Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Laptop freezing [Solved]


  • This topic is locked This topic is locked

#46
kenomikes

kenomikes

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
Hi Dakeyras,

Actually I'm not sure yet if you didn't fix everything. It's running great now at home (and last night after the last fixes), and today I had brought it to work (where we also have a public wifi) which is where I connected to this mmorning and had problems.

However, which I didn't find out until later, the public wifi was disabled for a few hours today. So maybe this is all fixed. :whistling:

I'll give it a day or two to see if any connections problems occur, and will give you a quick post to let you know.

Appreciate all your hard work.

Thx again,

Mike
  • 0

Advertisements


#47
kenomikes

kenomikes

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
Hi,

Well it lost network connection again, sry for multiple posts above, was stuck. :(

I'll try the other Forum as suggested.

Thanks again,

Mike
  • 0

#48
kenomikes

kenomikes

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
Hi,

FYI, I posted over in the Hardware forum, but I just ran a new Malwarebytes, and this popped up.

Also, I did find those old logs in Notebook that was showing some prior malware in August and November.

Not sure what to do now.

Thx

Mike



Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.12.13.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Liv :: LIV-VAIO [administrator]

12/12/2012 9:46:22 PM
mbam-log-2012-12-12 (21-46-22).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 227855
Time elapsed: 10 minute(s), 25 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Users\Liv\AppData\Local\Temp\.exe (Trojan.Agent) -> Quarantined and deleted successfully.

(end)
  • 0

#49
Dakeyras

Dakeyras

    Anti-Malware Mammoth

  • Expert
  • 9,772 posts
Hi. :)

FYI, I posted over in the Hardware forum

Acknowledged, I will temp' close that topic for now and will re-open it if the need OK.

I just ran a new Malwarebytes, and this popped up.

Hmmm interesting and no idea why that has suddenly been detected now. If I recall your step daughter has been using the machine during the course of the malware removal process ?

Also, I did find those old logs in Notebook that was showing some prior malware in August and November.

OK, please do post the contents for my review and we will go from there.
  • 0

#50
kenomikes

kenomikes

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
Hi thanks,

No she hasn't touched machine past 4 days, just me doing these scans.

Here's some older logs I found. When asked before by you for them, I was looking for the logs in the Malwarebytes log button but was empty. Found them in Notebook last night.

FYI, I deleted all the stuff we had installed, except Hippo, after getting the OK and then posting in the Hardware forum,, even ERUNT (my mistake). Ran the scan after doing that. :upset:

Thx again,

Mike


Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.23.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Liv :: LIV-VAIO [administrator]

8/23/2012 9:38:57 AM
mbam-log-2012-08-23 (09-38-57).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 200533
Time elapsed: 7 minute(s), 27 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 4
C:\Users\Liv\Downloads\DownloadSetup (36).exe (Affiliate.Downloader) -> Quarantined and deleted successfully.
C:\Users\Liv\Downloads\finalmediaplayer_2.exe (PUP.BundleOffers.IIQ) -> Quarantined and deleted successfully.
C:\Users\Liv\Downloads\FLVPlayerSetup_MMM.exe (PUP.Adware.Installcore) -> Quarantined and deleted successfully.
C:\Users\Liv\AppData\Local\Temp\.exe (Trojan.Agent) -> Quarantined and deleted successfully.

(end)


Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.11.11.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Liv :: LIV-VAIO [administrator]

11/11/2012 7:53:12 AM
mbam-log-2012-11-11 (07-53-12).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 210385
Time elapsed: 11 minute(s), 16 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Users\Liv\AppData\Local\Temp\.exe (Trojan.Agent) -> Quarantined and deleted successfully.

(end)




Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.11.11.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Liv :: LIV-VAIO [administrator]

11/12/2012 11:55:13 AM
mbam-log-2012-11-12 (11-55-13).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 205875
Time elapsed: 7 minute(s), 53 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)




Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.11.22.10

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Liv :: LIV-VAIO [administrator]

11/22/2012 5:31:50 PM
mbam-log-2012-11-22 (17-31-50).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 228407
Time elapsed: 10 minute(s), 26 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Users\TEST\Downloads\7 zip setup.exe (PUP.AdBundle) -> Quarantined and deleted successfully.

(end)




Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.11.22.11

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Liv :: LIV-VAIO [administrator]

11/22/2012 6:38:51 PM
mbam-log-2012-11-22 (18-38-51).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 228802
Time elapsed: 8 minute(s), 50 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

Edited by kenomikes, 13 December 2012 - 06:08 AM.

  • 0

#51
Dakeyras

Dakeyras

    Anti-Malware Mammoth

  • Expert
  • 9,772 posts
Hi. :)

No she hasn't touched machine past 4 days, just me doing these scans.

Fair play.

FYI, I deleted all the stuff we had installed, except Hippo, after getting the OK and then posting in the Hardware forum,, even ERUNT (my mistake). Ran the scan after doing that. :upset:

OK, not a problem RE Erunt as there will be a new System Restore point now and if the need we can always re-install Erunt and create a new registry backup etc.

Navigate to the below folders and delete the contents as a precaution(if anything still present):-

C:\Users\Liv\Downloads

C:\Users\TEST\Downloads

Any problems doing so merely inform myself in your next reply...lets check if the following will reveal anything further as follows...

Scan with Farbar Recovery Scan Tool:

Please download and save Farbar Recovery Scan Tool 64-Bit to a Flash/USB drive.

Then insert the Flash/USB drive into your machine....

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:

  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
On the System Recovery Options menu you will get the following options:


Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
[*]Select Command Prompt
[*]In the command window type in notepad and press Enter.
[*]The notepad opens. Under File menu select Open.
[*]Select "Computer" and find your flash drive letter and close the notepad.
[*]In the command window type e:\frst64.exe and press Enter[/list] Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste the contents of the aforementioned notepad file in your next reply.

  • 0

#52
kenomikes

kenomikes

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
Hi Dakeyras,


Navigate to the below folders and delete the contents as a precaution(if anything still present):-

C:\Users\Liv\Downloads

C:\Users\TEST\Downloads

Any problems doing so merely inform myself in your next reply...lets check if the following will reveal anything further as follows...


Deleted all, FYI, there was 224 items (7.7GB) in just the Liv download.




Please download and save Farbar Recovery Scan Tool 64-Bit to a Flash/USB drive.

Then insert the Flash/USB drive into your machine....




Are you asking me to download this to a USB using a different computer, and then insert in LIV's computer?


Thanks again, won't be able to do this step until sometime tonight anyway.

Mike
  • 0

#53
kenomikes

kenomikes

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
Hi Dakeyras,


Here you go.

Thx,

Mike

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-12-2012
Ran by SYSTEM at 13-12-2012 22:01:13
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001

==================== Registry (Whitelisted) ===================

HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [518784 2011-03-08] (Conexant Systems, Inc.)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2284328 2011-02-14] (Synaptics Incorporated)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1289704 2012-09-12] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [2757312 2011-02-15] (Sony Corporation)
HKLM-x32\...\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-26] (Sony Corporation)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-11-28] (Apple Inc.)
HKLM-x32\...\Run: [EEventManager] C:\PROGRA~2\EPSONS~1\EVENTM~1\EEventManager.exe [673616 2009-04-07] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [151952 2012-11-28] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [926896 2012-09-23] (Adobe Systems Incorporated)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\Liv\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

==================== Services (Whitelisted) ===================

2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE" [140672 2012-07-11] (SUPERAntiSpyware.com)
3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22072 2012-09-12] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [368896 2012-09-12] (Microsoft Corporation)
2 SampleCollector; "C:\Program Files\Sony\VAIO Care\VCPerfService.exe" "/service" "/sstates" "/sampleinterval=5000" "/procinterval=5" "/dllinterval=120" "/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1" "/counter=\Network Interface(*)\Bytes Total/sec:1" "/expandcounter=\Processor Information(*)\Processor Frequency:1" "/expandcounter=\Processor(*)\% Idle Time:1" "/expandcounter=\Processor(*)\% C1 Time:1" "/expandcounter=\Processor(*)\% C2 Time:1" "/expandcounter=\Processor(*)\% C3 Time:1" "/expandcounter=\Processor(*)\% Processor Time:1" "/directory=C:\ProgramData\Sony Corporation\VAIO Care\inteldata" [259192 2011-01-29] (Sony Corporation)
2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.)
3 VUAgent; "C:\Program Files\Sony\VAIO Update 5\VUAgent.exe" [1021112 2011-03-30] (Sony Corporation)

==================== Drivers (Whitelisted) =====================

3 ArcSoftKsUFilter; C:\Windows\System32\Drivers\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
0 MpFilter; C:\Windows\System32\Drivers\MpFilter.sys [228768 2012-08-30] (Microsoft Corporation)
2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [128456 2012-08-30] (Microsoft Corporation)
0 pavboot; C:\Windows\System32\drivers\pavboot64.sys [33800 2009-06-30] (Panda Security, S.L.)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
3 sscdserd; C:\Windows\System32\Drivers\sscdserd.sys [141384 2010-11-11] (MCCI Corporation)

==================== NetSvcs (Whitelisted) ====================


==================== One Month Created Files and Folders ========

2012-12-13 22:01 - 2012-12-13 22:01 - 00000000 ____D C:\FRST
2012-12-13 18:43 - 2012-08-21 06:20 - 00046080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncobjapi.dll
2012-12-13 18:43 - 2012-08-21 05:49 - 00058368 ____A (Microsoft Corporation) C:\Windows\System32\ncobjapi.dll
2012-12-13 18:42 - 2012-08-21 06:59 - 00001536 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winrsmgr.dll
2012-12-13 18:42 - 2012-08-21 06:56 - 00060416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll
2012-12-13 18:42 - 2012-08-21 06:29 - 00009728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winrssrv.dll
2012-12-13 18:42 - 2012-08-21 06:28 - 00010240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll
2012-12-13 18:42 - 2012-08-21 06:20 - 00001536 ____A (Microsoft Corporation) C:\Windows\System32\winrsmgr.dll
2012-12-13 18:42 - 2012-08-21 06:19 - 00060416 ____A (Microsoft Corporation) C:\Windows\System32\WsmRes.dll
2012-12-13 18:42 - 2012-08-21 06:18 - 00089088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mi.dll
2012-12-13 18:42 - 2012-08-21 06:14 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wecapi.dll
2012-12-13 18:42 - 2012-08-21 06:08 - 00083456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wevtfwd.dll
2012-12-13 18:42 - 2012-08-21 06:01 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Register-CimProvider.exe
2012-12-13 18:42 - 2012-08-21 05:58 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\winrssrv.dll
2012-12-13 18:42 - 2012-08-21 05:57 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\wsmplpxy.dll
2012-12-13 18:42 - 2012-08-21 05:56 - 00078336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wecutil.exe
2012-12-13 18:42 - 2012-08-21 05:48 - 00106496 ____A (Microsoft Corporation) C:\Windows\System32\mi.dll
2012-12-13 18:42 - 2012-08-21 05:45 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\wecapi.dll
2012-12-13 18:42 - 2012-08-21 05:44 - 00059904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\prvdmofcomp.dll
2012-12-13 18:42 - 2012-08-21 05:40 - 00108544 ____A (Microsoft Corporation) C:\Windows\System32\wevtfwd.dll
2012-12-13 18:42 - 2012-08-21 05:32 - 00021504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WsmAgent.dll
2012-12-13 18:42 - 2012-08-21 05:32 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\Register-CimProvider.exe
2012-12-13 18:42 - 2012-08-21 05:28 - 00105472 ____A (Microsoft Corporation) C:\Windows\System32\wecutil.exe
2012-12-13 18:42 - 2012-08-21 05:26 - 00216576 ____A (Microsoft Corporation) C:\Windows\System32\wecsvc.dll
2012-12-13 18:42 - 2012-08-21 05:17 - 00079360 ____A (Microsoft Corporation) C:\Windows\System32\prvdmofcomp.dll
2012-12-13 18:42 - 2012-08-21 05:13 - 00020480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winrshost.exe
2012-12-13 18:42 - 2012-08-21 05:06 - 00026112 ____A (Microsoft Corporation) C:\Windows\System32\WsmAgent.dll
2012-12-13 18:42 - 2012-08-21 05:04 - 00039936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winrs.exe
2012-12-13 18:42 - 2012-08-21 05:03 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe
2012-12-13 18:42 - 2012-08-21 05:02 - 00092160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winrscmd.dll
2012-12-13 18:42 - 2012-08-21 04:50 - 00036352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PSModuleDiscoveryProvider.dll
2012-12-13 18:42 - 2012-08-21 04:50 - 00030208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2012-12-13 18:42 - 2012-08-21 04:47 - 00023040 ____A (Microsoft Corporation) C:\Windows\System32\winrshost.exe
2012-12-13 18:42 - 2012-08-21 04:37 - 00046080 ____A (Microsoft Corporation) C:\Windows\System32\winrs.exe
2012-12-13 18:42 - 2012-08-21 04:36 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\wsmprovhost.exe
2012-12-13 18:42 - 2012-08-21 04:35 - 00106496 ____A (Microsoft Corporation) C:\Windows\System32\winrscmd.dll
2012-12-13 18:42 - 2012-08-21 04:30 - 00042496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pwrshplugin.dll
2012-12-13 18:42 - 2012-08-21 04:22 - 00048128 ____A (Microsoft Corporation) C:\Windows\System32\PSModuleDiscoveryProvider.dll
2012-12-13 18:42 - 2012-08-21 04:22 - 00028672 ____A (Microsoft Corporation) C:\Windows\System32\WSManHTTPConfig.exe
2012-12-13 18:42 - 2012-08-21 04:04 - 00058368 ____A (Microsoft Corporation) C:\Windows\System32\pwrshplugin.dll
2012-12-13 18:42 - 2012-07-23 10:17 - 00004675 ____A C:\Windows\System32\wsmanconfig_schema.xml
2012-12-13 18:42 - 2012-07-23 10:17 - 00004148 ____A C:\Windows\System32\psmodulediscoveryprovider.mof
2012-12-13 18:42 - 2012-07-23 10:16 - 00204105 ____A C:\Windows\SysWOW64\winrm.vbs
2012-12-13 18:42 - 2012-07-23 10:16 - 00004675 ____A C:\Windows\SysWOW64\wsmanconfig_schema.xml
2012-12-13 18:41 - 2012-08-21 05:43 - 00154112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmitomi.dll
2012-12-13 18:41 - 2012-08-21 05:36 - 00124416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmidcom.dll
2012-12-13 18:41 - 2012-08-21 05:34 - 00382464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wbemcomn2.dll
2012-12-13 18:41 - 2012-08-21 05:33 - 00172544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\miutils.dll
2012-12-13 18:41 - 2012-08-21 05:29 - 00192512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\framedynos.dll
2012-12-13 18:41 - 2012-08-21 05:27 - 00189952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\framedyn.dll
2012-12-13 18:41 - 2012-08-21 05:16 - 00214528 ____A (Microsoft Corporation) C:\Windows\System32\wmitomi.dll
2012-12-13 18:41 - 2012-08-21 05:09 - 00160768 ____A (Microsoft Corporation) C:\Windows\System32\wmidcom.dll
2012-12-13 18:41 - 2012-08-21 05:08 - 00494592 ____A (Microsoft Corporation) C:\Windows\System32\wbemcomn2.dll
2012-12-13 18:41 - 2012-08-21 05:07 - 00223232 ____A (Microsoft Corporation) C:\Windows\System32\miutils.dll
2012-12-13 18:41 - 2012-08-21 05:03 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\framedynos.dll
2012-12-13 18:41 - 2012-08-21 05:02 - 00242688 ____A (Microsoft Corporation) C:\Windows\System32\framedyn.dll
2012-12-13 18:41 - 2012-08-21 05:02 - 00227328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2012-12-13 18:41 - 2012-08-21 05:02 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2012-12-13 18:41 - 2012-08-21 04:56 - 00526848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WsmGCDeps.dll
2012-12-13 18:41 - 2012-08-21 04:52 - 02039296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2012-12-13 18:41 - 2012-08-21 04:35 - 00157184 ____A (Microsoft Corporation) C:\Windows\System32\WsmAuto.dll
2012-12-13 18:41 - 2012-08-21 04:34 - 00309248 ____A (Microsoft Corporation) C:\Windows\System32\WsmWmiPl.dll
2012-12-13 18:41 - 2012-08-21 04:26 - 00630784 ____A (Microsoft Corporation) C:\Windows\System32\WsmGCDeps.dll
2012-12-13 18:41 - 2012-08-21 04:24 - 02832384 ____A (Microsoft Corporation) C:\Windows\System32\WsmSvc.dll
2012-12-13 18:41 - 2012-08-21 03:26 - 00056832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2012-12-13 18:41 - 2012-08-21 03:05 - 00066560 ____A (Microsoft Corporation) C:\Windows\System32\WSManMigrationPlugin.dll
2012-12-13 18:41 - 2012-07-23 10:17 - 00204105 ____A C:\Windows\System32\winrm.vbs
