Hi there! I have this problem that probably similar to most. My gf laptop is so slow (Windows 8) that includes booting up, opening a folder or running application. Not really sure what happen, but below are the logs required (pre-req) for solving the issue: - Thanks in advance:
1. Run antivirus (Kapersky) - no virus or malware found.
2. Run Malawarebytes and the log is below:
3. Run DDS and the results are below:
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17344 BrowserJavaVersion: 10.25.2
Run by Farship at 14:00:44 on 2014-06-30
Microsoft Windows 8.1 6.3.9600.0.1252.1.1033.18.8080.5691 [GMT -6:00]
.
AV: Kaspersky PURE 3.0 *Enabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Kaspersky PURE 3.0 *Enabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky PURE 3.0 *Enabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Classic Shell\ClassicShellService.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\WLANExt.exe
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Samsung\AllShare Framework DMS\1.3.15\AllShareFrameworkManagerDMS.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Samsung\AllShare Framework DMS\1.3.15\AllShareFrameworkDMS.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe
C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
C:\WINDOWS\system32\dashost.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\dwm.exe
C:\Program Files\Classic Shell\ClassicStartMenu.exe
C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
C:\Program Files (x86)\Samsung\Settings\sSettings.exe
C:\Windows\System32\skydrive.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
C:\Windows\System32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Samsung\Quick Starter\Quick Starter.exe
C:\istgah_dic\dic_istgah.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Windows\System32\SettingSyncHost.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = www.google.com
uSearch Bar = Preserve
mWinlogon: Userinit = userinit.exe,
BHO: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
BHO: ExplorerBHO Class: {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
BHO: ClassicIE9BHO Class: {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll
TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
TB: Classic Explorer Bar: {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [Quick Starter] C:\Program Files (x86)\Samsung\Quick Starter\Quick Starter.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\runner_avp.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\Users\Farship\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\istgah Dictionary.lnk - C:\istgah_dic\dic_istgah.exe
mPolicies-Explorer: NoDriveTypeAutoRun = dword:28
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe
IE: {64964764-1101-4bbd-8891-B56B1A53B9B3} - {553891B7-A0D5-4526-BE18-D3CE461D6310}
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - <orphaned>
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.13.0.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{0817CE5A-D0D2-4CEA-BBEA-6689C26D1326} : NameServer = 208.69.150.250,208.69.150.252
TCP: Interfaces\{5C18A4BF-A235-447E-9184-B72500847B6C} : NameServer = 208.69.150.250,208.69.150.252
TCP: Interfaces\{8718928D-CBEB-45EA-A621-800A9249001D} : NameServer = 208.69.150.250,208.69.150.252
TCP: Interfaces\{CD822194-2C6A-40B0-BEC1-07E0404E282E} : NameServer = 208.69.150.250,208.69.150.252
TCP: Interfaces\{F2B57EF4-9386-4316-9160-275B45B8A16C} : NameServer = 208.69.150.250,208.69.150.252
TCP: Interfaces\{F2B57EF4-9386-4316-9160-275B45B8A16C} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{FB4A9047-0F8A-4CC6-97B5-599B653FCF6F}\54873656C63796F62733 : DHCPNameServer = 192.168.15.1
TCP: Interfaces\{FB4A9047-0F8A-4CC6-97B5-599B653FCF6F}\7616475637D27657563747 : NameServer = 208.69.150.250,208.69.150.252
TCP: Interfaces\{FB4A9047-0F8A-4CC6-97B5-599B653FCF6F}\7616475637D27657563747 : DHCPNameServer = 192.168.3.1
TCP: Interfaces\{FB4A9047-0F8A-4CC6-97B5-599B653FCF6F}\B61647562777F6F646 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{FB4A9047-0F8A-4CC6-97B5-599B653FCF6F}\E4F4B4941402C457D6961602932303D213 : DHCPNameServer = 192.168.137.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: ExplorerBHO Class: {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll
x64-BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
x64-BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\OnlineBanking\online_banking_bho.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
x64-BHO: ClassicIE9BHO Class: {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll
x64-TB: Classic Explorer Bar: {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [Samsung Link] "C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe"
x64-Run: [IgfxTray] "C:\WINDOWS\System32\igfxtray.exe"
x64-Run: [HotKeysCmds] "C:\WINDOWS\System32\hkcmd.exe"
x64-Run: [Persistence] "C:\WINDOWS\System32\igfxpers.exe"
x64-Run: [IAStorIcon] "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
x64-mPolicies-Explorer: NoDriveTypeAutoRun = dword:28
x64-mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
x64-mPolicies-System: PromptOnSecureDesktop = dword:0
x64-IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe
x64-IE: {64964764-1101-4bbd-8891-B56B1A53B9B3} - {553891B7-A0D5-4526-BE18-D3CE461D6310}
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Farship\AppData\Roaming\Mozilla\Firefox\Profiles\4qfd6w8x.default\
FF - plugin: C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Veetle\Player\npvlc.dll
FF - plugin: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
FF - plugin: C:\Program Files\Samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll
FF - plugin: C:\Program Files\Samsung\Samsung Link\utils\npSamsungLinkPCPluginUACElevator.dll
FF - plugin: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
FF - plugin: C:\windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\windows\SysWOW64\npmproxy.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
FF - user.js: extensions.astrmndasr.hmpg - true
FF - user.js: extensions.astrmndasr.hmpgUrl - hxxp://astromenda.com/?f=1&a=ast_orinteract_14_42_ie&cd=2XzuyEtN2Y1L1Qzu0CyCzzyDtDzz0C0F0C0CyE0F0ByEyB0DtN0D0Tzu0StCtDtBtCtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StDyB0C0AtAyDyE0CtG0FtC0AyEtGzztDzz0BtG0F0CyEtCtGtDtDtAyE0FyEtCtBtDyC0E0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtBtC0B0F0Bzy0FtG0BtDzztAtGyEtBtDzytGzz0FyEzytG0EtB0C0Czz0B0C0AtD0DyDtA2Q&cr=2082598172&ir=
FF - user.js: extensions.astrmndasr.dfltSrch - true
FF - user.js: extensions.astrmndasr.srchPrvdr - Astromenda
FF - user.js: extensions.astrmndasr.dnsErr - true
FF - user.js: extensions.astrmndasr_i.newTab - true
FF - user.js: extensions.astrmndasr.newTabUrl - hxxp://astromenda.com/?f=2&a=ast_orinteract_14_42_ie&cd=2XzuyEtN2Y1L1Qzu0CyCzzyDtDzz0C0F0C0CyE0F0ByEyB0DtN0D0Tzu0StCtDtBtCtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StDyB0C0AtAyDyE0CtG0FtC0AyEtGzztDzz0BtG0F0CyEtCtGtDtDtAyE0FyEtCtBtDyC0E0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtBtC0B0F0Bzy0FtG0BtDzztAtGyEtBtDzytGzz0FyEzytG0EtB0C0Czz0B0C0AtD0DyDtA2Q&cr=2082598172&ir=
FF - user.js: extensions.astrmndasr.tlbrSrchUrl - hxxp://astromenda.com/?f=3&a=ast_orinteract_14_42_ie&cd=2XzuyEtN2Y1L1Qzu0CyCzzyDtDzz0C0F0C0CyE0F0ByEyB0DtN0D0Tzu0StCtDtBtCtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StDyB0C0AtAyDyE0CtG0FtC0AyEtGzztDzz0BtG0F0CyEtCtGtDtDtAyE0FyEtCtBtDyC0E0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtBtC0B0F0Bzy0FtG0BtDzztAtGyEtBtDzytGzz0FyEzytG0EtB0C0Czz0B0C0AtD0DyDtA2Q&cr=2082598172&ir=&q=
FF - user.js: extensions.astrmndasr.id - C68508CFCC4FB47D
FF - user.js: extensions.astrmndasr.instlDay - 16360
FF - user.js: extensions.astrmndasr.vrsn -
FF - user.js: extensions.astrmndasr.vrsni -
FF - user.js: extensions.astrmndasr_i.vrsnTs - 22:3:1
FF - user.js: extensions.astrmndasr.prtnrId - WSE_Astromenda
FF - user.js: extensions.astrmndasr.prdct - astrmndasr
FF - user.js: extensions.astrmndasr.aflt - ast_orinteract_14_42_ie
FF - user.js: extensions.astrmndasr_i.smplGrp - none
FF - user.js: extensions.astrmndasr.tlbrId -
FF - user.js: extensions.astrmndasr.instlRef - 142905_b
FF - user.js: extensions.astrmndasr.dfltLng -
FF - user.js: extensions.astrmndasr.appId - {9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}
FF - user.js: extensions.astrmndasr.excTlbr - false
FF - user.js: extensions.astrmndasr.cr - 2082598172
FF - user.js: extensions.astrmndasr.cd - 2XzuyEtN2Y1L1Qzu0CyCzzyDtDzz0C0F0C0CyE0F0ByEyB0DtN0D0Tzu0StCtDtBtCtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StDyB0C0AtAyDyE0CtG0FtC0AyEtGzztDzz0BtG0F0CyEtCtGtDtDtAyE0FyEtCtBtDyC0E0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtBtC0B0F0Bzy0FtG0BtDzztAtGyEtBtDzytGzz0FyEzytG0EtB0C0Czz0B0C0AtD0DyDtA2Q
FF - user.js: extensions.astrmndasr.AL - 4
.
============= SERVICES / DRIVERS ===============
.
R0 CSCrySec;InfoWatch Encrypt Sector Library driver;C:\WINDOWS\System32\drivers\CSCrySec.sys [2013-10-29 98064]
R0 dlkmdldr;dlkmdldr;C:\WINDOWS\System32\drivers\dlkmdldr.sys [2014-9-5 18736]
R0 excsd;ExpressCache Storage Filter Driver;C:\WINDOWS\System32\drivers\excsd.sys [2013-8-20 103248]
R0 iaStorA;iaStorA;C:\WINDOWS\System32\drivers\iaStorA.sys [2013-8-7 644968]
R0 intelpep;Intel(R) Power Engine Plug-in Driver;C:\WINDOWS\System32\drivers\intelpep.sys [2013-12-14 39768]
R0 nvpciflt;nvpciflt;C:\WINDOWS\System32\drivers\nvpciflt.sys [2014-3-10 32544]
R0 Wof;Windows Overlay File System Filter Driver;C:\WINDOWS\System32\drivers\wof.sys [2014-4-18 157016]
R1 ahcache;Application Compatibility Cache;C:\WINDOWS\System32\drivers\ahcache.sys [2013-8-22 76800]
R1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;C:\WINDOWS\System32\drivers\CSVirtualDiskDrv.sys [2013-10-29 67344]
R1 excfs;ExpressCache File System Filter Driver;C:\WINDOWS\System32\drivers\excfs.sys [2013-8-20 23376]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\WINDOWS\System32\drivers\klim6.sys [2012-8-2 30304]
R1 klwfp;klwfp;C:\WINDOWS\System32\drivers\klwfp.sys [2013-10-29 50448]
R1 kneps;kneps;C:\WINDOWS\System32\drivers\kneps.sys [2013-10-29 178448]
R2 AllShare Framework DMS;AllShare Framework DMS;C:\Program Files\Samsung\AllShare Framework DMS\1.3.15\AllShareFrameworkManagerDMS.exe [2013-7-23 404360]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2013-4-11 772064]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe [2013-10-29 356128]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2013-8-26 1137016]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2013-8-26 1157496]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-9-12 135984]
R2 CSObjectsSrv;CryptoStorage control service;C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [2012-12-21 819040]
R2 DisplayLinkService;DisplayLinkManager;C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [2014-7-9 10571056]
R2 Easy Launcher;Easy Launcher;C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [2012-11-30 1591176]
R2 ExpressCache;ExpressCache;C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe [2012-8-17 102224]
R2 Garmin Core Update Service;Garmin Core Update Service;C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [2013-11-8 250712]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-8-7 15720]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-8-27 747520]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2014-3-10 131544]
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [2013-9-18 157128]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2014-3-10 169432]
R2 Samsung Link Service;Samsung Link Service;C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [2013-8-31 605768]
R2 SWUpdateService;SW Update Service;C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [2013-10-21 3018800]
R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2013-4-18 3388144]
R3 AMPPAL;Intel(r) Centrino(r) Wireless Bluetooth(r) + High Speed Virtual Adapter;C:\WINDOWS\System32\drivers\AmpPal.sys [2013-4-11 165344]
R3 BthLEEnum;Bluetooth Low Energy Driver;C:\WINDOWS\System32\drivers\BthLEEnum.sys [2014-4-18 226304]
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\WINDOWS\System32\drivers\btmaux.sys [2013-7-22 140600]
R3 btmhsf;btmhsf;C:\WINDOWS\System32\drivers\btmhsf.sys [2013-9-5 1390904]
R3 dlkmd;dlkmd;C:\WINDOWS\System32\drivers\dlkmd.sys [2014-9-5 435504]
R3 iBtFltCoex;iBtFltCoex;C:\WINDOWS\System32\drivers\iBtFltCoex.sys [2013-4-23 69088]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2014-2-26 169752]
R3 IntcDAud;Intel(R) Display Audio;C:\WINDOWS\System32\drivers\IntcDAud.sys [2013-9-9 449528]
R3 iwdbus;IWD Bus Enumerator;C:\WINDOWS\System32\drivers\iwdbus.sys [2013-9-30 26008]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;C:\WINDOWS\System32\drivers\klkbdflt.sys [2013-10-29 29280]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\WINDOWS\System32\drivers\klmouflt.sys [2013-10-29 29280]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\WINDOWS\System32\drivers\0E826AB4.sys [2014-6-30 129752]
R3 NcbService;Network Connection Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2013-8-22 37768]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [2013-8-22 16384]
R3 NETwNe64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit;C:\WINDOWS\System32\drivers\NETwew00.sys [2013-10-8 3345376]
R3 RadioHIDMini;Radio HID Mini-driver;C:\WINDOWS\System32\drivers\RadioHIDMini.sys [2012-7-30 23408]
R3 RTL8168;Realtek 8168 NT Driver;C:\WINDOWS\System32\drivers\Rt630x64.sys [2014-3-10 827096]
R3 usb3Hub;USB-IF USB 3.0 Hub;C:\WINDOWS\System32\drivers\usb3Hub.sys [2012-11-29 47072]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\drivers\WUDFRd.sys [2014-8-22 227840]
R3 XHCIPort;USB-IF xHCI USB Host Controller;C:\WINDOWS\System32\drivers\xHCIPort.sys [2012-10-9 188896]
S0 klelam;klelam;C:\WINDOWS\System32\drivers\klelam.sys [2013-11-13 29792]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 ADP80XX;ADP80XX;C:\WINDOWS\System32\drivers\adp80xx.sys [2013-8-22 782176]
S3 AppReadiness;App Readiness;C:\WINDOWS\System32\svchost.exe -k AppReadiness [2013-8-22 37768]
S3 AppXSvc;AppX Deployment Service (AppXSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2013-8-22 37768]
S3 bcm;WiMAX Network Adapter;C:\WINDOWS\System32\drivers\drxvi314_64.sys [2014-4-11 363136]
S3 bcmbusctr;WiMAX Bus Driver;C:\WINDOWS\System32\drivers\BcmBusCtr_64.sys [2014-4-11 62464]
S3 bcmfn2;bcmfn2 Service;C:\WINDOWS\System32\drivers\bcmfn2.sys [2013-8-22 17624]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\WINDOWS\System32\drivers\ssudbus.sys [2014-1-22 108800]
S3 DisplayLinkUsbIo_x64;DisplayLinkUsbIo_x64;C:\WINDOWS\System32\drivers\DisplayLinkUsbIo_x64_7.6.56275.0.sys [2014-7-10 46384]
S3 iaLPSSi_GPIO;Intel(R) Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [2013-8-22 24568]
S3 iaLPSSi_I2C;Intel(R) Serial IO I2C Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [2013-8-22 99320]
S3 iaStorAV;Intel(R) SATA RAID Controller Windows;C:\WINDOWS\System32\drivers\iaStorAV.sys [2013-8-22 651248]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\WINDOWS\System32\ieetwcollector.exe [2014-6-13 111616]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\WINDOWS\System32\drivers\intelaud.sys [2013-9-30 39320]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-8-27 828376]
S3 iumsvc;Intel(R) Update Manager;C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-2-28 174368]
S3 lfsvc;Windows Location Framework Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2013-8-22 37768]
S3 LSI_SAS3;LSI_SAS3;C:\WINDOWS\System32\drivers\lsi_sas3.sys [2013-8-22 81760]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2013-4-18 273136]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\WINDOWS\System32\drivers\netaapl64.sys [2013-7-25 23040]
S3 netvsc;netvsc;C:\WINDOWS\System32\drivers\netvsc63.sys [2013-8-22 87040]
S3 ReFS;ReFS;C:\WINDOWS\System32\drivers\refs.sys [2014-4-18 924504]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2013-8-22 37768]
S3 SerCx2;Serial UART Support Library;C:\WINDOWS\System32\drivers\SerCx2.sys [2013-12-14 146776]
S3 smphost;Microsoft Storage Spaces SMP;C:\WINDOWS\System32\svchost.exe -k smphost [2013-8-22 37768]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\WINDOWS\System32\drivers\ssudmdm.sys [2014-1-22 206080]
S3 stornvme;Microsoft Standard NVM Express Driver;C:\WINDOWS\System32\drivers\stornvme.sys [2013-11-23 57176]
S3 UEFI;Microsoft UEFI Driver;C:\WINDOWS\System32\drivers\uefi.sys [2013-8-22 26976]
S3 USBAAPL64;Apple Mobile USB Driver;C:\WINDOWS\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 vmicguestinterface;Hyper-V Guest Service Interface;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2013-8-22 37768]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\System32\drivers\wdcsam64.sys [2008-5-6 14464]
S3 WdNisDrv;Windows Defender Network Inspection System Driver;C:\WINDOWS\System32\drivers\WdNisDrv.sys [2014-5-14 123224]
S3 WdNisSvc;Windows Defender Network Inspection Service;C:\Program Files\Windows Defender\NisSrv.exe [2014-5-14 347880]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;C:\WINDOWS\System32\svchost.exe -k WepHostSvcGroup [2013-8-22 37768]
S3 workfolderssvc;Work Folders;C:\WINDOWS\System32\svchost.exe -k LocalService [2013-8-22 37768]
.
=============== Created Last 30 ================
.
2014-10-18 17:04:20 275968 ----a-w- C:\WINDOWS\System32\generaltel.dll
2014-10-18 17:04:19 678400 ----a-w- C:\WINDOWS\System32\aepdu.dll
2014-10-18 17:04:17 527360 ----a-w- C:\WINDOWS\System32\aeinv.dll
2014-10-18 17:04:14 3117568 ----a-w- C:\WINDOWS\SysWow64\msi.dll
2014-10-18 17:04:14 2779648 ----a-w- C:\WINDOWS\System32\msi.dll
2014-10-18 17:04:12 921600 ----a-w- C:\WINDOWS\System32\MrmCoreR.dll
2014-10-18 17:04:12 626688 ----a-w- C:\WINDOWS\SysWow64\MrmCoreR.dll
2014-10-18 17:04:11 118272 ----a-w- C:\WINDOWS\System32\winbici.dll
2014-10-18 16:49:12 76288 ----a-w- C:\WINDOWS\System32\packager.dll
2014-10-18 16:49:12 68608 ----a-w- C:\WINDOWS\SysWow64\packager.dll
2014-10-18 16:48:33 4183040 ----a-w- C:\WINDOWS\System32\win32k.sys
2014-10-18 16:45:35 590336 ----a-w- C:\WINDOWS\System32\rastls.dll
2014-10-18 16:45:35 514048 ----a-w- C:\WINDOWS\SysWow64\rastls.dll
2014-10-18 04:13:34 1664 ----a-w- C:\WINDOWS\System32\ASOROSet.bin
2014-10-18 04:03:02 -------- d-----w- C:\Users\Farship\AppData\Roaming\ASP
2014-10-18 04:02:53 -------- d-----w- C:\Users\Farship\AppData\Roaming\Systweak
2014-10-18 04:02:49 -------- d-----w- C:\Users\Farship\AppData\Roaming\Windows Essentials Codec Pack
2014-10-18 04:02:49 -------- d-----w- C:\Program Files (x86)\Windows Essentials Codec Pack
2014-10-18 04:02:44 20296 ----a-w- C:\WINDOWS\System32\roboot64.exe
2014-10-04 21:38:11 -------- d-----w- C:\ProgramData\Intel(R) Update Manager
2014-09-21 01:21:59 621056 ----a-w- C:\WINDOWS\System32\comdlg32.dll
2014-09-20 19:14:15 706016 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2014-09-20 19:14:15 105440 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2014-09-20 18:58:32 3231696 ----a-w- C:\Program Files (x86)\Mozilla Firefox\d3dcompiler_46.dll
2014-09-20 04:50:42 299520 ----a-w- C:\WINDOWS\System32\WSDMon.dll
2014-09-20 04:50:42 205824 ----a-w- C:\WINDOWS\System32\tcpmon.dll
2014-09-20 04:50:40 796672 ----a-w- C:\WINDOWS\System32\uDWM.dll
2014-09-20 04:50:40 2374784 ----a-w- C:\WINDOWS\explorer.exe
2014-09-20 04:50:40 2084520 ----a-w- C:\WINDOWS\SysWow64\explorer.exe
2014-09-20 04:50:38 13423104 ----a-w- C:\WINDOWS\System32\twinui.dll
2014-09-20 04:50:37 11818496 ----a-w- C:\WINDOWS\SysWow64\twinui.dll
2014-09-20 04:50:36 2860032 ----a-w- C:\WINDOWS\System32\actxprxy.dll
2014-09-20 04:50:36 1038336 ----a-w- C:\WINDOWS\SysWow64\actxprxy.dll
2014-09-20 04:50:35 68096 ----a-w- C:\WINDOWS\System32\UXInit.dll
2014-09-20 04:50:35 50176 ----a-w- C:\WINDOWS\SysWow64\UXInit.dll
2014-09-20 04:49:51 146752 ----a-w- C:\WINDOWS\System32\drivers\msgpioclx.sys
2014-09-20 04:38:09 97280 ----a-w- C:\WINDOWS\System32\aepic.dll
2014-09-20 04:36:38 1212928 ----a-w- C:\WINDOWS\System32\schedsvc.dll
2014-09-20 04:36:15 875688 ----a-w- C:\WINDOWS\SysWow64\msvcr120_clr0400.dll
2014-09-20 04:36:15 869544 ----a-w- C:\WINDOWS\System32\msvcr120_clr0400.dll
2014-09-06 03:46:26 435504 ----a-w- C:\WINDOWS\System32\drivers\dlkmd.sys
2014-09-06 03:46:26 18736 ----a-w- C:\WINDOWS\System32\drivers\dlkmdldr.sys
2014-09-05 05:32:56 1336624 ----a-w- C:\WINDOWS\System32\gdi32.dll
2014-09-05 05:32:56 1064448 ----a-w- C:\WINDOWS\SysWow64\gdi32.dll
2014-08-25 02:08:56 -------- d-----r- C:\Users\Farship\Music
2014-08-24 05:53:52 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware old
2014-08-23 04:31:01 26419488 ----a-w- C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2014-08-23 04:31:00 25693720 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2014-08-23 04:29:31 710144 ----a-w- C:\WINDOWS\SysWow64\rpcrt4.dll
2014-08-23 04:29:31 1273184 ----a-w- C:\WINDOWS\System32\rpcrt4.dll
2014-08-23 04:25:59 402432 ----a-w- C:\WINDOWS\System32\drivers\mrxsmb.sys
2014-08-23 04:24:57 356352 ----a-w- C:\WINDOWS\System32\msihnd.dll
2014-08-23 04:24:57 281088 ----a-w- C:\WINDOWS\SysWow64\msihnd.dll
2014-08-23 04:24:57 114520 ----a-w- C:\WINDOWS\System32\consent.exe
2014-08-23 04:24:52 623616 ----a-w- C:\WINDOWS\System32\MDMAgent.exe
2014-08-23 04:24:52 418816 ----a-w- C:\WINDOWS\System32\wbem\MDMSettingsProv.dll
2014-08-23 04:24:52 161792 ----a-w- C:\WINDOWS\System32\wbem\MDMAppProv.dll
2014-07-12 04:25:37 1018880 ----a-w- C:\WINDOWS\System32\termsrv.dll
2014-07-12 04:23:58 -------- d-s---w- C:\WINDOWS\System32\CompatTel
2014-07-10 13:28:16 46384 ----a-w- C:\WINDOWS\System32\drivers\DisplayLinkUsbIo_x64_7.6.56275.0.sys
2014-07-10 13:28:08 1017344 ----a-w- C:\WINDOWS\System32\DisplayLinkUsbCo64_7.6.56275.0.dll
2014-07-09 14:52:38 1469744 ----a-w- C:\WINDOWS\System32\dlumd9.dll
2014-07-09 14:52:38 1469744 ----a-w- C:\WINDOWS\System32\dlumd64.dll
2014-07-09 14:52:38 1469744 ----a-w- C:\WINDOWS\System32\dlumd11.dll
2014-07-09 14:52:38 1469744 ----a-w- C:\WINDOWS\System32\dlumd10.dll
2014-07-09 14:52:35 1146672 ----a-w- C:\WINDOWS\SysWow64\dlumd9.dll
2014-07-09 14:52:35 1146672 ----a-w- C:\WINDOWS\SysWow64\dlumd32.dll
2014-07-09 14:52:35 1146672 ----a-w- C:\WINDOWS\SysWow64\dlumd11.dll
2014-07-09 14:52:35 1146672 ----a-w- C:\WINDOWS\SysWow64\dlumd10.dll
2014-07-09 06:08:26 966144 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\tabskb.dll
2014-07-09 06:08:24 563200 ----a-w- C:\WINDOWS\System32\drivers\afd.sys
2014-07-09 06:08:23 735232 ----a-w- C:\WINDOWS\SysWow64\adtschema.dll
2014-07-09 06:08:23 735232 ----a-w- C:\WINDOWS\System32\adtschema.dll
2014-07-09 06:08:23 565576 ----a-w- C:\WINDOWS\System32\drivers\cng.sys
2014-07-09 06:03:25 79872 ----a-w- C:\WINDOWS\System32\WSReset.exe
2014-06-30 19:29:51 129752 ----a-w- C:\WINDOWS\System32\drivers\0E826AB4.sys
2014-06-30 19:29:40 129752 ----a-w- C:\WINDOWS\System32\drivers\40A96A90.sys
2014-06-30 19:29:34 93400 ----a-w- C:\WINDOWS\System32\drivers\mbamchameleon.sys
2014-06-30 19:29:34 64216 ----a-w- C:\WINDOWS\System32\drivers\mwac.sys
2014-06-30 19:29:34 25816 ----a-w- C:\WINDOWS\System32\drivers\mbam.sys
2014-06-30 19:24:55 129752 ----a-w- C:\WINDOWS\System32\drivers\02A966EE.sys
2014-06-30 19:24:48 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-28 01:48:21 -------- d-----r- C:\Users\Farship\Documents
2014-06-14 03:56:46 7173120 ----a-w- C:\WINDOWS\System32\Windows.Data.Pdf.dll
2014-06-14 03:55:32 98816 ----a-w- C:\WINDOWS\SysWow64\drvinst.exe
2014-06-14 03:55:32 57856 ----a-w- C:\WINDOWS\System32\drvcfg.exe
2014-06-14 03:55:32 110592 ----a-w- C:\WINDOWS\System32\drvinst.exe
2014-06-14 03:55:23 1975296 ----a-w- C:\WINDOWS\System32\DWrite.dll
2014-06-14 03:55:23 1345536 ----a-w- C:\WINDOWS\System32\FntCache.dll
2014-06-14 03:55:22 1509888 ----a-w- C:\WINDOWS\SysWow64\DWrite.dll
2014-06-14 03:30:44 55328 ----a-w- C:\WINDOWS\System32\drivers\wpcfltr.sys
2014-06-14 03:30:44 2834944 ----a-w- C:\WINDOWS\System32\wpccpl.dll
2014-06-14 03:29:46 53248 ----a-w- C:\WINDOWS\SysWow64\tsgqec.dll
2014-06-12 04:49:02 18636480 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
.
==================== Find3M ====================
.
2014-09-25 22:32:04 2017280 ----a-w- C:\WINDOWS\SysWow64\inetcpl.cpl
2014-09-25 22:31:02 2108416 ----a-w- C:\WINDOWS\System32\inetcpl.cpl
2014-09-20 19:01:30 2724864 ----a-w- C:\WINDOWS\System32\mshtml.tlb
2014-09-20 19:01:28 48640 ----a-w- C:\WINDOWS\System32\ieetwproxystub.dll
2014-09-20 19:01:28 4096 ----a-w- C:\WINDOWS\System32\ieetwcollectorres.dll
2014-09-20 19:01:28 139264 ----a-w- C:\WINDOWS\System32\ieUnatt.exe
2014-09-20 19:01:28 111616 ----a-w- C:\WINDOWS\System32\ieetwcollector.exe
2014-09-20 19:01:27 66048 ----a-w- C:\WINDOWS\System32\iesetup.dll
2014-09-19 01:40:03 547328 ----a-w- C:\WINDOWS\System32\vbscript.dll
2014-09-19 01:38:27 83968 ----a-w- C:\WINDOWS\System32\MshtmlDac.dll
2014-09-19 01:36:57 5829632 ----a-w- C:\WINDOWS\System32\jscript9.dll
2014-09-19 01:25:12 4201472 ----a-w- C:\WINDOWS\SysWow64\jscript9.dll
2014-09-19 01:25:09 758272 ----a-w- C:\WINDOWS\System32\jscript9diag.dll
2014-09-19 01:02:07 454656 ----a-w- C:\WINDOWS\SysWow64\vbscript.dll
2014-09-19 00:59:40 61952 ----a-w- C:\WINDOWS\SysWow64\MshtmlDac.dll
2014-09-19 00:33:18 2309632 ----a-w- C:\WINDOWS\System32\wininet.dll
2014-09-18 23:59:11 1810944 ----a-w- C:\WINDOWS\SysWow64\wininet.dll
2014-09-08 00:08:35 35328 ----a-w- C:\WINDOWS\System32\wuapp.exe
2014-09-08 00:07:59 137728 ----a-w- C:\WINDOWS\System32\wuwebv.dll
2014-09-08 00:04:52 388608 ----a-w- C:\WINDOWS\System32\WUSettingsProvider.dll
2014-09-08 00:04:20 93696 ----a-w- C:\WINDOWS\System32\wudriver.dll
2014-09-08 00:03:50 1702400 ----a-w- C:\WINDOWS\System32\wucltux.dll
2014-09-07 23:59:31 31232 ----a-w- C:\WINDOWS\SysWow64\wuapp.exe
2014-09-07 23:59:15 123904 ----a-w- C:\WINDOWS\SysWow64\wuwebv.dll
2014-09-07 23:56:51 80896 ----a-w- C:\WINDOWS\SysWow64\wudriver.dll
2014-08-29 01:58:52 109568 ----a-w- C:\WINDOWS\System32\appinfo.dll
2014-08-28 23:56:41 2646016 ----a-w- C:\WINDOWS\System32\authui.dll
2014-08-28 23:47:55 2321920 ----a-w- C:\WINDOWS\SysWow64\authui.dll
2014-08-16 04:08:38 1507648 ----a-w- C:\WINDOWS\System32\propsys.dll
2014-08-16 04:01:48 1710184 ----a-w- C:\WINDOWS\System32\ntdll.dll
2014-08-16 03:58:45 1112512 ----a-w- C:\WINDOWS\System32\KernelBase.dll
2014-08-16 03:57:37 2498880 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2014-08-16 03:57:36 428864 ----a-w- C:\WINDOWS\System32\drivers\FWPKCLNT.SYS
2014-08-16 03:16:37 1205976 ----a-w- C:\WINDOWS\SysWow64\propsys.dll
2014-08-16 03:03:51 1467384 ----a-w- C:\WINDOWS\SysWow64\ntdll.dll
2014-08-16 02:55:32 2407936 ----a-w- C:\WINDOWS\SysWow64\PrintConfig.dll
2014-08-16 01:31:16 838144 ----a-w- C:\WINDOWS\SysWow64\KernelBase.dll
2014-08-16 01:25:28 72704 ----a-w- C:\WINDOWS\System32\JavaScriptCollectionAgent.dll
2014-08-16 01:11:26 597504 ----a-w- C:\WINDOWS\SysWow64\jscript9diag.dll
2014-08-16 01:04:21 359424 ----a-w- C:\WINDOWS\System32\Wldap32.dll
2014-08-16 00:58:45 60416 ----a-w- C:\WINDOWS\SysWow64\JavaScriptCollectionAgent.dll
2014-08-16 00:58:35 287744 ----a-w- C:\WINDOWS\System32\SystemEventsBrokerServer.dll
2014-08-16 00:53:32 118272 ----a-w- C:\WINDOWS\System32\httpprxm.dll
2014-08-16 00:46:38 290816 ----a-w- C:\WINDOWS\System32\ProximityService.dll
2014-08-16 00:45:51 267776 ----a-w- C:\WINDOWS\System32\bisrv.dll
2014-08-16 00:43:38 75776 ----a-w- C:\WINDOWS\System32\adhsvc.dll
2014-08-16 00:43:25 321024 ----a-w- C:\WINDOWS\SysWow64\Wldap32.dll
2014-08-16 00:31:57 286208 ----a-w- C:\WINDOWS\System32\pcsvDevice.dll
2014-08-16 00:31:07 914432 ----a-w- C:\WINDOWS\System32\iphlpsvc.dll
2014-08-16 00:29:54 249344 ----a-w- C:\WINDOWS\System32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-08-16 00:23:10 1106432 ----a-w- C:\WINDOWS\System32\SearchFolder.dll
2014-08-16 00:22:56 717824 ----a-w- C:\WINDOWS\System32\SkyDriveTelemetry.dll
2014-08-16 00:22:06 286208 ----a-w- C:\WINDOWS\System32\SkyDriveShell.dll
2014-08-16 00:19:42 189952 ----a-w- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-08-16 00:18:36 4758528 ----a-w- C:\WINDOWS\System32\SyncEngine.dll
2014-08-16 00:17:51 8757760 ----a-w- C:\WINDOWS\System32\Windows.UI.Search.dll
2014-08-16 00:14:34 265216 ----a-w- C:\WINDOWS\SysWow64\SkyDriveShell.dll
2014-08-16 00:13:50 6649344 ----a-w- C:\WINDOWS\System32\mstscax.dll
2014-08-16 00:13:17 5902848 ----a-w- C:\WINDOWS\SysWow64\Windows.UI.Search.dll
2014-08-16 00:13:14 840192 ----a-w- C:\WINDOWS\SysWow64\SearchFolder.dll
2014-08-16 00:11:08 920064 ----a-w- C:\WINDOWS\System32\WSShared.dll
2014-08-16 00:10:35 1120768 ----a-w- C:\WINDOWS\System32\SkyDrive.exe
2014-08-16 00:08:48 5777408 ----a-w- C:\WINDOWS\SysWow64\mstscax.dll
2014-08-16 00:07:01 756224 ----a-w- C:\WINDOWS\SysWow64\WSShared.dll
2014-07-24 15:28:38 468288 -c--a-w- C:\WINDOWS\System32\drivers\USBHUB3.SYS
2014-07-24 15:28:38 419648 -c--a-w- C:\WINDOWS\System32\drivers\usbhub.sys
2014-07-24 15:28:38 412992 -c--a-w- C:\WINDOWS\System32\drivers\spaceport.sys
2014-07-24 15:28:38 143680 -c--a-w- C:\WINDOWS\System32\drivers\usbccgp.sys
2014-07-24 15:28:35 280384 -c--a-w- C:\WINDOWS\System32\drivers\pci.sys
2014-07-24 15:23:21 1519488 ----a-w- C:\WINDOWS\System32\user32.dll
2014-07-24 15:23:21 125472 ----a-w- C:\WINDOWS\System32\dwmapi.dll
2014-07-24 15:20:37 645592 ----a-w- C:\WINDOWS\System32\SHCore.dll
2014-07-24 15:20:37 263400 ----a-w- C:\WINDOWS\System32\SystemSettingsAdminFlows.exe
2014-07-24 15:16:25 2574208 ----a-w- C:\WINDOWS\System32\WMVDECOD.DLL
2014-07-24 15:16:24 211216 ----a-w- C:\WINDOWS\System32\SndVol.exe
2014-07-24 15:07:53 7424320 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2014-07-24 15:07:52 2009920 ----a-w- C:\WINDOWS\System32\drivers\ntfs.sys
2014-07-24 15:05:56 1660048 ----a-w- C:\WINDOWS\System32\winload.efi
2014-07-24 15:05:56 1519560 ----a-w- C:\WINDOWS\System32\winload.exe
2014-07-24 15:05:56 1488008 ----a-w- C:\WINDOWS\System32\winresume.efi
2014-07-24 15:05:56 1356840 ----a-w- C:\WINDOWS\System32\winresume.exe
2014-07-24 15:03:56 882136 ----a-w- C:\WINDOWS\System32\mfplat.dll
2014-07-24 15:03:55 818624 ----a-w- C:\WINDOWS\System32\mfmp4srcsnk.dll
2014-07-24 15:03:55 233888 ----a-w- C:\WINDOWS\System32\mfps.dll
2014-07-24 15:03:54 2141920 ----a-w- C:\WINDOWS\System32\mfcore.dll
2014-07-24 15:03:53 360480 ----a-w- C:\WINDOWS\System32\mfreadwrite.dll
2014-07-24 15:03:53 205512 ----a-w- C:\WINDOWS\System32\mftranscode.dll
2014-07-24 14:57:08 475968 ----a-w- C:\WINDOWS\System32\drivers\netio.sys
2014-07-24 13:50:07 98048 ----a-w- C:\WINDOWS\SysWow64\dwmapi.dll
2014-07-24 13:48:15 2410976 ----a-w- C:\WINDOWS\SysWow64\WMVDECOD.DLL
2014-07-24 13:48:15 180208 ----a-w- C:\WINDOWS\SysWow64\SndVol.exe
2014-07-24 13:46:50 477200 ----a-w- C:\WINDOWS\SysWow64\SHCore.dll
2014-07-24 13:36:22 707536 ----a-w- C:\WINDOWS\SysWow64\mfplat.dll
2014-07-24 13:36:22 674512 ----a-w- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll
2014-07-24 13:36:20 355800 ----a-w- C:\WINDOWS\SysWow64\mfreadwrite.dll
2014-07-24 13:36:20 2145472 ----a-w- C:\WINDOWS\SysWow64\mfcore.dll
2014-07-24 13:36:20 180720 ----a-w- C:\WINDOWS\SysWow64\mftranscode.dll
2014-07-24 11:51:24 7168 ----a-w- C:\WINDOWS\System32\KBDYAK.DLL
2014-07-24 11:51:22 7168 ----a-w- C:\WINDOWS\System32\KBDTT102.DLL
2014-07-24 11:51:18 8192 ----a-w- C:\WINDOWS\System32\KBDRUM.DLL
.
============= FINISH: 14:03:16.58 ===============
1. Run antivirus (Kapersky) - no virus or malware found.
2. Run Malawarebytes and the log is below:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 6/30/2014
Scan Time: 1:30:00 PM
Logfile: malawarebytes.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.10.30.12
Rootkit Database: v2014.10.22.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Farship
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 327232
Time Elapsed: 9 min, 8 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
www.malwarebytes.org
Scan Date: 6/30/2014
Scan Time: 1:30:00 PM
Logfile: malawarebytes.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.10.30.12
Rootkit Database: v2014.10.22.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Farship
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 327232
Time Elapsed: 9 min, 8 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
3. Run DDS and the results are below:
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17344 BrowserJavaVersion: 10.25.2
Run by Farship at 14:00:44 on 2014-06-30
Microsoft Windows 8.1 6.3.9600.0.1252.1.1033.18.8080.5691 [GMT -6:00]
.
AV: Kaspersky PURE 3.0 *Enabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Kaspersky PURE 3.0 *Enabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky PURE 3.0 *Enabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Classic Shell\ClassicShellService.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\WLANExt.exe
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Samsung\AllShare Framework DMS\1.3.15\AllShareFrameworkManagerDMS.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Samsung\AllShare Framework DMS\1.3.15\AllShareFrameworkDMS.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe
C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
C:\WINDOWS\system32\dashost.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\dwm.exe
C:\Program Files\Classic Shell\ClassicStartMenu.exe
C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
C:\Program Files (x86)\Samsung\Settings\sSettings.exe
C:\Windows\System32\skydrive.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
C:\Windows\System32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Samsung\Quick Starter\Quick Starter.exe
C:\istgah_dic\dic_istgah.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Windows\System32\SettingSyncHost.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = www.google.com
uSearch Bar = Preserve
mWinlogon: Userinit = userinit.exe,
BHO: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
BHO: ExplorerBHO Class: {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
BHO: ClassicIE9BHO Class: {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll
TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
TB: Classic Explorer Bar: {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [Quick Starter] C:\Program Files (x86)\Samsung\Quick Starter\Quick Starter.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\runner_avp.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\Users\Farship\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\istgah Dictionary.lnk - C:\istgah_dic\dic_istgah.exe
mPolicies-Explorer: NoDriveTypeAutoRun = dword:28
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe
IE: {64964764-1101-4bbd-8891-B56B1A53B9B3} - {553891B7-A0D5-4526-BE18-D3CE461D6310}
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - <orphaned>
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.13.0.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{0817CE5A-D0D2-4CEA-BBEA-6689C26D1326} : NameServer = 208.69.150.250,208.69.150.252
TCP: Interfaces\{5C18A4BF-A235-447E-9184-B72500847B6C} : NameServer = 208.69.150.250,208.69.150.252
TCP: Interfaces\{8718928D-CBEB-45EA-A621-800A9249001D} : NameServer = 208.69.150.250,208.69.150.252
TCP: Interfaces\{CD822194-2C6A-40B0-BEC1-07E0404E282E} : NameServer = 208.69.150.250,208.69.150.252
TCP: Interfaces\{F2B57EF4-9386-4316-9160-275B45B8A16C} : NameServer = 208.69.150.250,208.69.150.252
TCP: Interfaces\{F2B57EF4-9386-4316-9160-275B45B8A16C} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{FB4A9047-0F8A-4CC6-97B5-599B653FCF6F}\54873656C63796F62733 : DHCPNameServer = 192.168.15.1
TCP: Interfaces\{FB4A9047-0F8A-4CC6-97B5-599B653FCF6F}\7616475637D27657563747 : NameServer = 208.69.150.250,208.69.150.252
TCP: Interfaces\{FB4A9047-0F8A-4CC6-97B5-599B653FCF6F}\7616475637D27657563747 : DHCPNameServer = 192.168.3.1
TCP: Interfaces\{FB4A9047-0F8A-4CC6-97B5-599B653FCF6F}\B61647562777F6F646 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{FB4A9047-0F8A-4CC6-97B5-599B653FCF6F}\E4F4B4941402C457D6961602932303D213 : DHCPNameServer = 192.168.137.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: ExplorerBHO Class: {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll
x64-BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
x64-BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\OnlineBanking\online_banking_bho.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
x64-BHO: ClassicIE9BHO Class: {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll
x64-TB: Classic Explorer Bar: {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [Samsung Link] "C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe"
x64-Run: [IgfxTray] "C:\WINDOWS\System32\igfxtray.exe"
x64-Run: [HotKeysCmds] "C:\WINDOWS\System32\hkcmd.exe"
x64-Run: [Persistence] "C:\WINDOWS\System32\igfxpers.exe"
x64-Run: [IAStorIcon] "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
x64-mPolicies-Explorer: NoDriveTypeAutoRun = dword:28
x64-mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
x64-mPolicies-System: PromptOnSecureDesktop = dword:0
x64-IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe
x64-IE: {64964764-1101-4bbd-8891-B56B1A53B9B3} - {553891B7-A0D5-4526-BE18-D3CE461D6310}
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
x64-mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Farship\AppData\Roaming\Mozilla\Firefox\Profiles\4qfd6w8x.default\
FF - plugin: C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Veetle\Player\npvlc.dll
FF - plugin: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
FF - plugin: C:\Program Files\Samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll
FF - plugin: C:\Program Files\Samsung\Samsung Link\utils\npSamsungLinkPCPluginUACElevator.dll
FF - plugin: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
FF - plugin: C:\windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\windows\SysWOW64\npmproxy.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
FF - user.js: extensions.astrmndasr.hmpg - true
FF - user.js: extensions.astrmndasr.hmpgUrl - hxxp://astromenda.com/?f=1&a=ast_orinteract_14_42_ie&cd=2XzuyEtN2Y1L1Qzu0CyCzzyDtDzz0C0F0C0CyE0F0ByEyB0DtN0D0Tzu0StCtDtBtCtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StDyB0C0AtAyDyE0CtG0FtC0AyEtGzztDzz0BtG0F0CyEtCtGtDtDtAyE0FyEtCtBtDyC0E0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtBtC0B0F0Bzy0FtG0BtDzztAtGyEtBtDzytGzz0FyEzytG0EtB0C0Czz0B0C0AtD0DyDtA2Q&cr=2082598172&ir=
FF - user.js: extensions.astrmndasr.dfltSrch - true
FF - user.js: extensions.astrmndasr.srchPrvdr - Astromenda
FF - user.js: extensions.astrmndasr.dnsErr - true
FF - user.js: extensions.astrmndasr_i.newTab - true
FF - user.js: extensions.astrmndasr.newTabUrl - hxxp://astromenda.com/?f=2&a=ast_orinteract_14_42_ie&cd=2XzuyEtN2Y1L1Qzu0CyCzzyDtDzz0C0F0C0CyE0F0ByEyB0DtN0D0Tzu0StCtDtBtCtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StDyB0C0AtAyDyE0CtG0FtC0AyEtGzztDzz0BtG0F0CyEtCtGtDtDtAyE0FyEtCtBtDyC0E0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtBtC0B0F0Bzy0FtG0BtDzztAtGyEtBtDzytGzz0FyEzytG0EtB0C0Czz0B0C0AtD0DyDtA2Q&cr=2082598172&ir=
FF - user.js: extensions.astrmndasr.tlbrSrchUrl - hxxp://astromenda.com/?f=3&a=ast_orinteract_14_42_ie&cd=2XzuyEtN2Y1L1Qzu0CyCzzyDtDzz0C0F0C0CyE0F0ByEyB0DtN0D0Tzu0StCtDtBtCtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StDyB0C0AtAyDyE0CtG0FtC0AyEtGzztDzz0BtG0F0CyEtCtGtDtDtAyE0FyEtCtBtDyC0E0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtBtC0B0F0Bzy0FtG0BtDzztAtGyEtBtDzytGzz0FyEzytG0EtB0C0Czz0B0C0AtD0DyDtA2Q&cr=2082598172&ir=&q=
FF - user.js: extensions.astrmndasr.id - C68508CFCC4FB47D
FF - user.js: extensions.astrmndasr.instlDay - 16360
FF - user.js: extensions.astrmndasr.vrsn -
FF - user.js: extensions.astrmndasr.vrsni -
FF - user.js: extensions.astrmndasr_i.vrsnTs - 22:3:1
FF - user.js: extensions.astrmndasr.prtnrId - WSE_Astromenda
FF - user.js: extensions.astrmndasr.prdct - astrmndasr
FF - user.js: extensions.astrmndasr.aflt - ast_orinteract_14_42_ie
FF - user.js: extensions.astrmndasr_i.smplGrp - none
FF - user.js: extensions.astrmndasr.tlbrId -
FF - user.js: extensions.astrmndasr.instlRef - 142905_b
FF - user.js: extensions.astrmndasr.dfltLng -
FF - user.js: extensions.astrmndasr.appId - {9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}
FF - user.js: extensions.astrmndasr.excTlbr - false
FF - user.js: extensions.astrmndasr.cr - 2082598172
FF - user.js: extensions.astrmndasr.cd - 2XzuyEtN2Y1L1Qzu0CyCzzyDtDzz0C0F0C0CyE0F0ByEyB0DtN0D0Tzu0StCtDtBtCtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StDyB0C0AtAyDyE0CtG0FtC0AyEtGzztDzz0BtG0F0CyEtCtGtDtDtAyE0FyEtCtBtDyC0E0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtBtC0B0F0Bzy0FtG0BtDzztAtGyEtBtDzytGzz0FyEzytG0EtB0C0Czz0B0C0AtD0DyDtA2Q
FF - user.js: extensions.astrmndasr.AL - 4
.
============= SERVICES / DRIVERS ===============
.
R0 CSCrySec;InfoWatch Encrypt Sector Library driver;C:\WINDOWS\System32\drivers\CSCrySec.sys [2013-10-29 98064]
R0 dlkmdldr;dlkmdldr;C:\WINDOWS\System32\drivers\dlkmdldr.sys [2014-9-5 18736]
R0 excsd;ExpressCache Storage Filter Driver;C:\WINDOWS\System32\drivers\excsd.sys [2013-8-20 103248]
R0 iaStorA;iaStorA;C:\WINDOWS\System32\drivers\iaStorA.sys [2013-8-7 644968]
R0 intelpep;Intel(R) Power Engine Plug-in Driver;C:\WINDOWS\System32\drivers\intelpep.sys [2013-12-14 39768]
R0 nvpciflt;nvpciflt;C:\WINDOWS\System32\drivers\nvpciflt.sys [2014-3-10 32544]
R0 Wof;Windows Overlay File System Filter Driver;C:\WINDOWS\System32\drivers\wof.sys [2014-4-18 157016]
R1 ahcache;Application Compatibility Cache;C:\WINDOWS\System32\drivers\ahcache.sys [2013-8-22 76800]
R1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;C:\WINDOWS\System32\drivers\CSVirtualDiskDrv.sys [2013-10-29 67344]
R1 excfs;ExpressCache File System Filter Driver;C:\WINDOWS\System32\drivers\excfs.sys [2013-8-20 23376]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\WINDOWS\System32\drivers\klim6.sys [2012-8-2 30304]
R1 klwfp;klwfp;C:\WINDOWS\System32\drivers\klwfp.sys [2013-10-29 50448]
R1 kneps;kneps;C:\WINDOWS\System32\drivers\kneps.sys [2013-10-29 178448]
R2 AllShare Framework DMS;AllShare Framework DMS;C:\Program Files\Samsung\AllShare Framework DMS\1.3.15\AllShareFrameworkManagerDMS.exe [2013-7-23 404360]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2013-4-11 772064]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe [2013-10-29 356128]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2013-8-26 1137016]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2013-8-26 1157496]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-9-12 135984]
R2 CSObjectsSrv;CryptoStorage control service;C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [2012-12-21 819040]
R2 DisplayLinkService;DisplayLinkManager;C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [2014-7-9 10571056]
R2 Easy Launcher;Easy Launcher;C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [2012-11-30 1591176]
R2 ExpressCache;ExpressCache;C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe [2012-8-17 102224]
R2 Garmin Core Update Service;Garmin Core Update Service;C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [2013-11-8 250712]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-8-7 15720]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-8-27 747520]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2014-3-10 131544]
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [2013-9-18 157128]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2014-3-10 169432]
R2 Samsung Link Service;Samsung Link Service;C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [2013-8-31 605768]
R2 SWUpdateService;SW Update Service;C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [2013-10-21 3018800]
R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2013-4-18 3388144]
R3 AMPPAL;Intel(r) Centrino(r) Wireless Bluetooth(r) + High Speed Virtual Adapter;C:\WINDOWS\System32\drivers\AmpPal.sys [2013-4-11 165344]
R3 BthLEEnum;Bluetooth Low Energy Driver;C:\WINDOWS\System32\drivers\BthLEEnum.sys [2014-4-18 226304]
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\WINDOWS\System32\drivers\btmaux.sys [2013-7-22 140600]
R3 btmhsf;btmhsf;C:\WINDOWS\System32\drivers\btmhsf.sys [2013-9-5 1390904]
R3 dlkmd;dlkmd;C:\WINDOWS\System32\drivers\dlkmd.sys [2014-9-5 435504]
R3 iBtFltCoex;iBtFltCoex;C:\WINDOWS\System32\drivers\iBtFltCoex.sys [2013-4-23 69088]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2014-2-26 169752]
R3 IntcDAud;Intel(R) Display Audio;C:\WINDOWS\System32\drivers\IntcDAud.sys [2013-9-9 449528]
R3 iwdbus;IWD Bus Enumerator;C:\WINDOWS\System32\drivers\iwdbus.sys [2013-9-30 26008]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;C:\WINDOWS\System32\drivers\klkbdflt.sys [2013-10-29 29280]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\WINDOWS\System32\drivers\klmouflt.sys [2013-10-29 29280]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\WINDOWS\System32\drivers\0E826AB4.sys [2014-6-30 129752]
R3 NcbService;Network Connection Broker;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2013-8-22 37768]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [2013-8-22 16384]
R3 NETwNe64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit;C:\WINDOWS\System32\drivers\NETwew00.sys [2013-10-8 3345376]
R3 RadioHIDMini;Radio HID Mini-driver;C:\WINDOWS\System32\drivers\RadioHIDMini.sys [2012-7-30 23408]
R3 RTL8168;Realtek 8168 NT Driver;C:\WINDOWS\System32\drivers\Rt630x64.sys [2014-3-10 827096]
R3 usb3Hub;USB-IF USB 3.0 Hub;C:\WINDOWS\System32\drivers\usb3Hub.sys [2012-11-29 47072]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\drivers\WUDFRd.sys [2014-8-22 227840]
R3 XHCIPort;USB-IF xHCI USB Host Controller;C:\WINDOWS\System32\drivers\xHCIPort.sys [2012-10-9 188896]
S0 klelam;klelam;C:\WINDOWS\System32\drivers\klelam.sys [2013-11-13 29792]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 ADP80XX;ADP80XX;C:\WINDOWS\System32\drivers\adp80xx.sys [2013-8-22 782176]
S3 AppReadiness;App Readiness;C:\WINDOWS\System32\svchost.exe -k AppReadiness [2013-8-22 37768]
S3 AppXSvc;AppX Deployment Service (AppXSVC);C:\WINDOWS\System32\svchost.exe -k wsappx [2013-8-22 37768]
S3 bcm;WiMAX Network Adapter;C:\WINDOWS\System32\drivers\drxvi314_64.sys [2014-4-11 363136]
S3 bcmbusctr;WiMAX Bus Driver;C:\WINDOWS\System32\drivers\BcmBusCtr_64.sys [2014-4-11 62464]
S3 bcmfn2;bcmfn2 Service;C:\WINDOWS\System32\drivers\bcmfn2.sys [2013-8-22 17624]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\WINDOWS\System32\drivers\ssudbus.sys [2014-1-22 108800]
S3 DisplayLinkUsbIo_x64;DisplayLinkUsbIo_x64;C:\WINDOWS\System32\drivers\DisplayLinkUsbIo_x64_7.6.56275.0.sys [2014-7-10 46384]
S3 iaLPSSi_GPIO;Intel(R) Serial IO GPIO Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [2013-8-22 24568]
S3 iaLPSSi_I2C;Intel(R) Serial IO I2C Controller Driver;C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [2013-8-22 99320]
S3 iaStorAV;Intel(R) SATA RAID Controller Windows;C:\WINDOWS\System32\drivers\iaStorAV.sys [2013-8-22 651248]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\WINDOWS\System32\ieetwcollector.exe [2014-6-13 111616]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\WINDOWS\System32\drivers\intelaud.sys [2013-9-30 39320]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-8-27 828376]
S3 iumsvc;Intel(R) Update Manager;C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-2-28 174368]
S3 lfsvc;Windows Location Framework Service;C:\WINDOWS\System32\svchost.exe -k netsvcs [2013-8-22 37768]
S3 LSI_SAS3;LSI_SAS3;C:\WINDOWS\System32\drivers\lsi_sas3.sys [2013-8-22 81760]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2013-4-18 273136]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\WINDOWS\System32\drivers\netaapl64.sys [2013-7-25 23040]
S3 netvsc;netvsc;C:\WINDOWS\System32\drivers\netvsc63.sys [2013-8-22 87040]
S3 ReFS;ReFS;C:\WINDOWS\System32\drivers\refs.sys [2014-4-18 924504]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2013-8-22 37768]
S3 SerCx2;Serial UART Support Library;C:\WINDOWS\System32\drivers\SerCx2.sys [2013-12-14 146776]
S3 smphost;Microsoft Storage Spaces SMP;C:\WINDOWS\System32\svchost.exe -k smphost [2013-8-22 37768]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\WINDOWS\System32\drivers\ssudmdm.sys [2014-1-22 206080]
S3 stornvme;Microsoft Standard NVM Express Driver;C:\WINDOWS\System32\drivers\stornvme.sys [2013-11-23 57176]
S3 UEFI;Microsoft UEFI Driver;C:\WINDOWS\System32\drivers\uefi.sys [2013-8-22 26976]
S3 USBAAPL64;Apple Mobile USB Driver;C:\WINDOWS\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 vmicguestinterface;Hyper-V Guest Service Interface;C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted [2013-8-22 37768]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\System32\drivers\wdcsam64.sys [2008-5-6 14464]
S3 WdNisDrv;Windows Defender Network Inspection System Driver;C:\WINDOWS\System32\drivers\WdNisDrv.sys [2014-5-14 123224]
S3 WdNisSvc;Windows Defender Network Inspection Service;C:\Program Files\Windows Defender\NisSrv.exe [2014-5-14 347880]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;C:\WINDOWS\System32\svchost.exe -k WepHostSvcGroup [2013-8-22 37768]
S3 workfolderssvc;Work Folders;C:\WINDOWS\System32\svchost.exe -k LocalService [2013-8-22 37768]
.
=============== Created Last 30 ================
.
2014-10-18 17:04:20 275968 ----a-w- C:\WINDOWS\System32\generaltel.dll
2014-10-18 17:04:19 678400 ----a-w- C:\WINDOWS\System32\aepdu.dll
2014-10-18 17:04:17 527360 ----a-w- C:\WINDOWS\System32\aeinv.dll
2014-10-18 17:04:14 3117568 ----a-w- C:\WINDOWS\SysWow64\msi.dll
2014-10-18 17:04:14 2779648 ----a-w- C:\WINDOWS\System32\msi.dll
2014-10-18 17:04:12 921600 ----a-w- C:\WINDOWS\System32\MrmCoreR.dll
2014-10-18 17:04:12 626688 ----a-w- C:\WINDOWS\SysWow64\MrmCoreR.dll
2014-10-18 17:04:11 118272 ----a-w- C:\WINDOWS\System32\winbici.dll
2014-10-18 16:49:12 76288 ----a-w- C:\WINDOWS\System32\packager.dll
2014-10-18 16:49:12 68608 ----a-w- C:\WINDOWS\SysWow64\packager.dll
2014-10-18 16:48:33 4183040 ----a-w- C:\WINDOWS\System32\win32k.sys
2014-10-18 16:45:35 590336 ----a-w- C:\WINDOWS\System32\rastls.dll
2014-10-18 16:45:35 514048 ----a-w- C:\WINDOWS\SysWow64\rastls.dll
2014-10-18 04:13:34 1664 ----a-w- C:\WINDOWS\System32\ASOROSet.bin
2014-10-18 04:03:02 -------- d-----w- C:\Users\Farship\AppData\Roaming\ASP
2014-10-18 04:02:53 -------- d-----w- C:\Users\Farship\AppData\Roaming\Systweak
2014-10-18 04:02:49 -------- d-----w- C:\Users\Farship\AppData\Roaming\Windows Essentials Codec Pack
2014-10-18 04:02:49 -------- d-----w- C:\Program Files (x86)\Windows Essentials Codec Pack
2014-10-18 04:02:44 20296 ----a-w- C:\WINDOWS\System32\roboot64.exe
2014-10-04 21:38:11 -------- d-----w- C:\ProgramData\Intel(R) Update Manager
2014-09-21 01:21:59 621056 ----a-w- C:\WINDOWS\System32\comdlg32.dll
2014-09-20 19:14:15 706016 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2014-09-20 19:14:15 105440 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2014-09-20 18:58:32 3231696 ----a-w- C:\Program Files (x86)\Mozilla Firefox\d3dcompiler_46.dll
2014-09-20 04:50:42 299520 ----a-w- C:\WINDOWS\System32\WSDMon.dll
2014-09-20 04:50:42 205824 ----a-w- C:\WINDOWS\System32\tcpmon.dll
2014-09-20 04:50:40 796672 ----a-w- C:\WINDOWS\System32\uDWM.dll
2014-09-20 04:50:40 2374784 ----a-w- C:\WINDOWS\explorer.exe
2014-09-20 04:50:40 2084520 ----a-w- C:\WINDOWS\SysWow64\explorer.exe
2014-09-20 04:50:38 13423104 ----a-w- C:\WINDOWS\System32\twinui.dll
2014-09-20 04:50:37 11818496 ----a-w- C:\WINDOWS\SysWow64\twinui.dll
2014-09-20 04:50:36 2860032 ----a-w- C:\WINDOWS\System32\actxprxy.dll
2014-09-20 04:50:36 1038336 ----a-w- C:\WINDOWS\SysWow64\actxprxy.dll
2014-09-20 04:50:35 68096 ----a-w- C:\WINDOWS\System32\UXInit.dll
2014-09-20 04:50:35 50176 ----a-w- C:\WINDOWS\SysWow64\UXInit.dll
2014-09-20 04:49:51 146752 ----a-w- C:\WINDOWS\System32\drivers\msgpioclx.sys
2014-09-20 04:38:09 97280 ----a-w- C:\WINDOWS\System32\aepic.dll
2014-09-20 04:36:38 1212928 ----a-w- C:\WINDOWS\System32\schedsvc.dll
2014-09-20 04:36:15 875688 ----a-w- C:\WINDOWS\SysWow64\msvcr120_clr0400.dll
2014-09-20 04:36:15 869544 ----a-w- C:\WINDOWS\System32\msvcr120_clr0400.dll
2014-09-06 03:46:26 435504 ----a-w- C:\WINDOWS\System32\drivers\dlkmd.sys
2014-09-06 03:46:26 18736 ----a-w- C:\WINDOWS\System32\drivers\dlkmdldr.sys
2014-09-05 05:32:56 1336624 ----a-w- C:\WINDOWS\System32\gdi32.dll
2014-09-05 05:32:56 1064448 ----a-w- C:\WINDOWS\SysWow64\gdi32.dll
2014-08-25 02:08:56 -------- d-----r- C:\Users\Farship\Music
2014-08-24 05:53:52 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware old
2014-08-23 04:31:01 26419488 ----a-w- C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2014-08-23 04:31:00 25693720 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2014-08-23 04:29:31 710144 ----a-w- C:\WINDOWS\SysWow64\rpcrt4.dll
2014-08-23 04:29:31 1273184 ----a-w- C:\WINDOWS\System32\rpcrt4.dll
2014-08-23 04:25:59 402432 ----a-w- C:\WINDOWS\System32\drivers\mrxsmb.sys
2014-08-23 04:24:57 356352 ----a-w- C:\WINDOWS\System32\msihnd.dll
2014-08-23 04:24:57 281088 ----a-w- C:\WINDOWS\SysWow64\msihnd.dll
2014-08-23 04:24:57 114520 ----a-w- C:\WINDOWS\System32\consent.exe
2014-08-23 04:24:52 623616 ----a-w- C:\WINDOWS\System32\MDMAgent.exe
2014-08-23 04:24:52 418816 ----a-w- C:\WINDOWS\System32\wbem\MDMSettingsProv.dll
2014-08-23 04:24:52 161792 ----a-w- C:\WINDOWS\System32\wbem\MDMAppProv.dll
2014-07-12 04:25:37 1018880 ----a-w- C:\WINDOWS\System32\termsrv.dll
2014-07-12 04:23:58 -------- d-s---w- C:\WINDOWS\System32\CompatTel
2014-07-10 13:28:16 46384 ----a-w- C:\WINDOWS\System32\drivers\DisplayLinkUsbIo_x64_7.6.56275.0.sys
2014-07-10 13:28:08 1017344 ----a-w- C:\WINDOWS\System32\DisplayLinkUsbCo64_7.6.56275.0.dll
2014-07-09 14:52:38 1469744 ----a-w- C:\WINDOWS\System32\dlumd9.dll
2014-07-09 14:52:38 1469744 ----a-w- C:\WINDOWS\System32\dlumd64.dll
2014-07-09 14:52:38 1469744 ----a-w- C:\WINDOWS\System32\dlumd11.dll
2014-07-09 14:52:38 1469744 ----a-w- C:\WINDOWS\System32\dlumd10.dll
2014-07-09 14:52:35 1146672 ----a-w- C:\WINDOWS\SysWow64\dlumd9.dll
2014-07-09 14:52:35 1146672 ----a-w- C:\WINDOWS\SysWow64\dlumd32.dll
2014-07-09 14:52:35 1146672 ----a-w- C:\WINDOWS\SysWow64\dlumd11.dll
2014-07-09 14:52:35 1146672 ----a-w- C:\WINDOWS\SysWow64\dlumd10.dll
2014-07-09 06:08:26 966144 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\tabskb.dll
2014-07-09 06:08:24 563200 ----a-w- C:\WINDOWS\System32\drivers\afd.sys
2014-07-09 06:08:23 735232 ----a-w- C:\WINDOWS\SysWow64\adtschema.dll
2014-07-09 06:08:23 735232 ----a-w- C:\WINDOWS\System32\adtschema.dll
2014-07-09 06:08:23 565576 ----a-w- C:\WINDOWS\System32\drivers\cng.sys
2014-07-09 06:03:25 79872 ----a-w- C:\WINDOWS\System32\WSReset.exe
2014-06-30 19:29:51 129752 ----a-w- C:\WINDOWS\System32\drivers\0E826AB4.sys
2014-06-30 19:29:40 129752 ----a-w- C:\WINDOWS\System32\drivers\40A96A90.sys
2014-06-30 19:29:34 93400 ----a-w- C:\WINDOWS\System32\drivers\mbamchameleon.sys
2014-06-30 19:29:34 64216 ----a-w- C:\WINDOWS\System32\drivers\mwac.sys
2014-06-30 19:29:34 25816 ----a-w- C:\WINDOWS\System32\drivers\mbam.sys
2014-06-30 19:24:55 129752 ----a-w- C:\WINDOWS\System32\drivers\02A966EE.sys
2014-06-30 19:24:48 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-28 01:48:21 -------- d-----r- C:\Users\Farship\Documents
2014-06-14 03:56:46 7173120 ----a-w- C:\WINDOWS\System32\Windows.Data.Pdf.dll
2014-06-14 03:55:32 98816 ----a-w- C:\WINDOWS\SysWow64\drvinst.exe
2014-06-14 03:55:32 57856 ----a-w- C:\WINDOWS\System32\drvcfg.exe
2014-06-14 03:55:32 110592 ----a-w- C:\WINDOWS\System32\drvinst.exe
2014-06-14 03:55:23 1975296 ----a-w- C:\WINDOWS\System32\DWrite.dll
2014-06-14 03:55:23 1345536 ----a-w- C:\WINDOWS\System32\FntCache.dll
2014-06-14 03:55:22 1509888 ----a-w- C:\WINDOWS\SysWow64\DWrite.dll
2014-06-14 03:30:44 55328 ----a-w- C:\WINDOWS\System32\drivers\wpcfltr.sys
2014-06-14 03:30:44 2834944 ----a-w- C:\WINDOWS\System32\wpccpl.dll
2014-06-14 03:29:46 53248 ----a-w- C:\WINDOWS\SysWow64\tsgqec.dll
2014-06-12 04:49:02 18636480 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
.
==================== Find3M ====================
.
2014-09-25 22:32:04 2017280 ----a-w- C:\WINDOWS\SysWow64\inetcpl.cpl
2014-09-25 22:31:02 2108416 ----a-w- C:\WINDOWS\System32\inetcpl.cpl
2014-09-20 19:01:30 2724864 ----a-w- C:\WINDOWS\System32\mshtml.tlb
2014-09-20 19:01:28 48640 ----a-w- C:\WINDOWS\System32\ieetwproxystub.dll
2014-09-20 19:01:28 4096 ----a-w- C:\WINDOWS\System32\ieetwcollectorres.dll
2014-09-20 19:01:28 139264 ----a-w- C:\WINDOWS\System32\ieUnatt.exe
2014-09-20 19:01:28 111616 ----a-w- C:\WINDOWS\System32\ieetwcollector.exe
2014-09-20 19:01:27 66048 ----a-w- C:\WINDOWS\System32\iesetup.dll
2014-09-19 01:40:03 547328 ----a-w- C:\WINDOWS\System32\vbscript.dll
2014-09-19 01:38:27 83968 ----a-w- C:\WINDOWS\System32\MshtmlDac.dll
2014-09-19 01:36:57 5829632 ----a-w- C:\WINDOWS\System32\jscript9.dll
2014-09-19 01:25:12 4201472 ----a-w- C:\WINDOWS\SysWow64\jscript9.dll
2014-09-19 01:25:09 758272 ----a-w- C:\WINDOWS\System32\jscript9diag.dll
2014-09-19 01:02:07 454656 ----a-w- C:\WINDOWS\SysWow64\vbscript.dll
2014-09-19 00:59:40 61952 ----a-w- C:\WINDOWS\SysWow64\MshtmlDac.dll
2014-09-19 00:33:18 2309632 ----a-w- C:\WINDOWS\System32\wininet.dll
2014-09-18 23:59:11 1810944 ----a-w- C:\WINDOWS\SysWow64\wininet.dll
2014-09-08 00:08:35 35328 ----a-w- C:\WINDOWS\System32\wuapp.exe
2014-09-08 00:07:59 137728 ----a-w- C:\WINDOWS\System32\wuwebv.dll
2014-09-08 00:04:52 388608 ----a-w- C:\WINDOWS\System32\WUSettingsProvider.dll
2014-09-08 00:04:20 93696 ----a-w- C:\WINDOWS\System32\wudriver.dll
2014-09-08 00:03:50 1702400 ----a-w- C:\WINDOWS\System32\wucltux.dll
2014-09-07 23:59:31 31232 ----a-w- C:\WINDOWS\SysWow64\wuapp.exe
2014-09-07 23:59:15 123904 ----a-w- C:\WINDOWS\SysWow64\wuwebv.dll
2014-09-07 23:56:51 80896 ----a-w- C:\WINDOWS\SysWow64\wudriver.dll
2014-08-29 01:58:52 109568 ----a-w- C:\WINDOWS\System32\appinfo.dll
2014-08-28 23:56:41 2646016 ----a-w- C:\WINDOWS\System32\authui.dll
2014-08-28 23:47:55 2321920 ----a-w- C:\WINDOWS\SysWow64\authui.dll
2014-08-16 04:08:38 1507648 ----a-w- C:\WINDOWS\System32\propsys.dll
2014-08-16 04:01:48 1710184 ----a-w- C:\WINDOWS\System32\ntdll.dll
2014-08-16 03:58:45 1112512 ----a-w- C:\WINDOWS\System32\KernelBase.dll
2014-08-16 03:57:37 2498880 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2014-08-16 03:57:36 428864 ----a-w- C:\WINDOWS\System32\drivers\FWPKCLNT.SYS
2014-08-16 03:16:37 1205976 ----a-w- C:\WINDOWS\SysWow64\propsys.dll
2014-08-16 03:03:51 1467384 ----a-w- C:\WINDOWS\SysWow64\ntdll.dll
2014-08-16 02:55:32 2407936 ----a-w- C:\WINDOWS\SysWow64\PrintConfig.dll
2014-08-16 01:31:16 838144 ----a-w- C:\WINDOWS\SysWow64\KernelBase.dll
2014-08-16 01:25:28 72704 ----a-w- C:\WINDOWS\System32\JavaScriptCollectionAgent.dll
2014-08-16 01:11:26 597504 ----a-w- C:\WINDOWS\SysWow64\jscript9diag.dll
2014-08-16 01:04:21 359424 ----a-w- C:\WINDOWS\System32\Wldap32.dll
2014-08-16 00:58:45 60416 ----a-w- C:\WINDOWS\SysWow64\JavaScriptCollectionAgent.dll
2014-08-16 00:58:35 287744 ----a-w- C:\WINDOWS\System32\SystemEventsBrokerServer.dll
2014-08-16 00:53:32 118272 ----a-w- C:\WINDOWS\System32\httpprxm.dll
2014-08-16 00:46:38 290816 ----a-w- C:\WINDOWS\System32\ProximityService.dll
2014-08-16 00:45:51 267776 ----a-w- C:\WINDOWS\System32\bisrv.dll
2014-08-16 00:43:38 75776 ----a-w- C:\WINDOWS\System32\adhsvc.dll
2014-08-16 00:43:25 321024 ----a-w- C:\WINDOWS\SysWow64\Wldap32.dll
2014-08-16 00:31:57 286208 ----a-w- C:\WINDOWS\System32\pcsvDevice.dll
2014-08-16 00:31:07 914432 ----a-w- C:\WINDOWS\System32\iphlpsvc.dll
2014-08-16 00:29:54 249344 ----a-w- C:\WINDOWS\System32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-08-16 00:23:10 1106432 ----a-w- C:\WINDOWS\System32\SearchFolder.dll
2014-08-16 00:22:56 717824 ----a-w- C:\WINDOWS\System32\SkyDriveTelemetry.dll
2014-08-16 00:22:06 286208 ----a-w- C:\WINDOWS\System32\SkyDriveShell.dll
2014-08-16 00:19:42 189952 ----a-w- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-08-16 00:18:36 4758528 ----a-w- C:\WINDOWS\System32\SyncEngine.dll
2014-08-16 00:17:51 8757760 ----a-w- C:\WINDOWS\System32\Windows.UI.Search.dll
2014-08-16 00:14:34 265216 ----a-w- C:\WINDOWS\SysWow64\SkyDriveShell.dll
2014-08-16 00:13:50 6649344 ----a-w- C:\WINDOWS\System32\mstscax.dll
2014-08-16 00:13:17 5902848 ----a-w- C:\WINDOWS\SysWow64\Windows.UI.Search.dll
2014-08-16 00:13:14 840192 ----a-w- C:\WINDOWS\SysWow64\SearchFolder.dll
2014-08-16 00:11:08 920064 ----a-w- C:\WINDOWS\System32\WSShared.dll
2014-08-16 00:10:35 1120768 ----a-w- C:\WINDOWS\System32\SkyDrive.exe
2014-08-16 00:08:48 5777408 ----a-w- C:\WINDOWS\SysWow64\mstscax.dll
2014-08-16 00:07:01 756224 ----a-w- C:\WINDOWS\SysWow64\WSShared.dll
2014-07-24 15:28:38 468288 -c--a-w- C:\WINDOWS\System32\drivers\USBHUB3.SYS
2014-07-24 15:28:38 419648 -c--a-w- C:\WINDOWS\System32\drivers\usbhub.sys
2014-07-24 15:28:38 412992 -c--a-w- C:\WINDOWS\System32\drivers\spaceport.sys
2014-07-24 15:28:38 143680 -c--a-w- C:\WINDOWS\System32\drivers\usbccgp.sys
2014-07-24 15:28:35 280384 -c--a-w- C:\WINDOWS\System32\drivers\pci.sys
2014-07-24 15:23:21 1519488 ----a-w- C:\WINDOWS\System32\user32.dll
2014-07-24 15:23:21 125472 ----a-w- C:\WINDOWS\System32\dwmapi.dll
2014-07-24 15:20:37 645592 ----a-w- C:\WINDOWS\System32\SHCore.dll
2014-07-24 15:20:37 263400 ----a-w- C:\WINDOWS\System32\SystemSettingsAdminFlows.exe
2014-07-24 15:16:25 2574208 ----a-w- C:\WINDOWS\System32\WMVDECOD.DLL
2014-07-24 15:16:24 211216 ----a-w- C:\WINDOWS\System32\SndVol.exe
2014-07-24 15:07:53 7424320 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2014-07-24 15:07:52 2009920 ----a-w- C:\WINDOWS\System32\drivers\ntfs.sys
2014-07-24 15:05:56 1660048 ----a-w- C:\WINDOWS\System32\winload.efi
2014-07-24 15:05:56 1519560 ----a-w- C:\WINDOWS\System32\winload.exe
2014-07-24 15:05:56 1488008 ----a-w- C:\WINDOWS\System32\winresume.efi
2014-07-24 15:05:56 1356840 ----a-w- C:\WINDOWS\System32\winresume.exe
2014-07-24 15:03:56 882136 ----a-w- C:\WINDOWS\System32\mfplat.dll
2014-07-24 15:03:55 818624 ----a-w- C:\WINDOWS\System32\mfmp4srcsnk.dll
2014-07-24 15:03:55 233888 ----a-w- C:\WINDOWS\System32\mfps.dll
2014-07-24 15:03:54 2141920 ----a-w- C:\WINDOWS\System32\mfcore.dll
2014-07-24 15:03:53 360480 ----a-w- C:\WINDOWS\System32\mfreadwrite.dll
2014-07-24 15:03:53 205512 ----a-w- C:\WINDOWS\System32\mftranscode.dll
2014-07-24 14:57:08 475968 ----a-w- C:\WINDOWS\System32\drivers\netio.sys
2014-07-24 13:50:07 98048 ----a-w- C:\WINDOWS\SysWow64\dwmapi.dll
2014-07-24 13:48:15 2410976 ----a-w- C:\WINDOWS\SysWow64\WMVDECOD.DLL
2014-07-24 13:48:15 180208 ----a-w- C:\WINDOWS\SysWow64\SndVol.exe
2014-07-24 13:46:50 477200 ----a-w- C:\WINDOWS\SysWow64\SHCore.dll
2014-07-24 13:36:22 707536 ----a-w- C:\WINDOWS\SysWow64\mfplat.dll
2014-07-24 13:36:22 674512 ----a-w- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll
2014-07-24 13:36:20 355800 ----a-w- C:\WINDOWS\SysWow64\mfreadwrite.dll
2014-07-24 13:36:20 2145472 ----a-w- C:\WINDOWS\SysWow64\mfcore.dll
2014-07-24 13:36:20 180720 ----a-w- C:\WINDOWS\SysWow64\mftranscode.dll
2014-07-24 11:51:24 7168 ----a-w- C:\WINDOWS\System32\KBDYAK.DLL
2014-07-24 11:51:22 7168 ----a-w- C:\WINDOWS\System32\KBDTT102.DLL
2014-07-24 11:51:18 8192 ----a-w- C:\WINDOWS\System32\KBDRUM.DLL
.
============= FINISH: 14:03:16.58 ===============