iFIX Solutions
Posts: 73 +0
Here is the FRST log. Please help.
TIA,
Matt
Scan result of Farbar Recovery Scan Tool Version: 11-07-2012
Ran by SYSTEM at 11-07-2012 20:44:42
Running from E:\
Windows Vista (TM) Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [272896 2008-08-25] (Alps Electric Co., Ltd.)
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe [4119552 2008-12-22] (Dell Inc.)
HKLM\...\Run: [] [x]
HKLM\...\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray64.exe [462336 2008-12-22] (IDT, Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [161304 2010-08-25] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2010-08-25] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [415256 2010-08-25] (Intel Corporation)
HKLM\...\Run: [dldtmon.exe] "C:\Program Files (x86)\Dell V305\dldtmon.exe" [668912 2008-06-23] ()
HKLM\...\Run: [dldtamon] "C:\Program Files (x86)\Dell V305\dldtamon.exe" [16624 2008-06-23] ()
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281240 2012-06-12] (Microsoft Corporation)
HKLM-x32\...\Run: [PCMService] "C:\Program Files (x86)\Dell\MediaDirect\PCMService.exe" [132392 2008-07-04] (CyberLink Corp.)
HKLM-x32\...\Run: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m [1807600 2009-11-13] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe [x]
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\glohog43\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
HKU\glohog43\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\glohog43\...\Run: [SightSpeed] "C:\Program Files (x86)\Dell Video Chat\DellVideoChat.exe" -bootmode [4823928 2008-12-17] (Dell Inc. and SightSpeed Inc.)
HKU\glohog43\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKU\glohog43\...\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe [x]
HKU\hogihound\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\hogihound\...\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe 1 [x]
HKU\hogihound\...\Run: [SpeedItUpEX] C:\Program Files (x86)\SpeedItup Free\SpeedItUp.exe -MINI [x]
HKU\hogihound\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17147528 2012-01-31] (Skype Technologies S.A.)
HKU\hogihound\...\Run: [Spotify] "C:\Users\hogihound\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [x]
HKU\hogihound\...\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe [x]
HKU\RA Media Server\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent [462920 2012-07-03] (Malwarebytes Corporation)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickSet.lnk
ShortcutTarget: QuickSet.lnk -> C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\glohog43\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\hogihound\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\RA Media Server\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
==================== Services (Whitelisted) ======
2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_cce24a4c\AESTSr64.exe [88576 2008-12-22] (Andrea Electronics Corporation)
2 dldtCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\dldtserv.exe [33448 2009-07-09] ()
2 dldt_device; C:\Windows\system32\dldtcoms.exe -service [1045232 2008-02-25] ( )
2 dldt_device; C:\Windows\SysWow64\dldtcoms.exe -service [595184 2008-02-25] ( )
2 dsl-db; "C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe" "--defaults-file=C:\Program Files (x86)\Common Files\Dell\MySQL\my.ini" dsl-db [9459 2009-06-15] ()
2 McciCMService64; "C:\Program Files\Common Files\Motive\McciCMService.exe" [517632 2009-10-21] (Alcatel-Lucent)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22024 2012-06-12] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [357976 2012-06-12] (Microsoft Corporation)
2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_cce24a4c\STacSV64.exe [281600 2008-12-22] (IDT, Inc.)
2 wltrysvc; C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe [3051520 2008-12-22] (Dell Inc.)