2012-12-13 17:28 - 2012-11-13 23:06 - 17811968 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-12-13 17:28 - 2012-11-13 22:32 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-12-13 17:28 - 2012-11-13 22:11 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-12-13 17:28 - 2012-11-13 22:04 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-12-13 17:28 - 2012-11-13 22:04 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-12-13 17:28 - 2012-11-13 22:02 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-12-13 17:28 - 2012-11-13 22:02 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-12-13 17:28 - 2012-11-13 21:59 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-12-13 17:28 - 2012-11-13 21:58 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-12-13 17:28 - 2012-11-13 21:57 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-12-13 17:28 - 2012-11-13 21:57 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-12-13 17:28 - 2012-11-13 21:55 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-12-13 17:28 - 2012-11-13 21:55 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-12-13 17:28 - 2012-11-13 21:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-12-13 17:28 - 2012-11-13 21:52 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-12-13 17:28 - 2012-11-13 21:46 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-12-13 17:28 - 2012-11-13 18:48 - 12320256 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-12-13 17:28 - 2012-11-13 18:14 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-12-13 17:28 - 2012-11-13 18:09 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-12-13 17:28 - 2012-11-13 17:58 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-12-13 17:28 - 2012-11-13 17:57 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-12-13 17:28 - 2012-11-13 17:57 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-12-13 17:28 - 2012-11-13 17:55 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-12-13 17:28 - 2012-11-13 17:51 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-12-13 17:28 - 2012-11-13 17:49 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-12-13 17:28 - 2012-11-13 17:49 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-12-13 17:28 - 2012-11-13 17:48 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-12-13 17:28 - 2012-11-13 17:47 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-12-13 17:28 - 2012-11-13 17:46 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-12-13 17:28 - 2012-11-13 17:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-12-13 17:28 - 2012-11-13 17:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-12-13 17:28 - 2012-11-13 17:41 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-12-12 17:02 - 2012-12-12 17:02 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-12-12 17:02 - 2012-12-12 17:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-12-12 12:38 - 2012-11-08 21:45 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2012-12-12 12:38 - 2012-11-08 20:42 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2012-12-12 12:37 - 2012-11-21 19:26 - 03149824 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-12-12 12:37 - 2012-11-05 13:35 - 00046080 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
2012-12-12 12:37 - 2012-11-05 12:41 - 00367616 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2012-12-12 12:37 - 2012-11-05 12:32 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2012-12-12 12:37 - 2012-11-05 12:32 - 00034304 ____A (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2012-12-12 12:37 - 2012-10-04 09:46 - 00362496 ____A (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2012-12-12 12:37 - 2012-10-04 09:46 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\wow64.dll
2012-12-12 12:37 - 2012-10-04 09:46 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2012-12-12 12:37 - 2012-10-04 09:45 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2012-12-12 12:37 - 2012-10-04 09:43 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2012-12-12 12:37 - 2012-10-04 09:41 - 01161216 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2012-12-12 12:37 - 2012-10-04 09:41 - 00424960 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 09:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:47 - 01114112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2012-12-12 12:37 - 2012-10-04 08:47 - 00274944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2012-12-12 12:37 - 2012-10-04 08:47 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00005120 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2012-12-12 12:37 - 2012-10-04 07:21 - 00338432 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2012-12-12 12:37 - 2012-10-04 06:46 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2012-12-12 12:37 - 2012-10-04 06:46 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2012-12-12 12:37 - 2012-10-04 06:46 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2012-12-12 12:36 - 2012-10-04 09:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2012-12-12 12:36 - 2012-10-04 09:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2012-12-12 12:36 - 2012-10-04 09:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2012-12-12 12:36 - 2012-10-04 09:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2012-12-12 12:36 - 2012-10-04 08:40 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2012-12-12 12:36 - 2012-10-04 08:40 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2012-12-12 12:36 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2012-12-12 12:36 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2012-12-12 12:36 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2012-12-12 12:36 - 2012-10-04 06:46 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2012-12-12 12:36 - 2012-10-04 06:41 - 00006144 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2012-12-12 12:36 - 2012-10-04 06:41 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-12 12:36 - 2012-10-04 06:41 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2012-12-12 12:36 - 2012-10-04 06:41 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2012-12-12 12:32 - 2012-11-01 21:59 - 00478208 ____A (Microsoft Corporation) C:\Windows\System32\dpnet.dll
2012-12-12 12:32 - 2012-11-01 21:11 - 00376832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2012-12-10 18:26 - 2012-12-10 18:26 - 00000000 ____D C:\Windows\en
2012-12-10 18:23 - 2012-12-10 18:23 - 00000000 ____D C:\Program Files\Windows Live
2012-12-10 18:23 - 2012-09-12 12:20 - 00057856 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fssfltr.sys
2012-12-10 18:20 - 2012-12-10 18:20 - 00000000 ___RD C:\Users\Liv\SkyDrive
2012-12-10 18:20 - 2012-12-10 18:20 - 00000000 ____D C:\Users\All Users\Microsoft SkyDrive
2012-12-10 18:20 - 2012-12-10 18:20 - 00000000 ____D C:\Program Files (x86)\Microsoft SkyDrive
2012-12-10 18:12 - 2012-12-10 18:12 - 00001979 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
2012-12-10 18:05 - 2012-12-13 18:20 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-12-10 18:05 - 2012-12-13 08:20 - 00691128 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-12-10 18:05 - 2012-12-13 08:20 - 00070584 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-12-10 17:58 - 2012-12-10 17:58 - 00002358 ____A C:\Users\Liv\Desktop\Google Chrome.lnk
2012-12-10 16:13 - 2012-12-10 16:13 - 00001743 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-12-10 16:11 - 2012-12-10 16:13 - 00000000 ____D C:\Users\All Users\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-12-10 16:11 - 2012-12-10 16:13 - 00000000 ____D C:\Program Files\iTunes
2012-12-10 16:11 - 2012-12-10 16:13 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-12-10 16:11 - 2012-12-10 16:11 - 00000000 ____D C:\Program Files\iPod
2012-12-10 15:52 - 2012-12-10 15:52 - 00001817 ____A C:\Users\Public\Desktop\ooVoo.lnk
2012-12-10 15:52 - 2012-12-10 15:52 - 00000000 ____D C:\Program Files (x86)\oovoo
2012-12-10 15:26 - 2012-12-10 15:26 - 00000000 ____D C:\Users\Liv\AppData\Local\APN
2012-12-10 14:26 - 2012-12-10 14:26 - 00001933 ____A C:\Users\Liv\Desktop\Update Checker.lnk
2012-12-10 14:26 - 2012-12-10 14:26 - 00000000 ____D C:\Program Files (x86)\FileHippo.com
2012-12-09 15:55 - 2012-12-09 15:55 - 00000000 ____D C:\Program Files (x86)\Panda Security
2012-12-09 15:55 - 2009-06-30 07:37 - 00033800 ____A (Panda Security, S.L.) C:\Windows\System32\Drivers\pavboot64.sys
2012-12-07 06:02 - 2012-12-07 06:04 - 00000610 ____A C:\Users\Liv\Documents\combofix answer.txt
2012-12-05 12:04 - 2012-12-05 12:05 - 00009208 ____A C:\AdwCleaner[S1].txt
2012-12-04 13:54 - 2012-12-04 13:54 - 00009024 ____A C:\AdwCleaner[R1].txt
2012-12-03 14:10 - 2012-12-03 14:10 - 00031952 ____A C:\Users\Liv\Documents\README erunt.txt
2012-12-03 14:08 - 2012-12-12 15:35 - 00000000 ____D C:\Windows\ERDNT
2012-12-02 13:12 - 2012-12-02 13:12 - 01034216 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-12-02 13:12 - 2012-12-02 13:12 - 00289768 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2012-12-02 13:12 - 2012-12-02 13:12 - 00189416 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-12-02 13:12 - 2012-12-02 13:12 - 00188904 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2012-12-02 13:12 - 2012-12-02 13:12 - 00108008 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2012-12-02 13:12 - 2012-12-02 13:12 - 00000000 ____D C:\Windows\SysWOW64\Adobe
2012-12-02 13:10 - 2012-12-02 13:10 - 00246760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-12-02 13:10 - 2012-12-02 13:10 - 00095208 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2012-12-02 13:08 - 2012-12-02 13:08 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2012-12-02 13:08 - 2012-12-02 13:08 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2012-12-02 09:55 - 2012-12-02 10:58 - 00000000 ____D C:\Users\Liv\AppData\Local\Microsoft Games
2012-11-30 15:33 - 2012-08-23 06:13 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\rdpudd.dll
2012-11-30 15:33 - 2012-08-23 06:10 - 00019456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpvideominiport.sys
2012-11-30 15:33 - 2012-08-23 06:08 - 00030208 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbGD.sys
2012-11-30 15:33 - 2012-08-23 06:07 - 00057856 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbFlt.sys
2012-11-30 15:33 - 2012-08-23 05:47 - 00046592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2012-11-30 15:33 - 2012-08-23 05:46 - 00016896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2012-11-30 15:33 - 2012-08-23 05:41 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
2012-11-30 15:33 - 2012-08-23 05:40 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2012-11-30 15:33 - 2012-08-23 05:24 - 00015360 ____A (Microsoft Corporation) C:\Windows\System32\RdpGroupPolicyExtension.dll
2012-11-30 15:33 - 2012-08-23 05:20 - 00054272 ____A (Microsoft Corporation) C:\Windows\System32\MsRdpWebAccess.dll
2012-11-30 15:33 - 2012-08-23 05:18 - 00037376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2012-11-30 15:33 - 2012-08-23 05:17 - 00018432 ____A (Microsoft Corporation) C:\Windows\System32\wksprtPS.dll
2012-11-30 15:33 - 2012-08-23 05:06 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbGDCoInstaller.dll
2012-11-30 15:33 - 2012-08-23 04:52 - 00044032 ____A (Microsoft Corporation) C:\Windows\System32\tsgqec.dll
2012-11-30 15:33 - 2012-08-23 03:20 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\TSWbPrxy.exe
2012-11-30 15:33 - 2012-08-23 03:15 - 00269312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2012-11-30 15:33 - 2012-08-23 03:14 - 00384000 ____A (Microsoft Corporation) C:\Windows\System32\wksprt.exe
2012-11-30 15:33 - 2012-08-23 03:12 - 00192000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2012-11-30 15:33 - 2012-08-23 02:54 - 00322560 ____A (Microsoft Corporation) C:\Windows\System32\aaclient.dll
2012-11-30 15:33 - 2012-08-23 02:51 - 00228864 ____A (Microsoft Corporation) C:\Windows\System32\rdpendp_winip.dll
2012-11-30 15:33 - 2012-08-23 02:39 - 01048064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2012-11-30 15:33 - 2012-08-23 02:22 - 01123840 ____A (Microsoft Corporation) C:\Windows\System32\mstsc.exe
2012-11-30 15:33 - 2012-08-23 01:51 - 03174912 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2012-11-30 15:32 - 2012-08-23 00:19 - 04916224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2012-11-30 15:32 - 2012-08-23 00:13 - 05773824 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2012-11-30 15:07 - 2012-08-24 10:13 - 00154480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-11-30 15:07 - 2012-08-24 10:09 - 00458712 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-11-30 15:07 - 2012-08-24 10:05 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-11-30 15:07 - 2012-08-24 10:04 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-11-30 15:07 - 2012-08-24 10:03 - 01448448 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2012-11-30 15:07 - 2012-08-24 08:57 - 00247808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-11-30 15:07 - 2012-08-24 08:57 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-11-30 15:07 - 2012-08-24 08:57 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-11-30 15:07 - 2012-08-24 08:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-11-30 15:07 - 2012-05-04 03:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-11-30 15:07 - 2012-05-04 01:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-11-22 19:36 - 2012-11-22 19:36 - 00000032 ____A C:\Windows\SysWOW64\setup.log
2012-11-22 19:35 - 2012-11-22 19:36 - 00000000 ____D C:\Program Files (x86)\Atheros WiFi Driver Installation
2012-11-22 19:35 - 2011-06-29 17:46 - 00066623 ____A C:\Windows\System32\athrextx.cat
2012-11-22 19:35 - 2011-06-21 01:03 - 02753536 ____A (Atheros Communications, Inc.) C:\Windows\System32\Drivers\athrx.sys
2012-11-22 19:35 - 2011-06-21 01:03 - 02753536 ____A (Atheros Communications, Inc.) C:\Windows\System32\athrx.sys
2012-11-22 19:33 - 2012-11-22 19:33 - 00000000 ____D C:\Users\All Users\Atheros
2012-11-22 19:32 - 2012-11-22 19:45 - 00000021 ____A C:\Windows\Model.txt
2012-11-22 19:32 - 2012-11-22 19:45 - 00000000 ____A C:\Windows\Model.log
2012-11-22 19:31 - 2012-12-10 15:08 - 00000000 ____D C:\Update
2012-11-22 18:06 - 2012-11-22 18:06 - 00001808 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-11-22 18:06 - 2012-11-22 18:06 - 00000000 ____D C:\Users\Liv\AppData\Roaming\SUPERAntiSpyware.com
2012-11-22 18:06 - 2012-11-22 18:06 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-11-22 18:06 - 2012-11-22 18:06 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2012-11-16 07:27 - 2012-07-25 20:55 - 00785512 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\Wdf01000.sys
2012-11-16 07:27 - 2012-07-25 20:55 - 00054376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WdfLdr.sys
2012-11-16 07:27 - 2012-07-25 18:36 - 00009728 ____A (Microsoft Corporation) C:\Windows\System32\Wdfres.dll
2012-11-16 07:27 - 2012-06-02 06:35 - 00000003 ____A C:\Windows\System32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2012-11-15 21:45 - 2012-07-25 19:08 - 00744448 ____A (Microsoft Corporation) C:\Windows\System32\WUDFx.dll
2012-11-15 21:45 - 2012-07-25 19:08 - 00229888 ____A (Microsoft Corporation) C:\Windows\System32\WUDFHost.exe
2012-11-15 21:45 - 2012-07-25 19:08 - 00194048 ____A (Microsoft Corporation) C:\Windows\System32\WUDFPlatform.dll
2012-11-15 21:45 - 2012-07-25 19:08 - 00084992 ____A (Microsoft Corporation) C:\Windows\System32\WUDFSvc.dll
2012-11-15 21:45 - 2012-07-25 19:08 - 00045056 ____A (Microsoft Corporation) C:\Windows\System32\WUDFCoinstaller.dll
2012-11-15 21:45 - 2012-07-25 18:26 - 00198656 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WUDFRd.sys
2012-11-15 21:45 - 2012-07-25 18:26 - 00087040 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WUDFPf.sys
2012-11-15 21:45 - 2012-06-02 06:57 - 00000003 ____A C:\Windows\System32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2012-11-15 11:55 - 2012-10-09 10:17 - 00226816 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcore6.dll
2012-11-15 11:55 - 2012-10-09 10:17 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcsvc6.dll
2012-11-15 11:55 - 2012-10-09 09:40 - 00193536 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2012-11-15 11:55 - 2012-10-09 09:40 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2012-11-15 11:55 - 2012-10-03 09:56 - 01914248 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-11-15 11:55 - 2012-10-03 09:44 - 00303104 ____A (Microsoft Corporation) C:\Windows\System32\nlasvc.dll
2012-11-15 11:55 - 2012-10-03 09:44 - 00246272 ____A (Microsoft Corporation) C:\Windows\System32\netcorehc.dll
2012-11-15 11:55 - 2012-10-03 09:44 - 00216576 ____A (Microsoft Corporation) C:\Windows\System32\ncsi.dll
2012-11-15 11:55 - 2012-10-03 09:44 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\nlaapi.dll
2012-11-15 11:55 - 2012-10-03 09:44 - 00018944 ____A (Microsoft Corporation) C:\Windows\System32\netevent.dll
2012-11-15 11:55 - 2012-10-03 09:42 - 00569344 ____A (Microsoft Corporation) C:\Windows\System32\iphlpsvc.dll
2012-11-15 11:55 - 2012-10-03 08:42 - 00175104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2012-11-15 11:55 - 2012-10-03 08:42 - 00156672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2012-11-15 11:55 - 2012-10-03 08:42 - 00018944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2012-11-15 11:55 - 2012-10-03 08:07 - 00045568 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpipreg.sys
2012-11-15 11:55 - 2012-01-12 23:12 - 00052224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2012-11-15 11:54 - 2012-09-25 14:47 - 00078336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2012-11-15 11:54 - 2012-09-25 14:46 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\synceng.dll
2012-11-14 17:35 - 2012-11-14 17:35 - 00000000 ____D C:\IORRT

==================== One Month Modified Files and Folders =======

2012-12-13 22:01 - 2012-12-13 22:01 - 00000000 ____D C:\FRST
2012-12-13 18:54 - 2011-09-24 07:51 - 01216539 ____A C:\Windows\WindowsUpdate.log
2012-12-13 18:54 - 2009-07-13 21:13 - 00779724 ____A C:\Windows\System32\PerfStringBackup.INI
2012-12-13 18:54 - 2009-07-13 20:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-12-13 18:54 - 2009-07-13 20:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-12-13 18:52 - 2009-07-13 20:51 - 00066836 ____A C:\Windows\setupact.log
2012-12-13 18:47 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-12-13 18:46 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2012-12-13 18:36 - 2009-07-13 20:45 - 00437568 ____A C:\Windows\System32\FNTCACHE.DAT
2012-12-13 18:31 - 2011-11-28 13:46 - 67413224 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-12-13 18:24 - 2011-11-03 14:39 - 00000000 ____D C:\users\Liv
2012-12-13 18:20 - 2012-12-10 18:05 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-12-13 17:28 - 2011-11-06 21:16 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-12-13 08:50 - 2010-11-20 19:47 - 00413622 ____A C:\Windows\PFRO.log
2012-12-13 08:20 - 2012-12-10 18:05 - 00691128 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-12-13 08:20 - 2012-12-10 18:05 - 00070584 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-12-12 17:42 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2012-12-12 17:02 - 2012-12-12 17:02 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-12-12 17:02 - 2012-12-12 17:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-12-12 17:02 - 2011-11-03 20:03 - 00001945 ____A C:\Windows\epplauncher.mif
2012-12-12 15:35 - 2012-12-03 14:08 - 00000000 ____D C:\Windows\ERDNT
2012-12-10 18:52 - 2011-11-06 07:57 - 00000000 ____D C:\Users\Liv\AppData\Roaming\Epson
2012-12-10 18:26 - 2012-12-10 18:26 - 00000000 ____D C:\Windows\en
2012-12-10 18:24 - 2011-09-24 09:24 - 00000000 ____D C:\Program Files (x86)\Windows Live
2012-12-10 18:23 - 2012-12-10 18:23 - 00000000 ____D C:\Program Files\Windows Live
2012-12-10 18:23 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2012-12-10 18:21 - 2011-09-24 08:43 - 00000975 ____A C:\Windows\DirectX.log
2012-12-10 18:20 - 2012-12-10 18:20 - 00000000 ___RD C:\Users\Liv\SkyDrive
2012-12-10 18:20 - 2012-12-10 18:20 - 00000000 ____D C:\Users\All Users\Microsoft SkyDrive
2012-12-10 18:20 - 2012-12-10 18:20 - 00000000 ____D C:\Program Files (x86)\Microsoft SkyDrive
2012-12-10 18:18 - 2011-11-08 13:47 - 00000000 ____D C:\Users\Liv\AppData\Local\Windows Live
2012-12-10 18:12 - 2012-12-10 18:12 - 00001979 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
2012-12-10 18:12 - 2011-09-24 08:34 - 00000000 ____D C:\Users\All Users\Adobe
2012-12-10 18:11 - 2011-09-24 08:33 - 00000000 ____D C:\Program Files (x86)\Adobe
2012-12-10 18:06 - 2011-11-03 19:52 - 00000000 ____D C:\Users\Liv\AppData\Roaming\Adobe
2012-12-10 18:04 - 2012-01-25 23:07 - 00000000 ____D C:\Users\Liv\AppData\Local\Adobe
2012-12-10 17:58 - 2012-12-10 17:58 - 00002358 ____A C:\Users\Liv\Desktop\Google Chrome.lnk
2012-12-10 17:58 - 2011-11-03 20:32 - 00000000 ____D C:\Users\Liv\AppData\Local\Google
2012-12-10 16:13 - 2012-12-10 16:13 - 00001743 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-12-10 16:13 - 2012-12-10 16:11 - 00000000 ____D C:\Users\All Users\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-12-10 16:13 - 2012-12-10 16:11 - 00000000 ____D C:\Program Files\iTunes
2012-12-10 16:13 - 2012-12-10 16:11 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-12-10 16:11 - 2012-12-10 16:11 - 00000000 ____D C:\Program Files\iPod
2012-12-10 15:52 - 2012-12-10 15:52 - 00001817 ____A C:\Users\Public\Desktop\ooVoo.lnk
2012-12-10 15:52 - 2012-12-10 15:52 - 00000000 ____D C:\Program Files (x86)\oovoo
2012-12-10 15:34 - 2009-07-13 21:08 - 00032596 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-12-10 15:26 - 2012-12-10 15:26 - 00000000 ____D C:\Users\Liv\AppData\Local\APN
2012-12-10 15:08 - 2012-11-22 19:31 - 00000000 ____D C:\Update
2012-12-10 14:26 - 2012-12-10 14:26 - 00001933 ____A C:\Users\Liv\Desktop\Update Checker.lnk
2012-12-10 14:26 - 2012-12-10 14:26 - 00000000 ____D C:\Program Files (x86)\FileHippo.com
2012-12-09 15:55 - 2012-12-09 15:55 - 00000000 ____D C:\Program Files (x86)\Panda Security
2012-12-09 10:21 - 2012-01-04 07:11 - 00000000 ____D C:\Users\Liv\AppData\Local\CrashDumps
2012-12-07 06:04 - 2012-12-07 06:02 - 00000610 ____A C:\Users\Liv\Documents\combofix answer.txt
2012-12-07 05:41 - 2009-07-13 19:20 - 00000000 __RHD C:\users\Default
2012-12-07 05:39 - 2009-07-13 18:34 - 00000215 ____A C:\Windows\system.ini
2012-12-06 13:39 - 2012-01-10 13:59 - 00000000 ____D C:\Users\Liv\AppData\Roaming\Mozilla
2012-12-06 08:52 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2012-12-05 12:05 - 2012-12-05 12:04 - 00009208 ____A C:\AdwCleaner[S1].txt
2012-12-04 13:54 - 2012-12-04 13:54 - 00009024 ____A C:\AdwCleaner[R1].txt
2012-12-03 14:10 - 2012-12-03 14:10 - 00031952 ____A C:\Users\Liv\Documents\README erunt.txt
2012-12-02 13:12 - 2012-12-02 13:12 - 01034216 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-12-02 13:12 - 2012-12-02 13:12 - 00289768 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2012-12-02 13:12 - 2012-12-02 13:12 - 00189416 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-12-02 13:12 - 2012-12-02 13:12 - 00188904 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2012-12-02 13:12 - 2012-12-02 13:12 - 00108008 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2012-12-02 13:12 - 2012-12-02 13:12 - 00000000 ____D C:\Windows\SysWOW64\Adobe
2012-12-02 13:12 - 2011-09-24 08:08 - 00916456 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2012-12-02 13:11 - 2011-09-24 08:08 - 00000000 ____D C:\Program Files\Java
2012-12-02 13:10 - 2012-12-02 13:10 - 00246760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-12-02 13:10 - 2012-12-02 13:10 - 00095208 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2012-12-02 13:10 - 2012-10-12 19:45 - 00174056 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-12-02 13:10 - 2012-10-12 19:45 - 00174056 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-12-02 13:10 - 2011-09-24 08:09 - 00746984 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2012-12-02 13:10 - 2011-09-24 08:09 - 00000000 ____D C:\Program Files (x86)\Java
2012-12-02 13:08 - 2012-12-02 13:08 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2012-12-02 13:08 - 2012-12-02 13:08 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2012-12-02 10:58 - 2012-12-02 09:55 - 00000000 ____D C:\Users\Liv\AppData\Local\Microsoft Games
2012-12-02 06:00 - 2011-11-05 09:04 - 00000000 ____D C:\Users\Liv\AppData\Roaming\SoftGrid Client
2012-12-01 07:29 - 2011-03-14 18:36 - 00000000 ____D C:\Windows\ShellNew
2012-11-30 15:14 - 2011-09-24 07:53 - 00000000 ____D C:\Program Files (x86)\Intel
2012-11-30 14:19 - 2012-05-06 14:20 - 00000376 ____A C:\Windows\ODBC.INI
2012-11-30 13:36 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\system
2012-11-26 08:18 - 2012-01-05 18:22 - 00025959 ____A C:\test.xml
2012-11-22 19:46 - 2011-09-24 08:29 - 00000000 ____D C:\Documentation
2012-11-22 19:45 - 2012-11-22 19:32 - 00000021 ____A C:\Windows\Model.txt
2012-11-22 19:45 - 2012-11-22 19:32 - 00000000 ____A C:\Windows\Model.log
2012-11-22 19:36 - 2012-11-22 19:36 - 00000032 ____A C:\Windows\SysWOW64\setup.log
2012-11-22 19:36 - 2012-11-22 19:35 - 00000000 ____D C:\Program Files (x86)\Atheros WiFi Driver Installation
2012-11-22 19:35 - 2011-09-24 07:56 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-11-22 19:33 - 2012-11-22 19:33 - 00000000 ____D C:\Users\All Users\Atheros
2012-11-22 19:32 - 2011-09-24 08:24 - 00000000 ____D C:\Users\All Users\Sony Corporation
2012-11-22 18:06 - 2012-11-22 18:06 - 00001808 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-11-22 18:06 - 2012-11-22 18:06 - 00000000 ____D C:\Users\Liv\AppData\Roaming\SUPERAntiSpyware.com
2012-11-22 18:06 - 2012-11-22 18:06 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-11-22 18:06 - 2012-11-22 18:06 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2012-11-21 19:26 - 2012-12-12 12:37 - 03149824 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-11-18 17:41 - 2011-11-03 14:39 - 00117384 ____A C:\Users\Liv\AppData\Local\GDIPFONTCACHEV1.DAT
2012-11-17 12:26 - 2011-09-24 07:50 - 00000000 ____D C:\Program Files (x86)\DDNi
2012-11-14 17:35 - 2012-11-14 17:35 - 00000000 ____D C:\IORRT
2012-11-14 08:39 - 2012-11-12 10:17 - 00000000 ____D C:\Users\Liv\AppData\Local\LogMeIn Rescue Applet
2012-11-13 23:06 - 2012-12-13 17:28 - 17811968 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-11-13 22:32 - 2012-12-13 17:28 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-11-13 22:11 - 2012-12-13 17:28 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-11-13 22:04 - 2012-12-13 17:28 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-11-13 22:04 - 2012-12-13 17:28 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-11-13 22:02 - 2012-12-13 17:28 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-11-13 22:02 - 2012-12-13 17:28 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-11-13 21:59 - 2012-12-13 17:28 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-11-13 21:58 - 2012-12-13 17:28 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-11-13 21:57 - 2012-12-13 17:28 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-11-13 21:57 - 2012-12-13 17:28 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-11-13 21:55 - 2012-12-13 17:28 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-11-13 21:55 - 2012-12-13 17:28 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-11-13 21:53 - 2012-12-13 17:28 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-11-13 21:52 - 2012-12-13 17:28 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-11-13 21:46 - 2012-12-13 17:28 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-11-13 18:48 - 2012-12-13 17:28 - 12320256 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-11-13 18:14 - 2012-12-13 17:28 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-11-13 18:09 - 2012-12-13 17:28 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-11-13 17:58 - 2012-12-13 17:28 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-11-13 17:57 - 2012-12-13 17:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-11-13 17:57 - 2012-12-13 17:28 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-11-13 17:55 - 2012-12-13 17:28 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-11-13 17:51 - 2012-12-13 17:28 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-11-13 17:49 - 2012-12-13 17:28 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-11-13 17:49 - 2012-12-13 17:28 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-11-13 17:48 - 2012-12-13 17:28 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-11-13 17:47 - 2012-12-13 17:28 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-11-13 17:46 - 2012-12-13 17:28 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-11-13 17:45 - 2012-12-13 17:28 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-11-13 17:44 - 2012-12-13 17:28 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-11-13 17:41 - 2012-12-13 17:28 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll

==================== Known DLLs (Whitelisted) =================


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

Restore point made on: 2012-12-13 08:28:29
Restore point made on: 2012-12-13 12:50:30
Restore point made on: 2012-12-13 18:28:53
Restore point made on: 2012-12-13 18:40:55

==================== Memory info ===========================

Percentage of memory in use: 14%
Total physical RAM: 4043.86 MB
Available physical RAM: 3439.7 MB
Total Pagefile: 4042.01 MB
Available Pagefile: 3434.98 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB

==================== Partitions =============================

1 Drive c: () (Fixed) (Total:455.31 GB) (Free:408.42 GB) NTFS
2 Drive e: (Recovery) (Fixed) (Total:10.35 GB) (Free:1.11 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive g: (KINGSTON) (Removable) (Total:7.26 GB) (Free:7.16 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 7441 MB 0 B

Partitions of Disk 0:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 10 GB 1024 KB
Partition 2 Primary 100 MB 10 GB
Partition 3 Primary 455 GB 10 GB

==================================================================================

Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E Recovery NTFS Partition 10 GB Healthy Hidden

=========================================================

Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy

=========================================================

Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 455 GB Healthy

=========================================================

Partitions of Disk 1:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7437 MB 4032 KB

==================================================================================

Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G KINGSTON FAT32 Removable 7437 MB Healthy

=========================================================

Last Boot: 2012-12-06 07:47

==================== End Of Log =============================
  • 0

#54
Dakeyras

Dakeyras

    Anti-Malware Mammoth

  • Expert
  • 9,772 posts
Hi. :)

Are you asking me to download this to a USB using a different computer, and then insert in LIV's computer?

In this instance either would have sufficed etc...reason being I only wanted to review a log created without the Operating System booted.

Here you go

Can you confirm for myself if SUPERAntispyware is uninstalled now or not ?

Next:

Delete the following:-

C:\AdwCleaner[R1].txt
C:\AdwCleaner[S1].txt

Empty the Recycle Bin and reboot the machine...

Next:

After the reboot do not open any applications or windows what so ever, then navigate to the below:-

C:\ >> Users >> Liv >> AppData >> Local >> Temp

Let myself know if anything is residing now in the Temp folder etc.
  • 0

#55
kenomikes

kenomikes

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts

Can you confirm for myself if SUPERAntispyware is uninstalled now or not ?



It is not uninstalled. I open it, update, then scan. It does not stay running normally, free version.



Next:

Delete the following:-

C:\AdwCleaner[R1].txt
C:\AdwCleaner[S1].txt

Empty the Recycle Bin and reboot the machine



Done.



Next:

After the reboot do not open any applications or windows what so ever, then navigate to the below:-

C:\ >> Users >> Liv >> AppData >> Local >> Temp

Let myself know if anything is residing now in the Temp folder etc.




There's no AppData folder there under Liv, so no Local and Temp, so empty. One under Public, but that's empty.


Mike
  • 0

Advertisements


#56
Dakeyras

Dakeyras

    Anti-Malware Mammoth

  • Expert
  • 9,772 posts
Hi. :)

It is not uninstalled. I open it, update, then scan. It does not stay running normally, free version.

Fair play, overall it is not that particularly effective a security application in my humble opinion. Your choice to keep installed or not OK.

There's no AppData folder there under Liv, so no Local and Temp, so empty. One under Public, but that's empty.

Carry out the below:-

  • Click on Start(Windows 7 Orb).
  • Open Computer.
  • Press the ALT key.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Now check again please(remember to close all open applications/windows before doing so).
  • 0

#57
kenomikes

kenomikes

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
175 items are there in that folder.
  • 0

#58
Dakeyras

Dakeyras

    Anti-Malware Mammoth

  • Expert
  • 9,772 posts
Hi. :)

175 items are there in that folder.

That is somewhat excessive to say the least. The folder should be empty if nothing actively running, though some software vendors do foolishly make use of it all the time. Apart from the fact malware does make use I think at this time prudent to flush it completely and the prefetch folder also as a precaution. After running the below custom OTM fix some programs may take a tad longer to load/start initially because the aforementioned prefetch folder has been flushed.

Next:

Please download OTM to the Desktop.

  • Right-click on OTM.exe and select Run as Administrator to start the program.
  • Copy the lines from the quote-box(do not copy the word quote) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Commands
[CreateRestorePoint]

:Files
ipconfig /flushdns /c
%systemroot%\prefetch\*.*
C:\Users\Liv\AppData\Local\Temp\*.*

:Commands
[EmptyTemp]

  • Return to OTM, right-click in the "Paste instructions for items to be moved" window (under the yellow bar) and choose Paste
  • Then click the red MoveIt! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of it and pressing CTRL + C (or, after highlighting, right-click and choose Copy), and paste it into your next response.
  • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
  • Close OTM.
Note: The logfile can also be located C: >> _OTM >> MovedFiles >> DD/DD/DD TT/TT.txt <-- denotes date/time log created.

Malwarebytes Anti-Malware:

Note: Remember to right click MBAM and select Run As Administrator.

  • Launch the application, Check for Updates >> Perform quick scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

When completed the above, please post back the following in the order asked for:

  • How is the computer performing now, any further symptoms and or problems encountered?
  • OTM Log from the Custom Script.
  • Malwarebytes Anti-Malware Log.

  • 0

#59
kenomikes

kenomikes

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
Hi,

I'll report back on how it's running shortly, but seems to be loading pages quick and found wifi fast.

Thx,

Mike




Logs:


All processes killed
========== COMMANDS ==========
Restore point Set: OTM Restore Point
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Liv\Desktop\cmd.bat deleted successfully.
C:\Users\Liv\Desktop\cmd.txt deleted successfully.
C:\Windows\prefetch\ADMLOAD.EXE-BC3F26C0.pf moved successfully.
C:\Windows\prefetch\AgAppLaunch.db moved successfully.
C:\Windows\prefetch\AgCx_S1_S-1-5-21-4167750879-2311690763-2497449094-1008.snp.db moved successfully.
C:\Windows\prefetch\AgCx_S2_S-1-5-21-4167750879-2311690763-2497449094-1005.snp.db moved successfully.
C:\Windows\prefetch\AgCx_SC1.db moved successfully.
C:\Windows\prefetch\AgCx_SC1.db.trx moved successfully.
C:\Windows\prefetch\AgCx_SC2.db moved successfully.
C:\Windows\prefetch\AgCx_SC3_0002DD197280D7D6.db moved successfully.
C:\Windows\prefetch\AgCx_SC3_0F505DC5912758C7.db moved successfully.
C:\Windows\prefetch\AgCx_SC4.db moved successfully.
C:\Windows\prefetch\AgGlFaultHistory.db moved successfully.
C:\Windows\prefetch\AgGlFgAppHistory.db moved successfully.
C:\Windows\prefetch\AgGlGlobalHistory.db moved successfully.
C:\Windows\prefetch\AgGlUAD_P_S-1-5-21-4167750879-2311690763-2497449094-1005.db moved successfully.
C:\Windows\prefetch\AgGlUAD_P_S-1-5-21-4167750879-2311690763-2497449094-1008.db moved successfully.
C:\Windows\prefetch\AgGlUAD_S-1-5-21-4167750879-2311690763-2497449094-1005.db moved successfully.
C:\Windows\prefetch\AgGlUAD_S-1-5-21-4167750879-2311690763-2497449094-1008.db moved successfully.
C:\Windows\prefetch\AgRobust.db moved successfully.
C:\Windows\prefetch\AUDIODG.EXE-AB22E9A6.pf moved successfully.
C:\Windows\prefetch\CMD.EXE-0BD30981.pf moved successfully.
C:\Windows\prefetch\CMD.EXE-6D6290C5.pf moved successfully.
C:\Windows\prefetch\CONHOST.EXE-0C6456FB.pf moved successfully.
C:\Windows\prefetch\CONSENT.EXE-40419367.pf moved successfully.
C:\Windows\prefetch\DINOTIFY.EXE-6465574B.pf moved successfully.
C:\Windows\prefetch\DLLHOST.EXE-2E02FDCA.pf moved successfully.
C:\Windows\prefetch\DLLHOST.EXE-4B6CB38A.pf moved successfully.
C:\Windows\prefetch\DLLHOST.EXE-6389524F.pf moved successfully.
C:\Windows\prefetch\DLLHOST.EXE-63B92852.pf moved successfully.
C:\Windows\prefetch\DLLHOST.EXE-A010D183.pf moved successfully.
C:\Windows\prefetch\DLLHOST.EXE-F4536DB2.pf moved successfully.
C:\Windows\prefetch\DRVINST.EXE-39D9EAC7.pf moved successfully.
C:\Windows\prefetch\DW20.EXE-7D49EFFE.pf moved successfully.
C:\Windows\prefetch\FLASHPLAYERUPDATESERVICE.EXE-0129C0B2.pf moved successfully.
C:\Windows\prefetch\FLASHUTIL32_11_6_602_108_ACTI-8216B8DC.pf moved successfully.
C:\Windows\prefetch\IASTORDATAMGRSVC.EXE-C93872B4.pf moved successfully.
C:\Windows\prefetch\IEXPLORE.EXE-A033F7A0.pf moved successfully.
C:\Windows\prefetch\IGFXSRVC.EXE-C5618119.pf moved successfully.
C:\Windows\prefetch\IPCONFIG.EXE-10A15CF4.pf moved successfully.
C:\Windows\prefetch\Layout.ini moved successfully.
C:\Windows\prefetch\LISTENER.EXE-DC284414.pf moved successfully.
C:\Windows\prefetch\LMS.EXE-E687E9C2.pf moved successfully.
C:\Windows\prefetch\LOGONUI.EXE-F639BD7E.pf moved successfully.
C:\Windows\prefetch\MAKECAB.EXE-FC3CBE21.pf moved successfully.
C:\Windows\prefetch\MPCMDRUN.EXE-BA176062.pf moved successfully.
C:\Windows\prefetch\MSCORSVW.EXE-16B291C4.pf moved successfully.
C:\Windows\prefetch\MSCORSVW.EXE-8CE1A322.pf moved successfully.
C:\Windows\prefetch\NOTEPAD.EXE-D096D5BE.pf moved successfully.
C:\Windows\prefetch\NTOSBOOT-B00DFAAD.pf moved successfully.
C:\Windows\prefetch\OASIS2SERVICE.EXE-D7323A19.pf moved successfully.
C:\Windows\prefetch\OTM.EXE-CC45C0FB.pf moved successfully.
C:\Windows\prefetch\PfSvPerfStats.bin moved successfully.
C:\Windows\prefetch\PRESENTATIONFONTCACHE.EXE-AB1765B5.pf moved successfully.
C:\Windows\prefetch\RIBBONS.SCR-8B52496E.pf moved successfully.
C:\Windows\prefetch\RUNDLL32.EXE-0D53616E.pf moved successfully.
C:\Windows\prefetch\RUNDLL32.EXE-31898C74.pf moved successfully.
C:\Windows\prefetch\RUNDLL32.EXE-6FD72002.pf moved successfully.
C:\Windows\prefetch\RUNDLL32.EXE-86827AAF.pf moved successfully.
C:\Windows\prefetch\RUNDLL32.EXE-9932B185.pf moved successfully.
C:\Windows\prefetch\SDIAGNHOST.EXE-B3171AA1.pf moved successfully.
C:\Windows\prefetch\SEARCHFILTERHOST.EXE-44162447.pf moved successfully.
C:\Windows\prefetch\SEARCHPROTOCOLHOST.EXE-69C456C3.pf moved successfully.
C:\Windows\prefetch\SELFHEALUPDATE.EXE-6123CF79.pf moved successfully.
C:\Windows\prefetch\SPPSVC.EXE-96070FE0.pf moved successfully.
C:\Windows\prefetch\SUSSOUNDPROXY.EXE-9AF7057F.pf moved successfully.
C:\Windows\prefetch\SVCHOST.EXE-6A249820.pf moved successfully.
C:\Windows\prefetch\TASKENG.EXE-35FA9C06.pf moved successfully.
C:\Windows\prefetch\TASKHOST.EXE-A0F5E092.pf moved successfully.
C:\Windows\prefetch\TRUSTEDINSTALLER.EXE-766EFF52.pf moved successfully.
C:\Windows\prefetch\UCAMMONITOR.EXE-C92C4283.pf moved successfully.
C:\Windows\prefetch\UNS.EXE-40FB88B6.pf moved successfully.
C:\Windows\prefetch\VCAGENT.EXE-99920ED6.pf moved successfully.
C:\Windows\prefetch\VCPERFSERVICE.EXE-8C630ED1.pf moved successfully.
C:\Windows\prefetch\VCSERVICE.EXE-13D30248.pf moved successfully.
C:\Windows\prefetch\VDS.EXE-2FCA9D16.pf moved successfully.
C:\Windows\prefetch\VDSLDR.EXE-50179B50.pf moved successfully.
C:\Windows\prefetch\VSNCLIENT.EXE-E61BB47A.pf moved successfully.
C:\Windows\prefetch\VSNSERVICE.EXE-F4985EFC.pf moved successfully.
C:\Windows\prefetch\VSSVC.EXE-6C8F0C66.pf moved successfully.
C:\Windows\prefetch\VUAGENT.EXE-AA835391.pf moved successfully.
C:\Windows\prefetch\WERMGR.EXE-BE3A79B5.pf moved successfully.
C:\Windows\prefetch\WERMGR.EXE-F439C551.pf moved successfully.
C:\Windows\prefetch\WMIADAP.EXE-BB21CD77.pf moved successfully.
C:\Windows\prefetch\WMIPRVSE.EXE-E8B8DD29.pf moved successfully.
C:\Windows\prefetch\WMPNSCFG.EXE-18FC9E64.pf moved successfully.
DllUnregisterServer procedure not found in C:\Users\Liv\AppData\Local\Temp\AskSLib.dll
C:\Users\Liv\AppData\Local\Temp\1A34.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\3044.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\3045.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\3046.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\4F0.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\501.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\511.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\A7E3.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\AdobeARM.log moved successfully.
C:\Users\Liv\AppData\Local\Temp\AdobeSFX.log moved successfully.
C:\Users\Liv\AppData\Local\Temp\ApnStub.exe moved successfully.
C:\Users\Liv\AppData\Local\Temp\AskSLib.dll moved successfully.
C:\Users\Liv\AppData\Local\Temp\B2DC.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\B2DD.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\B2DE.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\chrome_installer.log moved successfully.
C:\Users\Liv\AppData\Local\Temp\FBBC.tmp moved successfully.
File move failed. C:\Users\Liv\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot.
C:\Users\Liv\AppData\Local\Temp\GoogleUpdate.exe4b43b5 moved successfully.
C:\Users\Liv\AppData\Local\Temp\goopdate.dll4b43c4 moved successfully.
C:\Users\Liv\AppData\Local\Temp\jusched.log moved successfully.
C:\Users\Liv\AppData\Local\Temp\MpCmdRun.log moved successfully.
C:\Users\Liv\AppData\Local\Temp\MSI4d519.LOG moved successfully.
C:\Users\Liv\AppData\Local\Temp\ooVooSetup.log moved successfully.
C:\Users\Liv\AppData\Local\Temp\oovoosetup.msi moved successfully.
C:\Users\Liv\AppData\Local\Temp\SetupAdmin568.log moved successfully.
C:\Users\Liv\AppData\Local\Temp\StructuredQuery.log moved successfully.
C:\Users\Liv\AppData\Local\Temp\TWAIN.LOG moved successfully.
C:\Users\Liv\AppData\Local\Temp\Twain001.Mtx moved successfully.
C:\Users\Liv\AppData\Local\Temp\Twunk001.MTX moved successfully.
C:\Users\Liv\AppData\Local\Temp\Twunk002.MTX moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct100D.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct10E9.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct1A0A.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct2107.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct2B11.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct2CE6.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct332A.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct44CE.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct44CF.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct5EF4.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct5F91.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct6A7A.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct6A7B.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct6BDB.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct6D50.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct6D61.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct7F8C.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct7F8D.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct876A.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct877B.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct8E9E.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct94C8.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wct9FF1.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wctABAA.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wctB666.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wctB7B3.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wctDC4.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wctDC5.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wctDC6C.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wctE2D8.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wctE2D9.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wctE2DA.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wctFEC.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\wctFED.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\{1A400549-745E-4CAD-A2E2-5BB1813956B5}.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\{5D265249-F40D-4947-9F32-15235A5BB28D}.tmp moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF061C34093FC055DF.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF09971C09B3E2ED63.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF0BF6D1294E3FAF02.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF172D8E0B0C321186.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF1E2309E5354CBD95.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF243F4C7F201DD369.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF2875E396D43EB187.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF2C14524F5310F806.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF2D4088492B46E8A1.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF2FBF0E15BEFFDD46.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF32B360BE16DCDFC9.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF35221ED4A74E05D6.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF366D2C2308D8B81A.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF38EA0E3DBB53DFAB.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF462DD3DE1BE7DBCD.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF4DDE13B7E043D460.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF536774786DA0E090.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF541795F0162057C6.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF54C9AE5B49B76930.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF59FE1502538745E6.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF5BC27B68324C3FE2.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF5E55AD563C6CF293.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF5EFCFC9F4BFFE96C.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF613EAF8E5C569267.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF62DD58D807EBFEC5.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF66713422A24969CD.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF6D2A4F42FBBE1A72.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF6EEC9D6F59903979.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF7087B730C4654EE6.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF7E84666697EEF32D.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF7F49FFAC7E30F844.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF826BF48597135803.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF86DBBBEB818610CC.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF8B4C227B85235246.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF8DEAACA1031B4C96.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF8DF608937B95DE66.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF9143E07F6AF57D4D.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF99B423A472552707.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DF9A0F66BA886320E4.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFA30502CE2409C0A2.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFA3FD2E6C2E2C2DF2.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFA4EBF9C356AF3C3A.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFAB2A9A0FF79841CB.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFB69F6741467AD48B.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFBF5D2353EA3E7B8B.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFC2FC2246BA01AEF4.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFC72772A8206AB295.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFCC3E0C4B12C2FB34.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFD735CEA7D2EE70E4.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFDAEA68B780E1C74F.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFDDA828622755A0B1.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFDEE2B8C557909A48.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFE188963BCACD7C7A.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFE3A25745541190A8.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFE6B99F95F8162255.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFEFF41B343026D75D.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFF8BEEC207959D770.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFFBE817A620A3E3E4.TMP moved successfully.
C:\Users\Liv\AppData\Local\Temp\~DFFE9287424B9ACCE7.TMP moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56504 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Liv
->Temp folder emptied: 122661185 bytes
->Temporary Internet Files folder emptied: 119022013 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 7929455 bytes
->Flash cache emptied: 57713 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8923179 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 753 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 85906 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 247.00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 12142012_152141

Files moved on Reboot...
C:\Users\Liv\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...






Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.12.14.10

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Liv :: LIV-VAIO [administrator]

12/14/2012 3:28:44 PM
mbam-log-2012-12-14 (15-28-44).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 210212
Time elapsed: 5 minute(s), 56 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
  • 0

#60
Dakeyras

Dakeyras

    Anti-Malware Mammoth

  • Expert
  • 9,772 posts

I'll report back on how it's running shortly, but seems to be loading pages quick and found wifi fast.

OK, fair play...do also try/use the machine online etc. :)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP