NorthLight
New member
Following a reinstall of Windows Vista, I find that Firefox is now redirecting to an unwanted site and Avast! is returning a URL:Mal2 warning. The site is blocked by Avast!. I also find that Windows does not shut down properly.
I am yet to install Windows SP2, which I'm not prepared to do until this malware is removed. A full Avast! scan returns no threats, neither does a Spyboat S&D scan.
DDS.txt:
DDS (Ver_2012-11-20.01) - NTFS_x86 NETWORK
Internet Explorer: 7.0.6001.18639
Run by ADB49 at 9:18:33 on 2013-10-17
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.44.1033.18.764.296 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Outdated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide
mRun: [SiSTray] c:\program files\sis vga utilities\SiSTray.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Skytel] Skytel.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [TouchPadHotKey] c:\program files\fsc\touchpad hotkey utility\TouchPad_HotKey.exe
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
StartupFolder: c:\users\adb49\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\wirele~1.lnk - c:\program files\fsc\wireless utility\WirelessSelector.exe
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{2B2610FD-EABF-4654-850F-5A4B9945AE07} : DHCPNameServer = 192.168.0.1
Notify: SDWinLogon - SDWinLogon.dll
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\adb49\appdata\roaming\mozilla\firefox\profiles\4vgpos24.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\users\adb49\appdata\roaming\mozilla\firefox\profiles\4vgpos24.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}\plugins\npAclmPlugin.dll
FF - plugin: c:\users\adb49\appdata\roaming\mozilla\firefox\profiles\4vgpos24.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}\plugins\npPitPlugin.dll
FF - plugin: c:\users\adb49\appdata\roaming\mozilla\firefox\profiles\4vgpos24.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}\plugins\npProductDetectPlugin.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_9_900_117.dll
FF - ExtSQL: 2013-10-11 16:41; wrc@avast.com; c:\program files\avast software\avast\webrep\FF
FF - ExtSQL: 2013-10-11 22:57; {ab91efd4-6975-4081-8552-1b3922ed79e2}; c:\users\adb49\appdata\roaming\mozilla\firefox\profiles\4vgpos24.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}
FF - ExtSQL: 2013-10-13 23:35; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - ExtSQL: 2013-10-16 16:25; {6005d9b1-d115-485a-a92a-3f6453ca3fe2}; c:\users\adb49\appdata\roaming\mozilla\firefox\profiles\4vgpos24.default\extensions\{6005d9b1-d115-485a-a92a-3f6453ca3fe2}.xpi
.
============= SERVICES / DRIVERS ===============
.
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\drivers\SiSGB6.sys [2008-9-9 48128]
S0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-10-11 49376]
S0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-10-11 177864]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-10-11 770344]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-10-11 369584]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-10-11 29816]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-10-11 66336]
S2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-10-11 46808]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2013-10-16 1817560]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2013-10-16 1033688]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2013-10-16 171928]
S3 SiS6350;SiS6350;c:\windows\system32\drivers\SISGRKMD.sys [2013-10-11 456568]
.
=============== Created Last 30 ================
.
2013-10-16 11:41:55 7328304 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{b0569338-4286-4c1b-86f5-0911ffda286e}\mpengine.dll
2013-10-16 11:31:37 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-10-16 11:30:33 15224 ----a-w- c:\windows\system32\sdnclean.exe
2013-10-16 11:29:37 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2013-10-14 19:40:23 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2013-10-14 19:40:23 297808 ----a-w- c:\windows\system32\mscoree.dll
2013-10-14 19:40:23 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2013-10-14 19:40:22 49472 ----a-w- c:\windows\system32\netfxperf.dll
2013-10-14 19:40:22 1130824 ----a-w- c:\windows\system32\dfshim.dll
2013-10-14 19:25:02 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2013-10-14 19:24:20 12800 ----a-w- c:\windows\system32\wsmprovhost.exe
2013-10-14 19:24:19 40448 ----a-w- c:\windows\system32\winrs.exe
2013-10-14 19:24:19 20480 ----a-w- c:\windows\system32\winrshost.exe
2013-10-14 19:24:16 10240 ----a-w- c:\windows\system32\wsmplpxy.dll
2013-10-14 19:24:16 10240 ----a-w- c:\windows\system32\winrssrv.dll
2013-10-14 19:24:10 81408 ----a-w- c:\windows\system32\wevtfwd.dll
2013-10-14 19:24:10 79872 ----a-w- c:\windows\system32\wecutil.exe
2013-10-14 19:24:10 56320 ----a-w- c:\windows\system32\wecapi.dll
2013-10-14 19:24:10 54272 ----a-w- c:\windows\system32\WsmRes.dll
2013-10-14 19:24:10 146944 ----a-w- c:\windows\system32\wecsvc.dll
2013-10-14 19:24:08 41472 ----a-w- c:\windows\system32\pwrshplugin.dll
2013-10-14 19:23:29 201184 ----a-w- c:\windows\system32\winrm.vbs
2013-10-14 19:23:10 145408 ----a-w- c:\windows\system32\WsmAuto.dll
2013-10-14 19:23:08 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll
2013-10-14 19:23:07 241152 ----a-w- c:\windows\system32\winrscmd.dll
2013-10-14 19:23:04 252416 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll
2013-10-14 19:23:03 246272 ----a-w- c:\windows\system32\WSManHTTPConfig.exe
2013-10-14 19:22:49 1181696 ----a-w- c:\windows\system32\WsmSvc.dll
2013-10-14 17:18:44 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2013-10-14 17:18:38 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2013-10-14 17:18:24 66048 ----a-w- c:\program files\windows mail\wabmig.exe
2013-10-14 17:18:24 515584 ----a-w- c:\program files\windows mail\wab.exe
2013-10-14 17:18:24 33280 ----a-w- c:\program files\windows mail\wabfind.dll
2013-10-14 17:18:21 501760 ----a-w- c:\windows\system32\usp10.dll
2013-10-14 17:18:14 125952 ----a-w- c:\windows\system32\srvsvc.dll
2013-10-14 17:18:13 17920 ----a-w- c:\windows\system32\netevent.dll
2013-10-14 17:18:01 72704 ----a-w- c:\windows\system32\fontsub.dll
2013-10-14 17:18:01 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-10-14 17:18:01 292864 ----a-w- c:\windows\system32\atmfd.dll
2013-10-14 17:16:56 3548048 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-10-14 17:15:36 1169408 ----a-w- c:\windows\system32\sdclt.exe
2013-10-14 17:15:27 10926592 ----a-w- c:\program files\movie maker\MOVIEMK.dll
