Hoi,
Ik weet niet zeker of het virusinfection is of malware of spyware. Maar als ik een website bekijk, worden er vaak spontane nieuwe schermen geopend met reclame over het onderwerp van de oorspronkelijke site.
Onderstaand volgt het bestand van MalwareBytes en DDS. Ik probeerde GMER scanner op root kits maar mijn laptop "freezes up" als ik dat programma opstart.
Malwarebytes Anti-Malware 1.75.0.1300
Database version: v2013.07.21.04
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16635
Jan :: JAN [administrator]
7/21/2013 11:19:06 AM
mbam-log-2013-07-21 (11-19-06).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 212383
Time elapsed: 5 minute(s), 17 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 6
HKCR\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Updater.AmiUpd.1 (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Updater.AmiUpd (PUP.Software.Updater) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Users\Jan\AppData\Local\SwvUpdater\Updater.exe (PUP.Software.Updater) -> Quarantined and deleted successfully.
C:\Windows\Tasks\AmiUpdXp.job (PUP.Software.Updater) -> Quarantined and deleted successfully.
(end)
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.25.2
Run by Jan at 11:44:06 on 2013-07-21
Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.3978.2247 [GMT -4:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\dwm.exe
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
C:\Program Files (x86)\Fast Free Converter\FastFreeConverterUpdt.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
C:\Program Files (x86)\PC Checkup\SymcPCCULaunchSvc.exe
C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.15\ccSvcHst.exe
C:\Windows\system32\TODDSrv.exe
C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe
C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe
C:\Program Files\Toshiba\Teco\TecoService.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\dashost.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.15\ccSvcHst.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\windows\system32\taskhostex.exe
C:\windows\Explorer.EXE
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe
C:\windows\system32\SearchIndexer.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Toshiba\Hotkey\TCrdMain_Win8.exe
C:\Program Files\Toshiba\Teco\TecoResident.exe
C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\AppIntegrator64.exe
C:\Users\Jan\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Users\Jan\AppData\Local\Smartbar\Application\SnapDo.exe
C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Norton Anti-Theft\Engine\1.8.0.32\ccSvcHst.exe
C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
C:\Program Files (x86)\Norton Anti-Theft\Engine\1.8.0.32\ccSvcHst.exe
C:\Program Files\TOSHIBA\HDD Accelerator\THAccelSvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\taskeng.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=US&userid=f1f46ed1-ee83-443a-85d0-eabbf90ab217&searchtype=hp&installDate=21/07/2013
uWindow Title = Internet Explorer provided by TOSHIBA
uSearch Bar = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=US&userid=f1f46ed1-ee83-443a-85d0-eabbf90ab217&searchtype=ds&q={searchTerms}&installDate=21/07/2013
uSearch Page = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=US&userid=f1f46ed1-ee83-443a-85d0-eabbf90ab217&searchtype=ds&q={searchTerms}&installDate=21/07/2013
uDefault_Page_URL = hxxp://toshiba13.msn.com
mStart Page = hxxp://toshiba13.msn.com
mWindow Title = Internet Explorer provided by TOSHIBA
mDefault_Page_URL = hxxp://toshiba13.msn.com
uSearchAssistant = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=US&userid=f1f46ed1-ee83-443a-85d0-eabbf90ab217&searchtype=ds&q={searchTerms}&installDate=21/07/2013
mWinlogon: Userinit = userinit.exe,
BHO: SelectionLinks: {1C8501DD-5580-48AB-B25C-6D5DBE835A6A} - C:\Program Files (x86)\OApps\SelectionLinks.dll
BHO: DownloadTerms: {2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3} - C:\Users\Jan\AppData\Local\DownloadTerms\temp.dat
BHO: Toolbar BHO: {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
BHO: LessTabs: {3178A392-8963-471E-B7A2-969CB58D6496} - C:\Program Files (x86)\LessTabs\IE32\LessTabsClientIE.dll
BHO: Snap.DoEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coieplg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ips\ipsbho.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Wajam: {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll
BHO: Fast Free Converter 4.1: {B422F1BC-9ADB-48A7-8B13-00C176039DC5} - C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\FastFreeConverter.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\urlredir.dll
BHO: Search Assistant BHO: {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: VideoDownloadConverter: {48586425-6BB7-4F51-8DC6-38C88E3EBB58} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
TB: VideoDownloadConverter: {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
TB: Snap.Do: {ae07101b-46d4-4a98-af68-0333ea26e113} -
uRun: [SkyDrive] "C:\Users\Jan\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
uRun: [SUPERAntiSpyware] C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [AROReminder] C:\Program Files (x86)\ARO 2013\ARO.exe -rem
uRun: [Browser Infrastructure Helper] C:\Users\Jan\AppData\Local\Smartbar\Application\SnapDo.exe startup
mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun: [ToshibaAppPlace] "C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe"
mRun: [VideoDownloadConverter Search Scope Monitor] "C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zsrchmn.exe" /m=2 /w /h
mRun: [VideoDownloadConverter_4z Browser Plugin Loader] C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbrmon.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [ApnTBMon] "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
IE: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\office15\onbttnie.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll
TCP: Interfaces\{93177218-41AE-4160-A125-B4B2CE3C2635} : DHCPNameServer = 192.168.1.1 192.168.1.1
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\msosb.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings
x64-mStart Page = hxxp://toshiba13.msn.com
x64-mWindow Title = Internet Explorer provided by TOSHIBA
x64-mDefault_Page_URL = hxxp://toshiba13.msn.com
x64-BHO: Snap.DoEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL
x64-BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL
x64-TB: Snap.Do: {ae07101b-46d4-4a98-af68-0333ea26e113} -
x64-Run: [IgfxTray] C:\windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\windows\System32\igfxpers.exe
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [TCrdMain] C:\Program Files (x86)\TOSHIBA\Hotkey\TCrdMain_Win8.exe
x64-Run: [TecoResident] C:\Program Files\TOSHIBA\Teco\TecoResident.exe
x64-Run: [TosWaitSrv] C:\Program Files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
x64-Run: [TODDMain] C:\Program Files (x86)\TOSHIBA\System Setting\TODDMain.exe
x64-Run: [VideoDownloadConverter Home Page Guard 64 bit] "C:\PROGRA~2\VIDEOD~2\bar\1.bin\AppIntegrator64.exe"
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\uibsb4ew.default\
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=US&userid=f1f46ed1-ee83-443a-85d0-eabbf90ab217&searchtype=ds&installDate={installDate}&q=
FF - prefs.js: keyword.enabled - false
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\Microsoft Office 15\root\Office15\npspwrap.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
FF - plugin: C:\windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-06-13 04:51; [email protected]; C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\uibsb4ew.default\extensions\[email protected]
FF - ExtSQL: 2013-07-01 16:39; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn
FF - ExtSQL: 2013-07-01 16:39; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFFPlgn
FF - ExtSQL: 2013-07-04 20:26; [email protected]_4z.com; C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\uibsb4ew.default\extensions\[email protected] loadConverter_4z.com
FF - ExtSQL: 2013-07-21 02:11; [email protected]; C:\Program Files (x86)\Mozilla Firefox\extensions\[email protected]
FF - ExtSQL: 2013-07-21 02:11; {2C86099C-4DE0-428F-9CF4-D991A5C16CD9}; C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\uibsb4ew.default\extensions\{2C86099C-4DE0-428F-9CF4-D991A5C16CD9}
FF - ExtSQL: !HIDDEN! 2013-07-04 20:28; [email protected]_4z.com; C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin
.
---- FIREFOX POLICIES ----
user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);user_pref('extensions.blocklist.enabled', false);
============= SERVICES / DRIVERS ===============
.
