Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

how to remove a (Trojan.Zeroaccess.C) [Solved]


  • This topic is locked This topic is locked

#1
manager1996

manager1996

    Member

  • Member
  • PipPip
  • 23 posts
On my computer,I get an alert from Norton that a (Trojan.Zeroaccess.C) has been blocked about every five minutes. I did a full system scan but Norton cannot see the virus(even though it tells me what file was blocked)and I cannot download Norton power eraser or some other files. It says that this document contains a virus, but I know its clean.

Edited by manager1996, 18 November 2013 - 06:15 PM.

  • 0

Advertisements


#2
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,958 posts
:welcome:

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

  • 0

#3
manager1996

manager1996

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
When I try to download it the computer says that there is a virus and the file has been deleted, even though it doesn't have one.

Edited by manager1996, 19 November 2013 - 04:33 PM.

  • 0

#4
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,958 posts
Which Operating System is in Place?
  • 0

#5
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,958 posts
Do you have a second computer and a flash drive? The file can be downloaded and saved in a flash drive.
  • 0

#6
manager1996

manager1996

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
Windows 7 Home Premium.
  • 0

#7
manager1996

manager1996

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-11-2013
Ran by lane (administrator) on LANE-PC on 19-11-2013 18:53:45
Running from J:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(iolo technologies, LLC) C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
(Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Wajam) C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Akamai Technologies, Inc.) C:\Users\lane\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\lane\AppData\Local\Akamai\netsession_win.exe
(NETGEAR) C:\Program Files (x86)\NETGEAR\WN111v2\WN111v2.exe
() C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
() C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE
(Microsoft Corporation) C:\windows\System32\MsSpellCheckingFacility.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11545192 2010-11-02] (Realtek Semiconductor)
HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] ()
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\lane\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path)
HKCU\...\Winlogon: [Shell] explorer.exe,C:\Users\lane\AppData\Roaming\skype.dat <==== ATTENTION
MountPoints2: {5820c856-37ef-11e1-9c7c-001374000000} - I:\picasa36-setup.exe
HKLM-x32\...\Run: [LogitechQuickCamRibbon] - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2793304 2009-10-14] ()
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-23] (Apple Inc.)
BootExecute:

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wcpatriots.com/
SearchScopes: HKLM - DefaultScope {5807584B-75B6-465D-88B0-3C4AC684276C} URL = http://www.bing.com/...rc=IE-SearchBox
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope {B28BFB32-206E-411B-98E4-4B3063A29E5E} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {B28BFB32-206E-411B-98E4-4B3063A29E5E} URL = http://search.condui...4492333631&UM=2
SearchScopes: HKCU - {5807584B-75B6-465D-88B0-3C4AC684276C} URL =
SearchScopes: HKCU - {588DC6FA-1C10-42B2-B940-8F13477C7ABF} URL = http://search.condui...q={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKCU - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = http://nortonsafe.se...t=kwd&qsrc=2869
SearchScopes: HKCU - {B28BFB32-206E-411B-98E4-4B3063A29E5E} URL = http://search.condui...4492333631&UM=2
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: No Name - {5F815AD7-A955-4943-91C4-7A96C2932399} - No File
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
BHO-x32: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: SocialRibbons LP2 - {AE92E5DE-20F7-9934-D515-7BE13880A842} - C:\Program Files (x86)\SocialRibbons LP2\Toolbar.dll ()
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo Layers Runtime\YontooIEClient_2.dll (Yontoo LLC)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog9 01 mswsock.dll File Not found ()
Winsock: Catalog9 02 mswsock.dll File Not found ()
Winsock: Catalog9 03 mswsock.dll File Not found ()
Winsock: Catalog9 04 mswsock.dll File Not found ()
Winsock: Catalog9 05 mswsock.dll File Not found ()
Winsock: Catalog9 06 mswsock.dll File Not found ()
Winsock: Catalog9 07 mswsock.dll File Not found ()
Winsock: Catalog9 08 mswsock.dll File Not found ()
Winsock: Catalog9 09 mswsock.dll File Not found ()
Winsock: Catalog9 10 mswsock.dll File Not found ()
Winsock: Catalog5-x64 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog9-x64 01 mswsock.dll File Not found ()
Winsock: Catalog9-x64 02 mswsock.dll File Not found ()
Winsock: Catalog9-x64 03 mswsock.dll File Not found ()
Winsock: Catalog9-x64 04 mswsock.dll File Not found ()
Winsock: Catalog9-x64 05 mswsock.dll File Not found ()
Winsock: Catalog9-x64 06 mswsock.dll File Not found ()
Winsock: Catalog9-x64 07 mswsock.dll File Not found ()
Winsock: Catalog9-x64 08 mswsock.dll File Not found ()
Winsock: Catalog9-x64 09 mswsock.dll File Not found ()
Winsock: Catalog9-x64 10 mswsock.dll File Not found ()

Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

==================== Services (Whitelisted) =================

R2 ioloSystemService; C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe [1053184 2012-12-06] (iolo technologies, LLC)
S3 jswpsapi; C:\Program Files (x86)\NETGEAR\WN111v2\jswpsapi.exe [942080 2008-02-29] (Atheros Communications, Inc.)
R2 N360; C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-20] (Symantec Corporation)
S4 SupportSoft RemoteAssist; C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe [386424 2010-02-24] (SupportSoft, Inc.)
R2 WajamUpdater; C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe [109064 2013-04-22] (Wajam)
U2 *etadpug; "C:\Program Files (x86)\Google\Desktop\Install\{8b4c78af-b05b-cb7e-2657-2193686f06c4}\ \...\???\{8b4c78af-b05b-cb7e-2657-2193686f06c4}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)

