Når jeg åbner en ny browser i Explorer, åbnes den i Facemoods. Jeg tror, at det er en malware. Jeg har fjernet programmet via kontrolpanelet, men det er tilsynelande ikke nok.
Jeg ved ikke, om der er nogen sammenhæng til, at min maskine umotiveret har genstartet et par gange over det sidste døgn.
Jeg har kørt CCleaner og Malwarebytes men ikke det sidste Super et eller andet, da den sagde, at der var et kompatibilitetsproblem.
Herunder logs:
Malwarebytes’ Anti-Malware 1.46
http://www.malwarebytes.org
Database version: 8365
Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514
15-12-2011 09:04:39
mbam-log-2011-12-15 (09-04-39).txt
Skanningstype: Fuldstændig skanning (C:\|G:\|)
Objekter skannet: 288235
Tid gået: 44 minut(ter), 8 sekund(er)
Hukommelses Processorer Inficeret: 0
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 0
Registreringsdatabaseværdier Inficeret: 0
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 0
Inficerede Filer: 0
Hukommelses Processorer Inficeret:
(Ingen skadelige objekter blev fundet)
Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)
Registreringsdatabasenøgler Inficeret:
(Ingen skadelige objekter blev fundet)
Registreringsdatabaseværdier Inficeret:
(Ingen skadelige objekter blev fundet)
Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)
Inficerede Mapper:
(Ingen skadelige objekter blev fundet)
Inficerede Filer:
(Ingen skadelige objekter blev fundet)
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514
Run by KPK at 10:34:41 on 2011-12-15
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.45.1030.18.8173.5362 [GMT 1:00]
.
AV: BullGuard Antivirus *Enabled/Updated* {504FFF66-3028-EB7E-2E60-62B19ADD791C}
SP: BullGuard Antispyware *Enabled/Updated* {EB2E1E82-1612-E4F0-14D0-59C3E15A33A1}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: BullGuard Firewall *Enabled* {68747E43-7A47-EA26-053F-CB84640E3E67}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ATKFUSService.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\SysWOW64\ASDR.exe
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardBhvScanner.exe
C:\Windows\System32\SvcHost.exe -k BullGuard_LowPriv
C:\Windows\System32\SvcHost.exe -k BullGuard
C:\Windows\System32\SvcHost.exe -k BullGuard_Main
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardScanner.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Logitech\SetPoint\LBTWiz.exe
C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
C:\Program Files\ASUS\GamerOSD\ATKFastUserSwitching.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files (x86)\SlySoft\AnyDVD\ADvdDiscHlp64.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\ASUS\GamerOSD\GamerOSD.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
C:\Program Files\BullGuard Ltd\BullGuard\files32\spamfilter\LittleHook.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe
C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.dk/
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
uURLSearchHooks: SearchHook Class: {bc86e1ab-eda5-4059-938f-ce307b0c6f0a} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Hjælp til logon til Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: BullGuard Safe Browsing: {fc872b94-35e3-4b94-b028-184a2a1c7cce} - C:\Program Files\BullGuard Ltd\BullGuard\Files32\Antiphishing\IE\BGAntiphishingIEBHO.dll
TB: {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - No File
TB: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
TB: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
uRun: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
uRun: [Spotify] “C:\Users\KPK\AppData\Roaming\Spotify\Spotify.exe” /uri spotify:autostart
mRun: [BCU] “C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe”
mRun: [NUSB3MON] “C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe”
mRun: [ASUSGamerOSD] C:\Program Files (x86)\ASUS\GamerOSD\GamerOSD.exe
mRun: [Adobe Reader Speed Launcher] “C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe”
mRun: [Adobe ARM] “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
mRun: [ConnectionCenter] “C:\Program Files (x86)\Citrix\ICA Client\concentr.exe” /startup
mRun: [SunJavaUpdateSched] “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
mRun: [BCSSync] “C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe” /DelayServices
mRun: [APSDaemon] “C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe”
mRun: [QuickTime Task] “C:\Program Files (x86)\QuickTime\QTTask.exe” -atboottime
mRun: [iTunesHelper] “C:\Program Files (x86)\iTunes\iTunesHelper.exe”
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\LOGITE~1.LNK - C:\Program Files\Logitech\SetPoint\SetPoint.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&ksporter; til Microsoft Excel - C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: S&end; til OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - C:\Program Files\BullGuard Ltd\BullGuard\Files32\Antiphishing\IE\BGAntiphishingIE.dll
LSP: C:\Windows\system32\BGLsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://connect.bankdata.dk/dana-cached/sc/JuniperSetupClient.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{50202FC4-429F-4275-A706-595762645CBA} : DhcpNameServer = 192.168.0.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: bglink - {FC872B94-35E3-4B94-B028-184A2A1C7CCE} - C:\Program Files\BullGuard Ltd\BullGuard\Files32\Antiphishing\IE\BGAntiphishingIEBHO.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: BgGamingMonitor.dll
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{9FDDE16B-836F-4806-AB1F-1455CBEFF289}
{B4F3A835-0E21-4959-BA22-42B3008E02FF}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{FC872B94-35E3-4B94-B028-184A2A1C7CCE}
TB-X64: {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - No File
TB-X64: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
TB-X64: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
mRun-x64: [BCU] “C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe”
mRun-x64: [NUSB3MON] “C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe”
mRun-x64: [ASUSGamerOSD] C:\Program Files (x86)\ASUS\GamerOSD\GamerOSD.exe
mRun-x64: [Adobe Reader Speed Launcher] “C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe”
mRun-x64: [Adobe ARM] “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
mRun-x64: [ConnectionCenter] “C:\Program Files (x86)\Citrix\ICA Client\concentr.exe” /startup
mRun-x64: [SunJavaUpdateSched] “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
mRun-x64: [BCSSync] “C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe” /DelayServices
mRun-x64: [APSDaemon] “C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe”
mRun-x64: [QuickTime Task] “C:\Program Files (x86)\QuickTime\QTTask.exe” -atboottime
mRun-x64: [iTunesHelper] “C:\Program Files (x86)\iTunes\iTunesHelper.exe”
AppInit_DLLs-X64: BgGamingMonitor.dll
.
============= SERVICES / DRIVERS ===============
.
R1 AFW;Agnitum Firewall Driver;C:\Windows\system32\DRIVERS\afw.sys—> C:\Windows\system32\DRIVERS\afw.sys [?]
R1 BdSpy;BdSpy;C:\Windows\system32\DRIVERS\BdSpy.sys—> C:\Windows\system32\DRIVERS\BdSpy.sys [?]
R1 EIO64;EIO Driver;C:\Windows\system32\DRIVERS\EIO64.sys—> C:\Windows\system32\DRIVERS\EIO64.sys [?]
R1 NovaShieldFilterDriver;NovaShieldFilterDriver;C:\Windows\system32\DRIVERS\NSKernel.sys—> C:\Windows\system32\DRIVERS\NSKernel.sys [?]
R1 NovaShieldTDIDriver;NovaShieldTDIDriver;C:\Windows\system32\DRIVERS\NSNetmon.sys—> C:\Windows\system32\DRIVERS\NSNetmon.sys [?]
