Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

MBAM just detected 2 Trojans!!


  • This topic is locked This topic is locked
13 replies to this topic

#1 texasmitch14

texasmitch14

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 01 June 2014 - 09:01 AM

The past 48 hours I have been noticing my computer running extremely loud. I open ctrl+alt+delete and noticed this processes was taking up all my CPU Memory; after googling the processes I figured it was a part of Windows Media Player and could be closed out- everytime I ended the process my computer would stop being super loud and go back to normal.


A couple days went by.. When I would power on my computer it would sound like a jet engine or the GPU is working in overdrive or something; So everytime I would just end the process.


This morning Malwarebytes detected 2 TROJANS on my computer with the same exact name of the process I found to be giving me issues. I have since quarantined in MBAM Premium. But I am afraid I am still infected.


Can someone please help verify if my computer is malware free?
Do I need to change ALL the passwords of the accounts I logged in to while I was infected? (I logged in to everything from my e-mail, bank to gaming accounts).


Please help me!!

Windows 7 Ultimate
64bit


Edited by texasmitch14, 01 June 2014 - 09:46 AM.


BC AdBot (Login to Remove)

 


m

#2 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Instructor
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:01:35 AM

Posted 01 June 2014 - 06:57 PM

Hello texasmitch14, and welcome to the forums! :)

My name is bloopie and I will be assisting you with your malware issues!

 

==========

 

Before we begin, I must impress the point of patience to your topic! It has been mere minutes without a reply, and already you have posted in the 'Please post in this topic if you have not received help after three days'!?! Did you not read the instructions posted there!!?!

 

There are many users waiting much longer without a response with situations that are much more time-sensitive than yours are!

 

Normally, your post in that topic would be removed without anyone even looking at it (as the instructions clearly state):

This thread is only to be posted in if you have not begun receiving help after three days of waiting. Posts made here prior to the three day mark will be deleted without notice.

 

So, consider yourself extremely lucky, that I have come across your post in the meantime! I sincerely hope that you will not be so impatient with the help that I provide, and analysis of your logs! I have a child, and a life at home...this time is what I use to help people in need.

 

==========

 

Because I would like a log that is not allowed in the Am I Infected sub-forum (a FRST log), I have moved this topic to the Malware Removal Logs forum where it will stay.

==========

As indicated by the name of your topic (MBAM just detected 2 Trojans!!), could you please post the log from MBAM (Malwarebytes) with those detections, and I will have a look at it for you? :)

==========

In addition to the MBAM log, please post the two logs from FRST (as instructed below):

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system....You will need the 64-bit version for your system!

  • Right-click FRST then click "Run as administrator".
  • When the tool opens, click Yes to disclaimer.
  • Press the Scan button.
  • When finished, it will produce a log called FRST.txt in the same directory the tool was run from.
  • Please copy and paste the log in your next reply.

Note 2: The first time the tool is run it generates another log (Addition.txt - also located in the same directory the tool was run from). Please also paste that, along with the FRST.txt into your next reply.

==========

Please attach only the Addition.txt in your next reply. Copy and Paste all other requested logs!

 

bloopie



#3 texasmitch14

texasmitch14
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 01 June 2014 - 07:23 PM

I apologize for posting in there- I explained my reason for doing so which I thought would be okay, but I was wrong. I recall a few years ago(a different account) I was left waiting for so long and the reason was because it was "overlooked" and was told that staff only look for posts with 0 replies. I am grateful you are helping me and I understand your time is valuable and will be patient with you- and again, apologize for the post.

 

As requested:

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 6/1/2014
Scan Time: 8:37:18 AM
Logfile:
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.06.01.04
Rootkit Database: v2014.05.21.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Mitch

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 319374
Time Elapsed: 5 min, 5 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 1
Trojan.Agent, HKU\S-1-5-21-669321762-1534808536-1154673294-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Windows Media Player Network Sharing Service, rundll32 "C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Recent\wmpnetwk.dll",_EntryPoint_RunDll32@16, Delete-on-Reboot, [db6dd1a26a11fe38769e5fbf05fef60a]

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 1
Trojan.Agent, C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Recent\wmpnetwk.dll, Quarantined, [db6dd1a26a11fe38769e5fbf05fef60a],

Physical Sectors: 0
(No malicious items detected)


(end)

 

After downloading and launching Farbar Recovery I got the following error mesage:

[Application Error]

Exception EAccessViolation in module ERUNT.exe at 00003A62. Access violation at address 00403A62 in module 'ERUNT.exe'. Read of address 0069005C.

 

 

Requested FRST Log:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-06-2014 01
Ran by Mitch (administrator) on MITCH-PC on 01-06-2014 19:20:24
Running from C:\Users\Mitch\Downloads
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(SoftThinks SAS) C:\Program Files (x86)\AlienRespawn\SftService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(SoftThinks - Dell) C:\Program Files (x86)\AlienRespawn\Toaster.exe
() C:\Program Files (x86)\AlienRespawn\Components\Scheduler\STService.exe
(SoftThinks - Dell) C:\Program Files (x86)\AlienRespawn\Components\DSUpdate\DSUpd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology enterprise\IAStorIcon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
(Alienware) C:\Program Files\Alienware\Command Center\ThermalController.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
(Blizzard Entertainment, Inc.) C:\Program Files (x86)\StarCraft II\Versions\Base28667\SC2.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6419560 2011-11-21] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1156712 2011-11-21] (Realtek Semiconductor)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [Command Center Controllers] => C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [12616 2012-01-10] (Alienware)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology enterprise\IAStorIcon.exe [286720 2011-10-12] (Intel Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [183376 2014-05-07] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-25] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585048 2014-04-17] (Razer Inc.)
HKU\S-1-5-21-669321762-1534808536-1154673294-1000\...\Run: [Steam] => c:\Program Files (x86)\Steam\steam.exe [1754816 2014-05-29] (Valve Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://AlienwareArena.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://AlienwareArena.com
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} -  No File
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll (Belarc, Inc.)
Tcpip\Parameters: [DhcpNameServer] 75.75.76.76 75.75.75.75

FireFox:
========
FF ProfilePath: C:\Users\Mitch\AppData\Roaming\Mozilla\Firefox\Profiles\32eti7c4.default
FF Homepage: google.com
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Extension: NoScript - C:\Users\Mitch\AppData\Roaming\Mozilla\Firefox\Profiles\32eti7c4.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-05-16]
FF Extension: Adblock Plus - C:\Users\Mitch\AppData\Roaming\Mozilla\Firefox\Profiles\32eti7c4.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-05-14]

==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [123984 2014-05-07] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [X]
S2 NvNetworkService; "C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe" [X]
S2 NvStreamSvc; "C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" [X]

