Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all articles
Browse latest Browse all 2798

Stealth Malware

$
0
0
I am cleaning up a friend's computer. It is running much better now but I know there is something still on it. When I try to run Hijackthis, I get an error message and the scan only runs to a certain point. When I try to remove files with HJT, they are not removed. Also, every time I run Superantispyware, I get 60+ items. The machine is also a lot noisier/working harder than it should be while resting. Thank you for any help that you can provide.

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.18163 BrowserJavaVersion: 11.60.2
Run by EJackson at 12:09:59 on 2016-01-24
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8157.6409 [GMT -5:00]
.
AV: Norton Security Suite *Enabled/Updated* {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Security Suite *Enabled/Updated* {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton Security Suite *Enabled* {6BFC5632-188D-B806-D13E-C607121B42A0}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\dlbucoms.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
C:\Program Files (x86)\Norton Security Suite\Engine\22.5.5.15\N360.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Norton Security Suite\Engine\22.5.5.15\N360.exe
C:\Windows\system32\viakaraokesrv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Dell Photo AIO Printer 942\DLBUmon.exe
C:\Program Files (x86)\Dell Photo AIO Printer 942\memcard.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\GWX\GWX.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\22.5.5.15\coIEPlg.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\22.5.5.15\coIEPlg.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
dRun: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
dRunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{24465103-2559-4CD9-B475-9ADD43D1F5FF} : DHCPNameServer = 75.75.75.75 75.75.76.76
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\msosb.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Skype for Business Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine64\22.5.5.15\coieplg.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL
x64-BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL
x64-TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine64\22.5.5.15\coieplg.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [DLBUCATS] rundll32 C:\Windows\System32\spool\DRIVERS\x64\3\DLBUtime.dll,RunDLLEntry
x64-Run: [dlbumon.exe] "C:\Program Files (x86)\Dell Photo AIO Printer 942\dlbumon.exe"
x64-Run: [MemoryCardManager] "C:\Program Files (x86)\Dell Photo AIO Printer 942\memcard.exe"
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
x64-Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\EJackson\AppData\Roaming\Mozilla\Firefox\Profiles\l8dfzosr.default-1445455446024\
FF - prefs.js: browser.startup.homepage - hxxp://my.xfinity.com/tt2/?cid=tbid08252014
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
FF - plugin: C:\Users\EJackson\AppData\Local\Citrix\Plugins\104\npappdetector.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2014-6-29 82240]
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2014-6-29 42304]
R0 SymEFASI;Symantec Extended File Attributes (SI);C:\Windows\System32\drivers\N360x64\1605050.00F\symefasi64.sys [2015-11-30 1621232]
R1 AppleCharger;AppleCharger;C:\Windows\System32\drivers\AppleCharger.sys [2014-6-29 22240]
R1 BHDrvx64;BHDrvx64;C:\Program Files (x86)\Norton Security Suite\NortonData\22.5.2.15\Definitions\BASHDefs\20160119.001\BHDrvx64.sys [2016-1-23 1665608]
R1 ccSet_N360;N360 Settings Manager;C:\Windows\System32\drivers\N360x64\1605050.00F\ccsetx64.sys [2015-11-30 173808]
R1 IDSVia64;IDSVia64;C:\Program Files (x86)\Norton Security Suite\NortonData\22.5.2.15\Definitions\IPSDefs\20160122.001\IDSviA64.sys [2016-1-23 767224]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\N360x64\1605050.00F\ironx64.sys [2015-11-30 297720]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\N360x64\1605050.00F\symnets.sys [2015-11-30 577768]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2014-7-22 172344]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2014-4-17 239616]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-4-17 344064]
R2 amdacpksd;ACP Kernel Service Driver;C:\Windows\System32\drivers\amdacpksd.sys [2014-4-17 274656]
R2 AODDriver4.2.0;AODDriver4.2.0;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2014-2-11 59616]
R2 ClickToRunSvc;Microsoft Office ClickToRun Service;C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe [2014-8-20 2787512]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 Garmin Device Interaction Service;Garmin Device Interaction Service;C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [2015-10-29 777744]
R2 N360;Norton 360;C:\Program Files (x86)\Norton Security Suite\Engine\22.5.5.15\n360.exe [2015-11-30 282016]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service;C:\Windows\System32\ViakaraokeSrv.exe [2014-6-29 27768]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2013-12-19 94720]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2015-12-29 157520]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2014-6-29 646248]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\System32\drivers\viahduaa.sys [2014-6-29 690864]
R3 VUSB3HUB;VIA USB 3 Root Hub Service;C:\Windows\System32\drivers\ViaHub3.sys [2014-6-29 225792]
R3 xhcdrv;VIA USB eXtensible Host Controller Service;C:\Windows\System32\drivers\xhcdrv.sys [2014-6-29 295424]
S1 UsbCharger;UsbCharger;C:\Windows\System32\drivers\UsbCharger.sys [2014-6-29 22240]
S2 AODDriver4.3;AODDriver4.3;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2014-2-11 59616]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-4-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-4-11 124088]
S3 athur;Atheros AR9271 Wireless Network Adapter Service;C:\Windows\System32\drivers\athurx.sys [2010-1-5 1847296]
S3 GVTDrv64;GVTDrv64;C:\Windows\GVTDrv64.sys [2014-6-29 30528]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2014-6-29 160256]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2016-1-13 114688]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2014-8-29 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-8-29 56832]
S4 amdacpusrsvc;ACP User Service;C:\AMD\amdacpusrsvc.exe [2014-4-17 82432]
S4 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S4 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2014-8-3 1255736]
.
=============== Created Last 30 ================
.
2016-01-23 22:55:32 -------- d-----w- C:\Desktop
2016-01-23 22:31:36 -------- d-----w- C:\Users\EJackson\AppData\Roaming\SUPERAntiSpyware.com
2016-01-23 22:30:38 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2016-01-23 22:30:38 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2016-01-23 22:30:03 -------- d-----w- C:\ProgramData\SUPERSetup
2016-01-19 01:40:56 -------- d-----w- C:\Users\EJackson\AppData\Local\TempTaskUpdateDetection7BB1DD06-6801-4043-9444-07782D42FAD6
2016-01-09 15:42:16 1065316 ----a-w- C:\ProgramData\SPLB231.tmp
2016-01-09 15:01:37 762254 ----a-w- C:\ProgramData\SPL7D3A.tmp
.
==================== Find3M ====================
.
2016-01-24 16:59:27 65536 ----a-w- C:\Windows\System32\spu_storage.bin
2016-01-07 14:53:28 796864 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2016-01-07 14:53:28 142528 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-12-30 19:08:35 5572544 ----a-w- C:\Windows\System32\ntoskrnl.exe
2015-12-30 19:08:34 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2015-12-30 19:08:34 154560 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2015-12-30 19:05:33 1730496 ----a-w- C:\Windows\System32\ntdll.dll
2015-12-30 19:02:28 362496 ----a-w- C:\Windows\System32\wow64win.dll
2015-12-30 19:02:28 243712 ----a-w- C:\Windows\System32\wow64.dll
2015-12-30 19:02:28 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2015-12-30 19:02:17 215040 ----a-w- C:\Windows\System32\winsrv.dll
2015-12-30 19:02:13 210432 ----a-w- C:\Windows\System32\wdigest.dll
2015-12-30 19:02:03 86528 ----a-w- C:\Windows\System32\TSpkg.dll
2015-12-30 19:01:56 28672 ----a-w- C:\Windows\System32\sspisrv.dll
2015-12-30 19:01:56 135680 ----a-w- C:\Windows\System32\sspicli.dll
2015-12-30 19:01:55 503808 ----a-w- C:\Windows\System32\srcore.dll
2015-12-30 19:01:55 50176 ----a-w- C:\Windows\System32\srclient.dll
2015-12-30 19:01:14 28160 ----a-w- C:\Windows\System32\secur32.dll
2015-12-30 19:01:12 344064 ----a-w- C:\Windows\System32\schannel.dll
2015-12-30 19:01:10 1214464 ----a-w- C:\Windows\System32\rpcrt4.dll
2015-12-30 19:00:23 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2015-12-30 18:59:11 312320 ----a-w- C:\Windows\System32\ncrypt.dll
2015-12-30 18:59:07 315392 ----a-w- C:\Windows\System32\msv1_0.dll
2015-12-30 18:59:02 60416 ----a-w- C:\Windows\System32\msobjs.dll
2015-12-30 18:58:31 146432 ----a-w- C:\Windows\System32\msaudite.dll
2015-12-30 18:58:00 1461248 ----a-w- C:\Windows\System32\lsasrv.dll
2015-12-30 18:57:55 729600 ----a-w- C:\Windows\System32\kerberos.dll
2015-12-30 18:57:55 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2015-12-30 18:55:46 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2015-12-30 18:55:45 43520 ----a-w- C:\Windows\System32\cryptbase.dll
2015-12-30 18:55:44 22016 ----a-w- C:\Windows\System32\credssp.dll
2015-12-30 18:47:23 3993536 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2015-12-30 18:47:23 3938240 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2015-12-30 18:44:26 1311768 ----a-w- C:\Windows\SysWow64\ntdll.dll
2015-12-30 18:41:32 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2015-12-30 18:41:31 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2015-12-30 18:41:31 665088 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2015-12-30 18:41:31 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2015-12-30 18:41:17 171520 ----a-w- C:\Windows\SysWow64\wdigest.dll
2015-12-30 18:41:11 65536 ----a-w- C:\Windows\SysWow64\TSpkg.dll
2015-12-30 18:41:03 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
2015-12-30 18:40:29 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2015-12-30 18:40:28 251392 ----a-w- C:\Windows\SysWow64\schannel.dll
2015-12-30 18:39:38 223232 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2015-12-30 18:39:35 259584 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2015-12-30 18:39:32 60416 ----a-w- C:\Windows\SysWow64\msobjs.dll
2015-12-30 18:39:17 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll
2015-12-30 18:38:56 552960 ----a-w- C:\Windows\SysWow64\kerberos.dll
2015-12-30 18:38:11 17408 ----a-w- C:\Windows\SysWow64\credssp.dll
2015-12-30 17:57:51 64000 ----a-w- C:\Windows\System32\auditpol.exe
2015-12-30 17:50:50 338432 ----a-w- C:\Windows\System32\conhost.exe
2015-12-30 17:49:09 296960 ----a-w- C:\Windows\System32\rstrui.exe
2015-12-30 17:44:49 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2015-12-30 17:43:39 159232 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2015-12-30 17:42:48 290816 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2015-12-30 17:42:41 129024 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2015-12-30 17:41:07 30720 ----a-w- C:\Windows\System32\lsass.exe
2015-12-30 17:41:00 112640 ----a-w- C:\Windows\System32\smss.exe
2015-12-30 17:32:54 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2015-12-30 17:32:53 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2015-12-30 17:32:52 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2015-12-30 17:32:51 2048 ----a-w- C:\Windows\SysWow64\user.exe
2015-12-30 17:30:55 36352 ----a-w- C:\Windows\SysWow64\cryptbase.dll
2015-12-30 17:30:40 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2015-12-30 17:30:40 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2015-12-30 17:30:40 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2015-12-30 17:30:40 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2015-12-12 18:31:10 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2015-12-12 18:30:59 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2015-12-12 18:16:29 66560 ----a-w- C:\Windows\System32\iesetup.dll
2015-12-12 18:15:46 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2015-12-12 18:15:40 417792 ----a-w- C:\Windows\System32\html.iec
2015-12-12 18:15:09 571904 ----a-w- C:\Windows\System32\vbscript.dll
2015-12-12 18:14:59 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2015-12-12 18:07:27 6051328 ----a-w- C:\Windows\System32\jscript9.dll
2015-12-12 18:02:34 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2015-12-12 18:02:34 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
2015-12-12 18:02:19 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2015-12-12 17:55:26 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2015-12-12 17:49:57 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2015-12-12 17:44:06 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2015-12-12 17:37:41 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2015-12-12 17:37:39 496640 ----a-w- C:\Windows\SysWow64\vbscript.dll
2015-12-12 17:37:05 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2015-12-12 17:36:57 341504 ----a-w- C:\Windows\SysWow64\html.iec
2015-12-12 17:36:04 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2015-12-12 17:27:24 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2015-12-12 17:27:04 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2015-12-12 17:21:12 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2015-12-12 17:20:50 2123264 ----a-w- C:\Windows\System32\inetcpl.cpl
2015-12-12 17:14:57 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2015-12-12 17:09:47 4610560 ----a-w- C:\Windows\SysWow64\jscript9.dll
2015-12-12 17:06:02 2487808 ----a-w- C:\Windows\System32\wininet.dll
2015-12-12 17:00:20 2050560 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2015-12-12 17:00:09 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2015-12-12 16:41:25 2011136 ----a-w- C:\Windows\SysWow64\wininet.dll
2015-12-11 18:57:53 1164800 ----a-w- C:\Windows\System32\aeinv.dll
2015-12-08 21:54:13 902144 ----a-w- C:\Windows\SysWow64\WMADMOD.DLL
2015-12-08 21:54:13 815616 ----a-w- C:\Windows\SysWow64\WMADMOE.DLL
2015-12-08 21:54:13 740352 ----a-w- C:\Windows\SysWow64\wmpmde.dll
.
============= FINISH: 12:11:11.70 ===============

Attached Files
File Type: txt attach.txt (6.0 KB)

Viewing all articles
Browse latest Browse all 2798

Trending Articles