needhelp51
Posts: 368 +0
Hello,
I recently installed win7 and everything was fine up til today. All certificates in all browser seem wrong, my browser suggest I might be being hacked. Windows update worked fine, but impossible since this morning. Also, two Toshiba drivers show as unknown origin even though they were downloaded from Toshiba site and worked fine before today. Computer is suddenly sluggish also. I suspect something is going on.
Here are the logs:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2006-07-01
Scan Time: 02:33:06
Logfile: Log MBAM.txt
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.04.06.09
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Admin
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 212294
Time Elapsed: 22 min, 12 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 2
PUP.Optional.BundleInstaller, C:\$Recycle.Bin\S-1-5-21-811221372-2198457851-1441504835-1000\$RYUI9P4.exe, Quarantined, [e83969beec8f2d09d9761651827f5ea2],
PUP.Optional.BundleInstaller, C:\Windows\Temp\_avast_\ws1673.dat, Quarantined, [be636dba5c1f8aacdc73df88b9483bc5],
Physical Sectors: 0
(No malicious items detected)
(end)
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.16521 BrowserJavaVersion: 10.51.2
Run by Admin at 2:34:43 on 2006-07-01
Microsoft Windows 7 Professionnel 6.1.7601.1.1252.1.1036.18.3070.1774 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: COMODO Antivirus *Disabled/Outdated* {0C2D2636-923D-EE52-2A83-E643204A8275}
FW: COMODO Firewall *Enabled* {8F7746F7-FE68-E084-3B6C-7404A51E8FB3}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Secunia\PSI\PSIA.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
c:\program files\windows defender\MpCmdRun.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
.
============== Pseudo HJT Report ===============
.
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AvastUI.exe] "c:\program files\avast software\avast\AvastUI.exe" /nogui
mRun: [COMODO Internet Security] c:\program files\comodo\comodo internet security\cistray.exe
mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [TPwrMain] c:\program files\toshiba\power saver\TPwrMain.EXE
mRun: [SmoothView] c:\program files\toshiba\smoothview\SmoothView.exe
mRun: [00TCrdMain] c:\program files\toshiba\flashcards\TCrdMain.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 47.55.55.55 142.166.166.166
TCP: Interfaces\{83A967BC-B179-4662-BC85-2206CCDD72C9} : DHCPNameServer = 47.55.55.55 142.166.166.166
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\33.0.1750.154\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\admin\appdata\roaming\mozilla\firefox\profiles\yk8py79e.default\
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.23.9\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [2014-4-4 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [2014-4-4 180760]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-4-4 776976]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-4-4 411552]
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [2014-3-25 20072]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2014-3-25 607168]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2014-3-25 43728]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-4-4 67824]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2014-4-4 50344]
R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2013-12-6 1229528]
R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-4-4 67264]
R3 netw5v32;Pilote de carte de liaison WiFi sans fil Intel(R) 5000 Series pour Windows Vista 32 bits;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-10-23 172192]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 cmdvirth;COMODO Virtual Service Manager;c:\program files\comodo\comodo internet security\cmdvirth.exe [2014-3-25 1663192]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2011-4-11 62464]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2014-4-3 108032]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf_x86.sys [2013-12-6 16024]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504]
S3 StorSvc;Service de stockage;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2014-4-3 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\wat\WatAdminSvc.exe [2014-4-3 1343400]
.
=============== Created Last 30 ================
.
2014-04-06 13:53:18 24576 ----a-w- c:\windows\system32\TSCI.dll
2014-04-06 13:53:18 24576 ----a-w- c:\windows\system32\THCI.dll
2014-04-05 19:49:01 -------- d-----w- c:\users\admin\appdata\roaming\OpenOffice
2014-04-05 17:03:10 -------- d-----w- c:\program files\EA GAMES
2014-04-05 17:01:42 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2014-04-05 17:01:42 225280 ----a-w- c:\program files\common files\installshield\iscript\iscript.dll
2014-04-05 17:01:42 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2014-04-05 17:01:41 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2014-04-05 14:19:56 107736 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-04-05 14:19:30 73432 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-04-05 14:19:30 51416 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-04-05 14:19:30 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-04-05 14:19:30 -------- d-----w- c:\programdata\Malwarebytes
2014-04-05 14:19:30 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2014-04-05 13:47:23 -------- d-----w- c:\programdata\Auslogics
2014-04-05 13:46:50 -------- d-----w- c:\program files\Auslogics
2014-04-05 13:36:06 -------- d-----w- c:\program files\Audacity
2014-04-05 13:31:10 -------- d-----w- c:\programdata\Oracle
2014-04-05 13:25:15 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2014-04-05 03:27:25 -------- d-----w- c:\users\admin\appdata\roaming\DonationCoder
2014-04-05 02:47:04 -------- d-----w- c:\programdata\DonationCoder
2014-04-05 02:47:03 -------- d-----w- c:\program files\ScreenshotCaptor
2014-04-05 02:46:50 -------- d-----w- c:\users\admin\appdata\local\Programs
2014-04-04 23:17:06 -------- d-----w- c:\program files\Synaptics
2014-04-04 23:14:16 430080 ----a-w- c:\windows\system32\TOSCDSPD.cpl
2014-04-04 23:12:49 32768 ----a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2014-04-04 23:12:48 729088 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iKernel.dll
2014-04-04 23:12:48 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\ctor.dll
2014-04-04 23:12:48 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\DotNetInstaller.exe
2014-04-04 23:12:48 266240 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iscript.dll
2014-04-04 23:12:48 192512 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iuser.dll
2014-04-04 23:12:47 311428 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\setup.dll
2014-04-04 23:12:47 188548 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iGdi.dll
2014-04-04 23:00:49 128344 ----a-w- c:\windows\system32\TODDSrv.exe
2014-04-04 23:00:39 -------- d-----w- c:\program files\TOSHIBA
2014-04-04 22:59:39 -------- d-----w- c:\users\admin\appdata\roaming\WinBatch
2014-04-04 22:17:22 -------- d-s---w- c:\programdata\Shared Space
2014-04-04 22:17:01 -------- d-----w- c:\program files\COMODO
2014-04-04 22:16:49 -------- d-----w- c:\programdata\Comodo Downloader
2014-04-04 22:13:29 -------- d-----w- c:\programdata\Comodo
2014-04-04 22:02:49 -------- d-----w- c:\users\admin\appdata\roaming\AVAST Software
2014-04-04 22:01:49 67264 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-04-04 22:01:44 180760 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-04-04 22:01:40 776976 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-04-04 22:01:37 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-04-04 22:01:34 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-04-04 22:01:32 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-04-04 22:01:19 43152 ----a-w- c:\windows\avastSS.scr
2014-04-04 21:58:34 -------- d-----w- c:\program files\AVAST Software
2014-04-04 21:57:11 -------- d-----w- c:\programdata\AVAST Software
2014-04-04 21:51:12 -------- d-----w- c:\users\admin\appdata\local\Secunia PSI
2014-04-04 21:50:58 -------- d-----w- c:\program files\Secunia
2014-04-04 21:49:30 7969936 ----a-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2014-04-04 21:49:23 7969936 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{86f4a052-cdea-46b7-88e4-279ec55a6db8}\mpengine.dll
2014-04-04 03:44:57 -------- d-----w- c:\users\admin\appdata\roaming\IrfanView
2014-04-04 03:44:56 -------- d-----w- c:\program files\IrfanView
2014-04-04 03:42:12 -------- d-----w- c:\users\admin\appdata\local\Adobe
2014-04-04 03:41:29 -------- d-----w- c:\program files\VideoLAN
2014-04-04 03:28:57 454656 ----a-w- c:\windows\system32\vbscript.dll
2014-04-04 03:23:46 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2014-04-04 03:23:17 3419136 ----a-w- c:\windows\system32\d2d1.dll
2014-04-04 03:23:17 1987584 ----a-w- c:\windows\system32\d3d10warp.dll
2014-04-04 03:15:52 -------- d-----w- c:\windows\system32\MRT
2014-04-04 03:07:38 32256 ----a-w- c:\windows\system32\TsUsbGDCoInstaller.dll
2014-04-04 03:07:28 12800 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-04-04 03:07:25 49152 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys
2014-04-04 03:07:22 855552 ----a-w- c:\windows\system32\rdvidcrl.dll
2014-04-04 03:07:22 76288 ----a-w- c:\windows\system32\TSWbPrxy.exe
2014-04-04 03:07:22 53248 ----a-w- c:\windows\system32\tsgqec.dll
2014-04-04 03:07:22 50176 ----a-w- c:\windows\system32\MsRdpWebAccess.dll
2014-04-04 03:07:22 350208 ----a-w- c:\windows\system32\wksprt.exe
2014-04-04 03:07:22 17920 ----a-w- c:\windows\system32\wksprtPS.dll
2014-04-04 03:07:22 14336 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-04-04 03:07:18 1068544 ----a-w- c:\windows\system32\mstsc.exe
2014-04-04 03:06:34 -------- d-----w- c:\program files\CONEXANT
2014-04-04 03:05:32 514560 ----a-w- c:\windows\system32\qdvd.dll
2014-04-04 03:05:29 792576 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-04-04 02:58:09 -------- d-----w- c:\windows\Migration
2014-04-04 02:48:04 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-04-04 02:48:04 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-04-04 02:47:55 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-04-04 02:47:55 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-04-04 02:47:53 613888 ----a-w- c:\windows\system32\WUDFx.dll
2014-04-04 02:47:53 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-04-04 02:47:53 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2014-04-04 02:41:02 -------- d-----w- c:\windows\system32\Wat
2014-04-04 02:29:54 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2014-04-04 02:29:53 164864 ----a-w- c:\program files\windows media player\wmplayer.exe
2014-04-04 02:02:03 5120 ----a-w- c:\windows\system32\wmi.dll
2014-04-04 02:02:03 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-04-04 02:00:39 -------- d-----w- c:\users\admin\appdata\local\Skype
2014-04-04 01:59:52 -------- d-----r- c:\program files\Skype
2014-04-04 01:55:17 46704 ----a-w- c:\program files\mozilla firefox\browser\components\browsercomps.dll
2014-04-04 01:52:59 75376 ----a-w- c:\program files\mozilla firefox\breakpadinjector.dll
2014-04-04 01:52:59 307824 ----a-w- c:\program files\mozilla firefox\freebl3.dll
2014-04-04 01:52:59 275568 ----a-w- c:\program files\mozilla firefox\firefox.exe
2014-04-04 01:52:59 2106216 ----a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll
2014-04-04 01:52:59 20080 ----a-w- c:\program files\mozilla firefox\AccessibleMarshal.dll
2014-04-04 01:52:59 117360 ----a-w- c:\program files\mozilla firefox\crashreporter.exe
2014-04-04 01:50:09 988672 ----a-w- c:\program files\windows journal\JNTFiltr.dll
2014-04-04 01:50:09 969216 ----a-w- c:\program files\windows journal\JNWDRV.dll
2014-04-04 01:50:09 936448 ----a-w- c:\program files\common files\microsoft shared\ink\journal.dll
2014-04-04 01:50:09 1221632 ----a-w- c:\program files\windows journal\NBDoc.DLL
2014-04-04 01:50:06 94208 ----a-w- c:\program files\common files\system\ole db\msdaosp.dll
2014-04-04 01:50:06 86016 ----a-w- c:\windows\system32\odbccu32.dll
2014-04-04 01:50:06 81920 ----a-w- c:\windows\system32\odbccr32.dll
2014-04-04 01:50:06 319488 ----a-w- c:\windows\system32\odbcjt32.dll
2014-04-04 01:50:06 122880 ----a-w- c:\windows\system32\odbccp32.dll
2014-04-04 01:50:05 163840 ----a-w- c:\windows\system32\odbctrac.dll
2014-04-04 01:41:36 1247744 ----a-w- c:\windows\system32\DWrite.dll
2014-04-04 01:41:30 2349056 ----a-w- c:\windows\system32\win32k.sys
2014-04-04 01:41:25 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2014-04-04 01:41:21 530432 ----a-w- c:\windows\system32\comctl32.dll
2014-04-04 01:41:16 626688 ----a-w- c:\windows\system32\usp10.dll
2014-04-04 01:41:12 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-04-04 01:41:09 55808 ----a-w- c:\windows\system32\drivers\hidclass.sys
2014-04-04 01:41:09 25728 ----a-w- c:\windows\system32\drivers\hidparse.sys
2014-04-04 01:41:06 652800 ----a-w- c:\windows\system32\rpcrt4.dll
2014-04-04 01:41:04 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2014-04-04 01:41:03 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2014-04-04 01:40:59 175104 ----a-w- c:\windows\system32\wintrust.dll
2014-04-04 01:40:46 1796096 ----a-w- c:\windows\system32\authui.dll
2014-04-04 01:40:45 152576 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll
2014-04-04 01:40:44 168960 ----a-w- c:\windows\system32\credui.dll
2014-04-04 01:40:11 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2014-04-04 01:39:50 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2014-04-04 01:39:50 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2014-04-04 01:39:50 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2014-04-04 01:39:47 376832 ----a-w- c:\windows\system32\dpnet.dll
2014-04-04 01:39:14 509440 ----a-w- c:\windows\system32\qedit.dll
2014-04-04 01:39:09 301568 ----a-w- c:\windows\system32\msieftp.dll
2014-04-04 01:39:05 196328 ----a-w- c:\windows\system32\drivers\fvevol.sys
2014-04-04 01:37:59 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2014-04-04 01:37:24 75776 ----a-w- c:\windows\system32\psisrndr.ax
2014-04-04 01:37:24 465408 ----a-w- c:\windows\system32\psisdecd.dll
2014-04-04 01:37:16 729024 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2014-04-04 01:37:16 218984 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2014-04-04 01:36:52 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2014-04-04 01:36:13 2048 ----a-w- c:\windows\system32\tzres.dll
2014-04-04 01:34:33 40960 ----a-w- c:\windows\system32\wwanprotdim.dll
2014-04-04 01:34:33 185344 ----a-w- c:\windows\system32\wwansvc.dll
2014-04-04 01:34:23 492544 ----a-w- c:\windows\system32\win32spl.dll
2014-04-04 01:34:14 1389568 ----a-w- c:\windows\system32\msxml6.dll
2014-04-04 01:34:03 295424 ----a-w- c:\windows\system32\atmfd.dll
2014-04-04 01:34:02 70656 ----a-w- c:\windows\system32\fontsub.dll
2014-04-04 01:34:02 34304 ----a-w- c:\windows\system32\atmlib.dll
2014-04-04 01:34:02 26112 ----a-w- c:\windows\system32\lpk.dll
2014-04-04 01:34:02 10240 ----a-w- c:\windows\system32\dciman32.dll
2014-04-04 01:33:48 434688 ----a-w- c:\windows\system32\scavengeui.dll
2014-04-04 01:32:54 903168 ----a-w- c:\windows\system32\certutil.exe
2014-04-04 01:32:52 43008 ----a-w- c:\windows\system32\certenc.dll
2014-04-04 01:32:01 52224 ----a-w- c:\windows\system32\nlaapi.dll
2014-04-04 01:32:01 499712 ----a-w- c:\windows\system32\iphlpsvc.dll
2014-04-04 01:32:01 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2014-04-04 01:32:01 242176 ----a-w- c:\windows\system32\nlasvc.dll
2014-04-04 01:32:01 175104 ----a-w- c:\windows\system32\netcorehc.dll
2014-04-04 01:32:01 156672 ----a-w- c:\windows\system32\ncsi.dll
2014-04-04 01:32:00 18944 ----a-w- c:\windows\system32\netevent.dll
2014-04-04 01:31:33 102608 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-04-04 01:29:23 680960 ----a-w- c:\program files\windows defender\MpSvc.dll
2014-04-04 01:29:23 392704 ----a-w- c:\program files\windows defender\MpClient.dll
2014-04-04 01:29:23 224768 ----a-w- c:\program files\windows defender\MpCommu.dll
2014-04-04 01:28:33 41984 ----a-w- c:\windows\system32\browcli.dll
2014-04-04 01:28:33 102912 ----a-w- c:\windows\system32\browser.dll
2014-04-04 01:25:21 805376 ----a-w- c:\windows\system32\cdosys.dll
2014-04-04 01:25:21 352256 ----a-w- c:\program files\common files\system\ado\msadomd.dll
2014-04-04 01:25:21 1019904 ----a-w- c:\program files\common files\system\ado\msado15.dll
2014-04-04 01:25:20 57344 ----a-w- c:\program files\common files\system\ado\msador15.dll
2014-04-04 01:25:20 372736 ----a-w- c:\program files\common files\system\ado\msadox.dll
2014-04-04 01:25:20 212992 ----a-w- c:\program files\common files\system\msadc\msadco.dll
2014-04-04 01:25:20 143360 ----a-w- c:\program files\common files\system\ado\msjro.dll
2014-04-04 01:25:15 400896 ----a-w- c:\windows\system32\srcore.dll
2014-04-04 01:25:12 1620992 ----a-w- c:\windows\system32\WMVDECOD.DLL
2014-04-04 01:25:10 1328128 ----a-w- c:\windows\system32\quartz.dll
2014-04-04 01:24:56 81408 ----a-w- c:\windows\system32\drivers\drmk.sys
2014-04-04 01:24:56 177152 ----a-w- c:\windows\system32\drivers\portcls.sys
2014-04-04 01:24:53 850944 ----a-w- c:\windows\system32\sbe.dll
2014-04-04 01:24:53 642048 ----a-w- c:\windows\system32\CPFilters.dll
2014-04-04 01:24:53 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2014-04-04 01:24:12 542208 ----a-w- c:\windows\system32\kerberos.dll
2014-04-04 01:15:48 31232 ----a-w- c:\windows\system32\prevhost.exe
2014-04-04 01:11:10 708608 ----a-w- c:\program files\common files\system\wab32.dll
2014-04-04 01:09:54 478720 ----a-w- c:\windows\system32\timedate.cpl
2014-04-04 01:09:46 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2014-04-04 01:09:42 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2014-04-04 01:09:42 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2014-04-04 01:09:42 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2014-04-04 01:09:39 741376 ----a-w- c:\windows\system32\inetcomm.dll
2014-04-04 01:09:35 67072 ----a-w- c:\windows\system32\packager.dll
2014-04-04 01:09:31 2342400 ----a-w- c:\windows\system32\msi.dll
2014-04-04 01:06:37 314880 ----a-w- c:\windows\system32\webio.dll
2014-04-04 01:05:58 240576 ----a-w- c:\windows\system32\drivers\netio.sys
2014-04-04 01:05:48 78336 ----a-w- c:\windows\system32\synceng.dll
2014-04-04 01:05:26 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2014-04-04 01:05:26 231424 ----a-w- c:\windows\system32\mswsock.dll
2014-04-04 01:05:26 187752 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2014-04-04 01:05:26 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-04-04 01:04:58 133056 ----a-w- c:\windows\system32\drivers\ataport.sys
2014-04-04 01:04:37 679424 ----a-w- c:\windows\system32\IKEEXT.DLL
2014-04-04 01:04:36 656896 ----a-w- c:\windows\system32\nshwfp.dll
2014-04-04 01:04:36 216576 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2014-04-04 01:04:23 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2014-04-04 01:04:23 193536 ----a-w- c:\windows\system32\dhcpcore6.dll
2014-04-04 01:03:32 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2014-04-04 01:03:32 1168384 ----a-w- c:\windows\system32\crypt32.dll
2014-04-04 01:03:31 103936 ----a-w- c:\windows\system32\cryptnet.dll
2014-04-04 01:02:08 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys
2014-04-04 00:59:51 381440 ----a-w- c:\windows\system32\wer.dll
2014-04-04 00:59:31 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2014-04-04 00:59:31 1137664 ----a-w- c:\windows\system32\mfc42.dll
2014-04-04 00:57:21 293376 ----a-w- c:\windows\system32\umpnpmgr.dll
2014-04-04 00:57:01 571904 ----a-w- c:\windows\system32\oleaut32.dll
2014-04-04 00:57:01 233472 ----a-w- c:\windows\system32\oleacc.dll
2014-04-04 00:53:51 86528 ----a-w- c:\windows\system32\SearchFilterHost.exe
2014-04-04 00:53:51 666624 ----a-w- c:\windows\system32\mssvp.dll
2014-04-04 00:53:51 427520 ----a-w- c:\windows\system32\SearchIndexer.exe
2014-04-04 00:53:51 337408 ----a-w- c:\windows\system32\mssph.dll
2014-04-04 00:53:51 164352 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2014-04-04 00:53:51 1549312 ----a-w- c:\windows\system32\tquery.dll
2014-04-04 00:53:51 1401344 ----a-w- c:\windows\system32\mssrch.dll
2014-04-04 00:53:50 59392 ----a-w- c:\windows\system32\msscntrs.dll
2014-04-04 00:53:50 197120 ----a-w- c:\windows\system32\mssphtb.dll
2014-04-04 00:51:13 534528 ----a-w- c:\windows\system32\EncDec.dll
2014-04-04 00:34:24 -------- d-----w- c:\program files\OpenOffice 4
2014-04-04 00:33:04 49152 ----a-w- c:\windows\system32\taskhost.exe
2014-04-04 00:32:57 690688 ----a-w- c:\windows\system32\msvcrt.dll
2014-04-04 00:32:08 164352 ----a-w- c:\windows\system32\profsvc.dll
2014-04-04 00:24:45 769024 ----a-w- c:\windows\system32\localspl.dll
2014-04-04 00:24:35 1505280 ----a-w- c:\windows\system32\d3d11.dll
2014-04-04 00:24:31 442880 ----a-w- c:\windows\system32\ntshrui.dll
2014-04-04 00:12:43 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2014-04-04 00:12:21 123904 ----a-w- c:\windows\system32\poqexec.exe
2014-04-04 00:12:18 9728 ----a-w- c:\windows\system32\Wdfres.dll
2014-04-04 00:12:18 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2014-04-04 00:12:18 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2014-04-04 00:12:08 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2014-04-04 00:12:03 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-04-04 00:12:03 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-04-04 00:12:03 43520 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-04-04 00:12:03 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-04-04 00:12:03 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-04-04 00:12:03 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-04-04 00:04:00 -------- d-----w- c:\windows\system32\wbem\en-US
2014-04-04 00:03:15 -------- d-----w- c:\program files\mp3DirectCut
2014-04-04 00:00:12 -------- d-----w- c:\program files\CCleaner
2014-04-03 23:45:05 101720 ----a-w- c:\windows\system32\consent.exe
2014-04-03 23:45:04 47104 ----a-w- c:\windows\system32\appinfo.dll
2014-04-03 23:40:12 -------- d-sh--w- c:\windows\Installer
2014-04-03 23:39:16 231584 ------w- c:\windows\system32\MpSigStub.exe
2014-04-03 23:37:28 826880 ----a-w- c:\windows\system32\rdpcore.dll
2014-04-03 23:37:28 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2014-04-03 23:34:22 -------- d-----w- c:\users\admin\appdata\local\Google
2014-04-03 23:33:40 -------- d-----w- c:\users\admin\appdata\local\Apps
2014-04-03 23:33:38 -------- d-----w- c:\users\admin\appdata\local\Deployment
2014-04-03 23:22:27 33792 ----a-w- c:\windows\system32\wuapp.exe
2014-04-03 23:22:27 171904 ----a-w- c:\windows\system32\wuwebv.dll
2014-04-03 23:22:24 2422272 ----a-w- c:\windows\system32\wucltux.dll
2014-04-03 23:21:44 88576 ----a-w- c:\windows\system32\wudriver.dll
2014-04-03 02:35:23 -------- d-sh--w- C:\Boot
2014-04-02 23:21:03 -------- d-----w- C:\Bureau2014
2014-04-02 21:54:03 -------- d-----w- c:\windows\Panther
2014-04-02 21:40:01 -------- d-----w- C:\Windows.old
2014-03-26 00:22:50 43728 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2014-03-26 00:22:48 607168 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2014-03-26 00:22:48 20072 ----a-w- c:\windows\system32\drivers\cmderd.sys
2014-03-26 00:22:38 363504 ----a-w- c:\windows\system32\guard32.dll
2014-03-26 00:22:38 36000 ----a-w- c:\windows\system32\cmdcsr.dll
2014-03-26 00:22:26 284888 ----a-w- c:\windows\system32\cmdvrt32.dll
2014-03-26 00:22:24 40664 ----a-w- c:\windows\system32\cmdkbd32.dll
2014-03-08 00:51:40 -------- d-----w- C:\Intel
2013-12-29 22:08:29 -------- d-----w- C:\Python27
2013-12-29 21:59:44 -------- d-----w- C:\Python33
2013-12-06 14:47:12 16024 ----a-w- c:\windows\system32\drivers\psi_mf_x86.sys
2013-09-12 01:21:54 863344 ----a-w- c:\windows\system32\msvcr110_clr0400.dll
2013-09-12 01:21:54 501872 ----a-w- c:\windows\system32\msvcp110_clr0400.dll
2013-09-12 01:21:54 28776 ----a-w- c:\windows\system32\aspnet_counters.dll
2013-09-12 01:21:54 18000 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2013-08-22 02:32:42 -------- d-sha-r- C:\cmdcons
2013-06-09 19:44:59 -------- d-----w- C:\Ancien Disque
2013-05-18 20:44:20 -------- d--h--w- C:\VTRoot
2013-05-12 15:13:10 -------- d-----w- C:\97317ce748271ca34c4e3f38a69f021d
2013-05-12 14:51:02 -------- d-----w- C:\Mes Affaires
2013-05-11 22:46:35 -------- d-----w- C:\4996927265dc45c02c01
2013-04-29 03:19:31 -------- d-----w- c:\program files\ImpotRapide 2007
2013-04-29 03:18:44 -------- d-----w- c:\program files\ImpotRapide 2012
2013-04-29 03:18:37 -------- d-----w- c:\program files\ImpotRapide 2010
2013-04-29 03:18:29 -------- d-----w- c:\program files\ImpotRapide 2009
2013-04-29 03:18:23 -------- d-----w- c:\program files\ImpotRapide 2008
2011-04-19 08:47:04 670032 ----a-w- c:\program files\common files\microsoft shared\vc\msdia90.dll
2011-04-12 01:45:14 -------- d-----w- c:\program files\Windows Journal
2011-04-12 01:45:07 -------- d-----w- c:\windows\ShellNew
2011-04-12 01:45:07 -------- d-----w- c:\windows\ehome
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\XPSViewer
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\winrm
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\WCN
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\slmgr
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\Printing_Admin_Scripts
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\fr
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\drivers\umdf\fr-FR
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\drivers\fr-FR
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\040C
2011-04-12 01:35:38 -------- d-----w- c:\windows\fr-FR
2011-04-12 01:35:38 -------- d-----w- c:\windows\DigitalLocker
2011-04-12 01:35:37 -------- d-----w- c:\windows\system32\wbem\fr-FR
2011-04-12 01:35:19 3584 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\fr-fr\LXKPTPRC.DLL.mui
2011-02-20 03:03:12 421200 ----a-w- c:\windows\system32\msvcp100.dll
2011-02-19 04:40:50 773968 ----a-w- c:\windows\system32\msvcr100.dll
2010-11-20 21:00:53 -------- d-----w- c:\windows\system32\wbem\Performance
2009-07-30 21:45:56 22912 ----a-w- c:\windows\system32\drivers\tdcmdpst.sys
2009-07-14 19:28:42 23512 ----a-w- c:\windows\system32\drivers\TVALZ_O.SYS
2009-07-14 04:53:55 -------- d-sh--we C:\Documents and Settings
2009-07-14 04:53:50 -------- d-----w- c:\windows\system32\wbem\mof\good
2009-07-14 04:53:50 -------- d-----w- c:\windows\system32\wbem\mof\bad
2009-07-14 04:41:11 -------- d-----w- c:\windows\system32\wbem\MOF
2009-07-14 04:34:16 -------- d-----w- c:\windows\Setup
2009-07-14 04:34:13 -------- d-----w- c:\windows\ServiceProfiles
2009-07-14 04:34:06 -------- d-s---w- c:\windows\system32\Microsoft
.
==================== Find3M ====================
.
2014-04-04 23:15:55 1060424 ----a-w- c:\windows\system32\WdfCoInstaller01000.dll
2014-04-04 23:15:49 143360 ----a-w- c:\windows\system32\SynTPAPI.dll
2014-04-04 23:15:49 110592 ----a-w- c:\windows\system32\SynTPCo4.dll
2014-04-04 23:15:48 179896 ----a-w- c:\windows\system32\drivers\SynTP.sys
2014-04-04 23:15:47 196608 ----a-w- c:\windows\system32\SynCtrl.dll
2014-04-04 23:15:46 163840 ----a-w- c:\windows\system32\SynCOM.dll
2014-04-04 22:54:28 172032 ----a-w- c:\windows\system32\UCI32114.dll
2014-04-04 22:54:27 61952 ----a-w- c:\windows\system32\CHDAudPropShortcut.exe
2014-04-04 22:54:26 566272 ----a-w- c:\windows\system32\drivers\CHDAud.sys
2014-04-04 22:54:26 5120 ----a-w- c:\windows\system32\CHdAudPropres.dll
2014-04-04 22:54:26 24064 ----a-w- c:\windows\system32\CHdAudprop.dll
2014-04-04 01:06:14 69632 ----a-w- c:\windows\system32\smss.exe
2014-04-04 01:06:14 640512 ----a-w- c:\windows\system32\advapi32.dll
2014-04-04 01:06:14 619520 ----a-w- c:\windows\system32\tdh.dll
2014-04-04 01:06:14 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2014-04-04 01:06:14 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe
2014-04-04 01:06:14 38912 ----a-w- c:\windows\system32\csrsrv.dll
2014-04-04 01:06:14 1289096 ----a-w- c:\windows\system32\ntdll.dll
2014-03-01 04:11:20 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-03-01 04:10:48 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-03-01 03:52:43 61952 ----a-w- c:\windows\system32\iesetup.dll
2014-03-01 03:51:53 51200 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-03-01 03:38:26 112128 ----a-w- c:\windows\system32\ieUnatt.exe
2014-03-01 03:38:23 108032 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-03-01 03:37:35 553472 ----a-w- c:\windows\system32\jscript9diag.dll
2014-03-01 03:31:30 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-03-01 03:14:15 4244480 ----a-w- c:\windows\system32\jscript9.dll
2014-03-01 03:00:08 1964032 ----a-w- c:\windows\system32\inetcpl.cpl
2014-03-01 02:32:16 1820160 ----a-w- c:\windows\system32\wininet.dll
2014-02-04 02:04:22 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-01-09 02:22:42 5694464 ----a-w- c:\windows\system32\mstscax.dll
2013-12-06 02:02:08 2048 ----a-w- c:\windows\system32\msxml3r.dll
2013-12-06 02:02:08 1237504 ----a-w- c:\windows\system32\msxml3.dll
2013-12-04 02:03:20 87040 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2013-12-04 02:03:20 87040 ----a-w- c:\windows\system32\secproc_ssp.dll
2013-12-04 02:03:20 423936 ----a-w- c:\windows\system32\secproc_isv.dll
2013-12-04 02:03:08 428032 ----a-w- c:\windows\system32\secproc.dll
2013-12-04 02:02:06 390144 ----a-w- c:\windows\system32\msdrm.dll
2013-12-04 01:54:14 510976 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2013-12-04 01:54:10 594944 ----a-w- c:\windows\system32\RMActivate_isv.exe
2013-12-04 01:54:09 572416 ----a-w- c:\windows\system32\RMActivate.exe
2013-12-04 01:54:06 508928 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2013-10-19 01:36:59 159232 ----a-w- c:\windows\system32\imagehlp.dll
2013-10-12 02:04:36 121856 ----a-w- c:\windows\system32\wshom.ocx
2013-10-12 02:03:31 163840 ----a-w- c:\windows\system32\scrrun.dll
2013-10-12 01:15:48 141824 ----a-w- c:\windows\system32\wscript.exe
2013-10-12 01:15:48 126976 ----a-w- c:\windows\system32\cscript.exe
2013-10-03 01:58:07 305152 ----a-w- c:\windows\system32\gdi32.dll
2013-10-02 03:01:40 3584 ----a-w- c:\windows\system32\drivers\fr-fr\tsusbflt.sys.mui
2013-09-25 02:01:08 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-09-25 02:01:06 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2013-09-25 01:57:46 99840 ----a-w- c:\windows\system32\sspicli.dll
2013-09-25 01:57:26 22016 ----a-w- c:\windows\system32\secur32.dll
2013-09-25 01:57:24 247808 ----a-w- c:\windows\system32\schannel.dll
2013-09-25 01:56:42 220160 ----a-w- c:\windows\system32\ncrypt.dll
2013-09-25 01:56:02 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2013-09-25 00:49:20 22016 ----a-w- c:\windows\system32\lsass.exe
2013-09-25 00:49:18 15872 ----a-w- c:\windows\system32\sspisrv.dll
2013-08-02 01:50:36 169984 ----a-w- c:\windows\system32\winsrv.dll
2013-08-02 01:49:19 293376 ----a-w- c:\windows\system32\KernelBase.dll
2013-08-02 00:52:57 271360 ----a-w- c:\windows\system32\conhost.exe
2013-08-02 00:43:05 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-08-02 00:43:05 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 00:43:05 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 00:43:05 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-07-04 12:16:47 369848 ----a-w- c:\windows\system32\drivers\cng.sys
2013-07-04 11:57:28 205824 ----a-w- c:\windows\system32\WebClnt.dll
2013-07-04 11:51:04 81920 ----a-w- c:\windows\system32\davclnt.dll
2013-07-04 09:48:52 115712 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2013-06-15 03:38:43 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-04-13 04:45:16 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2012-12-07 12:26:17 308736 ----a-w- c:\windows\system32\Wpc.dll
2012-12-07 12:20:43 2576384 ----a-w- c:\windows\system32\gameux.dll
2012-10-16 07:39:52 561664 ----a-w- c:\windows\apppatch\AcLayers.dll
2012-07-26 04:44:39 2560 ----a-w- c:\windows\system32\drivers\fr-fr\wdf01000.sys.mui
2012-04-26 04:45:55 58880 ----a-w- c:\windows\system32\rdpwsx.dll
2012-04-26 04:45:54 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-26 04:41:16 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-03-17 07:27:18 56176 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-02-11 05:37:49 317440 ----a-w- c:\windows\system32\spoolsv.exe
2011-03-11 05:39:05 148864 ----a-w- c:\windows\system32\drivers\storport.sys
2011-03-11 05:39:00 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2011-03-11 05:39:00 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2011-03-11 05:38:51 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2011-03-11 05:38:37 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2011-03-11 05:38:37 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2011-03-11 05:33:09 1699328 ----a-w- c:\windows\system32\esent.dll
2011-03-11 05:31:07 74240 ----a-w- c:\windows\system32\fsutil.exe
2011-03-03 05:38:01 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-03-03 05:36:16 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-02-25 05:30:54 2616320 ----a-w- c:\windows\explorer.exe
2010-11-20 21:31:02 152576 ----a-w- c:\windows\system32\msclmd.dll
2009-07-14 01:26:21 249408 ----a-w- c:\windows\system32\clfs.sys
2009-07-14 01:20:45 12368 ----a-w- c:\windows\system32\drivers\pciide.sys
2009-07-14 01:19:11 57424 ----a-w- c:\windows\system32\drivers\ULIAGPKX.SYS
2009-07-14 01:17:54 55584 ----a-w- c:\windows\system32\drivers\dumpfve.sys
2009-07-14 01:17:54 249680 ----a-w- c:\windows\system32\bcryptprimitives.dll
2009-07-14 01:17:54 242936 ----a-w- c:\windows\system32\rsaenh.dll
2009-07-14 01:17:54 156728 ----a-w- c:\windows\system32\dssenh.dll
.
============= FINISH: 2:38:30,37 ===============
I recently installed win7 and everything was fine up til today. All certificates in all browser seem wrong, my browser suggest I might be being hacked. Windows update worked fine, but impossible since this morning. Also, two Toshiba drivers show as unknown origin even though they were downloaded from Toshiba site and worked fine before today. Computer is suddenly sluggish also. I suspect something is going on.
Here are the logs:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2006-07-01
Scan Time: 02:33:06
Logfile: Log MBAM.txt
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.04.06.09
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Admin
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 212294
Time Elapsed: 22 min, 12 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 2
PUP.Optional.BundleInstaller, C:\$Recycle.Bin\S-1-5-21-811221372-2198457851-1441504835-1000\$RYUI9P4.exe, Quarantined, [e83969beec8f2d09d9761651827f5ea2],
PUP.Optional.BundleInstaller, C:\Windows\Temp\_avast_\ws1673.dat, Quarantined, [be636dba5c1f8aacdc73df88b9483bc5],
Physical Sectors: 0
(No malicious items detected)
(end)
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.16521 BrowserJavaVersion: 10.51.2
Run by Admin at 2:34:43 on 2006-07-01
Microsoft Windows 7 Professionnel 6.1.7601.1.1252.1.1036.18.3070.1774 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: COMODO Antivirus *Disabled/Outdated* {0C2D2636-923D-EE52-2A83-E643204A8275}
FW: COMODO Firewall *Enabled* {8F7746F7-FE68-E084-3B6C-7404A51E8FB3}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Secunia\PSI\PSIA.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
c:\program files\windows defender\MpCmdRun.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
.
============== Pseudo HJT Report ===============
.
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AvastUI.exe] "c:\program files\avast software\avast\AvastUI.exe" /nogui
mRun: [COMODO Internet Security] c:\program files\comodo\comodo internet security\cistray.exe
mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [TPwrMain] c:\program files\toshiba\power saver\TPwrMain.EXE
mRun: [SmoothView] c:\program files\toshiba\smoothview\SmoothView.exe
mRun: [00TCrdMain] c:\program files\toshiba\flashcards\TCrdMain.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 47.55.55.55 142.166.166.166
TCP: Interfaces\{83A967BC-B179-4662-BC85-2206CCDD72C9} : DHCPNameServer = 47.55.55.55 142.166.166.166
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\33.0.1750.154\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\admin\appdata\roaming\mozilla\firefox\profiles\yk8py79e.default\
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.23.9\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [2014-4-4 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [2014-4-4 180760]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-4-4 776976]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-4-4 411552]
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [2014-3-25 20072]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2014-3-25 607168]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2014-3-25 43728]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-4-4 67824]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2014-4-4 50344]
R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2013-12-6 1229528]
R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-4-4 67264]
R3 netw5v32;Pilote de carte de liaison WiFi sans fil Intel(R) 5000 Series pour Windows Vista 32 bits;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-10-23 172192]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 cmdvirth;COMODO Virtual Service Manager;c:\program files\comodo\comodo internet security\cmdvirth.exe [2014-3-25 1663192]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2011-4-11 62464]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2014-4-3 108032]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf_x86.sys [2013-12-6 16024]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504]
S3 StorSvc;Service de stockage;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2014-4-3 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\wat\WatAdminSvc.exe [2014-4-3 1343400]
.
=============== Created Last 30 ================
.
2014-04-06 13:53:18 24576 ----a-w- c:\windows\system32\TSCI.dll
2014-04-06 13:53:18 24576 ----a-w- c:\windows\system32\THCI.dll
2014-04-05 19:49:01 -------- d-----w- c:\users\admin\appdata\roaming\OpenOffice
2014-04-05 17:03:10 -------- d-----w- c:\program files\EA GAMES
2014-04-05 17:01:42 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2014-04-05 17:01:42 225280 ----a-w- c:\program files\common files\installshield\iscript\iscript.dll
2014-04-05 17:01:42 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2014-04-05 17:01:41 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2014-04-05 14:19:56 107736 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-04-05 14:19:30 73432 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-04-05 14:19:30 51416 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-04-05 14:19:30 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-04-05 14:19:30 -------- d-----w- c:\programdata\Malwarebytes
2014-04-05 14:19:30 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2014-04-05 13:47:23 -------- d-----w- c:\programdata\Auslogics
2014-04-05 13:46:50 -------- d-----w- c:\program files\Auslogics
2014-04-05 13:36:06 -------- d-----w- c:\program files\Audacity
2014-04-05 13:31:10 -------- d-----w- c:\programdata\Oracle
2014-04-05 13:25:15 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2014-04-05 03:27:25 -------- d-----w- c:\users\admin\appdata\roaming\DonationCoder
2014-04-05 02:47:04 -------- d-----w- c:\programdata\DonationCoder
2014-04-05 02:47:03 -------- d-----w- c:\program files\ScreenshotCaptor
2014-04-05 02:46:50 -------- d-----w- c:\users\admin\appdata\local\Programs
2014-04-04 23:17:06 -------- d-----w- c:\program files\Synaptics
2014-04-04 23:14:16 430080 ----a-w- c:\windows\system32\TOSCDSPD.cpl
2014-04-04 23:12:49 32768 ----a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2014-04-04 23:12:48 729088 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iKernel.dll
2014-04-04 23:12:48 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\ctor.dll
2014-04-04 23:12:48 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\DotNetInstaller.exe
2014-04-04 23:12:48 266240 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iscript.dll
2014-04-04 23:12:48 192512 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iuser.dll
2014-04-04 23:12:47 311428 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\setup.dll
2014-04-04 23:12:47 188548 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iGdi.dll
2014-04-04 23:00:49 128344 ----a-w- c:\windows\system32\TODDSrv.exe
2014-04-04 23:00:39 -------- d-----w- c:\program files\TOSHIBA
2014-04-04 22:59:39 -------- d-----w- c:\users\admin\appdata\roaming\WinBatch
2014-04-04 22:17:22 -------- d-s---w- c:\programdata\Shared Space
2014-04-04 22:17:01 -------- d-----w- c:\program files\COMODO
2014-04-04 22:16:49 -------- d-----w- c:\programdata\Comodo Downloader
2014-04-04 22:13:29 -------- d-----w- c:\programdata\Comodo
2014-04-04 22:02:49 -------- d-----w- c:\users\admin\appdata\roaming\AVAST Software
2014-04-04 22:01:49 67264 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-04-04 22:01:44 180760 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-04-04 22:01:40 776976 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-04-04 22:01:37 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-04-04 22:01:34 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-04-04 22:01:32 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-04-04 22:01:19 43152 ----a-w- c:\windows\avastSS.scr
2014-04-04 21:58:34 -------- d-----w- c:\program files\AVAST Software
2014-04-04 21:57:11 -------- d-----w- c:\programdata\AVAST Software
2014-04-04 21:51:12 -------- d-----w- c:\users\admin\appdata\local\Secunia PSI
2014-04-04 21:50:58 -------- d-----w- c:\program files\Secunia
2014-04-04 21:49:30 7969936 ----a-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2014-04-04 21:49:23 7969936 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{86f4a052-cdea-46b7-88e4-279ec55a6db8}\mpengine.dll
2014-04-04 03:44:57 -------- d-----w- c:\users\admin\appdata\roaming\IrfanView
2014-04-04 03:44:56 -------- d-----w- c:\program files\IrfanView
2014-04-04 03:42:12 -------- d-----w- c:\users\admin\appdata\local\Adobe
2014-04-04 03:41:29 -------- d-----w- c:\program files\VideoLAN
2014-04-04 03:28:57 454656 ----a-w- c:\windows\system32\vbscript.dll
2014-04-04 03:23:46 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2014-04-04 03:23:17 3419136 ----a-w- c:\windows\system32\d2d1.dll
2014-04-04 03:23:17 1987584 ----a-w- c:\windows\system32\d3d10warp.dll
2014-04-04 03:15:52 -------- d-----w- c:\windows\system32\MRT
2014-04-04 03:07:38 32256 ----a-w- c:\windows\system32\TsUsbGDCoInstaller.dll
2014-04-04 03:07:28 12800 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-04-04 03:07:25 49152 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys
2014-04-04 03:07:22 855552 ----a-w- c:\windows\system32\rdvidcrl.dll
2014-04-04 03:07:22 76288 ----a-w- c:\windows\system32\TSWbPrxy.exe
2014-04-04 03:07:22 53248 ----a-w- c:\windows\system32\tsgqec.dll
2014-04-04 03:07:22 50176 ----a-w- c:\windows\system32\MsRdpWebAccess.dll
2014-04-04 03:07:22 350208 ----a-w- c:\windows\system32\wksprt.exe
2014-04-04 03:07:22 17920 ----a-w- c:\windows\system32\wksprtPS.dll
2014-04-04 03:07:22 14336 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-04-04 03:07:18 1068544 ----a-w- c:\windows\system32\mstsc.exe
2014-04-04 03:06:34 -------- d-----w- c:\program files\CONEXANT
2014-04-04 03:05:32 514560 ----a-w- c:\windows\system32\qdvd.dll
2014-04-04 03:05:29 792576 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-04-04 02:58:09 -------- d-----w- c:\windows\Migration
2014-04-04 02:48:04 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-04-04 02:48:04 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-04-04 02:47:55 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-04-04 02:47:55 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-04-04 02:47:53 613888 ----a-w- c:\windows\system32\WUDFx.dll
2014-04-04 02:47:53 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-04-04 02:47:53 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2014-04-04 02:41:02 -------- d-----w- c:\windows\system32\Wat
2014-04-04 02:29:54 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2014-04-04 02:29:53 164864 ----a-w- c:\program files\windows media player\wmplayer.exe
2014-04-04 02:02:03 5120 ----a-w- c:\windows\system32\wmi.dll
2014-04-04 02:02:03 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-04-04 02:00:39 -------- d-----w- c:\users\admin\appdata\local\Skype
2014-04-04 01:59:52 -------- d-----r- c:\program files\Skype
2014-04-04 01:55:17 46704 ----a-w- c:\program files\mozilla firefox\browser\components\browsercomps.dll
2014-04-04 01:52:59 75376 ----a-w- c:\program files\mozilla firefox\breakpadinjector.dll
2014-04-04 01:52:59 307824 ----a-w- c:\program files\mozilla firefox\freebl3.dll
2014-04-04 01:52:59 275568 ----a-w- c:\program files\mozilla firefox\firefox.exe
2014-04-04 01:52:59 2106216 ----a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll
2014-04-04 01:52:59 20080 ----a-w- c:\program files\mozilla firefox\AccessibleMarshal.dll
2014-04-04 01:52:59 117360 ----a-w- c:\program files\mozilla firefox\crashreporter.exe
2014-04-04 01:50:09 988672 ----a-w- c:\program files\windows journal\JNTFiltr.dll
2014-04-04 01:50:09 969216 ----a-w- c:\program files\windows journal\JNWDRV.dll
2014-04-04 01:50:09 936448 ----a-w- c:\program files\common files\microsoft shared\ink\journal.dll
2014-04-04 01:50:09 1221632 ----a-w- c:\program files\windows journal\NBDoc.DLL
2014-04-04 01:50:06 94208 ----a-w- c:\program files\common files\system\ole db\msdaosp.dll
2014-04-04 01:50:06 86016 ----a-w- c:\windows\system32\odbccu32.dll
2014-04-04 01:50:06 81920 ----a-w- c:\windows\system32\odbccr32.dll
2014-04-04 01:50:06 319488 ----a-w- c:\windows\system32\odbcjt32.dll
2014-04-04 01:50:06 122880 ----a-w- c:\windows\system32\odbccp32.dll
2014-04-04 01:50:05 163840 ----a-w- c:\windows\system32\odbctrac.dll
2014-04-04 01:41:36 1247744 ----a-w- c:\windows\system32\DWrite.dll
2014-04-04 01:41:30 2349056 ----a-w- c:\windows\system32\win32k.sys
2014-04-04 01:41:25 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2014-04-04 01:41:21 530432 ----a-w- c:\windows\system32\comctl32.dll
2014-04-04 01:41:16 626688 ----a-w- c:\windows\system32\usp10.dll
2014-04-04 01:41:12 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-04-04 01:41:09 55808 ----a-w- c:\windows\system32\drivers\hidclass.sys
2014-04-04 01:41:09 25728 ----a-w- c:\windows\system32\drivers\hidparse.sys
2014-04-04 01:41:06 652800 ----a-w- c:\windows\system32\rpcrt4.dll
2014-04-04 01:41:04 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2014-04-04 01:41:03 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2014-04-04 01:40:59 175104 ----a-w- c:\windows\system32\wintrust.dll
2014-04-04 01:40:46 1796096 ----a-w- c:\windows\system32\authui.dll
2014-04-04 01:40:45 152576 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll
2014-04-04 01:40:44 168960 ----a-w- c:\windows\system32\credui.dll
2014-04-04 01:40:11 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2014-04-04 01:39:50 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2014-04-04 01:39:50 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2014-04-04 01:39:50 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2014-04-04 01:39:47 376832 ----a-w- c:\windows\system32\dpnet.dll
2014-04-04 01:39:14 509440 ----a-w- c:\windows\system32\qedit.dll
2014-04-04 01:39:09 301568 ----a-w- c:\windows\system32\msieftp.dll
2014-04-04 01:39:05 196328 ----a-w- c:\windows\system32\drivers\fvevol.sys
2014-04-04 01:37:59 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2014-04-04 01:37:24 75776 ----a-w- c:\windows\system32\psisrndr.ax
2014-04-04 01:37:24 465408 ----a-w- c:\windows\system32\psisdecd.dll
2014-04-04 01:37:16 729024 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2014-04-04 01:37:16 218984 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2014-04-04 01:36:52 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2014-04-04 01:36:13 2048 ----a-w- c:\windows\system32\tzres.dll
2014-04-04 01:34:33 40960 ----a-w- c:\windows\system32\wwanprotdim.dll
2014-04-04 01:34:33 185344 ----a-w- c:\windows\system32\wwansvc.dll
2014-04-04 01:34:23 492544 ----a-w- c:\windows\system32\win32spl.dll
2014-04-04 01:34:14 1389568 ----a-w- c:\windows\system32\msxml6.dll
2014-04-04 01:34:03 295424 ----a-w- c:\windows\system32\atmfd.dll
2014-04-04 01:34:02 70656 ----a-w- c:\windows\system32\fontsub.dll
2014-04-04 01:34:02 34304 ----a-w- c:\windows\system32\atmlib.dll
2014-04-04 01:34:02 26112 ----a-w- c:\windows\system32\lpk.dll
2014-04-04 01:34:02 10240 ----a-w- c:\windows\system32\dciman32.dll
2014-04-04 01:33:48 434688 ----a-w- c:\windows\system32\scavengeui.dll
2014-04-04 01:32:54 903168 ----a-w- c:\windows\system32\certutil.exe
2014-04-04 01:32:52 43008 ----a-w- c:\windows\system32\certenc.dll
2014-04-04 01:32:01 52224 ----a-w- c:\windows\system32\nlaapi.dll
2014-04-04 01:32:01 499712 ----a-w- c:\windows\system32\iphlpsvc.dll
2014-04-04 01:32:01 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2014-04-04 01:32:01 242176 ----a-w- c:\windows\system32\nlasvc.dll
2014-04-04 01:32:01 175104 ----a-w- c:\windows\system32\netcorehc.dll
2014-04-04 01:32:01 156672 ----a-w- c:\windows\system32\ncsi.dll
2014-04-04 01:32:00 18944 ----a-w- c:\windows\system32\netevent.dll
2014-04-04 01:31:33 102608 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-04-04 01:29:23 680960 ----a-w- c:\program files\windows defender\MpSvc.dll
2014-04-04 01:29:23 392704 ----a-w- c:\program files\windows defender\MpClient.dll
2014-04-04 01:29:23 224768 ----a-w- c:\program files\windows defender\MpCommu.dll
2014-04-04 01:28:33 41984 ----a-w- c:\windows\system32\browcli.dll
2014-04-04 01:28:33 102912 ----a-w- c:\windows\system32\browser.dll
2014-04-04 01:25:21 805376 ----a-w- c:\windows\system32\cdosys.dll
2014-04-04 01:25:21 352256 ----a-w- c:\program files\common files\system\ado\msadomd.dll
2014-04-04 01:25:21 1019904 ----a-w- c:\program files\common files\system\ado\msado15.dll
2014-04-04 01:25:20 57344 ----a-w- c:\program files\common files\system\ado\msador15.dll
2014-04-04 01:25:20 372736 ----a-w- c:\program files\common files\system\ado\msadox.dll
2014-04-04 01:25:20 212992 ----a-w- c:\program files\common files\system\msadc\msadco.dll
2014-04-04 01:25:20 143360 ----a-w- c:\program files\common files\system\ado\msjro.dll
2014-04-04 01:25:15 400896 ----a-w- c:\windows\system32\srcore.dll
2014-04-04 01:25:12 1620992 ----a-w- c:\windows\system32\WMVDECOD.DLL
2014-04-04 01:25:10 1328128 ----a-w- c:\windows\system32\quartz.dll
2014-04-04 01:24:56 81408 ----a-w- c:\windows\system32\drivers\drmk.sys
2014-04-04 01:24:56 177152 ----a-w- c:\windows\system32\drivers\portcls.sys
2014-04-04 01:24:53 850944 ----a-w- c:\windows\system32\sbe.dll
2014-04-04 01:24:53 642048 ----a-w- c:\windows\system32\CPFilters.dll
2014-04-04 01:24:53 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2014-04-04 01:24:12 542208 ----a-w- c:\windows\system32\kerberos.dll
2014-04-04 01:15:48 31232 ----a-w- c:\windows\system32\prevhost.exe
2014-04-04 01:11:10 708608 ----a-w- c:\program files\common files\system\wab32.dll
2014-04-04 01:09:54 478720 ----a-w- c:\windows\system32\timedate.cpl
2014-04-04 01:09:46 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2014-04-04 01:09:42 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2014-04-04 01:09:42 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2014-04-04 01:09:42 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2014-04-04 01:09:39 741376 ----a-w- c:\windows\system32\inetcomm.dll
2014-04-04 01:09:35 67072 ----a-w- c:\windows\system32\packager.dll
2014-04-04 01:09:31 2342400 ----a-w- c:\windows\system32\msi.dll
2014-04-04 01:06:37 314880 ----a-w- c:\windows\system32\webio.dll
2014-04-04 01:05:58 240576 ----a-w- c:\windows\system32\drivers\netio.sys
2014-04-04 01:05:48 78336 ----a-w- c:\windows\system32\synceng.dll
2014-04-04 01:05:26 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2014-04-04 01:05:26 231424 ----a-w- c:\windows\system32\mswsock.dll
2014-04-04 01:05:26 187752 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2014-04-04 01:05:26 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-04-04 01:04:58 133056 ----a-w- c:\windows\system32\drivers\ataport.sys
2014-04-04 01:04:37 679424 ----a-w- c:\windows\system32\IKEEXT.DLL
2014-04-04 01:04:36 656896 ----a-w- c:\windows\system32\nshwfp.dll
2014-04-04 01:04:36 216576 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2014-04-04 01:04:23 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2014-04-04 01:04:23 193536 ----a-w- c:\windows\system32\dhcpcore6.dll
2014-04-04 01:03:32 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2014-04-04 01:03:32 1168384 ----a-w- c:\windows\system32\crypt32.dll
2014-04-04 01:03:31 103936 ----a-w- c:\windows\system32\cryptnet.dll
2014-04-04 01:02:08 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys
2014-04-04 00:59:51 381440 ----a-w- c:\windows\system32\wer.dll
2014-04-04 00:59:31 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2014-04-04 00:59:31 1137664 ----a-w- c:\windows\system32\mfc42.dll
2014-04-04 00:57:21 293376 ----a-w- c:\windows\system32\umpnpmgr.dll
2014-04-04 00:57:01 571904 ----a-w- c:\windows\system32\oleaut32.dll
2014-04-04 00:57:01 233472 ----a-w- c:\windows\system32\oleacc.dll
2014-04-04 00:53:51 86528 ----a-w- c:\windows\system32\SearchFilterHost.exe
2014-04-04 00:53:51 666624 ----a-w- c:\windows\system32\mssvp.dll
2014-04-04 00:53:51 427520 ----a-w- c:\windows\system32\SearchIndexer.exe
2014-04-04 00:53:51 337408 ----a-w- c:\windows\system32\mssph.dll
2014-04-04 00:53:51 164352 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2014-04-04 00:53:51 1549312 ----a-w- c:\windows\system32\tquery.dll
2014-04-04 00:53:51 1401344 ----a-w- c:\windows\system32\mssrch.dll
2014-04-04 00:53:50 59392 ----a-w- c:\windows\system32\msscntrs.dll
2014-04-04 00:53:50 197120 ----a-w- c:\windows\system32\mssphtb.dll
2014-04-04 00:51:13 534528 ----a-w- c:\windows\system32\EncDec.dll
2014-04-04 00:34:24 -------- d-----w- c:\program files\OpenOffice 4
2014-04-04 00:33:04 49152 ----a-w- c:\windows\system32\taskhost.exe
2014-04-04 00:32:57 690688 ----a-w- c:\windows\system32\msvcrt.dll
2014-04-04 00:32:08 164352 ----a-w- c:\windows\system32\profsvc.dll
2014-04-04 00:24:45 769024 ----a-w- c:\windows\system32\localspl.dll
2014-04-04 00:24:35 1505280 ----a-w- c:\windows\system32\d3d11.dll
2014-04-04 00:24:31 442880 ----a-w- c:\windows\system32\ntshrui.dll
2014-04-04 00:12:43 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2014-04-04 00:12:21 123904 ----a-w- c:\windows\system32\poqexec.exe
2014-04-04 00:12:18 9728 ----a-w- c:\windows\system32\Wdfres.dll
2014-04-04 00:12:18 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2014-04-04 00:12:18 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2014-04-04 00:12:08 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2014-04-04 00:12:03 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-04-04 00:12:03 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-04-04 00:12:03 43520 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-04-04 00:12:03 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-04-04 00:12:03 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-04-04 00:12:03 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-04-04 00:04:00 -------- d-----w- c:\windows\system32\wbem\en-US
2014-04-04 00:03:15 -------- d-----w- c:\program files\mp3DirectCut
2014-04-04 00:00:12 -------- d-----w- c:\program files\CCleaner
2014-04-03 23:45:05 101720 ----a-w- c:\windows\system32\consent.exe
2014-04-03 23:45:04 47104 ----a-w- c:\windows\system32\appinfo.dll
2014-04-03 23:40:12 -------- d-sh--w- c:\windows\Installer
2014-04-03 23:39:16 231584 ------w- c:\windows\system32\MpSigStub.exe
2014-04-03 23:37:28 826880 ----a-w- c:\windows\system32\rdpcore.dll
2014-04-03 23:37:28 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2014-04-03 23:34:22 -------- d-----w- c:\users\admin\appdata\local\Google
2014-04-03 23:33:40 -------- d-----w- c:\users\admin\appdata\local\Apps
2014-04-03 23:33:38 -------- d-----w- c:\users\admin\appdata\local\Deployment
2014-04-03 23:22:27 33792 ----a-w- c:\windows\system32\wuapp.exe
2014-04-03 23:22:27 171904 ----a-w- c:\windows\system32\wuwebv.dll
2014-04-03 23:22:24 2422272 ----a-w- c:\windows\system32\wucltux.dll
2014-04-03 23:21:44 88576 ----a-w- c:\windows\system32\wudriver.dll
2014-04-03 02:35:23 -------- d-sh--w- C:\Boot
2014-04-02 23:21:03 -------- d-----w- C:\Bureau2014
2014-04-02 21:54:03 -------- d-----w- c:\windows\Panther
2014-04-02 21:40:01 -------- d-----w- C:\Windows.old
2014-03-26 00:22:50 43728 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2014-03-26 00:22:48 607168 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2014-03-26 00:22:48 20072 ----a-w- c:\windows\system32\drivers\cmderd.sys
2014-03-26 00:22:38 363504 ----a-w- c:\windows\system32\guard32.dll
2014-03-26 00:22:38 36000 ----a-w- c:\windows\system32\cmdcsr.dll
2014-03-26 00:22:26 284888 ----a-w- c:\windows\system32\cmdvrt32.dll
2014-03-26 00:22:24 40664 ----a-w- c:\windows\system32\cmdkbd32.dll
2014-03-08 00:51:40 -------- d-----w- C:\Intel
2013-12-29 22:08:29 -------- d-----w- C:\Python27
2013-12-29 21:59:44 -------- d-----w- C:\Python33
2013-12-06 14:47:12 16024 ----a-w- c:\windows\system32\drivers\psi_mf_x86.sys
2013-09-12 01:21:54 863344 ----a-w- c:\windows\system32\msvcr110_clr0400.dll
2013-09-12 01:21:54 501872 ----a-w- c:\windows\system32\msvcp110_clr0400.dll
2013-09-12 01:21:54 28776 ----a-w- c:\windows\system32\aspnet_counters.dll
2013-09-12 01:21:54 18000 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2013-08-22 02:32:42 -------- d-sha-r- C:\cmdcons
2013-06-09 19:44:59 -------- d-----w- C:\Ancien Disque
2013-05-18 20:44:20 -------- d--h--w- C:\VTRoot
2013-05-12 15:13:10 -------- d-----w- C:\97317ce748271ca34c4e3f38a69f021d
2013-05-12 14:51:02 -------- d-----w- C:\Mes Affaires
2013-05-11 22:46:35 -------- d-----w- C:\4996927265dc45c02c01
2013-04-29 03:19:31 -------- d-----w- c:\program files\ImpotRapide 2007
2013-04-29 03:18:44 -------- d-----w- c:\program files\ImpotRapide 2012
2013-04-29 03:18:37 -------- d-----w- c:\program files\ImpotRapide 2010
2013-04-29 03:18:29 -------- d-----w- c:\program files\ImpotRapide 2009
2013-04-29 03:18:23 -------- d-----w- c:\program files\ImpotRapide 2008
2011-04-19 08:47:04 670032 ----a-w- c:\program files\common files\microsoft shared\vc\msdia90.dll
2011-04-12 01:45:14 -------- d-----w- c:\program files\Windows Journal
2011-04-12 01:45:07 -------- d-----w- c:\windows\ShellNew
2011-04-12 01:45:07 -------- d-----w- c:\windows\ehome
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\XPSViewer
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\winrm
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\WCN
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\slmgr
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\Printing_Admin_Scripts
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\fr
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\drivers\umdf\fr-FR
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\drivers\fr-FR
2011-04-12 01:35:38 -------- d-----w- c:\windows\system32\040C
2011-04-12 01:35:38 -------- d-----w- c:\windows\fr-FR
2011-04-12 01:35:38 -------- d-----w- c:\windows\DigitalLocker
2011-04-12 01:35:37 -------- d-----w- c:\windows\system32\wbem\fr-FR
2011-04-12 01:35:19 3584 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\fr-fr\LXKPTPRC.DLL.mui
2011-02-20 03:03:12 421200 ----a-w- c:\windows\system32\msvcp100.dll
2011-02-19 04:40:50 773968 ----a-w- c:\windows\system32\msvcr100.dll
2010-11-20 21:00:53 -------- d-----w- c:\windows\system32\wbem\Performance
2009-07-30 21:45:56 22912 ----a-w- c:\windows\system32\drivers\tdcmdpst.sys
2009-07-14 19:28:42 23512 ----a-w- c:\windows\system32\drivers\TVALZ_O.SYS
2009-07-14 04:53:55 -------- d-sh--we C:\Documents and Settings
2009-07-14 04:53:50 -------- d-----w- c:\windows\system32\wbem\mof\good
2009-07-14 04:53:50 -------- d-----w- c:\windows\system32\wbem\mof\bad
2009-07-14 04:41:11 -------- d-----w- c:\windows\system32\wbem\MOF
2009-07-14 04:34:16 -------- d-----w- c:\windows\Setup
2009-07-14 04:34:13 -------- d-----w- c:\windows\ServiceProfiles
2009-07-14 04:34:06 -------- d-s---w- c:\windows\system32\Microsoft
.
==================== Find3M ====================
.
2014-04-04 23:15:55 1060424 ----a-w- c:\windows\system32\WdfCoInstaller01000.dll
2014-04-04 23:15:49 143360 ----a-w- c:\windows\system32\SynTPAPI.dll
2014-04-04 23:15:49 110592 ----a-w- c:\windows\system32\SynTPCo4.dll
2014-04-04 23:15:48 179896 ----a-w- c:\windows\system32\drivers\SynTP.sys
2014-04-04 23:15:47 196608 ----a-w- c:\windows\system32\SynCtrl.dll
2014-04-04 23:15:46 163840 ----a-w- c:\windows\system32\SynCOM.dll
2014-04-04 22:54:28 172032 ----a-w- c:\windows\system32\UCI32114.dll
2014-04-04 22:54:27 61952 ----a-w- c:\windows\system32\CHDAudPropShortcut.exe
2014-04-04 22:54:26 566272 ----a-w- c:\windows\system32\drivers\CHDAud.sys
2014-04-04 22:54:26 5120 ----a-w- c:\windows\system32\CHdAudPropres.dll
2014-04-04 22:54:26 24064 ----a-w- c:\windows\system32\CHdAudprop.dll
2014-04-04 01:06:14 69632 ----a-w- c:\windows\system32\smss.exe
2014-04-04 01:06:14 640512 ----a-w- c:\windows\system32\advapi32.dll
2014-04-04 01:06:14 619520 ----a-w- c:\windows\system32\tdh.dll
2014-04-04 01:06:14 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2014-04-04 01:06:14 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe
2014-04-04 01:06:14 38912 ----a-w- c:\windows\system32\csrsrv.dll
2014-04-04 01:06:14 1289096 ----a-w- c:\windows\system32\ntdll.dll
2014-03-01 04:11:20 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-03-01 04:10:48 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-03-01 03:52:43 61952 ----a-w- c:\windows\system32\iesetup.dll
2014-03-01 03:51:53 51200 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-03-01 03:38:26 112128 ----a-w- c:\windows\system32\ieUnatt.exe
2014-03-01 03:38:23 108032 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-03-01 03:37:35 553472 ----a-w- c:\windows\system32\jscript9diag.dll
2014-03-01 03:31:30 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-03-01 03:14:15 4244480 ----a-w- c:\windows\system32\jscript9.dll
2014-03-01 03:00:08 1964032 ----a-w- c:\windows\system32\inetcpl.cpl
2014-03-01 02:32:16 1820160 ----a-w- c:\windows\system32\wininet.dll
2014-02-04 02:04:22 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-01-09 02:22:42 5694464 ----a-w- c:\windows\system32\mstscax.dll
2013-12-06 02:02:08 2048 ----a-w- c:\windows\system32\msxml3r.dll
2013-12-06 02:02:08 1237504 ----a-w- c:\windows\system32\msxml3.dll
2013-12-04 02:03:20 87040 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2013-12-04 02:03:20 87040 ----a-w- c:\windows\system32\secproc_ssp.dll
2013-12-04 02:03:20 423936 ----a-w- c:\windows\system32\secproc_isv.dll
2013-12-04 02:03:08 428032 ----a-w- c:\windows\system32\secproc.dll
2013-12-04 02:02:06 390144 ----a-w- c:\windows\system32\msdrm.dll
2013-12-04 01:54:14 510976 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2013-12-04 01:54:10 594944 ----a-w- c:\windows\system32\RMActivate_isv.exe
2013-12-04 01:54:09 572416 ----a-w- c:\windows\system32\RMActivate.exe
2013-12-04 01:54:06 508928 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2013-10-19 01:36:59 159232 ----a-w- c:\windows\system32\imagehlp.dll
2013-10-12 02:04:36 121856 ----a-w- c:\windows\system32\wshom.ocx
2013-10-12 02:03:31 163840 ----a-w- c:\windows\system32\scrrun.dll
2013-10-12 01:15:48 141824 ----a-w- c:\windows\system32\wscript.exe
2013-10-12 01:15:48 126976 ----a-w- c:\windows\system32\cscript.exe
2013-10-03 01:58:07 305152 ----a-w- c:\windows\system32\gdi32.dll
2013-10-02 03:01:40 3584 ----a-w- c:\windows\system32\drivers\fr-fr\tsusbflt.sys.mui
2013-09-25 02:01:08 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-09-25 02:01:06 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2013-09-25 01:57:46 99840 ----a-w- c:\windows\system32\sspicli.dll
2013-09-25 01:57:26 22016 ----a-w- c:\windows\system32\secur32.dll
2013-09-25 01:57:24 247808 ----a-w- c:\windows\system32\schannel.dll
2013-09-25 01:56:42 220160 ----a-w- c:\windows\system32\ncrypt.dll
2013-09-25 01:56:02 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2013-09-25 00:49:20 22016 ----a-w- c:\windows\system32\lsass.exe
2013-09-25 00:49:18 15872 ----a-w- c:\windows\system32\sspisrv.dll
2013-08-02 01:50:36 169984 ----a-w- c:\windows\system32\winsrv.dll
2013-08-02 01:49:19 293376 ----a-w- c:\windows\system32\KernelBase.dll
2013-08-02 00:52:57 271360 ----a-w- c:\windows\system32\conhost.exe
2013-08-02 00:43:05 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-08-02 00:43:05 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 00:43:05 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 00:43:05 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-07-04 12:16:47 369848 ----a-w- c:\windows\system32\drivers\cng.sys
2013-07-04 11:57:28 205824 ----a-w- c:\windows\system32\WebClnt.dll
2013-07-04 11:51:04 81920 ----a-w- c:\windows\system32\davclnt.dll
2013-07-04 09:48:52 115712 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2013-06-15 03:38:43 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-04-13 04:45:16 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2012-12-07 12:26:17 308736 ----a-w- c:\windows\system32\Wpc.dll
2012-12-07 12:20:43 2576384 ----a-w- c:\windows\system32\gameux.dll
2012-10-16 07:39:52 561664 ----a-w- c:\windows\apppatch\AcLayers.dll
2012-07-26 04:44:39 2560 ----a-w- c:\windows\system32\drivers\fr-fr\wdf01000.sys.mui
2012-04-26 04:45:55 58880 ----a-w- c:\windows\system32\rdpwsx.dll
2012-04-26 04:45:54 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-26 04:41:16 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-03-17 07:27:18 56176 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-02-11 05:37:49 317440 ----a-w- c:\windows\system32\spoolsv.exe
2011-03-11 05:39:05 148864 ----a-w- c:\windows\system32\drivers\storport.sys
2011-03-11 05:39:00 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2011-03-11 05:39:00 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2011-03-11 05:38:51 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2011-03-11 05:38:37 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2011-03-11 05:38:37 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2011-03-11 05:33:09 1699328 ----a-w- c:\windows\system32\esent.dll
2011-03-11 05:31:07 74240 ----a-w- c:\windows\system32\fsutil.exe
2011-03-03 05:38:01 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-03-03 05:36:16 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-02-25 05:30:54 2616320 ----a-w- c:\windows\explorer.exe
2010-11-20 21:31:02 152576 ----a-w- c:\windows\system32\msclmd.dll
2009-07-14 01:26:21 249408 ----a-w- c:\windows\system32\clfs.sys
2009-07-14 01:20:45 12368 ----a-w- c:\windows\system32\drivers\pciide.sys
2009-07-14 01:19:11 57424 ----a-w- c:\windows\system32\drivers\ULIAGPKX.SYS
2009-07-14 01:17:54 55584 ----a-w- c:\windows\system32\drivers\dumpfve.sys
2009-07-14 01:17:54 249680 ----a-w- c:\windows\system32\bcryptprimitives.dll
2009-07-14 01:17:54 242936 ----a-w- c:\windows\system32\rsaenh.dll
2009-07-14 01:17:54 156728 ----a-w- c:\windows\system32\dssenh.dll
.
============= FINISH: 2:38:30,37 ===============