Bishman187
Posts: 23 +0
I've turned UAC to full for the time being, and also made the MSE icon visible in the system tray, which should make it a little more obvious should something disable it. Farbar and combofix logs:
Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-31 12:49:24 Run:2
Running from D:\
==============================================
HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Session Manager\SubSystems\\Windows No ZeroAccess entry found.
C:\Windows\System32\consrv.dll not found.
C:\Windows\Installer\{80d2dcb4-bf2f-2b69-974e-75896abb2390} moved successfully.
==== End of Fixlog ====
ComboFix 12-07-30.03 - i5 31/07/2012 12:59:28.3.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.4087.2661 [GMT 1:00]
Running from: D:\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\i5\AppData\Roaming\vso_ts_preview.xml
.
.
((((((((((((((((((((((((( Files Created from 2012-06-28 to 2012-07-31 )))))))))))))))))))))))))))))))
.
.
2012-07-31 12:08 . 2012-07-31 12:08 -------- d-----w- c:\users\i5\AppData\Local\temp
2012-07-31 12:08 . 2012-07-31 12:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-31 11:56 . 2012-07-31 11:56 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C6418C1C-E20F-414F-90F5-B1710D86C392}\offreg.dll
2012-07-30 13:11 . 2012-07-30 13:11 -------- d-----w- c:\program files\Enigma Software Group
2012-07-30 13:10 . 2012-07-30 13:19 -------- d-----w- c:\windows\F896D02690164122B9BD957FF092FFE9.TMP
2012-07-30 13:10 . 2012-07-30 13:10 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-07-29 22:58 . 2012-07-29 22:58 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-29 22:58 . 2012-07-29 22:58 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-29 22:35 . 2012-02-09 13:17 927800 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{83B279FC-5D45-4B3A-BF8B-14D56A606D71}\gapaengine.dll
2012-07-29 22:35 . 2012-07-16 01:40 9133488 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C6418C1C-E20F-414F-90F5-B1710D86C392}\mpengine.dll
2012-07-29 22:34 . 2012-07-29 22:34 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-07-29 22:34 . 2012-07-29 22:34 -------- d-----w- c:\program files\Microsoft Security Client
2012-07-28 09:13 . 2012-07-28 09:13 -------- d-----w- c:\program files\iPod
2012-07-28 09:13 . 2012-07-28 09:14 -------- d-----w- c:\program files\iTunes
2012-07-28 09:13 . 2012-07-28 09:14 -------- d-----w- c:\program files (x86)\iTunes
2012-07-28 09:04 . 2012-07-28 09:04 -------- d-----w- c:\users\i5\AppData\Local\Secunia PSI
2012-07-28 09:04 . 2012-07-28 09:04 -------- d-----w- c:\program files (x86)\Secunia
2012-07-26 03:39 . 2012-07-26 04:03 -------- d-----w- C:\FRST
2012-07-25 21:43 . 2012-07-25 21:43 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-07-25 21:42 . 2012-07-25 21:42 -------- d-----w- c:\program files (x86)\Java
2012-07-25 21:40 . 2012-07-25 21:39 955888 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-07-25 21:40 . 2012-07-25 21:39 839152 ----a-w- c:\windows\system32\deployJava1.dll
2012-07-25 21:39 . 2012-07-25 21:39 268784 ----a-w- c:\windows\system32\javaws.exe
2012-07-25 21:39 . 2012-07-25 21:39 189424 ----a-w- c:\windows\system32\javaw.exe
2012-07-25 21:39 . 2012-07-25 21:39 188912 ----a-w- c:\windows\system32\java.exe
2012-07-25 21:39 . 2012-07-25 21:39 -------- d-----w- c:\program files\Java
2012-07-24 13:42 . 2012-07-24 13:42 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-07-24 08:08 . 2012-07-24 08:08 -------- d-----w- c:\program files (x86)\Ubisoft
2012-07-24 07:27 . 2012-07-24 07:27 -------- d-----w- c:\program files (x86)\Microsoft CAPICOM 2.1.0.2
2012-07-23 12:42 . 2012-07-23 12:42 -------- d-----w- c:\program files\Logitech
2012-07-21 13:31 . 2012-07-21 13:31 1897984 ----a-w- c:\windows\SysWow64\mqrdim.dll
2012-07-19 19:43 . 2012-07-19 19:43 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-07-19 19:26 . 2012-07-19 19:26 -------- d-----w- c:\windows\Sun
2012-07-19 18:48 . 2012-07-20 16:34 -------- d-----w- C:\Pcsx
2012-07-18 11:32 . 2012-07-18 11:32 -------- d-----w- c:\program files\Intel
2012-07-18 11:31 . 2012-07-18 11:31 -------- d-----w- c:\users\i5\AppData\Roaming\InstallShield
2012-07-15 18:10 . 2012-07-15 18:10 -------- d-----w- c:\windows\SysWow64\Futuremark
2012-07-15 18:10 . 2004-10-25 19:02 21664 ----a-w- c:\windows\SysWow64\drivers\Entech.sys
2012-07-15 18:10 . 2004-06-22 14:44 5632 ----a-w- c:\windows\SysWow64\drivers\Entech64.sys
2012-07-15 18:10 . 2001-11-19 18:05 3972 ----a-w- c:\windows\SysWow64\drivers\PciBus.sys
2012-07-15 08:30 . 2012-07-15 08:30 -------- d-----w- c:\program files (x86)\Exif Viewer
2012-07-15 08:23 . 2012-07-15 08:27 -------- d-----w- c:\users\i5\AppData\Local\GameSpy
2012-07-15 08:21 . 2012-07-15 08:24 -------- d-----w- c:\users\i5\AppData\Local\ApplicationHistory
2012-07-14 15:40 . 2012-07-14 15:40 -------- d-----w- c:\windows\SysWow64\URTTEMP
2012-07-14 15:39 . 2012-07-14 15:39 669184 ----a-w- c:\windows\SysWow64\pbsvc.exe
2012-07-14 15:34 . 2012-07-14 15:34 -------- d-----w- c:\program files (x86)\Electronic Arts
2012-07-14 12:02 . 2012-07-14 13:17 -------- d-----w- c:\programdata\TrackMania
2012-07-13 23:03 . 2012-07-13 23:04 -------- d-----w- c:\program files\Core Temp
2012-07-13 10:19 . 2012-07-13 10:19 -------- d-----w- c:\users\i5\AppData\Roaming\LoneSurvivor
2012-07-11 17:24 . 2012-07-11 17:24 -------- d-----w- c:\users\i5\AppData\Roaming\Media Player Classic
2012-07-11 17:24 . 2012-05-26 11:36 178176 ----a-w- c:\windows\SysWow64\unrar.dll
2012-07-11 17:24 . 2012-07-11 17:24 -------- d-----w- c:\program files (x86)\MPC-HC
2012-07-11 14:12 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-07-11 14:04 . 2012-06-09 05:43 14172672 ----a-w- c:\windows\system32\shell32.dll
2012-07-10 20:58 . 2012-07-10 20:58 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
2012-07-10 20:56 . 2012-07-11 16:55 -------- d-----w- c:\programdata\EA Logs
2012-07-10 17:56 . 2012-07-10 17:56 -------- d-sh--w- c:\programdata\SecuROM
2012-07-10 17:49 . 2012-07-14 15:16 -------- d-----w- c:\users\i5\AppData\Local\Rockstar Games
2012-07-10 17:48 . 2012-07-10 17:48 -------- d--h--r- c:\users\i5\AppData\Roaming\SecuROM
2012-07-10 17:45 . 2012-07-10 17:45 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2012-07-10 16:58 . 2012-07-10 17:00 -------- d-----w- c:\users\i5\Heaven
2012-07-10 16:58 . 2012-07-10 16:58 -------- d-----w- c:\program files\Unigine
2012-07-10 13:34 . 2012-07-10 13:34 -------- d-----w- c:\programdata\ATI
2012-07-10 13:32 . 2012-07-10 13:32 -------- d-----w- c:\program files (x86)\AMD AVT
2012-07-10 13:32 . 2012-07-10 13:32 -------- d-----w- c:\program files (x86)\AMD APP
2012-07-10 13:32 . 2012-07-10 13:32 -------- d-----w- c:\program files\Common Files\ATI Technologies
2012-07-10 13:32 . 2012-07-10 13:32 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2012-07-10 13:31 . 2012-07-10 13:31 -------- d-----w- c:\program files (x86)\ATI Technologies
2012-07-10 13:30 . 2012-07-10 13:31 -------- d-----w- c:\program files\ATI Technologies
2012-07-10 13:30 . 2012-07-10 13:30 -------- d-----w- c:\program files\ATI
2012-07-08 11:48 . 2012-07-08 11:48 -------- d-----w- c:\users\i5\AppData\Local\CrashRpt
2012-07-08 09:07 . 2012-07-08 09:07 -------- d-----w- c:\programdata\ASUS OC Profiles
2012-07-08 09:03 . 2010-04-22 18:20 13440 ----a-w- c:\windows\SysWow64\drivers\AsIO.sys
2012-07-08 09:03 . 2009-09-30 10:33 24576 ----a-w- c:\windows\SysWow64\AsIO.dll
2012-07-08 09:03 . 2012-07-08 09:09 -------- d-----w- c:\program files (x86)\ASUS