==================== Drivers (Whitelisted) ====================

R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20131114.001\BHDrvx64.sys [1524824 2013-10-22] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys [169048 2013-04-15] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-27] (Symantec Corporation)
R1 ElRawDisk; C:\windows\system32\drivers\ElRawDsk.sys [30752 2012-12-06] (EldoS Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-11-12] (Symantec Corporation)
S1 FileDisk; No ImagePath
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20131118.001\IDSvia64.sys [521816 2013-11-11] (Symantec Corporation)
R1 JSWPSLWF; C:\Windows\SysWow64\DRIVERS\jswpslwfx.sys [26624 2008-10-01] (Atheros Communications, Inc.)
R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [15680 2006-11-01] ()
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20131119.001\ENG64.SYS [126040 2013-11-12] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20131119.001\EX64.SYS [2099288 2013-11-12] (Symantec Corporation)
S3 PCAMp50a64; C:\Windows\System32\Drivers\PCAMp50a64.sys [43328 2006-11-29] (Printing Communications Assoc., Inc. (PCAUSA))
R3 PCASp50a64; C:\Windows\System32\Drivers\PCASp50a64.sys [41280 2006-11-29] (Printing Communications Assoc., Inc. (PCAUSA))
R1 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 smserial; C:\Windows\System32\DRIVERS\SmSerl64.sys [1227776 2009-06-10] (Motorola Inc.)
R1 SRTSP; C:\Windows\System32\Drivers\N360x64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS [36952 2013-03-04] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-06-25] (Symantec Corporation)
R1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [43680 2013-03-04] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS [224416 2013-03-04] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1404000.028\SYMNETS.SYS [433752 2013-04-24] (Symantec Corporation)
R3 WN111v2; C:\Windows\System32\DRIVERS\WN111v2w7x.sys [767488 2009-10-21] (Atheros Communications, Inc.)
U2 wuauserv;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-19 18:53 - 2013-11-19 18:53 - 00000000 ____D C:\FRST
2013-11-19 17:54 - 2013-11-19 17:54 - 00004360 _____ C:\{FE37A3F1-5A60-4033-A4F1-C02981FE2832}
2013-11-18 18:28 - 2013-11-18 18:28 - 00004360 _____ C:\{BFDAA923-B25F-4D1F-8025-F341CD8ACB69}
2013-11-18 18:19 - 2013-11-18 18:19 - 00003304 ____N C:\bootsqm.dat
2013-11-15 21:48 - 2013-11-15 21:48 - 00000000 ____D C:\tmp
2013-11-12 22:20 - 2013-10-12 03:45 - 02241536 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-11-12 22:20 - 2013-10-12 03:45 - 01364992 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-11-12 22:20 - 2013-10-12 03:45 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-11-12 22:20 - 2013-10-12 03:43 - 15404544 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-11-12 22:20 - 2013-10-12 03:43 - 03959808 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-11-12 22:20 - 2013-10-12 03:43 - 02648576 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-11-12 22:20 - 2013-10-12 03:43 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-11-12 22:20 - 2013-10-12 03:43 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-11-12 22:20 - 2013-10-12 03:43 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-11-12 22:20 - 2013-10-12 03:43 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-11-12 22:20 - 2013-10-12 03:43 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-11-12 22:20 - 2013-10-12 03:43 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-11-12 22:20 - 2013-10-12 03:43 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-11-12 22:20 - 2013-10-12 02:03 - 01767936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-11-12 22:20 - 2013-10-12 02:03 - 01138176 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-11-12 22:20 - 2013-10-12 02:02 - 13761024 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-11-12 22:20 - 2013-10-12 02:02 - 02877952 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-11-12 22:20 - 2013-10-12 02:02 - 02049024 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-11-12 22:20 - 2013-10-12 02:02 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-11-12 22:20 - 2013-10-12 02:02 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-11-12 22:20 - 2013-10-12 02:02 - 00391168 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-11-12 22:20 - 2013-10-12 02:02 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2013-11-12 22:20 - 2013-10-12 02:02 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2013-11-12 22:20 - 2013-10-12 02:02 - 00039424 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-11-12 22:20 - 2013-10-12 02:02 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2013-11-12 22:20 - 2013-10-12 01:35 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-11-12 22:20 - 2013-10-12 01:08 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-11-12 22:20 - 2013-10-12 00:44 - 00089600 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-11-12 22:20 - 2013-10-12 00:15 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-12 22:19 - 2013-10-12 03:43 - 19269632 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-11-12 22:19 - 2013-10-12 02:02 - 14355968 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-11-12 19:44 - 2013-10-11 21:30 - 00830464 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2013-11-12 19:44 - 2013-10-11 21:29 - 00859648 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2013-11-12 19:44 - 2013-10-11 21:29 - 00324096 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2013-11-12 19:44 - 2013-10-11 21:03 - 00656896 _____ (Microsoft Corporation) C:\windows\SysWOW64\nshwfp.dll
2013-11-12 19:44 - 2013-10-11 21:01 - 00216576 _____ (Microsoft Corporation) C:\windows\SysWOW64\FWPUCLNT.DLL
2013-11-12 19:44 - 2013-10-05 15:25 - 01474048 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-11-12 19:44 - 2013-10-05 14:57 - 01168384 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2013-11-12 19:44 - 2013-10-03 21:28 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll
2013-11-12 19:44 - 2013-10-03 21:25 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\credui.dll
2013-11-12 19:44 - 2013-10-03 21:24 - 01930752 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2013-11-12 19:44 - 2013-10-03 20:58 - 00152576 _____ (Microsoft Corporation) C:\windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-12 19:44 - 2013-10-03 20:56 - 01796096 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2013-11-12 19:44 - 2013-10-03 20:56 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\credui.dll
2013-11-12 19:44 - 2013-10-02 21:23 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2013-11-12 19:44 - 2013-10-02 21:00 - 00311808 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2013-11-12 19:44 - 2013-09-27 20:09 - 00497152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2013-11-12 19:44 - 2013-09-24 21:26 - 00154560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2013-11-12 19:44 - 2013-09-24 21:26 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2013-11-12 19:44 - 2013-09-24 21:23 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2013-11-12 19:44 - 2013-09-24 21:23 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2013-11-12 19:44 - 2013-09-24 21:23 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2013-11-12 19:44 - 2013-09-24 21:22 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2013-11-12 19:44 - 2013-09-24 21:21 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2013-11-12 19:44 - 2013-09-24 21:21 - 00307200 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2013-11-12 19:44 - 2013-09-24 20:58 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2013-11-12 19:44 - 2013-09-24 20:57 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2013-11-12 19:44 - 2013-09-24 20:57 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2013-11-12 19:44 - 2013-09-24 20:56 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2013-11-12 19:44 - 2013-09-24 20:03 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2013-11-12 19:44 - 2013-07-04 07:18 - 00458712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2013-11-12 17:41 - 2013-11-12 17:41 - 00000000 ____D C:\ProgramData\qtoenam
2013-11-12 17:40 - 2013-11-12 19:26 - 00000000 ____D C:\ProgramData\nvhrasu
2013-11-12 17:40 - 2013-11-12 19:20 - 00000000 ____D C:\ProgramData\aaodcif
2013-11-12 17:40 - 2013-11-12 19:19 - 00000000 ____D C:\ProgramData\atkisx
