For the past week and a half, I noticed that my browsers have been very slow and the bandwidth usage has been insanely high (in the 8GB range per day, and most of it is from uploads). At first, I thought that someone may've been piggy-backing on my wifi, so I ended up changing and hiding the SSID and password for the wireless connection. However, the bandwidth usage continued to be as high. I had shut off wifi for a day and used a wired connection, but I still ended up using around 6GB or bandwidth within 3 hours of being connected. Also, I'm the only one using the connection. Below are all of the logs. GMER didn't produce any logs.
Malwarebytes Anti-Malware (Trial) 1.65.1.1000
www.malwarebytes.org
Database version: v2012.11.10.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
tony :: TONY-SAT-PC [administrator]
Protection: Enabled
11/11/2012 1:53:02 AM
mbam-log-2012-11-11 (01-53-02).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 201702
Time elapsed: 3 minute(s), 54 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
DDS (Ver_2012-11-07.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16450
Run by tony at 2:03:23 on 2012-11-11
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.7654.5601 [GMT -5:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\BandwidthMonitor\BWMonitor.exe
C:\Program Files\NetWorx\networx.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\taskmgr.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe
C:\Program Files (x86)\Notepad++\notepad++.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\notepad.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{0FD04827-A482-42FC-B871-0DEFA91E98EE} : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{0FD04827-A482-42FC-B871-0DEFA91E98EE}\0534E49687E23616 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{0FD04827-A482-42FC-B871-0DEFA91E98EE}\2454C4C4033353 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{0FD04827-A482-42FC-B871-0DEFA91E98EE}\2595542535F4E4 : DHCPNameServer = 141.117.199.78 141.117.199.82 141.117.199.74
TCP: Interfaces\{0FD04827-A482-42FC-B871-0DEFA91E98EE}\C4F4E474 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{11122252-4F96-447D-A760-051FAB1F5FD1}\0534E49687E23616 : DHCPNameServer = 192.168.2.1
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
x64-BHO: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [NetWorx] "C:\Program Files\NetWorx\networx.exe" /auto
x64-Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
x64-Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 amdkmpfd;AMD PCI Root Bus Lower Filter;C:\Windows\System32\drivers\amdkmpfd.sys [2012-2-1 31872]
R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.sys [2012-11-7 27800]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-2-13 235520]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-11-7 84256]
R2 AntiVirService;Avira Real-Time Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-11-7 108320]
R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2012-11-7 99248]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-11-7 399432]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-11-7 676936]
R3 amdhub30;AMD USB 3.0 Hub Driver;C:\Windows\System32\drivers\amdhub30.sys [2012-10-29 103552]
R3 amdxhc;AMD USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\amdxhc.sys [2012-10-29 220288]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2011-12-5 95248]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-11-7 25928]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2012-10-29 251496]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-10-29 565352]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\Windows\System32\drivers\rtl8192ce.sys [2012-10-29 880272]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2012-10-29 56448]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-10-19 160944]
S3 A5AGU;D-Link Wireless LAN 802.11 USB device driver;C:\Windows\System32\drivers\AGUx64.sys [2012-10-29 1077760]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-10-29 1255736]
.
=============== Created Last 30 ================
.
