DDS:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64 NETWORK
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_29
Run by Job der Kinderen at 10:55:32 on 2012-06-26
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3963.3258 [GMT 2:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Users\JOBDER~1\Desktop\Cleaning\Spybot - Search & Destroy\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
uRun: [TBPanel] C:\Program Files (x86)\Vtune\TBPanel.exe /A
uRun: [Facebook Update] "C:\Users\Job der Kinderen\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
uRun: [SpybotSD TeaTimer] C:\Users\Job der Kinderen\Desktop\Cleaning\Spybot - Search & Destroy\TeaTimer.exe
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [ThreatFire] C:\Users\Job der Kinderen\Desktop\Cleaning\ThreatFire\TFTray.exe
StartupFolder: C:\Users\JOBDER~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Job der Kinderen\AppData\Roaming\Dropbox\bin\Dropbox.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: &Verzenden naar OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: E&xporteren naar Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Users\JOBDER~1\Desktop\Cleaning\Spybot - Search & Destroy\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.1 8.8.8.8 8.8.4.4
TCP: Interfaces\{291712B0-5C29-4A10-B733-CFBE89962186} : DhcpNameServer = 192.168.1.1 8.8.8.8 8.8.4.4
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\Skype4COM.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Users\JOBDER~1\Desktop\Cleaning\Spybot - Search & Destroy\SDHelper.dll
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
mRun-x64: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
mRun-x64: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun-x64: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun-x64: [ThreatFire] C:\Users\Job der Kinderen\Desktop\Cleaning\ThreatFire\TFTray.exe
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Job der Kinderen\AppData\Roaming\Mozilla\Firefox\Profiles\6t98svv1.default\
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll
FF - plugin: C:\Users\Job der Kinderen\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF - plugin: C:\Users\Job der Kinderen\AppData\Local\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Users\Job der Kinderen\AppData\Roaming\Mozilla\Firefox\Profiles\6t98svv1.default\extensions\
DeviceDetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
.
============= SERVICES / DRIVERS ===============
.
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-12 140672]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
S1 AppleCharger;AppleCharger;C:\Windows\system32\DRIVERS\AppleCharger.sys --> C:\Windows\system32\DRIVERS\AppleCharger.sys [?]
S1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
S1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
S1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
S1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
S2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
S2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
S2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-6-18 44768]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 DES2 Service;DES2 Service for Energy Saving.;C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [2010-10-1 68136]
S2 gupdate;Google Updateservice (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-8 135664]
S2 MBAMService;MBAMService;C:\Users\Job der Kinderen\Desktop\Cleaning\Malwarebytes' Anti-Malware\mbamservice.exe [2012-6-18 654408]
S2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-9-13 2214504]
S2 SBSDWSCService;SBSD Security Center Service;C:\Users\Job der Kinderen\Desktop\Cleaning\Spybot - Search & Destroy\SDWinSec.exe [2012-6-19 1153368]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-4-5 158856]
S2 Smart TimeLock;Smart TimeLock Service;C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe [2010-10-1 114688]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-1-20 378984]
S2 ThreatFire;ThreatFire;C:\Users\Job der Kinderen\Desktop\Cleaning\ThreatFire\TFService.exe service --> C:\Users\Job der Kinderen\Desktop\Cleaning\ThreatFire\TFService.exe service [?]
S2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-10-1 2320920]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-5-22 257696]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
S3 etdrv;etdrv;C:\Windows\etdrv.sys [2010-10-1 25640]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-12-8 1315592]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-8 135664]
S3 GVTDrv64;GVTDrv64;C:\Windows\GVTDrv64.sys [2010-10-1 30528]
S3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
S3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\system32\DRIVERS\lvrs64.sys --> C:\Windows\system32\DRIVERS\lvrs64.sys [?]
S3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 31125880]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2012-06-26 08:40:15 9013136 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{82827488-20D5-40EB-8A09-21BB7D7E2A8A}\mpengine.dll
2012-06-26 08:30:54 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{D672AFF4-4337-407E-926D-0A99B1EEE53C}
2012-06-26 08:29:13 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{EF40F944-B46C-45E5-A293-11DCC1EA2DCC}
2012-06-26 07:53:07 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{AB14867C-8B7E-4DDB-927E-8409FAB8DAC8}
2012-06-26 07:52:52 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{C0CD00A8-8E72-4CF1-9C14-81E48BC1A990}
2012-06-25 17:40:53 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{D4889851-82D4-4DAE-B21B-EB0D0CA1C694}
2012-06-25 17:40:41 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{D90B9709-BCD9-4D23-A3FB-ABDAAD595471}
2012-06-25 17:25:22 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{D64EEF56-A8A6-4BE9-AB20-1AF9226C3FDB}
2012-06-25 17:25:10 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{B863EFB1-B8B8-4698-8271-BDC85D8C30BF}
2012-06-25 14:31:18 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{CB337A44-853A-4FED-A074-F540FCFBA86F}
2012-06-25 14:31:06 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{4C8F61A2-B8CA-475D-B350-83F7004DB5B7}
2012-06-25 05:55:13 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{EA1A12DD-0507-46FF-A2D6-37DF5C02D2D4}
2012-06-25 05:55:00 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{2506B82E-0900-420A-AC4F-36572C75BD2C}
2012-06-24 09:36:24 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{9C07E09C-FDB2-44BB-9449-383DAF69987C}
2012-06-24 07:30:52 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{1B7099A8-A706-44F0-B70D-5716454A0742}
2012-06-24 07:30:40 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{7C807792-E340-42F9-818B-0278E3B8EE17}
2012-06-24 07:19:29 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{72D61257-CDDC-4FBE-AEAC-4893B0470221}
2012-06-24 07:19:17 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{FAD23B71-D75C-4220-A1ED-0E97C6FA69DF}
2012-06-24 06:11:15 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{4CADD0B8-A9CD-4A57-A673-C0DF4979EAF2}
2012-06-24 06:11:03 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{335FF896-1521-4E7D-91E8-983E745B98AD}
2012-06-23 17:07:19 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{450C2602-2CBE-4808-98AF-C8E271B42369}
2012-06-23 17:07:08 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{29663E22-B97B-4D1A-B549-3D18A6287A08}
2012-06-23 16:54:29 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{154F4AF6-C2C1-4397-96D4-B79629F6B4E0}
2012-06-23 16:54:07 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{8F2D57EC-2B14-4DFA-AD0C-FA456DA6B4A8}
2012-06-23 16:16:48 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{A1B9E899-1E85-492D-91CD-CE04DEFD85CE}
2012-06-23 16:16:35 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{AB5E2DB3-2A3C-4C97-AEDC-22A8D93DA9E2}
2012-06-23 07:08:38 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{E76D7981-D61E-4267-A698-5832189F345B}
2012-06-23 07:08:26 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{BB264797-B386-40ED-92D7-897494A1F3DD}
2012-06-22 17:35:10 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{299D6F13-5C00-40B7-982F-52715EEE695C}
2012-06-22 17:34:58 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{68E94815-3AE1-4C4B-9337-7EA1EDF6AD5F}
2012-06-22 14:41:47 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{BBBCE876-BFF1-4E59-8FDA-8323112E39D3}
2012-06-22 14:41:34 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{6BCD5955-2AFC-4CC9-A5F1-B87BA6F6F6FF}
2012-06-22 06:21:16 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{3EDA3542-6BA3-4449-B0E0-F7E7044126CF}
2012-06-22 06:21:00 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{F93B3A9D-5F8A-4BB4-8F86-342372950AD4}
2012-06-21 15:18:49 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{910E51BC-3E76-489A-A39D-0B5A23971146}
2012-06-21 15:18:38 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{62B6E66B-AEC3-4C95-8865-5C7092917000}
2012-06-21 05:24:19 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{7FA44E26-DACC-486C-B5B8-0E4BE41D864A}
2012-06-21 05:24:05 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{03BA5D29-82E4-4EF4-9CFB-9705537B16D5}
2012-06-20 21:35:46 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{694D2294-434F-4D35-BCDE-CC40D626DD76}
2012-06-20 21:35:31 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{E06A6C63-2AD5-4071-95F5-255157526AB2}
2012-06-20 05:57:35 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{B8E4B885-65DC-494A-A534-617606AC8E1B}
2012-06-20 05:57:16 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{31E61343-CD81-4E9A-AC84-BFEF6EE84AE6}
2012-06-20 05:54:27 9013136 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-06-19 18:50:16 74824 ----a-w- C:\Windows\System32\drivers\TfSysMon.sys
2012-06-19 18:50:16 65072 ----a-w- C:\Windows\System32\drivers\TfFsMon.sys
2012-06-19 18:50:16 41888 ----a-w- C:\Windows\System32\drivers\TfNetMon.sys
2012-06-19 18:50:15 -------- d-----w- C:\ProgramData\PC Tools
2012-06-19 18:00:17 -------- d-----w- C:\Users\Job der Kinderen\DoctorWeb
2012-06-19 16:52:04 -------- d-----w- C:\Users\Job der Kinderen\AppData\Roaming\SUPERAntiSpyware.com
2012-06-19 16:51:53 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2012-06-19 16:51:53 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2012-06-19 16:24:09 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2012-06-18 20:11:15 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{A9E3B292-07B3-48CD-BD08-9AE308903B51}
2012-06-18 19:55:38 -------- d-----w- C:\Users\Job der Kinderen\AppData\Roaming\Malwarebytes
2012-06-18 19:55:34 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-06-18 19:55:34 -------- d-----w- C:\ProgramData\Malwarebytes
2012-06-18 17:09:22 53080 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2012-06-18 17:09:21 819032 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2012-06-18 17:09:17 69976 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2012-06-18 17:08:33 41184 ----a-w- C:\Windows\avastSS.scr
2012-06-18 17:08:23 -------- d-----w- C:\ProgramData\AVAST Software
2012-06-18 17:08:23 -------- d-----w- C:\Program Files\AVAST Software
2012-06-18 05:17:12 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{83F0F012-1D90-4E88-A8C3-93B04B48F4C0}
2012-06-17 15:50:32 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{F3456F1D-377B-4C89-8636-DF3612508750}
2012-06-15 08:02:32 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{1ABAB431-C325-4B8C-8363-1DF1AC3BB88F}
2012-06-14 05:55:42 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{9A8EDC63-D8E9-44A2-AD5F-2E615910D5B9}
2012-06-14 05:55:29 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{D743F3B2-F84C-4EE1-AE37-6D507BEFC52F}
2012-06-13 06:06:06 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-06-13 06:06:06 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-06-13 06:06:06 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-06-13 05:57:57 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{9E456BCF-2DAF-4689-91FB-3CC457829BEF}
2012-06-13 05:57:45 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{3F1C778F-683F-4584-8A7B-FE8535213E8F}
2012-06-12 06:00:14 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{BD4B2F4A-2022-471F-937F-E3A931FD7EE8}
2012-06-12 06:00:02 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{0BE1C546-5079-450B-AD7D-30E8958EE0B2}
2012-06-11 05:52:41 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{A2F7AA8C-0E0E-4AA8-96F7-1E106B049C38}
2012-06-11 05:52:29 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{46B9B157-9C40-4EDF-B6E7-8C93495A73D2}
2012-06-10 11:28:17 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{44405AAB-3989-4549-A632-1A9F90F8B2C5}
2012-06-10 11:28:05 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{600ACFEB-6BED-4238-BCBA-1B70EB6A01B3}
2012-06-09 11:06:37 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{2FCCC962-B79D-4A8C-BB38-4E47B6EDADD4}
2012-06-09 11:06:25 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{13D14F29-149B-4625-8F3C-F9EBFB0A9963}
2012-06-09 01:36:09 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-09 01:35:54 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-09 01:35:40 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-09 01:35:40 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-08 17:38:56 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{DEB93950-2B4B-4198-BDBD-7CC235AA4338}
2012-06-08 17:38:44 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{F1A2AFEE-B32A-4F34-9655-BAE97DFC4B92}
2012-06-08 05:47:16 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{9CFF3EED-0C6B-49E8-875E-26C0AE93F12A}
2012-06-08 05:47:04 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{34642675-C7FE-4EA2-BD37-64F64CCBEFAF}
2012-06-07 15:08:13 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{76D84811-78C0-4F4A-B05D-48A4A26A4CB2}
2012-06-07 15:07:59 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{C95664EE-E196-493E-A056-3978CE504860}
2012-06-07 05:51:40 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{96B7A69B-4EBE-4390-B25F-07F113831DE2}
2012-06-07 05:51:24 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{A6F65DF4-BAAC-4495-AF3E-8C8C0CAA8B7E}
2012-06-06 06:32:05 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{B483F667-ED80-42DC-B918-8ED76DFE5E0A}
2012-06-06 06:31:53 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{5B57DBB1-98CF-4CF5-A13D-B88F4C7BA8AA}
2012-06-05 05:02:41 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{6164906A-27A8-40FA-9F72-EED39331A3B5}
2012-06-05 05:02:28 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{5CFBC3B5-D5E4-4CEC-96B0-D8D26DB59F2F}
2012-06-04 05:32:35 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{F0B1115F-9A55-469D-A0F2-238976259095}
2012-06-04 05:32:23 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{FEAF9C77-300C-4DDE-BCDC-2E89160BE0D0}
2012-06-03 09:28:29 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{8CBF2003-544B-429C-834D-510944C5A274}
2012-06-03 09:28:16 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{58116E21-9659-4EFD-A988-729E6649F042}
2012-06-02 10:08:25 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{231F2F70-0053-4C37-AA0B-16BA4CE33BFB}
2012-06-02 10:08:14 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{B4DF299B-BB57-462F-BEE6-1EDAD6174C26}
2012-06-02 07:36:39 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{C2E971A7-E03D-44EE-AE27-04DC7F8CA64C}
2012-06-02 07:36:25 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{7D58B23D-39E8-4602-A97C-C1364BFC6820}
2012-06-01 05:57:50 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{E8EF04B5-7F0A-459D-8732-27D0986A5D22}
2012-06-01 05:57:37 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{FA2E4059-BE1A-45B3-A6BC-F3E702A38645}
2012-05-31 05:48:23 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{410EC1D3-6830-4125-BF57-68C1B7CDBF23}
2012-05-31 05:48:09 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{D2737C0C-DBAF-4DAF-8F0B-5BB13B59AB9A}
2012-05-30 05:49:36 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{0D1C87DF-92F1-4C98-9A7B-FE527477FA2F}
2012-05-30 05:49:22 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{9B29476A-CC4A-44C7-AB68-028088FF7DD9}
2012-05-29 05:50:38 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{EE1CF24F-F997-4F01-8A70-59BBC66B6698}
2012-05-29 05:50:26 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{3B880AAE-7331-4E69-B0E3-8170719DE674}
2012-05-28 05:39:20 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{1DAFA5E4-56B8-49AF-B26C-DDF97D9E9B51}
2012-05-28 05:39:08 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{28FFD7E6-6509-4F1B-A69D-90201F66E1CF}
2012-05-27 10:44:03 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{23CE778E-B3CB-4EB6-977C-9868403761B7}
2012-05-27 10:43:50 -------- d-----w- C:\Users\Job der Kinderen\AppData\Local\{0B79D3B2-9780-4B4A-AAF5-04A72CC561B8}
.
==================== Find3M ====================
.
2012-06-26 08:28:03 25640 ----a-w- C:\Windows\gdrv.sys
2012-05-22 06:05:21 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-22 06:05:21 419488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-15 04:01:31 1188864 ----a-w- C:\Windows\System32\wininet.dll
2012-05-15 03:03:54 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-05-15 01:32:33 3146752 ----a-w- C:\Windows\System32\win32k.sys
2012-05-04 11:06:22 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll
2012-04-28 05:32:05 1112064 ----a-w- C:\Windows\System32\rdpcorets.dll
2012-04-28 03:55:21 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-24 05:37:37 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2012-04-24 05:37:37 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2012-04-24 05:37:36 1462272 ----a-w- C:\Windows\System32\crypt32.dll
2012-04-24 04:36:42 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-04-24 04:36:42 1158656 ----a-w- C:\Windows\SysWow64\crypt32.dll
2012-04-24 04:36:42 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2012-04-20 03:45:41 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2012-04-20 03:16:44 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-04-07 12:31:40 3216384 ----a-w- C:\Windows\System32\msi.dll
2012-04-07 11:26:29 2342400 ----a-w- C:\Windows\SysWow64\msi.dll
2012-03-30 11:35:47 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys
.
============= FINISH: 10:56:15,63 ===============