Vaibhav Gupta
Posts: 27 +0
BAM Log
--------------------------------------
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.04.29.05
Windows 7 Service Pack 1 x64 NTFS (Safe Mode)
Internet Explorer 10.0.9200.16540
vibs :: VIBS-PC [administrator]
4/29/2013 9:07:04 PM
mbam-log-2013-04-29 (21-07-04).txt
Scan type: Full scan (C:\|D:\|E:\|F:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 645527
Time elapsed: 1 hour(s), 7 minute(s), 6 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 6
D:\MMI\Sygic KEYGEN 2010 FOR V8.16\SygicKG_win.exe (Worm.AutoRun) -> No action taken.
E:\Software\XP Related\Removing windows xp validation activation\amd64\AntiWPA.Dll (PUP.Wpakill) -> No action taken.
E:\Software\XP Related\Removing windows xp validation activation\x86\AntiWPA.Dll (PUP.Wpakill) -> No action taken.
D:\downloads\tetris setup.exe (PUP.AdBundle) -> Quarantined and deleted successfully.
E:\Work Softwares\Altova MapForce Enterprise 2010 12.3\MESMERiZE\keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
E:\Work Softwares\Altova MapForce Enterprise 2010 12.3\MESMERiZE\patch.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
(end)
---------------------------------------------------------------------------------------------------------------------------
DDS Log
--------------------------------------
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.21.2
Run by vibs at 20:36:05 on 2013-04-29
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.5630.3768 [GMT 5.5:30]
.
AV: AVG Internet Security 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG Internet Security 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
FW: AVG Internet Security 2013 *Enabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\My Connection\BackgroundService\ServiceManager.exe
C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
C:\Windows\system32\CISVC.EXE
C:\ProgramData\DatacardService\HWDeviceService64.exe
C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
C:\ProgramData\Reliance Netconnect+\OnlineUpdate\ouc.exe
C:\Windows\SysWOW64\vmnat.exe
C:\Windows\SysWOW64\vmnetdhcp.exe
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spool\drivers\x64\3\E_IATIGGI.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Program Files (x86)\My Connection\BackgroundService\ModemListener.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\My Connection\ModemApplication.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Program Files (x86)\Orbitdownloader\orbitdm.exe
C:\Program Files (x86)\Orbitdownloader\orbitnet.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: Octh Class: {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL
BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: Grab Pro: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: Grab Pro: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll
uRun: [EPSON TX121 Series] C:\Windows\System32\spool\DRIVERS\x64\3\E_IATIGGI.EXE /FU "C:\Windows\TEMP\E_S9D38.tmp" /EF "HKCU"
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [Alcatel Wave ModemListener] C:\Program Files (x86)\My Connection\BackgroundService\ModemListener.exe start
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
mRun: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
mRun: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~3\Office15\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
LSP: %windir%\system32\vsocklib.dll
DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1366989215214
TCP: Interfaces\{E03A5559-97BA-4CD2-986A-47B1C3C013CE} : NameServer = 10.169.30.244 10.170.30.245
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
SSODL: WebCheck - <orphaned>
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
x64-BHO: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL
x64-BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-TB: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\vibs\AppData\Roaming\Mozilla\Firefox\Profiles\f04almya.default\
FF - plugin: C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
FF - plugin: C:\Users\vibs\AppData\Roaming\Mozilla\Firefox\Profiles\f04almya.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-04-21 00:58; wrc@avast.com; C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2013-04-26 18:13; {e001c731-5e37-4538-a5cb-8168736a2360}; C:\Users\vibs\AppData\Roaming\Mozilla\Firefox\Profiles\f04almya.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-4-21 65336]
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-10-15 63328]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2012-9-21 225120]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2012-11-15 111968]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-9-14 40800]
R0 vsock;vSockets Driver;C:\Windows\System32\drivers\vsock.sys [2013-4-23 70296]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-4-21 1025808]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-4-21 377920]
R1 Avgfwfd;AVG network filter service;C:\Windows\System32\drivers\avgfwd6a.sys [2012-9-4 50296]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2012-10-22 154464]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-10-2 185696]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-9-21 200032]
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-5-14 759048]
R2 Alcatel Wave Modem Device Helper;Alcatel Wave Modem Device Helper;C:\Program Files (x86)\My Connection\BackgroundService\ServiceManager.exe -start --> C:\Program Files (x86)\My Connection\BackgroundService\ServiceManager.exe -start [?]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-4-20 203776]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-4-21 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-4-21 80816]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-4-21 45248]
R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2013\avgfws.exe [2012-12-10 1342024]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-15 5814904]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]
R2 HWDeviceService64.exe;HWDeviceService64.exe;C:\ProgramData\DatacardService\HWDeviceService64.exe [2011-3-14 346976]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2010-11-27 398176]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2012-10-11 918680]
R3 huawei_enumerator;huawei_enumerator;C:\Windows\System32\drivers\ew_jubusenum.sys [2013-4-26 86016]
R3 jrdusbser;Mobile Connector Device for Legacy Serial Communication;C:\Windows\System32\drivers\jrdusbser.sys [2013-4-21 120832]
R3 Ph3xIB64;Philips 713x Inbox PCI TV Card;C:\Windows\System32\drivers\Ph3xIB64.sys [2009-6-11 1627520]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-3-1 187392]
S2 Reliance Netconnect. RunOuc;Reliance Netconnect. OUC;C:\Program Files (x86)\Reliance Netconnect+\UpdateDog\ouc.exe [2013-4-26 218624]
S3 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-4-21 178624]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;C:\Windows\System32\drivers\ew_hwusbdev.sys [2013-4-26 117248]
S3 netr7364;RT73 USB Extensible Wireless LAN Card Driver;C:\Windows\System32\drivers\netr7364.sys [2011-10-5 729152]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-10-1 178824]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-4-20 59392]
.