R0 THAccel;THAccel;C:\windows\System32\Drivers\THAccel.sys [2013-1-20 131520]
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\windows\System32\Drivers\tos_sps64.sys [2013-1-20 499096]
R1 ccSet_NARA;NARA Settings Manager;C:\windows\System32\Drivers\NARAx64\0401000.00B\ccSetx64.sys [2012-11-13 168608]
R2 !SASCORE;SAS Core Service;C:\Program Files (x86)\SUPERAntiSpyware\SASCore.exe [2011-8-11 116608]
R2 APNMCP;Ask Update Service;C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [2013-6-13 169632]
R2 FastFreeConverterUpdt;FastFreeConverterUpdt;C:\Program Files (x86)\Fast Free Converter\FastFreeConverterUpdt.exe [2012-11-26 687104]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-1-20 129856]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-1-20 166720]
R2 NAT;Norton Anti-Theft;C:\Program Files (x86)\Norton Anti-Theft\Engine\1.8.0.32\ccsvchst.exe [2013-7-2 144368]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccsvchst.exe [2013-7-4 144368]
R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2012-7-11 3939008]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;C:\Program Files (x86)\PC Checkup\SymcPCCULaunchSvc.exe [2013-7-3 132056]
R2 OfficeSvc;Microsoft Office Service;C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-7-5 1900728]
R2 PCCUJobMgr;Common Client Job Manager Service;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.15\ccSvcHst.exe [2012-11-13 126392]
R2 THAccelSvc;TOSHIBA HDD Accelerator Service;C:\Program Files\Toshiba\HDD Accelerator\THAccelSvc.exe [2012-8-10 214488]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\Toshiba\Teco\TecoService.exe [2012-8-24 291240]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\windows\System32\Drivers\TVALZFL.sys [2012-7-21 16768]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-1-20 365376]
R2 VideoDownloadConverter_4zService;VideoDownloadConverterService;C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbars vc.exe [2013-7-4 42504]
R2 WajamUpdater;WajamUpdater;C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe [2013-5-2 109064]
R3 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [2013-7-16 1393240]
R3 ccSet_NAT;Norton Anti-Theft Settings Manager;C:\windows\System32\Drivers\NATx64\0108000.020\ccsetx64.sys [2013-7-2 169048]
R3 ccSet_NIS;Norton Internet Security Settings Manager;C:\windows\System32\Drivers\NISx64\1404000.028\ccsetx64.sys [2013-7-4 169048]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-7-4 138912]
R3 FwLnk;FwLnk Driver;C:\windows\System32\Drivers\FwLnk.sys [2013-1-20 9216]
R3 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130719.002\IDSviA64.sys [2013-7-20 513184]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;C:\windows\System32\Drivers\L1C63x64.sys [2012-7-13 103936]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\windows\System32\Drivers\RtsUVStor.sys [2013-1-20 315536]
R3 RTWlanE;Realtek Wireless LAN 802.11n PCI-E Network Adapter;C:\windows\System32\Drivers\rtwlane.sys [2012-6-29 1498256]
R3 SmbDrvI;SmbDrvI;C:\windows\System32\Drivers\Smb_driver_Intel.sys [2012-8-16 43832]
R3 SymDS;Symantec Data Store;C:\windows\System32\Drivers\NISx64\1404000.028\symds64.sys [2013-7-4 493656]
R3 SymEFA;Symantec Extended File Attributes;C:\windows\System32\Drivers\NISx64\1404000.028\symefa64.sys [2013-7-4 1139800]
R3 SymIRON;Symantec Iron Driver;C:\windows\System32\Drivers\NISx64\1404000.028\ironx64.sys [2013-7-4 224416]
R3 SymNetS;Symantec Network Security WFP Driver;C:\windows\System32\Drivers\NISx64\1404000.028\symnets.sys [2013-7-4 433752]
R3 TMachInfo;TMachInfo;C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe [2012-7-27 53384]
R3 TPCHSrv;TPCH Service;C:\Program Files\Toshiba\TPHM\TPCHSrv.exe [2012-7-28 458152]
S0 SymELAM;Symantec ELAM Driver;C:\windows\System32\Drivers\NISx64\1404000.028\symelam.sys [2013-7-4 23448]
S1 SASDIFSV;SASDIFSV;C:\Program Files (x86)\SUPERAntiSpyware\sasdifsv.sys [2011-7-22 12880]
S1 SASKUTIL;SASKUTIL;C:\Program Files (x86)\SUPERAntiSpyware\SASKUTIL.SYS [2011-7-12 67664]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\windows\System32\Drivers\rtwlane.sys [2012-6-29 1498256]
.
=============== Created Last 30 ================
.
2013-07-21 15:33:25 -------- d-----w- C:\Program Files\CCleaner
2013-07-21 15:14:16 -------- d-----w- C:\Users\Jan\AppData\Roaming\Malwarebytes
2013-07-21 15:14:05 -------- d-----w- C:\ProgramData\Malwarebytes
2013-07-21 15:14:03 25928 ----a-w- C:\windows\System32\drivers\mbam.sys
2013-07-21 15:14:03 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-21 06:15:54 -------- d-----w- C:\Users\Jan\AppData\Local\Smartbar
2013-07-21 06:11:30 -------- d-----w- C:\Program Files (x86)\Wajam
2013-07-21 06:11:11 -------- d-----w- C:\Program Files (x86)\LessTabs
2013-07-21 06:11:08 -------- d-----w- C:\Program Files (x86)\OApps
2013-07-20 19:19:44 -------- d-----w- C:\ProgramData\AskPartnerNetwork
2013-07-20 19:19:44 -------- d-----w- C:\Program Files (x86)\AskPartnerNetwork
2013-07-20 19:19:31 -------- d-----w- C:\Users\Jan\AppData\Roaming\Sammsoft
2013-07-20 19:19:20 -------- d-----w- C:\ProgramData\APN
2013-07-20 19:14:10 -------- d-----w- C:\Program Files (x86)\ARO 2013
2013-07-20 17:54:25 -------- d-----w- C:\Users\Jan\AppData\Roaming\SUPERAntiSpyware.com
2013-07-20 17:53:35 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2013-07-20 17:53:35 -------- d-----w- C:\Program Files (x86)\SUPERAntiSpyware
2013-07-17 00:38:58 252080 ----a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10210.bin
2013-07-15 23:56:01 -------- d-----w- C:\Program Files (x86)\LAVMediaCodec
2013-07-15 23:53:17 -------- d-----w- C:\Program Files (x86)\File Type Helper
2013-07-15 23:53:12 -------- d-----w- C:\Program Files (x86)\Fast Free Converter
2013-07-15 23:52:48 -------- d-----w- C:\Users\Jan\AppData\Local\DownloadTerms
2013-07-15 23:52:44 -------- d-----w- C:\Users\Jan\AppData\Local\SwvUpdater
2013-07-13 13:15:38 -------- d-----w- C:\windows\System32\MRT
2013-07-12 10:39:12 144384 ----a-w- C:\windows\System32\tssdisai.dll
2013-07-11 19:49:40 2035200 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\InkObj.dll
2013-07-11 19:49:40 1272320 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-07-11 19:49:39 1617920 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2013-07-11 19:49:39 1413632 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\InkObj.dll