2013-10-14 17:15:24 150016 ----a-w- c:\program files\movie maker\MOVIEMK.exe
2013-10-14 17:15:20 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2013-10-14 17:15:20 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2013-10-14 17:15:16 766464 ----a-w- c:\program files\common files\microsoft shared\vgx\VGX.dll
2013-10-14 17:15:14 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2013-10-14 17:15:11 430080 ----a-w- c:\windows\system32\vbscript.dll
2013-10-14 17:15:06 563200 ----a-w- c:\windows\system32\oleaut32.dll
2013-10-14 17:12:32 135168 ----a-w- c:\windows\system32\wshom.ocx
2013-10-14 17:12:31 90112 ----a-w- c:\windows\system32\wshext.dll
2013-10-14 17:12:31 155648 ----a-w- c:\windows\system32\wscript.exe
2013-10-14 17:12:30 135168 ----a-w- c:\windows\system32\cscript.exe
2013-10-14 17:12:29 180224 ----a-w- c:\windows\system32\scrobj.dll
2013-10-14 17:12:28 172032 ----a-w- c:\windows\system32\scrrun.dll
2013-10-14 17:12:12 375808 ----a-w- c:\windows\system32\winsrv.dll
2013-10-14 17:12:11 49152 ----a-w- c:\windows\system32\csrsrv.dll
2013-10-14 17:12:03 2067456 ----a-w- c:\windows\system32\mstscax.dll
2013-10-14 17:12:00 677888 ----a-w- c:\windows\system32\mstsc.exe
2013-10-14 17:11:48 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-10-14 16:42:56 531968 ----a-w- c:\windows\system32\comctl32.dll
2013-10-14 16:39:40 276992 ----a-w- c:\windows\system32\schannel.dll
2013-10-14 13:11:27 -------- d-----w- C:\PerfLogs
2013-10-14 12:35:19 47560 ----a-w- c:\windows\system32\SPReview.exe
2013-10-14 12:35:13 152576 ----a-w- c:\windows\system32\SPWizUI.dll
2013-10-14 12:10:15 193024 ----a-w- c:\windows\system32\recdisc.exe
2013-10-14 12:10:05 6656 ----a-w- c:\windows\system32\sdspres.dll
2013-10-14 12:08:42 599552 ----a-w- c:\windows\system32\vsp1cln.exe
2013-10-14 12:08:19 28160 ----a-w- c:\windows\system32\sxproxy.dll
2013-10-14 12:08:08 142336 ----a-w- c:\windows\system32\spp.dll
2013-10-14 12:06:54 34816 ----a-w- c:\windows\system32\drivers\npfs.sys
2013-10-14 12:05:58 391168 ----a-w- c:\windows\system32\mscms.dll
2013-10-14 12:04:59 146944 ----a-w- c:\windows\system32\RstrtMgr.dll
2013-10-14 12:03:59 616448 ----a-w- c:\windows\system32\dsuiext.dll
2013-10-14 12:02:59 83968 ----a-w- c:\windows\system32\hlink.dll
2013-10-14 12:01:59 533504 ----a-w- c:\windows\system32\wmdrmsdk.dll
2013-10-14 12:00:59 638976 ----a-w- c:\windows\system32\Utilman.exe
2013-10-14 11:53:47 44032 ----a-w- c:\windows\system32\cbsra.exe
2013-10-14 11:47:31 -------- d-----w- C:\03086a4ad6c74b04e539a6d7
2013-10-14 10:50:42 -------- d-----w- c:\users\adb49\appdata\local\WindowsUpdate
2013-10-14 10:39:25 33104 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll
2013-10-14 10:39:24 31640 ----a-w- c:\windows\system32\msonpmon.dll
2013-10-14 10:35:59 -------- d-----w- c:\windows\PCHEALTH
2013-10-14 10:33:34 -------- d-----w- c:\windows\SHELLNEW
2013-10-14 10:32:57 -------- d-----w- c:\users\adb49\appdata\local\Microsoft Help
2013-10-13 22:21:05 97800 ----a-w- c:\windows\system32\infocardapi.dll
2013-10-13 22:21:01 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-13 22:20:57 37384 ----a-w- c:\windows\system32\infocardcpl.cpl
2013-10-13 22:20:56 622080 ----a-w- c:\windows\system32\icardagt.exe
2013-10-13 22:20:55 11264 ----a-w- c:\windows\system32\icardres.dll
2013-10-13 22:20:43 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2013-10-12 20:47:04 -------- d-----w- c:\users\adb49\appdata\roaming\DigitalSite
2013-10-12 20:46:45 -------- d-----w- c:\program files\BonanzaDealsLive
2013-10-12 20:46:44 -------- d-----w- c:\users\adb49\appdata\local\BonanzaDealsLive
2013-10-12 20:46:44 -------- d-----w- c:\programdata\BonanzaDealsLive
2013-10-12 20:46:12 -------- d-----w- c:\users\adb49\appdata\local\Google
2013-10-12 20:46:07 -------- d-----w- c:\program files\BonanzaDeals
2013-10-12 20:45:50 -------- d-----w- c:\program files\Image Converter
2013-10-12 20:23:55 -------- d-----w- c:\users\adb49\appdata\roaming\HpUpdate
2013-10-12 20:23:44 -------- d-----w- c:\windows\Hewlett-Packard
2013-10-12 18:11:19 378368 ----a-w- c:\windows\system32\winhttp.dll
2013-10-12 18:09:36 269312 ----a-w- c:\windows\system32\es.dll
2013-10-12 18:08:56 411136 ----a-w- c:\windows\system32\drivers\http.sys
2013-10-12 18:08:56 31232 ----a-w- c:\windows\system32\httpapi.dll
2013-10-12 18:08:56 24064 ----a-w- c:\windows\system32\nshhttp.dll
2013-10-12 18:07:52 -------- d-----w- c:\program files\MSXML 4.0
2013-10-12 16:12:44 -------- d-----w- c:\programdata\Canneverbe Limited
2013-10-12 16:12:32 -------- d-----w- c:\users\adb49\appdata\roaming\Canneverbe Limited
2013-10-12 16:01:19 -------- d-----w- c:\users\adb49\appdata\local\Macromedia
2013-10-12 16:00:22 -------- d-----w- c:\users\adb49\appdata\roaming\IrfanView
2013-10-12 16:00:20 -------- d-----w- c:\program files\IrfanView
2013-10-12 15:49:30 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-10-12 15:49:29 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-10-12 15:36:28 -------- d-----w- c:\users\adb49\appdata\local\Adobe
2013-10-12 15:32:16 -------- d-----w- c:\users\adb49\appdata\local\Amazon
2013-10-12 15:28:09 -------- d-----w- c:\program files\EasyGPS
2013-10-12 15:13:39 -------- d-----w- c:\programdata\CheckPoint
2013-10-12 14:43:33 -------- d-----w- c:\users\adb49\appdata\local\FlickrNet
2013-10-12 13:58:39 312832 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\hpfpp70v.dll
2013-10-12 13:55:55 -------- d-----w- c:\program files\common files\HP
2013-10-12 02:10:37 68096 ----a-w- c:\windows\system32\wlanhlp.dll
2013-10-12 02:10:37 64512 ----a-w- c:\windows\system32\wlanapi.dll
2013-10-12 02:10:37 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2013-10-12 02:10:36 513024 ----a-w- c:\windows\system32\wlansvc.dll
2013-10-12 02:10:36 302592 ----a-w- c:\windows\system32\wlansec.dll
2013-10-12 02:10:36 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2013-10-12 02:10:36 15181 ----a-w- c:\windows\system32\gatherWirelessInfo.vbs
2013-10-12 02:09:26 14848 ----a-w- c:\windows\system32\wshrm.dll
2013-10-12 02:09:26 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2013-10-12 02:08:35 43520 ----a-w- c:\windows\system32\msdxm.tlb
2013-10-12 02:08:35 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2013-10-12 02:08:35 18432 ----a-w- c:\windows\system32\amcompat.tlb
2013-10-12 02:07:51 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2013-10-12 02:07:51 329216 ----a-w- c:\windows\system32\msdrm.dll
2013-10-12 02:07:50 472064 ----a-w- c:\windows\system32\secproc.dll