========================== Drivers (Whitelisted) =============
0 MrFilter; C:\Windows\SysWow64\Drivers\MrFilter.sys [27936 2003-05-29] (Roxio)
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-11 20:43 - 2012-07-11 20:43 - 00000000 ____D C:\FRST
2012-07-11 17:14 - 2012-07-11 17:14 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\osplbkee.sys
2012-07-11 17:14 - 2012-07-11 17:14 - 00000950 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-11 17:14 - 2012-07-11 17:14 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-11 17:14 - 2012-07-11 17:14 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-11 17:14 - 2012-07-03 10:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-11 17:13 - 2012-07-11 17:10 - 00607260 ____A (Swearware) C:\Users\hogihound\Desktop\dds.scr
2012-07-11 17:13 - 2012-07-11 17:09 - 00302592 ____A C:\Users\hogihound\Desktop\j50cocdh.exe
2012-07-11 17:13 - 2012-07-11 17:06 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\hogihound\Desktop\mbam-setup-1.62.0.1300.exe
2012-07-11 16:42 - 2012-07-11 16:42 - 00000732 ____A C:\Users\hogihound\AppData\Local\d3d9caps64.dat
2012-07-11 16:19 - 2012-07-11 16:19 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\pzpkygdp.sys
2012-07-11 16:14 - 2012-07-11 16:14 - 00000000 ____D C:\Users\glohog43\AppData\Local\{A8B0A6A2-44BE-4D22-8680-43A693EAFAA2}
2012-07-11 15:58 - 2012-07-11 15:58 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\aqlywuln.sys
2012-07-10 17:56 - 2012-07-10 17:56 - 00000000 ____D C:\Users\glohog43\AppData\Local\{EC81459A-C914-4D51-95A3-100CA24F818F}
2012-07-09 16:27 - 2012-07-09 16:27 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-09 16:27 - 2012-07-09 16:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-09 10:14 - 2012-07-09 10:15 - 00000000 ____D C:\Users\glohog43\AppData\Local\{4755219B-0111-406B-8F88-D8DD19BEC55E}
2012-07-09 10:14 - 2012-07-09 10:14 - 00000000 ____D C:\Users\glohog43\AppData\Local\{D123AAD1-7CF2-4578-BCD3-22FCC5427E17}
2012-07-08 16:00 - 2012-07-08 16:00 - 00314880 ____A C:\Users\hogihound\AppData\Local\mukrxhockd.exe
2012-07-08 16:00 - 2012-07-08 16:00 - 00012754 ____A C:\Users\hogihound\Desktop\hs_err_pid7724.log
2012-07-08 07:02 - 2012-07-08 07:03 - 00000000 ____D C:\Users\glohog43\AppData\Local\{FDBFA7D1-63BC-49D6-843B-F33074FB4156}
2012-07-08 07:02 - 2012-07-08 07:02 - 00000000 ____D C:\Users\glohog43\AppData\Local\{5A15722D-2D67-4B5C-A63D-FBBA670AD87F}
2012-07-07 10:12 - 2012-07-07 10:12 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-07 10:12 - 2012-07-07 10:12 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-06 16:06 - 2012-07-06 16:07 - 00000000 ____D C:\Users\glohog43\AppData\Local\{DB34E952-4F08-4B32-869A-47B64779A2A3}
2012-07-06 16:06 - 2012-07-06 16:06 - 00000000 ____D C:\Users\glohog43\AppData\Local\{D462D346-FCCE-461A-9C2A-52A3F10D5780}
2012-06-30 18:16 - 2012-06-30 18:16 - 00000000 ____D C:\Users\glohog43\AppData\Local\Stardock_Corporation
2012-06-30 08:27 - 2012-06-30 08:27 - 00000000 ____D C:\Users\glohog43\AppData\Local\{61BE5FB9-11ED-4FFD-BAFF-B34AED972EC5}
2012-06-30 08:27 - 2012-06-30 08:27 - 00000000 ____D C:\Users\glohog43\AppData\Local\{01214BC4-7F66-4AB3-A0BF-36C604A97999}
2012-06-29 11:55 - 2012-06-29 11:55 - 00000000 ____D C:\Users\glohog43\AppData\Local\{ECFE8E0C-76B4-4FD9-A53A-B08BE3142A99}
2012-06-29 11:55 - 2012-06-29 11:55 - 00000000 ____D C:\Users\glohog43\AppData\Local\{0F5FFB2D-1E8B-4318-980A-4F46243682C3}
2012-06-29 10:42 - 2012-06-29 10:42 - 00000000 ____D C:\Program Files (x86)\Inbox Toolbar
2012-06-27 11:00 - 2012-06-27 11:00 - 00000000 ____D C:\Users\glohog43\AppData\Local\{786E3B49-9582-4A15-BC4E-33855CA5C12A}
2012-06-23 17:56 - 2012-06-23 17:56 - 00000000 ____D C:\Users\glohog43\AppData\Local\{1860E69B-B11C-43C4-B8B5-FC7525AD2508}
2012-06-23 17:55 - 2012-06-23 17:56 - 00000000 ____D C:\Users\glohog43\AppData\Local\{509B7E9D-CA83-43B7-BB4D-E3E33189415B}
2012-06-21 16:23 - 2012-06-21 16:23 - 00001696 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-21 16:22 - 2012-06-21 16:23 - 00000000 ____D C:\Program Files\iTunes
2012-06-21 16:22 - 2012-06-21 16:23 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-06-21 16:22 - 2012-06-21 16:22 - 00000000 ____D C:\Program Files\iPod
2012-06-20 16:11 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-20 16:11 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-20 16:11 - 2012-06-02 14:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-20 16:11 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-20 16:11 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-20 16:11 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-20 16:11 - 2012-06-02 14:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-20 16:11 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-20 16:11 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-20 16:11 - 2012-06-02 14:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-20 16:11 - 2012-06-02 12:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-20 16:11 - 2012-06-02 12:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-20 16:11 - 2012-06-02 12:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-20 16:11 - 2012-06-02 12:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-06-16 18:16 - 2012-06-16 18:16 - 00000000 ____D C:\Users\glohog43\AppData\Local\{70D06DD2-68EB-4EED-BE92-F917B4AAA4B9}
