ComboFix 15-02-16.01 - Ronald 03/14/2015 20:56:39.3.2 - x64 NETWORK Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3836.2592 [GMT -5:00] Running from: c:\users\Ronald\Desktop\ComboFix.exe Command switches used :: c:\users\Ronald\Desktop\CFScript.txt AV: Kaspersky Internet Security *Enabled/Updated* {179979E8-273D-D14E-0543-2861940E4886} FW: Kaspersky Internet Security *Enabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} SP: Kaspersky Internet Security *Enabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . FILE :: "c:\windows\system32\drivers\2A32425D.sys" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\GUM4A96.tmp c:\program files (x86)\GUM4A96.tmp\GoogleCrashHandler.exe c:\program files (x86)\GUM4A96.tmp\GoogleUpdate.exe c:\program files (x86)\GUM4A96.tmp\GoogleUpdateBroker.exe c:\program files (x86)\GUM4A96.tmp\GoogleUpdateComRegisterShell64.exe c:\program files (x86)\GUM4A96.tmp\GoogleUpdateHelper.msi c:\program files (x86)\GUM4A96.tmp\GoogleUpdateOnDemand.exe c:\program files (x86)\GUM4A96.tmp\GoogleUpdateWebPlugin.exe c:\program files (x86)\GUM4A96.tmp\goopdate.dll c:\program files (x86)\GUM4A96.tmp\npGoogleUpdate3.dll c:\program files (x86)\GUM4A96.tmp\psmachine.dll c:\program files (x86)\GUM4A96.tmp\psmachine_64.dll c:\users\Ronald\AppData\Local\EmieBrowserModeList c:\users\Ronald\AppData\Local\EmieBrowserModeList\container.dat c:\windows\system32\drivers\2A32425D.sys . . ((((((((((((((((((((((((( Files Created from 2015-02-15 to 2015-03-15 ))))))))))))))))))))))))))))))) . . 2015-03-15 02:02 . 2015-03-15 02:02 -------- d-----w- c:\users\Tommie\AppData\Local\temp 2015-03-15 02:02 . 2015-03-15 02:02 -------- d-----w- c:\users\owner\AppData\Local\temp 2015-03-15 02:02 . 2015-03-15 02:02 -------- d-----w- c:\users\Default\AppData\Local\temp 2015-03-15 02:02 . 2015-03-15 02:02 -------- d-----w- c:\users\Administrator\AppData\Local\temp 2015-03-15 02:00 . 2015-03-15 02:00 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6BC559D1-62CE-4ED7-9D48-5861ADC4F64B}\offreg.dll 2015-02-23 03:52 . 2015-02-23 05:06 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2015-02-19 11:30 . 2015-02-23 02:37 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2 2015-02-19 11:20 . 2015-02-22 22:15 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2015-02-19 10:59 . 2015-02-19 11:17 -------- d-----w- C:\OETemp 2015-02-19 10:53 . 2015-02-19 10:53 -------- d-----w- c:\users\Ronald\AppData\Roaming\QuickScan 2015-02-19 10:06 . 2015-02-19 10:25 -------- d-----w- c:\programdata\HitmanPro 2015-02-19 08:59 . 2015-01-29 09:07 11910896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6BC559D1-62CE-4ED7-9D48-5861ADC4F64B}\mpengine.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-01-31 03:03 . 2015-01-31 03:03 74703 ----a-w- c:\windows\SysWow64\mfc45.dat 2015-01-30 02:20 . 2010-10-31 18:17 113365784 ----a-w- c:\windows\system32\MRT.exe 2015-01-08 15:55 . 2010-10-31 18:19 298120 ----a-w- c:\windows\system32\MpSigStub.exe 2014-12-19 03:06 . 2015-01-30 02:18 210432 ----a-w- c:\windows\system32\profsvc.dll 2014-12-19 01:46 . 2015-01-30 02:17 141312 ----a-w- c:\windows\system32\drivers\mrxdav.sys . . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ---- Directory of %user%\library ---- . . ---- Directory of c:\program files\Common Files ---- . 2015-02-01 16:06 . 2015-02-01 16:17 25318 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Motorola_Driver_Installer_Log.txt 2014-12-20 15:53 . 2014-11-22 02:08 1016832 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll 2014-12-02 21:42 . 2014-12-02 21:42 231784 ----a-r- c:\program files\Common Files\Western Digital\WD Update\WDUpdate.dll 2014-12-02 21:41 . 2014-12-02 21:41 146800 ----a-r- c:\program files\Common Files\Western Digital\WDVSS\WDShadow.5.2.dll 2014-12-02 21:41 . 2014-12-02 21:41 546160 ----a-r- c:\program files\Common Files\Western Digital\WDVSS\WDLockedFiles.exe 2014-10-16 08:07 . 2014-10-16 08:07 5085936 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE14\Csi.dll 2014-08-26 23:30 . 2014-08-26 23:30 10548 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motoandroid2.cat 2014-08-20 23:50 . 2014-08-20 23:50 3894 ---ha-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\SDI_Installation.ini 2014-08-18 23:43 . 2014-08-18 23:43 5567 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motoandroid2.inf 2014-07-13 12:03 . 2014-06-03 10:02 1354240 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2014-07-13 12:01 . 2014-06-18 02:19 1247232 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tipskins.dll 2014-07-13 12:01 . 2014-06-18 02:19 449024 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tabskb.dll 2014-07-13 12:01 . 2014-06-18 02:18 224768 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TabTip.exe 2014-07-13 12:01 . 2014-06-18 02:19 503296 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tiptsf.dll 2014-07-13 12:01 . 2014-06-18 02:19 110592 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TipBand.dll 2014-07-13 12:01 . 2014-06-18 02:17 544768 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TipRes.dll 2014-04-01 10:12 . 2014-04-01 10:12 2127040 ----a-w- c:\program files\Common Files\Microsoft Shared\Filters\VISFILT.DLL 2013-09-05 06:17 . 2013-09-05 06:17 4300456 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2013-09-04 00:09 . 2013-09-04 00:09 44966 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\Momdm.inf 2013-09-04 00:09 . 2013-09-04 00:09 1709 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\Moser.inf 2013-09-04 00:09 . 2013-09-04 00:09 2815 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motusbser.inf 2013-09-04 00:09 . 2013-09-04 00:09 17468 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motport.inf 2013-09-04 00:09 . 2013-09-04 00:09 6659 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motusbdevice.inf 2013-09-04 00:08 . 2013-09-04 00:08 31514 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motoandroid.inf 2013-09-04 00:08 . 2013-09-04 00:08 121551 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motodrv.inf 2013-09-04 00:08 . 2013-09-04 00:08 33485 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motousbnet.inf 2013-09-04 00:08 . 2013-09-04 00:08 24854 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motccgp.inf 2013-09-04 00:08 . 2013-09-04 00:08 69786 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motmodem.inf 2013-08-30 18:21 . 2013-08-30 18:21 24489 ---ha-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\trayicon.ico 2013-07-23 20:25 . 2013-07-23 20:25 519048 ---ha-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\difxapi.dll 2013-07-23 20:25 . 2013-07-23 20:25 481768 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Motorola Driver Installer.exe 2013-07-23 20:25 . 2013-07-23 20:25 8366 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Motorola License Agreement.rtf 2013-07-23 20:25 . 2013-07-23 20:25 93727 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motccgp.cat 2013-07-23 20:25 . 2013-07-23 20:25 23552 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motccgp.sys 2013-07-23 20:25 . 2013-07-23 20:25 6144 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motfilt.sys 2013-07-23 20:25 . 2013-07-23 20:25 93298 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motmodem.cat 2013-07-23 20:25 . 2013-07-23 20:25 31744 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motmodem.sys 2013-07-23 20:25 . 2013-07-23 20:25 43978 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motoandroid.cat 2013-07-23 20:25 . 2013-07-23 20:25 32768 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motoandroid.sys 2013-07-23 20:25 . 2013-07-23 20:25 144351 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motodrv.cat 2013-07-23 20:25 . 2013-07-23 20:25 53632 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motodrv.sys 2013-07-23 20:25 . 2013-07-23 20:25 94172 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motousbnet.cat 2013-07-23 20:25 . 2013-07-23 20:25 27648 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motousbnet.sys 2013-07-23 20:25 . 2013-07-23 20:25 93294 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motport.cat 2013-07-23 20:25 . 2013-07-23 20:25 31744 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motport.sys 2013-07-23 20:25 . 2013-07-23 20:25 8832 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motswch.sys 2013-07-23 20:25 . 2013-07-23 20:25 93314 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motusbdevice.cat 2013-07-23 20:25 . 2013-07-23 20:25 12288 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motusbdevice.sys 2013-07-23 20:25 . 2013-07-23 20:25 42980 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\motusbser.cat 2013-07-23 20:25 . 2013-07-23 20:25 15616 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\mot_ci.dll 2013-07-23 20:25 . 2013-07-23 20:25 8151 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\mousbser.cat 2013-07-23 20:25 . 2013-07-23 20:25 118016 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\Mousbser.sys 2013-07-23 20:25 . 2013-07-23 20:25 106496 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\usblan_ifconfig.exe 2013-07-23 20:25 . 2013-07-23 20:25 1721576 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\WdfCoInstaller01009.dll 2013-07-23 20:25 . 2013-07-23 20:25 1002728 ----a-w- c:\program files\Common Files\Motorola Shared\Mobile Drivers\Drivers\winusbcoinstaller2.dll 2013-06-26 02:28 . 2013-06-26 02:28 1332952 ----a-w- c:\program files\Common Files\Microsoft Shared\Filters\odffilt.dll 2013-06-26 02:28 . 2013-06-26 02:28 1509592 ----a-w- c:\program files\Common Files\Microsoft Shared\Filters\offfiltx.dll 2013-06-25 10:11 . 2013-06-25 10:11 1271512 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll 2013-03-09 14:52 . 2013-03-09 14:52 163968 ----a-w- c:\program files\Common Files\Microsoft Shared\VSTO\vstoee.dll 2013-03-09 14:52 . 2013-03-09 14:52 17048 ----a-w- c:\program files\Common Files\Microsoft Shared\VSTO\vstoee100.tlb 2013-03-09 14:52 . 2013-03-09 14:52 22656 ----a-w- c:\program files\Common Files\Microsoft Shared\VSTO\vstoee90.tlb 2013-03-09 14:52 . 2013-03-09 14:52 98448 ----a-w- c:\program files\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe 2013-03-09 14:52 . 2013-03-09 14:52 364168 ----a-w- c:\program files\Common Files\Microsoft Shared\VSTO\10.0\VSTOLoader.dll 2013-03-09 14:52 . 2013-03-09 14:52 48792 ----a-w- c:\program files\Common Files\Microsoft Shared\VSTO\10.0\VSTOMessageProvider.dll 2013-03-09 14:52 . 2013-03-09 14:52 10896 ----a-w- c:\program files\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOInstallerUI.dll 2013-03-09 14:52 . 2013-03-09 14:52 19080 ----a-w- c:\program files\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOLoaderUI.dll 2012-07-22 18:00 . 2012-06-06 06:05 1499136 ----a-w- c:\program files\Common Files\System\ado\msado15.dll 2012-07-22 18:00 . 2012-06-06 06:05 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll 2012-07-22 18:00 . 2012-06-06 06:05 258048 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll 2012-07-22 18:00 . 2012-06-06 06:05 495616 ----a-w- c:\program files\Common Files\System\ado\msadox.dll 2012-07-22 18:00 . 2012-06-06 06:05 61440 ----a-w- c:\program files\Common Files\System\ado\msador15.dll 2012-07-22 18:00 . 2012-06-06 04:37 40960 ----a-w- c:\program files\Common Files\System\ado\msador28.tlb 2012-07-22 18:00 . 2012-06-06 04:37 73728 ----a-w- c:\program files\Common Files\System\ado\msado26.tlb 2012-07-22 18:00 . 2012-06-06 04:37 73728 ----a-w- c:\program files\Common Files\System\ado\msado25.tlb 2012-07-22 18:00 . 2012-06-06 04:37 77824 ----a-w- c:\program files\Common Files\System\ado\msado27.tlb 2012-07-22 18:00 . 2012-06-06 04:37 73728 ----a-w- c:\program files\Common Files\System\ado\msado60.tlb 2012-07-22 18:00 . 2012-06-06 04:37 73728 ----a-w- c:\program files\Common Files\System\ado\msado28.tlb 2012-07-22 18:00 . 2012-06-06 04:37 57344 ----a-w- c:\program files\Common Files\System\ado\msado21.tlb 2012-07-22 18:00 . 2012-06-06 04:37 57344 ----a-w- c:\program files\Common Files\System\ado\msado20.tlb 2012-07-22 18:00 . 2012-06-06 04:37 20480 ----a-w- c:\program files\Common Files\System\ado\msadomd28.tlb 2012-05-24 18:28 . 2012-05-24 18:28 13159 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\Drivers\usbaapl64.cat 2012-05-24 18:28 . 2012-05-24 18:28 5493 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\Drivers\usbaapl64.inf 2012-05-24 18:28 . 2012-05-24 18:28 9615 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\NetDrivers\netaapl64.cat 2012-05-24 18:28 . 2012-05-24 18:28 4215 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\NetDrivers\netaapl64.inf 2012-04-25 17:11 . 2012-04-25 17:11 52736 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\Drivers\usbaapl64.sys 2012-04-25 17:11 . 2012-04-25 17:11 4547944 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\Drivers\usbaaplrc.dll 2012-04-25 14:44 . 2012-04-25 14:44 39728 ----a-w- c:\program files\Common Files\Microsoft Shared\Filters\msgfilt.dll 2012-03-26 19:50 . 2012-03-26 19:50 22528 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\NetDrivers\netaapl64.sys 2011-11-13 22:35 . 2011-10-01 05:45 886784 ----a-w- c:\program files\Common Files\System\wab32.dll 2011-08-11 01:49 . 2011-06-15 09:59 126976 ----a-w- c:\program files\Common Files\System\Ole DB\msdaosp.dll 2011-07-08 20:23 . 2010-11-20 13:27 749568 ----a-w- c:\program files\Common Files\System\msadc\msadce.dll 2011-07-08 20:23 . 2010-11-20 13:27 1101824 ----a-w- c:\program files\Common Files\System\Ole DB\oledb32.dll 2011-07-08 20:23 . 2010-11-20 13:24 378880 ----a-w- c:\program files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe 2011-07-08 20:22 . 2010-11-20 13:27 98304 ----a-w- c:\program files\Common Files\System\msadc\msadcs.dll 2011-07-08 20:22 . 2010-11-20 13:27 114688 ----a-w- c:\program files\Common Files\System\msadc\msadcf.dll 2011-07-08 20:22 . 2010-11-20 13:24 1547264 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\mip.exe 2011-07-08 20:22 . 2010-11-20 13:27 1212416 ----a-w- c:\program files\Common Files\System\Ole DB\sqloledb.dll 2011-07-08 20:22 . 2010-11-20 13:27 745472 ----a-w- c:\program files\Common Files\System\Ole DB\msdasql.dll 2011-07-08 20:21 . 2010-11-20 13:27 101376 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tpcps.dll 2011-07-08 20:21 . 2010-11-20 13:27 249856 ----a-w- c:\program files\Common Files\System\msadc\msdarem.dll 2011-07-08 20:21 . 2010-11-20 13:27 57344 ----a-w- c:\program files\Common Files\System\msadc\msdfmap.dll 2011-07-08 20:21 . 2010-11-20 12:48 4096 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fr-FR\tipresx.dll.mui 2011-07-08 20:21 . 2010-11-20 12:48 4096 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tr-TR\tipresx.dll.mui 2011-07-08 20:21 . 2010-11-20 12:47 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\zh-CN\tipresx.dll.mui 2011-04-19 09:09 . 2011-04-19 09:09 855376 ----a-w- c:\program files\Common Files\Microsoft Shared\VC\msdia90.dll 2011-02-18 21:45 . 2011-02-18 21:45 237344 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\OutlookChangeNotifierAddIn.dll 2010-11-26 10:31 . 2010-11-26 10:31 1784192 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE14\CsiSoap.dll 2010-09-21 19:54 . 2010-09-21 19:54 529280 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll 2010-09-21 19:51 . 2010-09-21 19:51 55704 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\msidcrl40.dll 2010-09-21 19:51 . 2010-09-21 19:51 1129880 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\wlidcli.dll 2010-09-21 19:49 . 2010-09-21 19:49 419712 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL 2010-09-21 19:49 . 2010-09-21 19:49 170880 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL 2010-09-21 19:49 . 2010-09-21 19:49 290176 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDPROV.DLL 2010-09-21 19:49 . 2010-09-21 19:49 2286976 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 2010-09-21 19:49 . 2010-09-21 19:49 222592 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE 2010-09-21 19:47 . 2010-09-21 19:47 1558016 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDRES.DLL 2010-06-24 16:33 . 2010-06-24 16:33 241984 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\SQMAPI.DLL 2010-06-24 16:22 . 2010-06-24 16:22 4657 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WLive48x48.png 2010-04-20 00:29 . 2010-04-20 00:29 1721576 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\NetDrivers\WdfCoInstaller01009.dll 2010-03-01 11:18 . 2010-03-01 11:18 56144 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXEV.DLL 2010-02-28 08:24 . 2010-02-28 08:24 121168 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE 2010-02-28 08:24 . 2010-02-28 08:24 56192 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL 2010-02-28 08:13 . 2010-02-28 08:13 716 ----a-w- c:\program files\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.config 2010-01-10 03:34 . 2010-01-10 03:34 148736 ----a-w- c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPC.DLL 2010-01-10 03:34 . 2010-01-10 03:34 1828608 ----a-w- c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPCEXT.DLL 2010-01-10 03:34 . 2010-01-10 03:34 11646 ----a-w- c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppobjs-spp-plugin-manifest-signed.xrm-ms 2010-01-10 03:34 . 2010-01-10 03:34 2173696 ----a-w- c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL 2010-01-10 03:34 . 2010-01-10 03:34 4925184 ----a-w- c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 2010-01-10 03:34 . 2010-01-10 03:34 146192 ----a-w- c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPWMI.DLL 2010-01-10 03:34 . 2010-01-10 03:34 47710 ----a-w- c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPWMI.MOF 2009-07-14 05:35 . 2009-07-14 02:24 93696 ----a-w- c:\program files\Common Files\System\en-US\wab32res.dll.mui 2009-07-14 05:35 . 2009-07-14 02:28 8704 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\micaut.dll.mui 2009-07-14 05:35 . 2009-07-14 02:24 3072 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\TipTsf.dll.mui 2009-07-14 05:35 . 2009-07-14 02:26 3072 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\tabskb.dll.mui 2009-07-14 05:35 . 2009-07-14 02:29 2560 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\rtscom.dll.mui 2009-07-14 05:35 . 2009-07-14 02:24 4608 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\InkObj.dll.mui 2009-07-14 05:35 . 2009-07-14 02:23 10240 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\mip.exe.mui 2009-07-14 05:35 . 2009-07-14 02:26 3072 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\TipBand.dll.mui 2009-07-14 05:35 . 2009-07-14 02:27 32768 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\TipRes.dll.mui 2009-07-14 05:35 . 2009-07-14 02:29 8704 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\FlickLearningWizard.exe.mui 2009-07-14 05:35 . 2009-07-14 02:29 9216 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\InkWatson.exe.mui 2009-07-14 05:35 . 2009-07-14 02:29 2560 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\mshwLatin.dll.mui 2009-07-14 05:35 . 2009-07-14 02:25 22528 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\IPSEventLogMsg.dll.mui 2009-07-14 05:35 . 2009-07-14 02:28 2560 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\IpsMigrationPlugin.dll.mui 2009-07-14 05:35 . 2009-07-14 02:24 43520 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\ShapeCollector.exe.mui 2009-07-14 05:35 . 2009-07-14 02:25 2560 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\InputPersonalization.exe.mui 2009-07-14 05:35 . 2009-07-14 02:27 26624 ----a-w- c:\program files\Common Files\Microsoft Shared\MSInfo\en-US\msinfo32.exe.mui 2009-07-14 05:35 . 2009-07-14 02:29 5632 ----a-w- c:\program files\Common Files\System\msadc\en-US\msdaremr.dll.mui 2009-07-14 05:35 . 2009-07-14 02:30 5632 ----a-w- c:\program files\Common Files\System\Ole DB\en-US\msdasqlr.dll.mui 2009-07-14 05:35 . 2009-07-14 02:29 44032 ----a-w- c:\program files\Common Files\System\Ole DB\en-US\sqloledb.rll.mui 2009-07-14 05:35 . 2009-07-14 02:25 13824 ----a-w- c:\program files\Common Files\System\msadc\en-US\msaddsr.dll.mui 2009-07-14 05:35 . 2009-07-14 02:30 7168 ----a-w- c:\program files\Common Files\System\msadc\en-US\msdaprsr.dll.mui 2009-07-14 05:35 . 2009-07-14 02:27 17920 ----a-w- c:\program files\Common Files\System\Ole DB\en-US\sqlxmlx.rll.mui 2009-07-14 05:35 . 2009-07-14 02:24 5632 ----a-w- c:\program files\Common Files\System\msadc\en-US\msadcor.dll.mui 2009-07-14 05:35 . 2009-07-14 02:24 47616 ----a-w- c:\program files\Common Files\System\Ole DB\en-US\oledb32r.dll.mui 2009-07-14 05:35 . 2009-07-14 02:26 2560 ----a-w- c:\program files\Common Files\SpeechEngines\Microsoft\TTS20\en-US\MSTTSLoc.dll.mui 2009-07-14 05:35 . 2009-07-14 02:24 9728 ----a-w- c:\program files\Common Files\System\msadc\en-US\msadcer.dll.mui 2009-07-14 05:35 . 2009-07-14 02:27 5120 ----a-w- c:\program files\Common Files\System\msadc\en-US\msadcfr.dll.mui 2009-07-14 05:35 . 2009-07-14 02:24 17408 ----a-w- c:\program files\Common Files\System\ado\en-US\msader15.dll.mui 2009-07-14 05:32 . 2009-07-14 05:32 645 --sha-w- c:\program files\Common Files\Microsoft Shared\Stationery\Desktop.ini 2009-07-14 01:17 . 2009-07-14 01:17 4096 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\et-EE\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\nb-NO\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ru-RU\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 4096 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\bg-BG\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\it-IT\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\sl-SI\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\th-TH\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\hu-HU\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ar-SA\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\sv-SE\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 4096 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\de-DE\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 4096 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\lv-LV\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\da-DK\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\cs-CZ\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ja-JP\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 4096 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\lt-LT\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\pt-BR\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\sk-SK\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 4096 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\hr-HR\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\nl-NL\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ko-KR\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 4096 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\pt-PT\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fi-FI\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 4096 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\pl-PL\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 4096 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\es-ES\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\sr-Latn-CS\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 4096 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\el-GR\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\he-IL\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\uk-UA\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\zh-TW\tipresx.dll.mui 2009-07-14 01:17 . 2009-07-14 01:17 3584 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ro-RO\tipresx.dll.mui 2009-07-14 00:34 . 2009-07-14 01:41 181248 ----a-w- c:\program files\Common Files\SpeechEngines\Microsoft\TTS20\MSTTSEngine.dll 2009-07-14 00:34 . 2009-07-14 01:41 373760 ----a-w- c:\program files\Common Files\SpeechEngines\Microsoft\TTS20\en-US\MSTTSFrontendENU.dll 2009-07-14 00:33 . 2009-07-14 01:41 9728 ----a-w- c:\program files\Common Files\SpeechEngines\Microsoft\TTS20\MSTTSLoc.dll 2009-07-14 00:33 . 2009-07-14 01:41 41472 ----a-w- c:\program files\Common Files\SpeechEngines\Microsoft\TTS20\MSTTSCommon.dll 2009-07-14 00:29 . 2009-07-14 01:41 364544 ----a-w- c:\program files\Common Files\System\Ole DB\sqlxmlx.dll 2009-07-14 00:28 . 2009-07-14 01:41 434176 ----a-w- c:\program files\Common Files\System\Ole DB\msdaps.dll 2009-07-14 00:28 . 2009-07-14 00:28 16384 ----a-w- c:\program files\Common Files\System\Ole DB\sqloledb.rll 2009-07-14 00:28 . 2009-07-14 00:28 8192 ----a-w- c:\program files\Common Files\System\Ole DB\sqlxmlx.rll 2009-07-14 00:28 . 2009-07-14 01:41 303104 ----a-w- c:\program files\Common Files\System\msadc\msadds.dll 2009-07-14 00:28 . 2009-07-14 01:41 389120 ----a-w- c:\program files\Common Files\System\msadc\msdaprst.dll 2009-07-14 00:28 . 2009-07-14 01:41 106496 ----a-w- c:\program files\Common Files\System\ado\msadrh15.dll 2009-07-14 00:28 . 2009-07-14 01:29 8192 ----a-w- c:\program files\Common Files\System\ado\msader15.dll 2009-07-14 00:28 . 2009-07-14 00:28 28672 ----a-w- c:\program files\Common Files\System\ado\msadox28.tlb 2009-07-14 00:28 . 2009-07-14 01:29 61440 ----a-w- c:\program files\Common Files\System\Ole DB\msdasqlr.dll 2009-07-14 00:28 . 2009-07-14 01:41 36864 ----a-w- c:\program files\Common Files\System\Ole DB\msxactps.dll 2009-07-14 00:28 . 2009-07-14 01:29 8192 ----a-w- c:\program files\Common Files\System\msadc\msdaprsr.dll 2009-07-14 00:28 . 2009-07-14 01:29 8192 ----a-w- c:\program files\Common Files\System\msadc\msdaremr.dll 2009-07-14 00:28 . 2009-07-14 01:29 8192 ----a-w- c:\program files\Common Files\System\msadc\msaddsr.dll 2009-07-14 00:28 . 2009-07-14 01:41 131072 ----a-w- c:\program files\Common Files\System\Ole DB\msdatl3.dll 2009-07-14 00:28 . 2009-07-14 01:29 8192 ----a-w- c:\program files\Common Files\System\msadc\msadcer.dll 2009-07-14 00:28 . 2009-07-14 01:29 8192 ----a-w- c:\program files\Common Files\System\msadc\msadcor.dll 2009-07-14 00:28 . 2009-07-14 01:29 8192 ----a-w- c:\program files\Common Files\System\msadc\msadcfr.dll 2009-07-14 00:28 . 2009-07-14 01:31 81920 ----a-w- c:\program files\Common Files\System\Ole DB\oledb32r.dll 2009-07-14 00:05 . 2009-06-10 20:44 15063 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Wrinkled_Paper.gif 2009-07-14 00:05 . 2009-06-10 20:44 3168 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\White_Chocolate.jpg 2009-07-14 00:05 . 2009-06-10 20:44 4638 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Tiki.gif 2009-07-14 00:05 . 2009-06-10 20:44 3650 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Tanspecks.jpg 2009-07-14 00:05 . 2009-06-10 20:44 1864 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Stucco.gif 2009-07-14 00:05 . 2009-06-10 20:44 1990 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Small_News.jpg 2009-07-14 00:05 . 2009-06-10 20:44 15776 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Sand_Paper.jpg 2009-07-14 00:05 . 2009-06-10 20:44 26720 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\To_Do_List.emf 2009-07-14 00:05 . 2009-06-10 20:44 81292 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Shorthand.emf 2009-07-14 00:05 . 2009-06-10 20:44 37316 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Seyes.emf 2009-07-14 00:05 . 2009-06-10 20:44 26036 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Music.emf 2009-07-14 00:05 . 2009-06-10 20:44 4192 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Month_Calendar.emf 2009-07-14 00:05 . 2009-06-10 20:44 152300 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Memo.emf 2009-07-14 00:05 . 2009-06-10 20:44 116724 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Graph.emf 2009-07-14 00:05 . 2009-06-10 20:44 10340 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Genko_2.emf 2009-07-14 00:05 . 2009-06-10 20:44 5524 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Genko_1.emf 2009-07-14 00:05 . 2009-06-10 20:44 3792 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Dotted_Lines.emf 2009-07-14 00:05 . 2009-06-10 20:44 2920 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\grid_(cm).wmf 2009-07-14 00:05 . 2009-06-10 20:44 7498 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\grid_(inch).wmf 2009-07-14 00:05 . 2009-06-10 20:44 14049 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Psychedelic.jpg 2009-07-14 00:05 . 2009-06-10 20:44 5115 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Pretty_Peacock.jpg 2009-07-14 00:05 . 2009-06-10 20:44 3981 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Pine_Lumber.jpg 2009-07-14 00:05 . 2009-06-10 20:44 2950 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Notebook.jpg 2009-07-14 00:05 . 2009-06-10 20:44 2209 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Monet.jpg 2009-07-14 00:05 . 2009-06-10 20:44 2319 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Connectivity.gif 2009-07-14 00:05 . 2009-06-10 20:44 4587 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Cave_Drawings.gif 2009-07-14 00:05 . 2009-06-10 20:44 2575 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Blue_Gradient.jpg 2009-07-14 00:03 . 2009-07-14 01:41 1071616 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\mshwLatin.dll 2009-07-14 00:03 . 2009-07-14 01:39 383488 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InputPersonalization.exe 2009-07-14 00:02 . 2009-07-14 01:39 193024 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ConvertInkStore.exe 2009-07-14 00:02 . 2009-07-14 01:41 2103296 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll 2009-07-14 00:02 . 2009-06-10 21:08 791686 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\Alphabet.xml 2009-07-14 00:02 . 2009-07-14 01:39 695296 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ShapeCollector.exe 2009-07-14 00:02 . 2009-07-14 01:41 1704448 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\micaut.dll 2009-07-14 00:02 . 2009-07-14 01:41 49664 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\mshwgst.dll 2009-07-14 00:02 . 2009-07-14 01:41 94720 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\IpsPlugin.dll 2009-07-14 00:02 . 2009-07-14 01:39 397312 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkWatson.exe 2009-07-14 00:02 . 2009-07-14 01:41 40960 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\IpsMigrationPlugin.dll 2009-07-14 00:02 . 2009-07-14 01:39 927744 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\FlickLearningWizard.exe 2009-07-14 00:02 . 2009-07-14 01:41 6331392 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\mraut.dll 2009-07-14 00:02 . 2009-07-14 01:28 2048 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\IPSEventLogMsg.dll 2009-07-14 00:02 . 2009-07-14 01:41 40448 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TabIpsps.dll 2009-07-14 00:01 . 2009-07-14 01:41 353280 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkDiv.dll 2009-07-14 00:01 . 2009-07-14 01:41 169984 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\rtscom.dll 2009-07-14 00:01 . 2009-07-14 01:33 12288 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tipresx.dll 2009-07-13 23:58 . 2009-07-14 01:33 1098752 ----a-w- c:\program files\Common Files\System\wab32res.dll 2009-07-13 23:57 . 2009-07-14 01:40 29184 ----a-w- c:\program files\Common Files\System\DirectDB.dll 2009-07-13 23:04 . 2009-07-14 01:51 507904 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\Microsoft.Ink.dll 2009-07-13 23:01 . 2009-06-10 20:47 7505 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Stars.jpg 2009-07-13 23:01 . 2009-07-13 23:01 232 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Soft Blue.htm 2009-07-13 23:01 . 2009-06-10 20:47 10569 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\SoftBlue.jpg 2009-07-13 23:01 . 2009-07-13 23:01 230 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Stars.htm 2009-07-13 23:01 . 2009-06-10 20:47 1920 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Roses.jpg 2009-07-13 23:01 . 2009-07-13 23:01 237 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Shades of Blue.htm 2009-07-13 23:01 . 2009-06-10 20:47 4734 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\ShadesOfBlue.jpg 2009-07-13 23:01 . 2009-06-10 20:47 5115 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Peacock.jpg 2009-07-13 23:01 . 2009-07-13 23:01 233 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Roses.htm 2009-07-13 23:01 . 2009-06-10 20:47 6381 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\OrangeCircles.jpg 2009-07-13 23:01 . 2009-07-13 23:01 232 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Peacock.htm 2009-07-13 23:01 . 2009-07-13 23:01 235 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Hand Prints.htm 2009-07-13 23:01 . 2009-06-10 20:47 4222 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\HandPrints.jpg 2009-07-13 23:01 . 2009-07-13 23:01 237 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Orange Circles.htm 2009-07-13 23:01 . 2009-06-10 20:47 6406 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\GreenBubbles.jpg 2009-07-13 23:01 . 2009-07-13 23:01 237 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Green Bubbles.htm 2009-07-13 23:01 . 2009-06-10 20:47 1074 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Bears.jpg 2009-07-13 23:01 . 2009-07-13 23:01 231 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Garden.htm 2009-07-13 23:01 . 2009-06-10 20:47 23871 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Garden.jpg 2009-07-13 23:01 . 2009-07-13 23:01 255 ----a-w- c:\program files\Common Files\Microsoft Shared\Stationery\Bears.htm 2009-07-13 22:31 . 2009-07-13 22:31 9804 ----a-w- c:\program files\Common Files\System\Ole DB\oledbjvs.inc 2009-07-13 22:31 . 2009-07-13 22:31 9975 ----a-w- c:\program files\Common Files\System\Ole DB\oledbvbs.inc 2009-07-13 22:31 . 2009-07-13 20:50 14610 ----a-w- c:\program files\Common Files\System\ado\adojavas.inc 2009-07-13 22:31 . 2009-07-13 20:50 14951 ----a-w- c:\program files\Common Files\System\ado\adovbs.inc 2009-07-13 22:31 . 2009-07-13 20:50 623 ----a-w- c:\program files\Common Files\System\msadc\adcvbs.inc 2009-07-13 22:31 . 2009-07-13 20:50 630 ----a-w- c:\program files\Common Files\System\msadc\adcjavas.inc 2009-07-13 20:49 . 2009-06-10 20:36 588 ----a-w- c:\program files\Common Files\System\msadc\handsafe.reg 2009-07-13 20:41 . 2009-07-13 20:41 4120784 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\hwrusash.dat 2009-07-13 20:41 . 2009-07-13 20:41 3195696 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\hwrusalm.dat 2009-07-13 20:41 . 2009-07-13 20:41 2227968 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\hwruksh.dat 2009-07-13 20:41 . 2009-07-13 20:41 3053984 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\hwruklm.dat 2009-07-13 20:40 . 2009-07-13 20:40 815680 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\hwrenclm.dat 2009-07-13 20:40 . 2009-07-13 20:40 1100368 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\hwrlatinlm.dat 2009-07-13 20:40 . 2009-07-13 20:40 747280 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\hwrenalm.dat 2009-07-13 20:40 . 2009-07-13 20:40 46624 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\hwrcommonlm.dat 2009-07-13 20:40 . 2009-06-10 21:08 2520 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipssve.xml 2009-07-13 20:40 . 2009-06-10 21:08 2596 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipssrl.xml 2009-07-13 20:40 . 2009-06-10 21:08 2542 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsrus.xml 2009-07-13 20:40 . 2009-06-10 21:08 2568 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipssrb.xml 2009-07-13 20:40 . 2009-06-10 21:08 2240 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsptg.xml 2009-07-13 20:40 . 2009-06-10 21:08 2644 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsrom.xml 2009-07-13 20:40 . 2009-06-10 21:08 2600 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsplk.xml 2009-07-13 20:40 . 2009-06-10 21:08 2246 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsptb.xml 2009-07-13 20:40 . 2009-06-10 21:08 2568 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipskor.xml 2009-07-13 20:40 . 2009-06-10 21:08 2626 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsnld.xml 2009-07-13 20:40 . 2009-06-10 21:08 2580 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsnor.xml 2009-07-13 20:40 . 2009-06-10 21:08 2522 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsjpn.xml 2009-07-13 20:40 . 2009-06-10 21:08 2652 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipshrv.xml 2009-07-13 20:40 . 2009-06-10 21:08 2526 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsita.xml 2009-07-13 20:40 . 2009-06-10 21:08 3024 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsesp.xml 2009-07-13 20:40 . 2009-06-10 21:08 2628 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsfra.xml 2009-07-13 20:40 . 2009-06-10 21:08 2658 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsfin.xml 2009-07-13 20:40 . 2009-06-10 21:08 2578 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsen.xml 2009-07-13 20:40 . 2009-06-10 21:08 2514 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsdan.xml 2009-07-13 20:40 . 2009-06-10 21:08 2616 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipsdeu.xml 2009-07-13 20:40 . 2009-06-10 21:08 2436 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipscht.xml 2009-07-13 20:40 . 2009-06-10 21:08 2556 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipscsy.xml 2009-07-13 20:40 . 2009-06-10 21:08 2462 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipschs.xml 2009-07-13 20:39 . 2009-06-10 20:47 194048 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\split.avi 2009-07-13 20:39 . 2009-06-10 20:47 222208 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\join.avi 2009-07-13 20:39 . 2009-06-10 20:47 224256 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\delete.avi 2009-07-13 20:39 . 2009-06-10 20:47 197120 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\correct.avi 2009-07-13 20:39 . 2009-06-10 20:47 62976 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\boxed-split.avi 2009-07-13 20:39 . 2009-06-10 20:47 33280 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\boxed-join.avi 2009-07-13 20:39 . 2009-06-10 20:47 31744 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\boxed-delete.avi 2009-07-13 20:39 . 2009-06-10 20:46 247 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\main\baseAltGr_rtl.xml 2009-07-13 20:39 . 2009-06-10 20:46 11067 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\main\zh-dayi.xml 2009-07-13 20:39 . 2009-06-10 20:46 10947 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\main\zh-phonetic.xml 2009-07-13 20:39 . 2009-06-10 20:46 749 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\symbols\ea-sym.xml 2009-07-13 20:39 . 2009-06-10 20:46 9803 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\main\zh-changjei.xml 2009-07-13 20:39 . 2009-06-10 20:46 749 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\symbols\ja-jp-sym.xml 2009-07-13 20:39 . 2009-06-10 20:46 15097 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\main\ko-kr.xml 2009-07-13 20:39 . 2009-06-10 20:46 16616 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\main\ja-jp.xml 2009-07-13 20:39 . 2009-06-10 20:46 617 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\main\base_rtl.xml 2009-07-13 20:39 . 2009-06-10 20:46 804 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\main\base_jpn.xml 2009-07-13 20:39 . 2009-06-10 20:46 488 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\main\base_kor.xml 2009-07-13 20:39 . 2009-06-10 20:46 738 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\main\base_heb.xml 2009-07-13 20:39 . 2009-06-10 20:46 392 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\keypad\kor-kor.xml 2009-07-13 20:39 . 2009-06-10 20:46 3166 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\main\base_ca.xml 2009-07-13 20:39 . 2009-06-10 20:46 1118 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\keypad\keypadbase.xml 2009-07-13 20:39 . 2009-06-10 20:46 3161 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\main\base_altgr.xml 2009-06-10 21:08 . 2009-06-10 21:08 1600388 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\FlickAnimation.avi 2009-06-10 21:08 . 2009-06-10 21:08 2592 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\ipscat.xml 2009-06-10 21:08 . 2009-06-10 21:08 27045 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\Content.xml 2009-06-10 20:47 . 2009-06-10 20:47 2702 ----a-w- c:\program files\Common Files\Services\verisign.bmp 2009-06-10 20:47 . 2009-06-10 20:47 89600 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\en-US\boxed-correct.avi 2009-06-10 20:46 . 2009-06-10 20:46 1166 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\web\webbase.xml 2009-06-10 20:46 . 2009-06-10 20:46 207 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\web.xml 2009-06-10 20:46 . 2009-06-10 20:46 2764 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\symbols\symbase.xml 2009-06-10 20:46 . 2009-06-10 20:46 591 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\symbols.xml 2009-06-10 20:46 . 2009-06-10 20:46 924 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\oskpred\oskpredbase.xml 2009-06-10 20:46 . 2009-06-10 20:46 215 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\oskpred.xml 2009-06-10 20:46 . 2009-06-10 20:46 1437 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\osknumpad\osknumpadbase.xml 2009-06-10 20:46 . 2009-06-10 20:46 219 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\osknumpad.xml 2009-06-10 20:46 . 2009-06-10 20:46 471 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\oskmenu\oskmenubase.xml 2009-06-10 20:46 . 2009-06-10 20:46 215 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\oskmenu.xml 2009-06-10 20:46 . 2009-06-10 20:46 1218 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\numbers\numbase.xml 2009-06-10 20:46 . 2009-06-10 20:46 209 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\numbers.xml 2009-06-10 20:46 . 2009-06-10 20:46 3150 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\main\base.xml 2009-06-10 20:46 . 2009-06-10 20:46 38485 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\main.xml 2009-06-10 20:46 . 2009-06-10 20:46 384 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\keypad\ea.xml 2009-06-10 20:46 . 2009-06-10 20:46 727 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\keypad.xml 2009-06-10 20:46 . 2009-06-10 20:46 1434 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\auxpad\auxbase.xml 2009-06-10 20:46 . 2009-06-10 20:46 212 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\fsdefinitions\auxpad.xml 2009-06-10 20:36 . 2009-06-10 20:36 518 ----a-w- c:\program files\Common Files\System\msadc\handler.reg 2007-02-23 08:40 . 2007-02-23 08:40 1451920 ----a-w- c:\program files\Common Files\Microsoft Shared\DW\DW20.EXE 2007-02-23 08:40 . 2007-02-23 08:40 1064872 ----a-w- c:\program files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2015-01-30 7780120] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-15 98304] "SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-02-23 352256] "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-04 423936] "KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-12-25 34160] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2011-02-11 1295736] "TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 2454840] "WD Quick View"="c:\program files (x86)\Western Digital\WD Quick View\WDDMStatus.exe" [2014-07-22 5562736] "Malwarebytes Anti-Exploit"="c:\program files (x86)\Malwarebytes Anti-Exploit\mbae.exe" [2014-12-10 2561848] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe "c:\programdata\Best Buy pc app\Best Buy pc app.application" [2010-6-24 9216] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService] @="Service" . R1 ESProtectionDriver;Malwarebytes Anti-Exploit;c:\program files (x86)\Malwarebytes Anti-Exploit\mbae64.sys;c:\program files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [x] R1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x] R1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x] R1 RawDisk3;RawDisk3;c:\windows\system32\drivers\rawdsk3.sys;c:\windows\SYSNATIVE\drivers\rawdsk3.sys [x] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [x] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [x] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 MbaeSvc;Malwarebytes Anti-Exploit Service;c:\program files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe;c:\program files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [x] R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x] R2 PDFsFilter;PDFsFilter;c:\windows\system32\DRIVERS\PDFsFilter.sys;c:\windows\SYSNATIVE\DRIVERS\PDFsFilter.sys [x] R2 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [x] R2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [x] R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe;c:\program files\TOSHIBA\TECO\TecoService.exe [x] R2 WDBackup;WD Backup;c:\program files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe;c:\program files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [x] R2 WDDriveService;WD Drive Manager;c:\program files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe;c:\program files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [x] R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS;c:\windows\SYSNATIVE\drivers\BVRPMPR5a64.SYS [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys;c:\windows\SYSNATIVE\DRIVERS\ivusb.sys [x] R3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x] R3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys;c:\windows\SYSNATIVE\DRIVERS\pgeffect.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys;c:\windows\SYSNATIVE\DRIVERS\rtl8192Ce.sys [x] R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x] R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 vpcuxd;USB Virtualization Stub Service;c:\windows\system32\DRIVERS\vpcuxd.sys;c:\windows\SYSNATIVE\DRIVERS\vpcuxd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x] R4 Garmin Core Update Service;Garmin Core Update Service;c:\program files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe;c:\program files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [x] R4 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [x] R4 klflt;klflt;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x] S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x] S2 ioloSystemService;iolo System Service;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe [x] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys;c:\windows\SYSNATIVE\DRIVERS\TVALZFL.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 RTWlanE;Realtek Wireless LAN 802.11n PCI-E Network Adapter;c:\windows\system32\DRIVERS\rtwlane.sys;c:\windows\SYSNATIVE\DRIVERS\rtwlane.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2015-02-22 22:18 1084744 ----a-w- c:\program files (x86)\Google\Chrome\Application\40.0.2214.115\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2015-02-23 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-22 20:25] . 2015-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-23 18:55] . 2015-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-23 18:55] . 2015-02-23 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 3b41acea-803c-4887-901a-aa2128d958c5.job - c:\program files\SUPERAntiSpyware\SASTask.exe [2013-11-07 20:08] . 2015-02-23 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 7776d1a6-5432-464c-8373-06202368eea0.job - c:\program files\SUPERAntiSpyware\SASTask.exe [2013-11-07 20:08] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-03-22 10134560] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-03-22 896032] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU] "HSON"="c:\program files (x86)\TOSHIBA\TBS\HSON.exe" [BU] "SmoothView"="c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe" [BU] "00TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU] "Teco"="c:\program files (x86)\TOSHIBA\TECO\Teco.exe" [BU] "TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU] "SmartFaceVWatcher"="c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [BU] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-06 709976] "TosNC"="c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe" [BU] "TosReelTimeMonitor"="c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU] . ------- Supplementary Scan ------- . uStart Page = hxxp://start.toshiba.com/?cid=C001B2Y uInternet Settings,ProxyOverride = IE: Add to Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ie_banner_deny.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 192.168.50.1 DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.4.0/GarminAxControl_32.CAB . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.16" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" "Key"="ActionsPane3" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2015-03-14 21:04:31 ComboFix-quarantined-files.txt 2015-03-15 02:04 ComboFix2.txt 2015-02-23 03:29 ComboFix3.txt 2015-02-22 21:04 . Pre-Run: 363,873,193,984 bytes free Post-Run: 363,783,290,880 bytes free . - - End Of File - - 080CF16B57825514A4FA0480C2FC7BB6