Jump to content

Can't remove Trojan.Agent svchost.exe


Recommended Posts

We need a different type of look...

FRST

Download the 64 bit version for your system of FRST and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:

  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:

  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:



    • Startup Repair
      System Restore
      Windows Complete PC Restore
      Windows Memory Diagnostic Tool
      Command Prompt

    [*]Select Command Prompt

    [*]In the command window type in notepad and press Enter.

    [*]The notepad opens. Under File menu select Open.

    [*]Select "Computer" and find your flash drive letter and close the notepad.

    [*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

    Note: Replace letter e with the drive letter of your flash drive.

    [*]The tool will start to run.

    [*]When the tool opens click Yes to disclaimer.

    [*]Press Scan button.

    [*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

----------

Link to post
Share on other sites

  • Replies 56
  • Created
  • Last Reply

Top Posters In This Topic

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-12-2012

Ran by SYSTEM at 20-12-2012 16:02:55

Running from F:\

Windows 7 Home Premium (X64) OS Language: English(US)

The current controlset is ControlSet001

==================== Registry (Whitelisted) ===================

HKLM\...\Run: [broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5470208 2009-12-16] (Dell Inc.)

HKLM\...\Run: [sysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-01-21] (IDT, Inc.)

HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [384296 2010-04-05] (Alps Electric Co., Ltd.)

HKLM-x32\...\Run: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)

HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)

HKLM-x32\...\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [409744 2009-06-24] (Creative Technology Ltd)

HKLM-x32\...\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [498160 2009-10-15] ()

HKLM-x32\...\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe /boot [3926528 2010-08-23] (Dell, Inc.)

HKLM-x32\...\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-25] (Dell, Inc.)

HKLM-x32\...\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)

HKU\nebraskarain\...\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe 1 [1652736 2011-10-05] (AWS Convergence Technologies, Inc.)

HKU\nebraskarain\...\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)

Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

==================== Services (Whitelisted) ===================

2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_4df47d9dbfb58b44\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation)

2 MBAMScheduler; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe" [399432 2012-09-29] (Malwarebytes Corporation)

2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [676936 2012-09-29] (Malwarebytes Corporation)

2 N360; "C:\Program Files (x86)\Norton 360\Engine\20.2.0.19\ccSvcHst.exe" /s "N360" /m "C:\Program Files (x86)\Norton 360\Engine\20.2.0.19\diMaster.dll" /prefetch:1 [535416 2012-10-11] (Symantec Corporation)

2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_4df47d9dbfb58b44\STacSV64.exe [244736 2010-01-21] (IDT, Inc.)

Link to post
Share on other sites

==================== Drivers (Whitelisted) =====================

1 BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20121130.005\BHDrvx64.sys [1384608 2012-10-23] (Symantec Corporation)

1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1402000.013\ccSetx64.sys [168096 2012-10-03] (Symantec Corporation)

1 eeCtrl; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2012-12-06] (Symantec Corporation)

3 EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2012-11-28] (Symantec Corporation)

1 IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20121219.001\IDSvia64.sys [513184 2012-11-30] (Symantec Corporation)

3 MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [25928 2012-09-29] (Malwarebytes Corporation)

3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20121220.004\ENG64.SYS [126112 2012-12-06] (Symantec Corporation)

3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20121220.004\EX64.SYS [2084000 2012-12-06] (Symantec Corporation)

3 SRTSP; C:\Windows\system32\drivers\N360x64\1402000.013\SRTSP64.SYS [776864 2012-10-08] (Symantec Corporation)

1 SRTSPX; C:\Windows\system32\drivers\N360x64\1402000.013\SRTSPX64.SYS [37496 2012-09-06] (Symantec Corporation)

0 SymDS; C:\Windows\System32\drivers\N360x64\1402000.013\SYMDS64.SYS [493216 2012-10-03] (Symantec Corporation)

0 SymEFA; C:\Windows\System32\drivers\N360x64\1402000.013\SYMEFA64.SYS [1133216 2012-10-03] (Symantec Corporation)

3 SymEvent; \??\C:\windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2012-11-30] (Symantec Corporation)

1 SymIRON; C:\Windows\system32\drivers\N360x64\1402000.013\Ironx64.SYS [224416 2012-09-06] (Symantec Corporation)

1 SymNetS; C:\Windows\system32\drivers\N360x64\1402000.013\SYMNETS.SYS [432800 2012-09-06] (Symantec Corporation)

3 catchme; \??\C:\ComboFix\catchme.sys [x]

==================== NetSvcs (Whitelisted) ====================

==================== One Month Created Files and Folders ========

2012-12-20 16:02 - 2012-12-20 16:02 - 00000000 ____D C:\FRST

2012-12-20 13:10 - 2012-12-20 13:10 - 01461035 ____A (Farbar) C:\Users\nebraskarain\Documents\FRST64.exe

2012-12-20 12:30 - 2012-12-20 12:30 - 00060260 ____A C:\Users\nebraskarain\Desktop\Extras.Txt

2012-12-20 12:29 - 2012-12-20 12:29 - 00103848 ____A C:\Users\nebraskarain\Desktop\OTL.Txt

2012-12-20 12:17 - 2012-12-20 12:17 - 00602112 ____A (OldTimer Tools) C:\Users\nebraskarain\Desktop\OTL.exe

2012-12-18 12:40 - 2012-12-18 12:40 - 00023988 ____A C:\Users\nebraskarain\Desktop\combolist2a.txt

2012-12-18 12:38 - 2012-12-18 12:38 - 00023988 ____A C:\Users\nebraskarain\Desktop\combolist2.txt

2012-12-18 12:37 - 2012-12-18 12:37 - 00023988 ____A C:\ComboFix.txt

2012-12-18 08:51 - 2012-12-18 08:49 - 05012571 ____R (Swearware) C:\Users\nebraskarain\Desktop\ComboFix.exe

2012-12-18 08:50 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe

2012-12-18 08:50 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe

2012-12-18 08:50 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe

2012-12-18 08:50 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe

2012-12-18 08:50 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe

2012-12-18 08:50 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe

2012-12-18 08:50 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe

2012-12-18 08:50 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe

2012-12-18 08:49 - 2012-12-18 12:37 - 00000000 ____D C:\Qoobox

2012-12-18 08:49 - 2012-12-18 08:59 - 00000000 ____D C:\Windows\erdnt

2012-12-18 08:48 - 2012-12-18 08:49 - 05012571 ____R (Swearware) C:\Users\nebraskarain\Downloads\ComboFix.exe

2012-12-17 20:21 - 2012-12-17 20:21 - 00000000 ____D C:\TDSSKiller_Quarantine

2012-12-17 14:58 - 2012-12-17 14:59 - 02213976 ____A (Kaspersky Lab ZAO) C:\Users\nebraskarain\Downloads\tdsskiller.exe

2012-12-17 14:23 - 2012-12-17 14:23 - 00688992 ____R (Swearware) C:\Users\nebraskarain\Desktop\dds.scr

2012-12-17 13:38 - 2012-12-17 13:40 - 00915464 ____A (Symantec Corporation) C:\Users\nebraskarain\Downloads\N360Downloader(1).exe

2012-12-16 08:16 - 2012-12-16 09:23 - 00000000 ____D C:\Program Files (x86)\Google

2012-12-16 08:16 - 2012-12-16 08:42 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\Google

2012-12-16 08:16 - 2012-12-16 08:16 - 00000000 ____A C:\Windows\SysWOW64\config.nt

2012-12-16 08:16 - 2012-10-30 14:50 - 00285328 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe

2012-12-16 08:13 - 2012-12-17 11:00 - 00000000 ____D C:\Users\All Users\AVAST Software

2012-12-16 08:13 - 2012-12-16 08:13 - 00000000 ____D C:\Program Files\AVAST Software

2012-12-16 07:54 - 2012-12-16 08:06 - 97495576 ____A C:\Users\nebraskarain\Downloads\avast_free_antivirus_setup.exe

2012-12-15 21:07 - 2012-12-15 21:07 - 00000000 ____A C:\Windows\SysWOW64\shoBCFA.tmp

2012-12-15 17:44 - 2012-12-15 17:44 - 00695296 ____A (AnjoCaido) C:\Users\nebraskarain\Desktop\Minecraft.exe

2012-12-15 07:05 - 2012-12-15 07:05 - 00000000 ____D C:\Windows\Sun

2012-12-12 06:49 - 2012-11-13 23:06 - 17811968 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll

2012-12-12 06:49 - 2012-11-13 22:32 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll

2012-12-12 06:49 - 2012-11-13 22:11 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll

2012-12-12 06:49 - 2012-11-13 22:04 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll

2012-12-12 06:49 - 2012-11-13 22:04 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll

2012-12-12 06:49 - 2012-11-13 22:02 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl

2012-12-12 06:49 - 2012-11-13 22:02 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll

2012-12-12 06:49 - 2012-11-13 21:59 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll

2012-12-12 06:49 - 2012-11-13 21:58 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll

2012-12-12 06:49 - 2012-11-13 21:57 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll

2012-12-12 06:49 - 2012-11-13 21:57 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe

2012-12-12 06:49 - 2012-11-13 21:55 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll

2012-12-12 06:49 - 2012-11-13 21:55 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll

2012-12-12 06:49 - 2012-11-13 21:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll

2012-12-12 06:49 - 2012-11-13 21:52 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb

2012-12-12 06:49 - 2012-11-13 21:46 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll

2012-12-12 06:49 - 2012-11-13 18:48 - 12320256 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll

2012-12-12 06:49 - 2012-11-13 18:14 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll

2012-12-12 06:49 - 2012-11-13 18:09 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll

2012-12-12 06:49 - 2012-11-13 17:58 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl

2012-12-12 06:49 - 2012-11-13 17:57 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll

2012-12-12 06:49 - 2012-11-13 17:57 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll

2012-12-12 06:49 - 2012-11-13 17:55 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll

2012-12-12 06:49 - 2012-11-13 17:51 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll

2012-12-12 06:49 - 2012-11-13 17:49 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll

2012-12-12 06:49 - 2012-11-13 17:49 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe

2012-12-12 06:49 - 2012-11-13 17:48 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll

2012-12-12 06:49 - 2012-11-13 17:47 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll

2012-12-12 06:49 - 2012-11-13 17:46 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll

2012-12-12 06:49 - 2012-11-13 17:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll

2012-12-12 06:49 - 2012-11-13 17:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb

2012-12-12 06:49 - 2012-11-13 17:41 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll

2012-12-12 03:33 - 2012-11-22 00:20 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys

2012-12-12 03:33 - 2012-11-08 21:34 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll

2012-12-12 03:33 - 2012-11-08 20:49 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll

2012-12-12 03:32 - 2012-11-05 08:25 - 00046080 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll

2012-12-12 03:32 - 2012-11-05 06:17 - 00367616 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll

2012-12-12 03:32 - 2012-11-05 06:03 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll

2012-12-12 03:32 - 2012-11-05 06:03 - 00034304 ____A (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll

2012-12-12 03:32 - 2012-11-01 21:27 - 00478208 ____A (Microsoft Corporation) C:\Windows\System32\dpnet.dll

2012-12-12 03:32 - 2012-11-01 20:48 - 00376832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll

2012-12-12 03:32 - 2012-10-04 09:38 - 00362496 ____A (Microsoft Corporation) C:\Windows\System32\wow64win.dll

2012-12-12 03:32 - 2012-10-04 09:38 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\wow64.dll

2012-12-12 03:32 - 2012-10-04 09:38 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll

2012-12-12 03:32 - 2012-10-04 09:38 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll

2012-12-12 03:32 - 2012-10-04 09:35 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll

2012-12-12 03:32 - 2012-10-04 09:32 - 01161216 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll

2012-12-12 03:32 - 2012-10-04 09:32 - 00425984 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 09:28 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:54 - 01114112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll

2012-12-12 03:32 - 2012-10-04 08:54 - 00274944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll

2012-12-12 03:32 - 2012-10-04 08:54 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00005120 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 07:19 - 00338432 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe

2012-12-12 03:32 - 2012-10-04 06:49 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe

2012-12-12 03:32 - 2012-10-04 06:49 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll

2012-12-12 03:32 - 2012-10-04 06:49 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe

2012-12-12 03:32 - 2012-10-04 06:49 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user.exe

2012-12-12 03:32 - 2012-10-04 06:44 - 00006144 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 06:44 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 06:44 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll

2012-12-12 03:32 - 2012-10-04 06:44 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll

2012-12-12 03:32 - 2012-09-06 09:38 - 00295792 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\volsnap.sys

2012-12-09 08:36 - 2012-12-09 08:36 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help

2012-12-09 08:36 - 2012-12-09 08:36 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help

2012-12-09 07:42 - 2012-12-09 07:42 - 00003021 ____A C:\Users\nebraskarain\Desktop\Microsoft Word 2010.lnk

2012-12-09 07:37 - 2012-12-09 07:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services

2012-12-09 07:36 - 2012-12-12 06:52 - 00000000 ____D C:\Users\All Users\Microsoft Help

2012-12-09 07:36 - 2012-12-09 07:36 - 00000000 ___RD C:\MSOCache

2012-12-09 07:36 - 2012-12-09 07:36 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\Microsoft Help

2012-12-09 07:24 - 2012-12-09 07:24 - 00001807 ____A C:\Users\nebraskarain\Desktop\Office Home and Student 2010_1355066645105.lnk

2012-12-08 21:12 - 2012-12-08 21:12 - 00002058 ____A C:\Users\nebraskarain\Desktop\Microsoft Download Manager_1355029939765.lnk

2012-12-08 21:08 - 2012-12-09 07:24 - 987942848 ____A (Microsoft Corporation) C:\Users\nebraskarain\Downloads\X17-75058.exe

2012-12-08 21:08 - 2012-12-08 21:08 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\MicrosoftStore

