So, I located the offending Ping.exe in C:\Windows\SysWOW64, killed the process, took ownership of the folder, and deleted it. Afterwards I thought it a good idea to download AVG and run a full scan to be sure. Sure enough, consrv.dll comes up as an infection.
Me being a bit impatient at this point, I had AVG immediately quarantine the file, and I deleted it from the vault. Very foolish. Immediately proceeded to uninstall AVG, and restart. Low and behold my computer does not boot. Refuses to boot in safe mode too.
Did some more research and found Cyjon's topic on this lovely forum that confirmed my suspicions that deleting consrv.dll caused this. Proceeded to boot my Hirens Boot CD and try to recover the deleted consrv.dll and restore it, just so I can properly remove the infection while the computer boots up correctly. Unfortunately I could not find the file, even knowing AVG renames it.
Last ditch effort even though a few people said it will not work was I loaded the SYSTEM hive from C:\Windows\System32\config and altered:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\SubSystems Windows
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\SubSystems Windows
Made it so that it would direct to winsrv.dll instead of consrv.dll.
Lo and behold, it worked! Computer booted up fine, but I know there are still lingering pieces of the infection from reading Cyjon's topic. I would GREATLY appreciate it if one of you brilliant people could assist me in removing the stragglers.
Edit: UPDATE - Updated Java to the most recent 7 build and installed Spyware Blaster.
Here is my DDS.txt log as is necessary, if I missed anything at all I apologize, I am new to this.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by Derek at 22:31:30 on 2011-11-15
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4094.2825 [GMT -5:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
D:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\userinit.exe
C:\Windows\system32\Dwm.exe
D:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
D:\Program Files\Raxco\PerfectDisk\PDAgentS1.exe
D:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - D:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
Trusted Zone: intuit.com\ttlc
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 208.67.222.222 208.67.220.220 167.206.254.2
TCP: Interfaces\{0F30D75A-4B2C-4FD9-906F-F4353BDB632F} : DhcpNameServer = 208.67.222.222 208.67.220.220 167.206.254.2
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Derek\AppData\Roaming\Mozilla\Firefox\Profiles\0lunwsnb.default\
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.96.0\npesnlaunch.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - plugin: D:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: D:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: D:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: D:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: D:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
.
============= SERVICES / DRIVERS ===============
.
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 cpuz134;cpuz134;\??\C:\Windows\system32\drivers\cpuz134_x64.sys --> C:\Windows\system32\drivers\cpuz134_x64.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 cmudaxp;ASUS Xonar Essence ST Audio Interface;C:\Windows\system32\drivers\cmudaxp.sys --> C:\Windows\system32\drivers\cmudaxp.sys [?]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\Windows\system32\DRIVERS\ManyCam_x64.sys --> C:\Windows\system32\DRIVERS\ManyCam_x64.sys [?]
R3 RTCore64;RTCore64;D:\Program Files (x86)\MSI Afterburner\RTCore64.sys [2011-10-2 13368]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-9-3 13592]
S3 AE1000;Linksys AE1000 Driver;C:\Windows\system32\DRIVERS\ae1000w7.sys --> C:\Windows\system32\DRIVERS\ae1000w7.sys [?]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
S3 atillk64;atillk64;E:\Desktop Shortcuts\Overclocking + PC Info\HD 6950 to 6970 Mod\HD_6950_to_HD_6970_mod\winflash\atillk64.sys [2011-3-15 14608]
S3 EyeOneDisplay;EyeOneDisplay;C:\Windows\system32\Drivers\i1display_x64.sys --> C:\Windows\system32\Drivers\i1display_x64.sys [?]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2011-3-16 129440]
S3 MAUSBMIDI;Service for M-Audio USB MIDI Series;C:\Windows\system32\DRIVERS\MAudioUSBMIDI.sys --> C:\Windows\system32\DRIVERS\MAudioUSBMIDI.sys [?]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;C:\Windows\system32\DRIVERS\MijXfilt.sys --> C:\Windows\system32\DRIVERS\MijXfilt.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TomTomHOMEService;TomTomHOMEService;D:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2011-4-22 92592]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S4 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
.
=============== Created Last 30 ================
.
2011-11-16 03:14:54 8006480 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-11-16 03:14:53 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{166B8041-8385-49BE-B497-591C99D0A66B}\mpengine.dll
2011-11-15 09:09:43 -------- d--h--w- C:\$AVG
2011-11-15 08:56:40 -------- d-----w- C:\Users\Derek\AppData\Roaming\AVG
2011-11-15 08:52:34 -------- d--h--w- C:\ProgramData\Common Files
2011-11-15 08:50:50 -------- d-----w- C:\ProgramData\MFAData
2011-11-14 05:46:25 -------- d-----w- C:\Windows\AutoKMS
2011-11-14 05:24:22 -------- d-----w- C:\Program Files (x86)\Microsoft Synchronization Services
2011-11-14 05:24:16 -------- d-----w- C:\Windows\PCHEALTH
2011-11-14 05:24:16 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-11-14 05:23:35 -------- d-----w- C:\Program Files (x86)\Microsoft Analysis Services
2011-11-14 04:26:45 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-14 04:12:40 -------- d-----w- C:\Users\Derek\AppData\Local\Mozilla
2011-11-12 18:04:44 -------- d-----w- C:\Users\Derek\AppData\Local\Skyrim
2011-11-12 07:02:01 53248 ----a-r- C:\Users\Derek\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-11-12 07:01:54 -------- d-----w- C:\Users\Derek\AppData\Local\Logishrd
2011-11-12 06:55:34 279616 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys
2011-11-12 06:31:12 -------- d-----we C:\Windows\system64
2011-11-11 22:32:43 -------- d-----w- C:\ProgramData\MediaMonkey
2011-11-11 22:32:42 -------- d-----w- C:\Users\Derek\AppData\Roaming\MediaMonkey
2011-11-10 03:37:27 -------- d-----w- C:\Users\Derek\AppData\Local\ATI
2011-11-10 03:37:08 0 ----a-w- C:\Windows\ativpsrm.bin
2011-11-10 03:36:07 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2011-11-10 03:35:45 -------- d-----w- C:\Program Files\ATI
2011-11-10 03:35:22 -------- d-----w- C:\Program Files\ATI Technologies
2011-11-10 02:42:31 886784 ----a-w- C:\Program Files\Common Files\System\wab32.dll
2011-11-10 02:42:31 708608 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2011-11-10 02:42:29 1923952 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-11-10 02:42:23 3144704 ----a-w- C:\Windows\System32\win32k.sys
2011-11-10 02:39:09 -------- d-----w- C:\Users\Derek\DxReport
2011-11-10 02:38:43 -------- d-----w- C:\Users\Derek\AppData\Roaming\LaunchPad
2011-10-22 07:45:12 -------- d-----w- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-10-22 07:45:01 -------- d-----w- C:\Program Files\Bonjour
2011-10-22 07:45:01 -------- d-----w- C:\Program Files (x86)\Bonjour
.
==================== Find3M ====================
.
2011-11-14 05:04:26 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-11-12 07:01:50 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2011-11-12 06:53:57 530488 ----a-w- C:\Windows\System32\drivers\sptd.sys
2011-11-11 01:32:42 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-11-11 01:32:42 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-11-11 01:32:09 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2011-11-03 06:58:54 10497024 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2011-11-03 06:15:30 24866816 ----a-w- C:\Windows\System32\atio6axx.dll
2011-11-03 06:06:44 159744 ----a-w- C:\Windows\System32\atiapfxx.exe
2011-11-03 06:06:26 748544 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2011-11-03 06:04:58 892416 ----a-w- C:\Windows\System32\aticfx64.dll
2011-11-03 06:02:10 466944 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2011-11-03 06:01:58 517120 ----a-w- C:\Windows\System32\atieclxx.exe
2011-11-03 06:01:22 204288 ----a-w- C:\Windows\System32\atiesrxx.exe
2011-11-03 06:00:10 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2011-11-03 05:59:50 423424 ----a-w- C:\Windows\System32\atipdl64.dll
2011-11-03 05:59:42 356352 ----a-w- C:\Windows\SysWow64\atipdlxx.dll
2011-11-03 05:59:32 278528 ----a-w- C:\Windows\SysWow64\Oemdspif.dll
2011-11-03 05:59:26 21504 ----a-w- C:\Windows\System32\atimuixx.dll
2011-11-03 05:59:22 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2011-11-03 05:59:16 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2011-11-03 05:58:58 18757120 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2011-11-03 05:57:38 53248 ----a-w- C:\Windows\System32\amdverag.dll
2011-11-03 05:56:06 4292096 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2011-11-03 05:46:10 5041664 ----a-w- C:\Windows\System32\atidxx64.dll
2011-11-03 05:44:48 58880 ----a-w- C:\Windows\System32\coinst.dll
2011-11-03 05:43:50 1113088 ----a-w- C:\Windows\System32\atiumd6v.dll
2011-11-03 05:43:26 1828864 ----a-w- C:\Windows\SysWow64\atiumdmv.dll
2011-11-03 05:43:14 4044288 ----a-w- C:\Windows\System32\atiumd6a.dll
2011-11-03 05:38:28 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2011-11-03 05:38:26 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2011-11-03 05:38:18 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2011-11-03 05:38:14 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2011-11-03 05:38:04 9978880 ----a-w- C:\Windows\System32\aticaldd64.dll
2011-11-03 05:35:16 4353536 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2011-11-03 05:34:48 8449024 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2011-11-03 05:32:40 4189184 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2011-11-03 05:29:04 5510144 ----a-w- C:\Windows\System32\atiumd64.dll
2011-11-03 05:22:20 486912 ----a-w- C:\Windows\System32\atiadlxx.dll
2011-11-03 05:22:08 339968 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2011-11-03 05:21:50 17408 ----a-w- C:\Windows\System32\atig6pxx.dll
2011-11-03 05:21:48 14336 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2011-11-03 05:21:48 14336 ----a-w- C:\Windows\System32\atiglpxx.dll
2011-11-03 05:21:44 39936 ----a-w- C:\Windows\System32\atig6txx.dll
2011-11-03 05:21:36 32768 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2011-11-03 05:21:30 326656 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2011-11-03 05:20:38 40960 ----a-w- C:\Windows\System32\atiuxp64.dll
2011-11-03 05:20:32 31744 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2011-11-03 05:20:24 38912 ----a-w- C:\Windows\System32\atiu9p64.dll
2011-11-03 05:20:18 29184 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2011-11-03 05:19:24 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2011-11-03 05:16:36 54784 ----a-w- C:\Windows\System32\atimpc64.dll
2011-11-03 05:16:36 54784 ----a-w- C:\Windows\System32\amdpcom64.dll
2011-11-03 05:16:20 53760 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2011-11-03 05:16:20 53760 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2011-10-25 04:48:28 75136 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-09-26 04:23:13 466520 ----a-w- C:\Windows\System32\wrap_oal.dll
2011-09-26 04:23:13 445016 ----a-w- C:\Windows\SysWow64\wrap_oal.dll
2011-09-26 04:23:13 123480 ----a-w- C:\Windows\System32\OpenAL32.dll
2011-09-26 04:23:13 109144 ----a-w- C:\Windows\SysWow64\OpenAL32.dll
2011-09-19 13:03:40 45056 ----a-w- C:\Windows\SysWow64\rtvcvfw32.dll
2011-09-02 06:30:46 55064 ----a-w- C:\Windows\System32\LMouFiltCoInst.dll
2011-09-02 06:30:46 42776 ----a-w- C:\Windows\System32\drivers\LUsbFilt.sys
2011-09-02 06:30:36 60696 ----a-w- C:\Windows\System32\drivers\LMouFilt.Sys
2011-09-02 06:30:36 1845528 ----a-w- C:\Windows\System32\LkmdfCoInst.dll
2011-09-02 06:30:24 66840 ----a-w- C:\Windows\System32\drivers\LHidFilt.Sys
2011-09-01 05:24:07 2309120 ----a-w- C:\Windows\System32\jscript9.dll
2011-09-01 05:17:57 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-09-01 05:12:04 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-09-01 02:35:59 1798144 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-09-01 02:28:15 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-09-01 02:22:54 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-08-31 21:00:50 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-31 03:05:32 96104 ----a-w- C:\Windows\System32\dns-sd.exe
2011-08-31 03:05:32 85864 ----a-w- C:\Windows\System32\dnssd.dll
2011-08-31 03:05:32 61288 ----a-w- C:\Windows\System32\jdns_sd.dll
2011-08-31 03:05:32 212840 ----a-w- C:\Windows\System32\dnssdX.dll
2011-08-31 03:05:04 83816 ----a-w- C:\Windows\SysWow64\dns-sd.exe
2011-08-31 03:05:04 73064 ----a-w- C:\Windows\SysWow64\dnssd.dll
2011-08-31 03:05:04 50536 ----a-w- C:\Windows\SysWow64\jdns_sd.dll
2011-08-31 03:05:04 178536 ----a-w- C:\Windows\SysWow64\dnssdX.dll
2011-08-27 05:37:49 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2011-08-27 05:37:48 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-08-27 04:26:27 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-08-27 04:26:27 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-08-25 07:43:26 45056 ----a-w- C:\Windows\System32\rtvcvfw32.dll
.
============= FINISH: 22:32:19.42 ===============
Attached File(s)
-
Attach.txt (12.78K)
Number of downloads: 0
This post has been edited by -Piper-: 15 November 2011 - 11:31 PM

Help
This topic is locked

Back to top