=============== Created Last 30 ================
.
2013-04-26 12:43:59 -------- d-----w- C:\Users\vibs\AppData\Roaming\QuickScan
2013-04-26 12:00:46 -------- d-----w- C:\ProgramData\Reliance Netconnect
2013-04-26 12:00:25 -------- d-----w- C:\ProgramData\Reliance Netconnect+
2013-04-26 11:57:57 -------- d-----w- C:\ProgramData\DatacardService
2013-04-24 13:38:24 866720 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-04-24 13:38:18 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-04-24 03:33:05 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2013-04-24 03:32:42 5073256 ----a-w- C:\Windows\System32\d3dx9_35.dll
2013-04-24 03:32:42 3727720 ----a-w- C:\Windows\SysWow64\d3dx9_35.dll
2013-04-24 03:29:51 -------- d-----w- C:\Program Files (x86)\Sony
2013-04-24 03:29:47 -------- d-----w- C:\ProgramData\Sony Corporation
2013-04-24 02:56:39 -------- d-----w- C:\ProgramData\UDL
2013-04-24 02:55:43 -------- d-----w- C:\Program Files\Epson Software
2013-04-24 02:53:50 -------- d-----w- C:\Program Files (x86)\Epson Software
2013-04-24 02:52:56 -------- d-----w- C:\Users\vibs\AppData\Local\ABBYY
2013-04-24 02:52:11 -------- d-----w- C:\ProgramData\ABBYY
2013-04-24 02:52:11 -------- d-----w- C:\Program Files (x86)\Common Files\ABBYY
2013-04-24 02:52:11 -------- d-----w- C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint
2013-04-24 02:50:22 -------- d-----w- C:\Program Files (x86)\epson
2013-04-23 10:40:04 -------- d-----w- C:\ProgramData\HitmanPro
2013-04-23 10:37:25 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-04-23 10:37:25 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2013-04-23 10:32:50 -------- d-----w- C:\Users\vibs\AppData\Local\Programs
2013-04-23 10:14:31 -------- d-----w- C:\Users\vibs\AppData\Roaming\Malwarebytes
2013-04-23 10:14:14 -------- d-----w- C:\ProgramData\Malwarebytes
2013-04-23 10:14:12 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-04-23 10:14:11 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-04-23 09:07:07 -------- d-----w- C:\Users\vibs\AppData\Local\VMware
2013-04-23 09:06:30 70296 ----a-w- C:\Windows\System32\drivers\vsock.sys
2013-04-23 09:06:30 67224 ----a-w- C:\Windows\System32\vsocklib.dll
2013-04-23 09:06:30 63128 ----a-w- C:\Windows\SysWow64\vsocklib.dll
2013-04-23 09:06:26 67664 ----a-w- C:\Windows\System32\drivers\vmx86.sys
2013-04-23 09:06:25 33360 ----a-w- C:\Windows\System32\drivers\VMkbd.sys
2013-04-23 09:06:24 31824 ----a-w- C:\Windows\System32\drivers\VMparport.sys
2013-04-23 09:05:50 357456 ----a-w- C:\Windows\SysWow64\vmnetdhcp.exe
2013-04-23 09:05:44 436304 ----a-w- C:\Windows\SysWow64\vmnat.exe
2013-04-23 09:05:44 30800 ----a-w- C:\Windows\System32\drivers\vmnetuserif.sys
2013-04-23 09:05:40 933968 ----a-w- C:\Windows\System32\vnetlib64.dll
2013-04-23 09:05:33 52376 ----a-w- C:\Windows\System32\drivers\hcmon.sys
2013-04-23 09:05:08 -------- d-----w- C:\Program Files\Common Files\VMware
2013-04-23 09:04:52 -------- d-----w- C:\Program Files (x86)\VMware
2013-04-23 09:04:52 -------- d-----w- C:\Program Files (x86)\Common Files\VMware
2013-04-22 14:29:40 -------- d-----w- C:\Users\vibs\AppData\Local\ElevatedDiagnostics
2013-04-22 14:17:12 -------- d-----w- C:\ProgramData\eMule
2013-04-22 13:03:49 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server
2013-04-22 13:03:08 -------- d-----w- C:\ProgramData\regid.1991-06.com.microsoft
2013-04-22 13:01:54 -------- d-----w- C:\Program Files\Microsoft SQL Server
2013-04-22 12:57:03 -------- d-----w- C:\Program Files\Microsoft Analysis Services
2013-04-22 12:57:03 -------- d-----w- C:\Program Files (x86)\Microsoft Analysis Services
2013-04-22 12:56:28 -------- d-----w- C:\Users\vibs\AppData\Local\Microsoft Help
2013-04-22 12:40:13 -------- d-----w- C:\Users\vibs\.VirtualBox
2013-04-22 12:39:14 237840 ----a-w- C:\Windows\System32\drivers\VBoxDrv.sys
2013-04-22 12:38:55 120080 ----a-w- C:\Windows\System32\drivers\VBoxUSBMon.sys
2013-04-22 12:38:44 -------- d-----w- C:\Program Files\Oracle
2013-04-22 03:31:10 26520 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe
2013-04-22 01:44:23 -------- d-----w- C:\Users\vibs\AppData\Roaming\AVG2013
2013-04-22 01:40:45 -------- d-----w- C:\Users\vibs\AppData\Roaming\TuneUp Software
2013-04-22 01:40:00 -------- d-----w- C:\ProgramData\AVG2013
2013-04-22 01:38:57 -------- d-----w- C:\Program Files (x86)\AVG
2013-04-21 14:25:48 -------- d-----w- C:\Users\vibs\AppData\Local\Adobe
2013-04-21 13:00:16 -------- d-----w- C:\Users\vibs\AppData\Local\Diagnostics
2013-04-21 07:28:27 -------- d-----w- C:\Windows\Panther
2013-04-21 07:26:27 -------- d-----w- C:\Users\vibs\Tracing
2013-04-21 07:20:54 -------- d-----w- C:\Program Files (x86)\Microsoft
2013-04-21 07:20:36 -------- d-----w- C:\Program Files (x86)\Windows Live SkyDrive
2013-04-21 07:19:59 -------- d-----w- C:\Windows\PCHEALTH
2013-04-21 07:12:37 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2013-04-21 06:40:15 0 ----a-w- C:\Windows\ativpsrm.bin
2013-04-21 04:42:39 -------- d-----w- C:\Program Files (x86)\OpenOffice.org 3
2013-04-21 04:20:19 -------- d-----w- C:\Program Files\Microsoft Games
2013-04-21 04:16:08 -------- d-----w- C:\Users\vibs\AppData\Local\Macromedia
2013-04-21 03:36:37 -------- d-----w- C:\Program Files (x86)\Elaborate Bytes
2013-04-21 03:22:08 605552 ----a-w- C:\Windows\System32\winload.exe
2013-04-21 03:22:08 566208 ----a-w- C:\Windows\System32\winresume.efi
2013-04-21 03:22:08 518672 ----a-w- C:\Windows\System32\winresume.exe
2013-04-21 03:22:07 642944 ----a-w- C:\Windows\System32\winload.efi
2013-04-21 03:22:07 20352 ----a-w- C:\Windows\System32\kdusb.dll
2013-04-21 03:22:07 19328 ----a-w- C:\Windows\System32\kd1394.dll
2013-04-21 03:22:07 17792 ----a-w- C:\Windows\System32\kdcom.dll
2013-04-21 03:22:04 395776 ----a-w- C:\Windows\System32\webio.dll
2013-04-21 03:22:04 314880 ----a-w- C:\Windows\SysWow64\webio.dll
2013-04-21 03:22:02 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2013-04-21 03:20:41 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2013-04-21 03:20:41 331776 ----a-w- C:\Windows\System32\oleacc.dll
2013-04-21 03:20:41 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2013-04-21 03:20:40 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2013-04-21 03:19:40 1732096 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2013-04-21 03:19:40 1367552 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-04-21 03:19:39 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-04-21 03:19:38 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
2013-04-21 03:19:38 1393664 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
2013-04-21 02:38:18 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-04-21 02:27:07 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2013-04-21 02:27:07 46080 ----a-w- C:\Windows\System32\atmlib.dll
2013-04-21 02:27:07 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2013-04-21 02:27:06 367616 ----a-w- C:\Windows\System32\atmfd.dll
2013-04-21 02:27:06 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2013-04-21 02:27:06 100864 ----a-w- C:\Windows\System32\fontsub.dll
2013-04-21 02:23:32 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-04-21 02:23:32 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-04-21 02:23:32 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-04-21 02:23:31 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2013-04-21 02:23:31 5120 ----a-w- C:\Windows\System32\wmi.dll
2013-04-21 02:23:19 691592 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-04-21 02:18:31 9317456 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{48D77485-AF34-4E15-9342-CBF204416DF2}\mpengine.dll
2013-04-21 02:18:26 282744 ------w- C:\Windows\System32\MpSigStub.exe
2013-04-21 02:16:42 1913192 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-04-21 02:16:41 376688 ----a-w- C:\Windows\System32\drivers\netio.sys
2013-04-21 02:16:41 288088 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2013-04-21 02:16:02 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-04-21 02:16:02 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-04-21 02:14:54 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2013-04-21 02:13:59 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2013-04-21 02:12:47 723456 ----a-w- C:\Windows\System32\EncDec.dll
2013-04-21 02:12:47 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2013-04-21 02:12:05 1464320 ----a-w- C:\Windows\System32\crypt32.dll
2013-04-21 02:12:04 1159680 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-04-21 02:12:03 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-04-21 02:12:03 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-04-21 02:12:03 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2013-04-21 02:12:03 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-04-21 02:10:13 956928 ----a-w- C:\Windows\System32\localspl.dll
2013-04-21 02:10:02 634880 ----a-w- C:\Windows\System32\msvcrt.dll
2013-04-21 02:10:01 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll
2013-04-21 02:10:00 59392 ----a-w- C:\Windows\System32\browcli.dll
2013-04-21 02:10:00 41984 ----a-w- C:\Windows\SysWow64\browcli.dll
2013-04-21 02:10:00 136704 ----a-w- C:\Windows\System32\browser.dll
2013-04-21 02:09:45 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2013-04-21 02:08:55 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-04-21 02:08:53 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-04-21 02:08:51 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
