My FEP2010 found the WIN64/Sirefer.y virus. It attempts a clean up but goes into a reboot cycle every minute or so. The FEP error box states the Trojan to be associated with services.exe file located at the following location:
C:\windows\system32\services.exe
I read some similar posts and ran FRST64.exe and collected the log. Log is too big so split into two posts on this thread.
Kindly help with next steps.
Pasted Section 1:
Scan result of Farbar Recovery Scan Tool Version: 13-06-2012 02
Ran by SYSTEM at 14-06-2012 16:01:04
Running from D:\
Windows 7 Enterprise Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [608112 2012-03-27] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167704 2012-03-27] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [392472 2012-03-27] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [416024 2012-03-27] (Intel Corporation)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [525312 2012-03-27] (IDT, Inc.)
HKLM\...\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start [312936 2011-06-05] (NVIDIA Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1436224 2010-11-30] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Communicator] "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey [12071200 2012-03-24] (Microsoft Corporation)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe" [135536 2010-12-13] (Microsoft Corporation)
HKLM-x32\...\Run: [Memeo Instant Backup] C:\Program Files (x86)\Memeo\AutoBackup\MemeoLauncher2.exe --silent --no_ui [136416 2011-05-04] (Memeo Inc.)
HKLM-x32\...\Run: [Seagate Dashboard] C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe --silent --no_ui [79112 2011-06-01] ()
HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [103536 2012-04-30] (VMware, Inc.)
HKU\aymanh\...\Run: [Google Update] "C:\Users\aymanh\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-04-07] (Google Inc.)
HKU\aymanh\...\Run: [WLSync] "C:\Program Files (x86)\Windows Live\Mesh\WLSync.exe" /background [1449824 2012-03-08] (Microsoft Corporation)
HKU\aymanh\...\Run: [SkyDrive] "C:\Users\aymanh\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background [296672 2012-05-30] (Microsoft Corporation)
HKU\aymanh\...\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart [11921064 2012-05-16] (Google)
HKU\aymanh\...\Run: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE" [718720 2011-07-21] (Microsoft Corporation)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll
Startup: C:\Users\aymanh\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ======
3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-02] (Microsoft Corporation)
2 CrmSqlStartupSvc; "C:\Program Files (x86)\Microsoft Dynamics CRM\Client\bin\CrmSqlStartupSvc.exe" [24168 2012-04-26] (Microsoft Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe" [12784 2010-11-11] (Microsoft Corporation)
2 msoidsvc; "C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE" [2078112 2011-09-28] (Microsoft Corp.)
3 NisSrv; "C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe" [282616 2010-11-11] ()
2 rpcld; C:\ProgramData\Rpcnet\Bin\rpcld.exe [179120 2011-09-28] (Absolute Software Corp.)
2 VMUSBArbService; "C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe" [846448 2011-08-29] (VMware, Inc.)
2 vmware-converter-agent; "C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe" -s "C:\ProgramData\VMware\VMware vCenter Converter Standalone\converter-agent.xml" [6269 2012-04-19] ()
2 vmware-converter-server; "C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe" -s "C:\ProgramData\VMware\VMware vCenter Converter Standalone\converter-server.xml" [4280 2012-04-19] ()
2 vmware-converter-worker; "C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe" -s "C:\ProgramData\VMware\VMware vCenter Converter Standalone\converter-worker.xml" [6882 2012-04-19] ()
2 VMwareHostd; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" [31995 2012-04-11] ()
========================== Drivers (Whitelisted) =============
3 bmdrvr; C:\Windows\SysWow64\Drivers\bmdrvr.sys [74352 2011-03-14] (VMware, Inc.)
3 cvusbdrv; C:\Windows\System32\Drivers\cvusbdrv.sys [45672 2012-03-27] (Broadcom Corporation)
3 O2MDFRDR; C:\Windows\System32\DRIVERS\O2MDFw7x64.sys [72808 2012-03-27] (O2Micro )
3 O2MDRRDR; C:\Windows\system32\drivers\O2MDRw7x64.sys [74984 2012-03-27] (O2Micro )
3 O2SDJRDR; C:\Windows\System32\DRIVERS\o2sdjw7x64.sys [83560 2012-03-27] (O2Micro )
3 prepdrvr; \??\C:\Windows\SysWOW64\CCM\prepdrv.sys [26992 2009-09-18] (Microsoft Corporation)
2 VMparport; C:\Windows\System32\Drivers\VMparport.sys [31344 2012-04-30] (VMware, Inc.)
3 dcdbas; C:\Windows\System32\DRIVERS\dcdbas64.sys [x]
1 SASDIFSV; \??\D:\SASDIFSV64.SYS [x]
1 SASKUTIL; \??\D:\SASKUTIL64.SYS [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-14 11:53 - 2012-06-14 11:53 - 00000701 ____A C:\Users\aymanh\Desktop\FEP2010-Log.txt
2012-06-14 11:52 - 2012-06-14 11:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{B705DA7A-F48F-40A8-994F-5E51A3149759}
2012-06-14 10:53 - 2012-06-14 10:53 - 00000000 ____D C:\Users\aymanh\AppData\Local\{E2CF3B84-334A-49CA-B162-96975CCFC3D5}
2012-06-14 10:49 - 2012-06-14 10:49 - 00000000 ____D C:\Users\aymanh\AppData\Local\{F3526EDA-3C1E-4E06-8A3C-E876AD8E87F2}
2012-06-14 10:36 - 2012-06-14 10:36 - 00000000 ____D C:\Users\aymanh\AppData\Roaming\SUPERAntiSpyware.com
2012-06-14 10:36 - 2012-06-14 10:36 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-06-14 07:57 - 2012-06-14 10:46 - 00984386 ____A C:\Windows\ntbtlog.txt
2012-06-14 07:50 - 2012-06-14 07:50 - 00000000 ____D C:\Users\aymanh\AppData\Local\{7330C731-1C51-4EBD-90E7-C6446D950479}