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-02-25] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-02-25] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [23832 2011-10-12] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-01] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 rusb3hub; C:\Windows\System32\DRIVERS\rusb3hub.sys [100352 2011-09-15] (Renesas Electronics Corporation)
R3 rusb3xhc; C:\Windows\System32\DRIVERS\rusb3xhc.sys [216064 2011-09-15] (Renesas Electronics Corporation)
R3 rzdaendpt; C:\Windows\System32\DRIVERS\rzdaendpt.sys [33448 2014-04-08] (Razer Inc)
R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39080 2014-04-08] (Razer Inc)
R3 rzvkeyboard; C:\Windows\System32\DRIVERS\rzvkeyboard.sys [31400 2014-04-08] (Razer Inc)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-01 19:20 - 2014-06-01 19:20 - 00010542 _____ () C:\Users\Mitch\Downloads\FRST.txt
2014-06-01 19:18 - 2014-06-01 19:20 - 00000000 ____D () C:\FRST
2014-06-01 19:17 - 2014-06-01 19:17 - 02067456 _____ (Farbar) C:\Users\Mitch\Downloads\FRST64.exe
2014-06-01 08:53 - 2014-06-01 16:08 - 00000718 _____ () C:\Windows\PFRO.log
2014-05-30 10:34 - 2014-05-30 10:34 - 00000942 __RSH () C:\ProgramData\ntuser.pol
2014-05-30 10:29 - 2014-05-30 10:29 - 00000906 ____R () C:\Users\Mitch\Documents\bl rcvy key.txt
2014-05-28 15:42 - 2014-05-28 15:42 - 00000038 _____ () C:\Users\Mitch\Desktop\comcast supervisor.txt
2014-05-28 15:17 - 2014-05-28 16:43 - 00001078 _____ () C:\Users\Mitch\Desktop\New Text Document (2).txt
2014-05-27 16:13 - 2014-05-27 16:13 - 00000000 _____ () C:\Users\Mitch\Desktop\New Text Document.txt
2014-05-25 11:24 - 2014-05-25 11:24 - 01977432 _____ () C:\Users\Mitch\Downloads\winrar-x64-501.exe
2014-05-25 11:24 - 2014-05-25 11:24 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\WinRAR
2014-05-25 11:24 - 2014-05-25 11:24 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-05-25 11:24 - 2014-05-25 11:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-05-25 11:24 - 2014-05-25 11:24 - 00000000 ____D () C:\Program Files\WinRAR
2014-05-21 08:46 - 2014-05-21 08:46 - 00002060 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-05-21 08:46 - 2014-05-21 08:46 - 00002048 _____ () C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2014-05-21 08:46 - 2014-05-21 08:46 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Thunderbird
2014-05-21 08:46 - 2014-05-21 08:46 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Thunderbird
2014-05-21 08:46 - 2014-05-21 08:46 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-05-21 08:45 - 2014-05-21 08:46 - 22155104 _____ (Mozilla) C:\Users\Mitch\Downloads\Thunderbird Setup 24.5.0.exe
2014-05-18 16:22 - 2014-05-18 16:22 - 01013805 _____ () C:\Users\Mitch\Downloads\pixel-vision.zip
2014-05-17 07:12 - 2014-06-01 16:15 - 00002028 _____ () C:\Windows\setupact.log
2014-05-17 07:12 - 2014-05-17 07:12 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-16 16:07 - 2014-05-16 16:07 - 00001810 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2014-05-16 16:07 - 2014-05-16 16:07 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\SUPERAntiSpyware.com
2014-05-16 16:07 - 2014-05-16 16:07 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2014-05-16 16:07 - 2014-05-16 16:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2014-05-16 16:07 - 2014-05-16 16:07 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-05-16 16:06 - 2014-05-16 16:06 - 19151800 _____ (SUPERAntiSpyware) C:\Users\Mitch\Downloads\SUPERAntiSpyware.exe
2014-05-16 15:25 - 2014-05-16 15:25 - 04745984 _____ (Piriform Ltd) C:\Users\Mitch\Downloads\ccsetup413.exe
2014-05-16 15:25 - 2014-05-16 15:25 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-05-16 15:25 - 2014-05-16 15:25 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-05-16 15:25 - 2014-05-16 15:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-05-16 15:25 - 2014-05-16 15:25 - 00000000 ____D () C:\Program Files\CCleaner
2014-05-16 15:22 - 2014-05-16 15:22 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\NVIDIA
2014-05-16 15:22 - 2014-05-16 15:22 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Blizzard Entertainment
2014-05-16 14:24 - 2014-05-16 16:41 - 00000000 ____D () C:\Users\Mitch\Documents\StarCraft II
2014-05-16 14:24 - 2014-05-16 14:24 - 54085656 _____ (Blizzard Entertainment) C:\Users\Mitch\Downloads\StarCraft-II-Setup-enUS(2).exe
2014-05-16 14:24 - 2014-05-16 14:24 - 00001055 _____ () C:\Users\Public\Desktop\StarCraft II.lnk
2014-05-16 14:24 - 2014-05-16 14:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II
2014-05-16 14:24 - 2014-05-16 14:24 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-05-16 13:53 - 2014-03-06 03:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-16 13:48 - 2014-05-16 13:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-05-16 13:44 - 2014-05-16 13:44 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-05-16 13:40 - 2014-05-16 13:41 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp
2014-05-16 13:40 - 2014-05-16 13:40 - 00000020 ___SH () C:\Users\UpdatusUser\ntuser.ini
2014-05-16 13:40 - 2014-05-16 13:29 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\SoftThinks
2014-05-16 13:40 - 2009-07-13 23:54 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-05-16 13:40 - 2009-07-13 23:49 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-05-16 13:39 - 2012-09-06 17:02 - 03492258 _____ () C:\Windows\system32\nvcoproc.bin
2014-05-16 13:34 - 2012-09-06 20:17 - 26228072 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 25256296 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 19829096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 18229096 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 17559912 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 15291752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 14879080 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 13392232 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-05-16 13:34 - 2012-09-06 20:17 - 12465512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 09066344 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 07626088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 07397736 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 06109032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 02745192 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 02573672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 02422120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 02216808 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 01866088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 01760104 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco64.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 01482600 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco64.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 00971624 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 00830312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 00355176 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 00308072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 00247144 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-05-16 13:34 - 2012-09-06 20:17 - 00202600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-05-16 13:34 - 2012-07-03 10:25 - 00189288 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2014-05-16 13:34 - 2012-07-03 10:25 - 00031080 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2014-05-16 13:34 - 2012-07-03 02:37 - 01472360 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2014-05-14 23:35 - 2014-05-14 23:34 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-05-14 20:44 - 2014-02-03 21:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-05-14 20:44 - 2014-02-03 21:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-05-14 20:44 - 2013-11-23 13:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-05-14 20:44 - 2013-11-23 12:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-05-14 20:44 - 2012-02-11 01:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2014-05-14 20:44 - 2012-02-11 01:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
2014-05-14 20:03 - 2014-05-14 20:04 - 00000000 __SHD () C:\Windows\BitLockerDiscoveryVolumeContents
2014-05-14 20:03 - 2014-05-14 20:03 - 00000000 ____D () C:\Windows\RemotePackages
2014-05-14 20:03 - 2014-05-14 20:03 - 00000000 ____D () C:\Windows\CSC
2014-05-14 20:01 - 2014-05-05 23:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-14 20:01 - 2014-05-05 23:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-14 20:01 - 2014-05-05 22:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-14 20:01 - 2014-05-05 22:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-14 20:01 - 2014-05-05 22:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-14 20:01 - 2014-05-05 21:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-14 19:53 - 2013-12-24 18:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-05-14 19:53 - 2013-12-24 17:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-05-14 19:53 - 2013-11-26 03:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-05-14 19:53 - 2013-11-22 17:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-05-14 19:49 - 2009-06-10 15:31 - 00051867 _____ () C:\Windows\Ultimate.xml
2014-05-14 19:30 - 2014-05-14 20:42 - 00000219 _____ () C:\Users\Mitch\Desktop\Counter-Strike Source.url
2014-05-14 19:23 - 2014-05-14 19:23 - 54085656 _____ (Blizzard Entertainment) C:\Users\Mitch\Downloads\StarCraft-II-Setup-enUS(1).exe
2014-05-14 18:58 - 2014-05-14 18:58 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-05-14 18:56 - 2014-05-14 18:56 - 00373982 _____ () C:\Users\Mitch\Downloads\DELL_U2212HM_MONITOR_A00_00_C8TRP.exe
2014-05-14 18:31 - 2014-05-16 15:41 - 00000000 ____D () C:\Windows\Minidump
2014-05-14 18:22 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2014-05-14 18:22 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2014-05-14 18:22 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2014-05-14 18:22 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2014-05-14 18:22 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2014-05-14 18:22 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2014-05-14 18:22 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2014-05-14 18:22 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2014-05-14 18:22 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2014-05-14 18:22 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2014-05-14 18:22 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2014-05-14 18:22 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2014-05-14 18:22 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2014-05-14 18:22 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2014-05-14 18:22 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2014-05-14 18:22 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2014-05-14 18:22 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2014-05-14 18:22 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2014-05-14 18:22 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2014-05-14 18:22 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2014-05-14 18:22 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2014-05-14 18:22 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2014-05-14 18:22 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2014-05-14 18:22 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2014-05-14 18:22 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2014-05-14 18:22 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2014-05-14 18:22 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2014-05-14 18:22 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2014-05-14 18:22 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2014-05-14 18:22 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2014-05-14 18:22 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2014-05-14 18:22 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2014-05-14 18:22 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2014-05-14 18:22 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2014-05-14 18:22 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2014-05-14 18:22 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2014-05-14 18:22 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2014-05-14 18:22 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2014-05-14 18:22 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2014-05-14 18:22 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2014-05-14 18:22 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2014-05-14 18:22 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2014-05-14 18:22 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2014-05-14 18:22 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2014-05-14 18:22 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2014-05-14 18:22 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2014-05-14 18:22 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2014-05-14 18:22 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2014-05-14 18:22 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2014-05-14 18:22 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2014-05-14 18:22 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2014-05-14 18:22 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2014-05-14 18:22 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2014-05-14 18:22 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2014-05-14 18:22 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2014-05-14 18:22 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2014-05-14 18:22 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2014-05-14 18:22 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2014-05-14 18:22 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2014-05-14 18:22 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2014-05-14 18:22 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2014-05-14 18:22 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2014-05-14 18:22 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2014-05-14 18:22 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2014-05-14 18:22 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2014-05-14 18:22 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2014-05-14 18:22 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2014-05-14 18:22 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2014-05-14 18:22 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2014-05-14 18:22 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2014-05-14 18:21 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2014-05-14 18:21 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2014-05-14 18:21 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2014-05-14 18:21 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2014-05-14 18:21 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2014-05-14 18:21 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2014-05-14 18:21 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2014-05-14 18:21 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2014-05-14 18:21 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2014-05-14 18:21 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2014-05-14 18:21 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2014-05-14 18:21 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2014-05-14 18:21 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2014-05-14 18:21 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2014-05-14 18:21 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2014-05-14 18:21 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2014-05-14 18:21 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2014-05-14 18:21 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2014-05-14 18:21 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2014-05-14 18:21 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2014-05-14 18:21 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2014-05-14 18:21 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2014-05-14 18:21 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2014-05-14 18:21 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2014-05-14 18:21 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2014-05-14 18:21 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2014-05-14 18:21 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2014-05-14 18:21 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2014-05-14 18:21 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2014-05-14 18:21 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2014-05-14 18:21 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2014-05-14 18:21 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2014-05-14 18:21 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2014-05-14 18:21 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2014-05-14 18:21 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2014-05-14 18:21 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2014-05-14 18:21 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2014-05-14 18:21 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2014-05-14 18:21 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2014-05-14 18:21 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2014-05-14 18:21 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2014-05-14 18:21 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2014-05-14 18:21 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2014-05-14 18:21 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2014-05-14 18:21 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2014-05-14 18:21 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2014-05-14 18:21 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2014-05-14 18:21 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2014-05-14 18:21 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2014-05-14 18:21 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2014-05-14 18:21 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2014-05-14 18:21 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2014-05-14 18:21 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2014-05-14 18:21 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2014-05-14 18:21 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2014-05-14 18:21 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2014-05-14 18:21 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2014-05-14 18:21 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2014-05-14 18:21 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2014-05-14 18:21 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2014-05-14 18:21 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2014-05-14 18:21 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2014-05-14 18:21 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2014-05-14 18:21 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2014-05-14 18:21 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2014-05-14 18:21 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2014-05-14 18:21 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2014-05-14 18:21 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2014-05-14 18:21 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2014-05-14 18:21 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2014-05-14 18:21 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2014-05-14 18:21 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2014-05-14 18:21 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2014-05-14 18:21 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2014-05-14 18:21 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2014-05-14 18:21 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2014-05-14 18:21 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2014-05-14 18:21 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2014-05-14 18:21 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2014-05-14 18:21 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2014-05-14 18:21 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2014-05-14 18:21 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2014-05-14 18:21 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2014-05-14 18:21 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2014-05-14 18:21 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2014-05-14 18:21 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2014-05-14 18:21 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2014-05-14 18:21 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2014-05-14 18:21 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2014-05-14 18:21 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2014-05-14 18:21 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2014-05-14 18:21 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2014-05-14 18:21 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2014-05-14 18:21 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2014-05-14 18:21 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2014-05-14 18:21 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2014-05-14 18:21 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2014-05-14 18:21 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2014-05-14 18:21 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2014-05-14 18:21 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2014-05-14 18:21 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2014-05-14 18:21 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2014-05-14 18:21 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2014-05-14 18:21 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2014-05-14 18:21 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2014-05-14 18:21 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2014-05-14 18:21 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2014-05-14 18:21 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2014-05-14 18:21 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2014-05-14 18:21 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2014-05-14 18:21 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2014-05-14 18:21 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2014-05-14 18:09 - 2014-05-16 14:14 - 00000219 _____ () C:\Users\Mitch\Desktop\Counter-Strike Global Offensive.url
2014-05-14 18:09 - 2014-05-14 19:30 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-05-14 18:07 - 2014-05-20 11:12 - 00000000 ____D () C:\Program Files (x86)\StarCraft II
2014-05-14 18:07 - 2014-05-14 18:07 - 00000000 ____D () C:\ProgramData\Battle.net
2014-05-14 18:06 - 2014-05-14 18:06 - 54085656 _____ (Blizzard Entertainment) C:\Users\Mitch\Downloads\StarCraft-II-Setup-enUS.exe
2014-05-14 17:52 - 2014-05-14 17:52 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_rzudd_01009.Wdf
2014-05-14 17:51 - 2014-05-14 17:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_rzendpt_01009.Wdf
2014-05-14 17:51 - 2014-05-14 17:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_rzdaendpt_01009.Wdf
2014-05-14 17:48 - 2014-05-14 17:48 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Razer
2014-05-14 17:48 - 2014-05-14 17:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2014-05-14 17:47 - 2014-05-14 17:50 - 00000000 ____D () C:\Program Files (x86)\Razer
2014-05-14 17:47 - 2014-05-14 17:47 - 00000000 ____D () C:\ProgramData\Razer
2014-05-14 17:46 - 2014-05-14 17:46 - 18155960 _____ (Razer Inc.) C:\Users\Mitch\Downloads\Razer_Synapse_Framework_V1.18.02.exe
2014-05-14 17:40 - 2014-05-14 17:40 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Macromedia
2014-05-14 17:40 - 2014-05-14 17:40 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Macromedia
2014-05-14 17:39 - 2014-06-01 17:25 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-14 17:39 - 2014-05-30 13:34 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-14 17:39 - 2014-05-30 13:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-14 17:39 - 2014-05-30 13:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-14 17:39 - 2014-05-14 17:39 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-14 17:39 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-14 17:39 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-14 17:39 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-14 17:38 - 2014-05-14 17:38 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Mitch\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-14 17:38 - 2014-05-14 17:38 - 01141680 _____ () C:\Users\Mitch\Downloads\SteamSetup.exe
2014-05-14 17:37 - 2014-05-14 17:37 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Avira
2014-05-14 17:34 - 2014-02-25 11:41 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-05-14 17:34 - 2014-02-25 11:41 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-05-14 17:34 - 2014-02-25 11:41 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-05-14 17:32 - 2014-05-14 17:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-05-14 17:32 - 2014-05-14 17:34 - 00000000 ____D () C:\ProgramData\Avira
2014-05-14 17:32 - 2014-05-14 17:34 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-05-14 17:32 - 2014-05-14 17:32 - 04536664 _____ (Avira Operations GmbH & Co. KG) C:\Users\Mitch\Downloads\avira_en_av___ws.exe
2014-05-14 17:32 - 2014-05-14 17:32 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-05-14 17:32 - 2014-05-14 17:32 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Adobe
2014-05-14 17:32 - 2014-05-14 17:32 - 00000000 ____D () C:\ProgramData\Package Cache
2014-05-14 17:30 - 2014-05-22 08:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-14 17:30 - 2014-05-14 17:31 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Mozilla
2014-05-14 17:30 - 2014-05-14 17:31 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Mozilla
2014-05-14 17:30 - 2014-05-14 17:30 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-14 17:30 - 2014-05-14 17:30 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-05-14 17:30 - 2014-05-14 17:30 - 00000000 ____D () C:\ProgramData\Mozilla
2014-05-14 17:30 - 2014-05-14 17:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-14 17:29 - 2014-05-14 17:29 - 00000000 __SHD () C:\Users\Mitch\AppData\Local\EmieUserList
2014-05-14 17:29 - 2014-05-14 17:29 - 00000000 __SHD () C:\Users\Mitch\AppData\Local\EmieSiteList
