Ran by SYSTEM at 26-08-2012 14:45:42
Running from E:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-06-18] (IDT, Inc.)
HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1928976 2010-03-05] (Intel® Corporation)
HKLM\...\Run: [DellStage] "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" --startup [207350 2011-01-25] ()
HKLM\...\Run: [HP LaserJet Professional CM1410 Series Fax] C:\Program Files\HP\HP LaserJet Professional CM1410 Series\Fax Driver\hppfaxprintersrv.exe "HP LaserJet Professional CM1410 Series Fax" [3707704 2010-04-09] (Hewlett-Packard Company)
HKLM\...\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe" [163552 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [PrintDisp] C:\Windows\system32\PrintDisp.exe [878080 2009-08-21] (ActMask Co.,Ltd - http://www.all2pdf.com)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284696 2010-06-08] (Intel Corporation)
HKLM-x32\...\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [409744 2009-06-24] (Creative Technology Ltd)
HKLM-x32\...\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe /boot [4144448 2010-11-10] (Dell, Inc.)
HKLM-x32\...\Run: [RoxWatchTray] "c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [514544 2010-11-17] ()
HKLM-x32\...\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-25] (Dell, Inc.)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [ToolboxFX] "C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on [58936 2010-04-16] (Hewlett-Packard Company)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\Marissa\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-06-07] (Google Inc.)
HKU\Marissa\...\Run: [ooVoo.exe] C:\Program Files (x86)\ooVoo\oovoo.exe /minimized [22631608 2011-05-18] (ooVoo LLC)
HKU\Marissa\...\Run: [Facebook Update] "C:\Users\Marissa\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-11] (Facebook Inc.)
HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [559616 2011-10-11] (Dell)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{20A38C2B-4AD4-4C9D-B912-36D8FD3A644A}: [NameServer]198.153.192.50,198.153.194.50
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Marissa\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ======
3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-03-05] ()
2 N360; "C:\Program Files (x86)\Norton 360\Norton 360\Engine\6.3.0.14\ccSvcHst.exe" /s "N360" /m "C:\Program Files (x86)\Norton 360\Norton 360\Engine\6.3.0.14\diMaster.dll" /prefetch:1 [309688 2012-04-12] (Symantec Corporation)
2 NAT; "C:\Program Files (x86)\Norton Anti-Theft\Engine\1.5.0.36\ccSvcHst.exe" /s "NAT" /m "C:\Program Files (x86)\Norton Anti-Theft\Engine\1.5.0.36\diMaster.dll" /prefetch:1 [309688 2012-04-12] (Symantec Corporation)
2 NSL; "C:\Program Files (x86)\Norton Safe Web Lite\Engine\2.0.0.16\ccSvcHst.exe" /s "NSL" /m "C:\Program Files (x86)\Norton Safe Web Lite\Engine\2.0.0.16\diMaster.dll" /prefetch:1 [303544 2011-10-11] (Symantec Corporation)
2 Printer Control; C:\Windows\system32\PrintCtrl.exe [77824 2009-06-16] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
3 stllssvr; "C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe" [74392 2010-11-08] (MicroVision Development, Inc.)
2 UNS; "C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe" [2320920 2010-03-03] (Intel Corporation)
==================== Drivers (Whitelisted) ===================
1 BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\Definitions\BASHDefs\20120803.001\BHDrvx64.sys [1161376 2012-06-18] (Symantec Corporation)
1 ccSet_N360; C:\Windows\system32\drivers\N360x64\0603000.00E\ccSetx64.sys [167072 2012-06-06] (Symantec Corporation)
1 ccSet_NAT; C:\Windows\system32\drivers\NATx64\0105000.024\ccSetx64.sys [167048 2011-11-04] (Symantec Corporation)
1 ccSet_NST; C:\Windows\system32\drivers\NSTx64\0200000.010\ccSetx64.sys [167048 2011-08-08] (Symantec Corporation)
1 IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\Definitions\IPSDefs\20120824.001\IDSvia64.sys [512672 2012-08-24] (Symantec Corporation)
3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\Definitions\VirusDefs\20120825.007\ENG64.SYS [125600 2012-08-25] (Symantec Corporation)
3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\Definitions\VirusDefs\20120825.007\EX64.SYS [2084000 2012-08-25] (Symantec Corporation)
3 Razerlow; C:\Windows\System32\drivers\DB3G.sys [21120 2005-11-07] (Razer (Asia-Pacific) Pte Ltd)
3 SRTSP; C:\Windows\system32\drivers\N360x64\0603000.00E\SRTSP64.SYS [737952 2012-07-05] (Symantec Corporation)
1 SRTSPX; C:\Windows\system32\drivers\N360x64\0603000.00E\SRTSPX64.SYS [37536 2012-07-05] (Symantec Corporation)
0 SymDS; C:\Windows\System32\drivers\N360x64\0603000.00E\SYMDS64.SYS [451192 2012-04-17] (Symantec Corporation)
0 SymEFA; C:\Windows\System32\drivers\N360x64\0603000.00E\SYMEFA64.SYS [1129120 2012-05-21] (Symantec Corporation)
3 SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [175736 2012-08-26] (Symantec Corporation)