2012-12-08 21:07 - 2012-12-08 21:07 - 02572752 ____A (Solid State Networks) C:\Users\nebraskarain\Downloads\4e75f434510343168fe2642ba767e276_Pod7_en-us(1).exe

2012-12-08 21:01 - 2012-12-08 21:03 - 02572752 ____A (Solid State Networks) C:\Users\nebraskarain\Downloads\4e75f434510343168fe2642ba767e276_Pod7_en-us.exe

2012-12-08 20:54 - 2012-12-08 21:05 - 02463516 ____A C:\Users\nebraskarain\Downloads\WinOffice2010-64-SL.exe.part

2012-12-08 16:45 - 2012-12-08 16:45 - 00279144 ____A C:\Windows\Minidump\120812-29671-01.dmp

2012-12-08 16:45 - 2012-12-08 16:45 - 00000000 ____D C:\Windows\Minidump

2012-12-08 16:44 - 2012-12-08 16:44 - 480341390 ____A C:\Windows\MEMORY.DMP

2012-12-05 21:20 - 2012-12-05 21:20 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\Adobe

2012-12-04 16:48 - 2012-12-04 16:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

2012-12-02 11:05 - 2012-12-02 11:07 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\.minecraft

2012-12-02 11:05 - 2012-12-02 11:05 - 00000000 ____D C:\Users\All Users\Sun

2012-12-02 11:04 - 2012-12-02 11:04 - 00821736 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll

2012-12-02 11:04 - 2012-12-02 11:04 - 00746984 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll

2012-12-02 11:04 - 2012-12-02 11:04 - 00246760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe

2012-12-02 11:04 - 2012-12-02 11:04 - 00174056 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe

2012-12-02 11:04 - 2012-12-02 11:04 - 00174056 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe

2012-12-02 11:04 - 2012-12-02 11:04 - 00095208 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll

2012-12-02 11:04 - 2012-12-02 11:04 - 00000000 ____D C:\Program Files (x86)\Java

2012-12-02 10:54 - 2012-12-02 10:54 - 00895464 ____A (Oracle Corporation) C:\Users\nebraskarain\Downloads\jxpiinstall.exe

2012-12-02 06:01 - 2012-12-02 06:01 - 00000000 ____A C:\Windows\SysWOW64\shoBFD6.tmp

2012-12-02 05:01 - 2011-03-28 19:32 - 00343040 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbhub.sys

2012-12-02 05:01 - 2011-03-28 19:32 - 00324608 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbport.sys

2012-12-02 05:01 - 2011-03-28 19:32 - 00099328 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbccgp.sys

2012-12-02 05:01 - 2011-03-28 19:32 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbehci.sys

2012-12-02 05:01 - 2011-03-28 19:32 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbuhci.sys

2012-12-02 05:01 - 2011-03-28 19:32 - 00025600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbohci.sys

2012-12-02 05:01 - 2011-03-28 19:32 - 00007936 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbd.sys

2012-12-02 05:01 - 2011-03-10 22:23 - 00410496 ____A (Intel Corporation) C:\Windows\System32\Drivers\iaStorV.sys

2012-12-02 05:01 - 2011-03-10 22:23 - 00187264 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\storport.sys

2012-12-02 05:01 - 2011-03-10 22:23 - 00166272 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvstor.sys

2012-12-02 05:01 - 2011-03-10 22:23 - 00148352 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvraid.sys

2012-12-02 05:01 - 2011-03-10 22:22 - 00107904 ____A (Advanced Micro Devices) C:\Windows\System32\Drivers\amdsata.sys

2012-12-02 05:01 - 2011-03-10 22:22 - 00027008 ____A (Advanced Micro Devices) C:\Windows\System32\Drivers\amdxata.sys

2012-12-02 05:01 - 2011-03-10 22:18 - 02566144 ____A (Microsoft Corporation) C:\Windows\System32\esent.dll

2012-12-02 05:01 - 2011-03-10 22:15 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\fsutil.exe

2012-12-02 05:01 - 2011-03-10 21:39 - 01686016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll

2012-12-02 05:01 - 2011-03-10 21:37 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe

2012-12-02 05:01 - 2011-03-10 20:31 - 00091136 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\USBSTOR.SYS

2012-12-01 09:44 - 2012-12-01 09:44 - 00000000 ____A C:\Windows\SysWOW64\sho62BD.tmp

2012-12-01 09:34 - 2010-09-13 22:45 - 00367104 ____A (Microsoft Corporation) C:\Windows\System32\wcncsvc.dll

2012-12-01 09:34 - 2010-09-13 22:07 - 00276992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wcncsvc.dll

2012-12-01 08:48 - 2012-07-25 20:55 - 00785512 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\Wdf01000.sys

2012-12-01 08:48 - 2012-07-25 20:55 - 00054376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WdfLdr.sys

2012-12-01 08:48 - 2012-07-25 18:36 - 00009728 ____A (Microsoft Corporation) C:\Windows\System32\Wdfres.dll

2012-12-01 08:48 - 2012-06-02 06:35 - 00000003 ____A C:\Windows\System32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf

2012-12-01 08:31 - 2009-11-25 10:47 - 01942856 ____A (Microsoft Corporation) C:\Windows\System32\dfshim.dll

2012-12-01 08:31 - 2009-11-25 10:47 - 01130824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll

2012-12-01 08:31 - 2009-11-25 10:47 - 00444752 ____A (Microsoft Corporation) C:\Windows\System32\mscoree.dll

2012-12-01 08:31 - 2009-11-25 10:47 - 00320352 ____A (Microsoft Corporation) C:\Windows\System32\PresentationHost.exe

2012-12-01 08:31 - 2009-11-25 10:47 - 00297808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mscoree.dll

2012-12-01 08:31 - 2009-11-25 10:47 - 00295264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHost.exe

2012-12-01 08:31 - 2009-11-25 10:47 - 00109912 ____A (Microsoft Corporation) C:\Windows\System32\PresentationHostProxy.dll

2012-12-01 08:31 - 2009-11-25 10:47 - 00099176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHostProxy.dll

2012-12-01 08:31 - 2009-11-25 10:47 - 00049472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netfxperf.dll

2012-12-01 08:31 - 2009-11-25 10:47 - 00048960 ____A (Microsoft Corporation) C:\Windows\System32\netfxperf.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 03695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat

2012-12-01 08:27 - 2012-12-01 08:27 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat

2012-12-01 08:27 - 2012-12-01 08:27 - 00534528 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00452608 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00448512 ____A (Microsoft Corporation) C:\Windows\System32\html.iec

2012-12-01 08:27 - 2012-12-01 08:27 - 00434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00403248 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec

2012-12-01 08:27 - 2012-12-01 08:27 - 00353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00282112 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00267776 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00249344 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00165888 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00145920 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00135168 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00114176 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00111616 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00091648 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx

2012-12-01 08:27 - 2012-12-01 08:27 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx

2012-12-01 08:27 - 2012-12-01 08:27 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00049664 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe

2012-12-01 08:20 - 2012-12-01 08:28 - 00003625 ____A C:\Windows\IE9_main.log

2012-12-01 08:12 - 2012-07-25 19:08 - 00744448 ____A (Microsoft Corporation) C:\Windows\System32\WUDFx.dll

2012-12-01 08:12 - 2012-07-25 19:08 - 00229888 ____A (Microsoft Corporation) C:\Windows\System32\WUDFHost.exe

2012-12-01 08:12 - 2012-07-25 19:08 - 00194048 ____A (Microsoft Corporation) C:\Windows\System32\WUDFPlatform.dll

2012-12-01 08:12 - 2012-07-25 19:08 - 00084992 ____A (Microsoft Corporation) C:\Windows\System32\WUDFSvc.dll

2012-12-01 08:12 - 2012-07-25 19:08 - 00045056 ____A (Microsoft Corporation) C:\Windows\System32\WUDFCoinstaller.dll

2012-12-01 08:12 - 2012-07-25 18:26 - 00198656 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WUDFRd.sys

2012-12-01 08:12 - 2012-07-25 18:26 - 00087040 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WUDFPf.sys

2012-12-01 08:12 - 2012-06-02 06:57 - 00000003 ____A C:\Windows\System32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf

2012-12-01 08:08 - 2012-02-29 22:54 - 00022896 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fs_rec.sys

2012-12-01 08:08 - 2012-02-29 22:40 - 00080896 ____A (Microsoft Corporation) C:\Windows\System32\imagehlp.dll

2012-12-01 08:08 - 2012-02-29 22:35 - 00005120 ____A (Microsoft Corporation) C:\Windows\System32\wmi.dll

2012-12-01 08:08 - 2012-02-29 21:45 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll

2012-12-01 08:08 - 2012-02-29 21:40 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll

2012-12-01 05:37 - 2012-08-31 10:02 - 01656688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys

2012-12-01 05:37 - 2012-03-02 22:29 - 01837568 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll

2012-12-01 05:37 - 2012-03-02 22:29 - 01541120 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll

2012-12-01 05:37 - 2012-03-02 22:29 - 00902656 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll

2012-12-01 05:37 - 2012-03-02 22:29 - 00320512 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll

2012-12-01 05:37 - 2012-03-02 22:29 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll

2012-12-01 05:37 - 2012-03-02 21:40 - 01170944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll

2012-12-01 05:37 - 2012-03-02 21:40 - 01074176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll

2012-12-01 05:37 - 2012-03-02 21:40 - 00739840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll

2012-12-01 05:37 - 2012-03-02 21:40 - 00218624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll

2012-12-01 05:37 - 2012-03-02 21:40 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll

2012-12-01 05:37 - 2011-06-15 21:31 - 00199680 ____A (Microsoft Corporation) C:\Windows\System32\xmllite.dll

2012-12-01 05:37 - 2011-06-15 20:35 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\xmllite.dll

2012-12-01 05:37 - 2011-06-15 01:58 - 00212992 ____A (Microsoft Corporation) C:\Windows\System32\odbctrac.dll

2012-12-01 05:37 - 2011-06-15 01:58 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\odbccp32.dll

2012-12-01 05:37 - 2011-06-15 01:58 - 00106496 ____A (Microsoft Corporation) C:\Windows\System32\odbccu32.dll

2012-12-01 05:37 - 2011-06-15 01:58 - 00106496 ____A (Microsoft Corporation) C:\Windows\System32\odbccr32.dll

2012-12-01 05:37 - 2011-06-15 01:04 - 00319488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll

2012-12-01 05:37 - 2011-06-15 01:04 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll

2012-12-01 05:37 - 2011-06-15 01:04 - 00122880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll

2012-12-01 05:37 - 2011-06-15 01:04 - 00086016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll

2012-12-01 05:37 - 2011-06-15 01:04 - 00081920 ____A (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll

2012-12-01 05:37 - 2011-04-26 18:57 - 00102400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dfsc.sys

2012-12-01 05:37 - 2010-08-03 23:07 - 00552960 ____A (Microsoft Corporation) C:\Windows\System32\msdri.dll

2012-12-01 05:35 - 2011-04-08 22:58 - 00142336 ____A (Microsoft Corporation) C:\Windows\System32\poqexec.exe

2012-12-01 05:35 - 2011-04-08 21:56 - 00123904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe

2012-12-01 05:35 - 2011-02-25 22:23 - 02870272 ____A (Microsoft Corporation) C:\Windows\explorer.exe

2012-12-01 05:35 - 2011-02-25 21:33 - 02614784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe

2012-12-01 05:35 - 2010-12-22 22:07 - 01118720 ____A (Microsoft Corporation) C:\Windows\System32\sbe.dll

2012-12-01 05:35 - 2010-12-22 22:07 - 00961024 ____A (Microsoft Corporation) C:\Windows\System32\CPFilters.dll

2012-12-01 05:35 - 2010-12-22 22:02 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\mpg2splt.ax

2012-12-01 05:35 - 2010-12-22 21:28 - 00850432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll

2012-12-01 05:35 - 2010-12-22 21:28 - 00642048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll

2012-12-01 05:35 - 2010-12-22 21:24 - 00199680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax

2012-12-01 05:35 - 2010-08-25 21:27 - 00148992 ____A (Microsoft Corporation) C:\Windows\System32\t2embed.dll

2012-12-01 05:35 - 2010-08-25 20:39 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll

2012-12-01 05:33 - 2012-01-04 01:58 - 00509952 ____A (Microsoft Corporation) C:\Windows\System32\ntshrui.dll

2012-12-01 05:33 - 2012-01-04 01:03 - 00442880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll

2012-12-01 05:33 - 2011-10-25 21:33 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll

2012-12-01 05:33 - 2011-10-25 21:22 - 01572864 ____A (Microsoft Corporation) C:\Windows\System32\quartz.dll

2012-12-01 05:33 - 2011-10-25 20:33 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll

2012-12-01 05:33 - 2011-10-25 20:28 - 01328640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll

2012-12-01 05:32 - 2011-07-08 18:44 - 00287744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys

2012-12-01 05:32 - 2011-05-03 21:30 - 02326016 ____A (Microsoft Corporation) C:\Windows\System32\tquery.dll

2012-12-01 05:32 - 2011-05-03 21:28 - 02228224 ____A (Microsoft Corporation) C:\Windows\System32\mssrch.dll

2012-12-01 05:32 - 2011-05-03 21:28 - 00779264 ____A (Microsoft Corporation) C:\Windows\System32\mssvp.dll

2012-12-01 05:32 - 2011-05-03 21:28 - 00491520 ____A (Microsoft Corporation) C:\Windows\System32\mssph.dll

2012-12-01 05:32 - 2011-05-03 21:28 - 00288256 ____A (Microsoft Corporation) C:\Windows\System32\mssphtb.dll

2012-12-01 05:32 - 2011-05-03 21:28 - 00075264 ____A (Microsoft Corporation) C:\Windows\System32\msscntrs.dll

2012-12-01 05:32 - 2011-05-03 21:24 - 00593408 ____A (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe

2012-12-01 05:32 - 2011-05-03 21:24 - 00249856 ____A (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe

2012-12-01 05:32 - 2011-05-03 21:24 - 00113664 ____A (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe

2012-12-01 05:32 - 2011-05-03 20:53 - 01553920 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll

2012-12-01 05:32 - 2011-05-03 20:52 - 01401856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll

2012-12-01 05:32 - 2011-05-03 20:52 - 00666624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll

2012-12-01 05:32 - 2011-05-03 20:52 - 00428032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe

2012-12-01 05:32 - 2011-05-03 20:52 - 00337408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll

2012-12-01 05:32 - 2011-05-03 20:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll

2012-12-01 05:32 - 2011-05-03 20:52 - 00164352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe

2012-12-01 05:32 - 2011-05-03 20:52 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe

2012-12-01 05:32 - 2011-05-03 20:52 - 00059392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll

2012-12-01 05:32 - 2011-05-03 18:51 - 00157696 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys

2012-12-01 05:32 - 2011-05-03 18:51 - 00126464 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys

2012-12-01 05:32 - 2010-11-01 21:18 - 00524288 ____A (Microsoft Corporation) C:\Windows\System32\wmicmiplugin.dll

2012-12-01 05:32 - 2010-11-01 21:17 - 01169408 ____A (Microsoft Corporation) C:\Windows\System32\taskschd.dll

2012-12-01 05:32 - 2010-11-01 21:17 - 00473600 ____A (Microsoft Corporation) C:\Windows\System32\taskcomp.dll

2012-12-01 05:32 - 2010-11-01 21:16 - 01114624 ____A (Microsoft Corporation) C:\Windows\System32\schedsvc.dll

2012-12-01 05:32 - 2010-11-01 21:10 - 00464384 ____A (Microsoft Corporation) C:\Windows\System32\taskeng.exe

2012-12-01 05:32 - 2010-11-01 21:10 - 00285696 ____A (Microsoft Corporation) C:\Windows\System32\schtasks.exe

2012-12-01 05:32 - 2010-11-01 20:40 - 00496128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll

2012-12-01 05:32 - 2010-11-01 20:40 - 00305152 ____A (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll

2012-12-01 05:32 - 2010-11-01 20:34 - 00192000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe

2012-12-01 05:32 - 2010-11-01 20:34 - 00179712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe

2012-12-01 05:32 - 2010-06-28 21:39 - 02085376 ____A (Microsoft Corporation) C:\Windows\System32\ole32.dll

2012-12-01 05:32 - 2010-06-28 21:02 - 01413632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll

2012-12-01 05:32 - 2010-05-04 23:37 - 00483840 ____A (Microsoft Corporation) C:\Windows\System32\StructuredQuery.dll

2012-12-01 05:32 - 2010-05-04 22:46 - 00363520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll

2012-12-01 05:31 - 2012-06-05 21:50 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll

2012-12-01 05:31 - 2012-06-05 21:50 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll

2012-12-01 05:31 - 2012-06-05 21:09 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll

2012-12-01 05:31 - 2012-06-05 21:09 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll

2012-12-01 05:31 - 2011-11-16 23:12 - 00395776 ____A (Microsoft Corporation) C:\Windows\System32\webio.dll

2012-12-01 05:31 - 2011-11-16 21:39 - 00314368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll

2012-12-01 05:29 - 2012-08-30 10:11 - 03971440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe

2012-12-01 05:29 - 2012-08-30 10:11 - 03915632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe

2012-12-01 05:29 - 2012-08-30 10:10 - 05473136 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe

2012-12-01 05:29 - 2012-01-02 22:24 - 00515584 ____A (Microsoft Corporation) C:\Windows\System32\timedate.cpl

2012-12-01 05:29 - 2012-01-02 21:44 - 00478208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl

2012-12-01 05:29 - 2011-10-25 21:19 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll

2012-12-01 05:29 - 2011-02-23 22:30 - 00476160 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll

2012-12-01 05:29 - 2011-02-23 21:32 - 00288256 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll

2012-12-01 05:29 - 2010-08-20 22:31 - 00633856 ____A (Microsoft Corporation) C:\Windows\System32\comctl32.dll

2012-12-01 05:29 - 2010-08-20 21:33 - 00530432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll

2012-12-01 05:28 - 2012-06-08 21:30 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll

2012-12-01 05:28 - 2012-06-08 20:46 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll

2012-12-01 05:28 - 2011-03-12 04:03 - 00662528 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll

2012-12-01 05:28 - 2011-03-12 03:31 - 00442880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll

2012-12-01 05:28 - 2011-03-10 22:19 - 01395712 ____A (Microsoft Corporation) C:\Windows\System32\mfc42.dll

2012-12-01 05:28 - 2011-03-10 22:19 - 01359872 ____A (Microsoft Corporation) C:\Windows\System32\mfc42u.dll

2012-12-01 05:28 - 2011-03-10 21:40 - 01164288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll

2012-12-01 05:28 - 2011-03-10 21:40 - 01137664 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll

2012-12-01 05:28 - 2010-12-20 22:16 - 00442880 ____A (Microsoft Corporation) C:\Windows\System32\winhttp.dll

2012-12-01 05:28 - 2010-12-20 22:16 - 00258048 ____A (Microsoft Corporation) C:\Windows\System32\WebClnt.dll

2012-12-01 05:28 - 2010-12-20 22:16 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\wscsvc.dll

2012-12-01 05:28 - 2010-12-20 22:16 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\wscapi.dll

2012-12-01 05:28 - 2010-12-20 22:15 - 00264192 ____A (Microsoft Corporation) C:\Windows\System32\upnp.dll

2012-12-01 05:28 - 2010-12-20 22:15 - 00015360 ____A (Microsoft Corporation) C:\Windows\System32\slwga.dll

2012-12-01 05:28 - 2010-12-20 22:10 - 00100864 ____A (Microsoft Corporation) C:\Windows\System32\davclnt.dll

2012-12-01 05:28 - 2010-12-20 21:38 - 00350720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll

2012-12-01 05:28 - 2010-12-20 21:38 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll

2012-12-01 05:28 - 2010-12-20 21:38 - 00204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\upnp.dll

2012-12-01 05:28 - 2010-12-20 21:38 - 00051200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll

2012-12-01 05:28 - 2010-12-20 21:38 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\slwga.dll

2012-12-01 05:28 - 2010-12-20 21:34 - 00080384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll

2012-12-01 05:27 - 2012-08-02 09:55 - 00574464 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll

2012-12-01 05:27 - 2012-08-02 09:05 - 00490496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll

2012-12-01 05:27 - 2012-06-01 21:38 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys

2012-12-01 05:27 - 2012-06-01 21:38 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys

2012-12-01 05:27 - 2012-06-01 21:37 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys

2012-12-01 05:27 - 2012-06-01 21:27 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll

2012-12-01 05:27 - 2012-06-01 21:27 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll

2012-12-01 05:27 - 2012-06-01 20:48 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll

2012-12-01 05:27 - 2012-06-01 20:48 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll

2012-12-01 05:27 - 2012-06-01 20:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll

2012-12-01 05:27 - 2012-06-01 20:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll

2012-12-01 05:27 - 2012-04-25 21:34 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll

2012-12-01 05:27 - 2012-04-25 21:34 - 00076288 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll

2012-12-01 05:27 - 2012-04-25 21:28 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe

2012-12-01 05:27 - 2011-11-16 23:11 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\sspicli.dll

2012-12-01 05:27 - 2011-11-16 23:11 - 00028672 ____A (Microsoft Corporation) C:\Windows\System32\sspisrv.dll

2012-12-01 05:27 - 2011-11-16 23:11 - 00028160 ____A (Microsoft Corporation) C:\Windows\System32\secur32.dll

2012-12-01 05:27 - 2011-11-16 23:08 - 01446912 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll

2012-12-01 05:27 - 2011-11-16 23:05 - 00031232 ____A (Microsoft Corporation) C:\Windows\System32\lsass.exe

2012-12-01 05:26 - 2011-01-25 22:53 - 00982912 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys

2012-12-01 05:26 - 2011-01-25 22:53 - 00265088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys

2012-12-01 05:26 - 2011-01-25 22:31 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll

2012-12-01 05:26 - 2010-11-01 21:18 - 00229888 ____A (Microsoft Corporation) C:\Windows\System32\XpsRasterService.dll

2012-12-01 05:26 - 2010-11-01 21:12 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll

2012-12-01 05:26 - 2010-11-01 20:41 - 00135168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsRasterService.dll

2012-12-01 05:26 - 2010-06-25 21:31 - 01863680 ____A (Microsoft Corporation) C:\Windows\System32\ExplorerFrame.dll

2012-12-01 05:26 - 2010-06-25 21:14 - 01495040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll

2012-12-01 05:26 - 2010-05-23 02:15 - 01619456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL

2012-12-01 05:26 - 2010-05-23 02:11 - 03181568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll

2012-12-01 05:26 - 2010-05-23 02:11 - 00196608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll

2012-12-01 05:26 - 2010-05-23 00:37 - 01888256 ____A (Microsoft Corporation) C:\Windows\System32\WMVDECOD.DLL

2012-12-01 05:26 - 2010-05-23 00:35 - 04068864 ____A (Microsoft Corporation) C:\Windows\System32\mf.dll

2012-12-01 05:26 - 2010-05-23 00:35 - 00257024 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll

2012-12-01 05:26 - 2010-05-23 00:35 - 00206848 ____A (Microsoft Corporation) C:\Windows\System32\mfps.dll

2012-12-01 05:25 - 2012-05-01 21:32 - 00208896 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll

2012-12-01 05:25 - 2011-04-22 12:18 - 00027008 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\Diskdump.sys

2012-12-01 05:25 - 2011-03-02 22:17 - 00356352 ____A (Microsoft Corporation) C:\Windows\System32\dnsapi.dll

2012-12-01 05:25 - 2011-03-02 22:17 - 00182272 ____A (Microsoft Corporation) C:\Windows\System32\dnsrslvr.dll

2012-12-01 05:25 - 2011-03-02 22:14 - 00030208 ____A (Microsoft Corporation) C:\Windows\System32\dnscacheugc.exe

2012-12-01 05:25 - 2011-03-02 21:29 - 00269824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll

2012-12-01 05:25 - 2011-03-02 21:27 - 00028672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe

2012-12-01 05:25 - 2009-09-25 22:20 - 00223448 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fvevol.sys

2012-12-01 05:24 - 2012-08-24 10:05 - 00220160 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll

2012-12-01 05:24 - 2012-08-24 09:10 - 00172544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll

2012-12-01 05:24 - 2010-08-20 22:38 - 01024512 ____A (Microsoft Corporation) C:\Windows\System32\wmpmde.dll

2012-12-01 05:24 - 2010-08-20 21:36 - 00738816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll

2012-12-01 05:23 - 2011-08-16 21:32 - 00613888 ____A (Microsoft Corporation) C:\Windows\System32\psisdecd.dll

2012-12-01 05:23 - 2011-08-16 21:27 - 00288256 ____A (Microsoft Corporation) C:\Windows\System32\MSNP.ax

2012-12-01 05:23 - 2011-08-16 21:27 - 00108032 ____A (Microsoft Corporation) C:\Windows\System32\psisrndr.ax

2012-12-01 05:23 - 2011-08-16 21:27 - 00104960 ____A (Microsoft Corporation) C:\Windows\System32\Mpeg2Data.ax

2012-12-01 05:23 - 2011-08-16 21:27 - 00075776 ____A (Microsoft Corporation) C:\Windows\System32\MSDvbNP.ax

2012-12-01 05:23 - 2011-08-16 20:26 - 00465408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll

2012-12-01 05:23 - 2011-08-16 20:22 - 00204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSNP.ax

2012-12-01 05:23 - 2011-08-16 20:22 - 00075776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax

2012-12-01 05:23 - 2011-08-16 20:22 - 00072704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Mpeg2Data.ax

2012-12-01 05:23 - 2011-08-16 20:22 - 00059904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSDvbNP.ax

2012-12-01 05:23 - 2011-04-28 19:13 - 00461312 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv.sys

2012-12-01 05:23 - 2011-04-28 19:12 - 00399872 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys

2012-12-01 05:23 - 2011-04-28 19:12 - 00161792 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys

2012-12-01 05:22 - 2012-09-25 14:39 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\synceng.dll

2012-12-01 05:22 - 2012-09-25 13:55 - 00078336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll

2012-12-01 05:22 - 2012-08-10 16:53 - 00714752 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll

2012-12-01 05:22 - 2012-08-10 15:54 - 00541184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll

2012-12-01 05:22 - 2012-04-27 19:50 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys

2012-12-01 05:22 - 2012-04-07 04:18 - 03213824 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll

2012-12-01 05:22 - 2012-04-07 03:34 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll

2012-12-01 05:22 - 2012-03-16 23:55 - 00075632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys

2012-12-01 05:22 - 2011-12-27 19:59 - 00499200 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\afd.sys

2012-12-01 05:22 - 2011-02-05 04:41 - 00640896 ____A (Microsoft Corporation) C:\Windows\System32\winload.efi

2012-12-01 05:22 - 2011-02-05 04:41 - 00556928 ____A (Microsoft Corporation) C:\Windows\System32\winresume.efi

2012-12-01 05:22 - 2011-02-05 04:41 - 00020352 ____A (Microsoft Corporation) C:\Windows\System32\kdusb.dll

2012-12-01 05:22 - 2011-02-05 04:41 - 00019328 ____A (Microsoft Corporation) C:\Windows\System32\kd1394.dll

2012-12-01 05:22 - 2011-02-05 04:41 - 00017792 ____A (Microsoft Corporation) C:\Windows\System32\kdcom.dll

2012-12-01 05:22 - 2011-02-05 04:39 - 00603976 ____A (Microsoft Corporation) C:\Windows\System32\winload.exe

2012-12-01 05:22 - 2011-02-05 04:39 - 00518160 ____A (Microsoft Corporation) C:\Windows\System32\winresume.exe

