This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Got virus, trojan or whatever [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The game I was playing would minimize itself. My firewall was disabled and I did not do it. I would turn it on, it would turn itself right off. And the block websites was not working on malewarebytes. I ran McAfee and Malwarebytes. They removed 5 things total and I restarted. McAfee said that there were two files it found, but could not remove them. I was able to turn my firewall back after the restart and I scanned again. Malwarebytes came up clean, McAfee brought up two it could not remove (see attachment). Please help me make sure that my com is clean. It is brand new about three weeks old.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:26:21 PM, on 7/27/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16447)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
C:\Program Files (x86)\Nero\SyncUP\SyncUP.exe
C:\Program Files (x86)\Nero\SyncUP\Nero.AndroidServer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
C:\Users\Sheila\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…mp;m=aspire_one
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://xfinity.comcast.net/?cid=insDate07202012
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120719162809.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [NeroLauncher] C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe 900
O4 - HKLM\..\Run: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" –startup
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Media Finder] "C:\Program Files (x86)\Media Finder\Media Finder.exe" /opentotray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files (x86)\Media Finder\hook.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~2\mcafee\msc\mcsniepl.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Active File Monitor V9 (AdobeActiveFileMonitor9.0) - Adobe Systems Incorporated - c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Bluetooth Device Monitor - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth Media Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
O23 - Service: Bluetooth OBEX Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service (BTHSSecurityMgr) - Intel® Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: CxUtilSvc - Conexant Systems, Inc. - C:\Program Files\Conexant\SA3\CxUtilSvc.exe
O23 - Service: Dell Digital Delivery Service (DellDigitalDelivery) - Dell Products, LP. - c:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee Activation Service (McAWFwk) - McAfee, Inc. - c:\PROGRA~1\mcafee\msc\mcawfwk.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\mcafee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NitroPDFReaderDriverCreatorReadSpool2 (NitroReaderDriverReadSpool2) - Nitro PDF Software - C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe
O23 - Service: Dell DataSafe Online (NOBU) - Dell, Inc. - C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: RoxMediaDB12OEM - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel® Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel® Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 16931 bytes

Attachments:

Hi Waterfall,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

As we work through your logs. Please remember to run any tools by Right-clicking on the icon and selecting Run As Administrator….

Download ComboFix from here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
I turned off McAfee and ran combo fix. I received a box saying that McAfee was still running. I checked again and made sure that the realtime scanner and such were turned off and hit okay. I got a box saying that it is still running and combofix will run at my own risk. I have not hit okay to that yet. I closed all processes from McAfee that I recognize in the task manager. Will that turn it off so I can continue? I have also noticed that Task manager says there are 83 processes running and that many are not showing up in the window. edit-I went ahead and ran it. Said it could not find file NI KCMD or something like that. Sorry I have forgotten the exact letters.
It's probably the infection fighting the tool.

Let's run a different tool and see if we can at least weaken the infection.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
I downloaded OTL, but before I could use it all my desktop icons disappeared. Along with the listings under all programs in the start menu. I was trying to get to notepad to copy down the script you put up. I am having trouble downloading OTL again, The recycle bin is still there. Any window I bring up is blank or I get a small little box with a yellow square in it. All I can do to that is close it.
OK… Plan c… your going to need a thumbdrive for this.

download Farbar Recovery Scan Tool 32-Bit
Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Had to get on phone. I am unable to get on line now. Ran tool. Trying to get results posted.
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01 Ran by [removed] at 29-07-2012 15:17:20 Running from F:\ Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US) The current controlset is ControlSet001 ========================== Registry (Whitelisted) ============= HKLM\…\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2803496 2011-06-23] (Synaptics Incorporated) HKLM\…\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [168216 2011-06-01] (Intel Corporation) HKLM\…\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [392472 2011-06-01] (Intel Corporation) HKLM\…\Run: [Persistence] C:\Windows\system32\igfxpers.exe [416024 2011-06-01] (Intel Corporation) HKLM\…\Run: [SmartAudio] C:\Program Files\CONEXANT\SA3\SACpl.exe /sa3 /nv:3.0 /dne /s [x] HKLM\…\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686704 2010-12-17] () HKLM\…\Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray [1935120 2011-11-01] (Intel® Corporation) HKLM\…\Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp [10357008 2011-10-18] (Intel Corporation) HKLM\…\Run: [QuickSet] c:\Program Files\Dell\QuickSet\QuickSet.exe [4500640 2011-03-10] (Dell Inc.) HKLM\…\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [4526 2010-11-29] () HKLM\…\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [499608 2011-03-30] (Adobe Systems Incorporated) HKLM\…\Run: [DellStage] "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" –startup [482661 2011-11-03] () HKLM-x32\…\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [503942 2011-04-13] (Creative Technology Ltd) HKLM-x32\…\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-25] (Dell, Inc.) HKLM-x32\…\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions) HKLM-x32\…\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [514544 2010-11-17] () HKLM-x32\…\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey [1675160 2012-03-21] (McAfee, Inc.) HKLM-x32\…\Run: [NeroLauncher] C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe 900 [66872 2011-12-31] () HKLM-x32\…\Run: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" –startup [2829241 2011-11-03] () HKLM-x32\…\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\…\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-04-04] (Adobe Systems Incorporated) HKLM-x32\…\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.) HKLM-x32\…\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.) HKLM-x32\…\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462920 2012-07-03] (Malwarebytes Corporation) HKLM-x32\…\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.) HKLM-x32\…\Run: [UnlockerAssistant] "C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe" [x] HKU\Sheila\…\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3671872 2012-04-17] (DT Soft Ltd) HKU\Sheila\…\Run: [Media Finder] "C:\Program Files (x86)\Media Finder\Media Finder.exe" /opentotray [x] Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation) Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76 Startup: C:\Users\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Sheila\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Services (Whitelisted) ====== 2 Bluetooth Device Monitor; "C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe" [936272 2011-10-18] (Intel Corporation) 3 Bluetooth Media Service; "C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe" [1354064 2011-10-18] (Intel Corporation) 2 Bluetooth OBEX Service; "C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe" [1001808 2011-10-18] (Intel Corporation) 2 BTHSSecurityMgr; "C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe" [135440 2011-10-20] (Intel® Corporation) 2 CxAudMsg; C:\Windows\system32\CxAudMsg64.exe [200320 2011-05-12] (Conexant Systems Inc.) 3 CxUtilSvc; "C:\Program Files\Conexant\SA3\CxUtilSvc.exe" [109184 2011-08-11] (Conexant Systems, Inc.) 2 DellDigitalDelivery; "C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe" [162816 2011-10-26] (Dell Products, LP.) 2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation) 3 McAWFwk; C:\PROGRA~1\mcafee\msc\mcawfwk.exe [224704 2011-03-08] (McAfee, Inc.) 3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe" [237008 2011-06-17] (McAfee, Inc.) 2 McMPFSvc; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [249936 2011-01-27] (McAfee, Inc.) 2 mcmscsvc; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [249936 2011-01-27] (McAfee, Inc.) 2 McNaiAnn; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [249936 2011-01-27] (McAfee, Inc.) 2 McNASvc; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [249936 2011-01-27] (McAfee, Inc.) 3 McODS; "C:\Program Files\mcafee\VirusScan\mcods.exe" [502032 2012-04-19] (McAfee, Inc.) 4 McOobeSv; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [249936 2011-01-27] (McAfee, Inc.) 2 McProxy; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [249936 2011-01-27] (McAfee, Inc.) 2 McShield; "C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe" [199304 2012-05-25] (McAfee, Inc.) 2 mfefire; "C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe" [210616 2012-05-25] (McAfee, Inc.) 2 mfevtp; "C:\Windows\system32\mfevtps.exe" [162224 2012-05-25] (McAfee, Inc.) 2 MSK80Service; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [249936 2011-01-27] (McAfee, Inc.) 3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-11-01] () 2 NitroReaderDriverReadSpool2; "C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe" [216080 2012-06-25] (Nitro PDF Software) 2 RoxWatch12; "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe" [219632 2010-11-25] (Sonic Solutions) 3 stllssvr; "C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe" [74392 2010-11-08] (MicroVision Development, Inc.) 2 UNS; "C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe" [2656280 2010-12-20] (Intel Corporation) ========================== Drivers (Whitelisted) ============= 3 cfwids; C:\Windows\System32\Drivers\cfwids.sys [65264 2012-02-22] (McAfee, Inc.) 3 iBtFltCoex; C:\Windows\System32\Drivers\iBtFltCoex.sys [60416 2011-12-09] (Intel Corporation) 3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-07-03] (Malwarebytes Corporation) 3 MCfilt; C:\Windows\System32\drivers\MCfilt64.sys [32344 2010-12-08] (Creative Technology Ltd.) 3 mfeapfk; C:\Windows\System32\Drivers\mfeapfk.sys [160792 2012-02-22] (McAfee, Inc.) 3 mfeavfk; C:\Windows\System32\Drivers\mfeavfk.sys [229528 2012-02-22] (McAfee, Inc.) 3 