.0373 0x17fc  [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv         C:\Windows\System32\tapisrv.dll
06:06:43.0420 0x17fc  TapiSrv - ok
06:06:43.0451 0x17fc  [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS             C:\Windows\System32\tbssvc.dll
06:06:43.0498 0x17fc  TBS - ok
06:06:43.0576 0x17fc  [ CA59F7C570AF70BC174F477CFE2D9EE3, F09E4E14207A2AC6957D2C0AC8707D0E356A9087FA6DC703373242D8EEB026BD ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
06:06:43.0638 0x17fc  Tcpip - ok
06:06:43.0700 0x17fc  [ CA59F7C570AF70BC174F477CFE2D9EE3, F09E4E14207A2AC6957D2C0AC8707D0E356A9087FA6DC703373242D8EEB026BD ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
06:06:43.0747 0x17fc  TCPIP6 - ok
06:06:43.0810 0x17fc  [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
06:06:43.0825 0x17fc  tcpipreg - ok
06:06:43.0872 0x17fc  [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
06:06:43.0934 0x17fc  TDPIPE - ok
06:06:43.0950 0x17fc  [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
06:06:43.0981 0x17fc  TDTCP - ok
06:06:44.0012 0x17fc  [ B459575348C20E8121D6039DA063C704, 1B4328A9EA39FF5A57F258E02254D04B73455F1DF7C997C13702A8B2F12D0347 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
06:06:44.0044 0x17fc  tdx - ok
06:06:44.0075 0x17fc  [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD          C:\Windows\system32\drivers\termdd.sys
06:06:44.0090 0x17fc  TermDD - ok
06:06:44.0137 0x17fc  [ 382C804C92811BE57829D8E550A900E2, 5F52C2E7902024CF1C9CC0069F411C3F19CCA3DB209F437FA0F3932D4898EB50 ] TermService     C:\Windows\System32\termsrv.dll
06:06:44.0200 0x17fc  TermService - ok
06:06:44.0231 0x17fc  [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes          C:\Windows\system32\themeservice.dll
06:06:44.0262 0x17fc  Themes - ok
06:06:44.0293 0x17fc  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER     C:\Windows\system32\mmcss.dll
06:06:44.0309 0x17fc  THREADORDER - ok
06:06:44.0340 0x17fc  [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks          C:\Windows\System32\trkwks.dll
06:06:44.0387 0x17fc  TrkWks - ok
06:06:44.0449 0x17fc  [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
06:06:44.0480 0x17fc  TrustedInstaller - ok
06:06:44.0512 0x17fc  [ B37B08F2E5EEB1A37E448E09BACE1101, 32CC9E06B88BAB6FAB4696B744548DFCE9199A7FD2BA8B019F269CA75895852C ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
06:06:44.0543 0x17fc  tssecsrv - ok
06:06:44.0590 0x17fc  [ C6A5FBD4977305E1FA23E02C042DB463, A6EB5E4B8051A258D40A385609E930318EAA3494C8466F48542B806FE6A7C47A ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
06:06:44.0621 0x17fc  TsUsbFlt - ok
06:06:44.0636 0x17fc  tsusbhub - ok
06:06:44.0668 0x17fc  [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
06:06:44.0714 0x17fc  tunnel - ok
06:06:44.0746 0x17fc  [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
06:06:44.0761 0x17fc  uagp35 - ok
06:06:44.0792 0x17fc  [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
06:06:44.0839 0x17fc  udfs - ok
06:06:44.0870 0x17fc  [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect       C:\Windows\system32\UI0Detect.exe
06:06:44.0902 0x17fc  UI0Detect - ok
06:06:44.0948 0x17fc  [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
06:06:44.0948 0x17fc  uliagpkx - ok
06:06:44.0980 0x17fc  [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
06:06:44.0995 0x17fc  umbus - ok
06:06:45.0042 0x17fc  [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
06:06:45.0073 0x17fc  UmPass - ok
06:06:45.0120 0x17fc  [ 409994A8EACEEE4E328749C0353527A0, FFC57B647147DE2957A7DE4B330CC534DE7AC892A2FCE3BB164F7A516CAB1B56 ] UmRdpService    C:\Windows\System32\umrdp.dll
06:06:45.0151 0x17fc  UmRdpService - ok
06:06:45.0198 0x17fc  [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost        C:\Windows\System32\upnphost.dll
06:06:45.0229 0x17fc  upnphost - ok
06:06:45.0276 0x17fc  [ 73B41F4EAD65F355962168D766AF0F2E, AA33CAE55D4766C9F1E9F1B50EEAE1CA4BE968380C89892A46D2D25EAEEDC64D ] USBAAPL         C:\Windows\system32\Drivers\usbaapl.sys
06:06:45.0323 0x17fc  USBAAPL - ok
06:06:45.0354 0x17fc  [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
06:06:45.0401 0x17fc  usbccgp - ok
06:06:45.0432 0x17fc  [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir          C:\Windows\system32\drivers\usbcir.sys
06:06:45.0510 0x17fc  usbcir - ok
06:06:45.0588 0x17fc  [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
06:06:45.0682 0x17fc  usbehci - ok
06:06:45.0744 0x17fc  [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
06:06:45.0791 0x17fc  usbhub - ok
06:06:45.0822 0x17fc  [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci         C:\Windows\system32\DRIVERS\usbohci.sys
06:06:45.0838 0x17fc  usbohci - ok
06:06:45.0869 0x17fc  [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
06:06:45.0900 0x17fc  usbprint - ok
06:06:45.0947 0x17fc  [ FC6B21DB4B5B398AB93DBE59CBF11036, A94094C208F376405C07822A6143001EF1B12AE93205CD8002E87F6EB45F6374 ] usbscan         C:\Windows\system32\drivers\usbscan.sys
06:06:45.0962 0x17fc  usbscan - ok
06:06:45.0994 0x17fc  [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
06:06:46.0072 0x17fc  USBSTOR - ok
06:06:46.0087 0x17fc  [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
06:06:46.0118 0x17fc  usbuhci - ok
06:06:46.0150 0x17fc  [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms           C:\Windows\System32\uxsms.dll
06:06:46.0181 0x17fc  UxSms - ok
06:06:46.0243 0x17fc  [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] VaultSvc        C:\Windows\system32\lsass.exe
06:06:46.0243 0x17fc  VaultSvc - ok
06:06:46.0274 0x17fc  [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
06:06:46.0274 0x17fc  vdrvroot - ok
06:06:46.0321 0x17fc  [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds             C:\Windows\System32\vds.exe
06:06:46.0384 0x17fc  vds - ok
06:06:46.0415 0x17fc  [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
06:06:46.0446 0x17fc  vga - ok
06:06:46.0462 0x17fc  [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave         C:\Windows\System32\drivers\vga.sys
06:06:46.0508 0x17fc  VgaSave - ok
06:06:46.0540 0x17fc  VGPU - ok
06:06:46.0571 0x17fc  [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
06:06:46.0586 0x17fc  vhdmp - ok
06:06:46.0602 0x17fc  [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp          C:\Windows\system32\drivers\viaagp.sys
06:06:46.0618 0x17fc  viaagp - ok
06:06:46.0633 0x17fc  [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7           C:\Windows\system32\DRIVERS\viac7.sys
06:06:46.0649 0x17fc  ViaC7 - ok
06:06:46.0696 0x17fc  [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide          C:\Windows\system32\drivers\viaide.sys
06:06:46.0696 0x17fc  viaide - ok
06:06:46.0742 0x17fc  [ C2F2911156FDC7817C52829C86DA494E, FE499F189B5016FCE0018AA3DE3970B72275B7B15F3D4D608117F6DDEC6B90DC ] vmbus           C:\Windows\system32\drivers\vmbus.sys
06:06:46.0758 0x17fc  vmbus - ok
06:06:46.0774 0x17fc  [ D4D77455211E204F370D08F4963063CE, 2018B2A84C73E0834200A594C02A9D28C74906F126DAD3CCDDFC9CD9A61669E2 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
06:06:46.0789 0x17fc  VMBusHID - ok
06:06:46.0820 0x17fc  [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
06:06:46.0820 0x17fc  volmgr - ok
06:06:46.0852 0x17fc  [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
06:06:46.0867 0x17fc  volmgrx - ok
06:06:46.0914 0x17fc  [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
06:06:46.0930 0x17fc  volsnap - ok
06:06:46.0961 0x17fc  [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid         C:\Windows\system32\DRIVERS\vsmraid.sys
06:06:46.0976 0x17fc  vsmraid - ok
06:06:47.0039 0x17fc  [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS             C:\Windows\system32\vssvc.exe
06:06:47.0132 0x17fc  VSS - ok
06:06:47.0164 0x17fc  [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
06:06:47.0210 0x17fc  vwifibus - ok
06:06:47.0273 0x17fc  [ 7090D3436EEB4E7DA3373090A23448F7, 3A130B28F2BFA7DCEC8596C4CE4E187B019F5ECF1AAC8DD1BBDE9CBD2428FEC2 ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
06:06:47.0304 0x17fc  vwififlt - ok
06:06:47.0335 0x17fc  [ A3F04CBEA6C2A10E6CB01F8B47611882, 32AFE18B07FECA30BC95831A5DC94C784E543784DF16165334A777DC84E91EF3 ] vwifimp         C:\Windows\system32\DRIVERS\vwifimp.sys
06:06:47.0351 0x17fc  vwifimp - ok
06:06:47.0382 0x17fc  [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time         C:\Windows\system32\w32time.dll
06:06:47.0444 0x17fc  W32Time - ok
06:06:47.0507 0x17fc  [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
06:06:47.0522 0x17fc  WacomPen - ok
06:06:47.0585 0x17fc  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
06:06:47.0616 0x17fc  WANARP - ok
06:06:47.0616 0x17fc  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
06:06:47.0647 0x17fc  Wanarpv6 - ok
06:06:47.0959 0x17fc  [ 353A04C273EC58475D8633E75CCD5604, FFAE53B6B53AEFC9E8A10BF27480E072D74430276BEB532FE1D473E9616D8CE0 ] WatAdminSvc     C:\Windows\system32\Wat\WatAdminSvc.exe
06:06:48.0037 0x17fc  WatAdminSvc - ok
06:06:48.0146 0x17fc  [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine        C:\Windows\system32\wbengine.exe
06:06:48.0287 0x17fc  wbengine - ok
06:06:48.0334 0x17fc  [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
06:06:48.0365 0x17fc  WbioSrvc - ok
06:06:48.0396 0x17fc  [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc         C:\Windows\System32\wcncsvc.dll
06:06:48.0427 0x17fc  wcncsvc - ok
06:06:48.0443 0x17fc  [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
06:06:48.0458 0x17fc  WcsPlugInService - ok
06:06:48.0474 0x17fc  [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd              C:\Windows\system32\DRIVERS\wd.sys
06:06:48.0490 0x17fc  Wd - ok
06:06:48.0521 0x17fc  [ D6EFAF429FD30C5DF613D220E344CCE7, 807D4563E8AD4073688691078EB13AF240E14BA5E0C8506A48B3060A20B90082 ] WDC_SAM         C:\Windows\system32\DRIVERS\wdcsam.sys
06:06:48.0552 0x17fc  WDC_SAM - ok
06:06:48.0614 0x17fc  [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
06:06:48.0661 0x17fc  Wdf01000 - ok
06:06:48.0692 0x17fc  [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiServiceHost  C:\Windows\system32\wdi.dll
06:06:48.0770 0x17fc  WdiServiceHost - ok
06:06:48.0770 0x17fc  [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiSystemHost   C:\Windows\system32\wdi.dll
06:06:48.0786 0x17fc  WdiSystemHost - ok
06:06:48.0833 0x17fc  [ 75E8EBD7040CE238684333F97014762A, 2CA0B267FBAEB303D1F8B639D733DC0DE17BA1276CC9096035B4F2BBBED3EF7F ] WebClient       C:\Windows\System32\webclnt.dll
06:06:48.0880 0x17fc  WebClient - ok
06:06:48.0911 0x17fc  [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc          C:\Windows\system32\wecsvc.dll
06:06:48.0942 0x17fc  Wecsvc - ok
06:06:48.0958 0x17fc  [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
06:06:49.0004 0x17fc  wercplsupport - ok
06:06:49.0082 0x17fc  [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc          C:\Windows\System32\WerSvc.dll
06:06:49.0129 0x17fc  WerSvc - ok
06:06:49.0192 0x17fc  [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
06:06:49.0223 0x17fc  WfpLwf - ok
06:06:49.0254 0x17fc  [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
06:06:49.0285 0x17fc  WIMMount - ok
06:06:49.0363 0x17fc  [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend       C:\Program Files\Windows Defender\mpsvc.dll
06:06:49.0441 0x17fc  WinDefend - ok
06:06:49.0457 0x17fc  WinHttpAutoProxySvc - ok
06:06:49.0504 0x17fc  [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
06:06:49.0535 0x17fc  Winmgmt - ok
06:06:49.0613 0x17fc  [ 1B91CD34EA3A90AB6A4EF0550174F4CC, 5B6618615EBFBA594C945AD35F5C68DA8C6053892B6D12D626BB6120910D80DC ] WinRM           C:\Windows\system32\WsmSvc.dll
06:06:49.0706 0x17fc  WinRM - ok
06:06:49.0800 0x17fc  [ A67E5F9A400F3BD1BE3D80613B45F708, E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
06:06:49.0831 0x17fc  WinUsb - ok
06:06:49.0894 0x17fc  [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc         C:\Windows\System32\wlansvc.dll
06:06:49.0925 0x17fc  Wlansvc - ok
06:06:50.0018 0x17fc  [ 6067ACEF367E79914AF628FA1E9B5330, 491A705267B48C103E00B26BBD21FA8829DB03A88343CBC27264CEE5DE8C8DEF ] wlcrasvc        C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
06:06:50.0034 0x17fc  wlcrasvc - ok
06:06:50.0330 0x17fc  [ FB01D4AE207B9EFDBABFC55DC95C7E31, E0EFDBBE0BAC275230C8C1A053948C21BCF20B99B92E50939E95FFB9DC87F6BA ] wlidsvc         C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
06:06:50.0408 0x17fc  wlidsvc - ok
06:06:50.0502 0x17fc  [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi         C:\Windows\system32\drivers\wmiacpi.sys
06:06:50.0533 0x17fc  WmiAcpi - ok
06:06:50.0611 0x17fc  [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
06:06:50.0642 0x17fc  wmiApSrv - ok
06:06:50.0720 0x17fc  [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc   C:\Program Files\Windows Media Player\wmpnetwk.exe
06:06:50.0845 0x17fc  WMPNetworkSvc - ok
06:06:50.0908 0x17fc  [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
06:06:50.0954 0x17fc  WPCSvc - ok
06:06:50.0970 0x17fc  [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
06:06:51.0001 0x17fc  WPDBusEnum - ok
06:06:51.0032 0x17fc  [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
06:06:51.0079 0x17fc  ws2ifsl - ok
06:06:51.0110 0x17fc  [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc          C:\Windows\system32\wscsvc.dll
06:06:51.0142 0x17fc  wscsvc - ok
06:06:51.0157 0x17fc  WSearch - ok
06:06:51.0578 0x17fc  [ FC3EC24FCE372C89423E015A2AC1A31E, 8D028182CF83667D3E4D148979972D208FA6D9B8540EE47A0A7831B770ECD257 ] wuauserv        C:\Windows\system32\wuaueng.dll
06:06:51.0688 0x17fc  wuauserv - ok
06:06:51.0734 0x17fc  [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
06:06:51.0781 0x17fc  WudfPf - ok
06:06:51.0844 0x17fc  [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
06:06:51.0906 0x17fc  WUDFRd - ok
06:06:51.0953 0x17fc  [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
06:06:52.0000 0x17fc  wudfsvc - ok
06:06:52.0031 0x17fc  [ 7CC38741B8F68F1E0D5D79DA6123666A, F90D2DA1C9AFB506C381CD386E1430931B5F81813FEDFD720F87FBC54E7A00DA ] WwanSvc         C:\Windows\System32\wwansvc.dll
06:06:52.0062 0x17fc  WwanSvc - ok
06:06:52.0093 0x17fc  ================ Scan global ===============================
06:06:52.0124 0x17fc  [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll
06:06:52.0156 0x17fc  [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
06:06:52.0171 0x17fc  [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
06:06:52.0202 0x17fc  [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
06:06:52.0234 0x17fc  [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\Windows\system32\services.exe
06:06:52.0234 0x17fc  [ Global ] - ok
06:06:52.0234 0x17fc  ================ Scan MBR ==================================
06:06:52.0249 0x17fc  [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
06:06:52.0483 0x17fc  \Device\Harddisk0\DR0 - ok
06:06:52.0624 0x17fc  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
06:06:53.0107 0x17fc  \Device\Harddisk1\DR1 - ok
06:06:53.0107 0x17fc  ================ Scan VBR ==================================
06:06:53.0107 0x17fc  [ EB30EEECC0DE47F94CB53B2769418FF0 ] \Device\Harddisk0\DR0\Partition1
06:06:53.0154 0x17fc  \Device\Harddisk0\DR0\Partition1 - ok
06:06:53.0185 0x17fc  [ 9C83CFC6667BF48F42EC4995C54D5A60 ] \Device\Harddisk1\DR1\Partition1
06:06:53.0185 0x17fc  \Device\Harddisk1\DR1\Partition1 - ok
06:06:53.0185 0x17fc  Waiting for KSN requests completion. In queue: 165
06:06:54.0199 0x17fc  Waiting for KSN requests completion. In queue: 165
06:06:55.0213 0x17fc  Waiting for KSN requests completion. In queue: 165
06:06:56.0227 0x17fc  Waiting for KSN requests completion. In queue: 165
06:06:57.0272 0x17fc  AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.4.304.0 ), 0x61000 ( enabled : updated )
06:06:57.0304 0x17fc  Win FW state via NFP2: enabled
06:07:00.0424 0x17fc  ============================================================
06:07:00.0424 0x17fc  Scan finished
06:07:00.0424 0x17fc  ============================================================
06:07:00.0424 0x0ba4  Detected object count: 0
06:07:00.0424 0x0ba4  Actual detected object count: 0
 



#4 Aurifex

Aurifex
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:12:34 PM

Posted 15 March 2014 - 02:42 PM

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014  01
Ran by unknown (administrator) on UNKNOWN-PC on 16-03-2014 06:12:52
Running from C:\Users\unknown\Downloads
Microsoft Windows 7 Ultimate  Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Ralink Technology, Corp.) C:\Program Files\NetComm\Common\RegistryWriter.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Nero AG) C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
() C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(NetComm Limited) C:\Program Files\NetComm\Common\RaUI.exe
(Ricoh Company, Ltd.) C:\Program Files\Caplio Software\RGateLXP.exe
(Nero AG) C:\Program Files\Nero\Update\NASvc.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Windows Live\Mail\wlmail.exe
(Microsoft Corporation) C:\Program Files\Windows Live\Contacts\wlcomm.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MpCmdRun.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [BrMfcWnd] - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
HKLM\...\Run: [NBAgent] - C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1234216 2010-03-26] (Nero AG)
HKLM\...\Run: [ArcSoft Connection Service] - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-08-27] (Apple Inc.)
HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [3524536 2012-07-16] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [421776 2012-09-10] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM\...\Run: [lkebutoh] - C:\ProgramData\ofjz\ecuwofez.exe [258048 2014-03-14] ()
HKU\S-1-5-21-2134969444-2299796119-3524533687-1000\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-06-17] (Hewlett-Packard Company)
HKU\S-1-5-21-2134969444-2299796119-3524533687-1000\...\Run: [KiesPDLR] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-07-16] ()
HKU\S-1-5-21-2134969444-2299796119-3524533687-1000\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [975800 2012-07-16] (Samsung)
HKU\S-1-5-21-2134969444-2299796119-3524533687-1000\...\Run: [News.net] - C:\Program Files\News.net\BreakingNews\DesktopContainer.exe
AppInit_DLLs: C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll File Not Found

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x495B2F24C440CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://iat.ninemsn.com.au/tickler/default.aspx?ocid=iehp
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {CD280D45-1C29-4E80-A506-D88F2ED4760C} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=9B874255-7D2C-47B9-97A1-9D9D5F6C44C1&apn_sauid=2B80A8AE-C505-44AC-B0EB-3E4E4063A8F8
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File
Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\unknown\AppData\Roaming\Mozilla\Firefox\Profiles\cr4c0zm7.default-1394486327657
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @alibaba.com/npwangwang;version=1.0 - C:\Program Files\Trademanager\npwangwang.dll ( )
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @pages.tvunetworks.com/WebPlayer - C:\Users\unknown\Desktop\TVUPlayer\npTVUAx.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @alibaba.com/npAliSSOLogin;version=1.0 - C:\Program Files\Trademanager\npAliSSOLogin.dll (Alibaba software (Shanghai) Corporation.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\unknown\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwangwang.dll ( )

Chrome:
=======
CHR HomePage: hxxp://www.news.net/index.php?referid=125

========================== Services (Whitelisted) =================

R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [490280 2010-03-25] (Nero AG)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 RalinkRegistryWriter; C:\Program Files\NetComm\Common\RegistryWriter.exe [69632 2008-05-13] (Ralink Technology, Corp.)