2013-04-21 02:08:51 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2013-04-21 02:08:51 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-04-21 02:08:51 112640 ----a-w- C:\Windows\System32\smss.exe
2013-04-21 02:08:42 -------- d-----w- C:\Program Files\Common Files\EPSON
2013-04-21 02:08:39 -------- d-----w- C:\ProgramData\EPSON
2013-04-21 02:06:57 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2013-04-21 02:06:56 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2013-04-21 02:06:16 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2013-04-21 02:05:44 1731920 ----a-w- C:\Windows\System32\ntdll.dll
2013-04-21 02:05:44 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
2013-04-21 02:05:33 77312 ----a-w- C:\Windows\System32\packager.dll
2013-04-21 02:05:32 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2013-04-21 02:01:21 -------- d-----w- C:\Users\vibs\AppData\Local\Mozilla
2013-04-20 19:38:54 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2013-04-20 19:38:48 99840 ----a-w- C:\Windows\System32\wudriver.dll
2013-04-20 19:38:42 36864 ----a-w- C:\Windows\System32\wuapp.exe
2013-04-20 19:38:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2013-04-20 19:32:00 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service
2013-04-20 19:31:24 -------- d-----w- C:\Users\vibs\AppData\Roaming\ProgSense
2013-04-20 19:31:14 -------- d-----w- C:\Users\vibs\AppData\Roaming\GrabPro
2013-04-20 19:31:14 -------- d-----w- C:\downloads
2013-04-20 19:31:11 -------- d-----w- C:\Program Files (x86)\Orbitdownloader
2013-04-20 19:29:36 178624 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-04-20 19:29:33 65336 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-04-20 19:22:51 -------- d--h--w- C:\ProgramData\Common Files
2013-04-20 19:22:51 -------- d-----w- C:\Users\vibs\AppData\Local\MFAData
2013-04-20 19:22:51 -------- d-----w- C:\Users\vibs\AppData\Local\Avg2013
2013-04-20 19:22:51 -------- d-----w- C:\ProgramData\MFAData
2013-04-20 19:22:12 -------- d-----w- C:\Program Files (x86)\VideoLAN
2013-04-20 19:21:49 788896 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-04-20 19:19:16 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-04-20 19:18:45 -------- d-sh--w- C:\Windows\Installer
2013-04-20 19:10:37 120832 ----a-w- C:\Windows\System32\drivers\jrdusbser.sys
2013-04-20 19:10:36 -------- d-----w- C:\Program Files (x86)\My Connection
2013-04-20 18:52:53 -------- d-----w- C:\Windows\System32\SPReview
2013-04-20 18:37:56 2560 ----a-w- C:\Windows\System32\drivers\en-US\rdpwd.sys.mui
2013-04-20 18:37:54 3072 ----a-w- C:\Windows\System32\drivers\en-US\tsusbflt.sys.mui
2013-04-20 18:37:39 6144 ----a-w- C:\Windows\System32\drivers\en-US\IPMIDrv.sys.mui
2013-04-20 18:37:38 4608 ----a-w- C:\Windows\System32\drivers\en-US\kbdclass.sys.mui
2013-04-20 18:28:59 89088 ----a-w- C:\Windows\System32\amstream.dll
2013-04-20 18:26:44 -------- d-----w- C:\Windows\System32\EventProviders
.
==================== Find3M ====================
.
2013-04-21 02:44:34 92160 ----a-w- C:\Windows\System32\SetIEInstalledDate.exe
2013-04-21 02:38:18 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-04-20 18:49:13 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2013-04-20 18:49:12 175616 ----a-w- C:\Windows\System32\msclmd.dll
2013-03-15 13:44:04 131856 ----a-w- C:\Windows\System32\drivers\VBoxNetAdp.sys
2013-03-15 13:43:06 146704 ----a-w- C:\Windows\System32\drivers\VBoxNetFlt.sys
2013-03-15 13:43:04 204048 ----a-w- C:\Windows\System32\VBoxNetFltNobj.dll
2013-03-06 23:33:21 70992 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-03-06 23:33:21 1025808 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-03-06 23:33:20 80816 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-03-06 23:32:51 41664 ----a-w- C:\Windows\avastSS.scr
2013-03-01 03:36:04 3153408 ----a-w- C:\Windows\System32\win32k.sys
2013-02-25 20:57:48 62104 ----a-w- C:\Windows\System32\vmnetbridge.dll
2013-02-25 20:57:48 48792 ----a-w- C:\Windows\System32\vnetinst.dll
2013-02-25 20:57:48 45720 ----a-w- C:\Windows\System32\drivers\vmnetbridge.sys
2013-02-25 20:57:48 24216 ----a-w- C:\Windows\System32\drivers\vmnet.sys
2013-02-25 20:57:48 20120 ----a-w- C:\Windows\System32\drivers\vmnetadapter.sys
2013-02-25 19:29:16 360528 ----a-w- C:\Windows\SysWow64\vmnc.dll
2013-02-15 06:08:40 44032 ----a-w- C:\Windows\System32\tsgqec.dll
2013-02-15 06:06:11 3717632 ----a-w- C:\Windows\System32\mstscax.dll
2013-02-15 06:02:26 158720 ----a-w- C:\Windows\System32\aaclient.dll
2013-02-15 04:37:10 3217408 ----a-w- C:\Windows\SysWow64\mstscax.dll
2013-02-15 04:34:10 131584 ----a-w- C:\Windows\SysWow64\aaclient.dll
2013-02-15 03:25:51 36864 ----a-w- C:\Windows\SysWow64\tsgqec.dll
2013-02-12 04:12:05 19968 ----a-w- C:\Windows\System32\drivers\usb8023.sys
.
