openadserving.com LOG
Napsal: 17 úno 2013 14:34
Ahoj, z ničeho nic se mi na obou PC začaly otevírat nová okna s reklamou při kliknutí na odkaz v prohlížeči. Používám Chrome. Stihl jsem si všimnout, že než se otevře samotná reklama, tak se prohlížeč směruje na
Zkoušel jsem spywareterminator, MAMB a nic. A problém stále přetrvává.
Do přílohy dávám DDS log.
Děkuji
Kód: Vybrat vše
http://www.openadserving.com
Do přílohy dávám DDS log.
Děkuji
Kód: Vybrat vše
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16457
Run by Desktop at 14:24:35 on 2013-02-18
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1033.18.8191.6055 [GMT -8:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\FUEL\FUEL.SERVICE.EXE
C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
C:\WINDOWS\SYSTEM32\DWM.EXE
C:\WINDOWS\SYSTEM32\TASKHOST.EXE
C:\WINDOWS\EXPLORER.EXE
C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
C:\PROGRAM FILES (X86)\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE
C:\PROGRAM FILES (X86)\SKYPE\PHONE\SKYPE.EXE
C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
C:\PROGRAM FILES (X86)\GADWIN SYSTEMS\PRINTSCREEN\PRINTSCREEN.EXE
C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE
C:\Windows\splwow64.exe
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\TRILLIAN\TRILLIAN.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\PROGRAM FILES (X86)\MSI\LIVE UPDATE 5\LU5.EXE
C:\PROGRAM FILES (X86)\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\MOM.EXE
C:\PROGRAM FILES (X86)\POWERISO\PWRISOVM.EXE
C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\WMPNETWK.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\CCC.EXE
C:\Windows\System32\svchost.exe -k secsvcs
C:\WINDOWS\SYSTEM32\WUAUCLT.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES\MICROSOFT GAMES\PURBLE PLACE\PURBLEPLACE.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\MALWAREBYTES' ANTI-MALWARE\MBAMSCHEDULER.EXE
C:\PROGRAM FILES (X86)\MALWAREBYTES' ANTI-MALWARE\MBAMSERVICE.EXE
C:\PROGRAM FILES (X86)\MALWAREBYTES' ANTI-MALWARE\MBAMGUI.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\SPYWARE TERMINATOR\SPYWARETERMINATORUPDATE.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
C:\WINDOWS\SYSTEM32\SEARCHPROTOCOLHOST.EXE
C:\WINDOWS\SYSTEM32\SEARCHFILTERHOST.EXE
C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
C:\WINDOWS\SYSTEM32\CSCRIPT.EXE
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe,
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [Gadwin PrintScreen] C:\Program Files (x86)\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
mRun: [Live Update 5] C:\Program Files (x86)\MSI\Live Update 5\BootStartLiveupdate.exe /reminder
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup
mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript
StartupFolder: C:\Users\Desktop\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Trillian.lnk - C:\Program Files (x86)\Trillian\trillian.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\TP-LIN~1.LNK - C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{ECC47740-3257-4D6C-9831-A5B66385BF7C} : DHCPNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [SpywareTerminatorShield] C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
x64-Run: [SpywareTerminatorUpdater] C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2013-1-24 283200]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-12-19 240640]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-12-19 361984]
R2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-4-9 57472]
R2 HTCMonitorService;HTCMonitorService;C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [2012-12-12 87368]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-2-17 682344]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-2-17 398184]
R2 PassThru Service;Internet Pass-Through Service;C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2013-2-9 167424]
R2 sp_rsdrv2;Spyware Terminator Driver Filter;C:\Windows\System32\drivers\stflt.sys [2013-2-15 51496]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [2013-2-15 1149104]
R3 athur;Wireless Network Adapter Service;C:\Windows\System32\drivers\athurx.sys [2013-1-23 1930240]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-11-6 96256]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-2-17 24176]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4;C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [2013-1-23 14136]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2013-1-23 44672]
S2 AODDriver4.2;AODDriver4.2;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-4-9 57472]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-1-8 161536]
S3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2013-1-23 46136]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2013-1-24 135584]
S3 HTCAND64;HTC Device Driver;C:\Windows\System32\drivers\ANDROIDUSB.sys [2009-11-2 33736]
S3 htcnprot;HTC NDIS Protocol Driver;C:\Windows\System32\drivers\htcnprot.sys [2012-12-7 36928]
S3 NTIOLib_1_0_6;NTIOLib_1_0_6;C:\Program Files (x86)\Setup Files\Ms7641vHD0\NTIOLib_X64.sys [2011-1-6 11888]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-1-24 59392]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-1-24 1255736]
.
=============== Created Last 30 ================
.
2013-02-18 04:00:48 -------- d-----w- C:\Users\Desktop\AppData\Roaming\Malwarebytes
2013-02-18 04:00:31 24176 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-02-18 04:00:31 -------- d-----w- C:\ProgramData\Malwarebytes
2013-02-18 04:00:31 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-02-18 04:00:21 -------- d-----w- C:\Users\Desktop\AppData\Local\Programs
2013-02-16 02:52:39 51496 ----a-w- C:\Windows\System32\drivers\stflt.sys
2013-02-16 02:52:37 -------- d-----w- C:\Users\Desktop\AppData\Roaming\Spyware Terminator
2013-02-16 02:52:37 -------- d-----w- C:\ProgramData\Spyware Terminator
2013-02-16 02:51:58 -------- d-----w- C:\Program Files (x86)\Spyware Terminator
2013-02-14 03:53:14 9161176 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C33EFEBC-077D-4D1A-A4CA-0B9A6DE08572}\mpengine.dll
2013-02-12 01:54:24 902656 ----a-w- C:\Windows\System32\d2d1.dll
2013-02-12 01:54:24 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
2013-02-12 01:54:24 1139200 ----a-w- C:\Windows\System32\FntCache.dll
2013-02-11 11:02:10 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2013-02-10 02:40:19 -------- d-----w- C:\SDK
2013-02-10 02:35:35 -------- d-----w- C:\Users\Desktop\AppData\Roaming\HTC
2013-02-10 02:35:31 -------- d-----w- C:\Users\Desktop\AppData\Roaming\HTC Sync
2013-02-10 02:35:24 -------- d-----w- C:\ProgramData\HTC
2013-02-10 02:34:33 -------- d-----w- C:\Users\Desktop\AppData\Local\Apple Computer
2013-02-10 02:34:31 -------- d-----w- C:\Users\Desktop\AppData\Local\HTC MediaHub
2013-02-10 02:34:27 -------- d-----w- C:\ProgramData\Motorola
2013-02-10 02:32:53 -------- d-----w- C:\Program Files (x86)\Spirent Communications
2013-02-10 02:32:53 -------- d-----w- C:\Program Files (x86)\HTC
2013-02-10 02:28:39 -------- d-----w- C:\Users\Desktop\AppData\Local\Downloaded Installations
2013-02-07 05:39:10 -------- d-----w- C:\Program Files (x86)\Gadwin Systems
2013-01-30 03:49:07 -------- d-----w- C:\Users\Desktop\AppData\Roaming\Wargaming.net
2013-01-30 02:46:39 -------- d-----w- C:\Users\Desktop\AppData\Roaming\Trillian
2013-01-30 02:39:21 -------- d-----r- C:\Program Files (x86)\Skype
2013-01-30 02:36:53 -------- d-----w- C:\Games
2013-01-28 19:11:46 55296 ----a-w- C:\Windows\System32\dhcpcsvc6.dll
2013-01-28 19:11:46 44032 ----a-w- C:\Windows\SysWow64\dhcpcsvc6.dll
2013-01-28 19:11:46 226816 ----a-w- C:\Windows\System32\dhcpcore6.dll
2013-01-28 19:11:46 193536 ----a-w- C:\Windows\SysWow64\dhcpcore6.dll
2013-01-28 19:11:18 950128 ----a-w- C:\Windows\System32\drivers\ndis.sys
2013-01-28 19:11:18 41472 ----a-w- C:\Windows\System32\drivers\RNDISMP.sys
2013-01-28 19:09:54 245760 ----a-w- C:\Windows\System32\OxpsConverter.exe
2013-01-28 19:06:55 68608 ----a-w- C:\Windows\System32\taskhost.exe
2013-01-27 23:52:45 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2013-01-27 23:52:19 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-01-27 22:10:36 -------- d-----w- C:\Users\Desktop\AppData\Local\2K Games
2013-01-27 22:01:35 -------- d-----w- C:\Program Files (x86)\2K Games
2013-01-27 19:21:58 -------- d-----w- C:\Windows\System32\SPReview
2013-01-27 19:20:59 -------- d-----w- C:\Windows\System32\EventProviders
2013-01-27 05:04:28 -------- d-sh--w- C:\Windows\ftpcache
2013-01-27 05:01:52 -------- d-----w- C:\Program Files (x86)\Activision
2013-01-27 04:54:32 -------- d-----w- C:\Users\Desktop\AppData\Roaming\PowerISO
2013-01-27 04:54:11 126944 ----a-w- C:\Windows\System32\drivers\scdemu.sys
2013-01-27 04:54:11 -------- d-----w- C:\Program Files (x86)\PowerISO
2013-01-27 03:47:01 -------- d-----w- C:\Users\Desktop\AppData\Local\Microsoft Games
2013-01-27 02:46:22 9161176 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-01-25 06:28:56 469264 ----a-w- C:\Windows\System32\d3dx10.dll
2013-01-25 06:25:57 -------- d--h--w- C:\Windows\msdownld.tmp
2013-01-25 06:25:57 -------- d-----w- C:\Windows\SysWow64\directx
2013-01-25 06:25:08 -------- d-----w- C:\Program Files (x86)\MSI Afterburner
2013-01-25 06:14:11 -------- d-----w- C:\Program Files (x86)\AMD
2013-01-25 06:02:59 488448 ----a-w- C:\Windows\System32\secproc.dll
2013-01-25 06:00:53 606208 ----a-w- C:\Windows\SysWow64\wbem\fastprox.dll
2013-01-25 06:00:53 363008 ----a-w- C:\Windows\SysWow64\wbemcomn.dll
2013-01-25 06:00:53 189952 ----a-w- C:\Program Files (x86)\Windows Portable Devices\sqmapi.dll
2013-01-25 05:58:41 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2013-01-25 05:58:41 244736 ----a-w- C:\Program Files\Windows Portable Devices\sqmapi.dll
2013-01-25 05:58:35 244736 ----a-w- C:\Windows\System32\sqmapi.dll
2013-01-25 05:24:52 -------- d-----w- C:\Program Files (x86)\Rockstar Games
2013-01-25 05:24:36 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2013-01-25 05:24:36 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2013-01-25 05:24:36 180224 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2013-01-25 05:24:35 749568 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2013-01-25 05:24:35 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2013-01-25 05:24:02 323716 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2013-01-25 05:24:02 192644 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2013-01-25 05:21:46 283200 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys
2013-01-25 05:21:43 -------- d-----w- C:\Users\Desktop\AppData\Roaming\DAEMON Tools Lite
2013-01-25 05:21:42 -------- d-----w- C:\Program Files (x86)\DAEMON Tools Lite
2013-01-25 05:20:03 -------- d-----w- C:\ProgramData\DAEMON Tools Lite
2013-01-25 05:16:48 2565632 ----a-w- C:\Windows\System32\esent.dll
2013-01-25 05:16:47 1699328 ----a-w- C:\Windows\SysWow64\esent.dll
2013-01-25 05:16:46 96768 ----a-w- C:\Windows\System32\fsutil.exe
2013-01-25 05:16:46 74240 ----a-w- C:\Windows\SysWow64\fsutil.exe
2013-01-25 05:16:46 410496 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2013-01-25 05:16:46 27008 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2013-01-25 05:16:46 189824 ----a-w- C:\Windows\System32\drivers\storport.sys
2013-01-25 05:16:46 166272 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2013-01-25 05:16:46 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2013-01-25 05:16:46 107904 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2013-01-25 05:13:38 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2013-01-25 05:13:38 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2013-01-25 05:13:38 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2013-01-25 05:13:37 98816 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2013-01-25 05:13:37 7936 ----a-w- C:\Windows\System32\drivers\usbd.sys
2013-01-25 05:13:37 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2013-01-25 05:13:37 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2013-01-25 05:09:19 -------- d-----w- C:\Users\Desktop\AppData\Local\IsolatedStorage
2013-01-25 05:09:16 -------- d-----w- C:\Users\Desktop\AppData\Local\Futuremark_Corporation
2013-01-24 11:14:54 -------- d-----w- C:\Program Files (x86)\BitTorrent
2013-01-24 11:14:20 -------- d-----w- C:\Users\Desktop\AppData\Roaming\BitTorrent
2013-01-24 11:00:32 -------- d-----w- C:\Windows\SysWow64\Wat
2013-01-24 11:00:32 -------- d-----w- C:\Windows\System32\Wat
2013-01-24 10:38:42 -------- d-----w- C:\Users\Desktop\AppData\Local\Google
2013-01-24 10:38:33 -------- d-----w- C:\Users\Desktop\AppData\Local\Deployment
2013-01-24 10:38:33 -------- d-----w- C:\Users\Desktop\AppData\Local\Apps
2013-01-24 10:38:26 -------- d-----w- C:\Users\Desktop\AppData\Local\AMD
2013-01-24 03:19:32 9728 ----a-w- C:\Windows\System32\Wdfres.dll
2013-01-24 03:19:32 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys
2013-01-24 03:19:32 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys
2013-01-24 03:19:32 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2013-01-24 03:10:59 294912 ----a-w- C:\Windows\System32\browserchoice.exe
2013-01-24 03:05:23 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2013-01-24 03:05:23 46080 ----a-w- C:\Windows\System32\atmlib.dll
2013-01-24 03:05:23 367616 ----a-w- C:\Windows\System32\atmfd.dll
2013-01-24 03:05:23 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2013-01-24 03:05:23 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2013-01-24 03:05:23 100864 ----a-w- C:\Windows\System32\fontsub.dll
2013-01-24 03:04:53 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2013-01-24 03:04:53 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2013-01-24 03:04:53 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2013-01-24 03:04:53 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2013-01-24 03:04:53 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2013-01-24 03:04:53 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2013-01-24 03:04:53 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2013-01-24 03:02:54 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-01-24 03:02:54 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2013-01-24 03:02:54 5120 ----a-w- C:\Windows\System32\wmi.dll
2013-01-24 03:02:54 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-01-24 03:02:54 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-01-24 02:58:26 1544704 ----a-w- C:\Windows\System32\DWrite.dll
2013-01-24 02:57:58 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2013-01-24 02:56:59 321024 ----a-w- C:\Windows\System32\d3d10_1core.dll
2013-01-24 02:48:24 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2013-01-24 02:47:54 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2013-01-24 02:47:53 559104 ----a-w- C:\Windows\System32\spoolsv.exe
2013-01-24 02:47:52 67072 ----a-w- C:\Windows\splwow64.exe
2013-01-24 02:47:50 723456 ----a-w- C:\Windows\System32\EncDec.dll
2013-01-24 02:47:50 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2013-01-24 02:47:48 77312 ----a-w- C:\Windows\System32\packager.dll
2013-01-24 02:47:48 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2013-01-24 02:42:13 0 ----a-w- C:\Windows\ativpsrm.bin
2013-01-24 02:41:24 -------- d-----w- C:\Program Files (x86)\AMD AVT
2013-01-24 02:41:22 -------- d-----w- C:\Program Files (x86)\AMD APP
2013-01-24 02:41:16 -------- d-----w- C:\Program Files\Common Files\ATI Technologies
2013-01-24 02:41:16 -------- d-----w- C:\Program Files (x86)\Common Files\ATI Technologies
2013-01-24 02:39:22 -------- d-----w- C:\Users\Desktop\AppData\Local\ATI
2013-01-24 02:38:08 -------- d-----w- C:\AMD
2013-01-24 02:32:34 44672 ----a-w- C:\Windows\System32\drivers\usbfilter.sys
2013-01-24 02:31:58 -------- d-----w- C:\ProgramData\AMD
2013-01-24 02:31:55 46136 ----a-w- C:\Windows\System32\drivers\amdiox64.sys
2013-01-24 02:31:40 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2013-01-24 02:31:33 -------- d-sh--w- C:\Windows\Installer
2013-01-24 02:31:20 -------- d-----w- C:\Program Files\ATI Technologies
2013-01-24 02:31:17 -------- d-----w- C:\Program Files\ATI
2013-01-24 02:30:30 16440 ----a-w- C:\Windows\System32\drivers\AtiPcie64.sys
2013-01-24 02:22:40 -------- d-----w- C:\Program Files (x86)\Setup Files
2013-01-23 23:10:51 273840 ------w- C:\Windows\System32\MpSigStub.exe
2013-01-23 23:02:39 11832 ----a-w- C:\Windows\acpimof.dll
2013-01-23 23:02:38 -------- d-----w- C:\Program Files (x86)\MSI
2013-01-23 23:01:52 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2013-01-23 23:01:52 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2013-01-23 23:01:52 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2013-01-23 22:58:41 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2013-01-23 22:58:35 99840 ----a-w- C:\Windows\System32\wudriver.dll
2013-01-23 22:58:29 36864 ----a-w- C:\Windows\System32\wuapp.exe
2013-01-23 22:58:29 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2013-01-23 22:57:25 -------- d-----w- C:\Users\Desktop\AppData\Roaming\TP-LINK
2013-01-23 22:56:57 -------- d-----w- C:\Program Files (x86)\TP-LINK
2013-01-23 22:55:44 1930240 ----a-w- C:\Windows\System32\drivers\athurx.sys
2013-01-23 22:55:44 1930240 ----a-w- C:\Windows\System32\athurx.sys
2013-01-23 22:55:21 -------- d-----w- C:\ProgramData\TP-LINK
2013-01-23 22:47:28 -------- d-----w- C:\Windows\Panther
.
==================== Find3M ====================
.
2013-01-27 19:31:35 175616 ----a-w- C:\Windows\System32\msclmd.dll
2013-01-27 19:31:35 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2012-12-19 23:45:12 222720 ----a-w- C:\Windows\System32\clinfo.exe
2012-12-19 23:44:48 76288 ----a-w- C:\Windows\System32\OpenVideo64.dll
2012-12-19 23:44:42 65536 ----a-w- C:\Windows\SysWow64\OpenVideo.dll
2012-12-19 23:44:36 64000 ----a-w- C:\Windows\System32\OVDecode64.dll
2012-12-19 23:44:32 56320 ----a-w- C:\Windows\SysWow64\OVDecode.dll
2012-12-19 23:44:20 34518016 ----a-w- C:\Windows\System32\amdocl64.dll
2012-12-19 23:38:48 28732928 ----a-w- C:\Windows\SysWow64\amdocl.dll
2012-12-19 23:34:40 54784 ----a-w- C:\Windows\System32\OpenCL.dll
2012-12-19 23:34:38 50176 ----a-w- C:\Windows\SysWow64\OpenCL.dll
2012-12-19 20:50:14 5630200 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2012-12-19 20:48:48 11278336 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2012-12-19 20:29:36 23461376 ----a-w- C:\Windows\System32\atio6axx.dll
2012-12-19 20:22:50 70144 ----a-w- C:\Windows\System32\coinst_9.012.dll
2012-12-19 20:19:46 163840 ----a-w- C:\Windows\System32\atiapfxx.exe
2012-12-19 20:18:04 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2012-12-19 20:18:02 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2012-12-19 20:17:54 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2012-12-19 20:17:52 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2012-12-19 20:17:40 16082944 ----a-w- C:\Windows\System32\aticaldd64.dll
2012-12-19 20:13:24 13703168 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2012-12-19 20:12:44 18982400 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2012-12-19 20:09:52 960512 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2012-12-19 20:08:04 1151488 ----a-w- C:\Windows\System32\aticfx64.dll
2012-12-19 20:06:00 6681088 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2012-12-19 19:59:44 5087744 ----a-w- C:\Windows\System32\atiumd6a.dll
2012-12-19 19:57:00 442368 ----a-w- C:\Windows\System32\atidemgy.dll
2012-12-19 19:56:46 550912 ----a-w- C:\Windows\System32\atieclxx.exe
2012-12-19 19:56:00 240640 ----a-w- C:\Windows\System32\atiesrxx.exe
2012-12-19 19:54:38 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2012-12-19 19:54:22 21504 ----a-w- C:\Windows\System32\atimuixx.dll
2012-12-19 19:54:18 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2012-12-19 19:54:12 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2012-12-19 19:49:00 7370752 ----a-w- C:\Windows\System32\atidxx64.dll
2012-12-19 19:44:28 4162048 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2012-12-19 19:44:12 6786560 ----a-w- C:\Windows\System32\atiumd64.dll
2012-12-19 19:34:28 79360 ----a-w- C:\Windows\System32\amdave64.dll
2012-12-19 19:34:22 78336 ----a-w- C:\Windows\SysWow64\amdave32.dll
2012-12-19 19:34:10 74240 ----a-w- C:\Windows\System32\atisamu64.dll
2012-12-19 19:34:04 71168 ----a-w- C:\Windows\SysWow64\atisamu32.dll
2012-12-19 19:33:50 56320 ----a-w- C:\Windows\System32\atimpc64.dll
2012-12-19 19:33:50 56320 ----a-w- C:\Windows\System32\amdpcom64.dll
2012-12-19 19:33:42 619008 ----a-w- C:\Windows\System32\atiadlxx.dll
2012-12-19 19:33:40 56832 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2012-12-19 19:33:40 56832 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2012-12-19 19:33:32 421888 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2012-12-19 19:33:18 17920 ----a-w- C:\Windows\System32\atig6pxx.dll
2012-12-19 19:33:14 14848 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2012-12-19 19:33:14 14848 ----a-w- C:\Windows\System32\atiglpxx.dll
2012-12-19 19:33:10 41984 ----a-w- C:\Windows\System32\atig6txx.dll
2012-12-19 19:33:04 33280 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2012-12-19 19:32:54 552960 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2012-12-19 19:31:14 130048 ----a-w- C:\Windows\System32\atiuxp64.dll
2012-12-19 19:31:08 109568 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2012-12-19 19:31:00 104448 ----a-w- C:\Windows\System32\atiu9p64.dll
2012-12-19 19:30:52 83968 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2012-12-19 19:30:16 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2012-12-08 02:27:50 36928 ----a-w- C:\Windows\System32\drivers\htcnprot.sys
2012-12-07 13:20:16 441856 ----a-w- C:\Windows\System32\Wpc.dll
2012-12-07 13:15:31 2746368 ----a-w- C:\Windows\System32\gameux.dll
2012-12-07 12:26:17 308736 ----a-w- C:\Windows\SysWow64\Wpc.dll
2012-12-07 12:20:43 2576384 ----a-w- C:\Windows\SysWow64\gameux.dll
2012-12-07 11:20:04 30720 ----a-w- C:\Windows\System32\usk.rs
2012-12-07 11:20:03 43520 ----a-w- C:\Windows\System32\csrr.rs
2012-12-07 11:20:03 23552 ----a-w- C:\Windows\System32\oflc.rs
2012-12-07 11:20:01 45568 ----a-w- C:\Windows\System32\oflc-nz.rs
2012-12-07 11:20:01 44544 ----a-w- C:\Windows\System32\pegibbfc.rs
2012-12-07 11:20:01 20480 ----a-w- C:\Windows\System32\pegi-fi.rs
2012-12-07 11:20:00 20480 ----a-w- C:\Windows\System32\pegi-pt.rs
2012-12-07 11:19:59 20480 ----a-w- C:\Windows\System32\pegi.rs
2012-12-07 11:19:58 46592 ----a-w- C:\Windows\System32\fpb.rs
2012-12-07 11:19:57 40960 ----a-w- C:\Windows\System32\cob-au.rs
2012-12-07 11:19:57 21504 ----a-w- C:\Windows\System32\grb.rs
2012-12-07 11:19:57 15360 ----a-w- C:\Windows\System32\djctq.rs
2012-12-07 11:19:56 55296 ----a-w- C:\Windows\System32\cero.rs
2012-12-07 11:19:55 51712 ----a-w- C:\Windows\System32\esrb.rs
2012-12-05 05:35:34 3242128 ----a-w- C:\Windows\System32\drivers\RTKVHD64.sys
2012-12-05 01:03:00 124560 ----a-w- C:\Windows\System32\RCoInstII64.dll
2012-12-04 22:13:56 10749952 ----a-w- C:\Windows\System32\RCoRes64.dat
2012-11-30 05:45:35 362496 ----a-w- C:\Windows\System32\wow64win.dll
2012-11-30 05:45:35 243200 ----a-w- C:\Windows\System32\wow64.dll
2012-11-30 05:45:35 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2012-11-30 05:45:14 215040 ----a-w- C:\Windows\System32\winsrv.dll
2012-11-30 05:43:12 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2012-11-30 05:41:07 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2012-11-30 04:54:00 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2012-11-30 04:53:59 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2012-11-30 03:23:48 338432 ----a-w- C:\Windows\System32\conhost.exe
2012-11-30 02:44:06 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2012-11-30 02:44:04 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2012-11-30 02:44:04 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-11-30 02:44:03 2048 ----a-w- C:\Windows\SysWow64\user.exe
2012-11-30 02:38:59 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:38:59 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:38:59 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:38:59 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-11-30 01:27:34 1562768 ----a-w- C:\Windows\System32\RTSnMg64.cpl
2012-11-23 03:26:31 3149824 ----a-w- C:\Windows\System32\win32k.sys
2012-11-22 05:44:23 800768 ----a-w- C:\Windows\System32\usp10.dll
.
============= FINISH: 14:25:22,69 ===============