2012-06-14 07:48 - 2012-06-14 07:48 - 00000000 ____D C:\Users\aymanh\AppData\Local\{B25D581F-97E3-4EE0-9AD5-C25FE27596E6}
2012-06-14 07:28 - 2012-06-14 07:34 - 00000000 ____D C:\Users\aymanh\Downloads\definitions
2012-06-14 07:26 - 2012-06-14 07:25 - 00868544 ____A (Microsoft Corporation) C:\Users\aymanh\Downloads\nis_full.exe
2012-06-14 07:09 - 2012-06-14 07:09 - 00000000 ____D C:\Users\aymanh\AppData\Local\{0A766A86-C024-4773-A969-278031034F5E}
2012-06-14 06:33 - 2012-06-14 06:33 - 00000000 ____D C:\Users\aymanh\AppData\Local\{59D7A61C-90C9-4B9A-B546-A15EABB4D0FF}
2012-06-13 18:12 - 2012-06-13 18:12 - 00001150 ____A C:\Users\aymanh\Downloads\w7-wscsvc.zip
2012-06-13 17:49 - 2012-06-13 17:49 - 00000000 ____D C:\Users\aymanh\AppData\Local\{D5FE9CDA-5F28-4B88-9854-1C3AF0D7B59E}
2012-06-13 05:48 - 2012-06-13 17:49 - 00000000 ____D C:\Users\aymanh\AppData\Local\{D63FF5E9-4E16-4A31-9B73-CB45B734D887}
2012-06-13 05:48 - 2012-06-13 05:48 - 00000000 ____D C:\Users\aymanh\AppData\Local\{DB77BC3A-EB80-4DE5-81CB-EC99D1662C47}
2012-06-12 20:31 - 2012-06-12 20:31 - 00000000 ____D C:\Users\aymanh\Documents\ProcAlyzer Dumps
2012-06-12 20:29 - 2012-06-14 11:05 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy
2012-06-12 20:24 - 2012-06-14 11:05 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2012-06-12 19:50 - 2012-06-12 19:50 - 00010376 ____A C:\Users\aymanh\Downloads\BFEWin764.zip
2012-06-12 19:26 - 2012-06-14 11:05 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-12 19:26 - 2012-06-12 19:26 - 00000000 ____D C:\Users\aymanh\AppData\Roaming\Malwarebytes
2012-06-12 19:26 - 2012-06-12 19:26 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-12 19:24 - 2012-06-12 19:24 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\aymanh\Downloads\mbam-setup-1.61.0.1400.exe
2012-06-12 16:53 - 2012-06-12 16:53 - 00000000 ____D C:\Users\aymanh\AppData\Local\{BFFCBFDF-ED42-417C-B6D7-79BC27EDF28E}
2012-06-12 16:53 - 2012-06-12 16:53 - 00000000 ____D C:\Users\aymanh\AppData\Local\{B11D25DF-D503-4DDE-8EA2-95B1C95F66C2}
2012-06-12 09:06 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-12 09:06 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-12 09:06 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 08:56 - 2012-06-14 11:05 - 00000000 ____D C:\Program Files\CCleaner
2012-06-12 08:54 - 2012-06-12 08:54 - 03862112 ____A (Piriform Ltd) C:\Users\aymanh\Downloads\ccsetup319.exe
2012-06-12 06:00 - 2012-06-12 18:57 - 00254947 ____A C:\Users\aymanh\AppData\Local\census.cache
2012-06-12 06:00 - 2012-06-12 18:57 - 00089208 ____A C:\Users\aymanh\AppData\Local\ars.cache
2012-06-12 05:56 - 2011-06-20 20:09 - 00200976 ____A (Trend Micro Inc.) C:\Windows\SysWOW64\Drivers\tmcomm.sys
2012-06-12 05:55 - 2012-06-12 05:55 - 00000036 ____A C:\Users\aymanh\AppData\Local\housecall.guid.cache
2012-06-12 05:20 - 2012-06-12 05:20 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-12 05:16 - 2012-06-12 05:27 - 00000000 ____D C:\Users\All Users\B7E858A700052AA600CCC89DB4EB2331
2012-06-12 04:52 - 2012-06-12 04:53 - 00000000 ____D C:\Users\aymanh\AppData\Local\{3DFC2E60-76B7-4941-8707-E62B2B20E971}
2012-06-12 04:52 - 2012-06-12 04:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{687BACC1-D0F7-48A5-A538-954EE20A115C}
2012-06-12 04:52 - 2012-06-12 04:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{5176700C-A91D-4836-B595-80F5EA5E6025}
2012-06-12 04:52 - 2012-06-12 04:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{32D4EBD7-8427-4ED1-B3A0-D5479E57188E}
2012-06-11 16:52 - 2012-06-11 16:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{FA240629-4662-4D2D-BE3B-ADB08C7DAFD8}
2012-06-11 09:58 - 2012-06-11 09:58 - 01081867 ____A C:\Users\aymanh\Desktop\2012_06_11 Seattle AIS Short - Cloud Security The Slalom Way.pptx
2012-06-11 09:42 - 2012-06-11 09:42 - 00873651 ____A C:\Users\aymanh\Desktop\MOSDAL - June 11.pdf
2012-06-11 08:16 - 2012-06-11 08:16 - 09896861 ____A C:\Users\aymanh\Desktop\National Mobility Master Sales Deck.pptx
2012-06-11 04:51 - 2012-06-11 16:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{1F1B3A19-7894-407D-9ACF-9B4C32C11331}
2012-06-11 04:51 - 2012-06-11 04:51 - 00000000 ____D C:\Users\aymanh\AppData\Local\{686E0935-D6FA-4D5E-B266-533C8DC07EBD}
2012-06-10 15:51 - 2012-06-10 15:51 - 00029437 ____A C:\Users\aymanh\Desktop\CC Assessment SOW.docx
2012-06-10 07:30 - 2012-06-10 07:30 - 00000000 ____D C:\Users\aymanh\AppData\Local\{AAD95F6E-81A1-401C-8CFF-A66219E4CAE8}
2012-06-10 07:30 - 2012-06-10 07:30 - 00000000 ____D C:\Users\aymanh\AppData\Local\{026CB8D2-A4E2-4BBA-A9FB-5A8B7BC6E697}
2012-06-09 19:29 - 2012-06-09 19:29 - 00000000 ____D C:\Users\aymanh\AppData\Local\{5C91F6CA-CC87-4247-AE07-4AB6F8F4E723}
2012-06-09 07:27 - 2012-06-09 07:27 - 00000000 ____D C:\Users\aymanh\AppData\Local\{ABFF5705-6A9F-426D-BAA5-E69897A2E986}
2012-06-09 07:26 - 2012-06-09 19:29 - 00000000 ____D C:\Users\aymanh\AppData\Local\{6C90BC26-3387-4154-96FA-5130E6603152}
2012-06-08 19:26 - 2012-06-08 19:26 - 00000000 ____D C:\Users\aymanh\AppData\Local\{7C3BF20D-4AB0-4DE7-A686-E48EC25E6559}
2012-06-08 07:25 - 2012-06-08 19:26 - 00000000 ____D C:\Users\aymanh\AppData\Local\{EBD054B6-F60A-424A-9901-D7C452B3C55B}
2012-06-08 07:25 - 2012-06-08 07:25 - 00000000 ____D C:\Users\aymanh\AppData\Local\{7C0CD159-1054-4D90-A485-6CEDEAA101A2}
2012-06-08 07:25 - 2012-06-08 07:25 - 00000000 ____D C:\Users\aymanh\AppData\Local\{2D7C1014-B589-4C9A-83AC-728AF2E553E7}
2012-06-08 07:25 - 2012-06-08 07:25 - 00000000 ____D C:\Users\aymanh\AppData\Local\{21010683-6ADD-4480-90E3-50BCA7AE241B}
2012-06-07 19:24 - 2012-06-07 19:25 - 00000000 ____D C:\Users\aymanh\AppData\Local\{6C4FC1BA-4959-43BA-8201-AE3DAE0C70D4}