============= FINISH: 20:37:05.98 ===============
--------------------------------------
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.04.29.05
Windows 7 Service Pack 1 x64 NTFS (Safe Mode)
Internet Explorer 10.0.9200.16540
vibs :: VIBS-PC [administrator]
4/29/2013 9:07:04 PM
mbam-log-2013-04-29 (21-07-04).txt
Scan type: Full scan (C:\|D:\|E:\|F:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 645527
Time elapsed: 1 hour(s), 7 minute(s), 6 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 6
D:\MMI\Sygic KEYGEN 2010 FOR V8.16\SygicKG_win.exe (Worm.AutoRun) -> No action taken.
E:\Software\XP Related\Removing windows xp validation activation\amd64\AntiWPA.Dll (PUP.Wpakill) -> No action taken.
E:\Software\XP Related\Removing windows xp validation activation\x86\AntiWPA.Dll (PUP.Wpakill) -> No action taken.
D:\downloads\tetris setup.exe (PUP.AdBundle) -> Quarantined and deleted successfully.
E:\Work Softwares\Altova MapForce Enterprise 2010 12.3\MESMERiZE\keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
E:\Work Softwares\Altova MapForce Enterprise 2010 12.3\MESMERiZE\patch.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
(end)
---------------------------------------------------------------------------------------------------------------------------
DDS Log
--------------------------------------
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.21.2
Run by vibs at 20:36:05 on 2013-04-29
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.5630.3768 [GMT 5.5:30]
.
AV: AVG Internet Security 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG Internet Security 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
FW: AVG Internet Security 2013 *Enabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\My Connection\BackgroundService\ServiceManager.exe
C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
C:\Windows\system32\CISVC.EXE
C:\ProgramData\DatacardService\HWDeviceService64.exe
C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
C:\ProgramData\Reliance Netconnect+\OnlineUpdate\ouc.exe
C:\Windows\SysWOW64\vmnat.exe
C:\Windows\SysWOW64\vmnetdhcp.exe
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spool\drivers\x64\3\E_IATIGGI.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Program Files (x86)\My Connection\BackgroundService\ModemListener.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\My Connection\ModemApplication.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Program Files (x86)\Orbitdownloader\orbitdm.exe
C:\Program Files (x86)\Orbitdownloader\orbitnet.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: Octh Class: {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL
BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: Grab Pro: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: Grab Pro: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll
uRun: [EPSON TX121 Series] C:\Windows\System32\spool\DRIVERS\x64\3\E_IATIGGI.EXE /FU "C:\Windows\TEMP\E_S9D38.tmp" /EF "HKCU"
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [Alcatel Wave ModemListener] C:\Program Files (x86)\My Connection\BackgroundService\ModemListener.exe start
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
mRun: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
mRun: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~3\Office15\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
LSP: %windir%\system32\vsocklib.dll
DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1366989215214
TCP: Interfaces\{E03A5559-97BA-4CD2-986A-47B1C3C013CE} : NameServer = 10.169.30.244 10.170.30.245
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
SSODL: WebCheck - <orphaned>
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
x64-BHO: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL
x64-BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-TB: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\vibs\AppData\Roaming\Mozilla\Firefox\Profiles\f04almya.default\
FF - plugin: C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
FF - plugin: C:\Users\vibs\AppData\Roaming\Mozilla\Firefox\Profiles\f04almya.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-04-21 00:58; wrc@avast.com; C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2013-04-26 18:13; {e001c731-5e37-4538-a5cb-8168736a2360}; C:\Users\vibs\AppData\Roaming\Mozilla\Firefox\Profiles\f04almya.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-4-21 65336]
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-10-15 63328]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2012-9-21 225120]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2012-11-15 111968]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-9-14 40800]
R0 vsock;vSockets Driver;C:\Windows\System32\drivers\vsock.sys [2013-4-23 70296]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-4-21 1025808]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-4-21 377920]
R1 Avgfwfd;AVG network filter service;C:\Windows\System32\drivers\avgfwd6a.sys [2012-9-4 50296]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2012-10-22 154464]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-10-2 185696]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-9-21 200032]
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-5-14 759048]
R2 Alcatel Wave Modem Device Helper;Alcatel Wave Modem Device Helper;C:\Program Files (x86)\My Connection\BackgroundService\ServiceManager.exe -start --> C:\Program Files (x86)\My Connection\BackgroundService\ServiceManager.exe -start [?]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-4-20 203776]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-4-21 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-4-21 80816]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-4-21 45248]
R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2013\avgfws.exe [2012-12-10 1342024]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-15 5814904]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]
R2 HWDeviceService64.exe;HWDeviceService64.exe;C:\ProgramData\DatacardService\HWDeviceService64.exe [2011-3-14 346976]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2010-11-27 398176]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2012-10-11 918680]
R3 huawei_enumerator;huawei_enumerator;C:\Windows\System32\drivers\ew_jubusenum.sys [2013-4-26 86016]
R3 jrdusbser;Mobile Connector Device for Legacy Serial Communication;C:\Windows\System32\drivers\jrdusbser.sys [2013-4-21 120832]
R3 Ph3xIB64;Philips 713x Inbox PCI TV Card;C:\Windows\System32\drivers\Ph3xIB64.sys [2009-6-11 1627520]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-3-1 187392]
S2 Reliance Netconnect. RunOuc;Reliance Netconnect. OUC;C:\Program Files (x86)\Reliance Netconnect+\UpdateDog\ouc.exe [2013-4-26 218624]
S3 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-4-21 178624]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;C:\Windows\System32\drivers\ew_hwusbdev.sys [2013-4-26 117248]
S3 netr7364;RT73 USB Extensible Wireless LAN Card Driver;C:\Windows\System32\drivers\netr7364.sys [2011-10-5 729152]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-10-1 178824]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-4-20 59392]
.
