[RESOLVED] exploit.drop.gs on dell inspiron
i have win 7 inspiron with three baddies. so far
mwbytes quarantined exploit.drop.gs. then
MSE removed java/anogre.E, and java/obfuscator.W
is there anything left?
i guess we better do the drill...
3 logs below...
thanks nancy
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 10/1/2014
Scan Time: 9:22:16 AM
Logfile:
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.10.01.05
Rootkit Database: v2014.09.19.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Gary
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 442577
Time Elapsed: 20 min, 58 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 1
Exploit.Drop.GS, C:\Users\Gary\AppData\Local\Temp\fvJcrgR.exe, Quarantined, [305964abf983a492a23c79e526dd0000],
Physical Sectors: 0
(No malicious items detected)
(end)
.
==== Installed Programs ======================
.
ABBYY FineReader 6.0 Sprint
Adobe AIR
Adobe Flash Player 15 ActiveX
Adobe Flash Player 15 Plugin
Adobe Reader XI (11.0.09)
Advanced Audio FX Engine
AnswerWorks 5.0 English Runtime
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Bonjour
CCleaner
Classic Shell
Compatibility Pack for the 2007 Office system
Cozi
D3DX10
Dell Dock
Dell Getting Started Guide
Dell Toolbar
Dell Touchpad
Dell V715w
Dell Webcam Central
ESET Online Scanner v3
Google Earth
Google Update Helper
Google+ Auto Backup
GoToAssist 8.0.0.514
GoToAssist Customer 2.2.0.758
Image Scan Tool
Intel(R) Control Center
Intel(R) Graphics Media Accelerator Driver
Intel(R) Rapid Storage Technology
iTunes
Java 7 Update 9
Java Auto Updater
Java(TM) 6 Update 37
Junk Mail filter update
Live! Cam Avatar Creator
Malwarebytes Anti-Malware version 2.0.2.1012
Microsoft .NET Framework 4.5.1
Microsoft Application Error Reporting
Microsoft IntelliPoint 8.1
Microsoft Office 2010
Microsoft Office Click-to-Run 2010
Microsoft Office Excel Viewer
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Starter 2010 - English
Microsoft Office Word Viewer 2003
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Movie Maker
Mozilla Firefox 32.0.3 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
MSVCRT110
MSVCRT110_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB2721691)
MSXML 4.0 SP3 Parser (KB2758694)
My Dell
Photo Common
Photo Gallery
Picasa 3
Quicken 2011
Quickset64
QuickTime
Realtek High Definition Audio Driver
Roxio Burn
Secunia PSI (2.0.0.4003)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4.5.1 (KB2894854v2)
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Security Update for Microsoft .NET Framework 4.5.1 (KB2931368)
Security Update for Microsoft .NET Framework 4.5.1 (KB2972216)
Shared C Run-time for x64
Skype Toolbars
Skype™ 6.18
SoftPerfect WiFi Guard version 1.0.2
SpywareBlaster 5.0
STOPzilla
SUPERAntiSpyware
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== End Of File ===========================
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.17088 BrowserJavaVersion: 10.9.2
Run by Gary at 15:15:26 on 2014-10-01
.
============== Running Processes ================
.
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Citrix\GoToAssist Remote Support Customer\758\g2ax_service.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files (x86)\Citrix\GoToAssist Remote Support Customer\758\g2ax_comm_customer.exe
C:\Program Files (x86)\Citrix\GoToAssist Remote Support Customer\758\g2ax_system_customer.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\Citrix\GoToAssist Remote Support Customer\758\g2ax_user_customer.exe
C:\Program Files (x86)\Dell V715w\dleemon.exe
C:\Program Files (x86)\Dell V715w\ezprint.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://midco.net/
uSearch Bar = Preserve
BHO: Dell Toolbar: {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Printable Web\toolband.dll
BHO: ExplorerBHO Class: {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: Classic Explorer Bar: {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
TB: Dell Toolbar: {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Printable Web\toolband.dll
uRun: [WiFi Guard] "C:\Program Files\SoftPerfect WiFi Guard\WiFiGuard.exe" /hide
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Dell V715w] "C:\Program Files (x86)\Dell V715w\fm3032.exe" /s
mRunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {64964764-1101-4bbd-8891-B56B1A53B9B3} - {553891B7-A0D5-4526-BE18-D3CE461D6310}
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
TCP: NameServer = 192.168.0.1 205.171.3.25
TCP: Interfaces\{74FE9CF5-AB5B-49A2-8C5F-0784B0576C26} : DHCPNameServer = 192.168.0.1 205.171.3.25
TCP: Interfaces\{E05FD617-412B-4848-A8BB-30116DCD33C1} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{E05FD617-412B-4848-A8BB-30116DCD33C1}\24561636866627F6E6470294E6E6 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{E05FD617-412B-4848-A8BB-30116DCD33C1}\34F657E647279794E6E613 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{E05FD617-412B-4848-A8BB-30116DCD33C1}\34F657E647279794E6E633 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{E05FD617-412B-4848-A8BB-30116DCD33C1}\36865636B607F696E6474616539363667316 : DHCPNameServer = 192.168.10.1
TCP: Interfaces\{E05FD617-412B-4848-A8BB-30116DCD33C1}\37E6F6F6079713937303 : DHCPNameServer = 192.168.10.1
TCP: Interfaces\{E05FD617-412B-4848-A8BB-30116DCD33C1}\E616E63697 : DHCPNameServer = 192.168.0.1 205.171.2.25
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - C:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
x64-BHO: ExplorerBHO Class: {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll
x64-BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - <orphaned>
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} -
x64-TB: Classic Explorer Bar: {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
x64-Run: [Classic Start Menu] C:\Program Files\Classic Shell\ClassicStartMenu.exe
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
x64-Run: [dleemon.exe] "C:\Program Files (x86)\Dell V715w\dleemon.exe"
x64-Run: [EzPrint] "C:\Program Files (x86)\Dell V715w\ezprint.exe"
x64-IE: {64964764-1101-4bbd-8891-B56B1A53B9B3} - {553891B7-A0D5-4526-BE18-D3CE461D6310}
x64-Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - <orphaned>
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: GoToAssist - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll
x64-Notify: GoToAssist Express Customer - C:\Program Files (x86)\Citrix\GoToAssist Remote Support Customer\758\g2ax_winlogonx64.dll
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\a1jjrayo.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://www.thefreedictionary.com/
FF - prefs.js: network.proxy.type - 0
FF - component: C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\a1jjrayo.default\extensions\{7E7165E2-0767-448c-852F-5FA8714F2C37}\components\PlainOldFavorites.dll
FF - plugin: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? dleeCATSCustConnectService;dleeCATSCustConnectService
R? OV550I;35mm Film Scanner
R? PSI;PSI
R? RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader
R? Secunia PSI Agent;Secunia PSI Agent
R? SkypeUpdate;Skype Updater
R? TsUsbFlt;TsUsbFlt
R? WatAdminSvc;Windows Activation Technologies Service
R? yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller
S? !SASCORE;SAS Core Service
S? AERTFilters;Andrea RT Filters Service
S? clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64
S? CtClsFlt;Creative Camera Class Upper Filter Driver
S? cvhsvc;Client Virtualization Handler
S? dlee_device;dlee_device
S? DockLoginService;Dock Login Service
S? GoToAssist Remote Support Customer;GoToAssist Remote Support Customer
S? IAStorDataMgrSvc;Intel(R) Rapid Storage Technology
S? L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller
S? MBAMProtector;MBAMProtector
S? MBAMScheduler;MBAMScheduler
S? MBAMService;MBAMService
S? MBAMSwissArmy;MBAMSwissArmy
S? MBAMWebAccessControl;MBAMWebAccessControl
S? MpFilter;Microsoft Malware Protection Driver
S? NisDrv;Microsoft Network Inspection System
S? NisSrv;Microsoft Network Inspection
S? PxHlpa64;PxHlpa64
S? SASDIFSV;SASDIFSV
S? SASKUTIL;SASKUTIL
S? sbapifs;sbapifs
S? SBRE;SBRE
S? Sftfs;Sftfs
S? sftlist;Application Virtualization Client
S? Sftplay;Sftplay
S? Sftredir;Sftredir
S? Sftvol;Sftvol
S? sftvsa;Application Virtualization Service Agent
.
=============== Created Last 30 ================
.
2014-10-01 18:46:30 2777088 ----a-w- C:\Windows\System32\msmpeg2vdec.dll
2014-10-01 18:46:30 2285056 ----a-w- C:\Windows\SysWow64\msmpeg2vdec.dll
2014-10-01 18:41:11 99480 ----a-w- C:\Windows\SysWow64\infocardapi.dll
2014-10-01 18:41:11 171160 ----a-w- C:\Windows\System32\infocardapi.dll
2014-10-01 18:41:11 1389208 ----a-w- C:\Windows\System32\icardagt.exe
2014-10-01 18:41:10 619672 ----a-w- C:\Windows\SysWow64\icardagt.exe
2014-10-01 18:41:07 8856 ----a-w- C:\Windows\SysWow64\icardres.dll
2014-10-01 18:41:07 8856 ----a-w- C:\Windows\System32\icardres.dll
2014-10-01 18:40:34 35480 ----a-w- C:\Windows\SysWow64\TsWpfWrp.exe
2014-10-01 18:40:34 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe
2014-10-01 18:37:03 340992 ----a-w- C:\Windows\System32\schannel.dll
2014-10-01 18:37:03 247808 ----a-w- C:\Windows\SysWow64\schannel.dll
2014-10-01 18:37:02 314880 ----a-w- C:\Windows\System32\msv1_0.dll
2014-10-01 18:37:02 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2014-10-01 18:37:02 259584 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2014-10-01 18:37:02 210944 ----a-w- C:\Windows\System32\wdigest.dll
2014-10-01 18:37:01 86528 ----a-w- C:\Windows\System32\TSpkg.dll
2014-10-01 18:37:01 65536 ----a-w- C:\Windows\SysWow64\TSpkg.dll
2014-10-01 18:37:01 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2014-10-01 18:37:01 22016 ----a-w- C:\Windows\System32\credssp.dll
2014-10-01 18:37:01 17408 ----a-w- C:\Windows\SysWow64\credssp.dll
2014-10-01 18:37:01 172032 ----a-w- C:\Windows\SysWow64\wdigest.dll
2014-10-01 18:35:41 2002432 ----a-w- C:\Windows\System32\msxml6.dll
2014-10-01 18:34:59 692736 ----a-w- C:\Windows\System32\osk.exe
2014-10-01 18:34:59 544768 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\TipRes.dll
2014-10-01 18:34:59 110592 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\TipBand.dll
2014-10-01 18:34:59 10240 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\TabTip32.exe
2014-10-01 18:34:58 288192 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2014-10-01 18:34:58 1903552 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2014-10-01 18:34:36 624128 ----a-w- C:\Windows\System32\qedit.dll
2014-10-01 18:34:36 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2014-10-01 14:21:09 1188440 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5C692C7E-064E-4212-BD51-1A3AB0E62245}\gapaengine.dll
2014-10-01 14:20:46 11578928 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5EC9B2B3-D721-4F43-A6B7-84B3404D773D}\mpengine.dll
2014-09-30 22:37:19 11578928 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-09-24 23:13:10 166984 ----a-w- C:\Windows\System32\g2ax_credential_provider64_758.dll
.
==================== Find3M ====================
.
2014-10-01 19:27:15 122584 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-09-25 02:08:38 371712 ----a-w- C:\Windows\System32\qdvd.dll
2014-09-25 01:40:50 519680 ----a-w- C:\Windows\SysWow64\qdvd.dll
2014-09-24 09:53:42 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-09-24 09:53:42 701104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-09-22 06:42:39 278152 ------w- C:\Windows\System32\MpSigStub.exe
2014-09-09 22:11:04 2048 ----a-w- C:\Windows\System32\tzres.dll
2014-09-09 21:47:10 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2014-09-05 02:10:43 578048 ----a-w- C:\Windows\System32\aepdu.dll
2014-09-05 02:05:42 424448 ----a-w- C:\Windows\System32\aeinv.dll
2014-08-25 13:13:14 0 ----a-w- C:\Windows\SysWow64\sho3816.tmp
2014-08-23 02:07:00 404480 ----a-w- C:\Windows\System32\gdi32.dll
2014-08-23 01:45:55 311808 ----a-w- C:\Windows\SysWow64\gdi32.dll
2014-08-23 00:59:01 3163648 ----a-w- C:\Windows\System32\win32k.sys
2014-08-22 15:50:48 0 ----a-w- C:\Windows\SysWow64\sho55C4.tmp
2014-08-17 04:00:04 2239488 ----a-w- C:\Windows\System32\wininet.dll
2014-08-17 03:58:51 3959296 ----a-w- C:\Windows\System32\jscript9.dll
2014-08-17 03:58:48 67072 ----a-w- C:\Windows\System32\iesetup.dll
2014-08-17 03:58:48 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2014-08-17 03:58:18 1508864 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-08-17 03:57:51 1766400 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-08-17 03:57:32 2861568 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-08-17 03:57:30 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-08-17 03:57:30 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2014-08-17 03:57:18 1440768 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-08-16 07:25:09 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2014-08-16 06:43:24 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-08-16 06:34:34 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2014-08-16 05:53:37 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2014-08-01 11:53:22 1031168 ----a-w- C:\Windows\System32\TSWorkspace.dll
2014-08-01 11:35:06 793600 ----a-w- C:\Windows\SysWow64\TSWorkspace.dll
2014-07-25 07:35:46 875688 ----a-w- C:\Windows\SysWow64\msvcr120_clr0400.dll
2014-07-25 04:47:06 869544 ----a-w- C:\Windows\System32\msvcr120_clr0400.dll
2014-07-17 23:05:06 269008 ----a-w- C:\Windows\System32\drivers\MpFilter.sys
2014-07-17 23:05:06 125584 ----a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2014-07-14 02:02:45 1216000 ----a-w- C:\Windows\System32\rpcrt4.dll
2014-07-14 01:40:58 664064 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2014-07-07 02:06:35 728064 ----a-w- C:\Windows\System32\kerberos.dll
2014-07-07 02:06:35 1460736 ----a-w- C:\Windows\System32\lsasrv.dll
2014-07-07 01:40:21 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2014-07-07 01:40:12 550912 ----a-w- C:\Windows\SysWow64\kerberos.dll
2014-07-07 01:39:16 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
.
============= FINISH: 15:17:07.86 ===============