needhelp51
Posts: 368 +0
Hello,
My old HDD was about to give up the ghost, so I installed a new one. Just finished installing windows, all necessary updates and installed basic applications. New HDD tests fine on Seatools, so I am quite sure it is A1. Problem is, since a few hours, when I type text, it seems to lag, some keys I enter seem ignored or skipped. It's been a little while during setup before I thought about installing AV and firewall. Read in forums, this can be a sign of malware, I would like to make sure my machine is clean.
Here are the logs:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Version de la base de données: v2013.05.12.06
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Admin :: TOSHIBA-29519BD [administrateur]
2013-05-12 21:04:02
mbam-log-2013-05-12 (21-04-02).txt
Type d'examen: Examen rapide
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 200562
Temps écoulé: 7 minute(s), 30 seconde(s)
Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)
Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)
Clé(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)
Valeur(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)
Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)
Dossier(s) détecté(s): 0
(Aucun élément nuisible détecté)
Fichier(s) détecté(s): 0
(Aucun élément nuisible détecté)
(fin)
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.21.2
Run by Admin at 21:11:54 on 2013-05-12
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.2.1036.18.3070.2223 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ================
.
c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
c:\program files\soluto\soluto.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Secunia\PSI\PSIA.exe
C:\Program Files\Soluto\SolutoLauncherService.exe
C:\Program Files\Soluto\SolutoService.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Secunia\PSI\sua.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
uInternet Connection Wizard,ShellNext = hxxp://shoptoshiba.ca/welcome
mWinlogon: Userinit = c:\windows\system32\userinit.exe,c:\program files\soluto\soluto.exe /userinit
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\fichiers communs\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: DriveLetterAccess: {5CA3D70E-1895-11CF-8E15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Programme d'aide de l'Assistant de connexion Windows Live: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\fichiers communs\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe
mRun: [LaunchApp] launchapp
mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
mRun: [NDSTray.exe] NDSTray.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [SmoothView] c:\program files\toshiba\utilitaire de zoom toshiba\SmoothView.exe
mRun: [Toshiba Hotkey Utility] "c:\program files\toshiba\windows utilities\Hotkey.exe" /lang FR
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [Adobe ARM] "c:\program files\fichiers communs\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\fichiers communs\java\java update\jusched.exe"
mRun: [IntelZeroConfig] "c:\program files\intel\wifi\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\fichiers communs\intel\wirelesscommon\iFrmewrk.exe" /tf Intel Wireless Tray
mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\fichie~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\ramasst.lnk - c:\windows\system32\RAMASST.exe
StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1368298732837
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1368300958171
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.13.0.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\fichiers communs\skype\Skype4COM.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\admin\application data\mozilla\firefox\profiles\63496oaa.default\
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
FF - ExtSQL: 2013-05-11 18:49; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2013-1-20 195296]
R0 Soluto;Soluto;c:\windows\system32\drivers\Soluto.sys [2013-5-12 51144]
R1 MpKsl9f3fb429;MpKsl9f3fb429;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6c435f5e-9efa-4b28-8b26-0b60394d1ec2}\MpKsl9f3fb429.sys [2013-5-12 29904]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2013-5-11 54760]