2012-11-10 05:22:22 -------- d-----w- C:\ProgramData\boost_interprocess
2012-11-09 17:37:14 -------- d-----w- C:\ProgramData\SoftPerfect
2012-11-09 17:37:14 -------- d-----w- C:\Program Files\NetWorx
2012-11-09 17:35:42 -------- d-----w- C:\Program Files (x86)\BandwidthMonitor
2012-11-08 15:42:14 -------- d-----w- C:\Users\tony\.thumbnails
2012-11-08 15:39:46 -------- d-----w- C:\Users\tony\AppData\Local\fontconfig
2012-11-08 15:39:43 -------- d-----w- C:\Users\tony\.gimp-2.8
2012-11-08 15:39:42 -------- d-----w- C:\Users\tony\AppData\Local\gegl-0.2
2012-11-08 13:52:12 -------- d-----w- C:\Program Files\GIMP 2
2012-11-08 13:50:21 -------- d-----w- C:\Users\tony\AppData\Roaming\tigerplayer
2012-11-08 13:50:21 -------- d-----w- C:\Users\tony\AppData\Roaming\CometPlayer
2012-11-08 13:50:21 -------- d-----w- C:\Program Files (x86)\MpcStar
2012-11-08 02:12:28 -------- d-----w- C:\Users\tony\AppData\Roaming\Malwarebytes
2012-11-08 02:12:19 -------- d-----w- C:\ProgramData\Malwarebytes
2012-11-08 02:12:17 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-11-08 02:12:17 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-11-07 16:05:51 -------- d-----w- C:\Users\tony\AppData\Roaming\Avira
2012-11-07 15:58:40 99248 ----a-w- C:\Windows\System32\drivers\avgntflt.sys
2012-11-07 15:58:40 27800 ----a-w- C:\Windows\System32\drivers\avkmgr.sys
2012-11-07 15:58:38 -------- d-----w- C:\ProgramData\Avira
2012-11-07 15:58:38 -------- d-----w- C:\Program Files (x86)\Avira
2012-11-07 15:44:01 -------- d-----w- C:\Users\tony\AppData\Local\Diagnostics
2012-11-06 19:01:02 -------- d-----w- C:\Users\tony\AppData\Local\LogMeIn Rescue Applet
2012-11-06 18:31:19 -------- d-----w- C:\Users\tony\AppData\Roaming\Bell
2012-11-06 18:31:13 -------- d-----w- C:\ProgramData\Radialpoint
2012-11-06 18:31:10 -------- d-----w- C:\ProgramData\Bell
2012-11-04 05:49:04 -------- d-----w- C:\Users\tony\bluej
2012-11-03 02:25:18 -------- d-----w- C:\Program Files (x86)\BlueJ
2012-11-01 14:11:58 -------- d-----w- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2012-11-01 13:22:37 1139200 ----a-w- C:\Windows\System32\FntCache.dll
2012-11-01 13:22:36 902656 ----a-w- C:\Windows\System32\d2d1.dll
2012-11-01 13:22:36 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
2012-10-31 02:46:02 73656 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-31 02:46:02 696760 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-10-30 22:26:56 -------- d-----w- C:\Program Files (x86)\Kill3rCombo
2012-10-30 22:03:35 -------- d-----w- C:\Users\tony\Tracing
2012-10-30 21:52:37 -------- d-----w- C:\Users\tony\AppData\Local\Windows Live
2012-10-30 21:52:23 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2012-10-30 18:18:52 -------- d-----w- C:\ProgramData\NexonUS
2012-10-30 18:18:28 -------- d-----w- C:\Nexon
2012-10-30 17:54:24 -------- d-----w- C:\Users\tony\AppData\Local\Microsoft Games
2012-10-30 17:43:49 -------- d-----w- C:\Users\tony\AppData\Local\Adobe
2012-10-30 16:53:05 916456 ----a-w- C:\Windows\System32\deployJava1.dll
2012-10-30 16:53:05 1034216 ----a-w- C:\Windows\System32\npDeployJava1.dll
2012-10-30 16:52:57 108008 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2012-10-30 16:41:21 -------- d-----w- C:\Program Files (x86)\Pando Networks
2012-10-30 16:33:18 -------- d-----w- C:\Users\tony\AppData\Local\Google
2012-10-30 16:32:42 -------- d-----w- C:\Users\tony\AppData\Local\Apps
2012-10-30 16:32:41 -------- d-----w- C:\Users\tony\AppData\Local\Deployment
2012-10-30 16:29:41 -------- d-----r- C:\Program Files (x86)\Skype
2012-10-30 13:17:56 9291768 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3E431A59-D7C6-4FE3-971B-B33D6001661E}\mpengine.dll
2012-10-30 13:08:51 -------- d-----w- C:\Windows\PCHEALTH
2012-10-30 13:06:46 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
2012-10-30 13:05:54 -------- d-----w- C:\Users\tony\AppData\Local\Microsoft Help
2012-10-29 23:36:00 -------- d-----w- C:\Windows\Panther
2012-10-29 21:37:39 -------- d-----w- C:\Windows\SysWow64\Wat
2012-10-29 21:37:39 -------- d-----w- C:\Windows\System32\Wat
2012-10-29 20:54:55 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-10-29 20:54:55 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-10-29 20:54:54 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-10-29 20:54:54 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-10-29 20:54:54 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-10-29 20:42:10 0 ----a-w- C:\Windows\ativpsrm.bin
2012-10-29 20:40:43 -------- d-----w- C:\Users\tony\AppData\Local\ATI