2013-07-11 19:49:39 1318912 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
2013-07-11 19:49:39 1306112 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
2013-07-11 19:49:38 1029632 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\journal.dll
2013-07-11 19:49:10 4036096 ----a-w- C:\windows\System32\win32k.sys
2013-07-11 19:48:14 595968 ----a-w- C:\windows\System32\qedit.dll
2013-07-11 19:48:13 496640 ----a-w- C:\windows\SysWow64\qedit.dll
2013-07-11 19:48:12 19187712 ----a-w- C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-07-11 19:48:11 18523648 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-07-11 19:46:33 2842112 ----a-w- C:\windows\System32\WMVDECOD.DLL
2013-07-11 19:46:32 2620928 ----a-w- C:\windows\SysWow64\WMVDECOD.DLL
2013-07-06 02:25:22 -------- d-----w- C:\Users\Jan\AppData\Local\Adobe
2013-07-06 02:16:37 867240 ----a-w- C:\windows\SysWow64\npDeployJava1.dll
2013-07-06 02:16:37 789416 ----a-w- C:\windows\SysWow64\deployJava1.dll
2013-07-06 02:16:32 96168 ----a-w- C:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-06 00:18:05 -------- d-----r- C:\Users\Jan\SkyDrive
2013-07-06 00:14:09 556696 ----a-w- C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2013-07-06 00:12:10 -------- d-----w- C:\Program Files\Microsoft Office 15
2013-07-05 06:09:14 -------- d-----w- C:\Users\Jan\AppData\Local\CrashDumps
2013-07-05 05:59:59 505344 ----a-w- C:\windows\System32\SpaceControl.dll
2013-07-05 05:58:49 82944 ----a-w- C:\windows\SysWow64\dskquota.dll
2013-07-05 05:58:49 109568 ----a-w- C:\windows\System32\dskquota.dll
2013-07-05 05:58:44 929792 ----a-w- C:\windows\SysWow64\mfnetsrc.dll
2013-07-05 05:58:44 677888 ----a-w- C:\windows\System32\mfnetcore.dll
2013-07-05 05:58:44 568832 ----a-w- C:\windows\SysWow64\mfnetcore.dll
2013-07-05 05:58:44 513024 ----a-w- C:\windows\SysWow64\mfmpeg2srcsnk.dll
2013-07-05 05:58:44 1172992 ----a-w- C:\windows\System32\mfnetsrc.dll
2013-07-05 05:58:43 673280 ----a-w- C:\windows\System32\mfmpeg2srcsnk.dll
2013-07-05 05:52:53 11459584 ----a-w- C:\windows\System32\glcndFilter.dll
2013-07-05 00:28:42 -------- d-----w- C:\Program Files (x86)\Video Download Converter
2013-07-05 00:26:09 -------- d-----w- C:\Users\Jan\AppData\Local\VideoDownloadConverter_4z
2013-07-05 00:26:03 -------- d-----w- C:\Program Files (x86)\VideoDownloadConverter_4z
2013-07-04 20:49:26 78200 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-07-04 20:49:26 693112 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2013-07-04 07:59:09 493656 ----a-w- C:\windows\System32\drivers\NISx64\1404000.028\symds64.sys
2013-07-04 07:59:09 433752 ----a-w- C:\windows\System32\drivers\NISx64\1404000.028\symnets.sys
2013-07-04 07:59:09 36952 ----a-w- C:\windows\System32\drivers\NISx64\1404000.028\srtspx64.sys
2013-07-04 07:59:09 23448 ----a-r- C:\windows\System32\drivers\NISx64\1404000.028\symelam.sys
2013-07-04 07:59:09 1139800 ----a-w- C:\windows\System32\drivers\NISx64\1404000.028\symefa64.sys
2013-07-04 07:59:08 796760 ----a-w- C:\windows\System32\drivers\NISx64\1404000.028\srtsp64.sys
2013-07-04 07:59:08 224416 ----a-w- C:\windows\System32\drivers\NISx64\1404000.028\ironx64.sys
2013-07-04 07:59:08 169048 ----a-w- C:\windows\System32\drivers\NISx64\1404000.028\ccsetx64.sys
2013-07-04 07:58:34 -------- d-----w- C:\windows\System32\drivers\NISx64\1404000.028
2013-07-03 04:29:51 17888 ----a-w- C:\windows\System32\msvcr100_clr0400.dll
2013-07-03 04:29:49 17888 ----a-w- C:\windows\SysWow64\msvcr100_clr0400.dll
2013-07-03 04:23:56 1161728 ----a-w- C:\windows\System32\sppobjs.dll
2013-07-03 04:20:15 13644288 ----a-w- C:\windows\System32\Windows.UI.Xaml.dll
2013-07-03 04:20:13 10116096 ----a-w- C:\windows\System32\twinui.dll
2013-07-03 04:20:07 8857088 ----a-w- C:\windows\SysWow64\twinui.dll
2013-07-03 04:20:04 10788864 ----a-w- C:\windows\SysWow64\Windows.UI.Xaml.dll
2013-07-03 04:20:01 1131520 ----a-w- C:\windows\System32\AppXDeploymentServer.dll
2013-07-03 04:18:25 3552768 ----a-w- C:\windows\System32\tquery.dll
2013-07-03 04:18:18 2107904 ----a-w- C:\windows\System32\mssrch.dll
2013-07-03 04:18:14 2767360 ----a-w- C:\windows\SysWow64\tquery.dll
2013-07-03 04:18:10 1593344 ----a-w- C:\windows\SysWow64\mssrch.dll
2013-07-03 04:18:07 1829408 ----a-w- C:\windows\System32\ntdll.dll
2013-07-03 03:59:53 -------- d-----w- C:\Program Files (x86)\PC Checkup
2013-07-03 03:59:41 169048 ----a-w- C:\windows\System32\drivers\NATx64\0108000.020\ccsetx64.sys
2013-07-03 03:59:37 -------- d-----w- C:\windows\System32\drivers\NATx64\0108000.020
2013-07-03 03:59:23 -------- d-----w- C:\Users\Jan\AppData\Local\Programs
2013-07-02 23:28:43 1455368 ----a-w- C:\windows\System32\drivers\dxgkrnl.sys
2013-07-02 23:28:40 94208 ----a-w- C:\windows\System32\synceng.dll
2013-07-02 23:28:40 72192 ----a-w- C:\windows\SysWow64\synceng.dll
2013-07-02 23:28:17 86016 ----a-w- C:\windows\System32\ncryptsslp.dll
2013-07-02 23:28:17 71168 ----a-w- C:\windows\SysWow64\ncryptsslp.dll
2013-07-02 23:26:38 -------- d-----w- C:\Users\Jan\AppData\Roaming\PCCUStubInstaller
2013-07-02 23:20:51 945152 ----a-w- C:\windows\System32\resetengmig.dll
2013-07-02 23:18:55 96256 ----a-w- C:\windows\System32\fontsub.dll
2013-07-02 23:17:33 915968 ----a-w- C:\windows\System32\uxtheme.dll
2013-07-02 23:03:20 50784 ----a-w- C:\ProgramData\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin
2013-07-02 23:03:14 17536 ----a-w- C:\ProgramData\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-07-02 00:17:47 -------- d-----w- C:\Users\Jan\AppData\Local\Macromedia
2013-07-01 22:36:06 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2013-07-01 21:12:17 13 --sh--r- C:\windows\System32\drivers\fbd.sys
2013-07-01 20:42:55 -------- d-----w- C:\Users\Jan\AppData\Local\TOSHIBA
2013-07-01 20:42:24 -------- d-----r- C:\Users\Jan\Searches
2013-07-01 20:42:24 -------- d-----r- C:\Users\Jan\Contacts
2013-07-01 20:42:12 -------- d-----w- C:\Users\Jan\AppData\Roaming\WinBatch
2013-07-01 20:40:17 -------- d-----w- C:\Users\Jan\AppData\Local\VirtualStore
2013-07-01 20:39:23 -------- d-----w- C:\Users\Jan\AppData\Local\Packages
.
==================== Find3M ====================
.