2013-10-12 02:07:50 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2013-10-12 02:07:50 151040 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2013-10-12 02:07:50 151040 ----a-w- c:\windows\system32\secproc_ssp.dll
2013-10-12 02:07:49 523776 ----a-w- c:\windows\system32\RMActivate_isv.exe
2013-10-12 02:07:49 511488 ----a-w- c:\windows\system32\RMActivate.exe
2013-10-12 02:07:49 472576 ----a-w- c:\windows\system32\secproc_isv.dll
2013-10-11 23:16:32 -------- d-sh--w- C:\Boot
2013-10-11 23:15:52 -------- d-----w- c:\windows\system32\OEM
2013-10-11 23:15:52 -------- d-----w- c:\windows\PANTHER
2013-10-11 20:23:29 23552 ----a-w- c:\windows\system32\lpk.dll
2013-10-11 20:23:29 10240 ----a-w- c:\windows\system32\dciman32.dll
2013-10-11 20:22:34 7328304 ----a-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2013-10-11 20:22:14 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-10-11 20:19:44 72704 ----a-w- c:\windows\system32\admparse.dll
2013-10-11 20:19:38 48128 ----a-w- c:\windows\system32\mshtmler.dll
2013-10-11 20:19:32 129536 ----a-w- c:\program files\internet explorer\sqmapi.dll
2013-10-11 20:17:41 61440 ----a-w- c:\windows\system32\winipsec.dll
2013-10-11 20:17:41 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2013-10-11 20:17:41 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2013-10-11 20:17:41 272896 ----a-w- c:\windows\system32\polstore.dll
2013-10-11 20:15:26 94720 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2013-10-11 20:15:26 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2013-10-11 20:15:26 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2013-10-11 20:13:53 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2013-10-11 20:13:53 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2013-10-11 20:13:53 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2013-10-11 20:13:53 104960 ----a-w- c:\windows\system32\netiohlp.dll
2013-10-11 20:13:52 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2013-10-11 20:13:52 19968 ----a-w- c:\windows\system32\ARP.EXE
2013-10-11 20:13:52 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2013-10-11 20:13:52 10240 ----a-w- c:\windows\system32\finger.exe
2013-10-11 20:04:48 2048 ----a-w- c:\windows\system32\msxml3r.dll
2013-10-11 20:04:47 2048 ----a-w- c:\windows\system32\msxml6r.dll
2013-10-11 20:04:47 1399296 ----a-w- c:\windows\system32\msxml6.dll
2013-10-11 19:58:28 213504 ----a-w- c:\windows\system32\msv1_0.dll
2013-10-11 19:56:04 2868224 ----a-w- c:\windows\system32\mf.dll
2013-10-11 19:56:03 98816 ----a-w- c:\windows\system32\mfps.dll
2013-10-11 19:56:03 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2013-10-11 19:56:03 24576 ----a-w- c:\windows\system32\mfpmp.exe
2013-10-11 19:56:03 2048 ----a-w- c:\windows\system32\mferror.dll
2013-10-11 19:50:24 71680 ----a-w- c:\windows\system32\atl.dll
2013-10-11 19:49:23 296960 ----a-w- c:\windows\system32\gdi32.dll
2013-10-11 19:44:54 562176 ----a-w- c:\windows\system32\msdtcprx.dll
2013-10-11 19:44:54 38912 ----a-w- c:\windows\system32\xolehlp.dll
2013-10-11 19:43:54 160256 ----a-w- c:\windows\system32\wkssvc.dll
2013-10-11 19:42:49 53248 ----a-w- c:\windows\system32\tsgqec.dll
2013-10-11 19:42:49 136192 ----a-w- c:\windows\system32\aaclient.dll
2013-10-11 19:41:45 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2013-10-11 19:39:44 714240 ----a-w- c:\windows\system32\timedate.cpl
2013-10-11 19:34:19 23040 ----a-w- c:\program files\movie maker\WMM2EXT.dll
2013-10-11 19:34:18 195072 ----a-w- c:\program files\movie maker\WMM2AE.dll
2013-10-11 19:25:14 636928 ----a-w- c:\windows\system32\localspl.dll
2013-10-11 19:21:53 2927104 ----a-w- c:\windows\explorer.exe
2013-10-11 19:16:06 -------- d-----w- c:\windows\system32\MRT
2013-10-11 19:14:42 8704 ----a-w- c:\windows\system32\hccoin.dll
2013-10-11 19:14:42 15872 ----a-w- c:\windows\system32\hcrstco.dll
2013-10-11 19:11:26 171520 ----a-w- c:\windows\system32\wintrust.dll
2013-10-11 19:09:33 499712 ----a-w- c:\windows\system32\kerberos.dll
2013-10-11 19:09:32 9728 ----a-w- c:\windows\system32\lsass.exe
2013-10-11 19:09:32 72704 ----a-w- c:\windows\system32\secur32.dll
2013-10-11 19:09:32 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2013-10-11 19:09:32 175104 ----a-w- c:\windows\system32\wdigest.dll
2013-10-11 19:09:31 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2013-10-11 19:04:59 6346240 ----a-w- c:\windows\system32\NlsLexicons001d.dll
2013-10-11 18:59:47 6656 ----a-w- c:\windows\system32\kbd106n.dll
2013-10-11 18:59:43 927288 ----a-w- c:\windows\system32\winresume.exe
2013-10-11 18:59:42 988216 ----a-w- c:\windows\system32\winload.exe
2013-10-11 18:59:42 40960 ----a-w- c:\windows\system32\srclient.dll
2013-10-11 18:59:42 378368 ----a-w- c:\windows\system32\srcore.dll
2013-10-11 18:59:42 318464 ----a-w- c:\windows\system32\rstrui.exe
2013-10-11 18:59:42 19000 ----a-w- c:\windows\system32\kd1394.dll
2013-10-11 18:59:42 14848 ----a-w- c:\windows\system32\srdelayed.exe
2013-10-11 18:59:41 615992 ----a-w- c:\windows\system32\ci.dll
2013-10-11 18:59:41 46592 ----a-w- c:\windows\system32\setbcdlocale.dll
2013-10-11 18:56:48 551424 ----a-w- c:\windows\system32\rpcss.dll
2013-10-11 18:56:47 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2013-10-11 18:56:46 666624 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2013-10-11 18:56:46 499200 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2013-10-11 18:56:46 247296 ----a-w- c:\windows\system32\wbem\WmiPrvSE.exe
2013-10-11 18:56:46 129024 ----a-w- c:\windows\system32\wbem\WmiDcPrv.dll
2013-10-11 18:56:45 615424 ----a-w- c:\windows\system32\wbem\fastprox.dll
2013-10-11 18:56:45 54784 ----a-w- c:\windows\system32\iasads.dll
2013-10-11 18:56:45 44032 ----a-w- c:\windows\system32\iasdatastore.dll
2013-10-11 18:56:45 17408 ----a-w- c:\windows\system32\iashost.exe
2013-10-11 18:56:44 98304 ----a-w- c:\windows\system32\iasrecst.dll
2013-10-11 18:56:44 183296 ----a-w- c:\windows\system32\sdohlp.dll
2013-10-11 18:54:59 62464 ----a-w- c:\windows\system32\l3codeca.acm
2013-10-11 18:54:59 220672 ----a-w- c:\windows\system32\l3codecp.acm
2013-10-11 18:54:45 -------- d-----w- c:\program files\common files\Hewlett-Packard
2013-10-11 18:51:53 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2013-10-11 18:51:53 190464 ----a-w- c:\windows\system32\iphlpsvc.dll
2013-10-11 18:51:53 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS
2013-10-11 18:49:55 454656 ----a-w- c:\program files\common files\system\msadc\msadce.dll
2013-10-11 18:46:55 293376 ----a-w- c:\windows\system32\browserchoice.exe
2013-10-11 18:45:04 24064 ----a-w- c:\windows\system32\amxread.dll