mfefirek; C:\Windows\System32\Drivers\mfefirek.sys [487296 2012-02-22] (McAfee, Inc.) 0 mfehidk; C:\Windows\System32\Drivers\mfehidk.sys [647208 2012-02-22] (McAfee, Inc.) 1 mfenlfk; C:\Windows\System32\Drivers\mfenlfk.sys [75936 2012-02-22] (McAfee, Inc.) 3 mferkdet; C:\Windows\System32\Drivers\mferkdet.sys [100912 2012-02-22] (McAfee, Inc.) 0 mfewfpk; C:\Windows\System32\Drivers\mfewfpk.sys [289664 2012-02-22] (McAfee, Inc.) 0 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-07-07] (Duplex Secure Ltd.) 3 mfeavfk01; [x] ========================== NetSvcs (Whitelisted) =========== ============ One Month Created Files and Folders ============== 2012-07-29 15:17 - 2012-07-29 15:17 - 00000000 ____D C:\FRST 2012-07-29 12:22 - 2012-07-29 12:22 - 00597504 ____A (OldTimer Tools) C:\Users\Sheila\Desktop\OTL.exe 2012-07-29 11:00 - 2012-07-29 11:00 - 00000000 ___SD C:\ComboFix 2012-07-29 10:55 - 2011-06-26 01:45 - 00256000 ____A C:\Windows\PEV.exe 2012-07-29 10:55 - 2010-11-07 12:20 - 00208896 ____A C:\Windows\MBR.exe 2012-07-29 10:55 - 2009-04-19 23:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2012-07-29 10:55 - 2000-08-30 19:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2012-07-29 10:55 - 2000-08-30 19:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2012-07-29 10:55 - 2000-08-30 19:00 - 00098816 ____A C:\Windows\sed.exe 2012-07-29 10:55 - 2000-08-30 19:00 - 00080412 ____A C:\Windows\grep.exe 2012-07-29 10:55 - 2000-08-30 19:00 - 00068096 ____A C:\Windows\zip.exe 2012-07-29 10:30 - 2012-07-29 10:54 - 00000000 ____D C:\Qoobox 2012-07-29 10:29 - 2012-07-29 10:29 - 00000000 ____D C:\Windows\erdnt 2012-07-28 20:40 - 2012-07-29 10:19 - 00000000 ____D C:\Users\Sheila\Local Settings\Application Data\Adobe 2012-07-28 20:40 - 2012-07-29 10:19 - 00000000 ____D C:\Users\Sheila\Local Settings\Adobe 2012-07-28 20:40 - 2012-07-29 10:19 - 00000000 ____D C:\Users\Sheila\AppData\Local\Adobe 2012-07-28 16:40 - 2012-07-28 16:41 - 02456480 ____A C:\Users\Sheila\Desktop\Video.avi 2012-07-28 15:54 - 2012-07-28 15:54 - 00000000 ____D C:\Users\Sheila\SyncUP 2012-07-28 14:43 - 2012-07-28 14:43 - 01100054 ____A C:\Users\Sheila\Downloads\MTS_spladoum_1303728_WheelchairSetS3Pack.rar 2012-07-28 14:43 - 2012-07-28 14:43 - 00121425 ____A C:\Users\Sheila\Downloads\MTS_spladoum_1303722_WheelchairPoses.rar 2012-07-27 20:41 - 2012-07-27 20:41 - 00169130 ____A C:\Users\Sheila\Downloads\PosePackCreator_1_3.rar 2012-07-27 20:35 - 2012-07-28 22:07 - 00000000 ____D C:\Users\Sheila\Desktop\ClipToolRigs 2012-07-27 20:12 - 2012-07-27 20:12 - 00000000 ____D C:\Users\Sheila\Application Data\Blender Foundation 2012-07-27 20:12 - 2012-07-27 20:12 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Blender Foundation 2012-07-27 16:42 - 2012-07-27 16:42 - 00166645 ____A C:\Users\Sheila\Downloads\MTS_CmarNYC_1311045_MeshToolKit_1_0_0_1.zip 2012-07-27 16:34 - 2012-07-27 16:34 - 06435923 ____A C:\Users\Sheila\Downloads\MTS_Nathia_1310244_WildFireFrofortheLadies.rar 2012-07-27 08:58 - 2012-07-27 13:54 - 00016933 ____A C:\Users\Sheila\Desktop\hijackthis.log 2012-07-27 08:49 - 2012-07-27 08:49 - 00388608 ____A (Trend Micro Inc.) C:\Users\Sheila\Desktop\HiJackThis.exe 2012-07-26 23:30 - 2012-07-26 23:31 - 00002148 ____A C:\Users\Sheila\Downloads\SuperDAT.log 2012-07-26 23:29 - 2012-07-26 23:30 - 105418616 ____A (McAfee, Inc.) C:\Users\Sheila\Downloads\6783xdat.exe 2012-07-24 23:11 - 2012-07-24 23:15 - 05531455 ____A C:\Users\Sheila\Downloads\Milkshape3D.zip 2012-07-24 22:55 - 2012-07-24 22:55 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA% 2012-07-24 22:53 - 2012-07-24 23:19 - 00000000 ____D C:\Users\Sheila\Application Data\Media Finder 2012-07-24 22:53 - 2012-07-24 23:19 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Media Finder 2012-07-24 22:46 - 2011-10-27 03:46 - 00000053 ____N C:\Users\Sheila\Downloads\FILE_ID.DIZ 2012-07-24 22:46 - 2011-10-26 02:34 - 00004902 ____N C:\Users\Sheila\Downloads\FUTURiTY.nfo 2012-07-24 21:40 - 2012-07-24 21:40 - 00000000 ____D C:\Users\All Users\FLEXnet 2012-07-24 21:40 - 2012-07-24 21:40 - 00000000 ____D C:\Users\All Users\Application Data\FLEXnet 2012-07-24 19:25 - 2012-07-24 19:25 - 01032390 ____A C:\Users\Sheila\Downloads\Danzxncrd_poseset01_Come_Sit_with_Me_updated_with_poses_list.rar 2012-07-24 19:16 - 2012-07-24 19:16 - 00874892 ____A C:\Users\Sheila\Downloads\a_dill_no013-022.rar 2012-07-24 19:10 - 2012-07-24 19:10 - 00118888 ____A C:\Users\Sheila\Downloads\a_come_1-6.rar 2012-07-24 15:43 - 2012-07-24 15:43 - 00000000 ____D C:\Users\Lotus\Local Settings\Macromedia 2012-07-24 15:43 - 2012-07-24 15:43 - 00000000 ____D C:\Users\Lotus\Local Settings\Application Data\Macromedia 2012-07-24 15:43 - 2012-07-24 15:43 - 00000000 ____D C:\Users\Lotus\AppData\Local\Macromedia 2012-07-24 15:36 - 2012-07-24 15:36 - 00000000 ____D C:\Users\Lotus\Application Data\Apple Computer 2012-07-24 15:36 - 2012-07-24 15:36 - 00000000 ____D C:\Users\Lotus\AppData\Roaming\Apple Computer 2012-07-22 22:26 - 2012-07-22 22:26 - 00000016 ___RH C:\Users\All Users\Application Data\552B474E.ini 2012-07-22 22:26 - 2012-07-22 22:26 - 00000016 ___RH C:\Users\All Users\552B474E.ini 2012-07-22 22:16 - 2012-07-22 22:16 - 00000016 ___RH C:\Users\Sheila\Local Settings\Application Data\2A95A3A7.ini 2012-07-22 22:16 - 2012-07-22 22:16 - 00000016 ___RH C:\Users\Sheila\Local Settings\2A95A3A7.ini 2012-07-22 22:16 - 2012-07-22 22:16 - 00000016 ___RH C:\Users\Sheila\AppData\Local\2A95A3A7.ini 2012-07-22 21:55 - 2012-07-24 23:17 - 00000000 ____D C:\Users\Sheila\Application Data\MilkShape 3D 1.x.x 2012-07-22 21:55 - 2012-07-24 23:17 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\MilkShape 3D 1.x.x 2012-07-22 21:25 - 2012-07-22 21:25 - 00000000 ____D C:\Users\Sheila\Application Data\Peter L Jones 2012-07-22 21:25 - 2012-07-22 21:25 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Peter L Jones 2012-07-22 20:58 - 2012-07-22 21:16 - 00000000 ____D C:\Users\Sheila\Desktop\CreatedPoses 2012-07-22 20:40 - 2012-07-22 20:40 - 00000000 ____D C:\Program Files\s3pe 2012-07-22 19:08 - 2012-07-22 21:10 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan 2012-07-22 19:08 - 2012-07-22 19:08 - 00000000 ____D C:\Users\All Users\McAfee Security Scan 2012-07-22 19:08 - 2012-07-22 19:08 - 00000000 ____D C:\Users\All Users\Application Data\McAfee Security Scan 2012-07-22 17:55 - 2012-07-22 17:55 - 00000000 ____D C:\Users\All Users\Application Data\ALM 2012-07-22 17:55 - 2012-07-22 17:55 - 00000000 ____D C:\Users\All Users\ALM 2012-07-22 17:53 - 2007-02-20 15:04 - 02463976 ____A C:\Windows\SysWOW64\NPSWF32.dll 2012-07-22 17:53 - 2007-02-20 15:04 - 00190696 ____A (Adobe Systems, Inc.) C:\Windows\SysWOW64\NPSWF32_FlashUtil.exe 2012-07-22 17:49 - 2012-07-22 17:49 - 00000000 ____D C:\Windows\SysWOW64\spool 2012-07-22 17:48 - 2012-07-22 17:48 - 00000000 ____D C:\Program Files (x86)\Bonjour 2012-07-22 07:43 - 2012-07-22 07:43 - 00000000 ____D C:\Users\Sheila\.thumbnails 2012-07-22 07:42 - 2012-07-22 07:42 - 00000000 ____D C:\Program Files\Blender Foundation 2012-07-22 07:32 - 2012-07-29 12:15 - 00000000 ____D C:\Program Files (x86)\MilkShape 3D 1.8.5 2012-07-22 07:08 - 2012-07-22 07:08 - 00000000 ____D C:\Users\Sheila\Application Data\YourFileDownloader 2012-07-22 07:08 - 2012-07-22 07:08 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\YourFileDownloader 2012-07-22 07:01 - 2012-07-22 07:01 - 00000000 ____D C:\Users\Sheila\My Documents\Sims3 Ani Prog 2012-07-22 07:01 - 2012-07-22 07:01 - 00000000 ____D C:\Users\Sheila\Documents\Sims3 Ani Prog 2012-07-22 05:14 - 2012-07-22 05:14 - 00592908 ____A C:\Users\Sheila\Downloads\MTS_SeeMyu_1309273_SeeMyu_StackableHiddenCrate.rar 2012-07-22 05:12 - 2012-07-22 05:12 - 00072835 ____A C:\Users\Sheila\Downloads\MTS_cmomoney_1309148_cmomoney_TimeShifter.rar 2012-07-22 05:06 - 2012-07-22 05:07 - 01307724 ____A C:\Users\Sheila\Downloads\MTS_heaven_1265504_heaven_MTSOfficialTS3Calendar.rar 2012-07-21 22:14 - 2012-07-21 22:16 - 72591904 ____A (Microsoft Corporation) C:\Users\Sheila\Downloads\msert.exe 2012-07-21 22:10 - 2012-07-03 02:13 - 57442464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MRT.exe 2012-07-21 20:57 - 2012-07-21 20:57 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2012-07-21 20:48 - 2012-07-21 20:48 - 13083592 ____A (Microsoft Corporation) C:\Users\Sheila\Downloads\Silverlight_x64.exe 2012-07-21 14:19 - 2012-07-21 14:19 - 00000000 ____D C:\Users\Sheila\My Backup Files 2012-07-21 13:59 - 2012-07-21 13:59 - 03879808 ____A (AVG Technologies) C:\Users\Sheila\Downloads\avg_isct_stb_all_2012_2197.exe 2012-07-20 18:06 - 2012-07-20 18:06 - 00000000 ____D C:\Program Files (x86)\Oracle 2012-07-20 18:03 - 2012-07-20 18:03 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2012-07-20 18:03 - 2012-07-20 18:03 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2012-07-20 18:03 - 2012-07-05 21:06 - 00772544 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2012-07-20 18:03 - 2012-07-05 21:06 - 00227760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2012-07-20 16:04 - 2012-07-20 16:04 - 00000000 ____D C:\Users\Sheila\Application Data\ZinioReader4 2012-07-20 16:04 - 2012-07-20 16:04 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\ZinioReader4 2012-07-20 14:33 - 2012-07-20 14:33 - 00375024 ____A C:\Users\Sheila\Downloads\tws_danceII.rar 2012-07-20 14:30 - 2012-07-20 14:30 - 03421260 ____A C:\Users\Sheila\Downloads\BT_ TEARS TO SERIES_(1)-(4).rar 2012-07-20 13:39 - 2012-07-20 13:39 - 00497811 ____A C:\Users\Sheila\Downloads\acc tea-pot + tea-cup.rar 2012-07-20 13:35 - 2012-07-20 13:35 - 00362424 ____A C:\Users\Sheila\Downloads\tws_m.zip 2012-07-20 13:17 - 2012-07-20 13:17 - 00117650 ____A C:\Users\Sheila\Downloads\addie_man_a.zip 2012-07-20 13:01 - 2012-07-20 13:01 - 00000000 ____D C:\Windows\Sun 2012-07-20 06:10 - 2012-07-20 06:10 - 00005290 ____A C:\comcastrelease.log 2012-07-20 06:10 - 2012-07-20 06:10 - 00001274 ____A C:\Users\Sheila\Desktop\XFINITY Connect.lnk 2012-07-20 06:10 - 2012-07-20 06:10 - 00001246 ____A C:\Users\Sheila\Desktop\Constant Guard Protection Suite.lnk 2012-07-20 06:10 - 2012-07-20 06:10 - 00001240 ____A C:\Users\Sheila\Desktop\XFINITY TV.lnk 2012-07-20 06:10 - 2012-07-20 06:10 - 00000000 ____D C:\Users\Sheila\Local Settings\Xfinity.com 2012-07-20 06:10 - 2012-07-20 06:10 - 00000000 ____D C:\Users\Sheila\Local Settings\Application Data\Xfinity.com 2012-07-20 06:10 - 2012-07-20 06:10 - 00000000 ____D C:\Users\Sheila\AppData\Local\Xfinity.com 2012-07-20 06:08 - 2012-07-20 06:08 - 00765768 ____A C:\Users\Sheila\Downloads\Comcast_Desktop_Software_1203.exe 2012-07-20 06:02 - 2012-07-20 06:02 - 02896333 ____A C:\Users\Sheila\Downloads\ATS3_objects_downtown_sport.zip 2012-07-19 14:52 - 2012-07-19 14:52 - 00000000 ____D C:\Users\All Users\Mozilla 2012-07-19 14:52 - 2012-07-19 14:52 - 00000000 ____D C:\Users\All Users\Application Data\Mozilla 2012-07-19 14:52 - 2012-07-19 14:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2012-07-19 14:50 - 2012-07-19 14:50 - 16801656 ____A (Mozilla) C:\Users\Sheila\Downloads\Firefox Setup 14.0.1.exe 2012-07-18 22:47 - 2012-07-18 22:47 - 00028772 ____A C:\Users\Sheila\Downloads\MTS_Buzzler_1218064_Buzz_ShellSoundEmitter.zip 2012-07-18 19:24 - 2012-07-28 15:55 - 00000000 ____D C:\Users\Sheila\My Documents\Bandicam 2012-07-18 19:24 - 2012-07-28 15:55 - 00000000 ____D C:\Users\Sheila\Documents\Bandicam 2012-07-18 19:24 - 2012-07-18 19:24 - 00000000 ____D C:\Users\Sheila\Application Data\BANDISOFT 2012-07-18 19:24 - 2012-07-18 19:24 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\BANDISOFT 2012-07-18 19:23 - 2012-07-18 19:23 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1 2012-07-18 19:23 - 2012-07-18 19:23 - 00000000 ____D C:\Program Files (x86)\Bandicam 2012-07-18 18:43 - 2012-07-18 18:43 - 01100022 ____A C:\Users\Sheila\Downloads\MTS_petallotus_976121_tksshower080209.rar 2012-07-18 18:36 - 2012-07-18 18:36 - 01571864 ____A C:\Users\Sheila\Downloads\MTS_orangemittens_1052170_OM_GlassWalls.rar 2012-07-18 17:37 - 2012-07-18 17:37 - 00068859 ____A C:\Users\Sheila\Downloads\keyblade_onwall_CloudwalkerNZ.rar 2012-07-17 10:28 - 2012-07-17 10:28 - 00137063 ____A C:\Users\Sheila\Downloads\rose_sims3_magic015.rar 2012-07-17 10:28 - 2012-07-17 10:28 - 00055149 ____A C:\Users\Sheila\Downloads\rose_sims3_magic009.rar 2012-07-17 10:27 - 2012-07-17 10:27 - 00149108 ____A C:\Users\Sheila\Downloads\rose_sims3_magic010.rar 2012-07-17 10:27 - 2012-07-17 10:27 - 00140074 ____A C:\Users\Sheila\Downloads\rose_sims3_magic013.rar 2012-07-17 10:27 - 2012-07-17 10:27 - 00094900 ____A C:\Users\Sheila\Downloads\rose_sims3_magic011.rar 2012-07-17 10:25 - 2012-07-17 10:25 - 00472361 ____A C:\Users\Sheila\Downloads\Kunai-Knife-right_cloudwalkerNZ.sims3pack 2012-07-17 10:11 - 2012-07-17 10:11 - 00998119 ____A C:\Users\Sheila\Downloads\PoliceTape.rar 2012-07-16 16:54 - 2012-07-16 16:54 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_ZuneDriver_01_09_00.Wdf 2012-07-16 16:54 - 2012-07-16 16:54 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01009.Wdf 2012-07-16 12:08 - 2012-07-16 12:08 - 00921584 ____A C:\Users\Sheila\Downloads\MTS_melodie9_1011575_tfPregnantTeenClothesNudes.rar 2012-07-16 11:59 - 2012-07-16 11:59 - 00000000 ____D C:\Users\Sheila\Local Settings\NRaas_Industries 2012-07-16 11:59 - 2012-07-16 11:59 - 00000000 ____D C:\Users\Sheila\Local Settings\Application Data\NRaas_Industries 2012-07-16 11:59 - 2012-07-16 11:59 - 00000000 ____D C:\Users\Sheila\AppData\Local\NRaas_Industries 2012-07-16 10:08 - 2012-07-16 11:18 - 00000000 ____D C:\Users\Sheila\Application Data\Notepad++ 2012-07-16 10:08 - 2012-07-16 11:18 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Notepad++ 2012-07-16 10:08 - 2012-07-16 10:08 - 00000000 ____D C:\Program Files (x86)\Notepad++ 2012-07-15 14:49 - 2012-07-15 14:49 - 00003109 ____A C:\Users\Sheila\Downloads\PHTHON_phridge_tuners.zip 2012-07-14 19:49 - 2012-07-14 19:49 - 00000000 ____D C:\Program Files\7-Zip 2012-07-14 19:23 - 2012-06-25 13:58 - 00029712 ____A (Nitro PDF Software) C:\Windows\System32\nitrolocalmon2.dll 2012-07-14 19:23 - 2012-06-25 13:58 - 00017936 ____A (Nitro PDF Software) C:\Windows\System32\nitrolocalui2.dll 2012-07-14 19:22 - 2012-07-14 19:22 - 00000000 ____D C:\Program Files\Common Files\Nitro PDF 2012-07-14 19:20 - 2012-07-21 23:22 - 00000000 ____D C:\Users\Sheila\Application Data\Nitro PDF 2012-07-14 19:20 - 2012-07-21 23:22 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Nitro PDF 2012-07-14 19:20 - 2012-07-14 19:20 - 00000000 ____D C:\Users\Sheila\Application Data\Downloaded Installations 2012-07-14 19:20 - 2012-07-14 19:20 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Downloaded Installations 2012-07-14 19:19 - 2012-07-14 19:19 - 00000000 ____D C:\Users\All Users\Nitro PDF 2012-07-14 19:19 - 2012-07-14 19:19 - 00000000 ____D C:\Users\All Users\Application Data\Nitro PDF 2012-07-14 19:18 - 2012-07-14 19:18 - 00001153 ____A C:\Users\Public\Desktop\PrimoPDF - Drop Files Here to Convert!.lnk 2012-07-14 19:18 - 2012-07-14 19:18 - 00001153 ____A C:\Users\All Users\Desktop\PrimoPDF - Drop Files Here to Convert!.lnk 2012-07-14 19:18 - 2011-02-28 17:37 - 00095008 ____A C:\Windows\System32\Primomonnt.dll 2012-07-14 19:17 - 2012-07-14 19:18 - 00000000 ____D C:\Users\Sheila\Application Data\OpenCandy 2012-07-14 19:17 - 2012-07-14 19:18 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\OpenCandy 2012-07-14 19:16 - 2012-07-22 21:15 - 00000000 ____D C:\Users\Sheila\My Documents\MySims 3 2012-07-14 19:16 - 2012-07-22 21:15 - 00000000 ____D C:\Users\Sheila\Documents\MySims 3 2012-07-12 20:02 - 2012-07-12 20:02 - 00000000 __RHD C:\Users\Sheila\Application Data\SecuROM 2012-07-12 20:02 - 2012-07-12 20:02 - 00000000 __RHD C:\Users\Sheila\AppData\Roaming\SecuROM 2012-07-12 16:23 - 2012-07-12 16:23 - 00000000 ____D C:\Users\All Users\regid.1986-12.com.adobe 2012-07-12 16:23 - 2012-07-12 16:23 - 00000000 ____D C:\Users\All Users\Application Data\regid.1986-12.com.adobe 2012-07-12 14:59 - 2012-07-12 14:59 - 00000000 ____D C:\Program Files (x86)\Adobe Story 2012-07-12 14:58 - 2012-07-12 14:58 - 00000000 ____D C:\Program Files (x86)\My Company Name 2012-07-12 12:27 - 2012-07-12 12:27 - 00000000 ____D C:\Users\Sheila\Application Data\Apple Computer 2012-07-12 12:27 - 2012-07-12 12:27 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Apple Computer 2012-07-12 11:30 - 2012-07-03 12:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-07-12 09:47 - 2012-07-12 09:47 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2012-07-11 20:42 - 2012-07-11 20:42 - 00000000 ____D C:\Users\Sheila\My Documents\Electronic Arts 2012-07-11 20:42 - 2012-07-11 20:42 - 00000000 ____D C:\Users\Sheila\Documents\Electronic Arts 2012-07-11 20:42 - 2012-07-11 20:42 - 00000000 ____D C:\Users\All Users\EA Core 2012-07-11 20:42 - 2012-07-11 20:42 - 00000000 ____D C:\Users\All Users\Application Data\EA Core 2012-07-11 19:47 - 2012-07-11 19:45 - 00447752 ____A (On2.com) C:\Windows\SysWOW64\vp6vfw.dll 2012-07-11 19:46 - 2012-07-11 19:46 - 00000000 ____D C:\Program Files (x86)\Microsoft WSE 2012-07-11 11:18 - 2012-07-12 20:01 - 00000000 ____D C:\Users\All Users\Origin 2012-07-11 11:18 - 2012-07-12 20:01 - 00000000 ____D C:\Users\All Users\Application Data\Origin 2012-07-11 11:18 - 2012-07-12 03:18 - 00000000 ____D C:\Program Files (x86)\Origin Games 2012-07-11 11:18 - 2012-07-11 11:18 - 00000000 ____D C:\Users\Sheila\Local Settings\Origin 2012-07-11 11:18 - 2012-07-11 11:18 - 00000000 ____D C:\Users\Sheila\Local Settings\Application Data\Origin 2012-07-11 11:18 - 2012-07-11 11:18 - 00000000 ____D C:\Users\Sheila\AppData\Local\Origin 2012-07-11 11:17 - 2012-07-11 11:18 - 00000000 ____D C:\Users\Sheila\Application Data\Origin 2012-07-11 11:17 - 2012-07-11 11:18 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Origin 2012-07-11 11:17 - 2012-07-11 11:18 - 00000000 ____D C:\Program Files (x86)\Origin 2012-07-11 11:17 - 2012-07-11 11:17 - 00000537 ____A C:\Windows\KB893803v2.log 2012-07-11 11:17 - 2012-07-11 11:17 - 00000000 ____D C:\Users\All Users\Electronic Arts 2012-07-11 11:17 - 2012-07-11 11:17 - 00000000 ____D C:\Users\All Users\Application Data\Electronic Arts 2012-07-11 10:36 - 2012-07-11 10:36 - 00000000 ____D C:\Users\All Users\Application Data\Apple Computer 2012-07-11 10:36 - 2012-07-11 10:36 - 00000000 ____D C:\Users\All Users\Apple Computer 2012-07-11 10:36 - 2012-07-11 10:36 - 00000000 ____D C:\Program Files (x86)\QuickTime 2012-07-11 10:35 - 2012-07-11 10:35 - 00000000 ____D C:\Users\All Users\Application Data\Apple 2012-07-11 10:35 - 2012-07-11 10:35 - 00000000 ____D C:\Users\All Users\Apple 2012-07-11 10:35 - 2012-07-11 10:35 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2012-07-11 10:27 - 2012-07-11 10:27 - 00000000 ____D C:\Users\Sheila\Local Settings\Macromedia 2012-07-11 10:27 - 2012-07-11 10:27 - 00000000 ____D C:\Users\Sheila\Local Settings\Application Data\Macromedia 2012-07-11 10:27 - 2012-07-11 10:27 - 00000000 ____D C:\Users\Sheila\AppData\Local\Macromedia 2012-07-11 10:26 - 2012-07-24 22:46 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-07-11 09:22 - 2012-07-11 09:22 - 00000000 ____D C:\Users\Sheila\My Documents\Amazon MP3 2012-07-11 09:22 - 2012-07-11 09:22 - 00000000 ____D C:\Users\Sheila\Documents\Amazon MP3 2012-07-11 09:22 - 2012-07-11 09:22 - 00000000 ____D C:\Users\Sheila\Application Data\Amazon 2012-07-11 09:22 - 2012-07-11 09:22 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Amazon 2012-07-11 09:21 - 2012-07-11 09:21 - 00000000 ____D C:\Program Files (x86)\Amazon 2012-07-11 09:09 - 2012-07-11 09:09 - 00000000 ____D C:\Users\Sheila\Application Data\PeaZip 2012-07-11 09:09 - 2012-07-11 09:09 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\PeaZip 2012-07-11 09:05 - 2012-07-11 09:05 - 00000000 __SHD C:\Users\Sheila\IECompatCache 2012-07-11 09:02 - 2012-07-11 09:08 - 00000000 ____D C:\Users\Sheila\Application Data\Skype 2012-07-11 09:02 - 2012-07-11 09:08 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Skype 2012-07-11 08:46 - 2012-07-11 08:46 - 00000000 ____D C:\Users\Sheila\Application Data\CBS Interactive 2012-07-11 08:46 - 2012-07-11 08:46 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\CBS Interactive 2012-07-11 08:44 - 2012-07-11 08:44 - 00000000 ____D C:\Program Files (x86)\PeaZip 2012-07-10 13:42 - 2012-06-11 22:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-07-10 13:35 - 2012-07-10 13:35 - 00296092 ____A C:\Windows\msxml4-KB973688-enu.LOG 2012-07-10 13:34 - 2012-07-10 13:34 - 00294342 ____A C:\Windows\msxml4-KB954430-enu.LOG 2012-07-10 13:34 - 2012-07-10 13:34 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0 2012-07-10 13:23 - 2012-07-03 02:19 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-07-10 13:15 - 2012-06-02 07:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-07-10 13:15 - 2012-06-02 07:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-07-10 13:15 - 2012-06-02 07:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-07-10 13:15 - 2012-06-02 07:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-07-10 13:15 - 2012-06-02 07:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-07-10 13:15 - 2012-06-02 07:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-07-10 13:15 - 2012-06-02 07:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-07-10 13:15 - 2012-06-02 07:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-07-10 13:15 - 2012-06-02 07:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-07-10 13:15 - 2012-06-02 07:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-07-10 13:15 - 2012-06-02 06:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-07-10 13:15 - 2012-06-02 06:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-07-10 13:15 - 2012-06-02 06:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-07-10 13:15 - 2012-06-02 06:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-07-10 13:15 - 2012-06-02 04:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-07-10 13:15 - 2012-06-02 03:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-07-10 13:15 - 2012-06-02 03:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-07-10 13:15 - 2012-06-02 03:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-07-10 13:15 - 2012-06-02 03:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-07-10 13:15 - 2012-06-02 03:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-07-10 13:15 - 2012-06-02 03:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-07-10 13:15 - 2012-06-02 03:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-07-10 13:15 - 2012-06-02 03:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-07-10 13:15 - 2012-06-02 03:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-07-10 13:15 - 2012-06-02 03:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-07-10 13:15 - 2012-06-02 03:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-07-10 13:15 - 2012-06-02 03:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-07-10 13:15 - 2012-06-02 03:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-07-10 13:15 - 2012-03-01 01:46 - 00023408 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fs_rec.sys 2012-07-10 13:15 - 2012-03-01 01:38 - 00220672 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll 2012-07-10 13:15 - 2012-03-01 01:33 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\imagehlp.dll 2012-07-10 13:15 - 2012-03-01 01:28 - 00005120 ____A (Microsoft Corporation) C:\Windows\System32\wmi.dll 2012-07-10 13:15 - 2012-03-01 00:37 - 00172544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2012-07-10 13:15 - 2012-03-01 00:33 - 00159232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2012-07-10 13:15 - 2012-03-01 00:29 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll 2012-07-10 13:08 - 2012-05-04 06:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll 2012-07-10 13:08 - 2012-05-04 04:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2012-07-10 12:35 - 2012-07-29 12:13 - 00000506 ____A C:\Windows\Tasks\SystemToolsDailyTest.job 2012-07-10 12:35 - 2012-07-12 12:25 - 00000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job 2012-07-10 12:35 - 2012-07-10 12:35 - 00000000 ____D C:\Program Files\Dell Support Center 2012-07-10 10:34 - 2012-06-06 01:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-07-10 10:34 - 2012-06-06 01:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll 2012-07-10 10:34 - 2012-06-06 00:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2012-07-10 10:34 - 2012-06-06 00:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2012-07-10 10:34 - 2012-03-03 01:35 - 01544704 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2012-07-10 10:34 - 2012-03-03 00:31 - 01077248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2012-07-10 10:34 - 2012-01-04 05:44 - 00509952 ____A (Microsoft Corporation) C:\Windows\System32\ntshrui.dll 2012-07-10 10:34 - 2012-01-04 03:58 - 00442880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll 2012-07-10 10:34 - 2011-12-30 01:26 - 00515584 ____A (Microsoft Corporation) C:\Windows\System32\timedate.cpl 2012-07-10 10:34 - 2011-12-30 00:27 - 00478720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl 2012-07-10 10:34 - 2010-06-25 22:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll 2012-07-10 10:34 - 2010-06-25 22:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2012-07-10 10:33 - 2012-06-09 00:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2012-07-10 10:33 - 2012-06-08 23:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2012-07-10 10:33 - 2012-06-02 00:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys 2012-07-10 10:33 - 2012-06-02 00:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2012-07-10 10:33 - 2012-06-02 00:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2012-07-10 10:33 - 2012-06-02 00:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2012-07-10 10:33 - 2012-06-02 00:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2012-07-10 10:33 - 2012-06-01 23:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2012-07-10 10:33 - 2012-06-01 23:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2012-07-10 10:33 - 2012-06-01 23:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2012-07-10 10:33 - 2012-06-01 23:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2012-07-10 10:33 - 2012-05-04 06:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-07-10 10:33 - 2012-05-04 05:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2012-07-10 10:33 - 2012-05-04 05:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2012-07-10 10:33 - 2012-05-01 00:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll 2012-07-10 10:33 - 2012-04-27 22:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys 2012-07-10 10:33 - 2012-04-26 00:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll 2012-07-10 10:33 - 2012-04-26 00:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll 2012-07-10 10:33 - 2012-04-26 00:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe 2012-07-10 10:33 - 2012-04-24 00:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2012-07-10 10:33 - 2012-04-24 00:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2012-07-10 10:33 - 2012-04-24 00:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2012-07-10 10:33 - 2012-04-23 23:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2012-07-10 10:33 - 2012-04-23 23:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2012-07-10 10:33 - 2012-04-23 23:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2012-07-10 10:33 - 2012-04-07 07:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll 2012-07-10 10:33 - 2012-04-07 06:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2012-07-10 10:33 - 2012-03-17 02:58 - 00075120 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys 2012-07-10 10:33 - 2011-12-27 22:59 - 00498688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\afd.sys 2012-07-10 10:33 - 2011-03-12 07:08 - 01465344 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll 2012-07-10 10:33 - 2011-03-12 06:23 - 00870912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2012-07-10 10:32 - 2012-06-06 01:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll 2012-07-10 10:32 - 2012-06-06 00:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2012-07-10 10:32 - 2012-03-30 06:35 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2012-07-10 10:32 - 2011-12-16 03:46 - 00634880 ____A (Microsoft Corporation) C:\Windows\System32\msvcrt.dll 2012-07-10 10:32 - 2011-12-16 02:52 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll 2012-07-10 10:32 - 2011-02-22 23:55 - 00090624 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bowser.sys 2012-07-10 10:21 - 2012-02-17 01:38 - 01031680 ____A (Microsoft Corporation) C:\Windows\System32\rdpcore.dll 2012-07-10 10:21 - 2012-02-17 00:34 - 00826880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2012-07-10 10:21 - 2012-02-16 23:57 - 00023552 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tdtcp.sys 2012-07-10 10:16 - 2012-06-02 17:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-07-10 10:16 - 2012-06-02 17:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-07-10 10:16 - 2012-06-02 17:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-07-10 10:16 - 2012-06-02 17:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-07-10 10:16 - 2012-06-02 17:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-07-10 10:16 - 2012-06-02 17:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-07-10 10:16 - 2012-06-02 17:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-07-10 10:16 - 2012-06-02 14:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-07-10 10:16 - 2012-06-02 14:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2012-07-09 18:16 - 2012-07-09 18:16 - 00000000 ____D C:\Users\Sheila\Application Data\PrimoPDF 2012-07-09 18:16 - 2012-07-09 18:16 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\PrimoPDF 2012-07-08 14:25 - 2012-07-08 14:26 - 00000000 ____D C:\Users\Lotus\Application Data\Mozilla 2012-07-08 14:25 - 2012-07-08 14:26 - 00000000 ____D C:\Users\Lotus\AppData\Roaming\Mozilla 2012-07-08 14:25 - 2012-07-08 14:25 - 00000000 ____D C:\Users\Lotus\Local Settings\Mozilla 2012-07-08 14:25 - 2012-07-08 14:25 - 00000000 ____D C:\Users\Lotus\Local Settings\Application Data\Mozilla 2012-07-08 14:25 - 2012-07-08 14:25 - 00000000 ____D C:\Users\Lotus\AppData\Local\Mozilla 2012-07-08 14:24 - 2012-07-08 14:24 - 00000000 ____D C:\Users\Lotus\Application Data\Adobe 2012-07-08 14:24 - 2012-07-08 14:24 - 00000000 ____D C:\Users\Lotus\AppData\Roaming\Adobe 2012-07-08 13:15 - 2012-07-24 15:51 - 00000000 ____D C:\Users\Lotus\Local Settings\Nero 2012-07-08 13:15 - 2012-07-24 15:51 - 00000000 ____D C:\Users\Lotus\Local Settings\Application Data\Nero 2012-07-08 13:15 - 2012-07-24 15:51 - 00000000 ____D C:\Users\Lotus\AppData\Local\Nero 2012-07-08 13:15 - 2012-07-08 13:15 - 00000000 ___RD C:\Users\Lotus\Desktop\MySyncUPFiles 2012-07-08 13:15 - 2012-07-08 13:15 - 00000000 ____D C:\Users\Lotus\Local Settings\Nero_AG 2012-07-08 13:15 - 2012-07-08 13:15 - 00000000 ____D C:\Users\Lotus\Local Settings\Application Data\Nero_AG 2012-07-08 13:15 - 2012-07-08 13:15 - 00000000 ____D C:\Users\Lotus\Application Data\Roxio Burn 2012-07-08 13:15 - 2012-07-08 13:15 - 00000000 ____D C:\Users\Lotus\Application Data\Nero 2012-07-08 13:15 - 2012-07-08 13:15 - 00000000 ____D C:\Users\Lotus\AppData\Roaming\Roxio Burn 2012-07-08 13:15 - 2012-07-08 13:15 - 00000000 ____D C:\Users\Lotus\AppData\Roaming\Nero 2012-07-08 13:15 - 2012-07-08 13:15 - 00000000 ____D C:\Users\Lotus\AppData\Local\Nero_AG 2012-07-08 13:13 - 2012-07-08 13:13 - 00000000 ____D C:\Users\Lotus\Application Data\Macrovision 2012-07-08 13:13 - 2012-07-08 13:13 - 00000000 ____D C:\Users\Lotus\AppData\Roaming\Macrovision 2012-07-08 13:12 - 2012-07-08 13:12 - 00000000 ____D C:\Users\Lotus\Local Settings\Dell 2012-07-08 13:12 - 2012-07-08 13:12 - 00000000 ____D C:\Users\Lotus\Local Settings\Application Data\Dell 2012-07-08 13:12 - 2012-07-08 13:12 - 00000000 ____D C:\Users\Lotus\AppData\Local\Dell 2012-07-08 13:11 - 2012-07-24 15:36 - 00126760 ____A C:\Users\Lotus\Local Settings\GDIPFONTCACHEV1.DAT 2012-07-08 13:11 - 2012-07-24 15:36 - 00126760 ____A C:\Users\Lotus\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2012-07-08 13:11 - 2012-07-24 15:36 - 00126760 ____A C:\Users\Lotus\AppData\Local\GDIPFONTCACHEV1.DAT 2012-07-08 13:11 - 2012-07-08 13:11 - 00000020 ___SH C:\Users\Lotus\ntuser.ini 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\Local Settings\VirtualStore 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\Local Settings\Conexant 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\Local Settings\Application Data\VirtualStore 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\Local Settings\Application Data\Conexant 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\Application Data\Roxio 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\Application Data\Leadertech 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\Application Data\Intel 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\Application Data\Dell 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\Application Data\Creative 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\AppData\Roaming\Roxio 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\AppData\Roaming\Leadertech 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\AppData\Roaming\Intel 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\AppData\Roaming\Dell 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\AppData\Roaming\Creative 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\AppData\Local\VirtualStore 2012-07-08 13:11 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\AppData\Local\Conexant 2012-07-07 16:28 - 2012-07-07 16:28 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services 2012-07-07 16:27 - 2012-07-07 16:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Sync Framework 2012-07-07 16:26 - 2012-07-07 16:26 - 00000000 ____D C:\Program Files\Microsoft Office 2012-07-07 16:26 - 2012-07-07 16:26 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8 2012-07-07 16:26 - 2012-07-07 16:26 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services 2012-07-07 16:25 - 2012-07-10 13:43 - 00000000 ____D C:\Users\All Users\Microsoft Help 2012-07-07 16:25 - 2012-07-10 13:43 - 00000000 ____D C:\Users\All Users\Application Data\Microsoft Help 2012-07-07 16:25 - 2012-07-07 16:25 - 00000000 __RHD C:\MSOCache 2012-07-07 16:25 - 2012-07-07 16:25 - 00000000 ____D C:\Users\Sheila\Local Settings\Microsoft Help 2012-07-07 16:25 - 2012-07-07 16:25 - 00000000 ____D C:\Users\Sheila\Local Settings\Application Data\Microsoft Help 2012-07-07 16:25 - 2012-07-07 16:25 - 00000000 ____D C:\Users\Sheila\AppData\Local\Microsoft Help 2012-07-07 16:13 - 2012-07-07 16:13 - 00000000 ____D C:\Users\Public\Documents\DAEMON Tools Images 2012-07-07 16:13 - 2012-07-07 16:13 - 00000000 ____D C:\Users\All Users\Documents\DAEMON Tools Images 2012-07-07 11:51 - 2012-07-07 16:14 - 00000000 ____D C:\Users\Sheila\Application Data\DAEMON Tools Lite 2012-07-07 11:51 - 2012-07-07 16:14 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\DAEMON Tools Lite 2012-07-07 11:51 - 2012-07-07 11:51 - 00560184 ____A (Duplex Secure Ltd.) C:\Windows\System32\Drivers\sptd.sys 2012-07-07 11:50 - 2012-07-07 11:51 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite 2012-07-07 11:10 - 2012-07-07 16:15 - 00000000 ____D C:\Users\All Users\DAEMON Tools Lite 2012-07-07 11:10 - 2012-07-07 16:15 - 00000000 ____D C:\Users\All Users\Application Data\DAEMON Tools Lite 2012-07-07 09:00 - 2012-07-10 12:34 - 00000000 ____D C:\Users\Sheila\Application Data\PCDr 2012-07-07 09:00 - 2012-07-10 12:34 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\PCDr 2012-07-06 21:20 - 2012-07-06 21:20 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2012-07-06 21:20 - 2012-07-06 21:20 - 00000000 ____D C:\Users\Sheila\Local Settings\Nero_AG 2012-07-06 21:20 - 2012-07-06 21:20 - 00000000 ____D C:\Users\Sheila\Local Settings\Application Data\Nero_AG 2012-07-06 21:20 - 2012-07-06 21:20 - 00000000 ____D C:\Users\Sheila\AppData\Local\Nero_AG 2012-07-06 21:19 - 2012-07-06 21:19 - 00000000 ____D C:\Users\Sheila\Local Settings\Mozilla 2012-07-06 21:19 - 2012-07-06 21:19 - 00000000 ____D C:\Users\Sheila\Local Settings\Application Data\Mozilla 2012-07-06 21:19 - 2012-07-06 21:19 - 00000000 ____D C:\Users\Sheila\Application Data\Mozilla 2012-07-06 21:19 - 2012-07-06 21:19 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Mozilla 2012-07-06 21:19 - 2012-07-06 21:19 - 00000000 ____D C:\Users\Sheila\AppData\Local\Mozilla 2012-07-06 21:18 - 2012-07-06 21:18 - 00000000 ____D C:\Users\Sheila\Application Data\Malwarebytes 2012-07-06 21:18 - 2012-07-06 21:18 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Malwarebytes 2012-07-06 21:18 - 2012-07-06 21:18 - 00000000 ____D C:\Users\All Users\Malwarebytes 2012-07-06 21:18 - 2012-07-06 21:18 - 00000000 ____D C:\Users\All Users\Application Data\Malwarebytes 2012-07-06 21:15 - 2012-07-24 23:24 - 00000000 ____D C:\Users\Sheila\Application Data\uTorrent 2012-07-06 21:15 - 2012-07-24 23:24 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\uTorrent 2012-07-06 21:14 - 2012-07-06 21:14 - 00000000 ____D C:\Users\Sheila\Application Data\Poppeman 2012-07-06 21:14 - 2012-07-06 21:14 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Poppeman 2012-07-06 21:14 - 2012-07-06 21:14 - 00000000 ____D C:\Program Files\Pictus 2012-07-06 19:42 - 2012-07-06 19:42 - 00000000 ____D C:\Program Files (x86)\Adobe Reader 64-bit fixes 2012-07-06 19:08 - 2012-07-28 15:54 - 00000000 ____D C:\Users\Sheila\Local Settings\Nero 2012-07-06 19:08 - 2012-07-28 15:54 - 00000000 ____D C:\Users\Sheila\Local Settings\Application Data\Nero 2012-07-06 19:08 - 2012-07-28 15:54 - 00000000 ____D C:\Users\Sheila\AppData\Local\Nero 2012-07-06 19:08 - 2012-07-06 19:08 - 00000000 ___RD C:\Users\Sheila\Desktop\MySyncUPFiles 2012-07-06 19:08 - 2012-07-06 19:08 - 00000000 ____D C:\Users\Sheila\Application Data\Nero 2012-07-06 19:08 - 2012-07-06 19:08 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Nero 2012-07-06 19:00 - 2012-07-06 19:00 - 00000000 ____D C:\Users\All Users\PCDr 2012-07-06 19:00 - 2012-07-06 19:00 - 00000000 ____D C:\Users\All Users\Application Data\PCDr 2012-07-06 18:57 - 2012-07-06 18:57 - 00000000 __SHD C:\Users\Sheila\IETldCache 2012-07-06 18:38 - 2012-07-06 18:38 - 00033840 ____A C:\Windows\System32\emptyregdb.dat 2012-07-06 16:58 - 2012-07-28 17:05 - 00000000 ____D C:\Users\Sheila\Application Data\Adobe 2012-07-06 16:58 - 2012-07-28 17:05 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Adobe 2012-07-06 16:13 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\Local Settings\SoftThinks 2012-07-06 16:13 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\Local Settings\Application Data\SoftThinks 2012-07-06 16:13 - 2012-07-08 13:11 - 00000000 ____D C:\Users\Lotus\AppData\Local\SoftThinks 2012-07-06 16:13 - 2012-07-08 13:11 - 00000000 ____D C:\users\Lotus 2012-07-06 16:13 - 2012-07-06 18:39 - 00025675 ____A C:\Windows\comsetup.log 2012-07-06 16:13 - 2012-03-08 05:45 - 00000000 ___RD C:\Users\Lotus\Desktop\Play Games 2012-07-06 16:13 - 2012-03-08 05:13 - 00000000 ____D C:\Users\Lotus\Application Data\Macromedia 2012-07-06 16:13 - 2012-03-08 05:13 - 00000000 ____D C:\Users\Lotus\AppData\Roaming\Macromedia 2012-07-06 16:04 - 2012-07-06 16:04 - 00000000 ___DC C:\Users\Sheila\Local Settings\MigWiz 2012-07-06 16:04 - 2012-07-06 16:04 - 00000000 ___DC C:\Users\Sheila\Local Settings\Application Data\MigWiz 2012-07-06 16:04 - 2012-07-06 16:04 - 00000000 ___DC C:\Users\Sheila\AppData\Local\MigWiz 2012-07-06 11:23 - 2012-07-06 11:23 - 00000000 ____D C:\Users\Sheila\Local Settings\Sonic_Solutions 2012-07-06 11:23 - 2012-07-06 11:23 - 00000000 ____D C:\Users\Sheila\Local Settings\Application Data\Sonic_Solutions 2012-07-06 11:23 - 2012-07-06 11:23 - 00000000 ____D C:\Users\Sheila\AppData\Local\Sonic_Solutions 2012-07-06 10:53 - 2012-07-06 10:53 - 00000000 ____D C:\Users\Sheila\Application Data\Roxio Burn 2012-07-06 10:53 - 2012-07-06 10:53 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Roxio Burn 2012-07-06 02:15 - 2012-07-06 02:15 - 00000000 ____D C:\Users\Sheila\Application Data\Macrovision 2012-07-06 02:15 - 2012-07-06 02:15 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Macrovision 2012-07-06 02:12 - 2012-07-06 02:12 - 00000000 ____D C:\Users\Sheila\Local Settings\Dell 2012-07-06 02:12 - 2012-07-06 02:12 - 00000000 ____D C:\Users\Sheila\Local Settings\Application Data\Dell 2012-07-06 02:12 - 2012-07-06 02:12 - 00000000 ____D C:\Users\Sheila\AppData\Local\Dell 2012-07-06 02:11 - 2012-07-06 02:11 - 00000000 ____D C:\Users\Sheila\Application Data\Leadertech 2012-07-06 02:11 - 2012-07-06 02:11 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Leadertech 2012-07-06 02:10 - 2012-07-06 11:24 - 00000000 ____D C:\Users\Sheila\Application Data\Roxio 2012-07-06 02:10 - 2012-07-06 11:24 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Roxio 2012-07-06 02:10 - 2012-07-06 02:10 - 00000000 ____D C:\Users\Sheila\Local Settings\Conexant 2012-07-06 02:10 - 2012-07-06 02:10 - 00000000 ____D C:\Users\Sheila\Local Settings\Application Data\Conexant 2012-07-06 02:10 - 2012-07-06 02:10 - 00000000 ____D C:\Users\Sheila\Application Data\Dell 2012-07-06 02:10 - 2012-07-06 02:10 - 00000000 ____D C:\Users\Sheila\Application Data\Creative 2012-07-06 02:10 - 2012-07-06 02:10 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Dell 2012-07-06 02:10 - 2012-07-06 02:10 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Creative 2012-07-06 02:10 - 2012-07-06 02:10 - 00000000 ____D C:\Users\Sheila\AppData\Local\Conexant 2012-07-06 02:09 - 2012-07-27 08:54 - 00000000 ____D C:\Users\Sheila\Local Settings\VirtualStore 2012-07-06 02:09 - 2012-07-27 08:54 - 00000000 ____D C:\Users\Sheila\Local Settings\Application Data\VirtualStore 2012-07-06 02:09 - 2012-07-27 08:54 - 00000000 ____D C:\Users\Sheila\AppData\Local\VirtualStore 2012-07-06 02:07 - 2012-07-22 17:55 - 00126760 ____A C:\Users\Sheila\Local Settings\GDIPFONTCACHEV1.DAT 2012-07-06 02:07 - 2012-07-22 17:55 - 00126760 ____A C:\Users\Sheila\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2012-07-06 02:07 - 2012-07-22 17:55 - 00126760 ____A C:\Users\Sheila\AppData\Local\GDIPFONTCACHEV1.DAT 2012-07-06 02:06 - 2012-07-28 15:54 - 00000000 ____D C:\users\Sheila 2012-07-06 02:06 - 2012-07-21 14:19 - 00000000 ____D C:\Users\Sheila\Local Settings\SoftThinks 2012-07-06 02:06 - 2012-07-21 14:19 - 00000000 ____D C:\Users\Sheila\Local Settings\Application Data\SoftThinks 2012-07-06 02:06 - 2012-07-21 14:19 - 00000000 ____D C:\Users\Sheila\AppData\Local\SoftThinks 2012-07-06 02:06 - 2012-07-06 02:06 - 00000020 ___SH C:\Users\Sheila\ntuser.ini 2012-07-06 02:06 - 2012-07-06 02:06 - 00000000 ____D C:\Users\Sheila\Application Data\Intel 2012-07-06 02:06 - 2012-07-06 02:06 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Intel 2012-07-06 02:06 - 2012-03-08 05:13 - 00000000 ____D C:\Users\Sheila\Application Data\Macromedia 2012-07-06 02:06 - 2012-03-08 05:13 - 00000000 ____D C:\Users\Sheila\AppData\Roaming\Macromedia 2012-07-06 01:04 - 2012-07-06 01:36 - 00000000 ____D C:\Windows\SMINST 2012-07-01 16:34 - 2012-07-06 17:43 - 00000000 ____D C:\Users\Public\Documents\Melaleuca 2012-07-01 16:34 - 2012-07-06 17:43 - 00000000 ____D C:\Users\All Users\Documents\Melaleuca 2012-06-30 18:20 - 2012-06-30 19:01 - 526160934 ____A C:\Users\Public\Documents\Ultimate_Getting_Started_with_Japanese_Package.zip 2012-06-30 18:20 - 2012-06-30 19:01 - 526160934 ____A C:\Users\All Users\Documents\Ultimate_Getting_Started_with_Japanese_Package.zip ============ 3 Months Modified Files ======================== 2012-07-29 12:22 - 2012-07-29 12:22 - 00597504 ____A (OldTimer Tools) C:\Users\Sheila\Desktop\OTL.exe 2012-07-29 12:13 - 2012-07-10 12:35 - 00000506 ____A C:\Windows\Tasks\SystemToolsDailyTest.job 2012-07-29 11:56 - 2009-07-14 00:13 - 00778660 ____A C:\Windows\System32\PerfStringBackup.INI 2012-07-29 10:27 - 2009-07-13 23:45 - 00021296 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-07-29 10:27 - 2009-07-13 23:45 - 00021296 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-07-29 10:18 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-07-29 10:18 - 2009-07-13 23:51 - 00044757 ____A C:\Windows\setupact.log 2012-07-28 16:41 - 2012-07-28 16:40 - 02456480 ____A C:\Users\Sheila\Desktop\Video.avi 2012-07-28 14:43 - 2012-07-28 14:43 - 01100054 ____A C:\Users\Sheila\Downloads\MTS_spladoum_1303728_WheelchairSetS3Pack.rar 2012-07-28 14:43 - 2012-07-28 14:43 - 00121425 ____A C:\Users\Sheila\Downloads\MTS_spladoum_1303722_WheelchairPoses.rar 2012-07-27 20:41 - 2012-07-27 20:41 - 00169130 ____A C:\Users\Sheila\Downloads\PosePackCreator_1_3.rar 2012-07-27 16:42 - 2012-07-27 16:42 - 00166645 ____A C:\Users\Sheila\Downloads\MTS_CmarNYC_1311045_MeshToolKit_1_0_0_1.zip 2012-07-27 16:34 - 2012-07-27 16:34 - 06435923 ____A C:\Users\Sheila\Downloads\MTS_Nathia_1310244_WildFireFrofortheLadies.rar 2012-07-27 13:54 - 2012-07-27 08:58 - 00016933 ____A C:\Users\Sheila\Desktop\hijackthis.log 2012-07-27 08:49 - 2012-07-27 08:49 - 00388608 ____A (Trend Micro Inc.) C:\Users\Sheila\Desktop\HiJackThis.exe 2012-07-27 07:37 - 2010-11-20 22:47 - 00047278 ____A C:\Windows\PFRO.log 2012-07-26 23:31 - 2012-07-26 23:30 - 00002148 ____A C:\Users\Sheila\Downloads\SuperDAT.log 2012-07-26 23:30 - 2012-07-26 23:29 - 105418616 ____A (McAfee, Inc.) C:\Users\Sheila\Downloads\6783xdat.exe 2012-07-24 23:15 - 2012-07-24 23:11 - 05531455 ____A C:\Users\Sheila\Downloads\Milkshape3D.zip 