2013-07-04 07:59:30 177312 ----a-w- C:\windows\System32\drivers\SYMEVENT64x86.SYS
2013-06-16 22:41:31 997632 ----a-w- C:\windows\System32\drivers\ndis.sys
2013-06-11 23:43:37 1767936 ----a-w- C:\windows\SysWow64\wininet.dll
2013-06-11 23:43:00 2877440 ----a-w- C:\windows\SysWow64\jscript9.dll
2013-06-11 23:26:20 2241024 ----a-w- C:\windows\System32\wininet.dll
2013-06-11 23:25:16 3958784 ----a-w- C:\windows\System32\jscript9.dll
2013-06-01 11:54:16 194816 ----a-w- C:\windows\System32\drivers\sdbus.sys
2013-06-01 11:54:10 125184 ----a-w- C:\windows\System32\drivers\dumpsd.sys
2013-06-01 11:34:21 2391280 ----a-w- C:\windows\explorer.exe
2013-06-01 11:33:13 2233600 ----a-w- C:\windows\System32\drivers\tcpip.sys
2013-06-01 11:29:35 337152 ----a-w- C:\windows\System32\drivers\USBXHCI.SYS
2013-06-01 11:29:35 213248 ----a-w- C:\windows\System32\drivers\UCX01000.SYS
2013-06-01 11:26:33 327936 ----a-w- C:\windows\System32\drivers\volsnap.sys
2013-06-01 11:26:31 6987008 ----a-w- C:\windows\System32\ntoskrnl.exe
2013-06-01 10:24:46 2106176 ----a-w- C:\windows\SysWow64\explorer.exe
2013-06-01 09:25:52 364544 ----a-w- C:\windows\SysWow64\XpsGdiConverter.dll
2013-06-01 09:25:05 67584 ----a-w- C:\windows\SysWow64\samlib.dll
2013-06-01 09:24:19 493056 ----a-w- C:\windows\SysWow64\mscms.dll
2013-06-01 09:24:09 850944 ----a-w- C:\windows\SysWow64\mfasfsrcsnk.dll
2013-06-01 09:24:09 1453568 ----a-w- C:\windows\SysWow64\mfcore.dll
2013-06-01 09:23:46 1842176 ----a-w- C:\windows\SysWow64\dwmcore.dll
2013-06-01 09:23:06 680960 ----a-w- C:\windows\System32\vds.exe
2013-06-01 09:22:47 80896 ----a-w- C:\windows\System32\MbaeParserTask.exe
2013-06-01 09:22:33 523264 ----a-w- C:\windows\System32\XpsGdiConverter.dll
2013-06-01 09:22:33 446976 ----a-w- C:\windows\System32\wwansvc.dll
2013-06-01 09:22:09 190976 ----a-w- C:\windows\System32\vdsutil.dll
2013-06-01 09:21:39 729600 ----a-w- C:\windows\System32\samsrv.dll
2013-06-01 09:21:39 106496 ----a-w- C:\windows\System32\samlib.dll
2013-06-01 09:20:45 583168 ----a-w- C:\windows\System32\mscms.dll
2013-06-01 09:20:34 1527808 ----a-w- C:\windows\System32\mfcore.dll
2013-06-01 09:20:34 1048576 ----a-w- C:\windows\System32\mfasfsrcsnk.dll
2013-06-01 09:20:04 2219520 ----a-w- C:\windows\System32\dwmcore.dll
2013-06-01 09:19:58 207872 ----a-w- C:\windows\System32\DeviceSetupManager.dll
2013-06-01 09:19:42 785408 ----a-w- C:\windows\System32\audiosrv.dll
2013-06-01 03:08:57 37632 ----a-w- C:\windows\System32\drivers\BthAvrcpTg.sys
2013-05-24 22:09:20 1403296 ----a-w- C:\windows\System32\winload.efi
2013-05-24 22:09:20 1271584 ----a-w- C:\windows\System32\winload.exe
2013-05-24 22:09:20 1217352 ----a-w- C:\windows\System32\winresume.efi
2013-05-24 22:09:20 1093904 ----a-w- C:\windows\System32\winresume.exe
2013-05-23 23:01:46 1300992 ----a-w- C:\windows\System32\gdi32.dll
2013-05-23 22:27:05 1022464 ----a-w- C:\windows\SysWow64\gdi32.dll
2013-05-15 22:37:03 44032 ----a-w- C:\windows\SysWow64\UXInit.dll
2013-05-15 22:35:49 53760 ----a-w- C:\windows\System32\UXInit.dll
2013-05-15 02:25:59 888320 ----a-w- C:\windows\System32\autochk.exe
2013-05-15 02:25:44 542208 ----a-w- C:\windows\System32\untfs.dll
2013-05-15 02:24:10 793088 ----a-w- C:\windows\SysWow64\autochk.exe
2013-05-15 02:24:01 482816 ----a-w- C:\windows\SysWow64\untfs.dll
2013-05-14 13:14:01 2706432 ----a-w- C:\windows\System32\mshtml.tlb
2013-05-14 09:23:31 2706432 ----a-w- C:\windows\SysWow64\mshtml.tlb
2013-05-04 07:58:17 120736 ----a-w- C:\windows\System32\AuthHost.exe
2013-05-04 07:34:17 446720 ----a-w- C:\windows\System32\drivers\USBHUB3.SYS
2013-05-04 07:34:15 284416 ----a-w- C:\windows\System32\drivers\spaceport.sys
2013-05-04 06:59:56 39424 ----a-w- C:\windows\System32\wuapp.exe
2013-05-04 06:59:51 1483776 ----a-w- C:\windows\System32\VSSVC.exe
2013-05-04 06:59:36 812544 ----a-w- C:\windows\System32\Magnify.exe
2013-05-04 06:59:25 98304 ----a-w- C:\windows\System32\wudriver.dll
2013-05-04 06:59:25 251904 ----a-w- C:\windows\System32\WUSettingsProvider.dll
2013-05-04 06:59:25 141824 ----a-w- C:\windows\System32\wuwebv.dll
2013-05-04 06:59:24 1619968 ----a-w- C:\windows\System32\wucltux.dll
2013-05-04 06:58:54 328192 ----a-w- C:\windows\System32\ubpm.dll
2013-05-04 06:58:49 173568 ----a-w- C:\windows\System32\storewuauth.dll
2013-05-04 06:58:49 1332736 ----a-w- C:\windows\System32\sysmain.dll
2013-05-04 06:58:48 330240 ----a-w- C:\windows\System32\stobject.dll
2013-05-04 06:58:28 93696 ----a-w- C:\windows\System32\psmsrv.dll
2013-05-04 06:58:02 470528 ----a-w- C:\windows\System32\netprofmsvc.dll
2013-05-04 06:58:02 151552 ----a-w- C:\windows\System32\netprofm.dll
2013-05-04 06:58:01 169984 ----a-w- C:\windows\System32\netplwiz.dll
2013-05-04 06:57:59 17408 ----a-w- C:\windows\System32\muifontsetup.dll
2013-05-04 06:57:46 560640 ----a-w- C:\windows\System32\mfmp4srcsnk.dll
2013-05-04 06:57:15 501760 ----a-w- C:\windows\System32\DevicePairing.dll
2013-05-04 06:57:05 179712 ----a-w- C:\windows\System32\bisrv.dll
2013-05-04 06:57:05 122368 ----a-w- C:\windows\System32\biwinrt.dll
2013-05-04 06:57:04 389120 ----a-w- C:\windows\System32\BCP47Langs.dll
2013-05-04 06:57:04 2305024 ----a-w- C:\windows\System32\authui.dll
2013-05-04 06:57:00 708096 ----a-w- C:\windows\System32\AppXDeploymentExtensions.dll
2013-05-04 06:56:53 419840 ----a-w- C:\windows\System32\intl.cpl
2013-05-04 04:58:34 34304 ----a-w- C:\windows\SysWow64\wuapp.exe
2013-05-04 04:58:14 758784 ----a-w- C:\windows\SysWow64\Magnify.exe
2013-05-04 04:58:02 83968 ----a-w- C:\windows\SysWow64\wudriver.dll
2013-05-04 04:58:02 125952 ----a-w- C:\windows\SysWow64\wuwebv.dll
2013-05-04 04:57:39 247296 ----a-w- C:\windows\SysWow64\ubpm.dll
2013-05-04 04:57:35 303616 ----a-w- C:\windows\SysWow64\stobject.dll
2013-05-04 04:57:16 18432 ----a-w- C:\windows\SysWow64\npmproxy.dll
2013-05-04 04:57:04 151040 ----a-w- C:\windows\SysWow64\netplwiz.dll
2013-05-04 04:57:04 115712 ----a-w- C:\windows\SysWow64\netprofm.dll
2013-05-04 04:57:02 14336 ----a-w- C:\windows\SysWow64\muifontsetup.dll
2013-05-04 04:56:48 411136 ----a-w- C:\windows\SysWow64\mfmp4srcsnk.dll
2013-05-04 04:56:14 449536 ----a-w- C:\windows\SysWow64\DevicePairing.dll
2013-05-04 04:56:06 92160 ----a-w- C:\windows\SysWow64\biwinrt.dll
2013-05-04 04:56:05 309760 ----a-w- C:\windows\SysWow64\BCP47Langs.dll
2013-05-04 04:56:05 2035712 ----a-w- C:\windows\SysWow64\authui.dll
2013-05-04 04:55:58 389632 ----a-w- C:\windows\SysWow64\intl.cpl
2013-05-04 04:51:38 14848 ----a-w- C:\windows\System32\rars.rs
2013-05-04 04:47:02 427520 ----a-w- C:\windows\System32\drivers\rdbss.sys
2013-05-04 04:10:47 14848 ----a-w- C:\windows\SysWow64\rars.rs
2013-04-27 05:20:12 733184 ----a-w- C:\windows\System32\win32spl.dll
2013-04-23 23:13:53 1013248 ----a-w- C:\windows\SysWow64\certutil.exe
2013-04-23 23:12:44 1569792 ----a-w- C:\windows\SysWow64\crypt32.dll
2013-04-23 23:12:44 109056 ----a-w- C:\windows\SysWow64\cryptnet.dll
2013-04-23 22:56:35 1255936 ----a-w- C:\windows\System32\certutil.exe
.
============= FINISH: 11:44:47.61 ===============
Thanks!
