Hi all, my computer is possibly infected and was just hoping to receive some help.
What happened was, i had my firefox browser open and then Microsoft Essentials popped up with a message in the bottom right hand corner claiming something, i can't remember what the message was exactly but i think it was something along the lines of 'infection cleaned' or infection blocked. There was a green tick as opposed to the red cross.
When checking MSE's quarantine, nothing i there, but when checking the 'all detected items' section it says it detected Rogue:JS/TechBrolo.A. It also states the action taken was to quarantine it but as i stated above, nothing is in the quarantine. In the details below it says 'Error Code 0x80508023. The program could not find the malware and other potentially unwanted software on this computer.'
I have run full scans of both MSE and MalwareBytes, both have found nothing. I have also run scans of Adwcleaner and Eset online, and again both have found nothing.
Am i clean? Did MSE possibly block the infection? All help would be much appreciated. Please find scan results below:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.18450 BrowserJavaVersion: 11.101.2
Run by Steve at 19:14:51 on 2016-09-19
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8174.5378 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {768124D7-F5F7-6D2F-DDC2-94DFA4017C95}
SP: Microsoft Security Essentials *Enabled/Updated* {CDE0C533-D3CD-62A1-E772-AFADDF863628}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ZoneAlarm Free Firewall Firewall *Enabled* {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe
C:\Program Files (x86)\Led Indicator Keyboard Driver\KeyboardIndicator.exe
C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\SearchIndexer.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
uRun: [Recovery Backup Wizard] C:\Program Files (x86)\TTG\Reminder\Reminder.exe
mRun: [LedIndicatorKeyboardDriver] "C:\Program Files (x86)\Led Indicator Keyboard Driver\KeyboardIndicator.exe" showhide
mRun: [ZoneAlarm] "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe"
mRun: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{04B4B090-9975-4758-BF22-6D97A4372D34} : DHCPNameServer = 192.168.1.254
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.116\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\2tsg8dj4.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.co.uk/
FF - prefs.js: keyword.URL - true
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.50709.0\npctrlui.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2015-11-13 289120]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2015-8-4 246784]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-8-5 83768]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2015-3-18 822496]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-14 27136]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2016-8-4 1514464]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2016-8-4 1136608]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2014-10-8 534184]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-8-31 2656536]
R2 ZAPrivacyService;ZoneAlarm Privacy Service;C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [2016-6-30 114424]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2016-3-1 104976]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-8-31 169584]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2016-8-4 27008]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\MBAMSwissArmy.sys [2016-8-4 192216]
R3 MBAMWebAccessControl;MBAMWebAccessControl;C:\Windows\System32\drivers\mwac.sys [2016-8-4 64896]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2015-11-13 133816]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2016-1-29 374344]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2014-10-8 766632]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2014-10-8 273576]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2014-10-8 29352]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2014-10-8 23208]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2014-10-8 211104]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-5 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-5 125112]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2016-9-14 114688]
S3 pmxdrv;pmxdrv;C:\Windows\System32\drivers\pmxdrv.sys [2016-8-20 38536]
S3 semav6msr64;semav6msr64;C:\Windows\System32\drivers\semav6msr64.sys [2016-8-4 21984]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2015-11-5 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2016-8-4 1255736]
.
=============== Created Last 30 ================
.
2016-09-19 17:36:08 -------- d-----w- C:\AdwCleaner
2016-09-19 16:03:11 75888 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BAE53C0F-5A77-4167-8ABB-B2085A8206BD}\offreg.932.dll
2016-09-19 15:59:46 11847048 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BAE53C0F-5A77-4167-8ABB-B2085A8206BD}\mpengine.dll
2016-09-19 12:27:21 11847048 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2016-09-18 00:07:12 -------- d-----w- C:\Program Files\iTunes
2016-09-18 00:07:12 -------- d-----w- C:\Program Files\iPod
2016-09-16 13:13:31 -------- d-----w- C:\Users\Steve\AppData\Local\Microsoft Games
2016-09-14 16:25:59 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2016-09-14 16:22:50 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2016-09-14 16:22:50 377576 ----a-w- C:\Windows\System32\drivers\netio.sys
2016-09-14 16:22:50 1896168 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2016-09-14 16:22:49 84480 ----a-w- C:\Windows\SysWow64\INETRES.dll
2016-09-14 16:22:49 84480 ----a-w- C:\Windows\System32\INETRES.dll
2016-09-14 16:22:49 741888 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2016-09-14 16:22:49 46080 ----a-w- C:\Windows\System32\drivers\tcpipreg.sys
2016-09-14 16:22:49 287976 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2016-09-14 16:22:45 877056 ----a-w- C:\Windows\System32\oleaut32.dll
2016-09-14 16:22:45 581632 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2016-09-14 09:05:49 1167568 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{76CD7CBD-FF52-445B-9060-11ABCE92442F}\gapaengine.dll
2016-09-04 10:34:07 -------- d-----w- C:\Users\Steve\AppData\Local\Apple Computer
2016-09-04 10:32:08 -------- d-----w- C:\Users\Steve\AppData\Local\Apple
2016-09-04 10:31:49 -------- d-----w- C:\Program Files\Bonjour
2016-09-04 10:31:49 -------- d-----w- C:\Program Files (x86)\Bonjour
2016-08-28 12:22:27 -------- d-----w- C:\Users\Steve\AppData\Local\ESET
2016-08-25 13:58:37 -------- d-----w- C:\ProgramData\Virtualized Applications
2016-08-23 09:20:45 -------- d-----w- C:\FRST
2016-08-22 16:52:49 -------- d-----w- C:\Users\Steve\AppData\Roaming\MediaInfo
2016-08-22 16:52:28 -------- d-----w- C:\Program Files\MediaInfo
2016-08-20 22:46:54 -------- d-----w- C:\Users\Steve\AppData\Local\CEF
.
==================== Find3M ====================
.
2016-09-19 16:42:21 192216 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2016-09-02 15:40:18 631176 ----a-w- C:\Windows\System32\winresume.efi
2016-09-02 15:35:48 706280 ----a-w- C:\Windows\System32\winload.efi
2016-09-02 15:35:47 95464 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2016-09-02 15:35:47 5548264 ----a-w- C:\Windows\System32\ntoskrnl.exe
2016-09-02 15:35:47 154856 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2016-09-02 15:34:22 1732864 ----a-w- C:\Windows\System32\ntdll.dll
2016-09-02 15:31:03 362496 ----a-w- C:\Windows\System32\wow64win.dll
2016-09-02 15:31:03 243712 ----a-w- C:\Windows\System32\wow64.dll
2016-09-02 15:31:03 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2016-09-02 15:31:02 215552 ----a-w- C:\Windows\System32\winsrv.dll
2016-09-02 15:31:02 210432 ----a-w- C:\Windows\System32\wdigest.dll
2016-09-02 15:31:01 86528 ----a-w- C:\Windows\System32\TSpkg.dll
2016-09-02 15:31:00 503808 ----a-w- C:\Windows\System32\srcore.dll
2016-09-02 15:31:00 50176 ----a-w- C:\Windows\System32\srclient.dll
2016-09-02 15:31:00 28672 ----a-w- C:\Windows\System32\sspisrv.dll
2016-09-02 15:31:00 135680 ----a-w- C:\Windows\System32\sspicli.dll
2016-09-02 15:21:25 4000488 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2016-09-02 15:21:25 3944680 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2016-09-02 15:18:23 1314112 ----a-w- C:\Windows\SysWow64\ntdll.dll
2016-09-02 15:02:33 148480 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2016-09-02 15:02:29 62464 ----a-w- C:\Windows\System32\drivers\appid.sys
2016-09-02 15:02:29 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2016-09-02 15:01:47 64000 ----a-w- C:\Windows\System32\auditpol.exe
2016-09-02 14:58:46 338432 ----a-w- C:\Windows\System32\conhost.exe
2016-09-02 14:57:53 296960 ----a-w- C:\Windows\System32\rstrui.exe
2016-09-02 14:55:12 159744 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2016-09-02 14:54:40 291328 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2016-09-02 14:54:38 129536 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2016-09-02 14:53:56 30720 ----a-w- C:\Windows\System32\lsass.exe
2016-09-02 14:53:52 112640 ----a-w- C:\Windows\System32\smss.exe