=============== Created Last 30 ================
.
2013-04-26 12:43:59 -------- d-----w- C:\Users\vibs\AppData\Roaming\QuickScan
2013-04-26 12:00:46 -------- d-----w- C:\ProgramData\Reliance Netconnect
2013-04-26 12:00:25 -------- d-----w- C:\ProgramData\Reliance Netconnect+
2013-04-26 11:57:57 -------- d-----w- C:\ProgramData\DatacardService
2013-04-24 13:38:24 866720 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-04-24 13:38:18 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-04-24 03:33:05 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2013-04-24 03:32:42 5073256 ----a-w- C:\Windows\System32\d3dx9_35.dll
2013-04-24 03:32:42 3727720 ----a-w- C:\Windows\SysWow64\d3dx9_35.dll
2013-04-24 03:29:51 -------- d-----w- C:\Program Files (x86)\Sony
2013-04-24 03:29:47 -------- d-----w- C:\ProgramData\Sony Corporation
2013-04-24 02:56:39 -------- d-----w- C:\ProgramData\UDL
2013-04-24 02:55:43 -------- d-----w- C:\Program Files\Epson Software
2013-04-24 02:53:50 -------- d-----w- C:\Program Files (x86)\Epson Software
2013-04-24 02:52:56 -------- d-----w- C:\Users\vibs\AppData\Local\ABBYY
2013-04-24 02:52:11 -------- d-----w- C:\ProgramData\ABBYY
2013-04-24 02:52:11 -------- d-----w- C:\Program Files (x86)\Common Files\ABBYY
2013-04-24 02:52:11 -------- d-----w- C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint
2013-04-24 02:50:22 -------- d-----w- C:\Program Files (x86)\epson
2013-04-23 10:40:04 -------- d-----w- C:\ProgramData\HitmanPro
2013-04-23 10:37:25 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-04-23 10:37:25 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2013-04-23 10:32:50 -------- d-----w- C:\Users\vibs\AppData\Local\Programs
2013-04-23 10:14:31 -------- d-----w- C:\Users\vibs\AppData\Roaming\Malwarebytes
2013-04-23 10:14:14 -------- d-----w- C:\ProgramData\Malwarebytes
2013-04-23 10:14:12 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-04-23 10:14:11 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-04-23 09:07:07 -------- d-----w- C:\Users\vibs\AppData\Local\VMware
2013-04-23 09:06:30 70296 ----a-w- C:\Windows\System32\drivers\vsock.sys
2013-04-23 09:06:30 67224 ----a-w- C:\Windows\System32\vsocklib.dll
2013-04-23 09:06:30 63128 ----a-w- C:\Windows\SysWow64\vsocklib.dll
2013-04-23 09:06:26 67664 ----a-w- C:\Windows\System32\drivers\vmx86.sys
2013-04-23 09:06:25 33360 ----a-w- C:\Windows\System32\drivers\VMkbd.sys
2013-04-23 09:06:24 31824 ----a-w- C:\Windows\System32\drivers\VMparport.sys
2013-04-23 09:05:50 357456 ----a-w- C:\Windows\SysWow64\vmnetdhcp.exe
2013-04-23 09:05:44 436304 ----a-w- C:\Windows\SysWow64\vmnat.exe
2013-04-23 09:05:44 30800 ----a-w- C:\Windows\System32\drivers\vmnetuserif.sys
2013-04-23 09:05:40 933968 ----a-w- C:\Windows\System32\vnetlib64.dll
2013-04-23 09:05:33 52376 ----a-w- C:\Windows\System32\drivers\hcmon.sys
2013-04-23 09:05:08 -------- d-----w- C:\Program Files\Common Files\VMware
2013-04-23 09:04:52 -------- d-----w- C:\Program Files (x86)\VMware
2013-04-23 09:04:52 -------- d-----w- C:\Program Files (x86)\Common Files\VMware
2013-04-22 14:29:40 -------- d-----w- C:\Users\vibs\AppData\Local\ElevatedDiagnostics
2013-04-22 14:17:12 -------- d-----w- C:\ProgramData\eMule
2013-04-22 13:03:49 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server
2013-04-22 13:03:08 -------- d-----w- C:\ProgramData\regid.1991-06.com.microsoft
2013-04-22 13:01:54 -------- d-----w- C:\Program Files\Microsoft SQL Server
2013-04-22 12:57:03 -------- d-----w- C:\Program Files\Microsoft Analysis Services
2013-04-22 12:57:03 -------- d-----w- C:\Program Files (x86)\Microsoft Analysis Services
2013-04-22 12:56:28 -------- d-----w- C:\Users\vibs\AppData\Local\Microsoft Help
2013-04-22 12:40:13 -------- d-----w- C:\Users\vibs\.VirtualBox
2013-04-22 12:39:14 237840 ----a-w- C:\Windows\System32\drivers\VBoxDrv.sys
2013-04-22 12:38:55 120080 ----a-w- C:\Windows\System32\drivers\VBoxUSBMon.sys
2013-04-22 12:38:44 -------- d-----w- C:\Program Files\Oracle
2013-04-22 03:31:10 26520 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe
2013-04-22 01:44:23 -------- d-----w- C:\Users\vibs\AppData\Roaming\AVG2013
2013-04-22 01:40:45 -------- d-----w- C:\Users\vibs\AppData\Roaming\TuneUp Software
2013-04-22 01:40:00 -------- d-----w- C:\ProgramData\AVG2013
2013-04-22 01:38:57 -------- d-----w- C:\Program Files (x86)\AVG
2013-04-21 14:25:48 -------- d-----w- C:\Users\vibs\AppData\Local\Adobe
2013-04-21 13:00:16 -------- d-----w- C:\Users\vibs\AppData\Local\Diagnostics
2013-04-21 07:28:27 -------- d-----w- C:\Windows\Panther
2013-04-21 07:26:27 -------- d-----w- C:\Users\vibs\Tracing
2013-04-21 07:20:54 -------- d-----w- C:\Program Files (x86)\Microsoft
2013-04-21 07:20:36 -------- d-----w- C:\Program Files (x86)\Windows Live SkyDrive
2013-04-21 07:19:59 -------- d-----w- C:\Windows\PCHEALTH
2013-04-21 07:12:37 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2013-04-21 06:40:15 0 ----a-w- C:\Windows\ativpsrm.bin
2013-04-21 04:42:39 -------- d-----w- C:\Program Files (x86)\OpenOffice.org 3
2013-04-21 04:20:19 -------- d-----w- C:\Program Files\Microsoft Games
2013-04-21 04:16:08 -------- d-----w- C:\Users\vibs\AppData\Local\Macromedia
2013-04-21 03:36:37 -------- d-----w- C:\Program Files (x86)\Elaborate Bytes
2013-04-21 03:22:08 605552 ----a-w- C:\Windows\System32\winload.exe
2013-04-21 03:22:08 566208 ----a-w- C:\Windows\System32\winresume.efi
2013-04-21 03:22:08 518672 ----a-w- C:\Windows\System32\winresume.exe
2013-04-21 03:22:07 642944 ----a-w- C:\Windows\System32\winload.efi
2013-04-21 03:22:07 20352 ----a-w- C:\Windows\System32\kdusb.dll
2013-04-21 03:22:07 19328 ----a-w- C:\Windows\System32\kd1394.dll
2013-04-21 03:22:07 17792 ----a-w- C:\Windows\System32\kdcom.dll
2013-04-21 03:22:04 395776 ----a-w- C:\Windows\System32\webio.dll
2013-04-21 03:22:04 314880 ----a-w- C:\Windows\SysWow64\webio.dll
2013-04-21 03:22:02 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2013-04-21 03:20:41 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2013-04-21 03:20:41 331776 ----a-w- C:\Windows\System32\oleacc.dll
2013-04-21 03:20:41 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2013-04-21 03:20:40 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2013-04-21 03:19:40 1732096 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2013-04-21 03:19:40 1367552 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-04-21 03:19:39 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-04-21 03:19:38 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
2013-04-21 03:19:38 1393664 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
2013-04-21 02:38:18 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-04-21 02:27:07 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2013-04-21 02:27:07 46080 ----a-w- C:\Windows\System32\atmlib.dll
2013-04-21 02:27:07 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2013-04-21 02:27:06 367616 ----a-w- C:\Windows\System32\atmfd.dll
2013-04-21 02:27:06 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2013-04-21 02:27:06 100864 ----a-w- C:\Windows\System32\fontsub.dll
2013-04-21 02:23:32 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-04-21 02:23:32 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-04-21 02:23:32 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-04-21 02:23:31 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2013-04-21 02:23:31 5120 ----a-w- C:\Windows\System32\wmi.dll
2013-04-21 02:23:19 691592 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-04-21 02:18:31 9317456 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{48D77485-AF34-4E15-9342-CBF204416DF2}\mpengine.dll
2013-04-21 02:18:26 282744 ------w- C:\Windows\System32\MpSigStub.exe
2013-04-21 02:16:42 1913192 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-04-21 02:16:41 376688 ----a-w- C:\Windows\System32\drivers\netio.sys
2013-04-21 02:16:41 288088 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2013-04-21 02:16:02 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-04-21 02:16:02 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-04-21 02:14:54 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2013-04-21 02:13:59 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2013-04-21 02:12:47 723456 ----a-w- C:\Windows\System32\EncDec.dll
2013-04-21 02:12:47 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2013-04-21 02:12:05 1464320 ----a-w- C:\Windows\System32\crypt32.dll
2013-04-21 02:12:04 1159680 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-04-21 02:12:03 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-04-21 02:12:03 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-04-21 02:12:03 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2013-04-21 02:12:03 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-04-21 02:10:13 956928 ----a-w- C:\Windows\System32\localspl.dll
2013-04-21 02:10:02 634880 ----a-w- C:\Windows\System32\msvcrt.dll
2013-04-21 02:10:01 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll
2013-04-21 02:10:00 59392 ----a-w- C:\Windows\System32\browcli.dll
2013-04-21 02:10:00 41984 ----a-w- C:\Windows\SysWow64\browcli.dll
2013-04-21 02:10:00 136704 ----a-w- C:\Windows\System32\browser.dll
2013-04-21 02:09:45 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2013-04-21 02:08:55 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-04-21 02:08:53 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-04-21 02:08:51 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