2012-12-01 05:22 - 2010-08-30 20:32 - 00954752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc40.dll

2012-12-01 05:22 - 2010-08-30 20:32 - 00954288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc40u.dll

2012-12-01 05:21 - 2011-05-24 03:21 - 00404992 ____A (Microsoft Corporation) C:\Windows\System32\umpnpmgr.dll

2012-12-01 05:21 - 2011-05-24 02:34 - 00145920 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll

2012-12-01 05:21 - 2011-05-24 02:34 - 00064512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll

2012-12-01 05:21 - 2011-05-24 02:34 - 00044544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll

2012-12-01 05:21 - 2011-05-24 02:32 - 00252928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe

2012-12-01 05:20 - 2012-07-04 14:04 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll

2012-12-01 05:20 - 2012-07-04 14:01 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll

2012-12-01 05:20 - 2012-07-04 14:01 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll

2012-12-01 05:20 - 2012-07-04 13:26 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll

2012-12-01 05:20 - 2012-07-04 13:23 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll

2012-12-01 05:20 - 2012-05-13 21:20 - 00956416 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll

2012-12-01 05:20 - 2012-05-05 00:30 - 00503808 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll

2012-12-01 05:20 - 2012-05-04 23:44 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll

2012-12-01 05:20 - 2012-03-30 03:09 - 01895280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys

2012-12-01 05:20 - 2011-12-16 00:42 - 00634368 ____A (Microsoft Corporation) C:\Windows\System32\msvcrt.dll

2012-12-01 05:20 - 2011-12-15 23:59 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll

2012-12-01 05:20 - 2011-10-14 22:25 - 00723456 ____A (Microsoft Corporation) C:\Windows\System32\EncDec.dll

2012-12-01 05:20 - 2011-10-14 21:48 - 00534528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll

2012-12-01 05:20 - 2011-08-26 21:40 - 00861184 ____A (Microsoft Corporation) C:\Windows\System32\oleaut32.dll

2012-12-01 05:20 - 2011-08-26 21:40 - 00331776 ____A (Microsoft Corporation) C:\Windows\System32\oleacc.dll

2012-12-01 05:20 - 2011-08-26 20:43 - 00571904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll

2012-12-01 05:20 - 2011-08-26 20:43 - 00233472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll

2012-12-01 05:20 - 2011-05-02 21:21 - 00976896 ____A (Microsoft Corporation) C:\Windows\System32\inetcomm.dll

2012-12-01 05:20 - 2011-05-02 20:50 - 00740864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll

2012-12-01 05:20 - 2011-02-22 21:15 - 00090624 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bowser.sys

2012-12-01 05:20 - 2011-02-17 22:33 - 00031232 ____A (Microsoft Corporation) C:\Windows\System32\prevhost.exe

2012-12-01 05:20 - 2011-02-17 21:33 - 00031232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe

2012-12-01 05:20 - 2011-02-11 22:14 - 00267776 ____A (Microsoft Corporation) C:\Windows\System32\FXSCOVER.exe

2012-12-01 05:20 - 2010-12-17 22:12 - 03138048 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll

2012-12-01 05:20 - 2010-12-17 22:08 - 01097216 ____A (Microsoft Corporation) C:\Windows\System32\mstsc.exe

2012-12-01 05:20 - 2010-12-17 21:30 - 02690560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll

2012-12-01 05:20 - 2010-12-17 21:26 - 01034240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe

2012-12-01 05:20 - 2010-10-15 21:23 - 00112000 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe

2012-12-01 05:20 - 2010-08-31 21:21 - 14627840 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll

2012-12-01 05:20 - 2010-08-31 21:12 - 12625920 ____A (Microsoft Corporation) C:\Windows\System32\wmploc.DLL

2012-12-01 05:20 - 2010-08-31 20:29 - 11406848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll

2012-12-01 05:20 - 2010-08-31 20:23 - 12625408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL

2012-12-01 05:19 - 2012-06-01 21:25 - 01462784 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll

2012-12-01 05:19 - 2012-06-01 21:25 - 00182272 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll

2012-12-01 05:19 - 2012-06-01 21:25 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll

2012-12-01 05:19 - 2012-06-01 20:45 - 01157632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll

2012-12-01 05:19 - 2012-06-01 20:45 - 00139264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll

2012-12-01 05:19 - 2012-06-01 20:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll

2012-12-01 05:19 - 2012-02-10 22:36 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll

2012-12-01 05:19 - 2012-02-10 22:29 - 00559104 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe

2012-12-01 05:19 - 2012-02-10 22:29 - 00067584 ____A (Microsoft Corporation) C:\Windows\splwow64.exe

2012-12-01 05:19 - 2012-02-10 21:44 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll

2012-12-01 05:19 - 2011-11-16 23:14 - 01739160 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll

2012-12-01 05:19 - 2011-11-16 21:41 - 01292592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll

2012-12-01 05:19 - 2010-10-15 21:17 - 00720896 ____A (Microsoft Corporation) C:\Windows\System32\odbc32.dll

2012-12-01 05:19 - 2010-10-15 20:34 - 00573440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\odbc32.dll

2012-12-01 05:19 - 2010-08-26 22:14 - 00236032 ____A (Microsoft Corporation) C:\Windows\System32\srvsvc.dll

2012-12-01 05:19 - 2010-08-26 21:46 - 00009728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll

2012-12-01 05:18 - 2011-11-19 07:07 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\packager.dll

2012-12-01 05:18 - 2011-11-19 06:06 - 00067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll

2012-11-30 20:46 - 2012-12-01 11:46 - 00000000 ____D C:\Users\All Users\VirtualizedApplications

2012-11-30 16:52 - 2012-12-09 08:33 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\SoftGrid Client

2012-11-30 16:52 - 2012-11-30 16:52 - 00002463 ____A C:\Users\nebraskarain\Desktop\Microsoft Word Starter 2010.lnk

2012-11-30 16:52 - 2012-11-30 16:52 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\SoftGrid Client

2012-11-30 16:51 - 2012-12-01 08:15 - 00731106 ____A C:\Windows\SysWOW64\PerfStringBackup.INI

2012-11-30 16:50 - 2012-12-01 08:15 - 00000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client

2012-11-30 16:50 - 2012-11-30 16:53 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\TP

2012-11-30 16:50 - 2012-11-30 16:50 - 00000000 ____D C:\Program Files\Microsoft Office

2012-11-30 14:09 - 2012-11-30 14:09 - 00177312 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS

2012-11-30 14:09 - 2012-11-30 14:09 - 00007466 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT

2012-11-30 14:09 - 2012-11-30 14:09 - 00002397 ____A C:\Users\Public\Desktop\Norton 360.lnk

2012-11-30 14:09 - 2012-11-30 14:09 - 00000000 ____D C:\Program Files\Symantec

2012-11-30 14:09 - 2012-11-30 14:09 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared

2012-11-30 14:09 - 2012-11-30 14:09 - 00000000 ____D C:\Program Files (x86)\Norton 360

2012-11-30 14:01 - 2012-11-30 14:01 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\Macromedia

2012-11-30 14:00 - 2012-11-30 14:00 - 00697272 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2012-11-30 14:00 - 2012-11-30 14:00 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

2012-11-30 14:00 - 2012-11-30 14:00 - 00000000 ____D C:\Windows\System32\Macromed

2012-11-30 13:55 - 2012-11-30 13:55 - 00000000 ____D C:\Users\All Users\PCSettings

2012-11-30 13:48 - 2012-12-15 22:05 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\WeatherBug

2012-11-30 13:46 - 2012-11-30 13:46 - 00001732 ____A C:\Users\nebraskarain\Desktop\WeatherBug.lnk

2012-11-30 13:46 - 2012-11-30 13:46 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\WeatherBug

2012-11-30 13:46 - 2012-11-30 13:46 - 00000000 ____D C:\Program Files (x86)\AWS

2012-11-30 13:44 - 2012-11-30 13:45 - 03059712 ____A C:\Users\nebraskarain\Downloads\WeatherBugSetup.msi

2012-11-30 13:11 - 2012-11-30 13:12 - 06257640 ____A (Symantec Corporation) C:\Users\nebraskarain\Downloads\NRnR.exe

2012-11-30 13:08 - 2012-11-30 13:08 - 00000000 ____D C:\Windows\System32\Drivers\N360x64

2012-11-30 12:45 - 2012-12-17 13:40 - 00001309 ____A C:\Users\nebraskarain\Desktop\Norton Installation Files.lnk

2012-11-30 12:45 - 2012-12-17 13:40 - 00000000 ____D C:\Users\All Users\Norton

2012-11-30 12:45 - 2012-11-30 12:45 - 00915464 ____A (Symantec Corporation) C:\Users\nebraskarain\Downloads\N360Downloader.exe

2012-11-30 12:45 - 2012-11-30 12:45 - 00000000 ____D C:\Users\Public\Downloads\Norton

2012-11-30 12:35 - 2012-12-05 05:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

2012-11-30 12:35 - 2012-11-30 12:35 - 00001153 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk

2012-11-30 12:35 - 2012-11-30 12:35 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\Mozilla

2012-11-30 12:35 - 2012-11-30 12:35 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\Mozilla

2012-11-30 12:35 - 2012-11-30 12:35 - 00000000 ____D C:\Users\All Users\Mozilla

2012-11-30 12:32 - 2012-11-30 12:32 - 00001115 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

2012-11-30 12:32 - 2012-11-30 12:32 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\Malwarebytes

2012-11-30 12:32 - 2012-11-30 12:32 - 00000000 ____D C:\Users\All Users\Malwarebytes

2012-11-30 12:32 - 2012-11-30 12:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware

2012-11-30 12:32 - 2012-09-29 17:54 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys

2012-11-30 12:27 - 2012-12-05 21:20 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\Adobe

2012-11-30 12:27 - 2012-11-30 12:27 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\Macromedia

2012-11-30 12:26 - 2012-11-30 12:26 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\Roxio

2012-11-30 12:26 - 2012-11-30 12:26 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\Leadertech

2012-11-30 12:26 - 2012-11-30 12:26 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\Intel Corporation

2012-11-30 12:26 - 2012-11-30 12:26 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\VirtualStore

2012-11-30 12:23 - 2012-02-14 22:27 - 01031680 ____A (Microsoft Corporation) C:\Windows\System32\rdpcore.dll

2012-11-30 12:23 - 2012-02-14 21:44 - 00826368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll

2012-11-30 12:23 - 2012-02-14 20:46 - 00023552 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tdtcp.sys

2012-11-30 12:18 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll

2012-11-30 12:18 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll

2012-11-30 12:18 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe

2012-11-30 12:18 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll

2012-11-30 12:18 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll

2012-11-30 12:18 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll

2012-11-30 12:18 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll

2012-11-30 12:18 - 2012-06-02 13:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll

2012-11-30 12:18 - 2012-06-02 13:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe

2012-11-30 12:17 - 2012-12-09 12:20 - 00086160 ____A C:\Users\nebraskarain\AppData\Local\GDIPFONTCACHEV1.DAT

2012-11-30 12:17 - 2012-11-30 12:26 - 00000000 ____D C:\users\nebraskarain

2012-11-30 12:17 - 2012-11-30 12:17 - 00000020 ___SH C:\Users\nebraskarain\ntuser.ini

==================== One Month Modified Files and Folders =======

2012-12-20 16:02 - 2012-12-20 16:02 - 00000000 ____D C:\FRST

2012-12-20 14:01 - 2010-12-12 20:49 - 01605714 ____A C:\Windows\WindowsUpdate.log

2012-12-20 14:01 - 2009-07-13 20:45 - 00013872 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2012-12-20 14:01 - 2009-07-13 20:45 - 00013872 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2012-12-20 13:56 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT

2012-12-20 13:56 - 2009-07-13 20:51 - 00041817 ____A C:\Windows\setupact.log

2012-12-20 13:19 - 2009-07-13 21:13 - 00727182 ____A C:\Windows\System32\PerfStringBackup.INI

2012-12-20 13:10 - 2012-12-20 13:10 - 01461035 ____A (Farbar) C:\Users\nebraskarain\Documents\FRST64.exe

2012-12-20 12:30 - 2012-12-20 12:30 - 00060260 ____A C:\Users\nebraskarain\Desktop\Extras.Txt

2012-12-20 12:29 - 2012-12-20 12:29 - 00103848 ____A C:\Users\nebraskarain\Desktop\OTL.Txt

2012-12-20 12:17 - 2012-12-20 12:17 - 00602112 ____A (OldTimer Tools) C:\Users\nebraskarain\Desktop\OTL.exe

2012-12-20 11:34 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache

2012-12-19 03:45 - 2010-12-12 21:49 - 00137708 ____A C:\Windows\PFRO.log

2012-12-18 12:40 - 2012-12-18 12:40 - 00023988 ____A C:\Users\nebraskarain\Desktop\combolist2a.txt

2012-12-18 12:38 - 2012-12-18 12:38 - 00023988 ____A C:\Users\nebraskarain\Desktop\combolist2.txt

2012-12-18 12:37 - 2012-12-18 12:37 - 00023988 ____A C:\ComboFix.txt

2012-12-18 12:37 - 2012-12-18 08:49 - 00000000 ____D C:\Qoobox

2012-12-18 12:17 - 2009-07-13 18:34 - 00000215 ____A C:\Windows\system.ini

2012-12-18 09:01 - 2009-07-13 19:20 - 00000000 __RHD C:\users\Default

2012-12-18 08:59 - 2012-12-18 08:49 - 00000000 ____D C:\Windows\erdnt

2012-12-18 08:49 - 2012-12-18 08:51 - 05012571 ____R (Swearware) C:\Users\nebraskarain\Desktop\ComboFix.exe

2012-12-18 08:49 - 2012-12-18 08:48 - 05012571 ____R (Swearware) C:\Users\nebraskarain\Downloads\ComboFix.exe

