Hiya, I need some urgent help, my bro in law has hacked my system. Tried all spyware, malware programs to detect any keyloggers, remote assist bugs etc but nothing comes up. I know there's something as he still figures out my fb passwords, freezes up my computer as he wishes, changing certain options, deleting files etc.
Need some help as I'm abit witty with pcs but it's been awhile so not really up to scratch with the latest stuff lol
I ran gaming pages and youtube channels so I tend to share content into groups etc, he makes life hard for me by getting me kicked/ banned from groups regularly... I assume he logs in as me on any of my accounts and posts porn into the groups am in so I can get banned/ kicked out... not to mention getting my fb accounts in trouble as well... and he does all this because he thinks he can get away with it because there's no poof or I can't show proof. Him and his minions troll me day and night, and he knows where to find my posts as he's hacked my system.
Update: Tried several anti virus programs including eset, spybot etc but nothing comes up... any help would be appreciated. Thanks
DDS
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16696 BrowserJavaVersion: 11.31.2
Run by User at 17:31:35 on 2015-09-11
Microsoft® Windows Vista Home Premium 6.0.6002.2.1252.44.1033.18.3061.1170 [GMT 1:00]
.
AV: ESET NOD32 Antivirus 8.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: AVG AntiVirus Free Edition 2015 *Disabled/Outdated* {4D41356F-32AD-7C42-C820-63775EE4F413}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition 2015 *Disabled/Outdated* {F620D48B-1497-73CC-F290-58052563BEAE}
SP: ESET NOD32 Antivirus 8.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: AVG Internet Security 2015 *Disabled* {757AB44A-78C2-7D1A-E37F-CA42A037B368}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2015\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\BlueStacks\HD-LogRotatorService.exe
C:\Program Files\BlueStacks\HD-UpdaterService.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Zemana AntiMalware\ZAM.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\AVG\AVG2015\avgui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\Taskmgr.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uStart Page = Google
uSearch Bar = Google
uDefault_Page_URL = about:blank
mStart Page = about:blank
mSearch Page = about:blank
mDefault_Page_URL = about:blank
mDefault_Search_URL = about:blank
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\programdata\realnetworks\realdownloader\browserplugins\ie\rndlbrowserrecordplugin.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.8.0_31\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre1.8.0_31\bin\jp2ssv.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [Xvid] c:\program files\xvid\CheckUpdate.exe
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5.5ServiceManager] "c:\program files\common files\adobe\cs5.5servicemanager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [AVG_UI] "c:\program files\avg\avg2015\avgui.exe" /TRAYONLY
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [ZAM] "c:\program files\zemana antimalware\ZAM.exe" /minimized
mRun: [PC Cleaners] "c:\programdata\pc cleaners\PCCleaners.exe" /minimize
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{278A7B0F-A822-43DD-A7E2-42510197FD1C} : DHCPNameServer = 149.254.230.7 149.254.192.126
TCP: Interfaces\{361C2C64-E765-485B-A392-96829E3B17EA} : DHCPNameServer = 192.168.0.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\45.0.2454.85\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2015-5-12 190944]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2015-5-7 290272]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2015-7-28 186800]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2015-3-20 35808]
R1 Avgdiskx;AVG Disk Driver;c:\windows\system32\drivers\avgdiskx.sys [2015-3-11 132576]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2015-7-28 250288]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2015-7-23 31664]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2015-6-16 207328]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2015-5-12 213984]
R2 BstHdDrv;BlueStacks Hypervisor;c:\program files\bluestacks\HD-Hypervisor-x86.sys [2015-6-16 131704]
.
=============== Created Last 30 ================
.
2015-09-11 11:50:16 -------- d-----w- c:\users\bodo\appdata\local\ESET
2015-09-09 19:38:22 102912 ----a-w- c:\windows\system32\drivers\srvnet.sys
2015-09-09 19:38:21 304640 ----a-w- c:\windows\system32\drivers\srv.sys
2015-09-09 19:32:08 1402368 ----a-w- c:\windows\system32\msxml6.dll
2015-09-09 19:32:08 1253376 ----a-w- c:\windows\system32\msxml3.dll
2015-09-09 19:07:20 2048 ----a-w- c:\windows\system32\tzres.dll
2015-09-09 19:04:53 940032 ----a-w- c:\program files\common files\microsoft shared\ink\journal.dll
2015-09-09 19:04:52 1850880 ----a-w- c:\program files\windows journal\Journal.exe
2015-09-09 19:04:51 1220608 ----a-w- c:\program files\windows journal\NBDoc.DLL
2015-09-09 19:04:50 985600 ----a-w- c:\program files\windows journal\JNTFiltr.dll
2015-09-09 19:04:50 967680 ----a-w- c:\program files\windows journal\JNWDRV.dll
2015-09-09 19:02:59 34304 ----a-w- c:\windows\system32\atmlib.dll
2015-09-09 19:02:59 297472 ----a-w- c:\windows\system32\atmfd.dll
2015-09-09 19:02:55 2067456 ----a-w- c:\windows\system32\win32k.sys
2015-09-09 19:00:50 602112 ----a-w- c:\windows\system32\schedsvc.dll
2015-08-31 22:50:40 -------- d-----w- c:\users\User\appdata\roaming\RealNetworks
2015-08-31 22:49:28 -------- d-----w- c:\program files\RealNetworks
2015-08-31 22:49:22 -------- d-----w- c:\programdata\RealNetworks
2015-08-31 10:18:30 -------- d-----w- c:\programdata\PC Cleaners
2015-08-31 10:18:23 -------- d-----w- c:\programdata\PC1Data
2015-08-30 01:00:30 -------- d-----w- c:\programdata\KingSoft
2015-08-30 00:57:55 -------- d-----w- c:\programdata\TXQMPC
2015-08-30 00:57:55 -------- d-----w- c:\program files\Rising
2015-08-30 00:57:53 -------- d-----w- c:\programdata\Rising
2015-08-30 00:54:35 -------- d-----w- c:\program files\common files\Tencent
2015-08-30 00:51:20 -------- d-----w- c:\users\User\appdata\roaming\Tencent
2015-08-30 00:51:15 -------- d-----w- c:\programdata\Tencent
2015-08-30 00:19:02 -------- d-----w- C:\ppsfile
2015-08-30 00:19:01 -------- d-----w- C:\qycache
2015-08-30 00:11:40 -------- d-----w- C:\IQIYI Video
2015-08-30 00:02:23 -------- d-----w- c:\users\User\appdata\local\globalUpdate
2015-08-30 00:02:23 -------- d-----w- c:\program files\globalUpdate
2015-08-30 00:00:23 -------- d-----w- c:\users\User\appdata\roaming\DailyPCClean
2015-08-29 23:39:35 -------- d-----w- c:\users\User\appdata\local\4C4C4544-1440895174-3710-8046-C4C04F4E334A
2015-08-29 23:38:12 -------- d-----w- c:\programdata\28341ff220e0446c9fff27c4493d622e
2015-08-29 23:35:41 -------- d-----w- c:\users\User\appdata\roaming\WeatherTool
2015-08-29 15:20:06 -------- d-----w- c:\program files\Controller
2015-08-29 15:00:36 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
2015-08-29 12:00:15 -------- d-----w- c:\users\User\appdata\local\{925B1088-DD5F-47C0-8964-53D8D1C5CF0E}
2015-08-29 11:29:38 -------- d-----w- c:\users\User\appdata\local\{8F1267F6-E90F-490A-82CA-509F1DFD0E9C}
2015-08-27 11:25:17 -------- d-----w- c:\programdata\Sony Corporation
2015-08-26 09:08:52 -------- d-----w- c:\program files\SystemRequirementsLab
2015-08-25 12:52:55 -------- d-----w- c:\users\User\appdata\local\{B318BA93-77DE-4D50-BAEA-A18131CFA774}
2015-08-24 10:45:29 -------- d-----w- c:\program files\World of Warcraft
2015-08-24 10:42:01 -------- d-----w- c:\users\User\appdata\local\Blizzard Entertainment
2015-08-24 10:41:41 -------- d-----w- c:\users\User\appdata\roaming\Battle.net
2015-08-24 10:41:41 -------- d-----w- c:\users\User\appdata\local\Battle.net
2015-08-24 10:40:34 -------- d-----w- c:\programdata\Blizzard Entertainment
2015-08-24 10:40:34 -------- d-----w- c:\program files\Battle.net
2015-08-24 10:38:13 -------- d-----w- c:\programdata\Battle.net
2015-08-22 22:46:01 -------- d-----w- c:\program files\SigmaTel
2015-08-22 14:23:20 12872 ----a-w- c:\windows\system32\bootdelete.exe
2015-08-22 04:34:52 97560 ----a-w- c:\windows\system32\drivers\zam32.sys
2015-08-22 04:34:34 97560 ----a-w- c:\windows\system32\drivers\zamguard32.sys
2015-08-20 20:10:58 -------- d-----w- c:\programdata\HitmanPro
2015-08-16 21:06:40 -------- d-----w- c:\users\User\appdata\local\{6E9ECE0F-B878-4E61-8406-5EC4DB3D4962}
2015-08-16 20:04:48 -------- d-----w- c:\users\User\appdata\local\DriverToolkit
2015-08-15 14:05:59 -------- d-----w- c:\users\User\appdata\roaming\NeroDigital(TM)
2015-08-13 13:32:28 920088 ----a-w- c:\windows\system32\igxpun.exe
2015-08-13 12:37:49 39936 ----a-w- c:\windows\system32\drivers\rimmptsk.sys
2015-08-13 12:37:49 37376 ----a-w- c:\windows\system32\drivers\rixdptsk.sys
2015-08-13 12:37:49 16480 ----a-w- c:\windows\system32\rixdicon.dll
2015-08-13 12:37:48 42496 ----a-w- c:\windows\system32\drivers\rimsptsk.sys
2015-08-13 12:37:11 57344 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\ctor.dll
2015-08-13 12:37:11 32768 ----a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2015-08-13 12:37:11 237568 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iscript.dll
2015-08-13 12:37:11 155648 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iuser.dll
2015-08-13 12:37:10 692224 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iKernel.dll
2015-08-13 12:37:10 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\DotNetInstaller.exe
2015-08-13 12:37:10 163972 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iGdi.dll
2015-08-13 12:37:09 282756 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\setup.dll
2015-08-13 10:48:38 107608 ----a-w- c:\program files\common files\microsoft shared\office14\EXP_PDF.DLL
2015-08-13 04:01:05 56256 ----a-w- c:\windows\system32\drivers\mountmgr.sys
2015-08-13 04:01:05 49664 ----a-w- c:\windows\system32\csrsrv.dll
2015-08-13 04:01:05 140224 ----a-w- c:\windows\system32\drivers\ecache.sys
2015-08-13 04:01:05 1206192 ----a-w- c:\windows\system32\ntdll.dll
2015-08-13 04:01:05 10752 ----a-w- c:\windows\system32\msmmsp.dll
2015-08-13 04:01:04 564224 ----a-w- c:\windows\system32\emdmgmt.dll
2015-08-13 04:01:04 3605440 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-08-13 04:01:03 3553216 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-08-13 03:59:53 103120 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 03:58:40 2067968 ----a-w- c:\windows\system32\mstscax.dll
2015-08-13 03:53:39 68608 ----a-w- c:\windows\system32\basesrv.dll
2015-08-13 03:42:39 682496 ----a-w- c:\windows\system32\d2d1.dll
2015-08-13 03:42:39 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2015-08-13 03:42:39 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2015-08-13 03:42:39 189952 ----a-w- c:\windows\system32\d3d10core.dll
2015-08-13 03:42:39 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2015-08-13 03:42:39 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2015-08-13 03:42:39 1029120 ----a-w- c:\windows\system32\d3d10.dll
2015-08-13 03:42:38 802304 ----a-w- c:\windows\system32\FntCache.dll
2015-08-13 03:42:38 1072640 ----a-w- c:\windows\system32\DWrite.dll
2015-08-13 03:41:08 199680 ----a-w- c:\windows\system32\WebClnt.dll
2015-08-13 03:40:46 151040 ----a-w- c:\windows\system32\notepad.exe
2015-08-13 03:40:46 151040 ----a-w- c:\windows\notepad.exe
2015-08-13 03:38:25 -------- d-----w- C:\DRIVERS
2015-08-13 03:25:39 53248 ----a-w- c:\windows\system32\RBK8F43.tmp
.
==================== Find3M ====================
.
2015-09-10 14:06:17 98520 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-08-31 22:48:00 499712 ----a-w- c:\windows\system32\msvcp71.dll
2015-08-31 22:48:00 348160 ----a-w- c:\windows\system32\msvcr71.dll
2015-08-17 17:18:19 1814016 ----a-w- c:\windows\system32\jscript9.dll
2015-08-17 17:14:56 367616 ----a-w- c:\windows\system32\html.iec
2015-08-17 17:12:06 1129472 ----a-w- c:\windows\system32\wininet.dll
2015-08-17 17:11:04 422400 ----a-w- c:\windows\system32\vbscript.dll
2015-08-17 17:11:02 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2015-08-17 17:10:36 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2015-08-17 17:10:08 11776 ----a-w- c:\windows\system32\mshta.exe
2015-08-17 17:09:58 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2015-08-14 05:22:27 1656 ----a-w- c:\windows\system32\ASOROSet.bin
2015-08-12 12:04:36 70168 ----a-w- c:\windows\system32\drivers\RapportHades.sys
2015-08-12 12:04:36 223000 ----a-w- c:\windows\system32\drivers\RapportKELL.sys
2015-08-11 22:33:16 778440 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-08-11 22:33:15 142536 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-08-04 23:03:08 877152 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2015-08-04 23:03:08 538208 ----a-w- c:\windows\system32\msvcp120_clr0400.dll
2015-07-28 10:02:10 250288 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2015-07-28 05:12:19 98520 ----a-w- c:\windows\system32\drivers\20F74CA3.sys
2015-07-23 15:44:26 31664 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys
2015-07-13 06:14:14 202704 ----a-w- c:\windows\system32\drivers\eamonm.sys
2015-07-13 06:14:14 199608 ----a-w- c:\windows\system32\drivers\edevmon.sys
2015-07-13 06:14:14 144536 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2015-07-13 06:14:14 132152 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2015-07-03 16:04:03 1316864 ----a-w- c:\windows\system32\ole32.dll
2015-06-27 16:03:22 783872 ----a-w- c:\windows\system32\rpcrt4.dll
2015-06-27 16:02:55 218112 ----a-w- c:\windows\system32\msv1_0.dll
2015-06-27 16:02:34 501248 ----a-w- c:\windows\system32\kerberos.dll
2015-06-27 16:01:58 801280 ----a-w- c:\windows\system32\advapi32.dll
2015-06-27 14:21:13 217088 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2015-06-27 14:21:10 81408 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2015-06-24 00:29:00 1217192 ----a-w- c:\windows\system32\FM20.DLL
2015-06-23 12:27:10 246952 ------w- c:\windows\system32\MpSigStub.exe
2015-06-18 07:41:50 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-06-18 07:41:42 94936 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-06-18 07:41:36 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-06-17 16:50:20 2264576 ----a-w- c:\windows\system32\msi.dll
2015-06-17 15:09:17 73216 ----a-w- c:\windows\system32\msiexec.exe
2015-06-16 14:54:52 207328 ----a-w- c:\windows\system32\drivers\avgldx86.sys
.
============= FINISH: 17:40:06.23 ===============
Need some help as I'm abit witty with pcs but it's been awhile so not really up to scratch with the latest stuff lol
I ran gaming pages and youtube channels so I tend to share content into groups etc, he makes life hard for me by getting me kicked/ banned from groups regularly... I assume he logs in as me on any of my accounts and posts porn into the groups am in so I can get banned/ kicked out... not to mention getting my fb accounts in trouble as well... and he does all this because he thinks he can get away with it because there's no poof or I can't show proof. Him and his minions troll me day and night, and he knows where to find my posts as he's hacked my system.
Update: Tried several anti virus programs including eset, spybot etc but nothing comes up... any help would be appreciated. Thanks
DDS
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16696 BrowserJavaVersion: 11.31.2
Run by User at 17:31:35 on 2015-09-11
Microsoft® Windows Vista Home Premium 6.0.6002.2.1252.44.1033.18.3061.1170 [GMT 1:00]
.
AV: ESET NOD32 Antivirus 8.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: AVG AntiVirus Free Edition 2015 *Disabled/Outdated* {4D41356F-32AD-7C42-C820-63775EE4F413}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition 2015 *Disabled/Outdated* {F620D48B-1497-73CC-F290-58052563BEAE}
SP: ESET NOD32 Antivirus 8.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: AVG Internet Security 2015 *Disabled* {757AB44A-78C2-7D1A-E37F-CA42A037B368}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2015\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\BlueStacks\HD-LogRotatorService.exe
C:\Program Files\BlueStacks\HD-UpdaterService.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Zemana AntiMalware\ZAM.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\AVG\AVG2015\avgui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\Taskmgr.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uStart Page = Google
uSearch Bar = Google
uDefault_Page_URL = about:blank
mStart Page = about:blank
mSearch Page = about:blank
mDefault_Page_URL = about:blank
mDefault_Search_URL = about:blank
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\programdata\realnetworks\realdownloader\browserplugins\ie\rndlbrowserrecordplugin.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.8.0_31\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre1.8.0_31\bin\jp2ssv.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [Xvid] c:\program files\xvid\CheckUpdate.exe
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5.5ServiceManager] "c:\program files\common files\adobe\cs5.5servicemanager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [AVG_UI] "c:\program files\avg\avg2015\avgui.exe" /TRAYONLY
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [ZAM] "c:\program files\zemana antimalware\ZAM.exe" /minimized
mRun: [PC Cleaners] "c:\programdata\pc cleaners\PCCleaners.exe" /minimize
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{278A7B0F-A822-43DD-A7E2-42510197FD1C} : DHCPNameServer = 149.254.230.7 149.254.192.126
TCP: Interfaces\{361C2C64-E765-485B-A392-96829E3B17EA} : DHCPNameServer = 192.168.0.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\45.0.2454.85\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2015-5-12 190944]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2015-5-7 290272]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2015-7-28 186800]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2015-3-20 35808]
R1 Avgdiskx;AVG Disk Driver;c:\windows\system32\drivers\avgdiskx.sys [2015-3-11 132576]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2015-7-28 250288]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2015-7-23 31664]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2015-6-16 207328]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2015-5-12 213984]
R2 BstHdDrv;BlueStacks Hypervisor;c:\program files\bluestacks\HD-Hypervisor-x86.sys [2015-6-16 131704]
.
=============== Created Last 30 ================
.
2015-09-11 11:50:16 -------- d-----w- c:\users\bodo\appdata\local\ESET
2015-09-09 19:38:22 102912 ----a-w- c:\windows\system32\drivers\srvnet.sys
2015-09-09 19:38:21 304640 ----a-w- c:\windows\system32\drivers\srv.sys
2015-09-09 19:32:08 1402368 ----a-w- c:\windows\system32\msxml6.dll
2015-09-09 19:32:08 1253376 ----a-w- c:\windows\system32\msxml3.dll
2015-09-09 19:07:20 2048 ----a-w- c:\windows\system32\tzres.dll
2015-09-09 19:04:53 940032 ----a-w- c:\program files\common files\microsoft shared\ink\journal.dll
2015-09-09 19:04:52 1850880 ----a-w- c:\program files\windows journal\Journal.exe
2015-09-09 19:04:51 1220608 ----a-w- c:\program files\windows journal\NBDoc.DLL
2015-09-09 19:04:50 985600 ----a-w- c:\program files\windows journal\JNTFiltr.dll
2015-09-09 19:04:50 967680 ----a-w- c:\program files\windows journal\JNWDRV.dll
2015-09-09 19:02:59 34304 ----a-w- c:\windows\system32\atmlib.dll
2015-09-09 19:02:59 297472 ----a-w- c:\windows\system32\atmfd.dll
2015-09-09 19:02:55 2067456 ----a-w- c:\windows\system32\win32k.sys
2015-09-09 19:00:50 602112 ----a-w- c:\windows\system32\schedsvc.dll
2015-08-31 22:50:40 -------- d-----w- c:\users\User\appdata\roaming\RealNetworks
2015-08-31 22:49:28 -------- d-----w- c:\program files\RealNetworks
2015-08-31 22:49:22 -------- d-----w- c:\programdata\RealNetworks
2015-08-31 10:18:30 -------- d-----w- c:\programdata\PC Cleaners
2015-08-31 10:18:23 -------- d-----w- c:\programdata\PC1Data
2015-08-30 01:00:30 -------- d-----w- c:\programdata\KingSoft
2015-08-30 00:57:55 -------- d-----w- c:\programdata\TXQMPC
2015-08-30 00:57:55 -------- d-----w- c:\program files\Rising
2015-08-30 00:57:53 -------- d-----w- c:\programdata\Rising
2015-08-30 00:54:35 -------- d-----w- c:\program files\common files\Tencent
2015-08-30 00:51:20 -------- d-----w- c:\users\User\appdata\roaming\Tencent
2015-08-30 00:51:15 -------- d-----w- c:\programdata\Tencent
2015-08-30 00:19:02 -------- d-----w- C:\ppsfile
2015-08-30 00:19:01 -------- d-----w- C:\qycache
2015-08-30 00:11:40 -------- d-----w- C:\IQIYI Video
2015-08-30 00:02:23 -------- d-----w- c:\users\User\appdata\local\globalUpdate
2015-08-30 00:02:23 -------- d-----w- c:\program files\globalUpdate
2015-08-30 00:00:23 -------- d-----w- c:\users\User\appdata\roaming\DailyPCClean
2015-08-29 23:39:35 -------- d-----w- c:\users\User\appdata\local\4C4C4544-1440895174-3710-8046-C4C04F4E334A
2015-08-29 23:38:12 -------- d-----w- c:\programdata\28341ff220e0446c9fff27c4493d622e
2015-08-29 23:35:41 -------- d-----w- c:\users\User\appdata\roaming\WeatherTool
2015-08-29 15:20:06 -------- d-----w- c:\program files\Controller
2015-08-29 15:00:36 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
2015-08-29 12:00:15 -------- d-----w- c:\users\User\appdata\local\{925B1088-DD5F-47C0-8964-53D8D1C5CF0E}
2015-08-29 11:29:38 -------- d-----w- c:\users\User\appdata\local\{8F1267F6-E90F-490A-82CA-509F1DFD0E9C}
2015-08-27 11:25:17 -------- d-----w- c:\programdata\Sony Corporation
2015-08-26 09:08:52 -------- d-----w- c:\program files\SystemRequirementsLab
2015-08-25 12:52:55 -------- d-----w- c:\users\User\appdata\local\{B318BA93-77DE-4D50-BAEA-A18131CFA774}
2015-08-24 10:45:29 -------- d-----w- c:\program files\World of Warcraft
2015-08-24 10:42:01 -------- d-----w- c:\users\User\appdata\local\Blizzard Entertainment
2015-08-24 10:41:41 -------- d-----w- c:\users\User\appdata\roaming\Battle.net
2015-08-24 10:41:41 -------- d-----w- c:\users\User\appdata\local\Battle.net
2015-08-24 10:40:34 -------- d-----w- c:\programdata\Blizzard Entertainment
2015-08-24 10:40:34 -------- d-----w- c:\program files\Battle.net
2015-08-24 10:38:13 -------- d-----w- c:\programdata\Battle.net
2015-08-22 22:46:01 -------- d-----w- c:\program files\SigmaTel
2015-08-22 14:23:20 12872 ----a-w- c:\windows\system32\bootdelete.exe
2015-08-22 04:34:52 97560 ----a-w- c:\windows\system32\drivers\zam32.sys
2015-08-22 04:34:34 97560 ----a-w- c:\windows\system32\drivers\zamguard32.sys
2015-08-20 20:10:58 -------- d-----w- c:\programdata\HitmanPro
2015-08-16 21:06:40 -------- d-----w- c:\users\User\appdata\local\{6E9ECE0F-B878-4E61-8406-5EC4DB3D4962}
2015-08-16 20:04:48 -------- d-----w- c:\users\User\appdata\local\DriverToolkit
2015-08-15 14:05:59 -------- d-----w- c:\users\User\appdata\roaming\NeroDigital(TM)
2015-08-13 13:32:28 920088 ----a-w- c:\windows\system32\igxpun.exe
2015-08-13 12:37:49 39936 ----a-w- c:\windows\system32\drivers\rimmptsk.sys
2015-08-13 12:37:49 37376 ----a-w- c:\windows\system32\drivers\rixdptsk.sys
2015-08-13 12:37:49 16480 ----a-w- c:\windows\system32\rixdicon.dll
2015-08-13 12:37:48 42496 ----a-w- c:\windows\system32\drivers\rimsptsk.sys
2015-08-13 12:37:11 57344 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\ctor.dll
2015-08-13 12:37:11 32768 ----a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2015-08-13 12:37:11 237568 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iscript.dll
2015-08-13 12:37:11 155648 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iuser.dll
2015-08-13 12:37:10 692224 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iKernel.dll
2015-08-13 12:37:10 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\DotNetInstaller.exe
2015-08-13 12:37:10 163972 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iGdi.dll
2015-08-13 12:37:09 282756 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\setup.dll
2015-08-13 10:48:38 107608 ----a-w- c:\program files\common files\microsoft shared\office14\EXP_PDF.DLL
2015-08-13 04:01:05 56256 ----a-w- c:\windows\system32\drivers\mountmgr.sys
2015-08-13 04:01:05 49664 ----a-w- c:\windows\system32\csrsrv.dll
2015-08-13 04:01:05 140224 ----a-w- c:\windows\system32\drivers\ecache.sys
2015-08-13 04:01:05 1206192 ----a-w- c:\windows\system32\ntdll.dll
2015-08-13 04:01:05 10752 ----a-w- c:\windows\system32\msmmsp.dll
2015-08-13 04:01:04 564224 ----a-w- c:\windows\system32\emdmgmt.dll
2015-08-13 04:01:04 3605440 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-08-13 04:01:03 3553216 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-08-13 03:59:53 103120 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 03:58:40 2067968 ----a-w- c:\windows\system32\mstscax.dll
2015-08-13 03:53:39 68608 ----a-w- c:\windows\system32\basesrv.dll
2015-08-13 03:42:39 682496 ----a-w- c:\windows\system32\d2d1.dll
2015-08-13 03:42:39 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2015-08-13 03:42:39 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2015-08-13 03:42:39 189952 ----a-w- c:\windows\system32\d3d10core.dll
2015-08-13 03:42:39 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2015-08-13 03:42:39 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2015-08-13 03:42:39 1029120 ----a-w- c:\windows\system32\d3d10.dll
2015-08-13 03:42:38 802304 ----a-w- c:\windows\system32\FntCache.dll
2015-08-13 03:42:38 1072640 ----a-w- c:\windows\system32\DWrite.dll
2015-08-13 03:41:08 199680 ----a-w- c:\windows\system32\WebClnt.dll
2015-08-13 03:40:46 151040 ----a-w- c:\windows\system32\notepad.exe
2015-08-13 03:40:46 151040 ----a-w- c:\windows\notepad.exe
2015-08-13 03:38:25 -------- d-----w- C:\DRIVERS
2015-08-13 03:25:39 53248 ----a-w- c:\windows\system32\RBK8F43.tmp
.
==================== Find3M ====================
.
2015-09-10 14:06:17 98520 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-08-31 22:48:00 499712 ----a-w- c:\windows\system32\msvcp71.dll
2015-08-31 22:48:00 348160 ----a-w- c:\windows\system32\msvcr71.dll
2015-08-17 17:18:19 1814016 ----a-w- c:\windows\system32\jscript9.dll
2015-08-17 17:14:56 367616 ----a-w- c:\windows\system32\html.iec
2015-08-17 17:12:06 1129472 ----a-w- c:\windows\system32\wininet.dll
2015-08-17 17:11:04 422400 ----a-w- c:\windows\system32\vbscript.dll
2015-08-17 17:11:02 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2015-08-17 17:10:36 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2015-08-17 17:10:08 11776 ----a-w- c:\windows\system32\mshta.exe
2015-08-17 17:09:58 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2015-08-14 05:22:27 1656 ----a-w- c:\windows\system32\ASOROSet.bin
2015-08-12 12:04:36 70168 ----a-w- c:\windows\system32\drivers\RapportHades.sys
2015-08-12 12:04:36 223000 ----a-w- c:\windows\system32\drivers\RapportKELL.sys
2015-08-11 22:33:16 778440 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-08-11 22:33:15 142536 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-08-04 23:03:08 877152 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2015-08-04 23:03:08 538208 ----a-w- c:\windows\system32\msvcp120_clr0400.dll
2015-07-28 10:02:10 250288 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2015-07-28 05:12:19 98520 ----a-w- c:\windows\system32\drivers\20F74CA3.sys
2015-07-23 15:44:26 31664 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys
2015-07-13 06:14:14 202704 ----a-w- c:\windows\system32\drivers\eamonm.sys
2015-07-13 06:14:14 199608 ----a-w- c:\windows\system32\drivers\edevmon.sys
2015-07-13 06:14:14 144536 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2015-07-13 06:14:14 132152 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2015-07-03 16:04:03 1316864 ----a-w- c:\windows\system32\ole32.dll
2015-06-27 16:03:22 783872 ----a-w- c:\windows\system32\rpcrt4.dll
2015-06-27 16:02:55 218112 ----a-w- c:\windows\system32\msv1_0.dll
2015-06-27 16:02:34 501248 ----a-w- c:\windows\system32\kerberos.dll
2015-06-27 16:01:58 801280 ----a-w- c:\windows\system32\advapi32.dll
2015-06-27 14:21:13 217088 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2015-06-27 14:21:10 81408 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2015-06-24 00:29:00 1217192 ----a-w- c:\windows\system32\FM20.DLL
2015-06-23 12:27:10 246952 ------w- c:\windows\system32\MpSigStub.exe
2015-06-18 07:41:50 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-06-18 07:41:42 94936 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-06-18 07:41:36 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-06-17 16:50:20 2264576 ----a-w- c:\windows\system32\msi.dll
2015-06-17 15:09:17 73216 ----a-w- c:\windows\system32\msiexec.exe
2015-06-16 14:54:52 207328 ----a-w- c:\windows\system32\drivers\avgldx86.sys
.
============= FINISH: 17:40:06.23 ===============