2013-11-11 22:26 - 2013-11-12 19:20 - 00000000 ____D C:\ProgramData\vdmers
2013-11-11 18:47 - 2013-11-11 18:47 - 00000000 ____D C:\Users\lane\AppData\Roaming\UpdaterEX
2013-11-06 22:28 - 2013-11-06 22:28 - 00000000 ____D C:\Users\lane\.thumbnails
2013-11-06 22:26 - 2013-11-06 22:26 - 00001899 _____ C:\Users\Public\Desktop\Blender.lnk
2013-11-06 22:26 - 2013-11-06 22:26 - 00000000 ____D C:\Program Files\Blender Foundation
2013-11-05 17:24 - 2013-11-05 17:24 - 00000000 ____D C:\Users\lane\AppData\Local\backburner
2013-11-04 21:09 - 2013-11-04 21:09 - 00000000 ____D C:\Program Files (x86)\Autodesk
2013-11-04 20:59 - 2013-11-04 20:59 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared
2013-11-04 20:53 - 2013-11-17 19:11 - 00000000 ____D C:\Program Files\Autodesk
2013-11-04 20:53 - 2013-11-04 21:13 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared
2013-11-04 20:32 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_7.dll
2013-11-04 20:32 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_7.dll
2013-11-04 20:32 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_7.dll
2013-11-04 20:32 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_7.dll
2013-11-04 20:32 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_5.dll
2013-11-04 20:32 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_5.dll
2013-11-04 20:32 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_43.dll
2013-11-04 20:32 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_43.dll
2013-11-04 20:32 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_43.dll
2013-11-04 20:32 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_43.dll
2013-11-04 20:32 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\windows\system32\d3dcsx_43.dll
2013-11-04 20:32 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dcsx_43.dll
2013-11-04 20:32 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_43.dll
2013-11-04 20:32 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_43.dll
2013-11-04 20:32 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\windows\system32\d3dx11_43.dll
2013-11-04 20:32 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx11_43.dll
2013-11-04 20:32 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_6.dll
2013-11-04 20:32 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_6.dll
2013-11-04 20:32 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_6.dll
2013-11-04 20:32 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_6.dll
2013-11-04 20:32 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_4.dll
2013-11-04 20:32 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_4.dll
2013-11-04 20:32 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_7.dll
2013-11-04 20:32 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_7.dll
2013-11-04 20:32 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_5.dll
2013-11-04 20:32 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_5.dll
2013-11-04 20:32 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_5.dll
2013-11-04 20:32 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_5.dll
2013-11-04 20:32 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_3.dll
2013-11-04 20:32 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_3.dll
2013-11-04 20:32 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\windows\system32\d3dcsx_42.dll
2013-11-04 20:32 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dcsx_42.dll
2013-11-04 20:32 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_42.dll
2013-11-04 20:32 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_42.dll
2013-11-04 20:32 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_42.dll
2013-11-04 20:32 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\windows\system32\d3dx11_42.dll
2013-11-04 20:32 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_4.dll
2013-11-04 20:32 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_4.dll
2013-11-04 20:32 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_4.dll
2013-11-04 20:32 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_4.dll
2013-11-04 20:32 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_6.dll
2013-11-04 20:32 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_6.dll
2013-11-04 20:32 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_41.dll
2013-11-04 20:32 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_41.dll
2013-11-04 20:32 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_41.dll
2013-11-04 20:32 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_41.dll
2013-11-04 20:32 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_41.dll
2013-11-04 20:32 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_41.dll
2013-11-04 20:32 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_3.dll
2013-11-04 20:32 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_3.dll
2013-11-04 20:32 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_3.dll
2013-11-04 20:32 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_3.dll
2013-11-04 20:32 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_2.dll
2013-11-04 20:32 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_2.dll
2013-11-04 20:32 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_5.dll
2013-11-04 20:32 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_5.dll
2013-11-04 20:32 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_40.dll
2013-11-04 20:32 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_40.dll
2013-11-04 20:32 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_40.dll
2013-11-04 20:32 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_40.dll
2013-11-04 20:32 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_40.dll
2013-11-04 20:32 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_40.dll
2013-11-04 20:32 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_2.dll
2013-11-04 20:32 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_2.dll
2013-11-04 20:32 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_1.dll
2013-11-04 20:32 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_1.dll
2013-11-04 20:32 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_2.dll
2013-11-04 20:32 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_2.dll
2013-11-04 20:32 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_39.dll
2013-11-04 20:32 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_39.dll
2013-11-04 20:32 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_39.dll
2013-11-04 20:32 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_39.dll
2013-11-04 20:32 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_39.dll
2013-11-04 20:32 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_39.dll
2013-11-04 20:32 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_1.dll
2013-11-04 20:32 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_1.dll
2013-11-04 20:32 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_1.dll
2013-11-04 20:32 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_1.dll
2013-11-04 20:32 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_0.dll
2013-11-04 20:32 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_0.dll
2013-11-04 20:32 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_4.dll
2013-11-04 20:32 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_4.dll
2013-11-04 20:32 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_38.dll
2013-11-04 20:32 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_38.dll
2013-11-04 20:32 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_38.dll
2013-11-04 20:32 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_38.dll
2013-11-04 20:32 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_38.dll
2013-11-04 20:32 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_38.dll
2013-11-04 20:32 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_0.dll
2013-11-04 20:32 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_0.dll
2013-11-04 20:32 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_0.dll
2013-11-04 20:32 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_0.dll
2013-11-04 20:32 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_3.dll
2013-11-04 20:32 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_3.dll
2013-11-04 20:32 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_37.dll
2013-11-04 20:32 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_37.dll
2013-11-04 20:32 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_37.dll