2014-05-14 17:12 - 2014-05-14 17:12 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-14 16:59 - 2013-05-10 00:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-05-14 16:59 - 2013-05-10 00:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-05-14 16:59 - 2013-05-09 23:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-05-14 16:59 - 2013-05-09 23:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-05-14 16:41 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2014-05-14 16:38 - 2014-05-14 16:38 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-14 16:38 - 2014-05-14 16:38 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-14 16:38 - 2014-05-14 16:38 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-05-14 16:38 - 2014-05-14 16:38 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-05-14 16:38 - 2014-05-14 16:38 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-05-14 16:38 - 2014-05-14 16:38 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-05-14 16:38 - 2014-05-14 16:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-05-14 16:38 - 2014-05-14 16:38 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-05-14 16:38 - 2014-05-14 16:38 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-05-14 15:52 - 2014-05-14 15:53 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-14 15:52 - 2014-05-04 17:12 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-14 15:43 - 2012-07-25 22:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2014-05-14 15:43 - 2012-07-25 22:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2014-05-14 15:43 - 2012-07-25 22:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2014-05-14 15:43 - 2012-07-25 22:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2014-05-14 15:43 - 2012-07-25 22:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2014-05-14 15:43 - 2012-07-25 21:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2014-05-14 15:43 - 2012-07-25 21:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2014-05-14 15:43 - 2012-06-02 09:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2014-05-14 15:30 - 2012-03-01 01:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2014-05-14 15:30 - 2012-03-01 01:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2014-05-14 15:30 - 2012-03-01 00:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2014-05-14 15:20 - 2013-12-05 21:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-05-14 15:20 - 2013-12-05 21:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-05-14 15:20 - 2013-12-05 21:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-05-14 15:20 - 2013-12-05 21:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-05-14 15:20 - 2013-07-09 00:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-05-14 15:20 - 2013-07-09 00:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-05-14 15:20 - 2013-07-08 23:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-05-14 15:20 - 2013-07-08 23:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-05-14 15:20 - 2013-07-04 07:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-05-14 15:20 - 2013-07-04 06:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2014-05-14 15:20 - 2013-06-25 17:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2014-05-14 15:20 - 2013-04-25 18:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2014-05-14 15:20 - 2013-03-31 17:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-05-14 15:20 - 2013-02-15 01:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-05-14 15:20 - 2013-02-15 01:06 - 03717632 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-05-14 15:20 - 2013-02-15 01:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-05-14 15:20 - 2013-02-14 23:37 - 03217408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-05-14 15:20 - 2013-02-14 23:34 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-05-14 15:20 - 2013-02-14 22:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-05-14 15:20 - 2012-11-28 17:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2014-05-14 15:20 - 2012-11-28 17:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2014-05-14 15:20 - 2012-11-28 17:56 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2014-05-14 15:20 - 2012-11-01 00:43 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-05-14 15:20 - 2012-10-31 23:47 - 01389568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-05-14 15:19 - 2013-10-18 21:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-05-14 15:19 - 2013-10-18 20:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-05-14 15:19 - 2013-10-03 21:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-05-14 15:19 - 2013-10-03 20:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2014-05-14 15:19 - 2013-09-27 20:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-05-14 15:19 - 2013-08-28 21:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-05-14 15:19 - 2013-08-28 21:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-05-14 15:19 - 2013-08-28 21:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-05-14 15:19 - 2013-08-28 20:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-05-14 15:19 - 2013-08-28 20:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2014-05-14 15:19 - 2013-08-28 20:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2014-05-14 15:19 - 2013-07-12 05:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2014-05-14 15:19 - 2013-07-02 23:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2014-05-14 15:19 - 2013-07-02 23:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2014-05-14 15:19 - 2012-12-07 08:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-05-14 15:19 - 2012-12-07 08:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2014-05-14 15:19 - 2012-12-07 07:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2014-05-14 15:19 - 2012-12-07 07:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2014-05-14 15:19 - 2012-12-07 06:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2014-05-14 15:19 - 2012-12-07 06:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2014-05-14 15:19 - 2012-12-07 06:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2014-05-14 15:19 - 2012-12-07 06:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2014-05-14 15:19 - 2012-12-07 06:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2014-05-14 15:19 - 2012-12-07 06:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2014-05-14 15:19 - 2012-12-07 06:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2014-05-14 15:19 - 2012-12-07 06:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2014-05-14 15:19 - 2012-12-07 06:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2014-05-14 15:19 - 2012-12-07 06:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2014-05-14 15:19 - 2012-12-07 06:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2014-05-14 15:19 - 2012-12-07 06:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2014-05-14 15:19 - 2012-12-07 06:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2014-05-14 15:19 - 2012-12-07 06:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2014-05-14 15:19 - 2012-12-07 05:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
2014-05-14 15:19 - 2012-12-07 05:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
2014-05-14 15:19 - 2012-12-07 05:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
2014-05-14 15:19 - 2012-12-07 05:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2014-05-14 15:19 - 2012-12-07 05:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2014-05-14 15:19 - 2012-12-07 05:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
2014-05-14 15:19 - 2012-12-07 05:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2014-05-14 15:19 - 2012-12-07 05:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
2014-05-14 15:19 - 2012-12-07 05:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
2014-05-14 15:19 - 2012-12-07 05:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
2014-05-14 15:19 - 2012-12-07 05:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2014-05-14 15:19 - 2012-12-07 05:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2014-05-14 15:19 - 2012-12-07 05:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
2014-05-14 15:19 - 2012-12-07 05:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
2014-05-14 15:18 - 2014-05-09 01:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-14 15:18 - 2014-05-09 01:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-14 15:18 - 2014-04-11 21:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 15:18 - 2014-04-11 21:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 15:18 - 2014-04-11 21:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 15:18 - 2014-04-11 21:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 15:18 - 2014-04-11 21:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 15:18 - 2014-04-11 21:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 15:18 - 2014-04-11 21:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-14 15:18 - 2014-04-11 21:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-14 15:18 - 2014-04-11 21:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-14 15:18 - 2014-03-04 04:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 15:18 - 2014-03-04 04:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 15:18 - 2014-03-04 04:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 15:18 - 2014-03-04 04:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 15:18 - 2014-03-04 04:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 15:18 - 2014-03-04 04:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 15:18 - 2014-03-04 04:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 15:18 - 2014-03-04 04:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 15:18 - 2014-03-04 04:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-14 15:18 - 2014-03-04 04:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 15:18 - 2014-03-04 04:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-14 15:18 - 2014-03-04 04:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-14 15:18 - 2014-03-04 04:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-14 15:18 - 2014-03-04 04:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-14 15:18 - 2014-03-04 04:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 15:18 - 2014-03-04 04:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 15:18 - 2014-03-04 04:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-14 15:18 - 2014-03-04 04:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-14 15:18 - 2014-03-04 04:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-14 15:18 - 2014-03-04 04:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-14 15:18 - 2014-03-04 04:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-14 15:18 - 2014-03-04 04:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-14 15:18 - 2014-03-04 04:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-14 15:18 - 2014-03-04 04:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-14 15:18 - 2014-03-04 04:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-14 15:18 - 2014-03-04 04:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-14 15:18 - 2014-03-04 04:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-14 15:18 - 2014-03-04 04:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-14 15:18 - 2014-03-04 04:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-14 15:18 - 2014-03-04 04:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-14 15:18 - 2014-03-04 04:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-14 15:18 - 2014-03-04 04:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-14 15:18 - 2013-12-03 21:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-05-14 15:18 - 2013-12-03 21:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-05-14 15:18 - 2013-12-03 21:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-05-14 15:18 - 2013-12-03 21:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-05-14 15:18 - 2013-12-03 21:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-05-14 15:18 - 2013-12-03 21:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-05-14 15:18 - 2013-12-03 21:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-05-14 15:18 - 2013-12-03 21:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-05-14 15:18 - 2013-12-03 21:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-05-14 15:18 - 2013-12-03 21:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-05-14 15:18 - 2013-12-03 21:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-05-14 15:18 - 2013-12-03 21:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-05-14 15:18 - 2013-12-03 21:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-05-14 15:18 - 2013-12-03 21:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-05-14 15:18 - 2013-12-03 20:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-05-14 15:18 - 2013-12-03 20:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-05-14 15:18 - 2013-12-03 20:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-05-14 15:18 - 2013-12-03 20:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-05-14 15:18 - 2013-09-24 21:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-05-14 15:18 - 2013-09-24 20:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-05-14 15:18 - 2013-08-01 21:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-05-14 15:18 - 2013-08-01 21:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2014-05-14 15:18 - 2013-08-01 20:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2014-05-14 15:18 - 2013-08-01 19:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-05-14 15:18 - 2013-07-04 07:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-05-14 15:16 - 2014-03-24 21:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 15:16 - 2014-03-24 21:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-14 15:16 - 2014-03-04 04:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-05-14 15:16 - 2014-03-04 04:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-05-14 15:16 - 2014-03-04 04:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-05-14 15:16 - 2014-03-04 04:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-05-14 15:16 - 2014-03-04 04:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-05-14 15:16 - 2014-03-04 04:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-05-14 15:16 - 2014-03-04 04:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-05-14 15:16 - 2014-03-04 04:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-05-14 15:16 - 2014-03-04 04:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-05-14 15:16 - 2014-03-04 03:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-05-14 15:16 - 2014-03-04 03:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-05-14 15:16 - 2013-11-26 06:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-05-14 15:16 - 2013-09-07 21:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-05-14 15:16 - 2013-08-01 21:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 20:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-05-14 15:16 - 2013-08-01 19:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 19:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 19:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-05-14 15:16 - 2013-08-01 19:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2014-05-14 15:16 - 2013-07-25 21:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2014-05-14 15:16 - 2013-07-25 20:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2014-05-14 15:16 - 2013-05-13 00:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2014-05-14 15:16 - 2013-05-12 22:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2014-05-14 15:16 - 2013-05-12 22:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2014-05-14 15:16 - 2013-05-12 22:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2014-05-14 15:16 - 2013-02-27 01:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-05-14 15:16 - 2013-02-27 00:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-05-14 15:16 - 2013-01-03 01:00 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-05-14 15:16 - 2012-10-03 12:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2014-05-14 15:16 - 2012-10-03 12:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2014-05-14 15:16 - 2012-10-03 12:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2014-05-14 15:16 - 2012-10-03 12:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2014-05-14 15:16 - 2012-10-03 12:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2014-05-14 15:16 - 2012-10-03 12:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2014-05-14 15:16 - 2012-10-03 11:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2014-05-14 15:16 - 2012-10-03 11:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2014-05-14 15:16 - 2012-10-03 11:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2014-05-14 15:16 - 2012-10-03 11:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-05-14 15:16 - 2012-01-13 02:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2014-05-14 15:15 - 2014-02-06 20:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-05-14 15:15 - 2014-02-03 21:37 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-05-14 15:15 - 2014-02-03 21:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-05-14 15:15 - 2014-02-03 21:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-05-14 15:15 - 2014-02-03 21:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-05-14 15:15 - 2014-02-03 21:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-05-14 15:15 - 2013-10-05 15:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-05-14 15:15 - 2013-10-05 14:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-05-14 15:15 - 2013-10-03 21:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2014-05-14 15:15 - 2013-10-03 21:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2014-05-14 15:15 - 2013-10-03 21:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-05-14 15:15 - 2013-10-03 20:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2014-05-14 15:15 - 2013-10-03 20:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-05-14 15:15 - 2013-10-03 20:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2014-05-14 15:15 - 2013-07-09 00:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-05-14 15:15 - 2013-07-09 00:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-05-14 15:15 - 2013-07-08 23:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-05-14 15:15 - 2013-07-08 23:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2014-05-14 15:15 - 2013-04-26 00:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-05-14 15:15 - 2013-04-25 23:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2014-05-14 15:15 - 2012-10-09 13:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2014-05-14 15:15 - 2012-10-09 13:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2014-05-14 15:15 - 2012-10-09 12:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2014-05-14 15:15 - 2012-10-09 12:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2014-05-14 15:15 - 2012-04-07 07:31 - 03216384 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-05-14 15:15 - 2012-04-07 06:26 - 02342400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-05-14 15:14 - 2013-11-26 20:42 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-05-14 15:14 - 2013-11-26 20:42 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-05-14 15:14 - 2013-11-26 20:42 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-05-14 15:14 - 2013-11-26 20:42 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-05-14 15:14 - 2013-11-26 20:42 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-05-14 15:14 - 2013-11-26 20:42 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-05-14 15:14 - 2013-11-26 20:42 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-05-14 15:14 - 2013-11-11 21:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-05-14 15:14 - 2013-11-11 21:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-05-14 15:14 - 2013-10-29 21:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-05-14 15:14 - 2013-10-29 21:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2014-05-14 15:14 - 2013-07-25 04:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-05-14 15:14 - 2013-07-25 03:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2014-05-14 15:14 - 2013-07-20 05:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-05-14 15:14 - 2013-07-20 05:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-05-14 15:14 - 2013-07-04 07:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-05-14 15:14 - 2013-07-04 07:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-05-14 15:14 - 2013-07-04 06:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2014-05-14 15:14 - 2013-07-04 06:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2014-05-14 15:14 - 2013-07-04 05:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2014-05-14 15:14 - 2013-06-14 23:35 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-05-14 15:14 - 2013-06-14 23:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-05-14 15:14 - 2013-05-10 00:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2014-05-14 15:14 - 2013-05-09 22:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2014-05-14 15:14 - 2012-11-02 00:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-05-14 15:14 - 2012-11-02 00:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2014-05-14 15:14 - 2012-03-17 02:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-05-14 15:13 - 2014-02-03 21:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-05-14 15:13 - 2014-02-03 21:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-05-14 15:13 - 2014-01-27 21:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-05-14 15:13 - 2013-12-31 18:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-05-14 15:13 - 2013-12-31 18:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-05-14 15:13 - 2013-10-02 21:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-05-14 15:13 - 2013-10-02 21:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-05-14 15:13 - 2013-09-07 21:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-05-14 15:13 - 2013-09-07 21:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2014-05-14 15:13 - 2013-08-04 21:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2014-05-14 15:13 - 2013-06-06 00:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2014-05-14 15:13 - 2013-06-06 00:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-05-14 15:13 - 2013-06-06 00:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2014-05-14 15:13 - 2013-06-06 00:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-05-14 15:13 - 2013-06-05 23:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2014-05-14 15:13 - 2013-06-05 23:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2014-05-14 15:13 - 2013-06-05 23:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2014-05-14 15:13 - 2013-06-05 22:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-05-14 15:13 - 2013-06-05 22:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2014-05-14 15:13 - 2013-06-05 22:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2014-05-14 15:13 - 2013-03-19 00:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2014-05-14 15:13 - 2013-02-11 23:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-05-14 15:13 - 2012-11-22 22:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-05-14 15:13 - 2012-09-25 17:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2014-05-14 15:13 - 2012-09-25 17:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-05-14 15:13 - 2012-08-22 13:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2014-05-14 15:13 - 2012-08-21 16:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2014-05-14 15:13 - 2012-07-04 17:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-05-14 15:13 - 2012-07-04 17:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-05-14 15:13 - 2012-07-04 17:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-05-14 15:13 - 2012-07-04 16:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2014-05-14 15:13 - 2012-07-04 16:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2014-05-14 15:13 - 2012-07-04 15:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2014-05-14 15:13 - 2012-04-27 22:55 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-05-14 15:13 - 2012-04-26 00:41 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-05-14 15:13 - 2012-04-26 00:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-05-14 15:13 - 2012-04-26 00:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-05-14 15:12 - 2014-01-28 21:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-05-14 15:12 - 2014-01-28 21:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-05-14 15:12 - 2014-01-23 21:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-05-14 15:12 - 2013-10-11 21:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-05-14 15:12 - 2013-10-11 21:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-05-14 15:12 - 2013-10-11 21:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2014-05-14 15:12 - 2013-10-11 21:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-05-14 15:12 - 2013-10-11 20:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-05-14 15:12 - 2013-10-11 20:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-05-14 15:12 - 2013-10-11 20:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2014-05-14 15:12 - 2013-10-11 20:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-05-14 15:12 - 2013-08-01 07:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-05-14 15:12 - 2013-04-10 01:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-05-14 15:12 - 2013-01-24 01:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-05-14 15:12 - 2012-11-22 00:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-05-14 15:12 - 2012-11-21 23:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-05-14 15:12 - 2012-05-14 00:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-05-14 15:12 - 2012-05-05 03:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-05-14 15:12 - 2012-05-05 02:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-05-14 15:12 - 2012-05-01 00:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2014-05-14 15:12 - 2012-02-17 01:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-05-14 15:12 - 2012-02-17 00:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2014-05-14 15:12 - 2012-02-16 23:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-05-14 15:12 - 2011-02-22 23:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2014-05-14 15:12 - 2011-02-03 06:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-05-14 14:56 - 2012-06-06 01:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2014-05-14 14:56 - 2012-06-06 00:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2014-05-14 14:54 - 2013-10-11 21:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-05-14 14:54 - 2013-10-11 21:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-05-14 14:54 - 2013-10-11 21:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-05-14 14:54 - 2013-10-11 21:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2014-05-14 14:54 - 2013-10-11 21:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2014-05-14 14:54 - 2013-08-27 20:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2014-05-14 14:42 - 2012-06-02 17:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-05-14 14:42 - 2012-06-02 17:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-05-14 14:42 - 2012-06-02 17:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-05-14 14:42 - 2012-06-02 17:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-05-14 14:42 - 2012-06-02 17:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-05-14 14:42 - 2012-06-02 17:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-05-14 14:42 - 2012-06-02 17:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-05-14 14:42 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-05-14 14:42 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-05-14 14:39 - 2014-05-14 14:53 - 00000000 ____D () C:\Windows\SMINST
2014-05-14 14:26 - 2014-05-14 14:26 - 00000000 ____D () C:\Users\Mitch\My Backup Files
2014-05-14 14:03 - 2014-05-14 14:34 - 00000000 ____D () C:\Users\Mitch\AppData\Local\LogMeIn Rescue Applet
2014-05-14 13:11 - 2014-05-14 13:11 - 00002094 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
2014-05-14 13:11 - 2014-05-14 13:11 - 00002082 _____ () C:\Users\Public\Desktop\Belarc Advisor.lnk
2014-05-14 13:11 - 2014-05-14 13:11 - 00000000 ____D () C:\Program Files (x86)\Belarc
2014-05-14 12:16 - 2014-05-14 12:16 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Adobe
2014-05-14 12:14 - 2014-05-14 17:49 - 00058464 _____ () C:\Users\Mitch\AppData\Local\GDIPFONTCACHEV1.DAT
2014-05-14 12:14 - 2014-05-14 12:14 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0.bak
2014-05-14 12:14 - 2014-05-14 12:14 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0.bak
2014-05-14 12:14 - 2014-05-14 12:14 - 00000552 _____ () C:\Windows\system32\spsys.log
2014-05-14 12:14 - 2014-05-14 12:14 - 00000000 ____D () C:\Users\Mitch\Documents\AlienFX
2014-05-14 12:14 - 2014-05-14 12:14 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Intel Corporation
2014-05-14 12:13 - 2014-05-14 17:25 - 00001415 _____ () C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-14 12:11 - 2014-05-14 17:27 - 00000000 ___RD () C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-14 12:11 - 2014-05-14 17:27 - 00000000 ___RD () C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-14 12:10 - 2014-05-14 12:10 - 00000000 ____D () C:\Users\Mitch\AppData\Local\VirtualStore
2014-05-14 12:04 - 2014-06-01 19:20 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Temp
2014-05-14 12:04 - 2014-05-14 14:26 - 00000000 ____D () C:\Users\Mitch\AppData\Local\SoftThinks
2014-05-14 12:04 - 2014-05-14 14:26 - 00000000 ____D () C:\Users\Mitch
2014-05-14 12:04 - 2014-05-14 12:04 - 00000020 ___SH () C:\Users\Mitch\ntuser.ini
2014-05-14 12:04 - 2009-07-13 23:54 - 00000000 ___RD () C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-05-14 12:04 - 2009-07-13 23:49 - 00000000 ___RD () C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-05-14 12:02 - 2014-05-14 12:02 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe

==================== One Month Modified Files and Folders =======

2014-06-01 19:20 - 2014-06-01 19:20 - 00010542 _____ () C:\Users\Mitch\Downloads\FRST.txt
2014-06-01 19:20 - 2014-06-01 19:18 - 00000000 ____D () C:\FRST
2014-06-01 19:20 - 2014-05-14 12:04 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Temp
2014-06-01 19:17 - 2014-06-01 19:17 - 02067456 _____ (Farbar) C:\Users\Mitch\Downloads\FRST64.exe
2014-06-01 18:55 - 2012-06-13 16:27 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-01 17:25 - 2014-05-14 17:39 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-01 16:24 - 2009-07-13 23:45 - 00020576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-01 16:24 - 2009-07-13 23:45 - 00020576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-01 16:20 - 2012-06-13 18:18 - 01129247 _____ () C:\Windows\WindowsUpdate.log
2014-06-01 16:17 - 2012-06-13 16:57 - 00000000 ____D () C:\Program Files (x86)\AlienRespawn
2014-06-01 16:16 - 2012-06-13 17:57 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-06-01 16:16 - 2012-06-13 17:05 - 00000000 ____D () C:\Users\Default\AppData\Local\SoftThinks
2014-06-01 16:16 - 2012-06-13 17:05 - 00000000 ____D () C:\Users\Default User\AppData\Local\SoftThinks
2014-06-01 16:15 - 2014-05-17 07:12 - 00002028 _____ () C:\Windows\setupact.log
2014-06-01 16:15 - 2012-06-13 16:55 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-01 16:15 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-01 16:08 - 2014-06-01 08:53 - 00000718 _____ () C:\Windows\PFRO.log
2014-05-31 15:51 - 2009-07-14 00:13 - 00873988 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-30 13:34 - 2014-05-14 17:39 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-30 13:34 - 2014-05-14 17:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-30 13:34 - 2014-05-14 17:39 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-30 10:34 - 2014-05-30 10:34 - 00000942 __RSH () C:\ProgramData\ntuser.pol
2014-05-30 10:33 - 2009-07-13 22:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-05-30 10:29 - 2014-05-30 10:29 - 00000906 ____R () C:\Users\Mitch\Documents\bl rcvy key.txt
2014-05-28 16:43 - 2014-05-28 15:17 - 00001078 _____ () C:\Users\Mitch\Desktop\New Text Document (2).txt
2014-05-28 15:42 - 2014-05-28 15:42 - 00000038 _____ () C:\Users\Mitch\Desktop\comcast supervisor.txt
2014-05-27 16:13 - 2014-05-27 16:13 - 00000000 _____ () C:\Users\Mitch\Desktop\New Text Document.txt
2014-05-25 11:24 - 2014-05-25 11:24 - 01977432 _____ () C:\Users\Mitch\Downloads\winrar-x64-501.exe
2014-05-25 11:24 - 2014-05-25 11:24 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\WinRAR
2014-05-25 11:24 - 2014-05-25 11:24 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-05-25 11:24 - 2014-05-25 11:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-05-25 11:24 - 2014-05-25 11:24 - 00000000 ____D () C:\Program Files\WinRAR
2014-05-22 08:23 - 2014-05-14 17:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-21 12:15 - 2012-06-13 16:58 - 00000000 ____D () C:\Temp
2014-05-21 08:46 - 2014-05-21 08:46 - 00002060 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-05-21 08:46 - 2014-05-21 08:46 - 00002048 _____ () C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2014-05-21 08:46 - 2014-05-21 08:46 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Thunderbird
2014-05-21 08:46 - 2014-05-21 08:46 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Thunderbird
2014-05-21 08:46 - 2014-05-21 08:46 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-05-21 08:46 - 2014-05-21 08:45 - 22155104 _____ (Mozilla) C:\Users\Mitch\Downloads\Thunderbird Setup 24.5.0.exe
2014-05-20 11:12 - 2014-05-14 18:07 - 00000000 ____D () C:\Program Files (x86)\StarCraft II
2014-05-18 16:22 - 2014-05-18 16:22 - 01013805 _____ () C:\Users\Mitch\Downloads\pixel-vision.zip
2014-05-17 07:12 - 2014-05-17 07:12 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-16 16:41 - 2014-05-16 14:24 - 00000000 ____D () C:\Users\Mitch\Documents\StarCraft II
2014-05-16 16:07 - 2014-05-16 16:07 - 00001810 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2014-05-16 16:07 - 2014-05-16 16:07 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\SUPERAntiSpyware.com
2014-05-16 16:07 - 2014-05-16 16:07 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2014-05-16 16:07 - 2014-05-16 16:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2014-05-16 16:07 - 2014-05-16 16:07 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-05-16 16:06 - 2014-05-16 16:06 - 19151800 _____ (SUPERAntiSpyware) C:\Users\Mitch\Downloads\SUPERAntiSpyware.exe
2014-05-16 15:41 - 2014-05-14 18:31 - 00000000 ____D () C:\Windows\Minidump
2014-05-16 15:41 - 2011-02-10 09:02 - 00000000 ____D () C:\Windows\panther
2014-05-16 15:25 - 2014-05-16 15:25 - 04745984 _____ (Piriform Ltd) C:\Users\Mitch\Downloads\ccsetup413.exe
2014-05-16 15:25 - 2014-05-16 15:25 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-05-16 15:25 - 2014-05-16 15:25 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-05-16 15:25 - 2014-05-16 15:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-05-16 15:25 - 2014-05-16 15:25 - 00000000 ____D () C:\Program Files\CCleaner
2014-05-16 15:22 - 2014-05-16 15:22 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\NVIDIA
2014-05-16 15:22 - 2014-05-16 15:22 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Blizzard Entertainment
2014-05-16 14:24 - 2014-05-16 14:24 - 54085656 _____ (Blizzard Entertainment) C:\Users\Mitch\Downloads\StarCraft-II-Setup-enUS(2).exe
2014-05-16 14:24 - 2014-05-16 14:24 - 00001055 _____ () C:\Users\Public\Desktop\StarCraft II.lnk
2014-05-16 14:24 - 2014-05-16 14:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II
2014-05-16 14:24 - 2014-05-16 14:24 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-05-16 14:14 - 2014-05-14 18:09 - 00000219 _____ () C:\Users\Mitch\Desktop\Counter-Strike Global Offensive.url
2014-05-16 13:48 - 2014-05-16 13:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-05-16 13:44 - 2014-05-16 13:44 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-05-16 13:44 - 2012-06-13 16:54 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-05-16 13:41 - 2014-05-16 13:40 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp
2014-05-16 13:40 - 2014-05-16 13:40 - 00000020 ___SH () C:\Users\UpdatusUser\ntuser.ini
2014-05-16 13:39 - 2012-06-13 16:51 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-05-16 13:29 - 2014-05-16 13:40 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\SoftThinks
2014-05-14 23:34 - 2014-05-14 23:35 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-05-14 23:23 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\rescache
2014-05-14 20:42 - 2014-05-14 19:30 - 00000219 _____ () C:\Users\Mitch\Desktop\Counter-Strike Source.url
2014-05-14 20:09 - 2009-07-14 00:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-14 20:09 - 2009-07-13 22:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-05-14 20:04 - 2014-05-14 20:03 - 00000000 __SHD () C:\Windows\BitLockerDiscoveryVolumeContents
2014-05-14 20:03 - 2014-05-14 20:03 - 00000000 ____D () C:\Windows\RemotePackages
2014-05-14 20:03 - 2014-05-14 20:03 - 00000000 ____D () C:\Windows\CSC
2014-05-14 20:03 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\security
2014-05-14 20:02 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-14 20:01 - 2009-07-14 00:32 - 00000000 ____D () C:\Windows\system32\restore
2014-05-14 19:58 - 2011-02-10 11:10 - 00866110 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-05-14 19:30 - 2014-05-14 18:09 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-05-14 19:23 - 2014-05-14 19:23 - 54085656 _____ (Blizzard Entertainment) C:\Users\Mitch\Downloads\StarCraft-II-Setup-enUS(1).exe
2014-05-14 19:02 - 2011-02-10 09:01 - 00000000 ____D () C:\dell
2014-05-14 18:58 - 2014-05-14 18:58 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-05-14 18:56 - 2014-05-14 18:56 - 00373982 _____ () C:\Users\Mitch\Downloads\DELL_U2212HM_MONITOR_A00_00_C8TRP.exe
2014-05-14 18:55 - 2012-06-13 16:27 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-14 18:55 - 2012-06-13 16:27 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-14 18:55 - 2012-06-13 16:27 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-14 18:07 - 2014-05-14 18:07 - 00000000 ____D () C:\ProgramData\Battle.net
2014-05-14 18:06 - 2014-05-14 18:06 - 54085656 _____ (Blizzard Entertainment) C:\Users\Mitch\Downloads\StarCraft-II-Setup-enUS.exe
2014-05-14 17:54 - 2009-07-13 23:45 - 00294648 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-05-14 17:52 - 2014-05-14 17:52 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_rzudd_01009.Wdf
2014-05-14 17:51 - 2014-05-14 17:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_rzendpt_01009.Wdf
2014-05-14 17:51 - 2014-05-14 17:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_rzdaendpt_01009.Wdf
2014-05-14 17:50 - 2014-05-14 17:47 - 00000000 ____D () C:\Program Files (x86)\Razer
2014-05-14 17:49 - 2014-05-14 12:14 - 00058464 _____ () C:\Users\Mitch\AppData\Local\GDIPFONTCACHEV1.DAT
2014-05-14 17:48 - 2014-05-14 17:48 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Razer
2014-05-14 17:48 - 2014-05-14 17:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2014-05-14 17:47 - 2014-05-14 17:47 - 00000000 ____D () C:\ProgramData\Razer
2014-05-14 17:46 - 2014-05-14 17:46 - 18155960 _____ (Razer Inc.) C:\Users\Mitch\Downloads\Razer_Synapse_Framework_V1.18.02.exe
2014-05-14 17:40 - 2014-05-14 17:40 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Macromedia
2014-05-14 17:40 - 2014-05-14 17:40 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Macromedia
2014-05-14 17:39 - 2014-05-14 17:39 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-14 17:38 - 2014-05-14 17:38 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Mitch\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-14 17:38 - 2014-05-14 17:38 - 01141680 _____ () C:\Users\Mitch\Downloads\SteamSetup.exe
2014-05-14 17:38 - 2012-06-13 17:01 - 00000925 _____ () C:\Users\Public\Desktop\Steam.lnk
2014-05-14 17:38 - 2012-06-13 17:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-05-14 17:37 - 2014-05-14 17:37 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Avira
2014-05-14 17:34 - 2014-05-14 17:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-05-14 17:34 - 2014-05-14 17:32 - 00000000 ____D () C:\ProgramData\Avira
2014-05-14 17:34 - 2014-05-14 17:32 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-05-14 17:32 - 2014-05-14 17:32 - 04536664 _____ (Avira Operations GmbH & Co. KG) C:\Users\Mitch\Downloads\avira_en_av___ws.exe
2014-05-14 17:32 - 2014-05-14 17:32 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-05-14 17:32 - 2014-05-14 17:32 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Adobe
2014-05-14 17:32 - 2014-05-14 17:32 - 00000000 ____D () C:\ProgramData\Package Cache
2014-05-14 17:31 - 2014-05-14 17:30 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Mozilla
2014-05-14 17:31 - 2014-05-14 17:30 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Mozilla
2014-05-14 17:30 - 2014-05-14 17:30 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-14 17:30 - 2014-05-14 17:30 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-05-14 17:30 - 2014-05-14 17:30 - 00000000 ____D () C:\ProgramData\Mozilla
2014-05-14 17:30 - 2014-05-14 17:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-14 17:29 - 2014-05-14 17:29 - 00000000 __SHD () C:\Users\Mitch\AppData\Local\EmieUserList
2014-05-14 17:29 - 2014-05-14 17:29 - 00000000 __SHD () C:\Users\Mitch\AppData\Local\EmieSiteList
2014-05-14 17:27 - 2014-05-14 12:11 - 00000000 ___RD () C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-14 17:27 - 2014-05-14 12:11 - 00000000 ___RD () C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-14 17:25 - 2014-05-14 12:13 - 00001415 _____ () C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-14 17:14 - 2009-07-13 22:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-05-14 17:13 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK
2014-05-14 17:13 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2014-05-14 17:12 - 2014-05-14 17:12 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-14 17:12 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-05-14 17:12 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-05-14 17:11 - 2009-07-14 00:32 - 00000000 ____D () C:\Program Files\Windows Defender
2014-05-14 17:11 - 2009-07-14 00:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-05-14 17:09 - 2010-11-21 02:17 - 00000000 ____D () C:\Program Files\Windows Journal
2014-05-14 16:38 - 2014-05-14 16:38 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-14 16:38 - 2014-05-14 16:38 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-14 16:38 - 2014-05-14 16:38 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-05-14 16:38 - 2014-05-14 16:38 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-05-14 16:38 - 2014-05-14 16:38 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-05-14 16:38 - 2014-05-14 16:38 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-05-14 16:38 - 2014-05-14 16:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-05-14 16:38 - 2014-05-14 16:38 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-05-14 16:38 - 2014-05-14 16:38 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-05-14 16:38 - 2014-05-14 16:38 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-05-14 16:38 - 2014-05-14 16:38 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-05-14 16:33 - 2014-05-14 16:33 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-05-14 15:53 - 2014-05-14 15:52 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-14 14:53 - 2014-05-14 14:39 - 00000000 ____D () C:\Windows\SMINST
2014-05-14 14:34 - 2014-05-14 14:03 - 00000000 ____D () C:\Users\Mitch\AppData\Local\LogMeIn Rescue Applet
2014-05-14 14:26 - 2014-05-14 14:26 - 00000000 ____D () C:\Users\Mitch\My Backup Files
2014-05-14 14:26 - 2014-05-14 12:04 - 00000000 ____D () C:\Users\Mitch\AppData\Local\SoftThinks
2014-05-14 14:26 - 2014-05-14 12:04 - 00000000 ____D () C:\Users\Mitch
2014-05-14 13:11 - 2014-05-14 13:11 - 00002094 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
2014-05-14 13:11 - 2014-05-14 13:11 - 00002082 _____ () C:\Users\Public\Desktop\Belarc Advisor.lnk
2014-05-14 13:11 - 2014-05-14 13:11 - 00000000 ____D () C:\Program Files (x86)\Belarc
2014-05-14 12:16 - 2014-05-14 12:16 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Adobe
2014-05-14 12:14 - 2014-05-14 12:14 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0.bak
2014-05-14 12:14 - 2014-05-14 12:14 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0.bak
2014-05-14 12:14 - 2014-05-14 12:14 - 00000552 _____ () C:\Windows\system32\spsys.log
2014-05-14 12:14 - 2014-05-14 12:14 - 00000000 ____D () C:\Users\Mitch\Documents\AlienFX
2014-05-14 12:14 - 2014-05-14 12:14 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Intel Corporation
2014-05-14 12:10 - 2014-05-14 12:10 - 00000000 ____D () C:\Users\Mitch\AppData\Local\VirtualStore
2014-05-14 12:04 - 2014-05-14 12:04 - 00000020 ___SH () C:\Users\Mitch\ntuser.ini
2014-05-14 12:04 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-05-14 12:02 - 2014-05-14 12:02 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2014-05-14 12:02 - 2010-11-20 21:50 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Temp
2014-05-12 07:26 - 2014-05-14 17:39 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-14 17:39 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-14 17:39 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-09 01:14 - 2014-05-14 15:18 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 01:11 - 2014-05-14 15:18 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-05 23:40 - 2014-05-14 20:01 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-05 23:17 - 2014-05-14 20:01 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-05 22:25 - 2014-05-14 20:01 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-05 22:07 - 2014-05-14 20:01 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-05 22:00 - 2014-05-14 20:01 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-05 21:10 - 2014-05-14 20:01 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-04 17:12 - 2014-05-14 15:52 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Some content of TEMP:
====================
C:\Users\Mitch\AppData\Local\Temp\avgnt.exe
C:\Users\Mitch\AppData\Local\Temp\nvStInst.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-05-29 09:46