2013-10-11 18:45:04 13824 ----a-w- c:\windows\system32\apilogen.dll
2013-10-11 18:42:04 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2013-10-11 18:42:03 712704 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-10-11 18:42:03 347136 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-10-11 18:41:06 966656 ----a-w- c:\windows\system32\hpost_p02c.dll
2013-10-11 18:41:06 315392 ----a-w- c:\windows\system32\hposc_p02a.dll
2013-10-11 18:41:05 712704 ----a-w- c:\windows\system32\hposwia_p02c.dll
2013-10-11 18:41:05 372736 ----a-w- c:\windows\system32\hppldcoi.dll
2013-10-11 18:41:05 309760 ----a-w- c:\windows\system32\difxapi.dll
2013-10-11 18:40:31 98304 ----a-w- c:\windows\system32\cabview.dll
2013-10-11 18:40:28 452408 ----a-w- c:\windows\system32\hpzids01.dll
2013-10-11 18:40:00 123904 ----a-w- c:\windows\system32\hpf3l70v.dll
2013-10-11 18:39:54 -------- d-----w- c:\users\adb49\{ea923793-435b-419d-b4c2-385cf01d320b}
2013-10-11 18:32:11 443392 ----a-w- c:\windows\system32\win32spl.dll
2013-10-11 18:32:11 37888 ----a-w- c:\windows\system32\printcom.dll
2013-10-11 18:23:24 -------- d-----w- c:\program files\HP
2013-10-11 17:48:37 83968 ----a-w- c:\windows\system32\mscories.dll
2013-10-11 17:48:37 158720 ----a-w- c:\windows\system32\mscorier.dll
2013-10-11 17:31:06 1695744 ----a-w- c:\windows\system32\gameux.dll
2013-10-11 17:30:37 94720 ----a-w- c:\windows\system32\logagent.exe
2013-10-11 17:30:36 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2013-10-11 17:29:44 84480 ----a-w- c:\windows\system32\INETRES.dll
2013-10-11 17:29:19 61440 ----a-w- c:\windows\system32\msasn1.dll
2013-10-11 17:28:57 1645568 ----a-w- c:\windows\system32\connect.dll
2013-10-11 17:28:30 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2013-10-11 17:27:45 281600 ----a-w- c:\windows\system32\raschap.dll
2013-10-11 17:27:45 244224 ----a-w- c:\windows\system32\rastls.dll
2013-10-11 17:27:20 351232 ----a-w- c:\windows\system32\WSDApi.dll
2013-10-11 17:26:09 91136 ----a-w- c:\windows\system32\avifil32.dll
2013-10-11 17:26:09 82944 ----a-w- c:\windows\system32\mciavi32.dll
2013-10-11 17:26:09 65024 ----a-w- c:\windows\system32\avicap32.dll
2013-10-11 17:26:09 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2013-10-11 17:26:09 31744 ----a-w- c:\windows\system32\msvidc32.dll
2013-10-11 17:26:09 22528 ----a-w- c:\windows\system32\msyuv.dll
2013-10-11 17:26:09 13312 ----a-w- c:\windows\system32\msrle32.dll
2013-10-11 17:26:09 123904 ----a-w- c:\windows\system32\msvfw32.dll
2013-10-11 17:26:09 11776 ----a-w- c:\windows\system32\tsbyuv.dll
2013-10-11 17:25:26 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2013-10-11 17:24:25 7680 ----a-w- c:\windows\system32\spwmp.dll
2013-10-11 17:24:25 4096 ----a-w- c:\windows\system32\dxmasf.dll
2013-10-11 17:24:25 107520 ----a-w- c:\program files\windows media player\wmpshare.exe
2013-10-11 17:24:24 4096 ----a-w- c:\windows\system32\msdxm.ocx
2013-10-11 17:24:24 107520 ----a-w- c:\program files\windows media player\wmpconfig.exe
2013-10-11 17:24:21 310784 ----a-w- c:\windows\system32\unregmp2.exe
2013-10-11 17:24:21 1418752 ----a-w- c:\program files\windows media player\setup_wm.exe
2013-10-11 15:51:59 91544 ----a-w- c:\program files\mozilla firefox\nssdbm3.dll
2013-10-11 15:42:49 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-10-11 15:42:48 177864 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-10-11 15:42:47 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-10-11 15:42:44 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-10-11 15:41:58 -------- d-sh--w- c:\windows\Installer
2013-10-11 15:41:33 41664 ----a-w- c:\windows\avastSS.scr
2013-10-11 15:40:42 -------- d-----w- c:\program files\AVAST Software
2013-10-11 15:39:10 -------- d-----w- c:\programdata\AVAST Software
2013-10-11 15:10:46 -------- d-----w- c:\program files\Synaptics
2013-10-11 15:07:48 520192 ----a-w- c:\windows\RtlExUpd.dll
2013-10-11 15:07:48 315392 ----a-w- c:\windows\HideWin.exe
2013-10-11 15:07:43 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\ctor.dll
2013-10-11 15:07:43 32768 ----a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2013-10-11 15:07:43 274432 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iscript.dll
2013-10-11 15:07:43 204800 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iuser.dll
2013-10-11 15:07:42 757760 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iKernel.dll
2013-10-11 15:07:42 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\DotNetInstaller.exe
2013-10-11 15:07:41 200836 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iGdi.dll
2013-10-11 15:07:40 331908 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\setup.dll
2013-10-11 15:07:09 6656 ----a-w- c:\windows\system32\SiSApi.dll
2013-10-11 15:07:06 -------- d-----w- c:\program files\SiS VGA Utilities
2013-10-11 15:06:27 196608 ----a-w- c:\windows\system32\SynCtrl.dll
2013-10-11 15:06:27 187320 ----a-w- c:\windows\system32\drivers\SynTP.sys
2013-10-11 15:06:27 163840 ----a-w- c:\windows\system32\SynCOM.dll
2013-10-11 15:06:27 143360 ----a-w- c:\windows\system32\SynTPAPI.dll
2013-10-11 15:06:27 110592 ----a-w- c:\windows\system32\SynTPCo4.dll
2013-10-11 15:06:27 1060424 ----a-w- c:\windows\system32\WdfCoInstaller01000.dll
2013-10-11 15:05:46 6656 ----a-w- c:\windows\system32\SiSCo.dll
2013-10-11 15:05:46 655360 ----a-w- c:\windows\system32\SiSClone.dll
2013-10-11 15:05:46 5632 ----a-w- c:\windows\system32\SiSKrl.dll
2013-10-11 15:05:46 456568 ----a-w- c:\windows\system32\drivers\SISGRKMD.sys
2013-10-11 15:05:46 4078592 ----a-w- c:\windows\system32\SiSGlv.dll
2013-10-11 15:05:46 3625984 ----a-w- c:\windows\system32\SISGRUMD.dll
2013-10-11 15:05:46 212992 ----a-w- c:\windows\system32\SiSFunc.dll
2013-10-11 15:05:45 56184 ----a-w- c:\windows\system32\drivers\SISAGPX.SYS
2013-10-11 15:05:13 22632 ----a-w- c:\windows\system32\streamci.dll
2013-10-11 14:55:25 -------- d-----w- C:\fsc.tmp
2013-10-11 14:46:56 516784 ----a-r- c:\windows\system32\XceedCry.dll
.
==================== Find3M ====================
.
2013-10-14 12:50:57 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2013-10-14 12:50:38 82432 ----a-w- c:\windows\system32\axaltocm.dll
2013-10-12 18:08:56 36864 ----a-w- c:\windows\system32\drivers\en-us\http.sys.mui
2013-10-11 19:04:59 9892864 ----a-w- c:\windows\system32\NlsLexicons000a.dll
2013-10-11 18:45:04 40960 ----a-w- c:\windows\apppatch\apihex86.dll
2013-10-11 17:31:08 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2013-10-11 15:08:11 319456 ----a-w- c:\windows\DIFxAPI.dll
.