2012-07-24 22:46 - 2012-07-11 10:26 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-07-24 22:46 - 2012-03-08 04:21 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-07-24 22:45 - 2012-03-08 06:16 - 01578611 ____A C:\Windows\WindowsUpdate.log 2012-07-24 19:25 - 2012-07-24 19:25 - 01032390 ____A C:\Users\Sheila\Downloads\Danzxncrd_poseset01_Come_Sit_with_Me_updated_with_poses_list.rar 2012-07-24 19:16 - 2012-07-24 19:16 - 00874892 ____A C:\Users\Sheila\Downloads\a_dill_no013-022.rar 2012-07-24 19:10 - 2012-07-24 19:10 - 00118888 ____A C:\Users\Sheila\Downloads\a_come_1-6.rar 2012-07-24 15:36 - 2012-07-08 13:11 - 00126760 ____A C:\Users\Lotus\Local Settings\GDIPFONTCACHEV1.DAT 2012-07-24 15:36 - 2012-07-08 13:11 - 00126760 ____A C:\Users\Lotus\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2012-07-24 15:36 - 2012-07-08 13:11 - 00126760 ____A C:\Users\Lotus\AppData\Local\GDIPFONTCACHEV1.DAT 2012-07-24 13:33 - 2009-07-13 23:45 - 05283232 ____A C:\Windows\System32\FNTCACHE.DAT 2012-07-22 22:26 - 2012-07-22 22:26 - 00000016 ___RH C:\Users\All Users\Application Data\552B474E.ini 2012-07-22 22:26 - 2012-07-22 22:26 - 00000016 ___RH C:\Users\All Users\552B474E.ini 2012-07-22 22:16 - 2012-07-22 22:16 - 00000016 ___RH C:\Users\Sheila\Local Settings\Application Data\2A95A3A7.ini 2012-07-22 22:16 - 2012-07-22 22:16 - 00000016 ___RH C:\Users\Sheila\Local Settings\2A95A3A7.ini 2012-07-22 22:16 - 2012-07-22 22:16 - 00000016 ___RH C:\Users\Sheila\AppData\Local\2A95A3A7.ini 2012-07-22 17:55 - 2012-07-06 02:07 - 00126760 ____A C:\Users\Sheila\Local Settings\GDIPFONTCACHEV1.DAT 2012-07-22 17:55 - 2012-07-06 02:07 - 00126760 ____A C:\Users\Sheila\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2012-07-22 17:55 - 2012-07-06 02:07 - 00126760 ____A C:\Users\Sheila\AppData\Local\GDIPFONTCACHEV1.DAT 2012-07-22 05:14 - 2012-07-22 05:14 - 00592908 ____A C:\Users\Sheila\Downloads\MTS_SeeMyu_1309273_SeeMyu_StackableHiddenCrate.rar 2012-07-22 05:12 - 2012-07-22 05:12 - 00072835 ____A C:\Users\Sheila\Downloads\MTS_cmomoney_1309148_cmomoney_TimeShifter.rar 2012-07-22 05:07 - 2012-07-22 05:06 - 01307724 ____A C:\Users\Sheila\Downloads\MTS_heaven_1265504_heaven_MTSOfficialTS3Calendar.rar 2012-07-21 22:16 - 2012-07-21 22:14 - 72591904 ____A (Microsoft Corporation) C:\Users\Sheila\Downloads\msert.exe 2012-07-21 20:48 - 2012-07-21 20:48 - 13083592 ____A (Microsoft Corporation) C:\Users\Sheila\Downloads\Silverlight_x64.exe 2012-07-21 13:59 - 2012-07-21 13:59 - 03879808 ____A (AVG Technologies) C:\Users\Sheila\Downloads\avg_isct_stb_all_2012_2197.exe 2012-07-20 18:03 - 2012-07-20 18:03 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2012-07-20 18:03 - 2012-07-20 18:03 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2012-07-20 14:33 - 2012-07-20 14:33 - 00375024 ____A C:\Users\Sheila\Downloads\tws_danceII.rar 2012-07-20 14:30 - 2012-07-20 14:30 - 03421260 ____A C:\Users\Sheila\Downloads\BT_ TEARS TO SERIES_(1)-(4).rar 2012-07-20 13:39 - 2012-07-20 13:39 - 00497811 ____A C:\Users\Sheila\Downloads\acc tea-pot + tea-cup.rar 2012-07-20 13:35 - 2012-07-20 13:35 - 00362424 ____A C:\Users\Sheila\Downloads\tws_m.zip 2012-07-20 13:17 - 2012-07-20 13:17 - 00117650 ____A C:\Users\Sheila\Downloads\addie_man_a.zip 2012-07-20 06:10 - 2012-07-20 06:10 - 00005290 ____A C:\comcastrelease.log 2012-07-20 06:10 - 2012-07-20 06:10 - 00001274 ____A C:\Users\Sheila\Desktop\XFINITY Connect.lnk 2012-07-20 06:10 - 2012-07-20 06:10 - 00001246 ____A C:\Users\Sheila\Desktop\Constant Guard Protection Suite.lnk 2012-07-20 06:10 - 2012-07-20 06:10 - 00001240 ____A C:\Users\Sheila\Desktop\XFINITY TV.lnk 2012-07-20 06:08 - 2012-07-20 06:08 - 00765768 ____A C:\Users\Sheila\Downloads\Comcast_Desktop_Software_1203.exe 2012-07-20 06:02 - 2012-07-20 06:02 - 02896333 ____A C:\Users\Sheila\Downloads\ATS3_objects_downtown_sport.zip 2012-07-19 14:50 - 2012-07-19 14:50 - 16801656 ____A (Mozilla) C:\Users\Sheila\Downloads\Firefox Setup 14.0.1.exe 2012-07-18 22:47 - 2012-07-18 22:47 - 00028772 ____A C:\Users\Sheila\Downloads\MTS_Buzzler_1218064_Buzz_ShellSoundEmitter.zip 2012-07-18 18:43 - 2012-07-18 18:43 - 01100022 ____A C:\Users\Sheila\Downloads\MTS_petallotus_976121_tksshower080209.rar 2012-07-18 18:36 - 2012-07-18 18:36 - 01571864 ____A C:\Users\Sheila\Downloads\MTS_orangemittens_1052170_OM_GlassWalls.rar 2012-07-18 17:37 - 2012-07-18 17:37 - 00068859 ____A C:\Users\Sheila\Downloads\keyblade_onwall_CloudwalkerNZ.rar 2012-07-17 10:28 - 2012-07-17 10:28 - 00137063 ____A C:\Users\Sheila\Downloads\rose_sims3_magic015.rar 2012-07-17 10:28 - 2012-07-17 10:28 - 00055149 ____A C:\Users\Sheila\Downloads\rose_sims3_magic009.rar 2012-07-17 10:27 - 2012-07-17 10:27 - 00149108 ____A C:\Users\Sheila\Downloads\rose_sims3_magic010.rar 2012-07-17 10:27 - 2012-07-17 10:27 - 00140074 ____A C:\Users\Sheila\Downloads\rose_sims3_magic013.rar 2012-07-17 10:27 - 2012-07-17 10:27 - 00094900 ____A C:\Users\Sheila\Downloads\rose_sims3_magic011.rar 2012-07-17 10:25 - 2012-07-17 10:25 - 00472361 ____A C:\Users\Sheila\Downloads\Kunai-Knife-right_cloudwalkerNZ.sims3pack 2012-07-17 10:11 - 2012-07-17 10:11 - 00998119 ____A C:\Users\Sheila\Downloads\PoliceTape.rar 2012-07-16 16:54 - 2012-07-16 16:54 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_ZuneDriver_01_09_00.Wdf 2012-07-16 16:54 - 2012-07-16 16:54 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01009.Wdf 2012-07-16 12:08 - 2012-07-16 12:08 - 00921584 ____A C:\Users\Sheila\Downloads\MTS_melodie9_1011575_tfPregnantTeenClothesNudes.rar 2012-07-16 11:32 - 2011-02-10 11:10 - 00773050 ____A C:\Windows\SysWOW64\PerfStringBackup.INI 2012-07-15 14:49 - 2012-07-15 14:49 - 00003109 ____A C:\Users\Sheila\Downloads\PHTHON_phridge_tuners.zip 2012-07-14 19:18 - 2012-07-14 19:18 - 00001153 ____A C:\Users\Public\Desktop\PrimoPDF - Drop Files Here to Convert!.lnk 2012-07-14 19:18 - 2012-07-14 19:18 - 00001153 ____A C:\Users\All Users\Desktop\PrimoPDF - Drop Files Here to Convert!.lnk 2012-07-14 19:17 - 2011-02-09 23:03 - 00000326 ____A C:\Windows\primopdf.ini 2012-07-12 12:25 - 2012-07-10 12:35 - 00000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job 2012-07-12 09:47 - 2012-07-12 09:47 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2012-07-11 19:45 - 2012-07-11 19:47 - 00447752 ____A (On2.com) C:\Windows\SysWOW64\vp6vfw.dll 2012-07-11 11:17 - 2012-07-11 11:17 - 00000537 ____A C:\Windows\KB893803v2.log 2012-07-10 13:36 - 2009-07-13 21:34 - 00000510 ____A C:\Windows\win.ini 2012-07-10 13:35 - 2012-07-10 13:35 - 00296092 ____A C:\Windows\msxml4-KB973688-enu.LOG 2012-07-10 13:34 - 2012-07-10 13:34 - 00294342 ____A C:\Windows\msxml4-KB954430-enu.LOG 2012-07-08 13:11 - 2012-07-08 13:11 - 00000020 ___SH C:\Users\Lotus\ntuser.ini 2012-07-07 11:51 - 2012-07-07 11:51 - 00560184 ____A (Duplex Secure Ltd.) C:\Windows\System32\Drivers\sptd.sys 2012-07-06 21:20 - 2012-07-06 21:20 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2012-07-06 18:39 - 2012-07-06 16:13 - 00025675 ____A C:\Windows\comsetup.log 2012-07-06 18:38 - 2012-07-06 18:38 - 00033840 ____A C:\Windows\System32\emptyregdb.dat 2012-07-06 02:09 - 2012-03-08 05:03 - 00017980 ____A C:\Windows\RPSETUP.EXE.LOG 2012-07-06 02:06 - 2012-07-06 02:06 - 00000020 ___SH C:\Users\Sheila\ntuser.ini 2012-07-05 21:06 - 2012-07-20 18:03 - 00772544 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2012-07-05 21:06 - 2012-07-20 18:03 - 00227760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2012-07-05 21:06 - 2012-03-08 04:41 - 00687544 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2012-07-03 12:46 - 2012-07-12 11:30 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-07-03 02:19 - 2012-07-10 13:23 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-07-03 02:13 - 2012-07-21 22:10 - 57442464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MRT.exe 2012-06-30 19:01 - 2012-06-30 18:20 - 526160934 ____A C:\Users\Public\Documents\Ultimate_Getting_Started_with_Japanese_Package.zip 2012-06-30 19:01 - 2012-06-30 18:20 - 526160934 ____A C:\Users\All Users\Documents\Ultimate_Getting_Started_with_Japanese_Package.zip 2012-06-25 13:58 - 2012-07-14 19:23 - 00029712 ____A (Nitro PDF Software) C:\Windows\System32\nitrolocalmon2.dll 2012-06-25 13:58 - 2012-07-14 19:23 - 00017936 ____A (Nitro PDF Software) C:\Windows\System32\nitrolocalui2.dll 2012-06-17 22:34 - 2012-06-17 22:34 - 00001492 ____A C:\Users\Lotus\My Documents\Scan.txt 2012-06-17 22:34 - 2012-06-17 22:34 - 00001492 ____A C:\Users\Lotus\Documents\Scan.txt 2012-06-11 22:08 - 2012-07-10 13:42 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-06-11 13:17 - 2012-06-11 13:17 - 00071680 ____A (Beepa P/L) C:\Windows\System32\frapsv64.dll 2012-06-11 13:17 - 2012-06-11 13:17 - 00065536 ____A (Beepa P/L) C:\Windows\SysWOW64\frapsvid.dll 2012-06-09 00:43 - 2012-07-10 10:33 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2012-06-08 23:41 - 2012-07-10 10:33 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2012-06-06 01:06 - 2012-07-10 10:34 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-06-06 01:06 - 2012-07-10 10:34 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll 2012-06-06 01:02 - 2012-07-10 10:32 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll 2012-06-06 00:36 - 2012-06-05 20:12 - 00027788 ____A C:\Users\Sheila\My Documents\Family Contact Sheet.xlsx 2012-06-06 00:36 - 2012-06-05 20:12 - 00027788 ____A C:\Users\Sheila\Documents\Family Contact Sheet.xlsx 2012-06-06 00:05 - 2012-07-10 10:34 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2012-06-06 00:05 - 2012-07-10 10:34 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2012-06-06 00:03 - 2012-07-10 10:32 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2012-06-04 13:03 - 2012-06-04 13:03 - 00106355 ____A C:\Users\Public\Documents\bookmarks.html 2012-06-04 13:03 - 2012-06-04 13:03 - 00106355 ____A C:\Users\All Users\Documents\bookmarks.html 2012-06-02 17:19 - 2012-07-10 10:16 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-02 17:19 - 2012-07-10 10:16 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-02 17:19 - 2012-07-10 10:16 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-02 17:19 - 2012-07-10 10:16 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-02 17:19 - 2012-07-10 10:16 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-02 17:15 - 2012-07-10 10:16 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-02 17:15 - 2012-07-10 10:16 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-02 14:19 - 2012-07-10 10:16 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-02 14:15 - 2012-07-10 10:16 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2012-06-02 07:49 - 2012-07-10 13:15 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-06-02 07:17 - 2012-07-10 13:15 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-06-02 07:12 - 2012-07-10 13:15 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-06-02 07:05 - 2012-07-10 13:15 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-06-02 07:05 - 2012-07-10 13:15 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-06-02 07:04 - 2012-07-10 13:15 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-06-02 07:04 - 2012-07-10 13:15 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-06-02 07:03 - 2012-07-10 13:15 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-06-02 07:01 - 2012-07-10 13:15 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-06-02 07:00 - 2012-07-10 13:15 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-06-02 06:59 - 2012-07-10 13:15 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-06-02 06:57 - 2012-07-10 13:15 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-06-02 06:57 - 2012-07-10 13:15 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-06-02 06:54 - 2012-07-10 13:15 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-06-02 04:07 - 2012-07-10 13:15 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-06-02 03:43 - 2012-07-10 13:15 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-06-02 03:33 - 2012-07-10 13:15 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-06-02 03:26 - 2012-07-10 13:15 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-06-02 03:25 - 2012-07-10 13:15 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-06-02 03:25 - 2012-07-10 13:15 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-06-02 03:23 - 2012-07-10 13:15 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-06-02 03:21 - 2012-07-10 13:15 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-06-02 03:20 - 2012-07-10 13:15 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-06-02 03:19 - 2012-07-10 13:15 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-06-02 03:19 - 2012-07-10 13:15 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-06-02 03:17 - 2012-07-10 13:15 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-06-02 03:16 - 2012-07-10 13:15 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-06-02 03:14 - 2012-07-10 13:15 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-06-02 00:50 - 2012-07-10 10:33 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys 2012-06-02 00:48 - 2012-07-10 10:33 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2012-06-02 00:48 - 2012-07-10 10:33 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2012-06-02 00:45 - 2012-07-10 10:33 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2012-06-02 00:44 - 2012-07-10 10:33 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2012-06-01 23:40 - 2012-07-10 10:33 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2012-06-01 23:40 - 2012-07-10 10:33 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2012-06-01 23:39 - 2012-07-10 10:33 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2012-06-01 23:34 - 2012-07-10 10:33 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2012-05-25 16:13 - 2012-03-08 05:46 - 00162224 ____A (McAfee, Inc.) C:\Windows\System32\mfevtps.exe 2012-05-04 06:06 - 2012-07-10 10:33 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-05-04 06:00 - 2012-07-10 13:08 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll 2012-05-04 05:03 - 2012-07-10 10:33 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2012-05-04 05:03 - 2012-07-10 10:33 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2012-05-04 04:59 - 2012-07-10 13:08 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2012-05-01 00:40 - 2012-07-10 10:33 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll ZeroAccess: C:\Windows\Installer\{7b675962-08f4-8c49-2a97-a008a5ae9e6b} C:\Windows\Installer\{7b675962-08f4-8c49-2a97-a008a5ae9e6b}\@ C:\Windows\Installer\{7b675962-08f4-8c49-2a97-a008a5ae9e6b}\L C:\Windows\Installer\{7b675962-08f4-8c49-2a97-a008a5ae9e6b}\U C:\Windows\Installer\{7b675962-08f4-8c49-2a97-a008a5ae9e6b}\L\00000004.@ C:\Windows\Installer\{7b675962-08f4-8c49-2a97-a008a5ae9e6b}\L\201d3dde ZeroAccess: C:\Users\Sheila\AppData\Local\{7b675962-08f4-8c49-2a97-a008a5ae9e6b} C:\Users\Sheila\AppData\Local\{7b675962-08f4-8c49-2a97-a008a5ae9e6b}\@ C:\Users\Sheila\AppData\Local\{7b675962-08f4-8c49-2a97-a008a5ae9e6b}\L C:\Users\Sheila\AppData\Local\{7b675962-08f4-8c49-2a97-a008a5ae9e6b}\U ZeroAccess: C:\Windows\assembly\GAC_32\Desktop.ini ZeroAccess: C:\Windows\assembly\GAC_64\Desktop.ini ========================= Known DLLs (Whitelisted) ============ ========================= Bamital & volsnap Check ============ C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ========================= Memory info ====================== Percentage of memory in use: 11% Total physical RAM: 6030.99 MB Available physical RAM: 5330.8 MB Total Pagefile: 6029.19 MB Available Pagefile: 5323.8 MB Total Virtual: 8192 MB Available Virtual: 8191.9 MB ======================= Partitions ========================= 1 Drive c: (OS) (Fixed) (Total:446.13 GB) (Free:276.25 GB) NTFS 3 Drive e: (RECOVERY) (Fixed) (Total:19.53 GB) (Free:6.82 GB) NTFS ==>[System with boot components (obtained from reading drive)] 4 Drive f: (LEO) (Removable) (Total:0.99 GB) (Free:0.88 GB) FAT 6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Disk ### Status Size Free Dyn Gpt ——– ————- ——- ——- — — Disk 0 Online 465 GB 2048 KB Disk 1 Online 1011 MB 0 B Disk 2 No Media 0 B 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 OEM 101 MB 31 KB Partition 2 Primary 19 GB 104 MB Partition 3 Primary 446 GB 19 GB ================================================================================ == Disk: 0 Partition 1 Type : DE Hidden: Yes Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 5 FAT Partition 101 MB Healthy Hidden ================================================================================ == Disk: 0 Partition 2 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 E RECOVERY NTFS Partition 19 GB Healthy ================================================================================ == Disk: 0 Partition 3 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 C OS NTFS Partition 446 GB Healthy ================================================================================ == Partitions of Disk 1: =============== Partition ### Type Size Offset ————- —————- ——- ——- * Partition 1 Primary 1011 MB 0 B ================================================================================ == Disk: 1 There is no partition selected. There is no partition selected. Please select a partition and try again. ================================================================================ == ========================================================== Last Boot: 2012-07-28 02:21 ======================= End Of Log ==========================
Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt

C:\Windows\Installer\{7b675962-08f4-8c49-2a97-a008a5ae9e6b}
C:\Users\Sheila\AppData\Local\{7b675962-08f4-8c49-2a97-a008a5ae9e6b}
C:\Windows\assembly\GAC_32\Desktop.ini
C:\Windows\assembly\GAC_64\Desktop.ini

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.

Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.
Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 25-07-2012 01 Ran by [removed] at 2012-07-29 23:33:14 Run:1 Running from F:\ ============================================== C:\Windows\Installer\{7b675962-08f4-8c49-2a97-a008a5ae9e6b} moved successfully. C:\Users\Sheila\AppData\Local\{7b675962-08f4-8c49-2a97-a008a5ae9e6b} moved successfully. C:\Windows\assembly\GAC_32\Desktop.ini moved successfully. C:\Windows\assembly\GAC_64\Desktop.ini moved successfully. ==== End of Fixlog ====
Still had Had to post from my cousin's com still. Mine said that Mozilla was marked for deletion. It said the same when I tried to use explorer. ComboFix 12-07-27.03 - Sheila 07/29/2012 23:58:25.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6031.4296 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe c:\programdata\552B474E.ini c:\programdata\PCDr\5907\Downloads\246b20c1-8ea9-4148-a34e-d03c8a1d5a76.dll c:\programdata\PCDr\5907\Downloads\27e5bc9a-105f-4d7f-8352-e6ef1c8933dd.dll c:\programdata\PCDr\5907\Downloads\a2192d8a-3d73-4ff7-be9b-02134f41db63.dll c:\programdata\Roaming c:\users\Sheila\Documents\~WRL0005.tmp c:\windows\RPSETUP.EXE.LOG . . ((((((((((((((((((((((((( Files Created from 2012-06-28 to 2012-07-30 ))))))))))))))))))))))))))))))) . . 2012-07-25 03:55 . 2012-07-25 03:55 ——– d-sh–w- c:\windows\SysWow64\%APPDATA% 2012-07-25 02:40 . 2012-07-25 02:40 ——– d—–w- c:\programdata\FLEXnet 2012-07-23 01:40 . 2012-07-23 01:40 ——– d—–w- c:\program files\s3pe 2012-07-22 22:58 . 2012-07-22 22:58 ——– d—–w- c:\program files (x86)\Common Files\Control Panels 2012-07-22 22:55 . 2012-07-22 22:55 ——– d—–w- c:\programdata\ALM 2012-07-22 22:53 . 2007-02-20 20:04 190696 —-a-w- c:\windows\SysWow64\NPSWF32_FlashUtil.exe 2012-07-22 22:53 . 2007-02-20 20:04 2463976 —-a-w- c:\windows\SysWow64\NPSWF32.dll 2012-07-22 22:49 . 2012-07-22 22:49 ——– d—–w- c:\windows\SysWow64\spool 2012-07-22 22:48 . 2012-07-22 22:48 ——– d—–w- c:\program files (x86)\Bonjour 2012-07-22 12:42 . 2012-07-22 12:42 ——– d—–w- c:\program files\Blender Foundation 2012-07-22 12:32 . 2012-07-29 17:15 ——– d—–w- c:\program files (x86)\MilkShape 3D 1.8.5 2012-07-22 01:57 . 2012-07-22 01:57 ——– d—–w- c:\program files\Microsoft Silverlight 2012-07-20 23:06 . 2012-07-20 23:06 ——– d—–w- c:\program files (x86)\Oracle 2012-07-20 23:03 . 2012-07-06 02:06 772544 —-a-w- c:\windows\SysWow64\npDeployJava1.dll 2012-07-20 18:01 . 2012-07-20 18:01 ——– d—–w- c:\windows\Sun 2012-07-19 20:28 . 2012-05-25 21:09 29312 —-a-w- c:\program files (x86)\Mozilla Firefox\ScriptFF.dll 2012-07-19 19:52 . 2012-07-19 19:52 ——– d—–w- c:\program files (x86)\Mozilla Maintenance Service 2012-07-19 19:52 . 2012-07-14 00:17 136672 —-a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll 2012-07-19 00:23 . 2012-07-19 00:23 ——– d—–w- c:\program files (x86)\Bandicam 2012-07-19 00:23 . 2012-07-19 00:23 ——– d—–w- c:\program files (x86)\BandiMPEG1 2012-07-16 15:08 . 2012-07-16 15:08 ——– d—–w- c:\program files (x86)\Notepad++ 2012-07-15 00:49 . 2012-07-15 00:49 ——– d—–w- c:\program files\7-Zip 2012-07-15 00:23 . 2012-06-25 18:58 17936 —-a-w- c:\windows\system32\nitrolocalui2.dll 2012-07-15 00:23 . 2012-06-25 18:58 29712 —-a-w- c:\windows\system32\nitrolocalmon2.dll 2012-07-15 00:22 . 2012-07-15 00:22 ——– d—–w- c:\program files\Common Files\Nitro PDF 2012-07-15 00:22 . 2012-07-15 00:22 ——– d—–w- c:\program files (x86)\Common Files\Nitro PDF 2012-07-15 00:19 . 2012-07-15 00:19 ——– d—–w- c:\programdata\Nitro PDF 2012-07-15 00:18 . 2011-02-28 22:37 95008 —-a-w- c:\windows\system32\Primomonnt.dll 2012-07-13 00:24 . 2012-07-13 00:24 ——– d—–w- c:\windows\SysWow64\Wat 2012-07-13 00:24 . 2012-07-13 00:24 ——– d—–w- c:\windows\system32\Wat 2012-07-12 21:23 . 2012-07-12 21:23 ——– d—–w- c:\programdata\regid.1986-12.com.adobe 2012-07-12 19:59 . 2012-07-12 19:59 ——– d—–w- c:\program files (x86)\Adobe Story 2012-07-12 19:58 . 2012-07-12 19:58 ——– d—–w- c:\program files (x86)\My Company Name 2012-07-12 16:30 . 2012-07-03 17:46 24904 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-07-12 01:42 . 2012-07-12 01:42 ——– d—–w- c:\programdata\EA Core 2012-07-12 00:47 . 2012-07-12 00:45 447752 —-a-w- c:\windows\SysWow64\vp6vfw.dll 2012-07-12 00:46 . 2012-07-12 00:46 ——– d—–w- c:\program files (x86)\Microsoft WSE 2012-07-11 16:18 . 2012-07-12 08:18 ——– d—–w- c:\program files (x86)\Origin Games 2012-07-11 16:18 . 2012-07-13 01:01 ——– d—–w- c:\programdata\Origin 2012-07-11 16:17 . 2012-07-11 16:17 ——– d—–w- c:\programdata\Electronic Arts 2012-07-11 16:17 . 2012-07-11 16:18 ——– d—–w- c:\program files (x86)\Origin 2012-07-11 15:36 . 2012-07-11 15:36 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2012-07-11 15:36 . 2012-07-11 15:36 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2012-07-11 15:36 . 2012-07-11 15:36 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2012-07-11 15:36 . 2012-07-11 15:36 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2012-07-11 15:36 . 2012-07-11 15:36 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2012-07-11 15:36 . 2012-07-11 15:36 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2012-07-11 15:36 . 2012-07-11 15:36 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2012-07-11 15:36 . 2012-07-11 15:36 ——– d—–w- c:\program files (x86)\QuickTime 2012-07-11 15:36 . 2012-07-11 15:36 ——– d—–w- c:\programdata\Apple Computer 2012-07-11 15:35 . 2012-07-11 15:35 ——– d—–w- c:\program files (x86)\Apple Software Update 2012-07-11 15:35 . 2012-07-11 15:35 ——– d—–w- c:\programdata\Apple 2012-07-11 15:26 . 2012-07-25 03:46 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-11 14:21 . 2012-07-11 14:21 ——– d—–w- c:\program files (x86)\Amazon 2012-07-11 14:02 . 2012-07-11 14:02 ——– d—–w- c:\program files (x86)\Common Files\Skype 2012-07-11 13:44 . 2012-07-11 13:44 ——– d—–w- c:\program files (x86)\PeaZip 2012-07-10 18:42 . 2012-06-12 03:08 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-07-10 18:34 . 2012-07-10 18:34 ——– d—–w- c:\program files (x86)\MSXML 4.0 2012-07-10 18:23 . 2012-07-03 07:19 59701280 —-a-w- c:\windows\system32\MRT.exe 2012-07-10 18:08 . 2012-05-04 11:00 366592 —-a-w- c:\windows\system32\qdvd.dll 2012-07-10 18:08 . 2012-05-04 09:59 514560 —-a-w- c:\windows\SysWow64\qdvd.dll 2012-07-10 17:35 . 2012-07-10 17:35 ——– d—–w- c:\program files\Dell Support Center 2012-07-10 15:33 . 2011-03-12 12:08 1465344 —-a-w- c:\windows\system32\XpsPrint.dll 2012-07-10 15:32 . 2011-12-16 08:46 634880 —-a-w- c:\windows\system32\msvcrt.dll 2012-07-10 15:21 . 2012-02-17 06:38 1031680 —-a-w- c:\windows\system32\rdpcore.dll 2012-07-10 15:21 . 2012-02-17 05:34 826880 —-a-w- c:\windows\SysWow64\rdpcore.dll 2012-07-10 15:21 . 2012-02-17 04:57 23552 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-07-10 15:16 . 2012-06-02 22:19 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-07-10 15:16 . 2012-06-02 22:19 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-07-10 15:16 . 2012-06-02 22:19 44056 —-a-w- c:\windows\system32\wups2.dll 2012-07-10 15:16 . 2012-06-02 22:15 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-07-10 15:16 . 2012-06-02 22:19 38424 —-a-w- c:\windows\system32\wups.dll 2012-07-10 15:16 . 2012-06-02 22:19 701976 —-a-w- c:\windows\system32\wuapi.dll 2012-07-10 15:16 . 2012-06-02 22:15 99840 —-a-w- c:\windows\system32\wudriver.dll 2012-07-10 15:16 . 2012-06-02 19:19 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-07-10 15:16 . 2012-06-02 19:15 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-07-07 21:28 . 2012-07-07 21:28 ——– d—–w- c:\program files (x86)\Microsoft Synchronization Services 2012-07-07 21:27 . 2012-07-07 21:27 ——– d—–w- c:\program files (x86)\Microsoft Sync Framework 2012-07-07 21:26 . 2012-07-07 21:26 ——– d—–w- c:\program files (x86)\Microsoft Visual Studio 8 2012-07-07 21:26 . 2012-07-07 21:26 ——– d—–w- c:\program files\Microsoft Office 2012-07-07 21:26 . 2012-07-07 21:26 ——– d—–w- c:\program files (x86)\Microsoft Analysis Services 2012-07-07 21:25 . 2012-07-10 18:43 ——– d—–w- c:\programdata\Microsoft Help 2012-07-07 21:25 . 2012-07-07 21:25 ——– d—–r- C:\MSOCache 2012-07-07 16:51 . 2012-07-07 16:51 560184 —-a-w- c:\windows\system32\drivers\sptd.sys 2012-07-07 16:50 . 2012-07-07 16:51 ——– d—–w- c:\program files (x86)\DAEMON Tools Lite 2012-07-07 16:10 . 2012-07-07 21:15 ——– d—–w- c:\programdata\DAEMON Tools Lite 2012-07-07 02:18 . 2012-07-07 02:18 ——– d—–w- c:\programdata\Malwarebytes 2012-07-07 02:14 . 2012-07-07 02:14 ——– d—–w- c:\program files\Pictus 2012-07-07 00:42 . 2012-07-07 00:42 ——– d—–w- c:\program files (x86)\Adobe Reader 64-bit fixes 2012-07-07 00:00 . 2012-07-07 00:00 ——– d—–w- c:\programdata\PCDr 2012-07-06 21:13 . 2012-07-08 18:11 ——– d—–w- c:\users\Lotus 2012-07-06 07:06 . 2012-07-28 20:54 ——– d—–w- c:\users\Sheila 2012-07-06 06:04 . 2012-07-06 06:36 ——– d—–w- c:\windows\SMINST . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-25 03:46 . 2012-03-08 09:21 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-07-10 16:45 . 2010-06-24 17:33 19736 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2012-07-06 02:06 . 2012-03-08 09:41 687544 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-06-11 18:17 . 2012-06-11 18:17 71680 —-a-w- c:\windows\system32\frapsv64.dll 2012-06-11 18:17 . 2012-06-11 18:17 65536 —-a-w- c:\windows\SysWow64\frapsvid.dll 2012-05-25 21:13 . 2012-03-08 10:46 162224 —-a-w- c:\windows\system32\mfevtps.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2011-04-13 503942] "Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528] "RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112] "Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1675160] "NeroLauncher"="c:\program files (x86)\Nero\SyncUP\NeroLauncher.exe" [2011-12-31 66872] "AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2011-11-03 957440] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296] . c:\users\Sheila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer3"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 DellDigitalDelivery;Dell Digital Delivery Service;c:\program files (x86)\Dell Digital Delivery\DeliveryService.exe [2011-10-26 162816] R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-03 160944] R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2011-10-19 195072] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-06-07 191752] R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-10-18 1354064] R3 CxUtilSvc;CxUtilSvc;c:\program files\Conexant\SA3\CxUtilSvc.exe [2011-08-12 109184] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-02-27 158976] R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-05-17 34200] R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2011-03-08 224704] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-02-22 100912] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-14 113120] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-11-01 340240] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-12-02 250984] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-07-13 1255736] R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 249936] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-02-22 289664] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856] S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [2010-08-20 21616] S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2012-02-22 75936] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928] S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-10-19 661504] S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-05-12 249648] S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-10-18 936272] S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-10-18 1001808] S2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-10-21 135440] S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe [2011-05-12 200320] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944] S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-28 249936] S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 249936] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-05-25 210616] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-05-25 162224] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400] S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2012-06-25 216080] S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-09-22 1692480] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-12-21 2656280] S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [2010-12-13 27760] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-10-19 195072] S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [2011-08-29 53760] S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-11-15 327168] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-02-22 65264] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2011-01-20 176096] S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2011-12-09 60416] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440] S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-05-17 25496] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2011-03-23 77936] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904] S3 MCfilt;MCfilt;c:\windows\system32\drivers\MCfilt64.sys [2010-12-09 32344] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-02-22 487296] S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2011-12-02 8615936] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-09-14 95744] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-09-14 212992] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] . . — Other Services/Drivers In Memory — . *Deregistered* - mfeavfk01 . Contents of the 'Scheduled Tasks' folder . 2012-07-12 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job - c:\program files\Dell Support Center\uaclauncher.exe [2012-05-22 07:16] . 2012-07-30 c:\windows\Tasks\SystemToolsDailyTest.job - c:\program files\Dell Support Center\uaclauncher.exe [2012-05-22 07:16] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-06-01 168216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-06-01 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-06-01 416024] "SmartAudio"="c:\program files\CONEXANT\SA3\SACpl.exe" [2011-08-01 1574016] "FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-11-01 1935120] "BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-10-18 10357008] "QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2011-03-11 4500640] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608] "DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-11-03 2190704] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://xfinity.comcast.net/?cid=insDate07202012 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Download with &Media Finder - c:\program files (x86)\Media Finder\hook.html IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 FF - ProfilePath - c:\users\Sheila\AppData\Roaming\Mozilla\Firefox\Profiles\rdj6rf1t.default\ FF - prefs.js: browser.search.selectedEngine - XFINITY FF - prefs.js: browser.startup.homepage - www.google.com . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-Media Finder - c:\program files (x86)\Media Finder\Media Finder.exe Wow6432Node-HKLM-Run-UnlockerAssistant - c:\program files (x86)\Unlocker\UnlockerAssistant.exe Toolbar-Locked - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-WT089446 - c:\program files (x86)\WildTangent\Dell Games\Wedding Dash - Ready . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-2450799959-646583983-317965361-1000\Software\SecuROM\License information*] "datasecu"=hex:a7,e2,39,a5,10,e6,57,14,93,e1,fe,02,76,71,9c,c2,02,2b,67,26,46, 2e,c8,9f,80,17,e7,5d,ec,6d,6d,3f,8f,80,57,d1,6f,e7,4f,64,dd,fd,ae,17,63,25,\ "rkeysecu"=hex:6c,89,26,1e,ba,8e,8d,cc,46,64,d9,c2,1d,f8,13,71 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Dell DataSafe Local Backup\TOASTER.EXE c:\program files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe . ************************************************************************** . Completion time: 2012-07-30 00:18:30 - machine was rebooted ComboFix-quarantined-files.txt 2012-07-30 04:18 . Pre-Run: 297,533,530,112 bytes free Post-Run: 295,935,655,936 bytes free . - - End Of File - - 93EFDC77A0BFB53C010F36027551A6D8

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI