Another PC with a Sirefef infection. Was affected by the restarting-every-minute issue but that appears to have gone away today? MSE claims to have removed it but I'm not entirely convinced, so I ran FRST, logs follow. Thanks for the help.
FRST.txt
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 25-07-2012 12:04:53
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-26] (Egis Technology Inc.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [9955872 2010-01-12] (Realtek Semiconductor)
HKLM\...\Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" [57928 2011-09-16] (LogMeIn, Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167704 2012-01-10] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [392984 2012-01-10] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417560 2012-01-10] (Intel Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [337264 2010-05-26] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d [201584 2010-03-10] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" [407920 2010-03-10] (Egis Technology Inc.)
HKLM-x32\...\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [611872 2010-08-04] ()
HKLM-x32\...\Run: [MDS_Menu] "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [ArcadeMovieService] "C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe" [124136 2010-06-29] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\John\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-05-11] (Google Inc.)
HKU\John\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17355912 2012-05-03] (Skype Technologies S.A.)
HKU\John\...\Run: [ANT Agent] C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe [14749544 2012-03-23] (GARMIN Corp.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76 192.168.1.1
==================== Services (Whitelisted) ======
2 GREGService; C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated)
2 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe" [375208 2012-07-12] (LogMeIn, Inc.)
2 LMIMaint; "C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe" [147368 2012-07-12] (LogMeIn, Inc.)
2 LogMeIn; "C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe" [407424 2011-09-16] (LogMeIn, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-26] (Egis Technology Inc.)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 NOBU; "C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE [2804568 2010-06-01] (Symantec Corporation)
2 RichVideo; "C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe" [244904 2010-05-12] ()
2 USBS3S4Detection; C:\OEM\USBDECTION\USBS3S4Detection.exe [76320 2009-12-09] ()
========================== Drivers (Whitelisted) =============
3 libusb0; C:\Windows\System32\Drivers\libusb0.sys [44480 2011-05-17] (http://libusb-win32.sourceforge.net)
2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [15928 2011-09-16] (LogMeIn, Inc.)
3 lmimirr; C:\Windows\System32\Drivers\lmimirr.sys [11552 2011-09-16] (LogMeIn, Inc.)
2 LMIRfsDriver; C:\Windows\System32\Drivers\LMIRfsDriver.sys [72216 2011-09-16] (LogMeIn, Inc.)
4 LMIRfsClientNP; [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-25 12:04 - 2012-07-25 12:04 - 00000000 ____D C:\FRST
2012-07-24 12:52 - 2012-07-24 12:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB1EA56D33AE6199
2012-07-24 12:36 - 2012-07-24 12:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4DB6A1706548C3D5
2012-07-24 12:22 - 2012-07-24 12:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.54F57B715141D40B
2012-07-24 12:19 - 2012-07-24 12:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15131A65FB02A0FE
2012-07-24 12:03 - 2012-07-24 12:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFFF008C7A471969
2012-07-24 11:47 - 2012-07-24 11:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6C3C323F6C38542E
2012-07-24 11:30 - 2012-07-24 11:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B69F24DD8C1A0F3E
2012-07-24 11:18 - 2012-07-24 11:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62DF5CE0534FD378
2012-07-24 11:13 - 2012-07-24 11:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7EB26E67A61EED38
2012-07-24 10:57 - 2012-07-24 10:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C049B24666361E31
2012-07-24 10:46 - 2012-07-24 10:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B79DAF875A54AB9A
2012-07-24 10:41 - 2012-07-24 10:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66D8ABEF0FF9D45C
2012-07-24 10:39 - 2009-06-10 13:00 - 00000824 ____A C:\Windows\System32\Drivers\etc\hosts.20120724-133900.backup
2012-07-24 10:38 - 2012-07-24 10:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5CB621C310B34BB0
2012-07-24 10:36 - 2012-07-24 10:36 - 00000000 ____D C:\Program Files (x86)\Oracle
2012-07-24 10:35 - 2012-07-05 19:06 - 00227760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-07-24 10:34 - 2012-06-26 22:43 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-07-24 10:34 - 2012-06-26 22:43 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-07-24 10:33 - 2012-07-24 10:34 - 00002954 ____A C:\Windows\SysWOW64\jupdate-1.7.0_05-b06.log
2012-07-24 10:31 - 2012-07-24 10:38 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy
2012-07-24 10:31 - 2012-07-24 10:36 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
2012-07-24 10:29 - 2012-07-24 10:29 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-24 10:29 - 2012-07-24 10:29 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-24 04:38 - 2012-07-24 04:38 - 00262144 ____A C:\Windows\Minidump\072412-17581-01.dmp
2012-07-23 13:09 - 2012-07-23 13:09 - 01116100 ____A C:\Users\John\Downloads\(No subject).zip
2012-07-19 06:36 - 2012-07-20 07:39 - 00000000 ____D C:\Users\John\Desktop\Pleasantdale
2012-07-19 06:30 - 2012-07-19 06:30 - 00000368 ____A C:\Users\John\Desktop\Oakley Enduring CndrRed Edge With VR28 Black Iridium 09-811 Joyride Cycles.url
2012-07-19 04:58 - 2012-07-19 04:58 - 01279901 ____A C:\Users\John\Desktop\gecko.zip
2012-07-16 12:59 - 2012-07-19 06:00 - 00000000 ____D C:\Users\John\Desktop\Avery Bball Camp July 2012
2012-07-14 19:37 - 2012-07-14 19:40 - 00012233 ____A C:\Users\John\Desktop\LGBC Nursery Schedule Pick up 2012-13.xlsx
2012-07-14 19:37 - 2012-07-14 19:37 - 00000165 ___AH C:\Users\John\Desktop\~$LGBC Nursery Schedule Pick up 2012-13.xlsx
