Thanks for the help so far. Now the only issue I have is that my home page has been changed to:
hxxp://www.searchnu.com/406 If I try and change it to anything else, I go back to having no connection to the internet. Here are the logs from what I ran.
ComboFix 12-11-14.01 - Scott 11/16/2012 9:35.3.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3963.2338 [GMT -6:00]
Running from: c:\users\Scott\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2012-10-16 to 2012-11-16 )))))))))))))))))))))))))))))))
.
.
2012-11-16 15:48 . 2012-11-16 15:48 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2012-11-16 15:48 . 2012-11-16 15:48 -------- d-----w- c:\users\TEMP\AppData\Local\temp
2012-11-16 15:48 . 2012-11-16 15:48 -------- d-----w- c:\users\Scott\AppData\Local\temp
2012-11-16 15:48 . 2012-11-16 15:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-14 19:48 . 2012-11-14 19:48 -------- d-----w- c:\program files\HitmanPro
2012-11-14 19:38 . 2012-11-14 19:38 -------- d-----w- c:\programdata\HitmanPro
2012-11-14 18:31 . 2012-11-14 18:31 -------- d-----w- c:\users\Scott\AppData\Roaming\Malwarebytes
2012-11-14 18:30 . 2012-11-14 18:30 -------- d-----w- c:\programdata\Malwarebytes
2012-11-14 18:30 . 2012-11-14 18:30 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-11-14 18:30 . 2012-09-30 01:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-10-20 22:58 . 2012-10-21 22:13 -------- d-----w- C:\temp
2012-10-20 22:11 . 2012-10-20 22:11 -------- d-----w- c:\windows\system32\kodak
2012-10-20 22:11 . 2012-06-28 17:14 78848 ----a-w- c:\windows\system32\Spool\prtprocs\x64\EKAiO2PPR.dll
2012-10-20 22:09 . 2012-10-21 00:24 -------- d-----w- c:\users\Scott\AppData\Local\Eastman_Kodak_Company
2012-10-20 22:08 . 2012-10-20 22:08 -------- d-----w- c:\users\Scott\AppData\Local\Eastman Kodak Company
2012-10-20 22:07 . 2012-10-20 22:07 -------- d-----w- c:\windows\SysWow64\kodak
2012-10-20 21:59 . 2012-11-16 15:25 -------- d-----w- c:\programdata\Kodak
2012-10-20 04:31 . 2012-10-20 04:31 -------- d-----w- c:\windows\Hewlett-Packard
2012-10-20 04:27 . 2012-06-01 20:30 376832 ----a-w- c:\windows\system32\hpbrprtmon.dll
2012-10-20 04:27 . 2012-06-01 20:26 171008 ----a-w- c:\windows\system32\hpbprtmonui.dll
2012-10-20 04:27 . 2012-06-01 20:30 355840 ----a-w- c:\windows\system32\hpbprtmon.dll
2012-10-20 04:22 . 2012-10-20 04:22 -------- d-----w- C:\HP_ePrint_Mobile
2012-10-19 20:42 . 2012-10-19 20:42 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\HP
2012-10-19 18:59 . 2012-10-19 18:59 -------- d-----w- c:\program files (x86)\Hewlett-Packard
2012-10-19 18:57 . 2012-10-19 18:57 -------- d-----w- c:\program files (x86)\Microsoft
2012-10-19 18:54 . 2012-10-26 19:25 -------- d-----w- c:\users\Scott\AppData\Roaming\HpUpdate
2012-10-19 18:51 . 2012-10-20 21:56 -------- d-----w- c:\program files (x86)\HP
2012-10-19 18:50 . 2012-10-20 02:33 -------- d-----w- c:\program files\HP
2012-10-19 18:49 . 2012-10-19 20:46 -------- d-----w- c:\users\Scott\AppData\Local\HP
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-10 08:07 . 2006-11-02 12:35 65309168 ----a-w- c:\windows\system32\mrt.exe
2012-10-09 01:37 . 2012-04-01 15:10 696760 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-09 01:37 . 2011-06-22 19:32 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-13 13:45 . 2012-10-09 18:34 2048 ----a-w- c:\windows\system32\tzres.dll
