Solved Win64/patched.a virus

Status
Not open for further replies.
Cont.
| ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll
[2012/10/24 12:13:01 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rtutils.dll
[2012/10/24 12:13:01 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe
[2012/10/24 12:13:00 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
[2012/10/24 12:13:00 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
[2012/10/24 12:12:46 | 001,446,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2012/10/24 12:12:46 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2012/10/24 12:12:46 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2012/10/24 12:12:46 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2012/10/24 12:12:46 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2012/10/24 12:12:29 | 000,367,104 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll
[2012/10/24 12:12:29 | 000,294,912 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
[2012/10/24 12:12:29 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll
[2012/10/24 12:12:29 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
[2012/10/24 12:12:29 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll
[2012/10/24 12:12:29 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll
[2012/10/24 12:12:27 | 001,888,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2012/10/24 12:12:26 | 004,068,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2012/10/24 12:12:26 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2012/10/24 12:12:25 | 001,863,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ExplorerFrame.dll
[2012/10/24 12:12:24 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2012/10/24 12:12:24 | 001,495,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll
[2012/10/24 12:12:24 | 000,265,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2012/10/24 12:12:24 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll
[2012/10/24 12:12:24 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsRasterService.dll
[2012/10/24 12:12:24 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2012/10/24 12:12:24 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll
[2012/10/24 12:12:24 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2012/10/24 12:12:24 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsRasterService.dll
[2012/10/24 12:12:13 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys
[2012/10/24 12:12:12 | 000,082,944 | ---- | C] (Radius Inc.) -- C:\Windows\SysWow64\iccvid.dll
[2012/10/24 12:12:09 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnsapi.dll
[2012/10/24 12:12:09 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnscacheugc.exe
[2012/10/24 12:12:09 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dnscacheugc.exe
[2012/10/24 12:11:24 | 001,024,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpmde.dll
[2012/10/24 12:11:24 | 000,738,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpmde.dll
[2012/10/24 12:11:23 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\avifil32.dll
[2012/10/24 12:11:23 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mciavi32.dll
[2012/10/24 12:11:22 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2012/10/24 12:11:07 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisdecd.dll
[2012/10/24 12:11:07 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll
[2012/10/24 12:11:07 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSNP.ax
[2012/10/24 12:11:07 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax
[2012/10/24 12:11:07 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisrndr.ax
[2012/10/24 12:11:07 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisrndr.ax
[2012/10/24 12:11:06 | 000,104,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Mpeg2Data.ax
[2012/10/24 12:11:06 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSDvbNP.ax
[2012/10/24 12:11:06 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Mpeg2Data.ax
[2012/10/24 12:11:06 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSDvbNP.ax
[2012/10/24 12:10:45 | 003,213,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2012/10/24 12:10:19 | 000,640,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2012/10/24 12:10:19 | 000,603,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2012/10/24 12:10:19 | 000,556,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2012/10/24 12:10:19 | 000,518,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe
[2012/10/24 12:10:19 | 000,020,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdusb.dll
[2012/10/24 12:10:19 | 000,019,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kd1394.dll
[2012/10/24 12:10:19 | 000,017,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdcom.dll
[2012/10/24 12:10:16 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc40.dll
[2012/10/24 12:10:16 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc40u.dll
[2012/10/24 12:10:11 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msasn1.dll
[2012/10/24 12:09:53 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drvinst.exe
[2012/10/24 12:09:53 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\devrtl.dll
[2012/10/24 12:09:51 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2012/10/24 12:09:51 | 002,690,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2012/10/24 12:09:51 | 001,097,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe
[2012/10/24 12:09:51 | 001,034,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe
[2012/10/24 12:09:50 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netapi32.dll
[2012/10/24 12:09:50 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browcli.dll
[2012/10/24 12:09:49 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\browcli.dll
[2012/10/24 12:09:48 | 014,627,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2012/10/24 12:09:47 | 011,406,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2012/10/24 12:09:46 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
[2012/10/24 12:09:45 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
[2012/10/24 12:09:42 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\prevhost.exe
[2012/10/24 12:09:42 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\prevhost.exe
[2012/10/24 12:09:41 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2012/10/24 12:09:38 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FXSCOVER.exe
[2012/10/24 12:09:35 | 000,634,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvcrt.dll
[2012/10/24 12:09:34 | 000,112,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\consent.exe
[2012/10/24 12:09:29 | 000,956,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll
[2012/10/24 12:09:27 | 000,861,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2012/10/24 12:09:27 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleacc.dll
[2012/10/24 12:09:26 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2012/10/24 12:09:25 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2012/10/24 12:09:08 | 000,720,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbc32.dll
[2012/10/24 12:09:08 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbc32.dll
[2012/10/24 12:09:06 | 000,751,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll
[2012/10/24 12:09:06 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll
[2012/10/24 12:09:06 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\splwow64.exe
[2012/10/24 12:09:04 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sscore.dll
[2012/10/24 12:09:03 | 001,739,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2012/10/24 12:08:59 | 001,462,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2012/10/24 12:08:58 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2012/10/24 12:08:52 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll
[2012/10/24 12:08:52 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll
[2012/10/24 11:51:13 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cabview.dll
[2012/10/24 11:51:13 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cabview.dll
[2012/10/24 11:50:52 | 001,031,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcore.dll
[2012/10/24 11:50:52 | 000,826,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpcore.dll
[2012/10/24 11:45:36 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2012/10/24 11:45:36 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2012/10/24 11:45:35 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2012/10/24 11:45:24 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2012/10/24 11:45:24 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2012/10/24 11:45:24 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2012/10/24 11:45:16 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2012/10/24 11:45:16 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2012/10/24 11:42:22 | 001,057,896 | ---- | C] (NETGEAR Corporation ) -- C:\Windows\SysNative\drivers\wna3100m.sys
[2012/10/24 11:42:20 | 000,595,968 | ---- | C] (Realtek Semiconductor Corp. ) -- C:\Windows\SysWow64\Rtlihvs.dll
[2012/10/24 11:42:20 | 000,595,968 | ---- | C] (Realtek Semiconductor Corp. ) -- C:\Windows\SysNative\Rtlihvs.dll
[2012/10/24 11:42:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NETGEAR WNA3100M Genie
[2012/10/24 11:42:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NETGEAR

========== Files - Modified Within 30 Days ==========

[2012/11/12 09:51:11 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/12 09:46:43 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/12 09:46:43 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/12 09:44:39 | 000,726,142 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/12 09:44:39 | 000,623,940 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/11/12 09:44:39 | 000,106,316 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/11/12 09:40:02 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/12 09:39:32 | 000,000,290 | ---- | M] () -- C:\Windows\tasks\AutoKMS.job
[2012/11/12 09:39:27 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/11/12 09:39:22 | 3169,013,760 | -HS- | M] () -- C:\hiberfil.sys
[2012/11/11 20:32:38 | 000,001,292 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2012/11/11 09:17:03 | 000,021,450 | ---- | M] () -- C:\Users\Owner\Documents\ArtisanBid.dotx
[2012/11/01 08:21:08 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012/10/30 20:27:08 | 000,696,760 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/10/30 20:27:08 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/10/30 14:51:56 | 000,059,728 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2012/10/30 14:51:55 | 000,984,144 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2012/10/30 14:51:55 | 000,370,288 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2012/10/30 14:51:55 | 000,071,600 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/10/30 14:51:53 | 000,025,232 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/10/30 14:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2012/10/30 14:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2012/10/30 14:50:30 | 000,285,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2012/10/25 08:35:50 | 000,001,437 | ---- | M] () -- C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/10/25 04:46:51 | 000,416,056 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/10/25 02:29:47 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/10/25 02:29:47 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2012/10/25 02:29:47 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll
[2012/10/25 02:29:47 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2012/10/25 02:29:47 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2012/10/25 02:29:47 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2012/10/25 02:29:47 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2012/10/25 02:29:46 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2012/10/25 02:29:46 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2012/10/25 02:29:46 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2012/10/25 02:29:46 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/10/25 02:29:46 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2012/10/25 02:29:46 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2012/10/25 02:29:46 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2012/10/25 02:29:46 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
[2012/10/25 02:29:46 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
 
Cont...
[2012/10/25 02:29:46 | 000,063,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2012/10/25 02:29:46 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2012/10/25 02:29:46 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2012/10/25 02:29:45 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012/10/25 02:29:45 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/10/25 02:29:45 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2012/10/25 02:29:45 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2012/10/25 02:29:45 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2012/10/25 02:29:45 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/10/25 02:29:45 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2012/10/25 02:29:45 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2012/10/25 02:29:45 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2012/10/25 02:29:44 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
[2012/10/25 02:29:44 | 000,222,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2012/10/25 02:29:44 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll
[2012/10/25 02:29:44 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012/10/25 02:29:44 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2012/10/25 02:29:44 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll
[2012/10/25 02:29:44 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2012/10/25 02:29:43 | 002,312,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012/10/25 02:29:43 | 000,816,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/10/25 02:29:43 | 000,267,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieaksie.dll
[2012/10/25 02:29:43 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2012/10/25 02:29:43 | 000,173,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012/10/25 02:29:43 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieakui.dll
[2012/10/25 02:29:43 | 000,149,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2012/10/25 02:29:43 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2012/10/25 02:29:43 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2012/10/25 02:29:43 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\admparse.dll
[2012/10/25 02:29:43 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2012/10/25 02:29:43 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2012/10/25 02:29:43 | 000,012,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2012/10/25 02:29:43 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2012/10/25 02:29:42 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2012/10/25 02:29:42 | 000,534,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2012/10/25 02:29:42 | 000,452,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2012/10/25 02:29:42 | 000,448,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2012/10/25 02:29:42 | 000,282,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2012/10/25 02:29:42 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/10/25 02:29:42 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieakeng.dll
[2012/10/25 02:29:42 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2012/10/25 02:29:42 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2012/10/25 02:29:42 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2012/10/25 02:29:42 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2012/10/25 02:29:42 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2012/10/25 02:29:42 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2012/10/25 02:29:42 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2012/10/25 02:29:42 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2012/10/25 02:29:42 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2012/10/25 02:29:41 | 001,494,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012/10/25 02:29:41 | 000,729,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2012/10/25 02:29:41 | 000,599,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2012/10/25 02:29:41 | 000,237,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/10/25 02:29:41 | 000,165,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2012/10/25 02:29:41 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2012/10/25 02:29:41 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2012/10/25 02:29:41 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/10/25 02:29:41 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2012/10/24 13:44:40 | 000,001,800 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/10/24 11:42:18 | 000,001,048 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNA3100M Genie.lnk
[2012/10/15 07:59:28 | 000,054,072 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys

========== Files Created - No Company Name ==========

[2012/11/11 18:46:33 | 000,000,896 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/11 18:46:32 | 000,000,892 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/11 09:17:03 | 000,021,450 | ---- | C] () -- C:\Users\Owner\Documents\ArtisanBid.dotx
[2012/11/01 08:21:07 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2012/10/25 02:29:46 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2012/10/25 02:29:42 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2012/10/24 11:42:18 | 000,001,048 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNA3100M Genie.lnk
[2012/10/23 20:42:58 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2012/10/01 13:36:36 | 000,033,134 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\UserTile.png
[2012/09/22 09:18:32 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin

========== ZeroAccess Check ==========

[2012/11/12 09:39:27 | 000,004,608 | -HS- | M] () -- C:\Windows\assembly\GAC_32\Desktop.ini
[2012/11/12 09:39:27 | 000,006,144 | -HS- | M] () -- C:\Windows\assembly\GAC_64\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 21:30:56 | 014,165,504 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 20:46:56 | 012,868,608 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 17:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/13 17:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 17:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report >
 
Frst log.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-11-2012
Ran by SYSTEM at 13-11-2012 12:08:51
Running from E:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [mxomssmenu] "C:\Program Files (x86)\Maxtor\OneTouch Status\maxmenumgr.exe" [169264 2007-09-06] (Maxtor Corporation)
HKLM-x32\...\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4297136 2012-10-30] (AVAST Software)
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
Startup: C:\Users\All Users\Start Menu\Programs\Startup\NETGEAR WNA3100M Genie.lnk
ShortcutTarget: NETGEAR WNA3100M Genie.lnk -> C:\Program Files (x86)\NETGEAR\WNA3100M\WNA3100M.exe ()
Startup: C:\Users\Owner\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ===================
2 avast! Antivirus; "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [44808 2012-10-30] (AVAST Software)
2 Maxtor Sync Service; "C:\Program Files (x86)\Maxtor\Sync\SyncServices.exe" [156976 2007-09-28] (Seagate Technology LLC)
2 MBAMScheduler; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe" [399432 2012-09-29] (Malwarebytes Corporation)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [676936 2012-09-29] (Malwarebytes Corporation)
2 WSWNA3100M; C:\Program Files (x86)\NETGEAR\WNA3100M\WifiSvc.exe [303360 2011-12-07] ()
==================== Drivers (Whitelisted) =====================
2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [25232 2012-10-30] (AVAST Software)
2 aswMonFlt; C:\Windows\System32\Drivers\aswMonFlt.sys [71600 2012-10-30] (AVAST Software)
1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [54072 2012-10-15] (AVAST Software)
1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [984144 2012-10-30] (AVAST Software)
1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [370288 2012-10-30] (AVAST Software)
1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [59728 2012-10-30] (AVAST Software)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [25928 2012-09-29] (Malwarebytes Corporation)
3 wna3100m; C:\Windows\System32\Drivers\wna3100m.sys [1057896 2011-11-28] (NETGEAR Corporation )
==================== NetSvcs (Whitelisted) ====================

==================== One Month Created Files and Folders ========
2012-11-13 12:08 - 2012-11-13 12:08 - 00000000 ____D C:\FRST
2012-11-12 08:45 - 2012-11-12 08:45 - 00001040 ____A C:\AdwCleaner[S2].txt
2012-11-12 08:45 - 2012-11-12 08:45 - 00000979 ____A C:\AdwCleaner[R5].txt
2012-11-12 08:43 - 2012-11-12 08:43 - 00000920 ____A C:\AdwCleaner[R4].txt
2012-11-11 18:46 - 2012-11-13 12:04 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-11-11 18:46 - 2012-11-13 11:51 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-11-11 18:46 - 2012-11-11 18:48 - 00000000 ____D C:\Users\Owner\AppData\Local\Google
2012-11-11 18:46 - 2012-11-11 18:48 - 00000000 ____D C:\Program Files (x86)\Google
2012-11-11 18:45 - 2012-11-11 18:45 - 00763416 ____A (Google Inc.) C:\Users\Owner\Downloads\GoogleEarthSetup.exe
2012-11-11 13:20 - 2012-11-11 13:20 - 00000000 ____D C:\_OTL
2012-11-11 09:17 - 2012-11-11 09:17 - 00021450 ____A C:\Users\Owner\Documents\ArtisanBid.dotx
2012-11-10 18:09 - 2012-11-11 13:20 - 00000000 ____D C:\Users\Owner\Desktop\antivirusSoft
2012-11-10 07:56 - 2012-11-12 09:45 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-11-01 17:09 - 2012-11-01 17:09 - 00000847 ____A C:\AdwCleaner[R3].txt
2012-11-01 16:25 - 2012-11-01 16:25 - 00000974 ____A C:\AdwCleaner[S1].txt
2012-11-01 16:24 - 2012-11-01 16:24 - 00000907 ____A C:\AdwCleaner[R2].txt
2012-11-01 16:18 - 2012-11-01 16:18 - 00000848 ____A C:\AdwCleaner[R1].txt
2012-11-01 15:25 - 2012-11-01 15:25 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Malwarebytes
2012-11-01 15:24 - 2012-11-01 15:24 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-11-01 15:24 - 2012-11-01 15:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-11-01 15:24 - 2012-09-29 18:54 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-11-01 14:58 - 2012-11-01 15:00 - 10669952 ____A (Malwarebytes Corporation ) C:\Users\Owner\Downloads\mbam-setup-1.65.1.1000.exe
2012-11-01 08:26 - 2012-11-01 08:26 - 00540977 ____A C:\Users\Owner\Downloads\adwcleaner (1).exe
2012-11-01 08:21 - 2012-11-01 08:21 - 00000000 ____A C:\Windows\SysWOW64\config.nt
2012-11-01 08:21 - 2012-10-30 14:51 - 00984144 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2012-11-01 08:21 - 2012-10-30 14:51 - 00370288 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2012-11-01 08:21 - 2012-10-30 14:51 - 00071600 ____A (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
2012-11-01 08:21 - 2012-10-30 14:51 - 00059728 ____A (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys
2012-11-01 08:21 - 2012-10-30 14:51 - 00025232 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys
2012-11-01 08:21 - 2012-10-30 14:50 - 00285328 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe
2012-11-01 08:21 - 2012-10-15 07:59 - 00054072 ____A (AVAST Software) C:\Windows\System32\Drivers\aswRdr2.sys
2012-11-01 08:20 - 2012-11-01 08:20 - 00000000 ____D C:\Users\All Users\AVAST Software
2012-11-01 08:20 - 2012-11-01 08:20 - 00000000 ____D C:\Program Files\AVAST Software
2012-11-01 08:20 - 2012-10-30 14:51 - 00041224 ____A (AVAST Software) C:\Windows\avastSS.scr
2012-11-01 08:20 - 2012-10-30 14:50 - 00227648 ____A (AVAST Software) C:\Windows\SysWOW64\aswBoot.exe
2012-11-01 08:09 - 2012-11-01 08:09 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-10-31 10:56 - 2012-10-31 10:56 - 00540977 ____A C:\Users\Owner\Downloads\adwcleaner.exe
2012-10-26 08:26 - 2012-10-26 08:27 - 00000000 ____D C:\Program Files (x86)\Maxtor
2012-10-26 08:26 - 2012-10-26 08:26 - 00000000 ____D C:\Users\All Users\Maxtor
2012-10-26 08:25 - 2012-10-26 08:25 - 00000000 ____D C:\Windows\Downloaded Installations
2012-10-25 16:43 - 2012-10-25 16:43 - 00000000 ____D C:\Program Files (x86)\Red Sky
 
