Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all articles
Browse latest Browse all 2798

help! mixidj on browsers and messing with OS

$
0
0
I just reformated my hard drive. I updated windows 7, then downloaded MS Security Essentials, Malwarebytes, FF, Spywareblaster, and while downloading peerblock things started to go weird. I got a popup to install realplayer, which I hadn't downloaded and a weird toolbar appeared on my browsers - mixidj - that I saw no where in my downloads, no checks for any toolbars, etc. I'm very careful when downloading things to read everything and uncheck things that are checked automatically that I don't want (which is almost always everything - I don't even want desktop icons).

Now windows is very slow to respond. My browsers are acting weird and not responding well. this ugly malware toolbar is taking up space I don't want taken up on my browser, and don't want this malware.

MS Security Essentials keeps popping up warnings and I've quarantined two things:



I downloaded peerblock from CNET - is that no longer a safe place to download from?

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16521
Run by 93 at 6:42:43 on 2013-04-03
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8151.6281 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Users\93\AppData\Roaming\SearchProtect\bin\cltmng.exe
C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\servicing\TrustedInstaller.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com/?ctid=CT3287822&octid=CT3287822&SearchSource=61&CUI=UN16619964442442727&UM=2&UP=SP8E154D70-DEDA-4F97-ACF5-4CEBB885468A
uURLSearchHooks: MixiDJ V8 Toolbar: {e4c3a8b6-7724-45d1-a629-17b69118ebcd} - C:\Program Files (x86)\MixiDJ_V8\prxtbMixi.dll
mURLSearchHooks: MixiDJ V8 Toolbar: {e4c3a8b6-7724-45d1-a629-17b69118ebcd} - C:\Program Files (x86)\MixiDJ_V8\prxtbMixi.dll
mWinlogon: Userinit = userinit.exe
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: GetSavin 5.0: {BB8F49D7-B79C-4559-9561-FFA800DBF046} - C:\Users\93\AppData\Local\getsavin\ie\getsavin_1364995801.dll
BHO: MixiDJ V8 Toolbar: {e4c3a8b6-7724-45d1-a629-17b69118ebcd} - C:\Program Files (x86)\MixiDJ_V8\prxtbMixi.dll
TB: MixiDJ V8 Toolbar: {E4C3A8B6-7724-45D1-A629-17B69118EBCD} - C:\Program Files (x86)\MixiDJ_V8\prxtbMixi.dll
TB: MixiDJ V8 Toolbar: {e4c3a8b6-7724-45d1-a629-17b69118ebcd} - C:\Program Files (x86)\MixiDJ_V8\prxtbMixi.dll
uRun: [SearchProtect] C:\Users\93\AppData\Roaming\SearchProtect\bin\cltmng.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
mRun: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe
dRunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\IMAGEB~1.LNK - C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.0.1 205.171.3.25
TCP: Interfaces\{EDC76E06-AB1A-4B09-8319-6AFAF2CD384F} : DHCPNameServer = 192.168.0.1 205.171.3.25
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
SSODL: WebCheck - <orphaned>
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3287822&CUI=UN29271921011434028&UM=2&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - MixiDJ V8 Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3287822&octid=CT3287822&SearchSource=61&CUI=UN29271921011434028&UM=2&UP=SP8E154D70-DEDA-4F97-ACF5-4CEBB885468A
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3287822&SearchSource=2&CUI=UN29271921011434028&UM=2&q=
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\{e4c3a8b6-7724-45d1-a629-17b69118ebcd}\plugins\np-mswmp.dll
FF - plugin: C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\{e4c3a8b6-7724-45d1-a629-17b69118ebcd}\plugins\npConduitFirefoxPlugin.dll
FF - ExtSQL: 2013-04-03 06:05; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-04-03 06:16; {fe0258ab-4f74-43a1-8781-bcdf340f9ee9}; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\{fe0258ab-4f74-43a1-8781-bcdf340f9ee9}.xpi
FF - ExtSQL: 2013-04-03 06:16; {ea9be299-129b-4c3c-8876-d98c18c2fd39}; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\{ea9be299-129b-4c3c-8876-d98c18c2fd39}
FF - ExtSQL: 2013-04-03 06:16; {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
FF - ExtSQL: 2013-04-03 06:16; {cf47767d-5f3a-4e32-9fce-5d79565c9702}; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\{cf47767d-5f3a-4e32-9fce-5d79565c9702}.xpi
FF - ExtSQL: 2013-04-03 06:16; {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - ExtSQL: 2013-04-03 06:16; {73a6fe31-595d-460b-a920-fcc0f8843232}; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF - ExtSQL: 2013-04-03 06:16; {4BBDD651-70CF-4821-84F8-2B918CF89CA3}; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
FF - ExtSQL: 2013-04-03 06:16; {45d8ff86-d909-11db-9705-005056c00008}; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\{45d8ff86-d909-11db-9705-005056c00008}.xpi
FF - ExtSQL: 2013-04-03 06:16; {1018e4d6-728f-4b20-ad56-37578a4de76b}; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
FF - ExtSQL: 2013-04-03 06:16; translator@zoli.bod; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\translator@zoli.bod.xpi
FF - ExtSQL: 2013-04-03 06:16; rikaichan-jpnames@polarcloud.com; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\rikaichan-jpnames@polarcloud.com
FF - ExtSQL: 2013-04-03 06:16; rikaichan-jpen@polarcloud.com; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\rikaichan-jpen@polarcloud.com
FF - ExtSQL: 2013-04-03 06:16; peraperakun@gmail.com; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\peraperakun@gmail.com
FF - ExtSQL: 2013-04-03 06:16; fr-dicollecte@dictionaries.addons.mozilla.org; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\fr-dicollecte@dictionaries.addons.mozilla.org
FF - ExtSQL: 2013-04-03 06:16; firefox@ghostery.com; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\firefox@ghostery.com
FF - ExtSQL: 2013-04-03 06:16; en-GB@dictionaries.addons.mozilla.org; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\en-GB@dictionaries.addons.mozilla.org
FF - ExtSQL: 2013-04-03 06:30; infoatoms@infoatoms.com; C:\Program Files (x86)\Mozilla Firefox\extensions\infoatoms@infoatoms.com
FF - ExtSQL: 2013-04-03 06:31; {e4c3a8b6-7724-45d1-a629-17b69118ebcd}; C:\Users\93\AppData\Roaming\Mozilla\Firefox\Profiles\fqzd54f9.default\extensions\{e4c3a8b6-7724-45d1-a629-17b69118ebcd}
FF - ExtSQL: !HIDDEN! 2013-04-03 06:30; infoatoms@infoatoms.com; C:\Program Files (x86)\Mozilla Firefox\extensions\infoatoms@infoatoms.com
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-1-20 230320]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2013-4-2 203264]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
R2 CltMngSvc;Search Protect by Conduit Updater;C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe [2013-3-6 93984]
R2 HsfXAudioService;HsfXAudioService;C:\Windows\System32\svchost.exe -k HsfXAudioService [2009-7-13 27136]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-1-20 130008]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-4-2 2320920]
R3 CAXHWBS2;CAXHWBS2;C:\Windows\System32\drivers\CAXHWBS2.sys [2013-4-2 411136]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;C:\Windows\System32\drivers\HCW85BDA.sys [2013-4-2 1707776]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2013-4-2 56344]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2009-10-16 321064]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-1-27 379360]
S2 SetupARService;SetupARService;C:\Program Files (x86)\Realtek\Audio\SetupAfterRebootService.exe [2013-4-2 24576]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-4-3 59392]
S3 VST64_DPV;VST64_DPV;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 VST64HWBS2;VST64HWBS2;C:\Windows\System32\drivers\VSTBS26.SYS [2009-7-13 411136]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-4-2 1255736]
.
=============== Created Last 30 ================
.
2013-04-03 13:32:53 -------- d-----w- C:\Program Files (x86)\Conduit
2013-04-03 13:32:49 -------- d-----w- C:\Users\93\AppData\Local\Conduit
2013-04-03 13:32:49 -------- d-----w- C:\Program Files (x86)\MixiDJ_V8
2013-04-03 13:31:45 770384 ----a-w- C:\Windows\SysWow64\msvcr100.dll
2013-04-03 13:31:45 421200 ----a-w- C:\Windows\SysWow64\msvcp100.dll
2013-04-03 13:31:45 -------- d-----w- C:\Program Files (x86)\SearchProtect
2013-04-03 13:31:21 -------- d-----w- C:\Program Files\PeerBlock
2013-04-03 13:31:19 -------- d-----w- C:\Users\93\AppData\Roaming\SearchProtect
2013-04-03 13:30:21 -------- d-----w- C:\Program Files (x86)\InfoAtoms
2013-04-03 13:30:20 -------- d-----w- C:\Users\93\AppData\Local\getsavin
2013-04-03 13:27:54 -------- d-----w- C:\ProgramData\Licenses
2013-04-03 13:27:51 129872 ----a-w- C:\Windows\SysWow64\MSSTDFMT.DLL
2013-04-03 13:27:49 -------- d-----w- C:\Program Files (x86)\SpywareBlaster
2013-04-03 13:16:11 -------- d-----w- C:\Users\93\AppData\Roaming\Malwarebytes
2013-04-03 13:15:54 -------- d-----w- C:\ProgramData\Malwarebytes
2013-04-03 13:15:53 24176 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-04-03 13:15:53 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-04-03 13:15:40 -------- d-----w- C:\Users\93\AppData\Local\Programs
2013-04-03 13:10:18 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-04-03 13:03:04 -------- d-----w- C:\Users\93\AppData\Local\Mozilla
2013-04-03 12:15:00 569344 ----a-w- C:\Windows\System32\iphlpsvc.dll
2013-04-03 12:15:00 303104 ----a-w- C:\Windows\System32\nlasvc.dll
2013-04-03 12:15:00 246272 ----a-w- C:\Windows\System32\netcorehc.dll
2013-04-03 12:15:00 216576 ----a-w- C:\Windows\System32\ncsi.dll
2013-04-03 12:15:00 156672 ----a-w- C:\Windows\SysWow64\ncsi.dll
2013-04-03 12:11:32 68608 ----a-w- C:\Windows\System32\taskhost.exe
2013-04-03 12:07:38 9311288 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{732110E0-0E0C-48A5-85AF-729CDF8DC9E1}\mpengine.dll
2013-04-03 12:00:53 9728 ----a-w- C:\Windows\System32\Wdfres.dll
2013-04-03 12:00:53 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys
2013-04-03 12:00:53 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys
2013-04-03 12:00:53 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2013-04-03 11:59:32 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2013-04-03 11:59:32 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2013-04-03 11:59:31 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2013-04-03 11:59:31 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2013-04-03 11:59:29 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2013-04-03 11:59:29 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2013-04-03 11:59:29 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2013-04-03 11:40:01 -------- d-----w- C:\Windows\System32\SPReview
2013-04-03 11:39:49 -------- d-----w- C:\Windows\System32\EventProviders
2013-04-03 11:37:59 988160 ----a-w- C:\Windows\SysWow64\propsys.dll
2013-04-03 11:36:59 762368 ----a-w- C:\Windows\System32\sdcpl.dll
2013-04-03 11:35:58 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2013-04-03 04:11:03 -------- d-----w- C:\Users\93\AppData\Local\Microsoft Games
2013-04-03 03:54:07 972264 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E850FC95-3B24-4095-B5A5-8E41CE560E52}\gapaengine.dll
2013-04-03 03:54:04 9311288 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-04-03 03:49:56 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2013-04-03 03:41:16 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2013-04-03 03:41:11 -------- d-----w- C:\Program Files\Microsoft Security Client
2013-04-03 03:31:33 -------- d-----w- C:\Windows\SysWow64\Wat
2013-04-03 03:31:33 -------- d-----w- C:\Windows\System32\Wat
2013-04-03 03:31:11 19968 ----a-w- C:\Windows\System32\drivers\usb8023.sys
2013-04-03 03:22:10 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2013-04-03 03:22:10 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2013-04-03 03:22:09 850944 ----a-w- C:\Windows\SysWow64\sbe.dll
2013-04-03 03:22:09 259072 ----a-w- C:\Windows\System32\mpg2splt.ax
2013-04-03 03:22:09 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2013-04-03 03:22:09 1118720 ----a-w- C:\Windows\System32\sbe.dll
2013-04-03 03:12:19 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2013-04-03 03:12:19 46080 ----a-w- C:\Windows\System32\atmlib.dll
2013-04-03 03:12:19 367616 ----a-w- C:\Windows\System32\atmfd.dll
2013-04-03 03:12:19 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2013-04-03 03:12:19 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2013-04-03 03:12:19 100864 ----a-w- C:\Windows\System32\fontsub.dll
2013-04-03 03:11:47 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-04-03 03:11:47 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2013-04-03 03:11:47 5120 ----a-w- C:\Windows\System32\wmi.dll
2013-04-03 03:11:47 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-04-03 03:11:47 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-04-03 03:09:55 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2013-04-03 03:00:29 376688 ----a-w- C:\Windows\System32\drivers\netio.sys
2013-04-03 02:53:44 65024 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2013-04-03 02:53:44 32768 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2013-04-03 02:53:44 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2013-04-03 02:53:44 204800 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2013-04-03 02:53:43 757760 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2013-04-03 02:53:43 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2013-04-03 02:53:43 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2013-04-03 02:53:42 331908 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2013-04-03 02:53:42 200836 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2013-04-03 02:38:58 -------- d-----w- C:\Windows\Panther
2013-04-03 02:38:34 -------- d-----w- C:\Windows\System32\oem
2013-04-03 02:37:42 -------- d-----w- C:\Users\93\AppData\Roaming\Canon_Inc_IC
2013-04-03 02:36:39 -------- d-----w- C:\Program Files (x86)\Canon
2013-04-03 02:36:36 -------- d-----w- C:\Program Files (x86)\Common Files\Canon_Inc_IC
2013-04-03 02:34:58 -------- d-----w- C:\ProgramData\Canon_Inc_IC
2013-04-03 02:34:06 -------- d-----w- C:\Program Files (x86)\Realtek
2013-04-03 02:28:21 -------- d-----w- C:\Windows\PCHEALTH
2013-04-03 02:27:38 9311288 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DD48E814-C77A-48C1-AE8F-47AD339B7B5B}\mpengine.dll
2013-04-03 02:27:37 282744 ------w- C:\Windows\System32\MpSigStub.exe
2013-04-03 02:26:34 -------- d-----w- C:\Program Files (x86)\Microsoft Analysis Services
2013-04-03 02:26:20 -------- d-----w- C:\Users\93\AppData\Local\Microsoft Help
2013-04-03 02:06:07 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2013-04-03 02:06:02 99840 ----a-w- C:\Windows\System32\wudriver.dll
2013-04-03 02:05:51 36864 ----a-w- C:\Windows\System32\wuapp.exe
2013-04-03 02:05:51 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2013-04-03 02:02:30 -------- d-----w- C:\Users\93\AppData\Local\ATI
2013-04-03 02:02:08 0 ----a-w- C:\Windows\ativpsrm.bin
2013-04-03 02:00:00 53248 ----a-w- C:\Windows\SysWow64\CSVer.dll
2013-04-03 01:59:19 -------- d-----w- C:\Program Files (x86)\Common Files\postureAgent
2013-04-03 01:59:06 56344 ----a-w- C:\Windows\System32\drivers\HECIx64.sys
2013-04-03 01:58:41 -------- d-----w- C:\Program Files\Realtek
2013-04-03 01:58:35 72192 ----a-w- C:\Windows\System32\MBWrp64.dll
2013-04-03 01:58:35 601088 ----a-w- C:\Windows\System32\MBAPO64.dll
2013-04-03 01:58:35 369664 ----a-w- C:\Windows\System32\MBTHX64.dll
2013-04-03 01:58:35 1632800 ----a-w- C:\Windows\System32\RtkAPO64.dll
2013-04-03 01:58:33 1284712 ----a-w- C:\Windows\RtlExUpd.dll
2013-04-03 01:58:33 -------- d--h--w- C:\Program Files (x86)\Temp
2013-04-03 01:56:44 99328 ----a-w- C:\Windows\System32\hcwcp.ax
2013-04-03 01:56:44 32768 ----a-w- C:\Windows\System32\drivers\HCW85cir.sys
2013-04-03 01:56:44 1707776 ----a-w- C:\Windows\System32\drivers\HCW85BDA.sys
2013-04-03 01:56:44 147456 ----a-w- C:\Windows\System32\hcwecppp.ax
2013-04-03 01:56:44 139776 ----a-w- C:\Windows\System32\hcw85enc.ax
2013-04-03 01:56:44 110592 ----a-w- C:\Windows\System32\hcw85prop.ax
2013-04-03 01:56:23 -------- d-----w- C:\Windows\System32\Hauppauge
2013-04-03 01:56:03 40960 ----a-w- C:\Windows\SysWow64\SSubTmr6.dll
2013-04-03 01:56:03 212240 ----a-w- C:\Windows\SysWow64\RICHTX32.OCX
2013-04-03 01:55:52 36921 ----a-w- C:\Windows\SysWow64\hcwutl32.dll
2013-04-03 01:55:52 -------- d-----w- C:\Program Files (x86)\HCW85
2013-04-03 01:54:29 -------- d-----w- C:\Intel
2013-04-03 01:53:07 -------- d-----w- C:\Program Files\Common Files\ATI Technologies
2013-04-03 01:52:51 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2013-04-03 01:52:23 -------- d-----w- C:\Program Files\ATI Technologies
2013-04-03 01:52:21 -------- d-----w- C:\Program Files\ATI
2013-04-03 01:50:25 -------- d-----w- C:\Program Files\CONEXANT
2013-04-03 01:50:23 740864 ----a-w- C:\Windows\System32\drivers\CAX_CNXT.sys
2013-04-03 01:50:23 1485824 ----a-w- C:\Windows\System32\drivers\CAX_DPV.sys
2013-04-03 01:50:18 94208 ----a-w- C:\Windows\SysWow64\mdmxsdk.dll
2013-04-03 01:50:18 436736 ----a-w- C:\Windows\SysWow64\XAudio64.dll
2013-04-03 01:50:18 411136 ----a-w- C:\Windows\System32\drivers\CAXHWBS2.sys
2013-04-03 01:50:18 394240 ----a-w- C:\Windows\System32\UCI64M40.dll
2013-04-03 01:50:18 17024 ----a-w- C:\Windows\System32\drivers\mdmxsdk.sys
2013-04-03 01:50:18 10240 ----a-w- C:\Windows\System32\drivers\XAudio64.sys
2013-04-03 01:49:13 -------- d-----w- C:\Program Files\Broadcom
2013-04-03 01:48:52 -------- d-----w- C:\Windows\Dell
2013-04-03 01:48:36 -------- d-sh--w- C:\Windows\Installer
2013-04-03 01:48:31 -------- d-----w- C:\Users\93\AppData\Local\Downloaded Installations
2013-04-03 01:47:41 1478144 ----a-w- C:\Windows\System32\drivers\athrx.sys
2013-04-03 01:47:41 1478144 ----a-w- C:\Windows\System32\athrx.sys
2013-04-03 01:47:41 -------- d-----w- C:\Program Files (x86)\DW
2013-04-03 01:47:01 -------- d-----w- C:\dell
.
==================== Find3M ====================
.
2013-04-03 13:10:18 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-04-03 11:43:30 175616 ----a-w- C:\Windows\System32\msclmd.dll
2013-04-03 11:43:30 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2013-02-12 05:45:24 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45:22 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45:22 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45:22 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48:31 474112 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-02-12 04:48:26 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
2013-01-20 22:59:04 230320 ----a-w- C:\Windows\System32\drivers\MpFilter.sys
2013-01-20 22:59:04 130008 ----a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2013-01-05 05:53:43 5553512 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-01-05 05:00:15 3967848 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-01-05 05:00:11 3913064 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-01-04 05:46:09 215040 ----a-w- C:\Windows\System32\winsrv.dll
2013-01-04 04:51:16 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2013-01-04 04:43:21 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2013-01-04 03:26:48 3153408 ----a-w- C:\Windows\System32\win32k.sys
2013-01-04 02:47:35 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2013-01-04 02:47:34 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2013-01-04 02:47:34 2048 ----a-w- C:\Windows\SysWow64\user.exe
2013-01-04 02:47:33 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
.
============= FINISH: 6:44:32.42 ===============

Attached Thumbnails
Click image for larger version

Name:	mixidj toolbar.png
Views:	N/A
Size:	133.1 KB
ID:	123858  
Attached Files
File Type: zip ark.zip (745 Bytes)
File Type: zip attach.zip (2.7 KB)

Viewing all articles
Browse latest Browse all 2798

Trending Articles