2012-10-29 20:40:32 220288 ----a-w- C:\Windows\System32\drivers\amdxhc.sys
2012-10-29 20:40:32 103552 ----a-w- C:\Windows\System32\drivers\amdhub30.sys
2012-10-29 20:39:26 -------- d-----w- C:\Windows\kdb
2012-10-29 20:39:24 -------- d-----w- C:\Program Files\AMD
2012-10-29 20:39:24 -------- d-----w- C:\Program Files (x86)\AMD
2012-10-29 20:39:22 -------- d-----w- C:\Program Files (x86)\AMD APP
2012-10-29 20:39:19 -------- d-----w- C:\Program Files\Common Files\ATI Technologies
2012-10-29 20:39:19 -------- d-----w- C:\Program Files (x86)\Common Files\ATI Technologies
2012-10-29 20:38:09 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2012-10-29 20:34:35 56448 ----a-w- C:\Windows\System32\drivers\usbfilter.sys
2012-10-29 20:34:27 -------- d-sh--w- C:\Windows\Installer
2012-10-29 20:34:22 -------- d-----w- C:\Program Files\ATI Technologies
2012-10-29 20:34:20 -------- d-----w- C:\Program Files\ATI
2012-10-29 20:23:35 1659760 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2012-10-29 20:22:56 142336 ----a-w- C:\Windows\System32\poqexec.exe
2012-10-29 20:20:41 950128 ----a-w- C:\Windows\System32\drivers\ndis.sys
2012-10-29 20:19:56 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2012-10-29 20:17:28 -------- d-----w- C:\Windows\SysWow64\sda
2012-10-29 20:17:03 9887848 ----a-w- C:\Windows\SysWow64\RtsUStoricon.dll
2012-10-29 20:17:03 422504 ----a-w- C:\Windows\System32\RtsUStor.dll
2012-10-29 20:17:03 251496 ----a-w- C:\Windows\System32\drivers\RtsUStor.sys
2012-10-29 20:14:57 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
2012-10-29 20:13:49 956928 ----a-w- C:\Windows\System32\localspl.dll
2012-10-29 19:59:27 9291768 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-10-29 19:57:12 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-10-29 19:57:12 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-10-29 19:57:11 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-10-29 19:53:14 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-10-29 19:53:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-10-29 19:52:47 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-10-29 19:52:47 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-10-29 19:50:24 1077760 ----a-w- C:\Windows\System32\drivers\AGUx64.sys
2012-10-29 19:47:03 -------- d-----w- C:\Users\tony\AppData\Local\VirtualStore
.
==================== Find3M ====================
.
2012-09-14 19:19:29 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-09-14 18:28:53 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-09-12 20:07:44 58368 ----a-w- C:\Windows\SysWow64\sirenacm.dll
2012-08-30 18:03:45 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-08-30 17:12:02 3968880 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12:02 3914096 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-08-24 18:05:07 220160 ----a-w- C:\Windows\System32\wintrust.dll
2012-08-24 16:57:48 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-08-22 18:12:50 1913200 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-08-22 18:12:40 376688 ----a-w- C:\Windows\System32\drivers\netio.sys
2012-08-22 18:12:33 288624 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2012-08-21 21:01:00 245760 ----a-w- C:\Windows\System32\OxpsConverter.exe
2012-08-20 18:48:44 362496 ----a-w- C:\Windows\System32\wow64win.dll
2012-08-20 18:48:44 243200 ----a-w- C:\Windows\System32\wow64.dll
2012-08-20 18:48:44 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2012-08-20 18:48:43 215040 ----a-w- C:\Windows\System32\winsrv.dll
2012-08-20 18:48:37 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2012-08-20 18:48:35 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2012-08-20 18:46:22 338432 ----a-w- C:\Windows\System32\conhost.exe
2012-08-20 17:40:21 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-08-20 17:38:44 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2012-08-20 17:38:26 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2012-08-20 17:37:19 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2012-08-20 17:37:18 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2012-08-20 15:38:21 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2012-08-20 15:38:20 2048 ----a-w- C:\Windows\SysWow64\user.exe
2012-08-20 15:33:28 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-08-20 15:33:28 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-08-20 15:33:28 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-08-20 15:33:28 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
.
============= FINISH: 2:04:04.13 ===============
Malwarebytes Anti-Malware (Trial) 1.65.1.1000
www.malwarebytes.org
Database version: v2012.11.10.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
tony :: TONY-SAT-PC [administrator]
Protection: Enabled
11/11/2012 1:53:02 AM
mbam-log-2012-11-11 (01-53-02).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 201702
Time elapsed: 3 minute(s), 54 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
DDS (Ver_2012-11-07.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16450
Run by tony at 2:03:23 on 2012-11-11
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.7654.5601 [GMT -5:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\BandwidthMonitor\BWMonitor.exe
C:\Program Files\NetWorx\networx.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\taskmgr.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe
C:\Program Files (x86)\Notepad++\notepad++.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\notepad.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{0FD04827-A482-42FC-B871-0DEFA91E98EE} : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{0FD04827-A482-42FC-B871-0DEFA91E98EE}\0534E49687E23616 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{0FD04827-A482-42FC-B871-0DEFA91E98EE}\2454C4C4033353 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{0FD04827-A482-42FC-B871-0DEFA91E98EE}\2595542535F4E4 : DHCPNameServer = 141.117.199.78 141.117.199.82 141.117.199.74
TCP: Interfaces\{0FD04827-A482-42FC-B871-0DEFA91E98EE}\C4F4E474 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{11122252-4F96-447D-A760-051FAB1F5FD1}\0534E49687E23616 : DHCPNameServer = 192.168.2.1
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
x64-BHO: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [NetWorx] "C:\Program Files\NetWorx\networx.exe" /auto
x64-Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
x64-Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 amdkmpfd;AMD PCI Root Bus Lower Filter;C:\Windows\System32\drivers\amdkmpfd.sys [2012-2-1 31872]
R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.sys [2012-11-7 27800]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-2-13 235520]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-11-7 84256]
R2 AntiVirService;Avira Real-Time Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-11-7 108320]
R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2012-11-7 99248]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-11-7 399432]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-11-7 676936]
R3 amdhub30;AMD USB 3.0 Hub Driver;C:\Windows\System32\drivers\amdhub30.sys [2012-10-29 103552]
R3 amdxhc;AMD USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\amdxhc.sys [2012-10-29 220288]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2011-12-5 95248]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-11-7 25928]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2012-10-29 251496]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-10-29 565352]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\Windows\System32\drivers\rtl8192ce.sys [2012-10-29 880272]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2012-10-29 56448]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-10-19 160944]
S3 A5AGU;D-Link Wireless LAN 802.11 USB device driver;C:\Windows\System32\drivers\AGUx64.sys [2012-10-29 1077760]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-10-29 1255736]
.
=============== Created Last 30 ================
.
2012-11-10 05:22:22 -------- d-----w- C:\ProgramData\boost_interprocess
2012-11-09 17:37:14 -------- d-----w- C:\ProgramData\SoftPerfect
2012-11-09 17:37:14 -------- d-----w- C:\Program Files\NetWorx
2012-11-09 17:35:42 -------- d-----w- C:\Program Files (x86)\BandwidthMonitor
2012-11-08 15:42:14 -------- d-----w- C:\Users\tony\.thumbnails
2012-11-08 15:39:46 -------- d-----w- C:\Users\tony\AppData\Local\fontconfig
2012-11-08 15:39:43 -------- d-----w- C:\Users\tony\.gimp-2.8
2012-11-08 15:39:42 -------- d-----w- C:\Users\tony\AppData\Local\gegl-0.2
2012-11-08 13:52:12 -------- d-----w- C:\Program Files\GIMP 2
2012-11-08 13:50:21 -------- d-----w- C:\Users\tony\AppData\Roaming\tigerplayer
2012-11-08 13:50:21 -------- d-----w- C:\Users\tony\AppData\Roaming\CometPlayer
2012-11-08 13:50:21 -------- d-----w- C:\Program Files (x86)\MpcStar
2012-11-08 02:12:28 -------- d-----w- C:\Users\tony\AppData\Roaming\Malwarebytes
2012-11-08 02:12:19 -------- d-----w- C:\ProgramData\Malwarebytes
2012-11-08 02:12:17 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-11-08 02:12:17 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-11-07 16:05:51 -------- d-----w- C:\Users\tony\AppData\Roaming\Avira
2012-11-07 15:58:40 99248 ----a-w- C:\Windows\System32\drivers\avgntflt.sys
2012-11-07 15:58:40 27800 ----a-w- C:\Windows\System32\drivers\avkmgr.sys
2012-11-07 15:58:38 -------- d-----w- C:\ProgramData\Avira
2012-11-07 15:58:38 -------- d-----w- C:\Program Files (x86)\Avira
2012-11-07 15:44:01 -------- d-----w- C:\Users\tony\AppData\Local\Diagnostics
2012-11-06 19:01:02 -------- d-----w- C:\Users\tony\AppData\Local\LogMeIn Rescue Applet
2012-11-06 18:31:19 -------- d-----w- C:\Users\tony\AppData\Roaming\Bell
2012-11-06 18:31:13 -------- d-----w- C:\ProgramData\Radialpoint
2012-11-06 18:31:10 -------- d-----w- C:\ProgramData\Bell
2012-11-04 05:49:04 -------- d-----w- C:\Users\tony\bluej
2012-11-03 02:25:18 -------- d-----w- C:\Program Files (x86)\BlueJ
2012-11-01 14:11:58 -------- d-----w- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2012-11-01 13:22:37 1139200 ----a-w- C:\Windows\System32\FntCache.dll
2012-11-01 13:22:36 902656 ----a-w- C:\Windows\System32\d2d1.dll
2012-11-01 13:22:36 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
2012-10-31 02:46:02 73656 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-31 02:46:02 696760 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-10-30 22:26:56 -------- d-----w- C:\Program Files (x86)\Kill3rCombo
2012-10-30 22:03:35 -------- d-----w- C:\Users\tony\Tracing
2012-10-30 21:52:37 -------- d-----w- C:\Users\tony\AppData\Local\Windows Live
2012-10-30 21:52:23 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2012-10-30 18:18:52 -------- d-----w- C:\ProgramData\NexonUS
2012-10-30 18:18:28 -------- d-----w- C:\Nexon
2012-10-30 17:54:24 -------- d-----w- C:\Users\tony\AppData\Local\Microsoft Games
2012-10-30 17:43:49 -------- d-----w- C:\Users\tony\AppData\Local\Adobe
2012-10-30 16:53:05 916456 ----a-w- C:\Windows\System32\deployJava1.dll
2012-10-30 16:53:05 1034216 ----a-w- C:\Windows\System32\npDeployJava1.dll
2012-10-30 16:52:57 108008 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2012-10-30 16:41:21 -------- d-----w- C:\Program Files (x86)\Pando Networks
2012-10-30 16:33:18 -------- d-----w- C:\Users\tony\AppData\Local\Google
2012-10-30 16:32:42 -------- d-----w- C:\Users\tony\AppData\Local\Apps
2012-10-30 16:32:41 -------- d-----w- C:\Users\tony\AppData\Local\Deployment
2012-10-30 16:29:41 -------- d-----r- C:\Program Files (x86)\Skype
2012-10-30 13:17:56 9291768 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3E431A59-D7C6-4FE3-971B-B33D6001661E}\mpengine.dll
2012-10-30 13:08:51 -------- d-----w- C:\Windows\PCHEALTH
2012-10-30 13:06:46 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
2012-10-30 13:05:54 -------- d-----w- C:\Users\tony\AppData\Local\Microsoft Help
2012-10-29 23:36:00 -------- d-----w- C:\Windows\Panther
2012-10-29 21:37:39 -------- d-----w- C:\Windows\SysWow64\Wat
2012-10-29 21:37:39 -------- d-----w- C:\Windows\System32\Wat
2012-10-29 20:54:55 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-10-29 20:54:55 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-10-29 20:54:54 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-10-29 20:54:54 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-10-29 20:54:54 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-10-29 20:42:10 0 ----a-w- C:\Windows\ativpsrm.bin
2012-10-29 20:40:43 -------- d-----w- C:\Users\tony\AppData\Local\ATI
2012-10-29 20:40:32 220288 ----a-w- C:\Windows\System32\drivers\amdxhc.sys
2012-10-29 20:40:32 103552 ----a-w- C:\Windows\System32\drivers\amdhub30.sys
2012-10-29 20:39:26 -------- d-----w- C:\Windows\kdb
2012-10-29 20:39:24 -------- d-----w- C:\Program Files\AMD
2012-10-29 20:39:24 -------- d-----w- C:\Program Files (x86)\AMD
2012-10-29 20:39:22 -------- d-----w- C:\Program Files (x86)\AMD APP
2012-10-29 20:39:19 -------- d-----w- C:\Program Files\Common Files\ATI Technologies
2012-10-29 20:39:19 -------- d-----w- C:\Program Files (x86)\Common Files\ATI Technologies
2012-10-29 20:38:09 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2012-10-29 20:34:35 56448 ----a-w- C:\Windows\System32\drivers\usbfilter.sys
2012-10-29 20:34:27 -------- d-sh--w- C:\Windows\Installer
2012-10-29 20:34:22 -------- d-----w- C:\Program Files\ATI Technologies
2012-10-29 20:34:20 -------- d-----w- C:\Program Files\ATI
2012-10-29 20:23:35 1659760 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2012-10-29 20:22:56 142336 ----a-w- C:\Windows\System32\poqexec.exe
2012-10-29 20:20:41 950128 ----a-w- C:\Windows\System32\drivers\ndis.sys
2012-10-29 20:19:56 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2012-10-29 20:17:28 -------- d-----w- C:\Windows\SysWow64\sda
2012-10-29 20:17:03 9887848 ----a-w- C:\Windows\SysWow64\RtsUStoricon.dll
2012-10-29 20:17:03 422504 ----a-w- C:\Windows\System32\RtsUStor.dll
2012-10-29 20:17:03 251496 ----a-w- C:\Windows\System32\drivers\RtsUStor.sys
2012-10-29 20:14:57 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
2012-10-29 20:13:49 956928 ----a-w- C:\Windows\System32\localspl.dll
2012-10-29 19:59:27 9291768 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-10-29 19:57:12 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-10-29 19:57:12 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-10-29 19:57:11 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-10-29 19:53:14 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-10-29 19:53:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-10-29 19:52:47 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-10-29 19:52:47 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-10-29 19:50:24 1077760 ----a-w- C:\Windows\System32\drivers\AGUx64.sys
2012-10-29 19:47:03 -------- d-----w- C:\Users\tony\AppData\Local\VirtualStore
.
==================== Find3M ====================
.
2012-09-14 19:19:29 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-09-14 18:28:53 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-09-12 20:07:44 58368 ----a-w- C:\Windows\SysWow64\sirenacm.dll
2012-08-30 18:03:45 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-08-30 17:12:02 3968880 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12:02 3914096 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-08-24 18:05:07 220160 ----a-w- C:\Windows\System32\wintrust.dll
2012-08-24 16:57:48 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-08-22 18:12:50 1913200 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-08-22 18:12:40 376688 ----a-w- C:\Windows\System32\drivers\netio.sys
2012-08-22 18:12:33 288624 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2012-08-21 21:01:00 245760 ----a-w- C:\Windows\System32\OxpsConverter.exe
2012-08-20 18:48:44 362496 ----a-w- C:\Windows\System32\wow64win.dll
2012-08-20 18:48:44 243200 ----a-w- C:\Windows\System32\wow64.dll
2012-08-20 18:48:44 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2012-08-20 18:48:43 215040 ----a-w- C:\Windows\System32\winsrv.dll
2012-08-20 18:48:37 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2012-08-20 18:48:35 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2012-08-20 18:46:22 338432 ----a-w- C:\Windows\System32\conhost.exe
2012-08-20 17:40:21 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-08-20 17:38:44 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2012-08-20 17:38:26 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2012-08-20 17:37:19 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2012-08-20 17:37:18 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2012-08-20 15:38:21 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2012-08-20 15:38:20 2048 ----a-w- C:\Windows\SysWow64\user.exe
2012-08-20 15:33:28 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-08-20 15:33:28 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-08-20 15:33:28 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-08-20 15:33:28 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
.
============= FINISH: 2:04:04.13 ===============