R2 BCUService;Browser Configuration Utility Service;C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-3-5 235752]
R2 BsBhvScan;BullGuard Behavioural Detection;C:\Program Files\BullGuard Ltd\BullGuard\BullGuardBhvScanner.exe [2011-9-18 382808]
R2 BsBrowser;BullGuard antiphishing service;C:\Windows\System32\SvcHost.exe -k BullGuard_LowPriv [2009-7-14 20992]
R2 BsFileScan;BullGuard on-access service;C:\Windows\System32\SvcHost.exe -k BullGuard [2009-7-14 20992]
R2 BsFire;BullGuard firewall service;C:\Windows\System32\SvcHost.exe -k BullGuard [2009-7-14 20992]
R2 BsMailProxy;BullGuard e-mail monitoring service;C:\Windows\System32\SvcHost.exe -k BullGuard [2009-7-14 20992]
R2 BsMain;BullGuard main service;C:\Windows\System32\SvcHost.exe -k BullGuard_Main [2009-7-14 20992]
R2 BsUpdate;BullGuard update service;C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe [2011-7-5 392536]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-8-19 235624]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-5-13 2656280]
R2 UsbClientService;UsbClientService;C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [2011-2-18 245760]
R3 afwcore;afwcore;C:\Windows\system32\DRIVERS\afwcore.sys—> C:\Windows\system32\DRIVERS\afwcore.sys [?]
R3 BsScanner;BullGuard scanning service;C:\Program Files\BullGuard Ltd\BullGuard\BullGuardScanner.exe [2011-11-10 341848]
R3 busenum;Synology Virtual USB Hub;C:\Windows\system32\DRIVERS\busenum.sys—> C:\Windows\system32\DRIVERS\busenum.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys—> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys—> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys—> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys—> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys—> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R4 IOMap;IOMap;\??\C:\Windows\system32\drivers\IOMap64.sys—> C:\Windows\system32\drivers\IOMap64.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 BgRaSvc;BgRaSvc;C:\Program Files\BullGuard Ltd\BullGuard\Support\BgRaSvc.exe [2011-7-5 161112]
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys—> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-22 1493352]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;C:\Windows\System32\svchost.exe -k nosGetPlusHelper [2009-7-14 20992]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys—> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys—> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys—> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Tjenesten Windows Aktivering;C:\Windows\system32\Wat\WatAdminSvc.exe—> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-12-15 05:52:31 ———— d——-w- C:\Users\KPK\AppData\Local\{DB413BBB-F5A3-4F5A-996C-DB781B354FF6}
2011-12-15 05:52:20 ———— d——-w- C:\Users\KPK\AppData\Local\{1D55895F-9DA4-4A05-92C8-F4477FE00442}
2011-12-14 20:21:35 3145216 ——a-w- C:\Windows\System32\win32k.sys
2011-12-14 20:21:33 723456 ——a-w- C:\Windows\System32\EncDec.dll
2011-12-14 20:21:33 534528 ——a-w- C:\Windows\SysWow64\EncDec.dll
2011-12-14 20:21:29 2048 ——a-w- C:\Windows\SysWow64\tzres.dll
2011-12-14 20:21:29 2048 ——a-w- C:\Windows\System32\tzres.dll
2011-12-14 15:12:42 ———— d——-w- C:\Users\KPK\AppData\Local\{B12FDF16-9F5D-4DFC-99D6-DDA6C8A9FCAF}
2011-12-14 15:12:30 ———— d——-w- C:\Users\KPK\AppData\Local\{6DA0F000-B287-447B-AD7B-B34AED56B770}
2011-12-13 19:23:32 ———— d——-w- C:\Users\KPK\AppData\Local\{68B666F5-6F6B-4FE0-87C9-BF9DF71EF010}
2011-12-13 19:23:21 ———— d——-w- C:\Users\KPK\AppData\Local\{C907C070-3ABA-4695-87C6-0E3BBB02A3DE}
2011-12-13 12:59:53 ———— d——-w- C:\Users\KPK\AppData\Roaming\Malwarebytes
2011-12-13 12:59:44 38224 ——a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-12-13 12:59:43 24664 ——a-w- C:\Windows\System32\drivers\mbam.sys
2011-12-13 12:59:43 ———— d——-w- C:\ProgramData\Malwarebytes
2011-12-13 12:59:43 ———— d——-w- C:\Program Files (x86)\Malwarebytes’ Anti-Malware
2011-12-13 12:37:56 ———— d——-w- C:\Program Files\CCleaner
2011-12-09 12:17:17 ———— d——-w- C:\Users\KPK\AppData\Local\{F8E311BF-3093-4187-A74C-CC4C1FB60F94}
2011-12-09 12:17:05 ———— d——-w- C:\Users\KPK\AppData\Local\{EF5FB508-77C6-452E-A740-6FB247F71CAB}
2011-12-08 19:25:08 ———— d——-w- C:\Program Files (x86)\JDownloader
2011-12-07 13:53:55 ———— d——-w- C:\Users\KPK\AppData\Local\{C622ABD5-78BF-44B7-91E2-7E3DCD531FE0}
2011-12-07 13:53:43 ———— d——-w- C:\Users\KPK\AppData\Local\{224199E1-D2AE-4DAA-8022-47FFA8F87854}
2011-12-04 19:27:21 ———— d——-w- C:\Users\KPK\AppData\Local\{9904024F-5C96-4423-85C8-AC550D80BCD4}
2011-12-04 19:27:10 ———— d——-w- C:\Users\KPK\AppData\Local\{1244B1F9-291E-4704-A9F0-3E59E253B286}
2011-11-27 14:43:00 ———— d——-w- C:\Users\KPK\AppData\Local\{A68A8B4F-3E96-4E10-A518-F23029B696F1}
2011-11-27 14:42:49 ———— d——-w- C:\Users\KPK\AppData\Local\{A42CA1DF-D173-4A1D-B103-34429CE4816C}
2011-11-27 12:40:01 ———— d——-w- C:\Program Files\iTunes
2011-11-27 12:40:01 ———— d——-w- C:\Program Files\iPod
2011-11-23 15:25:22 ———— d——-w- C:\Users\KPK\AppData\Local\{5CA22225-8E5E-4D80-86EC-9490EA03B727}
2011-11-23 15:25:10 ———— d——-w- C:\Users\KPK\AppData\Local\{8C2F858F-0F8D-4773-8C79-408536B029A3}
2011-11-16 14:48:08 ———— d——-w- C:\Users\KPK\AppData\Local\{40B88B52-5C94-4C3C-B7E1-D23E5768103B}
2011-11-16 14:47:56 ———— d——-w- C:\Users\KPK\AppData\Local\{ECEF41E0-54FF-4BE7-BB25-4FDC2D84CED5}
2011-11-15 16:02:18 ———— d——-w- C:\Users\KPK\AppData\Local\{8362DA70-F99B-4B0C-B484-233201AC265C}
2011-11-15 16:02:06 ———— d——-w- C:\Users\KPK\AppData\Local\{9F5C9C25-5814-43E7-AC6C-CC9E9946A340}
.
==================== Find3M ====================
.
2011-12-04 16:09:00 414368 ——a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-10 09:59:33 98648 ——a-w- C:\Windows\System32\BGLsp.dll
2011-11-10 09:59:33 82776 ——a-w- C:\Windows\SysWow64\BGLsp.dll
2011-11-05 05:41:43 1188864 ——a-w- C:\Windows\System32\wininet.dll
2011-11-05 04:35:00 981504 ——a-w- C:\Windows\SysWow64\wininet.dll
2011-11-05 03:32:47 1638912 ——a-w- C:\Windows\System32\mshtml.tlb
2011-11-05 02:48:51 1638912 ——a-w- C:\Windows\SysWow64\mshtml.tlb
2011-10-26 05:21:20 43520 ——a-w- C:\Windows\System32\csrsrv.dll
2011-10-24 13:29:02 94208 ——a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2011-10-24 13:29:02 69632 ——a-w- C:\Windows\SysWow64\QuickTime.qts
2011-09-29 16:29:28 1923952 ——a-w- C:\Windows\System32\drivers\tcpip.sys
.
============= FINISH: 10:35:41,18 ===============