2016-09-02 14:53:18 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2016-09-02 14:49:51 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2016-09-02 14:49:49 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2016-09-02 14:49:49 2048 ----a-w- C:\Windows\SysWow64\user.exe
2016-09-02 14:49:49 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2016-09-02 14:49:04 36352 ----a-w- C:\Windows\SysWow64\cryptbase.dll
2016-09-02 14:48:57 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2016-09-02 14:48:57 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2016-09-02 14:48:57 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2016-09-02 14:48:57 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2016-09-01 03:18:32 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2016-09-01 02:48:10 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2016-09-01 02:46:36 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2016-09-01 02:46:11 341504 ----a-w- C:\Windows\SysWow64\html.iec
2016-09-01 02:46:04 498688 ----a-w- C:\Windows\SysWow64\vbscript.dll
2016-09-01 02:44:20 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2016-09-01 02:24:16 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2016-09-01 02:23:43 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2016-09-01 01:59:47 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2016-09-01 01:29:35 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2016-09-01 01:29:30 2055680 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2016-09-01 01:24:36 4607488 ----a-w- C:\Windows\SysWow64\jscript9.dll
2016-09-01 00:43:05 2445824 ----a-w- C:\Windows\SysWow64\wininet.dll
2016-09-01 00:40:49 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2016-09-01 00:40:38 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2016-09-01 00:25:20 66560 ----a-w- C:\Windows\System32\iesetup.dll
2016-09-01 00:24:36 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2016-09-01 00:24:29 417792 ----a-w- C:\Windows\System32\html.iec
2016-09-01 00:24:09 576000 ----a-w- C:\Windows\System32\vbscript.dll
2016-09-01 00:24:02 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2016-09-01 00:11:19 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
2016-09-01 00:11:18 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2016-09-01 00:10:55 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2016-09-01 00:06:08 6047232 ----a-w- C:\Windows\System32\jscript9.dll
2016-09-01 00:03:41 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2016-08-31 23:27:32 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2016-08-31 23:26:53 2131456 ----a-w- C:\Windows\System32\inetcpl.cpl
2016-08-31 23:10:42 2921472 ----a-w- C:\Windows\System32\wininet.dll
2016-08-19 23:38:04 38536 ----a-w- C:\Windows\System32\drivers\pmxdrv.sys
2016-08-16 17:36:50 1009152 ----a-w- C:\Windows\System32\user32.dll
2016-08-16 02:48:15 833024 ----a-w- C:\Windows\SysWow64\user32.dll
2016-08-16 02:35:57 3218432 ----a-w- C:\Windows\System32\win32k.sys
2016-08-12 16:26:18 464896 ----a-w- C:\Windows\System32\drivers\srv.sys
2016-08-12 16:26:12 405504 ----a-w- C:\Windows\System32\drivers\srv2.sys
2016-08-12 16:26:05 168960 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2016-08-04 18:07:45 97856 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2016-08-03 19:15:55 68608 ----a-w- C:\Windows\System32\taskhost.exe
2016-08-03 19:13:26 1887232 ----a-w- C:\Windows\System32\d3d11.dll
2016-08-03 19:13:26 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2016-07-27 22:03:56 462296 ----a-w- C:\Windows\System32\drivers\vsdatant.sys
2016-07-27 19:25:34 504488 ------w- C:\Windows\System32\MpSigStub.exe
2016-07-08 15:32:47 2048 ----a-w- C:\Windows\System32\tzres.dll
2016-07-08 15:16:59 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2016-06-26 00:35:09 41704 ----a-w- C:\Windows\System32\CompatTelRunner.exe
2016-06-26 00:27:39 756736 ----a-w- C:\Windows\System32\win32spl.dll
2016-06-26 00:27:32 344576 ----a-w- C:\Windows\System32\ntprint.dll
2016-06-26 00:27:26 970240 ----a-w- C:\Windows\System32\localspl.dll
2016-06-26 00:27:25 22528 ----a-w- C:\Windows\System32\inetppui.dll
2016-06-26 00:27:25 166400 ----a-w- C:\Windows\System32\inetpp.dll
2016-06-26 00:27:07 1208320 ----a-w- C:\Windows\System32\aeinv.dll
2016-06-25 19:54:03 497152 ----a-w- C:\Windows\SysWow64\win32spl.dll
2016-06-25 19:53:56 297472 ----a-w- C:\Windows\SysWow64\ntprint.dll
2016-06-25 19:53:05 48640 ----a-w- C:\Windows\System32\wpnpinst.exe
2016-06-25 19:53:04 61952 ----a-w- C:\Windows\System32\ntprint.exe
2016-06-25 19:41:53 61952 ----a-w- C:\Windows\SysWow64\ntprint.exe
2016-06-22 13:06:29 268800 ----a-w- C:\Windows\System32\centel.dll
.