2013-04-21 02:08:51 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2013-04-21 02:08:51 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-04-21 02:08:51 112640 ----a-w- C:\Windows\System32\smss.exe
2013-04-21 02:08:42 -------- d-----w- C:\Program Files\Common Files\EPSON
2013-04-21 02:08:39 -------- d-----w- C:\ProgramData\EPSON
2013-04-21 02:06:57 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2013-04-21 02:06:56 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2013-04-21 02:06:16 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2013-04-21 02:05:44 1731920 ----a-w- C:\Windows\System32\ntdll.dll
2013-04-21 02:05:44 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
2013-04-21 02:05:33 77312 ----a-w- C:\Windows\System32\packager.dll
2013-04-21 02:05:32 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2013-04-21 02:01:21 -------- d-----w- C:\Users\vibs\AppData\Local\Mozilla
2013-04-20 19:38:54 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2013-04-20 19:38:48 99840 ----a-w- C:\Windows\System32\wudriver.dll
2013-04-20 19:38:42 36864 ----a-w- C:\Windows\System32\wuapp.exe
2013-04-20 19:38:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2013-04-20 19:32:00 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service
2013-04-20 19:31:24 -------- d-----w- C:\Users\vibs\AppData\Roaming\ProgSense
2013-04-20 19:31:14 -------- d-----w- C:\Users\vibs\AppData\Roaming\GrabPro
2013-04-20 19:31:14 -------- d-----w- C:\downloads
2013-04-20 19:31:11 -------- d-----w- C:\Program Files (x86)\Orbitdownloader
2013-04-20 19:29:36 178624 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-04-20 19:29:33 65336 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-04-20 19:22:51 -------- d--h--w- C:\ProgramData\Common Files
2013-04-20 19:22:51 -------- d-----w- C:\Users\vibs\AppData\Local\MFAData
2013-04-20 19:22:51 -------- d-----w- C:\Users\vibs\AppData\Local\Avg2013
2013-04-20 19:22:51 -------- d-----w- C:\ProgramData\MFAData
2013-04-20 19:22:12 -------- d-----w- C:\Program Files (x86)\VideoLAN
2013-04-20 19:21:49 788896 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-04-20 19:19:16 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-04-20 19:18:45 -------- d-sh--w- C:\Windows\Installer
2013-04-20 19:10:37 120832 ----a-w- C:\Windows\System32\drivers\jrdusbser.sys
2013-04-20 19:10:36 -------- d-----w- C:\Program Files (x86)\My Connection
2013-04-20 18:52:53 -------- d-----w- C:\Windows\System32\SPReview
2013-04-20 18:37:56 2560 ----a-w- C:\Windows\System32\drivers\en-US\rdpwd.sys.mui
2013-04-20 18:37:54 3072 ----a-w- C:\Windows\System32\drivers\en-US\tsusbflt.sys.mui
2013-04-20 18:37:39 6144 ----a-w- C:\Windows\System32\drivers\en-US\IPMIDrv.sys.mui
2013-04-20 18:37:38 4608 ----a-w- C:\Windows\System32\drivers\en-US\kbdclass.sys.mui
2013-04-20 18:28:59 89088 ----a-w- C:\Windows\System32\amstream.dll
2013-04-20 18:26:44 -------- d-----w- C:\Windows\System32\EventProviders
.
==================== Find3M ====================
.
2013-04-21 02:44:34 92160 ----a-w- C:\Windows\System32\SetIEInstalledDate.exe
2013-04-21 02:38:18 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-04-20 18:49:13 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2013-04-20 18:49:12 175616 ----a-w- C:\Windows\System32\msclmd.dll
2013-03-15 13:44:04 131856 ----a-w- C:\Windows\System32\drivers\VBoxNetAdp.sys
2013-03-15 13:43:06 146704 ----a-w- C:\Windows\System32\drivers\VBoxNetFlt.sys
2013-03-15 13:43:04 204048 ----a-w- C:\Windows\System32\VBoxNetFltNobj.dll
2013-03-06 23:33:21 70992 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-03-06 23:33:21 1025808 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-03-06 23:33:20 80816 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-03-06 23:32:51 41664 ----a-w- C:\Windows\avastSS.scr
2013-03-01 03:36:04 3153408 ----a-w- C:\Windows\System32\win32k.sys
2013-02-25 20:57:48 62104 ----a-w- C:\Windows\System32\vmnetbridge.dll
2013-02-25 20:57:48 48792 ----a-w- C:\Windows\System32\vnetinst.dll
2013-02-25 20:57:48 45720 ----a-w- C:\Windows\System32\drivers\vmnetbridge.sys
2013-02-25 20:57:48 24216 ----a-w- C:\Windows\System32\drivers\vmnet.sys
2013-02-25 20:57:48 20120 ----a-w- C:\Windows\System32\drivers\vmnetadapter.sys
2013-02-25 19:29:16 360528 ----a-w- C:\Windows\SysWow64\vmnc.dll
2013-02-15 06:08:40 44032 ----a-w- C:\Windows\System32\tsgqec.dll
2013-02-15 06:06:11 3717632 ----a-w- C:\Windows\System32\mstscax.dll
2013-02-15 06:02:26 158720 ----a-w- C:\Windows\System32\aaclient.dll
2013-02-15 04:37:10 3217408 ----a-w- C:\Windows\SysWow64\mstscax.dll
2013-02-15 04:34:10 131584 ----a-w- C:\Windows\SysWow64\aaclient.dll
2013-02-15 03:25:51 36864 ----a-w- C:\Windows\SysWow64\tsgqec.dll
2013-02-12 04:12:05 19968 ----a-w- C:\Windows\System32\drivers\usb8023.sys
.
============= FINISH: 20:37:05.98 ===============