2012-07-14 16:03 - 2012-07-14 16:03 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-11 00:05 - 2012-06-11 19:02 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 00:02 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 00:02 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 00:02 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 00:02 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 00:02 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 00:02 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 00:02 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 00:02 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 00:02 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 00:02 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 00:02 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 00:02 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 00:02 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 00:02 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 00:02 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 00:02 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 00:02 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 00:02 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 00:02 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 00:02 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 00:02 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 00:02 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 00:02 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 00:02 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 00:02 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 00:02 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 00:02 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 00:02 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-10 21:58 - 2012-06-08 21:30 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 21:58 - 2012-06-08 20:46 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 21:58 - 2012-06-05 21:50 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 21:58 - 2012-06-05 21:50 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 21:58 - 2012-06-05 21:09 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 21:58 - 2012-06-05 21:09 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 21:58 - 2012-06-01 21:38 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 21:58 - 2012-06-01 21:38 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 21:58 - 2012-06-01 21:37 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 21:58 - 2012-06-01 21:27 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 21:58 - 2012-06-01 21:27 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 21:58 - 2012-06-01 20:48 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 21:58 - 2012-06-01 20:48 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 21:58 - 2012-06-01 20:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 21:58 - 2012-06-01 20:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-03 07:00 - 2012-07-24 10:29 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-03 06:59 - 2012-07-24 10:29 - 00742892 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-03 06:59 - 2010-04-09 03:06 - 00374664 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2012-06-29 21:33 - 2012-01-31 02:59 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-06-29 11:10 - 2012-06-29 11:13 - 00000000 ____D C:\Users\John\Desktop\John Picture Frame Files
2012-06-28 15:00 - 2012-06-28 15:38 - 00000000 ____D C:\Users\John\Desktop\Frame
2012-06-26 11:59 - 2012-06-26 12:45 - 00000000 ____D C:\Users\John\Desktop\blinds
2012-06-25 07:25 - 2012-07-18 06:24 - 00000000 ____D C:\Users\John\Desktop\Leopard Geckos
============ 3 Months Modified Files ========================
2012-07-25 09:02 - 2009-07-13 20:51 - 00084515 ____A C:\Windows\setupact.log
2012-07-25 09:02 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-25 09:02 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-25 09:00 - 2009-07-13 21:13 - 00729514 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-25 08:56 - 2012-05-11 06:40 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-25 08:56 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-25 08:56 - 2007-10-10 23:05 - 01190293 ____A C:\Windows\WindowsUpdate.log
2012-07-25 08:48 - 2012-05-08 11:23 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-25 07:56 - 2012-05-11 06:40 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-24 13:02 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-24 12:52 - 2012-07-24 12:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB1EA56D33AE6199
2012-07-24 12:36 - 2012-07-24 12:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4DB6A1706548C3D5
2012-07-24 12:22 - 2012-07-24 12:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.54F57B715141D40B
2012-07-24 12:19 - 2012-07-24 12:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15131A65FB02A0FE
2012-07-24 12:03 - 2012-07-24 12:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFFF008C7A471969
2012-07-24 11:47 - 2012-07-24 11:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6C3C323F6C38542E
2012-07-24 11:30 - 2012-07-24 11:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B69F24DD8C1A0F3E
2012-07-24 11:18 - 2012-07-24 11:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62DF5CE0534FD378
2012-07-24 11:13 - 2012-07-24 11:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7EB26E67A61EED38
2012-07-24 10:57 - 2012-07-24 10:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C049B24666361E31
2012-07-24 10:46 - 2012-07-24 10:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B79DAF875A54AB9A
2012-07-24 10:41 - 2012-07-24 10:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66D8ABEF0FF9D45C
2012-07-24 10:38 - 2012-07-24 10:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5CB621C310B34BB0
2012-07-24 10:34 - 2012-07-24 10:33 - 00002954 ____A C:\Windows\SysWOW64\jupdate-1.7.0_05-b06.log
2012-07-24 10:29 - 2012-07-03 07:00 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-24 10:29 - 2012-07-03 06:59 - 00742892 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-24 04:38 - 2012-07-24 04:38 - 00262144 ____A C:\Windows\Minidump\072412-17581-01.dmp
2012-07-24 04:37 - 2012-05-08 17:54 - 585182112 ____A C:\Windows\MEMORY.DMP
2012-07-23 13:09 - 2012-07-23 13:09 - 01116100 ____A C:\Users\John\Downloads\(No subject).zip
2012-07-22 05:05 - 2012-06-24 05:57 - 00086368 ____A C:\Users\John\Desktop\2012-13 LGBC Nursery Schedule FINAL COPY_TEST.xlsx
2012-07-19 06:30 - 2012-07-19 06:30 - 00000368 ____A C:\Users\John\Desktop\Oakley Enduring CndrRed Edge With VR28 Black Iridium 09-811 Joyride Cycles.url
2012-07-19 04:58 - 2012-07-19 04:58 - 01279901 ____A C:\Users\John\Desktop\gecko.zip
2012-07-17 05:18 - 2007-10-10 23:01 - 00054166 ____A C:\Windows\PFRO.log
2012-07-14 19:40 - 2012-07-14 19:37 - 00012233 ____A C:\Users\John\Desktop\LGBC Nursery Schedule Pick up 2012-13.xlsx
2012-07-14 19:37 - 2012-07-14 19:37 - 00000165 ___AH C:\Users\John\Desktop\~$LGBC Nursery Schedule Pick up 2012-13.xlsx
2012-07-12 11:13 - 2012-05-08 11:34 - 00087488 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll
2012-07-12 11:13 - 2012-05-08 11:34 - 00080800 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll
2012-07-12 11:13 - 2012-05-08 11:34 - 00034720 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll
2012-07-11 18:48 - 2012-05-08 11:23 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-11 18:48 - 2012-05-08 11:23 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-11 00:23 - 2009-07-13 20:45 - 00345528 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 00:02 - 2012-05-29 13:36 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-05 19:06 - 2012-07-24 10:35 - 00227760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-07-05 19:06 - 2012-05-08 11:22 - 00772544 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2012-07-05 19:06 - 2012-05-08 11:22 - 00687544 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2012-07-02 11:09 - 2012-06-13 05:41 - 00001747 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-26 22:43 - 2012-07-24 10:34 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-06-26 22:43 - 2012-07-24 10:34 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-06-24 05:58 - 2012-06-24 05:57 - 00000165 ___AH C:\Users\John\Desktop\~$2012-13 LGBC Nursery Schedule FINAL COPY_TEST.xlsx
2012-06-20 16:08 - 2012-06-18 05:57 - 00155648 ____A C:\Users\John\Desktop\2012-13 LGBC Nursery Schedule.xls
2012-06-18 11:20 - 2012-06-10 19:32 - 00101376 ____H C:\Users\John\Desktop\~WRL1855.tmp
2012-06-17 12:56 - 2012-06-10 19:32 - 00101376 ____H C:\Users\John\Desktop\~WRL0004.tmp
2012-06-12 03:42 - 2012-06-12 03:42 - 00262144 ____A C:\Windows\Minidump\061212-16255-01.dmp
2012-06-11 19:02 - 2012-07-11 00:05 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-10 20:27 - 2012-06-10 19:32 - 00100864 ____H C:\Users\John\Desktop\~WRL0003.tmp
2012-06-08 21:30 - 2012-07-10 21:58 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:46 - 2012-07-10 21:58 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 21:50 - 2012-07-10 21:58 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:50 - 2012-07-10 21:58 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:09 - 2012-07-10 21:58 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:09 - 2012-07-10 21:58 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 10:30 - 2012-06-05 09:31 - 00098816 ____H C:\Users\John\Desktop\~WRL0002.tmp
2012-06-02 14:19 - 2012-06-20 23:18 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 23:18 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 23:18 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 23:18 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 23:18 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-20 23:18 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-20 23:18 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 12:19 - 2012-06-20 23:18 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:15 - 2012-06-20 23:18 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-11 00:02 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 00:02 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 00:02 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 00:02 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 00:02 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 00:02 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 00:02 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 00:02 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 00:02 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 00:02 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 00:02 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 00:02 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 00:02 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 00:02 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 00:02 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 00:02 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 00:02 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 00:02 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 00:02 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 00:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 00:02 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 00:02 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 00:02 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 00:02 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 00:02 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 00:02 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 00:02 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 00:02 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:38 - 2012-07-10 21:58 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:38 - 2012-07-10 21:58 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:37 - 2012-07-10 21:58 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:27 - 2012-07-10 21:58 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:27 - 2012-07-10 21:58 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:48 - 2012-07-10 21:58 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:48 - 2012-07-10 21:58 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:47 - 2012-07-10 21:58 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:42 - 2012-07-10 21:58 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-30 00:02 - 2012-05-30 00:00 - 00003881 ____A C:\Windows\IE9_main.log