2012-09-13 13:28 . 2012-10-09 18:34 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-08-29 16:05 . 2012-08-29 16:05 100344 ----a-w- c:\windows\HPBroker.dll
2012-08-29 11:40 . 2012-10-09 18:33 4699520 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-24 16:07 . 2012-10-09 18:33 218624 ----a-w- c:\windows\system32\wintrust.dll
2012-08-24 15:53 . 2012-10-09 18:33 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-08-24 11:15 . 2012-09-22 08:00 17810944 ----a-w- c:\windows\system32\mshtml.dll
2012-08-24 10:39 . 2012-09-22 08:00 10925568 ----a-w- c:\windows\system32\ieframe.dll
2012-08-24 10:31 . 2012-09-22 08:00 2312704 ----a-w- c:\windows\system32\jscript9.dll
2012-08-24 10:22 . 2012-09-22 08:00 1346048 ----a-w- c:\windows\system32\urlmon.dll
2012-08-24 10:21 . 2012-09-22 08:00 1392128 ----a-w- c:\windows\system32\wininet.dll
2012-08-24 10:20 . 2012-09-22 08:00 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-24 10:18 . 2012-09-22 08:00 237056 ----a-w- c:\windows\system32\url.dll
2012-08-24 10:17 . 2012-09-22 08:00 85504 ----a-w- c:\windows\system32\jsproxy.dll
2012-08-24 10:14 . 2012-09-22 08:00 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-08-24 10:14 . 2012-09-22 08:00 816640 ----a-w- c:\windows\system32\jscript.dll
2012-08-24 10:13 . 2012-09-22 08:00 599040 ----a-w- c:\windows\system32\vbscript.dll
2012-08-24 10:12 . 2012-09-22 08:00 2144768 ----a-w- c:\windows\system32\iertutil.dll
2012-08-24 10:11 . 2012-09-22 08:00 729088 ----a-w- c:\windows\system32\msfeeds.dll
2012-08-24 10:10 . 2012-09-22 08:00 96768 ----a-w- c:\windows\system32\mshtmled.dll
2012-08-24 10:09 . 2012-09-22 08:00 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-08-24 10:04 . 2012-09-22 08:00 248320 ----a-w- c:\windows\system32\ieui.dll
2012-08-24 06:59 . 2012-09-22 08:00 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2012-08-24 06:51 . 2012-09-22 08:00 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2012-08-24 06:51 . 2012-09-22 08:00 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2012-08-24 06:47 . 2012-09-22 08:00 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2012-08-24 06:47 . 2012-09-22 08:00 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-08-24 06:43 . 2012-09-22 08:00 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2012-08-21 18:01 . 2012-09-21 03:30 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-08-21 18:01 . 2009-09-12 22:33 125872 ----a-w- c:\windows\system32\GEARAspi64.dll
2012-08-21 18:01 . 2009-09-12 22:33 106928 ----a-w- c:\windows\SysWow64\GEARAspi.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn9\yt.dll" [2012-06-11 1524056]
"{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}"= "c:\program files (x86)\Swag_Bucks\prxtbSwag.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_CLASSES_ROOT\clsid\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}]
2011-05-09 08:49 176936 ----a-w- c:\program files (x86)\Swag_Bucks\prxtbSwag.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}]
2011-10-31 13:37 88976 ----a-w- c:\progra~2\WI371A~1\Datamngr\ToolBar\searchqudtx.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{99079a25-328f-4bd4-be04-00955acaa0a7}"= "c:\progra~2\WI371A~1\Datamngr\ToolBar\searchqudtx.dll" [2011-10-31 88976]
"{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}"= "c:\program files (x86)\Swag_Bucks\prxtbSwag.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{99079a25-328f-4bd4-be04-00955acaa0a7}]
.