============= FINISH: 9:20:12.63 ===============
View attachment attach.zip
View attachment aswMBR.txt
I am yet to install Windows SP2, which I'm not prepared to do until this malware is removed. A full Avast! scan returns no threats, neither does a Spyboat S&D scan.
DDS.txt:
DDS (Ver_2012-11-20.01) - NTFS_x86 NETWORK
Internet Explorer: 7.0.6001.18639
Run by ADB49 at 9:18:33 on 2013-10-17
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.44.1033.18.764.296 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Outdated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide
mRun: [SiSTray] c:\program files\sis vga utilities\SiSTray.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Skytel] Skytel.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [TouchPadHotKey] c:\program files\fsc\touchpad hotkey utility\TouchPad_HotKey.exe
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
StartupFolder: c:\users\adb49\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\wirele~1.lnk - c:\program files\fsc\wireless utility\WirelessSelector.exe
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{2B2610FD-EABF-4654-850F-5A4B9945AE07} : DHCPNameServer = 192.168.0.1
Notify: SDWinLogon - SDWinLogon.dll
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\adb49\appdata\roaming\mozilla\firefox\profiles\4vgpos24.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\users\adb49\appdata\roaming\mozilla\firefox\profiles\4vgpos24.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}\plugins\npAclmPlugin.dll
FF - plugin: c:\users\adb49\appdata\roaming\mozilla\firefox\profiles\4vgpos24.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}\plugins\npPitPlugin.dll
FF - plugin: c:\users\adb49\appdata\roaming\mozilla\firefox\profiles\4vgpos24.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}\plugins\npProductDetectPlugin.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_9_900_117.dll
FF - ExtSQL: 2013-10-11 16:41; wrc@avast.com; c:\program files\avast software\avast\webrep\FF
FF - ExtSQL: 2013-10-11 22:57; {ab91efd4-6975-4081-8552-1b3922ed79e2}; c:\users\adb49\appdata\roaming\mozilla\firefox\profiles\4vgpos24.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}
FF - ExtSQL: 2013-10-13 23:35; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - ExtSQL: 2013-10-16 16:25; {6005d9b1-d115-485a-a92a-3f6453ca3fe2}; c:\users\adb49\appdata\roaming\mozilla\firefox\profiles\4vgpos24.default\extensions\{6005d9b1-d115-485a-a92a-3f6453ca3fe2}.xpi
.
============= SERVICES / DRIVERS ===============
.
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\drivers\SiSGB6.sys [2008-9-9 48128]
S0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-10-11 49376]
S0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-10-11 177864]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-10-11 770344]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-10-11 369584]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-10-11 29816]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-10-11 66336]
S2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-10-11 46808]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2013-10-16 1817560]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2013-10-16 1033688]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2013-10-16 171928]
S3 SiS6350;SiS6350;c:\windows\system32\drivers\SISGRKMD.sys [2013-10-11 456568]
.
=============== Created Last 30 ================
.
2013-10-16 11:41:55 7328304 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{b0569338-4286-4c1b-86f5-0911ffda286e}\mpengine.dll
2013-10-16 11:31:37 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-10-16 11:30:33 15224 ----a-w- c:\windows\system32\sdnclean.exe
2013-10-16 11:29:37 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2013-10-14 19:40:23 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2013-10-14 19:40:23 297808 ----a-w- c:\windows\system32\mscoree.dll
2013-10-14 19:40:23 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2013-10-14 19:40:22 49472 ----a-w- c:\windows\system32\netfxperf.dll
2013-10-14 19:40:22 1130824 ----a-w- c:\windows\system32\dfshim.dll
2013-10-14 19:25:02 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2013-10-14 19:24:20 12800 ----a-w- c:\windows\system32\wsmprovhost.exe
2013-10-14 19:24:19 40448 ----a-w- c:\windows\system32\winrs.exe
2013-10-14 19:24:19 20480 ----a-w- c:\windows\system32\winrshost.exe
2013-10-14 19:24:16 10240 ----a-w- c:\windows\system32\wsmplpxy.dll
2013-10-14 19:24:16 10240 ----a-w- c:\windows\system32\winrssrv.dll
2013-10-14 19:24:10 81408 ----a-w- c:\windows\system32\wevtfwd.dll
2013-10-14 19:24:10 79872 ----a-w- c:\windows\system32\wecutil.exe
2013-10-14 19:24:10 56320 ----a-w- c:\windows\system32\wecapi.dll
2013-10-14 19:24:10 54272 ----a-w- c:\windows\system32\WsmRes.dll
2013-10-14 19:24:10 146944 ----a-w- c:\windows\system32\wecsvc.dll
2013-10-14 19:24:08 41472 ----a-w- c:\windows\system32\pwrshplugin.dll
2013-10-14 19:23:29 201184 ----a-w- c:\windows\system32\winrm.vbs
2013-10-14 19:23:10 145408 ----a-w- c:\windows\system32\WsmAuto.dll
2013-10-14 19:23:08 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll
2013-10-14 19:23:07 241152 ----a-w- c:\windows\system32\winrscmd.dll
2013-10-14 19:23:04 252416 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll
2013-10-14 19:23:03 246272 ----a-w- c:\windows\system32\WSManHTTPConfig.exe
2013-10-14 19:22:49 1181696 ----a-w- c:\windows\system32\WsmSvc.dll
2013-10-14 17:18:44 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2013-10-14 17:18:38 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2013-10-14 17:18:24 66048 ----a-w- c:\program files\windows mail\wabmig.exe
2013-10-14 17:18:24 515584 ----a-w- c:\program files\windows mail\wab.exe
2013-10-14 17:18:24 33280 ----a-w- c:\program files\windows mail\wabfind.dll
2013-10-14 17:18:21 501760 ----a-w- c:\windows\system32\usp10.dll
2013-10-14 17:18:14 125952 ----a-w- c:\windows\system32\srvsvc.dll
2013-10-14 17:18:13 17920 ----a-w- c:\windows\system32\netevent.dll
2013-10-14 17:18:01 72704 ----a-w- c:\windows\system32\fontsub.dll
2013-10-14 17:18:01 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-10-14 17:18:01 292864 ----a-w- c:\windows\system32\atmfd.dll
2013-10-14 17:16:56 3548048 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-10-14 17:15:36 1169408 ----a-w- c:\windows\system32\sdclt.exe
2013-10-14 17:15:27 10926592 ----a-w- c:\program files\movie maker\MOVIEMK.dll
2013-10-14 17:15:24 150016 ----a-w- c:\program files\movie maker\MOVIEMK.exe