2012-05-30 00:01 - 2012-05-30 00:01 - 03695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2012-05-30 00:01 - 2012-05-30 00:01 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-05-30 00:01 - 2012-05-30 00:01 - 00697344 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00603648 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00580608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00534528 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00452608 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00448512 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-05-30 00:01 - 2012-05-30 00:01 - 00434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00403248 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-05-30 00:01 - 2012-05-30 00:01 - 00353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00282112 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00267776 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00249344 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00165888 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00145920 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00135168 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00114176 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00111616 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00091648 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-05-30 00:01 - 2012-05-30 00:01 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2012-05-30 00:01 - 2012-05-30 00:01 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00049664 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-05-29 14:06 - 2012-05-29 13:26 - 00002024 ___AH C:\Users\John\Documents\Default.rdp
2012-05-24 13:18 - 2012-05-24 13:18 - 04472832 ____A (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
2012-05-23 08:33 - 2012-05-23 08:33 - 00037376 ____A C:\Users\John\Desktop\Copy of LGBC Nursery Worker Screening_5-23-12.xls
2012-05-19 18:50 - 2012-05-09 09:34 - 00099328 ____H C:\Users\John\Desktop\~WRL0001.tmp
2012-05-19 14:38 - 2012-05-08 11:34 - 00087456 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll.000.bak
2012-05-17 00:02 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-05-16 15:15 - 2012-05-16 15:15 - 00001074 ____A C:\Users\Public\Desktop\Picasa 3.lnk
2012-05-15 12:16 - 2012-05-15 12:16 - 00008607 ____A C:\Windows\System32\lvcoinst.log
2012-05-15 12:11 - 2012-05-15 12:11 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-05-12 00:00 - 2012-05-10 00:14 - 00283562 ____A C:\Windows\msxml4-KB973688-enu.LOG
2012-05-12 00:00 - 2012-05-10 00:11 - 00287348 ____A C:\Windows\msxml4-KB954430-enu.LOG
2012-05-11 00:30 - 2012-05-08 11:18 - 00088080 ____A C:\Users\John\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-10 19:47 - 2012-05-10 19:47 - 06448935 ____A C:\Users\John\Desktop\fontsforpeas.zip
2012-05-10 11:53 - 2012-05-10 11:53 - 00002550 ____N C:\Users\Public\Desktop\WildTangent Games App - acer.lnk
2012-05-09 11:13 - 2012-05-09 11:13 - 00001521 ____A C:\Users\John\Downloads\bergcert.cer
2012-05-09 11:06 - 2012-05-09 11:10 - 00000277 ____A C:\Users\John\Desktop\Berg Remote Office.url
2012-05-09 10:53 - 2012-05-09 10:53 - 00000020 ___SH C:\Users\LogMeInRemoteUser\ntuser.ini
2012-05-09 10:00 - 2012-05-09 10:00 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-05-08 17:54 - 2012-05-08 17:54 - 00873584 ____A C:\Windows\Minidump\050812-15568-01.dmp
2012-05-08 11:34 - 2012-05-08 11:34 - 00001024 ____A C:\.rnd
2012-05-08 11:20 - 2010-08-29 23:17 - 00058267 ____A C:\Windows\patch.log
2012-05-08 11:18 - 2007-10-10 23:26 - 00000413 ____A C:\Windows\System32\oem_Get_OS_Language.log
2012-05-08 11:17 - 2012-05-08 11:17 - 00000020 ___SH C:\Users\John\ntuser.ini
2012-05-04 02:52 - 2012-06-12 12:34 - 05505392 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:08 - 2012-06-12 12:34 - 03958128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:08 - 2012-06-12 12:34 - 03902320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-01 21:32 - 2012-06-12 12:34 - 00208896 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:50 - 2012-06-12 12:34 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
ZeroAccess:
C:\Windows\Installer\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}
C:\Windows\Installer\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}\@
C:\Windows\Installer\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}\L
C:\Windows\Installer\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}\U
C:\Windows\Installer\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}\U\00000001.@
ZeroAccess:
C:\Users\John\AppData\Local\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}
C:\Users\John\AppData\Local\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}\@
C:\Users\John\AppData\Local\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}\L
C:\Users\John\AppData\Local\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 18%
Total physical RAM: 3959.11 MB
Available physical RAM: 3219.84 MB
Total Pagefile: 3957.26 MB
Available Pagefile: 3207.46 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (Acer) (Fixed) (Total:446.13 GB) (Free:334.63 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:19.53 GB) (Free:6.24 GB) NTFS
4 Drive g: () (Removable) (Total:3.83 GB) (Free:2.82 GB) FAT32
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
9 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 3935 MB 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 19 GB 1024 KB
Partition 2 Primary 100 MB 19 GB
Partition 3 Primary 446 GB 19 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E PQSERVICE NTFS Partition 19 GB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Acer NTFS Partition 446 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3929 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 3929 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-18 03:24
======================= End Of Log ==========================
Search.txt
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-25 12:09:59
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2012-07-24 13:02] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======
FRST.txt
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 25-07-2012 12:04:53
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-26] (Egis Technology Inc.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [9955872 2010-01-12] (Realtek Semiconductor)
HKLM\...\Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" [57928 2011-09-16] (LogMeIn, Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167704 2012-01-10] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [392984 2012-01-10] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417560 2012-01-10] (Intel Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [337264 2010-05-26] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d [201584 2010-03-10] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" [407920 2010-03-10] (Egis Technology Inc.)
HKLM-x32\...\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [611872 2010-08-04] ()
HKLM-x32\...\Run: [MDS_Menu] "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [ArcadeMovieService] "C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe" [124136 2010-06-29] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\John\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-05-11] (Google Inc.)
HKU\John\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17355912 2012-05-03] (Skype Technologies S.A.)
HKU\John\...\Run: [ANT Agent] C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe [14749544 2012-03-23] (GARMIN Corp.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76 192.168.1.1
==================== Services (Whitelisted) ======
2 GREGService; C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated)
2 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe" [375208 2012-07-12] (LogMeIn, Inc.)
2 LMIMaint; "C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe" [147368 2012-07-12] (LogMeIn, Inc.)
2 LogMeIn; "C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe" [407424 2011-09-16] (LogMeIn, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-26] (Egis Technology Inc.)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 NOBU; "C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE [2804568 2010-06-01] (Symantec Corporation)
2 RichVideo; "C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe" [244904 2010-05-12] ()
2 USBS3S4Detection; C:\OEM\USBDECTION\USBS3S4Detection.exe [76320 2009-12-09] ()
========================== Drivers (Whitelisted) =============
3 libusb0; C:\Windows\System32\Drivers\libusb0.sys [44480 2011-05-17] (http://libusb-win32.sourceforge.net)
2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [15928 2011-09-16] (LogMeIn, Inc.)
3 lmimirr; C:\Windows\System32\Drivers\lmimirr.sys [11552 2011-09-16] (LogMeIn, Inc.)
2 LMIRfsDriver; C:\Windows\System32\Drivers\LMIRfsDriver.sys [72216 2011-09-16] (LogMeIn, Inc.)
4 LMIRfsClientNP; [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-25 12:04 - 2012-07-25 12:04 - 00000000 ____D C:\FRST
2012-07-24 12:52 - 2012-07-24 12:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB1EA56D33AE6199
2012-07-24 12:36 - 2012-07-24 12:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4DB6A1706548C3D5
2012-07-24 12:22 - 2012-07-24 12:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.54F57B715141D40B
2012-07-24 12:19 - 2012-07-24 12:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15131A65FB02A0FE
2012-07-24 12:03 - 2012-07-24 12:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFFF008C7A471969
2012-07-24 11:47 - 2012-07-24 11:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6C3C323F6C38542E
2012-07-24 11:30 - 2012-07-24 11:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B69F24DD8C1A0F3E
2012-07-24 11:18 - 2012-07-24 11:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62DF5CE0534FD378
2012-07-24 11:13 - 2012-07-24 11:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7EB26E67A61EED38
2012-07-24 10:57 - 2012-07-24 10:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C049B24666361E31
2012-07-24 10:46 - 2012-07-24 10:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B79DAF875A54AB9A
2012-07-24 10:41 - 2012-07-24 10:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66D8ABEF0FF9D45C
2012-07-24 10:39 - 2009-06-10 13:00 - 00000824 ____A C:\Windows\System32\Drivers\etc\hosts.20120724-133900.backup
2012-07-24 10:38 - 2012-07-24 10:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5CB621C310B34BB0
2012-07-24 10:36 - 2012-07-24 10:36 - 00000000 ____D C:\Program Files (x86)\Oracle
2012-07-24 10:35 - 2012-07-05 19:06 - 00227760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-07-24 10:34 - 2012-06-26 22:43 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-07-24 10:34 - 2012-06-26 22:43 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-07-24 10:33 - 2012-07-24 10:34 - 00002954 ____A C:\Windows\SysWOW64\jupdate-1.7.0_05-b06.log
2012-07-24 10:31 - 2012-07-24 10:38 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy
2012-07-24 10:31 - 2012-07-24 10:36 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
2012-07-24 10:29 - 2012-07-24 10:29 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-24 10:29 - 2012-07-24 10:29 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-24 04:38 - 2012-07-24 04:38 - 00262144 ____A C:\Windows\Minidump\072412-17581-01.dmp
2012-07-23 13:09 - 2012-07-23 13:09 - 01116100 ____A C:\Users\John\Downloads\(No subject).zip
2012-07-19 06:36 - 2012-07-20 07:39 - 00000000 ____D C:\Users\John\Desktop\Pleasantdale
2012-07-19 06:30 - 2012-07-19 06:30 - 00000368 ____A C:\Users\John\Desktop\Oakley Enduring CndrRed Edge With VR28 Black Iridium 09-811 Joyride Cycles.url
2012-07-19 04:58 - 2012-07-19 04:58 - 01279901 ____A C:\Users\John\Desktop\gecko.zip
2012-07-16 12:59 - 2012-07-19 06:00 - 00000000 ____D C:\Users\John\Desktop\Avery Bball Camp July 2012
2012-07-14 19:37 - 2012-07-14 19:40 - 00012233 ____A C:\Users\John\Desktop\LGBC Nursery Schedule Pick up 2012-13.xlsx
2012-07-14 19:37 - 2012-07-14 19:37 - 00000165 ___AH C:\Users\John\Desktop\~$LGBC Nursery Schedule Pick up 2012-13.xlsx
2012-07-14 16:03 - 2012-07-14 16:03 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-11 00:05 - 2012-06-11 19:02 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 00:02 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 00:02 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 00:02 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 00:02 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 00:02 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 00:02 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 00:02 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 00:02 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 00:02 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 00:02 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 00:02 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 00:02 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 00:02 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 00:02 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 00:02 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 00:02 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 00:02 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 00:02 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 00:02 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 00:02 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 00:02 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 00:02 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 00:02 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 00:02 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 00:02 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 00:02 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 00:02 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 00:02 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-10 21:58 - 2012-06-08 21:30 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 21:58 - 2012-06-08 20:46 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 21:58 - 2012-06-05 21:50 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 21:58 - 2012-06-05 21:50 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 21:58 - 2012-06-05 21:09 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 21:58 - 2012-06-05 21:09 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 21:58 - 2012-06-01 21:38 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 21:58 - 2012-06-01 21:38 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 21:58 - 2012-06-01 21:37 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 21:58 - 2012-06-01 21:27 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 21:58 - 2012-06-01 21:27 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 21:58 - 2012-06-01 20:48 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 21:58 - 2012-06-01 20:48 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 21:58 - 2012-06-01 20:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 21:58 - 2012-06-01 20:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-03 07:00 - 2012-07-24 10:29 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-03 06:59 - 2012-07-24 10:29 - 00742892 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-03 06:59 - 2010-04-09 03:06 - 00374664 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2012-06-29 21:33 - 2012-01-31 02:59 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-06-29 11:10 - 2012-06-29 11:13 - 00000000 ____D C:\Users\John\Desktop\John Picture Frame Files
2012-06-28 15:00 - 2012-06-28 15:38 - 00000000 ____D C:\Users\John\Desktop\Frame
2012-06-26 11:59 - 2012-06-26 12:45 - 00000000 ____D C:\Users\John\Desktop\blinds
2012-06-25 07:25 - 2012-07-18 06:24 - 00000000 ____D C:\Users\John\Desktop\Leopard Geckos
============ 3 Months Modified Files ========================
2012-07-25 09:02 - 2009-07-13 20:51 - 00084515 ____A C:\Windows\setupact.log
2012-07-25 09:02 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-25 09:02 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-25 09:00 - 2009-07-13 21:13 - 00729514 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-25 08:56 - 2012-05-11 06:40 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-25 08:56 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-25 08:56 - 2007-10-10 23:05 - 01190293 ____A C:\Windows\WindowsUpdate.log
2012-07-25 08:48 - 2012-05-08 11:23 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-25 07:56 - 2012-05-11 06:40 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-24 13:02 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-24 12:52 - 2012-07-24 12:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB1EA56D33AE6199
2012-07-24 12:36 - 2012-07-24 12:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4DB6A1706548C3D5
2012-07-24 12:22 - 2012-07-24 12:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.54F57B715141D40B
2012-07-24 12:19 - 2012-07-24 12:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15131A65FB02A0FE
2012-07-24 12:03 - 2012-07-24 12:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFFF008C7A471969
2012-07-24 11:47 - 2012-07-24 11:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6C3C323F6C38542E
2012-07-24 11:30 - 2012-07-24 11:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B69F24DD8C1A0F3E
2012-07-24 11:18 - 2012-07-24 11:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62DF5CE0534FD378
2012-07-24 11:13 - 2012-07-24 11:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7EB26E67A61EED38
2012-07-24 10:57 - 2012-07-24 10:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C049B24666361E31
2012-07-24 10:46 - 2012-07-24 10:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B79DAF875A54AB9A
2012-07-24 10:41 - 2012-07-24 10:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66D8ABEF0FF9D45C
2012-07-24 10:38 - 2012-07-24 10:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5CB621C310B34BB0
2012-07-24 10:34 - 2012-07-24 10:33 - 00002954 ____A C:\Windows\SysWOW64\jupdate-1.7.0_05-b06.log
2012-07-24 10:29 - 2012-07-03 07:00 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-24 10:29 - 2012-07-03 06:59 - 00742892 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-24 04:38 - 2012-07-24 04:38 - 00262144 ____A C:\Windows\Minidump\072412-17581-01.dmp
2012-07-24 04:37 - 2012-05-08 17:54 - 585182112 ____A C:\Windows\MEMORY.DMP
2012-07-23 13:09 - 2012-07-23 13:09 - 01116100 ____A C:\Users\John\Downloads\(No subject).zip
2012-07-22 05:05 - 2012-06-24 05:57 - 00086368 ____A C:\Users\John\Desktop\2012-13 LGBC Nursery Schedule FINAL COPY_TEST.xlsx
2012-07-19 06:30 - 2012-07-19 06:30 - 00000368 ____A C:\Users\John\Desktop\Oakley Enduring CndrRed Edge With VR28 Black Iridium 09-811 Joyride Cycles.url
2012-07-19 04:58 - 2012-07-19 04:58 - 01279901 ____A C:\Users\John\Desktop\gecko.zip
2012-07-17 05:18 - 2007-10-10 23:01 - 00054166 ____A C:\Windows\PFRO.log
2012-07-14 19:40 - 2012-07-14 19:37 - 00012233 ____A C:\Users\John\Desktop\LGBC Nursery Schedule Pick up 2012-13.xlsx
2012-07-14 19:37 - 2012-07-14 19:37 - 00000165 ___AH C:\Users\John\Desktop\~$LGBC Nursery Schedule Pick up 2012-13.xlsx
2012-07-12 11:13 - 2012-05-08 11:34 - 00087488 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll
2012-07-12 11:13 - 2012-05-08 11:34 - 00080800 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll
2012-07-12 11:13 - 2012-05-08 11:34 - 00034720 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll
2012-07-11 18:48 - 2012-05-08 11:23 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-11 18:48 - 2012-05-08 11:23 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-11 00:23 - 2009-07-13 20:45 - 00345528 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 00:02 - 2012-05-29 13:36 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-05 19:06 - 2012-07-24 10:35 - 00227760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-07-05 19:06 - 2012-05-08 11:22 - 00772544 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2012-07-05 19:06 - 2012-05-08 11:22 - 00687544 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2012-07-02 11:09 - 2012-06-13 05:41 - 00001747 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-26 22:43 - 2012-07-24 10:34 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-06-26 22:43 - 2012-07-24 10:34 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-06-24 05:58 - 2012-06-24 05:57 - 00000165 ___AH C:\Users\John\Desktop\~$2012-13 LGBC Nursery Schedule FINAL COPY_TEST.xlsx
2012-06-20 16:08 - 2012-06-18 05:57 - 00155648 ____A C:\Users\John\Desktop\2012-13 LGBC Nursery Schedule.xls
2012-06-18 11:20 - 2012-06-10 19:32 - 00101376 ____H C:\Users\John\Desktop\~WRL1855.tmp
2012-06-17 12:56 - 2012-06-10 19:32 - 00101376 ____H C:\Users\John\Desktop\~WRL0004.tmp
2012-06-12 03:42 - 2012-06-12 03:42 - 00262144 ____A C:\Windows\Minidump\061212-16255-01.dmp
2012-06-11 19:02 - 2012-07-11 00:05 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-10 20:27 - 2012-06-10 19:32 - 00100864 ____H C:\Users\John\Desktop\~WRL0003.tmp
2012-06-08 21:30 - 2012-07-10 21:58 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:46 - 2012-07-10 21:58 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 21:50 - 2012-07-10 21:58 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:50 - 2012-07-10 21:58 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:09 - 2012-07-10 21:58 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:09 - 2012-07-10 21:58 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 10:30 - 2012-06-05 09:31 - 00098816 ____H C:\Users\John\Desktop\~WRL0002.tmp
2012-06-02 14:19 - 2012-06-20 23:18 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 23:18 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 23:18 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 23:18 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 23:18 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-20 23:18 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-20 23:18 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 12:19 - 2012-06-20 23:18 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:15 - 2012-06-20 23:18 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-11 00:02 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 00:02 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 00:02 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 00:02 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 00:02 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 00:02 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 00:02 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 00:02 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 00:02 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 00:02 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 00:02 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 00:02 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 00:02 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 00:02 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 00:02 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 00:02 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 00:02 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 00:02 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 00:02 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 00:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 00:02 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 00:02 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 00:02 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 00:02 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 00:02 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 00:02 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 00:02 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 00:02 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:38 - 2012-07-10 21:58 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:38 - 2012-07-10 21:58 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:37 - 2012-07-10 21:58 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:27 - 2012-07-10 21:58 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:27 - 2012-07-10 21:58 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:48 - 2012-07-10 21:58 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:48 - 2012-07-10 21:58 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:47 - 2012-07-10 21:58 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:42 - 2012-07-10 21:58 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-30 00:02 - 2012-05-30 00:00 - 00003881 ____A C:\Windows\IE9_main.log
2012-05-30 00:01 - 2012-05-30 00:01 - 03695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2012-05-30 00:01 - 2012-05-30 00:01 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-05-30 00:01 - 2012-05-30 00:01 - 00697344 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00603648 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00580608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00534528 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00452608 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00448512 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-05-30 00:01 - 2012-05-30 00:01 - 00434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00403248 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-05-30 00:01 - 2012-05-30 00:01 - 00353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00282112 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00267776 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00249344 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00165888 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00145920 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00135168 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00114176 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00111616 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00091648 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-05-30 00:01 - 2012-05-30 00:01 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2012-05-30 00:01 - 2012-05-30 00:01 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00049664 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-05-30 00:01 - 2012-05-30 00:01 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-05-30 00:01 - 2012-05-30 00:01 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-05-29 14:06 - 2012-05-29 13:26 - 00002024 ___AH C:\Users\John\Documents\Default.rdp
2012-05-24 13:18 - 2012-05-24 13:18 - 04472832 ____A (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
2012-05-23 08:33 - 2012-05-23 08:33 - 00037376 ____A C:\Users\John\Desktop\Copy of LGBC Nursery Worker Screening_5-23-12.xls
2012-05-19 18:50 - 2012-05-09 09:34 - 00099328 ____H C:\Users\John\Desktop\~WRL0001.tmp
2012-05-19 14:38 - 2012-05-08 11:34 - 00087456 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll.000.bak
2012-05-17 00:02 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-05-16 15:15 - 2012-05-16 15:15 - 00001074 ____A C:\Users\Public\Desktop\Picasa 3.lnk
2012-05-15 12:16 - 2012-05-15 12:16 - 00008607 ____A C:\Windows\System32\lvcoinst.log
2012-05-15 12:11 - 2012-05-15 12:11 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-05-12 00:00 - 2012-05-10 00:14 - 00283562 ____A C:\Windows\msxml4-KB973688-enu.LOG
2012-05-12 00:00 - 2012-05-10 00:11 - 00287348 ____A C:\Windows\msxml4-KB954430-enu.LOG
2012-05-11 00:30 - 2012-05-08 11:18 - 00088080 ____A C:\Users\John\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-10 19:47 - 2012-05-10 19:47 - 06448935 ____A C:\Users\John\Desktop\fontsforpeas.zip
2012-05-10 11:53 - 2012-05-10 11:53 - 00002550 ____N C:\Users\Public\Desktop\WildTangent Games App - acer.lnk
2012-05-09 11:13 - 2012-05-09 11:13 - 00001521 ____A C:\Users\John\Downloads\bergcert.cer
2012-05-09 11:06 - 2012-05-09 11:10 - 00000277 ____A C:\Users\John\Desktop\Berg Remote Office.url
2012-05-09 10:53 - 2012-05-09 10:53 - 00000020 ___SH C:\Users\LogMeInRemoteUser\ntuser.ini
2012-05-09 10:00 - 2012-05-09 10:00 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-05-08 17:54 - 2012-05-08 17:54 - 00873584 ____A C:\Windows\Minidump\050812-15568-01.dmp
2012-05-08 11:34 - 2012-05-08 11:34 - 00001024 ____A C:\.rnd
2012-05-08 11:20 - 2010-08-29 23:17 - 00058267 ____A C:\Windows\patch.log
2012-05-08 11:18 - 2007-10-10 23:26 - 00000413 ____A C:\Windows\System32\oem_Get_OS_Language.log
2012-05-08 11:17 - 2012-05-08 11:17 - 00000020 ___SH C:\Users\John\ntuser.ini
2012-05-04 02:52 - 2012-06-12 12:34 - 05505392 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:08 - 2012-06-12 12:34 - 03958128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:08 - 2012-06-12 12:34 - 03902320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-01 21:32 - 2012-06-12 12:34 - 00208896 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:50 - 2012-06-12 12:34 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
ZeroAccess:
C:\Windows\Installer\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}
C:\Windows\Installer\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}\@
C:\Windows\Installer\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}\L
C:\Windows\Installer\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}\U
C:\Windows\Installer\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}\U\00000001.@
ZeroAccess:
C:\Users\John\AppData\Local\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}
C:\Users\John\AppData\Local\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}\@
C:\Users\John\AppData\Local\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}\L
C:\Users\John\AppData\Local\{f614ccec-c0d4-98dd-495d-b98431fdf5c1}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 18%
Total physical RAM: 3959.11 MB
Available physical RAM: 3219.84 MB
Total Pagefile: 3957.26 MB
Available Pagefile: 3207.46 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (Acer) (Fixed) (Total:446.13 GB) (Free:334.63 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:19.53 GB) (Free:6.24 GB) NTFS
4 Drive g: () (Removable) (Total:3.83 GB) (Free:2.82 GB) FAT32
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
9 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 3935 MB 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 19 GB 1024 KB
Partition 2 Primary 100 MB 19 GB
Partition 3 Primary 446 GB 19 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E PQSERVICE NTFS Partition 19 GB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Acer NTFS Partition 446 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3929 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 3929 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-18 03:24
======================= End Of Log ==========================
Search.txt
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-25 12:09:59
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2012-07-24 13:02] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======