==================== End Of Log ============================

 

Kindest Regards,

Mitch

 

Sneaky Edit- I still have the Farbar Recovery tool open. I will await further instructions :)

Attached Files


Edited by texasmitch14, 01 June 2014 - 07:28 PM.


#4 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Instructor
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:01:35 AM

Posted 04 June 2014 - 04:04 PM

Hello again texasmitch14,

I sincerely apologize for the delay in responding to this topic. I must have missed your reply for some reason. For that, I apologize!
 
==========

If there is a "next time", please contact me directly...as I mention in my signature, please PM me if I have not replied within 48 hours of your last post.
 
==========
 
The MBAM log you posted is a little dodgy, but I do not see it in your FRST logs. This issue may not be malware related, but since we're here, let's check another tool...Could you please run this for me next:

Run Combofix

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out here or here

Combofix may need to reboot your computer more than once to do its job...this is normal.

You can download Combofix from one of these links.

  • Close any open browsers or any other programs that are open.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you C:\Combofix.txt. Please include that in your next reply.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

==========

In your next reply, please include:
 

  • The Combofix log
  • How is the machine running now? Same issues as before?
     

bloopie



#5 texasmitch14

texasmitch14
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 04 June 2014 - 05:17 PM

 

If there is a "next time", please contact me directly...as I mention in my signature, please PM me if I have not replied within 48 hours of your last post.

Your first post you were stressing how you needed me to be patient and how you had children and a life(which I understand). I didn't want to bother you. Next time, i'll PM you directly.
 

 

 

The MBAM log you posted is a little dodgy, but I do not see it in your FRST logs. This issue may not be malware related,

After doing a google search of the process that MBAM detected, I ended up on a page to BleepingComputer and the result of this process was masked as a cryptocurrency "miner". ( http://www.bleepingcomputer.com/forums/t/520843/wmpnetwkexe-wtf/ - apperently this person was having a similar issue with this process, though they could be totally unrelated. From what I can understand it is plausible and likley the same. )

 

I have personally used a GPU miner(before I formatted my computer) and my GPU and computer would instantly become very loud as the GPU/miner was on. After hearing my computer sound so loud I actually thought to myself, geez it sounds like i'm running a GPU/CPU miner why is my computer running so hard/much. That's what lead me to CTRL+ALT+DELETE to find that process in the first place. I could be wrong, but i'm almost certain it was malware and like the other BleepingComputer thread said about this process:"wmpnetwk.exe"  is actually a piece of malware. But since you are saying my logs look clean, I can't argue/oppose that.

 

 

ComboFix 14-06-04.01 - Mitch 06/04/2014  16:54:30.1.8 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.1.1033.18.8144.6144 [GMT -5:00]
Running from: c:\users\Mitch\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Mitch\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\users\Mitch\AppData\Roaming\Microsoft\Windows\Recent\Counter-Strike Global Offensive.url
c:\users\Mitch\AppData\Roaming\Microsoft\Windows\Recent\libcurl-4.dll
c:\users\Mitch\AppData\Roaming\Microsoft\Windows\Recent\libiconv-2.dll
c:\users\Mitch\AppData\Roaming\Microsoft\Windows\Recent\libidn-11.dll
c:\users\Mitch\AppData\Roaming\Microsoft\Windows\Recent\libintl-8.dll
c:\users\Mitch\AppData\Roaming\Microsoft\Windows\Recent\libwinpthread-1.dll
c:\users\Mitch\AppData\Roaming\Microsoft\Windows\Recent\wmpnetwk.exe
c:\users\Mitch\AppData\Roaming\Microsoft\Windows\Recent\zlib1.dll
X:\Autorun.inf
.
.
(((((((((((((((((((((((((   Files Created from 2014-05-04 to 2014-06-04  )))))))))))))))))))))))))))))))
.
.
2014-06-02 00:18 . 2014-06-02 00:21    --------    d-----w-    C:\FRST
2014-05-25 16:24 . 2014-05-25 16:24    --------    d-----w-    c:\program files\WinRAR
2014-05-21 13:46 . 2014-05-21 13:46    --------    d-----w-    c:\program files (x86)\Mozilla Thunderbird
2014-05-16 21:07 . 2014-05-16 21:07    --------    d-----w-    c:\program files\SUPERAntiSpyware
2014-05-16 21:07 . 2014-05-16 21:07    --------    d-----w-    c:\programdata\SUPERAntiSpyware.com
2014-05-16 20:25 . 2014-05-16 20:25    --------    d-----w-    c:\program files\CCleaner
2014-05-16 19:24 . 2014-05-16 19:24    --------    d-----w-    c:\programdata\Blizzard Entertainment
2014-05-16 19:24 . 2014-05-16 19:24    --------    d-----w-    c:\program files (x86)\Common Files\Blizzard Entertainment
2014-05-16 18:53 . 2014-03-06 08:15    940032    ----a-w-    c:\windows\system32\MsSpellCheckingFacility.exe
2014-05-16 18:44 . 2014-05-16 18:44    --------    d-----w-    c:\program files (x86)\AGEIA Technologies
2014-05-16 18:40 . 2014-05-16 18:40    --------    d-----w-    c:\users\UpdatusUser
2014-05-16 18:39 . 2012-09-06 22:02    3492258    ----a-w-    c:\windows\system32\nvcoproc.bin
2014-05-15 04:35 . 2014-05-15 04:34    84720    ----a-w-    c:\windows\system32\drivers\avnetflt.sys
2014-05-15 01:44 . 2013-11-23 18:26    417792    ----a-w-    c:\windows\SysWow64\WMPhoto.dll
2014-05-15 01:44 . 2013-11-23 17:47    465920    ----a-w-    c:\windows\system32\WMPhoto.dll
2014-05-15 01:44 . 2014-02-04 02:32    1424384    ----a-w-    c:\windows\system32\WindowsCodecs.dll
2014-05-15 01:44 . 2014-02-04 02:04    1230336    ----a-w-    c:\windows\SysWow64\WindowsCodecs.dll
2014-05-15 01:44 . 2012-02-11 06:36    559104    ----a-w-    c:\windows\system32\spoolsv.exe
2014-05-15 01:44 . 2012-02-11 06:36    67072    ----a-w-    c:\windows\splwow64.exe
2014-05-15 01:03 . 2014-05-15 01:04    --------    d-sh--w-    c:\windows\BitLockerDiscoveryVolumeContents
2014-05-15 01:03 . 2014-05-15 01:03    --------    d-----w-    c:\windows\RemotePackages
2014-05-15 01:01 . 2014-05-06 04:40    23544320    ----a-w-    c:\windows\system32\mshtml.dll
2014-05-15 01:01 . 2014-05-06 03:00    84992    ----a-w-    c:\windows\system32\mshtmled.dll
2014-05-15 01:01 . 2014-05-06 04:17    2724864    ----a-w-    c:\windows\system32\mshtml.tlb
2014-05-15 01:01 . 2014-05-06 03:07    2724864    ----a-w-    c:\windows\SysWow64\mshtml.tlb
2014-05-15 00:53 . 2013-12-24 23:09    1987584    ----a-w-    c:\windows\SysWow64\d3d10warp.dll
2014-05-15 00:53 . 2013-12-24 22:48    2565120    ----a-w-    c:\windows\system32\d3d10warp.dll
2014-05-15 00:53 . 2013-11-26 08:16    3419136    ----a-w-    c:\windows\SysWow64\d2d1.dll
2014-05-15 00:53 . 2013-11-22 22:48    3928064    ----a-w-    c:\windows\system32\d2d1.dll
2014-05-14 23:21 . 2008-07-31 15:41    238088    ----a-w-    c:\windows\SysWow64\xactengine3_2.dll
2014-05-14 23:07 . 2014-05-20 16:12    --------    d-----w-    c:\program files (x86)\StarCraft II
2014-05-14 23:07 . 2014-05-14 23:07    --------    d-----w-    c:\programdata\Battle.net
2014-05-14 22:47 . 2014-05-14 22:50    --------    d-----w-    c:\program files (x86)\Razer
2014-05-14 22:47 . 2014-05-14 22:47    --------    d-----w-    c:\programdata\Razer
2014-05-14 22:39 . 2014-06-04 22:02    122584    ----a-w-    c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-05-14 22:39 . 2014-05-30 18:34    --------    d-----w-    c:\program files (x86)\Malwarebytes Anti-Malware
2014-05-14 22:39 . 2014-05-14 22:39    --------    d-----w-    c:\programdata\Malwarebytes
2014-05-14 22:39 . 2014-05-12 12:26    63704    ----a-w-    c:\windows\system32\drivers\mwac.sys
2014-05-14 22:39 . 2014-05-12 12:26    91352    ----a-w-    c:\windows\system32\drivers\mbamchameleon.sys
2014-05-14 22:39 . 2014-05-12 12:25    25816    ----a-w-    c:\windows\system32\drivers\mbam.sys
2014-05-14 22:34 . 2014-06-03 12:38    130584    ----a-w-    c:\windows\system32\drivers\avipbb.sys
2014-05-14 22:34 . 2014-06-03 12:38    112080    ----a-w-    c:\windows\system32\drivers\avgntflt.sys
2014-05-14 22:34 . 2014-02-25 16:41    28600    ----a-w-    c:\windows\system32\drivers\avkmgr.sys
2014-05-14 22:32 . 2014-05-14 22:34    --------    d-----w-    c:\program files (x86)\Avira
2014-05-14 22:32 . 2014-05-14 22:34    --------    d-----w-    c:\programdata\Avira
2014-05-14 22:32 . 2014-05-14 22:32    --------    d-----w-    c:\programdata\Package Cache
2014-05-14 22:30 . 2014-05-22 13:23    --------    d-----w-    c:\program files (x86)\Mozilla Maintenance Service
2014-05-14 22:12 . 2014-05-14 22:12    --------    d-s---w-    c:\windows\system32\CompatTel
2014-05-14 21:59 . 2013-05-10 05:56    12625920    ----a-w-    c:\windows\system32\wmploc.DLL
2014-05-14 21:59 . 2013-05-10 04:56    12625408    ----a-w-    c:\windows\SysWow64\wmploc.DLL
2014-05-14 21:59 . 2013-05-10 04:30    167424    ----a-w-    c:\program files\Windows Media Player\wmplayer.exe
2014-05-14 21:59 . 2013-05-10 03:48    164864    ----a-w-    c:\program files (x86)\Windows Media Player\wmplayer.exe
2014-05-14 21:59 . 2013-05-10 05:56    14631424    ----a-w-    c:\windows\system32\wmp.dll
2014-05-14 21:51 . 2014-05-14 21:51    --------    d-----w-    c:\windows\Migration
2014-05-14 21:41 . 2013-10-14 23:00    28368    ----a-w-    c:\windows\system32\IEUDINIT.EXE
2014-05-14 21:33 . 2014-05-14 21:33    9728    ---ha-w-    c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-05-14 21:18 . 2012-07-26 04:47    2560    ----a-w-    c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2014-05-14 20:52 . 2014-05-14 20:53    --------    d-----w-    c:\windows\system32\MRT
2014-05-14 20:43 . 2012-07-26 02:26    87040    ----a-w-    c:\windows\system32\drivers\WUDFPf.sys
2014-05-14 20:43 . 2012-07-26 02:26    198656    ----a-w-    c:\windows\system32\drivers\WUDFRd.sys
2014-05-14 20:43 . 2012-07-26 03:08    229888    ----a-w-    c:\windows\system32\WUDFHost.exe
2014-05-14 20:43 . 2012-07-26 03:08    84992    ----a-w-    c:\windows\system32\WUDFSvc.dll
2014-05-14 20:43 . 2012-07-26 03:08    744448    ----a-w-    c:\windows\system32\WUDFx.dll
2014-05-14 20:43 . 2012-07-26 03:08    45056    ----a-w-    c:\windows\system32\WUDFCoinstaller.dll
2014-05-14 20:43 . 2012-07-26 03:08    194048    ----a-w-    c:\windows\system32\WUDFPlatform.dll
2014-05-14 20:38 . 2014-04-17 10:31    10651704    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{F01499FF-3168-4E99-85B9-F8F16B8F9347}\mpengine.dll
2014-05-14 20:30 . 2012-03-01 06:46    23408    ----a-w-    c:\windows\system32\drivers\fs_rec.sys
2014-05-14 20:30 . 2012-03-01 06:28    5120    ----a-w-    c:\windows\system32\wmi.dll
2014-05-14 20:30 . 2012-03-01 05:29    5120    ----a-w-    c:\windows\SysWow64\wmi.dll
2014-05-14 20:19 . 2013-10-19 02:18    81408    ----a-w-    c:\windows\system32\imagehlp.dll
2014-05-14 20:18 . 2014-04-12 02:19    1460736    ----a-w-    c:\windows\system32\lsasrv.dll
2014-05-14 20:16 . 2013-02-27 06:02    111448    ----a-w-    c:\windows\system32\consent.exe
2014-05-14 20:15 . 2013-10-04 02:24    1930752    ----a-w-    c:\windows\system32\authui.dll
2014-05-14 20:14 . 2013-05-10 05:49    30720    ----a-w-    c:\windows\system32\cryptdlg.dll
2014-05-14 20:13 . 2013-09-08 02:27    327168    ----a-w-    c:\windows\system32\mswsock.dll
2014-05-14 20:12 . 2012-11-22 05:44    800768    ----a-w-    c:\windows\system32\usp10.dll
2014-05-14 19:56 . 2012-06-06 06:05    495616    ----a-w-    c:\program files\Common Files\System\ado\msadox.dll
2014-05-14 19:56 . 2012-06-06 06:05    466944    ----a-w-    c:\program files\Common Files\System\ado\msadomd.dll
2014-05-14 19:56 . 2012-06-06 06:05    1499136    ----a-w-    c:\program files\Common Files\System\ado\msado15.dll
2014-05-14 19:56 . 2012-06-06 06:05    258048    ----a-w-    c:\program files\Common Files\System\msadc\msadco.dll
2014-05-14 19:56 . 2012-06-06 05:05    57344    ----a-w-    c:\program files (x86)\Common Files\System\ado\msador15.dll
2014-05-14 19:56 . 2012-06-06 05:05    352256    ----a-w-    c:\program files (x86)\Common Files\System\ado\msadomd.dll
2014-05-14 19:56 . 2012-06-06 05:05    1019904    ----a-w-    c:\program files (x86)\Common Files\System\ado\msado15.dll
2014-05-14 19:56 . 2012-06-06 05:03    805376    ----a-w-    c:\windows\SysWow64\cdosys.dll
2014-05-14 19:56 . 2012-06-06 06:05    61440    ----a-w-    c:\program files\Common Files\System\ado\msador15.dll
2014-05-14 19:56 . 2012-06-06 06:02    1133568    ----a-w-    c:\windows\system32\cdosys.dll
2014-05-14 19:56 . 2012-06-06 05:05    143360    ----a-w-    c:\program files (x86)\Common Files\System\ado\msjro.dll
2014-05-14 19:56 . 2012-06-06 05:05    372736    ----a-w-    c:\program files (x86)\Common Files\System\ado\msadox.dll
2014-05-14 19:56 . 2012-06-06 05:05    212992    ----a-w-    c:\program files (x86)\Common Files\System\msadc\msadco.dll
2014-05-14 19:54 . 2013-10-12 02:30    830464    ----a-w-    c:\windows\system32\nshwfp.dll
2014-05-14 19:54 . 2013-10-12 02:29    859648    ----a-w-    c:\windows\system32\IKEEXT.DLL
2014-05-14 19:54 . 2013-10-12 02:29    324096    ----a-w-    c:\windows\system32\FWPUCLNT.DLL
2014-05-14 19:54 . 2013-10-12 02:03    656896    ----a-w-    c:\windows\SysWow64\nshwfp.dll
2014-05-14 19:54 . 2013-10-12 02:01    216576    ----a-w-    c:\windows\SysWow64\FWPUCLNT.DLL
2014-05-14 19:54 . 2013-08-28 01:12    461312    ----a-w-    c:\windows\system32\scavengeui.dll
2014-05-14 19:42 . 2012-06-02 22:19    2428952    ----a-w-    c:\windows\system32\wuaueng.dll
2014-05-14 19:42 . 2012-06-02 22:19    57880    ----a-w-    c:\windows\system32\wuauclt.exe
2014-05-14 19:42 . 2012-06-02 22:19    44056    ----a-w-    c:\windows\system32\wups2.dll
2014-05-14 19:42 . 2012-06-02 22:15    2622464    ----a-w-    c:\windows\system32\wucltux.dll
2014-05-14 19:42 . 2012-06-02 22:19    38424    ----a-w-    c:\windows\system32\wups.dll
2014-05-14 19:42 . 2012-06-02 22:19    701976    ----a-w-    c:\windows\system32\wuapi.dll
2014-05-14 19:42 . 2012-06-02 22:15    99840    ----a-w-    c:\windows\system32\wudriver.dll
2014-05-14 19:42 . 2012-06-02 20:19    186752    ----a-w-    c:\windows\system32\wuwebv.dll
2014-05-14 19:42 . 2012-06-02 20:15    36864    ----a-w-    c:\windows\system32\wuapp.exe
2014-05-14 19:39 . 2014-05-14 19:53    --------    d-----w-    c:\windows\SMINST
2014-05-14 18:30 . 2014-05-14 18:30    --------    d-----w-    c:\windows\SysWow64\Wat
2014-05-14 18:30 . 2014-05-14 18:30    --------    d-----w-    c:\windows\system32\Wat
2014-05-14 18:11 . 2014-05-14 18:11    --------    d-----w-    c:\program files (x86)\Belarc
2014-05-14 17:04 . 2014-05-14 19:26    --------    d-----w-    c:\users\Mitch
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-14 23:55 . 2012-06-13 21:27    70832    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-14 23:55 . 2012-06-13 21:27    692400    ----a-w-    c:\windows\SysWow64\FlashPlayerApp.exe
2014-04-09 02:52 . 2014-04-09 02:52    33448    ----a-w-    c:\windows\system32\drivers\rzdaendpt.sys
2014-04-09 02:52 . 2014-04-09 02:52    31400    ----a-w-    c:\windows\system32\drivers\rzvkeyboard.sys
2014-04-09 02:52 . 2014-04-09 02:52    39080    ----a-w-    c:\windows\system32\drivers\rzendpt.sys
2014-04-09 02:52 . 2014-04-09 02:52    154792    ----a-w-    c:\windows\system32\drivers\rzudd.sys
2014-04-09 02:24 . 2014-04-09 02:24    88576    ----a-w-    c:\windows\SysWow64\rzdevinfo.dll
2014-04-09 02:24 . 2014-04-09 02:24    154624    ----a-w-    c:\windows\SysWow64\rztouchdll.dll
2014-04-09 02:24 . 2014-04-09 02:24    117248    ----a-w-    c:\windows\SysWow64\rzdisplaydll.dll
2014-04-09 02:24 . 2014-04-09 02:24    856576    ----a-w-    c:\windows\SysWow64\rzdevicedll.dll
2014-04-09 02:24 . 2014-04-09 02:24    306688    ----a-w-    c:\windows\SysWow64\rzaudiodll.dll
2014-03-31 14:35 . 2010-11-21 03:27    270496    ------w-    c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2014-05-29 1754816]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology enterprise\IAStorIcon.exe" [2011-10-12 286720]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-16 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-16 932288]
"Avira Systray"="c:\program files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [2014-05-07 183376]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-06-03 737872]
"Razer Synapse"="c:\program files (x86)\Razer\Synapse\RzSynapse.exe" [2014-04-17 585048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 AlienFusionService;Alienware Fusion Service;c:\program files\Alienware\Command Center\AlienFusionService.exe;c:\program files\Alienware\Command Center\AlienFusionService.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
R2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 AntiVirWebService;Avira Web Protection;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
S0 iaStorA;iaStorA;c:\windows\system32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\drivers\iaStorF.sys;c:\windows\SYSNATIVE\drivers\iaStorF.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [x]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [x]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [x]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel® Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\AlienRespawn\sftservice.EXE;c:\program files (x86)\AlienRespawn\sftservice.EXE [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 rusb3hub;Renesas Electronics USB 3.0 Hub Driver (Version 3.0);c:\windows\system32\DRIVERS\rusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\rusb3hub.sys [x]
S3 rusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver (Version 3.0);c:\windows\system32\DRIVERS\rusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\rusb3xhc.sys [x]
S3 rzdaendpt;Razer DeathAdder end point;c:\windows\system32\DRIVERS\rzdaendpt.sys;c:\windows\SYSNATIVE\DRIVERS\rzdaendpt.sys [x]
S3 rzendpt;rzendpt;c:\windows\system32\DRIVERS\rzendpt.sys;c:\windows\SYSNATIVE\DRIVERS\rzendpt.sys [x]
S3 rzudd;Razer Mouse Driver;c:\windows\system32\DRIVERS\rzudd.sys;c:\windows\SYSNATIVE\DRIVERS\rzudd.sys [x]
S3 rzvkeyboard;Razer Virtual Keyboard Driver;c:\windows\system32\DRIVERS\rzvkeyboard.sys;c:\windows\SYSNATIVE\DRIVERS\rzvkeyboard.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MBAMSWISSARMY
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2014-06-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-13 23:55]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-11-21 6419560]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-11-21 1156712]
"Command Center Controllers"="c:\program files\Alienware\Command Center\AWCCStartupOrchestrator.exe" [2012-01-10 12616]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://AlienwareArena.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 75.75.76.76 75.75.75.75
FF - ProfilePath - c:\users\Mitch\AppData\Roaming\Mozilla\Firefox\Profiles\32eti7c4.default\
FF - prefs.js: browser.startup.homepage - google.com
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
AddRemove-World of Warcraft - c:\users\Public\Games\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exe
.
.
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
c:\program files (x86)\AlienRespawn\TOASTER.EXE
c:\program files (x86)\AlienRespawn\Components\DSUpdate\DSUpd.exe
c:\program files (x86)\AlienRespawn\COMPONENTS\SCHEDULER\STSERVICE.EXE
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Completion time: 2014-06-04  17:04:11 - machine was rebooted
ComboFix-quarantined-files.txt  2014-06-04 22:04
.
Pre-Run: 922,147,446,784 bytes free
Post-Run: 921,996,939,264 bytes free
.
- - End Of File - - 3DD14339D2FD63F3292436A88D7546A2

 

 

How is the machine running now? Same issues as before?

I got 3 or 4 error messages during the ComboFix.. I copied one of them:

[Application Error]
Exception EAccessViolation in module ERUNT.3XE at 00003A62. Access violation at address 00403A62 in module
'ERUNT.3XE'. Read of address 006F004E.

 

There other 2 or 3 similiar messages had different numbers/address, but same overall message.

 

Also, upon booting up right now it didn't detect Firefox to be my default browser. My mouse and keyboard utility program didn't load instantly, along with Avira Anti Virus, and I had to right click my GPU to get the icon back as-well. I had to manually load programs that usually auto-start.

 

The machine seems to be running fine. The issue was the process I discovered and kept manually closing, then waking up to MBAM quarantining it. Now I am just concerned that my computer is clean and safe to use. I also have questions regarding the consequences. Using those two programs- is that enough information to come to the conclusion that my computer is clean? Though I take your word, it is hard to believe it was not malware related like you said; but I suppose that is a good thing.

 

Is there any explanation or reason you can tell me about that proccess; why my computer would sound so loud; why it was taking so much of my CPU when I CRTL+ALT+DELETE; was it just a corrupted file or something?

 

Regards,

Mitch


Edited by texasmitch14, 04 June 2014 - 05:25 PM.


#6 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Instructor
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:01:35 AM

Posted 06 June 2014 - 05:56 PM

Hello again Mitch,

 

I apologize for the delay, I was not feeling well the past couple of days.

 

I could be wrong, but i'm almost certain it was malware and like the other BleepingComputer thread said about this process:"wmpnetwk.exe"  is actually a piece of malware.

The process "wmpnetwk.exe" is part of Windows Media Player and by itself, is not malware. What MBAM detected was merely a registry entry point that could potentially lead to malware. The process itself is safe. :)

 

==========

 

I have personally used a GPU miner(before I formatted my computer) and my GPU and computer would instantly become very loud as the GPU/miner was on. After hearing my computer sound so loud I actually thought to myself, geez it sounds like i'm running a GPU/CPU miner why is my computer running so hard/much.

I will be looking into this behavior as soon as I can, but so far, things aren't looking too bad. :)

 

==========

 

As long as Combofix ran, then the errors shouldn't be a problem.

 

Also, upon booting up right now it didn't detect Firefox to be my default browser.

This is only a part of CF's routines, and once changed back to FF again, it should act as normal. :thumbup2:

 

==========

 

I'm going to be mobile very soon, but I just wanted to get a reply back to you. I will cover the rest of your questions/issues as soon as I can!

 

Thank you for being patient thus far, :)

 

bloopie



#7 texasmitch14

texasmitch14
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 07 June 2014 - 11:17 AM

Alright thanks. I will await further instructions.



#8 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Instructor
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:01:35 AM

Posted 08 June 2014 - 04:07 PM

Hello again,

 

Again, thanks for your patience! :) 

 

==========
 
Your logs are looking okay, and the "loud fan" you're experiencing has to be related to your GPU miner. There are a few things that you could do, but I'm not really comfortable giving you instructions to "clock" your machine in such a way that the GPU miner works the way you want it to. This is not really "clocking" your machine, but that program must be the root cause of the issue, and I cannot really condone the use of such programs.
 
In either case, your logs are looking pretty good and your issue is not related to malware ATM, but I would have to suggest not using those "mining" programs to begin with. They could be a prelude to a malware situation pretty quickly.

 

Any malware entry points, or files/folders that are malware related, have already been removed, so your machine is looking pretty good as of now. :)
 
==========
 
Now, I'd like you to just run one more script with Combofix (and post me the log) before we uninstall it, and you can then be on your merry way! :wink:

Run a Combofix Script


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy the text in the codebox below, then paste it into the empty notepad:
 

ClearJavaCache::

Quit::

Save this as CFScript.txt, in the same location as ComboFix.exe


CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

==========

Let me know if you have problems running CF again this time with the script above, and also let me know if you're having any other problems with your machine!

bloopie



#9 texasmitch14

texasmitch14
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 08 June 2014 - 06:01 PM

As requested:

 

ComboFix 14-06-04.01 - Mitch 06/08/2014  17:44:12.2.8 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.1.1033.18.8144.5975 [GMT -5:00]
Running from: c:\users\Mitch\Downloads\ComboFix.exe
Command switches used :: c:\users\Mitch\Desktop\CFScript.txt.txt
AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Mitch\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
.
.
(((((((((((((((((((((((((   Files Created from 2014-05-08 to 2014-06-08  )))))))))))))))))))))))))))))))
.
.
2014-06-08 22:47 . 2014-06-08 22:47    --------    d-----w-    c:\users\Default\AppData\Local\temp
2014-06-08 22:47 . 2014-06-08 22:47    --------    d-----w-    c:\users\Administrator\AppData\Local\temp
2014-06-02 00:18 . 2014-06-02 00:21    --------    d-----w-    C:\FRST
2014-05-25 16:24 . 2014-05-25 16:24    --------    d-----w-    c:\program files\WinRAR
2014-05-24 02:33 . 2014-05-24 02:33    864256    ----a-w-    c:\windows\SysWow64\rzdevicedll.dll
2014-05-24 02:33 . 2014-05-24 02:33    325120    ----a-w-    c:\windows\SysWow64\rzaudiodll.dll
2014-05-21 13:46 . 2014-05-21 13:46    --------    d-----w-    c:\program files (x86)\Mozilla Thunderbird
2014-05-19 06:47 . 2014-05-19 06:47    33448    ----a-w-    c:\windows\system32\drivers\rzdaendpt.sys
2014-05-19 06:47 . 2014-05-19 06:47    31400    ----a-w-    c:\windows\system32\drivers\rzvkeyboard.sys
2014-05-19 06:47 . 2014-05-19 06:47    39080    ----a-w-    c:\windows\system32\drivers\rzendpt.sys
2014-05-19 06:47 . 2014-05-19 06:47    155816    ----a-w-    c:\windows\system32\drivers\rzudd.sys
2014-05-19 06:26 . 2014-05-19 06:26    89088    ----a-w-    c:\windows\SysWow64\rzdevinfo.dll
2014-05-19 06:26 . 2014-05-19 06:26    155136    ----a-w-    c:\windows\SysWow64\rztouchdll.dll
2014-05-19 06:26 . 2014-05-19 06:26    117248    ----a-w-    c:\windows\SysWow64\rzdisplaydll.dll
2014-05-16 21:07 . 2014-05-16 21:07    --------    d-----w-    c:\program files\SUPERAntiSpyware
2014-05-16 21:07 . 2014-05-16 21:07    --------    d-----w-    c:\programdata\SUPERAntiSpyware.com
2014-05-16 20:25 . 2014-05-16 20:25    --------    d-----w-    c:\program files\CCleaner
2014-05-16 19:24 . 2014-05-16 19:24    --------    d-----w-    c:\programdata\Blizzard Entertainment
2014-05-16 19:24 . 2014-05-16 19:24    --------    d-----w-    c:\program files (x86)\Common Files\Blizzard Entertainment
2014-05-16 18:53 . 2014-03-06 08:15    940032    ----a-w-    c:\windows\system32\MsSpellCheckingFacility.exe
2014-05-16 18:44 . 2014-05-16 18:44    --------    d-----w-    c:\program files (x86)\AGEIA Technologies
2014-05-16 18:40 . 2014-05-16 18:40    --------    d-----w-    c:\users\UpdatusUser
2014-05-16 18:39 . 2012-09-06 22:02    3492258    ----a-w-    c:\windows\system32\nvcoproc.bin
2014-05-15 04:35 . 2014-05-15 04:34    84720    ----a-w-    c:\windows\system32\drivers\avnetflt.sys
2014-05-15 01:44 . 2013-11-23 18:26    417792    ----a-w-    c:\windows\SysWow64\WMPhoto.dll
2014-05-15 01:44 . 2013-11-23 17:47    465920    ----a-w-    c:\windows\system32\WMPhoto.dll
2014-05-15 01:44 . 2014-02-04 02:32    1424384    ----a-w-    c:\windows\system32\WindowsCodecs.dll
2014-05-15 01:44 . 2014-02-04 02:04    1230336    ----a-w-    c:\windows\SysWow64\WindowsCodecs.dll
2014-05-15 01:44 . 2012-02-11 06:36    559104    ----a-w-    c:\windows\system32\spoolsv.exe
2014-05-15 01:44 . 2012-02-11 06:36    67072    ----a-w-    c:\windows\splwow64.exe
2014-05-15 01:03 . 2014-05-15 01:04    --------    d-sh--w-    c:\windows\BitLockerDiscoveryVolumeContents
2014-05-15 01:03 . 2014-05-15 01:03    --------    d-----w-    c:\windows\RemotePackages
2014-05-15 01:01 . 2014-05-06 04:40    23544320    ----a-w-    c:\windows\system32\mshtml.dll
2014-05-15 01:01 . 2014-05-06 03:00    84992    ----a-w-    c:\windows\system32\mshtmled.dll
2014-05-15 01:01 . 2014-05-06 04:17    2724864    ----a-w-    c:\windows\system32\mshtml.tlb
2014-05-15 01:01 . 2014-05-06 03:07    2724864    ----a-w-    c:\windows\SysWow64\mshtml.tlb
2014-05-15 00:53 . 2013-12-24 23:09    1987584    ----a-w-    c:\windows\SysWow64\d3d10warp.dll
2014-05-15 00:53 . 2013-12-24 22:48    2565120    ----a-w-    c:\windows\system32\d3d10warp.dll
2014-05-15 00:53 . 2013-11-26 08:16    3419136    ----a-w-    c:\windows\SysWow64\d2d1.dll
2014-05-15 00:53 . 2013-11-22 22:48    3928064    ----a-w-    c:\windows\system32\d2d1.dll
2014-05-14 23:21 . 2008-07-31 15:41    238088    ----a-w-    c:\windows\SysWow64\xactengine3_2.dll
2014-05-14 23:07 . 2014-06-06 19:25    --------    d-----w-    c:\program files (x86)\StarCraft II
2014-05-14 23:07 . 2014-05-14 23:07    --------    d-----w-    c:\programdata\Battle.net
2014-05-14 22:47 . 2014-05-14 22:50    --------    d-----w-    c:\program files (x86)\Razer
2014-05-14 22:47 . 2014-05-14 22:47    --------    d-----w-    c:\programdata\Razer
2014-05-14 22:39 . 2014-06-08 22:51    122584    ----a-w-    c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-05-14 22:39 . 2014-05-30 18:34    --------    d-----w-    c:\program files (x86)\Malwarebytes Anti-Malware
2014-05-14 22:39 . 2014-05-14 22:39    --------    d-----w-    c:\programdata\Malwarebytes
2014-05-14 22:39 . 2014-05-12 12:26    63704    ----a-w-    c:\windows\system32\drivers\mwac.sys
2014-05-14 22:39 . 2014-05-12 12:26    91352    ----a-w-    c:\windows\system32\drivers\mbamchameleon.sys
2014-05-14 22:39 . 2014-05-12 12:25    25816    ----a-w-    c:\windows\system32\drivers\mbam.sys
2014-05-14 22:34 . 2014-06-03 12:38    130584    ----a-w-    c:\windows\system32\drivers\avipbb.sys
2014-05-14 22:34 . 2014-06-03 12:38    112080    ----a-w-    c:\windows\system32\drivers\avgntflt.sys
2014-05-14 22:34 . 2014-02-25 16:41    28600    ----a-w-    c:\windows\system32\drivers\avkmgr.sys
2014-05-14 22:32 . 2014-05-14 22:34    --------    d-----w-    c:\program files (x86)\Avira
2014-05-14 22:32 . 2014-05-14 22:34    --------    d-----w-    c:\programdata\Avira
2014-05-14 22:32 . 2014-05-14 22:32    --------    d-----w-    c:\programdata\Package Cache
2014-05-14 22:30 . 2014-05-22 13:23    --------    d-----w-    c:\program files (x86)\Mozilla Maintenance Service
2014-05-14 22:12 . 2014-05-14 22:12    --------    d-s---w-    c:\windows\system32\CompatTel
2014-05-14 21:59 . 2013-05-10 05:56    12625920    ----a-w-    c:\windows\system32\wmploc.DLL
2014-05-14 21:59 . 2013-05-10 04:56    12625408    ----a-w-    c:\windows\SysWow64\wmploc.DLL
2014-05-14 21:59 . 2013-05-10 04:30    167424    ----a-w-    c:\program files\Windows Media Player\wmplayer.exe
2014-05-14 21:59 . 2013-05-10 03:48    164864    ----a-w-    c:\program files (x86)\Windows Media Player\wmplayer.exe
2014-05-14 21:59 . 2013-05-10 05:56    14631424    ----a-w-    c:\windows\system32\wmp.dll
2014-05-14 21:51 . 2014-05-14 21:51    --------    d-----w-    c:\windows\Migration
2014-05-14 21:41 . 2013-10-14 23:00    28368    ----a-w-    c:\windows\system32\IEUDINIT.EXE
2014-05-14 21:33 . 2014-05-14 21:33    9728    ---ha-w-    c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-05-14 21:18 . 2012-07-26 04:47    2560    ----a-w-    c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2014-05-14 20:52 . 2014-05-14 20:53    --------    d-----w-    c:\windows\system32\MRT
2014-05-14 20:43 . 2012-07-26 02:26    87040    ----a-w-    c:\windows\system32\drivers\WUDFPf.sys
2014-05-14 20:43 . 2012-07-26 02:26    198656    ----a-w-    c:\windows\system32\drivers\WUDFRd.sys
2014-05-14 20:43 . 2012-07-26 03:08    229888    ----a-w-    c:\windows\system32\WUDFHost.exe
2014-05-14 20:43 . 2012-07-26 03:08    84992    ----a-w-    c:\windows\system32\WUDFSvc.dll
2014-05-14 20:43 . 2012-07-26 03:08    744448    ----a-w-    c:\windows\system32\WUDFx.dll
2014-05-14 20:43 . 2012-07-26 03:08    45056    ----a-w-    c:\windows\system32\WUDFCoinstaller.dll
2014-05-14 20:43 . 2012-07-26 03:08    194048    ----a-w-    c:\windows\system32\WUDFPlatform.dll
2014-05-14 20:38 . 2014-04-17 10:31    10651704    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{F01499FF-3168-4E99-85B9-F8F16B8F9347}\mpengine.dll
2014-05-14 20:30 . 2012-03-01 06:46    23408    ----a-w-    c:\windows\system32\drivers\fs_rec.sys
2014-05-14 20:30 . 2012-03-01 06:28    5120    ----a-w-    c:\windows\system32\wmi.dll
2014-05-14 20:30 . 2012-03-01 05:29    5120    ----a-w-    c:\windows\SysWow64\wmi.dll
2014-05-14 20:19 . 2013-10-19 02:18    81408    ----a-w-    c:\windows\system32\imagehlp.dll
2014-05-14 20:18 . 2014-04-12 02:19    1460736    ----a-w-    c:\windows\system32\lsasrv.dll
2014-05-14 20:16 . 2013-02-27 06:02    111448    ----a-w-    c:\windows\system32\consent.exe
2014-05-14 20:15 . 2013-10-04 02:24    1930752    ----a-w-    c:\windows\system32\authui.dll
2014-05-14 20:14 . 2013-05-10 05:49    30720    ----a-w-    c:\windows\system32\cryptdlg.dll
2014-05-14 20:13 . 2013-09-08 02:27    327168    ----a-w-    c:\windows\system32\mswsock.dll
2014-05-14 20:12 . 2012-11-22 05:44    800768    ----a-w-    c:\windows\system32\usp10.dll
2014-05-14 19:56 . 2012-06-06 06:05    495616    ----a-w-    c:\program files\Common Files\System\ado\msadox.dll
2014-05-14 19:56 . 2012-06-06 06:05    466944    ----a-w-    c:\program files\Common Files\System\ado\msadomd.dll
2014-05-14 19:56 . 2012-06-06 06:05    1499136    ----a-w-    c:\program files\Common Files\System\ado\msado15.dll
2014-05-14 19:56 . 2012-06-06 06:05    258048    ----a-w-    c:\program files\Common Files\System\msadc\msadco.dll
2014-05-14 19:56 . 2012-06-06 05:05    57344    ----a-w-    c:\program files (x86)\Common Files\System\ado\msador15.dll
2014-05-14 19:56 . 2012-06-06 05:05    352256    ----a-w-    c:\program files (x86)\Common Files\System\ado\msadomd.dll
2014-05-14 19:56 . 2012-06-06 05:05    1019904    ----a-w-    c:\program files (x86)\Common Files\System\ado\msado15.dll
2014-05-14 19:56 . 2012-06-06 05:03    805376    ----a-w-    c:\windows\SysWow64\cdosys.dll
2014-05-14 19:56 . 2012-06-06 06:05    61440    ----a-w-    c:\program files\Common Files\System\ado\msador15.dll
2014-05-14 19:56 . 2012-06-06 06:02    1133568    ----a-w-    c:\windows\system32\cdosys.dll
2014-05-14 19:56 . 2012-06-06 05:05    143360    ----a-w-    c:\program files (x86)\Common Files\System\ado\msjro.dll
2014-05-14 19:56 . 2012-06-06 05:05    372736    ----a-w-    c:\program files (x86)\Common Files\System\ado\msadox.dll
2014-05-14 19:56 . 2012-06-06 05:05    212992    ----a-w-    c:\program files (x86)\Common Files\System\msadc\msadco.dll
2014-05-14 19:54 . 2013-10-12 02:30    830464    ----a-w-    c:\windows\system32\nshwfp.dll
2014-05-14 19:54 . 2013-10-12 02:29    859648    ----a-w-    c:\windows\system32\IKEEXT.DLL
2014-05-14 19:54 . 2013-10-12 02:29    324096    ----a-w-    c:\windows\system32\FWPUCLNT.DLL
2014-05-14 19:54 . 2013-10-12 02:03    656896    ----a-w-    c:\windows\SysWow64\nshwfp.dll
2014-05-14 19:54 . 2013-10-12 02:01    216576    ----a-w-    c:\windows\SysWow64\FWPUCLNT.DLL
2014-05-14 19:54 . 2013-08-28 01:12    461312    ----a-w-    c:\windows\system32\scavengeui.dll
2014-05-14 19:42 . 2012-06-02 22:19    2428952    ----a-w-    c:\windows\system32\wuaueng.dll
2014-05-14 19:42 . 2012-06-02 22:19    57880    ----a-w-    c:\windows\system32\wuauclt.exe
2014-05-14 19:42 . 2012-06-02 22:19    44056    ----a-w-    c:\windows\system32\wups2.dll
2014-05-14 19:42 . 2012-06-02 22:15    2622464    ----a-w-    c:\windows\system32\wucltux.dll
2014-05-14 19:42 . 2012-06-02 22:19    38424    ----a-w-    c:\windows\system32\wups.dll
2014-05-14 19:42 . 2012-06-02 22:19    701976    ----a-w-    c:\windows\system32\wuapi.dll
2014-05-14 19:42 . 2012-06-02 22:15    99840    ----a-w-    c:\windows\system32\wudriver.dll
2014-05-14 19:42 . 2012-06-02 20:19    186752    ----a-w-    c:\windows\system32\wuwebv.dll
2014-05-14 19:42 . 2012-06-02 20:15    36864    ----a-w-    c:\windows\system32\wuapp.exe
2014-05-14 19:39 . 2014-05-14 19:53    --------    d-----w-    c:\windows\SMINST
2014-05-14 18:30 . 2014-05-14 18:30    --------    d-----w-    c:\windows\SysWow64\Wat
2014-05-14 18:30 . 2014-05-14 18:30    --------    d-----w-    c:\windows\system32\Wat
2014-05-14 18:11 . 2014-05-14 18:11    --------    d-----w-    c:\program files (x86)\Belarc
2014-05-14 17:04 . 2014-05-14 19:26    --------    d-----w-    c:\users\Mitch
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-14 23:55 . 2012-06-13 21:27    70832    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-14 23:55 . 2012-06-13 21:27    692400    ----a-w-    c:\windows\SysWow64\FlashPlayerApp.exe
2014-03-31 14:35 . 2010-11-21 03:27    270496    ------w-    c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2014-05-29 1754816]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology enterprise\IAStorIcon.exe" [2011-10-12 286720]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-16 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-16 932288]
"Avira Systray"="c:\program files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [2014-05-07 183376]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-06-03 737872]
"Razer Synapse"="c:\program files (x86)\Razer\Synapse\RzSynapse.exe" [2014-05-31 585048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 AlienFusionService;Alienware Fusion Service;c:\program files\Alienware\Command Center\AlienFusionService.exe;c:\program files\Alienware\Command Center\AlienFusionService.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
R2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 AntiVirWebService;Avira Web Protection;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
S0 iaStorA;iaStorA;c:\windows\system32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\drivers\iaStorF.sys;c:\windows\SYSNATIVE\drivers\iaStorF.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [x]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [x]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [x]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel® Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\AlienRespawn\sftservice.EXE;c:\program files (x86)\AlienRespawn\sftservice.EXE [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 rusb3hub;Renesas Electronics USB 3.0 Hub Driver (Version 3.0);c:\windows\system32\DRIVERS\rusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\rusb3hub.sys [x]
S3 rusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver (Version 3.0);c:\windows\system32\DRIVERS\rusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\rusb3xhc.sys [x]
S3 rzdaendpt;Razer DeathAdder end point;c:\windows\system32\DRIVERS\rzdaendpt.sys;c:\windows\SYSNATIVE\DRIVERS\rzdaendpt.sys [x]
S3 rzendpt;rzendpt;c:\windows\system32\DRIVERS\rzendpt.sys;c:\windows\SYSNATIVE\DRIVERS\rzendpt.sys [x]
S3 rzudd;Razer Mouse Driver;c:\windows\system32\DRIVERS\rzudd.sys;c:\windows\SYSNATIVE\DRIVERS\rzudd.sys [x]
S3 rzvkeyboard;Razer Virtual Keyboard Driver;c:\windows\system32\DRIVERS\rzvkeyboard.sys;c:\windows\SYSNATIVE\DRIVERS\rzvkeyboard.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MBAMSWISSARMY
.
Contents of the 'Scheduled Tasks' folder
.
2014-06-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-13 23:55]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-11-21 6419560]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-11-21 1156712]
"Command Center Controllers"="c:\program files\Alienware\Command Center\AWCCStartupOrchestrator.exe" [2012-01-10 12616]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://AlienwareArena.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 75.75.76.76 75.75.75.75
FF - ProfilePath - c:\users\Mitch\AppData\Roaming\Mozilla\Firefox\Profiles\32eti7c4.default\
FF - prefs.js: browser.startup.homepage - google.com
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
AddRemove-World of Warcraft - c:\users\Public\Games\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
c:\program files (x86)\AlienRespawn\TOASTER.EXE
c:\program files (x86)\AlienRespawn\COMPONENTS\SCHEDULER\STSERVICE.EXE
c:\program files (x86)\AlienRespawn\Components\DSUpdate\DSUpd.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Completion time: 2014-06-08  17:54:03 - machine was rebooted
ComboFix-quarantined-files.txt  2014-06-08 22:54
ComboFix2.txt  2014-06-04 22:04
.
Pre-Run: 920,262,856,704 bytes free
Post-Run: 920,172,019,712 bytes free
.
- - End Of File - - 79935FFFAF47EEFD7FBEA4A34CD87874
 