2012-06-07 07:24 - 2012-06-07 07:24 - 00000000 ____D C:\Users\aymanh\AppData\Local\{F07CF9C3-2056-45E7-A81A-92BD103F2012}
2012-06-07 07:24 - 2012-06-07 07:24 - 00000000 ____D C:\Users\aymanh\AppData\Local\{E55EADFE-8384-40BC-9F4E-DBE9651323A5}
2012-06-07 07:23 - 2012-06-07 07:24 - 00000000 ____D C:\Users\aymanh\AppData\Local\{C492575B-A2C2-40B2-9D77-EC48819314A0}
2012-06-06 18:20 - 2012-06-07 19:24 - 00000000 ____D C:\Users\aymanh\AppData\Local\{042B9A73-D233-4C04-8A37-D86E95714F53}
2012-06-06 18:20 - 2012-06-06 18:20 - 00000000 ____D C:\Users\aymanh\AppData\Local\{F474E0B4-51CA-41ED-9E4B-F02D4A2B58B9}
2012-06-06 11:36 - 2012-06-06 11:36 - 00267264 ____A C:\Users\aymanh\Desktop\Enterprise-Backup-Software-RFP-Template.doc
2012-06-06 11:35 - 2012-06-06 13:24 - 00459595 ____N C:\Users\aymanh\Desktop\Meeting Minutes - 20120605.docx
2012-06-06 11:06 - 2012-06-06 13:34 - 00030615 ____N C:\Users\aymanh\Desktop\Contact List.xlsx
2012-06-06 06:19 - 2012-06-06 06:20 - 00000000 ____D C:\Users\aymanh\AppData\Local\{50BFB023-DCD2-43E1-8C3D-5D82A099B087}
2012-06-06 06:19 - 2012-06-06 06:19 - 00000000 ____D C:\Users\aymanh\AppData\Local\{49F7C4D5-4500-4D15-9FDF-E9797CD4F80A}
2012-06-05 18:19 - 2012-06-05 18:19 - 00000000 ____D C:\Users\aymanh\AppData\Local\{8F00FB63-E266-442E-BB05-2BFCB62C32B8}
2012-06-05 10:44 - 2012-06-05 10:46 - 18350026 ____A C:\Users\aymanh\Desktop\666795_IntroWinServ2012.pdf
2012-06-05 10:02 - 2012-06-05 10:02 - 04112488 ____A C:\Users\aymanh\Desktop\cbsi_msft_webcast_06052012_presentation_final.pdf
2012-06-05 05:10 - 2012-06-05 05:10 - 00000000 ____D C:\Users\aymanh\AppData\Local\{CB68736B-41D8-4A99-930C-6CCFDD1FE359}
2012-06-05 05:09 - 2012-06-06 06:19 - 00000000 ____D C:\Users\aymanh\AppData\Local\{6C96DDD1-CFE1-4E1B-9072-8DCA5AE09399}
2012-06-04 12:40 - 2012-06-04 12:40 - 00000000 ____D C:\Users\aymanh\AppData\Local\{E5B80928-EA1F-4615-88E6-AA6EA33508B9}
2012-06-04 12:40 - 2012-06-04 12:40 - 00000000 ____D C:\Users\aymanh\AppData\Local\{527830C3-5D11-4375-BB10-1C5C307C7A43}
2012-06-04 09:53 - 2012-06-04 09:53 - 00009008 __RSH C:\Users\All Users\3002.abs
2012-06-04 09:37 - 2012-06-04 09:37 - 00969728 ____A C:\Users\aymanh\Downloads\ADTD.Net Setup.msi
2012-06-04 00:30 - 2012-06-04 00:30 - 00000000 ____D C:\Users\aymanh\AppData\Local\{42396869-D95B-4347-935A-9B493586E430}
2012-06-03 12:29 - 2012-06-03 12:29 - 00000000 ____D C:\Users\aymanh\AppData\Local\{051E821A-6B78-4537-BF9A-C853A8BB6F6A}
2012-06-03 00:29 - 2012-06-03 00:29 - 00000000 ____D C:\Users\aymanh\AppData\Local\{AC247F66-9E07-4A56-A062-1CA54CB40DB4}
2012-06-02 12:28 - 2012-06-02 12:28 - 00000000 ____D C:\Users\aymanh\AppData\Local\{B1D6FCD3-13FE-415A-9B1B-089D218D4D84}
2012-06-02 00:28 - 2012-06-02 00:28 - 00000000 ____D C:\Users\aymanh\AppData\Local\{E2D81F3A-CB2D-4A82-BF7D-E887FA954F6A}
2012-06-01 12:27 - 2012-06-01 12:27 - 00000000 ____D C:\Users\aymanh\AppData\Local\{CB7DEFC7-FEAA-4FDA-8A6F-2387F7516BD3}
2012-06-01 12:27 - 2012-06-01 12:27 - 00000000 ____D C:\Users\aymanh\AppData\Local\{7A13FD8B-9E56-46DC-8C3D-08830CBB5D6B}
2012-06-01 00:27 - 2012-06-01 00:27 - 00000000 ____D C:\Users\aymanh\AppData\Local\{58E6DEE2-1B91-45B3-8671-2351F828E003}
2012-06-01 00:26 - 2012-06-04 00:30 - 00000000 ____D C:\Users\aymanh\AppData\Local\{F442995B-EE84-4F7C-87AF-7381BE52B9E2}
2012-05-31 18:03 - 2012-04-30 16:56 - 00063088 ____A (VMware, Inc.) C:\Windows\System32\Drivers\vmx86.sys
2012-05-31 18:03 - 2012-04-30 16:56 - 00031344 ____A (VMware, Inc.) C:\Windows\System32\Drivers\VMparport.sys
2012-05-31 18:02 - 2012-05-31 18:02 - 00000000 ____D C:\Program Files\Common Files\VMware
2012-05-31 18:02 - 2012-04-30 16:56 - 00942192 ____A (VMware, Inc.) C:\Windows\System32\vnetlib64.dll
2012-05-31 18:02 - 2012-04-30 16:56 - 00433264 ____A (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
2012-05-31 18:02 - 2012-04-30 16:56 - 00354416 ____A (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
2012-05-31 18:02 - 2012-04-30 16:54 - 00030320 ____A (VMware, Inc.) C:\Windows\System32\Drivers\vmnetuserif.sys
2012-05-31 18:02 - 2011-08-29 19:11 - 00039024 ____A (VMware, Inc.) C:\Windows\System32\Drivers\hcmon.sys
2012-05-31 12:26 - 2012-05-31 12:26 - 00000000 ____D C:\Users\aymanh\AppData\Local\{9E8B3832-20FD-4560-AC1B-E8A3B9D66992}
2012-05-31 12:26 - 2012-05-31 12:26 - 00000000 ____D C:\Users\aymanh\AppData\Local\{98004457-BEFF-4CD2-BFF1-27C0CBCADD0B}
2012-05-31 00:25 - 2012-05-31 00:26 - 00000000 ____D C:\Users\aymanh\AppData\Local\{45DC0870-6DEB-40F5-8B0E-CCC9BD015AC0}
2012-05-30 18:22 - 2012-05-30 18:22 - 02617278 ____A C:\Users\aymanh\Downloads\Flipboard-1.8.4-63-beta-release.apk
2012-05-30 12:25 - 2012-05-30 12:25 - 00000000 ____D C:\Users\aymanh\AppData\Local\{7B4BF414-F91B-4100-82AF-5D15D966A816}
2012-05-30 12:25 - 2012-05-30 12:25 - 00000000 ____D C:\Users\aymanh\AppData\Local\{205E4846-1873-4DBB-98C3-B8ACD97717F5}
2012-05-30 12:21 - 2012-05-31 12:26 - 00000000 ____D C:\Users\aymanh\AppData\Local\{0D3EC36C-7AC3-4D7B-809A-7B55CEB19B2A}
2012-05-29 19:35 - 2012-05-29 19:35 - 00000000 ____D C:\Users\aymanh\AppData\Local\{4DE3C574-5331-44D2-A098-AEDFACA95183}
2012-05-29 19:34 - 2012-05-29 19:35 - 00000000 ____D C:\Users\aymanh\AppData\Local\{AD0DC94F-36B1-4F19-B303-5C5E6B46BD64}
2012-05-29 19:34 - 2012-05-29 19:34 - 00000000 ____D C:\Users\aymanh\AppData\Local\{7C8EC434-390F-4EB0-BAF5-96EDA39C4B32}
2012-05-29 07:34 - 2012-05-29 07:34 - 00000000 ____D C:\Users\aymanh\AppData\Local\{481C8670-9383-4B0A-82F4-DB098F2AD223}
2012-05-29 07:34 - 2012-05-29 07:34 - 00000000 ____D C:\Users\aymanh\AppData\Local\{25F1FA27-A500-441B-936D-75F38BCF2563}
2012-05-28 19:33 - 2012-05-28 19:33 - 00000000 ____D C:\Users\aymanh\AppData\Local\{21AA06EA-C897-4859-8CA1-390375350898}
2012-05-28 15:36 - 2012-05-28 15:47 - 00000000 ____D C:\Users\aymanh\Desktop\Pics
2012-05-28 07:33 - 2012-05-28 07:33 - 00000000 ____D C:\Users\aymanh\AppData\Local\{45CC4CAA-2102-4D95-BC1A-A53F42BF8BF5}
2012-05-27 19:32 - 2012-05-27 19:32 - 00000000 ____D C:\Users\aymanh\AppData\Local\{922435CC-050E-4E53-9A26-3FA01A2171FD}
2012-05-27 07:32 - 2012-05-27 07:32 - 00000000 ____D C:\Users\aymanh\AppData\Local\{E78B5A3A-2AF7-44D2-8886-B40F9D24AF0A}
2012-05-26 19:00 - 2012-05-29 19:34 - 00000000 ____D C:\Users\aymanh\AppData\Local\{593A9D2F-D210-4688-A950-DEE050B982CB}
2012-05-26 19:00 - 2012-05-26 19:00 - 00000000 ____D C:\Users\aymanh\AppData\Local\{53760101-447E-4A53-95EA-A844684DDE2F}
2012-05-26 06:59 - 2012-05-26 07:00 - 00000000 ____D C:\Users\aymanh\AppData\Local\{CA7701D7-4268-40F5-87FF-3A3D46646B19}
2012-05-25 17:06 - 2012-05-25 17:06 - 00000000 ____D C:\Users\aymanh\AppData\Local\{2E8DDDCA-5B04-41D0-BDAC-260392906BDE}
2012-05-25 17:06 - 2012-05-25 17:06 - 00000000 ____D C:\Users\aymanh\AppData\Local\{00E77EF4-F3A7-4387-B2AD-3DDA4F540F2A}
2012-05-25 05:10 - 2012-05-25 06:08 - 00455850 ____A C:\Users\aymanh\Desktop\Sample-Draft-BPOS to O365 Readiness.docx
2012-05-25 05:05 - 2012-05-26 06:59 - 00000000 ____D C:\Users\aymanh\AppData\Local\{F5840025-FE0B-4B30-A039-2F1F893D3A7B}
2012-05-25 05:05 - 2012-05-25 05:05 - 00000000 ____D C:\Users\aymanh\AppData\Local\{4E3BE758-2D2E-4428-83CE-887091B86BBC}
2012-05-24 12:27 - 2012-05-24 12:27 - 00000000 ____D C:\Users\aymanh\AppData\Local\{BAE3543F-7980-4373-B260-C2F900B49DB3}
2012-05-24 12:00 - 2012-05-24 12:00 - 00000000 ____D C:\Users\aymanh\AppData\Local\{1A0FAF98-3B6C-4123-B522-72D375795747}
2012-05-24 11:56 - 2012-05-24 12:00 - 00000000 ____D C:\Users\aymanh\AppData\Local\{D3339A4B-A9C5-4984-978E-CE64522D9F46}
2012-05-24 00:27 - 2012-05-24 12:27 - 00000000 ____D C:\Users\aymanh\AppData\Local\{1D678444-D161-40D7-B00F-E3F0694E8102}
2012-05-23 13:59 - 2012-05-23 13:59 - 00000000 ___HD C:\Windows\$CrmUninstallKB2600644_Mui_1033$
2012-05-23 13:59 - 2012-05-23 13:59 - 00000000 ___HD C:\Windows\$CrmUninstallKB2600644_Client_1033$
2012-05-23 06:13 - 2012-05-23 06:13 - 00000000 ____D C:\Users\aymanh\AppData\Local\{94A5AD52-996E-4D8C-A0D7-9651852A766B}
2012-05-23 06:12 - 2012-05-23 06:13 - 00000000 ____D C:\Users\aymanh\AppData\Local\{5DF70016-E452-4E5A-BF87-FCC12F1192ED}
2012-05-22 17:42 - 2012-05-22 17:42 - 00000000 ____D C:\Users\aymanh\AppData\Local\{EF30597F-E6E9-4846-9639-6D8997E2B851}
2012-05-22 03:16 - 2012-05-22 03:16 - 00000000 ____D C:\Users\aymanh\AppData\Local\{E5F550C3-34E3-42ED-9133-55E91A6DE188}
2012-05-21 08:08 - 2012-05-21 08:08 - 00000000 ____D C:\Users\aymanh\AppData\Local\{890B34F5-A78E-4A3F-A48C-A02886DB6538}
2012-05-21 08:08 - 2012-05-21 08:08 - 00000000 ____D C:\Users\aymanh\AppData\Local\{69CF7954-5376-40B8-925B-281EA841CD02}
2012-05-20 20:55 - 2012-05-20 20:55 - 00000000 ____D C:\Users\aymanh\AppData\Roaming\Mozilla
2012-05-20 20:08 - 2012-05-20 20:08 - 00000000 ____D C:\Users\aymanh\AppData\Local\{8BED8D63-6561-42C3-BD98-FAA4B1A9E201}
2012-05-20 08:07 - 2012-05-20 08:08 - 00000000 ____D C:\Users\aymanh\AppData\Local\{D8145C38-C49D-4A55-A857-565EC614A44D}
2012-05-19 17:52 - 2012-05-19 17:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{A20460A2-6CF9-42D3-8B04-4E35950E6059}
2012-05-19 05:52 - 2012-05-19 05:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{8CB1668B-949B-40DC-BD6B-2201FBD23844}
2012-05-18 17:51 - 2012-05-18 17:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{E3D9D1B1-8FA7-4D5B-8236-3119ABF61AF0}
2012-05-18 14:01 - 2012-05-18 14:01 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{4ea376b1-9e85-11e1-9935-6427378f5ffd}.TxR.blf
2012-05-18 10:13 - 2012-05-18 10:13 - 00435386 ____A C:\Users\aymanh\Desktop\System Center 2012 Licensing Datasheet.pdf
2012-05-18 05:51 - 2012-05-18 05:51 - 00000000 ____D C:\Users\aymanh\AppData\Local\{B7619558-2DD4-44B4-BDFB-8B5C3960F15A}
2012-05-18 05:51 - 2012-05-18 05:51 - 00000000 ____D C:\Users\aymanh\AppData\Local\{A8B1235C-6DAD-4F61-951C-06E8CA44C5E1}
2012-05-17 17:50 - 2012-05-22 17:42 - 00000000 ____D C:\Users\aymanh\AppData\Local\{9DEC14F4-77AF-44F5-B292-88AD66487B94}
2012-05-17 17:50 - 2012-05-17 17:51 - 00000000 ____D C:\Users\aymanh\AppData\Local\{3E3B78A7-E0D0-4A80-A657-F20FD9D28EDF}
2012-05-17 05:50 - 2012-05-17 05:50 - 00000000 ____D C:\Users\aymanh\AppData\Local\{74D0162A-EC4C-4224-8CAA-3C5208BAA24B}
2012-05-17 05:49 - 2012-05-17 05:50 - 00000000 ____D C:\Users\aymanh\AppData\Local\{439F56D7-1C45-4A09-A27A-31D5AB80D475}
2012-05-16 17:49 - 2012-05-17 05:49 - 00000000 ____D C:\Users\aymanh\AppData\Local\{89863D76-EF77-4D06-8410-0614D34F1D9A}
2012-05-16 17:49 - 2012-05-16 17:49 - 00000000 ____D C:\Users\aymanh\AppData\Local\{8AB41F8A-C1FC-4A3E-ABE3-803183F75894}
2012-05-16 05:49 - 2012-05-16 05:49 - 00000000 ____D C:\Users\aymanh\AppData\Local\{FED8551C-9617-4A21-9AF5-41CC54EA41D0}
2012-05-15 16:00 - 2012-05-15 16:00 - 00000000 ____D C:\Users\aymanh\AppData\Local\{026F9174-06C3-47DD-888C-40A1932551F4}
2012-05-15 06:56 - 2012-05-15 06:56 - 00784742 ____A C:\Users\aymanh\Desktop\VL_CaseStudy_Slalom.pdf
2012-05-15 03:59 - 2012-05-16 05:49 - 00000000 ____D C:\Users\aymanh\AppData\Local\{EDD993F3-8AFE-4888-AC07-2B4F34A0F017}
2012-05-15 03:59 - 2012-05-15 04:00 - 00000000 ____D C:\Users\aymanh\AppData\Local\{C8CFD8D3-2351-40FE-B48A-9138D6BCED66}
C:\windows\system32\services.exe
I read some similar posts and ran FRST64.exe and collected the log. Log is too big so split into two posts on this thread.
Kindly help with next steps.
Pasted Section 1:
Scan result of Farbar Recovery Scan Tool Version: 13-06-2012 02
Ran by SYSTEM at 14-06-2012 16:01:04
Running from D:\
Windows 7 Enterprise Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [608112 2012-03-27] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167704 2012-03-27] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [392472 2012-03-27] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [416024 2012-03-27] (Intel Corporation)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [525312 2012-03-27] (IDT, Inc.)
HKLM\...\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start [312936 2011-06-05] (NVIDIA Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1436224 2010-11-30] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Communicator] "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey [12071200 2012-03-24] (Microsoft Corporation)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe" [135536 2010-12-13] (Microsoft Corporation)
HKLM-x32\...\Run: [Memeo Instant Backup] C:\Program Files (x86)\Memeo\AutoBackup\MemeoLauncher2.exe --silent --no_ui [136416 2011-05-04] (Memeo Inc.)
HKLM-x32\...\Run: [Seagate Dashboard] C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe --silent --no_ui [79112 2011-06-01] ()
HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [103536 2012-04-30] (VMware, Inc.)
HKU\aymanh\...\Run: [Google Update] "C:\Users\aymanh\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-04-07] (Google Inc.)
HKU\aymanh\...\Run: [WLSync] "C:\Program Files (x86)\Windows Live\Mesh\WLSync.exe" /background [1449824 2012-03-08] (Microsoft Corporation)
HKU\aymanh\...\Run: [SkyDrive] "C:\Users\aymanh\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background [296672 2012-05-30] (Microsoft Corporation)
HKU\aymanh\...\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart [11921064 2012-05-16] (Google)
HKU\aymanh\...\Run: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE" [718720 2011-07-21] (Microsoft Corporation)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll
Startup: C:\Users\aymanh\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ======
3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-02] (Microsoft Corporation)
2 CrmSqlStartupSvc; "C:\Program Files (x86)\Microsoft Dynamics CRM\Client\bin\CrmSqlStartupSvc.exe" [24168 2012-04-26] (Microsoft Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe" [12784 2010-11-11] (Microsoft Corporation)
2 msoidsvc; "C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE" [2078112 2011-09-28] (Microsoft Corp.)
3 NisSrv; "C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe" [282616 2010-11-11] ()
2 rpcld; C:\ProgramData\Rpcnet\Bin\rpcld.exe [179120 2011-09-28] (Absolute Software Corp.)
2 VMUSBArbService; "C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe" [846448 2011-08-29] (VMware, Inc.)
2 vmware-converter-agent; "C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe" -s "C:\ProgramData\VMware\VMware vCenter Converter Standalone\converter-agent.xml" [6269 2012-04-19] ()
2 vmware-converter-server; "C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe" -s "C:\ProgramData\VMware\VMware vCenter Converter Standalone\converter-server.xml" [4280 2012-04-19] ()
2 vmware-converter-worker; "C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe" -s "C:\ProgramData\VMware\VMware vCenter Converter Standalone\converter-worker.xml" [6882 2012-04-19] ()
2 VMwareHostd; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" [31995 2012-04-11] ()
========================== Drivers (Whitelisted) =============
3 bmdrvr; C:\Windows\SysWow64\Drivers\bmdrvr.sys [74352 2011-03-14] (VMware, Inc.)
3 cvusbdrv; C:\Windows\System32\Drivers\cvusbdrv.sys [45672 2012-03-27] (Broadcom Corporation)
3 O2MDFRDR; C:\Windows\System32\DRIVERS\O2MDFw7x64.sys [72808 2012-03-27] (O2Micro )
3 O2MDRRDR; C:\Windows\system32\drivers\O2MDRw7x64.sys [74984 2012-03-27] (O2Micro )
3 O2SDJRDR; C:\Windows\System32\DRIVERS\o2sdjw7x64.sys [83560 2012-03-27] (O2Micro )
3 prepdrvr; \??\C:\Windows\SysWOW64\CCM\prepdrv.sys [26992 2009-09-18] (Microsoft Corporation)
2 VMparport; C:\Windows\System32\Drivers\VMparport.sys [31344 2012-04-30] (VMware, Inc.)
3 dcdbas; C:\Windows\System32\DRIVERS\dcdbas64.sys [x]
1 SASDIFSV; \??\D:\SASDIFSV64.SYS [x]
1 SASKUTIL; \??\D:\SASKUTIL64.SYS [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-14 11:53 - 2012-06-14 11:53 - 00000701 ____A C:\Users\aymanh\Desktop\FEP2010-Log.txt
2012-06-14 11:52 - 2012-06-14 11:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{B705DA7A-F48F-40A8-994F-5E51A3149759}
2012-06-14 10:53 - 2012-06-14 10:53 - 00000000 ____D C:\Users\aymanh\AppData\Local\{E2CF3B84-334A-49CA-B162-96975CCFC3D5}
2012-06-14 10:49 - 2012-06-14 10:49 - 00000000 ____D C:\Users\aymanh\AppData\Local\{F3526EDA-3C1E-4E06-8A3C-E876AD8E87F2}
2012-06-14 10:36 - 2012-06-14 10:36 - 00000000 ____D C:\Users\aymanh\AppData\Roaming\SUPERAntiSpyware.com
2012-06-14 10:36 - 2012-06-14 10:36 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-06-14 07:57 - 2012-06-14 10:46 - 00984386 ____A C:\Windows\ntbtlog.txt
2012-06-14 07:50 - 2012-06-14 07:50 - 00000000 ____D C:\Users\aymanh\AppData\Local\{7330C731-1C51-4EBD-90E7-C6446D950479}
2012-06-14 07:48 - 2012-06-14 07:48 - 00000000 ____D C:\Users\aymanh\AppData\Local\{B25D581F-97E3-4EE0-9AD5-C25FE27596E6}
2012-06-14 07:28 - 2012-06-14 07:34 - 00000000 ____D C:\Users\aymanh\Downloads\definitions
2012-06-14 07:26 - 2012-06-14 07:25 - 00868544 ____A (Microsoft Corporation) C:\Users\aymanh\Downloads\nis_full.exe
2012-06-14 07:09 - 2012-06-14 07:09 - 00000000 ____D C:\Users\aymanh\AppData\Local\{0A766A86-C024-4773-A969-278031034F5E}
2012-06-14 06:33 - 2012-06-14 06:33 - 00000000 ____D C:\Users\aymanh\AppData\Local\{59D7A61C-90C9-4B9A-B546-A15EABB4D0FF}
2012-06-13 18:12 - 2012-06-13 18:12 - 00001150 ____A C:\Users\aymanh\Downloads\w7-wscsvc.zip
2012-06-13 17:49 - 2012-06-13 17:49 - 00000000 ____D C:\Users\aymanh\AppData\Local\{D5FE9CDA-5F28-4B88-9854-1C3AF0D7B59E}
2012-06-13 05:48 - 2012-06-13 17:49 - 00000000 ____D C:\Users\aymanh\AppData\Local\{D63FF5E9-4E16-4A31-9B73-CB45B734D887}
2012-06-13 05:48 - 2012-06-13 05:48 - 00000000 ____D C:\Users\aymanh\AppData\Local\{DB77BC3A-EB80-4DE5-81CB-EC99D1662C47}
2012-06-12 20:31 - 2012-06-12 20:31 - 00000000 ____D C:\Users\aymanh\Documents\ProcAlyzer Dumps
2012-06-12 20:29 - 2012-06-14 11:05 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy
2012-06-12 20:24 - 2012-06-14 11:05 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2012-06-12 19:50 - 2012-06-12 19:50 - 00010376 ____A C:\Users\aymanh\Downloads\BFEWin764.zip
2012-06-12 19:26 - 2012-06-14 11:05 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-12 19:26 - 2012-06-12 19:26 - 00000000 ____D C:\Users\aymanh\AppData\Roaming\Malwarebytes
2012-06-12 19:26 - 2012-06-12 19:26 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-12 19:24 - 2012-06-12 19:24 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\aymanh\Downloads\mbam-setup-1.61.0.1400.exe
2012-06-12 16:53 - 2012-06-12 16:53 - 00000000 ____D C:\Users\aymanh\AppData\Local\{BFFCBFDF-ED42-417C-B6D7-79BC27EDF28E}
2012-06-12 16:53 - 2012-06-12 16:53 - 00000000 ____D C:\Users\aymanh\AppData\Local\{B11D25DF-D503-4DDE-8EA2-95B1C95F66C2}
2012-06-12 09:06 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-12 09:06 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-12 09:06 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 08:56 - 2012-06-14 11:05 - 00000000 ____D C:\Program Files\CCleaner
2012-06-12 08:54 - 2012-06-12 08:54 - 03862112 ____A (Piriform Ltd) C:\Users\aymanh\Downloads\ccsetup319.exe
2012-06-12 06:00 - 2012-06-12 18:57 - 00254947 ____A C:\Users\aymanh\AppData\Local\census.cache
2012-06-12 06:00 - 2012-06-12 18:57 - 00089208 ____A C:\Users\aymanh\AppData\Local\ars.cache
2012-06-12 05:56 - 2011-06-20 20:09 - 00200976 ____A (Trend Micro Inc.) C:\Windows\SysWOW64\Drivers\tmcomm.sys
2012-06-12 05:55 - 2012-06-12 05:55 - 00000036 ____A C:\Users\aymanh\AppData\Local\housecall.guid.cache
2012-06-12 05:20 - 2012-06-12 05:20 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-12 05:16 - 2012-06-12 05:27 - 00000000 ____D C:\Users\All Users\B7E858A700052AA600CCC89DB4EB2331
2012-06-12 04:52 - 2012-06-12 04:53 - 00000000 ____D C:\Users\aymanh\AppData\Local\{3DFC2E60-76B7-4941-8707-E62B2B20E971}
2012-06-12 04:52 - 2012-06-12 04:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{687BACC1-D0F7-48A5-A538-954EE20A115C}
2012-06-12 04:52 - 2012-06-12 04:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{5176700C-A91D-4836-B595-80F5EA5E6025}
2012-06-12 04:52 - 2012-06-12 04:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{32D4EBD7-8427-4ED1-B3A0-D5479E57188E}
2012-06-11 16:52 - 2012-06-11 16:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{FA240629-4662-4D2D-BE3B-ADB08C7DAFD8}
2012-06-11 09:58 - 2012-06-11 09:58 - 01081867 ____A C:\Users\aymanh\Desktop\2012_06_11 Seattle AIS Short - Cloud Security The Slalom Way.pptx
2012-06-11 09:42 - 2012-06-11 09:42 - 00873651 ____A C:\Users\aymanh\Desktop\MOSDAL - June 11.pdf
2012-06-11 08:16 - 2012-06-11 08:16 - 09896861 ____A C:\Users\aymanh\Desktop\National Mobility Master Sales Deck.pptx
2012-06-11 04:51 - 2012-06-11 16:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{1F1B3A19-7894-407D-9ACF-9B4C32C11331}
2012-06-11 04:51 - 2012-06-11 04:51 - 00000000 ____D C:\Users\aymanh\AppData\Local\{686E0935-D6FA-4D5E-B266-533C8DC07EBD}
2012-06-10 15:51 - 2012-06-10 15:51 - 00029437 ____A C:\Users\aymanh\Desktop\CC Assessment SOW.docx
2012-06-10 07:30 - 2012-06-10 07:30 - 00000000 ____D C:\Users\aymanh\AppData\Local\{AAD95F6E-81A1-401C-8CFF-A66219E4CAE8}
2012-06-10 07:30 - 2012-06-10 07:30 - 00000000 ____D C:\Users\aymanh\AppData\Local\{026CB8D2-A4E2-4BBA-A9FB-5A8B7BC6E697}
2012-06-09 19:29 - 2012-06-09 19:29 - 00000000 ____D C:\Users\aymanh\AppData\Local\{5C91F6CA-CC87-4247-AE07-4AB6F8F4E723}
2012-06-09 07:27 - 2012-06-09 07:27 - 00000000 ____D C:\Users\aymanh\AppData\Local\{ABFF5705-6A9F-426D-BAA5-E69897A2E986}
2012-06-09 07:26 - 2012-06-09 19:29 - 00000000 ____D C:\Users\aymanh\AppData\Local\{6C90BC26-3387-4154-96FA-5130E6603152}
2012-06-08 19:26 - 2012-06-08 19:26 - 00000000 ____D C:\Users\aymanh\AppData\Local\{7C3BF20D-4AB0-4DE7-A686-E48EC25E6559}
2012-06-08 07:25 - 2012-06-08 19:26 - 00000000 ____D C:\Users\aymanh\AppData\Local\{EBD054B6-F60A-424A-9901-D7C452B3C55B}
2012-06-08 07:25 - 2012-06-08 07:25 - 00000000 ____D C:\Users\aymanh\AppData\Local\{7C0CD159-1054-4D90-A485-6CEDEAA101A2}
2012-06-08 07:25 - 2012-06-08 07:25 - 00000000 ____D C:\Users\aymanh\AppData\Local\{2D7C1014-B589-4C9A-83AC-728AF2E553E7}
2012-06-08 07:25 - 2012-06-08 07:25 - 00000000 ____D C:\Users\aymanh\AppData\Local\{21010683-6ADD-4480-90E3-50BCA7AE241B}
2012-06-07 19:24 - 2012-06-07 19:25 - 00000000 ____D C:\Users\aymanh\AppData\Local\{6C4FC1BA-4959-43BA-8201-AE3DAE0C70D4}
2012-06-07 07:24 - 2012-06-07 07:24 - 00000000 ____D C:\Users\aymanh\AppData\Local\{F07CF9C3-2056-45E7-A81A-92BD103F2012}
2012-06-07 07:24 - 2012-06-07 07:24 - 00000000 ____D C:\Users\aymanh\AppData\Local\{E55EADFE-8384-40BC-9F4E-DBE9651323A5}
2012-06-07 07:23 - 2012-06-07 07:24 - 00000000 ____D C:\Users\aymanh\AppData\Local\{C492575B-A2C2-40B2-9D77-EC48819314A0}
2012-06-06 18:20 - 2012-06-07 19:24 - 00000000 ____D C:\Users\aymanh\AppData\Local\{042B9A73-D233-4C04-8A37-D86E95714F53}
2012-06-06 18:20 - 2012-06-06 18:20 - 00000000 ____D C:\Users\aymanh\AppData\Local\{F474E0B4-51CA-41ED-9E4B-F02D4A2B58B9}
2012-06-06 11:36 - 2012-06-06 11:36 - 00267264 ____A C:\Users\aymanh\Desktop\Enterprise-Backup-Software-RFP-Template.doc
2012-06-06 11:35 - 2012-06-06 13:24 - 00459595 ____N C:\Users\aymanh\Desktop\Meeting Minutes - 20120605.docx
2012-06-06 11:06 - 2012-06-06 13:34 - 00030615 ____N C:\Users\aymanh\Desktop\Contact List.xlsx
2012-06-06 06:19 - 2012-06-06 06:20 - 00000000 ____D C:\Users\aymanh\AppData\Local\{50BFB023-DCD2-43E1-8C3D-5D82A099B087}
2012-06-06 06:19 - 2012-06-06 06:19 - 00000000 ____D C:\Users\aymanh\AppData\Local\{49F7C4D5-4500-4D15-9FDF-E9797CD4F80A}
2012-06-05 18:19 - 2012-06-05 18:19 - 00000000 ____D C:\Users\aymanh\AppData\Local\{8F00FB63-E266-442E-BB05-2BFCB62C32B8}
2012-06-05 10:44 - 2012-06-05 10:46 - 18350026 ____A C:\Users\aymanh\Desktop\666795_IntroWinServ2012.pdf
2012-06-05 10:02 - 2012-06-05 10:02 - 04112488 ____A C:\Users\aymanh\Desktop\cbsi_msft_webcast_06052012_presentation_final.pdf
2012-06-05 05:10 - 2012-06-05 05:10 - 00000000 ____D C:\Users\aymanh\AppData\Local\{CB68736B-41D8-4A99-930C-6CCFDD1FE359}
2012-06-05 05:09 - 2012-06-06 06:19 - 00000000 ____D C:\Users\aymanh\AppData\Local\{6C96DDD1-CFE1-4E1B-9072-8DCA5AE09399}
2012-06-04 12:40 - 2012-06-04 12:40 - 00000000 ____D C:\Users\aymanh\AppData\Local\{E5B80928-EA1F-4615-88E6-AA6EA33508B9}
2012-06-04 12:40 - 2012-06-04 12:40 - 00000000 ____D C:\Users\aymanh\AppData\Local\{527830C3-5D11-4375-BB10-1C5C307C7A43}
2012-06-04 09:53 - 2012-06-04 09:53 - 00009008 __RSH C:\Users\All Users\3002.abs
2012-06-04 09:37 - 2012-06-04 09:37 - 00969728 ____A C:\Users\aymanh\Downloads\ADTD.Net Setup.msi
2012-06-04 00:30 - 2012-06-04 00:30 - 00000000 ____D C:\Users\aymanh\AppData\Local\{42396869-D95B-4347-935A-9B493586E430}
2012-06-03 12:29 - 2012-06-03 12:29 - 00000000 ____D C:\Users\aymanh\AppData\Local\{051E821A-6B78-4537-BF9A-C853A8BB6F6A}
2012-06-03 00:29 - 2012-06-03 00:29 - 00000000 ____D C:\Users\aymanh\AppData\Local\{AC247F66-9E07-4A56-A062-1CA54CB40DB4}
2012-06-02 12:28 - 2012-06-02 12:28 - 00000000 ____D C:\Users\aymanh\AppData\Local\{B1D6FCD3-13FE-415A-9B1B-089D218D4D84}
2012-06-02 00:28 - 2012-06-02 00:28 - 00000000 ____D C:\Users\aymanh\AppData\Local\{E2D81F3A-CB2D-4A82-BF7D-E887FA954F6A}
2012-06-01 12:27 - 2012-06-01 12:27 - 00000000 ____D C:\Users\aymanh\AppData\Local\{CB7DEFC7-FEAA-4FDA-8A6F-2387F7516BD3}
2012-06-01 12:27 - 2012-06-01 12:27 - 00000000 ____D C:\Users\aymanh\AppData\Local\{7A13FD8B-9E56-46DC-8C3D-08830CBB5D6B}
2012-06-01 00:27 - 2012-06-01 00:27 - 00000000 ____D C:\Users\aymanh\AppData\Local\{58E6DEE2-1B91-45B3-8671-2351F828E003}
2012-06-01 00:26 - 2012-06-04 00:30 - 00000000 ____D C:\Users\aymanh\AppData\Local\{F442995B-EE84-4F7C-87AF-7381BE52B9E2}
2012-05-31 18:03 - 2012-04-30 16:56 - 00063088 ____A (VMware, Inc.) C:\Windows\System32\Drivers\vmx86.sys
2012-05-31 18:03 - 2012-04-30 16:56 - 00031344 ____A (VMware, Inc.) C:\Windows\System32\Drivers\VMparport.sys
2012-05-31 18:02 - 2012-05-31 18:02 - 00000000 ____D C:\Program Files\Common Files\VMware
2012-05-31 18:02 - 2012-04-30 16:56 - 00942192 ____A (VMware, Inc.) C:\Windows\System32\vnetlib64.dll
2012-05-31 18:02 - 2012-04-30 16:56 - 00433264 ____A (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
2012-05-31 18:02 - 2012-04-30 16:56 - 00354416 ____A (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
2012-05-31 18:02 - 2012-04-30 16:54 - 00030320 ____A (VMware, Inc.) C:\Windows\System32\Drivers\vmnetuserif.sys
2012-05-31 18:02 - 2011-08-29 19:11 - 00039024 ____A (VMware, Inc.) C:\Windows\System32\Drivers\hcmon.sys
2012-05-31 12:26 - 2012-05-31 12:26 - 00000000 ____D C:\Users\aymanh\AppData\Local\{9E8B3832-20FD-4560-AC1B-E8A3B9D66992}
2012-05-31 12:26 - 2012-05-31 12:26 - 00000000 ____D C:\Users\aymanh\AppData\Local\{98004457-BEFF-4CD2-BFF1-27C0CBCADD0B}
2012-05-31 00:25 - 2012-05-31 00:26 - 00000000 ____D C:\Users\aymanh\AppData\Local\{45DC0870-6DEB-40F5-8B0E-CCC9BD015AC0}
2012-05-30 18:22 - 2012-05-30 18:22 - 02617278 ____A C:\Users\aymanh\Downloads\Flipboard-1.8.4-63-beta-release.apk
2012-05-30 12:25 - 2012-05-30 12:25 - 00000000 ____D C:\Users\aymanh\AppData\Local\{7B4BF414-F91B-4100-82AF-5D15D966A816}
2012-05-30 12:25 - 2012-05-30 12:25 - 00000000 ____D C:\Users\aymanh\AppData\Local\{205E4846-1873-4DBB-98C3-B8ACD97717F5}
2012-05-30 12:21 - 2012-05-31 12:26 - 00000000 ____D C:\Users\aymanh\AppData\Local\{0D3EC36C-7AC3-4D7B-809A-7B55CEB19B2A}
2012-05-29 19:35 - 2012-05-29 19:35 - 00000000 ____D C:\Users\aymanh\AppData\Local\{4DE3C574-5331-44D2-A098-AEDFACA95183}
2012-05-29 19:34 - 2012-05-29 19:35 - 00000000 ____D C:\Users\aymanh\AppData\Local\{AD0DC94F-36B1-4F19-B303-5C5E6B46BD64}
2012-05-29 19:34 - 2012-05-29 19:34 - 00000000 ____D C:\Users\aymanh\AppData\Local\{7C8EC434-390F-4EB0-BAF5-96EDA39C4B32}
2012-05-29 07:34 - 2012-05-29 07:34 - 00000000 ____D C:\Users\aymanh\AppData\Local\{481C8670-9383-4B0A-82F4-DB098F2AD223}
2012-05-29 07:34 - 2012-05-29 07:34 - 00000000 ____D C:\Users\aymanh\AppData\Local\{25F1FA27-A500-441B-936D-75F38BCF2563}
2012-05-28 19:33 - 2012-05-28 19:33 - 00000000 ____D C:\Users\aymanh\AppData\Local\{21AA06EA-C897-4859-8CA1-390375350898}
2012-05-28 15:36 - 2012-05-28 15:47 - 00000000 ____D C:\Users\aymanh\Desktop\Pics
2012-05-28 07:33 - 2012-05-28 07:33 - 00000000 ____D C:\Users\aymanh\AppData\Local\{45CC4CAA-2102-4D95-BC1A-A53F42BF8BF5}
2012-05-27 19:32 - 2012-05-27 19:32 - 00000000 ____D C:\Users\aymanh\AppData\Local\{922435CC-050E-4E53-9A26-3FA01A2171FD}
2012-05-27 07:32 - 2012-05-27 07:32 - 00000000 ____D C:\Users\aymanh\AppData\Local\{E78B5A3A-2AF7-44D2-8886-B40F9D24AF0A}
2012-05-26 19:00 - 2012-05-29 19:34 - 00000000 ____D C:\Users\aymanh\AppData\Local\{593A9D2F-D210-4688-A950-DEE050B982CB}
2012-05-26 19:00 - 2012-05-26 19:00 - 00000000 ____D C:\Users\aymanh\AppData\Local\{53760101-447E-4A53-95EA-A844684DDE2F}
2012-05-26 06:59 - 2012-05-26 07:00 - 00000000 ____D C:\Users\aymanh\AppData\Local\{CA7701D7-4268-40F5-87FF-3A3D46646B19}
2012-05-25 17:06 - 2012-05-25 17:06 - 00000000 ____D C:\Users\aymanh\AppData\Local\{2E8DDDCA-5B04-41D0-BDAC-260392906BDE}
2012-05-25 17:06 - 2012-05-25 17:06 - 00000000 ____D C:\Users\aymanh\AppData\Local\{00E77EF4-F3A7-4387-B2AD-3DDA4F540F2A}
2012-05-25 05:10 - 2012-05-25 06:08 - 00455850 ____A C:\Users\aymanh\Desktop\Sample-Draft-BPOS to O365 Readiness.docx
2012-05-25 05:05 - 2012-05-26 06:59 - 00000000 ____D C:\Users\aymanh\AppData\Local\{F5840025-FE0B-4B30-A039-2F1F893D3A7B}
2012-05-25 05:05 - 2012-05-25 05:05 - 00000000 ____D C:\Users\aymanh\AppData\Local\{4E3BE758-2D2E-4428-83CE-887091B86BBC}
2012-05-24 12:27 - 2012-05-24 12:27 - 00000000 ____D C:\Users\aymanh\AppData\Local\{BAE3543F-7980-4373-B260-C2F900B49DB3}
2012-05-24 12:00 - 2012-05-24 12:00 - 00000000 ____D C:\Users\aymanh\AppData\Local\{1A0FAF98-3B6C-4123-B522-72D375795747}
2012-05-24 11:56 - 2012-05-24 12:00 - 00000000 ____D C:\Users\aymanh\AppData\Local\{D3339A4B-A9C5-4984-978E-CE64522D9F46}
2012-05-24 00:27 - 2012-05-24 12:27 - 00000000 ____D C:\Users\aymanh\AppData\Local\{1D678444-D161-40D7-B00F-E3F0694E8102}
2012-05-23 13:59 - 2012-05-23 13:59 - 00000000 ___HD C:\Windows\$CrmUninstallKB2600644_Mui_1033$
2012-05-23 13:59 - 2012-05-23 13:59 - 00000000 ___HD C:\Windows\$CrmUninstallKB2600644_Client_1033$
2012-05-23 06:13 - 2012-05-23 06:13 - 00000000 ____D C:\Users\aymanh\AppData\Local\{94A5AD52-996E-4D8C-A0D7-9651852A766B}
2012-05-23 06:12 - 2012-05-23 06:13 - 00000000 ____D C:\Users\aymanh\AppData\Local\{5DF70016-E452-4E5A-BF87-FCC12F1192ED}
2012-05-22 17:42 - 2012-05-22 17:42 - 00000000 ____D C:\Users\aymanh\AppData\Local\{EF30597F-E6E9-4846-9639-6D8997E2B851}
2012-05-22 03:16 - 2012-05-22 03:16 - 00000000 ____D C:\Users\aymanh\AppData\Local\{E5F550C3-34E3-42ED-9133-55E91A6DE188}
2012-05-21 08:08 - 2012-05-21 08:08 - 00000000 ____D C:\Users\aymanh\AppData\Local\{890B34F5-A78E-4A3F-A48C-A02886DB6538}
2012-05-21 08:08 - 2012-05-21 08:08 - 00000000 ____D C:\Users\aymanh\AppData\Local\{69CF7954-5376-40B8-925B-281EA841CD02}
2012-05-20 20:55 - 2012-05-20 20:55 - 00000000 ____D C:\Users\aymanh\AppData\Roaming\Mozilla
2012-05-20 20:08 - 2012-05-20 20:08 - 00000000 ____D C:\Users\aymanh\AppData\Local\{8BED8D63-6561-42C3-BD98-FAA4B1A9E201}
2012-05-20 08:07 - 2012-05-20 08:08 - 00000000 ____D C:\Users\aymanh\AppData\Local\{D8145C38-C49D-4A55-A857-565EC614A44D}
2012-05-19 17:52 - 2012-05-19 17:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{A20460A2-6CF9-42D3-8B04-4E35950E6059}
2012-05-19 05:52 - 2012-05-19 05:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{8CB1668B-949B-40DC-BD6B-2201FBD23844}
2012-05-18 17:51 - 2012-05-18 17:52 - 00000000 ____D C:\Users\aymanh\AppData\Local\{E3D9D1B1-8FA7-4D5B-8236-3119ABF61AF0}
2012-05-18 14:01 - 2012-05-18 14:01 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{4ea376b1-9e85-11e1-9935-6427378f5ffd}.TxR.blf
2012-05-18 10:13 - 2012-05-18 10:13 - 00435386 ____A C:\Users\aymanh\Desktop\System Center 2012 Licensing Datasheet.pdf
2012-05-18 05:51 - 2012-05-18 05:51 - 00000000 ____D C:\Users\aymanh\AppData\Local\{B7619558-2DD4-44B4-BDFB-8B5C3960F15A}
2012-05-18 05:51 - 2012-05-18 05:51 - 00000000 ____D C:\Users\aymanh\AppData\Local\{A8B1235C-6DAD-4F61-951C-06E8CA44C5E1}
2012-05-17 17:50 - 2012-05-22 17:42 - 00000000 ____D C:\Users\aymanh\AppData\Local\{9DEC14F4-77AF-44F5-B292-88AD66487B94}
2012-05-17 17:50 - 2012-05-17 17:51 - 00000000 ____D C:\Users\aymanh\AppData\Local\{3E3B78A7-E0D0-4A80-A657-F20FD9D28EDF}
2012-05-17 05:50 - 2012-05-17 05:50 - 00000000 ____D C:\Users\aymanh\AppData\Local\{74D0162A-EC4C-4224-8CAA-3C5208BAA24B}
2012-05-17 05:49 - 2012-05-17 05:50 - 00000000 ____D C:\Users\aymanh\AppData\Local\{439F56D7-1C45-4A09-A27A-31D5AB80D475}
2012-05-16 17:49 - 2012-05-17 05:49 - 00000000 ____D C:\Users\aymanh\AppData\Local\{89863D76-EF77-4D06-8410-0614D34F1D9A}
2012-05-16 17:49 - 2012-05-16 17:49 - 00000000 ____D C:\Users\aymanh\AppData\Local\{8AB41F8A-C1FC-4A3E-ABE3-803183F75894}
2012-05-16 05:49 - 2012-05-16 05:49 - 00000000 ____D C:\Users\aymanh\AppData\Local\{FED8551C-9617-4A21-9AF5-41CC54EA41D0}
2012-05-15 16:00 - 2012-05-15 16:00 - 00000000 ____D C:\Users\aymanh\AppData\Local\{026F9174-06C3-47DD-888C-40A1932551F4}
2012-05-15 06:56 - 2012-05-15 06:56 - 00784742 ____A C:\Users\aymanh\Desktop\VL_CaseStudy_Slalom.pdf
2012-05-15 03:59 - 2012-05-16 05:49 - 00000000 ____D C:\Users\aymanh\AppData\Local\{EDD993F3-8AFE-4888-AC07-2B4F34A0F017}
2012-05-15 03:59 - 2012-05-15 04:00 - 00000000 ____D C:\Users\aymanh\AppData\Local\{C8CFD8D3-2351-40FE-B48A-9138D6BCED66}