Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all articles
Browse latest Browse all 2798

Not working correctly Windows Firewall

$
0
0
My issue is as follows a few weeks ago,maybe even months,i noticed that my firewall would turn on without me knowing and ask to let the program through.the reason i didnt have firewall turned on at the time was because the firewall would turn the a few minute process into a few hours.Some time later firewall would start asking to let through programs like steam,origin,games from steam and origin.This programs i have used before so i knew right away there was something wrong.A few weeks later firewall stopped blocking programs even when he did ask for permission.I noticed that it stopped because before when i got the prompt the program would not have full internet access and would be slower.Now i am asking for a fix since it is NOT working correcly only a few days ago it started blocking again,2 days later it stopped,and now it is not.
i have made a thread where the person helping me simply told me to go here.This issue has been quite annoying.
P.S. i do not have access to the windows or boot cd.
link to the thread:
hxxp://www.techsupportforum.com/forums/f112/windows-firewall-not-working-correctly-1161473.html#post7240897

the log will be attached below because i wasnt sure if i should place the dds one here or attach.the attach.txt will also be attached below in case you need it.

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.18500 BrowserJavaVersion: 11.91.2
Run by violeta at 16:52:43 on 2016-10-13
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.2013.1231 [GMT 2:00]
.
AV: Trend Micro Titanium Internet Security *Disabled/Outdated* {68F968AC-2AA0-091D-848C-803E83E35902}
SP: Trend Micro Titanium Internet Security *Disabled/Outdated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
C:\Program Files\Hi-Rez Studios\HiPatchService.exe
C:\Program Files\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe
C:\Windows\system32\PnkBstrA.exe
C:\Program Files\Razer\Razer Services\GSS\GameScannerService.exe
C:\Program Files\Razer\Razer Cortex\RzKLService.exe
C:\Program Files\ShadowExplorer\sesvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\TeamViewer\TeamViewer_Service.exe
C:\ProgramData\Telenor Internet\OnlineUpdate\ouc.exe
C:\Program Files\TunnelBear\TBear.Maintenance.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\Microsoft\BingBar\7.1.362.0\SeaPort.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\vssvc.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\System32\svchost.exe -k swprv
.
============== Pseudo HJT Report ===============
.
uDefault_Page_URL = about:blank
mStart Page = about:blank
mDefault_Page_URL = about:blank
uWindows: Load = c:\windows\system32\Microsoft.com
uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount
uRun: [{57E0064B-6CDF-4014-A8FF-F401291F5488}] c:\windows\system32\windowspowershell\v1.0\powershell.exe -noprofile -windowstyle hidden -executionpolicy bypass iex ([text.encoding]::ascii.getstring([convert]::frombase64string((gp 'hkcu:\software\classes\NYQUMMEV').KgJaKWdyhxnot)));
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [LogMeIn Hamachi Ui] "c:\program files\logmein hamachi\hamachi-2-ui.exe" --auto-start
mRun: [Lightshot] c:\program files\skillbrains\lightshot\Lightshot.exe
dRunOnce: [SPReview] "c:\windows\system32\spreview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
dRunOnce: [SpUninstallDeleteDir] rmdir /s /q "\SearchProtect"
StartupFolder: c:\users\violeta\appdata\roaming\microsoft\windows\start menu\programs\startup\Registration RAYMAN
mPolicies-Explorer: NoDriveTypeAutoRun = dword:221
mPolicies-Explorer: HideSCAHealth = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-Explorer: HideSCAHealth = dword:1
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: Interfaces\{5A19095F-7933-4DA1-AD09-19E979DC22C7} : NameServer = 217.65.192.101 217.65.192.102
TCP: Interfaces\{79289764-7478-4021-A6D0-8EAF6EFDDD53} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{79976A8E-F478-4642-88DD-27DD71B01DC2} : DHCPNameServer = 172.18.12.1
TCP: Interfaces\{9F6CCFF6-FC61-4F75-BD9A-39A7BE019C6E} : NameServer = 217.65.192.101 217.65.192.102
TCP: Interfaces\{C2E0376F-F85D-46E3-80E2-201AFBF0F518} : NameServer = 217.65.192.101 217.65.192.102
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - c:\program files\trend micro\amsp\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - c:\program files\trend micro\amsp\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
IFEO: AvastSvc.exe - c:\windows\system32\Microsoft.com
IFEO: AvastUI.exe - c:\windows\system32\Microsoft.com
IFEO: avcenter.exe - c:\windows\system32\Microsoft.com
IFEO: avconfig.exe - c:\windows\system32\Microsoft.com
IFEO: avgcsrvx.exe - c:\windows\system32\Microsoft.com
.