1 SymIRON; C:\Windows\system32\drivers\N360x64\0603000.00E\Ironx64.SYS [190072 2012-04-17] (Symantec Corporation)
1 SymNetS; C:\Windows\system32\drivers\N360x64\0603000.00E\SYMNETS.SYS [405624 2012-04-17] (Symantec Corporation)
2 TurboB; C:\Windows\System32\Drivers\TurboB.sys [13784 2009-11-02] ()
3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) =================
==================== One Month Created Files and Folders ======================
2012-08-26 08:04 - 2012-08-26 08:04 - 00000000 ____D C:\Users\Marissa\My Documents\Symantec
2012-08-26 08:04 - 2012-08-26 08:04 - 00000000 ____D C:\Users\Marissa\Documents\Symantec
2012-08-26 08:03 - 2012-08-26 08:03 - 00175736 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS
2012-08-26 08:03 - 2012-08-26 08:03 - 00007488 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT
2012-08-26 08:03 - 2012-08-26 08:03 - 00002573 ____A C:\Users\Public\Desktop\Norton 360.lnk
2012-08-26 08:03 - 2012-08-26 08:03 - 00002573 ____A C:\Users\All Users\Desktop\Norton 360.lnk
2012-08-26 08:03 - 2012-08-26 08:03 - 00000000 ____D C:\Program Files\Symantec
2012-08-26 07:47 - 2012-08-26 07:47 - 00920096 ____A C:\Users\Marissa\Desktop\Norton_Removal_Tool.exe
2012-08-26 02:06 - 2012-07-06 15:07 - 00552960 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bthport.sys
2012-08-26 02:05 - 2012-06-28 22:49 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-26 02:05 - 2012-06-28 22:47 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-26 02:05 - 2012-06-28 22:42 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-26 02:05 - 2012-06-28 22:40 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-26 02:05 - 2012-06-28 22:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-26 02:05 - 2012-06-28 19:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-08-26 02:05 - 2012-06-28 19:07 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-08-26 02:05 - 2012-06-28 19:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-08-26 02:05 - 2012-06-28 19:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-08-26 02:05 - 2012-06-28 19:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-08-26 02:04 - 2012-06-28 23:55 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-26 02:04 - 2012-06-28 23:09 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-26 02:04 - 2012-06-28 22:56 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-08-26 02:04 - 2012-06-28 22:49 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-26 02:04 - 2012-06-28 22:48 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-26 02:04 - 2012-06-28 22:45 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-26 02:04 - 2012-06-28 22:44 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-26 02:04 - 2012-06-28 22:43 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-26 02:04 - 2012-06-28 22:35 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-26 02:04 - 2012-06-28 19:52 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-08-26 02:04 - 2012-06-28 19:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-08-26 02:04 - 2012-06-28 19:16 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-08-26 02:04 - 2012-06-28 19:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-08-26 02:04 - 2012-06-28 19:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-08-26 02:04 - 2012-06-28 19:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-08-26 02:04 - 2012-06-28 19:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-08-26 02:04 - 2012-06-28 19:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-08-26 02:04 - 2012-06-28 18:57 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-08-25 13:30 - 2012-07-18 13:15 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-08-25 13:30 - 2012-07-04 17:16 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-08-25 13:30 - 2012-07-04 17:13 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-08-25 13:30 - 2012-07-04 17:13 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-08-25 13:30 - 2012-07-04 16:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-08-25 13:30 - 2012-07-04 16:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2012-08-25 13:30 - 2012-05-14 00:26 - 00956928 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2012-08-25 13:30 - 2012-05-05 03:36 - 00503808 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll
2012-08-25 13:30 - 2012-05-05 02:46 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2012-08-25 13:30 - 2012-02-11 01:43 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2012-08-25 13:30 - 2012-02-11 01:36 - 00559104 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe
2012-08-25 13:30 - 2012-02-11 01:36 - 00067072 ____A (Microsoft Corporation) C:\Windows\splwow64.exe
2012-08-25 13:30 - 2012-02-11 00:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2012-08-25 11:43 - 2012-08-25 11:43 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-08-25 09:22 - 2012-08-25 09:22 - 00000000 ____D C:\Users\Marissa\Desktop\tdsskiller
2012-08-25 09:11 - 2009-07-13 20:14 - 00020480 ____A (Microsoft Corporation) C:\Windows\svchost.exe
2012-08-25 08:51 - 2012-08-25 08:51 - 00262144 ____A C:\Windows\Minidump\082512-53040-01.dmp
2012-08-24 19:53 - 2012-08-24 19:53 - 00082548 ____A C:\Users\Marissa\Desktop\Extras.Txt
2012-08-24 19:33 - 2012-08-24 19:33 - 00006288 ____A C:\Users\Marissa\Desktop\BITS.reg
2012-08-24 19:02 - 2012-08-24 19:03 - 00000000 ____D C:\Users\Marissa\Desktop\nortonpowereraserwebsite
2012-08-24 18:59 - 2012-08-24 19:00 - 02892816 ____A (Symantec Corporation) C:\Users\Marissa\Downloads\NPE (1).exe
2012-08-24 18:37 - 2012-08-25 09:27 - 00002458 ____A C:\Users\Marissa\Desktop\FSS.txt
2012-08-24 18:36 - 2012-08-24 18:36 - 00693235 ____A (Farbar) C:\Users\Marissa\Desktop\FSS.exe
2012-08-24 18:12 - 2012-08-24 18:12 - 00030583 ____A C:\ComboFix.txt
2012-08-24 17:34 - 2012-08-24 18:12 - 00000000 ____D C:\Qoobox
2012-08-24 17:34 - 2011-06-26 01:45 - 00256000 ____A C:\Windows\PEV.exe
2012-08-24 17:34 - 2010-11-07 12:20 - 00208896 ____A C:\Windows\MBR.exe
2012-08-24 17:34 - 2009-04-19 23:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-08-24 17:34 - 2000-08-30 19:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-08-24 17:34 - 2000-08-30 19:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-08-24 17:34 - 2000-08-30 19:00 - 00098816 ____A C:\Windows\sed.exe
2012-08-24 17:34 - 2000-08-30 19:00 - 00080412 ____A C:\Windows\grep.exe
2012-08-24 17:34 - 2000-08-30 19:00 - 00068096 ____A C:\Windows\zip.exe
2012-08-24 17:33 - 2012-08-24 18:04 - 00000000 ____D C:\Windows\erdnt
2012-08-24 17:33 - 2012-08-24 17:33 - 04737458 ____R (Swearware) C:\Users\Marissa\Desktop\ComboFix.exe
2012-08-24 16:07 - 2012-08-24 16:07 - 00000000 ____D C:\_OTL
2012-08-24 16:05 - 2012-08-24 16:05 - 04731392 ____A (AVAST Software) C:\Users\Marissa\Desktop\aswMBR.exe
2012-08-24 16:05 - 2012-08-24 16:05 - 00596480 ____A (OldTimer Tools) C:\Users\Marissa\Desktop\OTL.exe
2012-08-24 12:55 - 2012-08-24 12:55 - 00266288 ____A C:\Windows\Minidump\082412-41667-01.dmp
2012-08-24 09:47 - 2012-08-24 09:47 - 00262144 ____A C:\Windows\Minidump\082412-50747-01.dmp
2012-08-24 09:27 - 2012-08-24 09:27 - 00728096 ____A C:\Windows\Minidump\082412-37845-01.dmp
2012-08-24 07:00 - 2012-08-24 07:00 - 00001785 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-08-24 07:00 - 2012-08-24 07:00 - 00001785 ____A C:\Users\All Users\Desktop\iTunes.lnk
2012-08-24 06:59 - 2012-08-24 06:59 - 00000000 ____D C:\Program Files\iTunes
2012-08-24 06:59 - 2012-08-24 06:59 - 00000000 ____D C:\Program Files\iPod
2012-08-24 06:59 - 2012-08-24 06:59 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-08-24 06:55 - 2012-08-24 06:55 - 00001847 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-08-24 06:55 - 2012-08-24 06:55 - 00001847 ____A C:\Users\All Users\Desktop\QuickTime Player.lnk
2012-08-24 06:55 - 2012-08-24 06:55 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-08-22 09:37 - 2012-08-25 12:37 - 00003690 ____A C:\Users\Marissa\Desktop\aswMBR.txt
2012-08-22 09:37 - 2012-08-25 12:37 - 00000512 ____A C:\Users\Marissa\Desktop\MBR.dat
2012-08-22 09:29 - 2012-08-22 09:29 - 00070560 ____A C:\Users\Marissa\Downloads\Extras.Txt
2012-08-22 09:27 - 2012-08-26 08:14 - 00121322 ____A C:\Users\Marissa\Desktop\OTL.Txt
2012-08-11 14:19 - 2012-08-11 14:19 - 00809840 ____A (AirInstaller Inc.) C:\Users\Marissa\Downloads\setup.exe
2012-08-07 19:52 - 2012-08-07 19:52 - 00728048 ____A C:\Windows\Minidump\080712-24804-01.dmp
2012-08-06 16:26 - 2012-08-06 16:26 - 00001908 ____A C:\Windows\diagwrn.xml
2012-08-06 16:26 - 2012-08-06 16:26 - 00001908 ____A C:\Windows\diagerr.xml
2012-08-06 16:23 - 2012-08-06 16:23 - 00262144 ____A C:\Windows\Minidump\080612-29000-01.dmp
2012-08-05 20:10 - 2012-08-05 20:10 - 00000000 ____D C:\Windows\Sun
2012-08-05 17:02 - 2012-08-05 17:02 - 00262144 ____A C:\Windows\Minidump\080512-34055-01.dmp
2012-08-05 16:34 - 2012-08-05 16:34 - 00002143 ____A C:\Users\Marissa\Desktop\repair your computer.txt
2012-08-05 15:24 - 2012-08-05 15:24 - 00371097 ____A C:\Users\Marissa\Downloads\Base Filtering Engine.reg
2012-08-05 15:03 - 2012-08-05 15:03 - 00002450 ____A C:\Users\Public\Desktop\Norton Anti-Theft.lnk
2012-08-05 15:03 - 2012-08-05 15:03 - 00002450 ____A C:\Users\All Users\Desktop\Norton Anti-Theft.lnk
2012-08-05 15:03 - 2012-08-05 15:03 - 00000000 ____D C:\Windows\System32\Drivers\NATx64
2012-08-05 15:03 - 2012-08-05 15:03 - 00000000 ____D C:\Program Files (x86)\Norton Anti-Theft
2012-08-05 14:55 - 2012-08-05 14:55 - 00828736 ____A (Symantec Corporation) C:\Users\Marissa\Downloads\NortonAnti-TheftDownloader.exe
2012-08-05 14:17 - 2012-08-05 14:17 - 00000000 ____D C:\N360_BACKUP
2012-08-05 14:05 - 2012-08-05 14:05 - 00000000 ____D C:\Windows\SysWOW64\N360_BACKUP
2012-08-04 22:43 - 2012-08-04 22:43 - 00262144 ____A C:\Windows\Minidump\080412-29203-01.dmp
2012-08-04 22:11 - 2012-08-04 22:11 - 02841104 ____A (Symantec Corporation) C:\Users\Marissa\Downloads\NPE.exe
2012-08-04 21:24 - 2012-08-24 19:20 - 00000000 ____D C:\Users\Marissa\Local Settings\NPE
2012-08-04 21:24 - 2012-08-24 19:20 - 00000000 ____D C:\Users\Marissa\Local Settings\Application Data\NPE
2012-08-04 21:24 - 2012-08-24 19:20 - 00000000 ____D C:\Users\Marissa\AppData\Local\NPE
2012-08-04 21:05 - 2012-08-26 08:03 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2012-08-04 21:05 - 2012-08-26 08:02 - 00000000 ____D C:\Windows\System32\Drivers\N360x64
2012-08-04 21:05 - 2012-08-26 08:02 - 00000000 ____D C:\Program Files (x86)\Norton 360
2012-08-04 20:53 - 2012-08-26 08:01 - 00001300 ____A C:\Users\Marissa\Desktop\Norton Installation Files.lnk
2012-08-04 20:53 - 2012-08-26 08:01 - 00000000 ____D C:\Users\Public\Downloads\Norton
2012-08-04 20:23 - 2012-08-05 16:20 - 00000000 ____D C:\Users\Marissa\Local Settings\LogMeIn Rescue Applet
2012-08-04 20:23 - 2012-08-05 16:20 - 00000000 ____D C:\Users\Marissa\Local Settings\Application Data\LogMeIn Rescue Applet
2012-08-04 20:23 - 2012-08-05 16:20 - 00000000 ____D C:\Users\Marissa\AppData\Local\LogMeIn Rescue Applet
2012-08-04 20:20 - 2012-08-04 20:20 - 01187504 ____A (LogMeIn, Inc.) C:\Users\Marissa\Downloads\Support-LogMeInRescue.exe
2012-08-04 19:38 - 2012-08-04 19:38 - 00000000 ____D C:\Windows\System32\Drivers\NSTx64
2012-08-04 19:38 - 2012-08-04 19:38 - 00000000 ____D C:\Program Files (x86)\Norton Safe Web Lite
2012-08-03 15:07 - 2012-08-03 15:07 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-07-29 20:08 - 2012-07-29 20:08 - 00262144 ____A C:\Windows\Minidump\072912-22682-01.dmp
==================== 3 Months Modified Files ================================
2012-08-26 13:39 - 2011-03-28 04:25 - 01624336 ____A C:\Windows\WindowsUpdate.log
2012-08-26 13:37 - 2009-07-14 00:13 - 00727334 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-26 13:35 - 2012-04-26 20:24 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-26 13:35 - 2011-08-23 21:32 - 00000936 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-957519283-3269216495-3174932433-1001UA.job
2012-08-26 13:35 - 2011-06-07 14:42 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-26 13:35 - 2009-07-13 23:51 - 00003076 ____A C:\Windows\setupact.log
2012-08-26 08:14 - 2012-08-22 09:27 - 00121322 ____A C:\Users\Marissa\Desktop\OTL.Txt
2012-08-26 08:03 - 2012-08-26 08:03 - 00175736 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS
2012-08-26 08:03 - 2012-08-26 08:03 - 00007488 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT
2012-08-26 08:03 - 2012-08-26 08:03 - 00002573 ____A C:\Users\Public\Desktop\Norton 360.lnk
2012-08-26 08:03 - 2012-08-26 08:03 - 00002573 ____A C:\Users\All Users\Desktop\Norton 360.lnk
2012-08-26 08:02 - 2009-07-13 23:45 - 00013872 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-26 08:02 - 2009-07-13 23:45 - 00013872 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-26 08:01 - 2012-08-04 20:53 - 00001300 ____A C:\Users\Marissa\Desktop\Norton Installation Files.lnk
2012-08-26 07:55 - 2011-06-07 14:42 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-26 07:54 - 2011-03-28 04:46 - 00086226 ____A C:\Windows\PFRO.log
2012-08-26 07:54 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-26 07:47 - 2012-08-26 07:47 - 00920096 ____A C:\Users\Marissa\Desktop\Norton_Removal_Tool.exe
2012-08-26 02:23 - 2009-07-13 23:45 - 00463600 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-26 02:10 - 2011-08-23 21:32 - 00000914 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-957519283-3269216495-3174932433-1001Core.job
2012-08-26 02:01 - 2011-05-14 20:43 - 62134624 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-25 16:52 - 2012-02-01 17:52 - 00000456 ___AH C:\Windows\Tasks\Norton Security Scan for Marissa.job
2012-08-25 12:37 - 2012-08-22 09:37 - 00003690 ____A C:\Users\Marissa\Desktop\aswMBR.txt
2012-08-25 12:37 - 2012-08-22 09:37 - 00000512 ____A C:\Users\Marissa\Desktop\MBR.dat
2012-08-25 09:27 - 2012-08-24 18:37 - 00002458 ____A C:\Users\Marissa\Desktop\FSS.txt
2012-08-25 08:51 - 2012-08-25 08:51 - 00262144 ____A C:\Windows\Minidump\082512-53040-01.dmp
2012-08-25 08:51 - 2011-05-17 16:29 - 539660446 ____A C:\Windows\MEMORY.DMP
2012-08-25 06:42 - 2009-07-14 00:08 - 00032562 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-24 19:53 - 2012-08-24 19:53 - 00082548 ____A C:\Users\Marissa\Desktop\Extras.Txt
2012-08-24 19:33 - 2012-08-24 19:33 - 00006288 ____A C:\Users\Marissa\Desktop\BITS.reg
2012-08-24 19:00 - 2012-08-24 18:59 - 02892816 ____A (Symantec Corporation) C:\Users\Marissa\Downloads\NPE (1).exe
2012-08-24 18:36 - 2012-08-24 18:36 - 00693235 ____A (Farbar) C:\Users\Marissa\Desktop\FSS.exe
2012-08-24 18:12 - 2012-08-24 18:12 - 00030583 ____A C:\ComboFix.txt
2012-08-24 17:52 - 2009-07-13 21:34 - 00000215 ____A C:\Windows\system.ini
2012-08-24 17:50 - 2009-07-13 21:34 - 80216064 ____A C:\Windows\System32\config\software.bak
2012-08-24 17:50 - 2009-07-13 21:34 - 23068672 ____A C:\Windows\System32\config\system.bak