2013-10-14 17:15:20 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2013-10-14 17:15:20 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2013-10-14 17:15:16 766464 ----a-w- c:\program files\common files\microsoft shared\vgx\VGX.dll
2013-10-14 17:15:14 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2013-10-14 17:15:11 430080 ----a-w- c:\windows\system32\vbscript.dll
2013-10-14 17:15:06 563200 ----a-w- c:\windows\system32\oleaut32.dll
2013-10-14 17:12:32 135168 ----a-w- c:\windows\system32\wshom.ocx
2013-10-14 17:12:31 90112 ----a-w- c:\windows\system32\wshext.dll
2013-10-14 17:12:31 155648 ----a-w- c:\windows\system32\wscript.exe
2013-10-14 17:12:30 135168 ----a-w- c:\windows\system32\cscript.exe
2013-10-14 17:12:29 180224 ----a-w- c:\windows\system32\scrobj.dll
2013-10-14 17:12:28 172032 ----a-w- c:\windows\system32\scrrun.dll
2013-10-14 17:12:12 375808 ----a-w- c:\windows\system32\winsrv.dll
2013-10-14 17:12:11 49152 ----a-w- c:\windows\system32\csrsrv.dll
2013-10-14 17:12:03 2067456 ----a-w- c:\windows\system32\mstscax.dll
2013-10-14 17:12:00 677888 ----a-w- c:\windows\system32\mstsc.exe
2013-10-14 17:11:48 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-10-14 16:42:56 531968 ----a-w- c:\windows\system32\comctl32.dll
2013-10-14 16:39:40 276992 ----a-w- c:\windows\system32\schannel.dll
2013-10-14 13:11:27 -------- d-----w- C:\PerfLogs
2013-10-14 12:35:19 47560 ----a-w- c:\windows\system32\SPReview.exe
2013-10-14 12:35:13 152576 ----a-w- c:\windows\system32\SPWizUI.dll
2013-10-14 12:10:15 193024 ----a-w- c:\windows\system32\recdisc.exe
2013-10-14 12:10:05 6656 ----a-w- c:\windows\system32\sdspres.dll
2013-10-14 12:08:42 599552 ----a-w- c:\windows\system32\vsp1cln.exe
2013-10-14 12:08:19 28160 ----a-w- c:\windows\system32\sxproxy.dll
2013-10-14 12:08:08 142336 ----a-w- c:\windows\system32\spp.dll
2013-10-14 12:06:54 34816 ----a-w- c:\windows\system32\drivers\npfs.sys
2013-10-14 12:05:58 391168 ----a-w- c:\windows\system32\mscms.dll
2013-10-14 12:04:59 146944 ----a-w- c:\windows\system32\RstrtMgr.dll
2013-10-14 12:03:59 616448 ----a-w- c:\windows\system32\dsuiext.dll
2013-10-14 12:02:59 83968 ----a-w- c:\windows\system32\hlink.dll
2013-10-14 12:01:59 533504 ----a-w- c:\windows\system32\wmdrmsdk.dll
2013-10-14 12:00:59 638976 ----a-w- c:\windows\system32\Utilman.exe
2013-10-14 11:53:47 44032 ----a-w- c:\windows\system32\cbsra.exe
2013-10-14 11:47:31 -------- d-----w- C:\03086a4ad6c74b04e539a6d7
2013-10-14 10:50:42 -------- d-----w- c:\users\adb49\appdata\local\WindowsUpdate
2013-10-14 10:39:25 33104 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll
2013-10-14 10:39:24 31640 ----a-w- c:\windows\system32\msonpmon.dll
2013-10-14 10:35:59 -------- d-----w- c:\windows\PCHEALTH
2013-10-14 10:33:34 -------- d-----w- c:\windows\SHELLNEW
2013-10-14 10:32:57 -------- d-----w- c:\users\adb49\appdata\local\Microsoft Help
2013-10-13 22:21:05 97800 ----a-w- c:\windows\system32\infocardapi.dll
2013-10-13 22:21:01 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-13 22:20:57 37384 ----a-w- c:\windows\system32\infocardcpl.cpl
2013-10-13 22:20:56 622080 ----a-w- c:\windows\system32\icardagt.exe
2013-10-13 22:20:55 11264 ----a-w- c:\windows\system32\icardres.dll
2013-10-13 22:20:43 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2013-10-12 20:47:04 -------- d-----w- c:\users\adb49\appdata\roaming\DigitalSite
2013-10-12 20:46:45 -------- d-----w- c:\program files\BonanzaDealsLive
2013-10-12 20:46:44 -------- d-----w- c:\users\adb49\appdata\local\BonanzaDealsLive
2013-10-12 20:46:44 -------- d-----w- c:\programdata\BonanzaDealsLive
2013-10-12 20:46:12 -------- d-----w- c:\users\adb49\appdata\local\Google
2013-10-12 20:46:07 -------- d-----w- c:\program files\BonanzaDeals
2013-10-12 20:45:50 -------- d-----w- c:\program files\Image Converter
2013-10-12 20:23:55 -------- d-----w- c:\users\adb49\appdata\roaming\HpUpdate
2013-10-12 20:23:44 -------- d-----w- c:\windows\Hewlett-Packard
2013-10-12 18:11:19 378368 ----a-w- c:\windows\system32\winhttp.dll
2013-10-12 18:09:36 269312 ----a-w- c:\windows\system32\es.dll
2013-10-12 18:08:56 411136 ----a-w- c:\windows\system32\drivers\http.sys
2013-10-12 18:08:56 31232 ----a-w- c:\windows\system32\httpapi.dll
2013-10-12 18:08:56 24064 ----a-w- c:\windows\system32\nshhttp.dll
2013-10-12 18:07:52 -------- d-----w- c:\program files\MSXML 4.0
2013-10-12 16:12:44 -------- d-----w- c:\programdata\Canneverbe Limited
2013-10-12 16:12:32 -------- d-----w- c:\users\adb49\appdata\roaming\Canneverbe Limited
2013-10-12 16:01:19 -------- d-----w- c:\users\adb49\appdata\local\Macromedia
2013-10-12 16:00:22 -------- d-----w- c:\users\adb49\appdata\roaming\IrfanView
2013-10-12 16:00:20 -------- d-----w- c:\program files\IrfanView
2013-10-12 15:49:30 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-10-12 15:49:29 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-10-12 15:36:28 -------- d-----w- c:\users\adb49\appdata\local\Adobe
2013-10-12 15:32:16 -------- d-----w- c:\users\adb49\appdata\local\Amazon
2013-10-12 15:28:09 -------- d-----w- c:\program files\EasyGPS
2013-10-12 15:13:39 -------- d-----w- c:\programdata\CheckPoint
2013-10-12 14:43:33 -------- d-----w- c:\users\adb49\appdata\local\FlickrNet
2013-10-12 13:58:39 312832 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\hpfpp70v.dll
2013-10-12 13:55:55 -------- d-----w- c:\program files\common files\HP
2013-10-12 02:10:37 68096 ----a-w- c:\windows\system32\wlanhlp.dll
2013-10-12 02:10:37 64512 ----a-w- c:\windows\system32\wlanapi.dll
2013-10-12 02:10:37 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2013-10-12 02:10:36 513024 ----a-w- c:\windows\system32\wlansvc.dll
2013-10-12 02:10:36 302592 ----a-w- c:\windows\system32\wlansec.dll
2013-10-12 02:10:36 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2013-10-12 02:10:36 15181 ----a-w- c:\windows\system32\gatherWirelessInfo.vbs
2013-10-12 02:09:26 14848 ----a-w- c:\windows\system32\wshrm.dll
2013-10-12 02:09:26 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2013-10-12 02:08:35 43520 ----a-w- c:\windows\system32\msdxm.tlb
2013-10-12 02:08:35 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2013-10-12 02:08:35 18432 ----a-w- c:\windows\system32\amcompat.tlb
2013-10-12 02:07:51 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2013-10-12 02:07:51 329216 ----a-w- c:\windows\system32\msdrm.dll
2013-10-12 02:07:50 472064 ----a-w- c:\windows\system32\secproc.dll
2013-10-12 02:07:50 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2013-10-12 02:07:50 151040 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2013-10-12 02:07:50 151040 ----a-w- c:\windows\system32\secproc_ssp.dll
2013-10-12 02:07:49 523776 ----a-w- c:\windows\system32\RMActivate_isv.exe
2013-10-12 02:07:49 511488 ----a-w- c:\windows\system32\RMActivate.exe
2013-10-12 02:07:49 472576 ----a-w- c:\windows\system32\secproc_isv.dll
2013-10-11 23:16:32 -------- d-sh--w- C:\Boot
2013-10-11 23:15:52 -------- d-----w- c:\windows\system32\OEM
2013-10-11 23:15:52 -------- d-----w- c:\windows\PANTHER
2013-10-11 20:23:29 23552 ----a-w- c:\windows\system32\lpk.dll
2013-10-11 20:23:29 10240 ----a-w- c:\windows\system32\dciman32.dll
2013-10-11 20:22:34 7328304 ----a-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2013-10-11 20:22:14 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-10-11 20:19:44 72704 ----a-w- c:\windows\system32\admparse.dll
2013-10-11 20:19:38 48128 ----a-w- c:\windows\system32\mshtmler.dll
2013-10-11 20:19:32 129536 ----a-w- c:\program files\internet explorer\sqmapi.dll
2013-10-11 20:17:41 61440 ----a-w- c:\windows\system32\winipsec.dll
2013-10-11 20:17:41 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2013-10-11 20:17:41 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2013-10-11 20:17:41 272896 ----a-w- c:\windows\system32\polstore.dll
2013-10-11 20:15:26 94720 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2013-10-11 20:15:26 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2013-10-11 20:15:26 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2013-10-11 20:13:53 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2013-10-11 20:13:53 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2013-10-11 20:13:53 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2013-10-11 20:13:53 104960 ----a-w- c:\windows\system32\netiohlp.dll
2013-10-11 20:13:52 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2013-10-11 20:13:52 19968 ----a-w- c:\windows\system32\ARP.EXE
2013-10-11 20:13:52 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2013-10-11 20:13:52 10240 ----a-w- c:\windows\system32\finger.exe
2013-10-11 20:04:48 2048 ----a-w- c:\windows\system32\msxml3r.dll
2013-10-11 20:04:47 2048 ----a-w- c:\windows\system32\msxml6r.dll
2013-10-11 20:04:47 1399296 ----a-w- c:\windows\system32\msxml6.dll
2013-10-11 19:58:28 213504 ----a-w- c:\windows\system32\msv1_0.dll
2013-10-11 19:56:04 2868224 ----a-w- c:\windows\system32\mf.dll
2013-10-11 19:56:03 98816 ----a-w- c:\windows\system32\mfps.dll
2013-10-11 19:56:03 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2013-10-11 19:56:03 24576 ----a-w- c:\windows\system32\mfpmp.exe
2013-10-11 19:56:03 2048 ----a-w- c:\windows\system32\mferror.dll
2013-10-11 19:50:24 71680 ----a-w- c:\windows\system32\atl.dll
2013-10-11 19:49:23 296960 ----a-w- c:\windows\system32\gdi32.dll
2013-10-11 19:44:54 562176 ----a-w- c:\windows\system32\msdtcprx.dll
2013-10-11 19:44:54 38912 ----a-w- c:\windows\system32\xolehlp.dll
2013-10-11 19:43:54 160256 ----a-w- c:\windows\system32\wkssvc.dll
2013-10-11 19:42:49 53248 ----a-w- c:\windows\system32\tsgqec.dll
2013-10-11 19:42:49 136192 ----a-w- c:\windows\system32\aaclient.dll
2013-10-11 19:41:45 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2013-10-11 19:39:44 714240 ----a-w- c:\windows\system32\timedate.cpl
2013-10-11 19:34:19 23040 ----a-w- c:\program files\movie maker\WMM2EXT.dll
2013-10-11 19:34:18 195072 ----a-w- c:\program files\movie maker\WMM2AE.dll
2013-10-11 19:25:14 636928 ----a-w- c:\windows\system32\localspl.dll
2013-10-11 19:21:53 2927104 ----a-w- c:\windows\explorer.exe
2013-10-11 19:16:06 -------- d-----w- c:\windows\system32\MRT
2013-10-11 19:14:42 8704 ----a-w- c:\windows\system32\hccoin.dll
2013-10-11 19:14:42 15872 ----a-w- c:\windows\system32\hcrstco.dll
2013-10-11 19:11:26 171520 ----a-w- c:\windows\system32\wintrust.dll
2013-10-11 19:09:33 499712 ----a-w- c:\windows\system32\kerberos.dll
2013-10-11 19:09:32 9728 ----a-w- c:\windows\system32\lsass.exe
2013-10-11 19:09:32 72704 ----a-w- c:\windows\system32\secur32.dll
2013-10-11 19:09:32 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2013-10-11 19:09:32 175104 ----a-w- c:\windows\system32\wdigest.dll
2013-10-11 19:09:31 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2013-10-11 19:04:59 6346240 ----a-w- c:\windows\system32\NlsLexicons001d.dll
2013-10-11 18:59:47 6656 ----a-w- c:\windows\system32\kbd106n.dll
2013-10-11 18:59:43 927288 ----a-w- c:\windows\system32\winresume.exe
2013-10-11 18:59:42 988216 ----a-w- c:\windows\system32\winload.exe
2013-10-11 18:59:42 40960 ----a-w- c:\windows\system32\srclient.dll
2013-10-11 18:59:42 378368 ----a-w- c:\windows\system32\srcore.dll
2013-10-11 18:59:42 318464 ----a-w- c:\windows\system32\rstrui.exe
2013-10-11 18:59:42 19000 ----a-w- c:\windows\system32\kd1394.dll
2013-10-11 18:59:42 14848 ----a-w- c:\windows\system32\srdelayed.exe
2013-10-11 18:59:41 615992 ----a-w- c:\windows\system32\ci.dll
2013-10-11 18:59:41 46592 ----a-w- c:\windows\system32\setbcdlocale.dll
2013-10-11 18:56:48 551424 ----a-w- c:\windows\system32\rpcss.dll
2013-10-11 18:56:47 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2013-10-11 18:56:46 666624 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2013-10-11 18:56:46 499200 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2013-10-11 18:56:46 247296 ----a-w- c:\windows\system32\wbem\WmiPrvSE.exe
2013-10-11 18:56:46 129024 ----a-w- c:\windows\system32\wbem\WmiDcPrv.dll
2013-10-11 18:56:45 615424 ----a-w- c:\windows\system32\wbem\fastprox.dll
2013-10-11 18:56:45 54784 ----a-w- c:\windows\system32\iasads.dll
2013-10-11 18:56:45 44032 ----a-w- c:\windows\system32\iasdatastore.dll
2013-10-11 18:56:45 17408 ----a-w- c:\windows\system32\iashost.exe
2013-10-11 18:56:44 98304 ----a-w- c:\windows\system32\iasrecst.dll
2013-10-11 18:56:44 183296 ----a-w- c:\windows\system32\sdohlp.dll
2013-10-11 18:54:59 62464 ----a-w- c:\windows\system32\l3codeca.acm
2013-10-11 18:54:59 220672 ----a-w- c:\windows\system32\l3codecp.acm
2013-10-11 18:54:45 -------- d-----w- c:\program files\common files\Hewlett-Packard
2013-10-11 18:51:53 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2013-10-11 18:51:53 190464 ----a-w- c:\windows\system32\iphlpsvc.dll
2013-10-11 18:51:53 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS
2013-10-11 18:49:55 454656 ----a-w- c:\program files\common files\system\msadc\msadce.dll
2013-10-11 18:46:55 293376 ----a-w- c:\windows\system32\browserchoice.exe
2013-10-11 18:45:04 24064 ----a-w- c:\windows\system32\amxread.dll
2013-10-11 18:45:04 13824 ----a-w- c:\windows\system32\apilogen.dll
2013-10-11 18:42:04 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2013-10-11 18:42:03 712704 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-10-11 18:42:03 347136 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-10-11 18:41:06 966656 ----a-w- c:\windows\system32\hpost_p02c.dll
2013-10-11 18:41:06 315392 ----a-w- c:\windows\system32\hposc_p02a.dll
2013-10-11 18:41:05 712704 ----a-w- c:\windows\system32\hposwia_p02c.dll
2013-10-11 18:41:05 372736 ----a-w- c:\windows\system32\hppldcoi.dll
2013-10-11 18:41:05 309760 ----a-w- c:\windows\system32\difxapi.dll
2013-10-11 18:40:31 98304 ----a-w- c:\windows\system32\cabview.dll
2013-10-11 18:40:28 452408 ----a-w- c:\windows\system32\hpzids01.dll
2013-10-11 18:40:00 123904 ----a-w- c:\windows\system32\hpf3l70v.dll
2013-10-11 18:39:54 -------- d-----w- c:\users\adb49\{ea923793-435b-419d-b4c2-385cf01d320b}
2013-10-11 18:32:11 443392 ----a-w- c:\windows\system32\win32spl.dll
2013-10-11 18:32:11 37888 ----a-w- c:\windows\system32\printcom.dll
2013-10-11 18:23:24 -------- d-----w- c:\program files\HP
2013-10-11 17:48:37 83968 ----a-w- c:\windows\system32\mscories.dll
2013-10-11 17:48:37 158720 ----a-w- c:\windows\system32\mscorier.dll
2013-10-11 17:31:06 1695744 ----a-w- c:\windows\system32\gameux.dll
2013-10-11 17:30:37 94720 ----a-w- c:\windows\system32\logagent.exe
2013-10-11 17:30:36 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2013-10-11 17:29:44 84480 ----a-w- c:\windows\system32\INETRES.dll
2013-10-11 17:29:19 61440 ----a-w- c:\windows\system32\msasn1.dll
2013-10-11 17:28:57 1645568 ----a-w- c:\windows\system32\connect.dll
2013-10-11 17:28:30 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2013-10-11 17:27:45 281600 ----a-w- c:\windows\system32\raschap.dll
2013-10-11 17:27:45 244224 ----a-w- c:\windows\system32\rastls.dll
2013-10-11 17:27:20 351232 ----a-w- c:\windows\system32\WSDApi.dll
2013-10-11 17:26:09 91136 ----a-w- c:\windows\system32\avifil32.dll
2013-10-11 17:26:09 82944 ----a-w- c:\windows\system32\mciavi32.dll
2013-10-11 17:26:09 65024 ----a-w- c:\windows\system32\avicap32.dll
2013-10-11 17:26:09 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2013-10-11 17:26:09 31744 ----a-w- c:\windows\system32\msvidc32.dll
2013-10-11 17:26:09 22528 ----a-w- c:\windows\system32\msyuv.dll
2013-10-11 17:26:09 13312 ----a-w- c:\windows\system32\msrle32.dll
2013-10-11 17:26:09 123904 ----a-w- c:\windows\system32\msvfw32.dll
2013-10-11 17:26:09 11776 ----a-w- c:\windows\system32\tsbyuv.dll
2013-10-11 17:25:26 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2013-10-11 17:24:25 7680 ----a-w- c:\windows\system32\spwmp.dll
2013-10-11 17:24:25 4096 ----a-w- c:\windows\system32\dxmasf.dll
2013-10-11 17:24:25 107520 ----a-w- c:\program files\windows media player\wmpshare.exe
2013-10-11 17:24:24 4096 ----a-w- c:\windows\system32\msdxm.ocx
2013-10-11 17:24:24 107520 ----a-w- c:\program files\windows media player\wmpconfig.exe
2013-10-11 17:24:21 310784 ----a-w- c:\windows\system32\unregmp2.exe
2013-10-11 17:24:21 1418752 ----a-w- c:\program files\windows media player\setup_wm.exe
2013-10-11 15:51:59 91544 ----a-w- c:\program files\mozilla firefox\nssdbm3.dll
2013-10-11 15:42:49 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-10-11 15:42:48 177864 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-10-11 15:42:47 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-10-11 15:42:44 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-10-11 15:41:58 -------- d-sh--w- c:\windows\Installer
2013-10-11 15:41:33 41664 ----a-w- c:\windows\avastSS.scr
2013-10-11 15:40:42 -------- d-----w- c:\program files\AVAST Software
2013-10-11 15:39:10 -------- d-----w- c:\programdata\AVAST Software
2013-10-11 15:10:46 -------- d-----w- c:\program files\Synaptics
2013-10-11 15:07:48 520192 ----a-w- c:\windows\RtlExUpd.dll
2013-10-11 15:07:48 315392 ----a-w- c:\windows\HideWin.exe
2013-10-11 15:07:43 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\ctor.dll
2013-10-11 15:07:43 32768 ----a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2013-10-11 15:07:43 274432 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iscript.dll
2013-10-11 15:07:43 204800 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iuser.dll
2013-10-11 15:07:42 757760 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iKernel.dll
2013-10-11 15:07:42 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\DotNetInstaller.exe
2013-10-11 15:07:41 200836 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iGdi.dll
2013-10-11 15:07:40 331908 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\setup.dll
2013-10-11 15:07:09 6656 ----a-w- c:\windows\system32\SiSApi.dll
2013-10-11 15:07:06 -------- d-----w- c:\program files\SiS VGA Utilities
2013-10-11 15:06:27 196608 ----a-w- c:\windows\system32\SynCtrl.dll
2013-10-11 15:06:27 187320 ----a-w- c:\windows\system32\drivers\SynTP.sys
2013-10-11 15:06:27 163840 ----a-w- c:\windows\system32\SynCOM.dll
2013-10-11 15:06:27 143360 ----a-w- c:\windows\system32\SynTPAPI.dll
2013-10-11 15:06:27 110592 ----a-w- c:\windows\system32\SynTPCo4.dll
2013-10-11 15:06:27 1060424 ----a-w- c:\windows\system32\WdfCoInstaller01000.dll
2013-10-11 15:05:46 6656 ----a-w- c:\windows\system32\SiSCo.dll
2013-10-11 15:05:46 655360 ----a-w- c:\windows\system32\SiSClone.dll
2013-10-11 15:05:46 5632 ----a-w- c:\windows\system32\SiSKrl.dll
2013-10-11 15:05:46 456568 ----a-w- c:\windows\system32\drivers\SISGRKMD.sys
2013-10-11 15:05:46 4078592 ----a-w- c:\windows\system32\SiSGlv.dll
2013-10-11 15:05:46 3625984 ----a-w- c:\windows\system32\SISGRUMD.dll
2013-10-11 15:05:46 212992 ----a-w- c:\windows\system32\SiSFunc.dll
2013-10-11 15:05:45 56184 ----a-w- c:\windows\system32\drivers\SISAGPX.SYS
2013-10-11 15:05:13 22632 ----a-w- c:\windows\system32\streamci.dll
2013-10-11 14:55:25 -------- d-----w- C:\fsc.tmp
2013-10-11 14:46:56 516784 ----a-r- c:\windows\system32\XceedCry.dll
.
==================== Find3M ====================
.
2013-10-14 12:50:57 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2013-10-14 12:50:38 82432 ----a-w- c:\windows\system32\axaltocm.dll
2013-10-12 18:08:56 36864 ----a-w- c:\windows\system32\drivers\en-us\http.sys.mui
2013-10-11 19:04:59 9892864 ----a-w- c:\windows\system32\NlsLexicons000a.dll
2013-10-11 18:45:04 40960 ----a-w- c:\windows\apppatch\apihex86.dll
2013-10-11 17:31:08 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2013-10-11 15:08:11 319456 ----a-w- c:\windows\DIFxAPI.dll
.
============= FINISH: 9:20:12.63 ===============
View attachment attach.zip
View attachment aswMBR.txt