==================== Drivers (Whitelisted) ====================

S3 61883; C:\Windows\System32\DRIVERS\61883.sys [46976 2009-07-14] (Microsoft Corporation)
S3 bqusbser; C:\Windows\System32\DRIVERS\Mousbser.sys [103936 2008-05-22] (Motorola Incorporated)
R2 Hardlock; C:\Windows\system32\drivers\hardlock.sys [685056 2005-07-28] (Aladdin Knowledge Systems Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
R1 MpKsldff1a976; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{75783977-8EB0-4949-91CF-29E83014DA71}\MpKsldff1a976.sys [39464 2014-03-14] (Microsoft Corporation)
S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [657408 2009-07-14] (Ralink Technology Corp.)
S3 catchme; \??\C:\Users\unknown\AppData\Local\Temp\catchme.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
U3 mbr; \??\C:\Users\unknown\AppData\Local\Temp\mbr.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-16 06:12 - 2014-03-16 06:13 - 00012403 _____ () C:\Users\unknown\Downloads\FRST.txt
2014-03-16 06:12 - 2014-03-16 06:12 - 00000000 ____D () C:\FRST
2014-03-16 06:11 - 2014-03-16 06:11 - 01145856 _____ (Farbar) C:\Users\unknown\Downloads\FRST.exe
2014-03-16 06:04 - 2014-03-16 06:04 - 04130656 _____ (Kaspersky Lab ZAO) C:\Users\unknown\Downloads\tdsskiller.exe
2014-03-16 06:02 - 2014-03-16 06:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{72275A55-063E-4860-BAEE-9ABBD9080EED}
2014-03-15 07:59 - 2014-03-15 07:59 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D8090C2D-71FD-481E-AB68-1FBC0756BA3A}
2014-03-14 16:34 - 2014-03-14 16:35 - 00000000 ____D () C:\Users\unknown\Desktop\New help
2014-03-14 16:33 - 2014-03-14 16:33 - 00021764 _____ () C:\Users\unknown\Desktop\dds.txt
2014-03-14 16:33 - 2014-03-14 16:33 - 00006187 _____ () C:\Users\unknown\Desktop\attach.txt
2014-03-14 16:30 - 2014-03-14 16:30 - 00688992 ____R (Swearware) C:\Users\unknown\Downloads\dds.com
2014-03-14 16:10 - 2014-03-14 16:10 - 00000000 ____D () C:\Users\unknown\AppData\Local\{22417392-7AD2-419B-9A6E-E56B23C6F117}
2014-03-14 03:00 - 2014-03-14 03:00 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B831E33C-181D-4798-99D1-47DC39FA776B}
2014-03-14 03:00 - 2014-03-14 03:00 - 00000000 ____D () C:\ProgramData\ofjz
2014-03-13 11:22 - 2014-03-01 15:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-13 11:22 - 2014-03-01 15:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-13 11:22 - 2014-03-01 15:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-13 11:22 - 2014-03-01 14:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-13 11:22 - 2014-03-01 14:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-13 11:22 - 2014-03-01 14:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-13 11:22 - 2014-03-01 14:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-13 11:22 - 2014-03-01 14:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-13 11:22 - 2014-03-01 14:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-13 11:22 - 2014-03-01 14:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-13 11:22 - 2014-03-01 14:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-13 11:22 - 2014-03-01 14:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-13 11:22 - 2014-03-01 14:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-13 11:22 - 2014-03-01 14:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-13 11:22 - 2014-03-01 14:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-13 11:22 - 2014-03-01 14:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-13 11:22 - 2014-03-01 14:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-13 11:22 - 2014-03-01 14:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-13 11:22 - 2014-03-01 13:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-13 11:22 - 2014-03-01 13:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-13 11:22 - 2014-03-01 13:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-13 11:22 - 2014-03-01 13:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-13 11:22 - 2014-02-04 13:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-13 11:20 - 2014-02-07 12:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-13 11:20 - 2014-02-04 13:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-13 11:20 - 2014-01-29 13:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-13 11:20 - 2014-01-28 13:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-13 11:20 - 2014-01-09 13:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-03-13 08:19 - 2014-03-13 08:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{58513ECF-F5D2-44E5-9F4C-9A0CBDF45CC6}
2014-03-12 09:26 - 2013-10-02 11:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-03-12 09:26 - 2013-10-02 11:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-03-12 09:26 - 2013-10-02 10:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-03-12 09:26 - 2012-08-24 01:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-03-12 09:26 - 2012-08-24 01:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-03-12 09:26 - 2012-08-24 00:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-03-12 09:26 - 2012-08-23 22:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-03-12 09:26 - 2012-08-23 21:08 - 02739712 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-03-12 09:25 - 2013-10-02 11:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-03-12 09:25 - 2013-10-02 11:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-03-12 09:25 - 2013-10-02 11:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-03-12 09:25 - 2013-10-02 10:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-03-12 09:25 - 2013-10-02 10:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-03-12 09:25 - 2013-10-02 10:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-03-12 09:25 - 2013-10-02 09:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-03-12 09:25 - 2013-10-02 09:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-03-12 09:24 - 2013-09-25 12:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-03-12 09:24 - 2012-05-04 20:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-03-12 09:19 - 2014-03-12 09:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F96658A8-FAF7-4C1D-86ED-1C0CEFDA33BE}
2014-03-11 20:57 - 2014-03-11 20:57 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3CBA1460-F382-4ECA-BC06-C439939ADE7C}
2014-03-11 16:55 - 2014-03-11 17:00 - 00000058 _____ () C:\Users\unknown\Desktop\New Text Document.txt
2014-03-11 16:45 - 2014-03-11 16:45 - 00000941 _____ () C:\Users\Public\Desktop\Speccy.lnk
2014-03-11 16:45 - 2014-03-11 16:45 - 00000000 ____D () C:\Program Files\Speccy
2014-03-11 16:45 - 2014-03-11 16:42 - 04845384 _____ (Piriform Ltd) C:\Users\unknown\Desktop\spsetup125.exe
2014-03-11 14:30 - 2014-03-11 14:30 - 00000035 _____ () C:\Users\unknown\Desktop\eset.txt
2014-03-11 11:45 - 2014-03-11 11:45 - 00000000 ____D () C:\Program Files\ESET
2014-03-11 11:25 - 2014-03-11 11:25 - 00027544 _____ () C:\Users\unknown\Desktop\Result.txt
2014-03-11 11:24 - 2014-03-11 11:24 - 00000854 _____ () C:\Users\unknown\Desktop\checkup.txt
2014-03-11 08:27 - 2014-03-11 08:27 - 00001071 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-11 08:27 - 2014-03-11 08:27 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-11 08:27 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-11 08:18 - 2014-03-11 08:18 - 00000000 ____D () C:\Users\unknown\Desktop\Old Firefox Data
2014-03-11 07:46 - 2014-03-11 07:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{824DB67E-2AF1-4AB3-B831-9599F9BFBA69}
2014-03-10 19:46 - 2014-03-10 19:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{480D26A8-315E-4F8A-99F9-64C14003FA5E}
2014-03-10 16:37 - 2014-03-14 03:00 - 00000000 ____D () C:\ProgramData\ebdc
2014-03-10 07:43 - 2014-03-10 07:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CBF052D1-D3A3-4F18-BAE7-9B7CD75C2A6C}
2014-03-08 19:30 - 2014-03-14 16:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\CrashDumps
2014-03-08 19:30 - 2014-03-09 14:57 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A88AE5B2-ABEB-4965-B22F-71157B3D3010}
2014-03-08 07:15 - 2014-02-15 10:33 - 00000426 _____ () C:\AVScanner.ini
2014-03-08 07:14 - 2014-03-10 16:37 - 00000000 ____D () C:\ProgramData\iflr
2014-03-08 07:12 - 2014-03-08 07:12 - 00000855 _____ () C:\Users\unknown\Desktop\µTorrent.lnk
2014-03-08 07:09 - 2014-03-08 07:10 - 01853008 _____ (BitTorrent Inc.) C:\Users\unknown\Downloads\uTorrent.exe
2014-03-08 07:06 - 2014-03-08 07:06 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D96128E7-775A-4D37-96E2-8E5A5750BEC2}
2014-03-07 12:44 - 2014-03-07 13:05 - 00000000 ____D () C:\Users\unknown\Desktop\GARAGE BUILDING DOCS
2014-03-07 10:13 - 2014-03-07 10:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F9AAEE8B-864D-4ACD-9F94-7F0FCF0559E7}
2014-03-06 09:03 - 2014-03-06 09:03 - 03819008 _____ () C:\Users\unknown\Downloads\RogueKiller.exe
2014-03-06 09:02 - 2014-03-06 09:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DE030B0A-6BE1-4FDF-A1FF-1B6262C897A8}
2014-03-05 19:44 - 2014-03-05 19:44 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E56DB46F-396F-4167-85EE-422A02FE158C}
2014-03-05 07:47 - 2014-03-05 07:48 - 00380416 _____ () C:\Users\unknown\Downloads\jh0vxwq9.exe
2014-03-05 07:43 - 2014-03-05 07:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{937EBBB1-75AC-416B-8518-6FFDD411C514}
2014-03-04 12:44 - 2014-03-08 07:14 - 00000000 ____D () C:\ProgramData\ilin
2014-03-04 11:17 - 2014-03-04 11:17 - 02347384 _____ (ESET) C:\Users\unknown\Desktop\esetsmartinstaller_enu.exe
2014-03-04 07:40 - 2014-03-04 07:40 - 00144400 _____ () C:\Windows\Minidump\030414-21933-01.dmp
2014-03-04 06:53 - 2014-03-04 06:53 - 00000000 ____D () C:\ProgramData\Oracle
2014-03-04 06:52 - 2014-03-04 06:52 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-03-04 06:52 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-03-04 06:52 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-03-04 06:52 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-03-04 06:52 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-03-04 06:51 - 2014-03-04 06:52 - 00005822 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-03-04 06:43 - 2014-03-04 06:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{8445ED36-709F-489C-8A19-08FA29853D50}
2014-03-03 17:17 - 2014-03-03 17:17 - 00144400 _____ () C:\Windows\Minidump\030314-23181-01.dmp
2014-03-03 16:19 - 2014-03-03 16:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CE1B8D22-0818-46C6-B5C6-5ABD7F0F53A1}
2014-03-03 14:44 - 2014-03-03 14:46 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\unknown\Desktop\mbam-setup.exe
2014-03-03 14:40 - 2014-03-03 14:40 - 00982016 _____ (Farbar) C:\Users\unknown\Desktop\MiniToolBox.exe
2014-03-03 14:35 - 2014-03-03 14:35 - 00987425 _____ () C:\Users\unknown\Desktop\SecurityCheck.exe
2014-03-03 14:04 - 2014-03-04 12:43 - 00000000 ____D () C:\ProgramData\inyv
2014-03-03 13:18 - 2014-03-14 16:24 - 00000000 ____D () C:\ProgramData\amepugyf
2014-03-03 13:18 - 2014-03-03 14:04 - 00000000 ____D () C:\ProgramData\yqyc
2014-03-03 04:19 - 2014-03-03 04:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{C8553F1C-DCC3-4186-81AC-D59DC80B7754}
2014-03-02 08:22 - 2014-03-02 08:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{7988F25E-42D5-483F-8C31-AA7B00BB8350}
2014-03-01 08:53 - 2014-03-01 08:54 - 00000000 ____D () C:\Users\unknown\AppData\Local\{76D4D32B-9E1E-4329-9BDD-16DD7866C0E9}
2014-02-28 06:52 - 2014-02-28 06:52 - 00000000 ____D () C:\Users\unknown\AppData\Local\{12C0B45D-95EB-4F40-8055-5988414D1F2A}
2014-02-27 07:35 - 2014-02-27 07:35 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D95EA739-1005-4962-8FE2-6DC10B269C6C}
2014-02-26 08:11 - 2014-02-26 08:11 - 00000000 ____D () C:\Users\unknown\AppData\Local\{4A52383B-9DA4-4D77-8997-3635B681EF21}
2014-02-25 18:25 - 2014-02-25 18:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D6B27FDB-5D94-4B77-929F-CD800B3BBD30}
2014-02-25 07:14 - 2014-02-25 07:28 - 00000000 ____D () C:\Users\unknown\Desktop\2014-02-25 Stephanies Jewellery resell
2014-02-25 06:22 - 2014-02-25 06:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E5CAC627-E354-4FFA-B81B-40B990A40CF8}
2014-02-24 17:49 - 2014-02-24 17:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{414E4E6C-C6CE-42E7-8CF4-26CF6F52FE1A}
2014-02-24 05:49 - 2014-02-24 05:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A0A0B8AF-CB9C-44E5-B043-D982A1548B56}
2014-02-23 05:52 - 2014-02-23 05:53 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A2C20AE5-2970-4901-8E5F-28854CF0719C}
2014-02-22 16:55 - 2014-02-22 16:56 - 00263680 _____ () C:\Users\unknown\Desktop\Irrigation Solution Questionnaire.xls
2014-02-22 16:30 - 2014-02-22 16:31 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3B0DA881-2B59-4EC3-B6FE-7A4AE0C68BAF}
2014-02-21 11:46 - 2014-02-21 11:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{18F099C4-3CE5-4516-806F-E73F1F33770E}
2014-02-20 21:12 - 2014-02-21 17:51 - 00021504 _____ () C:\Users\unknown\Desktop\SAMS JERSEY BUSINESS.xls
2014-02-20 20:39 - 2014-02-20 20:39 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B2E264EE-87EE-479E-88C8-D3AFA709CA5A}
2014-02-20 16:12 - 2014-02-20 16:25 - 00000000 ____D () C:\Users\unknown\Desktop\Stephanie Vodnik
2014-02-20 08:13 - 2014-02-20 08:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{FE58155E-F2DB-4206-94D2-C076D381045C}
2014-02-19 18:42 - 2014-02-19 18:42 - 00000000 ____D () C:\Users\unknown\AppData\Local\{78E0DC29-60A3-4BDC-B96D-7589151BC609}
2014-02-19 05:51 - 2014-02-19 05:51 - 00000000 ____D () C:\Users\unknown\AppData\Local\{6F44F1E2-F261-4814-A0D5-0D559FB63055}
2014-02-18 07:19 - 2014-02-18 07:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DCD5934F-9564-4666-AD95-8BDC02E6BE98}
2014-02-17 19:19 - 2014-02-17 19:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{86C8749A-58DF-4C3A-BD14-E688182BDF44}
2014-02-17 08:04 - 2014-02-17 08:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-17 07:19 - 2014-02-17 07:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A9E9283D-0593-43EF-9943-D1F3E42C9CD8}
2014-02-16 09:56 - 2014-02-16 09:56 - 00000000 ____D () C:\Users\unknown\AppData\Local\{0026EF2A-4381-4248-971F-F281B13CD76A}
2014-02-15 07:21 - 2014-02-15 07:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{FD2DB3B0-C157-432F-BE58-343311AAECEA}
2014-02-14 07:59 - 2014-02-14 07:59 - 00000000 ____D () C:\Users\unknown\AppData\Local\{C804A8BE-2355-45AD-BEFF-CAD9EE7AEAF9}

==================== One Month Modified Files and Folders =======

2014-03-16 06:13 - 2014-03-16 06:12 - 00012403 _____ () C:\Users\unknown\Downloads\FRST.txt
2014-03-16 06:13 - 2011-03-16 10:13 - 01816145 _____ () C:\Windows\WindowsUpdate.log
2014-03-16 06:12 - 2014-03-16 06:12 - 00000000 ____D () C:\FRST
2014-03-16 06:11 - 2014-03-16 06:11 - 01145856 _____ (Farbar) C:\Users\unknown\Downloads\FRST.exe
2014-03-16 06:09 - 2011-08-29 11:55 - 00000884 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-16 06:04 - 2014-03-16 06:04 - 04130656 _____ (Kaspersky Lab ZAO) C:\Users\unknown\Downloads\tdsskiller.exe
2014-03-16 06:02 - 2014-03-16 06:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{72275A55-063E-4860-BAEE-9ABBD9080EED}
2014-03-16 06:02 - 2011-08-29 11:55 - 00000888 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-16 06:01 - 2012-04-01 17:58 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-15 15:05 - 2011-03-26 13:00 - 00000000 ____D () C:\Users\unknown\AppData\Roaming\uTorrent
2014-03-15 14:32 - 2009-07-14 15:34 - 00014416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-15 14:32 - 2009-07-14 15:34 - 00014416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-15 07:59 - 2014-03-15 07:59 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D8090C2D-71FD-481E-AB68-1FBC0756BA3A}
2014-03-14 18:39 - 2011-03-16 10:23 - 00782510 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-14 16:35 - 2014-03-14 16:34 - 00000000 ____D () C:\Users\unknown\Desktop\New help
2014-03-14 16:33 - 2014-03-14 16:33 - 00021764 _____ () C:\Users\unknown\Desktop\dds.txt
2014-03-14 16:33 - 2014-03-14 16:33 - 00006187 _____ () C:\Users\unknown\Desktop\attach.txt
2014-03-14 16:30 - 2014-03-14 16:30 - 00688992 ____R (Swearware) C:\Users\unknown\Downloads\dds.com
2014-03-14 16:25 - 2014-03-08 19:30 - 00000000 ____D () C:\Users\unknown\AppData\Local\CrashDumps
2014-03-14 16:24 - 2014-03-03 13:18 - 00000000 ____D () C:\ProgramData\amepugyf
2014-03-14 16:24 - 2011-12-03 09:54 - 08405015 _____ () C:\Windows\TempFile
2014-03-14 16:24 - 2011-10-29 20:10 - 00000000 ____D () C:\ProgramData\Sun
2014-03-14 16:24 - 2009-07-14 15:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-14 16:24 - 2009-07-14 15:39 - 00133961 _____ () C:\Windows\setupact.log
2014-03-14 16:21 - 2013-08-05 11:39 - 00000000 ____D () C:\Program Files\Brother
2014-03-14 16:10 - 2014-03-14 16:10 - 00000000 ____D () C:\Users\unknown\AppData\Local\{22417392-7AD2-419B-9A6E-E56B23C6F117}
2014-03-14 11:28 - 2009-07-14 13:37 - 00000000 ____D () C:\Windows\rescache
2014-03-14 03:28 - 2009-07-14 15:33 - 03692064 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-14 03:27 - 2011-06-13 11:57 - 00000362 __RSH () C:\ProgramData\ntuser.pol
2014-03-14 03:26 - 2011-03-16 15:53 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-14 03:00 - 2014-03-14 03:00 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B831E33C-181D-4798-99D1-47DC39FA776B}
2014-03-14 03:00 - 2014-03-14 03:00 - 00000000 ____D () C:\ProgramData\ofjz
2014-03-14 03:00 - 2014-03-10 16:37 - 00000000 ____D () C:\ProgramData\ebdc
2014-03-13 08:19 - 2014-03-13 08:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{58513ECF-F5D2-44E5-9F4C-9A0CBDF45CC6}
2014-03-12 09:56 - 2012-04-01 17:58 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-12 09:56 - 2011-05-20 08:14 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-12 09:19 - 2014-03-12 09:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F96658A8-FAF7-4C1D-86ED-1C0CEFDA33BE}
2014-03-11 20:57 - 2014-03-11 20:57 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3CBA1460-F382-4ECA-BC06-C439939ADE7C}
2014-03-11 17:00 - 2014-03-11 16:55 - 00000058 _____ () C:\Users\unknown\Desktop\New Text Document.txt
2014-03-11 16:45 - 2014-03-11 16:45 - 00000941 _____ () C:\Users\Public\Desktop\Speccy.lnk
2014-03-11 16:45 - 2014-03-11 16:45 - 00000000 ____D () C:\Program Files\Speccy
2014-03-11 16:42 - 2014-03-11 16:45 - 04845384 _____ (Piriform Ltd) C:\Users\unknown\Desktop\spsetup125.exe
2014-03-11 14:30 - 2014-03-11 14:30 - 00000035 _____ () C:\Users\unknown\Desktop\eset.txt
2014-03-11 11:45 - 2014-03-11 11:45 - 00000000 ____D () C:\Program Files\ESET
2014-03-11 11:25 - 2014-03-11 11:25 - 00027544 _____ () C:\Users\unknown\Desktop\Result.txt
2014-03-11 11:24 - 2014-03-11 11:24 - 00000854 _____ () C:\Users\unknown\Desktop\checkup.txt
2014-03-11 08:27 - 2014-03-11 08:27 - 00001071 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-11 08:27 - 2014-03-11 08:27 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-11 08:18 - 2014-03-11 08:18 - 00000000 ____D () C:\Users\unknown\Desktop\Old Firefox Data
2014-03-11 07:54 - 2011-03-17 01:23 - 00164038 _____ () C:\Windows\PFRO.log
2014-03-11 07:46 - 2014-03-11 07:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{824DB67E-2AF1-4AB3-B831-9599F9BFBA69}
2014-03-10 19:46 - 2014-03-10 19:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{480D26A8-315E-4F8A-99F9-64C14003FA5E}
2014-03-10 16:37 - 2014-03-08 07:14 - 00000000 ____D () C:\ProgramData\iflr
2014-03-10 13:02 - 2011-07-24 20:00 - 12102144 ___SH () C:\Users\unknown\Desktop\Thumbs.db
2014-03-10 07:43 - 2014-03-10 07:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CBF052D1-D3A3-4F18-BAE7-9B7CD75C2A6C}
2014-03-09 14:57 - 2014-03-08 19:30 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A88AE5B2-ABEB-4965-B22F-71157B3D3010}
2014-03-08 07:14 - 2014-03-04 12:44 - 00000000 ____D () C:\ProgramData\ilin
2014-03-08 07:12 - 2014-03-08 07:12 - 00000855 _____ () C:\Users\unknown\Desktop\µTorrent.lnk
2014-03-08 07:10 - 2014-03-08 07:09 - 01853008 _____ (BitTorrent Inc.) C:\Users\unknown\Downloads\uTorrent.exe
2014-03-08 07:06 - 2014-03-08 07:06 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D96128E7-775A-4D37-96E2-8E5A5750BEC2}
2014-03-07 13:05 - 2014-03-07 12:44 - 00000000 ____D () C:\Users\unknown\Desktop\GARAGE BUILDING DOCS
2014-03-07 10:13 - 2014-03-07 10:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F9AAEE8B-864D-4ACD-9F94-7F0FCF0559E7}
2014-03-06 09:03 - 2014-03-06 09:03 - 03819008 _____ () C:\Users\unknown\Downloads\RogueKiller.exe
2014-03-06 09:02 - 2014-03-06 09:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DE030B0A-6BE1-4FDF-A1FF-1B6262C897A8}
2014-03-05 19:44 - 2014-03-05 19:44 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E56DB46F-396F-4167-85EE-422A02FE158C}
2014-03-05 07:48 - 2014-03-05 07:47 - 00380416 _____ () C:\Users\unknown\Downloads\jh0vxwq9.exe
2014-03-05 07:43 - 2014-03-05 07:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{937EBBB1-75AC-416B-8518-6FFDD411C514}
2014-03-04 12:56 - 2013-07-11 13:46 - 00000000 ____D () C:\Users\unknown\Desktop\microsoft office
2014-03-04 12:43 - 2014-03-03 14:04 - 00000000 ____D () C:\ProgramData\inyv
2014-03-04 11:17 - 2014-03-04 11:17 - 02347384 _____ (ESET) C:\Users\unknown\Desktop\esetsmartinstaller_enu.exe
2014-03-04 11:11 - 2009-07-14 13:37 - 00000000 ____D () C:\Windows\L2Schemas
2014-03-04 07:40 - 2014-03-04 07:40 - 00144400 _____ () C:\Windows\Minidump\030414-21933-01.dmp
2014-03-04 07:40 - 2011-04-19 16:38 - 257085711 _____ () C:\Windows\MEMORY.DMP
2014-03-04 07:40 - 2011-04-19 16:38 - 00000000 ____D () C:\Windows\Minidump
2014-03-04 07:03 - 2011-03-17 06:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\Adobe
2014-03-04 07:01 - 2011-06-18 08:08 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-03-04 07:01 - 2011-03-17 06:46 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-04 07:01 - 2011-03-17 06:46 - 00000000 ____D () C:\Program Files\Adobe
2014-03-04 06:53 - 2014-03-04 06:53 - 00000000 ____D () C:\ProgramData\Oracle
2014-03-04 06:52 - 2014-03-04 06:52 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-03-04 06:52 - 2014-03-04 06:51 - 00005822 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-03-04 06:52 - 2011-10-29 20:09 - 00000000 ____D () C:\Program Files\Java
2014-03-04 06:43 - 2014-03-04 06:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{8445ED36-709F-489C-8A19-08FA29853D50}
2014-03-03 17:17 - 2014-03-03 17:17 - 00144400 _____ () C:\Windows\Minidump\030314-23181-01.dmp
2014-03-03 16:19 - 2014-03-03 16:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CE1B8D22-0818-46C6-B5C6-5ABD7F0F53A1}
2014-03-03 15:12 - 2009-07-14 13:37 - 00000000 ____D () C:\Windows\PLA
2014-03-03 14:46 - 2014-03-03 14:44 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\unknown\Desktop\mbam-setup.exe
2014-03-03 14:40 - 2014-03-03 14:40 - 00982016 _____ (Farbar) C:\Users\unknown\Desktop\MiniToolBox.exe
2014-03-03 14:35 - 2014-03-03 14:35 - 00987425 _____ () C:\Users\unknown\Desktop\SecurityCheck.exe
2014-03-03 14:04 - 2014-03-03 13:18 - 00000000 ____D () C:\ProgramData\yqyc
2014-03-03 04:19 - 2014-03-03 04:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{C8553F1C-DCC3-4186-81AC-D59DC80B7754}
2014-03-02 08:22 - 2014-03-02 08:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{7988F25E-42D5-483F-8C31-AA7B00BB8350}
2014-03-01 15:30 - 2014-03-13 11:22 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-01 15:11 - 2014-03-13 11:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-01 15:10 - 2014-03-13 11:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-01 14:52 - 2014-03-13 11:22 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-01 14:51 - 2014-03-13 11:22 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-01 14:47 - 2014-03-13 11:22 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-01 14:43 - 2014-03-13 11:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-01 14:43 - 2014-03-13 11:22 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-01 14:40 - 2014-03-13 11:22 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-01 14:38 - 2014-03-13 11:22 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-01 14:38 - 2014-03-13 11:22 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-01 14:37 - 2014-03-13 11:22 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-01 14:31 - 2014-03-13 11:22 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-01 14:25 - 2014-03-13 11:22 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-01 14:16 - 2014-03-13 11:22 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-01 14:14 - 2014-03-13 11:22 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-01 14:03 - 2014-03-13 11:22 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-01 14:00 - 2014-03-13 11:22 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-01 13:57 - 2014-03-13 11:22 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-01 13:32 - 2014-03-13 11:22 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-01 13:27 - 2014-03-13 11:22 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-01 13:25 - 2014-03-13 11:22 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-01 08:54 - 2014-03-01 08:53 - 00000000 ____D () C:\Users\unknown\AppData\Local\{76D4D32B-9E1E-4329-9BDD-16DD7866C0E9}
2014-02-28 06:52 - 2014-02-28 06:52 - 00000000 ____D () C:\Users\unknown\AppData\Local\{12C0B45D-95EB-4F40-8055-5988414D1F2A}
2014-02-27 07:35 - 2014-02-27 07:35 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D95EA739-1005-4962-8FE2-6DC10B269C6C}
2014-02-26 08:11 - 2014-02-26 08:11 - 00000000 ____D () C:\Users\unknown\AppData\Local\{4A52383B-9DA4-4D77-8997-3635B681EF21}
2014-02-25 18:25 - 2014-02-25 18:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D6B27FDB-5D94-4B77-929F-CD800B3BBD30}
2014-02-25 07:28 - 2014-02-25 07:14 - 00000000 ____D () C:\Users\unknown\Desktop\2014-02-25 Stephanies Jewellery resell
2014-02-25 06:22 - 2014-02-25 06:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E5CAC627-E354-4FFA-B81B-40B990A40CF8}
2014-02-24 17:49 - 2014-02-24 17:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{414E4E6C-C6CE-42E7-8CF4-26CF6F52FE1A}
2014-02-24 05:49 - 2014-02-24 05:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A0A0B8AF-CB9C-44E5-B043-D982A1548B56}
2014-02-23 05:53 - 2014-02-23 05:52 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A2C20AE5-2970-4901-8E5F-28854CF0719C}
2014-02-22 16:56 - 2014-02-22 16:55 - 00263680 _____ () C:\Users\unknown\Desktop\Irrigation Solution Questionnaire.xls
2014-02-22 16:44 - 2013-12-30 14:26 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-02-22 16:44 - 2011-12-09 19:21 - 00000000 ____D () C:\Program Files\Trademanager
2014-02-22 16:31 - 2014-02-22 16:30 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3B0DA881-2B59-4EC3-B6FE-7A4AE0C68BAF}
2014-02-22 16:31 - 2011-03-16 15:51 - 00000000 ____D () C:\Users\unknown\AppData\Local\Windows Live
2014-02-21 17:51 - 2014-02-20 21:12 - 00021504 _____ () C:\Users\unknown\Desktop\SAMS JERSEY BUSINESS.xls
2014-02-21 11:46 - 2014-02-21 11:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{18F099C4-3CE5-4516-806F-E73F1F33770E}
2014-02-21 07:08 - 2012-05-05 09:08 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-20 22:09 - 2014-02-05 13:56 - 00000000 ____D () C:\Users\unknown\Desktop\Mary and Mohammad
2014-02-20 20:39 - 2014-02-20 20:39 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B2E264EE-87EE-479E-88C8-D3AFA709CA5A}
2014-02-20 16:25 - 2014-02-20 16:12 - 00000000 ____D () C:\Users\unknown\Desktop\Stephanie Vodnik
2014-02-20 08:13 - 2014-02-20 08:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{FE58155E-F2DB-4206-94D2-C076D381045C}
2014-02-19 18:42 - 2014-02-19 18:42 - 00000000 ____D () C:\Users\unknown\AppData\Local\{78E0DC29-60A3-4BDC-B96D-7589151BC609}
2014-02-19 05:51 - 2014-02-19 05:51 - 00000000 ____D () C:\Users\unknown\AppData\Local\{6F44F1E2-F261-4814-A0D5-0D559FB63055}
2014-02-18 07:19 - 2014-02-18 07:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DCD5934F-9564-4666-AD95-8BDC02E6BE98}
2014-02-17 19:19 - 2014-02-17 19:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{86C8749A-58DF-4C3A-BD14-E688182BDF44}
2014-02-17 08:05 - 2014-02-17 08:04 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-17 07:19 - 2014-02-17 07:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A9E9283D-0593-43EF-9943-D1F3E42C9CD8}
2014-02-16 09:56 - 2014-02-16 09:56 - 00000000 ____D () C:\Users\unknown\AppData\Local\{0026EF2A-4381-4248-971F-F281B13CD76A}
2014-02-15 10:33 - 2014-03-08 07:15 - 00000426 _____ () C:\AVScanner.ini
2014-02-15 07:22 - 2014-02-15 07:21 - 00000000 ____D () C:\Users\unknown\AppData\Local\{FD2DB3B0-C157-432F-BE58-343311AAECEA}
2014-02-14 07:59 - 2014-02-14 07:59 - 00000000 ____D () C:\Users\unknown\AppData\Local\{C804A8BE-2355-45AD-BEFF-CAD9EE7AEAF9}

Some content of TEMP:
====================
C:\Users\unknown\AppData\Local\temp\install_flashplayer11x32au_mssd_aih.exe
C:\Users\unknown\AppData\Local\temp\jna8022015762983612278.dll
C:\Users\unknown\AppData\Local\temp\jre-6u35-windows-i586-iftw.exe
C:\Users\unknown\AppData\Local\temp\jre-7u15-windows-i586-iftw.exe
C:\Users\unknown\AppData\Local\temp\jre-7u25-windows-i586-iftw.exe
C:\Users\unknown\AppData\Local\temp\ntdll_dump.dll
C:\Users\unknown\AppData\Local\temp\Quarantine.exe
C:\Users\unknown\AppData\Local\temp\SHSetup.exe
C:\Users\unknown\AppData\Local\temp\utt89E8.tmp.exe
C:\Users\unknown\AppData\Local\temp\utt946F.tmp.exe
C:\Users\unknown\AppData\Local\temp\uttF1A3.tmp.exe
C:\Users\unknown\AppData\Local\temp\_is492.exe
C:\Users\unknown\AppData\Local\temp\_is5FD.exe
C:\Users\unknown\AppData\Local\temp\_is8ADF.exe
C:\Users\unknown\AppData\Local\temp\_isF7E6.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-10 08:28

==================== End Of Log ============================


Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-03-2014  01
Ran by unknown at 2014-03-16 06:37:57
Running from C:\Users\unknown\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

µTorrent (HKCU\...\uTorrent) (Version: 3.4.0.30635 - BitTorrent Inc.)
Adobe AIR (HKLM\...\Adobe AIR) (Version: 2.5.1.17730 - Adobe Systems Inc.)
Adobe AIR (Version: 2.5.1.17730 - Adobe Systems Inc.) Hidden
Adobe Community Help (HKLM\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Community Help (Version: 3.0.0 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 12 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Media Player (HKLM\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Media Player (Version: 1.8 - Adobe Systems Incorporated) Hidden
Adobe Reader XI (11.0.06) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Apple Application Support (HKLM\...\{63EC2120-1742-4625-AA47-C6A8AEC9C64C}) (Version: 2.2.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}) (Version: 6.0.0.59 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft TotalMedia Extreme (HKLM\...\{A7B5F110-CE19-456D-8E45-F6D8823A793E}) (Version: 2.0.36.1 - ArcSoft)
Audio Signal Generator (HKLM\...\ToneGenHQY) (Version:  - )
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Caplio Software (HKLM\...\{5BC1F10D-6A7A-41AE-AC7C-6BD454204729}) (Version:  - )
Compatibility Pack for the 2007 Office system (HKLM\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
ConvertHelper 2.2 (HKLM\...\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1) (Version:  - DownloadHelper)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version:  - )
Free DWG Viewer 7.0 (HKLM\...\{B8B4D43C-EAA0-4EEC-B93E-D4D012316286}) (Version: 7.0.1 - IGC)
Google Earth Plug-in (HKLM\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.22.5 - Google Inc.) Hidden
High-Definition Video Playback 10 (Version: 7.0.11400.29.0 - Nero AG) Hidden
Internet TV for Windows Media Center (HKLM\...\{9D318C86-AF4C-409F-A6AC-7183FF4CF424}) (Version: 4.2.2.0 - Microsoft Corporation)
iTunes (HKLM\...\{0F6F6876-6334-4977-B5DD-CFC12E193420}) (Version: 10.7.0.21 - Apple Inc.)
Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
K-Lite Mega Codec Pack 8.4.0 (HKLM\...\KLiteCodecPack_is1) (Version: 8.4.0 - )
LightScribe System Software (HKLM\...\{82EF29B1-9B60-4142-A155-0599216DD053}) (Version: 1.18.6.1 - LightScribe)
Malwarebytes Anti-Malware version 1.75.0.1300 (HKLM\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Mesh Runtime (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Office XP Professional (HKLM\...\{90110409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft Primary Interoperability Assemblies 2005 (HKLM\...\{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.4.304.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft_VC80_ATL_x86 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC90_ATL_x86 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86 (Version: 1.00.0000 - Adobe) Hidden
Mozilla Firefox 27.0.1 (x86 en-US) (HKLM\...\Mozilla Firefox 27.0.1 (x86 en-US)) (Version: 27.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla)
MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT Redists (Version: 1.0 - Sony Creative Software Inc.) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyFreeCodec (HKCU\...\MyFreeCodec) (Version:  - )
Nero 10 Menu TemplatePack Basic (Version: 10.0.10600.6.0 - Nero AG) Hidden
Nero 10 Movie ThemePack Basic (Version: 10.0.10600.6.0 - Nero AG) Hidden
Nero BackItUp 10 (HKLM\...\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.4.11600.19.100 - Nero AG)
Nero BackItUp 10 Help (CHM) (Version: 1.0.10700 - Nero AG) Hidden
Nero Burning ROM 10 (HKLM\...\{7A5D731D-B4B3-490E-B339-75685712BAAB}) (Version: 10.0.11100.10.100 - Nero AG)
Nero BurningROM 10 Help (CHM) (Version: 1.0.10700 - Nero AG) Hidden
Nero BurnRights 10 (HKLM\...\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.0.11000.12.100 - Nero AG)
Nero BurnRights 10 Help (CHM) (Version: 1.0.10600 - Nero AG) Hidden
Nero Control Center 10 (Version: 10.0.12000.1.4 - Nero AG) Hidden
Nero ControlCenter 10 Help (CHM) (Version: 1.0.10700 - Nero AG) Hidden
Nero Core Components 10 (Version: 2.0.13700.0.1 - Nero AG) Hidden
Nero CoverDesigner 10 (HKLM\...\{FCF00A6E-FB58-477A-ABE9-232907105521}) (Version: 5.0.10900.11.100 - Nero AG)
Nero CoverDesigner 10 Help (CHM) (Version: 1.0.10600 - Nero AG) Hidden
Nero DiscCopy Gadget 10 (HKLM\...\{92EC1A84-7FFC-42DF-A8F6-79C21C4765A5}) (Version: 3.0.10700.9.100 - Nero AG)
Nero DiscCopyGadget 10 Help (CHM) (Version: 1.0.10600 - Nero AG) Hidden
Nero DiscSpeed 10 (HKLM\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.0.10800.7.100 - Nero AG)
Nero DiscSpeed 10 Help (CHM) (Version: 1.0.10600 - Nero AG) Hidden
Nero Dolby Files 10 (Version: 2.0.11000.0.10 - Nero AG) Hidden
Nero Express 10 (HKLM\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.0.11000.10.100 - Nero AG)
Nero Express 10 Help (CHM) (Version: 1.0.10700 - Nero AG) Hidden
Nero InfoTool 10 (HKLM\...\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.0.10800.8.100 - Nero AG)
Nero InfoTool 10 Help (CHM) (Version: 1.0.10600 - Nero AG) Hidden
Nero MediaHub 10 (HKLM\...\{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}) (Version: 1.0.13400.11.100 - Nero AG)
Nero MediaHub 10 Help (CHM) (Version: 1.0.10700 - Nero AG) Hidden
Nero Multimedia Suite 10 (HKLM\...\{277C1559-4CF7-44FF-8D07-98AA9C13AABD}) (Version: 10.0.13100 - Nero AG)
Nero Recode 10 (HKLM\...\{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}) (Version: 4.6.10900.4.100 - Nero AG)
Nero Recode 10 Help (CHM) (Version: 1.0.10600 - Nero AG) Hidden
Nero RescueAgent 10 (HKLM\...\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.0.10900.9.100 - Nero AG)
Nero RescueAgent 10 Help (CHM) (Version: 1.0.10700 - Nero AG) Hidden
Nero SoundTrax 10 (HKLM\...\{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}) (Version: 4.6.10600.2.100 - Nero AG)
Nero SoundTrax 10 Help (CHM) (Version: 1.0.10600 - Nero AG) Hidden
Nero StartSmart 10 (HKLM\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.0.11200.12.100 - Nero AG)
Nero StartSmart 10 Help (CHM) (Version: 1.0.10700 - Nero AG) Hidden
Nero Update (HKLM\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0017 - Nero AG)
Nero Vision 10 (HKLM\...\{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}) (Version: 7.0.11100.8.100 - Nero AG)
Nero Vision 10 Help (CHM) (Version: 1.0.10600 - Nero AG) Hidden
Nero WaveEditor 10 (HKLM\...\{EDCDFAD5-DF80-4600-A493-E9DAD6810230}) (Version: 5.6.10600.2.100 - Nero AG)
Nero WaveEditor 10 Help (CHM) (Version: 1.0.10600 - Nero AG) Hidden
NetComm 900n Series Wireless LAN (HKLM\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.0.2.0 - NetComm)
Orb Runtime libraries (Version: 1.0.0 - Orb Networks, Inc.) Hidden
PIXresizer 2.0.4 (HKLM\...\PIXresizer_is1) (Version:  - Bluefive software)
Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.1.1.11124_17 - Samsung Electronics Co., Ltd.)
Samsung Kies (Version: 2.1.1.11124_17 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.6.0 - SAMSUNG Electronics Co., Ltd.)
Speccy (HKLM\...\Speccy) (Version: 1.25 - Piriform)
TradeManager 2011 SP2 (HKLM\...\TradeManager 2011 SP2) (Version:  - Alisoft)
Unity Web Player (HKCU\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
VLC media player 1.1.11 (HKLM\...\VLC media player) (Version: 1.1.11 - VideoLAN)
WBFS Manager 3.0 (HKLM\...\WBFS Manager 3.0) (Version: 3.0 - AlexDP)
Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net  (09/10/2009 02.03.05.012) (HKLM\...\8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D) (Version: 09/10/2009 02.03.05.012 - Leapfrog)
Windows Live Communications Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Essentials (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mail (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX Control for Remote Connections (HKLM\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Messenger Companion Core (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
Windows Movie Maker 2.6 (HKLM\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation)
WinRAR 4.00 (32-bit) (HKLM\...\WinRAR archiver) (Version: 4.00.0 - win.rar GmbH)
Xiph.Org Open Codecs 0.85.17777 (HKLM\...\Open Codecs) (Version: 0.85.17777 - Xiph.Org)

==================== Restore Points  =========================

02-03-2014 04:38:41 Windows Update
03-03-2014 19:50:44 Installed Java 7 Update 51
06-03-2014 01:41:34 Windows Update
09-03-2014 04:13:41 Windows Update
11-03-2014 22:24:29 Windows Update
13-03-2014 16:00:45 Windows Update
14-03-2014 05:20:59 Removed MFL-Pro Suite

==================== Hosts content: ==========================

2009-07-14 13:04 - 2012-04-19 10:43 - 00000027 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {09A7252E-3A04-4B24-A726-C4FB6A4A0CE4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-08-29] (Google Inc.)
Task: {268494F2-BD07-4065-941B-ABB4305D0D59} - System32\Tasks\Microsoft\Windows\Media Center\Extender\Update media permissions for Mcx1-UNKNOWN-PC => C:\Windows\ehome\McxTask.exe [2009-07-14] (Microsoft Corporation)
Task: {4BC2A903-69D3-4312-BBF2-D69981756908} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated)
Task: {5E964BD1-2C12-4285-A0CF-338CFFC79B71} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {E325C764-AC5A-4D1B-B75D-6E2DE1BC2D59} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-08-29] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-09-27 07:23 - 2011-09-27 07:23 - 00087912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2011-09-27 07:22 - 2011-09-27 07:22 - 01242472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2011-04-22 19:23 - 2011-03-02 13:40 - 00140288 _____ () C:\Program Files\WinRAR\rarext.dll
2009-06-17 12:40 - 2009-06-17 12:40 - 02121728 _____ () C:\Program Files\Common Files\LightScribe\QtCore4.dll
2009-06-17 12:40 - 2009-06-17 12:40 - 07745536 _____ () C:\Program Files\Common Files\LightScribe\QtGui4.dll
2009-06-17 12:40 - 2009-06-17 12:40 - 00135168 _____ () C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
2011-12-27 23:21 - 2012-07-16 15:24 - 00021432 _____ () C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
2012-07-30 19:38 - 2012-07-30 19:38 - 00115137 _____ () C:\Users\unknown\AppData\Local\Temp\99cab429-f99d-4f69-9d04-113ad532bd0f\CliSecureRT.dll
2011-03-28 16:30 - 2004-05-11 11:38 - 00061952 _____ () C:\Program Files\Caplio Software\zlib.dll
2014-02-17 08:04 - 2014-02-17 08:04 - 03578992 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:ADF211B1
AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2

==================== Safe Mode (whitelisted) ===================


==================== Disabled items from MSCONFIG ==============


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (03/15/2014 03:06:01 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15584

Error: (03/15/2014 03:06:01 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15584

Error: (03/15/2014 03:06:01 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (03/15/2014 02:46:49 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "Microsoft.VC80.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"1".Error in manifest or policy file "Microsoft.VC80.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"2" on line Microsoft.VC80.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"3.
Component identity found in manifest does not match the identity of the component requested.
Reference is Microsoft.VC80.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762".
Definition is Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762".
Please use sxstrace.exe for detailed diagnosis.

Error: (03/14/2014 05:08:22 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15600

Error: (03/14/2014 05:08:22 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15600

Error: (03/14/2014 05:08:22 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (03/14/2014 04:25:18 PM) (Source: Application Error) (User: )
Description: Faulting application name: firefox.exe, version: 27.0.1.5156, time stamp: 0x52fc0faa
Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea91c
Exception code: 0xc0000374
Fault offset: 0x000c3873
Faulting process id: 0x1230
Faulting application start time: 0xfirefox.exe0
Faulting application path: firefox.exe1
Faulting module path: firefox.exe2
Report Id: firefox.exe3

Error: (03/14/2014 04:20:50 PM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.


Operation:
   Gathering Writer Data

Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {810341ab-a97e-4aca-a6ca-138e43f3b4b0}

Error: (03/14/2014 04:19:01 PM) (Source: Application Error) (User: )
Description: Faulting application name: firefox.exe, version: 27.0.1.5156, time stamp: 0x52fc0faa
Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea91c
Exception code: 0xc0000374
Fault offset: 0x000c3873
Faulting process id: 0x934
Faulting application start time: 0xfirefox.exe0
Faulting application path: firefox.exe1
Faulting module path: firefox.exe2
Report Id: firefox.exe3


System errors:
=============
Error: (03/14/2014 04:34:45 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

    New Signature Version: 1.167.1923.0

    Previous Signature Version: 1.167.1811.0

    Update Source: %NT AUTHORITY15

    Update Stage: 4.4.0304.00

    Source Path: 4.4.0304.01

    Signature Type: %NT AUTHORITY602

    Update Type: %NT AUTHORITY604

    User: NT AUTHORITY\SYSTEM

    Current Engine Version: %NT AUTHORITY605

    Previous Engine Version: %NT AUTHORITY606

    Error code: %NT AUTHORITY607

    Error description: %NT AUTHORITY608

Error: (03/14/2014 04:22:52 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.167.1811.0

    Update Source: %NT AUTHORITY59

    Update Stage: 4.4.0304.00

    Source Path: 4.4.0304.01

    Signature Type: %NT AUTHORITY602

    Update Type: %NT AUTHORITY604

    User: NT AUTHORITY\SYSTEM

    Current Engine Version: %NT AUTHORITY605

    Previous Engine Version: %NT AUTHORITY606

    Error code: %NT AUTHORITY607

    Error description: %NT AUTHORITY608

Error: (03/14/2014 04:22:46 PM) (Source: DCOM) (User: )
Description: {3EB3C877-1F16-487C-9050-104DBCD66683}

Error: (03/14/2014 04:22:34 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (03/14/2014 04:09:50 PM) (Source: Service Control Manager) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the IPBusEnum service.

Error: (03/14/2014 03:22:56 AM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (03/12/2014 09:35:41 AM) (Source: DCOM) (User: )
Description: {3EB3C877-1F16-487C-9050-104DBCD66683}

Error: (03/12/2014 09:35:30 AM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (03/11/2014 05:05:47 PM) (Source: DCOM) (User: )
Description: {3EB3C877-1F16-487C-9050-104DBCD66683}

Error: (03/11/2014 03:30:21 PM) (Source: DCOM) (User: )
Description: {3EB3C877-1F16-487C-9050-104DBCD66683}


Microsoft Office Sessions:
=========================
Error: (03/15/2014 03:06:01 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15584

Error: (03/15/2014 03:06:01 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15584

Error: (03/15/2014 03:06:01 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (03/15/2014 02:46:49 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"c:\program files\trademanager\wwst64.exec:\program files\trademanager\Microsoft.VC80.CRT.MANIFEST4

Error: (03/14/2014 05:08:22 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15600

Error: (03/14/2014 05:08:22 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15600

Error: (03/14/2014 05:08:22 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (03/14/2014 04:25:18 PM) (Source: Application Error)(User: )
Description: firefox.exe27.0.1.515652fc0faantdll.dll6.1.7601.18247521ea91cc0000374000c3873123001cf3f45c3a4174dC:\Program Files\Mozilla Firefox\firefox.exeC:\Windows\SYSTEM32\ntdll.dll070dc867-ab39-11e3-982b-001fd0d9f5b8

Error: (03/14/2014 04:20:50 PM) (Source: VSS)(User: )
Description: 0x80070005, Access is denied.


Operation:
   Gathering Writer Data

Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {810341ab-a97e-4aca-a6ca-138e43f3b4b0}

Error: (03/14/2014 04:19:01 PM) (Source: Application Error)(User: )
Description: firefox.exe27.0.1.515652fc0faantdll.dll6.1.7601.18247521ea91cc0000374000c387393401cf3f44e1b9e366C:\Program Files\Mozilla Firefox\firefox.exeC:\Windows\SYSTEM32\ntdll.dll26d21f70-ab38-11e3-b00e-001fd0d9f5b8


CodeIntegrity Errors:
===================================
  Date: 2011-10-08 12:53:35.786
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Spyware Doctor\klg.dat because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-08 12:53:35.724
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Spyware Doctor\smumhook.dll because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-08 12:40:51.564
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Spyware Doctor\klg.dat because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-08 12:40:51.517
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Spyware Doctor\smumhook.dll because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-08 12:34:32.308
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Spyware Doctor\klg.dat because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-08 12:34:32.261
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Spyware Doctor\smumhook.dll because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-08 12:28:13.216
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Spyware Doctor\klg.dat because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-08 12:28:13.185
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Spyware Doctor\smumhook.dll because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-08 12:13:29.044
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Spyware Doctor\klg.dat because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-08 12:13:28.993
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Spyware Doctor\smumhook.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 55%
Total physical RAM: 1790.49 MB
Available physical RAM: 796.75 MB
Total Pagefile: 3580.98 MB
Available Pagefile: 1939.36 MB
Total Virtual: 2047.88 MB
Available Virtual: 1894.88 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:298.09 GB) (Free:210.56 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: () (Fixed) (Total:465.76 GB) (Free:206.95 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 5F96A20B)
Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: D0B92625)

Partition: GPT Partition Type.

==================== End Of Log ============================



#5 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:34 AM

Posted 15 March 2014 - 02:56 PM

All right, now let's delete the malware.
How is your computer running after the following fix?


Step 1

Please download this attached Attached File  fixlist.txt   875bytes   3 downloads and save it in the same directory as FRST.

  • Start FRST with Administrator privileges.
  • Press the Fix button. Allow a reboot if requested.
  • When finished, a log file (Fixlog.txt) pops up and is saved to the same location the tool was run from.
    Please copy and paste its contents in your next reply.

 

 

 

Step 2

Start FRST with administator privileges.

  • Press the Scan button.
  • When finished, FRST will produce a log (FRST.txt) in the same directory the tool was run from.
    Please copy and paste this log in your next reply.


#6 Aurifex

Aurifex
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:12:34 PM

Posted 16 March 2014 - 05:03 PM

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014  01
Ran by unknown at 2014-03-17 08:48:06 Run:1
Running from C:\Users\unknown\Downloads
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
HKLM\...\Run: [lkebutoh] - C:\ProgramData\ofjz\ecuwofez.exe [258048 2014-03-14] ()
AppInit_DLLs: C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll File Not Found
2014-03-14 03:00 - 2014-03-14 03:00 - 00000000 ____D () C:\ProgramData\ofjz
2014-03-10 16:37 - 2014-03-14 03:00 - 00000000 ____D () C:\ProgramData\ebdc
2014-03-08 07:14 - 2014-03-10 16:37 - 00000000 ____D () C:\ProgramData\iflr
2014-03-04 12:44 - 2014-03-08 07:14 - 00000000 ____D () C:\ProgramData\ilin
2014-03-03 14:04 - 2014-03-04 12:43 - 00000000 ____D () C:\ProgramData\inyv
2014-03-03 13:18 - 2014-03-14 16:24 - 00000000 ____D () C:\ProgramData\amepugyf
2014-03-03 13:18 - 2014-03-03 14:04 - 00000000 ____D () C:\ProgramData\yqyc
C:\Users\unknown\AppData\Local\temp\*.dll
C:\Users\unknown\AppData\Local\temp\*.exe
Reboot:
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\lkebutoh => Value deleted successfully.
"C:\\PROGRA~1\\SearchProtect\\SearchProtect\\bin\\SPVC32Loader.dll" => Value Data removed successfully.
C:\ProgramData\ofjz => Moved successfully.
C:\ProgramData\ebdc => Moved successfully.
C:\ProgramData\iflr => Moved successfully.
C:\ProgramData\ilin => Moved successfully.
C:\ProgramData\inyv => Moved successfully.

"C:\ProgramData\amepugyf" directory move:

C:\ProgramData\amepugyf\ahevfxec.dat => Moved successfully.
C:\ProgramData\amepugyf\amuzafys.dat => Moved successfully.
C:\ProgramData\amepugyf\apprijyg.dat => Moved successfully.
C:\ProgramData\amepugyf\ibiquqok.dat => Moved successfully.
Could not move "C:\ProgramData\amepugyf\omifaheb.dat" => Scheduled to move on reboot.
C:\ProgramData\amepugyf\qjublryg.dat => Moved successfully.
C:\ProgramData\amepugyf\udjqotat.dat => Moved successfully.
C:\ProgramData\amepugyf\ulyzosyl.dat => Moved successfully.
Could not move "C:\ProgramData\amepugyf" directory. => Scheduled to move on reboot.

C:\ProgramData\yqyc => Moved successfully.
C:\Users\unknown\AppData\Local\temp\*.dll => Moved successfully.
C:\Users\unknown\AppData\Local\temp\*.exe => Moved successfully.

=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-03-17 08:52:12)<=

C:\ProgramData\amepugyf\omifaheb.dat => Is moved successfully.
C:\ProgramData\amepugyf => Moved successfully.

==== End of Fixlog ====


Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014  01
Ran by unknown (administrator) on UNKNOWN-PC on 17-03-2014 08:59:20
Running from C:\Users\unknown\Downloads
Microsoft Windows 7 Ultimate  Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Ralink Technology, Corp.) C:\Program Files\NetComm\Common\RegistryWriter.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Nero AG) C:\Program Files\Nero\Update\NASvc.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Nero AG) C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
() C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(NetComm Limited) C:\Program Files\NetComm\Common\RaUI.exe
(Ricoh Company, Ltd.) C:\Program Files\Caplio Software\RGateLXP.exe
(Piriform Ltd) C:\Program Files\Speccy\Speccy.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Windows Live\Mail\wlmail.exe
(Microsoft Corporation) C:\Program Files\Windows Live\Contacts\wlcomm.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MpCmdRun.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [BrMfcWnd] - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
HKLM\...\Run: [NBAgent] - C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1234216 2010-03-26] (Nero AG)
HKLM\...\Run: [ArcSoft Connection Service] - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-08-27] (Apple Inc.)
HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [3524536 2012-07-16] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [421776 2012-09-10] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM\...\Run: [ofrzutuz] - C:\ProgramData\ypmj\aqajsvid.exe [258048 2014-03-17] ()
HKLM\...\Run: [ykdhyved] - C:\ProgramData\ixem\umozufes.exe [258048 2014-03-17] ()
HKU\S-1-5-21-2134969444-2299796119-3524533687-1000\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-06-17] (Hewlett-Packard Company)
HKU\S-1-5-21-2134969444-2299796119-3524533687-1000\...\Run: [KiesPDLR] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-07-16] ()
HKU\S-1-5-21-2134969444-2299796119-3524533687-1000\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [975800 2012-07-16] (Samsung)
HKU\S-1-5-21-2134969444-2299796119-3524533687-1000\...\Run: [News.net] - C:\Program Files\News.net\BreakingNews\DesktopContainer.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x495B2F24C440CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://iat.ninemsn.com.au/tickler/default.aspx?ocid=iehp
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {CD280D45-1C29-4E80-A506-D88F2ED4760C} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=9B874255-7D2C-47B9-97A1-9D9D5F6C44C1&apn_sauid=2B80A8AE-C505-44AC-B0EB-3E4E4063A8F8
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File
Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\unknown\AppData\Roaming\Mozilla\Firefox\Profiles\cr4c0zm7.default-1394486327657
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @alibaba.com/npwangwang;version=1.0 - C:\Program Files\Trademanager\npwangwang.dll ( )
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @pages.tvunetworks.com/WebPlayer - C:\Users\unknown\Desktop\TVUPlayer\npTVUAx.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @alibaba.com/npAliSSOLogin;version=1.0 - C:\Program Files\Trademanager\npAliSSOLogin.dll (Alibaba software (Shanghai) Corporation.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\unknown\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwangwang.dll ( )

Chrome:
=======
CHR HomePage: hxxp://www.news.net/index.php?referid=125

========================== Services (Whitelisted) =================

R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [490280 2010-03-25] (Nero AG)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 RalinkRegistryWriter; C:\Program Files\NetComm\Common\RegistryWriter.exe [69632 2008-05-13] (Ralink Technology, Corp.)

==================== Drivers (Whitelisted) ====================

S3 61883; C:\Windows\System32\DRIVERS\61883.sys [46976 2009-07-14] (Microsoft Corporation)
S3 bqusbser; C:\Windows\System32\DRIVERS\Mousbser.sys [103936 2008-05-22] (Motorola Incorporated)
R2 Hardlock; C:\Windows\system32\drivers\hardlock.sys [685056 2005-07-28] (Aladdin Knowledge Systems Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
R1 MpKsl070720a0; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{21E2CE18-A0FD-4236-AAE4-D355A272C7C9}\MpKsl070720a0.sys [39464 2014-03-17] (Microsoft Corporation)
S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [657408 2009-07-14] (Ralink Technology Corp.)
S3 catchme; \??\C:\Users\unknown\AppData\Local\Temp\catchme.sys [X]
R3 cpuz136; \??\C:\Users\unknown\AppData\Local\Temp\cpuz136\cpuz136_x32.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-17 08:52 - 2014-03-17 08:52 - 00000000 ____D () C:\ProgramData\ixem
2014-03-17 08:52 - 2014-03-17 08:52 - 00000000 ____D () C:\ProgramData\amepugyf
2014-03-17 08:48 - 2014-03-17 08:48 - 00000000 ____D () C:\ProgramData\ypmj
2014-03-17 08:25 - 2014-03-17 08:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\{7EE084DF-8CA9-4041-A5EE-97D4E5342390}
2014-03-16 18:02 - 2014-03-16 18:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{5631B219-0285-4AE6-A2C9-F746D7221D87}
2014-03-16 06:14 - 2014-03-16 06:38 - 00029196 _____ () C:\Users\unknown\Downloads\Addition.txt
2014-03-16 06:12 - 2014-03-17 08:59 - 00012322 _____ () C:\Users\unknown\Downloads\FRST.txt
2014-03-16 06:12 - 2014-03-17 08:59 - 00000000 ____D () C:\FRST
2014-03-16 06:11 - 2014-03-16 06:11 - 01145856 _____ (Farbar) C:\Users\unknown\Downloads\FRST.exe
2014-03-16 06:04 - 2014-03-16 06:04 - 04130656 _____ (Kaspersky Lab ZAO) C:\Users\unknown\Downloads\tdsskiller.exe
2014-03-16 06:02 - 2014-03-16 06:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{72275A55-063E-4860-BAEE-9ABBD9080EED}
2014-03-15 07:59 - 2014-03-15 07:59 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D8090C2D-71FD-481E-AB68-1FBC0756BA3A}
2014-03-14 16:34 - 2014-03-14 16:35 - 00000000 ____D () C:\Users\unknown\Desktop\New help
2014-03-14 16:33 - 2014-03-14 16:33 - 00021764 _____ () C:\Users\unknown\Desktop\dds.txt
2014-03-14 16:33 - 2014-03-14 16:33 - 00006187 _____ () C:\Users\unknown\Desktop\attach.txt
2014-03-14 16:30 - 2014-03-14 16:30 - 00688992 ____R (Swearware) C:\Users\unknown\Downloads\dds.com
2014-03-14 16:10 - 2014-03-14 16:10 - 00000000 ____D () C:\Users\unknown\AppData\Local\{22417392-7AD2-419B-9A6E-E56B23C6F117}
2014-03-14 03:00 - 2014-03-14 03:00 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B831E33C-181D-4798-99D1-47DC39FA776B}
2014-03-13 11:22 - 2014-03-01 15:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-13 11:22 - 2014-03-01 15:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-13 11:22 - 2014-03-01 15:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-13 11:22 - 2014-03-01 14:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-13 11:22 - 2014-03-01 14:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-13 11:22 - 2014-03-01 14:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-13 11:22 - 2014-03-01 14:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-13 11:22 - 2014-03-01 14:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-13 11:22 - 2014-03-01 14:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-13 11:22 - 2014-03-01 14:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-13 11:22 - 2014-03-01 14:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-13 11:22 - 2014-03-01 14:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-13 11:22 - 2014-03-01 14:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-13 11:22 - 2014-03-01 14:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-13 11:22 - 2014-03-01 14:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-13 11:22 - 2014-03-01 14:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-13 11:22 - 2014-03-01 14:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-13 11:22 - 2014-03-01 14:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-13 11:22 - 2014-03-01 13:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-13 11:22 - 2014-03-01 13:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-13 11:22 - 2014-03-01 13:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-13 11:22 - 2014-03-01 13:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-13 11:22 - 2014-02-04 13:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-13 11:20 - 2014-02-07 12:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-13 11:20 - 2014-02-04 13:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-13 11:20 - 2014-01-29 13:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-13 11:20 - 2014-01-28 13:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-13 11:20 - 2014-01-09 13:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-03-13 08:19 - 2014-03-13 08:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{58513ECF-F5D2-44E5-9F4C-9A0CBDF45CC6}
2014-03-12 09:26 - 2013-10-02 11:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-03-12 09:26 - 2013-10-02 11:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-03-12 09:26 - 2013-10-02 10:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-03-12 09:26 - 2012-08-24 01:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-03-12 09:26 - 2012-08-24 01:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-03-12 09:26 - 2012-08-24 00:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-03-12 09:26 - 2012-08-23 22:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-03-12 09:26 - 2012-08-23 21:08 - 02739712 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-03-12 09:25 - 2013-10-02 11:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-03-12 09:25 - 2013-10-02 11:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-03-12 09:25 - 2013-10-02 11:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-03-12 09:25 - 2013-10-02 10:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-03-12 09:25 - 2013-10-02 10:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-03-12 09:25 - 2013-10-02 10:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-03-12 09:25 - 2013-10-02 09:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-03-12 09:25 - 2013-10-02 09:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-03-12 09:24 - 2013-09-25 12:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-03-12 09:24 - 2012-05-04 20:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-03-12 09:19 - 2014-03-12 09:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F96658A8-FAF7-4C1D-86ED-1C0CEFDA33BE}
2014-03-11 20:57 - 2014-03-11 20:57 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3CBA1460-F382-4ECA-BC06-C439939ADE7C}
2014-03-11 16:45 - 2014-03-11 16:45 - 00000941 _____ () C:\Users\Public\Desktop\Speccy.lnk
2014-03-11 16:45 - 2014-03-11 16:45 - 00000000 ____D () C:\Program Files\Speccy
2014-03-11 16:45 - 2014-03-11 16:42 - 04845384 _____ (Piriform Ltd) C:\Users\unknown\Desktop\spsetup125.exe
2014-03-11 14:30 - 2014-03-11 14:30 - 00000035 _____ () C:\Users\unknown\Desktop\eset.txt
2014-03-11 11:45 - 2014-03-11 11:45 - 00000000 ____D () C:\Program Files\ESET
2014-03-11 11:25 - 2014-03-11 11:25 - 00027544 _____ () C:\Users\unknown\Desktop\Result.txt
2014-03-11 11:24 - 2014-03-11 11:24 - 00000854 _____ () C:\Users\unknown\Desktop\checkup.txt
2014-03-11 08:27 - 2014-03-11 08:27 - 00001071 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-11 08:27 - 2014-03-11 08:27 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-11 08:27 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-11 08:18 - 2014-03-11 08:18 - 00000000 ____D () C:\Users\unknown\Desktop\Old Firefox Data
2014-03-11 07:46 - 2014-03-11 07:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{824DB67E-2AF1-4AB3-B831-9599F9BFBA69}
2014-03-10 19:46 - 2014-03-10 19:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{480D26A8-315E-4F8A-99F9-64C14003FA5E}
2014-03-10 07:43 - 2014-03-10 07:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CBF052D1-D3A3-4F18-BAE7-9B7CD75C2A6C}
2014-03-08 19:30 - 2014-03-17 08:55 - 00000000 ____D () C:\Users\unknown\AppData\Local\CrashDumps
2014-03-08 19:30 - 2014-03-09 14:57 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A88AE5B2-ABEB-4965-B22F-71157B3D3010}
2014-03-08 07:15 - 2014-02-15 10:33 - 00000426 _____ () C:\AVScanner.ini
2014-03-08 07:12 - 2014-03-08 07:12 - 00000855 _____ () C:\Users\unknown\Desktop\µTorrent.lnk
2014-03-08 07:09 - 2014-03-08 07:10 - 01853008 _____ (BitTorrent Inc.) C:\Users\unknown\Downloads\uTorrent.exe
2014-03-08 07:06 - 2014-03-08 07:06 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D96128E7-775A-4D37-96E2-8E5A5750BEC2}
2014-03-07 12:44 - 2014-03-07 13:05 - 00000000 ____D () C:\Users\unknown\Desktop\GARAGE BUILDING DOCS
2014-03-07 10:13 - 2014-03-07 10:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F9AAEE8B-864D-4ACD-9F94-7F0FCF0559E7}
2014-03-06 09:03 - 2014-03-06 09:03 - 03819008 _____ () C:\Users\unknown\Downloads\RogueKiller.exe
2014-03-06 09:02 - 2014-03-06 09:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DE030B0A-6BE1-4FDF-A1FF-1B6262C897A8}
2014-03-05 19:44 - 2014-03-05 19:44 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E56DB46F-396F-4167-85EE-422A02FE158C}
2014-03-05 07:47 - 2014-03-05 07:48 - 00380416 _____ () C:\Users\unknown\Downloads\jh0vxwq9.exe
2014-03-05 07:43 - 2014-03-05 07:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{937EBBB1-75AC-416B-8518-6FFDD411C514}
2014-03-04 11:17 - 2014-03-04 11:17 - 02347384 _____ (ESET) C:\Users\unknown\Desktop\esetsmartinstaller_enu.exe
2014-03-04 07:40 - 2014-03-04 07:40 - 00144400 _____ () C:\Windows\Minidump\030414-21933-01.dmp
2014-03-04 06:53 - 2014-03-04 06:53 - 00000000 ____D () C:\ProgramData\Oracle
2014-03-04 06:52 - 2014-03-04 06:52 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-03-04 06:52 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-03-04 06:52 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-03-04 06:52 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-03-04 06:52 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-03-04 06:51 - 2014-03-04 06:52 - 00005822 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-03-04 06:43 - 2014-03-04 06:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{8445ED36-709F-489C-8A19-08FA29853D50}
2014-03-03 17:17 - 2014-03-03 17:17 - 00144400 _____ () C:\Windows\Minidump\030314-23181-01.dmp
2014-03-03 16:19 - 2014-03-03 16:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CE1B8D22-0818-46C6-B5C6-5ABD7F0F53A1}
2014-03-03 14:44 - 2014-03-03 14:46 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\unknown\Desktop\mbam-setup.exe
2014-03-03 14:40 - 2014-03-03 14:40 - 00982016 _____ (Farbar) C:\Users\unknown\Desktop\MiniToolBox.exe
2014-03-03 14:35 - 2014-03-03 14:35 - 00987425 _____ () C:\Users\unknown\Desktop\SecurityCheck.exe
2014-03-03 04:19 - 2014-03-03 04:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{C8553F1C-DCC3-4186-81AC-D59DC80B7754}
2014-03-02 08:22 - 2014-03-02 08:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{7988F25E-42D5-483F-8C31-AA7B00BB8350}
2014-03-01 08:53 - 2014-03-01 08:54 - 00000000 ____D () C:\Users\unknown\AppData\Local\{76D4D32B-9E1E-4329-9BDD-16DD7866C0E9}
2014-02-28 06:52 - 2014-02-28 06:52 - 00000000 ____D () C:\Users\unknown\AppData\Local\{12C0B45D-95EB-4F40-8055-5988414D1F2A}
2014-02-27 07:35 - 2014-02-27 07:35 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D95EA739-1005-4962-8FE2-6DC10B269C6C}
2014-02-26 08:11 - 2014-02-26 08:11 - 00000000 ____D () C:\Users\unknown\AppData\Local\{4A52383B-9DA4-4D77-8997-3635B681EF21}
2014-02-25 18:25 - 2014-02-25 18:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D6B27FDB-5D94-4B77-929F-CD800B3BBD30}
2014-02-25 07:14 - 2014-02-25 07:28 - 00000000 ____D () C:\Users\unknown\Desktop\2014-02-25 Stephanies Jewellery resell
2014-02-25 06:22 - 2014-02-25 06:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E5CAC627-E354-4FFA-B81B-40B990A40CF8}
2014-02-24 17:49 - 2014-02-24 17:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{414E4E6C-C6CE-42E7-8CF4-26CF6F52FE1A}
2014-02-24 05:49 - 2014-02-24 05:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A0A0B8AF-CB9C-44E5-B043-D982A1548B56}
2014-02-23 05:52 - 2014-02-23 05:53 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A2C20AE5-2970-4901-8E5F-28854CF0719C}
2014-02-22 16:55 - 2014-02-22 16:56 - 00263680 _____ () C:\Users\unknown\Desktop\Irrigation Solution Questionnaire.xls
2014-02-22 16:30 - 2014-02-22 16:31 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3B0DA881-2B59-4EC3-B6FE-7A4AE0C68BAF}
2014-02-21 11:46 - 2014-02-21 11:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{18F099C4-3CE5-4516-806F-E73F1F33770E}
2014-02-20 21:12 - 2014-02-21 17:51 - 00021504 _____ () C:\Users\unknown\Desktop\SAMS JERSEY BUSINESS.xls
2014-02-20 20:39 - 2014-02-20 20:39 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B2E264EE-87EE-479E-88C8-D3AFA709CA5A}
2014-02-20 16:12 - 2014-02-20 16:25 - 00000000 ____D () C:\Users\unknown\Desktop\Stephanie Vodnik
2014-02-20 08:13 - 2014-02-20 08:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{FE58155E-F2DB-4206-94D2-C076D381045C}
2014-02-19 18:42 - 2014-02-19 18:42 - 00000000 ____D () C:\Users\unknown\AppData\Local\{78E0DC29-60A3-4BDC-B96D-7589151BC609}
2014-02-19 05:51 - 2014-02-19 05:51 - 00000000 ____D () C:\Users\unknown\AppData\Local\{6F44F1E2-F261-4814-A0D5-0D559FB63055}
2014-02-18 07:19 - 2014-02-18 07:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DCD5934F-9564-4666-AD95-8BDC02E6BE98}
2014-02-17 19:19 - 2014-02-17 19:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{86C8749A-58DF-4C3A-BD14-E688182BDF44}
2014-02-17 08:04 - 2014-02-17 08:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-17 07:19 - 2014-02-17 07:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A9E9283D-0593-43EF-9943-D1F3E42C9CD8}
2014-02-16 09:56 - 2014-02-16 09:56 - 00000000 ____D () C:\Users\unknown\AppData\Local\{0026EF2A-4381-4248-971F-F281B13CD76A}
2014-02-15 07:21 - 2014-02-15 07:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{FD2DB3B0-C157-432F-BE58-343311AAECEA}

==================== One Month Modified Files and Folders =======

2014-03-17 08:59 - 2014-03-16 06:12 - 00012322 _____ () C:\Users\unknown\Downloads\FRST.txt
2014-03-17 08:59 - 2014-03-16 06:12 - 00000000 ____D () C:\FRST
2014-03-17 08:56 - 2012-04-01 17:58 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-17 08:56 - 2009-07-14 15:34 - 00014416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-17 08:56 - 2009-07-14 15:34 - 00014416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-17 08:55 - 2014-03-08 19:30 - 00000000 ____D () C:\Users\unknown\AppData\Local\CrashDumps
2014-03-17 08:53 - 2011-03-16 10:13 - 01924322 _____ () C:\Windows\WindowsUpdate.log
2014-03-17 08:52 - 2014-03-17 08:52 - 00000000 ____D () C:\ProgramData\ixem
2014-03-17 08:52 - 2014-03-17 08:52 - 00000000 ____D () C:\ProgramData\amepugyf
2014-03-17 08:52 - 2011-10-29 20:10 - 00000000 ____D () C:\ProgramData\Sun
2014-03-17 08:49 - 2011-12-03 09:54 - 08405015 _____ () C:\Windows\TempFile
2014-03-17 08:49 - 2011-08-29 11:55 - 00000884 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-17 08:49 - 2011-03-17 01:23 - 00164338 _____ () C:\Windows\PFRO.log
2014-03-17 08:49 - 2009-07-14 15:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-17 08:49 - 2009-07-14 15:39 - 00134811 _____ () C:\Windows\setupact.log
2014-03-17 08:48 - 2014-03-17 08:48 - 00000000 ____D () C:\ProgramData\ypmj
2014-03-17 08:25 - 2014-03-17 08:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\{7EE084DF-8CA9-4041-A5EE-97D4E5342390}
2014-03-17 08:25 - 2011-08-29 11:55 - 00000888 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-16 18:02 - 2014-03-16 18:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{5631B219-0285-4AE6-A2C9-F746D7221D87}
2014-03-16 17:06 - 2011-03-16 10:23 - 00782510 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-16 06:38 - 2014-03-16 06:14 - 00029196 _____ () C:\Users\unknown\Downloads\Addition.txt
2014-03-16 06:11 - 2014-03-16 06:11 - 01145856 _____ (Farbar) C:\Users\unknown\Downloads\FRST.exe
2014-03-16 06:04 - 2014-03-16 06:04 - 04130656 _____ (Kaspersky Lab ZAO) C:\Users\unknown\Downloads\tdsskiller.exe
2014-03-16 06:02 - 2014-03-16 06:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{72275A55-063E-4860-BAEE-9ABBD9080EED}
2014-03-15 15:05 - 2011-03-26 13:00 - 00000000 ____D () C:\Users\unknown\AppData\Roaming\uTorrent
2014-03-15 07:59 - 2014-03-15 07:59 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D8090C2D-71FD-481E-AB68-1FBC0756BA3A}
2014-03-14 16:35 - 2014-03-14 16:34 - 00000000 ____D () C:\Users\unknown\Desktop\New help
2014-03-14 16:33 - 2014-03-14 16:33 - 00021764 _____ () C:\Users\unknown\Desktop\dds.txt
2014-03-14 16:33 - 2014-03-14 16:33 - 00006187 _____ () C:\Users\unknown\Desktop\attach.txt
2014-03-14 16:30 - 2014-03-14 16:30 - 00688992 ____R (Swearware) C:\Users\unknown\Downloads\dds.com
2014-03-14 16:21 - 2013-08-05 11:39 - 00000000 ____D () C:\Program Files\Brother
2014-03-14 16:10 - 2014-03-14 16:10 - 00000000 ____D () C:\Users\unknown\AppData\Local\{22417392-7AD2-419B-9A6E-E56B23C6F117}
2014-03-14 11:28 - 2009-07-14 13:37 - 00000000 ____D () C:\Windows\rescache
2014-03-14 03:28 - 2009-07-14 15:33 - 03692064 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-14 03:27 - 2011-06-13 11:57 - 00000362 __RSH () C:\ProgramData\ntuser.pol
2014-03-14 03:26 - 2011-03-16 15:53 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-14 03:00 - 2014-03-14 03:00 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B831E33C-181D-4798-99D1-47DC39FA776B}
2014-03-13 08:19 - 2014-03-13 08:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{58513ECF-F5D2-44E5-9F4C-9A0CBDF45CC6}
2014-03-12 09:56 - 2012-04-01 17:58 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-12 09:56 - 2011-05-20 08:14 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-12 09:19 - 2014-03-12 09:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F96658A8-FAF7-4C1D-86ED-1C0CEFDA33BE}
2014-03-11 20:57 - 2014-03-11 20:57 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3CBA1460-F382-4ECA-BC06-C439939ADE7C}
2014-03-11 16:45 - 2014-03-11 16:45 - 00000941 _____ () C:\Users\Public\Desktop\Speccy.lnk
2014-03-11 16:45 - 2014-03-11 16:45 - 00000000 ____D () C:\Program Files\Speccy
2014-03-11 16:42 - 2014-03-11 16:45 - 04845384 _____ (Piriform Ltd) C:\Users\unknown\Desktop\spsetup125.exe
2014-03-11 14:30 - 2014-03-11 14:30 - 00000035 _____ () C:\Users\unknown\Desktop\eset.txt
2014-03-11 11:45 - 2014-03-11 11:45 - 00000000 ____D () C:\Program Files\ESET
2014-03-11 11:25 - 2014-03-11 11:25 - 00027544 _____ () C:\Users\unknown\Desktop\Result.txt
2014-03-11 11:24 - 2014-03-11 11:24 - 00000854 _____ () C:\Users\unknown\Desktop\checkup.txt
2014-03-11 08:27 - 2014-03-11 08:27 - 00001071 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-11 08:27 - 2014-03-11 08:27 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-11 08:18 - 2014-03-11 08:18 - 00000000 ____D () C:\Users\unknown\Desktop\Old Firefox Data
2014-03-11 07:46 - 2014-03-11 07:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{824DB67E-2AF1-4AB3-B831-9599F9BFBA69}
2014-03-10 19:46 - 2014-03-10 19:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{480D26A8-315E-4F8A-99F9-64C14003FA5E}
2014-03-10 13:02 - 2011-07-24 20:00 - 12102144 ___SH () C:\Users\unknown\Desktop\Thumbs.db
2014-03-10 07:43 - 2014-03-10 07:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CBF052D1-D3A3-4F18-BAE7-9B7CD75C2A6C}
2014-03-09 14:57 - 2014-03-08 19:30 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A88AE5B2-ABEB-4965-B22F-71157B3D3010}
2014-03-08 07:12 - 2014-03-08 07:12 - 00000855 _____ () C:\Users\unknown\Desktop\µTorrent.lnk
2014-03-08 07:10 - 2014-03-08 07:09 - 01853008 _____ (BitTorrent Inc.) C:\Users\unknown\Downloads\uTorrent.exe
2014-03-08 07:06 - 2014-03-08 07:06 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D96128E7-775A-4D37-96E2-8E5A5750BEC2}
2014-03-07 13:05 - 2014-03-07 12:44 - 00000000 ____D () C:\Users\unknown\Desktop\GARAGE BUILDING DOCS
2014-03-07 10:13 - 2014-03-07 10:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F9AAEE8B-864D-4ACD-9F94-7F0FCF0559E7}
2014-03-06 09:03 - 2014-03-06 09:03 - 03819008 _____ () C:\Users\unknown\Downloads\RogueKiller.exe
2014-03-06 09:02 - 2014-03-06 09:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DE030B0A-6BE1-4FDF-A1FF-1B6262C897A8}
2014-03-05 19:44 - 2014-03-05 19:44 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E56DB46F-396F-4167-85EE-422A02FE158C}
2014-03-05 07:48 - 2014-03-05 07:47 - 00380416 _____ () C:\Users\unknown\Downloads\jh0vxwq9.exe
2014-03-05 07:43 - 2014-03-05 07:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{937EBBB1-75AC-416B-8518-6FFDD411C514}
2014-03-04 12:56 - 2013-07-11 13:46 - 00000000 ____D () C:\Users\unknown\Desktop\microsoft office
2014-03-04 11:17 - 2014-03-04 11:17 - 02347384 _____ (ESET) C:\Users\unknown\Desktop\esetsmartinstaller_enu.exe
2014-03-04 11:11 - 2009-07-14 13:37 - 00000000 ____D () C:\Windows\L2Schemas
2014-03-04 07:40 - 2014-03-04 07:40 - 00144400 _____ () C:\Windows\Minidump\030414-21933-01.dmp
2014-03-04 07:40 - 2011-04-19 16:38 - 257085711 _____ () C:\Windows\MEMORY.DMP
2014-03-04 07:40 - 2011-04-19 16:38 - 00000000 ____D () C:\Windows\Minidump
2014-03-04 07:03 - 2011-03-17 06:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\Adobe
2014-03-04 07:01 - 2011-06-18 08:08 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-03-04 07:01 - 2011-03-17 06:46 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-04 07:01 - 2011-03-17 06:46 - 00000000 ____D () C:\Program Files\Adobe
2014-03-04 06:53 - 2014-03-04 06:53 - 00000000 ____D () C:\ProgramData\Oracle
2014-03-04 06:52 - 2014-03-04 06:52 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-03-04 06:52 - 2014-03-04 06:51 - 00005822 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-03-04 06:52 - 2011-10-29 20:09 - 00000000 ____D () C:\Program Files\Java
2014-03-04 06:43 - 2014-03-04 06:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{8445ED36-709F-489C-8A19-08FA29853D50}
2014-03-03 17:17 - 2014-03-03 17:17 - 00144400 _____ () C:\Windows\Minidump\030314-23181-01.dmp
2014-03-03 16:19 - 2014-03-03 16:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CE1B8D22-0818-46C6-B5C6-5ABD7F0F53A1}
2014-03-03 15:12 - 2009-07-14 13:37 - 00000000 ____D () C:\Windows\PLA
2014-03-03 14:46 - 2014-03-03 14:44 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\unknown\Desktop\mbam-setup.exe
2014-03-03 14:40 - 2014-03-03 14:40 - 00982016 _____ (Farbar) C:\Users\unknown\Desktop\MiniToolBox.exe
2014-03-03 14:35 - 2014-03-03 14:35 - 00987425 _____ () C:\Users\unknown\Desktop\SecurityCheck.exe
2014-03-03 04:19 - 2014-03-03 04:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{C8553F1C-DCC3-4186-81AC-D59DC80B7754}
2014-03-02 08:22 - 2014-03-02 08:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{7988F25E-42D5-483F-8C31-AA7B00BB8350}
2014-03-01 15:30 - 2014-03-13 11:22 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-01 15:11 - 2014-03-13 11:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-01 15:10 - 2014-03-13 11:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-01 14:52 - 2014-03-13 11:22 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-01 14:51 - 2014-03-13 11:22 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-01 14:47 - 2014-03-13 11:22 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-01 14:43 - 2014-03-13 11:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-01 14:43 - 2014-03-13 11:22 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-01 14:40 - 2014-03-13 11:22 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-01 14:38 - 2014-03-13 11:22 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-01 14:38 - 2014-03-13 11:22 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-01 14:37 - 2014-03-13 11:22 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-01 14:31 - 2014-03-13 11:22 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-01 14:25 - 2014-03-13 11:22 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-01 14:16 - 2014-03-13 11:22 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-01 14:14 - 2014-03-13 11:22 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-01 14:03 - 2014-03-13 11:22 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-01 14:00 - 2014-03-13 11:22 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-01 13:57 - 2014-03-13 11:22 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-01 13:32 - 2014-03-13 11:22 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-01 13:27 - 2014-03-13 11:22 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-01 13:25 - 2014-03-13 11:22 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-01 08:54 - 2014-03-01 08:53 - 00000000 ____D () C:\Users\unknown\AppData\Local\{76D4D32B-9E1E-4329-9BDD-16DD7866C0E9}
2014-02-28 06:52 - 2014-02-28 06:52 - 00000000 ____D () C:\Users\unknown\AppData\Local\{12C0B45D-95EB-4F40-8055-5988414D1F2A}
2014-02-27 07:35 - 2014-02-27 07:35 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D95EA739-1005-4962-8FE2-6DC10B269C6C}
2014-02-26 08:11 - 2014-02-26 08:11 - 00000000 ____D () C:\Users\unknown\AppData\Local\{4A52383B-9DA4-4D77-8997-3635B681EF21}
2014-02-25 18:25 - 2014-02-25 18:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D6B27FDB-5D94-4B77-929F-CD800B3BBD30}
2014-02-25 07:28 - 2014-02-25 07:14 - 00000000 ____D () C:\Users\unknown\Desktop\2014-02-25 Stephanies Jewellery resell
2014-02-25 06:22 - 2014-02-25 06:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E5CAC627-E354-4FFA-B81B-40B990A40CF8}
2014-02-24 17:49 - 2014-02-24 17:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{414E4E6C-C6CE-42E7-8CF4-26CF6F52FE1A}
2014-02-24 05:49 - 2014-02-24 05:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A0A0B8AF-CB9C-44E5-B043-D982A1548B56}
2014-02-23 05:53 - 2014-02-23 05:52 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A2C20AE5-2970-4901-8E5F-28854CF0719C}
2014-02-22 16:56 - 2014-02-22 16:55 - 00263680 _____ () C:\Users\unknown\Desktop\Irrigation Solution Questionnaire.xls
2014-02-22 16:44 - 2013-12-30 14:26 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-02-22 16:44 - 2011-12-09 19:21 - 00000000 ____D () C:\Program Files\Trademanager
2014-02-22 16:31 - 2014-02-22 16:30 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3B0DA881-2B59-4EC3-B6FE-7A4AE0C68BAF}
2014-02-22 16:31 - 2011-03-16 15:51 - 00000000 ____D () C:\Users\unknown\AppData\Local\Windows Live
2014-02-21 17:51 - 2014-02-20 21:12 - 00021504 _____ () C:\Users\unknown\Desktop\SAMS JERSEY BUSINESS.xls
2014-02-21 11:46 - 2014-02-21 11:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{18F099C4-3CE5-4516-806F-E73F1F33770E}
2014-02-21 07:08 - 2012-05-05 09:08 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-20 22:09 - 2014-02-05 13:56 - 00000000 ____D () C:\Users\unknown\Desktop\Mary and Mohammad
2014-02-20 20:39 - 2014-02-20 20:39 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B2E264EE-87EE-479E-88C8-D3AFA709CA5A}
2014-02-20 16:25 - 2014-02-20 16:12 - 00000000 ____D () C:\Users\unknown\Desktop\Stephanie Vodnik
2014-02-20 08:13 - 2014-02-20 08:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{FE58155E-F2DB-4206-94D2-C076D381045C}
2014-02-19 18:42 - 2014-02-19 18:42 - 00000000 ____D () C:\Users\unknown\AppData\Local\{78E0DC29-60A3-4BDC-B96D-7589151BC609}
2014-02-19 05:51 - 2014-02-19 05:51 - 00000000 ____D () C:\Users\unknown\AppData\Local\{6F44F1E2-F261-4814-A0D5-0D559FB63055}
2014-02-18 07:19 - 2014-02-18 07:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DCD5934F-9564-4666-AD95-8BDC02E6BE98}
2014-02-17 19:19 - 2014-02-17 19:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{86C8749A-58DF-4C3A-BD14-E688182BDF44}
2014-02-17 08:05 - 2014-02-17 08:04 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-17 07:19 - 2014-02-17 07:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A9E9283D-0593-43EF-9943-D1F3E42C9CD8}
2014-02-16 09:56 - 2014-02-16 09:56 - 00000000 ____D () C:\Users\unknown\AppData\Local\{0026EF2A-4381-4248-971F-F281B13CD76A}
2014-02-15 10:33 - 2014-03-08 07:15 - 00000426 _____ () C:\AVScanner.ini
2014-02-15 07:22 - 2014-02-15 07:21 - 00000000 ____D () C:\Users\unknown\AppData\Local\{FD2DB3B0-C157-432F-BE58-343311AAECEA}

Some content of TEMP:
====================
C:\Users\unknown\AppData\Local\temp\speccycpuid.dll


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-10 08:28

==================== End Of Log ============================



#7 Aurifex

Aurifex
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:12:34 PM

Posted 16 March 2014 - 05:11 PM

Hi, still the same. When you write 'Start FRST with administator privileges.' Should I be doing anything prior to running FRST? I've just been running it.



#8 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:34 AM

Posted 17 March 2014 - 04:48 AM

Hi,

this guy doesn't like to be deleted as it seems.. Let's go to RE then:



Move FRST to a flash drive.
  • Plug the flashdrive into the infected PC and enter System Recovery Options.
To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
Note: In case you can not enter System Recovery Options by using F8 method, you can use Windows installation disc, or make a repair disc. Any Windows installation disc or a repair disc made on another computer can be used.
To make a repair disk on Windows 7 consult: http://www.sevenforums.com/tutorials/2083-system-repair-disc-create.html




To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
==========

On the System Recovery Options menu you will get the following options:

Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt


Select Command Prompt

==========


Once in the Command Prompt:
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.


#9 Aurifex

Aurifex
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:12:34 PM

Posted 17 March 2014 - 09:24 PM

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014  01
Ran by SYSTEM on MININT-9KMKNMR on 18-03-2014 13:09:55
Running from E:\
Windows 7 Ultimate (X86) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.


The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [BrMfcWnd] - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-25] (Brother Industries, Ltd.)
HKLM\...\Run: [NBAgent] - C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1234216 2010-03-25] (Nero AG)
HKLM\...\Run: [ArcSoft Connection Service] - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-08-27] (Apple Inc.)
HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [3524536 2012-07-15] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-05] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-22] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [421776 2012-09-09] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-01] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-20] (Adobe Systems Incorporated)
HKLM\...\Run: [ofrzutuz] - C:\ProgramData\ypmj\aqajsvid.exe [258048 2014-03-16] ()
HKLM\...\Run: [ykdhyved] - C:\ProgramData\ixem\umozufes.exe [258048 2014-03-16] ()
HKLM\...\Run: [ControlCenter3] - C:\Program Files\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-23] (Brother Industries, Ltd.)
HKU\Mcx1-UNKNOWN-PC\...\Winlogon: [Shell] C:\Windows\eHome\McrMgr.exe [313344 2009-07-13] (Microsoft Corporation) <==== ATTENTION
HKU\unknown\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-06-16] (Hewlett-Packard Company)
HKU\unknown\...\Run: [KiesPDLR] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-07-15] ()
HKU\unknown\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [975800 2012-07-15] (Samsung)
HKU\unknown\...\Run: [News.net] - C:\Program Files\News.net\BreakingNews\DesktopContainer.exe

========================== Services (Whitelisted) =================

S2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-17] (ArcSoft Inc.)
S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-03] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-03] (Malwarebytes Corporation)
S2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-22] (Microsoft Corporation)
S2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [490280 2010-03-24] (Nero AG)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-22] (Microsoft Corporation)
S2 RalinkRegistryWriter; C:\Program Files\NetComm\Common\RegistryWriter.exe [69632 2008-05-12] (Ralink Technology, Corp.)