============= FINISH: 19:15:23.77 ===============
What happened was, i had my firefox browser open and then Microsoft Essentials popped up with a message in the bottom right hand corner claiming something, i can't remember what the message was exactly but i think it was something along the lines of 'infection cleaned' or infection blocked. There was a green tick as opposed to the red cross.
When checking MSE's quarantine, nothing i there, but when checking the 'all detected items' section it says it detected Rogue:JS/TechBrolo.A. It also states the action taken was to quarantine it but as i stated above, nothing is in the quarantine. In the details below it says 'Error Code 0x80508023. The program could not find the malware and other potentially unwanted software on this computer.'
I have run full scans of both MSE and MalwareBytes, both have found nothing. I have also run scans of Adwcleaner and Eset online, and again both have found nothing.
Am i clean? Did MSE possibly block the infection? All help would be much appreciated. Please find scan results below:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.18450 BrowserJavaVersion: 11.101.2
Run by Steve at 19:14:51 on 2016-09-19
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8174.5378 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {768124D7-F5F7-6D2F-DDC2-94DFA4017C95}
SP: Microsoft Security Essentials *Enabled/Updated* {CDE0C533-D3CD-62A1-E772-AFADDF863628}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ZoneAlarm Free Firewall Firewall *Enabled* {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe
C:\Program Files (x86)\Led Indicator Keyboard Driver\KeyboardIndicator.exe
C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\SearchIndexer.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
uRun: [Recovery Backup Wizard] C:\Program Files (x86)\TTG\Reminder\Reminder.exe
mRun: [LedIndicatorKeyboardDriver] "C:\Program Files (x86)\Led Indicator Keyboard Driver\KeyboardIndicator.exe" showhide
mRun: [ZoneAlarm] "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe"
mRun: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{04B4B090-9975-4758-BF22-6D97A4372D34} : DHCPNameServer = 192.168.1.254
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.116\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\2tsg8dj4.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.co.uk/
FF - prefs.js: keyword.URL - true
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.50709.0\npctrlui.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2015-11-13 289120]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2015-8-4 246784]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-8-5 83768]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2015-3-18 822496]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-14 27136]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2016-8-4 1514464]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2016-8-4 1136608]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2014-10-8 534184]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-8-31 2656536]
R2 ZAPrivacyService;ZoneAlarm Privacy Service;C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [2016-6-30 114424]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2016-3-1 104976]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-8-31 169584]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2016-8-4 27008]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\MBAMSwissArmy.sys [2016-8-4 192216]
R3 MBAMWebAccessControl;MBAMWebAccessControl;C:\Windows\System32\drivers\mwac.sys [2016-8-4 64896]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2015-11-13 133816]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2016-1-29 374344]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2014-10-8 766632]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2014-10-8 273576]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2014-10-8 29352]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2014-10-8 23208]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2014-10-8 211104]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-5 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-5 125112]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2016-9-14 114688]
S3 pmxdrv;pmxdrv;C:\Windows\System32\drivers\pmxdrv.sys [2016-8-20 38536]
S3 semav6msr64;semav6msr64;C:\Windows\System32\drivers\semav6msr64.sys [2016-8-4 21984]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2015-11-5 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2016-8-4 1255736]
.
=============== Created Last 30 ================
.
2016-09-19 17:36:08 -------- d-----w- C:\AdwCleaner
2016-09-19 16:03:11 75888 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BAE53C0F-5A77-4167-8ABB-B2085A8206BD}\offreg.932.dll
2016-09-19 15:59:46 11847048 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BAE53C0F-5A77-4167-8ABB-B2085A8206BD}\mpengine.dll
2016-09-19 12:27:21 11847048 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2016-09-18 00:07:12 -------- d-----w- C:\Program Files\iTunes
2016-09-18 00:07:12 -------- d-----w- C:\Program Files\iPod
2016-09-16 13:13:31 -------- d-----w- C:\Users\Steve\AppData\Local\Microsoft Games
2016-09-14 16:25:59 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2016-09-14 16:22:50 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2016-09-14 16:22:50 377576 ----a-w- C:\Windows\System32\drivers\netio.sys
2016-09-14 16:22:50 1896168 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2016-09-14 16:22:49 84480 ----a-w- C:\Windows\SysWow64\INETRES.dll
2016-09-14 16:22:49 84480 ----a-w- C:\Windows\System32\INETRES.dll
2016-09-14 16:22:49 741888 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2016-09-14 16:22:49 46080 ----a-w- C:\Windows\System32\drivers\tcpipreg.sys
2016-09-14 16:22:49 287976 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2016-09-14 16:22:45 877056 ----a-w- C:\Windows\System32\oleaut32.dll
2016-09-14 16:22:45 581632 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2016-09-14 09:05:49 1167568 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{76CD7CBD-FF52-445B-9060-11ABCE92442F}\gapaengine.dll
2016-09-04 10:34:07 -------- d-----w- C:\Users\Steve\AppData\Local\Apple Computer
2016-09-04 10:32:08 -------- d-----w- C:\Users\Steve\AppData\Local\Apple
2016-09-04 10:31:49 -------- d-----w- C:\Program Files\Bonjour
2016-09-04 10:31:49 -------- d-----w- C:\Program Files (x86)\Bonjour
2016-08-28 12:22:27 -------- d-----w- C:\Users\Steve\AppData\Local\ESET
2016-08-25 13:58:37 -------- d-----w- C:\ProgramData\Virtualized Applications
2016-08-23 09:20:45 -------- d-----w- C:\FRST
2016-08-22 16:52:49 -------- d-----w- C:\Users\Steve\AppData\Roaming\MediaInfo
2016-08-22 16:52:28 -------- d-----w- C:\Program Files\MediaInfo
2016-08-20 22:46:54 -------- d-----w- C:\Users\Steve\AppData\Local\CEF
.
==================== Find3M ====================
.
2016-09-19 16:42:21 192216 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2016-09-02 15:40:18 631176 ----a-w- C:\Windows\System32\winresume.efi
2016-09-02 15:35:48 706280 ----a-w- C:\Windows\System32\winload.efi
2016-09-02 15:35:47 95464 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2016-09-02 15:35:47 5548264 ----a-w- C:\Windows\System32\ntoskrnl.exe
2016-09-02 15:35:47 154856 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2016-09-02 15:34:22 1732864 ----a-w- C:\Windows\System32\ntdll.dll
2016-09-02 15:31:03 362496 ----a-w- C:\Windows\System32\wow64win.dll
2016-09-02 15:31:03 243712 ----a-w- C:\Windows\System32\wow64.dll
2016-09-02 15:31:03 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2016-09-02 15:31:02 215552 ----a-w- C:\Windows\System32\winsrv.dll
2016-09-02 15:31:02 210432 ----a-w- C:\Windows\System32\wdigest.dll
2016-09-02 15:31:01 86528 ----a-w- C:\Windows\System32\TSpkg.dll
2016-09-02 15:31:00 503808 ----a-w- C:\Windows\System32\srcore.dll
2016-09-02 15:31:00 50176 ----a-w- C:\Windows\System32\srclient.dll
2016-09-02 15:31:00 28672 ----a-w- C:\Windows\System32\sspisrv.dll
2016-09-02 15:31:00 135680 ----a-w- C:\Windows\System32\sspicli.dll
2016-09-02 15:21:25 4000488 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2016-09-02 15:21:25 3944680 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2016-09-02 15:18:23 1314112 ----a-w- C:\Windows\SysWow64\ntdll.dll
2016-09-02 15:02:33 148480 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2016-09-02 15:02:29 62464 ----a-w- C:\Windows\System32\drivers\appid.sys
2016-09-02 15:02:29 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2016-09-02 15:01:47 64000 ----a-w- C:\Windows\System32\auditpol.exe
2016-09-02 14:58:46 338432 ----a-w- C:\Windows\System32\conhost.exe
2016-09-02 14:57:53 296960 ----a-w- C:\Windows\System32\rstrui.exe
2016-09-02 14:55:12 159744 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2016-09-02 14:54:40 291328 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2016-09-02 14:54:38 129536 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2016-09-02 14:53:56 30720 ----a-w- C:\Windows\System32\lsass.exe
2016-09-02 14:53:52 112640 ----a-w- C:\Windows\System32\smss.exe
2016-09-02 14:53:18 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2016-09-02 14:49:51 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2016-09-02 14:49:49 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2016-09-02 14:49:49 2048 ----a-w- C:\Windows\SysWow64\user.exe
2016-09-02 14:49:49 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2016-09-02 14:49:04 36352 ----a-w- C:\Windows\SysWow64\cryptbase.dll
2016-09-02 14:48:57 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2016-09-02 14:48:57 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2016-09-02 14:48:57 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2016-09-02 14:48:57 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2016-09-01 03:18:32 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2016-09-01 02:48:10 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2016-09-01 02:46:36 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2016-09-01 02:46:11 341504 ----a-w- C:\Windows\SysWow64\html.iec
2016-09-01 02:46:04 498688 ----a-w- C:\Windows\SysWow64\vbscript.dll
2016-09-01 02:44:20 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2016-09-01 02:24:16 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2016-09-01 02:23:43 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2016-09-01 01:59:47 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2016-09-01 01:29:35 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2016-09-01 01:29:30 2055680 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2016-09-01 01:24:36 4607488 ----a-w- C:\Windows\SysWow64\jscript9.dll
2016-09-01 00:43:05 2445824 ----a-w- C:\Windows\SysWow64\wininet.dll
2016-09-01 00:40:49 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2016-09-01 00:40:38 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2016-09-01 00:25:20 66560 ----a-w- C:\Windows\System32\iesetup.dll
2016-09-01 00:24:36 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2016-09-01 00:24:29 417792 ----a-w- C:\Windows\System32\html.iec
2016-09-01 00:24:09 576000 ----a-w- C:\Windows\System32\vbscript.dll
2016-09-01 00:24:02 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2016-09-01 00:11:19 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
2016-09-01 00:11:18 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2016-09-01 00:10:55 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2016-09-01 00:06:08 6047232 ----a-w- C:\Windows\System32\jscript9.dll
2016-09-01 00:03:41 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2016-08-31 23:27:32 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2016-08-31 23:26:53 2131456 ----a-w- C:\Windows\System32\inetcpl.cpl
2016-08-31 23:10:42 2921472 ----a-w- C:\Windows\System32\wininet.dll
2016-08-19 23:38:04 38536 ----a-w- C:\Windows\System32\drivers\pmxdrv.sys
2016-08-16 17:36:50 1009152 ----a-w- C:\Windows\System32\user32.dll
2016-08-16 02:48:15 833024 ----a-w- C:\Windows\SysWow64\user32.dll
2016-08-16 02:35:57 3218432 ----a-w- C:\Windows\System32\win32k.sys
2016-08-12 16:26:18 464896 ----a-w- C:\Windows\System32\drivers\srv.sys
2016-08-12 16:26:12 405504 ----a-w- C:\Windows\System32\drivers\srv2.sys
2016-08-12 16:26:05 168960 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2016-08-04 18:07:45 97856 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2016-08-03 19:15:55 68608 ----a-w- C:\Windows\System32\taskhost.exe
2016-08-03 19:13:26 1887232 ----a-w- C:\Windows\System32\d3d11.dll
2016-08-03 19:13:26 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2016-07-27 22:03:56 462296 ----a-w- C:\Windows\System32\drivers\vsdatant.sys
2016-07-27 19:25:34 504488 ------w- C:\Windows\System32\MpSigStub.exe
2016-07-08 15:32:47 2048 ----a-w- C:\Windows\System32\tzres.dll
2016-07-08 15:16:59 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2016-06-26 00:35:09 41704 ----a-w- C:\Windows\System32\CompatTelRunner.exe
2016-06-26 00:27:39 756736 ----a-w- C:\Windows\System32\win32spl.dll
2016-06-26 00:27:32 344576 ----a-w- C:\Windows\System32\ntprint.dll
2016-06-26 00:27:26 970240 ----a-w- C:\Windows\System32\localspl.dll
2016-06-26 00:27:25 22528 ----a-w- C:\Windows\System32\inetppui.dll
2016-06-26 00:27:25 166400 ----a-w- C:\Windows\System32\inetpp.dll
2016-06-26 00:27:07 1208320 ----a-w- C:\Windows\System32\aeinv.dll
2016-06-25 19:54:03 497152 ----a-w- C:\Windows\SysWow64\win32spl.dll
2016-06-25 19:53:56 297472 ----a-w- C:\Windows\SysWow64\ntprint.dll
2016-06-25 19:53:05 48640 ----a-w- C:\Windows\System32\wpnpinst.exe
2016-06-25 19:53:04 61952 ----a-w- C:\Windows\System32\ntprint.exe
2016-06-25 19:41:53 61952 ----a-w- C:\Windows\SysWow64\ntprint.exe
2016-06-22 13:06:29 268800 ----a-w- C:\Windows\System32\centel.dll
.
============= FINISH: 19:15:23.77 ===============