Cont.
2012-10-25 16:43 - 2012-10-25 16:43 - 00000000 ____D C:\Program Files (x86)\Red Sky
2012-10-25 09:22 - 2011-03-24 19:23 - 00343040 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbhub.sys
2012-10-25 09:22 - 2011-03-24 19:23 - 00324608 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbport.sys
2012-10-25 09:22 - 2011-03-24 19:23 - 00098816 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbccgp.sys
2012-10-25 09:22 - 2011-03-24 19:22 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbehci.sys
2012-10-25 09:22 - 2011-03-24 19:22 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbuhci.sys
2012-10-25 09:22 - 2011-03-24 19:22 - 00025600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbohci.sys
2012-10-25 09:22 - 2011-03-24 19:22 - 00007936 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usbd.sys
2012-10-25 09:22 - 2011-03-10 22:23 - 00410496 ____A (Intel Corporation) C:\Windows\System32\Drivers\iaStorV.sys
2012-10-25 09:22 - 2011-03-10 22:23 - 00187264 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\storport.sys
2012-10-25 09:22 - 2011-03-10 22:23 - 00166272 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvstor.sys
2012-10-25 09:22 - 2011-03-10 22:23 - 00148352 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvraid.sys
2012-10-25 09:22 - 2011-03-10 22:22 - 00107904 ____A (Advanced Micro Devices) C:\Windows\System32\Drivers\amdsata.sys
2012-10-25 09:22 - 2011-03-10 22:22 - 00027008 ____A (Advanced Micro Devices) C:\Windows\System32\Drivers\amdxata.sys
2012-10-25 09:22 - 2011-03-10 22:18 - 02566144 ____A (Microsoft Corporation) C:\Windows\System32\esent.dll
2012-10-25 09:22 - 2011-03-10 22:15 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\fsutil.exe
2012-10-25 09:22 - 2011-03-10 21:39 - 01686016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2012-10-25 09:22 - 2011-03-10 21:37 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe
2012-10-25 09:22 - 2011-03-10 20:31 - 00091136 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\USBSTOR.SYS
2012-10-25 04:07 - 2010-09-13 22:45 - 00367104 ____A (Microsoft Corporation) C:\Windows\System32\wcncsvc.dll
2012-10-25 04:07 - 2010-09-13 22:07 - 00276992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wcncsvc.dll
2012-10-25 03:20 - 2009-09-09 22:28 - 00311808 ____A (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
2012-10-25 03:20 - 2009-09-09 21:52 - 00257024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2012-10-25 02:37 - 2009-11-25 11:47 - 01942856 ____A (Microsoft Corporation) C:\Windows\System32\dfshim.dll
2012-10-25 02:37 - 2009-11-25 11:47 - 01130824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2012-10-25 02:37 - 2009-11-25 11:47 - 00444752 ____A (Microsoft Corporation) C:\Windows\System32\mscoree.dll
2012-10-25 02:37 - 2009-11-25 11:47 - 00320352 ____A (Microsoft Corporation) C:\Windows\System32\PresentationHost.exe
2012-10-25 02:37 - 2009-11-25 11:47 - 00297808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mscoree.dll
2012-10-25 02:37 - 2009-11-25 11:47 - 00295264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHost.exe
2012-10-25 02:37 - 2009-11-25 11:47 - 00109912 ____A (Microsoft Corporation) C:\Windows\System32\PresentationHostProxy.dll
2012-10-25 02:37 - 2009-11-25 11:47 - 00099176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHostProxy.dll
2012-10-25 02:37 - 2009-11-25 11:47 - 00049472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netfxperf.dll
2012-10-25 02:37 - 2009-11-25 11:47 - 00048960 ____A (Microsoft Corporation) C:\Windows\System32\netfxperf.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 17810944 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 12319744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 03695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2012-10-25 02:29 - 2012-10-25 02:29 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-10-25 02:29 - 2012-10-25 02:29 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-10-25 02:29 - 2012-10-25 02:29 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-10-25 02:29 - 2012-10-25 02:29 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-10-25 02:29 - 2012-10-25 02:29 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-10-25 02:29 - 2012-10-25 02:29 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00534528 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00452608 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00448512 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-10-25 02:29 - 2012-10-25 02:29 - 00434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00403248 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
 
Cont.
2012-10-25 02:29 - 2012-10-25 02:29 - 00353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00282112 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00267776 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00249344 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00165888 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00145920 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00135168 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00114176 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00111616 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00091648 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-10-25 02:29 - 2012-10-25 02:29 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2012-10-25 02:29 - 2012-10-25 02:29 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00049664 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-10-25 02:25 - 2012-10-25 02:31 - 00004039 ____A C:\Windows\IE9_main.log
2012-10-25 02:05 - 2012-02-29 22:54 - 00022896 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fs_rec.sys
2012-10-25 02:05 - 2012-02-29 22:40 - 00080896 ____A (Microsoft Corporation) C:\Windows\System32\imagehlp.dll
2012-10-25 02:05 - 2012-02-29 22:35 - 00005120 ____A (Microsoft Corporation) C:\Windows\System32\wmi.dll
2012-10-25 02:05 - 2012-02-29 21:45 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2012-10-25 02:05 - 2012-02-29 21:40 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2012-10-25 02:01 - 2010-03-03 20:32 - 00243712 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ks.sys
2012-10-24 12:37 - 2012-10-30 20:27 - 00696760 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-10-24 12:37 - 2012-10-30 20:27 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-10-24 12:37 - 2012-10-24 12:37 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2012-10-24 12:37 - 2012-10-24 12:37 - 00000000 ____D C:\Windows\System32\Macromed
2012-10-24 12:17 - 2012-08-31 10:02 - 01656688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
2012-10-24 12:16 - 2012-07-18 09:31 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-10-24 12:16 - 2012-03-02 22:29 - 01837568 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll
2012-10-24 12:16 - 2012-03-02 22:29 - 01541120 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2012-10-24 12:16 - 2012-03-02 22:29 - 00902656 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll
2012-10-24 12:16 - 2012-03-02 22:29 - 00320512 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll
2012-10-24 12:16 - 2012-03-02 22:29 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll
2012-10-24 12:16 - 2012-03-02 21:40 - 01170944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2012-10-24 12:16 - 2012-03-02 21:40 - 01074176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2012-10-24 12:16 - 2012-03-02 21:40 - 00739840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2012-10-24 12:16 - 2012-03-02 21:40 - 00218624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2012-10-24 12:16 - 2012-03-02 21:40 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2012-10-24 12:16 - 2011-06-15 21:31 - 00199680 ____A (Microsoft Corporation) C:\Windows\System32\xmllite.dll
2012-10-24 12:16 - 2011-06-15 20:35 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\xmllite.dll
2012-10-24 12:16 - 2011-06-15 01:58 - 00212992 ____A (Microsoft Corporation) C:\Windows\System32\odbctrac.dll
2012-10-24 12:16 - 2011-06-15 01:58 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\odbccp32.dll
2012-10-24 12:16 - 2011-06-15 01:58 - 00106496 ____A (Microsoft Corporation) C:\Windows\System32\odbccu32.dll
2012-10-24 12:16 - 2011-06-15 01:58 - 00106496 ____A (Microsoft Corporation) C:\Windows\System32\odbccr32.dll
2012-10-24 12:16 - 2011-06-15 01:04 - 00319488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
2012-10-24 12:16 - 2011-06-15 01:04 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
2012-10-24 12:16 - 2011-06-15 01:04 - 00122880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
2012-10-24 12:16 - 2011-06-15 01:04 - 00086016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
2012-10-24 12:16 - 2011-06-15 01:04 - 00081920 ____A (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
2012-10-24 12:16 - 2011-04-26 18:57 - 00102400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dfsc.sys
2012-10-24 12:16 - 2011-04-08 22:58 - 00142336 ____A (Microsoft Corporation) C:\Windows\System32\poqexec.exe
2012-10-24 12:16 - 2011-04-08 21:56 - 00123904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2012-10-24 12:16 - 2011-02-25 22:23 - 02870272 ____A (Microsoft Corporation) C:\Windows\explorer.exe
 