2012-06-14 06:33 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 06:33 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 06:33 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 06:33 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 06:33 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 06:33 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 06:33 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 06:33 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 06:33 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 06:33 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 06:33 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 06:33 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 06:33 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 06:33 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 06:33 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 06:33 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 06:33 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 06:33 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 06:33 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 06:33 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 06:33 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 06:33 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 06:33 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 06:33 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 06:33 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 06:33 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 06:33 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 06:33 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-12 16:54 - 2012-05-01 06:29 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 16:52 - 2012-05-15 12:15 - 02767360 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 16:49 - 2012-04-23 08:25 - 01267200 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 16:49 - 2012-04-23 08:25 - 00174592 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 16:49 - 2012-04-23 08:25 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-12 16:49 - 2012-04-23 08:00 - 00984064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-12 16:49 - 2012-04-23 08:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-12 16:49 - 2012-04-23 08:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-11 16:56 - 2012-06-11 17:31 - 00000000 ____D C:\Users\hogihound\AppData\Local\Conduit
2012-06-11 16:56 - 2012-06-11 16:56 - 00000000 ____D C:\Program Files (x86)\Conduit
2012-06-11 11:37 - 2012-06-11 11:37 - 00000000 ____D C:\Users\glohog43\AppData\Local\{3E5970CA-2AE8-4FF6-8309-F3E77F28D9C5}
2012-06-11 11:36 - 2012-06-11 11:37 - 00000000 ____D C:\Users\glohog43\AppData\Local\{74BCFCE6-7D9D-4178-B215-989E8E06DD79}
============ 3 Months Modified Files ========================
2012-07-11 17:14 - 2012-07-11 17:14 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\osplbkee.sys
2012-07-11 17:14 - 2012-07-11 17:14 - 00000950 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-11 17:10 - 2012-07-11 17:13 - 00607260 ____A (Swearware) C:\Users\hogihound\Desktop\dds.scr
2012-07-11 17:09 - 2012-07-11 17:13 - 00302592 ____A C:\Users\hogihound\Desktop\j50cocdh.exe
2012-07-11 17:06 - 2012-07-11 17:13 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\hogihound\Desktop\mbam-setup-1.62.0.1300.exe
2012-07-11 16:48 - 2009-09-16 07:44 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-11 16:47 - 2006-11-02 07:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-11 16:47 - 2006-11-02 07:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-11 16:47 - 2006-11-02 07:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-11 16:42 - 2012-07-11 16:42 - 00000732 ____A C:\Users\hogihound\AppData\Local\d3d9caps64.dat
2012-07-11 16:21 - 2009-05-19 12:50 - 00000732 ____A C:\Users\glohog43\AppData\Local\d3d9caps64.dat
2012-07-11 16:19 - 2012-07-11 16:19 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\pzpkygdp.sys
2012-07-11 15:59 - 2008-01-20 19:26 - 00161334 ____A C:\Windows\PFRO.log
2012-07-11 15:58 - 2012-07-11 15:58 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\aqlywuln.sys
2012-07-10 18:04 - 2006-11-02 07:42 - 00032630 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-10 17:54 - 2012-02-12 15:50 - 00000944 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1407243386-2725741204-579605368-1000UA.job
2012-07-10 17:26 - 2009-09-16 07:45 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-10 16:41 - 2009-03-23 09:45 - 01559265 ____A C:\Windows\WindowsUpdate.log
2012-07-09 17:47 - 2012-05-01 08:48 - 00002216 ____A C:\Windows\epplauncher.mif
2012-07-09 16:03 - 2012-03-19 15:26 - 00000390 ___AH C:\Windows\Tasks\System Update.job
2012-07-09 14:54 - 2012-02-12 15:50 - 00000922 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1407243386-2725741204-579605368-1000Core.job
2012-07-09 11:52 - 2009-09-16 07:43 - 00000880 ____A C:\Windows\Tasks\Google Software Updater.job
2012-07-08 16:00 - 2012-07-08 16:00 - 00314880 ____A C:\Users\hogihound\AppData\Local\mukrxhockd.exe
2012-07-08 16:00 - 2012-07-08 16:00 - 00012754 ____A C:\Users\hogihound\Desktop\hs_err_pid7724.log
2012-07-08 15:45 - 2012-01-27 10:02 - 04268856 ____A (PC Cleaners) C:\Windows\uninst.exe
2012-07-07 10:12 - 2012-07-07 10:12 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-07 10:12 - 2012-07-07 10:12 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-06 06:53 - 2009-05-09 10:36 - 00007052 ____A C:\Users\hogihound\AppData\Local\d3d9caps.dat
2012-07-05 17:16 - 2012-05-25 06:02 - 00196608 ____A C:\Windows\System32\Ikeext.etl
2012-07-05 15:45 - 2012-01-22 15:58 - 00000438 ____A C:\Windows\System32\Drivers\etc\hosts.ics
2012-07-03 10:46 - 2012-07-11 17:14 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-21 16:23 - 2012-06-21 16:23 - 00001696 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-14 06:38 - 2006-11-02 07:21 - 00282240 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 06:31 - 2006-11-02 04:46 - 00722512 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-14 06:27 - 2006-11-02 04:35 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-05 04:29 - 2012-06-05 04:29 - 00227688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-06-05 04:29 - 2012-06-05 04:29 - 00117464 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-06-02 14:19 - 2012-06-20 16:11 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 16:11 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 16:11 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-02 14:19 - 2012-06-20 16:11 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 16:11 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 16:11 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:19 - 2012-06-20 16:11 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-02 14:15 - 2012-06-20 16:11 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-20 16:11 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:12 - 2012-06-20 16:11 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-02 12:19 - 2012-06-20 16:11 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:19 - 2012-06-20 16:11 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-02 12:15 - 2012-06-20 16:11 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 12:12 - 2012-06-20 16:11 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-05-27 18:34 - 2012-05-27 18:34 - 00001758 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-05-25 17:28 - 2012-01-01 14:40 - 00722192 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-05-25 17:26 - 2012-05-25 17:25 - 12621696 ____A (Microsoft Corporation) C:\Users\hogihound\Downloads\mseinstall.exe
2012-05-20 04:24 - 2012-05-20 04:24 - 00001919 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-05-17 18:47 - 2012-06-14 06:33 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-14 06:33 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-14 06:33 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-14 06:33 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-14 06:33 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-14 06:33 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-14 06:33 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-14 06:33 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-14 06:33 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-14 06:33 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-14 06:33 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-14 06:33 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-14 06:33 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-14 06:33 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-14 06:33 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-14 06:33 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-14 06:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-14 06:33 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-14 06:33 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-14 06:33 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-14 06:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-14 06:33 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-14 06:33 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-14 06:33 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-14 06:33 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-14 06:33 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-14 06:33 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-14 06:33 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-15 12:15 - 2012-06-12 16:52 - 02767360 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-06 14:36 - 2009-03-23 15:46 - 00682617 ____A C:\Windows\DirectX.log
2012-05-05 16:35 - 2012-05-05 16:35 - 00001653 ____A C:\Users\hogihound\Desktop\Magnify.lnk
2012-05-01 06:29 - 2012-06-12 16:54 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-23 08:25 - 2012-06-12 16:49 - 01267200 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 08:25 - 2012-06-12 16:49 - 00174592 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 08:25 - 2012-06-12 16:49 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 08:00 - 2012-06-12 16:49 - 00984064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 08:00 - 2012-06-12 16:49 - 00133120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 08:00 - 2012-06-12 16:49 - 00098304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-18 17:56 - 2012-04-18 17:56 - 00094208 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTimeVR.qtx
2012-04-18 17:56 - 2012-04-18 17:56 - 00069632 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTime.qts
2012-04-13 04:57 - 2012-04-13 04:57 - 00033582 ____A C:\Users\glohog43\Downloads\ROI to email to patients.tif
ZeroAccess:
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\@
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\L
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\U
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\L\00000004.@
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\L\1afb2d56
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\L\201d3dde
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\U\00000008.@
ZeroAccess:
C:\Users\hogihound\AppData\Local\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}
C:\Users\hogihound\AppData\Local\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\@
C:\Users\hogihound\AppData\Local\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\L
C:\Users\hogihound\AppData\Local\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\U
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-09 14:29] - [2009-04-10 23:10] - 0381952 ____A (Microsoft Corporation) B8844F93D2C5F1DCDB179AAA9AF134B7
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 10%
Total physical RAM: 4053.98 MB
Available physical RAM: 3631.39 MB
Total Pagefile: 3927.62 MB
Available Pagefile: 3605.89 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:288.01 GB) (Free:193.41 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive e: () (Removable) (Total:7.45 GB) (Free:6.36 GB) FAT32
4 Drive x: (RECOVERY) (Fixed) (Total:10 GB) (Free:2.22 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 7634 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 78 MB 32 KB
Partition 2 Primary 10 GB 79 MB
Partition 3 Primary 288 GB 10 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 78 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 X RECOVERY NTFS Partition 10 GB Healthy Boot
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 288 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7633 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E FAT32 Removable 7633 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-10 17:19
======================= End Of Log ==========================
TIA,
Matt
Scan result of Farbar Recovery Scan Tool Version: 11-07-2012
Ran by SYSTEM at 11-07-2012 20:44:42
Running from E:\
Windows Vista (TM) Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [272896 2008-08-25] (Alps Electric Co., Ltd.)
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe [4119552 2008-12-22] (Dell Inc.)
HKLM\...\Run: [] [x]
HKLM\...\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray64.exe [462336 2008-12-22] (IDT, Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [161304 2010-08-25] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2010-08-25] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [415256 2010-08-25] (Intel Corporation)
HKLM\...\Run: [dldtmon.exe] "C:\Program Files (x86)\Dell V305\dldtmon.exe" [668912 2008-06-23] ()
HKLM\...\Run: [dldtamon] "C:\Program Files (x86)\Dell V305\dldtamon.exe" [16624 2008-06-23] ()
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281240 2012-06-12] (Microsoft Corporation)
HKLM-x32\...\Run: [PCMService] "C:\Program Files (x86)\Dell\MediaDirect\PCMService.exe" [132392 2008-07-04] (CyberLink Corp.)
HKLM-x32\...\Run: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m [1807600 2009-11-13] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe [x]
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\glohog43\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
HKU\glohog43\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\glohog43\...\Run: [SightSpeed] "C:\Program Files (x86)\Dell Video Chat\DellVideoChat.exe" -bootmode [4823928 2008-12-17] (Dell Inc. and SightSpeed Inc.)
HKU\glohog43\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKU\glohog43\...\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe [x]
HKU\hogihound\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\hogihound\...\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe 1 [x]
HKU\hogihound\...\Run: [SpeedItUpEX] C:\Program Files (x86)\SpeedItup Free\SpeedItUp.exe -MINI [x]
HKU\hogihound\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17147528 2012-01-31] (Skype Technologies S.A.)
HKU\hogihound\...\Run: [Spotify] "C:\Users\hogihound\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [x]
HKU\hogihound\...\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe [x]
HKU\RA Media Server\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent [462920 2012-07-03] (Malwarebytes Corporation)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickSet.lnk
ShortcutTarget: QuickSet.lnk -> C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\glohog43\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\hogihound\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\RA Media Server\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
==================== Services (Whitelisted) ======
2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_cce24a4c\AESTSr64.exe [88576 2008-12-22] (Andrea Electronics Corporation)
2 dldtCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\dldtserv.exe [33448 2009-07-09] ()
2 dldt_device; C:\Windows\system32\dldtcoms.exe -service [1045232 2008-02-25] ( )
2 dldt_device; C:\Windows\SysWow64\dldtcoms.exe -service [595184 2008-02-25] ( )
2 dsl-db; "C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe" "--defaults-file=C:\Program Files (x86)\Common Files\Dell\MySQL\my.ini" dsl-db [9459 2009-06-15] ()
2 McciCMService64; "C:\Program Files\Common Files\Motive\McciCMService.exe" [517632 2009-10-21] (Alcatel-Lucent)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22024 2012-06-12] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [357976 2012-06-12] (Microsoft Corporation)
2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_cce24a4c\STacSV64.exe [281600 2008-12-22] (IDT, Inc.)
2 wltrysvc; C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe [3051520 2008-12-22] (Dell Inc.)
========================== Drivers (Whitelisted) =============
0 MrFilter; C:\Windows\SysWow64\Drivers\MrFilter.sys [27936 2003-05-29] (Roxio)
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-11 20:43 - 2012-07-11 20:43 - 00000000 ____D C:\FRST
2012-07-11 17:14 - 2012-07-11 17:14 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\osplbkee.sys
2012-07-11 17:14 - 2012-07-11 17:14 - 00000950 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-11 17:14 - 2012-07-11 17:14 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-11 17:14 - 2012-07-11 17:14 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-11 17:14 - 2012-07-03 10:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-11 17:13 - 2012-07-11 17:10 - 00607260 ____A (Swearware) C:\Users\hogihound\Desktop\dds.scr
2012-07-11 17:13 - 2012-07-11 17:09 - 00302592 ____A C:\Users\hogihound\Desktop\j50cocdh.exe
2012-07-11 17:13 - 2012-07-11 17:06 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\hogihound\Desktop\mbam-setup-1.62.0.1300.exe
2012-07-11 16:42 - 2012-07-11 16:42 - 00000732 ____A C:\Users\hogihound\AppData\Local\d3d9caps64.dat
2012-07-11 16:19 - 2012-07-11 16:19 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\pzpkygdp.sys
2012-07-11 16:14 - 2012-07-11 16:14 - 00000000 ____D C:\Users\glohog43\AppData\Local\{A8B0A6A2-44BE-4D22-8680-43A693EAFAA2}
2012-07-11 15:58 - 2012-07-11 15:58 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\aqlywuln.sys
2012-07-10 17:56 - 2012-07-10 17:56 - 00000000 ____D C:\Users\glohog43\AppData\Local\{EC81459A-C914-4D51-95A3-100CA24F818F}
2012-07-09 16:27 - 2012-07-09 16:27 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-09 16:27 - 2012-07-09 16:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-09 10:14 - 2012-07-09 10:15 - 00000000 ____D C:\Users\glohog43\AppData\Local\{4755219B-0111-406B-8F88-D8DD19BEC55E}
2012-07-09 10:14 - 2012-07-09 10:14 - 00000000 ____D C:\Users\glohog43\AppData\Local\{D123AAD1-7CF2-4578-BCD3-22FCC5427E17}
2012-07-08 16:00 - 2012-07-08 16:00 - 00314880 ____A C:\Users\hogihound\AppData\Local\mukrxhockd.exe
2012-07-08 16:00 - 2012-07-08 16:00 - 00012754 ____A C:\Users\hogihound\Desktop\hs_err_pid7724.log
2012-07-08 07:02 - 2012-07-08 07:03 - 00000000 ____D C:\Users\glohog43\AppData\Local\{FDBFA7D1-63BC-49D6-843B-F33074FB4156}
2012-07-08 07:02 - 2012-07-08 07:02 - 00000000 ____D C:\Users\glohog43\AppData\Local\{5A15722D-2D67-4B5C-A63D-FBBA670AD87F}
2012-07-07 10:12 - 2012-07-07 10:12 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-07 10:12 - 2012-07-07 10:12 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-06 16:06 - 2012-07-06 16:07 - 00000000 ____D C:\Users\glohog43\AppData\Local\{DB34E952-4F08-4B32-869A-47B64779A2A3}
2012-07-06 16:06 - 2012-07-06 16:06 - 00000000 ____D C:\Users\glohog43\AppData\Local\{D462D346-FCCE-461A-9C2A-52A3F10D5780}
2012-06-30 18:16 - 2012-06-30 18:16 - 00000000 ____D C:\Users\glohog43\AppData\Local\Stardock_Corporation
2012-06-30 08:27 - 2012-06-30 08:27 - 00000000 ____D C:\Users\glohog43\AppData\Local\{61BE5FB9-11ED-4FFD-BAFF-B34AED972EC5}
2012-06-30 08:27 - 2012-06-30 08:27 - 00000000 ____D C:\Users\glohog43\AppData\Local\{01214BC4-7F66-4AB3-A0BF-36C604A97999}
2012-06-29 11:55 - 2012-06-29 11:55 - 00000000 ____D C:\Users\glohog43\AppData\Local\{ECFE8E0C-76B4-4FD9-A53A-B08BE3142A99}
2012-06-29 11:55 - 2012-06-29 11:55 - 00000000 ____D C:\Users\glohog43\AppData\Local\{0F5FFB2D-1E8B-4318-980A-4F46243682C3}
2012-06-29 10:42 - 2012-06-29 10:42 - 00000000 ____D C:\Program Files (x86)\Inbox Toolbar
2012-06-27 11:00 - 2012-06-27 11:00 - 00000000 ____D C:\Users\glohog43\AppData\Local\{786E3B49-9582-4A15-BC4E-33855CA5C12A}
2012-06-23 17:56 - 2012-06-23 17:56 - 00000000 ____D C:\Users\glohog43\AppData\Local\{1860E69B-B11C-43C4-B8B5-FC7525AD2508}
2012-06-23 17:55 - 2012-06-23 17:56 - 00000000 ____D C:\Users\glohog43\AppData\Local\{509B7E9D-CA83-43B7-BB4D-E3E33189415B}
2012-06-21 16:23 - 2012-06-21 16:23 - 00001696 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-21 16:22 - 2012-06-21 16:23 - 00000000 ____D C:\Program Files\iTunes
2012-06-21 16:22 - 2012-06-21 16:23 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-06-21 16:22 - 2012-06-21 16:22 - 00000000 ____D C:\Program Files\iPod
2012-06-20 16:11 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-20 16:11 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-20 16:11 - 2012-06-02 14:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-20 16:11 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-20 16:11 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-20 16:11 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-20 16:11 - 2012-06-02 14:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-20 16:11 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-20 16:11 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-20 16:11 - 2012-06-02 14:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-20 16:11 - 2012-06-02 12:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-20 16:11 - 2012-06-02 12:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-20 16:11 - 2012-06-02 12:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-20 16:11 - 2012-06-02 12:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-06-16 18:16 - 2012-06-16 18:16 - 00000000 ____D C:\Users\glohog43\AppData\Local\{70D06DD2-68EB-4EED-BE92-F917B4AAA4B9}
2012-06-14 06:33 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 06:33 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 06:33 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 06:33 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 06:33 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 06:33 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 06:33 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 06:33 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 06:33 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 06:33 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 06:33 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 06:33 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 06:33 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 06:33 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 06:33 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 06:33 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 06:33 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 06:33 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 06:33 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 06:33 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 06:33 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 06:33 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 06:33 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 06:33 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 06:33 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 06:33 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 06:33 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 06:33 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-12 16:54 - 2012-05-01 06:29 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 16:52 - 2012-05-15 12:15 - 02767360 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 16:49 - 2012-04-23 08:25 - 01267200 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 16:49 - 2012-04-23 08:25 - 00174592 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 16:49 - 2012-04-23 08:25 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-12 16:49 - 2012-04-23 08:00 - 00984064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-12 16:49 - 2012-04-23 08:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-12 16:49 - 2012-04-23 08:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-11 16:56 - 2012-06-11 17:31 - 00000000 ____D C:\Users\hogihound\AppData\Local\Conduit
2012-06-11 16:56 - 2012-06-11 16:56 - 00000000 ____D C:\Program Files (x86)\Conduit
2012-06-11 11:37 - 2012-06-11 11:37 - 00000000 ____D C:\Users\glohog43\AppData\Local\{3E5970CA-2AE8-4FF6-8309-F3E77F28D9C5}
2012-06-11 11:36 - 2012-06-11 11:37 - 00000000 ____D C:\Users\glohog43\AppData\Local\{74BCFCE6-7D9D-4178-B215-989E8E06DD79}
============ 3 Months Modified Files ========================
2012-07-11 17:14 - 2012-07-11 17:14 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\osplbkee.sys
2012-07-11 17:14 - 2012-07-11 17:14 - 00000950 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-11 17:10 - 2012-07-11 17:13 - 00607260 ____A (Swearware) C:\Users\hogihound\Desktop\dds.scr
2012-07-11 17:09 - 2012-07-11 17:13 - 00302592 ____A C:\Users\hogihound\Desktop\j50cocdh.exe
2012-07-11 17:06 - 2012-07-11 17:13 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\hogihound\Desktop\mbam-setup-1.62.0.1300.exe
2012-07-11 16:48 - 2009-09-16 07:44 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-11 16:47 - 2006-11-02 07:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-11 16:47 - 2006-11-02 07:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-11 16:47 - 2006-11-02 07:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-11 16:42 - 2012-07-11 16:42 - 00000732 ____A C:\Users\hogihound\AppData\Local\d3d9caps64.dat
2012-07-11 16:21 - 2009-05-19 12:50 - 00000732 ____A C:\Users\glohog43\AppData\Local\d3d9caps64.dat
2012-07-11 16:19 - 2012-07-11 16:19 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\pzpkygdp.sys
2012-07-11 15:59 - 2008-01-20 19:26 - 00161334 ____A C:\Windows\PFRO.log
2012-07-11 15:58 - 2012-07-11 15:58 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\aqlywuln.sys
2012-07-10 18:04 - 2006-11-02 07:42 - 00032630 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-10 17:54 - 2012-02-12 15:50 - 00000944 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1407243386-2725741204-579605368-1000UA.job
2012-07-10 17:26 - 2009-09-16 07:45 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-10 16:41 - 2009-03-23 09:45 - 01559265 ____A C:\Windows\WindowsUpdate.log
2012-07-09 17:47 - 2012-05-01 08:48 - 00002216 ____A C:\Windows\epplauncher.mif
2012-07-09 16:03 - 2012-03-19 15:26 - 00000390 ___AH C:\Windows\Tasks\System Update.job
2012-07-09 14:54 - 2012-02-12 15:50 - 00000922 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1407243386-2725741204-579605368-1000Core.job
2012-07-09 11:52 - 2009-09-16 07:43 - 00000880 ____A C:\Windows\Tasks\Google Software Updater.job
2012-07-08 16:00 - 2012-07-08 16:00 - 00314880 ____A C:\Users\hogihound\AppData\Local\mukrxhockd.exe
2012-07-08 16:00 - 2012-07-08 16:00 - 00012754 ____A C:\Users\hogihound\Desktop\hs_err_pid7724.log
2012-07-08 15:45 - 2012-01-27 10:02 - 04268856 ____A (PC Cleaners) C:\Windows\uninst.exe
2012-07-07 10:12 - 2012-07-07 10:12 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-07 10:12 - 2012-07-07 10:12 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-06 06:53 - 2009-05-09 10:36 - 00007052 ____A C:\Users\hogihound\AppData\Local\d3d9caps.dat
2012-07-05 17:16 - 2012-05-25 06:02 - 00196608 ____A C:\Windows\System32\Ikeext.etl
2012-07-05 15:45 - 2012-01-22 15:58 - 00000438 ____A C:\Windows\System32\Drivers\etc\hosts.ics
2012-07-03 10:46 - 2012-07-11 17:14 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-21 16:23 - 2012-06-21 16:23 - 00001696 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-14 06:38 - 2006-11-02 07:21 - 00282240 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 06:31 - 2006-11-02 04:46 - 00722512 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-14 06:27 - 2006-11-02 04:35 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-05 04:29 - 2012-06-05 04:29 - 00227688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-06-05 04:29 - 2012-06-05 04:29 - 00117464 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-06-02 14:19 - 2012-06-20 16:11 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 16:11 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 16:11 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-02 14:19 - 2012-06-20 16:11 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 16:11 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 16:11 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:19 - 2012-06-20 16:11 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-02 14:15 - 2012-06-20 16:11 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-20 16:11 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:12 - 2012-06-20 16:11 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-02 12:19 - 2012-06-20 16:11 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:19 - 2012-06-20 16:11 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-02 12:15 - 2012-06-20 16:11 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 12:12 - 2012-06-20 16:11 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-05-27 18:34 - 2012-05-27 18:34 - 00001758 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-05-25 17:28 - 2012-01-01 14:40 - 00722192 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-05-25 17:26 - 2012-05-25 17:25 - 12621696 ____A (Microsoft Corporation) C:\Users\hogihound\Downloads\mseinstall.exe
2012-05-20 04:24 - 2012-05-20 04:24 - 00001919 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-05-17 18:47 - 2012-06-14 06:33 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-14 06:33 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-14 06:33 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-14 06:33 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-14 06:33 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-14 06:33 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-14 06:33 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-14 06:33 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-14 06:33 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-14 06:33 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-14 06:33 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-14 06:33 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-14 06:33 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-14 06:33 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-14 06:33 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-14 06:33 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-14 06:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-14 06:33 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-14 06:33 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-14 06:33 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-14 06:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-14 06:33 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-14 06:33 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-14 06:33 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-14 06:33 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-14 06:33 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-14 06:33 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-14 06:33 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-15 12:15 - 2012-06-12 16:52 - 02767360 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-06 14:36 - 2009-03-23 15:46 - 00682617 ____A C:\Windows\DirectX.log
2012-05-05 16:35 - 2012-05-05 16:35 - 00001653 ____A C:\Users\hogihound\Desktop\Magnify.lnk
2012-05-01 06:29 - 2012-06-12 16:54 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-23 08:25 - 2012-06-12 16:49 - 01267200 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 08:25 - 2012-06-12 16:49 - 00174592 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 08:25 - 2012-06-12 16:49 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 08:00 - 2012-06-12 16:49 - 00984064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 08:00 - 2012-06-12 16:49 - 00133120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 08:00 - 2012-06-12 16:49 - 00098304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-18 17:56 - 2012-04-18 17:56 - 00094208 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTimeVR.qtx
2012-04-18 17:56 - 2012-04-18 17:56 - 00069632 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTime.qts
2012-04-13 04:57 - 2012-04-13 04:57 - 00033582 ____A C:\Users\glohog43\Downloads\ROI to email to patients.tif
ZeroAccess:
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\@
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\L
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\U
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\L\00000004.@
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\L\1afb2d56
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\L\201d3dde
C:\Windows\Installer\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\U\00000008.@
ZeroAccess:
C:\Users\hogihound\AppData\Local\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}
C:\Users\hogihound\AppData\Local\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\@
C:\Users\hogihound\AppData\Local\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\L
C:\Users\hogihound\AppData\Local\{50b5e7c3-d7d9-002f-ebb1-57daf9ab13a3}\U
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-09 14:29] - [2009-04-10 23:10] - 0381952 ____A (Microsoft Corporation) B8844F93D2C5F1DCDB179AAA9AF134B7
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 10%
Total physical RAM: 4053.98 MB
Available physical RAM: 3631.39 MB
Total Pagefile: 3927.62 MB
Available Pagefile: 3605.89 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:288.01 GB) (Free:193.41 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive e: () (Removable) (Total:7.45 GB) (Free:6.36 GB) FAT32
4 Drive x: (RECOVERY) (Fixed) (Total:10 GB) (Free:2.22 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 7634 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 78 MB 32 KB
Partition 2 Primary 10 GB 79 MB
Partition 3 Primary 288 GB 10 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 78 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 X RECOVERY NTFS Partition 10 GB Healthy Boot
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 288 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7633 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E FAT32 Removable 7633 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-10 17:19
======================= End Of Log ==========================