2013-11-04 20:32 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_37.dll
2013-11-04 20:32 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_37.dll
2013-11-04 20:32 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_37.dll
2013-11-04 20:32 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_10.dll
2013-11-04 20:32 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_10.dll
2013-11-04 20:32 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_2.dll
2013-11-04 20:32 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_2.dll
2013-11-04 20:32 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_36.dll
2013-11-04 20:32 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_36.dll
2013-11-04 20:32 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_36.dll
2013-11-04 20:32 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_36.dll
2013-11-04 20:32 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_36.dll
2013-11-04 20:32 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_36.dll
2013-11-04 20:32 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_9.dll
2013-11-04 20:32 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_9.dll
2013-11-04 20:32 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_35.dll
2013-11-04 20:32 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_35.dll
2013-11-04 20:32 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_35.dll
2013-11-04 20:32 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_35.dll
2013-11-04 20:32 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_35.dll
2013-11-04 20:32 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_35.dll
2013-11-04 20:32 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_8.dll
2013-11-04 20:32 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_8.dll
2013-11-04 20:32 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_34.dll
2013-11-04 20:32 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_34.dll
2013-11-04 20:32 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_34.dll
2013-11-04 20:32 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_34.dll
2013-11-04 20:32 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_34.dll
2013-11-04 20:32 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_34.dll
2013-11-04 20:32 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_7.dll
2013-11-04 20:32 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_7.dll
2013-11-04 20:32 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\windows\system32\xinput1_3.dll
2013-11-04 20:32 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\windows\SysWOW64\xinput1_3.dll
2013-11-04 20:32 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_33.dll
2013-11-04 20:32 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_33.dll
2013-11-04 20:32 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_33.dll
2013-11-04 20:32 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_33.dll
2013-11-04 20:32 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_33.dll
2013-11-04 20:32 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_6.dll
2013-11-04 20:32 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_6.dll
2013-11-04 20:32 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_5.dll
2013-11-04 20:32 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_5.dll
2013-11-04 20:32 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\windows\system32\d3dx10.dll
2013-11-04 20:32 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10.dll
2013-11-04 20:31 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\windows\system32\x3daudio1_1.dll
2013-11-04 20:31 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\windows\SysWOW64\x3daudio1_1.dll
2013-11-04 20:31 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_31.dll
2013-11-04 20:31 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_31.dll
2013-11-04 20:31 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_4.dll
2013-11-04 20:31 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_4.dll
2013-11-04 20:31 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\windows\system32\xinput1_2.dll
2013-11-04 20:31 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_3.dll
2013-11-04 20:31 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_3.dll
2013-11-04 20:31 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\windows\SysWOW64\xinput1_2.dll
2013-11-04 20:31 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_2.dll
2013-11-04 20:31 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_2.dll
2013-11-04 20:31 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_30.dll
2013-11-04 20:31 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_30.dll
2013-11-04 20:31 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_1.dll
2013-11-04 20:31 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_1.dll
2013-11-04 20:31 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\windows\system32\xinput1_1.dll
2013-11-04 20:31 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\windows\SysWOW64\xinput1_1.dll
2013-11-04 20:31 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_29.dll
2013-11-04 20:31 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_29.dll
2013-11-04 20:31 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_0.dll
2013-11-04 20:31 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_0.dll
2013-11-04 20:31 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\windows\system32\x3daudio1_0.dll
2013-11-04 20:31 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\windows\SysWOW64\x3daudio1_0.dll
2013-11-04 20:31 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_28.dll
2013-11-04 20:31 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_28.dll
2013-11-04 20:31 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_27.dll
2013-11-04 20:31 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_27.dll
2013-11-04 20:31 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_26.dll
2013-11-04 20:31 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_26.dll
2013-11-04 20:31 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_25.dll
2013-11-04 20:31 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_25.dll
2013-11-04 20:31 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_24.dll
2013-11-04 20:31 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_24.dll
2013-11-04 20:16 - 2013-11-04 20:56 - 00000000 ____D C:\ProgramData\Autodesk
2013-11-04 20:16 - 2013-11-04 20:16 - 00000000 ____D C:\Users\lane\AppData\Roaming\Autodesk
2013-11-04 20:15 - 2013-11-12 19:26 - 00000000 ____D C:\Users\lane\AppData\Local\Akamai
2013-11-04 20:15 - 2013-11-04 20:15 - 00000000 ____D C:\Autodesk
2013-11-03 18:44 - 2013-11-03 18:44 - 00001785 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-11-03 18:43 - 2013-11-03 18:44 - 00000000 ____D C:\Program Files\iTunes
2013-11-03 18:43 - 2013-11-03 18:43 - 00000000 ____D C:\Program Files\iPod
2013-11-03 18:39 - 2013-11-03 18:39 - 00001847 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
2013-11-03 18:39 - 2013-11-03 18:39 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-11-02 12:29 - 2013-11-02 12:29 - 00176940 _____ C:\Users\lane\Downloads\BFE.reg
2013-11-02 12:28 - 2013-11-02 12:28 - 00006396 _____ C:\Users\lane\Downloads\MpsSvc.reg
2013-11-02 12:09 - 2013-11-02 12:09 - 00347440 _____ (Microsoft Corporation) C:\Users\lane\Downloads\MicrosoftFixit-portable.exe
2013-11-02 11:29 - 2013-11-02 11:29 - 00347304 _____ (Microsoft Corporation) C:\Users\lane\Downloads\MicrosoftFixit.WindowsFirewall.RNP.131306839614491013.5.3.Run.exe
2013-11-02 11:25 - 2013-11-02 11:25 - 00347304 _____ (Microsoft Corporation) C:\Users\lane\Downloads\MicrosoftFixit.WindowsFirewall.RNP.131306839614491013.5.1.Run.exe
2013-11-02 11:18 - 2013-11-02 11:18 - 00347304 _____ (Microsoft Corporation) C:\Users\lane\Downloads\MicrosoftFixit.WindowsFirewall.RNP.131306839614491013.1.3.Run.exe
2013-11-02 10:59 - 2013-11-02 10:59 - 03053496 _____ (Symantec Corporation) C:\Users\lane\Downloads\NPE (1).exe
2013-11-02 10:57 - 2013-11-02 10:58 - 03053496 ____N (Symantec Corporation) C:\Users\lane\Downloads\NPE.exe
2013-10-30 17:44 - 2013-10-30 17:44 - 00002224 _____ C:\{C98DFB5A-E521-4891-AFA8-874809BA5B1D}
2013-10-30 17:34 - 2013-10-30 17:34 - 00002480 _____ C:\{360FB33A-1B77-44E9-BBEB-3D6F605B4742}
2013-10-30 17:21 - 2013-10-30 17:21 - 00002624 _____ C:\{CAD3CF24-ADDA-4655-BCEC-A35849E06F71}
2013-10-26 15:13 - 2013-10-26 15:14 - 00000004 _____ C:\Users\lane\AppData\Roaming\skype.ini

==================== One Month Modified Files and Folders =======

2013-11-19 18:53 - 2013-11-19 18:53 - 00000000 ____D C:\FRST
2013-11-19 18:53 - 2010-12-25 15:00 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-19 18:41 - 2009-07-13 23:45 - 00010240 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-19 18:41 - 2009-07-13 23:45 - 00010240 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-19 18:37 - 2009-07-14 00:13 - 00793416 _____ C:\windows\system32\PerfStringBackup.INI
2013-11-19 18:28 - 2012-05-21 20:37 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-11-19 18:28 - 2010-12-30 20:16 - 00000000 ____D C:\Users\lane\AppData\Roaming\Skype
2013-11-19 17:54 - 2013-11-19 17:54 - 00004360 _____ C:\{FE37A3F1-5A60-4033-A4F1-C02981FE2832}
2013-11-19 17:53 - 2010-12-25 15:00 - 00000890 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-19 16:44 - 2012-11-22 23:29 - 00012700 _____ C:\windows\setupact.log
2013-11-19 16:44 - 2010-03-01 17:47 - 02032028 _____ C:\windows\PFRO.log
2013-11-19 16:44 - 2009-07-14 00:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-11-18 19:40 - 2010-12-15 14:31 - 01513517 _____ C:\windows\WindowsUpdate.log
2013-11-18 18:28 - 2013-11-18 18:28 - 00004360 _____ C:\{BFDAA923-B25F-4D1F-8025-F341CD8ACB69}
2013-11-18 18:26 - 2010-12-25 11:24 - 00000000 ____D C:\Users\lane
2013-11-18 18:19 - 2013-11-18 18:19 - 00003304 ____N C:\bootsqm.dat
2013-11-17 20:26 - 2011-01-17 14:02 - 00000000 ____D C:\Users\lane\AppData\Local\CrashDumps
2013-11-17 19:52 - 2010-12-25 15:00 - 00000000 ____D C:\Users\lane\AppData\Local\Google
2013-11-17 19:52 - 2010-12-25 15:00 - 00000000 ____D C:\ProgramData\Google
2013-11-17 19:52 - 2010-12-25 15:00 - 00000000 ____D C:\Program Files (x86)\Google
2013-11-17 19:11 - 2013-11-04 20:53 - 00000000 ____D C:\Program Files\Autodesk
2013-11-15 21:48 - 2013-11-15 21:48 - 00000000 ____D C:\tmp
2013-11-14 18:45 - 2009-07-13 22:20 - 00000000 ____D C:\windows\rescache
2013-11-13 17:05 - 2012-05-21 20:37 - 00003768 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-11-13 17:04 - 2012-05-21 20:37 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-11-13 17:04 - 2011-11-29 00:05 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-13 17:04 - 2011-01-22 21:39 - 00000000 ____D C:\Users\lane\AppData\Local\Adobe
2013-11-12 22:18 - 2013-07-12 02:01 - 00000000 ____D C:\windows\system32\MRT
2013-11-12 22:11 - 2012-01-29 15:52 - 82896128 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-11-12 19:31 - 2009-07-13 22:20 - 00000000 ____D C:\windows\system32\NDF
2013-11-12 19:26 - 2013-11-12 17:40 - 00000000 ____D C:\ProgramData\nvhrasu
2013-11-12 19:26 - 2013-11-04 20:15 - 00000000 ____D C:\Users\lane\AppData\Local\Akamai
2013-11-12 19:26 - 2013-10-09 15:20 - 00000000 ____D C:\Users\lane\AppData\Roaming\jvhdutft
2013-11-12 19:26 - 2012-08-28 21:56 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-11-12 19:26 - 2011-02-13 10:26 - 00000000 __RSD C:\Users\lane\Documents\My Stationery
2013-11-12 19:26 - 2011-01-11 11:09 - 00000000 ____D C:\Users\lane\AppData\Roaming\SoftGrid Client
2013-11-12 19:26 - 2010-12-30 20:16 - 00000000 ____D C:\ProgramData\Skype
2013-11-12 19:26 - 2010-03-01 17:46 - 00000000 ____D C:\ProgramData\Norton
2013-11-12 19:26 - 2009-07-13 22:20 - 00000000 ____D C:\windows\registration
2013-11-12 19:20 - 2013-11-12 17:40 - 00000000 ____D C:\ProgramData\aaodcif
2013-11-12 19:20 - 2013-11-11 22:26 - 00000000 ____D C:\ProgramData\vdmers
2013-11-12 19:19 - 2013-11-12 17:40 - 00000000 ____D C:\ProgramData\atkisx
2013-11-12 17:41 - 2013-11-12 17:41 - 00000000 ____D C:\ProgramData\qtoenam
2013-11-11 18:47 - 2013-11-11 18:47 - 00000000 ____D C:\Users\lane\AppData\Roaming\UpdaterEX
2013-11-09 08:22 - 2009-07-14 00:08 - 00032532 _____ C:\windows\Tasks\SCHEDLGU.TXT
2013-11-06 22:28 - 2013-11-06 22:28 - 00000000 ____D C:\Users\lane\.thumbnails
2013-11-06 22:26 - 2013-11-06 22:26 - 00001899 _____ C:\Users\Public\Desktop\Blender.lnk
2013-11-06 22:26 - 2013-11-06 22:26 - 00000000 ____D C:\Program Files\Blender Foundation
2013-11-05 20:11 - 2011-01-11 11:08 - 00787504 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2013-11-05 17:24 - 2013-11-05 17:24 - 00000000 ____D C:\Users\lane\AppData\Local\backburner
2013-11-04 21:13 - 2013-11-04 20:53 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared
2013-11-04 21:09 - 2013-11-04 21:09 - 00000000 ____D C:\Program Files (x86)\Autodesk
2013-11-04 20:59 - 2013-11-04 20:59 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared
2013-11-04 20:56 - 2013-11-04 20:16 - 00000000 ____D C:\ProgramData\Autodesk
2013-11-04 20:16 - 2013-11-04 20:16 - 00000000 ____D C:\Users\lane\AppData\Roaming\Autodesk
2013-11-04 20:15 - 2013-11-04 20:15 - 00000000 ____D C:\Autodesk
2013-11-03 18:44 - 2013-11-03 18:44 - 00001785 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-11-03 18:44 - 2013-11-03 18:43 - 00000000 ____D C:\Program Files\iTunes
2013-11-03 18:44 - 2012-11-20 19:57 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-11-03 18:43 - 2013-11-03 18:43 - 00000000 ____D C:\Program Files\iPod
2013-11-03 18:43 - 2011-03-13 20:45 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-11-03 18:39 - 2013-11-03 18:39 - 00001847 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
2013-11-03 18:39 - 2013-11-03 18:39 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-11-02 12:29 - 2013-11-02 12:29 - 00176940 _____ C:\Users\lane\Downloads\BFE.reg
2013-11-02 12:28 - 2013-11-02 12:28 - 00006396 _____ C:\Users\lane\Downloads\MpsSvc.reg
2013-11-02 12:09 - 2013-11-02 12:09 - 00347440 _____ (Microsoft Corporation) C:\Users\lane\Downloads\MicrosoftFixit-portable.exe
2013-11-02 11:29 - 2013-11-02 11:29 - 00347304 _____ (Microsoft Corporation) C:\Users\lane\Downloads\MicrosoftFixit.WindowsFirewall.RNP.131306839614491013.5.3.Run.exe
2013-11-02 11:25 - 2013-11-02 11:25 - 00347304 _____ (Microsoft Corporation) C:\Users\lane\Downloads\MicrosoftFixit.WindowsFirewall.RNP.131306839614491013.5.1.Run.exe
2013-11-02 11:18 - 2013-11-02 11:18 - 00347304 _____ (Microsoft Corporation) C:\Users\lane\Downloads\MicrosoftFixit.WindowsFirewall.RNP.131306839614491013.1.3.Run.exe
2013-11-02 11:09 - 2013-04-01 11:21 - 00000000 ____D C:\Users\lane\AppData\Local\NPE
2013-11-02 10:59 - 2013-11-02 10:59 - 03053496 _____ (Symantec Corporation) C:\Users\lane\Downloads\NPE (1).exe
2013-11-02 10:58 - 2013-11-02 10:57 - 03053496 ____N (Symantec Corporation) C:\Users\lane\Downloads\NPE.exe
2013-10-30 17:44 - 2013-10-30 17:44 - 00002224 _____ C:\{C98DFB5A-E521-4891-AFA8-874809BA5B1D}
2013-10-30 17:34 - 2013-10-30 17:34 - 00002480 _____ C:\{360FB33A-1B77-44E9-BBEB-3D6F605B4742}
2013-10-30 17:21 - 2013-10-30 17:21 - 00002624 _____ C:\{CAD3CF24-ADDA-4655-BCEC-A35849E06F71}
2013-10-26 15:14 - 2013-10-26 15:13 - 00000004 _____ C:\Users\lane\AppData\Roaming\skype.ini
ZeroAccess:
C:\Users\lane\AppData\Local\Google\Desktop\Install

ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini

ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini

Files to move or delete:
====================
C:\Users\lane\AppData\Roaming\skype.ini


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Windows\system64


LastRegBack: 2013-11-10 12:03

==================== End Of Log ============================Attached File  Addition.txt   17.66KB   41 downloads
  • 0

#8
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,958 posts
Download the enclosed file. Attached File  fixlist.txt   3.37KB   73 downloads

Save it next to FRST.

Run FRST and click on the Fix button. Wait until finished.

The tool will make a log next to FRST (Fixlog.txt). Please post it to your reply.

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.

  • 0

#9
manager1996

manager1996

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-11-2013
Ran by lane at 2013-11-20 19:50:13 Run:1
Running from J:\
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path)
HKCU\...\Winlogon: [Shell] explorer.exe,C:\Users\lane\AppData\Roaming\skype.dat <==== ATTENTION
MountPoints2: {5820c856-37ef-11e1-9c7c-001374000000} - I:\picasa36-setup.exe
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: No Name - {5F815AD7-A955-4943-91C4-7A96C2932399} - No File
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog9 01 mswsock.dll File Not found ()
Winsock: Catalog9 02 mswsock.dll File Not found ()
Winsock: Catalog9 03 mswsock.dll File Not found ()
Winsock: Catalog9 04 mswsock.dll File Not found ()
Winsock: Catalog9 05 mswsock.dll File Not found ()
Winsock: Catalog9 06 mswsock.dll File Not found ()
Winsock: Catalog9 07 mswsock.dll File Not found ()
Winsock: Catalog9 08 mswsock.dll File Not found ()
Winsock: Catalog9 09 mswsock.dll File Not found ()
Winsock: Catalog9 10 mswsock.dll File Not found ()
Winsock: Catalog5-x64 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog9-x64 01 mswsock.dll File Not found ()
Winsock: Catalog9-x64 02 mswsock.dll File Not found ()
Winsock: Catalog9-x64 03 mswsock.dll File Not found ()
Winsock: Catalog9-x64 04 mswsock.dll File Not found ()
Winsock: Catalog9-x64 05 mswsock.dll File Not found ()
Winsock: Catalog9-x64 06 mswsock.dll File Not found ()
Winsock: Catalog9-x64 07 mswsock.dll File Not found ()
Winsock: Catalog9-x64 08 mswsock.dll File Not found ()
Winsock: Catalog9-x64 09 mswsock.dll File Not found ()
Winsock: Catalog9-x64 10 mswsock.dll File Not found ()
U2 *etadpug; "C:\Program Files (x86)\Google\Desktop\Install\{8b4c78af-b05b-cb7e-2657-2193686f06c4}\ \...\???\{8b4c78af-b05b-cb7e-2657-2193686f06c4}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)
C:\Users\lane\AppData\Local\Google\Desktop\Install
C:\Windows\assembly\GAC_64\Desktop.ini
C:\Users\lane\AppData\Roaming\skype.ini
DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
DeleteJunctionsIndirectory: C:\Windows\system64
Task: {02CA3CAE-8142-4E41-9140-23086B2244C7} - System32\Tasks\{3D931536-43B4-4709-A6A1-C59CA1C13691} => C:\Westwood\RA2\Ra2.exe [2000-09-26] ()
Task: {6F7032D0-0678-46A7-8D36-FF229BA10B4C} - System32\Tasks\{2EF33553-B273-4AD9-BD0A-508BCA822D4F} => C:\Westwood\RA2\Ra2.exe [2000-09-26] ()
Task: {7E1EB7B8-F42C-43DB-9EB8-F589596B5FDE} - System32\Tasks\{62CEA84A-78B2-4AC7-B9DC-F40372E4E2AE} => C:\Westwood\RA2\Ra2.exe [2000-09-26] ()
Task: {A17FBFDC-3F20-4933-ABF7-6A0A5E63FA1F} - System32\Tasks\{A2F68EC7-515C-4909-A46E-3FF81754E03D} => C:\Westwood\RA2\Ra2.exe [2000-09-26] ()
Task: {BA5F9672-84ED-49C6-9DC5-ED051345FB7E} - System32\Tasks\{84509B6D-7217-4C31-896C-EA14B1FD114E} => C:\Westwood\RA2\Ra2.exe [2000-09-26] ()
Hosts: Hosts file not detected in the default directory
End
*****************

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update* => Value deleted successfully.
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5820c856-37ef-11e1-9c7c-001374000000} => Key deleted successfully.
HKCR\CLSID\{5820c856-37ef-11e1-9c7c-001374000000} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5F815AD7-A955-4943-91C4-7A96C2932399} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{5F815AD7-A955-4943-91C4-7A96C2932399} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => Value deleted successfully.
HKCR\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => Value deleted successfully.
HKCR\Wow6432Node\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} => Key deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Value deleted successfully.
HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found.
Winsock: Catalog5 entry 000000000001\\LibraryPath was set successfully to %SystemRoot%\system32\NLAapi.dll
Winsock: Catalog5 entry 000000000005\\LibraryPath was set successfully to %SystemRoot%\System32\mswsock.dll
The possible legit Catalog entry 000000000001 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000002 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000003 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000004 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000005 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000006 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000007 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000008 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000009 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000010 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
Winsock: Catalog5-x64 entry 000000000001\\LibraryPath was set successfully to %SystemRoot%\system32\NLAapi.dll
Winsock: Catalog5-x64 entry 000000000005\\LibraryPath was set successfully to %SystemRoot%\System32\mswsock.dll
The possible legit Catalog entry 000000000001 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000002 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000003 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000004 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000005 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000006 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000007 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000008 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000009 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
The possible legit Catalog entry 000000000010 will not be deleted with FRST. Instead, "netsh winsock reset" can be used.
*etadpug => Service deleted successfully.
C:\Users\lane\AppData\Local\Google\Desktop\Install => Moved successfully.
C:\Windows\assembly\GAC_64\Desktop.ini => Moved successfully.
C:\Users\lane\AppData\Roaming\skype.ini => Moved successfully.
"C:\Program Files\Windows Defender" => Deleting reparse point and unlocking started.
"C:\Program Files\Windows Defender\en-US" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpAsDesc.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpClient.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpCmdRun.exe" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpCommu.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpEvMsg.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpOAV.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpRTP.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpSvc.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MSASCui.exe" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MsMpCom.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MsMpLics.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MsMpRes.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender" => Deleting reparse point and unlocking completed.
"C:\Windows\system64" => Deleting reparse point and unlocking started.
"C:\Windows\system64" => Deleting reparse point and unlocking done.
"C:\Windows\system64" => Deleting reparse point and unlocking completed.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{02CA3CAE-8142-4E41-9140-23086B2244C7} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02CA3CAE-8142-4E41-9140-23086B2244C7} => Key deleted successfully.
C:\Windows\System32\Tasks\{3D931536-43B4-4709-A6A1-C59CA1C13691} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3D931536-43B4-4709-A6A1-C59CA1C13691} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6F7032D0-0678-46A7-8D36-FF229BA10B4C} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F7032D0-0678-46A7-8D36-FF229BA10B4C} => Key deleted successfully.
C:\Windows\System32\Tasks\{2EF33553-B273-4AD9-BD0A-508BCA822D4F} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2EF33553-B273-4AD9-BD0A-508BCA822D4F} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7E1EB7B8-F42C-43DB-9EB8-F589596B5FDE} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7E1EB7B8-F42C-43DB-9EB8-F589596B5FDE} => Key deleted successfully.
C:\Windows\System32\Tasks\{62CEA84A-78B2-4AC7-B9DC-F40372E4E2AE} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{62CEA84A-78B2-4AC7-B9DC-F40372E4E2AE} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A17FBFDC-3F20-4933-ABF7-6A0A5E63FA1F} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A17FBFDC-3F20-4933-ABF7-6A0A5E63FA1F} => Key deleted successfully.
C:\Windows\System32\Tasks\{A2F68EC7-515C-4909-A46E-3FF81754E03D} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A2F68EC7-515C-4909-A46E-3FF81754E03D} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BA5F9672-84ED-49C6-9DC5-ED051345FB7E} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BA5F9672-84ED-49C6-9DC5-ED051345FB7E} => Key deleted successfully.
C:\Windows\System32\Tasks\{84509B6D-7217-4C31-896C-EA14B1FD114E} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{84509B6D-7217-4C31-896C-EA14B1FD114E} => Key deleted successfully.
Hosts was reset successfully.