[HKEY_CLASSES_ROOT\clsid\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\Scott\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\Scott\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\Scott\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Search Protection"="c:\program files (x86)\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"YSearchProtection"="c:\program files (x86)\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"Skype"="c:\program files (x86)\Skype\\Phone\Skype.exe" [2012-07-13 17418928]
"ANT Agent"="c:\program files (x86)\Garmin\ANT Agent\ANT Agent.exe" [2012-03-23 14749544]
"gStart"="c:\program files (x86)\Garmin\Training Center\gStart.exe" [2008-08-13 1891416]
"iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-08-29 59280]
"ApplePhotoStreams"="c:\program files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-09-10 59280]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AprvRemoveLegacyExcelKeys"="c:\program files (x86)\ApproveIt\Support\Tools\AprvClean.exe -k HKCU SOFTWARE\Microsoft\Office\Excel\Addins\OfficeAddIn.OfficeAddIn" [X]
"AprvRemoveLegacyWordKeys"="c:\program files (x86)\ApproveIt\Support\Tools\AprvClean.exe -k HKCU SOFTWARE\Microsoft\Office\Word\Addins\OfficeAddIn.OfficeAddIn" [X]
"ITSecMng"="c:\program files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-28 75136]
"NDSTray.exe"="NDSTray.exe" [BU]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2011-02-11 1295736]
"PCMAgent"="c:\program files (x86)\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe" [2007-12-14 143360]
"CLMLServer"="c:\program files (x86)\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe" [2008-07-11 188416]
"YMailAdvisor"="c:\program files (x86)\Yahoo!\Common\YMailAdvisor.exe" [2009-05-08 174424]
"YSearchProtection"="c:\program files (x86)\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"ApproveItForOfficeSetup"="c:\program files (x86)\ApproveIt\Support\Tools\ApproveItForOfficeSetup.exe" [2010-01-26 155648]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
"ArcSoft MediaImpression Monitor"="c:\program files (x86)\Kodak\MediaImpression\ArcMonitor.exe" [2010-07-20 80384]
"Sprint SmartView"="c:\program files (x86)\Sprint\Sprint SmartView\SprintSV.exe" [2009-09-10 75072]
"RDVCHG"="c:\program files (x86)\Sprint\Sprint SmartView\RDVCHG.exe" [2009-09-10 316736]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1675160]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-09-10 421776]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"Conime"="c:\windows\system32\conime.exe" [2009-04-11 69120]
.
c:\users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Scott\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
ActivClient Agent.lnk - c:\program files\ActivIdentity\ActivClient\acsagent.exe [2009-6-3 164904]
ApproveIt StartUp.lnk - c:\windows\Installer\{4E01B649-0023-4EB5-9263-57DE317C3418}\Icon9557F1BC1.ico [2011-8-12 9216]
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
Yahoo! Autosync.lnk - c:\program files (x86)\Yahoo!\Yahoo! Autosync\AutosyncForYahoo.exe [2007-8-21 391680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~2\WI371A~1\Datamngr\datamngr.dll c:\progra~2\WI371A~1\Datamngr\IEBHO.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
S2 ac.sharedstore;ActivIdentity Shared Store Service;c:\program files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-06-03 277032]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 01:38]
.
2012-11-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-10-25 23:30]
.
2012-11-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-10-25 23:30]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\Scott\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\Scott\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\Scott\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\Scott\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="E" [X]
"HotKeysCmds"="E" [X]
"Persistence"="E" [X]
"RtHDVCpl"="E" [X]
"Skytel"="E" [X]
"TPwrMain"="E" [X]
"HSON"="E" [X]
"SmoothView"="E" [X]
"00TCrdMain"="E" [X]
"SynTPEnh"="E" [X]
"acevents"="E" [X]
"accrdsub"="E" [X]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~2\WI371A~1\Datamngr\x64\datamngr.dll c:\progra~2\WI371A~1\Datamngr\x64\IEBHO.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://att.yahoo.com
mDefault_Page_URL = hxxp://att.yahoo.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: army.mil
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: ngbenefits
Trusted Zone: pentagon.mil\*.atrrs.army
TCP: DhcpNameServer = 192.168.1.254
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB
DPF: {3528A58B-595D-4AFD-A5F6-B914BD306DC3} - hxxp://dishconnectivity.sling.com/dpit/downloads/pc/SlingHealth.cab
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
WebBrowser-{8BDEA9D6-6F62-45EB-8EE9-8A81AF0D2F94} - (no file)
AddRemove-Move Networks Player - IE - c:\users\Scott\AppData\Roaming\Move Networks\ie_bin\Uninst.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2012-11-16 09:52:18
ComboFix-quarantined-files.txt 2012-11-16 15:52
ComboFix2.txt 2012-11-15 23:26
.
Pre-Run: 113,829,330,944 bytes free
Post-Run: 113,793,077,248 bytes free
.
- - End Of File - - 410BBA2AA165582CCDC159FA0689DE2D
./
(o o)
--------------------------------------oOOo-(_)-oOOo--------------------------------------
[15/11/2012 17:32:11] Resetting all TCP/IP Interfaces, Please wait.....
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:12] TCP/IP interfaces reset successful.
[15/11/2012 17:32:12] TCP/IP v6 interfaces reset successful.
[15/11/2012 17:32:12] You may need to restart your computer for the settings to take effect.
[15/11/2012 17:32:12] Finished resetting the Internet Protocol (TCP/IP).
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:12] Attempting to reset Winsock catalog, Please wait.....
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:13] Successfully reset the Winsock Catalog.
[15/11/2012 17:32:13] Finished repairing Winsock
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:13] Releasing TCP/IP connections, Please wait.....
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:14] Successfully released TCP/IP connections.
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:14] Renewing TCP/IP connections, Please wait.....
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:17] Successfully renewed TCP/IP adapters.
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:17] Configuring the Windows Event Log Service, Please wait.....
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:19] Windows Event Log Service Configured.
[15/11/2012 17:32:19] Starting the Windows Event Log Service.....
[15/11/2012 17:32:19] Windows Event Log Service Started Successfully.
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:19] Flushing DNS Resolver Cache, Please wait.....
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:19] Successfully flushed DNS Resolver Cache.
[15/11/2012 17:32:19] Refreshing all DHCP leases and re-registering DNS names, Please wait.....
[15/11/2012 17:32:22] Registration of the DNS resource records has been initiated.
[15/11/2012 17:32:23] Note: Any errors will be reported in the 'Event Viewer' in about 15 minutes.
[15/11/2012 17:32:23] Note: Click on 'File' and then 'Event Viewer...' to open the Event Viewer.
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:23] Resetting the Windows Firewall configuraton, Please wait.....
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:23] Could not reset Windows Firewall configuration.
[15/11/2012 17:32:23] Finished resetting the Windows Firewall configuraton.
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:23] Restoring the default Windows HOSTS file, Please wait.....
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:27] Writing data to the HOSTS file.....
[15/11/2012 17:32:27] HOSTS file created successfully.
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:27] You will need to reboot your computer before the settings will take effect.
-----------------------------------------------------------------------------------------
[15/11/2012 17:32:38] Your computer is restarting now.....
-----------------------------------------------------------------------------------------
./
(o o)
--------------------------------------oOOo-(_)-oOOo--------------------------------------
[16/11/2012 09:12:45] Resetting all TCP/IP Interfaces, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:12:47] TCP/IP interfaces reset successful.
[16/11/2012 09:12:48] TCP/IP v6 interfaces reset successful.
[16/11/2012 09:12:48] You may need to restart your computer for the settings to take effect.
[16/11/2012 09:12:48] Finished resetting the Internet Protocol (TCP/IP).
-----------------------------------------------------------------------------------------
[16/11/2012 09:12:48] Attempting to reset Winsock catalog, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:12:49] Successfully reset the Winsock Catalog.
[16/11/2012 09:12:49] Finished repairing Winsock
-----------------------------------------------------------------------------------------
[16/11/2012 09:12:49] Releasing TCP/IP connections, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:12:49] Successfully released TCP/IP connections.
-----------------------------------------------------------------------------------------
[16/11/2012 09:12:49] Renewing TCP/IP connections, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:12:55] Successfully renewed TCP/IP adapters.
-----------------------------------------------------------------------------------------
[16/11/2012 09:12:55] Configuring the Windows Event Log Service, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:12:57] Windows Event Log Service Configured.
[16/11/2012 09:12:57] Starting the Windows Event Log Service.....
[16/11/2012 09:12:57] Windows Event Log Service Started Successfully.
-----------------------------------------------------------------------------------------
[16/11/2012 09:12:57] Flushing DNS Resolver Cache, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:12:57] Successfully flushed DNS Resolver Cache.
[16/11/2012 09:12:57] Refreshing all DHCP leases and re-registering DNS names, Please wait.....
[16/11/2012 09:13:00] Registration of the DNS resource records has been initiated.
[16/11/2012 09:13:00] Note: Any errors will be reported in the 'Event Viewer' in about 15 minutes.
[16/11/2012 09:13:00] Note: Click on 'File' and then 'Event Viewer...' to open the Event Viewer.
-----------------------------------------------------------------------------------------
[16/11/2012 09:13:00] Resetting the Windows Firewall configuraton, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:13:01] Could not reset Windows Firewall configuration.
[16/11/2012 09:13:01] Finished resetting the Windows Firewall configuraton.
-----------------------------------------------------------------------------------------
[16/11/2012 09:13:01] Restoring the default Windows HOSTS file, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:13:17] Writing data to the HOSTS file.....
[16/11/2012 09:13:17] HOSTS file created successfully.
-----------------------------------------------------------------------------------------
[16/11/2012 09:13:17] You will need to reboot your computer before the settings will take effect.
-----------------------------------------------------------------------------------------
[16/11/2012 09:13:38] Your computer is restarting now.....
-----------------------------------------------------------------------------------------
./
(o o)
--------------------------------------oOOo-(_)-oOOo--------------------------------------
[16/11/2012 09:55:56] Resetting all TCP/IP Interfaces, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:55:57] TCP/IP interfaces reset successful.
[16/11/2012 09:55:57] TCP/IP v6 interfaces reset successful.
[16/11/2012 09:55:57] You may need to restart your computer for the settings to take effect.
[16/11/2012 09:55:57] Finished resetting the Internet Protocol (TCP/IP).
-----------------------------------------------------------------------------------------
[16/11/2012 09:55:57] Attempting to reset Winsock catalog, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:55:58] Successfully reset the Winsock Catalog.
[16/11/2012 09:55:58] Finished repairing Winsock
-----------------------------------------------------------------------------------------
[16/11/2012 09:55:58] Releasing TCP/IP connections, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:55:58] Successfully released TCP/IP connections.
-----------------------------------------------------------------------------------------
[16/11/2012 09:55:58] Renewing TCP/IP connections, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:56:02] Successfully renewed TCP/IP adapters.
-----------------------------------------------------------------------------------------
[16/11/2012 09:56:02] Configuring the Windows Event Log Service, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:56:04] Windows Event Log Service Configured.
[16/11/2012 09:56:04] Starting the Windows Event Log Service.....
[16/11/2012 09:56:04] Windows Event Log Service Started Successfully.
-----------------------------------------------------------------------------------------
[16/11/2012 09:56:04] Flushing DNS Resolver Cache, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:56:04] Successfully flushed DNS Resolver Cache.
[16/11/2012 09:56:04] Refreshing all DHCP leases and re-registering DNS names, Please wait.....
[16/11/2012 09:56:08] Registration of the DNS resource records has been initiated.
[16/11/2012 09:56:08] Note: Any errors will be reported in the 'Event Viewer' in about 15 minutes.
[16/11/2012 09:56:08] Note: Click on 'File' and then 'Event Viewer...' to open the Event Viewer.
-----------------------------------------------------------------------------------------
[16/11/2012 09:56:08] Resetting the Windows Firewall configuraton, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:56:08] Could not reset Windows Firewall configuration.
[16/11/2012 09:56:08] Finished resetting the Windows Firewall configuraton.
-----------------------------------------------------------------------------------------
[16/11/2012 09:56:08] Restoring the default Windows HOSTS file, Please wait.....
-----------------------------------------------------------------------------------------
[16/11/2012 09:56:12] Writing data to the HOSTS file.....
[16/11/2012 09:56:12] HOSTS file created successfully.
-----------------------------------------------------------------------------------------
[16/11/2012 09:56:12] You will need to reboot your computer before the settings will take effect.
-----------------------------------------------------------------------------------------
[16/11/2012 09:56:14] Your computer is restarting now.....
-----------------------------------------------------------------------------------------
Farbar Service Scanner Version: 09-11-2012
Ran by Scott (administrator) on 16-11-2012 at 10:01:40
Running from "C:\Users\Scott\Desktop"
Windows Vista (TM) Home Premium Service Pack 2 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Security Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.
Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
Other Services:
==============
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcsvc.dll
[2009-12-02 20:17] - [2009-04-11 01:11] - 0268288 ____A (Microsoft Corporation) 3ED0321127CE70ACDAABBF77E157C2A7
C:\Windows\System32\drivers\afd.sys
[2012-02-15 21:09] - [2012-01-03 08:25] - 0404992 ____A (Microsoft Corporation) C4F6CE6087760AD70960C9EB130E7943
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2012-05-11 18:11] - [2012-03-30 06:45] - 1423744 ____A (Microsoft Corporation) 46D448E9117464E4D3BBF36D7E3FA48E
C:\Windows\System32\dnsrslvr.dll
[2011-04-14 21:37] - [2011-03-02 10:12] - 0117760 ____A (Microsoft Corporation) 06230F1B721494A6DF8D47FD395BB1B0
C:\Windows\System32\mpssvc.dll
[2009-12-02 20:17] - [2009-04-11 01:11] - 0603136 ____A (Microsoft Corporation) 897E3BAF68BA406A61682AE39C83900C
C:\Windows\System32\bfe.dll
[2009-12-02 20:16] - [2009-04-11 01:11] - 0458240 ____A (Microsoft Corporation) FFB96C2589FFA60473EAD78B39FBDE29
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe
[2009-12-02 20:17] - [2009-04-11 01:11] - 1433600 ____A (Microsoft Corporation) B75232DAD33BFD95BF6F0A3E6BFF51E1
C:\Windows\System32\wscsvc.dll
[2009-12-02 20:16] - [2009-04-11 01:11] - 0074752 ____A (Microsoft Corporation) 9EA3E6D0EF7A5C2B9181961052A4B01A
C:\Windows\System32\wbem\WMIsvc.dll
[2009-12-02 20:17] - [2009-04-11 01:11] - 0221696 ____A (Microsoft Corporation) D2E7296ED1BD26D8DB2799770C077A02
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll
[2009-12-02 20:18] - [2009-04-11 01:11] - 1081856 ____A (Microsoft Corporation) 6D316F4859634071CC25C4FD4589AD2C
C:\Windows\System32\es.dll
[2009-12-02 20:17] - [2009-04-11 01:11] - 0361984 ____A (Microsoft Corporation) E12F22B73F153DECE721CD45EC05B4AF
C:\Windows\System32\cryptsvc.dll
[2012-10-09 12:33] - [2012-06-01 18:20] - 0174592 ____A (Microsoft Corporation) CA78B312C44E4D52E842C2C8BD48E452
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2009-12-02 20:18] - [2009-04-11 01:11] - 0719872 ____A (Microsoft Corporation) CF8B9A3A5E7DC57724A89D0C3E8CF9EF
**** End of log ****