Cont.
2012-10-24 12:16 - 2011-02-25 21:33 - 02614784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2012-10-24 12:16 - 2010-12-22 22:07 - 01118720 ____A (Microsoft Corporation) C:\Windows\System32\sbe.dll
2012-10-24 12:16 - 2010-12-22 22:07 - 00961024 ____A (Microsoft Corporation) C:\Windows\System32\CPFilters.dll
2012-10-24 12:16 - 2010-12-22 22:02 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\mpg2splt.ax
2012-10-24 12:16 - 2010-12-22 21:28 - 00850432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2012-10-24 12:16 - 2010-12-22 21:28 - 00642048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2012-10-24 12:16 - 2010-12-22 21:24 - 00199680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax
2012-10-24 12:16 - 2010-08-25 21:27 - 00148992 ____A (Microsoft Corporation) C:\Windows\System32\t2embed.dll
2012-10-24 12:16 - 2010-08-25 20:39 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2012-10-24 12:16 - 2010-03-04 23:52 - 00084992 ____A (Microsoft Corporation) C:\Windows\System32\asycfilt.dll
2012-10-24 12:16 - 2010-03-04 23:42 - 00067584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2012-10-24 12:15 - 2012-01-04 01:58 - 00509952 ____A (Microsoft Corporation) C:\Windows\System32\ntshrui.dll
2012-10-24 12:15 - 2012-01-04 01:03 - 00442880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2012-10-24 12:15 - 2011-10-25 21:22 - 01572864 ____A (Microsoft Corporation) C:\Windows\System32\quartz.dll
2012-10-24 12:15 - 2011-10-25 21:22 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-10-24 12:15 - 2011-10-25 20:28 - 01328640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2012-10-24 12:15 - 2011-10-25 20:28 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-10-24 12:15 - 2010-06-28 21:39 - 02085376 ____A (Microsoft Corporation) C:\Windows\System32\ole32.dll
2012-10-24 12:15 - 2010-06-28 21:02 - 01413632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2012-10-24 12:14 - 2012-06-05 21:50 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-10-24 12:14 - 2012-06-05 21:50 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-10-24 12:14 - 2012-06-05 21:09 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-10-24 12:14 - 2012-06-05 21:09 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-10-24 12:14 - 2012-01-02 22:24 - 00515584 ____A (Microsoft Corporation) C:\Windows\System32\timedate.cpl
2012-10-24 12:14 - 2012-01-02 21:44 - 00478208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
2012-10-24 12:14 - 2011-11-16 23:12 - 00395776 ____A (Microsoft Corporation) C:\Windows\System32\webio.dll
2012-10-24 12:14 - 2011-11-16 21:39 - 00314368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2012-10-24 12:14 - 2011-10-25 21:19 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
2012-10-24 12:14 - 2011-07-08 18:44 - 00287744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys
2012-10-24 12:14 - 2011-05-03 21:30 - 02326016 ____A (Microsoft Corporation) C:\Windows\System32\tquery.dll
2012-10-24 12:14 - 2011-05-03 21:28 - 02228224 ____A (Microsoft Corporation) C:\Windows\System32\mssrch.dll
2012-10-24 12:14 - 2011-05-03 21:28 - 00779264 ____A (Microsoft Corporation) C:\Windows\System32\mssvp.dll
2012-10-24 12:14 - 2011-05-03 21:28 - 00491520 ____A (Microsoft Corporation) C:\Windows\System32\mssph.dll
2012-10-24 12:14 - 2011-05-03 21:28 - 00288256 ____A (Microsoft Corporation) C:\Windows\System32\mssphtb.dll
2012-10-24 12:14 - 2011-05-03 21:28 - 00075264 ____A (Microsoft Corporation) C:\Windows\System32\msscntrs.dll
2012-10-24 12:14 - 2011-05-03 21:24 - 00593408 ____A (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe
2012-10-24 12:14 - 2011-05-03 21:24 - 00249856 ____A (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe
2012-10-24 12:14 - 2011-05-03 21:24 - 00113664 ____A (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe
2012-10-24 12:14 - 2011-05-03 20:53 - 01553920 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2012-10-24 12:14 - 2011-05-03 20:52 - 01401856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2012-10-24 12:14 - 2011-05-03 20:52 - 00666624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2012-10-24 12:14 - 2011-05-03 20:52 - 00428032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2012-10-24 12:14 - 2011-05-03 20:52 - 00337408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2012-10-24 12:14 - 2011-05-03 20:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2012-10-24 12:14 - 2011-05-03 20:52 - 00164352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2012-10-24 12:14 - 2011-05-03 20:52 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2012-10-24 12:14 - 2011-05-03 20:52 - 00059392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2012-10-24 12:14 - 2011-05-03 18:51 - 00157696 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys
2012-10-24 12:14 - 2011-05-03 18:51 - 00126464 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys
2012-10-24 12:14 - 2011-02-23 22:30 - 00476160 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll
2012-10-24 12:14 - 2011-02-23 21:32 - 00288256 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2012-10-24 12:14 - 2010-11-01 21:18 - 00524288 ____A (Microsoft Corporation) C:\Windows\System32\wmicmiplugin.dll
2012-10-24 12:14 - 2010-11-01 21:17 - 01169408 ____A (Microsoft Corporation) C:\Windows\System32\taskschd.dll
2012-10-24 12:14 - 2010-11-01 21:17 - 00473600 ____A (Microsoft Corporation) C:\Windows\System32\taskcomp.dll
2012-10-24 12:14 - 2010-11-01 21:16 - 01114624 ____A (Microsoft Corporation) C:\Windows\System32\schedsvc.dll
2012-10-24 12:14 - 2010-11-01 21:10 - 00464384 ____A (Microsoft Corporation) C:\Windows\System32\taskeng.exe
2012-10-24 12:14 - 2010-11-01 21:10 - 00285696 ____A (Microsoft Corporation) C:\Windows\System32\schtasks.exe
2012-10-24 12:14 - 2010-11-01 20:40 - 00496128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll
2012-10-24 12:14 - 2010-11-01 20:40 - 00305152 ____A (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2012-10-24 12:14 - 2010-11-01 20:34 - 00192000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2012-10-24 12:14 - 2010-11-01 20:34 - 00179712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
2012-10-24 12:14 - 2010-08-03 23:07 - 00552960 ____A (Microsoft Corporation) C:\Windows\System32\msdri.dll
2012-10-24 12:14 - 2010-05-04 23:37 - 00483840 ____A (Microsoft Corporation) C:\Windows\System32\StructuredQuery.dll
2012-10-24 12:14 - 2010-05-04 22:46 - 00363520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2012-10-24 12:14 - 2010-01-19 01:05 - 00424960 ____A (Microsoft Corporation) C:\Windows\System32\secproc.dll
2012-10-24 12:14 - 2010-01-19 01:05 - 00422912 ____A (Microsoft Corporation) C:\Windows\System32\secproc_isv.dll
2012-10-24 12:14 - 2010-01-19 01:05 - 00121856 ____A (Microsoft Corporation) C:\Windows\System32\secproc_ssp_isv.dll
2012-10-24 12:14 - 2010-01-19 01:05 - 00121856 ____A (Microsoft Corporation) C:\Windows\System32\secproc_ssp.dll
2012-10-24 12:14 - 2010-01-19 01:00 - 00357888 ____A (Microsoft Corporation) C:\Windows\System32\RMActivate_isv.exe
2012-10-24 12:14 - 2010-01-19 01:00 - 00356352 ____A (Microsoft Corporation) C:\Windows\System32\RMActivate.exe
2012-10-24 12:14 - 2010-01-19 01:00 - 00306688 ____A (Microsoft Corporation) C:\Windows\System32\RMActivate_ssp.exe
2012-10-24 12:14 - 2010-01-19 01:00 - 00305152 ____A (Microsoft Corporation) C:\Windows\System32\RMActivate_ssp_isv.exe
2012-10-24 12:14 - 2010-01-18 15:29 - 00369152 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2012-10-24 12:14 - 2010-01-18 15:29 - 00365568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2012-10-24 12:14 - 2010-01-18 15:29 - 00085504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2012-10-24 12:14 - 2010-01-18 15:29 - 00085504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2012-10-24 12:14 - 2010-01-18 15:28 - 00324608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2012-10-24 12:14 - 2010-01-18 15:28 - 00320512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2012-10-24 12:14 - 2010-01-18 15:28 - 00280064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2012-10-24 12:14 - 2010-01-18 15:28 - 00277504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2012-10-24 12:14 - 2009-09-02 23:36 - 01975296 ____A (Microsoft Corporation) C:\Windows\System32\CertEnroll.dll
2012-10-24 12:14 - 2009-09-02 23:04 - 01320960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2012-10-24 12:13 - 2012-08-30 10:11 - 05505904 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-10-24 12:13 - 2012-08-30 09:18 - 03958128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-10-24 12:13 - 2012-08-30 09:18 - 03902832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-10-24 12:13 - 2012-08-18 07:43 - 00362496 ____A (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2012-10-24 12:13 - 2012-08-18 07:43 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\wow64.dll
2012-10-24 12:13 - 2012-08-18 07:43 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2012-10-24 12:13 - 2012-08-18 07:42 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2012-10-24 12:13 - 2012-08-18 07:40 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2012-10-24 12:13 - 2012-08-18 07:37 - 01162240 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2012-10-24 12:13 - 2012-08-18 07:37 - 00425984 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2012-10-24 12:13 - 2012-08-18 07:34 - 00338432 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
 