2012-08-24 17:50 - 2009-07-13 21:34 - 00262144 ____A C:\Windows\System32\config\security.bak
2012-08-24 17:50 - 2009-07-13 21:34 - 00262144 ____A C:\Windows\System32\config\sam.bak
2012-08-24 17:50 - 2009-07-13 21:34 - 00262144 ____A C:\Windows\System32\config\default.bak
2012-08-24 17:33 - 2012-08-24 17:33 - 04737458 ____R (Swearware) C:\Users\Marissa\Desktop\ComboFix.exe
2012-08-24 16:05 - 2012-08-24 16:05 - 04731392 ____A (AVAST Software) C:\Users\Marissa\Desktop\aswMBR.exe
2012-08-24 16:05 - 2012-08-24 16:05 - 00596480 ____A (OldTimer Tools) C:\Users\Marissa\Desktop\OTL.exe
2012-08-24 12:55 - 2012-08-24 12:55 - 00266288 ____A C:\Windows\Minidump\082412-41667-01.dmp
2012-08-24 09:47 - 2012-08-24 09:47 - 00262144 ____A C:\Windows\Minidump\082412-50747-01.dmp
2012-08-24 09:27 - 2012-08-24 09:27 - 00728096 ____A C:\Windows\Minidump\082412-37845-01.dmp
2012-08-24 07:02 - 2011-07-22 20:14 - 00002342 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-08-24 07:02 - 2011-07-22 20:14 - 00002342 ____A C:\Users\All Users\Desktop\Google Chrome.lnk
2012-08-24 07:00 - 2012-08-24 07:00 - 00001785 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-08-24 07:00 - 2012-08-24 07:00 - 00001785 ____A C:\Users\All Users\Desktop\iTunes.lnk
2012-08-24 06:55 - 2012-08-24 06:55 - 00001847 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-08-24 06:55 - 2012-08-24 06:55 - 00001847 ____A C:\Users\All Users\Desktop\QuickTime Player.lnk
2012-08-22 09:29 - 2012-08-22 09:29 - 00070560 ____A C:\Users\Marissa\Downloads\Extras.Txt
2012-08-19 19:27 - 2012-04-26 20:24 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-19 19:27 - 2011-07-12 10:01 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-11 14:19 - 2012-08-11 14:19 - 00809840 ____A (AirInstaller Inc.) C:\Users\Marissa\Downloads\setup.exe
2012-08-07 19:52 - 2012-08-07 19:52 - 00728048 ____A C:\Windows\Minidump\080712-24804-01.dmp
2012-08-06 21:13 - 2011-10-03 19:28 - 00001157 ____A C:\Users\Marissa\My Documents\Einstein.txt
2012-08-06 21:13 - 2011-10-03 19:28 - 00001157 ____A C:\Users\Marissa\Documents\Einstein.txt
2012-08-06 21:13 - 2011-10-03 19:27 - 00001416 ____A C:\Users\Marissa\My Documents\Einstein.html
2012-08-06 21:13 - 2011-10-03 19:27 - 00001416 ____A C:\Users\Marissa\Documents\Einstein.html
2012-08-06 21:13 - 2011-10-03 19:26 - 00001153 ____A C:\Users\Marissa\My Documents\hi.html
2012-08-06 21:13 - 2011-10-03 19:26 - 00001153 ____A C:\Users\Marissa\Documents\hi.html
2012-08-06 21:12 - 2012-06-03 20:32 - 18315743 ____A C:\Users\Marissa\Downloads\Backstreet Boys - I Want It That Way(1).mp4
2012-08-06 21:12 - 2012-06-03 20:29 - 18315743 ____A C:\Users\Marissa\Downloads\Backstreet Boys - I Want It That Way.mp4
2012-08-06 21:12 - 2012-06-03 20:20 - 14144292 ____A C:\Users\Marissa\Downloads\Backstreet Boys - Everybody (Backstreets Back).mp4
2012-08-06 21:12 - 2012-06-03 19:58 - 16848712 ____A C:\Users\Marissa\Downloads\Aqua - Barbie Girl.mp4
2012-08-06 21:12 - 2012-06-03 19:46 - 00622260 ____A C:\Users\Marissa\Downloads\Backstreet Boys - Quit Playing Games (With My Heart).mp4
2012-08-06 21:12 - 2012-06-03 19:39 - 12195710 ____A C:\Users\Marissa\Downloads\Alanis Morissette - Ironic.mp4
2012-08-06 21:12 - 2012-06-03 19:02 - 16391544 ____A C:\Users\Marissa\Downloads\Ace Of Base - 1994 - The Sign.mp4
2012-08-06 21:12 - 2011-10-05 19:27 - 00000259 ____A C:\Users\Marissa\My Documents\Snoopy.html
2012-08-06 21:12 - 2011-10-05 19:27 - 00000259 ____A C:\Users\Marissa\Documents\Snoopy.html
2012-08-06 21:12 - 2011-10-03 19:36 - 00002141 ____A C:\Users\Marissa\My Documents\Snowman.html
2012-08-06 21:12 - 2011-10-03 19:36 - 00002141 ____A C:\Users\Marissa\Documents\Snowman.html
2012-08-06 21:11 - 2012-06-03 20:45 - 18219129 ____A C:\Users\Marissa\Downloads\Lou Bega - Mambo No. 5 (A Little Bit Of...).mp4
2012-08-06 21:11 - 2012-06-03 20:33 - 16078580 ____A C:\Users\Marissa\Downloads\Eiffel 65 - Blue (Da Ba Dee) (Original Video with subtitles).mp4
2012-08-06 21:11 - 2012-06-03 20:29 - 18026014 ____A C:\Users\Marissa\Downloads\Christina Aguilera - Genie In A Bottle.mp4
2012-08-06 21:11 - 2012-06-03 20:28 - 19661435 ____A C:\Users\Marissa\Downloads\Britney Spears - ...Baby One More Time.mp4
2012-08-06 21:11 - 2012-06-03 20:28 - 13562150 ____A C:\Users\Marissa\Downloads\Cher - Believe [Official Music Video].mp4
2012-08-06 21:11 - 2012-06-03 20:18 - 14828028 ____A C:\Users\Marissa\Downloads\I Want You Back - The Jackson 5.mp4
2012-08-06 21:11 - 2012-06-03 19:55 - 20102949 ____A C:\Users\Marissa\Downloads\Los del Rio - Macarena (Original Video) [HD].mp4
2012-08-06 21:11 - 2012-06-03 19:49 - 19295043 ____A C:\Users\Marissa\Downloads\Hanson - MMMBop.mp4
2012-08-06 21:11 - 2012-06-03 19:48 - 17880854 ____A C:\Users\Marissa\Downloads\Eurythmics - Sweet Dreams (Are Made Of This).mp4
2012-08-06 21:11 - 2012-06-03 19:26 - 09944136 ____A C:\Users\Marissa\Downloads\Macarena - Original version.mp4
2012-08-06 21:11 - 2012-06-03 19:25 - 21271353 ____A C:\Users\Marissa\Downloads\Mariah Carey - Always Be My Baby.mp4
2012-08-06 21:11 - 2012-06-03 19:22 - 21046746 ____A C:\Users\Marissa\Downloads\Hootie And The Blowfish - Only Wanna Be With You (Video).mp4
2012-08-06 21:11 - 2012-06-03 19:21 - 17123046 ____A C:\Users\Marissa\Downloads\Bonnie Tyler - Total Eclipse of the Heart (official music video + lyrics).mp4
2012-08-06 21:11 - 2012-06-03 19:20 - 10844446 ____A C:\Users\Marissa\Downloads\Gangstas Paradise - Coolio.mp4
2012-08-06 21:11 - 2012-06-03 19:12 - 12900701 ____A C:\Users\Marissa\Downloads\Haddaway - What Is Love.mp4
2012-08-06 21:11 - 2012-06-03 18:59 - 19248881 ____A C:\Users\Marissa\Downloads\Gin Blossoms - Hey Jealousy.mp4
2012-08-06 21:11 - 2012-06-03 18:59 - 16858247 ____A C:\Users\Marissa\Downloads\Cypress Hill - Insane In The Brain.mp4
2012-08-06 21:11 - 2012-06-03 18:37 - 19633389 ____A C:\Users\Marissa\Downloads\House of Pain - Jump Around.mp4
2012-08-06 21:11 - 2012-06-03 18:37 - 18207911 ____A C:\Users\Marissa\Downloads\Billy Ray Cyrus - Achy Breaky Heart.mp4
2012-08-06 21:11 - 2012-06-03 18:02 - 20083931 ____A C:\Users\Marissa\Downloads\Deee Lite - Groove is in the Heart (Music Video).mp4
2012-08-06 21:11 - 2012-06-03 18:00 - 18780876 ____A C:\Users\Marissa\Downloads\EMF - Unbelievable.mp4
2012-08-06 21:11 - 2012-06-03 17:59 - 25457193 ____A C:\Users\Marissa\Downloads\C & C Music Factory Gonna Make You Sweat Deejay gu Flash House anos 80, 90 - www.gtpromo.com.br.mp4
2012-08-06 21:11 - 2012-06-03 17:36 - 24573707 ____A C:\Users\Marissa\Downloads\Madonna - Vogue (video).mp4
2012-08-06 21:11 - 2011-07-26 19:34 - 97144226 ____A C:\Users\Marissa\Downloads\Katy Perry - Last Friday Night (T.G.I.F.)_(1080p)-1.mp4
2012-08-06 21:10 - 2012-06-03 20:33 - 18795249 ____A C:\Users\Marissa\Downloads\Ricky Martin - Livin La Vida Loca.mp4
2012-08-06 21:10 - 2012-06-03 20:32 - 21458015 ____A C:\Users\Marissa\Downloads\Santana - Smooth (feat. Rob Thomas).mp4
2012-08-06 21:10 - 2012-06-03 20:32 - 19632394 ____A C:\Users\Marissa\Downloads\Smash Mouth - All Star.mp4
2012-08-06 21:10 - 2012-06-03 20:16 - 21800896 ____A C:\Users\Marissa\Downloads\The Verve - Bitter Sweet Symphony.mp4
2012-08-06 21:10 - 2012-06-03 20:15 - 14685410 ____A C:\Users\Marissa\Downloads\Spice Girls - Spice Up Your Life.mp4
2012-08-06 21:10 - 2012-06-03 20:13 - 17878008 ____A C:\Users\Marissa\Downloads\Will Smith - Getting jiggy with it(1).mp4
2012-08-06 21:10 - 2012-06-03 20:09 - 17878008 ____A C:\Users\Marissa\Downloads\Will Smith - Getting jiggy with it.mp4
2012-08-06 21:10 - 2012-06-03 19:53 - 10640509 ____A C:\Users\Marissa\Downloads\Tubthumping (I Get Knocked Down) Lyrics.mp4
2012-08-06 21:10 - 2012-06-03 19:50 - 19236472 ____A C:\Users\Marissa\Downloads\Third Eye Blind - Semi Charmed Life (Official Music Video) HD.mp4
2012-08-06 21:10 - 2012-06-03 19:46 - 18638204 ____A C:\Users\Marissa\Downloads\Spice Girls - Wannabe.mp4
2012-08-06 21:10 - 2012-06-03 19:40 - 11341420 ____A C:\Users\Marissa\Downloads\Wonderwall.mp4
2012-08-06 21:10 - 2012-06-03 19:39 - 22866760 ____A C:\Users\Marissa\Downloads\Marilyn manson - Sweet Dreams (Official Video).mp4
2012-08-06 21:10 - 2012-06-03 19:23 - 14271011 ____A C:\Users\Marissa\Downloads\the pretenders - Ill stand by you ( video ).mp4
2012-08-06 21:10 - 2012-06-03 19:23 - 12994160 ____A C:\Users\Marissa\Downloads\Rednex - Cotton Eye Joe.mp4
2012-08-06 21:10 - 2012-06-03 19:11 - 19269693 ____A C:\Users\Marissa\Downloads\Salt N Pepa - Whatta Man 1994 (feat. En Vogue).mp4
2012-08-06 21:10 - 2012-06-03 19:05 - 19335280 ____A C:\Users\Marissa\Downloads\Sheryl Crow All I Wanna Do.mp4
2012-08-06 21:10 - 2012-06-03 18:56 - 13017053 ____A C:\Users\Marissa\Downloads\Whoomp There It Is - Tag Team.mp4
2012-08-06 21:10 - 2012-06-03 18:42 - 21438103 ____A C:\Users\Marissa\Downloads\Nirvana - Smells Like Teen Spirit.mp4
2012-08-06 21:10 - 2012-06-03 18:42 - 08952369 ____A C:\Users\Marissa\Downloads\Whitney Houston - I Will Always Love You Official Music Video.mp4
2012-08-06 21:10 - 2012-06-03 18:36 - 14083232 ____A C:\Users\Marissa\Downloads\Right Said Fred - I`m Too Sexy (The Original).mp4
2012-08-06 21:10 - 2012-06-03 18:36 - 12506849 ____A C:\Users\Marissa\Downloads\Sir Mix-A-Lot - Baby Got Back (I Like Big Butts) [ORIGINAL].mp4
2012-08-06 21:10 - 2012-06-03 18:04 - 23263847 ____A C:\Users\Marissa\Downloads\Marky Mark And The Funky Bunch - Good Vibrations.mp4
2012-08-06 21:10 - 2012-06-03 17:50 - 21810647 ____A C:\Users\Marissa\Downloads\MC Hammer - U Cant Touch This.mp4
2012-08-06 21:10 - 2012-06-03 17:48 - 12323548 ____A C:\Users\Marissa\Downloads\Snap - The power.mp4
2012-08-06 21:10 - 2012-06-03 17:47 - 18944047 ____A C:\Users\Marissa\Downloads\Vanilla Ice - Ice Ice Baby.mp4
2012-08-06 21:10 - 2012-06-03 17:45 - 30694648 ____A C:\Users\Marissa\Downloads\Technotronic - Pump Up The Jam.mp4
2012-08-06 20:54 - 2011-03-28 04:52 - 00000204 ____A C:\Users\Public\Desktop\My Identity Protection.url