Jan
Ik weet niet zeker of het virusinfection is of malware of spyware. Maar als ik een website bekijk, worden er vaak spontane nieuwe schermen geopend met reclame over het onderwerp van de oorspronkelijke site.
Onderstaand volgt het bestand van MalwareBytes en DDS. Ik probeerde GMER scanner op root kits maar mijn laptop "freezes up" als ik dat programma opstart.
Malwarebytes Anti-Malware 1.75.0.1300
Database version: v2013.07.21.04
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16635
Jan :: JAN [administrator]
7/21/2013 11:19:06 AM
mbam-log-2013-07-21 (11-19-06).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 212383
Time elapsed: 5 minute(s), 17 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 6
HKCR\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Updater.AmiUpd.1 (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Updater.AmiUpd (PUP.Software.Updater) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Users\Jan\AppData\Local\SwvUpdater\Updater.exe (PUP.Software.Updater) -> Quarantined and deleted successfully.
C:\Windows\Tasks\AmiUpdXp.job (PUP.Software.Updater) -> Quarantined and deleted successfully.
(end)
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.25.2
Run by Jan at 11:44:06 on 2013-07-21
Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.3978.2247 [GMT -4:00]
.
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\dwm.exe
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
C:\Program Files (x86)\Fast Free Converter\FastFreeConverterUpdt.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
C:\Program Files (x86)\PC Checkup\SymcPCCULaunchSvc.exe
C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.15\ccSvcHst.exe
C:\Windows\system32\TODDSrv.exe
C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe
C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe
C:\Program Files\Toshiba\Teco\TecoService.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\dashost.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.15\ccSvcHst.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\windows\system32\taskhostex.exe
C:\windows\Explorer.EXE
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe
C:\windows\system32\SearchIndexer.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Toshiba\Hotkey\TCrdMain_Win8.exe
C:\Program Files\Toshiba\Teco\TecoResident.exe
C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\AppIntegrator64.exe
C:\Users\Jan\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Users\Jan\AppData\Local\Smartbar\Application\SnapDo.exe
C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Norton Anti-Theft\Engine\1.8.0.32\ccSvcHst.exe
C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
C:\Program Files (x86)\Norton Anti-Theft\Engine\1.8.0.32\ccSvcHst.exe
C:\Program Files\TOSHIBA\HDD Accelerator\THAccelSvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\taskeng.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=US&userid=f1f46ed1-ee83-443a-85d0-eabbf90ab217&searchtype=hp&installDate=21/07/2013
uWindow Title = Internet Explorer provided by TOSHIBA
uSearch Bar = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=US&userid=f1f46ed1-ee83-443a-85d0-eabbf90ab217&searchtype=ds&q={searchTerms}&installDate=21/07/2013
uSearch Page = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=US&userid=f1f46ed1-ee83-443a-85d0-eabbf90ab217&searchtype=ds&q={searchTerms}&installDate=21/07/2013
uDefault_Page_URL = hxxp://toshiba13.msn.com
mStart Page = hxxp://toshiba13.msn.com
mWindow Title = Internet Explorer provided by TOSHIBA
mDefault_Page_URL = hxxp://toshiba13.msn.com
uSearchAssistant = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=US&userid=f1f46ed1-ee83-443a-85d0-eabbf90ab217&searchtype=ds&q={searchTerms}&installDate=21/07/2013
mWinlogon: Userinit = userinit.exe,
BHO: SelectionLinks: {1C8501DD-5580-48AB-B25C-6D5DBE835A6A} - C:\Program Files (x86)\OApps\SelectionLinks.dll
BHO: DownloadTerms: {2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3} - C:\Users\Jan\AppData\Local\DownloadTerms\temp.dat
BHO: Toolbar BHO: {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
BHO: LessTabs: {3178A392-8963-471E-B7A2-969CB58D6496} - C:\Program Files (x86)\LessTabs\IE32\LessTabsClientIE.dll
BHO: Snap.DoEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coieplg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ips\ipsbho.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Wajam: {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll
BHO: Fast Free Converter 4.1: {B422F1BC-9ADB-48A7-8B13-00C176039DC5} - C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\FastFreeConverter.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\urlredir.dll
BHO: Search Assistant BHO: {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: VideoDownloadConverter: {48586425-6BB7-4F51-8DC6-38C88E3EBB58} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
TB: VideoDownloadConverter: {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
TB: Snap.Do: {ae07101b-46d4-4a98-af68-0333ea26e113} -
uRun: [SkyDrive] "C:\Users\Jan\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
uRun: [SUPERAntiSpyware] C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [AROReminder] C:\Program Files (x86)\ARO 2013\ARO.exe -rem
uRun: [Browser Infrastructure Helper] C:\Users\Jan\AppData\Local\Smartbar\Application\SnapDo.exe startup
mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun: [ToshibaAppPlace] "C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe"
mRun: [VideoDownloadConverter Search Scope Monitor] "C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zsrchmn.exe" /m=2 /w /h
mRun: [VideoDownloadConverter_4z Browser Plugin Loader] C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbrmon.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [ApnTBMon] "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
IE: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\office15\onbttnie.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll
TCP: Interfaces\{93177218-41AE-4160-A125-B4B2CE3C2635} : DHCPNameServer = 192.168.1.1 192.168.1.1
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\msosb.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings
x64-mStart Page = hxxp://toshiba13.msn.com
x64-mWindow Title = Internet Explorer provided by TOSHIBA
x64-mDefault_Page_URL = hxxp://toshiba13.msn.com
x64-BHO: Snap.DoEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL
x64-BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL
x64-TB: Snap.Do: {ae07101b-46d4-4a98-af68-0333ea26e113} -
x64-Run: [IgfxTray] C:\windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\windows\System32\igfxpers.exe
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [TCrdMain] C:\Program Files (x86)\TOSHIBA\Hotkey\TCrdMain_Win8.exe
x64-Run: [TecoResident] C:\Program Files\TOSHIBA\Teco\TecoResident.exe
x64-Run: [TosWaitSrv] C:\Program Files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
x64-Run: [TODDMain] C:\Program Files (x86)\TOSHIBA\System Setting\TODDMain.exe
x64-Run: [VideoDownloadConverter Home Page Guard 64 bit] "C:\PROGRA~2\VIDEOD~2\bar\1.bin\AppIntegrator64.exe"
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\uibsb4ew.default\
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=US&userid=f1f46ed1-ee83-443a-85d0-eabbf90ab217&searchtype=ds&installDate={installDate}&q=
FF - prefs.js: keyword.enabled - false
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\Microsoft Office 15\root\Office15\npspwrap.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
FF - plugin: C:\windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-06-13 04:51; [email protected]; C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\uibsb4ew.default\extensions\[email protected]
FF - ExtSQL: 2013-07-01 16:39; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn
FF - ExtSQL: 2013-07-01 16:39; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFFPlgn
FF - ExtSQL: 2013-07-04 20:26; [email protected]_4z.com; C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\uibsb4ew.default\extensions\[email protected] loadConverter_4z.com
FF - ExtSQL: 2013-07-21 02:11; [email protected]; C:\Program Files (x86)\Mozilla Firefox\extensions\[email protected]
FF - ExtSQL: 2013-07-21 02:11; {2C86099C-4DE0-428F-9CF4-D991A5C16CD9}; C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\uibsb4ew.default\extensions\{2C86099C-4DE0-428F-9CF4-D991A5C16CD9}
FF - ExtSQL: !HIDDEN! 2013-07-04 20:28; [email protected]_4z.com; C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin
.
---- FIREFOX POLICIES ----
user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);user_pref('extensions.blocklist.enabled', false);
============= SERVICES / DRIVERS ===============
.
R0 THAccel;THAccel;C:\windows\System32\Drivers\THAccel.sys [2013-1-20 131520]
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\windows\System32\Drivers\tos_sps64.sys [2013-1-20 499096]
R1 ccSet_NARA;NARA Settings Manager;C:\windows\System32\Drivers\NARAx64\0401000.00B\ccSetx64.sys [2012-11-13 168608]
R2 !SASCORE;SAS Core Service;C:\Program Files (x86)\SUPERAntiSpyware\SASCore.exe [2011-8-11 116608]
R2 APNMCP;Ask Update Service;C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [2013-6-13 169632]
R2 FastFreeConverterUpdt;FastFreeConverterUpdt;C:\Program Files (x86)\Fast Free Converter\FastFreeConverterUpdt.exe [2012-11-26 687104]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-1-20 129856]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-1-20 166720]
R2 NAT;Norton Anti-Theft;C:\Program Files (x86)\Norton Anti-Theft\Engine\1.8.0.32\ccsvchst.exe [2013-7-2 144368]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccsvchst.exe [2013-7-4 144368]
R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2012-7-11 3939008]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;C:\Program Files (x86)\PC Checkup\SymcPCCULaunchSvc.exe [2013-7-3 132056]
R2 OfficeSvc;Microsoft Office Service;C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-7-5 1900728]
R2 PCCUJobMgr;Common Client Job Manager Service;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.15\ccSvcHst.exe [2012-11-13 126392]
R2 THAccelSvc;TOSHIBA HDD Accelerator Service;C:\Program Files\Toshiba\HDD Accelerator\THAccelSvc.exe [2012-8-10 214488]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\Toshiba\Teco\TecoService.exe [2012-8-24 291240]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\windows\System32\Drivers\TVALZFL.sys [2012-7-21 16768]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-1-20 365376]
R2 VideoDownloadConverter_4zService;VideoDownloadConverterService;C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbars vc.exe [2013-7-4 42504]
R2 WajamUpdater;WajamUpdater;C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe [2013-5-2 109064]
R3 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [2013-7-16 1393240]
R3 ccSet_NAT;Norton Anti-Theft Settings Manager;C:\windows\System32\Drivers\NATx64\0108000.020\ccsetx64.sys [2013-7-2 169048]
R3 ccSet_NIS;Norton Internet Security Settings Manager;C:\windows\System32\Drivers\NISx64\1404000.028\ccsetx64.sys [2013-7-4 169048]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-7-4 138912]
R3 FwLnk;FwLnk Driver;C:\windows\System32\Drivers\FwLnk.sys [2013-1-20 9216]
R3 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130719.002\IDSviA64.sys [2013-7-20 513184]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;C:\windows\System32\Drivers\L1C63x64.sys [2012-7-13 103936]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\windows\System32\Drivers\RtsUVStor.sys [2013-1-20 315536]
R3 RTWlanE;Realtek Wireless LAN 802.11n PCI-E Network Adapter;C:\windows\System32\Drivers\rtwlane.sys [2012-6-29 1498256]
R3 SmbDrvI;SmbDrvI;C:\windows\System32\Drivers\Smb_driver_Intel.sys [2012-8-16 43832]
R3 SymDS;Symantec Data Store;C:\windows\System32\Drivers\NISx64\1404000.028\symds64.sys [2013-7-4 493656]
R3 SymEFA;Symantec Extended File Attributes;C:\windows\System32\Drivers\NISx64\1404000.028\symefa64.sys [2013-7-4 1139800]
R3 SymIRON;Symantec Iron Driver;C:\windows\System32\Drivers\NISx64\1404000.028\ironx64.sys [2013-7-4 224416]
R3 SymNetS;Symantec Network Security WFP Driver;C:\windows\System32\Drivers\NISx64\1404000.028\symnets.sys [2013-7-4 433752]
R3 TMachInfo;TMachInfo;C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe [2012-7-27 53384]
R3 TPCHSrv;TPCH Service;C:\Program Files\Toshiba\TPHM\TPCHSrv.exe [2012-7-28 458152]
S0 SymELAM;Symantec ELAM Driver;C:\windows\System32\Drivers\NISx64\1404000.028\symelam.sys [2013-7-4 23448]
S1 SASDIFSV;SASDIFSV;C:\Program Files (x86)\SUPERAntiSpyware\sasdifsv.sys [2011-7-22 12880]
S1 SASKUTIL;SASKUTIL;C:\Program Files (x86)\SUPERAntiSpyware\SASKUTIL.SYS [2011-7-12 67664]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\windows\System32\Drivers\rtwlane.sys [2012-6-29 1498256]
.
=============== Created Last 30 ================
.
2013-07-21 15:33:25 -------- d-----w- C:\Program Files\CCleaner
2013-07-21 15:14:16 -------- d-----w- C:\Users\Jan\AppData\Roaming\Malwarebytes
2013-07-21 15:14:05 -------- d-----w- C:\ProgramData\Malwarebytes
2013-07-21 15:14:03 25928 ----a-w- C:\windows\System32\drivers\mbam.sys
2013-07-21 15:14:03 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-21 06:15:54 -------- d-----w- C:\Users\Jan\AppData\Local\Smartbar
2013-07-21 06:11:30 -------- d-----w- C:\Program Files (x86)\Wajam
2013-07-21 06:11:11 -------- d-----w- C:\Program Files (x86)\LessTabs
2013-07-21 06:11:08 -------- d-----w- C:\Program Files (x86)\OApps
2013-07-20 19:19:44 -------- d-----w- C:\ProgramData\AskPartnerNetwork
2013-07-20 19:19:44 -------- d-----w- C:\Program Files (x86)\AskPartnerNetwork
2013-07-20 19:19:31 -------- d-----w- C:\Users\Jan\AppData\Roaming\Sammsoft
2013-07-20 19:19:20 -------- d-----w- C:\ProgramData\APN
2013-07-20 19:14:10 -------- d-----w- C:\Program Files (x86)\ARO 2013
2013-07-20 17:54:25 -------- d-----w- C:\Users\Jan\AppData\Roaming\SUPERAntiSpyware.com
2013-07-20 17:53:35 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2013-07-20 17:53:35 -------- d-----w- C:\Program Files (x86)\SUPERAntiSpyware
2013-07-17 00:38:58 252080 ----a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10210.bin
2013-07-15 23:56:01 -------- d-----w- C:\Program Files (x86)\LAVMediaCodec
2013-07-15 23:53:17 -------- d-----w- C:\Program Files (x86)\File Type Helper
2013-07-15 23:53:12 -------- d-----w- C:\Program Files (x86)\Fast Free Converter
2013-07-15 23:52:48 -------- d-----w- C:\Users\Jan\AppData\Local\DownloadTerms
2013-07-15 23:52:44 -------- d-----w- C:\Users\Jan\AppData\Local\SwvUpdater
2013-07-13 13:15:38 -------- d-----w- C:\windows\System32\MRT
2013-07-12 10:39:12 144384 ----a-w- C:\windows\System32\tssdisai.dll
2013-07-11 19:49:40 2035200 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\InkObj.dll
2013-07-11 19:49:40 1272320 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-07-11 19:49:39 1617920 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2013-07-11 19:49:39 1413632 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\InkObj.dll