2012-12-17 20:21 - 2012-12-17 20:21 - 00000000 ____D C:\TDSSKiller_Quarantine

2012-12-17 14:59 - 2012-12-17 14:58 - 02213976 ____A (Kaspersky Lab ZAO) C:\Users\nebraskarain\Downloads\tdsskiller.exe

2012-12-17 14:23 - 2012-12-17 14:23 - 00688992 ____R (Swearware) C:\Users\nebraskarain\Desktop\dds.scr

2012-12-17 13:40 - 2012-12-17 13:38 - 00915464 ____A (Symantec Corporation) C:\Users\nebraskarain\Downloads\N360Downloader(1).exe

2012-12-17 13:40 - 2012-11-30 12:45 - 00001309 ____A C:\Users\nebraskarain\Desktop\Norton Installation Files.lnk

2012-12-17 13:40 - 2012-11-30 12:45 - 00000000 ____D C:\Users\All Users\Norton

2012-12-17 11:00 - 2012-12-16 08:13 - 00000000 ____D C:\Users\All Users\AVAST Software

2012-12-16 17:36 - 2009-07-13 21:08 - 00032596 ____A C:\Windows\Tasks\SCHEDLGU.TXT

2012-12-16 09:23 - 2012-12-16 08:16 - 00000000 ____D C:\Program Files (x86)\Google

2012-12-16 08:42 - 2012-12-16 08:16 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\Google

2012-12-16 08:16 - 2012-12-16 08:16 - 00000000 ____A C:\Windows\SysWOW64\config.nt

2012-12-16 08:13 - 2012-12-16 08:13 - 00000000 ____D C:\Program Files\AVAST Software

2012-12-16 08:06 - 2012-12-16 07:54 - 97495576 ____A C:\Users\nebraskarain\Downloads\avast_free_antivirus_setup.exe

2012-12-15 22:05 - 2012-11-30 13:48 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\WeatherBug

2012-12-15 21:07 - 2012-12-15 21:07 - 00000000 ____A C:\Windows\SysWOW64\shoBCFA.tmp

2012-12-15 17:44 - 2012-12-15 17:44 - 00695296 ____A (AnjoCaido) C:\Users\nebraskarain\Desktop\Minecraft.exe

2012-12-15 07:05 - 2012-12-15 07:05 - 00000000 ____D C:\Windows\Sun

2012-12-12 06:56 - 2009-07-13 20:45 - 00342688 ____A C:\Windows\System32\FNTCACHE.DAT

2012-12-12 06:52 - 2012-12-09 07:36 - 00000000 ____D C:\Users\All Users\Microsoft Help

2012-12-09 12:20 - 2012-11-30 12:17 - 00086160 ____A C:\Users\nebraskarain\AppData\Local\GDIPFONTCACHEV1.DAT

2012-12-09 08:36 - 2012-12-09 08:36 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help

2012-12-09 08:36 - 2012-12-09 08:36 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help

2012-12-09 08:33 - 2012-11-30 16:52 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\SoftGrid Client

2012-12-09 07:42 - 2012-12-09 07:42 - 00003021 ____A C:\Users\nebraskarain\Desktop\Microsoft Word 2010.lnk

2012-12-09 07:41 - 2010-12-12 21:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Office

2012-12-09 07:38 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared

2012-12-09 07:37 - 2012-12-09 07:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services

2012-12-09 07:37 - 2010-12-12 22:41 - 00000000 ____D C:\Windows\ShellNew

2012-12-09 07:36 - 2012-12-09 07:36 - 00000000 ___RD C:\MSOCache

2012-12-09 07:36 - 2012-12-09 07:36 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\Microsoft Help

2012-12-09 07:24 - 2012-12-09 07:24 - 00001807 ____A C:\Users\nebraskarain\Desktop\Office Home and Student 2010_1355066645105.lnk

2012-12-09 07:24 - 2012-12-08 21:08 - 987942848 ____A (Microsoft Corporation) C:\Users\nebraskarain\Downloads\X17-75058.exe

2012-12-08 21:12 - 2012-12-08 21:12 - 00002058 ____A C:\Users\nebraskarain\Desktop\Microsoft Download Manager_1355029939765.lnk

2012-12-08 21:08 - 2012-12-08 21:08 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\MicrosoftStore

2012-12-08 21:07 - 2012-12-08 21:07 - 02572752 ____A (Solid State Networks) C:\Users\nebraskarain\Downloads\4e75f434510343168fe2642ba767e276_Pod7_en-us(1).exe

2012-12-08 21:05 - 2012-12-08 20:54 - 02463516 ____A C:\Users\nebraskarain\Downloads\WinOffice2010-64-SL.exe.part

2012-12-08 21:03 - 2012-12-08 21:01 - 02572752 ____A (Solid State Networks) C:\Users\nebraskarain\Downloads\4e75f434510343168fe2642ba767e276_Pod7_en-us.exe

2012-12-08 16:45 - 2012-12-08 16:45 - 00279144 ____A C:\Windows\Minidump\120812-29671-01.dmp

2012-12-08 16:45 - 2012-12-08 16:45 - 00000000 ____D C:\Windows\Minidump

2012-12-08 16:44 - 2012-12-08 16:44 - 480341390 ____A C:\Windows\MEMORY.DMP

2012-12-05 21:20 - 2012-12-05 21:20 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\Adobe

2012-12-05 21:20 - 2012-11-30 12:27 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\Adobe

2012-12-05 05:09 - 2012-11-30 12:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

2012-12-04 16:48 - 2012-12-04 16:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

2012-12-02 11:07 - 2012-12-02 11:05 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\.minecraft

2012-12-02 11:05 - 2012-12-02 11:05 - 00000000 ____D C:\Users\All Users\Sun

2012-12-02 11:04 - 2012-12-02 11:04 - 00821736 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll

2012-12-02 11:04 - 2012-12-02 11:04 - 00746984 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll

2012-12-02 11:04 - 2012-12-02 11:04 - 00246760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe

2012-12-02 11:04 - 2012-12-02 11:04 - 00174056 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe

2012-12-02 11:04 - 2012-12-02 11:04 - 00174056 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe

2012-12-02 11:04 - 2012-12-02 11:04 - 00095208 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll

2012-12-02 11:04 - 2012-12-02 11:04 - 00000000 ____D C:\Program Files (x86)\Java

2012-12-02 11:01 - 2010-12-12 21:44 - 00000000 ____D C:\Users\All Users\McAfee

2012-12-02 10:54 - 2012-12-02 10:54 - 00895464 ____A (Oracle Corporation) C:\Users\nebraskarain\Downloads\jxpiinstall.exe

2012-12-02 06:01 - 2012-12-02 06:01 - 00000000 ____A C:\Windows\SysWOW64\shoBFD6.tmp

2012-12-01 11:46 - 2012-11-30 20:46 - 00000000 ____D C:\Users\All Users\VirtualizedApplications

2012-12-01 11:10 - 2010-12-12 21:27 - 00000000 ____D C:\Program Files (x86)\Windows Live

2012-12-01 11:02 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\PolicyDefinitions

2012-12-01 11:02 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\System

2012-12-01 11:01 - 2010-12-12 22:41 - 00000000 ____D C:\Program Files\Windows Journal

2012-12-01 09:44 - 2012-12-01 09:44 - 00000000 ____A C:\Windows\SysWOW64\sho62BD.tmp

2012-12-01 08:28 - 2012-12-01 08:20 - 00003625 ____A C:\Windows\IE9_main.log

2012-12-01 08:27 - 2012-12-01 08:27 - 03695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat

2012-12-01 08:27 - 2012-12-01 08:27 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat

2012-12-01 08:27 - 2012-12-01 08:27 - 00534528 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00452608 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00448512 ____A (Microsoft Corporation) C:\Windows\System32\html.iec

2012-12-01 08:27 - 2012-12-01 08:27 - 00434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00403248 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec

2012-12-01 08:27 - 2012-12-01 08:27 - 00353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00282112 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00267776 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00249344 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00165888 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00145920 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00135168 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00114176 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00111616 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00091648 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx

2012-12-01 08:27 - 2012-12-01 08:27 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx

2012-12-01 08:27 - 2012-12-01 08:27 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00049664 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll

2012-12-01 08:27 - 2012-12-01 08:27 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe

2012-12-01 08:27 - 2012-12-01 08:27 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe

2012-12-01 08:15 - 2012-11-30 16:51 - 00731106 ____A C:\Windows\SysWOW64\PerfStringBackup.INI

2012-12-01 08:15 - 2012-11-30 16:50 - 00000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client

2012-12-01 08:06 - 2010-12-12 21:30 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight

2012-11-30 16:53 - 2012-11-30 16:50 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\TP

2012-11-30 16:52 - 2012-11-30 16:52 - 00002463 ____A C:\Users\nebraskarain\Desktop\Microsoft Word Starter 2010.lnk

2012-11-30 16:52 - 2012-11-30 16:52 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\SoftGrid Client

2012-11-30 16:50 - 2012-11-30 16:50 - 00000000 ____D C:\Program Files\Microsoft Office

2012-11-30 14:09 - 2012-11-30 14:09 - 00177312 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS

2012-11-30 14:09 - 2012-11-30 14:09 - 00007466 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT

2012-11-30 14:09 - 2012-11-30 14:09 - 00002397 ____A C:\Users\Public\Desktop\Norton 360.lnk

2012-11-30 14:09 - 2012-11-30 14:09 - 00000000 ____D C:\Program Files\Symantec

2012-11-30 14:09 - 2012-11-30 14:09 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared

2012-11-30 14:09 - 2012-11-30 14:09 - 00000000 ____D C:\Program Files (x86)\Norton 360

2012-11-30 14:01 - 2012-11-30 14:01 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\Macromedia

2012-11-30 14:01 - 2010-12-12 21:36 - 00000000 ____D C:\Users\All Users\Adobe

2012-11-30 14:00 - 2012-11-30 14:00 - 00697272 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2012-11-30 14:00 - 2012-11-30 14:00 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

2012-11-30 14:00 - 2012-11-30 14:00 - 00000000 ____D C:\Windows\System32\Macromed

2012-11-30 13:55 - 2012-11-30 13:55 - 00000000 ____D C:\Users\All Users\PCSettings

2012-11-30 13:46 - 2012-11-30 13:46 - 00001732 ____A C:\Users\nebraskarain\Desktop\WeatherBug.lnk

2012-11-30 13:46 - 2012-11-30 13:46 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\WeatherBug

2012-11-30 13:46 - 2012-11-30 13:46 - 00000000 ____D C:\Program Files (x86)\AWS

2012-11-30 13:45 - 2012-11-30 13:44 - 03059712 ____A C:\Users\nebraskarain\Downloads\WeatherBugSetup.msi

2012-11-30 13:12 - 2012-11-30 13:11 - 06257640 ____A (Symantec Corporation) C:\Users\nebraskarain\Downloads\NRnR.exe

2012-11-30 13:08 - 2012-11-30 13:08 - 00000000 ____D C:\Windows\System32\Drivers\N360x64

2012-11-30 12:45 - 2012-11-30 12:45 - 00915464 ____A (Symantec Corporation) C:\Users\nebraskarain\Downloads\N360Downloader.exe

2012-11-30 12:45 - 2012-11-30 12:45 - 00000000 ____D C:\Users\Public\Downloads\Norton

2012-11-30 12:35 - 2012-11-30 12:35 - 00001153 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk

2012-11-30 12:35 - 2012-11-30 12:35 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\Mozilla

2012-11-30 12:35 - 2012-11-30 12:35 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\Mozilla

2012-11-30 12:35 - 2012-11-30 12:35 - 00000000 ____D C:\Users\All Users\Mozilla

2012-11-30 12:32 - 2012-11-30 12:32 - 00001115 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

2012-11-30 12:32 - 2012-11-30 12:32 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\Malwarebytes

2012-11-30 12:32 - 2012-11-30 12:32 - 00000000 ____D C:\Users\All Users\Malwarebytes

2012-11-30 12:32 - 2012-11-30 12:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware

2012-11-30 12:27 - 2012-11-30 12:27 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\Macromedia

2012-11-30 12:26 - 2012-11-30 12:26 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\Roxio

2012-11-30 12:26 - 2012-11-30 12:26 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\Leadertech

2012-11-30 12:26 - 2012-11-30 12:26 - 00000000 ____D C:\Users\nebraskarain\AppData\Roaming\Intel Corporation

2012-11-30 12:26 - 2012-11-30 12:26 - 00000000 ____D C:\Users\nebraskarain\AppData\Local\VirtualStore

2012-11-30 12:26 - 2012-11-30 12:17 - 00000000 ____D C:\users\nebraskarain

2012-11-30 12:26 - 2010-12-12 22:25 - 00000000 ___AD C:\Windows\WisTools

2012-11-30 12:18 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\System32\restore

2012-11-30 12:17 - 2012-11-30 12:17 - 00000020 ___SH C:\Users\nebraskarain\ntuser.ini

2012-11-30 12:17 - 2009-07-13 19:20 - 00000000 __RHD C:\Users\Public\Libraries

2012-11-30 12:14 - 2010-12-13 00:05 - 00000000 ____D C:\Dell

2012-11-22 00:20 - 2012-12-12 03:33 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys

==================== Known DLLs (Whitelisted) =================

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\SysWOW64\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\SysWOW64\explorer.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\SysWOW64\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\SysWOW64\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\SysWOW64\userinit.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys

[2012-12-12 03:32] - [2012-09-06 09:38] - 0295792 ____A (Microsoft Corporation) 9E425AC5C9A5A973273D169F43B4F5E1