2012-08-06 20:54 - 2011-03-28 04:52 - 00000204 ____A C:\Users\All Users\Desktop\My Identity Protection.url
2012-08-06 16:26 - 2012-08-06 16:26 - 00001908 ____A C:\Windows\diagwrn.xml
2012-08-06 16:26 - 2012-08-06 16:26 - 00001908 ____A C:\Windows\diagerr.xml
2012-08-06 16:26 - 2009-07-13 23:51 - 00000000 ____A C:\Windows\setuperr.log
2012-08-06 16:23 - 2012-08-06 16:23 - 00262144 ____A C:\Windows\Minidump\080612-29000-01.dmp
2012-08-05 17:02 - 2012-08-05 17:02 - 00262144 ____A C:\Windows\Minidump\080512-34055-01.dmp
2012-08-05 16:34 - 2012-08-05 16:34 - 00002143 ____A C:\Users\Marissa\Desktop\repair your computer.txt
2012-08-05 15:24 - 2012-08-05 15:24 - 00371097 ____A C:\Users\Marissa\Downloads\Base Filtering Engine.reg
2012-08-05 15:03 - 2012-08-05 15:03 - 00002450 ____A C:\Users\Public\Desktop\Norton Anti-Theft.lnk
2012-08-05 15:03 - 2012-08-05 15:03 - 00002450 ____A C:\Users\All Users\Desktop\Norton Anti-Theft.lnk
2012-08-05 14:55 - 2012-08-05 14:55 - 00828736 ____A (Symantec Corporation) C:\Users\Marissa\Downloads\NortonAnti-TheftDownloader.exe
2012-08-04 22:43 - 2012-08-04 22:43 - 00262144 ____A C:\Windows\Minidump\080412-29203-01.dmp
2012-08-04 22:11 - 2012-08-04 22:11 - 02841104 ____A (Symantec Corporation) C:\Users\Marissa\Downloads\NPE.exe
2012-08-04 20:20 - 2012-08-04 20:20 - 01187504 ____A (LogMeIn, Inc.) C:\Users\Marissa\Downloads\Support-LogMeInRescue.exe
2012-07-29 20:12 - 2012-04-23 17:46 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-29 20:12 - 2012-04-23 17:46 - 00001111 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-29 20:08 - 2012-07-29 20:08 - 00262144 ____A C:\Windows\Minidump\072912-22682-01.dmp
2012-07-26 22:14 - 2012-07-26 22:13 - 00728128 ____A C:\Windows\Minidump\072612-15724-01.dmp
2012-07-18 13:15 - 2012-08-25 13:30 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 20:01 - 2012-07-11 20:01 - 00266728 ____A C:\Windows\Minidump\071112-23587-01.dmp
2012-07-11 14:33 - 2009-07-13 21:34 - 00000510 ____A C:\Windows\win.ini
2012-07-07 07:14 - 2012-07-07 07:14 - 00262144 ____A C:\Windows\Minidump\070712-17862-01.dmp
2012-07-06 15:07 - 2012-08-26 02:06 - 00552960 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bthport.sys
2012-07-04 17:16 - 2012-08-25 13:30 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 17:13 - 2012-08-25 13:30 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 17:13 - 2012-08-25 13:30 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-07-04 16:16 - 2012-08-25 13:30 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-07-04 16:14 - 2012-08-25 13:30 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2012-07-03 12:46 - 2011-08-04 20:40 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-28 23:55 - 2012-08-26 02:04 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-28 23:09 - 2012-08-26 02:04 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-28 22:56 - 2012-08-26 02:04 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-28 22:49 - 2012-08-26 02:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-28 22:49 - 2012-08-26 02:04 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-28 22:48 - 2012-08-26 02:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-28 22:47 - 2012-08-26 02:05 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-28 22:45 - 2012-08-26 02:04 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-28 22:44 - 2012-08-26 02:04 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-28 22:43 - 2012-08-26 02:04 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-28 22:42 - 2012-08-26 02:05 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-28 22:40 - 2012-08-26 02:05 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-28 22:39 - 2012-08-26 02:05 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-28 22:35 - 2012-08-26 02:04 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-28 19:52 - 2012-08-26 02:04 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-28 19:27 - 2012-08-26 02:04 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-28 19:16 - 2012-08-26 02:04 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-28 19:09 - 2012-08-26 02:05 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-28 19:09 - 2012-08-26 02:04 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-28 19:08 - 2012-08-26 02:04 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-28 19:07 - 2012-08-26 02:05 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-28 19:06 - 2012-08-26 02:04 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-28 19:04 - 2012-08-26 02:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-28 19:04 - 2012-08-26 02:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-28 19:01 - 2012-08-26 02:05 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-28 19:01 - 2012-08-26 02:05 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-28 19:00 - 2012-08-26 02:05 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-28 18:57 - 2012-08-26 02:04 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 22:51 - 2012-06-13 22:51 - 00000118 ____A C:\Windows\System32\MRT.INI