R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2013-4-18 1227800]
R2 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2013-4-18 659992]
R2 SolutoLauncherService;Soluto Launcher Service;c:\program files\soluto\SolutoLauncherService.exe [2013-5-7 166976]
R2 SolutoService;Soluto PCGenome Core Service;c:\program files\soluto\SolutoService.exe [2013-5-7 727616]
R3 cpuz136;cpuz136;\??\c:\windows\temp\cpuz136\cpuz136_x32.sys --> c:\windows\temp\cpuz136\cpuz136_x32.sys [?]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2013-5-12 40776]
R3 NETwLx32; Pilote de carte de la série Intel(R) Wireless WiFi Link 5000 pour Windows XP 32 bits ;c:\windows\system32\drivers\NETwLx32.sys [2013-5-11 6609920]
R3 PSI;PSI;c:\windows\system32\drivers\psi_mf_x86.sys [2013-4-18 16024]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-3-1 161384]
S3 cpudrv;cpudrv;c:\program files\systemrequirementslab\cpudrv.sys [2011-6-2 11336]
S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 SolutoRemoteService;Soluto Remote Service;c:\program files\soluto\SolutoRemoteService.exe [2013-5-7 1395712]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2013-05-13 01:02:53 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2013-05-13 01:02:53 -------- d-----w- c:\documents and settings\admin\application data\Malwarebytes
2013-05-13 01:02:22 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2013-05-13 01:02:19 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-05-13 01:02:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-05-13 00:52:21 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6c435f5e-9efa-4b28-8b26-0b60394d1ec2}\MpKsl9f3fb429.sys
2013-05-13 00:43:20 217088 ----a-w- c:\windows\system32\UCI32A21.dll
2013-05-12 22:54:41 -------- d-----w- c:\program files\Defraggler
2013-05-12 22:48:45 -------- d-----w- c:\documents and settings\admin\application data\OpenOffice.org
2013-05-12 22:45:02 -------- d-----w- c:\program files\OpenOffice.org 3
2013-05-12 21:53:50 -------- d-sh--w- c:\windows\system32\AI_RecycleBin
2013-05-12 21:53:26 51144 ----a-w- c:\windows\system32\drivers\Soluto.sys
2013-05-12 21:53:13 -------- d-----w- c:\program files\Soluto
2013-05-12 21:52:16 -------- d-----w- c:\documents and settings\all users\application data\Soluto
2013-05-12 21:42:52 -------- d-sh--w- c:\documents and settings\admin\IECompatCache
2013-05-12 21:26:58 6906960 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6c435f5e-9efa-4b28-8b26-0b60394d1ec2}\mpengine.dll
2013-05-12 16:03:00 -------- d-----w- c:\program files\mp3DirectCut
2013-05-12 15:58:40 -------- d-----w- c:\program files\Audacity
2013-05-12 15:55:39 -------- d-----w- c:\program files\VideoLAN
2013-05-12 15:54:32 -------- d-----w- c:\documents and settings\admin\local settings\application data\PCHealth
2013-05-12 15:22:02 -------- d-----w- c:\program files\Seagate
2013-05-12 15:13:10 -------- d-----w- C:\97317ce748271ca34c4e3f38a69f021d
2013-05-12 14:52:58 -------- d-----w- c:\program files\CCleaner
2013-05-12 14:51:02 -------- d-----w- C:\Mes Affaires
2013-05-12 14:14:48 6906960 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2013-05-12 13:36:31 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-12 13:36:31 691592 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-05-12 03:07:28 -------- d-----r- c:\program files\Skype
2013-05-12 02:58:09 21504 ----a-w- c:\windows\system32\NicIn32.dll
2013-05-12 02:58:09 20480 ----a-w- c:\windows\system32\NicCo32.dll
2013-05-12 02:58:09 126976 ----a-w- c:\windows\system32\Prounstl.exe
2013-05-12 02:58:08 179200 ----a-w- c:\windows\system32\drivers\e1e5132.sys
2013-05-12 02:58:08 17408 ----a-w- c:\windows\system32\EtCo32.dll
2013-05-12 01:53:31 -------- d-----w- c:\documents and settings\admin\application data\Intel
2013-05-12 01:52:24 675840 ----a-w- c:\windows\system32\NETwLc32.dll
2013-05-12 01:52:24 6609920 ----a-w- c:\windows\system32\drivers\NETwLx32.sys
2013-05-12 01:52:24 2756608 ----a-w- c:\windows\system32\NETwLr32.dll
2013-05-12 01:51:30 -------- d-----w- c:\program files\fichiers communs\Intel
2013-05-12 01:31:57 -------- d-----w- c:\program files\SystemRequirementsLab
2013-05-12 01:23:56 -------- d-----w- c:\documents and settings\admin\local settings\application data\Secunia PSI
2013-05-12 01:22:55 -------- d-----w- c:\program files\Secunia
2013-05-12 00:39:16 -------- d-----w- c:\program files\fichiers communs\Wise Installation Wizard
2013-05-12 00:16:35 14048 ------w- c:\windows\system32\spmsg2.dll
2013-05-11 23:51:41 -------- d-----w- c:\documents and settings\admin\local settings\application data\Sun
2013-05-11 23:18:30 866720 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-05-11 23:18:30 788896 ----a-w- c:\windows\system32\deployJava1.dll
2013-05-11 23:18:30 144896 ----a-w- c:\windows\system32\javacpl.cpl
2013-05-11 23:18:24 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-05-11 23:04:33 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2013-05-11 23:04:29 -------- d-----w- c:\documents and settings\admin\Tracing
2013-05-11 23:03:50 54760 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2013-05-11 23:02:49 -------- d-----w- c:\program files\Microsoft
2013-05-11 23:02:27 -------- d-----w- c:\program files\Windows Live SkyDrive
2013-05-11 23:01:44 4927864 ----a-w- c:\program files\fichiers communs\windows live\.cache\8189230e1ce4e9b\Silverlight.2.0.exe
2013-05-11 22:56:22 -------- d-----w- c:\program files\fichiers communs\Windows Live
2013-05-11 22:47:50 -------- d-----w- c:\windows\system32\XPSViewer
2013-05-11 22:46:54 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2013-05-11 22:46:37 117760 ------w- c:\windows\system32\prntvpt.dll
2013-05-11 22:46:36 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2013-05-11 22:46:36 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2013-05-11 22:46:36 597504 ------w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2013-05-11 22:46:36 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2013-05-11 22:46:36 575488 ------w- c:\windows\system32\xpsshhdr.dll
2013-05-11 22:46:36 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2013-05-11 22:46:36 1676288 ------w- c:\windows\system32\xpssvcs.dll
2013-05-11 22:46:35 -------- d-----w- C:\4996927265dc45c02c01
2013-05-11 22:42:11 -------- d-----w- c:\program files\Windows Media Connect 2
2013-05-11 22:40:22 -------- d-----w- c:\windows\system32\LogFiles
2013-05-11 22:38:37 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2013-05-11 21:58:38 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2013-05-11 21:55:47 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
2013-05-11 21:55:20 954368 -c----w- c:\windows\system32\dllcache\mfc40.dll
2013-05-11 21:55:20 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2013-05-11 21:55:19 978944 -c----w- c:\windows\system32\dllcache\mfc42.dll
2013-05-11 21:54:25 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2013-05-11 21:54:20 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2013-05-11 21:52:43 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2013-05-11 21:50:53 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2013-05-11 21:50:53 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2013-05-11 21:50:27 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2013-05-11 21:50:24 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2013-05-11 21:50:24 286720 -c----w- c:\windows\system32\dllcache\pdh.dll
2013-05-11 21:50:24 111104 -c----w- c:\windows\system32\dllcache\services.exe
2013-05-11 21:50:21 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2013-05-11 21:50:20 35328 -c----w- c:\windows\system32\dllcache\sc.exe
2013-05-11 21:50:17 685568 -c----w- c:\windows\system32\dllcache\advapi32.dll
2013-05-11 21:50:16 736768 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2013-05-11 21:50:15 743424 -c----w- c:\windows\system32\dllcache\ntdll.dll
2013-05-11 21:50:15 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2013-05-11 21:49:55 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2013-05-11 21:47:42 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2013-05-11 21:47:37 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2013-05-11 21:47:05 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2013-05-11 21:43:41 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2013-05-11 21:43:31 354816 -c----w- c:\windows\system32\dllcache\winhttp.dll
2013-05-11 21:41:42 221696 -c----w- c:\windows\system32\dllcache\wordpad.exe
2013-05-11 21:41:05 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2013-05-11 21:34:23 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2013-05-11 21:33:54 590848 -c----w- c:\windows\system32\dllcache\rpcrt4.dll
2013-05-11 21:33:54 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-05-11 21:30:25 275696 ----a-w- c:\windows\system32\mucltui.dll
2013-05-11 21:30:25 18672 ----a-w- c:\windows\system32\mucltui.dll.mui
2013-05-11 21:29:29 -------- d-----w- c:\program files\Microsoft Security Client
2013-05-11 21:27:29 -------- d-sh--w- c:\documents and settings\admin\PrivacIE
2013-05-11 21:26:04 -------- d-sh--w- c:\documents and settings\admin\IETldCache
2013-05-11 21:17:13 522240 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
2013-05-11 21:16:26 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2013-05-11 21:15:59 -------- d-----w- c:\windows\ie8updates
2013-05-11 21:15:27 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2013-05-11 21:15:27 630272 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2013-05-11 21:15:27 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2013-05-11 21:15:27 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2013-05-11 21:15:27 2004992 -c----w- c:\windows\system32\dllcache\iertutil.dll
2013-05-11 21:15:27 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2013-05-11 21:15:27 11111424 -c----w- c:\windows\system32\dllcache\ieframe.dll
2013-05-11 21:12:12 -------- dc-h--w- c:\windows\ie8
2013-05-11 20:56:17 12928 -c----w- c:\windows\system32\dllcache\usb8023x.sys
2013-05-11 20:56:17 12928 -c----w- c:\windows\system32\dllcache\usb8023.sys
2013-05-11 20:55:27 290560 -c----w- c:\windows\system32\dllcache\atmfd.dll
2013-05-11 20:54:24 139784 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2013-05-11 20:53:32 536576 -c----w- c:\windows\system32\dllcache\msado15.dll
2013-05-11 20:51:54 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2013-05-11 20:51:54 3072 ------w- c:\windows\system32\iacenc.dll
2013-05-11 20:30:28 16408 ----a-w- c:\windows\system32\wuapi.dll.mui
2013-05-11 20:19:49 -------- d-----w- c:\windows\system32\fr-fr
2013-05-11 20:19:48 -------- d-----w- c:\windows\system32\fr
2013-05-11 20:19:48 -------- d-----w- c:\windows\l2schemas
2013-05-11 20:19:47 -------- d-----w- c:\windows\system32\bits
2013-05-11 20:17:38 -------- d-----w- c:\windows\ServicePackFiles
2013-05-11 20:14:04 -------- d-----w- c:\windows\network diagnostic
2013-05-11 20:08:54 -------- d-----w- c:\windows\EHome
2013-05-11 20:04:58 685056 ------w- c:\windows\system32\drivers\hsfcxts2.sys
2013-05-11 19:55:13 -------- d-----w- c:\windows\system32\PreInstall
2013-05-11 19:49:24 221184 ----a-w- c:\windows\system32\wmpns.dll
2013-05-11 19:42:50 6528 ----a-w- c:\windows\system32\drivers\Tbiosdrv.sys
2013-05-11 19:42:47 262144 ----a-w- c:\windows\system32\SMBIOS.ocx
2013-05-11 19:42:45 -------- d-----w- c:\windows\TOSHOFER
2013-05-11 19:34:57 -------- d-----w- c:\windows\iehome
2013-05-11 19:34:38 -------- d-----w- c:\program files\Datalode
2013-05-11 19:16:59 91544 ----a-w- c:\program files\mozilla firefox\nssdbm3.dll
2013-05-11 18:56:27 -------- d-sh--w- c:\documents and settings\admin\UserData
2013-04-18 13:55:52 16024 ----a-w- c:\windows\system32\drivers\psi_mf_x86.sys
.
==================== Find3M ====================
.
2013-03-08 08:36:13 293888 ----a-w- c:\windows\system32\winsrv.dll
2013-03-07 15:56:56 2151936 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-07 15:56:56 2030592 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-02 01:57:47 1867392 ----a-w- c:\windows\system32\win32k.sys
2013-03-02 01:55:11 916480 ----a-w- c:\windows\system32\wininet.dll
2013-03-02 01:55:09 43520 ------w- c:\windows\system32\licmgr10.dll
2013-03-02 01:55:09 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-03-02 01:08:47 385024 ------w- c:\windows\system32\html.iec
2013-02-27 07:56:45 2067456 ----a-w- c:\windows\system32\mstscax.dll
.
============= FINISH: 21:12:10,65 ===============
My old HDD was about to give up the ghost, so I installed a new one. Just finished installing windows, all necessary updates and installed basic applications. New HDD tests fine on Seatools, so I am quite sure it is A1. Problem is, since a few hours, when I type text, it seems to lag, some keys I enter seem ignored or skipped. It's been a little while during setup before I thought about installing AV and firewall. Read in forums, this can be a sign of malware, I would like to make sure my machine is clean.
Here are the logs:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Version de la base de données: v2013.05.12.06
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Admin :: TOSHIBA-29519BD [administrateur]
2013-05-12 21:04:02
mbam-log-2013-05-12 (21-04-02).txt
Type d'examen: Examen rapide
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 200562
Temps écoulé: 7 minute(s), 30 seconde(s)
Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)
Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)
Clé(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)
Valeur(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)
Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)
Dossier(s) détecté(s): 0
(Aucun élément nuisible détecté)
Fichier(s) détecté(s): 0
(Aucun élément nuisible détecté)
(fin)
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.21.2
Run by Admin at 21:11:54 on 2013-05-12
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.2.1036.18.3070.2223 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ================
.
c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
c:\program files\soluto\soluto.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Secunia\PSI\PSIA.exe
C:\Program Files\Soluto\SolutoLauncherService.exe
C:\Program Files\Soluto\SolutoService.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Secunia\PSI\sua.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
uInternet Connection Wizard,ShellNext = hxxp://shoptoshiba.ca/welcome
mWinlogon: Userinit = c:\windows\system32\userinit.exe,c:\program files\soluto\soluto.exe /userinit
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\fichiers communs\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: DriveLetterAccess: {5CA3D70E-1895-11CF-8E15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Programme d'aide de l'Assistant de connexion Windows Live: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\fichiers communs\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe
mRun: [LaunchApp] launchapp
mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
mRun: [NDSTray.exe] NDSTray.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [SmoothView] c:\program files\toshiba\utilitaire de zoom toshiba\SmoothView.exe
mRun: [Toshiba Hotkey Utility] "c:\program files\toshiba\windows utilities\Hotkey.exe" /lang FR
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [Adobe ARM] "c:\program files\fichiers communs\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\fichiers communs\java\java update\jusched.exe"
mRun: [IntelZeroConfig] "c:\program files\intel\wifi\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\fichiers communs\intel\wirelesscommon\iFrmewrk.exe" /tf Intel Wireless Tray
mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\fichie~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\ramasst.lnk - c:\windows\system32\RAMASST.exe
StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1368298732837
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1368300958171
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.13.0.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\fichiers communs\skype\Skype4COM.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\admin\application data\mozilla\firefox\profiles\63496oaa.default\
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
FF - ExtSQL: 2013-05-11 18:49; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2013-1-20 195296]
R0 Soluto;Soluto;c:\windows\system32\drivers\Soluto.sys [2013-5-12 51144]
R1 MpKsl9f3fb429;MpKsl9f3fb429;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6c435f5e-9efa-4b28-8b26-0b60394d1ec2}\MpKsl9f3fb429.sys [2013-5-12 29904]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2013-5-11 54760]
R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2013-4-18 1227800]
R2 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2013-4-18 659992]
R2 SolutoLauncherService;Soluto Launcher Service;c:\program files\soluto\SolutoLauncherService.exe [2013-5-7 166976]
R2 SolutoService;Soluto PCGenome Core Service;c:\program files\soluto\SolutoService.exe [2013-5-7 727616]
R3 cpuz136;cpuz136;\??\c:\windows\temp\cpuz136\cpuz136_x32.sys --> c:\windows\temp\cpuz136\cpuz136_x32.sys [?]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2013-5-12 40776]
R3 NETwLx32; Pilote de carte de la série Intel(R) Wireless WiFi Link 5000 pour Windows XP 32 bits ;c:\windows\system32\drivers\NETwLx32.sys [2013-5-11 6609920]
R3 PSI;PSI;c:\windows\system32\drivers\psi_mf_x86.sys [2013-4-18 16024]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-3-1 161384]
S3 cpudrv;cpudrv;c:\program files\systemrequirementslab\cpudrv.sys [2011-6-2 11336]
S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 SolutoRemoteService;Soluto Remote Service;c:\program files\soluto\SolutoRemoteService.exe [2013-5-7 1395712]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2013-05-13 01:02:53 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2013-05-13 01:02:53 -------- d-----w- c:\documents and settings\admin\application data\Malwarebytes
2013-05-13 01:02:22 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2013-05-13 01:02:19 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-05-13 01:02:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-05-13 00:52:21 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6c435f5e-9efa-4b28-8b26-0b60394d1ec2}\MpKsl9f3fb429.sys
2013-05-13 00:43:20 217088 ----a-w- c:\windows\system32\UCI32A21.dll
2013-05-12 22:54:41 -------- d-----w- c:\program files\Defraggler
2013-05-12 22:48:45 -------- d-----w- c:\documents and settings\admin\application data\OpenOffice.org
2013-05-12 22:45:02 -------- d-----w- c:\program files\OpenOffice.org 3
2013-05-12 21:53:50 -------- d-sh--w- c:\windows\system32\AI_RecycleBin
2013-05-12 21:53:26 51144 ----a-w- c:\windows\system32\drivers\Soluto.sys
2013-05-12 21:53:13 -------- d-----w- c:\program files\Soluto
2013-05-12 21:52:16 -------- d-----w- c:\documents and settings\all users\application data\Soluto
2013-05-12 21:42:52 -------- d-sh--w- c:\documents and settings\admin\IECompatCache
2013-05-12 21:26:58 6906960 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6c435f5e-9efa-4b28-8b26-0b60394d1ec2}\mpengine.dll
2013-05-12 16:03:00 -------- d-----w- c:\program files\mp3DirectCut
2013-05-12 15:58:40 -------- d-----w- c:\program files\Audacity
2013-05-12 15:55:39 -------- d-----w- c:\program files\VideoLAN
2013-05-12 15:54:32 -------- d-----w- c:\documents and settings\admin\local settings\application data\PCHealth
2013-05-12 15:22:02 -------- d-----w- c:\program files\Seagate
2013-05-12 15:13:10 -------- d-----w- C:\97317ce748271ca34c4e3f38a69f021d
2013-05-12 14:52:58 -------- d-----w- c:\program files\CCleaner
2013-05-12 14:51:02 -------- d-----w- C:\Mes Affaires
2013-05-12 14:14:48 6906960 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2013-05-12 13:36:31 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-12 13:36:31 691592 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-05-12 03:07:28 -------- d-----r- c:\program files\Skype
2013-05-12 02:58:09 21504 ----a-w- c:\windows\system32\NicIn32.dll
2013-05-12 02:58:09 20480 ----a-w- c:\windows\system32\NicCo32.dll
2013-05-12 02:58:09 126976 ----a-w- c:\windows\system32\Prounstl.exe
2013-05-12 02:58:08 179200 ----a-w- c:\windows\system32\drivers\e1e5132.sys
2013-05-12 02:58:08 17408 ----a-w- c:\windows\system32\EtCo32.dll
2013-05-12 01:53:31 -------- d-----w- c:\documents and settings\admin\application data\Intel
2013-05-12 01:52:24 675840 ----a-w- c:\windows\system32\NETwLc32.dll
2013-05-12 01:52:24 6609920 ----a-w- c:\windows\system32\drivers\NETwLx32.sys
2013-05-12 01:52:24 2756608 ----a-w- c:\windows\system32\NETwLr32.dll
2013-05-12 01:51:30 -------- d-----w- c:\program files\fichiers communs\Intel
2013-05-12 01:31:57 -------- d-----w- c:\program files\SystemRequirementsLab
2013-05-12 01:23:56 -------- d-----w- c:\documents and settings\admin\local settings\application data\Secunia PSI
2013-05-12 01:22:55 -------- d-----w- c:\program files\Secunia
2013-05-12 00:39:16 -------- d-----w- c:\program files\fichiers communs\Wise Installation Wizard
2013-05-12 00:16:35 14048 ------w- c:\windows\system32\spmsg2.dll
2013-05-11 23:51:41 -------- d-----w- c:\documents and settings\admin\local settings\application data\Sun
2013-05-11 23:18:30 866720 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-05-11 23:18:30 788896 ----a-w- c:\windows\system32\deployJava1.dll
2013-05-11 23:18:30 144896 ----a-w- c:\windows\system32\javacpl.cpl
2013-05-11 23:18:24 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-05-11 23:04:33 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2013-05-11 23:04:29 -------- d-----w- c:\documents and settings\admin\Tracing
2013-05-11 23:03:50 54760 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2013-05-11 23:02:49 -------- d-----w- c:\program files\Microsoft
2013-05-11 23:02:27 -------- d-----w- c:\program files\Windows Live SkyDrive
2013-05-11 23:01:44 4927864 ----a-w- c:\program files\fichiers communs\windows live\.cache\8189230e1ce4e9b\Silverlight.2.0.exe
2013-05-11 22:56:22 -------- d-----w- c:\program files\fichiers communs\Windows Live
2013-05-11 22:47:50 -------- d-----w- c:\windows\system32\XPSViewer
2013-05-11 22:46:54 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2013-05-11 22:46:37 117760 ------w- c:\windows\system32\prntvpt.dll
2013-05-11 22:46:36 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2013-05-11 22:46:36 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2013-05-11 22:46:36 597504 ------w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2013-05-11 22:46:36 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2013-05-11 22:46:36 575488 ------w- c:\windows\system32\xpsshhdr.dll
2013-05-11 22:46:36 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2013-05-11 22:46:36 1676288 ------w- c:\windows\system32\xpssvcs.dll
2013-05-11 22:46:35 -------- d-----w- C:\4996927265dc45c02c01
2013-05-11 22:42:11 -------- d-----w- c:\program files\Windows Media Connect 2
2013-05-11 22:40:22 -------- d-----w- c:\windows\system32\LogFiles
2013-05-11 22:38:37 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2013-05-11 21:58:38 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2013-05-11 21:55:47 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
2013-05-11 21:55:20 954368 -c----w- c:\windows\system32\dllcache\mfc40.dll
2013-05-11 21:55:20 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2013-05-11 21:55:19 978944 -c----w- c:\windows\system32\dllcache\mfc42.dll
2013-05-11 21:54:25 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2013-05-11 21:54:20 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2013-05-11 21:52:43 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2013-05-11 21:50:53 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2013-05-11 21:50:53 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2013-05-11 21:50:27 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2013-05-11 21:50:24 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2013-05-11 21:50:24 286720 -c----w- c:\windows\system32\dllcache\pdh.dll
2013-05-11 21:50:24 111104 -c----w- c:\windows\system32\dllcache\services.exe
2013-05-11 21:50:21 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2013-05-11 21:50:20 35328 -c----w- c:\windows\system32\dllcache\sc.exe
2013-05-11 21:50:17 685568 -c----w- c:\windows\system32\dllcache\advapi32.dll
2013-05-11 21:50:16 736768 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2013-05-11 21:50:15 743424 -c----w- c:\windows\system32\dllcache\ntdll.dll
2013-05-11 21:50:15 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2013-05-11 21:49:55 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2013-05-11 21:47:42 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2013-05-11 21:47:37 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2013-05-11 21:47:05 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2013-05-11 21:43:41 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2013-05-11 21:43:31 354816 -c----w- c:\windows\system32\dllcache\winhttp.dll
2013-05-11 21:41:42 221696 -c----w- c:\windows\system32\dllcache\wordpad.exe
2013-05-11 21:41:05 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2013-05-11 21:34:23 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2013-05-11 21:33:54 590848 -c----w- c:\windows\system32\dllcache\rpcrt4.dll
2013-05-11 21:33:54 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-05-11 21:30:25 275696 ----a-w- c:\windows\system32\mucltui.dll
2013-05-11 21:30:25 18672 ----a-w- c:\windows\system32\mucltui.dll.mui
2013-05-11 21:29:29 -------- d-----w- c:\program files\Microsoft Security Client
2013-05-11 21:27:29 -------- d-sh--w- c:\documents and settings\admin\PrivacIE
2013-05-11 21:26:04 -------- d-sh--w- c:\documents and settings\admin\IETldCache
2013-05-11 21:17:13 522240 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
2013-05-11 21:16:26 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2013-05-11 21:15:59 -------- d-----w- c:\windows\ie8updates
2013-05-11 21:15:27 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2013-05-11 21:15:27 630272 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2013-05-11 21:15:27 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2013-05-11 21:15:27 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2013-05-11 21:15:27 2004992 -c----w- c:\windows\system32\dllcache\iertutil.dll
2013-05-11 21:15:27 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2013-05-11 21:15:27 11111424 -c----w- c:\windows\system32\dllcache\ieframe.dll
2013-05-11 21:12:12 -------- dc-h--w- c:\windows\ie8
2013-05-11 20:56:17 12928 -c----w- c:\windows\system32\dllcache\usb8023x.sys
2013-05-11 20:56:17 12928 -c----w- c:\windows\system32\dllcache\usb8023.sys
2013-05-11 20:55:27 290560 -c----w- c:\windows\system32\dllcache\atmfd.dll
2013-05-11 20:54:24 139784 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2013-05-11 20:53:32 536576 -c----w- c:\windows\system32\dllcache\msado15.dll
2013-05-11 20:51:54 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2013-05-11 20:51:54 3072 ------w- c:\windows\system32\iacenc.dll
2013-05-11 20:30:28 16408 ----a-w- c:\windows\system32\wuapi.dll.mui
2013-05-11 20:19:49 -------- d-----w- c:\windows\system32\fr-fr
2013-05-11 20:19:48 -------- d-----w- c:\windows\system32\fr
2013-05-11 20:19:48 -------- d-----w- c:\windows\l2schemas
2013-05-11 20:19:47 -------- d-----w- c:\windows\system32\bits
2013-05-11 20:17:38 -------- d-----w- c:\windows\ServicePackFiles
2013-05-11 20:14:04 -------- d-----w- c:\windows\network diagnostic
2013-05-11 20:08:54 -------- d-----w- c:\windows\EHome
2013-05-11 20:04:58 685056 ------w- c:\windows\system32\drivers\hsfcxts2.sys
2013-05-11 19:55:13 -------- d-----w- c:\windows\system32\PreInstall
2013-05-11 19:49:24 221184 ----a-w- c:\windows\system32\wmpns.dll
2013-05-11 19:42:50 6528 ----a-w- c:\windows\system32\drivers\Tbiosdrv.sys
2013-05-11 19:42:47 262144 ----a-w- c:\windows\system32\SMBIOS.ocx
2013-05-11 19:42:45 -------- d-----w- c:\windows\TOSHOFER
2013-05-11 19:34:57 -------- d-----w- c:\windows\iehome
2013-05-11 19:34:38 -------- d-----w- c:\program files\Datalode
2013-05-11 19:16:59 91544 ----a-w- c:\program files\mozilla firefox\nssdbm3.dll
2013-05-11 18:56:27 -------- d-sh--w- c:\documents and settings\admin\UserData
2013-04-18 13:55:52 16024 ----a-w- c:\windows\system32\drivers\psi_mf_x86.sys
.
==================== Find3M ====================
.
2013-03-08 08:36:13 293888 ----a-w- c:\windows\system32\winsrv.dll
2013-03-07 15:56:56 2151936 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-07 15:56:56 2030592 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-02 01:57:47 1867392 ----a-w- c:\windows\system32\win32k.sys
2013-03-02 01:55:11 916480 ----a-w- c:\windows\system32\wininet.dll
2013-03-02 01:55:09 43520 ------w- c:\windows\system32\licmgr10.dll
2013-03-02 01:55:09 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-03-02 01:08:47 385024 ------w- c:\windows\system32\html.iec
2013-02-27 07:56:45 2067456 ----a-w- c:\windows\system32\mstscax.dll
.
============= FINISH: 21:12:10,65 ===============