 

 

No problems running combofix.

 

Thanks for checking my logs and making sure my computer is safe- I appreciate it.

 

Kindest Regards,

Mitch



#10 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Instructor
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:01:35 AM

Posted 08 June 2014 - 06:34 PM

Hello again Mitch,
 
Logs are looking good, and you should be good to go! :)
 

Thanks for checking my logs and making sure my computer is safe- I appreciate it.

It was my pleasure! Normally, I'm much more attentive then I was here with you, but it was really nothing personal...it was just how my life is moving at the moment. I again, apologize for the delays in my responses.
 
==========

Your machine appears to be clean! :thumbsup:

Let's do some housekeeping now:



The following steps will implement some cleanup procedures. It will also reset your System Restore by flushing out previous restore points and create a new restore point. It will also remove all the backups our tools may have made.


Step :step1:

DeFogger:

Note** This only needs to be run if it was run before - If not then skip it.

To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
Your Emulation drivers are now re-enabled.

==========

Step :step2:

Uninstall ComboFix:
  • Turn off all active protection software.
  • Hold the "Windows0d8a4985-b5e2-41a6-a1b6-e4bafb517937_92." key and press "R" to open the runbox, then copy/paste ComboFix /Uninstall into the box and click Ok.
  • Note the space between the X and the /Uninstall, it needs to be there.
CF-Uninstall.png

==========

Step :step3:

Download and Run TFC:

Please download TFC (Temp File Cleaner) by Old Timer and save it to your desktop.
Double-click on TFC.exe to run it. If you are using Vista, right-click on the file and choose Run as Administrator.
Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
  • TFC will clear out all temp folders for all user accounts (temp, IE temp, Java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder.
    • Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.
    Note: It is normal for the computer to be slow to boot after running TFC cleaner the first time.
==========

Step :step4:

Download and Run OTC:

We will now remove the tools we used during this fix using OTC.
  • Download OTC by OldTimer and save it to your desktop.
  • Double click OTC_Icon.jpg icon to start the program. If you are using Vista or Windows 7, please right-click and choose run as administrator
  • Then Click the big CleanUp.jpg button.
  • You will get a prompt saying "Begin Cleanup Process". Please select Yes.
  • Restart your computer when prompted.
Any programs and logs that are left over you can just delete from the desktop.


Are you having any additional problems at this point? If so, please let me know. Otherwise feel free to enjoy use of your repaired machine :thumbup2:


Useful information!
Below is some more information and useful tools and tips about how to keep your computer safe in the future.



The most common cause of an infected machine is the Trojan Horse, or programs which appear to be legitimate but which contain malicious payloads, or which are simply malicious in and of themselves. No antivirus, firewall, host-based intrusion prevention system (HIPS), or other security software can fully protect you against this kind of attack. The best way to project yourself is not to run email attachments from untrusted sources, and avoid software downloaded from the internet wherever possible. Remember, when you run an application, you are giving that application permission to do to your machine anything you can do the machine, including create, modify, or destroy files or other data. In the Windows (and most other systems' such as Unix) security model, applications don't have privileges, users do.

The second most common cause of infection is out of date software. Leaving your system unpatched leaves holes through which attackers can execute code on your behalf without your consent. This goes for far more than common targets such as Windows and Internet Explorer. Most recent threats target other third party software, such as Adobe's Adobe Reader, Shockwave Player, or Flash Player, or Oracle's Java browser plugins. you can check your system for out of date software manually, or by using automated tools such as Secunia's Personal Software Inspector. This goes doubly for security applications such as antivirus and other antimalware products based on definition lists, where out of date lists mean no detection of newer malware.

Finally, occasionally you will be forced to run some potentially infected binary, or attackers will use a hole which is unpatched by software vendors, so a last line of defense is needed. That means turning on a firewall (Windows Firewall included with Windows XP SP2 or later is fine) and leaving it on, and using and keeping up to date an antivirus solution such as Norton AntiVirus. Antiviral solutions don't even have to cost money; for instance Microsoft Secuity Essentials provides perfectly acceptable protection for free. If for some reason you don't like MSE, there are other free products available as well:
  • Avast (home use only)
  • Avira (shows nag screen to purchase full product when updating, home use only)
That should be fine for the majority of users. However, if you absolutely want additional protection, consider one or more of the following products:If you want more information on methods malware use to infect your computer, consider browsing our How did I get infected? topic.

Please respond to this post so I can close the thread unless you have any other questions.


Best of regards, and happy surfing!! :wink:

bloopie

#11 texasmitch14

texasmitch14
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 08 June 2014 - 07:06 PM

 

Logs are looking good, and you should be good to go! :)

That's a huge relief! Thanks again friend :bowdown:

 

 

 

 

It was my pleasure! Normally, I'm much more attentive then I was here with you, but it was really nothing personal...it was just how my life is moving at the moment. I again, apologize for the delays in my responses.

No hard feelings! I really do appreciate the help you volunteers have to offer. I understand about the delays, bleep happens. :lmao:

 

 

 

 

 

Let's do some housekeeping now:

 

Done and done!

 

 

 

Please respond to this post so I can close the thread unless you have any other questions.

Before I take off and vanish in to the interweb- I have a couple quick questions:

 

1. What exactly did MBAM detect? Was it malware but caught early enough to not become harmful/spread?

2. Should I change my passwords? I logged in to my online banking, e-mail and pretty much all my sesnitive information while this occured. (I reguarly change passwords every so often, but as you know it can be a bit of a hastle- if I don't have to or more specifically if they were not at risk I will not bother to.)

 

 

Kindest regards,

Mitch


Edited by texasmitch14, 08 June 2014 - 10:15 PM.


#12 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Instructor
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:01:35 AM

Posted 09 June 2014 - 05:40 PM

Hello again Mitch,

 

That's a huge relief! Thanks again friend :bowdown:

It was my pleasure, and glad I could help! :)

 

==========

 

No hard feelings! I really do appreciate the help you volunteers have to offer. I understand about the delays, bleep happens. :lmao:

Indeed it does, but your appreciation means a lot! :wink:

 

==========

 

1. What exactly did MBAM detect? Was it malware but caught early enough to not become harmful/spread?

Yes, that's pretty much it. It looks like MBAM detected some "malicious code" injected into the Windows Media Player Network Sharing Service dll, and the associated registry location, which were both removed on the first run. Then Combofix removed the now-orphaned .exe associated with it. So basically, it didn't have enough time to download any more malicious code and further infect your system.

 

2. Should I change my passwords?

That's not necessary at this time, but as long as you do it every once in a while, you'll keep one step ahead. :)

 

There are other variants of a similar infection that would be an "infostealer" (see here and here), and that would then certainly constitute a changing of passwords...but if you'll notice in that first link, the CLSID is different from the CLSID that MBAM detected on your system ({ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}), so it's not the same malware variant in your case. :wink:

 

Does this answer your questions more clearly?

 

==========

 

Thanks for all of your prompt replies in this topic, and I again apologize that I did not reciprocate in the same fashion (I'm usually much more attentive, but as you so eloquently put it...bleep happens!). :)

 

Regards,

 

bloopie



#13 texasmitch14

texasmitch14
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 09 June 2014 - 08:04 PM

Hey bloopie,

 

Awesome- yes, everything is answered! :bowdown:

 

Thanks and take care!

 

 

Regards,

Mitch



#14 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Instructor
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:01:35 AM

Posted 12 June 2014 - 05:23 PM

Hi Mitch,

 

It was my pleasure! Stay safe! :)

 

==========

 

Since this issue appears to be resolved, I am closing this topic. If you feel this is not the case, and you need or want to continue with this topic, please send me a PM and I will re-open it for you.

If you have a new issue, please begin a new topic. Everyone else, please begin a new topic. Thank you.

 

bloopie






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users