2012-07-08 09:02 . 2001-09-05 03:13 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2012-07-07 16:57 . 2012-07-27 10:46 -------- d-----w- c:\program files (x86)\Rockstar Games
2012-07-07 16:57 . 2012-07-07 16:57 -------- d-----w- c:\programdata\Rockstar Games
2012-07-06 12:24 . 2012-07-06 12:24 -------- d-----w- c:\users\i5\AppData\Roaming\fltk.org
2012-07-06 12:24 . 2012-07-06 12:24 -------- d-----w- c:\programdata\fltk.org
2012-07-05 19:48 . 2012-07-05 19:48 476936 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-07-05 19:47 . 2012-07-05 19:47 -------- d-----w- c:\programdata\McAfee
2012-07-01 12:26 . 2012-07-28 09:16 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-25 21:42 . 2012-03-10 14:27 687600 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-07-14 15:39 . 2012-06-18 16:10 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-07-14 15:39 . 2012-06-18 16:10 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-07-13 23:12 . 2012-06-18 16:10 283304 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-07-12 17:21 . 2012-03-15 20:44 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-07-11 14:06 . 2012-03-10 08:51 59701280 ----a-w- c:\windows\system32\MRT.exe
2012-07-10 21:03 . 2012-06-16 15:04 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-07-03 12:46 . 2012-05-01 17:01 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-21 15:04 . 2012-06-21 15:04 549704 ----a-w- c:\windows\system32\drivers\SRS_AE_amd64.sys
2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll
2012-06-11 18:29 . 2012-06-11 18:29 24826368 ----a-w- c:\windows\system32\atio6axx.dll
2012-06-11 18:00 . 2012-06-11 18:00 20467712 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe
2012-06-11 17:24 . 2012-06-11 17:24 924160 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-06-11 17:23 . 2012-06-11 17:23 1090560 ----a-w- c:\windows\system32\aticfx64.dll
2012-06-11 17:20 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe
2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe
2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-06-11 17:17 . 2012-06-11 17:17 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-06-11 17:16 . 2012-06-11 17:16 6301696 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-06-11 17:01 . 2012-06-11 17:01 6914560 ----a-w- c:\windows\system32\atidxx64.dll
2012-06-11 16:51 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll
2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-06-11 16:45 . 2012-06-11 16:45 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-06-11 16:45 . 2012-06-11 16:45 5480448 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-06-11 16:45 . 2012-06-11 16:45 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll
2012-06-11 16:43 . 2012-06-11 16:43 4729344 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-06-11 16:40 . 2012-06-11 16:40 13277696 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-06-11 16:36 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll
2012-06-11 16:34 . 2012-06-11 16:34 77312 ----a-w- c:\windows\system32\amdave64.dll
2012-06-11 16:34 . 2012-06-11 16:34 77312 ----a-w- c:\windows\SysWow64\amdave32.dll
2012-06-11 16:34 . 2012-06-11 16:34 74240 ----a-w- c:\windows\system32\atisamu64.dll
2012-06-11 16:34 . 2012-06-11 16:34 71168 ----a-w- c:\windows\atisamu32.dll
2012-06-11 16:27 . 2012-02-15 02:14 539136 ----a-w- c:\windows\system32\atiadlxx.dll
2012-06-11 16:26 . 2012-06-11 16:26 368640 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-06-11 16:26 . 2012-06-11 16:26 17920 ----a-w- c:\windows\system32\atig6pxx.dll
2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll
2012-06-11 16:26 . 2012-06-11 16:26 41984 ----a-w- c:\windows\system32\atig6txx.dll
2012-06-11 16:26 . 2012-06-11 16:26 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-06-11 16:25 . 2012-06-11 16:25 54784 ----a-w- c:\windows\system32\atiuxp64.dll
2012-06-11 16:25 . 2012-06-11 16:25 42496 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-06-11 16:25 . 2012-06-11 16:25 45056 ----a-w- c:\windows\system32\atiu9p64.dll
2012-06-11 16:24 . 2012-06-11 16:24 32768 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll
2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll
2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll
2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2012-06-11 12:50 . 2012-06-11 12:50 187392 ----a-w- c:\windows\system32\clinfo.exe
2012-06-11 12:50 . 2012-06-11 12:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-06-11 12:50 . 2012-06-11 12:50 65024 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-06-11 12:50 . 2012-06-11 12:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll
2012-06-11 12:50 . 2012-06-11 12:50 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-06-11 12:50 . 2012-06-11 12:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll
2012-06-11 12:49 . 2012-06-11 12:49 13008896 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-06-02 22:19 . 2012-06-23 08:20 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-23 08:20 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-23 08:20 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-23 08:20 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-23 08:20 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-23 08:20 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-23 08:20 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 14:19 . 2012-06-23 08:20 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 14:15 . 2012-06-23 08:20 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-05-30 12:10 . 2012-05-30 12:10 16168 ----a-w- c:\windows\system32\drivers\TurboB.sys
2012-05-18 13:09 . 2012-05-18 13:09 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2012-05-18 13:09 . 2012-05-18 13:09 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-05-18 13:09 . 2012-05-18 13:09 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2012-05-10 15:35 . 2012-05-10 15:35 43520 ----a-w- c:\windows\system32\kdbsdk64.dll
2012-05-10 15:35 . 2012-05-10 15:35 29184 ----a-w- c:\windows\SysWow64\kdbsdk32.dll
2012-05-04 11:06 . 2012-06-14 20:59 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 11:00 . 2012-06-14 20:59 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-05-04 10:03 . 2012-06-14 20:59 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03 . 2012-06-14 20:59 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-05-04 09:59 . 2012-06-14 20:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-05-03 02:54 . 2012-05-03 02:54 42392 ----a-w- c:\windows\SysWow64\xfcodec.dll
2012-05-03 02:54 . 2012-05-03 02:54 28056 ----a-w- c:\windows\system32\xfcodec64.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-29_22.23.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:54 . 2012-07-29 22:24 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-07-31 07:24 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-07-28 09:04 . 2012-07-31 07:24 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2012-07-28 09:04 . 2012-07-29 22:24 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-07-31 07:24 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-07-29 22:24 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-03-10 08:41 . 2012-07-31 11:54 54436 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-07-31 11:54 32490 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-03-10 08:41 . 2012-07-31 11:54 14996 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2300901077-4285810195-2663683418-1001_UserData.bin
- 2012-03-09 23:56 . 2012-07-29 22:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-03-09 23:56 . 2012-07-31 11:51 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-07-14 15:38 . 2012-07-31 10:14 10134 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\visitWebsite_000E79B7E7254F01870AC12942B7F8E4.exe
- 2012-07-14 15:38 . 2012-07-14 15:38 10134 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\visitWebsite_000E79B7E7254F01870AC12942B7F8E4.exe
+ 2012-07-14 15:38 . 2012-07-31 10:14 10134 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\checkForUpdatesSC_000E79B7E7254F01870AC12942B7F8E4.exe
- 2012-07-14 15:38 . 2012-07-14 15:38 10134 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\checkForUpdatesSC_000E79B7E7254F01870AC12942B7F8E4.exe
+ 2003-12-13 07:30 . 2003-12-13 07:30 70656 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\zlib1.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 13024 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\shallocator.dll
+ 2007-10-24 23:11 . 2007-10-24 23:11 17120 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crysisdedicatedserver.exe
+ 2007-10-24 23:11 . 2007-10-24 23:11 53472 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crysis64.exe
+ 2012-07-30 13:18 . 2012-07-30 13:18 66956 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCall.dll
+ 2012-07-31 11:50 . 2012-07-31 11:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-07-29 22:22 . 2012-07-29 22:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-07-31 11:50 . 2012-07-31 11:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-07-29 22:22 . 2012-07-29 22:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-07-14 15:38 . 2012-07-14 15:38 9662 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\ARPPRODUCTICON.exe
+ 2012-07-14 15:38 . 2012-07-31 10:14 9662 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\ARPPRODUCTICON.exe
- 2012-07-29 22:24 . 2009-10-07 00:46 131608 c:\windows\Temp\logishrd\LVPrcInj02.dll
+ 2012-07-31 11:51 . 2009-10-07 00:46 131608 c:\windows\Temp\logishrd\LVPrcInj02.dll
+ 2012-07-31 11:51 . 2009-10-07 00:47 109080 c:\windows\Temp\logishrd\LVPrcInj01.dll
- 2012-07-29 22:24 . 2009-10-07 00:47 109080 c:\windows\Temp\logishrd\LVPrcInj01.dll
+ 2012-07-29 22:58 . 2012-07-29 22:58 686792 c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_268_Plugin.exe
+ 2012-07-29 22:58 . 2012-07-29 22:58 250056 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2009-07-14 02:36 . 2012-07-29 22:34 630354 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-07-29 22:34 113418 c:\windows\system32\perfc009.dat
+ 2012-07-29 22:58 . 2012-07-29 22:58 417992 c:\windows\system32\Macromed\Flash\FlashUtil64_11_3_300_268_Plugin.exe
+ 2009-07-14 05:01 . 2012-07-31 11:46 370152 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-07-29 22:22 370152 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2012-04-25 08:34 . 2012-07-25 17:54 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\SCEP.exe
+ 2012-04-25 08:34 . 2012-07-29 22:34 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\SCEP.exe
+ 2012-07-29 22:34 . 2012-07-29 22:34 123352 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\MSE.exe
- 2012-07-25 17:54 . 2012-07-25 17:54 123352 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\MSE.exe
- 2012-04-25 08:34 . 2012-07-25 17:54 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\INTUNE.exe
+ 2012-04-25 08:34 . 2012-07-29 22:34 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\INTUNE.exe
+ 2012-04-25 08:34 . 2012-07-29 22:34 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\FEP.exe
- 2012-04-25 08:34 . 2012-07-25 17:54 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\FEP.exe
+ 2012-04-25 08:34 . 2012-07-29 22:34 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\EPP.exe
- 2012-04-25 08:34 . 2012-07-25 17:54 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\EPP.exe
+ 2007-09-19 15:29 . 2007-09-19 15:29 294912 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\pbsv.dll
+ 2004-01-13 19:16 . 2004-01-13 19:16 153966 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\jpeg62.dll
+ 2007-06-14 09:20 . 2007-06-14 09:20 118784 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\intellaptopgaming.dll
+ 2004-06-16 09:57 . 2004-06-16 09:57 372736 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\ijl15.dll
+ 2007-05-16 15:45 . 2007-05-16 15:45 118104 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\fxc.exe
+ 2007-10-14 14:35 . 2007-10-14 14:35 920576 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\fmodex64.dll
+ 2007-10-14 14:30 . 2007-10-14 14:30 794624 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\fmodex.dll
+ 2007-10-14 14:34 . 2007-10-14 14:34 240640 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\fmod_event64.dll
+ 2007-10-14 14:33 . 2007-10-14 14:33 283136 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\fmod_event_net64.dll
+ 2007-10-14 14:25 . 2007-10-14 14:25 237568 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\fmod_event_net.dll
+ 2007-10-14 14:26 . 2007-10-14 14:26 208896 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\fmod_event.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 644320 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crysoundsystem.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 660704 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryscriptsystem.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 885984 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryrendernull.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 943328 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crynetwork.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 386272 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crymovie.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 197856 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryinput.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 394464 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryfont.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 840928 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryentitysystem.dll
+ 2007-10-24 23:11 . 2007-10-24 23:11 110304 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\b64.dll
+ 2007-09-24 10:55 . 2007-09-24 10:55 159744 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\atimgpud.dll
+ 2012-07-30 13:10 . 2012-07-30 13:10 190063 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla36.exe
+ 2012-07-30 13:18 . 2012-07-30 13:18 190063 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla36.dll
+ 2012-07-30 13:18 . 2012-07-30 13:18 175992 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla34.dll
+ 2012-07-30 13:18 . 2012-07-30 13:18 176035 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla33.dll
+ 2012-07-30 13:18 . 2012-07-30 13:18 176545 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla32.dll
+ 2012-07-30 13:18 . 2012-07-30 13:18 184966 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla31.exe
+ 2012-07-30 13:18 . 2012-07-30 13:18 189776 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla21.dll
+ 2012-07-30 13:18 . 2012-07-30 13:18 176035 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla2.dll
+ 2012-07-30 13:18 . 2012-07-30 13:18 179526 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla.dll
+ 2012-07-29 22:58 . 2012-07-29 22:58 9465032 c:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll
+ 2012-07-29 22:58 . 2012-07-29 22:58 1536712 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe
+ 2012-03-10 09:42 . 2012-07-31 11:47 3145760 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2012-03-10 09:42 . 2012-07-29 22:04 3145760 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2012-03-26 18:21 . 2012-03-26 18:21 7622656 c:\windows\Installer\a17cf.msi
+ 2007-10-24 20:13 . 2007-10-24 20:13 2098400 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crysystem.dll
+ 2007-11-11 06:55 . 2007-11-11 06:55 9556801 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crysis.exe
+ 2007-10-24 20:13 . 2007-10-24 20:13 3024096 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryrenderd3d9.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 3036384 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryrenderd3d10.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 1991904 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryphysics.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 2823392 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crygame.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 1574112 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryanimation.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 1942752 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryaisystem.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 2942176 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryaction.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 1778912 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cry3dengine.dll
+ 2012-07-29 22:58 . 2012-07-29 22:58 12315336 c:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll
+ 2012-03-09 23:54 . 2012-07-31 11:47 47524112 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2300901077-4285810195-2663683418-1001-8192.dat
+ 2012-03-10 09:42 . 2012-07-30 21:52 46670080 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2300901077-4285810195-2663683418-1001-12288.dat
+ 2012-07-31 10:13 . 2012-07-31 10:13 378156544 c:\windows\Installer\9bec44.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-02-13 3481408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2010-08-11 2472048]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
"vmware-tray"="c:\program files (x86)\VMware\VMware Workstation\vmware-tray.exe" [2012-04-30 103536]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"TaskbarNoThumbnail"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 LVPrcS64;Process Monitor;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-07 191000]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944]
R2 VMwareHostd;VMware Workstation Server;c:\program files (x86)\VMware\VMware Workstation\vmware-hostd.exe [2012-04-30 11839488]
R3 ALSysIO;ALSysIO;c:\users\i5\AppData\Local\Temp\ALSysIO64.sys [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-12-08 36328]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-02-24 99384]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-06-28 1436424]
R3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files (x86)\NETGEAR\WN111v2\jswpsapi.exe [2008-02-29 942080]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-14 113120]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 98688]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 PCAMp50a64;PCAMp50a64 NDIS Protocol Driver;c:\windows\system32\Drivers\PCAMp50a64.sys [2006-11-28 43328]
R3 PCASp50a64;PCASp50a64 NDIS Protocol Driver;c:\windows\system32\Drivers\PCASp50a64.sys [2006-11-28 41280]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtl8187.sys [2010-01-07 448512]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-12-08 157672]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-12-08 16872]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-12-08 177640]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2011-12-08 146920]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-02-24 203320]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.6;c:\program files\Intel\TurboBoost\TurboBoost.exe [2012-05-30 149544]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys [2012-04-03 117040]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-04-23 1255736]
R3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;c:\windows\system32\DRIVERS\WN111v2w7x.sys [2010-04-27 783360]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2011-08-08 116336]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-03-17 283200]
S1 JSWPSLWF;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwfx.sys [2008-10-01 26624]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2012-04-03 224048]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2012-04-03 130864]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-12-28 96896]
S2 Realtek87B;Realtek87B;c:\program files (x86)\REALTEK\RTL8187 Wireless LAN Utility\RtlService.exe [2009-12-07 40960]
S2 SRSHDAudioService;SRS HDAudio Lab Service;c:\program files (x86)\Common Files\SRS Labs\SRS HD Audio Lab Service 2\SRSAudioLabService.exe [2012-06-25 13232]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2012-05-30 16168]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-29 846448]
S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);SysWOW64\drivers\vstor2-mntapi10-shared.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
S3 lvpopf64;Logitech POP Suppression Filter;c:\windows\system32\DRIVERS\lvpopf64.sys [2009-10-07 271640]
S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys [2009-10-07 30232]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [2009-10-07 327704]
S3 LVUVC64;Logitech QuickCam Fusion(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [2009-10-07 6379288]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-04-27 83080]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-04-27 184968]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 SRS_AE_Service;SRS Audio;c:\windows\system32\drivers\SRS_AE_amd64.sys [2012-06-21 549704]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2012-04-03 147248]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2012-04-03 166192]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2010-08-04 1342064]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2300901077-4285810195-2663683418-1001Core.job
- c:\users\i5\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-05 09:03]
.
2012-07-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2300901077-4285810195-2663683418-1001UA.job
- c:\users\i5\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-05 09:03]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1873256]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\i5\AppData\Roaming\Mozilla\Firefox\Profiles\d83v883a.default\
FF - prefs.js: browser.startup.homepage - google.co.uk
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2300901077-4285810195-2663683418-1001\Software\SecuROM\License information*]
"datasecu"=hex:28,93,59,f4,04,67,df,91,46,c6,e6,32,04,6c,63,8d,ba,5a,06,d8,c0,
ae,70,70,81,14,c2,c8,0b,72,16,6c,a5,2e,3e,f7,50,a9,78,4e,91,3e,04,e0,80,f4,\
"rkeysecu"=hex:1f,06,e0,90,f7,ce,d5,0d,ab,6c,0b,77,89,c7,61,83
.
[HKEY_USERS\S-1-5-21-2300901077-4285810195-2663683418-1001_Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):2e,dc,c3,b2,4f,8d,29,5b,6f,bf,77,cf,ed,b1,a8,08,77,36,c0,54,f7,
75,fe,1f,e2,ff,bd,60,f8,03,5d,03,6f,b1,f4,4a,7b,5f,ec,9d,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-2300901077-4285810195-2663683418-1001_Classes\Wow6432Node\CLSID\{f96638f8-3b2b-4583-9123-431b480980fb}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000098
"Therad"=dword:00000008
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-07-31 13:11:20
ComboFix-quarantined-files.txt 2012-07-31 12:11
ComboFix2.txt 2012-07-29 22:29
.
Pre-Run: 132,601,987,072 bytes free
Post-Run: 132,946,862,080 bytes free
.
- - End Of File - - 52805F4959DA86ACADA8DF98A63E228A
Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-31 12:49:24 Run:2
Running from D:\
==============================================
HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Session Manager\SubSystems\\Windows No ZeroAccess entry found.
C:\Windows\System32\consrv.dll not found.
C:\Windows\Installer\{80d2dcb4-bf2f-2b69-974e-75896abb2390} moved successfully.
==== End of Fixlog ====
ComboFix 12-07-30.03 - i5 31/07/2012 12:59:28.3.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.4087.2661 [GMT 1:00]
Running from: D:\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\i5\AppData\Roaming\vso_ts_preview.xml
.
.
((((((((((((((((((((((((( Files Created from 2012-06-28 to 2012-07-31 )))))))))))))))))))))))))))))))
.
.
2012-07-31 12:08 . 2012-07-31 12:08 -------- d-----w- c:\users\i5\AppData\Local\temp
2012-07-31 12:08 . 2012-07-31 12:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-31 11:56 . 2012-07-31 11:56 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C6418C1C-E20F-414F-90F5-B1710D86C392}\offreg.dll
2012-07-30 13:11 . 2012-07-30 13:11 -------- d-----w- c:\program files\Enigma Software Group
2012-07-30 13:10 . 2012-07-30 13:19 -------- d-----w- c:\windows\F896D02690164122B9BD957FF092FFE9.TMP
2012-07-30 13:10 . 2012-07-30 13:10 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-07-29 22:58 . 2012-07-29 22:58 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-29 22:58 . 2012-07-29 22:58 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-29 22:35 . 2012-02-09 13:17 927800 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{83B279FC-5D45-4B3A-BF8B-14D56A606D71}\gapaengine.dll
2012-07-29 22:35 . 2012-07-16 01:40 9133488 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C6418C1C-E20F-414F-90F5-B1710D86C392}\mpengine.dll
2012-07-29 22:34 . 2012-07-29 22:34 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-07-29 22:34 . 2012-07-29 22:34 -------- d-----w- c:\program files\Microsoft Security Client
2012-07-28 09:13 . 2012-07-28 09:13 -------- d-----w- c:\program files\iPod
2012-07-28 09:13 . 2012-07-28 09:14 -------- d-----w- c:\program files\iTunes
2012-07-28 09:13 . 2012-07-28 09:14 -------- d-----w- c:\program files (x86)\iTunes
2012-07-28 09:04 . 2012-07-28 09:04 -------- d-----w- c:\users\i5\AppData\Local\Secunia PSI
2012-07-28 09:04 . 2012-07-28 09:04 -------- d-----w- c:\program files (x86)\Secunia
2012-07-26 03:39 . 2012-07-26 04:03 -------- d-----w- C:\FRST
2012-07-25 21:43 . 2012-07-25 21:43 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-07-25 21:42 . 2012-07-25 21:42 -------- d-----w- c:\program files (x86)\Java
2012-07-25 21:40 . 2012-07-25 21:39 955888 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-07-25 21:40 . 2012-07-25 21:39 839152 ----a-w- c:\windows\system32\deployJava1.dll
2012-07-25 21:39 . 2012-07-25 21:39 268784 ----a-w- c:\windows\system32\javaws.exe
2012-07-25 21:39 . 2012-07-25 21:39 189424 ----a-w- c:\windows\system32\javaw.exe
2012-07-25 21:39 . 2012-07-25 21:39 188912 ----a-w- c:\windows\system32\java.exe
2012-07-25 21:39 . 2012-07-25 21:39 -------- d-----w- c:\program files\Java
2012-07-24 13:42 . 2012-07-24 13:42 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-07-24 08:08 . 2012-07-24 08:08 -------- d-----w- c:\program files (x86)\Ubisoft
2012-07-24 07:27 . 2012-07-24 07:27 -------- d-----w- c:\program files (x86)\Microsoft CAPICOM 2.1.0.2
2012-07-23 12:42 . 2012-07-23 12:42 -------- d-----w- c:\program files\Logitech
2012-07-21 13:31 . 2012-07-21 13:31 1897984 ----a-w- c:\windows\SysWow64\mqrdim.dll
2012-07-19 19:43 . 2012-07-19 19:43 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-07-19 19:26 . 2012-07-19 19:26 -------- d-----w- c:\windows\Sun
2012-07-19 18:48 . 2012-07-20 16:34 -------- d-----w- C:\Pcsx
2012-07-18 11:32 . 2012-07-18 11:32 -------- d-----w- c:\program files\Intel
2012-07-18 11:31 . 2012-07-18 11:31 -------- d-----w- c:\users\i5\AppData\Roaming\InstallShield
2012-07-15 18:10 . 2012-07-15 18:10 -------- d-----w- c:\windows\SysWow64\Futuremark
2012-07-15 18:10 . 2004-10-25 19:02 21664 ----a-w- c:\windows\SysWow64\drivers\Entech.sys
2012-07-15 18:10 . 2004-06-22 14:44 5632 ----a-w- c:\windows\SysWow64\drivers\Entech64.sys
2012-07-15 18:10 . 2001-11-19 18:05 3972 ----a-w- c:\windows\SysWow64\drivers\PciBus.sys
2012-07-15 08:30 . 2012-07-15 08:30 -------- d-----w- c:\program files (x86)\Exif Viewer
2012-07-15 08:23 . 2012-07-15 08:27 -------- d-----w- c:\users\i5\AppData\Local\GameSpy
2012-07-15 08:21 . 2012-07-15 08:24 -------- d-----w- c:\users\i5\AppData\Local\ApplicationHistory
2012-07-14 15:40 . 2012-07-14 15:40 -------- d-----w- c:\windows\SysWow64\URTTEMP
2012-07-14 15:39 . 2012-07-14 15:39 669184 ----a-w- c:\windows\SysWow64\pbsvc.exe
2012-07-14 15:34 . 2012-07-14 15:34 -------- d-----w- c:\program files (x86)\Electronic Arts
2012-07-14 12:02 . 2012-07-14 13:17 -------- d-----w- c:\programdata\TrackMania
2012-07-13 23:03 . 2012-07-13 23:04 -------- d-----w- c:\program files\Core Temp
2012-07-13 10:19 . 2012-07-13 10:19 -------- d-----w- c:\users\i5\AppData\Roaming\LoneSurvivor
2012-07-11 17:24 . 2012-07-11 17:24 -------- d-----w- c:\users\i5\AppData\Roaming\Media Player Classic
2012-07-11 17:24 . 2012-05-26 11:36 178176 ----a-w- c:\windows\SysWow64\unrar.dll
2012-07-11 17:24 . 2012-07-11 17:24 -------- d-----w- c:\program files (x86)\MPC-HC
2012-07-11 14:12 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-07-11 14:04 . 2012-06-09 05:43 14172672 ----a-w- c:\windows\system32\shell32.dll
2012-07-10 20:58 . 2012-07-10 20:58 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
2012-07-10 20:56 . 2012-07-11 16:55 -------- d-----w- c:\programdata\EA Logs
2012-07-10 17:56 . 2012-07-10 17:56 -------- d-sh--w- c:\programdata\SecuROM
2012-07-10 17:49 . 2012-07-14 15:16 -------- d-----w- c:\users\i5\AppData\Local\Rockstar Games
2012-07-10 17:48 . 2012-07-10 17:48 -------- d--h--r- c:\users\i5\AppData\Roaming\SecuROM
2012-07-10 17:45 . 2012-07-10 17:45 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2012-07-10 16:58 . 2012-07-10 17:00 -------- d-----w- c:\users\i5\Heaven
2012-07-10 16:58 . 2012-07-10 16:58 -------- d-----w- c:\program files\Unigine
2012-07-10 13:34 . 2012-07-10 13:34 -------- d-----w- c:\programdata\ATI
2012-07-10 13:32 . 2012-07-10 13:32 -------- d-----w- c:\program files (x86)\AMD AVT
2012-07-10 13:32 . 2012-07-10 13:32 -------- d-----w- c:\program files (x86)\AMD APP
2012-07-10 13:32 . 2012-07-10 13:32 -------- d-----w- c:\program files\Common Files\ATI Technologies
2012-07-10 13:32 . 2012-07-10 13:32 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2012-07-10 13:31 . 2012-07-10 13:31 -------- d-----w- c:\program files (x86)\ATI Technologies
2012-07-10 13:30 . 2012-07-10 13:31 -------- d-----w- c:\program files\ATI Technologies
2012-07-10 13:30 . 2012-07-10 13:30 -------- d-----w- c:\program files\ATI
2012-07-08 11:48 . 2012-07-08 11:48 -------- d-----w- c:\users\i5\AppData\Local\CrashRpt
2012-07-08 09:07 . 2012-07-08 09:07 -------- d-----w- c:\programdata\ASUS OC Profiles
2012-07-08 09:03 . 2010-04-22 18:20 13440 ----a-w- c:\windows\SysWow64\drivers\AsIO.sys
2012-07-08 09:03 . 2009-09-30 10:33 24576 ----a-w- c:\windows\SysWow64\AsIO.dll
2012-07-08 09:03 . 2012-07-08 09:09 -------- d-----w- c:\program files (x86)\ASUS
2012-07-08 09:02 . 2001-09-05 03:13 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2012-07-07 16:57 . 2012-07-27 10:46 -------- d-----w- c:\program files (x86)\Rockstar Games
2012-07-07 16:57 . 2012-07-07 16:57 -------- d-----w- c:\programdata\Rockstar Games
2012-07-06 12:24 . 2012-07-06 12:24 -------- d-----w- c:\users\i5\AppData\Roaming\fltk.org
2012-07-06 12:24 . 2012-07-06 12:24 -------- d-----w- c:\programdata\fltk.org
2012-07-05 19:48 . 2012-07-05 19:48 476936 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-07-05 19:47 . 2012-07-05 19:47 -------- d-----w- c:\programdata\McAfee
2012-07-01 12:26 . 2012-07-28 09:16 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-25 21:42 . 2012-03-10 14:27 687600 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-07-14 15:39 . 2012-06-18 16:10 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-07-14 15:39 . 2012-06-18 16:10 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-07-13 23:12 . 2012-06-18 16:10 283304 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-07-12 17:21 . 2012-03-15 20:44 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-07-11 14:06 . 2012-03-10 08:51 59701280 ----a-w- c:\windows\system32\MRT.exe
2012-07-10 21:03 . 2012-06-16 15:04 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-07-03 12:46 . 2012-05-01 17:01 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-21 15:04 . 2012-06-21 15:04 549704 ----a-w- c:\windows\system32\drivers\SRS_AE_amd64.sys
2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll
2012-06-11 18:29 . 2012-06-11 18:29 24826368 ----a-w- c:\windows\system32\atio6axx.dll
2012-06-11 18:00 . 2012-06-11 18:00 20467712 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe
2012-06-11 17:24 . 2012-06-11 17:24 924160 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-06-11 17:23 . 2012-06-11 17:23 1090560 ----a-w- c:\windows\system32\aticfx64.dll
2012-06-11 17:20 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe
2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe
2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-06-11 17:17 . 2012-06-11 17:17 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-06-11 17:16 . 2012-06-11 17:16 6301696 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-06-11 17:01 . 2012-06-11 17:01 6914560 ----a-w- c:\windows\system32\atidxx64.dll
2012-06-11 16:51 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll
2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-06-11 16:45 . 2012-06-11 16:45 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-06-11 16:45 . 2012-06-11 16:45 5480448 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-06-11 16:45 . 2012-06-11 16:45 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll
2012-06-11 16:43 . 2012-06-11 16:43 4729344 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-06-11 16:40 . 2012-06-11 16:40 13277696 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-06-11 16:36 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll
2012-06-11 16:34 . 2012-06-11 16:34 77312 ----a-w- c:\windows\system32\amdave64.dll
2012-06-11 16:34 . 2012-06-11 16:34 77312 ----a-w- c:\windows\SysWow64\amdave32.dll
2012-06-11 16:34 . 2012-06-11 16:34 74240 ----a-w- c:\windows\system32\atisamu64.dll
2012-06-11 16:34 . 2012-06-11 16:34 71168 ----a-w- c:\windows\atisamu32.dll
2012-06-11 16:27 . 2012-02-15 02:14 539136 ----a-w- c:\windows\system32\atiadlxx.dll
2012-06-11 16:26 . 2012-06-11 16:26 368640 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-06-11 16:26 . 2012-06-11 16:26 17920 ----a-w- c:\windows\system32\atig6pxx.dll
2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll
2012-06-11 16:26 . 2012-06-11 16:26 41984 ----a-w- c:\windows\system32\atig6txx.dll
2012-06-11 16:26 . 2012-06-11 16:26 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-06-11 16:25 . 2012-06-11 16:25 54784 ----a-w- c:\windows\system32\atiuxp64.dll
2012-06-11 16:25 . 2012-06-11 16:25 42496 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-06-11 16:25 . 2012-06-11 16:25 45056 ----a-w- c:\windows\system32\atiu9p64.dll
2012-06-11 16:24 . 2012-06-11 16:24 32768 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll
2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll
2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll
2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2012-06-11 12:50 . 2012-06-11 12:50 187392 ----a-w- c:\windows\system32\clinfo.exe
2012-06-11 12:50 . 2012-06-11 12:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-06-11 12:50 . 2012-06-11 12:50 65024 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-06-11 12:50 . 2012-06-11 12:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll
2012-06-11 12:50 . 2012-06-11 12:50 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-06-11 12:50 . 2012-06-11 12:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll
2012-06-11 12:49 . 2012-06-11 12:49 13008896 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-06-02 22:19 . 2012-06-23 08:20 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-23 08:20 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-23 08:20 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-23 08:20 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-23 08:20 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-23 08:20 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-23 08:20 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 14:19 . 2012-06-23 08:20 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 14:15 . 2012-06-23 08:20 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-05-30 12:10 . 2012-05-30 12:10 16168 ----a-w- c:\windows\system32\drivers\TurboB.sys
2012-05-18 13:09 . 2012-05-18 13:09 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2012-05-18 13:09 . 2012-05-18 13:09 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-05-18 13:09 . 2012-05-18 13:09 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2012-05-10 15:35 . 2012-05-10 15:35 43520 ----a-w- c:\windows\system32\kdbsdk64.dll
2012-05-10 15:35 . 2012-05-10 15:35 29184 ----a-w- c:\windows\SysWow64\kdbsdk32.dll
2012-05-04 11:06 . 2012-06-14 20:59 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 11:00 . 2012-06-14 20:59 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-05-04 10:03 . 2012-06-14 20:59 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03 . 2012-06-14 20:59 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-05-04 09:59 . 2012-06-14 20:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-05-03 02:54 . 2012-05-03 02:54 42392 ----a-w- c:\windows\SysWow64\xfcodec.dll
2012-05-03 02:54 . 2012-05-03 02:54 28056 ----a-w- c:\windows\system32\xfcodec64.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-29_22.23.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:54 . 2012-07-29 22:24 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-07-31 07:24 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-07-28 09:04 . 2012-07-31 07:24 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2012-07-28 09:04 . 2012-07-29 22:24 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-07-31 07:24 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-07-29 22:24 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-03-10 08:41 . 2012-07-31 11:54 54436 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-07-31 11:54 32490 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-03-10 08:41 . 2012-07-31 11:54 14996 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2300901077-4285810195-2663683418-1001_UserData.bin
- 2012-03-09 23:56 . 2012-07-29 22:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-03-09 23:56 . 2012-07-31 11:51 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-07-14 15:38 . 2012-07-31 10:14 10134 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\visitWebsite_000E79B7E7254F01870AC12942B7F8E4.exe
- 2012-07-14 15:38 . 2012-07-14 15:38 10134 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\visitWebsite_000E79B7E7254F01870AC12942B7F8E4.exe
+ 2012-07-14 15:38 . 2012-07-31 10:14 10134 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\checkForUpdatesSC_000E79B7E7254F01870AC12942B7F8E4.exe
- 2012-07-14 15:38 . 2012-07-14 15:38 10134 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\checkForUpdatesSC_000E79B7E7254F01870AC12942B7F8E4.exe
+ 2003-12-13 07:30 . 2003-12-13 07:30 70656 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\zlib1.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 13024 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\shallocator.dll
+ 2007-10-24 23:11 . 2007-10-24 23:11 17120 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crysisdedicatedserver.exe
+ 2007-10-24 23:11 . 2007-10-24 23:11 53472 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crysis64.exe
+ 2012-07-30 13:18 . 2012-07-30 13:18 66956 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCall.dll
+ 2012-07-31 11:50 . 2012-07-31 11:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-07-29 22:22 . 2012-07-29 22:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-07-31 11:50 . 2012-07-31 11:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-07-29 22:22 . 2012-07-29 22:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-07-14 15:38 . 2012-07-14 15:38 9662 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\ARPPRODUCTICON.exe
+ 2012-07-14 15:38 . 2012-07-31 10:14 9662 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\ARPPRODUCTICON.exe
- 2012-07-29 22:24 . 2009-10-07 00:46 131608 c:\windows\Temp\logishrd\LVPrcInj02.dll
+ 2012-07-31 11:51 . 2009-10-07 00:46 131608 c:\windows\Temp\logishrd\LVPrcInj02.dll
+ 2012-07-31 11:51 . 2009-10-07 00:47 109080 c:\windows\Temp\logishrd\LVPrcInj01.dll
- 2012-07-29 22:24 . 2009-10-07 00:47 109080 c:\windows\Temp\logishrd\LVPrcInj01.dll
+ 2012-07-29 22:58 . 2012-07-29 22:58 686792 c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_268_Plugin.exe
+ 2012-07-29 22:58 . 2012-07-29 22:58 250056 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2009-07-14 02:36 . 2012-07-29 22:34 630354 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-07-29 22:34 113418 c:\windows\system32\perfc009.dat
+ 2012-07-29 22:58 . 2012-07-29 22:58 417992 c:\windows\system32\Macromed\Flash\FlashUtil64_11_3_300_268_Plugin.exe
+ 2009-07-14 05:01 . 2012-07-31 11:46 370152 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-07-29 22:22 370152 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2012-04-25 08:34 . 2012-07-25 17:54 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\SCEP.exe
+ 2012-04-25 08:34 . 2012-07-29 22:34 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\SCEP.exe
+ 2012-07-29 22:34 . 2012-07-29 22:34 123352 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\MSE.exe
- 2012-07-25 17:54 . 2012-07-25 17:54 123352 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\MSE.exe
- 2012-04-25 08:34 . 2012-07-25 17:54 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\INTUNE.exe
+ 2012-04-25 08:34 . 2012-07-29 22:34 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\INTUNE.exe
+ 2012-04-25 08:34 . 2012-07-29 22:34 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\FEP.exe
- 2012-04-25 08:34 . 2012-07-25 17:54 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\FEP.exe
+ 2012-04-25 08:34 . 2012-07-29 22:34 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\EPP.exe
- 2012-04-25 08:34 . 2012-07-25 17:54 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\EPP.exe
+ 2007-09-19 15:29 . 2007-09-19 15:29 294912 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\pbsv.dll
+ 2004-01-13 19:16 . 2004-01-13 19:16 153966 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\jpeg62.dll
+ 2007-06-14 09:20 . 2007-06-14 09:20 118784 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\intellaptopgaming.dll
+ 2004-06-16 09:57 . 2004-06-16 09:57 372736 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\ijl15.dll
+ 2007-05-16 15:45 . 2007-05-16 15:45 118104 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\fxc.exe
+ 2007-10-14 14:35 . 2007-10-14 14:35 920576 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\fmodex64.dll
+ 2007-10-14 14:30 . 2007-10-14 14:30 794624 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\fmodex.dll
+ 2007-10-14 14:34 . 2007-10-14 14:34 240640 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\fmod_event64.dll
+ 2007-10-14 14:33 . 2007-10-14 14:33 283136 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\fmod_event_net64.dll
+ 2007-10-14 14:25 . 2007-10-14 14:25 237568 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\fmod_event_net.dll
+ 2007-10-14 14:26 . 2007-10-14 14:26 208896 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\fmod_event.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 644320 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crysoundsystem.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 660704 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryscriptsystem.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 885984 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryrendernull.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 943328 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crynetwork.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 386272 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crymovie.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 197856 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryinput.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 394464 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryfont.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 840928 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryentitysystem.dll
+ 2007-10-24 23:11 . 2007-10-24 23:11 110304 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\b64.dll
+ 2007-09-24 10:55 . 2007-09-24 10:55 159744 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\atimgpud.dll
+ 2012-07-30 13:10 . 2012-07-30 13:10 190063 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla36.exe
+ 2012-07-30 13:18 . 2012-07-30 13:18 190063 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla36.dll
+ 2012-07-30 13:18 . 2012-07-30 13:18 175992 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla34.dll
+ 2012-07-30 13:18 . 2012-07-30 13:18 176035 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla33.dll
+ 2012-07-30 13:18 . 2012-07-30 13:18 176545 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla32.dll
+ 2012-07-30 13:18 . 2012-07-30 13:18 184966 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla31.exe
+ 2012-07-30 13:18 . 2012-07-30 13:18 189776 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla21.dll
+ 2012-07-30 13:18 . 2012-07-30 13:18 176035 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla2.dll
+ 2012-07-30 13:18 . 2012-07-30 13:18 179526 c:\windows\F896D02690164122B9BD957FF092FFE9.TMP\WiseCustomCalla.dll
+ 2012-07-29 22:58 . 2012-07-29 22:58 9465032 c:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll
+ 2012-07-29 22:58 . 2012-07-29 22:58 1536712 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe
+ 2012-03-10 09:42 . 2012-07-31 11:47 3145760 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2012-03-10 09:42 . 2012-07-29 22:04 3145760 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2012-03-26 18:21 . 2012-03-26 18:21 7622656 c:\windows\Installer\a17cf.msi
+ 2007-10-24 20:13 . 2007-10-24 20:13 2098400 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crysystem.dll
+ 2007-11-11 06:55 . 2007-11-11 06:55 9556801 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crysis.exe
+ 2007-10-24 20:13 . 2007-10-24 20:13 3024096 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryrenderd3d9.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 3036384 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryrenderd3d10.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 1991904 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryphysics.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 2823392 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crygame.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 1574112 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryanimation.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 1942752 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryaisystem.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 2942176 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryaction.dll
+ 2007-10-24 20:13 . 2007-10-24 20:13 1778912 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cry3dengine.dll
+ 2012-07-29 22:58 . 2012-07-29 22:58 12315336 c:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll
+ 2012-03-09 23:54 . 2012-07-31 11:47 47524112 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2300901077-4285810195-2663683418-1001-8192.dat
+ 2012-03-10 09:42 . 2012-07-30 21:52 46670080 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2300901077-4285810195-2663683418-1001-12288.dat
+ 2012-07-31 10:13 . 2012-07-31 10:13 378156544 c:\windows\Installer\9bec44.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-02-13 3481408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2010-08-11 2472048]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
"vmware-tray"="c:\program files (x86)\VMware\VMware Workstation\vmware-tray.exe" [2012-04-30 103536]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"TaskbarNoThumbnail"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 LVPrcS64;Process Monitor;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-07 191000]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944]
R2 VMwareHostd;VMware Workstation Server;c:\program files (x86)\VMware\VMware Workstation\vmware-hostd.exe [2012-04-30 11839488]
R3 ALSysIO;ALSysIO;c:\users\i5\AppData\Local\Temp\ALSysIO64.sys [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-12-08 36328]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-02-24 99384]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-06-28 1436424]
R3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files (x86)\NETGEAR\WN111v2\jswpsapi.exe [2008-02-29 942080]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-14 113120]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 98688]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 PCAMp50a64;PCAMp50a64 NDIS Protocol Driver;c:\windows\system32\Drivers\PCAMp50a64.sys [2006-11-28 43328]
R3 PCASp50a64;PCASp50a64 NDIS Protocol Driver;c:\windows\system32\Drivers\PCASp50a64.sys [2006-11-28 41280]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtl8187.sys [2010-01-07 448512]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-12-08 157672]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-12-08 16872]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-12-08 177640]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2011-12-08 146920]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-02-24 203320]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.6;c:\program files\Intel\TurboBoost\TurboBoost.exe [2012-05-30 149544]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys [2012-04-03 117040]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-04-23 1255736]
R3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;c:\windows\system32\DRIVERS\WN111v2w7x.sys [2010-04-27 783360]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2011-08-08 116336]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-03-17 283200]
S1 JSWPSLWF;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwfx.sys [2008-10-01 26624]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2012-04-03 224048]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2012-04-03 130864]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-12-28 96896]
S2 Realtek87B;Realtek87B;c:\program files (x86)\REALTEK\RTL8187 Wireless LAN Utility\RtlService.exe [2009-12-07 40960]
S2 SRSHDAudioService;SRS HDAudio Lab Service;c:\program files (x86)\Common Files\SRS Labs\SRS HD Audio Lab Service 2\SRSAudioLabService.exe [2012-06-25 13232]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2012-05-30 16168]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-29 846448]
S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);SysWOW64\drivers\vstor2-mntapi10-shared.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
S3 lvpopf64;Logitech POP Suppression Filter;c:\windows\system32\DRIVERS\lvpopf64.sys [2009-10-07 271640]
S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys [2009-10-07 30232]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [2009-10-07 327704]
S3 LVUVC64;Logitech QuickCam Fusion(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [2009-10-07 6379288]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-04-27 83080]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-04-27 184968]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 SRS_AE_Service;SRS Audio;c:\windows\system32\drivers\SRS_AE_amd64.sys [2012-06-21 549704]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2012-04-03 147248]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2012-04-03 166192]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2010-08-04 1342064]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2300901077-4285810195-2663683418-1001Core.job
- c:\users\i5\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-05 09:03]
.
2012-07-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2300901077-4285810195-2663683418-1001UA.job
- c:\users\i5\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-05 09:03]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1873256]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\i5\AppData\Roaming\Mozilla\Firefox\Profiles\d83v883a.default\
FF - prefs.js: browser.startup.homepage - google.co.uk
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2300901077-4285810195-2663683418-1001\Software\SecuROM\License information*]
"datasecu"=hex:28,93,59,f4,04,67,df,91,46,c6,e6,32,04,6c,63,8d,ba,5a,06,d8,c0,
ae,70,70,81,14,c2,c8,0b,72,16,6c,a5,2e,3e,f7,50,a9,78,4e,91,3e,04,e0,80,f4,\
"rkeysecu"=hex:1f,06,e0,90,f7,ce,d5,0d,ab,6c,0b,77,89,c7,61,83
.
[HKEY_USERS\S-1-5-21-2300901077-4285810195-2663683418-1001_Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):2e,dc,c3,b2,4f,8d,29,5b,6f,bf,77,cf,ed,b1,a8,08,77,36,c0,54,f7,
75,fe,1f,e2,ff,bd,60,f8,03,5d,03,6f,b1,f4,4a,7b,5f,ec,9d,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-2300901077-4285810195-2663683418-1001_Classes\Wow6432Node\CLSID\{f96638f8-3b2b-4583-9123-431b480980fb}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000098
"Therad"=dword:00000008
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-07-31 13:11:20
ComboFix-quarantined-files.txt 2012-07-31 12:11
ComboFix2.txt 2012-07-29 22:29
.
Pre-Run: 132,601,987,072 bytes free
Post-Run: 132,946,862,080 bytes free
.
- - End Of File - - 52805F4959DA86ACADA8DF98A63E228A