learninmypc
Posts: 9,676 +724
I'm simply wanting to find out if it is clean.Owner said Norton would not turn on & it was taken over by a virus.
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.07.29.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16635
Loren :: PAVILIONSLIM [administrator]
7/29/2013 12:57:49 PM
mbam-log-2013-07-29 (12-57-49).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 385287
Time elapsed: 33 minute(s), 55 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16635
Run by Loren at 13:34:13 on 2013-07-29
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2987.1431 [GMT -7:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files\Microsoft LifeCam\MSCamS64.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\Windows\notepad.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = www.kirotv.com
mWinlogon: Userinit = userinit.exe
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com/bin/srldetect_intel_4.5.15.0.cab
TCP: NameServer = 192.168.1.1 74.40.74.40
TCP: Interfaces\{99D28E7B-A177-4331-A285-4AE396420A06} : DHCPNameServer = 192.168.1.1 74.40.74.40
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Loren\AppData\Roaming\Mozilla\Firefox\Profiles\iu13exco.default\
FF - prefs.js: browser.startup.homepage - www.kirotv.com
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
FF - ExtSQL: 2013-07-29 11:16; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\Loren\AppData\Roaming\Mozilla\Firefox\Profiles\iu13exco.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-07-29 11:19; {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}; C:\Users\Loren\AppData\Roaming\Mozilla\Firefox\Profiles\iu13exco.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
.
============= SERVICES / DRIVERS ===============
.
R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-7-29 189936]
R0 iaStorA;iaStorA;C:\Windows\System32\drivers\iaStorA.sys [2012-11-19 651832]
R0 iaStorF;iaStorF;C:\Windows\System32\drivers\iaStorF.sys [2012-11-19 28216]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-7-29 378944]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2013-5-7 143088]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-7-29 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-7-29 80816]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-7-29 46808]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-5-16 533096]
S0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-7-29 65336]
S1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-7-29 1030952]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-7-20 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-7-20 57856]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-7-20 1255736]
.
=============== Created Last 30 ================
.
2013-07-29 19:43:49 72016 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-07-29 19:43:47 1030952 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-07-29 19:43:46 189936 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-07-29 19:43:45 65336 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-07-29 19:43:43 80816 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-07-29 19:42:14 41664 ----a-w- C:\Windows\avastSS.scr
2013-07-29 19:27:57 -------- d-----w- C:\199d700d78615acc70ce
2013-07-29 19:26:27 -------- d-----w- C:\Program Files\CCleaner
2013-07-29 19:22:05 -------- d-s---w- C:\Windows\SysWow64\Microsoft
2013-07-29 19:11:45 -------- d-----w- C:\Program Files\AVAST Software
2013-07-29 19:06:59 -------- d-----w- C:\Users\Loren\AppData\Local\Macromedia
2013-07-29 19:00:04 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2013-07-29 18:51:22 -------- d-----w- C:\ProgramData\Licenses
2013-07-29 18:51:19 129872 ----a-w- C:\Windows\SysWow64\MSSTDFMT.DLL
2013-07-29 18:51:19 1070352 ----a-w- C:\Windows\SysWow64\MSCOMCTL.OCX
2013-07-29 18:51:18 -------- d-----w- C:\Program Files (x86)\SpywareBlaster
2013-07-29 18:48:55 -------- d-----w- C:\Users\Loren\AppData\Roaming\Malwarebytes
2013-07-29 18:48:43 -------- d-----w- C:\ProgramData\Malwarebytes
2013-07-29 18:48:42 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-07-29 18:48:42 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-29 18:48:21 -------- d-----w- C:\Users\Loren\AppData\Local\Programs
2013-07-29 18:34:34 -------- d-----w- C:\Users\Loren\AppData\Roaming\SUPERAntiSpyware.com
2013-07-29 18:34:34 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2013-07-29 18:20:39 -------- d-----w- C:\ProgramData\AVAST Software
2013-07-29 18:14:05 -------- d-----w- C:\Users\Loren\AppData\Local\Mozilla
2013-07-28 04:00:47 -------- d-----w- C:\Users\Loren\AppData\Local\Diagnostics
2013-07-26 17:27:59 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{97E6D375-F243-4DBA-9E21-F752FE35BE8D}\mpengine.dll
2013-07-23 20:19:40 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-07-23 20:19:37 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-07-22 16:09:10 -------- d-----w- C:\Program Files\Microsoft LifeCam
2013-07-22 16:09:10 -------- d-----w- C:\Program Files (x86)\Microsoft LifeCam
2013-07-22 16:09:05 1974616 ----a-w- C:\Windows\SysWow64\D3DCompiler_42.dll
2013-07-22 16:09:04 1892184 ----a-w- C:\Windows\SysWow64\D3DX9_42.dll
2013-07-21 03:01:38 -------- d-----w- C:\Users\Loren\AppData\Local\Google
2013-07-21 03:01:28 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-07-21 03:01:27 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-07-21 03:00:57 -------- d-----w- C:\Users\Loren\AppData\Local\Adobe
2013-07-21 02:37:04 -------- d-----w- C:\Windows\pss
2013-07-21 02:29:17 -------- d-----w- C:\Users\Loren\AppData\Local\ElevatedDiagnostics
2013-07-21 00:21:57 -------- d-----w- C:\Users\Loren\AbiSuite
2013-07-21 00:21:57 -------- d-----w- C:\Users\Loren\.gimp-2.6
2013-07-20 22:43:04 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2013-07-20 22:43:04 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2013-07-20 22:15:49 1643520 ----a-w- C:\Windows\System32\DWrite.dll
2013-07-20 22:15:49 1247744 ----a-w- C:\Windows\SysWow64\DWrite.dll
2013-07-20 21:55:37 57856 ----a-w- C:\Windows\System32\drivers\TsUsbFlt.sys
2013-07-20 21:52:15 2776576 ----a-w- C:\Windows\System32\msmpeg2vdec.dll
2013-07-20 21:42:35 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2013-07-20 21:42:35 458712 ----a-w- C:\Windows\System32\drivers\cng.sys
2013-07-20 21:42:35 340992 ----a-w- C:\Windows\System32\schannel.dll
2013-07-20 21:42:35 247808 ----a-w- C:\Windows\SysWow64\schannel.dll
2013-07-20 21:42:35 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2013-07-20 21:42:35 154480 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2013-07-20 21:42:35 1448448 ----a-w- C:\Windows\System32\lsasrv.dll
2013-07-20 21:42:32 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2013-07-20 21:42:32 366592 ----a-w- C:\Windows\System32\qdvd.dll
2013-07-20 21:40:17 1887232 ----a-w- C:\Windows\System32\d3d11.dll
2013-07-20 21:40:17 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2013-07-20 21:06:42 -------- d-----w- C:\Program Files\Common Files\Intel
2013-07-20 21:06:42 -------- d-----w- C:\Program Files (x86)\Common Files\Intel
2013-07-20 21:06:29 -------- d-----w- C:\Intel
2013-07-20 20:43:42 -------- d-----w- C:\Windows\System32\MRT
2013-07-20 20:08:38 -------- d-----w- C:\Windows\System32\SPReview
2013-07-20 20:08:22 -------- d-----w- C:\Windows\System32\EventProviders
2013-07-20 19:40:59 428032 ----a-w- C:\Windows\SysWow64\secproc.dll
2013-07-20 19:39:59 189952 ----a-w- C:\Windows\SysWow64\sqmapi.dll
2013-07-20 19:39:56 606208 ----a-w- C:\Windows\SysWow64\wbem\fastprox.dll
2013-07-20 19:39:56 363008 ----a-w- C:\Windows\SysWow64\wbemcomn.dll
2013-07-20 19:39:56 189952 ----a-w- C:\Program Files (x86)\Windows Portable Devices\sqmapi.dll
2013-07-20 19:39:20 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2013-07-20 19:39:20 244736 ----a-w- C:\Program Files\Windows Portable Devices\sqmapi.dll
2013-07-20 19:39:17 244736 ----a-w- C:\Windows\System32\sqmapi.dll
2013-07-20 18:33:04 -------- d-----w- C:\Program Files\Realtek
2013-07-20 18:33:03 -------- d-----w- C:\Windows\SysWow64\RTCOM
2013-07-20 11:18:05 -------- d-----w- C:\Windows\SysWow64\Wat
2013-07-20 11:18:05 -------- d-----w- C:\Windows\System32\Wat
2013-07-20 10:30:05 9728 ----a-w- C:\Windows\System32\Wdfres.dll
2013-07-20 10:30:05 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys
2013-07-20 10:30:05 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys
2013-07-20 10:30:05 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2013-07-20 10:08:33 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2013-07-20 10:08:33 46080 ----a-w- C:\Windows\System32\atmlib.dll
2013-07-20 10:08:33 367616 ----a-w- C:\Windows\System32\atmfd.dll
2013-07-20 10:08:33 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2013-07-20 10:08:33 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2013-07-20 10:08:33 100864 ----a-w- C:\Windows\System32\fontsub.dll
2013-07-20 10:07:39 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2013-07-20 10:07:39 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2013-07-20 10:07:38 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2013-07-20 10:07:38 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2013-07-20 10:07:38 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2013-07-20 10:07:38 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2013-07-20 10:07:38 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2013-07-20 10:03:31 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-07-20 10:03:31 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2013-07-20 10:03:31 5120 ----a-w- C:\Windows\System32\wmi.dll
2013-07-20 10:03:31 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-07-20 10:03:31 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-07-19 23:48:27 886784 ----a-w- C:\Program Files\Common Files\System\wab32.dll
2013-07-19 23:48:27 708608 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2013-07-19 23:46:12 142336 ----a-w- C:\Windows\System32\poqexec.exe
2013-07-19 23:46:12 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2013-07-19 23:45:11 2871808 ----a-w- C:\Windows\explorer.exe
2013-07-19 23:45:11 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
2013-07-19 23:45:06 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-07-19 23:45:06 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-07-19 23:44:56 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2013-07-19 23:44:56 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2013-07-19 23:44:55 850944 ----a-w- C:\Windows\SysWow64\sbe.dll
2013-07-19 23:44:55 259072 ----a-w- C:\Windows\System32\mpg2splt.ax
2013-07-19 23:44:55 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2013-07-19 23:44:55 1118720 ----a-w- C:\Windows\System32\sbe.dll
2013-07-19 23:39:28 1572864 ----a-w- C:\Windows\System32\quartz.dll
2013-07-19 23:39:28 1328128 ----a-w- C:\Windows\SysWow64\quartz.dll
2013-07-19 23:39:22 509952 ----a-w- C:\Windows\System32\ntshrui.dll
2013-07-19 23:39:22 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
2013-07-19 23:33:06 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2013-07-19 23:31:58 515584 ----a-w- C:\Windows\System32\timedate.cpl
2013-07-19 23:31:58 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl
2013-07-19 23:30:21 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2013-07-19 23:30:21 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2013-07-19 23:30:21 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2013-07-19 23:30:21 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2013-07-19 23:29:41 19968 ----a-w- C:\Windows\System32\drivers\usb8023.sys
2013-07-19 23:29:40 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2013-07-19 23:29:40 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2013-07-19 23:29:40 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2013-07-19 23:29:39 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2013-07-19 23:29:39 31232 ----a-w- C:\Windows\System32\lsass.exe
2013-07-19 23:29:39 29184 ----a-w- C:\Windows\System32\sspisrv.dll
2013-07-19 23:29:39 28160 ----a-w- C:\Windows\System32\secur32.dll
2013-07-19 23:29:39 136192 ----a-w- C:\Windows\System32\sspicli.dll
2013-07-19 23:26:42 478208 ----a-w- C:\Windows\System32\dpnet.dll
2013-07-19 23:25:47 46592 ----a-w- C:\Windows\SysWow64\fpb.rs
2013-07-19 23:24:47 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2013-07-19 23:23:27 498688 ----a-w- C:\Windows\System32\drivers\afd.sys
2013-07-19 23:23:25 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2013-07-19 23:16:05 95744 ----a-w- C:\Windows\System32\synceng.dll
2013-07-19 23:16:05 78336 ----a-w- C:\Windows\SysWow64\synceng.dll
2013-07-19 23:16:04 642944 ----a-w- C:\Windows\System32\winload.efi
2013-07-19 23:16:04 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
2013-07-19 23:16:04 605552 ----a-w- C:\Windows\System32\winload.exe
2013-07-19 23:16:04 566208 ----a-w- C:\Windows\System32\winresume.efi
2013-07-19 23:16:04 518672 ----a-w- C:\Windows\System32\winresume.exe
2013-07-19 23:16:04 20352 ----a-w- C:\Windows\System32\kdusb.dll
2013-07-19 23:16:04 19328 ----a-w- C:\Windows\System32\kd1394.dll
2013-07-19 23:16:04 17792 ----a-w- C:\Windows\System32\kdcom.dll
2013-07-19 23:11:59 503808 ----a-w- C:\Windows\System32\srcore.dll
2013-07-19 23:10:34 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2013-07-19 23:09:47 67072 ----a-w- C:\Windows\splwow64.exe
2013-07-19 23:09:47 559104 ----a-w- C:\Windows\System32\spoolsv.exe
2013-07-19 23:09:10 77312 ----a-w- C:\Windows\System32\packager.dll
2013-07-19 23:09:10 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2013-07-19 22:32:08 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2013-07-19 22:32:07 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2013-07-19 22:32:07 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2013-07-19 22:11:35 -------- d-sh--w- C:\Windows\Installer
.
==================== Find3M ====================
.
2013-07-20 20:20:38 175616 ----a-w- C:\Windows\System32\msclmd.dll
2013-07-20 20:20:38 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2013-06-05 03:34:27 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-06-04 06:00:13 624128 ----a-w- C:\Windows\System32\qedit.dll
2013-06-04 04:53:07 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2013-05-13 05:51:01 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-05-13 05:51:00 1464320 ----a-w- C:\Windows\System32\crypt32.dll
2013-05-13 05:51:00 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-05-13 05:50:40 52224 ----a-w- C:\Windows\System32\certenc.dll
2013-05-13 04:45:55 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-05-13 04:45:55 1160192 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-05-13 04:45:55 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-05-13 03:43:55 1192448 ----a-w- C:\Windows\System32\certutil.exe
2013-05-13 03:08:10 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2013-05-13 03:08:06 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2013-05-10 05:49:27 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2013-05-10 03:20:54 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2013-05-08 06:39:01 1910632 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-05-06 06:03:49 1887744 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2013-05-06 04:56:35 1620480 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
.
============= FINISH: 13:34:46.94 ===============
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.07.29.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16635
Loren :: PAVILIONSLIM [administrator]
7/29/2013 12:57:49 PM
mbam-log-2013-07-29 (12-57-49).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 385287
Time elapsed: 33 minute(s), 55 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16635
Run by Loren at 13:34:13 on 2013-07-29
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2987.1431 [GMT -7:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files\Microsoft LifeCam\MSCamS64.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\Windows\notepad.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = www.kirotv.com
mWinlogon: Userinit = userinit.exe
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com/bin/srldetect_intel_4.5.15.0.cab
TCP: NameServer = 192.168.1.1 74.40.74.40
TCP: Interfaces\{99D28E7B-A177-4331-A285-4AE396420A06} : DHCPNameServer = 192.168.1.1 74.40.74.40
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Loren\AppData\Roaming\Mozilla\Firefox\Profiles\iu13exco.default\
FF - prefs.js: browser.startup.homepage - www.kirotv.com
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
FF - ExtSQL: 2013-07-29 11:16; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\Loren\AppData\Roaming\Mozilla\Firefox\Profiles\iu13exco.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-07-29 11:19; {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}; C:\Users\Loren\AppData\Roaming\Mozilla\Firefox\Profiles\iu13exco.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
.
============= SERVICES / DRIVERS ===============
.
R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-7-29 189936]
R0 iaStorA;iaStorA;C:\Windows\System32\drivers\iaStorA.sys [2012-11-19 651832]
R0 iaStorF;iaStorF;C:\Windows\System32\drivers\iaStorF.sys [2012-11-19 28216]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-7-29 378944]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2013-5-7 143088]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-7-29 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-7-29 80816]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-7-29 46808]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-5-16 533096]
S0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-7-29 65336]
S1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-7-29 1030952]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-7-20 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-7-20 57856]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-7-20 1255736]
.
=============== Created Last 30 ================
.
2013-07-29 19:43:49 72016 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-07-29 19:43:47 1030952 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-07-29 19:43:46 189936 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-07-29 19:43:45 65336 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-07-29 19:43:43 80816 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-07-29 19:42:14 41664 ----a-w- C:\Windows\avastSS.scr
2013-07-29 19:27:57 -------- d-----w- C:\199d700d78615acc70ce
2013-07-29 19:26:27 -------- d-----w- C:\Program Files\CCleaner
2013-07-29 19:22:05 -------- d-s---w- C:\Windows\SysWow64\Microsoft
2013-07-29 19:11:45 -------- d-----w- C:\Program Files\AVAST Software
2013-07-29 19:06:59 -------- d-----w- C:\Users\Loren\AppData\Local\Macromedia
2013-07-29 19:00:04 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2013-07-29 18:51:22 -------- d-----w- C:\ProgramData\Licenses
2013-07-29 18:51:19 129872 ----a-w- C:\Windows\SysWow64\MSSTDFMT.DLL
2013-07-29 18:51:19 1070352 ----a-w- C:\Windows\SysWow64\MSCOMCTL.OCX
2013-07-29 18:51:18 -------- d-----w- C:\Program Files (x86)\SpywareBlaster
2013-07-29 18:48:55 -------- d-----w- C:\Users\Loren\AppData\Roaming\Malwarebytes
2013-07-29 18:48:43 -------- d-----w- C:\ProgramData\Malwarebytes
2013-07-29 18:48:42 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-07-29 18:48:42 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-29 18:48:21 -------- d-----w- C:\Users\Loren\AppData\Local\Programs
2013-07-29 18:34:34 -------- d-----w- C:\Users\Loren\AppData\Roaming\SUPERAntiSpyware.com
2013-07-29 18:34:34 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2013-07-29 18:20:39 -------- d-----w- C:\ProgramData\AVAST Software
2013-07-29 18:14:05 -------- d-----w- C:\Users\Loren\AppData\Local\Mozilla
2013-07-28 04:00:47 -------- d-----w- C:\Users\Loren\AppData\Local\Diagnostics
2013-07-26 17:27:59 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{97E6D375-F243-4DBA-9E21-F752FE35BE8D}\mpengine.dll
2013-07-23 20:19:40 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-07-23 20:19:37 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-07-22 16:09:10 -------- d-----w- C:\Program Files\Microsoft LifeCam
2013-07-22 16:09:10 -------- d-----w- C:\Program Files (x86)\Microsoft LifeCam
2013-07-22 16:09:05 1974616 ----a-w- C:\Windows\SysWow64\D3DCompiler_42.dll
2013-07-22 16:09:04 1892184 ----a-w- C:\Windows\SysWow64\D3DX9_42.dll
2013-07-21 03:01:38 -------- d-----w- C:\Users\Loren\AppData\Local\Google
2013-07-21 03:01:28 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-07-21 03:01:27 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-07-21 03:00:57 -------- d-----w- C:\Users\Loren\AppData\Local\Adobe
2013-07-21 02:37:04 -------- d-----w- C:\Windows\pss
2013-07-21 02:29:17 -------- d-----w- C:\Users\Loren\AppData\Local\ElevatedDiagnostics
2013-07-21 00:21:57 -------- d-----w- C:\Users\Loren\AbiSuite
2013-07-21 00:21:57 -------- d-----w- C:\Users\Loren\.gimp-2.6
2013-07-20 22:43:04 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2013-07-20 22:43:04 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2013-07-20 22:15:49 1643520 ----a-w- C:\Windows\System32\DWrite.dll
2013-07-20 22:15:49 1247744 ----a-w- C:\Windows\SysWow64\DWrite.dll
2013-07-20 21:55:37 57856 ----a-w- C:\Windows\System32\drivers\TsUsbFlt.sys
2013-07-20 21:52:15 2776576 ----a-w- C:\Windows\System32\msmpeg2vdec.dll
2013-07-20 21:42:35 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2013-07-20 21:42:35 458712 ----a-w- C:\Windows\System32\drivers\cng.sys
2013-07-20 21:42:35 340992 ----a-w- C:\Windows\System32\schannel.dll
2013-07-20 21:42:35 247808 ----a-w- C:\Windows\SysWow64\schannel.dll
2013-07-20 21:42:35 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2013-07-20 21:42:35 154480 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2013-07-20 21:42:35 1448448 ----a-w- C:\Windows\System32\lsasrv.dll
2013-07-20 21:42:32 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2013-07-20 21:42:32 366592 ----a-w- C:\Windows\System32\qdvd.dll
2013-07-20 21:40:17 1887232 ----a-w- C:\Windows\System32\d3d11.dll
2013-07-20 21:40:17 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2013-07-20 21:06:42 -------- d-----w- C:\Program Files\Common Files\Intel
2013-07-20 21:06:42 -------- d-----w- C:\Program Files (x86)\Common Files\Intel
2013-07-20 21:06:29 -------- d-----w- C:\Intel
2013-07-20 20:43:42 -------- d-----w- C:\Windows\System32\MRT
2013-07-20 20:08:38 -------- d-----w- C:\Windows\System32\SPReview
2013-07-20 20:08:22 -------- d-----w- C:\Windows\System32\EventProviders
2013-07-20 19:40:59 428032 ----a-w- C:\Windows\SysWow64\secproc.dll
2013-07-20 19:39:59 189952 ----a-w- C:\Windows\SysWow64\sqmapi.dll
2013-07-20 19:39:56 606208 ----a-w- C:\Windows\SysWow64\wbem\fastprox.dll
2013-07-20 19:39:56 363008 ----a-w- C:\Windows\SysWow64\wbemcomn.dll
2013-07-20 19:39:56 189952 ----a-w- C:\Program Files (x86)\Windows Portable Devices\sqmapi.dll
2013-07-20 19:39:20 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2013-07-20 19:39:20 244736 ----a-w- C:\Program Files\Windows Portable Devices\sqmapi.dll
2013-07-20 19:39:17 244736 ----a-w- C:\Windows\System32\sqmapi.dll
2013-07-20 18:33:04 -------- d-----w- C:\Program Files\Realtek
2013-07-20 18:33:03 -------- d-----w- C:\Windows\SysWow64\RTCOM
2013-07-20 11:18:05 -------- d-----w- C:\Windows\SysWow64\Wat
2013-07-20 11:18:05 -------- d-----w- C:\Windows\System32\Wat
2013-07-20 10:30:05 9728 ----a-w- C:\Windows\System32\Wdfres.dll
2013-07-20 10:30:05 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys
2013-07-20 10:30:05 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys
2013-07-20 10:30:05 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2013-07-20 10:08:33 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2013-07-20 10:08:33 46080 ----a-w- C:\Windows\System32\atmlib.dll
2013-07-20 10:08:33 367616 ----a-w- C:\Windows\System32\atmfd.dll
2013-07-20 10:08:33 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2013-07-20 10:08:33 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2013-07-20 10:08:33 100864 ----a-w- C:\Windows\System32\fontsub.dll
2013-07-20 10:07:39 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2013-07-20 10:07:39 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2013-07-20 10:07:38 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2013-07-20 10:07:38 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2013-07-20 10:07:38 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2013-07-20 10:07:38 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2013-07-20 10:07:38 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2013-07-20 10:03:31 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-07-20 10:03:31 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2013-07-20 10:03:31 5120 ----a-w- C:\Windows\System32\wmi.dll
2013-07-20 10:03:31 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-07-20 10:03:31 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-07-19 23:48:27 886784 ----a-w- C:\Program Files\Common Files\System\wab32.dll
2013-07-19 23:48:27 708608 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2013-07-19 23:46:12 142336 ----a-w- C:\Windows\System32\poqexec.exe
2013-07-19 23:46:12 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2013-07-19 23:45:11 2871808 ----a-w- C:\Windows\explorer.exe
2013-07-19 23:45:11 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
2013-07-19 23:45:06 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-07-19 23:45:06 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-07-19 23:44:56 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2013-07-19 23:44:56 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2013-07-19 23:44:55 850944 ----a-w- C:\Windows\SysWow64\sbe.dll
2013-07-19 23:44:55 259072 ----a-w- C:\Windows\System32\mpg2splt.ax
2013-07-19 23:44:55 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2013-07-19 23:44:55 1118720 ----a-w- C:\Windows\System32\sbe.dll
2013-07-19 23:39:28 1572864 ----a-w- C:\Windows\System32\quartz.dll
2013-07-19 23:39:28 1328128 ----a-w- C:\Windows\SysWow64\quartz.dll
2013-07-19 23:39:22 509952 ----a-w- C:\Windows\System32\ntshrui.dll
2013-07-19 23:39:22 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
2013-07-19 23:33:06 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2013-07-19 23:31:58 515584 ----a-w- C:\Windows\System32\timedate.cpl
2013-07-19 23:31:58 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl
2013-07-19 23:30:21 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2013-07-19 23:30:21 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2013-07-19 23:30:21 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2013-07-19 23:30:21 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2013-07-19 23:29:41 19968 ----a-w- C:\Windows\System32\drivers\usb8023.sys
2013-07-19 23:29:40 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2013-07-19 23:29:40 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2013-07-19 23:29:40 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2013-07-19 23:29:39 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2013-07-19 23:29:39 31232 ----a-w- C:\Windows\System32\lsass.exe
2013-07-19 23:29:39 29184 ----a-w- C:\Windows\System32\sspisrv.dll
2013-07-19 23:29:39 28160 ----a-w- C:\Windows\System32\secur32.dll
2013-07-19 23:29:39 136192 ----a-w- C:\Windows\System32\sspicli.dll
2013-07-19 23:26:42 478208 ----a-w- C:\Windows\System32\dpnet.dll
2013-07-19 23:25:47 46592 ----a-w- C:\Windows\SysWow64\fpb.rs
2013-07-19 23:24:47 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2013-07-19 23:23:27 498688 ----a-w- C:\Windows\System32\drivers\afd.sys
2013-07-19 23:23:25 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2013-07-19 23:16:05 95744 ----a-w- C:\Windows\System32\synceng.dll
2013-07-19 23:16:05 78336 ----a-w- C:\Windows\SysWow64\synceng.dll
2013-07-19 23:16:04 642944 ----a-w- C:\Windows\System32\winload.efi
2013-07-19 23:16:04 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
2013-07-19 23:16:04 605552 ----a-w- C:\Windows\System32\winload.exe
2013-07-19 23:16:04 566208 ----a-w- C:\Windows\System32\winresume.efi
2013-07-19 23:16:04 518672 ----a-w- C:\Windows\System32\winresume.exe
2013-07-19 23:16:04 20352 ----a-w- C:\Windows\System32\kdusb.dll
2013-07-19 23:16:04 19328 ----a-w- C:\Windows\System32\kd1394.dll
2013-07-19 23:16:04 17792 ----a-w- C:\Windows\System32\kdcom.dll
2013-07-19 23:11:59 503808 ----a-w- C:\Windows\System32\srcore.dll
2013-07-19 23:10:34 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2013-07-19 23:09:47 67072 ----a-w- C:\Windows\splwow64.exe
2013-07-19 23:09:47 559104 ----a-w- C:\Windows\System32\spoolsv.exe
2013-07-19 23:09:10 77312 ----a-w- C:\Windows\System32\packager.dll
2013-07-19 23:09:10 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2013-07-19 22:32:08 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2013-07-19 22:32:07 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2013-07-19 22:32:07 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2013-07-19 22:11:35 -------- d-sh--w- C:\Windows\Installer
.
==================== Find3M ====================
.
2013-07-20 20:20:38 175616 ----a-w- C:\Windows\System32\msclmd.dll
2013-07-20 20:20:38 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2013-06-05 03:34:27 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-06-04 06:00:13 624128 ----a-w- C:\Windows\System32\qedit.dll
2013-06-04 04:53:07 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2013-05-13 05:51:01 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-05-13 05:51:00 1464320 ----a-w- C:\Windows\System32\crypt32.dll
2013-05-13 05:51:00 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-05-13 05:50:40 52224 ----a-w- C:\Windows\System32\certenc.dll
2013-05-13 04:45:55 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-05-13 04:45:55 1160192 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-05-13 04:45:55 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-05-13 03:43:55 1192448 ----a-w- C:\Windows\System32\certutil.exe
2013-05-13 03:08:10 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2013-05-13 03:08:06 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2013-05-10 05:49:27 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2013-05-10 03:20:54 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2013-05-08 06:39:01 1910632 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-05-06 06:03:49 1887744 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2013-05-06 04:56:35 1620480 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
.
============= FINISH: 13:34:46.94 ===============