2013-07-11 19:49:39 1318912 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
2013-07-11 19:49:39 1306112 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
2013-07-11 19:49:38 1029632 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\journal.dll
2013-07-11 19:49:10 4036096 ----a-w- C:\windows\System32\win32k.sys
2013-07-11 19:48:14 595968 ----a-w- C:\windows\System32\qedit.dll
2013-07-11 19:48:13 496640 ----a-w- C:\windows\SysWow64\qedit.dll
2013-07-11 19:48:12 19187712 ----a-w- C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-07-11 19:48:11 18523648 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-07-11 19:46:33 2842112 ----a-w- C:\windows\System32\WMVDECOD.DLL
2013-07-11 19:46:32 2620928 ----a-w- C:\windows\SysWow64\WMVDECOD.DLL
2013-07-06 02:25:22 -------- d-----w- C:\Users\Jan\AppData\Local\Adobe
2013-07-06 02:16:37 867240 ----a-w- C:\windows\SysWow64\npDeployJava1.dll
2013-07-06 02:16:37 789416 ----a-w- C:\windows\SysWow64\deployJava1.dll
2013-07-06 02:16:32 96168 ----a-w- C:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-06 00:18:05 -------- d-----r- C:\Users\Jan\SkyDrive
2013-07-06 00:14:09 556696 ----a-w- C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2013-07-06 00:12:10 -------- d-----w- C:\Program Files\Microsoft Office 15
2013-07-05 06:09:14 -------- d-----w- C:\Users\Jan\AppData\Local\CrashDumps
2013-07-05 05:59:59 505344 ----a-w- C:\windows\System32\SpaceControl.dll
2013-07-05 05:58:49 82944 ----a-w- C:\windows\SysWow64\dskquota.dll
2013-07-05 05:58:49 109568 ----a-w- C:\windows\System32\dskquota.dll
2013-07-05 05:58:44 929792 ----a-w- C:\windows\SysWow64\mfnetsrc.dll
2013-07-05 05:58:44 677888 ----a-w- C:\windows\System32\mfnetcore.dll
2013-07-05 05:58:44 568832 ----a-w- C:\windows\SysWow64\mfnetcore.dll
2013-07-05 05:58:44 513024 ----a-w- C:\windows\SysWow64\mfmpeg2srcsnk.dll
2013-07-05 05:58:44 1172992 ----a-w- C:\windows\System32\mfnetsrc.dll
2013-07-05 05:58:43 673280 ----a-w- C:\windows\System32\mfmpeg2srcsnk.dll
2013-07-05 05:52:53 11459584 ----a-w- C:\windows\System32\glcndFilter.dll
2013-07-05 00:28:42 -------- d-----w- C:\Program Files (x86)\Video Download Converter
2013-07-05 00:26:09 -------- d-----w- C:\Users\Jan\AppData\Local\VideoDownloadConverter_4z
2013-07-05 00:26:03 -------- d-----w- C:\Program Files (x86)\VideoDownloadConverter_4z
2013-07-04 20:49:26 78200 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-07-04 20:49:26 693112 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2013-07-04 07:59:09 493656 ----a-w- C:\windows\System32\drivers\NISx64\1404000.028\symds64.sys
2013-07-04 07:59:09 433752 ----a-w- C:\windows\System32\drivers\NISx64\1404000.028\symnets.sys
2013-07-04 07:59:09 36952 ----a-w- C:\windows\System32\drivers\NISx64\1404000.028\srtspx64.sys
2013-07-04 07:59:09 23448 ----a-r- C:\windows\System32\drivers\NISx64\1404000.028\symelam.sys
2013-07-04 07:59:09 1139800 ----a-w- C:\windows\System32\drivers\NISx64\1404000.028\symefa64.sys
2013-07-04 07:59:08 796760 ----a-w- C:\windows\System32\drivers\NISx64\1404000.028\srtsp64.sys
2013-07-04 07:59:08 224416 ----a-w- C:\windows\System32\drivers\NISx64\1404000.028\ironx64.sys
2013-07-04 07:59:08 169048 ----a-w- C:\windows\System32\drivers\NISx64\1404000.028\ccsetx64.sys
2013-07-04 07:58:34 -------- d-----w- C:\windows\System32\drivers\NISx64\1404000.028
2013-07-03 04:29:51 17888 ----a-w- C:\windows\System32\msvcr100_clr0400.dll
2013-07-03 04:29:49 17888 ----a-w- C:\windows\SysWow64\msvcr100_clr0400.dll
2013-07-03 04:23:56 1161728 ----a-w- C:\windows\System32\sppobjs.dll
2013-07-03 04:20:15 13644288 ----a-w- C:\windows\System32\Windows.UI.Xaml.dll
2013-07-03 04:20:13 10116096 ----a-w- C:\windows\System32\twinui.dll
2013-07-03 04:20:07 8857088 ----a-w- C:\windows\SysWow64\twinui.dll
2013-07-03 04:20:04 10788864 ----a-w- C:\windows\SysWow64\Windows.UI.Xaml.dll
2013-07-03 04:20:01 1131520 ----a-w- C:\windows\System32\AppXDeploymentServer.dll
2013-07-03 04:18:25 3552768 ----a-w- C:\windows\System32\tquery.dll
2013-07-03 04:18:18 2107904 ----a-w- C:\windows\System32\mssrch.dll
2013-07-03 04:18:14 2767360 ----a-w- C:\windows\SysWow64\tquery.dll
2013-07-03 04:18:10 1593344 ----a-w- C:\windows\SysWow64\mssrch.dll
2013-07-03 04:18:07 1829408 ----a-w- C:\windows\System32\ntdll.dll
2013-07-03 03:59:53 -------- d-----w- C:\Program Files (x86)\PC Checkup
2013-07-03 03:59:41 169048 ----a-w- C:\windows\System32\drivers\NATx64\0108000.020\ccsetx64.sys
2013-07-03 03:59:37 -------- d-----w- C:\windows\System32\drivers\NATx64\0108000.020
2013-07-03 03:59:23 -------- d-----w- C:\Users\Jan\AppData\Local\Programs
2013-07-02 23:28:43 1455368 ----a-w- C:\windows\System32\drivers\dxgkrnl.sys
2013-07-02 23:28:40 94208 ----a-w- C:\windows\System32\synceng.dll
2013-07-02 23:28:40 72192 ----a-w- C:\windows\SysWow64\synceng.dll
2013-07-02 23:28:17 86016 ----a-w- C:\windows\System32\ncryptsslp.dll
2013-07-02 23:28:17 71168 ----a-w- C:\windows\SysWow64\ncryptsslp.dll
2013-07-02 23:26:38 -------- d-----w- C:\Users\Jan\AppData\Roaming\PCCUStubInstaller
2013-07-02 23:20:51 945152 ----a-w- C:\windows\System32\resetengmig.dll
2013-07-02 23:18:55 96256 ----a-w- C:\windows\System32\fontsub.dll
2013-07-02 23:17:33 915968 ----a-w- C:\windows\System32\uxtheme.dll
2013-07-02 23:03:20 50784 ----a-w- C:\ProgramData\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin
2013-07-02 23:03:14 17536 ----a-w- C:\ProgramData\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-07-02 00:17:47 -------- d-----w- C:\Users\Jan\AppData\Local\Macromedia
2013-07-01 22:36:06 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2013-07-01 21:12:17 13 --sh--r- C:\windows\System32\drivers\fbd.sys
2013-07-01 20:42:55 -------- d-----w- C:\Users\Jan\AppData\Local\TOSHIBA
2013-07-01 20:42:24 -------- d-----r- C:\Users\Jan\Searches
2013-07-01 20:42:24 -------- d-----r- C:\Users\Jan\Contacts
2013-07-01 20:42:12 -------- d-----w- C:\Users\Jan\AppData\Roaming\WinBatch
2013-07-01 20:40:17 -------- d-----w- C:\Users\Jan\AppData\Local\VirtualStore
2013-07-01 20:39:23 -------- d-----w- C:\Users\Jan\AppData\Local\Packages
.
==================== Find3M ====================
.