Note: multiple IFEO entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\violeta\appdata\roaming\mozilla\firefox\profiles\pgyttybc._\
FF - plugin: c:\program files\foxit software\foxit reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.31.5\npGoogleUpdate3.dll
FF - plugin: c:\program files\heroes & generals\live\npretox-1.0.6.1\npretoxlive-1.0.6.1.dll
FF - plugin: c:\program files\java\jre1.8.0_91\bin\dtplugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre1.8.0_91\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.50901.0\npctrlui.dll
FF - plugin: c:\program files\ubisoft\ubisoft game launcher\npuplaypc.dll
FF - plugin: c:\program files\ubisoft\ubisoft game launcher\npuplaypchub.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\happycloud\application\npHappyCloudPlugin.dll
FF - plugin: c:\programdata\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\users\violeta\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1213153.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_23_0_0_162.dll
.
============= SERVICES / DRIVERS ===============
.
P2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files\hi-rez studios\HiPatchService.exe [2016-9-18 9728]
R2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files\skype\toolbars\autoupdate\SkypeC2CAutoUpdateSvc.exe [2016-5-25 1364096]
R2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files\skype\toolbars\pnrsvc\SkypeC2CPNRSvc.exe [2016-5-25 1687680]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2016-9-13 1958408]
R2 IntelHaxm;Intel HAXM Service;c:\windows\system32\drivers\IntelHaxm.sys [2016-3-12 78848]
R2 IpOverUsbSvc;Windows Phone IP over USB Transport (IpOverUsbSvc);c:\program files\common files\microsoft shared\phone tools\corecon\11.0\bin\IpOverUsbSvc.exe [2014-4-17 22768]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein hamachi\LMIGuardianSvc.exe [2016-8-31 405424]
R2 Razer Game Scanner Service;Razer Game Scanner;c:\program files\razer\razer services\gss\GameScannerService.exe [2015-8-15 188072]
R2 RzKLService;RzKLService;c:\program files\razer\razer cortex\RzKLService.exe [2015-5-2 129168]
R2 rzpmgrk;rzpmgrk;c:\windows\system32\drivers\rzpmgrk.sys [2015-5-2 20288]
R2 sesvc;ShadowExplorer Service;c:\program files\shadowexplorer\sesvc.exe [2015-9-1 9216]
R2 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968]
R2 TeamViewer;TeamViewer 11;c:\program files\teamviewer\TeamViewer_Service.exe [2015-8-3 6889232]
R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2012-1-6 64080]
R2 TunnelBearMaintenance;TunnelBear Maintenance;c:\program files\tunnelbear\TBear.Maintenance.exe [2016-5-11 41472]
R3 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\7.1.362.0\SeaPort.EXE [2012-2-13 240408]
R3 EvolveVirtualAdapter;Evolve Virtual Miniport Driver;c:\windows\system32\drivers\evolve.sys [2013-6-12 18584]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [2011-12-19 73216]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\drivers\L1C62x86.sys [2009-6-10 50688]
R3 tap-tb-0901;TunnelBear Adapter V9;c:\windows\system32\drivers\tap-tb-0901.sys [2015-8-10 33280]
R3 XSplit_Dummy;XSplit Stream Audio Renderer;c:\windows\system32\drivers\xspltspk.sys [2014-7-2 22104]
R3 zttap200;ZeroTier One Virtual Network Port;c:\windows\system32\drivers\zttap200.sys [2014-11-20 28824]
S2 Amsp;Trend Micro Solution Platform;c:\program files\trend micro\amsp\coreServiceShell.exe [2012-1-6 188272]
S2 BBSvc;BingBar Service;c:\program files\microsoft\bingbar\7.1.362.0\BBSvc.EXE [2012-2-13 193816]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2015-11-5 105144]
S2 HWDeviceService.exe;HWDeviceService.exe;"c:\programdata\datacardservice\hwdeviceservice.exe" -/service --> c:\programdata\datacardservice\HWDeviceService.exe [?]
S2 Origin Web Helper Service;Origin Web Helper Service;c:\program files\origin\OriginWebHelperService.exe [2016-9-15 2209296]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\skype\toolbars\skype c2c service\c2c_service.exe [2012-5-30 3048136]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2016-5-23 324224]
S2 Telenor Internet. RunOuc;Telenor Internet. OUC;c:\program files\telenor internet\updatedog\ouc.exe [2011-12-19 246112]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 BroadcomWModem;Broadcom Corporation BroadcomWModem;c:\windows\system32\drivers\bcmww.sys [2005-6-2 118400]
S3 c2wts;Claims to Windows Token Service;c:\program files\windows identity foundation\v3.5\c2wtshost.exe [2014-10-8 15768]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2014-12-11 23456]
S3 EvoSvc;Evolve Service;c:\program files\echobit\evolve\EvoSvc.exe [2015-8-18 1583488]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [2011-12-19 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\drivers\ew_usbenumfilter.sys [2011-12-19 11136]
S3 ewusbmbb;HUAWEI USB-WWAN miniport;c:\windows\system32\drivers\ewusbwwan.sys [2011-12-19 353280]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2012-9-4 49088]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-7-28 1511872]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2016-10-12 102912]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-2-8 22856]
S3 mvusbews;USB EWS Device;c:\windows\system32\drivers\mvusbews.sys [2012-12-24 17408]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 Origin Client Service;Origin Client Service;c:\program files\origin\OriginClientService.exe [2016-9-15 2142728]
S3 OverwolfUpdater;Overwolf Updater Windows SCM;c:\program files\overwolf\OverwolfUpdater.exe [2016-8-29 1310448]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2015-8-24 14848]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 Te.Service;Te.Service;c:\program files\windows kits\8.1\testing\runtimes\taef\Wex.Services.exe [2013-8-21 91136]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2015-8-24 49152]
S3 VsEtwService120;Visual Studio ETW Event Collection Service;c:\program files\microsoft visual studio 12.0\common7\packages\debugger\services\VsEtwService.exe [2014-7-23 73360]
S3 VSStandardCollectorService140;Visual Studio Standard Collector Service;c:\program files\microsoft visual studio 14.0\team tools\diagnosticshub\collector\StandardCollector.Service.exe [2016-3-22 48872]
.
=============== File Associations ===============
.
FileExt: .js: Applications\notepad++.exe="c:\program files\notepad++\notepad++.exe" "%1" [UserChoice]
.
=============== Created Last 30 ================
.
2016-10-13 12:14:31 62576 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{1b03c628-ca8d-470f-8393-bca3279c2538}\offreg.3268.dll
2016-10-12 13:13:07 -------- d-----w- c:\program files\Skillbrains
2016-10-12 11:55:59 815304 ----a-w- c:\program files\internet explorer\iexplore.exe
2016-10-11 14:14:37 62576 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{1b03c628-ca8d-470f-8393-bca3279c2538}\offreg.3732.dll
2016-10-11 07:25:22 9837072 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{1b03c628-ca8d-470f-8393-bca3279c2538}\mpengine.dll
2016-10-06 15:17:22 -------- d-----w- c:\users\violeta\appdata\roaming\Duelyst
2016-09-21 06:47:47 2048 ----a-w- c:\windows\system32\tzres.dll
2016-09-19 18:35:27 -------- d-----w- c:\users\violeta\appdata\local\{26E83D09-9D35-755D-7492-57CF5473C38A}
2016-09-18 19:36:50 -------- d-----w- c:\users\violeta\appdata\local\HirezLauncherUI
2016-09-18 19:31:39 -------- d-----w- c:\program files\Hi-Rez Studios
2016-09-18 14:19:06 -------- d-----w- c:\users\violeta\appdata\roaming\.minecraft
2016-09-15 13:51:48 -------- d-----w- c:\users\violeta\.QtWebEngineProcess
2016-09-15 13:51:46 -------- d-----w- c:\users\violeta\.Origin
2016-09-14 04:52:22 -------- d-----w- c:\program files\LogMeIn Hamachi
.
==================== Find3M ====================
.
2016-09-30 15:20:30 4000488 ----a-w- c:\windows\system32\ntkrnlpa.exe
2016-09-30 15:20:30 3944680 ----a-w- c:\windows\system32\ntoskrnl.exe
2016-09-30 05:54:40 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2016-09-30 05:54:29 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2016-09-30 05:42:47 498688 ----a-w- c:\windows\system32\vbscript.dll
2016-09-30 05:42:45 62464 ----a-w- c:\windows\system32\iesetup.dll
2016-09-30 05:42:09 47616 ----a-w- c:\windows\system32\ieetwproxystub.dll
2016-09-30 05:42:01 341504 ----a-w- c:\windows\system32\html.iec
2016-09-30 05:41:14 64000 ----a-w- c:\windows\system32\MshtmlDac.dll
2016-09-30 05:32:43 102912 ----a-w- c:\windows\system32\ieetwcollector.exe
2016-09-30 05:32:38 115712 ----a-w- c:\windows\system32\ieUnatt.exe
2016-09-30 05:32:21 620032 ----a-w- c:\windows\system32\jscript9diag.dll
2016-09-30 05:27:34 667648 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2016-09-30 05:19:54 60416 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2016-09-30 05:12:59 4608512 ----a-w- c:\windows\system32\jscript9.dll
2016-09-30 05:05:17 2055680 ----a-w- c:\windows\system32\inetcpl.cpl
2016-09-30 05:05:00 1155072 ----a-w- c:\windows\system32\mshtmlmedia.dll
2016-09-30 04:46:52 2444288 ----a-w- c:\windows\system32\wininet.dll
2016-09-24 08:29:15 47920 ----a-w- c:\windows\system32\partizan.exe
2016-09-15 15:15:01 84480 ----a-w- c:\windows\system32\INETRES.dll
2016-09-15 15:15:01 741888 ----a-w- c:\windows\system32\inetcomm.dll
2016-09-14 07:30:06 796352 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2016-09-14 07:30:06 142528 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2016-09-13 16:53:44 27040 ---ha-w- c:\windows\system32\hamachi.sys
2016-09-12 20:54:23 67816 ----a-w- c:\windows\system32\CompatTelRunner.exe
2016-09-12 20:53:41 67304 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2016-09-12 20:53:41 137960 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2016-09-12 20:29:45 50176 ----a-w- c:\windows\system32\auditpol.exe
2016-09-12 20:28:41 2399232 ----a-w- c:\windows\system32\win32k.sys
2016-09-12 20:26:06 226304 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2016-09-12 20:26:04 98304 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2016-09-12 20:26:00 124416 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2016-09-12 20:25:30 36352 ----a-w- c:\windows\system32\cryptbase.dll
2016-09-12 20:25:29 22016 ----a-w- c:\windows\system32\lsass.exe
2016-09-12 20:25:29 15872 ----a-w- c:\windows\system32\sspisrv.dll
2016-09-12 19:08:46 909824 ----a-w- c:\windows\system32\FntCache.dll
2016-09-12 19:08:46 1251328 ----a-w- c:\windows\system32\DWrite.dll
2016-09-10 15:53:43 2291712 ----a-w- c:\windows\system32\MSVidCtl.dll
2016-09-09 18:01:23 1310528 ----a-w- c:\windows\system32\ntdll.dll
2016-09-09 18:00:00 43008 ----a-w- c:\windows\system32\srclient.dll
2016-09-09 18:00:00 400896 ----a-w- c:\windows\system32\srcore.dll
2016-09-09 17:59:58 50176 ----a-w- c:\windows\system32\setbcdlocale.dll
2016-09-09 17:59:47 38912 ----a-w- c:\windows\system32\csrsrv.dll
2016-09-09 17:59:46 6656 ----a-w- c:\windows\system32\apisetschema.dll
2016-09-09 17:59:46 644096 ----a-w- c:\windows\system32\advapi32.dll
2016-09-09 17:59:46 50688 ----a-w- c:\windows\system32\appidapi.dll
2016-09-09 17:42:07 97792 ----a-w- c:\windows\system32\appidpolicyconverter.exe
2016-09-09 17:42:05 50688 ----a-w- c:\windows\system32\drivers\appid.sys
2016-09-09 17:42:05 16896 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2016-09-09 17:42:04 29696 ----a-w- c:\windows\system32\appidsvc.dll
2016-09-09 17:39:47 262656 ----a-w- c:\windows\system32\rstrui.exe
2016-09-09 17:37:25 69632 ----a-w- c:\windows\system32\smss.exe
2016-09-09 15:53:28 488448 ----a-w- c:\windows\system32\devinv.dll
2016-09-09 15:53:28 478208 ----a-w- c:\windows\system32\generaltel.dll
2016-09-09 15:53:28 268800 ----a-w- c:\windows\system32\invagent.dll
2016-09-09 15:53:28 213504 ----a-w- c:\windows\system32\centel.dll
2016-09-09 15:53:27 184320 ----a-w- c:\windows\system32\aepic.dll
2016-09-09 15:53:27 1406976 ----a-w- c:\windows\system32\appraiser.dll
2016-09-09 15:53:27 107008 ----a-w- c:\windows\system32\acmigration.dll
2016-09-08 20:34:14 208896 ----a-w- c:\windows\system32\WebClnt.dll
2016-09-08 20:34:01 87040 ----a-w- c:\windows\system32\davclnt.dll
2016-09-08 14:49:59 117248 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2016-09-08 14:49:56 81408 ----a-w- c:\windows\system32\drivers\dfsc.sys
2016-08-29 15:12:38 1499648 ----a-w- c:\windows\system32\ExplorerFrame.dll
2016-08-29 15:12:35 1806848 ----a-w- c:\windows\system32\authui.dll
2016-08-29 14:55:07 2972672 ----a-w- c:\windows\explorer.exe
2016-08-16 20:42:13 3072 ----a-w- c:\windows\system32\drivers\en-us\usbehci.sys.mui
2016-08-16 20:42:12 11776 ----a-w- c:\windows\system32\drivers\en-us\usbhub.sys.mui
2016-08-16 20:41:57 24576 ----a-w- c:\windows\system32\drivers\en-us\usbport.sys.mui
2016-08-16 20:27:20 259072 ----a-w- c:\windows\system32\drivers\usbhub.sys
2016-08-16 20:27:02 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2016-08-16 20:26:59 46592 ----a-w- c:\windows\system32\drivers\usbehci.sys
2016-08-16 20:26:59 285696 ----a-w- c:\windows\system32\drivers\usbport.sys
2016-08-16 20:26:58 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2016-08-16 20:26:56 24576 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2016-08-16 20:26:55 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2016-08-16 02:48:13 811520 ----a-w- c:\windows\system32\user32.dll
2016-08-12 16:47:20 12574208 ----a-w- c:\windows\system32\wmploc.DLL
2016-08-12 16:46:55 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2016-08-12 16:31:37 4096 ----a-w- c:\windows\system32\msdxm.ocx
2016-08-12 16:31:37 4096 ----a-w- c:\windows\system32\dxmasf.dll
2016-08-12 16:31:35 8192 ----a-w- c:\windows\system32\spwmp.dll
2016-08-12 16:21:28 437248 ----a-w- c:\windows\system32\scavengeui.dll
2016-08-12 16:21:11 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2016-08-12 16:21:05 313856 ----a-w- c:\windows\system32\drivers\srv2.sys
2016-08-12 16:21:01 116224 ----a-w- c:\windows\system32\drivers\srvnet.sys
2016-08-06 15:15:08 54272 ----a-w- c:\windows\system32\WsmRes.dll
2016-08-06 15:15:08 249344 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll
2016-08-06 15:15:08 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll
2016-08-06 15:15:08 146944 ----a-w- c:\windows\system32\WsmAuto.dll
2016-08-06 15:15:08 1178112 ----a-w- c:\windows\system32\WsmSvc.dll
2016-08-06 15:15:01 581632 ----a-w- c:\windows\system32\oleaut32.dll
2016-08-06 14:53:18 12288 ----a-w- c:\windows\system32\wsmprovhost.exe
2016-08-06 14:53:17 199168 ----a-w- c:\windows\system32\WSManHTTPConfig.exe
2016-08-06 14:53:16 10240 ----a-w- c:\windows\system32\wsmplpxy.dll
2016-08-04 06:50:40 282624 --sha-w- c:\users\violeta\spopoi.exe
2016-07-26 12:24:26 406184 ------w- c:\windows\system32\MpSigStub.exe
2016-07-22 14:51:37 123904 ----a-w- c:\windows\system32\poqexec.exe
2016-03-13 13:32:02 3120771 ----a-w- c:\program files\common files\4gzl5t3d.exe
2016-03-12 10:24:11 3170418 ----a-w- c:\program files\common files\kqhpkjmf.exe
2010-11-05 01:58:03 32768 --sha-r- c:\windows\system32\Microsoft.com
.
============= FINISH: 17:02:57.87 ===============

Attached Files
File Type: txt attach.txt (30.7 KB)
File Type: txt dds.txt (22.7 KB)

Viewing all articles
Browse latest Browse all 2798

Trending Articles