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK

HKLM\...\exefile\DefaultIcon: %1 => OK

HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

Restore point made on: 2012-12-13 17:26:32

Restore point made on: 2012-12-14 01:00:42

Restore point made on: 2012-12-14 08:17:32

Restore point made on: 2012-12-14 10:43:31

Restore point made on: 2012-12-14 14:13:37

Restore point made on: 2012-12-14 19:32:33

Restore point made on: 2012-12-15 06:08:31

Restore point made on: 2012-12-15 09:22:07

Restore point made on: 2012-12-15 11:25:17

Restore point made on: 2012-12-15 21:07:03

Restore point made on: 2012-12-15 22:56:04

Restore point made on: 2012-12-16 08:13:41

Restore point made on: 2012-12-16 19:04:01

Restore point made on: 2012-12-16 21:04:06

Restore point made on: 2012-12-17 07:12:23

Restore point made on: 2012-12-17 10:14:40

Restore point made on: 2012-12-17 10:58:32

Restore point made on: 2012-12-17 11:27:55

Restore point made on: 2012-12-17 12:11:30

Restore point made on: 2012-12-17 21:08:36

==================== Memory info ===========================

Percentage of memory in use: 17%

Total physical RAM: 3894.7 MB

Available physical RAM: 3219.88 MB

Total Pagefile: 3892.85 MB

Available Pagefile: 3206.36 MB

Total Virtual: 8192 MB

Available Virtual: 8191.9 MB

==================== Partitions =============================

1 Drive c: (OS) (Fixed) (Total:283.34 GB) (Free:236.06 GB) NTFS ==>[system with boot components (obtained from reading drive)]

3 Drive f: () (Removable) (Total:1.86 GB) (Free:0.04 GB) FAT

4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

5 Drive y: (Recovery) (Fixed) (Total:14.65 GB) (Free:7.87 GB) NTFS ==>[system with boot components (obtained from reading drive)]

Disk ### Status Size Free Dyn Gpt

-------- ------------- ------- ------- --- ---

Disk 0 Online 298 GB 0 B

Disk 1 Online 1907 MB 0 B

Partitions of Disk 0:

===============

Partition ### Type Size Offset

------------- ---------------- ------- -------

Partition 1 OEM 100 MB 1024 KB

Partition 2 Primary 14 GB 101 MB

Partition 3 Primary 283 GB 14 GB

==================================================================================

Disk: 0

Partition 1

Type : DE

Hidden: Yes

Active: No

Volume ### Ltr Label Fs Type Size Status Info

---------- --- ----------- ----- ---------- ------- --------- --------

* Volume 4 DELLUTILITY FAT Partition 100 MB Healthy Hidden

=========================================================

Disk: 0

Partition 2

Type : 07

Hidden: No

Active: Yes

Volume ### Ltr Label Fs Type Size Status Info

---------- --- ----------- ----- ---------- ------- --------- --------

* Volume 1 Y Recovery NTFS Partition 14 GB Healthy

=========================================================

Disk: 0

Partition 3

Type : 07

Hidden: No

Active: No

Volume ### Ltr Label Fs Type Size Status Info

---------- --- ----------- ----- ---------- ------- --------- --------

* Volume 2 C OS NTFS Partition 283 GB Healthy

=========================================================

Partitions of Disk 1:

===============

Partition ### Type Size Offset

------------- ---------------- ------- -------

Partition 1 Primary 1907 MB 64 KB

==================================================================================

Disk: 1

Partition 1

Type : 06

Hidden: No

Active: No

Volume ### Ltr Label Fs Type Size Status Info

---------- --- ----------- ----- ---------- ------- --------- --------

* Volume 3 F FAT Removable 1907 MB Healthy

=========================================================

Last Boot: 2012-12-18 08:40

==================== End Of Log =======================

Link to post
Share on other sites

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt


C:\Windows\SysWOW64\shoBCFA.tmp
C:\Windows\SysWOW64\shoBFD6.tmp
C:\Windows\SysWOW64\sho62BD.tmp

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.

Run FRST/FRST64 and press the Fix button just once and wait.

The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

----------

Post the new log and let me know exactly how your system is running now. :)

Link to post
Share on other sites

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-12-2012

Ran by SYSTEM at 2012-12-20 20:55:21 Run:1

Running from F:\

==============================================

C:\Windows\SysWOW64\shoBCFA.tmp moved successfully.

C:\Windows\SysWOW64\shoBFD6.tmp moved successfully.

C:\Windows\SysWOW64\sho62BD.tmp moved successfully.

==== End of Fixlog ====

Link to post
Share on other sites

Reinstalled and working!! Thank you again!!!
Great!

I see that your Java software is out of date. Please go to Start >> Control Panel >> Programs and Features >> uninstall all versions of Java.

Now download and install the newest version from here >> http://java.com/en/download/index.jsp

-------------

Clear Java Cache

See this page for instructions on how to clear java's cache.

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)

  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked

    • Downloaded Applets
      Downloaded Applications
      Other Files

    [*]Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.

    [*]Click OK to leave the Java Control Panel.

----------

Malwarebytes

Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.

----------

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator

  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file..."
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.

----------

Link to post
Share on other sites

Malwarebytes Anti-Malware 1.65.1.1000

www.malwarebytes.org

Database version: v2012.12.21.17

Windows 7 x64 NTFS

Internet Explorer 9.0.8112.16421

nebraskarain :: NEBRASKARAIN-PC [administrator]

12/21/2012 4:54:15 PM

mbam-log-2012-12-21 (16-54-15).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 208694

Time elapsed: 3 minute(s), 1 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

Link to post
Share on other sites

C:\TDSSKiller_Quarantine\17.12.2012_22.20.22\mbr0000\tdlfs0000\tsk0000.dta a variant of Win32/Olmarik.AYI trojan unable to clean

C:\TDSSKiller_Quarantine\17.12.2012_22.20.22\mbr0000\tdlfs0000\tsk0001.dta a variant of Win64/Olmarik.AM trojan unable to clean

C:\TDSSKiller_Quarantine\17.12.2012_22.20.22\mbr0000\tdlfs0000\tsk0003.dta Win64/Olmarik.AN trojan unable to clean

C:\TDSSKiller_Quarantine\17.12.2012_22.20.22\mbr0000\tdlfs0000\tsk0007.dta Win32/Olmarik.AFK trojan unable to clean

C:\TDSSKiller_Quarantine\17.12.2012_22.20.22\mbr0000\tdlfs0000\tsk0008.dta Win64/Olmarik.AK trojan unable to clean

C:\TDSSKiller_Quarantine\17.12.2012_22.20.22\mbr0000\tdlfs0000\tsk0002.dta Win32/Olmarik.AWO trojan cleaned by deleting - quarantined

Link to post
Share on other sites

Now my system is running very slow and is freezing so I have to restart a lot
Nothing has been removed since last you posted so I am not sure what happened? The entries found by ESET were already quarantined so those aren't a problem.

Please delete the current version of Combofix.exe from your desktop and download a new version from here to your desktop.

Disable your AntiVirus and AntiSpyware applications.

Right-click and Run as Administrator on the Combofix.exe and follow the prombts on your display. When finish, it will create a C:\Combofix.txt. Please post this log for further review.

---------

Link to post
Share on other sites

ComboFix 12-12-17.02 - nebraskarain 12/18/2012 14:05:43.2.2 - x64

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3895.2678 [GMT -6:00]

Running from: c:\users\nebraskarain\Desktop\ComboFix.exe

Command switches used :: c:\users\nebraskarain\Desktop\CFScript.txt

AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

SP: Norton 360 *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((( Files Created from 2012-11-18 to 2012-12-18 )))))))))))))))))))))))))))))))

.

.

2012-12-18 20:17 . 2012-12-18 20:17 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-12-18 04:21 . 2012-12-18 04:21 -------- d-----w- C:\TDSSKiller_Quarantine

2012-12-16 16:16 . 2012-12-16 17:23 -------- d-----w- c:\program files (x86)\Google

2012-12-16 16:16 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe

2012-12-16 16:13 . 2012-12-17 19:00 -------- d-----w- c:\programdata\AVAST Software

2012-12-16 16:13 . 2012-12-16 16:13 -------- d-----w- c:\program files\AVAST Software

2012-12-16 05:07 . 2012-12-16 05:07 0 ----a-w- c:\windows\SysWow64\shoBCFA.tmp

2012-12-15 15:05 . 2012-12-15 15:05 -------- d-----w- c:\windows\Sun

2012-12-12 11:33 . 2012-11-09 05:34 2048 ----a-w- c:\windows\system32\tzres.dll

2012-12-12 11:33 . 2012-11-09 04:49 2048 ----a-w- c:\windows\SysWow64\tzres.dll

2012-12-12 11:33 . 2012-11-22 08:20 3147264 ----a-w- c:\windows\system32\win32k.sys

2012-12-09 16:36 . 2012-12-09 16:36 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help

2012-12-09 15:37 . 2012-12-09 15:37 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services

2012-12-09 15:36 . 2012-12-12 14:52 -------- d-----w- c:\programdata\Microsoft Help

2012-12-09 15:36 . 2012-12-09 15:36 -------- d-----r- C:\MSOCache

2012-12-02 19:05 . 2012-12-02 19:05 -------- d-----w- c:\program files (x86)\Common Files\Java

2012-12-02 19:04 . 2012-12-02 19:04 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-12-02 19:04 . 2012-12-02 19:04 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-12-02 19:04 . 2012-12-02 19:04 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2012-12-02 19:04 . 2012-12-02 19:04 -------- d-----w- c:\program files (x86)\Java

2012-12-02 14:01 . 2012-12-02 14:01 0 ----a-w- c:\windows\SysWow64\shoBFD6.tmp

2012-12-02 13:55 . 2012-12-09 15:41 -------- d-----w- c:\program files (x86)\Microsoft.NET

2012-12-01 19:01 . 2012-12-01 19:01 -------- d-----w- c:\windows\SysWow64\Wat

2012-12-01 19:01 . 2012-12-01 19:01 -------- d-----w- c:\windows\system32\Wat

2012-12-01 17:44 . 2012-12-01 17:44 0 ----a-w- c:\windows\SysWow64\sho62BD.tmp

2012-12-01 17:34 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll

2012-12-01 17:34 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll

2012-12-01 16:48 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys

2012-12-01 16:48 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys

2012-12-01 16:48 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui

2012-12-01 16:48 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll

2012-12-01 16:31 . 2009-11-25 18:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll

2012-12-01 16:31 . 2009-11-25 18:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll

2012-12-01 16:31 . 2009-11-25 18:47 48960 ----a-w- c:\windows\system32\netfxperf.dll

2012-12-01 16:31 . 2009-11-25 18:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll

2012-12-01 16:31 . 2009-11-25 18:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe

2012-12-01 16:31 . 2009-11-25 18:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll

2012-12-01 16:31 . 2009-11-25 18:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll

2012-12-01 16:31 . 2009-11-25 18:47 444752 ----a-w- c:\windows\system32\mscoree.dll

2012-12-01 16:31 . 2009-11-25 18:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe

2012-12-01 16:31 . 2009-11-25 18:47 1942856 ----a-w- c:\windows\system32\dfshim.dll

2012-12-01 16:12 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys

2012-12-01 16:12 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys

2012-12-01 16:12 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll

2012-12-01 16:12 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll

2012-12-01 16:12 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe

2012-12-01 16:12 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll

2012-12-01 16:12 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll

2012-12-01 16:08 . 2012-03-01 06:54 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys

2012-12-01 16:08 . 2012-03-01 06:40 80896 ----a-w- c:\windows\system32\imagehlp.dll

2012-12-01 16:08 . 2012-03-01 06:35 5120 ----a-w- c:\windows\system32\wmi.dll

2012-12-01 16:08 . 2012-03-01 05:45 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll

2012-12-01 16:08 . 2012-03-01 05:40 5120 ----a-w- c:\windows\SysWow64\wmi.dll

2012-12-01 13:36 . 2011-10-01 05:28 886784 ----a-w- c:\program files\Common Files\System\wab32.dll

2012-12-01 13:36 . 2011-10-01 04:43 708608 ----a-w- c:\program files (x86)\Common Files\System\wab32.dll

2012-12-01 13:35 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe

2012-12-01 13:35 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe

2012-12-01 13:35 . 2011-02-26 06:23 2870272 ----a-w- c:\windows\explorer.exe

2012-12-01 13:35 . 2011-02-26 05:33 2614784 ----a-w- c:\windows\SysWow64\explorer.exe

2012-12-01 13:35 . 2010-12-23 06:07 961024 ----a-w- c:\windows\system32\CPFilters.dll

2012-12-01 13:35 . 2010-12-23 05:28 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll

2012-12-01 13:35 . 2010-12-23 06:07 1118720 ----a-w- c:\windows\system32\sbe.dll

2012-12-01 13:35 . 2010-12-23 06:02 259072 ----a-w- c:\windows\system32\mpg2splt.ax

2012-12-01 13:35 . 2010-12-23 05:28 850432 ----a-w- c:\windows\SysWow64\sbe.dll

2012-12-01 13:35 . 2010-12-23 05:24 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax

2012-12-01 13:35 . 2010-08-26 05:27 148992 ----a-w- c:\windows\system32\t2embed.dll

2012-12-01 13:35 . 2010-08-26 04:39 109056 ----a-w- c:\windows\SysWow64\t2embed.dll

2012-12-01 13:33 . 2011-10-26 05:22 1572864 ----a-w- c:\windows\system32\quartz.dll

2012-12-01 13:33 . 2011-10-26 04:28 1328640 ----a-w- c:\windows\SysWow64\quartz.dll

2012-12-01 13:33 . 2011-10-26 05:33 366592 ----a-w- c:\windows\system32\qdvd.dll

2012-12-01 13:33 . 2011-10-26 04:33 514560 ----a-w- c:\windows\SysWow64\qdvd.dll

2012-12-01 13:33 . 2012-01-04 09:58 509952 ----a-w- c:\windows\system32\ntshrui.dll

2012-12-01 13:33 . 2012-01-04 09:03 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll

2012-12-01 13:31 . 2011-11-17 07:12 395776 ----a-w- c:\windows\system32\webio.dll

2012-12-01 13:31 . 2011-11-17 05:39 314368 ----a-w- c:\windows\SysWow64\webio.dll

2012-12-01 13:31 . 2012-06-06 05:50 2003968 ----a-w- c:\windows\system32\msxml6.dll

2012-12-01 13:31 . 2012-06-06 05:50 1880064 ----a-w- c:\windows\system32\msxml3.dll

2012-12-01 13:31 . 2012-06-06 05:09 1389568 ----a-w- c:\windows\SysWow64\msxml6.dll

2012-12-01 13:31 . 2012-06-06 05:09 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll

2012-12-01 13:29 . 2011-10-26 05:19 43520 ----a-w- c:\windows\system32\csrsrv.dll

2012-12-01 13:29 . 2012-01-03 06:24 515584 ----a-w- c:\windows\system32\timedate.cpl

2012-12-01 13:29 . 2012-01-03 05:44 478208 ----a-w- c:\windows\SysWow64\timedate.cpl

2012-12-01 13:29 . 2011-02-24 06:30 476160 ----a-w- c:\windows\system32\XpsGdiConverter.dll

2012-12-01 13:29 . 2011-02-24 05:32 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll

2012-12-01 13:29 . 2010-08-21 06:31 633856 ----a-w- c:\windows\system32\comctl32.dll

2012-12-01 13:29 . 2010-08-21 05:33 530432 ----a-w- c:\windows\SysWow64\comctl32.dll

2012-12-01 13:29 . 2012-08-30 18:10 5473136 ----a-w- c:\windows\system32\ntoskrnl.exe

2012-12-01 13:29 . 2012-08-30 18:11 3971440 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

2012-12-01 13:29 . 2012-08-30 18:11 3915632 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

2012-12-01 13:27 . 2012-08-02 17:55 574464 ----a-w- c:\windows\system32\d3d10level9.dll

2012-12-01 13:26 . 2010-05-23 08:37 1888256 ----a-w- c:\windows\system32\WMVDECOD.DLL

2012-12-01 13:25 . 2011-04-22 20:18 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys

2012-12-01 13:25 . 2009-09-26 06:20 223448 ----a-w- c:\windows\system32\drivers\fvevol.sys

2012-12-01 13:25 . 2012-05-02 05:32 208896 ----a-w- c:\windows\system32\profsvc.dll

2012-12-01 13:25 . 2011-03-03 06:17 182272 ----a-w- c:\windows\system32\dnsrslvr.dll

2012-12-01 13:25 . 2011-03-03 06:17 356352 ----a-w- c:\windows\system32\dnsapi.dll

2012-12-01 13:25 . 2011-03-03 06:14 30208 ----a-w- c:\windows\system32\dnscacheugc.exe

2012-12-01 13:25 . 2011-03-03 05:27 28672 ----a-w- c:\windows\SysWow64\dnscacheugc.exe

2012-12-01 13:24 . 2010-08-21 06:38 1024512 ----a-w- c:\windows\system32\wmpmde.dll

2012-12-01 13:24 . 2010-08-21 05:36 738816 ----a-w- c:\windows\SysWow64\wmpmde.dll

2012-12-01 13:24 . 2012-08-24 18:05 220160 ----a-w- c:\windows\system32\wintrust.dll

2012-12-01 13:24 . 2012-08-24 17:10 172544 ----a-w- c:\windows\SysWow64\wintrust.dll

2012-12-01 13:22 . 2012-04-28 03:50 204800 ----a-w- c:\windows\system32\drivers\rdpwd.sys

2012-12-01 13:21 . 2011-05-24 11:21 404992 ----a-w- c:\windows\system32\umpnpmgr.dll

2012-12-01 13:21 . 2011-05-24 10:34 64512 ----a-w- c:\windows\SysWow64\devobj.dll

2012-12-01 13:21 . 2011-05-24 10:34 44544 ----a-w- c:\windows\SysWow64\devrtl.dll

2012-12-01 13:21 . 2011-05-24 10:34 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll

2012-12-01 13:21 . 2011-05-24 10:32 252928 ----a-w- c:\windows\SysWow64\drvinst.exe

2012-12-01 13:19 . 2012-06-06 05:50 1425408 ----a-w- c:\program files\Common Files\System\ado\msado15.dll

2012-12-01 13:18 . 2011-11-19 15:07 77312 ----a-w- c:\windows\system32\packager.dll

2012-12-01 13:18 . 2011-11-19 14:06 67072 ----a-w- c:\windows\SysWow64\packager.dll

2012-12-01 04:46 . 2012-12-01 19:46 -------- d-----w- c:\programdata\VirtualizedApplications

2012-12-01 00:50 . 2012-12-01 16:15 -------- d-----w- c:\program files (x86)\Microsoft Application Virtualization Client

2012-12-01 00:50 . 2012-12-01 00:50 -------- d-----w- c:\program files\Microsoft Office

2012-12-01 00:05 . 2012-12-01 00:05 -------- d-----w- c:\program files (x86)\Common Files\Symantec Shared

2012-11-30 22:09 . 2012-11-30 22:09 177312 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS

2012-11-30 22:09 . 2012-11-30 22:09 -------- d-----w- c:\program files\Symantec

2012-11-30 22:09 . 2012-11-30 22:09 -------- d-----w- c:\program files\Common Files\Symantec Shared

2012-11-30 22:09 . 2012-11-30 22:09 -------- d-----w- c:\program files (x86)\Norton 360

2012-11-30 22:09 . 2012-11-30 22:09 -------- d-----w- c:\program files (x86)\NortonInstaller

2012-11-30 22:00 . 2012-11-30 22:00 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-11-30 22:00 . 2012-11-30 22:00 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-11-30 22:00 . 2012-11-30 22:00 -------- d-----w- c:\windows\system32\Macromed

2012-11-30 21:55 . 2012-11-30 21:55 -------- d-----w- c:\programdata\PCSettings

2012-11-30 21:46 . 2012-11-30 21:46 -------- d-----w- c:\program files (x86)\AWS

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-10-16 21:20 . 2012-12-01 13:22 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll

2012-10-16 21:20 . 2012-12-01 13:22 347648 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll

2012-10-16 20:34 . 2012-12-01 13:22 559104 ----a-w- c:\windows\apppatch\AcLayers.dll

2012-10-04 16:45 . 2012-12-12 11:32 44032 ----a-w- c:\windows\apppatch\acwow64.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Weather"="c:\program files (x86)\AWS\WeatherBug\Weather.exe" [2011-10-05 1652736]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744]

"Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-10-15 498160]

"Dell Registration"="c:\program files (x86)\System Registration\prodreg.exe" [2010-08-23 3926528]

"Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

.

R2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-03-17 232480]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-12-01 1255736]

R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-06-10 389120]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]

S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\1402000.013\SYMDS64.SYS [2012-10-04 493216]

S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\1402000.013\SYMEFA64.SYS [2012-10-04 1133216]

S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20121130.005\BHDrvx64.sys [2012-10-23 1384608]

S1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360x64\1402000.013\ccSetx64.sys [2012-10-04 168096]

S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20121215.001\IDSvia64.sys [2012-11-30 513184]

S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\1402000.013\Ironx64.SYS [2012-09-07 224416]

S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\N360x64\1402000.013\SYMNETS.SYS [2012-09-07 432800]

S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_4df47d9dbfb58b44\AESTSr64.exe [2009-03-03 89600]

S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]

S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]

S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336]

S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-30 399432]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-30 676936]

S2 N360;Norton 360;c:\program files (x86)\Norton 360\Engine\20.2.0.19\ccSvcHst.exe [2012-10-11 143928]

S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]

S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]

S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]

S3 BcmVWL;Broadcom Virtual Wireless;c:\windows\system32\DRIVERS\bcmvwl64.sys [2009-12-17 20984]

S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2009-06-15 172704]

S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-11-29 138912]

S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]

S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-27 158976]

S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-04-21 76912]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-30 25928]

S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]

S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]

S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]

S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]

S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]

.

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - WS2IFSL

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-09-07 161304]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-09-07 386584]

"Persistence"="c:\windows\system32\igfxpers.exe" [2010-09-07 415256]

"Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2009-12-17 5470208]

"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-01-21 487424]

"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-04-05 384296]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MIF5BA~1\Office14\ONBttnIE.dll/105

TCP: DhcpNameServer = 192.168.1.1

FF - ProfilePath - c:\users\nebraskarain\AppData\Roaming\Mozilla\Firefox\Profiles\b8ix3dpj.default\

FF - ExtSQL: 2012-11-30 16:10; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\coFFPlgn

FF - ExtSQL: 2012-11-30 16:10; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\IPSFFPlgn

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360]

"ImagePath"="\"c:\program files (x86)\Norton 360\Engine\20.2.0.19\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Engine\20.2.0.19\diMaster.dll\" /prefetch:1"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.10"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Completion time: 2012-12-18 14:37:14

ComboFix-quarantined-files.txt 2012-12-18 20:37

ComboFix2.txt 2012-12-18 17:01

.

Pre-Run: 254,941,192,192 bytes free

Post-Run: 254,880,440,320 bytes free

.

- - End Of File - - A795EA3DD2C543CA6F18C2791C5D88D6

Link to post
Share on other sites

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the box below:

    KillAll::
    File::
    c:\windows\SysWow64\shoBCFA.tmp
    c:\windows\SysWow64\shoBFD6.tmp
    c:\windows\SysWow64\sho62BD.tmp
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.
    CFScriptB-4.gif
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Post the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

----------

Post the new ComboFix log and let me know how your system is running.

Link to post
Share on other sites

ComboFix 12-12-23.01 - nebraskarain 12/23/2012 16:57:03.3.2 - x64

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3895.2504 [GMT -6:00]

Running from: c:\users\nebraskarain\Desktop\ComboFix.exe

Command switches used :: c:\users\nebraskarain\Desktop\CFScript.txt

AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

FILE ::

"c:\windows\SysWow64\sho62BD.tmp"

"c:\windows\SysWow64\shoBCFA.tmp"

"c:\windows\SysWow64\shoBFD6.tmp"

.

.

((((((((((((((((((((((((( Files Created from 2012-11-23 to 2012-12-23 )))))))))))))))))))))))))))))))

.

.

2012-12-23 23:02 . 2012-12-23 23:02 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-12-23 15:54 . 2012-12-23 15:54 0 ----a-w- c:\windows\SysWow64\sho2F6D.tmp

2012-12-21 22:52 . 2012-12-21 22:52 -------- d-----w- c:\program files (x86)\Common Files\Java

2012-12-21 22:51 . 2012-12-21 22:51 95184 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2012-12-21 22:50 . 2012-12-21 22:50 -------- d-----w- c:\program files (x86)\Java

2012-12-21 17:36 . 2012-12-21 17:36 -------- d-----w- c:\program files (x86)\Norton Identity Safe

2012-12-21 17:36 . 2012-12-21 17:36 -------- d-----w- c:\windows\system32\drivers\NSTx64

2012-12-21 13:48 . 2012-12-16 16:52 46080 ----a-w- c:\windows\system32\atmlib.dll

2012-12-21 13:48 . 2012-12-16 14:25 34304 ----a-w- c:\windows\SysWow64\atmlib.dll

2012-12-21 13:48 . 2012-12-16 14:40 367616 ----a-w- c:\windows\system32\atmfd.dll

2012-12-21 13:48 . 2012-12-16 14:25 295424 ----a-w- c:\windows\SysWow64\atmfd.dll

2012-12-21 00:02 . 2012-12-21 00:02 -------- d-----w- C:\FRST

2012-12-18 04:21 . 2012-12-18 04:21 -------- d-----w- C:\TDSSKiller_Quarantine

2012-12-16 16:16 . 2012-12-16 17:23 -------- d-----w- c:\program files (x86)\Google

2012-12-16 16:16 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe

2012-12-16 16:13 . 2012-12-17 19:00 -------- d-----w- c:\programdata\AVAST Software

2012-12-16 16:13 . 2012-12-16 16:13 -------- d-----w- c:\program files\AVAST Software

2012-12-15 15:05 . 2012-12-15 15:05 -------- d-----w- c:\windows\Sun

2012-12-12 11:33 . 2012-11-09 05:34 2048 ----a-w- c:\windows\system32\tzres.dll

2012-12-12 11:33 . 2012-11-09 04:49 2048 ----a-w- c:\windows\SysWow64\tzres.dll

2012-12-12 11:33 . 2012-11-22 08:20 3147264 ----a-w- c:\windows\system32\win32k.sys

2012-12-09 16:36 . 2012-12-09 16:36 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help

2012-12-09 15:37 . 2012-12-09 15:37 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services

2012-12-09 15:36 . 2012-12-12 14:52 -------- d-----w- c:\programdata\Microsoft Help

2012-12-09 15:36 . 2012-12-09 15:36 -------- d-----r- C:\MSOCache

2012-12-02 19:04 . 2012-12-21 22:50 859072 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-12-02 19:04 . 2012-12-21 22:50 779704 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-12-02 13:55 . 2012-12-09 15:41 -------- d-----w- c:\program files (x86)\Microsoft.NET

2012-12-01 19:01 . 2012-12-01 19:01 -------- d-----w- c:\windows\SysWow64\Wat

2012-12-01 19:01 . 2012-12-01 19:01 -------- d-----w- c:\windows\system32\Wat

2012-12-01 17:34 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll

2012-12-01 17:34 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll

2012-12-01 16:48 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys

2012-12-01 16:48 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys

2012-12-01 16:48 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui

2012-12-01 16:48 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll

2012-12-01 16:31 . 2009-11-25 18:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll

2012-12-01 16:31 . 2009-11-25 18:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll

2012-12-01 16:31 . 2009-11-25 18:47 48960 ----a-w- c:\windows\system32\netfxperf.dll

2012-12-01 16:31 . 2009-11-25 18:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll

2012-12-01 16:31 . 2009-11-25 18:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe

2012-12-01 16:31 . 2009-11-25 18:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll

2012-12-01 16:31 . 2009-11-25 18:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll

2012-12-01 16:31 . 2009-11-25 18:47 444752 ----a-w- c:\windows\system32\mscoree.dll

2012-12-01 16:31 . 2009-11-25 18:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe

2012-12-01 16:31 . 2009-11-25 18:47 1942856 ----a-w- c:\windows\system32\dfshim.dll

2012-12-01 16:12 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys

2012-12-01 16:12 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys

2012-12-01 16:12 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll

2012-12-01 16:12 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll

2012-12-01 16:12 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe

2012-12-01 16:12 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll

2012-12-01 16:12 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll

2012-12-01 16:08 . 2012-03-01 06:54 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys

2012-12-01 16:08 . 2012-03-01 06:40 80896 ----a-w- c:\windows\system32\imagehlp.dll

2012-12-01 16:08 . 2012-03-01 06:35 5120 ----a-w- c:\windows\system32\wmi.dll

2012-12-01 16:08 . 2012-03-01 05:45 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll

2012-12-01 16:08 . 2012-03-01 05:40 5120 ----a-w- c:\windows\SysWow64\wmi.dll

2012-12-01 13:36 . 2011-10-01 05:28 886784 ----a-w- c:\program files\Common Files\System\wab32.dll

2012-12-01 13:36 . 2011-10-01 04:43 708608 ----a-w- c:\program files (x86)\Common Files\System\wab32.dll

2012-12-01 13:35 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe

2012-12-01 13:35 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe

2012-12-01 13:35 . 2011-02-26 06:23 2870272 ----a-w- c:\windows\explorer.exe

2012-12-01 13:35 . 2011-02-26 05:33 2614784 ----a-w- c:\windows\SysWow64\explorer.exe

2012-12-01 13:35 . 2010-12-23 06:07 961024 ----a-w- c:\windows\system32\CPFilters.dll

2012-12-01 13:35 . 2010-12-23 05:28 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll

2012-12-01 13:35 . 2010-12-23 06:07 1118720 ----a-w- c:\windows\system32\sbe.dll

2012-12-01 13:35 . 2010-12-23 06:02 259072 ----a-w- c:\windows\system32\mpg2splt.ax

2012-12-01 13:35 . 2010-12-23 05:28 850432 ----a-w- c:\windows\SysWow64\sbe.dll

2012-12-01 13:35 . 2010-12-23 05:24 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax

2012-12-01 13:35 . 2010-08-26 05:27 148992 ----a-w- c:\windows\system32\t2embed.dll

2012-12-01 13:35 . 2010-08-26 04:39 109056 ----a-w- c:\windows\SysWow64\t2embed.dll

2012-12-01 13:33 . 2011-10-26 05:22 1572864 ----a-w- c:\windows\system32\quartz.dll

2012-12-01 13:33 . 2011-10-26 04:28 1328640 ----a-w- c:\windows\SysWow64\quartz.dll

2012-12-01 13:33 . 2011-10-26 05:33 366592 ----a-w- c:\windows\system32\qdvd.dll

2012-12-01 13:33 . 2011-10-26 04:33 514560 ----a-w- c:\windows\SysWow64\qdvd.dll

2012-12-01 13:33 . 2012-01-04 09:58 509952 ----a-w- c:\windows\system32\ntshrui.dll

2012-12-01 13:33 . 2012-01-04 09:03 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll

2012-12-01 13:31 . 2011-11-17 07:12 395776 ----a-w- c:\windows\system32\webio.dll

2012-12-01 13:31 . 2011-11-17 05:39 314368 ----a-w- c:\windows\SysWow64\webio.dll

2012-12-01 13:31 . 2012-06-06 05:50 2003968 ----a-w- c:\windows\system32\msxml6.dll

2012-12-01 13:31 . 2012-06-06 05:50 1880064 ----a-w- c:\windows\system32\msxml3.dll

2012-12-01 13:31 . 2012-06-06 05:09 1389568 ----a-w- c:\windows\SysWow64\msxml6.dll

2012-12-01 13:31 . 2012-06-06 05:09 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll

2012-12-01 13:29 . 2011-10-26 05:19 43520 ----a-w- c:\windows\system32\csrsrv.dll

2012-12-01 13:29 . 2012-01-03 06:24 515584 ----a-w- c:\windows\system32\timedate.cpl

2012-12-01 13:29 . 2012-01-03 05:44 478208 ----a-w- c:\windows\SysWow64\timedate.cpl

2012-12-01 13:29 . 2011-02-24 06:30 476160 ----a-w- c:\windows\system32\XpsGdiConverter.dll

2012-12-01 13:29 . 2011-02-24 05:32 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll

2012-12-01 13:29 . 2010-08-21 06:31 633856 ----a-w- c:\windows\system32\comctl32.dll

2012-12-01 13:29 . 2010-08-21 05:33 530432 ----a-w- c:\windows\SysWow64\comctl32.dll

2012-12-01 13:29 . 2012-08-30 18:10 5473136 ----a-w- c:\windows\system32\ntoskrnl.exe

2012-12-01 13:29 . 2012-08-30 18:11 3971440 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

2012-12-01 13:29 . 2012-08-30 18:11 3915632 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

2012-12-01 13:27 . 2012-08-02 17:55 574464 ----a-w- c:\windows\system32\d3d10level9.dll

2012-12-01 13:26 . 2010-05-23 08:37 1888256 ----a-w- c:\windows\system32\WMVDECOD.DLL

2012-12-01 13:25 . 2011-04-22 20:18 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys

2012-12-01 13:25 . 2009-09-26 06:20 223448 ----a-w- c:\windows\system32\drivers\fvevol.sys

2012-12-01 13:25 . 2012-05-02 05:32 208896 ----a-w- c:\windows\system32\profsvc.dll

2012-12-01 13:25 . 2011-03-03 06:17 182272 ----a-w- c:\windows\system32\dnsrslvr.dll

2012-12-01 13:25 . 2011-03-03 06:17 356352 ----a-w- c:\windows\system32\dnsapi.dll

2012-12-01 13:25 . 2011-03-03 06:14 30208 ----a-w- c:\windows\system32\dnscacheugc.exe

2012-12-01 13:25 . 2011-03-03 05:27 28672 ----a-w- c:\windows\SysWow64\dnscacheugc.exe

2012-12-01 13:24 . 2010-08-21 06:38 1024512 ----a-w- c:\windows\system32\wmpmde.dll

2012-12-01 13:24 . 2010-08-21 05:36 738816 ----a-w- c:\windows\SysWow64\wmpmde.dll

2012-12-01 13:24 . 2012-08-24 18:05 220160 ----a-w- c:\windows\system32\wintrust.dll

2012-12-01 13:24 . 2012-08-24 17:10 172544 ----a-w- c:\windows\SysWow64\wintrust.dll

2012-12-01 13:22 . 2012-04-28 03:50 204800 ----a-w- c:\windows\system32\drivers\rdpwd.sys

2012-12-01 13:21 . 2011-05-24 11:21 404992 ----a-w- c:\windows\system32\umpnpmgr.dll

2012-12-01 13:21 . 2011-05-24 10:34 64512 ----a-w- c:\windows\SysWow64\devobj.dll

2012-12-01 13:21 . 2011-05-24 10:34 44544 ----a-w- c:\windows\SysWow64\devrtl.dll

2012-12-01 13:21 . 2011-05-24 10:34 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll

2012-12-01 13:21 . 2011-05-24 10:32 252928 ----a-w- c:\windows\SysWow64\drvinst.exe

2012-12-01 13:19 . 2012-06-06 05:50 1425408 ----a-w- c:\program files\Common Files\System\ado\msado15.dll

2012-12-01 13:18 . 2011-11-19 15:07 77312 ----a-w- c:\windows\system32\packager.dll

2012-12-01 13:18 . 2011-11-19 14:06 67072 ----a-w- c:\windows\SysWow64\packager.dll

2012-12-01 04:46 . 2012-12-01 19:46 -------- d-----w- c:\programdata\VirtualizedApplications

2012-12-01 00:50 . 2012-12-01 16:15 -------- d-----w- c:\program files (x86)\Microsoft Application Virtualization Client

2012-12-01 00:50 . 2012-12-01 00:50 -------- d-----w- c:\program files\Microsoft Office

2012-12-01 00:05 . 2012-12-23 22:55 -------- d-----w- c:\program files (x86)\Common Files\Symantec Shared

2012-11-30 22:09 . 2012-12-23 22:55 -------- d-----w- c:\program files (x86)\NortonInstaller

2012-11-30 22:00 . 2012-11-30 22:00 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-11-30 22:00 . 2012-11-30 22:00 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-11-30 22:00 . 2012-11-30 22:00 -------- d-----w- c:\windows\system32\Macromed

2012-11-30 21:55 . 2012-11-30 21:55 -------- d-----w- c:\programdata\PCSettings

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-10-16 21:20 . 2012-12-01 13:22 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll

2012-10-16 21:20 . 2012-12-01 13:22 347648 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll

2012-10-16 20:34 . 2012-12-01 13:22 559104 ----a-w- c:\windows\apppatch\AcLayers.dll

2012-10-04 16:45 . 2012-12-12 11:32 44032 ----a-w- c:\windows\apppatch\acwow64.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{AB4C7833-A6EC-433f-B9FE-6B14B1A2F836}]

2012-10-18 17:57 498584 ----a-r- c:\program files (x86)\Norton Identity Safe\Engine\2013.2.0.18\CoIEPlg.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]

"{A13C2648-91D4-4bf3-BC6D-0079707C4389}"= "c:\program files (x86)\Norton Identity Safe\Engine\2013.2.0.18\coIEPlg.dll" [2012-10-18 498584]

.

[HKEY_CLASSES_ROOT\clsid\{a13c2648-91d4-4bf3-bc6d-0079707c4389}]

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Weather"="c:\program files (x86)\AWS\WeatherBug\Weather.exe" [2011-10-05 1652736]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744]

"Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-10-15 498160]

"Dell Registration"="c:\program files (x86)\System Registration\prodreg.exe" [2010-08-23 3926528]

"Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R3 EraserUtilDrv11220;EraserUtilDrv11220;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11220.sys [x]

R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-03-17 232480]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-12-01 1255736]

R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-06-10 389120]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]

S1 ccSet_NST;Norton Identity Safe Settings Manager;c:\windows\system32\drivers\NSTx64\7DD02000.012\ccSetx64.sys [2012-10-04 168096]

S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_4df47d9dbfb58b44\AESTSr64.exe [2009-03-03 89600]

S2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]

S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]

S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]

S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336]

S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-30 399432]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-30 676936]

S2 NCO;Norton Identity Safe;c:\program files (x86)\Norton Identity Safe\Engine\2013.2.0.18\ccSvcHst.exe [2012-10-11 143928]

S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]

S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]

S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]

S3 BcmVWL;Broadcom Virtual Wireless;c:\windows\system32\DRIVERS\bcmvwl64.sys [2009-12-17 20984]

S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2009-06-15 172704]

S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]

S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-27 158976]

S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-04-21 76912]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-30 25928]

S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]

S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]

S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]

S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]

S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]

.

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-09-07 161304]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-09-07 386584]

"Persistence"="c:\windows\system32\igfxpers.exe" [2010-09-07 415256]

"Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2009-12-17 5470208]

"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-01-21 487424]

"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-04-05 384296]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MIF5BA~1\Office14\ONBttnIE.dll/105

TCP: DhcpNameServer = 192.168.1.1

FF - ProfilePath - c:\users\nebraskarain\AppData\Roaming\Mozilla\Firefox\Profiles\b8ix3dpj.default\

FF - ExtSQL: 2012-12-22 10:57; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\coFFPlgn

FF - ExtSQL: 2012-12-22 12:48; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\IPSFFPlgn

.

- - - - ORPHANS REMOVED - - - -

.

Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NCO]

"ImagePath"="\"c:\program files (x86)\Norton Identity Safe\Engine\2013.2.0.18\ccSvcHst.exe\" /s \"NCO\" /m \"c:\program files (x86)\Norton Identity Safe\Engine\2013.2.0.18\diMaster.dll\" /prefetch:1"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.10"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

.

**************************************************************************

.

Completion time: 2012-12-23 17:08:39 - machine was rebooted

ComboFix-quarantined-files.txt 2012-12-23 23:08

ComboFix2.txt 2012-12-18 20:37

ComboFix3.txt 2012-12-18 17:01

.

Pre-Run: 257,702,252,544 bytes free

Post-Run: 257,310,711,808 bytes free

.

- - End Of File - - 666D0D485CB66E2DB99CA12E26CACAE7

Link to post
Share on other sites

Malwarebytes Anti-Rootkit

Please download Malwarebytes Anti-Rootkit and save it to your desktop.

  • Be sure to print out and follow the instructions provided on that same page.
  • Caution: This is a beta version so please be sure to read the disclaimer and back up all your data before using.
  • Scan your system for malware
  • If malware is found, please go to the MBAR folder and then copy/paste the contents of the MBAR-log-***.txt file to your next reply.

If no malware is found please let me know.

----------

Link to post
Share on other sites

Please download OTM by OldTimer.

  • Save it to your desktop.
  • Please Right-click and Run as Administrator OTM and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Files
c:\windows\SysWow64\sho2F6D.tmp

:Commands
[emptytemp]
[start explorer]
[Reboot]

  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM

Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Post the log made by OTM and let me know how your system is running.

Link to post
Share on other sites

All processes killed

========== PROCESSES ==========

No active process named explorer.exe was found!

========== FILES ==========

c:\windows\SysWow64\sho2F6D.tmp moved successfully.

========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: nebraskarain

->Temp folder emptied: 1365799 bytes

->Temporary Internet Files folder emptied: 895495 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 372133590 bytes

->Google Chrome cache emptied: 6502498 bytes

->Flash cache emptied: 14725 bytes

User: Public

->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32 (64bit) .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 41144 bytes

%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 52503022 bytes

%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 617 bytes

%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 46427033 bytes

%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 749 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 458.00 mb

OTM by OldTimer - Version 3.1.21.0 log created on 12242012_111852

Files moved on Reboot...

File move failed. C:\Users\nebraskarain\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.