==== End of Fixlog ====
  • 0

#10
manager1996

manager1996

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
Farbar Service Scanner Version: 10-11-2013
Ran by lane (administrator) on 20-11-2013 at 19:53:17
Running from "C:\Users\lane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q8KHSBPC"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.

MpsSvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.

bfe Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.


Firewall Disabled Policy:
==================
"HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile" registry key does not exist.


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

wscsvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.

Action Center Notification Icon =====> HKLM\...\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A}\\"AutoStart" value does not exist.


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is OK.
Checking ImagePath: ATTENTION!=====> Unable to retrieve ImagePath of wuauserv. The value does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.

BITS Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.


Windows Autoupdate Disabled Policy:
============================


Other Services:
==============
Checking Start type iphlpsvc: ATTENTION!=====> Unable to retrieve start type of iphlpsvc. The value does not exist.
Checking ImagePath of iphlpsvc: ATTENTION!=====> Unable to retrieve ImagePath of iphlpsvc. The value does not exist.
Checking ServiceDll of iphlpsvc: ATTENTION!=====> Unable to retrieve ServiceDll of iphlpsvc. The value does not exist.
Checking Start type of SharedAccess: ATTENTION!=====> Unable to retrieve start type of SharedAccess. The value does not exist.
Checking ImagePath of SharedAccess: ATTENTION!=====> Unable to retrieve ImagePath of SharedAccess. The value does not exist.
Checking ServiceDll of SharedAccess: ATTENTION!=====> Unable to retrieve ServiceDll of SharedAccess. The value does not exist.
Checking FirewallRules of SharedAccess: ATTENTION!=====> Unable to open "SharedAccess\Defaults\FirewallPolicy\FirewallRules" registry key. The key does not exist.
Checking Start type of PolicyAgent: ATTENTION!=====> Unable to open PolicyAgent registry key. The service key does not exist.
Checking ImagePath of PolicyAgent: ATTENTION!=====> Unable to open PolicyAgent registry key. The service key does not exist.
Checking ServiceDll of PolicyAgent: ATTENTION!=====> Unable to open PolicyAgent registry key. The service key does not exist.

Checking Start type of RemoteAccess: ATTENTION!=====> Unable to open RemoteAccess registry key. The service key does not exist.
Checking ImagePath of RemoteAccess: ATTENTION!=====> Unable to open RemoteAccess registry key. The service key does not exist.
Checking ServiceDll of RemoteAccess: ATTENTION!=====> Unable to open RemoteAccess registry key. The service key does not exist.



File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys
[2013-11-12 19:44] - [2013-09-27 20:09] - 0497152 ____A (Microsoft Corporation) 79059559E89D06E8B80CE2944BE20228

C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2013-10-09 15:21] - [2013-09-07 21:30] - 1903552 ____A (Microsoft Corporation) 40AF23633D197905F03AB5628C558C51

C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****
  • 0

Advertisements


#11
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,958 posts
Open an administrator Command Prompt. (Click on the Orb, type CMD and press CTRL+SHIFT+Enter.)

At the prompt type the following and press Enter:

netsh winsock reset

Restart the computer when prompted.

Download Services Repair tool, available here, and save it to your Desktop. Right click on it and select Run As Administrator, follow the prompts. It should reboot when it finishes. If not, please reboot it yourself.

Please re-run the Farbar Service Scanner and post its report.

Are you still having issues downloading or online?
  • 0

#12
manager1996

manager1996

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
The command prompt is saying:
The following helper DLL cannot be loaded: WSHELPER.DLL.
The following command was not found: winsock reset.

Just to let you know I will be on between 4:00pm - 9:00pm today/tomorrow

Edited by manager1996, 21 November 2013 - 03:58 PM.

  • 0

#13
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,958 posts
Run FRST as you did before.

Type the following in the edit box on FRST, after "Search:".

WSHELPER.DLL

It then should look like:

Search: WSHELPER.DLL

Click Search button and post the log (Search.txt) it makes next to FRST in your next reply.
  • 0

#14
manager1996

manager1996

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
Farbar Recovery Scan Tool (x64) Version: 18-11-2013
Ran by lane at 2013-11-21 20:29:49
Running from J:\
Boot Mode: Normal

================== Search: "WSHELPER.DLL" ===================

C:\Windows\winsxs\wow64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6ace9e67456cc40b\wshelper.dll
[2009-07-13 18:55] - [2009-07-13 20:16] - 0015360 ____A (Microsoft Corporation) 5B90BB3171504C9DAF3C5CB44B203CA7

C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\wshelper.dll
[2009-07-13 19:10] - [2009-07-13 20:41] - 0019968 ____A (Microsoft Corporation) D314DA4B0B8DCD023D547FC568E34FB6

C:\Windows\SysWOW64\wshelper.dll
[2009-07-13 18:55] - [2009-07-13 20:16] - 0015360 ____A (Microsoft Corporation) 5B90BB3171504C9DAF3C5CB44B203CA7

C:\Windows\System32\wshelper.dll
[2009-07-13 19:10] - [2009-07-13 20:41] - 0019968 ____A (Microsoft Corporation) D314DA4B0B8DCD023D547FC568E34FB6

====== End Of Search ======
  • 0

#15
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,958 posts
The file is in its place. Lets scan the computer.

Posted Image Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Download : ADWCleaner to your desktop.

NOTE: If using Internet Explorer and get an alert that stops the program downloading, click on the warning and allow the download to complete.

Close all programs and click on the AdwCleaner icon.

Posted Image

Click on Scan and follow the prompts. Let it run unhindered. When done, click on the Clean button, and follow the prompts. Allow the system to reboot. You will then be presented with the report. Copy & Paste this report on your next reply.

The report will be saved in the C:\AdwCleaner folder. as AdwCleaner[S0].txt

Posted Image Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP