Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all articles
Browse latest Browse all 2798

Opened email and downloaded attachment... concerned

$
0
0
Hi, I was expecting an email from someone that I don't know, it's job related and so I opened this email and clicked to download the word document. It opened up and said that I was the something or rather winner, or my email address was. I immediately knew I should not have opened it. Hopefully it's nothing but I did run my Microsoft Security Essentials as well as Malwarebits prior to doing your steps as I forgot and wanted to stop anything... I did get a Malware warning for OpenCandy and I quarantined and removed it. I also had these, Files Detected: 13

C:\Backup\Linnea\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JKYDJ941\DmailerSync[1].zip (Malware.Packer.as) -> Quarantined and deleted successfully.
C:\Users\Linnea\AppData\Local\Temp\Temp1_passrec.zip\astlog.exe (HackTool.Asterisk) -> Quarantined and deleted successfully.
C:\Users\Linnea\AppData\Local\Temp\Temp1_passrec.zip\ChromePass.exe (PUP.ChromePasswordTool) -> Quarantined and deleted successfully.
C:\Users\Linnea\AppData\Local\Temp\Temp1_passrec.zip\mspass.exe (PUP.PSW.MessenPass) -> Quarantined and deleted successfully.
C:\Users\Linnea\AppData\Local\Temp\Temp1_passrec.zip\PstPassword.exe (PUP.MailPassView) -> Quarantined and deleted successfully.
C:\Users\Linnea\AppData\Local\Temp\Temp1_passrec.zip\WebBrowserPassView.exe (PUP.PassView) -> Quarantined and deleted successfully.
C:\Users\Linnea\AppData\Local\Temp\Temp1_produkey-x64.zip\ProduKey.exe (PUP.PSWTool.ProductKey) -> Quarantined and deleted successfully.
C:\Users\Linnea\AppData\Local\Temp\Temp1_saminside.zip\SAMInside.exe (PUP.SAMInside) -> Quarantined and deleted successfully.
C:\Users\Linnea\AppData\Local\Temp\Temp1_saminside.zip\Tools\GetSyskey.exe (PUP.SAMInside) -> Quarantined and deleted successfully.
C:\Users\Linnea\AppData\Local\Temp\Temp1_saminside.zip\Tools\LRConvert.exe (PUP.SAMInside) -> Quarantined and deleted successfully.
C:\Users\Linnea\Downloads\passrec.zip (PUP.PSW.MessenPass) -> Quarantined and deleted successfully.
C:\Users\Linnea\Downloads\produkey-x64.zip (PUP.PSWTool.ProductKey) -> Quarantined and deleted successfully.
C:\Users\Linnea\Downloads\saminside.zip (PUP.SAMInside) -> Quarantined and deleted successfully.

As per the rest of the instructions I am pasting the DDS.txt next and then attaching the other two files.

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.17.2
Run by Linnea at 20:58:20 on 2013-04-12
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.4061.1214 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\LSI SoftModem\agr64svc.exe
C:\Windows\system32\svchost.exe -k apphost
C:\Windows\system32\CISVC.EXE
C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
C:\Windows\SysWOW64\ENAgent.exe
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k ftpsvc
C:\Program Files (x86)\EaseUS\Todo Backup\bin\GuardAgent.exe
C:\Windows\System32\svchost.exe -k ipripsvc
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Secunia\PSI\PSIA.exe
C:\Windows\System32\tcpsvcs.exe
C:\Windows\System32\snmp.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\ShowMyPCService\tvnserver.exe
C:\Windows\system32\svchost.exe -k iissvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Secunia\PSI\sua.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Plantronics\MyHeadsetUpdater\MyHeadsetUpdater.exe
C:\Windows\System32\spool\drivers\x64\3\E_YATIHVA.EXE
C:\Users\Linnea\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
C:\Program Files (x86)\ShowMyPCService\tvnserver.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Windows\explorer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uWindow Title = Internet Explorer, enhanced for Bing and MSN
mWinlogon: Userinit = userinit.exe,
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: PodcastBHO Class: {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} -
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
EB: <No Name>: {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 - <no file>
EB: <No Name>: {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 - <no file>
uRun: [EPLTarget\P0000000000000000] C:\Windows\System32\spool\DRIVERS\x64\3\E_YATIHVA.EXE /EPT "EPLTarget\P0000000000000000" /M "WorkForce 645" /EF "HKCU"
uRun: [EPLTarget\P0000000000000001] C:\Windows\System32\spool\DRIVERS\x64\3\E_YATIHVA.EXE /EPT "EPLTarget\P0000000000000001" /M "WorkForce 645"
uRun: [EPLTarget\P0000000000000002] C:\Windows\System32\spool\DRIVERS\x64\3\E_YATIHVA.EXE /EPT "EPLTarget\P0000000000000002" /M "WorkForce 645" /EF "HKCU"
uRun: [Google Update] "C:\Users\Linnea\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
mRun: [Cisco AnyConnect Secure Mobility Agent for Windows] "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized
mRun: [tvncontrol] "C:\Program Files (x86)\ShowMyPCService\tvnserver.exe" -controlservice -slave
dRun: [EPLTarget\P0000000000000000] C:\Windows\System32\spool\DRIVERS\x64\3\E_YATIHVA.EXE /EPT "EPLTarget\P0000000000000000" /M "WorkForce 645"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SECUNI~1.LNK - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\VPNGUI~1.LNK - C:\Windows\Installer\{467D5E81-8349-4892-9E81-C3674ED8E451}\Icon09DB8A851.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 68.105.28.11 68.105.29.11 68.105.28.12
TCP: Interfaces\{23163821-A585-433D-A0CE-0F86751E3299} : DHCPNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [Plantronics MyHeadset Updater] C:\Program Files\Plantronics\MyHeadsetUpdater\MyHeadsetUpdater.exe
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_43-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_43-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_43-windows-i586.cab
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Linnea\AppData\Roaming\Mozilla\Firefox\Profiles\4vb490z4.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.myyahoo.com
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Linnea\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true
============= SERVICES / DRIVERS ===============
.
R0 EUBAKUP;EUBAKUP;C:\Windows\System32\drivers\eubakup.sys [2012-2-4 44680]
R0 EUBKMON;EUBKMON;C:\Windows\System32\drivers\EUBKMON.sys [2012-2-4 50312]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-1-20 230320]
R0 xssflt;xssflt;C:\Windows\System32\drivers\xssflt.sys [2012-4-25 88200]
R1 EUDSKACS;EUDSKACS;C:\Windows\System32\drivers\eudskacs.sys [2012-2-4 19592]
R1 EUFDDISK;EUFDDISK;C:\Windows\System32\drivers\EuFdDisk.sys [2012-2-4 189576]
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-5-14 759048]
R2 EaseUS Agent;EaseUS Agent;C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [2012-2-4 60552]
R2 ENAgent;Epson Redirect Agent;C:\Windows\SysWOW64\ENAgent.exe [2013-1-30 4209856]
R2 EPSON_PM_RPCV4_05;EPSON V3 Service4(05);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE [2013-1-30 136576]
R2 ftpsvc;Microsoft FTP Service;C:\Windows\System32\svchost.exe -k ftpsvc [2009-7-13 27136]
R2 Guard Agent;Guard Agent;C:\Program Files (x86)\EaseUS\Todo Backup\bin\GuardAgent.exe [2012-2-4 23176]
R2 iprip;RIP Listener;C:\Windows\System32\svchost.exe -k ipripsvc [2009-7-13 27136]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2011-4-27 130008]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;C:\Windows\System32\drivers\e1y60x64.sys [2009-6-10 281088]
R3 mbamchameleon;mbamchameleon;C:\Windows\System32\drivers\mbamchameleon.sys [2013-4-12 36680]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-4-12 25928]
R3 PSI;PSI;C:\Windows\System32\drivers\psi_mf.sys [2010-9-1 17976]
R3 WSDScan;WSD Scan Support via UMB;C:\Windows\System32\drivers\WSDScan.sys [2009-7-13 25088]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 EpsonCustomerParticipation;EpsonCustomerParticipation;"C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe" --> C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe [?]
S3 acsock;acsock;C:\Windows\System32\drivers\acsock64.sys [2012-12-13 112080]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2013-2-7 57856]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-9-12 1512448]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-3-30 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-3-30 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-3-30 30208]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2011-2-16 14464]
.
=============== File Associations ===============
.
FileExt: .txt: Applications\firefox.exe="C:\Program Files (x86)\Mozilla Firefox\firefox.exe" "%1" [UserChoice]
.
=============== Created Last 30 ================
.
2013-04-13 03:29:25 9311288 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{3AE6E30E-2551-42F1-9149-0D42D2E13883}\mpengine.dll
2013-04-13 03:26:24 -------- d-----w- C:\Program Files (x86)\FileASSASSIN
2013-04-13 03:23:02 36680 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2013-04-12 23:41:54 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-04-12 23:41:54 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-04-12 01:36:53 9311288 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-04-09 23:30:52 -------- d-----w- C:\Program Files (x86)\ShowMyPCService
2013-04-09 22:29:53 3153408 ----a-w- C:\Windows\System32\win32k.sys
2013-04-09 22:29:51 1655656 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2013-04-09 22:29:50 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-04-09 22:29:49 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-04-09 22:29:49 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-04-09 22:29:48 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
2013-04-09 22:29:48 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2013-04-09 22:29:48 112640 ----a-w- C:\Windows\System32\smss.exe
2013-04-02 00:19:25 -------- d-----w- C:\Users\Linnea\AppData\Roaming\Malwarebytes
2013-04-02 00:19:08 -------- d-----w- C:\ProgramData\Malwarebytes
2013-04-01 19:14:28 -------- d--h--w- C:\Windows\msdownld.tmp
2013-03-30 09:50:35 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2013-03-30 09:50:34 9728 ----a-w- C:\Windows\System32\Wdfres.dll
2013-03-30 09:50:34 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys
2013-03-30 09:50:34 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys
2013-03-30 09:50:05 -------- d-----w- C:\Windows\PCHEALTH
2013-03-30 09:46:08 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2013-03-30 09:46:08 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2013-03-30 09:46:07 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2013-03-30 09:46:07 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2013-03-30 09:46:06 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2013-03-30 09:46:06 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2013-03-30 09:46:06 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2013-03-30 09:38:38 591872 ----a-w- C:\Windows\System32\SearchIndexer.exe
2013-03-30 09:37:57 509952 ----a-w- C:\Windows\System32\ntshrui.dll
2013-03-30 09:36:55 246272 ----a-w- C:\Windows\System32\netcorehc.dll
2013-03-30 09:35:54 950128 ----a-w- C:\Windows\System32\drivers\ndis.sys
2013-03-30 09:27:52 559104 ----a-w- C:\Windows\System32\spoolsv.exe
2013-03-30 09:27:51 67072 ----a-w- C:\Windows\splwow64.exe
2013-03-30 06:04:25 46080 ----a-w- C:\Windows\System32\atmlib.dll
2013-03-30 06:04:25 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2013-03-30 06:04:24 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2013-03-30 06:04:24 367616 ----a-w- C:\Windows\System32\atmfd.dll
2013-03-30 06:04:24 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2013-03-30 06:04:24 100864 ----a-w- C:\Windows\System32\fontsub.dll
2013-03-30 06:02:55 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-03-30 06:02:55 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2013-03-30 06:02:55 5120 ----a-w- C:\Windows\System32\wmi.dll
2013-03-30 06:02:55 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-03-30 06:02:55 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-03-30 05:59:57 19968 ----a-w- C:\Windows\System32\drivers\usb8023.sys
2013-03-30 05:59:34 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-03-30 05:59:34 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-03-30 05:57:51 142336 ----a-w- C:\Windows\System32\poqexec.exe
2013-03-30 05:56:59 60928 ----a-w- C:\Windows\System32\ahadmin.dll
2013-03-30 05:55:45 642944 ----a-w- C:\Windows\System32\winload.efi
2013-03-30 05:44:20 77312 ----a-w- C:\Windows\System32\packager.dll
2013-03-30 05:44:20 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2013-03-30 04:09:51 -------- d-----w- C:\Users\Linnea\AppData\Roaming\Cisco
2013-03-30 04:04:52 108448 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2013-03-30 03:28:20 -------- d-----w- C:\Program Files\Common Files\Deterministic Networks
2013-03-30 02:58:55 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2013-03-30 02:58:55 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2013-03-30 02:58:55 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2013-03-30 02:47:46 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2013-03-30 02:45:12 99840 ----a-w- C:\Windows\System32\wudriver.dll
2013-03-30 02:43:36 36864 ----a-w- C:\Windows\System32\wuapp.exe
2013-03-30 02:43:36 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2013-03-30 02:43:15 -------- d-----w- C:\Windows\Panther
2013-03-30 02:42:02 -------- d-----w- C:\Windows\SysWow64\BestPractices
2013-03-30 02:42:02 -------- d-----w- C:\Windows\System32\BestPractices
2013-03-30 02:42:02 -------- d-----w- C:\Program Files\Microsoft Games
2013-03-30 02:34:07 -------- d--h--w- C:\$WINDOWS.~Q
2013-03-30 02:28:25 -------- d--h--w- C:\$INPLACE.~TR
2013-03-30 01:47:34 -------- d-----w- C:\Program Files\LSI SoftModem
2013-03-29 21:17:38 -------- d-----w- C:\Users\Linnea\AppData\Local\LogMeIn Rescue Applet
2013-03-29 20:36:05 27392 ----a-r- C:\Windows\System32\drivers\CipcCdp.sys
2013-03-29 20:36:05 1919968 ----a-r- C:\Windows\System32\wdfcoinstaller01005.dll
2013-03-29 20:35:46 -------- d-----w- C:\Program Files (x86)\Common Files\Plantronics
2013-03-29 20:35:46 -------- d-----w- C:\Program Files (x86)\Common Files\Cisco Systems
2013-03-29 20:24:28 -------- d-----w- C:\Windows\System32\appmgmt
2013-03-29 02:51:21 -------- d-----w- C:\ProgramData\FirstClass
2013-03-29 02:51:21 -------- d-----w- C:\Program Files (x86)\FirstClass
2013-03-29 02:49:51 -------- d-----w- C:\Users\Linnea\AppData\Local\Cisco
2013-03-29 02:49:51 -------- d-----w- C:\ProgramData\Cisco
2013-03-29 02:49:51 -------- d-----w- C:\Program Files (x86)\Cisco
2013-03-28 21:18:45 -------- d-----w- C:\Program Files (x86)\Computer Requirements
2013-03-26 05:10:48 -------- d-----w- C:\Program Files\Plantronics
2013-03-26 02:47:19 -------- d-----w- C:\Users\Linnea\AppData\Roaming\FLEXnet
2013-03-26 02:46:05 -------- d-----w- C:\Users\Linnea\AppData\Local\Plantronics
2013-03-26 02:43:52 -------- d-----w- C:\ProgramData\Plantronics
2013-03-26 02:42:27 -------- d-----w- C:\Program Files\Common Files\Plantronics
2013-03-21 12:29:50 972264 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B5F02CE9-F36E-42D6-B5C2-C9929F3692FA}\gapaengine.dll
.
==================== Find3M ====================
.
2013-04-02 10:34:28 282744 ------w- C:\Windows\System32\MpSigStub.exe
2013-03-30 04:04:44 1085344 ----a-w- C:\Windows\System32\npdeployJava1.dll
2013-03-30 04:04:43 963488 ----a-w- C:\Windows\System32\deployJava1.dll
2013-03-12 21:31:49 73432 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-12 21:31:49 693976 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-03-06 13:24:53 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-03-06 13:24:50 861088 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-03-06 13:24:50 782240 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-02-21 10:30:16 1766912 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-02-21 10:29:39 2877440 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-02-21 10:29:37 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-02-21 10:29:37 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-02-21 10:15:07 2240512 ----a-w- C:\Windows\System32\wininet.dll
2013-02-21 10:14:09 3958784 ----a-w- C:\Windows\System32\jscript9.dll
2013-02-21 10:14:05 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-02-21 10:14:05 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-02-19 12:01:03 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-02-19 11:42:14 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-02-19 11:10:53 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-02-19 10:51:18 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-02-13 13:48:06 33152 ----a-w- C:\Windows\System32\drivers\csrbcx64.sys
2013-02-12 05:45:24 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45:22 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45:22 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45:22 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48:31 474112 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-02-12 04:48:26 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
2013-01-30 07:09:45 4209856 ----a-w- C:\Windows\SysWow64\ENAgent.exe
2013-01-30 07:09:44 83968 ----a-w- C:\Windows\System32\E_YD4BHVA.DLL
2013-01-30 07:09:44 120320 ----a-w- C:\Windows\System32\E_YLMHVA.DLL
2013-01-20 22:59:04 230320 ----a-w- C:\Windows\System32\drivers\MpFilter.sys
2013-01-20 22:59:04 130008 ----a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2013-01-13 21:17:03 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 21:17:02 2560 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 21:16:42 10752 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 21:12:46 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 21:11:21 4096 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 21:11:08 5632 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 21:11:07 5632 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 21:11:07 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 21:11:07 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:35:31 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 20:35:31 2560 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 20:35:18 10752 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 20:32:07 3584 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 20:31:48 4096 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 20:31:41 5632 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 20:31:40 5632 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 20:31:40 3072 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 20:31:40 3072 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:31:00 1247744 ----a-w- C:\Windows\SysWow64\DWrite.dll
2013-01-13 20:22:22 1988096 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2013-01-13 20:20:31 293376 ----a-w- C:\Windows\SysWow64\dxgi.dll
2013-01-13 20:09:00 249856 ----a-w- C:\Windows\SysWow64\d3d10_1core.dll
2013-01-13 20:08:43 220160 ----a-w- C:\Windows\SysWow64\d3d10core.dll
2013-01-13 20:08:35 1504768 ----a-w- C:\Windows\SysWow64\d3d11.dll
2013-01-13 19:59:04 1643520 ----a-w- C:\Windows\System32\DWrite.dll
2013-01-13 19:58:28 1175552 ----a-w- C:\Windows\System32\FntCache.dll
2013-01-13 19:54:01 604160 ----a-w- C:\Windows\SysWow64\d3d10level9.dll
2013-01-13 19:53:58 207872 ----a-w- C:\Windows\SysWow64\WindowsCodecsExt.dll
2013-01-13 19:53:14 187392 ----a-w- C:\Windows\SysWow64\UIAnimation.dll
2013-01-13 19:51:30 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2013-01-13 19:49:17 363008 ----a-w- C:\Windows\System32\dxgi.dll
2013-01-13 19:48:47 161792 ----a-w- C:\Windows\SysWow64\d3d10_1.dll
2013-01-13 19:46:25 1080832 ----a-w- C:\Windows\SysWow64\d3d10.dll
2013-01-13 19:43:21 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2013-01-13 19:38:39 333312 ----a-w- C:\Windows\System32\d3d10_1core.dll
2013-01-13 19:38:32 1887232 ----a-w- C:\Windows\System32\d3d11.dll
2013-01-13 19:38:21 296960 ----a-w- C:\Windows\System32\d3d10core.dll
2013-01-13 19:37:57 3419136 ----a-w- C:\Windows\SysWow64\d2d1.dll
2013-01-13 19:25:04 245248 ----a-w- C:\Windows\System32\WindowsCodecsExt.dll
2013-01-13 19:24:33 648192 ----a-w- C:\Windows\System32\d3d10level9.dll
2013-01-13 19:24:30 221184 ----a-w- C:\Windows\System32\UIAnimation.dll
2013-01-13 19:20:42 194560 ----a-w- C:\Windows\System32\d3d10_1.dll
2013-01-13 19:20:04 1238528 ----a-w- C:\Windows\System32\d3d10.dll
2013-01-13 19:15:40 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2013-01-13 19:10:36 3928064 ----a-w- C:\Windows\System32\d2d1.dll
2013-01-13 19:02:06 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll
2013-01-13 18:34:58 364544 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2013-01-13 18:32:43 465920 ----a-w- C:\Windows\System32\WMPhoto.dll
2013-01-13 18:09:52 522752 ----a-w- C:\Windows\System32\XpsGdiConverter.dll
2013-01-13 17:26:42 1158144 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2013-01-13 17:05:09 1682432 ----a-w- C:\Windows\System32\XpsPrint.dll
.
============= FINISH: 21:00:35.62 ===============

Okay, I just spent over two hours trying to find my Windows Zip. I have Winrar on my computer and when I right click on a file to compress it it automatically changes it to a .zip file but looks to me that it is Winrar??? I first tried to change my default program on zip to Windows Zip. That never came up as an option. Then I tried to find the program and or files on the Windows 7 DVD... Then I tried to find another place to download it.. All to no avail. I can not figure out how to change from Winrar to Windows Zip so hopefully someone can help and open these zipped files or tell me how to get Windows Zip back and set as my default so that I can re-zip and attach for you.

I use this computer for my work. If you notice a ton of unnecessary files I had to install Windows 7 again a year or two back and I upgraded to Professional so I didn't know how to delete all the Windows.old files and or if I would need any of them so they are all still here....

Thanks in Advance for any help...:hide::bow:

Attached Files
File Type: txt ark.txt (7.6 KB)
File Type: txt attach.txt (14.1 KB)

Viewing all articles
Browse latest Browse all 2798

Trending Articles