Sorry had ik niet gezien, ik heb gewoon de 1e link aangeklikt
nu wel goed hopelijk ??
enneuh..bedankt voor je geduld
DDS (Ver_2012-11-07.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16450 BrowserJavaVersion: 10.9.2
Run by Anca at 14:14:56 on 2012-11-09
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3691.2307
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Windows\SysWOW64\ezSharedSvcHost.exe
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe
C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Windows\system32\SearchIndexer.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Aanmeldhulp voor Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: “C:\Users\Anca\AppData\Local\Facebook\Update\FacebookUpdate.exe” /c /nocrashserver
mRun: “C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun
mRun: “C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe”
mRun: C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: “C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe”
mRun: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
mRun: C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun: C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
mRun: “C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe” /d=60
mRun: “C:\Program Files\AVAST Software\Avast\avastUI.exe” /nogui
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: EnableShellExecuteHooks = dword:1
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: HideFastUserSwitching = dword:0
IE: Afbeelding verzenden naar &Bluetooth-apparaat… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Pagina verzenden naar &Bluetooth-apparaat… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the ‘Force scan all domains’ option.
.
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: NameServer = 192.168.2.254
TCP: Interfaces\{490A553E-01A7-4292-9E78-E3F2B990C2A1} : DHCPNameServer = 192.168.2.254
TCP: Interfaces\{490A553E-01A7-4292-9E78-E3F2B990C2A1}\16B6B65627D616E637 : DHCPNameServer = 192.168.7.1 192.168.7.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck -
SEH: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll
LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} -
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Anca\AppData\Roaming\Mozilla\Firefox\Profiles\v8056ts0.default\
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Anca\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF - plugin: C:\Users\Anca\AppData\Roaming\Mozilla\Firefox\Profiles\v8056ts0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2012-10-28 15:19; {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}; C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
FF - ExtSQL: 2012-10-29 20:38; {e001c731-5e37-4538-a5cb-8168736a2360}; C:\Users\Anca\AppData\Roaming\Mozilla\Firefox\Profiles\v8056ts0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
FF - ExtSQL: 2012-11-09 00:08; wrc@avast.com; C:\Program Files\AVAST Software\Avast\WebRep\FF
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys
R1 A2DDA;A2 Direct Disk Access Support Driver;C:\Users\Anca\Downloads\EmsisoftEmergencyKit\Run\a2ddax64.sys
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys
R2 a2AntiMalware;Emsisoft Anti-Malware 7.0 - Service;C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
R2 ezSharedSvc;Easybits Services for Windows;C:\Windows\System32\ezSharedSvcHost.exe –> C:\Windows\System32\ezSharedSvcHost.exe
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\System32\drivers\bcbtums.sys
R3 btwampfl;btwampfl;C:\Windows\System32\drivers\btwampfl.sys
R3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\System32\drivers\btwdpan.sys
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe
S3 a2acc;a2acc;C:\Program Files (x86)\Emsisoft Anti-Malware\a2accx64.sys
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys
S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
.
=============== Created Last 30 ================
.
2012-11-09 12:25:28 9291768 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F70FD25A-493D-4041-909C-82E64927C3EA}\mpengine.dll
2012-11-08 22:49:36 54072 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys
2012-11-08 22:49:34 984144 —-a-w- C:\Windows\System32\drivers\aswSnx.sys
2012-11-08 22:49:27 71600 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2012-11-08 22:49:02 41224 —-a-w- C:\Windows\avastSS.scr
2012-11-08 22:15:02 24064 —-a-w- C:\Windows\zoek-delete.exe
2012-11-08 22:15:02 ——– d—–w- C:\Users\Anca\AppData\Local\Temp
2012-10-31 08:54:29 ——– d-sh–w- C:\$RECYCLE.BIN
2012-10-30 18:52:38 ——– d—–w- C:\ComboFix
2012-10-29 19:37:55 ——– d—–w- C:\Users\Anca\AppData\Local\Macromedia
2012-10-29 19:24:26 696760 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-10-29 19:15:11 3584 —-a-w- C:\Windows\System32\drivers\nl-NL\tsusbflt.sys.mui
2012-10-29 19:15:09 13312 —-a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2012-10-29 19:15:08 15360 —-a-w- C:\Windows\System32\RdpGroupPolicyExtension.dll
2012-10-29 19:15:08 13312 —-a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
2012-10-29 19:15:00 19456 —-a-w- C:\Windows\System32\drivers\rdpvideominiport.sys
2012-10-29 19:11:46 340992 —-a-w- C:\Windows\System32\schannel.dll
2012-10-29 19:11:46 247808 —-a-w- C:\Windows\SysWow64\schannel.dll
2012-10-29 19:11:45 458712 —-a-w- C:\Windows\System32\drivers\cng.sys
2012-10-29 19:11:45 307200 —-a-w- C:\Windows\System32\ncrypt.dll
2012-10-29 19:11:45 154480 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-10-29 19:11:44 220160 —-a-w- C:\Windows\SysWow64\ncrypt.dll
2012-10-29 19:11:44 1448448 —-a-w- C:\Windows\System32\lsasrv.dll
2012-10-29 19:11:43 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll
2012-10-29 19:11:43 22016 —-a-w- C:\Windows\SysWow64\secur32.dll
2012-10-29 19:11:39 514560 —-a-w- C:\Windows\SysWow64\qdvd.dll
2012-10-29 19:11:39 366592 —-a-w- C:\Windows\System32\qdvd.dll
2012-10-29 18:55:14 95208 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2012-10-28 21:36:43 98816 —-a-w- C:\Windows\sed.exe
2012-10-28 21:36:43 256000 —-a-w- C:\Windows\PEV.exe
2012-10-28 21:36:43 208896 —-a-w- C:\Windows\MBR.exe
2012-10-27 18:01:12 ——– d—–w- C:\ProgramData\clp
2012-10-27 18:00:48 ——– d—–w- C:\Users\Anca\AppData\Roaming\Fighters
2012-10-27 17:59:56 ——– d—–w- C:\ProgramData\Common Toolkit Suite
2012-10-27 17:58:09 ——– d—–w- C:\ProgramData\Fighters
2012-10-27 14:51:27 ——– d—–w- C:\Program Files (x86)\Emsisoft Anti-Malware
2012-10-10 14:36:53 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2012-10-10 14:36:53 2048 —-a-w- C:\Windows\System32\tzres.dll
2012-10-10 14:36:37 715776 —-a-w- C:\Windows\System32\kerberos.dll
2012-10-10 14:36:37 542208 —-a-w- C:\Windows\SysWow64\kerberos.dll
2012-10-10 14:36:11 1464320 —-a-w- C:\Windows\System32\crypt32.dll
2012-10-10 14:36:11 1159680 —-a-w- C:\Windows\SysWow64\crypt32.dll
2012-10-10 14:36:10 184320 —-a-w- C:\Windows\System32\cryptsvc.dll
2012-10-10 14:36:10 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-10-10 14:36:10 140288 —-a-w- C:\Windows\System32\cryptnet.dll
2012-10-10 14:36:10 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll
.
==================== Find3M ====================
.
2012-10-29 19:51:15 73656 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-29 17:54:26 25928 —-a-w- C:\Windows\System32\drivers\mbam.sys
2012-09-27 20:26:59 821736 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-09-27 20:26:59 746984 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2012-08-31 18:19:35 1659760 —-a-w- C:\Windows\System32\drivers\ntfs.sys
2012-08-30 18:03:45 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe
2012-08-30 17:12:02 3968880 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12:02 3914096 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-08-24 18:05:07 220160 —-a-w- C:\Windows\System32\wintrust.dll
2012-08-24 16:57:48 172544 —-a-w- C:\Windows\SysWow64\wintrust.dll
2012-08-24 10:31:32 2312704 —-a-w- C:\Windows\System32\jscript9.dll
2012-08-24 10:21:18 1392128 —-a-w- C:\Windows\System32\wininet.dll
2012-08-24 10:20:11 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl
2012-08-24 10:14:45 173056 —-a-w- C:\Windows\System32\ieUnatt.exe
2012-08-24 10:13:29 599040 —-a-w- C:\Windows\System32\vbscript.dll
2012-08-24 10:09:42 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2012-08-24 06:59:17 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll
2012-08-24 06:51:27 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll
2012-08-24 06:51:02 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-08-24 06:47:26 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-08-24 06:47:12 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll
2012-08-24 06:43:58 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2012-08-23 14:13:11 243200 —-a-w- C:\Windows\System32\rdpudd.dll
2012-08-23 14:08:26 30208 —-a-w- C:\Windows\System32\drivers\TsUsbGD.sys
2012-08-23 14:07:35 57856 —-a-w- C:\Windows\System32\drivers\TsUsbFlt.sys
2012-08-23 13:47:20 46592 —-a-w- C:\Windows\SysWow64\MsRdpWebAccess.dll
2012-08-23 13:46:20 16896 —-a-w- C:\Windows\SysWow64\wksprtPS.dll
2012-08-23 13:20:40 54272 —-a-w- C:\Windows\System32\MsRdpWebAccess.dll
2012-08-23 13:18:14 37376 —-a-w- C:\Windows\SysWow64\tsgqec.dll
2012-08-23 13:17:54 18432 —-a-w- C:\Windows\System32\wksprtPS.dll
2012-08-23 13:06:58 43520 —-a-w- C:\Windows\System32\TsUsbGDCoInstaller.dll
2012-08-23 12:52:53 44032 —-a-w- C:\Windows\System32\tsgqec.dll
2012-08-23 11:20:06 62976 —-a-w- C:\Windows\System32\TSWbPrxy.exe
2012-08-23 11:15:57 269312 —-a-w- C:\Windows\SysWow64\aaclient.dll
2012-08-23 11:14:09 384000 —-a-w- C:\Windows\System32\wksprt.exe
2012-08-23 11:12:17 192000 —-a-w- C:\Windows\SysWow64\rdpendp_winip.dll
2012-08-23 10:54:24 322560 —-a-w- C:\Windows\System32\aaclient.dll
2012-08-23 10:51:14 228864 —-a-w- C:\Windows\System32\rdpendp_winip.dll
2012-08-23 10:39:24 1048064 —-a-w- C:\Windows\SysWow64\mstsc.exe
2012-08-23 10:22:22 1123840 —-a-w- C:\Windows\System32\mstsc.exe
2012-08-23 09:51:57 3174912 —-a-w- C:\Windows\System32\rdpcorets.dll
2012-08-23 08:19:01 4916224 —-a-w- C:\Windows\SysWow64\mstscax.dll
2012-08-23 08:13:07 5773824 —-a-w- C:\Windows\System32\mstscax.dll
2012-08-22 18:12:50 1913200 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2012-08-22 18:12:40 950128 —-a-w- C:\Windows\System32\drivers\ndis.sys
2012-08-22 18:12:40 376688 —-a-w- C:\Windows\System32\drivers\netio.sys
2012-08-22 18:12:33 288624 —-a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2012-08-21 21:01:00 245760 —-a-w- C:\Windows\System32\OxpsConverter.exe
2012-08-20 18:48:44 362496 —-a-w- C:\Windows\System32\wow64win.dll
2012-08-20 18:48:44 243200 —-a-w- C:\Windows\System32\wow64.dll
2012-08-20 18:48:44 13312 —-a-w- C:\Windows\System32\wow64cpu.dll
2012-08-20 18:48:43 215040 —-a-w- C:\Windows\System32\winsrv.dll
2012-08-20 18:48:37 16384 —-a-w- C:\Windows\System32\ntvdm64.dll
2012-08-20 18:48:35 424448 —-a-w- C:\Windows\System32\KernelBase.dll
2012-08-20 18:46:22 338432 —-a-w- C:\Windows\System32\conhost.exe
2012-08-20 17:40:21 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-08-20 17:38:44 44032 —-a-w- C:\Windows\apppatch\acwow64.dll
2012-08-20 17:38:26 25600 —-a-w- C:\Windows\SysWow64\setup16.exe
2012-08-20 17:37:19 5120 —-a-w- C:\Windows\SysWow64\wow32.dll
2012-08-20 17:37:18 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll
2012-08-20 15:38:21 7680 —-a-w- C:\Windows\SysWow64\instnm.exe
2012-08-20 15:38:20 2048 —-a-w- C:\Windows\SysWow64\user.exe
2012-08-20 15:33:28 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-08-20 15:33:28 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-08-20 15:33:28 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-08-20 15:33:28 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
.
============= FINISH: 14:15:28,95 ===============