2013-07-04 07:59:30 177312 ----a-w- C:\windows\System32\drivers\SYMEVENT64x86.SYS
2013-06-16 22:41:31 997632 ----a-w- C:\windows\System32\drivers\ndis.sys
2013-06-11 23:43:37 1767936 ----a-w- C:\windows\SysWow64\wininet.dll
2013-06-11 23:43:00 2877440 ----a-w- C:\windows\SysWow64\jscript9.dll
2013-06-11 23:26:20 2241024 ----a-w- C:\windows\System32\wininet.dll
2013-06-11 23:25:16 3958784 ----a-w- C:\windows\System32\jscript9.dll
2013-06-01 11:54:16 194816 ----a-w- C:\windows\System32\drivers\sdbus.sys
2013-06-01 11:54:10 125184 ----a-w- C:\windows\System32\drivers\dumpsd.sys
2013-06-01 11:34:21 2391280 ----a-w- C:\windows\explorer.exe
2013-06-01 11:33:13 2233600 ----a-w- C:\windows\System32\drivers\tcpip.sys
2013-06-01 11:29:35 337152 ----a-w- C:\windows\System32\drivers\USBXHCI.SYS
2013-06-01 11:29:35 213248 ----a-w- C:\windows\System32\drivers\UCX01000.SYS
2013-06-01 11:26:33 327936 ----a-w- C:\windows\System32\drivers\volsnap.sys
2013-06-01 11:26:31 6987008 ----a-w- C:\windows\System32\ntoskrnl.exe
2013-06-01 10:24:46 2106176 ----a-w- C:\windows\SysWow64\explorer.exe
2013-06-01 09:25:52 364544 ----a-w- C:\windows\SysWow64\XpsGdiConverter.dll
2013-06-01 09:25:05 67584 ----a-w- C:\windows\SysWow64\samlib.dll
2013-06-01 09:24:19 493056 ----a-w- C:\windows\SysWow64\mscms.dll
2013-06-01 09:24:09 850944 ----a-w- C:\windows\SysWow64\mfasfsrcsnk.dll
2013-06-01 09:24:09 1453568 ----a-w- C:\windows\SysWow64\mfcore.dll
2013-06-01 09:23:46 1842176 ----a-w- C:\windows\SysWow64\dwmcore.dll
2013-06-01 09:23:06 680960 ----a-w- C:\windows\System32\vds.exe
2013-06-01 09:22:47 80896 ----a-w- C:\windows\System32\MbaeParserTask.exe
2013-06-01 09:22:33 523264 ----a-w- C:\windows\System32\XpsGdiConverter.dll
2013-06-01 09:22:33 446976 ----a-w- C:\windows\System32\wwansvc.dll
2013-06-01 09:22:09 190976 ----a-w- C:\windows\System32\vdsutil.dll
2013-06-01 09:21:39 729600 ----a-w- C:\windows\System32\samsrv.dll
2013-06-01 09:21:39 106496 ----a-w- C:\windows\System32\samlib.dll
2013-06-01 09:20:45 583168 ----a-w- C:\windows\System32\mscms.dll
2013-06-01 09:20:34 1527808 ----a-w- C:\windows\System32\mfcore.dll
2013-06-01 09:20:34 1048576 ----a-w- C:\windows\System32\mfasfsrcsnk.dll
2013-06-01 09:20:04 2219520 ----a-w- C:\windows\System32\dwmcore.dll
2013-06-01 09:19:58 207872 ----a-w- C:\windows\System32\DeviceSetupManager.dll
2013-06-01 09:19:42 785408 ----a-w- C:\windows\System32\audiosrv.dll
2013-06-01 03:08:57 37632 ----a-w- C:\windows\System32\drivers\BthAvrcpTg.sys
2013-05-24 22:09:20 1403296 ----a-w- C:\windows\System32\winload.efi
2013-05-24 22:09:20 1271584 ----a-w- C:\windows\System32\winload.exe
2013-05-24 22:09:20 1217352 ----a-w- C:\windows\System32\winresume.efi
2013-05-24 22:09:20 1093904 ----a-w- C:\windows\System32\winresume.exe
2013-05-23 23:01:46 1300992 ----a-w- C:\windows\System32\gdi32.dll
2013-05-23 22:27:05 1022464 ----a-w- C:\windows\SysWow64\gdi32.dll
2013-05-15 22:37:03 44032 ----a-w- C:\windows\SysWow64\UXInit.dll
2013-05-15 22:35:49 53760 ----a-w- C:\windows\System32\UXInit.dll
2013-05-15 02:25:59 888320 ----a-w- C:\windows\System32\autochk.exe
2013-05-15 02:25:44 542208 ----a-w- C:\windows\System32\untfs.dll
2013-05-15 02:24:10 793088 ----a-w- C:\windows\SysWow64\autochk.exe
2013-05-15 02:24:01 482816 ----a-w- C:\windows\SysWow64\untfs.dll
2013-05-14 13:14:01 2706432 ----a-w- C:\windows\System32\mshtml.tlb
2013-05-14 09:23:31 2706432 ----a-w- C:\windows\SysWow64\mshtml.tlb
2013-05-04 07:58:17 120736 ----a-w- C:\windows\System32\AuthHost.exe
2013-05-04 07:34:17 446720 ----a-w- C:\windows\System32\drivers\USBHUB3.SYS
2013-05-04 07:34:15 284416 ----a-w- C:\windows\System32\drivers\spaceport.sys
2013-05-04 06:59:56 39424 ----a-w- C:\windows\System32\wuapp.exe
2013-05-04 06:59:51 1483776 ----a-w- C:\windows\System32\VSSVC.exe
2013-05-04 06:59:36 812544 ----a-w- C:\windows\System32\Magnify.exe
2013-05-04 06:59:25 98304 ----a-w- C:\windows\System32\wudriver.dll
2013-05-04 06:59:25 251904 ----a-w- C:\windows\System32\WUSettingsProvider.dll
2013-05-04 06:59:25 141824 ----a-w- C:\windows\System32\wuwebv.dll
2013-05-04 06:59:24 1619968 ----a-w- C:\windows\System32\wucltux.dll
2013-05-04 06:58:54 328192 ----a-w- C:\windows\System32\ubpm.dll
2013-05-04 06:58:49 173568 ----a-w- C:\windows\System32\storewuauth.dll
2013-05-04 06:58:49 1332736 ----a-w- C:\windows\System32\sysmain.dll
2013-05-04 06:58:48 330240 ----a-w- C:\windows\System32\stobject.dll
2013-05-04 06:58:28 93696 ----a-w- C:\windows\System32\psmsrv.dll
2013-05-04 06:58:02 470528 ----a-w- C:\windows\System32\netprofmsvc.dll
2013-05-04 06:58:02 151552 ----a-w- C:\windows\System32\netprofm.dll
2013-05-04 06:58:01 169984 ----a-w- C:\windows\System32\netplwiz.dll
2013-05-04 06:57:59 17408 ----a-w- C:\windows\System32\muifontsetup.dll
2013-05-04 06:57:46 560640 ----a-w- C:\windows\System32\mfmp4srcsnk.dll
2013-05-04 06:57:15 501760 ----a-w- C:\windows\System32\DevicePairing.dll
2013-05-04 06:57:05 179712 ----a-w- C:\windows\System32\bisrv.dll
2013-05-04 06:57:05 122368 ----a-w- C:\windows\System32\biwinrt.dll
2013-05-04 06:57:04 389120 ----a-w- C:\windows\System32\BCP47Langs.dll
2013-05-04 06:57:04 2305024 ----a-w- C:\windows\System32\authui.dll
2013-05-04 06:57:00 708096 ----a-w- C:\windows\System32\AppXDeploymentExtensions.dll
2013-05-04 06:56:53 419840 ----a-w- C:\windows\System32\intl.cpl
2013-05-04 04:58:34 34304 ----a-w- C:\windows\SysWow64\wuapp.exe
2013-05-04 04:58:14 758784 ----a-w- C:\windows\SysWow64\Magnify.exe
2013-05-04 04:58:02 83968 ----a-w- C:\windows\SysWow64\wudriver.dll
2013-05-04 04:58:02 125952 ----a-w- C:\windows\SysWow64\wuwebv.dll
2013-05-04 04:57:39 247296 ----a-w- C:\windows\SysWow64\ubpm.dll
2013-05-04 04:57:35 303616 ----a-w- C:\windows\SysWow64\stobject.dll
2013-05-04 04:57:16 18432 ----a-w- C:\windows\SysWow64\npmproxy.dll
2013-05-04 04:57:04 151040 ----a-w- C:\windows\SysWow64\netplwiz.dll
2013-05-04 04:57:04 115712 ----a-w- C:\windows\SysWow64\netprofm.dll
2013-05-04 04:57:02 14336 ----a-w- C:\windows\SysWow64\muifontsetup.dll
2013-05-04 04:56:48 411136 ----a-w- C:\windows\SysWow64\mfmp4srcsnk.dll
2013-05-04 04:56:14 449536 ----a-w- C:\windows\SysWow64\DevicePairing.dll
2013-05-04 04:56:06 92160 ----a-w- C:\windows\SysWow64\biwinrt.dll
2013-05-04 04:56:05 309760 ----a-w- C:\windows\SysWow64\BCP47Langs.dll
2013-05-04 04:56:05 2035712 ----a-w- C:\windows\SysWow64\authui.dll
2013-05-04 04:55:58 389632 ----a-w- C:\windows\SysWow64\intl.cpl
2013-05-04 04:51:38 14848 ----a-w- C:\windows\System32\rars.rs
2013-05-04 04:47:02 427520 ----a-w- C:\windows\System32\drivers\rdbss.sys
2013-05-04 04:10:47 14848 ----a-w- C:\windows\SysWow64\rars.rs
2013-04-27 05:20:12 733184 ----a-w- C:\windows\System32\win32spl.dll
2013-04-23 23:13:53 1013248 ----a-w- C:\windows\SysWow64\certutil.exe
2013-04-23 23:12:44 1569792 ----a-w- C:\windows\SysWow64\crypt32.dll
2013-04-23 23:12:44 109056 ----a-w- C:\windows\SysWow64\cryptnet.dll
2013-04-23 22:56:35 1255936 ----a-w- C:\windows\System32\certutil.exe
.
============= FINISH: 11:44:47.61 ===============
Thanks!
Jan
Comment