Jump to content

Not sure infected - encryption threat


Recommended Posts

Hi all,

 

MrC helped me last time...

 

Anyway, I was wandering around the web then went to close my browser and the browser wouldn't close, went to a threat that the browser was encrypted and there were ads to pay them to unlock.  I immediately powered down, then powered  up in safe mode and checked several files - they didn't seem encrypted.  I ran adware killer in safe mode, then powered back down.

 

This morning I went into the command prompt and ran FRST64, the log is pasted below.  I know my company got hit with malware that could encrypt everything on a harddrive (which is why I powered down so fast).  Anyway, if you guys could give me a hand to make sure that my machine isn't infected, I would be very thankful.

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-12-2013 01
Ran by SYSTEM on MININT-KK1B6PV on 07-12-2013 07:33:32
Running from I:\
Windows 7 Ultimate (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor)
HKLM\...\Run: [RunDLLEntry_THXCfg] - C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64
HKLM\...\Run: [RunDLLEntry_EptMon] - C:\Windows\system32\RunDLL32.exe C:\Windows\system32\EptMon64.dll,RunDLLEntry EptMon64
HKLM\...\Run: [DellStage] - C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj [483424 2012-02-01] ()
HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] - "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [559616 2011-10-13] (Dell)
HKLM-x32\...\RunOnce: [Launcher] - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe [165184 2011-01-13] (Softthinks)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM-x32\...\Run: [startCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-11-10] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [iAStorIcon] - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [shwiconXP9106] - C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe [237568 2010-03-10] (Alcor Micro Corp.)
HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe [963584 2009-12-01] (Creative Technology Ltd)
HKLM-x32\...\Run: [updReg] - C:\Windows\Updreg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [Dell DataSafe Online] - C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-25] (Dell, Inc.)
HKLM-x32\...\Run: [mcui_exe] - C:\Program Files\mcafee.com\agent\mcagent.exe [1532992 2013-03-13] (McAfee, Inc.)
HKLM-x32\...\Run: [bCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AccuWeatherWidget] - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj [2835443 2012-02-01] ()
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [sunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [ConnectionCenter] - C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [304568 2010-10-12] (Citrix Systems, Inc.)
HKU\John\...\Run: [steam] - C:\Program Files (x86)\Steam\Steam.exe [1823656 2013-12-03] (Valve Corporation)
HKU\John\...\Run: [HP Photosmart 5510 series (NET)] - C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe [2672488 2011-05-25] (Hewlett-Packard Co.)
Startup: C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Photosmart 5510 series (Network).lnk
ShortcutTarget: Monitor Ink Alerts - HP Photosmart 5510 series (Network).lnk -> C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)

==================== Services (Whitelisted) =================

S3 McAWFwk; C:\Program Files\mcafee\msc\McAWFwk.exe [220528 2010-08-30] (McAfee, Inc.)
S2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
S2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
S2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
S2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [383608 2012-11-16] (McAfee, Inc.)
S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
S2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
S2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [241456 2013-02-19] (McAfee, Inc.)
S2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [218760 2013-02-19] (McAfee, Inc.)
S2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-02-19] (McAfee, Inc.)
S2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)

==================== Drivers (Whitelisted) ====================

S1 AEP_TDI_DRV; C:\Windows\System32\DRIVERS\aeptdipfwd.sys [61328 2012-10-28] (AEP Networks Inc.)
S1 AEP_TDI_DRV; C:\Windows\SysWow64\DRIVERS\aeptdipfwd.sys [61328 2012-10-28] (AEP Networks Inc.)
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-02-19] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.)
S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179280 2013-02-19] (McAfee, Inc.)
S3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [309840 2013-02-19] (McAfee, Inc.)
S3 mfeavfk01; No ImagePath
S3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [515968 2013-02-19] (McAfee, Inc.)
S0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [771536 2013-02-19] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [106552 2013-02-19] (McAfee, Inc.)
S0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [340216 2013-02-19] (McAfee, Inc.)
S3 RemoteControl-USBLAN; C:\Windows\System32\DRIVERS\rcblan.sys [46616 2007-01-24] (Belcarra Technologies)
S3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0; \??\c:\program files\dell support center\pcdsrvc_x64.pkms [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2013-12-07 07:33 - 2013-12-07 07:33 - 00000000 ____D C:\FRST
2013-12-06 17:22 - 2013-12-06 17:22 - 00001650 _____ C:\AdwCleaner[s2].txt
2013-12-06 17:22 - 2013-12-06 17:22 - 00001578 _____ C:\AdwCleaner[R3].txt
2013-12-06 17:21 - 2013-12-06 17:22 - 00001518 _____ C:\AdwCleaner[R2].txt
2013-11-25 22:24 - 2013-10-14 17:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\System32\IEUDINIT.EXE
2013-11-25 22:22 - 2013-11-25 22:22 - 23212032 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 12995584 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 05765120 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 02764288 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-25 22:22 - 2013-11-25 22:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-11-25 22:22 - 2013-11-25 22:22 - 02332160 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 01993728 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-11-25 22:22 - 2013-11-25 22:22 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-25 22:22 - 2013-11-25 22:22 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 01394176 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 01228800 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00942592 _____ (Microsoft Corporation) C:\Windows\System32\jsIntl.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00940032 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00817664 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00774144 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00708608 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00626176 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-25 22:22 - 2013-11-25 22:22 - 00616104 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2013-11-25 22:22 - 2013-11-25 22:22 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00574976 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00548352 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00453120 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00413696 _____ (Microsoft Corporation) C:\Windows\System32\html.iec
2013-11-25 22:22 - 2013-11-25 22:22 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-25 22:22 - 2013-11-25 22:22 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00263376 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00247808 _____ (Microsoft Corporation) C:\Windows\System32\msls31.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00243200 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00235520 _____ (Microsoft Corporation) C:\Windows\System32\url.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00235008 _____ (Microsoft Corporation) C:\Windows\System32\elshyph.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00218624 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00195584 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00167424 _____ (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00147968 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00143872 _____ (Microsoft Corporation) C:\Windows\System32\wextract.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00139264 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00135680 _____ (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00131072 _____ (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00111616 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00105984 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00101376 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00090112 _____ (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00086016 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00084992 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00083968 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00081408 _____ (Microsoft Corporation) C:\Windows\System32\icardie.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00077312 _____ (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2013-11-25 22:22 - 2013-11-25 22:22 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00066048 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-25 22:22 - 2013-11-25 22:22 - 00062464 _____ (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00053760 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00052224 _____ (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00048128 _____ (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00040448 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00033792 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00030208 _____ (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00013824 _____ (Microsoft Corporation) C:\Windows\System32\mshta.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2013-11-25 22:20 - 2013-11-25 22:24 - 00007785 _____ C:\Windows\IE11_main.log
2013-11-15 15:44 - 2013-11-15 15:46 - 00000000 ____D C:\Users\John\AppData\Roaming\VASSAL
2013-11-14 17:02 - 2013-10-11 20:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\System32\nshwfp.dll
2013-11-14 17:02 - 2013-10-11 20:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\System32\IKEEXT.DLL
2013-11-14 17:02 - 2013-10-11 20:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\System32\FWPUCLNT.DLL
2013-11-14 17:02 - 2013-10-11 20:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-14 17:02 - 2013-10-11 20:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-14 17:02 - 2013-10-05 14:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-11-14 17:02 - 2013-10-05 13:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-14 17:02 - 2013-10-03 20:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\System32\SmartcardCredentialProvider.dll
2013-11-14 17:02 - 2013-10-03 20:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\System32\credui.dll
2013-11-14 17:02 - 2013-10-03 20:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-11-14 17:02 - 2013-10-03 19:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-14 17:02 - 2013-10-03 19:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-14 17:02 - 2013-10-03 19:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-14 17:02 - 2013-10-02 20:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll
2013-11-14 17:02 - 2013-10-02 20:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-14 17:02 - 2013-09-27 19:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\afd.sys
2013-11-14 17:02 - 2013-09-24 20:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2013-11-14 17:02 - 2013-09-24 20:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2013-11-14 17:02 - 2013-09-24 20:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2013-11-14 17:02 - 2013-09-24 20:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2013-11-14 17:02 - 2013-09-24 20:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll
2013-11-14 17:02 - 2013-09-24 20:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-11-14 17:02 - 2013-09-24 20:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2013-11-14 17:02 - 2013-09-24 20:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2013-11-14 17:02 - 2013-09-24 19:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-14 17:02 - 2013-09-24 19:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-14 17:02 - 2013-09-24 19:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-14 17:02 - 2013-09-24 19:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-14 17:02 - 2013-09-24 19:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe
2013-11-14 17:02 - 2013-07-04 06:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2013-11-14 16:47 - 2013-11-14 16:52 - 00000000 ____D C:\Users\John\AppData\Roaming\ICAClient
2013-11-14 16:47 - 2013-11-14 16:47 - 00000000 ____D C:\Users\John\AppData\Local\Citrix
2013-11-14 16:47 - 2013-11-14 16:47 - 00000000 ____D C:\ProgramData\Citrix
2013-11-14 16:47 - 2013-11-14 16:47 - 00000000 ____D C:\Program Files (x86)\Citrix

==================== One Month Modified Files and Folders =======

2013-12-07 07:33 - 2013-12-07 07:33 - 00000000 ____D C:\FRST
2013-12-06 17:24 - 2011-05-02 21:16 - 00000000 ____D C:\Program Files (x86)\Steam
2013-12-06 17:24 - 2011-04-21 13:18 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2013-12-06 17:23 - 2012-02-11 22:00 - 00000890 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-06 17:23 - 2011-05-02 21:05 - 00000000 ____D C:\Users\John\AppData\Local\SoftThinks
2013-12-06 17:23 - 2009-07-13 23:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-06 17:23 - 2009-07-13 22:51 - 00077461 _____ C:\Windows\setupact.log
2013-12-06 17:22 - 2013-12-06 17:22 - 00001650 _____ C:\AdwCleaner[s2].txt
2013-12-06 17:22 - 2013-12-06 17:22 - 00001578 _____ C:\AdwCleaner[R3].txt
2013-12-06 17:22 - 2013-12-06 17:21 - 00001518 _____ C:\AdwCleaner[R2].txt
2013-12-06 17:01 - 2013-08-04 08:56 - 00002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-12-06 17:01 - 2013-08-04 08:56 - 00002185 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2013-12-06 17:01 - 2012-02-13 15:40 - 00000254 _____ C:\Windows\Tasks\HP Photo Creations Messager.job
2013-12-06 17:01 - 2012-02-11 22:01 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-06 16:50 - 2013-08-04 08:54 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-06 16:41 - 2011-05-02 21:08 - 00000422 _____ C:\Windows\Tasks\SystemToolsDailyTest.job
2013-12-06 16:40 - 2011-09-05 11:00 - 00003488 _____ C:\Windows\System32\Tasks\PCDEventLauncher
2013-12-06 16:40 - 2011-05-02 21:08 - 00003440 _____ C:\Windows\System32\Tasks\SystemToolsDailyTest
2013-12-06 16:33 - 2009-07-13 22:45 - 00014224 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-06 16:33 - 2009-07-13 22:45 - 00014224 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-06 16:30 - 2009-07-13 23:10 - 01932612 _____ C:\Windows\WindowsUpdate.log
2013-12-02 17:02 - 2009-07-13 23:08 - 00032604 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-01 06:51 - 2011-04-21 15:03 - 00127008 _____ C:\Windows\PFRO.log
2013-11-27 07:55 - 2012-02-11 22:01 - 00003890 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-11-27 07:55 - 2012-02-11 22:01 - 00003638 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-11-26 18:41 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\rescache
2013-11-26 18:00 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-11-25 22:24 - 2013-11-25 22:20 - 00007785 _____ C:\Windows\IE11_main.log
2013-11-25 22:22 - 2013-11-25 22:22 - 23212032 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 12995584 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 05765120 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 02764288 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-25 22:22 - 2013-11-25 22:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-11-25 22:22 - 2013-11-25 22:22 - 02332160 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 01993728 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-11-25 22:22 - 2013-11-25 22:22 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-25 22:22 - 2013-11-25 22:22 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 01394176 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 01228800 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00942592 _____ (Microsoft Corporation) C:\Windows\System32\jsIntl.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00940032 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00817664 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00774144 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00708608 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00626176 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-25 22:22 - 2013-11-25 22:22 - 00616104 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2013-11-25 22:22 - 2013-11-25 22:22 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00574976 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00548352 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00453120 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00413696 _____ (Microsoft Corporation) C:\Windows\System32\html.iec
2013-11-25 22:22 - 2013-11-25 22:22 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-25 22:22 - 2013-11-25 22:22 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00263376 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00247808 _____ (Microsoft Corporation) C:\Windows\System32\msls31.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00243200 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00235520 _____ (Microsoft Corporation) C:\Windows\System32\url.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00235008 _____ (Microsoft Corporation) C:\Windows\System32\elshyph.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00218624 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00195584 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00167424 _____ (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00147968 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00143872 _____ (Microsoft Corporation) C:\Windows\System32\wextract.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00139264 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00135680 _____ (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00131072 _____ (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00111616 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00105984 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00101376 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00090112 _____ (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00086016 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00084992 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00083968 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00081408 _____ (Microsoft Corporation) C:\Windows\System32\icardie.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00077312 _____ (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2013-11-25 22:22 - 2013-11-25 22:22 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00066048 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-25 22:22 - 2013-11-25 22:22 - 00062464 _____ (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00053760 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00052224 _____ (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00048128 _____ (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00040448 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00033792 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00030208 _____ (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-25 22:22 - 2013-11-25 22:22 - 00013824 _____ (Microsoft Corporation) C:\Windows\System32\mshta.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-25 22:22 - 2013-11-25 22:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2013-11-24 19:09 - 2012-09-18 21:19 - 00000000 ____D C:\Users\John\AppData\Local\Netilla
2013-11-24 12:36 - 2009-07-13 23:13 - 00726444 _____ C:\Windows\System32\PerfStringBackup.INI
2013-11-22 07:30 - 2011-05-02 21:08 - 00000564 _____ C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2013-11-15 16:59 - 2011-05-04 16:04 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-15 15:48 - 2011-12-11 21:14 - 00000000 ____D C:\Users\John\VASSAL
2013-11-15 15:46 - 2013-11-15 15:44 - 00000000 ____D C:\Users\John\AppData\Roaming\VASSAL
2013-11-15 15:44 - 2011-12-11 21:13 - 00000981 _____ C:\Users\John\Desktop\VASSAL.lnk
2013-11-15 15:44 - 2011-12-11 21:13 - 00000000 ____D C:\Program Files (x86)\VASSAL
2013-11-15 15:38 - 2011-05-02 21:09 - 00000000 ____D C:\Users\John\AppData\Local\VirtualStore
2013-11-14 22:05 - 2013-08-14 21:13 - 00000000 ____D C:\Windows\System32\MRT
2013-11-14 22:03 - 2013-06-07 04:07 - 82896128 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-11-14 16:52 - 2013-11-14 16:47 - 00000000 ____D C:\Users\John\AppData\Roaming\ICAClient
2013-11-14 16:47 - 2013-11-14 16:47 - 00000000 ____D C:\Users\John\AppData\Local\Citrix
2013-11-14 16:47 - 2013-11-14 16:47 - 00000000 ____D C:\ProgramData\Citrix
2013-11-14 16:47 - 2013-11-14 16:47 - 00000000 ____D C:\Program Files (x86)\Citrix
2013-11-11 04:50 - 2012-07-02 22:26 - 00267936 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe

Some content of TEMP:
====================
C:\Users\John\AppData\Local\Temp\~idle26556288.dll
C:\Users\John\AppData\Local\Temp\~idle90844203.dll
C:\Users\John\AppData\Local\Temp\~min25591353.dll
C:\Users\John\AppData\Local\Temp\~min42528368.dll
C:\Users\John\AppData\Local\Temp\~min68699775.dll
C:\Users\John\AppData\Local\Temp\~min71268751.dll
C:\Users\John\AppData\Local\Temp\~min98438426.dll
C:\Users\John\AppData\Local\Temp\~popupunblocker95988247.dll
C:\Users\John\AppData\Local\Temp\~rdp94750462.dll
C:\Users\John\AppData\Local\Temp\~registryhlp17382475.dll

==================== Known DLLs (Whitelisted) ================

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================

7
Restore point made on: 2013-11-14 22:02:27
Restore point made on: 2013-11-15 16:55:58
Restore point made on: 2013-11-19 16:07:09
Restore point made on: 2013-11-22 19:33:56
Restore point made on: 2013-11-25 22:20:15
Restore point made on: 2013-11-30 12:06:10
Restore point made on: 2013-12-05 16:24:41

==================== Memory info ===========================

Percentage of memory in use: 9%
Total physical RAM: 8174.46 MB
Available physical RAM: 7379.25 MB
Total Pagefile: 8172.61 MB
Available Pagefile: 7377.58 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:1384.51 GB) (Free:1249.75 GB) NTFS
Drive i: () (Removable) (Total:1.87 GB) (Free:0.99 GB) FAT32
Drive j: (RECOVERY) (Fixed) (Total:12.71 GB) (Free:5.17 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 1397 GB) (Disk ID: 3887DDD0)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=13 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=-712415117312) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 2 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=2 GB) - (Type=0C)

LastRegBack: 2013-11-30 12:33

==================== End Of Log ============================

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.