==================== Drivers (Whitelisted) ====================

S3 61883; C:\Windows\System32\DRIVERS\61883.sys [46976 2009-07-13] (Microsoft Corporation)
S3 bqusbser; C:\Windows\System32\DRIVERS\Mousbser.sys [103936 2008-05-21] (Motorola Incorporated)
S2 Hardlock; C:\Windows\system32\drivers\hardlock.sys [685056 2005-07-27] (Aladdin Knowledge Systems Ltd.)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-03] (Malwarebytes Corporation)
S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-26] (Microsoft Corporation)
S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [657408 2009-07-13] (Ralink Technology Corp.)
S3 catchme; \??\C:\Users\unknown\AppData\Local\Temp\catchme.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-17 17:55 - 2014-03-17 17:55 - 00002270 _____ () C:\Users\unknown\Desktop\New Text Document.txt
2014-03-17 12:32 - 2014-03-17 12:32 - 00000000 ____D () C:\Users\unknown\AppData\Local\{5CE6112E-A4C7-4801-AEA8-28616B63FCD3}
2014-03-16 21:23 - 2014-03-16 21:25 - 00000066 _____ () C:\Windows\Brfaxrx.ini
2014-03-16 21:23 - 2009-01-15 00:20 - 00003072 ____N (Brother Industries Ltd.) C:\Windows\System32\BrDctF2S.dll
2014-03-16 21:23 - 2008-10-17 01:02 - 00126976 ____N (Brother Industries, Ltd.) C:\Windows\System32\BrfxD05b.dll
2014-03-16 21:23 - 2007-12-13 03:16 - 00073728 ____N (Brother Industries Ltd.) C:\Windows\System32\BrDctF2.dll
2014-03-16 21:23 - 2007-12-13 03:16 - 00005120 ____N (Brother Industries Ltd.) C:\Windows\System32\BrDctF2L.dll
2014-03-16 21:23 - 2006-12-27 18:39 - 00176128 ____N (Brother Industries, Ltd.) C:\Windows\System32\BroSNMP.dll
2014-03-16 21:23 - 2003-11-27 23:57 - 00000000 _____ () C:\Windows\brdfxspd.dat
2014-03-16 21:22 - 2014-03-16 21:22 - 00000000 ____D () C:\Users\unknown\Downloads\mflpro
2014-03-16 21:22 - 2014-03-16 21:22 - 00000000 ____D () C:\Users\unknown\AppData\Roaming\InstallShield
2014-03-16 21:17 - 2014-03-16 21:21 - 42628541 _____ (A.I.SOFT,INC.) C:\Users\unknown\Downloads\MFC-665CW-inst-win7-A2.EXE
2014-03-16 13:52 - 2014-03-17 18:01 - 00000000 ____D () C:\ProgramData\amepugyf
2014-03-16 13:52 - 2014-03-16 13:52 - 00000000 ____D () C:\ProgramData\ixem
2014-03-16 13:48 - 2014-03-16 13:48 - 00000000 ____D () C:\ProgramData\ypmj
2014-03-16 13:25 - 2014-03-16 13:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\{7EE084DF-8CA9-4041-A5EE-97D4E5342390}
2014-03-15 23:02 - 2014-03-15 23:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{5631B219-0285-4AE6-A2C9-F746D7221D87}
2014-03-15 11:14 - 2014-03-15 11:38 - 00029196 _____ () C:\Users\unknown\Downloads\Addition.txt
2014-03-15 11:12 - 2014-03-18 13:09 - 00000000 ____D () C:\FRST
2014-03-15 11:12 - 2014-03-16 14:00 - 00043772 _____ () C:\Users\unknown\Downloads\FRST.txt
2014-03-15 11:11 - 2014-03-15 11:11 - 01145856 _____ (Farbar) C:\Users\unknown\Downloads\FRST.exe
2014-03-15 11:04 - 2014-03-15 11:04 - 04130656 _____ (Kaspersky Lab ZAO) C:\Users\unknown\Downloads\tdsskiller.exe
2014-03-15 11:02 - 2014-03-15 11:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{72275A55-063E-4860-BAEE-9ABBD9080EED}
2014-03-14 12:59 - 2014-03-14 12:59 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D8090C2D-71FD-481E-AB68-1FBC0756BA3A}
2014-03-13 21:34 - 2014-03-13 21:35 - 00000000 ____D () C:\Users\unknown\Desktop\New help
2014-03-13 21:33 - 2014-03-13 21:33 - 00021764 _____ () C:\Users\unknown\Desktop\dds.txt
2014-03-13 21:33 - 2014-03-13 21:33 - 00006187 _____ () C:\Users\unknown\Desktop\attach.txt
2014-03-13 21:30 - 2014-03-13 21:30 - 00688992 ____R (Swearware) C:\Users\unknown\Downloads\dds.com
2014-03-13 21:10 - 2014-03-13 21:10 - 00000000 ____D () C:\Users\unknown\AppData\Local\{22417392-7AD2-419B-9A6E-E56B23C6F117}
2014-03-13 08:00 - 2014-03-13 08:00 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B831E33C-181D-4798-99D1-47DC39FA776B}
2014-03-12 16:22 - 2014-02-28 20:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2014-03-12 16:22 - 2014-02-28 20:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2014-03-12 16:22 - 2014-02-28 20:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2014-03-12 16:22 - 2014-02-28 19:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2014-03-12 16:22 - 2014-02-28 19:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2014-03-12 16:22 - 2014-02-28 19:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2014-03-12 16:22 - 2014-02-28 19:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2014-03-12 16:22 - 2014-02-28 19:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2014-03-12 16:22 - 2014-02-28 19:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2014-03-12 16:22 - 2014-02-28 19:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2014-03-12 16:22 - 2014-02-28 19:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2014-03-12 16:22 - 2014-02-28 19:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2014-03-12 16:22 - 2014-02-28 19:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2014-03-12 16:22 - 2014-02-28 19:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2014-03-12 16:22 - 2014-02-28 19:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2014-03-12 16:22 - 2014-02-28 19:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2014-03-12 16:22 - 2014-02-28 19:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2014-03-12 16:22 - 2014-02-28 19:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2014-03-12 16:22 - 2014-02-28 18:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2014-03-12 16:22 - 2014-02-28 18:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2014-03-12 16:22 - 2014-02-28 18:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2014-03-12 16:22 - 2014-02-28 18:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2014-03-12 16:22 - 2014-02-03 18:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\System32\qedit.dll
2014-03-12 16:20 - 2014-02-06 17:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2014-03-12 16:20 - 2014-02-03 18:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2014-03-12 16:20 - 2014-01-28 18:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\System32\wer.dll
2014-03-12 16:20 - 2014-01-27 18:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2014-03-12 16:20 - 2014-01-08 18:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2014-03-12 13:19 - 2014-03-12 13:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{58513ECF-F5D2-44E5-9F4C-9A0CBDF45CC6}
2014-03-11 14:26 - 2013-10-01 16:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbFlt.sys
2014-03-11 14:26 - 2013-10-01 16:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
2014-03-11 14:26 - 2013-10-01 15:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbGDCoInstaller.dll
2014-03-11 14:26 - 2012-08-23 06:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\System32\rdpudd.dll
2014-03-11 14:26 - 2012-08-23 06:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\rdpvideominiport.sys
2014-03-11 14:26 - 2012-08-23 05:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\System32\RdpGroupPolicyExtension.dll
2014-03-11 14:26 - 2012-08-23 03:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\System32\rdpendp_winip.dll
2014-03-11 14:26 - 2012-08-23 02:08 - 02739712 _____ (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2014-03-11 14:25 - 2013-10-01 16:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2014-03-11 14:25 - 2013-10-01 16:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\MsRdpWebAccess.dll
2014-03-11 14:25 - 2013-10-01 16:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\System32\wksprtPS.dll
2014-03-11 14:25 - 2013-10-01 15:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\System32\tsgqec.dll
2014-03-11 14:25 - 2013-10-01 15:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\System32\rdvidcrl.dll
2014-03-11 14:25 - 2013-10-01 15:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\System32\TSWbPrxy.exe
2014-03-11 14:25 - 2013-10-01 14:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\System32\wksprt.exe
2014-03-11 14:25 - 2013-10-01 14:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\System32\mstsc.exe
2014-03-11 14:24 - 2013-09-24 17:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\System32\TSWorkspace.dll
2014-03-11 14:24 - 2012-05-04 01:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2014-03-11 14:19 - 2014-03-11 14:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F96658A8-FAF7-4C1D-86ED-1C0CEFDA33BE}
2014-03-11 01:57 - 2014-03-11 01:57 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3CBA1460-F382-4ECA-BC06-C439939ADE7C}
2014-03-10 21:45 - 2014-03-10 21:45 - 00000941 _____ () C:\Users\Public\Desktop\Speccy.lnk
2014-03-10 21:45 - 2014-03-10 21:45 - 00000000 ____D () C:\Program Files\Speccy
2014-03-10 21:45 - 2014-03-10 21:42 - 04845384 _____ (Piriform Ltd) C:\Users\unknown\Desktop\spsetup125.exe
2014-03-10 19:30 - 2014-03-10 19:30 - 00000035 _____ () C:\Users\unknown\Desktop\eset.txt
2014-03-10 16:45 - 2014-03-10 16:45 - 00000000 ____D () C:\Program Files\ESET
2014-03-10 16:25 - 2014-03-10 16:25 - 00027544 _____ () C:\Users\unknown\Desktop\Result.txt
2014-03-10 16:24 - 2014-03-10 16:24 - 00000854 _____ () C:\Users\unknown\Desktop\checkup.txt
2014-03-10 13:27 - 2014-03-10 13:27 - 00001071 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-10 13:27 - 2014-03-10 13:27 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-10 13:27 - 2013-04-03 19:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2014-03-10 13:18 - 2014-03-10 13:18 - 00000000 ____D () C:\Users\unknown\Desktop\Old Firefox Data
2014-03-10 12:46 - 2014-03-10 12:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{824DB67E-2AF1-4AB3-B831-9599F9BFBA69}
2014-03-10 00:46 - 2014-03-10 00:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{480D26A8-315E-4F8A-99F9-64C14003FA5E}
2014-03-09 12:43 - 2014-03-09 12:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CBF052D1-D3A3-4F18-BAE7-9B7CD75C2A6C}
2014-03-08 00:30 - 2014-03-16 21:35 - 00000000 ____D () C:\Users\unknown\AppData\Local\CrashDumps
2014-03-08 00:30 - 2014-03-08 19:57 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A88AE5B2-ABEB-4965-B22F-71157B3D3010}
2014-03-07 12:15 - 2014-02-14 15:33 - 00000426 _____ () C:\AVScanner.ini
2014-03-07 12:12 - 2014-03-07 12:12 - 00000855 _____ () C:\Users\unknown\Desktop\µTorrent.lnk
2014-03-07 12:09 - 2014-03-07 12:10 - 01853008 _____ (BitTorrent Inc.) C:\Users\unknown\Downloads\uTorrent.exe
2014-03-07 12:06 - 2014-03-07 12:06 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D96128E7-775A-4D37-96E2-8E5A5750BEC2}
2014-03-06 17:44 - 2014-03-06 18:05 - 00000000 ____D () C:\Users\unknown\Desktop\GARAGE BUILDING DOCS
2014-03-06 15:13 - 2014-03-06 15:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F9AAEE8B-864D-4ACD-9F94-7F0FCF0559E7}
2014-03-05 14:03 - 2014-03-05 14:03 - 03819008 _____ () C:\Users\unknown\Downloads\RogueKiller.exe
2014-03-05 14:02 - 2014-03-05 14:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DE030B0A-6BE1-4FDF-A1FF-1B6262C897A8}
2014-03-05 00:44 - 2014-03-05 00:44 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E56DB46F-396F-4167-85EE-422A02FE158C}
2014-03-04 12:47 - 2014-03-04 12:48 - 00380416 _____ () C:\Users\unknown\Downloads\jh0vxwq9.exe
2014-03-04 12:43 - 2014-03-04 12:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{937EBBB1-75AC-416B-8518-6FFDD411C514}
2014-03-03 16:17 - 2014-03-03 16:17 - 02347384 _____ (ESET) C:\Users\unknown\Desktop\esetsmartinstaller_enu.exe
2014-03-03 12:40 - 2014-03-03 12:40 - 00144400 _____ () C:\Windows\Minidump\030414-21933-01.dmp
2014-03-03 11:53 - 2014-03-03 11:53 - 00000000 ____D () C:\ProgramData\Oracle
2014-03-03 11:52 - 2014-03-03 11:52 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-03-03 11:52 - 2013-12-18 02:10 - 00094632 _____ (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll
2014-03-03 11:52 - 2013-12-18 02:04 - 00264616 _____ (Oracle Corporation) C:\Windows\System32\javaws.exe
2014-03-03 11:52 - 2013-12-18 02:04 - 00175016 _____ (Oracle Corporation) C:\Windows\System32\javaw.exe
2014-03-03 11:52 - 2013-12-18 02:03 - 00174504 _____ (Oracle Corporation) C:\Windows\System32\java.exe
2014-03-03 11:51 - 2014-03-03 11:52 - 00005822 _____ () C:\Windows\System32\jupdate-1.7.0_51-b13.log
2014-03-03 11:43 - 2014-03-03 11:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{8445ED36-709F-489C-8A19-08FA29853D50}
2014-03-02 22:17 - 2014-03-02 22:17 - 00144400 _____ () C:\Windows\Minidump\030314-23181-01.dmp
2014-03-02 21:19 - 2014-03-02 21:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CE1B8D22-0818-46C6-B5C6-5ABD7F0F53A1}
2014-03-02 19:44 - 2014-03-02 19:46 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\unknown\Desktop\mbam-setup.exe
2014-03-02 19:40 - 2014-03-02 19:40 - 00982016 _____ (Farbar) C:\Users\unknown\Desktop\MiniToolBox.exe
2014-03-02 19:35 - 2014-03-02 19:35 - 00987425 _____ () C:\Users\unknown\Desktop\SecurityCheck.exe
2014-03-02 09:19 - 2014-03-02 09:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{C8553F1C-DCC3-4186-81AC-D59DC80B7754}
2014-03-01 13:22 - 2014-03-01 13:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{7988F25E-42D5-483F-8C31-AA7B00BB8350}
2014-02-28 13:53 - 2014-02-28 13:54 - 00000000 ____D () C:\Users\unknown\AppData\Local\{76D4D32B-9E1E-4329-9BDD-16DD7866C0E9}
2014-02-27 11:52 - 2014-02-27 11:52 - 00000000 ____D () C:\Users\unknown\AppData\Local\{12C0B45D-95EB-4F40-8055-5988414D1F2A}
2014-02-26 12:35 - 2014-02-26 12:35 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D95EA739-1005-4962-8FE2-6DC10B269C6C}
2014-02-25 13:11 - 2014-02-25 13:11 - 00000000 ____D () C:\Users\unknown\AppData\Local\{4A52383B-9DA4-4D77-8997-3635B681EF21}
2014-02-24 23:25 - 2014-02-24 23:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D6B27FDB-5D94-4B77-929F-CD800B3BBD30}
2014-02-24 12:14 - 2014-02-24 12:28 - 00000000 ____D () C:\Users\unknown\Desktop\2014-02-25 Stephanies Jewellery resell
2014-02-24 11:22 - 2014-02-24 11:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E5CAC627-E354-4FFA-B81B-40B990A40CF8}
2014-02-23 22:49 - 2014-02-23 22:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{414E4E6C-C6CE-42E7-8CF4-26CF6F52FE1A}
2014-02-23 10:49 - 2014-02-23 10:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A0A0B8AF-CB9C-44E5-B043-D982A1548B56}
2014-02-22 10:52 - 2014-02-22 10:53 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A2C20AE5-2970-4901-8E5F-28854CF0719C}
2014-02-21 21:55 - 2014-02-21 21:56 - 00263680 _____ () C:\Users\unknown\Desktop\Irrigation Solution Questionnaire.xls
2014-02-21 21:30 - 2014-02-21 21:31 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3B0DA881-2B59-4EC3-B6FE-7A4AE0C68BAF}
2014-02-20 16:46 - 2014-02-20 16:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{18F099C4-3CE5-4516-806F-E73F1F33770E}
2014-02-20 02:12 - 2014-02-20 22:51 - 00021504 _____ () C:\Users\unknown\Desktop\SAMS JERSEY BUSINESS.xls
2014-02-20 01:39 - 2014-02-20 01:39 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B2E264EE-87EE-479E-88C8-D3AFA709CA5A}
2014-02-19 21:12 - 2014-02-19 21:25 - 00000000 ____D () C:\Users\unknown\Desktop\Stephanie Vodnik
2014-02-19 13:13 - 2014-02-19 13:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{FE58155E-F2DB-4206-94D2-C076D381045C}
2014-02-18 23:42 - 2014-02-18 23:42 - 00000000 ____D () C:\Users\unknown\AppData\Local\{78E0DC29-60A3-4BDC-B96D-7589151BC609}
2014-02-18 10:51 - 2014-02-18 10:51 - 00000000 ____D () C:\Users\unknown\AppData\Local\{6F44F1E2-F261-4814-A0D5-0D559FB63055}
2014-02-17 12:19 - 2014-02-17 12:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DCD5934F-9564-4666-AD95-8BDC02E6BE98}
2014-02-17 00:19 - 2014-02-17 00:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{86C8749A-58DF-4C3A-BD14-E688182BDF44}
2014-02-16 13:04 - 2014-02-16 13:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-16 12:19 - 2014-02-16 12:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A9E9283D-0593-43EF-9943-D1F3E42C9CD8}

==================== One Month Modified Files and Folders =======

2014-03-18 13:09 - 2014-03-15 11:12 - 00000000 ____D () C:\FRST
2014-03-17 18:01 - 2014-03-16 13:52 - 00000000 ____D () C:\ProgramData\amepugyf
2014-03-17 18:01 - 2011-12-02 14:54 - 08405015 _____ () C:\Windows\TempFile
2014-03-17 18:01 - 2011-10-29 01:10 - 00000000 ____D () C:\ProgramData\Sun
2014-03-17 18:00 - 2009-07-13 20:39 - 00134923 _____ () C:\Windows\setupact.log
2014-03-17 17:59 - 2011-03-15 15:13 - 02016481 _____ () C:\Windows\WindowsUpdate.log
2014-03-17 17:55 - 2014-03-17 17:55 - 00002270 _____ () C:\Users\unknown\Desktop\New Text Document.txt
2014-03-17 17:55 - 2011-03-15 15:23 - 00782510 _____ () C:\Windows\System32\PerfStringBackup.INI
2014-03-17 12:32 - 2014-03-17 12:32 - 00000000 ____D () C:\Users\unknown\AppData\Local\{5CE6112E-A4C7-4801-AEA8-28616B63FCD3}
2014-03-16 21:39 - 2009-07-13 20:34 - 00014416 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-16 21:39 - 2009-07-13 20:34 - 00014416 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-16 21:35 - 2014-03-08 00:30 - 00000000 ____D () C:\Users\unknown\AppData\Local\CrashDumps
2014-03-16 21:27 - 2011-03-16 11:20 - 00000829 _____ () C:\Windows\Brpfx04a.ini
2014-03-16 21:27 - 2011-03-16 11:20 - 00000419 _____ () C:\Windows\BRWMARK.INI
2014-03-16 21:27 - 2011-03-16 11:20 - 00000163 _____ () C:\Windows\brpcfx.ini
2014-03-16 21:27 - 2011-03-16 11:20 - 00000027 _____ () C:\Windows\BRPP2KA.INI
2014-03-16 21:25 - 2014-03-16 21:23 - 00000066 _____ () C:\Windows\Brfaxrx.ini
2014-03-16 21:25 - 2011-03-16 11:19 - 00000050 _____ () C:\Windows\System32\bridf06a.dat
2014-03-16 21:24 - 2013-08-04 16:39 - 00000000 ____D () C:\Program Files\Brother
2014-03-16 21:23 - 2011-03-16 11:18 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-03-16 21:22 - 2014-03-16 21:22 - 00000000 ____D () C:\Users\unknown\Downloads\mflpro
2014-03-16 21:22 - 2014-03-16 21:22 - 00000000 ____D () C:\Users\unknown\AppData\Roaming\InstallShield
2014-03-16 21:21 - 2014-03-16 21:17 - 42628541 _____ (A.I.SOFT,INC.) C:\Users\unknown\Downloads\MFC-665CW-inst-win7-A2.EXE
2014-03-16 14:00 - 2014-03-15 11:12 - 00043772 _____ () C:\Users\unknown\Downloads\FRST.txt
2014-03-16 13:52 - 2014-03-16 13:52 - 00000000 ____D () C:\ProgramData\ixem
2014-03-16 13:49 - 2011-03-16 06:23 - 00164338 _____ () C:\Windows\PFRO.log
2014-03-16 13:48 - 2014-03-16 13:48 - 00000000 ____D () C:\ProgramData\ypmj
2014-03-16 13:25 - 2014-03-16 13:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\{7EE084DF-8CA9-4041-A5EE-97D4E5342390}
2014-03-15 23:02 - 2014-03-15 23:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{5631B219-0285-4AE6-A2C9-F746D7221D87}
2014-03-15 11:38 - 2014-03-15 11:14 - 00029196 _____ () C:\Users\unknown\Downloads\Addition.txt
2014-03-15 11:11 - 2014-03-15 11:11 - 01145856 _____ (Farbar) C:\Users\unknown\Downloads\FRST.exe
2014-03-15 11:04 - 2014-03-15 11:04 - 04130656 _____ (Kaspersky Lab ZAO) C:\Users\unknown\Downloads\tdsskiller.exe
2014-03-15 11:02 - 2014-03-15 11:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{72275A55-063E-4860-BAEE-9ABBD9080EED}
2014-03-14 20:05 - 2011-03-25 18:00 - 00000000 ____D () C:\Users\unknown\AppData\Roaming\uTorrent
2014-03-14 12:59 - 2014-03-14 12:59 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D8090C2D-71FD-481E-AB68-1FBC0756BA3A}
2014-03-13 21:35 - 2014-03-13 21:34 - 00000000 ____D () C:\Users\unknown\Desktop\New help
2014-03-13 21:33 - 2014-03-13 21:33 - 00021764 _____ () C:\Users\unknown\Desktop\dds.txt
2014-03-13 21:33 - 2014-03-13 21:33 - 00006187 _____ () C:\Users\unknown\Desktop\attach.txt
2014-03-13 21:30 - 2014-03-13 21:30 - 00688992 ____R (Swearware) C:\Users\unknown\Downloads\dds.com
2014-03-13 21:10 - 2014-03-13 21:10 - 00000000 ____D () C:\Users\unknown\AppData\Local\{22417392-7AD2-419B-9A6E-E56B23C6F117}
2014-03-13 16:28 - 2009-07-13 18:37 - 00000000 ____D () C:\Windows\rescache
2014-03-13 08:28 - 2009-07-13 20:33 - 03692064 _____ () C:\Windows\System32\FNTCACHE.DAT
2014-03-13 08:27 - 2011-06-12 16:57 - 00000362 __RSH () C:\ProgramData\ntuser.pol
2014-03-13 08:26 - 2011-03-15 20:53 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-13 08:00 - 2014-03-13 08:00 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B831E33C-181D-4798-99D1-47DC39FA776B}
2014-03-12 13:19 - 2014-03-12 13:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{58513ECF-F5D2-44E5-9F4C-9A0CBDF45CC6}
2014-03-11 14:56 - 2012-03-31 22:58 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2014-03-11 14:56 - 2011-05-19 13:14 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2014-03-11 14:19 - 2014-03-11 14:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F96658A8-FAF7-4C1D-86ED-1C0CEFDA33BE}
2014-03-11 01:57 - 2014-03-11 01:57 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3CBA1460-F382-4ECA-BC06-C439939ADE7C}
2014-03-10 21:45 - 2014-03-10 21:45 - 00000941 _____ () C:\Users\Public\Desktop\Speccy.lnk
2014-03-10 21:45 - 2014-03-10 21:45 - 00000000 ____D () C:\Program Files\Speccy
2014-03-10 21:42 - 2014-03-10 21:45 - 04845384 _____ (Piriform Ltd) C:\Users\unknown\Desktop\spsetup125.exe
2014-03-10 19:30 - 2014-03-10 19:30 - 00000035 _____ () C:\Users\unknown\Desktop\eset.txt
2014-03-10 16:45 - 2014-03-10 16:45 - 00000000 ____D () C:\Program Files\ESET
2014-03-10 16:25 - 2014-03-10 16:25 - 00027544 _____ () C:\Users\unknown\Desktop\Result.txt
2014-03-10 16:24 - 2014-03-10 16:24 - 00000854 _____ () C:\Users\unknown\Desktop\checkup.txt
2014-03-10 13:27 - 2014-03-10 13:27 - 00001071 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-10 13:27 - 2014-03-10 13:27 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-10 13:18 - 2014-03-10 13:18 - 00000000 ____D () C:\Users\unknown\Desktop\Old Firefox Data
2014-03-10 12:46 - 2014-03-10 12:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{824DB67E-2AF1-4AB3-B831-9599F9BFBA69}
2014-03-10 00:46 - 2014-03-10 00:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{480D26A8-315E-4F8A-99F9-64C14003FA5E}
2014-03-09 18:02 - 2011-07-24 01:00 - 12102144 ___SH () C:\Users\unknown\Desktop\Thumbs.db
2014-03-09 12:43 - 2014-03-09 12:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CBF052D1-D3A3-4F18-BAE7-9B7CD75C2A6C}
2014-03-08 19:57 - 2014-03-08 00:30 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A88AE5B2-ABEB-4965-B22F-71157B3D3010}
2014-03-07 12:12 - 2014-03-07 12:12 - 00000855 _____ () C:\Users\unknown\Desktop\µTorrent.lnk
2014-03-07 12:10 - 2014-03-07 12:09 - 01853008 _____ (BitTorrent Inc.) C:\Users\unknown\Downloads\uTorrent.exe
2014-03-07 12:06 - 2014-03-07 12:06 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D96128E7-775A-4D37-96E2-8E5A5750BEC2}
2014-03-06 18:05 - 2014-03-06 17:44 - 00000000 ____D () C:\Users\unknown\Desktop\GARAGE BUILDING DOCS
2014-03-06 15:13 - 2014-03-06 15:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F9AAEE8B-864D-4ACD-9F94-7F0FCF0559E7}
2014-03-05 14:03 - 2014-03-05 14:03 - 03819008 _____ () C:\Users\unknown\Downloads\RogueKiller.exe
2014-03-05 14:02 - 2014-03-05 14:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DE030B0A-6BE1-4FDF-A1FF-1B6262C897A8}
2014-03-05 00:44 - 2014-03-05 00:44 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E56DB46F-396F-4167-85EE-422A02FE158C}
2014-03-04 12:48 - 2014-03-04 12:47 - 00380416 _____ () C:\Users\unknown\Downloads\jh0vxwq9.exe
2014-03-04 12:43 - 2014-03-04 12:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{937EBBB1-75AC-416B-8518-6FFDD411C514}
2014-03-03 17:56 - 2013-07-10 18:46 - 00000000 ____D () C:\Users\unknown\Desktop\microsoft office
2014-03-03 16:17 - 2014-03-03 16:17 - 02347384 _____ (ESET) C:\Users\unknown\Desktop\esetsmartinstaller_enu.exe
2014-03-03 16:11 - 2009-07-13 18:37 - 00000000 ____D () C:\Windows\L2Schemas
2014-03-03 12:40 - 2014-03-03 12:40 - 00144400 _____ () C:\Windows\Minidump\030414-21933-01.dmp
2014-03-03 12:40 - 2011-04-18 21:38 - 257085711 _____ () C:\Windows\MEMORY.DMP
2014-03-03 12:40 - 2011-04-18 21:38 - 00000000 ____D () C:\Windows\Minidump
2014-03-03 12:03 - 2011-03-16 11:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\Adobe
2014-03-03 12:01 - 2011-06-17 13:08 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-03-03 12:01 - 2011-03-16 11:46 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-03 12:01 - 2011-03-16 11:46 - 00000000 ____D () C:\Program Files\Adobe
2014-03-03 11:53 - 2014-03-03 11:53 - 00000000 ____D () C:\ProgramData\Oracle
2014-03-03 11:52 - 2014-03-03 11:52 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-03-03 11:52 - 2014-03-03 11:51 - 00005822 _____ () C:\Windows\System32\jupdate-1.7.0_51-b13.log
2014-03-03 11:52 - 2011-10-29 01:09 - 00000000 ____D () C:\Program Files\Java
2014-03-03 11:43 - 2014-03-03 11:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{8445ED36-709F-489C-8A19-08FA29853D50}
2014-03-02 22:17 - 2014-03-02 22:17 - 00144400 _____ () C:\Windows\Minidump\030314-23181-01.dmp
2014-03-02 21:19 - 2014-03-02 21:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CE1B8D22-0818-46C6-B5C6-5ABD7F0F53A1}
2014-03-02 20:12 - 2009-07-13 18:37 - 00000000 ____D () C:\Windows\PLA
2014-03-02 19:46 - 2014-03-02 19:44 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\unknown\Desktop\mbam-setup.exe
2014-03-02 19:40 - 2014-03-02 19:40 - 00982016 _____ (Farbar) C:\Users\unknown\Desktop\MiniToolBox.exe
2014-03-02 19:35 - 2014-03-02 19:35 - 00987425 _____ () C:\Users\unknown\Desktop\SecurityCheck.exe
2014-03-02 09:19 - 2014-03-02 09:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{C8553F1C-DCC3-4186-81AC-D59DC80B7754}
2014-03-01 13:22 - 2014-03-01 13:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{7988F25E-42D5-483F-8C31-AA7B00BB8350}
2014-02-28 20:30 - 2014-03-12 16:22 - 17074688 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2014-02-28 20:11 - 2014-03-12 16:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2014-02-28 20:10 - 2014-03-12 16:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2014-02-28 19:52 - 2014-03-12 16:22 - 00061952 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2014-02-28 19:51 - 2014-03-12 16:22 - 00051200 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2014-02-28 19:47 - 2014-03-12 16:22 - 02168320 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2014-02-28 19:43 - 2014-03-12 16:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2014-02-28 19:43 - 2014-03-12 16:22 - 00032768 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2014-02-28 19:40 - 2014-03-12 16:22 - 00440832 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2014-02-28 19:38 - 2014-03-12 16:22 - 00112128 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2014-02-28 19:38 - 2014-03-12 16:22 - 00108032 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2014-02-28 19:37 - 2014-03-12 16:22 - 00553472 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2014-02-28 19:31 - 2014-03-12 16:22 - 00646144 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2014-02-28 19:25 - 2014-03-12 16:22 - 00208896 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2014-02-28 19:16 - 2014-03-12 16:22 - 00164864 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2014-02-28 19:14 - 2014-03-12 16:22 - 04244480 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2014-02-28 19:03 - 2014-03-12 16:22 - 00524288 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2014-02-28 19:00 - 2014-03-12 16:22 - 01964032 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2014-02-28 18:57 - 2014-03-12 16:22 - 11266048 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2014-02-28 18:32 - 2014-03-12 16:22 - 01820160 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2014-02-28 18:27 - 2014-03-12 16:22 - 01156096 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2014-02-28 18:25 - 2014-03-12 16:22 - 00703488 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2014-02-28 13:54 - 2014-02-28 13:53 - 00000000 ____D () C:\Users\unknown\AppData\Local\{76D4D32B-9E1E-4329-9BDD-16DD7866C0E9}
2014-02-27 11:52 - 2014-02-27 11:52 - 00000000 ____D () C:\Users\unknown\AppData\Local\{12C0B45D-95EB-4F40-8055-5988414D1F2A}
2014-02-26 12:35 - 2014-02-26 12:35 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D95EA739-1005-4962-8FE2-6DC10B269C6C}
2014-02-25 13:11 - 2014-02-25 13:11 - 00000000 ____D () C:\Users\unknown\AppData\Local\{4A52383B-9DA4-4D77-8997-3635B681EF21}
2014-02-24 23:25 - 2014-02-24 23:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D6B27FDB-5D94-4B77-929F-CD800B3BBD30}
2014-02-24 12:28 - 2014-02-24 12:14 - 00000000 ____D () C:\Users\unknown\Desktop\2014-02-25 Stephanies Jewellery resell
2014-02-24 11:22 - 2014-02-24 11:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E5CAC627-E354-4FFA-B81B-40B990A40CF8}
2014-02-23 22:49 - 2014-02-23 22:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{414E4E6C-C6CE-42E7-8CF4-26CF6F52FE1A}
2014-02-23 10:49 - 2014-02-23 10:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A0A0B8AF-CB9C-44E5-B043-D982A1548B56}
2014-02-22 10:53 - 2014-02-22 10:52 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A2C20AE5-2970-4901-8E5F-28854CF0719C}
2014-02-21 21:56 - 2014-02-21 21:55 - 00263680 _____ () C:\Users\unknown\Desktop\Irrigation Solution Questionnaire.xls
2014-02-21 21:44 - 2013-12-29 19:26 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-02-21 21:44 - 2011-12-09 00:21 - 00000000 ____D () C:\Program Files\Trademanager
2014-02-21 21:31 - 2014-02-21 21:30 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3B0DA881-2B59-4EC3-B6FE-7A4AE0C68BAF}
2014-02-21 21:31 - 2011-03-15 20:51 - 00000000 ____D () C:\Users\unknown\AppData\Local\Windows Live
2014-02-20 22:51 - 2014-02-20 02:12 - 00021504 _____ () C:\Users\unknown\Desktop\SAMS JERSEY BUSINESS.xls
2014-02-20 16:46 - 2014-02-20 16:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{18F099C4-3CE5-4516-806F-E73F1F33770E}
2014-02-20 12:08 - 2012-05-04 14:08 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-20 03:09 - 2014-02-04 18:56 - 00000000 ____D () C:\Users\unknown\Desktop\Mary and Mohammad
2014-02-20 01:39 - 2014-02-20 01:39 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B2E264EE-87EE-479E-88C8-D3AFA709CA5A}
2014-02-19 21:25 - 2014-02-19 21:12 - 00000000 ____D () C:\Users\unknown\Desktop\Stephanie Vodnik
2014-02-19 13:13 - 2014-02-19 13:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{FE58155E-F2DB-4206-94D2-C076D381045C}
2014-02-18 23:42 - 2014-02-18 23:42 - 00000000 ____D () C:\Users\unknown\AppData\Local\{78E0DC29-60A3-4BDC-B96D-7589151BC609}
2014-02-18 10:51 - 2014-02-18 10:51 - 00000000 ____D () C:\Users\unknown\AppData\Local\{6F44F1E2-F261-4814-A0D5-0D559FB63055}
2014-02-17 12:19 - 2014-02-17 12:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DCD5934F-9564-4666-AD95-8BDC02E6BE98}
2014-02-17 00:19 - 2014-02-17 00:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{86C8749A-58DF-4C3A-BD14-E688182BDF44}
2014-02-16 13:05 - 2014-02-16 13:04 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-16 12:19 - 2014-02-16 12:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A9E9283D-0593-43EF-9943-D1F3E42C9CD8}

==================== Known DLLs (Whitelisted) ============


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================

Restore point made on: 2014-03-03 11:51:04
Restore point made on: 2014-03-05 17:41:48
Restore point made on: 2014-03-08 20:14:17
Restore point made on: 2014-03-11 14:24:41
Restore point made on: 2014-03-13 08:01:22
Restore point made on: 2014-03-13 21:21:16
Restore point made on: 2014-03-16 13:36:47
Restore point made on: 2014-03-16 21:23:08

==================== Memory info ===========================

Percentage of memory in use: 23%
Total physical RAM: 1790.49 MB
Available physical RAM: 1363.2 MB
Total Pagefile: 1790.49 MB
Available Pagefile: 1369.46 MB
Total Virtual: 2047.88 MB
Available Virtual: 1951 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:298.09 GB) (Free:210.21 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: (LEXAR) (Removable) (Total:7.32 GB) (Free:3.21 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: () (Fixed) (Total:465.76 GB) (Free:206.95 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 5F96A20B)
Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: D0B92625)

Partition: GPT Partition Type.

========================================================
Disk: 2 (MBR Code: Windows XP) (Size: 7 GB) (Disk ID: C3072E18)

Partition: GPT Partition Type.


LastRegBack: 2014-03-09 13:28

==================== End Of Log ============================



#10 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:34 AM

Posted 18 March 2014 - 03:48 AM

Ok, let's try again:


Step 1

Please download this attached Attached File  fixlist.txt   401bytes   1 downloads and save it in the same directory as FRST.

  • Start FRST with Administrator privileges.
  • Press the Fix button.
  • When finished, a log file (Fixlog.txt) pops up and is saved to the same location the tool was run from.
    Please copy and paste its contents in your next reply.

 

 

 

Step 2

Restart your computer in normal mode again.
Start FRST with administator privileges.

  • Press the Scan button.
  • When finished, FRST will produce a log (FRST.txt) in the same directory the tool was run from.
    Please copy and paste this log in your next reply.


#11 Aurifex

Aurifex
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:12:34 PM

Posted 18 March 2014 - 05:05 PM

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014  01
Ran by unknown at 2014-03-19 09:04:48 Run:2
Running from C:\Users\unknown\Downloads
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
HKLM\...\Run: [ofrzutuz] - C:\ProgramData\ypmj\aqajsvid.exe [258048 2014-03-16] ()
HKLM\...\Run: [ykdhyved] - C:\ProgramData\ixem\umozufes.exe [258048 2014-03-16] ()
2014-03-16 13:52 - 2014-03-17 18:01 - 00000000 ____D () C:\ProgramData\amepugyf
2014-03-16 13:52 - 2014-03-16 13:52 - 00000000 ____D () C:\ProgramData\ixem
2014-03-16 13:48 - 2014-03-16 13:48 - 00000000 ____D () C:\ProgramData\ypmj
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ofrzutuz => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ykdhyved => Value deleted successfully.
C:\ProgramData\amepugyf => Moved successfully.
C:\ProgramData\ixem => Moved successfully.
C:\ProgramData\ypmj => Moved successfully.

==== End of Fixlog ====



#12 Aurifex

Aurifex
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:12:34 PM

Posted 18 March 2014 - 05:19 PM

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014  01
Ran by unknown (administrator) on UNKNOWN-PC on 19-03-2014 09:09:50
Running from C:\Users\unknown\Downloads
Microsoft Windows 7 Ultimate  Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Ralink Technology, Corp.) C:\Program Files\NetComm\Common\RegistryWriter.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corporation) C:\Windows\system32\PrintIsolationHost.exe
(Brother Industries, Ltd.) C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
(Nero AG) C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
() C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Brother Industries, Ltd.) C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
(Brother Industries, Ltd.) C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(NetComm Limited) C:\Program Files\NetComm\Common\RaUI.exe
(Ricoh Company, Ltd.) C:\Program Files\Caplio Software\RGateLXP.exe
(Nero AG) C:\Program Files\Nero\Update\NASvc.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [BrMfcWnd] - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.)
HKLM\...\Run: [NBAgent] - C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1234216 2010-03-26] (Nero AG)
HKLM\...\Run: [ArcSoft Connection Service] - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-08-27] (Apple Inc.)
HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [3524536 2012-07-16] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [421776 2012-09-10] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM\...\Run: [ControlCenter3] - C:\Program Files\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
HKU\S-1-5-21-2134969444-2299796119-3524533687-1000\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-06-17] (Hewlett-Packard Company)
HKU\S-1-5-21-2134969444-2299796119-3524533687-1000\...\Run: [KiesPDLR] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-07-16] ()
HKU\S-1-5-21-2134969444-2299796119-3524533687-1000\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [975800 2012-07-16] (Samsung)
HKU\S-1-5-21-2134969444-2299796119-3524533687-1000\...\Run: [News.net] - C:\Program Files\News.net\BreakingNews\DesktopContainer.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x495B2F24C440CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://iat.ninemsn.com.au/tickler/default.aspx?ocid=iehp
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {CD280D45-1C29-4E80-A506-D88F2ED4760C} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=9B874255-7D2C-47B9-97A1-9D9D5F6C44C1&apn_sauid=2B80A8AE-C505-44AC-B0EB-3E4E4063A8F8
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File
Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\unknown\AppData\Roaming\Mozilla\Firefox\Profiles\cr4c0zm7.default-1394486327657
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @alibaba.com/npwangwang;version=1.0 - C:\Program Files\Trademanager\npwangwang.dll ( )
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @pages.tvunetworks.com/WebPlayer - C:\Users\unknown\Desktop\TVUPlayer\npTVUAx.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @alibaba.com/npAliSSOLogin;version=1.0 - C:\Program Files\Trademanager\npAliSSOLogin.dll (Alibaba software (Shanghai) Corporation.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\unknown\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwangwang.dll ( )

Chrome:
=======
CHR HomePage: hxxp://www.news.net/index.php?referid=125

========================== Services (Whitelisted) =================

R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [490280 2010-03-25] (Nero AG)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 RalinkRegistryWriter; C:\Program Files\NetComm\Common\RegistryWriter.exe [69632 2008-05-13] (Ralink Technology, Corp.)

==================== Drivers (Whitelisted) ====================

S3 61883; C:\Windows\System32\DRIVERS\61883.sys [46976 2009-07-14] (Microsoft Corporation)
S3 bqusbser; C:\Windows\System32\DRIVERS\Mousbser.sys [103936 2008-05-22] (Motorola Incorporated)
R2 Hardlock; C:\Windows\system32\drivers\hardlock.sys [685056 2005-07-28] (Aladdin Knowledge Systems Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [657408 2009-07-14] (Ralink Technology Corp.)
S3 catchme; \??\C:\Users\unknown\AppData\Local\Temp\catchme.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S1 MpKsl03b5b6b2; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B4E7980A-07A0-474E-B014-2F1146D5B6EF}\MpKsl03b5b6b2.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-19 08:52 - 2014-03-19 08:52 - 00000000 ____D () C:\Users\unknown\AppData\Local\{2E36FFB0-D5CA-41A6-AEE9-CF2551AD81AE}
2014-03-18 12:55 - 2014-03-18 12:55 - 00002270 _____ () C:\Users\unknown\Desktop\New Text Document.txt
2014-03-18 07:32 - 2014-03-18 07:32 - 00000000 ____D () C:\Users\unknown\AppData\Local\{5CE6112E-A4C7-4801-AEA8-28616B63FCD3}
2014-03-17 16:23 - 2014-03-17 16:25 - 00000066 _____ () C:\Windows\Brfaxrx.ini
2014-03-17 16:23 - 2009-01-15 19:20 - 00003072 ____N (Brother Industries Ltd.) C:\Windows\system32\BrDctF2S.dll
2014-03-17 16:23 - 2008-10-17 20:02 - 00126976 ____N (Brother Industries, Ltd.) C:\Windows\system32\BrfxD05b.dll
2014-03-17 16:23 - 2007-12-13 22:16 - 00073728 ____N (Brother Industries Ltd.) C:\Windows\system32\BrDctF2.dll
2014-03-17 16:23 - 2007-12-13 22:16 - 00005120 ____N (Brother Industries Ltd.) C:\Windows\system32\BrDctF2L.dll
2014-03-17 16:23 - 2006-12-28 13:39 - 00176128 ____N (Brother Industries, Ltd.) C:\Windows\system32\BroSNMP.dll
2014-03-17 16:23 - 2003-11-28 18:57 - 00000000 _____ () C:\Windows\brdfxspd.dat
2014-03-17 16:22 - 2014-03-17 16:22 - 00000000 ____D () C:\Users\unknown\Downloads\mflpro
2014-03-17 16:22 - 2014-03-17 16:22 - 00000000 ____D () C:\Users\unknown\AppData\Roaming\InstallShield
2014-03-17 16:17 - 2014-03-17 16:21 - 42628541 _____ (A.I.SOFT,INC.) C:\Users\unknown\Downloads\MFC-665CW-inst-win7-A2.EXE
2014-03-17 08:25 - 2014-03-17 08:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\{7EE084DF-8CA9-4041-A5EE-97D4E5342390}
2014-03-16 18:02 - 2014-03-16 18:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{5631B219-0285-4AE6-A2C9-F746D7221D87}
2014-03-16 06:14 - 2014-03-16 06:38 - 00029196 _____ () C:\Users\unknown\Downloads\Addition.txt
2014-03-16 06:12 - 2014-03-19 09:09 - 00012164 _____ () C:\Users\unknown\Downloads\FRST.txt
2014-03-16 06:12 - 2014-03-19 09:09 - 00000000 ____D () C:\FRST
2014-03-16 06:11 - 2014-03-16 06:11 - 01145856 _____ (Farbar) C:\Users\unknown\Downloads\FRST.exe
2014-03-16 06:04 - 2014-03-16 06:04 - 04130656 _____ (Kaspersky Lab ZAO) C:\Users\unknown\Downloads\tdsskiller.exe
2014-03-16 06:02 - 2014-03-16 06:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{72275A55-063E-4860-BAEE-9ABBD9080EED}
2014-03-15 07:59 - 2014-03-15 07:59 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D8090C2D-71FD-481E-AB68-1FBC0756BA3A}
2014-03-14 16:34 - 2014-03-14 16:35 - 00000000 ____D () C:\Users\unknown\Desktop\New help
2014-03-14 16:33 - 2014-03-14 16:33 - 00021764 _____ () C:\Users\unknown\Desktop\dds.txt
2014-03-14 16:33 - 2014-03-14 16:33 - 00006187 _____ () C:\Users\unknown\Desktop\attach.txt
2014-03-14 16:30 - 2014-03-14 16:30 - 00688992 ____R (Swearware) C:\Users\unknown\Downloads\dds.com
2014-03-14 16:10 - 2014-03-14 16:10 - 00000000 ____D () C:\Users\unknown\AppData\Local\{22417392-7AD2-419B-9A6E-E56B23C6F117}
2014-03-14 03:00 - 2014-03-14 03:00 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B831E33C-181D-4798-99D1-47DC39FA776B}
2014-03-13 11:22 - 2014-03-01 15:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-13 11:22 - 2014-03-01 15:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-13 11:22 - 2014-03-01 15:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-13 11:22 - 2014-03-01 14:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-13 11:22 - 2014-03-01 14:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-13 11:22 - 2014-03-01 14:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-13 11:22 - 2014-03-01 14:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-13 11:22 - 2014-03-01 14:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-13 11:22 - 2014-03-01 14:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-13 11:22 - 2014-03-01 14:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-13 11:22 - 2014-03-01 14:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-13 11:22 - 2014-03-01 14:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-13 11:22 - 2014-03-01 14:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-13 11:22 - 2014-03-01 14:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-13 11:22 - 2014-03-01 14:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-13 11:22 - 2014-03-01 14:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-13 11:22 - 2014-03-01 14:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-13 11:22 - 2014-03-01 14:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-13 11:22 - 2014-03-01 13:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-13 11:22 - 2014-03-01 13:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-13 11:22 - 2014-03-01 13:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-13 11:22 - 2014-03-01 13:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-13 11:22 - 2014-02-04 13:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-13 11:20 - 2014-02-07 12:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-13 11:20 - 2014-02-04 13:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-13 11:20 - 2014-01-29 13:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-13 11:20 - 2014-01-28 13:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-13 11:20 - 2014-01-09 13:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-03-13 08:19 - 2014-03-13 08:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{58513ECF-F5D2-44E5-9F4C-9A0CBDF45CC6}
2014-03-12 09:26 - 2013-10-02 11:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-03-12 09:26 - 2013-10-02 11:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-03-12 09:26 - 2013-10-02 10:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-03-12 09:26 - 2012-08-24 01:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-03-12 09:26 - 2012-08-24 01:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-03-12 09:26 - 2012-08-24 00:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-03-12 09:26 - 2012-08-23 22:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-03-12 09:26 - 2012-08-23 21:08 - 02739712 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-03-12 09:25 - 2013-10-02 11:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-03-12 09:25 - 2013-10-02 11:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-03-12 09:25 - 2013-10-02 11:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-03-12 09:25 - 2013-10-02 10:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-03-12 09:25 - 2013-10-02 10:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-03-12 09:25 - 2013-10-02 10:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-03-12 09:25 - 2013-10-02 09:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-03-12 09:25 - 2013-10-02 09:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-03-12 09:24 - 2013-09-25 12:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-03-12 09:24 - 2012-05-04 20:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-03-12 09:19 - 2014-03-12 09:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F96658A8-FAF7-4C1D-86ED-1C0CEFDA33BE}
2014-03-11 20:57 - 2014-03-11 20:57 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3CBA1460-F382-4ECA-BC06-C439939ADE7C}
2014-03-11 16:45 - 2014-03-11 16:45 - 00000941 _____ () C:\Users\Public\Desktop\Speccy.lnk
2014-03-11 16:45 - 2014-03-11 16:45 - 00000000 ____D () C:\Program Files\Speccy
2014-03-11 16:45 - 2014-03-11 16:42 - 04845384 _____ (Piriform Ltd) C:\Users\unknown\Desktop\spsetup125.exe
2014-03-11 14:30 - 2014-03-11 14:30 - 00000035 _____ () C:\Users\unknown\Desktop\eset.txt
2014-03-11 11:45 - 2014-03-11 11:45 - 00000000 ____D () C:\Program Files\ESET
2014-03-11 11:25 - 2014-03-11 11:25 - 00027544 _____ () C:\Users\unknown\Desktop\Result.txt
2014-03-11 11:24 - 2014-03-11 11:24 - 00000854 _____ () C:\Users\unknown\Desktop\checkup.txt
2014-03-11 08:27 - 2014-03-11 08:27 - 00001071 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-11 08:27 - 2014-03-11 08:27 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-11 08:27 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-11 08:18 - 2014-03-11 08:18 - 00000000 ____D () C:\Users\unknown\Desktop\Old Firefox Data
2014-03-11 07:46 - 2014-03-11 07:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{824DB67E-2AF1-4AB3-B831-9599F9BFBA69}
2014-03-10 19:46 - 2014-03-10 19:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{480D26A8-315E-4F8A-99F9-64C14003FA5E}
2014-03-10 07:43 - 2014-03-10 07:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CBF052D1-D3A3-4F18-BAE7-9B7CD75C2A6C}
2014-03-08 19:30 - 2014-03-19 09:00 - 00000000 ____D () C:\Users\unknown\AppData\Local\CrashDumps
2014-03-08 19:30 - 2014-03-09 14:57 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A88AE5B2-ABEB-4965-B22F-71157B3D3010}
2014-03-08 07:15 - 2014-02-15 10:33 - 00000426 _____ () C:\AVScanner.ini
2014-03-08 07:12 - 2014-03-08 07:12 - 00000855 _____ () C:\Users\unknown\Desktop\µTorrent.lnk
2014-03-08 07:09 - 2014-03-08 07:10 - 01853008 _____ (BitTorrent Inc.) C:\Users\unknown\Downloads\uTorrent.exe
2014-03-08 07:06 - 2014-03-08 07:06 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D96128E7-775A-4D37-96E2-8E5A5750BEC2}
2014-03-07 12:44 - 2014-03-07 13:05 - 00000000 ____D () C:\Users\unknown\Desktop\GARAGE BUILDING DOCS
2014-03-07 10:13 - 2014-03-07 10:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F9AAEE8B-864D-4ACD-9F94-7F0FCF0559E7}
2014-03-06 09:03 - 2014-03-06 09:03 - 03819008 _____ () C:\Users\unknown\Downloads\RogueKiller.exe
2014-03-06 09:02 - 2014-03-06 09:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DE030B0A-6BE1-4FDF-A1FF-1B6262C897A8}
2014-03-05 19:44 - 2014-03-05 19:44 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E56DB46F-396F-4167-85EE-422A02FE158C}
2014-03-05 07:47 - 2014-03-05 07:48 - 00380416 _____ () C:\Users\unknown\Downloads\jh0vxwq9.exe
2014-03-05 07:43 - 2014-03-05 07:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{937EBBB1-75AC-416B-8518-6FFDD411C514}
2014-03-04 11:17 - 2014-03-04 11:17 - 02347384 _____ (ESET) C:\Users\unknown\Desktop\esetsmartinstaller_enu.exe
2014-03-04 07:40 - 2014-03-04 07:40 - 00144400 _____ () C:\Windows\Minidump\030414-21933-01.dmp
2014-03-04 06:53 - 2014-03-04 06:53 - 00000000 ____D () C:\ProgramData\Oracle
2014-03-04 06:52 - 2014-03-04 06:52 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-03-04 06:52 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-03-04 06:52 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-03-04 06:52 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-03-04 06:52 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-03-04 06:51 - 2014-03-04 06:52 - 00005822 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-03-04 06:43 - 2014-03-04 06:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{8445ED36-709F-489C-8A19-08FA29853D50}
2014-03-03 17:17 - 2014-03-03 17:17 - 00144400 _____ () C:\Windows\Minidump\030314-23181-01.dmp
2014-03-03 16:19 - 2014-03-03 16:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CE1B8D22-0818-46C6-B5C6-5ABD7F0F53A1}
2014-03-03 14:44 - 2014-03-03 14:46 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\unknown\Desktop\mbam-setup.exe
2014-03-03 14:40 - 2014-03-03 14:40 - 00982016 _____ (Farbar) C:\Users\unknown\Desktop\MiniToolBox.exe
2014-03-03 14:35 - 2014-03-03 14:35 - 00987425 _____ () C:\Users\unknown\Desktop\SecurityCheck.exe
2014-03-03 04:19 - 2014-03-03 04:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{C8553F1C-DCC3-4186-81AC-D59DC80B7754}
2014-03-02 08:22 - 2014-03-02 08:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{7988F25E-42D5-483F-8C31-AA7B00BB8350}
2014-03-01 08:53 - 2014-03-01 08:54 - 00000000 ____D () C:\Users\unknown\AppData\Local\{76D4D32B-9E1E-4329-9BDD-16DD7866C0E9}
2014-02-28 06:52 - 2014-02-28 06:52 - 00000000 ____D () C:\Users\unknown\AppData\Local\{12C0B45D-95EB-4F40-8055-5988414D1F2A}
2014-02-27 07:35 - 2014-02-27 07:35 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D95EA739-1005-4962-8FE2-6DC10B269C6C}
2014-02-26 08:11 - 2014-02-26 08:11 - 00000000 ____D () C:\Users\unknown\AppData\Local\{4A52383B-9DA4-4D77-8997-3635B681EF21}
2014-02-25 18:25 - 2014-02-25 18:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D6B27FDB-5D94-4B77-929F-CD800B3BBD30}
2014-02-25 07:14 - 2014-02-25 07:28 - 00000000 ____D () C:\Users\unknown\Desktop\2014-02-25 Stephanies Jewellery resell
2014-02-25 06:22 - 2014-02-25 06:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E5CAC627-E354-4FFA-B81B-40B990A40CF8}
2014-02-24 17:49 - 2014-02-24 17:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{414E4E6C-C6CE-42E7-8CF4-26CF6F52FE1A}
2014-02-24 05:49 - 2014-02-24 05:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A0A0B8AF-CB9C-44E5-B043-D982A1548B56}
2014-02-23 05:52 - 2014-02-23 05:53 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A2C20AE5-2970-4901-8E5F-28854CF0719C}
2014-02-22 16:55 - 2014-02-22 16:56 - 00263680 _____ () C:\Users\unknown\Desktop\Irrigation Solution Questionnaire.xls
2014-02-22 16:30 - 2014-02-22 16:31 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3B0DA881-2B59-4EC3-B6FE-7A4AE0C68BAF}
2014-02-21 11:46 - 2014-02-21 11:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{18F099C4-3CE5-4516-806F-E73F1F33770E}
2014-02-20 21:12 - 2014-02-21 17:51 - 00021504 _____ () C:\Users\unknown\Desktop\SAMS JERSEY BUSINESS.xls
2014-02-20 20:39 - 2014-02-20 20:39 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B2E264EE-87EE-479E-88C8-D3AFA709CA5A}
2014-02-20 16:12 - 2014-02-20 16:25 - 00000000 ____D () C:\Users\unknown\Desktop\Stephanie Vodnik
2014-02-20 08:13 - 2014-02-20 08:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{FE58155E-F2DB-4206-94D2-C076D381045C}
2014-02-19 18:42 - 2014-02-19 18:42 - 00000000 ____D () C:\Users\unknown\AppData\Local\{78E0DC29-60A3-4BDC-B96D-7589151BC609}
2014-02-19 05:51 - 2014-02-19 05:51 - 00000000 ____D () C:\Users\unknown\AppData\Local\{6F44F1E2-F261-4814-A0D5-0D559FB63055}
2014-02-18 07:19 - 2014-02-18 07:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DCD5934F-9564-4666-AD95-8BDC02E6BE98}
2014-02-17 19:19 - 2014-02-17 19:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{86C8749A-58DF-4C3A-BD14-E688182BDF44}
2014-02-17 08:04 - 2014-02-17 08:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-17 07:19 - 2014-02-17 07:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A9E9283D-0593-43EF-9943-D1F3E42C9CD8}

==================== One Month Modified Files and Folders =======

2014-03-19 09:10 - 2014-03-16 06:12 - 00012164 _____ () C:\Users\unknown\Downloads\FRST.txt
2014-03-19 09:09 - 2014-03-16 06:12 - 00000000 ____D () C:\FRST
2014-03-19 09:07 - 2011-12-03 09:54 - 08405015 _____ () C:\Windows\TempFile
2014-03-19 09:07 - 2011-08-29 11:55 - 00000884 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-19 09:07 - 2009-07-14 15:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-19 09:07 - 2009-07-14 15:39 - 00135035 _____ () C:\Windows\setupact.log
2014-03-19 09:05 - 2011-03-16 10:13 - 02051464 _____ () C:\Windows\WindowsUpdate.log
2014-03-19 09:00 - 2014-03-08 19:30 - 00000000 ____D () C:\Users\unknown\AppData\Local\CrashDumps
2014-03-19 08:56 - 2012-04-01 17:58 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-19 08:52 - 2014-03-19 08:52 - 00000000 ____D () C:\Users\unknown\AppData\Local\{2E36FFB0-D5CA-41A6-AEE9-CF2551AD81AE}
2014-03-19 08:52 - 2011-08-29 11:55 - 00000888 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-18 13:20 - 2009-07-14 15:34 - 00014416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-18 13:20 - 2009-07-14 15:34 - 00014416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-18 13:13 - 2011-10-29 20:10 - 00000000 ____D () C:\ProgramData\Sun
2014-03-18 12:55 - 2014-03-18 12:55 - 00002270 _____ () C:\Users\unknown\Desktop\New Text Document.txt
2014-03-18 12:55 - 2011-03-16 10:23 - 00782510 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-18 07:32 - 2014-03-18 07:32 - 00000000 ____D () C:\Users\unknown\AppData\Local\{5CE6112E-A4C7-4801-AEA8-28616B63FCD3}
2014-03-17 16:27 - 2011-03-17 06:20 - 00000829 _____ () C:\Windows\Brpfx04a.ini
2014-03-17 16:27 - 2011-03-17 06:20 - 00000419 _____ () C:\Windows\BRWMARK.INI
2014-03-17 16:27 - 2011-03-17 06:20 - 00000163 _____ () C:\Windows\brpcfx.ini
2014-03-17 16:27 - 2011-03-17 06:20 - 00000027 _____ () C:\Windows\BRPP2KA.INI
2014-03-17 16:25 - 2014-03-17 16:23 - 00000066 _____ () C:\Windows\Brfaxrx.ini
2014-03-17 16:25 - 2011-03-17 06:19 - 00000050 _____ () C:\Windows\system32\bridf06a.dat
2014-03-17 16:24 - 2013-08-05 11:39 - 00000000 ____D () C:\Program Files\Brother
2014-03-17 16:23 - 2011-03-17 06:18 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-03-17 16:22 - 2014-03-17 16:22 - 00000000 ____D () C:\Users\unknown\Downloads\mflpro
2014-03-17 16:22 - 2014-03-17 16:22 - 00000000 ____D () C:\Users\unknown\AppData\Roaming\InstallShield
2014-03-17 16:21 - 2014-03-17 16:17 - 42628541 _____ (A.I.SOFT,INC.) C:\Users\unknown\Downloads\MFC-665CW-inst-win7-A2.EXE
2014-03-17 08:49 - 2011-03-17 01:23 - 00164338 _____ () C:\Windows\PFRO.log
2014-03-17 08:25 - 2014-03-17 08:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\{7EE084DF-8CA9-4041-A5EE-97D4E5342390}
2014-03-16 18:02 - 2014-03-16 18:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{5631B219-0285-4AE6-A2C9-F746D7221D87}
2014-03-16 06:38 - 2014-03-16 06:14 - 00029196 _____ () C:\Users\unknown\Downloads\Addition.txt
2014-03-16 06:11 - 2014-03-16 06:11 - 01145856 _____ (Farbar) C:\Users\unknown\Downloads\FRST.exe
2014-03-16 06:04 - 2014-03-16 06:04 - 04130656 _____ (Kaspersky Lab ZAO) C:\Users\unknown\Downloads\tdsskiller.exe
2014-03-16 06:02 - 2014-03-16 06:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{72275A55-063E-4860-BAEE-9ABBD9080EED}
2014-03-15 15:05 - 2011-03-26 13:00 - 00000000 ____D () C:\Users\unknown\AppData\Roaming\uTorrent
2014-03-15 07:59 - 2014-03-15 07:59 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D8090C2D-71FD-481E-AB68-1FBC0756BA3A}
2014-03-14 16:35 - 2014-03-14 16:34 - 00000000 ____D () C:\Users\unknown\Desktop\New help
2014-03-14 16:33 - 2014-03-14 16:33 - 00021764 _____ () C:\Users\unknown\Desktop\dds.txt
2014-03-14 16:33 - 2014-03-14 16:33 - 00006187 _____ () C:\Users\unknown\Desktop\attach.txt
2014-03-14 16:30 - 2014-03-14 16:30 - 00688992 ____R (Swearware) C:\Users\unknown\Downloads\dds.com
2014-03-14 16:10 - 2014-03-14 16:10 - 00000000 ____D () C:\Users\unknown\AppData\Local\{22417392-7AD2-419B-9A6E-E56B23C6F117}
2014-03-14 11:28 - 2009-07-14 13:37 - 00000000 ____D () C:\Windows\rescache
2014-03-14 03:28 - 2009-07-14 15:33 - 03692064 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-14 03:27 - 2011-06-13 11:57 - 00000362 __RSH () C:\ProgramData\ntuser.pol
2014-03-14 03:26 - 2011-03-16 15:53 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-14 03:00 - 2014-03-14 03:00 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B831E33C-181D-4798-99D1-47DC39FA776B}
2014-03-13 08:19 - 2014-03-13 08:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{58513ECF-F5D2-44E5-9F4C-9A0CBDF45CC6}
2014-03-12 09:56 - 2012-04-01 17:58 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-12 09:56 - 2011-05-20 08:14 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-12 09:19 - 2014-03-12 09:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F96658A8-FAF7-4C1D-86ED-1C0CEFDA33BE}
2014-03-11 20:57 - 2014-03-11 20:57 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3CBA1460-F382-4ECA-BC06-C439939ADE7C}
2014-03-11 16:45 - 2014-03-11 16:45 - 00000941 _____ () C:\Users\Public\Desktop\Speccy.lnk
2014-03-11 16:45 - 2014-03-11 16:45 - 00000000 ____D () C:\Program Files\Speccy
2014-03-11 16:42 - 2014-03-11 16:45 - 04845384 _____ (Piriform Ltd) C:\Users\unknown\Desktop\spsetup125.exe
2014-03-11 14:30 - 2014-03-11 14:30 - 00000035 _____ () C:\Users\unknown\Desktop\eset.txt
2014-03-11 11:45 - 2014-03-11 11:45 - 00000000 ____D () C:\Program Files\ESET
2014-03-11 11:25 - 2014-03-11 11:25 - 00027544 _____ () C:\Users\unknown\Desktop\Result.txt
2014-03-11 11:24 - 2014-03-11 11:24 - 00000854 _____ () C:\Users\unknown\Desktop\checkup.txt
2014-03-11 08:27 - 2014-03-11 08:27 - 00001071 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-11 08:27 - 2014-03-11 08:27 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-11 08:18 - 2014-03-11 08:18 - 00000000 ____D () C:\Users\unknown\Desktop\Old Firefox Data
2014-03-11 07:46 - 2014-03-11 07:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{824DB67E-2AF1-4AB3-B831-9599F9BFBA69}
2014-03-10 19:46 - 2014-03-10 19:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{480D26A8-315E-4F8A-99F9-64C14003FA5E}
2014-03-10 13:02 - 2011-07-24 20:00 - 12102144 ___SH () C:\Users\unknown\Desktop\Thumbs.db
2014-03-10 07:43 - 2014-03-10 07:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CBF052D1-D3A3-4F18-BAE7-9B7CD75C2A6C}
2014-03-09 14:57 - 2014-03-08 19:30 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A88AE5B2-ABEB-4965-B22F-71157B3D3010}
2014-03-08 07:12 - 2014-03-08 07:12 - 00000855 _____ () C:\Users\unknown\Desktop\µTorrent.lnk
2014-03-08 07:10 - 2014-03-08 07:09 - 01853008 _____ (BitTorrent Inc.) C:\Users\unknown\Downloads\uTorrent.exe
2014-03-08 07:06 - 2014-03-08 07:06 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D96128E7-775A-4D37-96E2-8E5A5750BEC2}
2014-03-07 13:05 - 2014-03-07 12:44 - 00000000 ____D () C:\Users\unknown\Desktop\GARAGE BUILDING DOCS
2014-03-07 10:13 - 2014-03-07 10:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{F9AAEE8B-864D-4ACD-9F94-7F0FCF0559E7}
2014-03-06 09:03 - 2014-03-06 09:03 - 03819008 _____ () C:\Users\unknown\Downloads\RogueKiller.exe
2014-03-06 09:02 - 2014-03-06 09:02 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DE030B0A-6BE1-4FDF-A1FF-1B6262C897A8}
2014-03-05 19:44 - 2014-03-05 19:44 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E56DB46F-396F-4167-85EE-422A02FE158C}
2014-03-05 07:48 - 2014-03-05 07:47 - 00380416 _____ () C:\Users\unknown\Downloads\jh0vxwq9.exe
2014-03-05 07:43 - 2014-03-05 07:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{937EBBB1-75AC-416B-8518-6FFDD411C514}
2014-03-04 12:56 - 2013-07-11 13:46 - 00000000 ____D () C:\Users\unknown\Desktop\microsoft office
2014-03-04 11:17 - 2014-03-04 11:17 - 02347384 _____ (ESET) C:\Users\unknown\Desktop\esetsmartinstaller_enu.exe
2014-03-04 11:11 - 2009-07-14 13:37 - 00000000 ____D () C:\Windows\L2Schemas
2014-03-04 07:40 - 2014-03-04 07:40 - 00144400 _____ () C:\Windows\Minidump\030414-21933-01.dmp
2014-03-04 07:40 - 2011-04-19 16:38 - 257085711 _____ () C:\Windows\MEMORY.DMP
2014-03-04 07:40 - 2011-04-19 16:38 - 00000000 ____D () C:\Windows\Minidump
2014-03-04 07:03 - 2011-03-17 06:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\Adobe
2014-03-04 07:01 - 2011-06-18 08:08 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-03-04 07:01 - 2011-03-17 06:46 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-04 07:01 - 2011-03-17 06:46 - 00000000 ____D () C:\Program Files\Adobe
2014-03-04 06:53 - 2014-03-04 06:53 - 00000000 ____D () C:\ProgramData\Oracle
2014-03-04 06:52 - 2014-03-04 06:52 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-03-04 06:52 - 2014-03-04 06:51 - 00005822 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-03-04 06:52 - 2011-10-29 20:09 - 00000000 ____D () C:\Program Files\Java
2014-03-04 06:43 - 2014-03-04 06:43 - 00000000 ____D () C:\Users\unknown\AppData\Local\{8445ED36-709F-489C-8A19-08FA29853D50}
2014-03-03 17:17 - 2014-03-03 17:17 - 00144400 _____ () C:\Windows\Minidump\030314-23181-01.dmp
2014-03-03 16:19 - 2014-03-03 16:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{CE1B8D22-0818-46C6-B5C6-5ABD7F0F53A1}
2014-03-03 15:12 - 2009-07-14 13:37 - 00000000 ____D () C:\Windows\PLA
2014-03-03 14:46 - 2014-03-03 14:44 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\unknown\Desktop\mbam-setup.exe
2014-03-03 14:40 - 2014-03-03 14:40 - 00982016 _____ (Farbar) C:\Users\unknown\Desktop\MiniToolBox.exe
2014-03-03 14:35 - 2014-03-03 14:35 - 00987425 _____ () C:\Users\unknown\Desktop\SecurityCheck.exe
2014-03-03 04:19 - 2014-03-03 04:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{C8553F1C-DCC3-4186-81AC-D59DC80B7754}
2014-03-02 08:22 - 2014-03-02 08:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{7988F25E-42D5-483F-8C31-AA7B00BB8350}
2014-03-01 15:30 - 2014-03-13 11:22 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-01 15:11 - 2014-03-13 11:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-01 15:10 - 2014-03-13 11:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-01 14:52 - 2014-03-13 11:22 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-01 14:51 - 2014-03-13 11:22 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-01 14:47 - 2014-03-13 11:22 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-01 14:43 - 2014-03-13 11:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-01 14:43 - 2014-03-13 11:22 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-01 14:40 - 2014-03-13 11:22 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-01 14:38 - 2014-03-13 11:22 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-01 14:38 - 2014-03-13 11:22 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-01 14:37 - 2014-03-13 11:22 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-01 14:31 - 2014-03-13 11:22 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-01 14:25 - 2014-03-13 11:22 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-01 14:16 - 2014-03-13 11:22 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-01 14:14 - 2014-03-13 11:22 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-01 14:03 - 2014-03-13 11:22 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-01 14:00 - 2014-03-13 11:22 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-01 13:57 - 2014-03-13 11:22 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-01 13:32 - 2014-03-13 11:22 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-01 13:27 - 2014-03-13 11:22 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-01 13:25 - 2014-03-13 11:22 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-01 08:54 - 2014-03-01 08:53 - 00000000 ____D () C:\Users\unknown\AppData\Local\{76D4D32B-9E1E-4329-9BDD-16DD7866C0E9}
2014-02-28 06:52 - 2014-02-28 06:52 - 00000000 ____D () C:\Users\unknown\AppData\Local\{12C0B45D-95EB-4F40-8055-5988414D1F2A}
2014-02-27 07:35 - 2014-02-27 07:35 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D95EA739-1005-4962-8FE2-6DC10B269C6C}
2014-02-26 08:11 - 2014-02-26 08:11 - 00000000 ____D () C:\Users\unknown\AppData\Local\{4A52383B-9DA4-4D77-8997-3635B681EF21}
2014-02-25 18:25 - 2014-02-25 18:25 - 00000000 ____D () C:\Users\unknown\AppData\Local\{D6B27FDB-5D94-4B77-929F-CD800B3BBD30}
2014-02-25 07:28 - 2014-02-25 07:14 - 00000000 ____D () C:\Users\unknown\Desktop\2014-02-25 Stephanies Jewellery resell
2014-02-25 06:22 - 2014-02-25 06:22 - 00000000 ____D () C:\Users\unknown\AppData\Local\{E5CAC627-E354-4FFA-B81B-40B990A40CF8}
2014-02-24 17:49 - 2014-02-24 17:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{414E4E6C-C6CE-42E7-8CF4-26CF6F52FE1A}
2014-02-24 05:49 - 2014-02-24 05:49 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A0A0B8AF-CB9C-44E5-B043-D982A1548B56}
2014-02-23 05:53 - 2014-02-23 05:52 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A2C20AE5-2970-4901-8E5F-28854CF0719C}
2014-02-22 16:56 - 2014-02-22 16:55 - 00263680 _____ () C:\Users\unknown\Desktop\Irrigation Solution Questionnaire.xls
2014-02-22 16:44 - 2013-12-30 14:26 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-02-22 16:44 - 2011-12-09 19:21 - 00000000 ____D () C:\Program Files\Trademanager
2014-02-22 16:31 - 2014-02-22 16:30 - 00000000 ____D () C:\Users\unknown\AppData\Local\{3B0DA881-2B59-4EC3-B6FE-7A4AE0C68BAF}
2014-02-22 16:31 - 2011-03-16 15:51 - 00000000 ____D () C:\Users\unknown\AppData\Local\Windows Live
2014-02-21 17:51 - 2014-02-20 21:12 - 00021504 _____ () C:\Users\unknown\Desktop\SAMS JERSEY BUSINESS.xls
2014-02-21 11:46 - 2014-02-21 11:46 - 00000000 ____D () C:\Users\unknown\AppData\Local\{18F099C4-3CE5-4516-806F-E73F1F33770E}
2014-02-21 07:08 - 2012-05-05 09:08 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-20 22:09 - 2014-02-05 13:56 - 00000000 ____D () C:\Users\unknown\Desktop\Mary and Mohammad
2014-02-20 20:39 - 2014-02-20 20:39 - 00000000 ____D () C:\Users\unknown\AppData\Local\{B2E264EE-87EE-479E-88C8-D3AFA709CA5A}
2014-02-20 16:25 - 2014-02-20 16:12 - 00000000 ____D () C:\Users\unknown\Desktop\Stephanie Vodnik
2014-02-20 08:13 - 2014-02-20 08:13 - 00000000 ____D () C:\Users\unknown\AppData\Local\{FE58155E-F2DB-4206-94D2-C076D381045C}
2014-02-19 18:42 - 2014-02-19 18:42 - 00000000 ____D () C:\Users\unknown\AppData\Local\{78E0DC29-60A3-4BDC-B96D-7589151BC609}
2014-02-19 05:51 - 2014-02-19 05:51 - 00000000 ____D () C:\Users\unknown\AppData\Local\{6F44F1E2-F261-4814-A0D5-0D559FB63055}
2014-02-18 07:19 - 2014-02-18 07:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{DCD5934F-9564-4666-AD95-8BDC02E6BE98}
2014-02-17 19:19 - 2014-02-17 19:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{86C8749A-58DF-4C3A-BD14-E688182BDF44}
2014-02-17 08:05 - 2014-02-17 08:04 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-17 07:19 - 2014-02-17 07:19 - 00000000 ____D () C:\Users\unknown\AppData\Local\{A9E9283D-0593-43EF-9943-D1F3E42C9CD8}

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-10 08:28

==================== End Of Log ============================



#13 Aurifex

Aurifex
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:12:34 PM

Posted 18 March 2014 - 05:23 PM

Seems to be working now, what did you do? what kind of virus was that?

 

Thanks heaps.



#14 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:34 AM

Posted 18 March 2014 - 05:42 PM

Are all problems and symptoms now gone?
This seems to be infostealer malware. I therefor recommend to change all credentials (passwords etc.) that have been used on this computer as they might have been logged.

 

 

Let's do a final quickscan with MBAM:

  • Start MBAM with administator privileges.
  • Open the tab Update and click on Check for Updates.
  • Open the tab Scanner, select Perform Quick Scan and press the Scan button.
  • When the scan is finished click on Show results.
  • Make sure that all the malware found is checked and click on Remove selected. Allow a reboot if one is required.
  • When finished MBAM shows a log file. (It can also be found under the Logs tab.)
    Please copy and paste the contents of this log file in your next reply.


#15 Aurifex

Aurifex
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:12:34 PM

Posted 18 March 2014 - 09:25 PM

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2014.03.19.01

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16521
unknown :: UNKNOWN-PC [administrator]

19-Mar-14 1:03:51 PM
mbam-log-2014-03-19 (13-03-51).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 265260
Time elapsed: 16 minute(s), 29 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
 






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users