2012-06-09 00:43 - 2012-07-10 13:27 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 23:41 - 2012-07-10 13:27 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-06 19:59 - 2012-06-06 19:59 - 01070152 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2012-06-06 01:06 - 2012-07-10 13:27 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-06 01:06 - 2012-07-10 13:27 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-06 01:02 - 2012-07-10 13:26 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-06 00:05 - 2012-07-10 13:27 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-06 00:05 - 2012-07-10 13:27 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-06 00:03 - 2012-07-10 13:27 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-03 20:51 - 2012-06-03 20:51 - 231751168 ____A C:\Users\Marissa\My Documents\1990s Music.wmv
2012-06-03 20:51 - 2012-06-03 20:51 - 231751168 ____A C:\Users\Marissa\Documents\1990s Music.wmv
2012-06-03 20:19 - 2012-06-03 20:19 - 00001010 ____A C:\Users\Marissa\Desktop\MixMeister Studio.lnk
2012-06-02 17:19 - 2012-06-22 08:49 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 17:19 - 2012-06-22 08:49 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 17:19 - 2012-06-22 08:49 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 17:19 - 2012-06-22 08:49 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 17:19 - 2012-06-22 08:49 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 17:15 - 2012-06-22 08:49 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 17:15 - 2012-06-22 08:49 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:19 - 2012-06-22 08:48 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:15 - 2012-06-22 08:48 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 00:50 - 2012-07-10 13:27 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-02 00:48 - 2012-07-10 13:27 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-02 00:48 - 2012-07-10 13:27 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 00:45 - 2012-07-10 13:27 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-02 00:44 - 2012-07-10 13:27 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 23:40 - 2012-07-10 13:27 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 23:40 - 2012-07-10 13:27 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 23:39 - 2012-07-10 13:27 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 23:34 - 2012-07-10 13:27 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
ZeroAccess:
C:\Windows\Installer\{3b99f81f-31d5-dbab-1bcf-87d0107a285a}
C:\Windows\Installer\{3b99f81f-31d5-dbab-1bcf-87d0107a285a}\@
C:\Windows\Installer\{3b99f81f-31d5-dbab-1bcf-87d0107a285a}\L
C:\Windows\Installer\{3b99f81f-31d5-dbab-1bcf-87d0107a285a}\U
C:\Windows\Installer\{3b99f81f-31d5-dbab-1bcf-87d0107a285a}\L\00000004.@
C:\Windows\Installer\{3b99f81f-31d5-dbab-1bcf-87d0107a285a}\L\201d3dde
ZeroAccess:
C:\Users\Marissa\AppData\Local\{3b99f81f-31d5-dbab-1bcf-87d0107a285a}
C:\Users\Marissa\AppData\Local\{3b99f81f-31d5-dbab-1bcf-87d0107a285a}\@
C:\Users\Marissa\AppData\Local\{3b99f81f-31d5-dbab-1bcf-87d0107a285a}\L
C:\Users\Marissa\AppData\Local\{3b99f81f-31d5-dbab-1bcf-87d0107a285a}\U
Type 00 partition infection:
C:\Windows\svchost.exe
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-08-24 16:08:21
Restore point made on: 2012-08-24 17:11:31
Restore point made on: 2012-08-24 19:17:10
Restore point made on: 2012-08-24 19:36:13
Restore point made on: 2012-08-24 19:37:33
Restore point made on: 2012-08-24 19:38:13
Restore point made on: 2012-08-24 19:39:01
Restore point made on: 2012-08-26 02:01:26
==================== Memory info ===========================
Percentage of memory in use: 12%
Total physical RAM: 5942.68 MB
Available physical RAM: 5196.56 MB
Total Pagefile: 5940.83 MB
Available Pagefile: 5196.09 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions ============================
1 Drive c: (OS) (Fixed) (Total:581.42 GB) (Free:468.38 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive e: () (Removable) (Total:3.79 GB) (Free:3.79 GB) FAT32
4 Drive f: (Recovery) (Fixed) (Total:14.65 GB) (Free:6.29 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 596 GB 0 B
Disk 1 Online 3892 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 100 MB 1024 KB
Partition 2 Primary 14 GB 101 MB
Partition 3 Primary 581 GB 14 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 DELLUTILITY FAT Partition 100 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 F Recovery NTFS Partition 14 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 581 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3891 MB 400 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E FAT32 Removable 3891 MB Healthy
==================================================================================
Last Boot: 2012-08-18 16:02
==================== End Of Log =============================