Cont.
2012-10-24 12:13 - 2012-08-18 07:22 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 07:22 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:22 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2012-10-24 12:13 - 2012-08-18 03:19 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2012-10-24 12:13 - 2012-08-18 03:17 - 01114112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2012-10-24 12:13 - 2012-08-18 03:17 - 00274944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2012-10-24 12:13 - 2012-08-18 03:17 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00005120 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 03:09 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 01:12 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2012-10-24 12:13 - 2012-08-18 01:12 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2012-10-24 12:13 - 2012-08-18 01:07 - 00006144 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 01:07 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 01:07 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2012-10-24 12:13 - 2012-08-18 01:07 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2012-10-24 12:13 - 2012-08-02 09:55 - 00574464 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-10-24 12:13 - 2012-08-02 09:05 - 00490496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2012-10-24 12:13 - 2012-06-08 21:30 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-10-24 12:13 - 2012-06-08 20:46 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-10-24 12:13 - 2012-04-25 21:34 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-10-24 12:13 - 2012-04-25 21:34 - 00076288 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-10-24 12:13 - 2012-04-25 21:28 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-10-24 12:13 - 2011-03-12 04:03 - 00662528 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll
2012-10-24 12:13 - 2011-03-12 03:31 - 00442880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2012-10-24 12:13 - 2011-03-10 22:19 - 01395712 ____A (Microsoft Corporation) C:\Windows\System32\mfc42.dll
2012-10-24 12:13 - 2011-03-10 22:19 - 01359872 ____A (Microsoft Corporation) C:\Windows\System32\mfc42u.dll
2012-10-24 12:13 - 2011-03-10 21:40 - 01164288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2012-10-24 12:13 - 2011-03-10 21:40 - 01137664 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2012-10-24 12:13 - 2010-12-20 22:16 - 00442880 ____A (Microsoft Corporation) C:\Windows\System32\winhttp.dll
2012-10-24 12:13 - 2010-12-20 22:16 - 00258048 ____A (Microsoft Corporation) C:\Windows\System32\WebClnt.dll
2012-10-24 12:13 - 2010-12-20 22:16 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\wscsvc.dll
2012-10-24 12:13 - 2010-12-20 22:16 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\wscapi.dll
2012-10-24 12:13 - 2010-12-20 22:15 - 00264192 ____A (Microsoft Corporation) C:\Windows\System32\upnp.dll
2012-10-24 12:13 - 2010-12-20 22:15 - 00015360 ____A (Microsoft Corporation) C:\Windows\System32\slwga.dll
2012-10-24 12:13 - 2010-12-20 22:10 - 00100864 ____A (Microsoft Corporation) C:\Windows\System32\davclnt.dll
2012-10-24 12:13 - 2010-12-20 21:38 - 00350720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2012-10-24 12:13 - 2010-12-20 21:38 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2012-10-24 12:13 - 2010-12-20 21:38 - 00204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\upnp.dll
2012-10-24 12:13 - 2010-12-20 21:38 - 00051200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2012-10-24 12:13 - 2010-12-20 21:38 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\slwga.dll
2012-10-24 12:13 - 2010-12-20 21:34 - 00080384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2012-10-24 12:13 - 2010-08-20 22:31 - 00633856 ____A (Microsoft Corporation) C:\Windows\System32\comctl32.dll
2012-10-24 12:13 - 2010-08-20 21:33 - 00530432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2012-10-24 12:13 - 2010-06-18 22:53 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\rtutils.dll
2012-10-24 12:13 - 2010-06-18 22:23 - 00037376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rtutils.dll
2012-10-24 12:13 - 2009-10-27 22:24 - 00389632 ____A (Microsoft Corporation) C:\Windows\System32\winlogon.exe
2012-10-24 12:12 - 2012-06-01 21:38 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-10-24 12:12 - 2012-06-01 21:38 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-10-24 12:12 - 2012-06-01 21:37 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-10-24 12:12 - 2012-06-01 21:27 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-10-24 12:12 - 2012-06-01 21:27 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-10-24 12:12 - 2012-06-01 20:48 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-10-24 12:12 - 2012-06-01 20:48 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-10-24 12:12 - 2012-06-01 20:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-10-24 12:12 - 2012-06-01 20:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-10-24 12:12 - 2012-05-01 21:32 - 00208896 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-10-24 12:12 - 2011-11-16 23:11 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2012-10-24 12:12 - 2011-11-16 23:11 - 00028672 ____A (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2012-10-24 12:12 - 2011-11-16 23:11 - 00028160 ____A (Microsoft Corporation) C:\Windows\System32\secur32.dll
2012-10-24 12:12 - 2011-11-16 23:08 - 01446912 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2012-10-24 12:12 - 2011-11-16 23:05 - 00031232 ____A (Microsoft Corporation) C:\Windows\System32\lsass.exe
2012-10-24 12:12 - 2011-04-22 12:18 - 00027008 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\Diskdump.sys
2012-10-24 12:12 - 2011-03-02 22:17 - 00356352 ____A (Microsoft Corporation) C:\Windows\System32\dnsapi.dll
2012-10-24 12:12 - 2011-03-02 22:17 - 00182272 ____A (Microsoft Corporation) C:\Windows\System32\dnsrslvr.dll
2012-10-24 12:12 - 2011-03-02 22:14 - 00030208 ____A (Microsoft Corporation) C:\Windows\System32\dnscacheugc.exe
2012-10-24 12:12 - 2011-03-02 21:29 - 00269824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2012-10-24 12:12 - 2011-03-02 21:27 - 00028672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2012-10-24 12:12 - 2011-02-18 22:36 - 00046080 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
2012-10-24 12:12 - 2011-02-18 21:32 - 00034304 ____A (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2012-10-24 12:12 - 2011-02-18 20:13 - 00367104 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2012-10-24 12:12 - 2011-02-18 19:37 - 00294912 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2012-10-24 12:12 - 2011-01-25 22:53 - 00982912 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2012-10-24 12:12 - 2011-01-25 22:53 - 00265088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2012-10-24 12:12 - 2011-01-25 22:31 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll
2012-10-24 12:12 - 2010-11-01 21:18 - 00229888 ____A (Microsoft Corporation) C:\Windows\System32\XpsRasterService.dll
2012-10-24 12:12 - 2010-11-01 21:12 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll
2012-10-24 12:12 - 2010-11-01 20:41 - 00135168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsRasterService.dll
2012-10-24 12:12 - 2010-07-28 22:30 - 00082944 ____A (Radius Inc.) C:\Windows\SysWOW64\iccvid.dll
2012-10-24 12:12 - 2010-06-25 21:31 - 01863680 ____A (Microsoft Corporation) C:\Windows\System32\ExplorerFrame.dll
2012-10-24 12:12 - 2010-06-25 21:14 - 01495040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2012-10-24 12:12 - 2010-05-23 02:15 - 01619456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2012-10-24 12:12 - 2010-05-23 02:11 - 03181568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2012-10-24 12:12 - 2010-05-23 02:11 - 00196608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2012-10-24 12:12 - 2010-05-23 00:37 - 01888256 ____A (Microsoft Corporation) C:\Windows\System32\WMVDECOD.DLL
2012-10-24 12:12 - 2010-05-23 00:35 - 04068864 ____A (Microsoft Corporation) C:\Windows\System32\mf.dll
2012-10-24 12:12 - 2010-05-23 00:35 - 00257024 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll
2012-10-24 12:12 - 2010-05-23 00:35 - 00206848 ____A (Microsoft Corporation) C:\Windows\System32\mfps.dll
2012-10-24 12:12 - 2009-10-19 06:46 - 00100864 ____A (Microsoft Corporation) C:\Windows\System32\fontsub.dll
2012-10-24 12:12 - 2009-10-19 06:10 - 00070656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2012-10-24 12:12 - 2009-09-25 22:20 - 00223448 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fvevol.sys
2012-10-24 12:11 - 2012-09-14 11:23 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2012-10-24 12:11 - 2012-09-14 10:30 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2012-10-24 12:11 - 2012-08-24 10:05 - 00220160 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2012-10-24 12:11 - 2012-08-24 09:10 - 00172544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2012-10-24 12:11 - 2011-08-16 21:32 - 00613888 ____A (Microsoft Corporation) C:\Windows\System32\psisdecd.dll
2012-10-24 12:11 - 2011-08-16 21:27 - 00288256 ____A (Microsoft Corporation) C:\Windows\System32\MSNP.ax
2012-10-24 12:11 - 2011-08-16 21:27 - 00108032 ____A (Microsoft Corporation) C:\Windows\System32\psisrndr.ax
2012-10-24 12:11 - 2011-08-16 21:27 - 00104960 ____A (Microsoft Corporation) C:\Windows\System32\Mpeg2Data.ax
2012-10-24 12:11 - 2011-08-16 21:27 - 00075776 ____A (Microsoft Corporation) C:\Windows\System32\MSDvbNP.ax
2012-10-24 12:11 - 2011-08-16 20:26 - 00465408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2012-10-24 12:11 - 2011-08-16 20:22 - 00204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSNP.ax
2012-10-24 12:11 - 2011-08-16 20:22 - 00075776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2012-10-24 12:11 - 2011-08-16 20:22 - 00072704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Mpeg2Data.ax
2012-10-24 12:11 - 2011-08-16 20:22 - 00059904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSDvbNP.ax
2012-10-24 12:11 - 2011-04-28 19:13 - 00461312 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv.sys
2012-10-24 12:11 - 2011-04-28 19:12 - 00399872 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
2012-10-24 12:11 - 2011-04-28 19:12 - 00161792 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
2012-10-24 12:11 - 2010-08-20 22:38 - 01024512 ____A (Microsoft Corporation) C:\Windows\System32\wmpmde.dll
2012-10-24 12:11 - 2010-08-20 21:36 - 00738816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
2012-10-24 12:11 - 2009-12-19 01:50 - 00014848 ____A (Microsoft Corporation) C:\Windows\System32\tsbyuv.dll
2012-10-24 12:11 - 2009-12-19 01:47 - 00038912 ____A (Microsoft Corporation) C:\Windows\System32\msvidc32.dll
2012-10-24 12:11 - 2009-12-19 01:47 - 00025088 ____A (Microsoft Corporation) C:\Windows\System32\msyuv.dll
2012-10-24 12:11 - 2009-12-19 01:47 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\msrle32.dll
2012-10-24 12:11 - 2009-12-19 01:46 - 00054272 ____A (Microsoft Corporation) C:\Windows\System32\iyuv_32.dll
2012-10-24 12:11 - 2009-12-19 01:02 - 00091648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\avifil32.dll
2012-10-24 12:11 - 2009-12-19 01:02 - 00084480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mciavi32.dll
2012-10-24 12:11 - 2009-12-19 01:02 - 00050176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iyuv_32.dll
2012-10-24 12:11 - 2009-12-19 01:02 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvidc32.dll
2012-10-24 12:11 - 2009-12-19 01:02 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msyuv.dll
2012-10-24 12:11 - 2009-12-19 01:02 - 00013312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrle32.dll
2012-10-24 12:11 - 2009-12-19 01:02 - 00012288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsbyuv.dll
2012-10-24 12:10 - 2012-08-10 16:53 - 00714752 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2012-10-24 12:10 - 2012-08-10 15:54 - 00541184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2012-10-24 12:10 - 2012-04-27 19:50 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-10-24 12:10 - 2012-04-07 04:18 - 03213824 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-10-24 12:10 - 2012-04-07 03:34 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-10-24 12:10 - 2012-03-16 23:55 - 00075632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys
2012-10-24 12:10 - 2011-12-27 19:59 - 00499200 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\afd.sys
2012-10-24 12:10 - 2011-02-05 04:41 - 00640896 ____A (Microsoft Corporation) C:\Windows\System32\winload.efi
2012-10-24 12:10 - 2011-02-05 04:41 - 00556928 ____A (Microsoft Corporation) C:\Windows\System32\winresume.efi
2012-10-24 12:10 - 2011-02-05 04:41 - 00020352 ____A (Microsoft Corporation) C:\Windows\System32\kdusb.dll
2012-10-24 12:10 - 2011-02-05 04:41 - 00019328 ____A (Microsoft Corporation) C:\Windows\System32\kd1394.dll
2012-10-24 12:10 - 2011-02-05 04:41 - 00017792 ____A (Microsoft Corporation) C:\Windows\System32\kdcom.dll
2012-10-24 12:10 - 2011-02-05 04:39 - 00603976 ____A (Microsoft Corporation) C:\Windows\System32\winload.exe
2012-10-24 12:10 - 2011-02-05 04:39 - 00518160 ____A (Microsoft Corporation) C:\Windows\System32\winresume.exe
2012-10-24 12:10 - 2010-08-30 20:32 - 00954752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc40.dll
2012-10-24 12:10 - 2010-08-30 20:32 - 00954288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc40u.dll
2012-10-24 12:10 - 2009-08-28 23:50 - 00046592 ____A (Microsoft Corporation) C:\Windows\System32\msasn1.dll
2012-10-24 12:10 - 2009-08-28 22:57 - 00034816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msasn1.dll
2012-10-24 12:09 - 2012-07-04 14:04 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-10-24 12:09 - 2012-07-04 14:01 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-10-24 12:09 - 2012-07-04 14:01 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-10-24 12:09 - 2012-07-04 13:26 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-10-24 12:09 - 2012-07-04 13:23 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2012-10-24 12:09 - 2012-05-13 21:20 - 00956416 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2012-10-24 12:09 - 2012-05-05 00:30 - 00503808 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll
2012-10-24 12:09 - 2012-05-04 23:44 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2012-10-24 12:09 - 2012-03-30 03:09 - 01895280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-10-24 12:09 - 2012-02-10 22:36 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2012-10-24 12:09 - 2012-02-10 22:29 - 00559104 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe
2012-10-24 12:09 - 2012-02-10 22:29 - 00067584 ____A (Microsoft Corporation) C:\Windows\splwow64.exe
 
Cont.
2012-10-24 12:09 - 2012-02-10 21:44 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2012-10-24 12:09 - 2011-12-16 00:42 - 00634368 ____A (Microsoft Corporation) C:\Windows\System32\msvcrt.dll
2012-10-24 12:09 - 2011-12-15 23:59 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2012-10-24 12:09 - 2011-11-16 23:14 - 01739160 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2012-10-24 12:09 - 2011-11-16 21:41 - 01292592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2012-10-24 12:09 - 2011-10-14 22:25 - 00723456 ____A (Microsoft Corporation) C:\Windows\System32\EncDec.dll
2012-10-24 12:09 - 2011-10-14 21:48 - 00534528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2012-10-24 12:09 - 2011-08-26 21:40 - 00861184 ____A (Microsoft Corporation) C:\Windows\System32\oleaut32.dll
2012-10-24 12:09 - 2011-08-26 21:40 - 00331776 ____A (Microsoft Corporation) C:\Windows\System32\oleacc.dll
2012-10-24 12:09 - 2011-08-26 20:43 - 00571904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2012-10-24 12:09 - 2011-08-26 20:43 - 00233472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2012-10-24 12:09 - 2011-05-24 03:21 - 00404992 ____A (Microsoft Corporation) C:\Windows\System32\umpnpmgr.dll
2012-10-24 12:09 - 2011-05-24 02:34 - 00145920 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2012-10-24 12:09 - 2011-05-24 02:34 - 00064512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2012-10-24 12:09 - 2011-05-24 02:34 - 00044544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2012-10-24 12:09 - 2011-05-24 02:32 - 00252928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2012-10-24 12:09 - 2011-05-02 21:21 - 00976896 ____A (Microsoft Corporation) C:\Windows\System32\inetcomm.dll
2012-10-24 12:09 - 2011-05-02 20:50 - 00740864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2012-10-24 12:09 - 2011-02-22 21:15 - 00090624 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bowser.sys
2012-10-24 12:09 - 2011-02-17 22:33 - 00031232 ____A (Microsoft Corporation) C:\Windows\System32\prevhost.exe
2012-10-24 12:09 - 2011-02-17 21:33 - 00031232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe
2012-10-24 12:09 - 2011-02-11 22:14 - 00267776 ____A (Microsoft Corporation) C:\Windows\System32\FXSCOVER.exe
2012-10-24 12:09 - 2010-12-17 22:12 - 03138048 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2012-10-24 12:09 - 2010-12-17 22:08 - 01097216 ____A (Microsoft Corporation) C:\Windows\System32\mstsc.exe
2012-10-24 12:09 - 2010-12-17 21:30 - 02690560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2012-10-24 12:09 - 2010-12-17 21:26 - 01034240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2012-10-24 12:09 - 2010-10-15 21:23 - 00112000 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2012-10-24 12:09 - 2010-10-15 21:17 - 00720896 ____A (Microsoft Corporation) C:\Windows\System32\odbc32.dll
2012-10-24 12:09 - 2010-10-15 20:34 - 00573440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\odbc32.dll
2012-10-24 12:09 - 2010-08-31 21:21 - 14627840 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll
2012-10-24 12:09 - 2010-08-31 21:12 - 12625920 ____A (Microsoft Corporation) C:\Windows\System32\wmploc.DLL
2012-10-24 12:09 - 2010-08-31 20:29 - 11406848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2012-10-24 12:09 - 2010-08-31 20:23 - 12625408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2012-10-24 12:09 - 2010-08-26 22:14 - 00236032 ____A (Microsoft Corporation) C:\Windows\System32\srvsvc.dll
2012-10-24 12:09 - 2010-08-26 21:46 - 00009728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
2012-10-24 12:08 - 2012-06-01 21:25 - 01462784 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-10-24 12:08 - 2012-06-01 21:25 - 00182272 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-10-24 12:08 - 2012-06-01 21:25 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-10-24 12:08 - 2012-06-01 20:45 - 01157632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-10-24 12:08 - 2012-06-01 20:45 - 00139264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-10-24 12:08 - 2012-06-01 20:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-10-24 12:08 - 2011-11-19 07:07 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\packager.dll
2012-10-24 12:08 - 2011-11-19 06:06 - 00067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2012-10-24 11:51 - 2010-01-08 23:19 - 00139264 ____A (Microsoft Corporation) C:\Windows\System32\cabview.dll
2012-10-24 11:51 - 2010-01-08 22:52 - 00132608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cabview.dll
2012-10-24 11:50 - 2012-02-14 22:27 - 01031680 ____A (Microsoft Corporation) C:\Windows\System32\rdpcore.dll
2012-10-24 11:50 - 2012-02-14 21:44 - 00826368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2012-10-24 11:50 - 2012-02-14 20:46 - 00023552 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tdtcp.sys
2012-10-24 11:45 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-10-24 11:45 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-10-24 11:45 - 2012-06-02 14:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-10-24 11:45 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-10-24 11:45 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-10-24 11:45 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-10-24 11:45 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-10-24 11:45 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-10-24 11:45 - 2012-06-02 14:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-10-24 11:42 - 2012-10-24 11:42 - 00000000 ____D C:\Program Files (x86)\NETGEAR
2012-10-24 11:42 - 2011-11-28 20:43 - 01057896 ____A (NETGEAR Corporation ) C:\Windows\System32\Drivers\wna3100m.sys
2012-10-24 11:42 - 2011-07-06 22:31 - 00595968 ____A (Realtek Semiconductor Corp. ) C:\Windows\SysWOW64\Rtlihvs.dll
2012-10-24 11:42 - 2011-07-06 22:31 - 00595968 ____A (Realtek Semiconductor Corp. ) C:\Windows\System32\Rtlihvs.dll
2012-10-23 20:42 - 2012-04-09 14:21 - 00451072 ____A C:\Windows\SysWOW64\ISSRemoveSP.exe
==================== One Month Modified Files and Folders =======
2012-11-13 12:08 - 2012-11-13 12:08 - 00000000 ____D C:\FRST
2012-11-13 12:06 - 2009-07-13 20:45 - 00014192 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-11-13 12:06 - 2009-07-13 20:45 - 00014192 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-11-13 12:04 - 2012-11-11 18:46 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-11-13 12:03 - 2012-09-22 10:12 - 00000290 ____A C:\Windows\Tasks\AutoKMS.job
2012-11-13 12:03 - 2012-09-22 09:51 - 00009302 ____A C:\Windows\setupact.log
2012-11-13 12:03 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-11-13 11:52 - 2009-07-13 21:13 - 00726142 ____A C:\Windows\System32\PerfStringBackup.INI
2012-11-13 11:51 - 2012-11-11 18:46 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-11-12 11:08 - 2012-09-22 10:27 - 00010012 ____A C:\Windows\PFRO.log
2012-11-12 09:45 - 2012-11-10 07:56 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-11-12 08:45 - 2012-11-12 08:45 - 00001040 ____A C:\AdwCleaner[S2].txt
2012-11-12 08:45 - 2012-11-12 08:45 - 00000979 ____A C:\AdwCleaner[R5].txt
2012-11-12 08:43 - 2012-11-12 08:43 - 00000920 ____A C:\AdwCleaner[R4].txt
2012-11-11 18:48 - 2012-11-11 18:46 - 00000000 ____D C:\Users\Owner\AppData\Local\Google
2012-11-11 18:48 - 2012-11-11 18:46 - 00000000 ____D C:\Program Files (x86)\Google
2012-11-11 18:45 - 2012-11-11 18:45 - 00763416 ____A (Google Inc.) C:\Users\Owner\Downloads\GoogleEarthSetup.exe
2012-11-11 13:20 - 2012-11-11 13:20 - 00000000 ____D C:\_OTL
2012-11-11 13:20 - 2012-11-10 18:09 - 00000000 ____D C:\Users\Owner\Desktop\antivirusSoft
2012-11-11 09:17 - 2012-11-11 09:17 - 00021450 ____A C:\Users\Owner\Documents\ArtisanBid.dotx
2012-11-01 17:09 - 2012-11-01 17:09 - 00000847 ____A C:\AdwCleaner[R3].txt
2012-11-01 16:25 - 2012-11-01 16:25 - 00000974 ____A C:\AdwCleaner[S1].txt
2012-11-01 16:24 - 2012-11-01 16:24 - 00000907 ____A C:\AdwCleaner[R2].txt
2012-11-01 16:18 - 2012-11-01 16:18 - 00000848 ____A C:\AdwCleaner[R1].txt
2012-11-01 15:25 - 2012-11-01 15:25 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Malwarebytes
2012-11-01 15:24 - 2012-11-01 15:24 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-11-01 15:24 - 2012-11-01 15:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-11-01 15:00 - 2012-11-01 14:58 - 10669952 ____A (Malwarebytes Corporation ) C:\Users\Owner\Downloads\mbam-setup-1.65.1.1000.exe
2012-11-01 08:26 - 2012-11-01 08:26 - 00540977 ____A C:\Users\Owner\Downloads\adwcleaner (1).exe
2012-11-01 08:21 - 2012-11-01 08:21 - 00000000 ____A C:\Windows\SysWOW64\config.nt
2012-11-01 08:20 - 2012-11-01 08:20 - 00000000 ____D C:\Users\All Users\AVAST Software
2012-11-01 08:20 - 2012-11-01 08:20 - 00000000 ____D C:\Program Files\AVAST Software
2012-11-01 08:09 - 2012-11-01 08:09 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-11-01 08:03 - 2012-09-22 10:19 - 00000000 ____D C:\Users\All Users\AVG2012
2012-11-01 08:02 - 2012-09-22 10:16 - 00000000 ____D C:\Users\All Users\MFAData
2012-11-01 08:01 - 2012-10-01 13:15 - 00000000 ___HD C:\$AVG
2012-11-01 08:01 - 2012-09-22 10:19 - 00000000 ____D C:\Windows\System32\Drivers\AVG
2012-10-31 10:56 - 2012-10-31 10:56 - 00540977 ____A C:\Users\Owner\Downloads\adwcleaner.exe
2012-10-30 20:27 - 2012-10-24 12:37 - 00696760 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-10-30 20:27 - 2012-10-24 12:37 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-10-30 20:27 - 2012-09-22 09:34 - 00000000 ____D C:\Users\All Users\Adobe
 
Cont.
2012-10-30 14:51 - 2012-11-01 08:21 - 00984144 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2012-10-30 14:51 - 2012-11-01 08:21 - 00370288 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2012-10-30 14:51 - 2012-11-01 08:21 - 00071600 ____A (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
2012-10-30 14:51 - 2012-11-01 08:21 - 00059728 ____A (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys
2012-10-30 14:51 - 2012-11-01 08:21 - 00025232 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys
2012-10-30 14:51 - 2012-11-01 08:20 - 00041224 ____A (AVAST Software) C:\Windows\avastSS.scr
2012-10-30 14:50 - 2012-11-01 08:21 - 00285328 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe
2012-10-30 14:50 - 2012-11-01 08:20 - 00227648 ____A (AVAST Software) C:\Windows\SysWOW64\aswBoot.exe
2012-10-26 09:55 - 2012-09-22 09:19 - 01283746 ____A C:\Windows\WindowsUpdate.log
2012-10-26 08:27 - 2012-10-26 08:26 - 00000000 ____D C:\Program Files (x86)\Maxtor
2012-10-26 08:27 - 2012-09-22 09:27 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-10-26 08:26 - 2012-10-26 08:26 - 00000000 ____D C:\Users\All Users\Maxtor
2012-10-26 08:25 - 2012-10-26 08:25 - 00000000 ____D C:\Windows\Downloaded Installations
2012-10-26 08:25 - 2012-09-22 09:23 - 00000000 ____D C:\Users\Owner\AppData\Local\VirtualStore
2012-10-25 16:43 - 2012-10-25 16:43 - 00000000 ____D C:\Program Files (x86)\Red Sky
2012-10-25 04:46 - 2009-07-13 20:45 - 00416056 ____A C:\Windows\System32\FNTCACHE.DAT
2012-10-25 04:44 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\System
2012-10-25 04:43 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2012-10-25 04:42 - 2009-07-13 23:46 - 00000000 ____D C:\Program Files\Windows Journal
2012-10-25 02:31 - 2012-10-25 02:25 - 00004039 ____A C:\Windows\IE9_main.log
2012-10-25 02:29 - 2012-10-25 02:29 - 17810944 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 12319744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 03695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2012-10-25 02:29 - 2012-10-25 02:29 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-10-25 02:29 - 2012-10-25 02:29 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-10-25 02:29 - 2012-10-25 02:29 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-10-25 02:29 - 2012-10-25 02:29 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-10-25 02:29 - 2012-10-25 02:29 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-10-25 02:29 - 2012-10-25 02:29 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00534528 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00452608 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00448512 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-10-25 02:29 - 2012-10-25 02:29 - 00434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00403248 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-10-25 02:29 - 2012-10-25 02:29 - 00353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00282112 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00267776 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00249344 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00165888 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00145920 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00135168 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00114176 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00111616 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00091648 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
 
Cont.
2012-10-25 02:29 - 2012-10-25 02:29 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2012-10-25 02:29 - 2012-10-25 02:29 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00049664 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-10-25 02:29 - 2012-10-25 02:29 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-10-25 02:29 - 2012-10-25 02:29 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-10-24 17:02 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2012-10-24 15:34 - 2012-09-22 09:37 - 00000000 ____D C:\Users\Owner\AppData\Local\Adobe
2012-10-24 13:23 - 2012-09-22 09:37 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Adobe
2012-10-24 12:37 - 2012-10-24 12:37 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2012-10-24 12:37 - 2012-10-24 12:37 - 00000000 ____D C:\Windows\System32\Macromed
2012-10-24 11:42 - 2012-10-24 11:42 - 00000000 ____D C:\Program Files (x86)\NETGEAR
2012-10-24 11:18 - 2009-07-13 18:34 - 00000486 ____A C:\Windows\win.ini
2012-10-15 07:59 - 2012-11-01 08:21 - 00054072 ____A (AVAST Software) C:\Windows\System32\Drivers\aswRdr2.sys
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
==================== Known DLLs (Whitelisted) =================

==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-10-26 08:25:59
Restore point made on: 2012-10-26 09:24:23
Restore point made on: 2012-11-01 07:59:41
Restore point made on: 2012-11-01 08:01:50
Restore point made on: 2012-11-01 08:19:57
 
Cont.

==================== Memory info ===========================
Percentage of memory in use: 13%
Total physical RAM: 4029.61 MB
Available physical RAM: 3474.81 MB
Total Pagefile: 4027.76 MB
Available Pagefile: 3460.3 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
2 Drive c: () (Fixed) (Total:74.5 GB) (Free:42.67 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
4 Drive e: (ANTI'Z 256) (Removable) (Total:0.24 GB) (Free:0.2 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 74 GB 6144 KB
Disk 1 Online 244 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 74 GB 31 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 74 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 244 MB 49 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E ANTI'Z 256 FAT Removable 244 MB Healthy
=========================================================
Last Boot: 2012-10-24 16:54
==================== End Of Log =============================
 
Search.txt log
Farbar Recovery Scan Tool (x64) Version: 12-11-2012
Ran by SYSTEM at 2012-11-13 12:11:40
Running from E:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0329216 ____A (Microsoft Corporation) 50BEA589F7D7958BDD2528A8F69D05CC
====== End Of Search ======
 
FRST Fixlist

Please download attached fixlist.txt below, and save it to your flash drive in the same location as FRST.exe. Make sure it maintains the same name, otherwise the fix will fail.

NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system

Now, please enter System Recovery Options then select Command Prompt.

Run FRST and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Now restart, let it boot normally and tell me how it went.


Any more issues?

We need to know any other issues that are plaguing your computer. Kindly give a summary so we know how to continue from here.

Many of the things to note for us would be:

  • Slow computer
  • Error messages
  • Fake antivirus alerts or the icon in the system tray
  • svchost.exe running at 100%
  • System crashes or blue screen of death
 

Attachments

  • fixlist.txt
    265 bytes · Views: 2
Fixlog.

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-11-2012
Ran by SYSTEM at 2012-11-15 20:58:39 Run:1
Running from E:\
==============================================
C:\Windows\assembly\GAC_32\Desktop.ini moved successfully.
C:\Windows\assembly\GAC_64\Desktop.ini moved successfully.
C:\Windows\System32\services.exe moved successfully.
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe copied successfully to C:\Windows\System32\services.exe
==== End of Fixlog ====
 
Well I still cant Enable my windows firewall. When I go to Enable it a window pops up saying, "windows firewall cannot change some of your settings: error code:0x80070424."
 
Next steps. Delete any past version of this tool...

ComboFix scan

Please download ComboFix
combofix.gif
by sUBs
From BleepingComputer.com

Please save the file to your Desktop.

Important information about ComboFix


After the download:
  • Close any open browsers.
  • Very Important: Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results". Please visit here if you don't know how.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until ComboFix has completely finished.
  • If there is no Internet connection after running ComboFix, then restart your computer to restore back your connection.
Running ComboFix:
  • Double click on ComboFix.exe & follow the prompts.
  • When ComboFix finishes, it will produce a report for you.
  • Please post the report, which will launch or be found at "C:\Combo-Fix.txt" in your next reply.
Troubleshooting ComboFix

Safe Mode:

If you still cannot get ComboFix to run, try booting into Safe Mode, and run it there.

(To boot into Safe Mode, tap F8 after BIOS, and just before the Windows
logo appears. A list of options will appear, select "Safe Mode.")

Re-downloading:

If this doesn't work either, try the same method (above method), but try to download it again, except name
ComboFix.exe to iexplore.exe, explorer.exe, or winlogon.exe.

Malware is known for blocking all "user" processes, except for its whitelist of system important processes such as iexplore.exe, explorer.exe, winlogon.exe.

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
 
Combo fix.
ComboFix 12-11-21.01 - Owner 11/21/2012 10:08:12.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.4030.3159 [GMT -8:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
AV: AVG Internet Security Business Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
FW: AVG Internet Security Business Edition 2012 *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}
SP: AVG Internet Security Business Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2012-10-21 to 2012-11-21 )))))))))))))))))))))))))))))))
.
.
2012-11-13 20:08 . 2012-11-13 20:08 -------- d-----w- C:\FRST
2012-11-12 02:46 . 2012-11-12 02:48 -------- d-----w- c:\program files (x86)\Google
2012-11-12 02:46 . 2012-11-12 02:48 -------- d-----w- c:\users\Owner\AppData\Local\Google
2012-11-11 21:20 . 2012-11-11 21:20 -------- d-----w- C:\_OTL
2012-11-10 15:56 . 2012-11-12 17:45 -------- d-----w- C:\TDSSKiller_Quarantine
2012-11-01 23:25 . 2012-11-01 23:25 -------- d-----w- c:\users\Owner\AppData\Roaming\Malwarebytes
2012-11-01 23:24 . 2012-11-01 23:24 -------- d-----w- c:\programdata\Malwarebytes
2012-11-01 23:24 . 2012-11-01 23:24 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-11-01 23:24 . 2012-09-30 02:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-01 16:21 . 2012-10-30 22:51 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-11-01 16:21 . 2012-10-30 22:51 370288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-11-01 16:21 . 2012-10-15 15:59 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-11-01 16:21 . 2012-10-30 22:51 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-11-01 16:21 . 2012-10-30 22:51 984144 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-11-01 16:21 . 2012-10-30 22:51 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-11-01 16:21 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe
2012-11-01 16:20 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-11-01 16:20 . 2012-10-30 22:50 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-11-01 16:20 . 2012-11-01 16:20 -------- d-----w- c:\programdata\AVAST Software
2012-11-01 16:20 . 2012-11-01 16:20 -------- d-----w- c:\program files\AVAST Software
2012-11-01 16:09 . 2012-11-01 16:09 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
2012-10-26 16:26 . 2012-10-26 16:27 -------- d-----w- c:\program files (x86)\Maxtor
2012-10-26 16:26 . 2012-10-26 16:26 -------- d-----w- c:\programdata\Maxtor
2012-10-26 16:25 . 2012-10-26 16:25 -------- d-----w- c:\windows\Downloaded Installations
2012-10-26 00:43 . 2012-10-26 00:43 -------- d-----w- c:\program files (x86)\Red Sky
2012-10-25 12:43 . 2012-10-25 12:43 -------- d-----w- c:\windows\SysWow64\Wat
2012-10-25 12:43 . 2012-10-25 12:43 -------- d-----w- c:\windows\system32\Wat
2012-10-25 12:07 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
2012-10-25 12:07 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
2012-10-25 11:20 . 2009-09-10 06:28 311808 ----a-w- c:\windows\system32\msv1_0.dll
2012-10-25 11:20 . 2009-09-10 05:52 257024 ----a-w- c:\windows\SysWow64\msv1_0.dll
2012-10-25 10:37 . 2009-11-25 19:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2012-10-25 10:37 . 2009-11-25 19:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2012-10-25 10:37 . 2009-11-25 19:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2012-10-25 10:37 . 2009-11-25 19:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2012-10-25 10:37 . 2009-11-25 19:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2012-10-25 10:37 . 2009-11-25 19:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2012-10-25 10:37 . 2009-11-25 19:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-10-25 10:37 . 2009-11-25 19:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2012-10-25 10:37 . 2009-11-25 19:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2012-10-25 10:37 . 2009-11-25 19:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2012-10-25 10:05 . 2012-03-01 06:54 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-10-25 10:05 . 2012-03-01 06:40 80896 ----a-w- c:\windows\system32\imagehlp.dll
2012-10-25 10:05 . 2012-03-01 05:45 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-10-25 10:05 . 2012-03-01 06:35 5120 ----a-w- c:\windows\system32\wmi.dll
2012-10-25 10:05 . 2012-03-01 05:40 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-10-25 10:01 . 2010-03-04 04:32 243712 ----a-w- c:\windows\system32\drivers\ks.sys
2012-10-25 09:47 . 2012-10-25 09:47 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2012-10-25 09:46 . 2012-10-25 09:46 2876528 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2012-10-25 09:46 . 2012-10-25 09:46 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2012-10-25 09:46 . 2012-10-25 09:46 539984 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2012-10-24 20:37 . 2012-10-31 04:27 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-24 20:37 . 2012-10-31 04:27 696760 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-24 20:37 . 2012-10-24 20:37 -------- d-----w- c:\windows\SysWow64\Macromed
2012-10-24 20:37 . 2012-10-24 20:37 -------- d-----w- c:\windows\system32\Macromed
2012-10-24 20:17 . 2012-08-31 18:02 1656688 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-10-24 20:15 . 2011-10-26 05:22 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-10-24 20:15 . 2011-10-26 05:22 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-10-24 20:15 . 2011-10-26 04:28 1328640 ----a-w- c:\windows\SysWow64\quartz.dll
2012-10-24 20:15 . 2011-10-26 04:28 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-10-24 20:15 . 2012-01-04 09:58 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-10-24 20:15 . 2012-01-04 09:03 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-10-24 20:15 . 2010-06-29 05:35 4582912 ----a-w- c:\program files\Windows NT\Accessories\wordpad.exe
2012-10-24 20:15 . 2010-06-29 05:39 2085376 ----a-w- c:\windows\system32\ole32.dll
2012-10-24 20:15 . 2010-06-29 05:02 1413632 ----a-w- c:\windows\SysWow64\ole32.dll
2012-10-24 20:15 . 2010-06-29 04:57 4247040 ----a-w- c:\program files (x86)\Windows NT\Accessories\wordpad.exe
2012-10-24 20:13 . 2010-08-21 06:31 633856 ----a-w- c:\windows\system32\comctl32.dll
2012-10-24 20:12 . 2012-06-02 05:27 340992 ----a-w- c:\windows\system32\schannel.dll
2012-10-24 20:11 . 2010-08-21 06:38 1024512 ----a-w- c:\windows\system32\wmpmde.dll
2012-10-24 20:10 . 2012-04-28 03:50 204800 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-10-24 20:09 . 2011-05-24 11:21 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
 
Cont..
2012-10-24 20:08 . 2012-06-02 05:25 182272 ----a-w- c:\windows\system32\cryptsvc.dll
2012-10-24 20:08 . 2012-06-02 05:25 1462784 ----a-w- c:\windows\system32\crypt32.dll
2012-10-24 20:08 . 2012-06-02 04:45 1157632 ----a-w- c:\windows\SysWow64\crypt32.dll
2012-10-24 20:08 . 2012-06-02 05:25 140288 ----a-w- c:\windows\system32\cryptnet.dll
2012-10-24 20:08 . 2012-06-02 04:45 139264 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2012-10-24 20:08 . 2012-06-02 04:45 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2012-10-24 20:08 . 2011-11-19 15:07 77312 ----a-w- c:\windows\system32\packager.dll
2012-10-24 20:08 . 2011-11-19 14:06 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-10-24 19:51 . 2010-01-09 07:19 139264 ----a-w- c:\windows\system32\cabview.dll
2012-10-24 19:51 . 2010-01-09 06:52 132608 ----a-w- c:\windows\SysWow64\cabview.dll
2012-10-24 19:50 . 2012-02-15 06:27 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-10-24 19:50 . 2012-02-15 05:44 826368 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-10-24 19:50 . 2012-02-15 04:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-10-24 19:45 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-10-24 19:45 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
2012-10-24 19:45 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-10-24 19:45 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-10-24 19:45 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
2012-10-24 19:45 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-10-24 19:45 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-10-24 19:45 . 2012-06-02 22:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-10-24 19:45 . 2012-06-02 22:15 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-10-24 19:44 . 2012-10-24 19:44 163056 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10142.bin
2012-10-24 19:42 . 2011-11-29 04:43 1057896 ----a-w- c:\windows\system32\drivers\wna3100m.sys
2012-10-24 19:42 . 2011-07-07 06:31 595968 ----a-w- c:\windows\SysWow64\Rtlihvs.dll
2012-10-24 19:42 . 2011-07-07 06:31 595968 ----a-w- c:\windows\system32\Rtlihvs.dll
2012-10-24 19:42 . 2012-10-24 19:42 -------- d-----w- c:\program files (x86)\NETGEAR
2012-10-24 04:42 . 2012-04-09 22:21 451072 ----a-w- c:\windows\SysWow64\ISSRemoveSP.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"mxomssmenu"="c:\program files (x86)\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-09-06 169264]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-1-21 226176]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NETGEAR WNA3100M Genie.lnk - c:\program files (x86)\NETGEAR\WNA3100M\WNA3100M.exe [2012-10-24 8364288]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-10-25 1255736]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-30 399432]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-30 676936]
S2 WSWNA3100M;WSWNA3100M;c:\program files (x86)\NETGEAR\WNA3100M\WifiSvc.exe [2011-12-08 303360]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-30 25928]
S3 wna3100m;NETGEAR WNA3100M N300 Wireless Mini USB Adapter;c:\windows\system32\DRIVERS\wna3100m.sys [2011-11-29 1057896]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-12 02:46]
.
2012-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-12 02:46]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://flickr.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
.
 
Cont.

- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Maxtor\Sync\SyncServices.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
.
**************************************************************************
.
Completion time: 2012-11-21 10:25:48 - machine was rebooted
ComboFix-quarantined-files.txt 2012-11-21 18:25
.
Pre-Run: 47,906,689,024 bytes free
Post-Run: 47,668,391,936 bytes free
.
- - End Of File - - 8612127810EC93E68D7A3326F81DA4D9
 
Sorry for delay. I just came back from my short vacation. :)

We will finish up to make sure your computer is protected from malware in the future.

Clean up System Restore

Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."

To manually create a new Restore Point
  • Go to Control Panel and select System and Maintenance
  • Select System
  • On the left select Advance System Settings and accept the warning if you get one
  • Select System Protection Tab
  • Select Create at the bottom
  • Type in a name I.e. Clean
  • Select Create
Now we can purge the infected ones
  • Go back to the System and Maintenance page
  • Select Performance Information and Tools
  • On the left select Open Disk Cleanup
  • Select Files from all users and accept the warning if you get one
  • In the drop down box select your main drive I.e. C
  • For a few moments the system will make some calculations:
    diskcleanup1.png
  • Select the More Options tab
    moreoptions.png
  • In the System Restore and Shadow Backups select Clean up
    moreoptions2.png
  • Select Delete on the pop up
  • Select OK
  • Select Delete
Run OTC to remove our tools

To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe by OldTimer:
  • Save it to your Desktop.
  • Double click OTC.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note:If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

Purge old temporary files

NOTE: If you already have this installed, you don't have to reinstall it.

Please download CCleaner Slim and save it to your Desktop - Alternate download link

When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
Follow the prompts to install the program.

  • Double-click the CCleaner shortcut on the desktop to start the program.
  • A prompt will ask you if you want CCleaner to do a check to see what cookies it needs to keep. Allow that operation.
  • On the Cleaner tab, click on Run Cleaner on the bottom-right to run the program.
  • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner, or it will ask if you want the program to close them for you (when you do this, all unsaved data may be lost in the browser).
Caution: Only use the Registry feature if you are very familiar with the registry.
Always back up your registry before making any changes. Exit CCleaner after it has completed it's process.

Security Check

Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
 
Status
Not open for further replies.
Back