Inactive [A] Still yet more Win64/Sirefef.AE

Status
Not open for further replies.
1. Please open Notepad (Start>All Programs>Accessories>Notepad).

2. Now copy/paste the entire content of the codebox below into the Notepad window:

Code:
File::
c:\programdata\oy8XOlg2sbfSWB\Y5xkSVzVWD4sthWP\L55sp76B5np740\tkKLFoADIKs6k\SUjBQoPeYelf\bPw84MTuWvN35R\rNGZaBBdw.exe

Folder::
c:\programdata\oy8XOlg2sbfSWB

Driver::

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"b6jcgvAHL"=-

ClearJavaCache::


3. Save the above as CFScript.txt

4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

CFScript.gif



6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
 
ComboFix 12-06-24.03 - Dan 06/24/2012 20:59:03.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4084.2518 [GMT -7:00]
Running from: c:\users\Dan\Desktop\ComboFix.exe
Command switches used :: E:\CFScript.txt
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\programdata\oy8XOlg2sbfSWB\Y5xkSVzVWD4sthWP\L55sp76B5np740\tkKLFoADIKs6k\SUjBQoPeYelf\bPw84MTuWvN35R\rNGZaBBdw.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\6c2c9f7c19cc348bc2ecb60e6fdb722fe298a6fd
c:\programdata\oy8XOlg2sbfSWB
.
.
((((((((((((((((((((((((( Files Created from 2012-05-25 to 2012-06-25 )))))))))))))))))))))))))))))))
.
.
2012-06-25 04:11 . 2012-06-25 04:11 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2012-06-25 04:11 . 2012-06-25 04:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-24 23:55 . 2012-06-24 23:55 -------- d-sh--w- c:\programdata\5YiyzgQKmWPc
2012-06-24 23:40 . 2012-06-24 23:40 -------- d-sh--w- c:\programdata\tIKsOHoxEXhE
2012-06-24 23:26 . 2012-06-24 23:26 -------- d-----w- c:\users\Dan\AppData\Roaming\TeamViewer
2012-06-24 21:37 . 2012-06-24 21:39 -------- d-----w- C:\FRST
2012-06-23 23:01 . 2012-06-23 23:01 -------- d-----w- c:\program files\CCleaner
2012-06-23 22:41 . 2012-06-23 22:54 -------- d-----w- c:\programdata\HitmanPro
2012-06-13 03:57 . 2012-05-01 05:40 209920 ----a-w- c:\windows\system32\profsvc.dll
2012-06-10 20:14 . 2012-06-10 20:14 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll
2012-06-10 20:14 . 2012-06-10 20:14 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-15 10:48 . 2012-05-23 15:06 25743168 ----a-w- c:\windows\system32\nvoglv64.dll
2012-05-15 10:48 . 2012-05-23 15:06 19607872 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2012-05-15 10:48 . 2012-05-23 15:06 18044224 ----a-w- c:\windows\system32\nvd3dumx.dll
2012-05-15 10:48 . 2012-05-23 15:06 14298944 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-05-15 10:48 . 2012-05-23 15:06 2881856 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-05-15 10:48 . 2012-05-23 15:06 2681664 ----a-w- c:\windows\system32\nvcuvid.dll
2012-05-15 10:48 . 2012-05-23 15:06 2524992 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2012-05-15 10:48 . 2012-05-23 15:06 8139072 ----a-w- c:\windows\system32\nvcuda.dll
2012-05-15 10:48 . 2012-05-23 15:06 5982528 ----a-w- c:\windows\SysWow64\nvcuda.dll
2012-05-15 10:48 . 2012-05-23 15:06 2445120 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2012-05-15 10:48 . 2012-05-23 15:06 25248064 ----a-w- c:\windows\system32\nvcompiler.dll
2012-05-15 10:48 . 2012-05-23 15:06 2368832 ----a-w- c:\windows\SysWow64\nvapi.dll
2012-05-15 10:48 . 2012-05-23 15:06 17551680 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2012-05-15 10:48 . 2011-09-16 19:19 68928 ----a-w- c:\windows\system32\OpenCL.dll
2012-05-15 10:48 . 2011-09-16 19:19 61248 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-05-15 10:48 . 2011-09-12 15:16 1738048 ----a-w- c:\windows\system32\nvdispco64.dll
2012-05-15 10:48 . 2011-09-12 15:16 1468224 ----a-w- c:\windows\system32\nvgenco64.dll
2012-05-15 10:48 . 2010-01-16 08:02 8105280 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2012-05-15 10:48 . 2010-01-16 08:02 15322432 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2012-05-15 10:48 . 2009-12-07 01:30 2741568 ----a-w- c:\windows\system32\nvapi64.dll
2012-05-15 10:48 . 2009-12-07 01:30 10194752 ----a-w- c:\windows\system32\nvwgf2umx.dll
2012-05-15 09:29 . 2010-01-18 05:44 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-05-15 09:29 . 2010-01-18 05:44 2561856 ----a-w- c:\windows\system32\nvsvcr.dll
2012-05-15 09:29 . 2010-01-18 05:44 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-05-15 09:29 . 2009-12-07 17:02 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-05-15 09:29 . 2010-01-18 05:44 3149632 ----a-w- c:\windows\system32\nvsvc64.dll
2012-05-15 09:28 . 2010-01-18 05:44 6151488 ----a-w- c:\windows\system32\nvcpl.dll
2012-05-09 19:21 . 2012-05-17 05:12 476936 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-05-09 19:21 . 2011-09-28 05:39 472840 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-04-18 17:08 . 2012-05-23 15:06 31040 ----a-w- c:\windows\system32\nvhdap64.dll
2012-04-18 17:08 . 2012-05-23 15:06 188736 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2012-04-18 17:08 . 2012-05-23 15:06 1451840 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
2012-04-04 22:56 . 2011-04-09 10:02 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-30 11:35 . 2012-05-10 00:41 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-06-24_23.26.20 )))))))))))))))))))))))))))))))))))))))))
.
- 2010-06-28 05:57 . 2012-06-24 23:25 49152 c:\windows\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-28 05:57 . 2012-06-25 04:13 49152 c:\windows\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-28 05:57 . 2012-06-25 04:13 32768 c:\windows\Temp\History\History.IE5\index.dat
- 2010-06-28 05:57 . 2012-06-24 23:25 32768 c:\windows\Temp\History\History.IE5\index.dat
+ 2010-06-28 05:57 . 2012-06-25 04:13 32768 c:\windows\Temp\Cookies\index.dat
- 2010-06-28 05:57 . 2012-06-24 23:25 32768 c:\windows\Temp\Cookies\index.dat
- 2012-06-24 23:24 . 2012-06-24 23:24 24818 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2012-06-25 04:11 . 2012-06-25 04:11 24818 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2010-04-14 01:59 . 2012-06-25 03:41 75564 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-06-25 03:41 50450 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-06-28 05:27 . 2012-06-25 03:41 20474 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4217868683-3232887460-3359410862-1000_UserData.bin
- 2010-06-28 05:26 . 2012-06-24 23:09 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-28 05:26 . 2012-06-25 03:09 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-28 05:26 . 2012-06-25 03:09 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-06-28 05:26 . 2012-06-24 23:09 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-11-25 04:50 . 2012-06-24 23:25 4001 c:\windows\SysWOW64\mmf.sys
+ 2010-11-25 04:50 . 2012-06-25 04:13 4001 c:\windows\SysWOW64\mmf.sys
- 2012-06-24 23:25 . 2012-06-24 23:25 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-06-25 04:12 . 2012-06-25 04:12 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-06-24 23:25 . 2012-06-24 23:25 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-06-25 04:12 . 2012-06-25 04:12 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2012-06-24 23:24 330484 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-06-25 04:11 330484 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-03-23 00:27 . 2012-06-25 04:12 24708702 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4217868683-3232887460-3359410862-1000-8192.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn5\yt.dll" [2012-06-11 1524056]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Dan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Dan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Dan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-14 39408]
"Messenger (Yahoo!)"="c:\progra~2\Yahoo!\MESSEN~1\YahooMessenger.exe" [2011-08-22 6276408]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-04-19 15146376]
"GameXN GO"="c:\programdata\GameXN\GameXNGO.exe" [2011-09-09 347008]
"cMVk34"="c:\programdata\5YiyzgQKmWPc\Be5bbosH9x19A\tDIylWAAW4bwXzb4\sdQgmASGVCUe\QQUHJX8q4I2aSeg\gvUcAUUaegZ9xnc\XzjLTSO.exe" [2012-06-24 31231801]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-10-02 284696]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136]
"NortonOnlineBackupReminder"="c:\program files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" [2009-08-10 529256]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-11-24 2454840]
"HostManager"="c:\program files (x86)\Common Files\AOL\1277704962\ee\AOLSoftware.exe" [2010-02-10 41800]
"BrStsWnd"="c:\program files (x86)\Brownie\BrstsW64.exe" [2009-08-19 3695928]
"LifeCam"="c:\program files (x86)\Microsoft LifeCam\LifeExp.exe" [2010-05-20 119152]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-12-14 421160]
"PrintServer Diagnostic"="c:\program files (x86)\Print Server2\PTP\PSDiagnostic.exe" [2004-11-25 266240]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Dan\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-10-13 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro36Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro36CrusaderBoot]
@=""
.
R1 SASDIFSV;SASDIFSV;c:\users\Dan\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x]
R1 SASKUTIL;SASKUTIL;c:\users\Dan\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-28 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-03-01 183560]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-28 135664]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-16 113120]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-11-05 137560]
R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-11-10 824688]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [x]
S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [x]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2010-03-25 810120]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-10-02 13336]
S2 LicCtrlService;LicCtrl Service;c:\windows\runservice.exe [2011-11-17 2560]
S2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\SymcPCCULaunchSvc.exe [2010-09-02 115056]
S2 PCCUJobMgr;Common Client Job Manager Service;c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe [2009-08-24 126392]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-17 14112]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-10-14 994360]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-10-14 399416]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-09-28 251760]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 O2MDGRDR;O2MDGRDR;c:\windows\system32\DRIVERS\o2mdgx64.sys [x]
S3 O2SDGRDR;O2SDGRDR;c:\windows\system32\DRIVERS\o2sdgx64.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 QIOMem;Generic IO & Memory Access;c:\windows\system32\DRIVERS\QIOMem.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-25 c:\windows\Tasks\Free File Viewer Update Checker.job
- c:\program files (x86)\FreeFileViewer\FFVCheckForUpdates.exe [2010-11-11 19:25]
.
2012-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-28 05:37]
.
2012-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-28 05:37]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Dan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Dan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Dan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Dan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ThpSrv"="c:\windows\system32\thpsrv" [X]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-07-16 307768]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2009-10-09 508472]
"HDMICtrlMan"="c:\program files (x86)\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe" [BU]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU]
"HSON"="c:\program files (x86)\TOSHIBA\TBS\HSON.exe" [BU]
"SmoothView"="c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe" [BU]
"00TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU]
"Teco"="c:\program files (x86)\TOSHIBA\TECO\Teco.exe" [BU]
"TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU]
"SmartFaceVWatcher"="c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [BU]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-11-05 709976]
"TosNC"="c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe" [BU]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-03-25 2839840]
"VX3000"="c:\windows\vVX3000.exe" [2010-05-20 762736]
"TosReelTimeMonitor"="c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/ig?brand=TSNA&bmod=TSNA
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\llnx2h19.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aolTB50CL-chromesbox-en-us
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=843&invocationType=tb50-ff-aolTB50CL-ab-en-us&query=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCCUJobMgr]
"ImagePath"="\"c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10y_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10y_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10y.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10y.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10y.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10y.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$I&#&y@^t! #^$ g9^$&pgb SDB36o \F3F0046F119EFA4F]
"1"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,c2,97,86,6a,a5,82,f8,
d5,42,54,3b,7e,24,3e,19,f8
"2"=hex:74,3a,ea,7a,01,1a,f6,06,21,62,93,b5,cb,23,e3,91,85,38,0e,f8,ce,56,2c,
d2,a4,f2,d0,33,2d,ee,33,13
"3"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,c2,97,86,6a,a5,82,f8,
d5,be,55,66,4e,06,ba,4c,d8,66,9a,0f,4f,39,c4,a1,1d,fa,72,08,2f,25,9c,e8,b6,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$I&#&y@^t! #^$ g9^$&pgb SDB36o \F3F0046F119EFA4F\D26BD25DC85E777542CA969E56548E46]
"1"=hex:c0,52,20,b1,47,91,30,5f,58,6a,ea,d4,ff,71,4b,c6,a8,87,6f,5a,78,c6,5d,
5b,22,26,64,2f,88,eb,a4,7b
"2"=hex:2e,2a,64,cc,69,b1,fa,45
"3"=hex:86,66,03,06,89,8e,9d,a3,06,17,94,c5,23,94,55,f5,00,b5,44,3b,73,36,0d,
21,8f,76,99,bb,cd,2d,44,93,93,b6,87,bc,e5,d6,f1,26,47,22,e1,e5,51,d9,ec,95,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:c0,52,20,b1,47,91,30,5f,58,6a,ea,d4,ff,71,4b,c6,a8,87,6f,5a,78,c6,5d,
5b,8c,75,7b,03,a2,57,45,f3,7d,9a,95,05,b8,ad,07,d6,8a,81,08,3a,da,7f,4f,29,\
"7"=hex:9c,0f,26,c5,43,55,e2,9e,79,40,de,a7,ca,bc,f3,99,99,4d,91,38,55,4f,0b,
a5,8f,9b,e5,fc,d6,5f,45,dd,f6,df,ab,53,85,3c,a2,16,6d,58,d5,44,e1,b2,db,fb,\
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,dd,5f,b3,ed,0b,f3,84,
77,45,a9,de,2e,a4,95,f6,88,d1,8e,cf,5a,45,90,66,fc,23,93,03,59,55,2d,c6,bd,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:05,0c,6b,5f,6a,e7,f2,0c,7b,5d,7e,4f,98,94,49,3c,08,30,53,db,b5,36,5a,
12,fc,04,63,b0,bd,11,3b,3b,f2,cb,44,61,2e,42,17,38,30,b2,34,94,56,a2,ce,d2,\
"13"=hex:55,c2,ec,dd,1b,5b,87,c5,9c,06,6b,0b,f0,a2,40,58,36,88,0f,00,5a,a1,f6,
0b
"14"=hex:dd,25,64,f3,20,04,ef,cb
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:f9,15,03,41,f4,b7,0c,d1,1a,2e,f4,1f,4d,6e,68,c4
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:89,16,99,f7,70,4e,1d,5f,63,c5,26,4f,e0,0c,92,99,f7,48,f8,1b,96,ca,89,
e5,1a,ea,1e,5d,4c,7e,e8,e3,80,83,f8,2b,48,64,04,b0,ea,63,3d,68,13,28,07,a9,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$I&#&y@^t! #^$ g9^$&pgb SDB36o \F93383AA3238BCCB]
"1"=hex:47,af,e3,b9,38,4b,f6,e6,cb,8b,59,0c,3a,af,c5,a2,d6,9f,52,ce,23,dc,1a,
c2
"2"=hex:d1,c8,c3,5e,08,10,b9,8f,1e,fd,a6,7c,f5,6d,b0,f3,a6,71,8f,f8,ab,bd,bd,
76,64,10,04,f0,92,77,f9,20
"3"=hex:47,af,e3,b9,38,4b,f6,e6,cb,8b,59,0c,3a,af,c5,a2,ac,98,11,9b,be,95,83,
07,ae,ba,7e,d8,e6,d6,56,50,c4,dc,bb,7b,18,78,a4,de,04,5c,25,4e,9f,d7,39,6d
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$I&#&y@^t! #^$ g9^$&pgb SDB36o \F93383AA3238BCCB\DBF31101A5C3B93315CBBEA90ED13257]
"1"=hex:05,63,4e,ca,af,1d,39,e0,e8,3b,06,bc,35,26,5b,04,02,70,fd,49,72,ea,3f,
0d,c1,ed,7b,62,a7,87,bb,89
"2"=hex:c6,d7,96,b5,5f,fa,3f,77
"3"=hex:35,4f,bd,24,f4,ff,1d,e6,1f,8b,ea,de,24,6b,4b,03,7e,2c,ae,6b,69,82,4d,
61,99,79,85,94,21,41,ce,93,21,d2,1a,d7,12,1f,8c,68,a6,a5,ff,ee,42,ec,f5,27,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:05,63,4e,ca,af,1d,39,e0,e8,3b,06,bc,35,26,5b,04,02,70,fd,49,72,ea,3f,
0d,38,a0,6c,90,31,db,5a,af,1a,99,07,f1,ef,d1,93,a4,80,fd,34,8b,e9,c5,e1,a0,\
"7"=hex:3b,e8,2f,01,6c,32,33,d8,e1,d7,f3,f6,0e,0a,fa,46,62,39,09,43,d3,da,73,
d4,4e,db,d0,f9,b1,fb,0a,f1,d3,99,57,af,7d,98,93,fd,a5,1e,64,b6,5b,35,28,e1,\
"8"=hex:63,5a,d7,1b,b1,d4,18,46,3c,25,e7,95,a9,cd,5a,04,96,a6,43,00,08,a7,a8,
d1,a4,cd,ac,42,1d,60,62,ae,4b,ee,0e,92,e7,bf,f1,1a
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:fb,49,8e,8a,e1,88,6c,77,f4,d6,c4,14,d5,18,6b,97,ae,40,37,a0,e6,5c,11,
15,86,b5,53,01,4d,75,1a,6a,2a,45,7d,7c,ac,a9,63,3d,fe,6c,e5,92,b2,eb,13,d4,\
"13"=hex:d0,10,23,f6,a8,4f,4a,53,31,a8,38,4d,41,49,59,4a,98,82,a7,a2,6d,5a,ec,
40
"14"=hex:79,6a,b1,0b,fb,82,9f,17
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:0d,08,86,72,91,5d,e3,bf,a2,0d,fc,d5,c9,fe,2c,cd
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:3b,0c,4d,b3,79,79,33,9b,c4,65,a4,fd,16,13,8b,a4,a6,0d,9f,81,8c,50,22,
8b,8f,9f,cf,80,b9,99,e0,68,80,4f,34,27,61,a4,f4,b6,b1,b8,33,2a,a1,80,e8,df,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Swearware\backup\winsock2\Parameters]
@DACL=(02 0000)
@SACL=
"NameSpace_Callout"=expand:"%SystemRoot%\\System32\\fwpuclnt.dll"
"WinSock_Registry_Version"="2.0"
"AutodialDLL"="rasadhlp.dll"
"Current_NameSpace_Catalog"="NameSpace_Catalog5"
"Current_Protocol_Catalog"="Protocol_Catalog9"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\system32\DRIVERS\o2flash.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
.
**************************************************************************
.
Completion time: 2012-06-24 21:20:12 - machine was rebooted
ComboFix-quarantined-files.txt 2012-06-25 04:20
ComboFix2.txt 2012-06-24 23:31
.
Pre-Run: 402,839,056,384 bytes free
Post-Run: 402,541,461,504 bytes free
.
- - End Of File - - D00FDC13AD1522E600BF6DED87178E07
 
Combofix created restore point today around 4:16 PM.
Use it and see if it brings your connection back.
 
The closest restore point was 4:52 (the two on either side were 10:32 a.m. And 7:53 p.m.). The system restore (to 4:52) was successful, but still no Internet. Girlfriend's computer in the same room has access on the same wireless network.

The good news is, I'm not getting the error popups anymore!
 
Actually got an error message right after the restore, but haven't had one since. Before, I was getting them every minute or two.
 
Scan result of Farbar Recovery Scan Tool Version: 24-06-2012
Ran by SYSTEM at 25-06-2012 18:13:25
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry (Whitelisted) =============

HKLM\...\Run: [] [x]
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2009-07-16] ()
HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [508472 2009-10-09] (Conexant Systems, Inc.)
HKLM\...\Run: [HDMICtrlMan] %ProgramFiles%\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe [1032536 2009-10-23] (TOSHIBA Corporation.)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1810728 2009-07-30] (Synaptics Incorporated)
HKLM\...\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE [505696 2009-11-05] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe [52600 2009-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe [508216 2009-07-28] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe [910136 2009-11-10] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r [1482592 2009-09-28] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe [707416 2009-11-10] (TOSHIBA Corporation)
HKLM\...\Run: [ThpSrv] C:\windows\system32\thpsrv /logon [x]
HKLM\...\Run: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-10-19] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2009-11-05] (TOSHIBA Corporation)
HKLM\...\Run: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe [595816 2010-03-19] (TOSHIBA Corporation)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [2839840 2010-03-24] (ESET)
HKLM\...\Run: [VX3000] C:\windows\vVX3000.exe [762736 2010-05-20] (Microsoft Corporation)
HKLM\...\Run: [TosReelTimeMonitor] %programFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [35672 2010-03-03] (TOSHIBA Corporation)
HKLM-x32\...\Run: [TUSBSleepChargeSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe [x]
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-10-02] (Intel Corporation)
HKLM-x32\...\Run: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 [1294136 2009-10-06] (TOSHIBA Corporation)
HKLM-x32\...\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" UNATTENDED [529256 2009-08-09] (Toshiba)
HKLM-x32\...\Run: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun [2454840 2009-11-24] (TOSHIBA CORPORATION.)
HKLM-x32\...\Run: [HostManager] C:\Program Files (x86)\Common Files\AOL\1277704962\ee\AOLSoftware.exe [41800 2010-02-10] (AOL Inc.)
HKLM-x32\...\Run: [BrStsWnd] C:\Program Files (x86)\Brownie\BrstsW64.exe Autorun [3695928 2009-08-19] (brother)
HKLM-x32\...\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe" [119152 2010-05-20] (Microsoft Corporation)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421160 2010-12-13] (Apple Inc.)
HKLM-x32\...\Run: [PrintServer Diagnostic] C:\Program Files (x86)\Print Server2\PTP\PSDiagnostic.exe [266240 2004-11-24] ()
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKU\Dan\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-04-13] (Google Inc.)
HKU\Dan\...\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet [6276408 2011-08-22] (Yahoo! Inc.)
HKU\Dan\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
HKU\Dan\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized [15146376 2011-04-18] (Skype Technologies S.A.)
HKU\Dan\...\Run: [GameXN GO] "C:\ProgramData\GameXN\GameXNGO.exe" /startup [347008 2011-09-09] (EasyBits Software AS)
HKU\Dan\...\Run: [b6jcgvAHL] C:\ProgramData\oy8XOlg2sbfSWB\Y5xkSVzVWD4sthWP\L55sp76B5np740\tkKLFoADIKs6k\SUjBQoPeYelf\bPw84MTuWvN35R\rNGZaBBdw.exe [x]
HKU\Dan\...\Run: [zDNw8scVag] C:\ProgramData\kHZH44zq0ihdK\um4onlIcaTYIf\N3iNwWddUDYg\k9QqBEl.exe [31231801 2012-06-25] (Nrsft)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Dan\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)

==================== Services (Whitelisted) ======

3 AOL ACS; "C:\Program Files (x86)\Common Files\AOL\ACS\AOLAcsd.exe" [46640 2006-10-23] (AOL LLC)
3 EhttpSrv; "C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe" [42336 2010-03-24] (ESET)
2 ekrn; "C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe" [810120 2010-03-24] (ESET)
2 IviRegMgr; "C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe" [112152 2007-01-04] (InterVideo)
2 LicCtrlService; C:\windows\runservice.exe [2560 2011-11-17] ()
3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe" [227232 2010-01-15] (McAfee, Inc.)
2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\SymcPCCULaunchSvc.exe /s [115056 2010-09-01] (Symantec Corporation)
2 PCCUJobMgr; "C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe" /s "PCCUJobMgr" /m "C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\diMaster.dll" /prefetch:1 [132984 2009-08-29] (Symantec Corporation)
2 RpcEptMapper; C:\Windows\System32\RpcEpMap.dll [67072 2009-07-13] (Microsoft Corporation)
2 Secunia PSI Agent; "C:\Program Files (x86)\Secunia\PSI\PSIA.exe" --start-service [994360 2011-10-13] (Secunia)
2 Secunia Update Agent; "C:\Program Files (x86)\Secunia\PSI\sua.exe" --start-service [399416 2011-10-13] (Secunia)
3 WinHttpAutoProxySvc; winhttp.dll [444416 2010-11-20] (Microsoft Corporation)
3 WinHttpAutoProxySvc; winhttp.dll [351232 2010-11-20] (Microsoft Corporation)

========================== Drivers (Whitelisted) =============

2 eamonm; C:\Windows\System32\Drivers\eamonm.sys [163888 2010-03-24] (ESET)
1 ehdrv; C:\Windows\System32\Drivers\ehdrv.sys [139704 2010-03-24] (ESET)
2 epfwwfpr; C:\Windows\System32\Drivers\epfwwfpr.sys [124760 2010-03-24] (ESET)
3 O2SDGRDR; C:\Windows\System32\DRIVERS\o2sdgx64.sys [49568 2009-08-18] (O2Micro )
3 QIOMem; C:\Windows\System32\Drivers\QIOMem.sys [12800 2009-06-15] (TOSHIBA)
2 regi; C:\Windows\System32\Drivers\regi.sys [14112 2007-04-17] (InterVideo)
2 regi; C:\Windows\SysWow64\Drivers\regi.sys [11032 2007-04-17] (InterVideo)
3 tosrfec; C:\Windows\System32\Drivers\tosrfec.sys [19824 2009-07-13] (TOSHIBA Corporation)
0 TVALZ; C:\Windows\System32\DRIVERS\TVALZ_O.SYS [26840 2009-07-14] (TOSHIBA Corporation)
3 VX3000; C:\Windows\System32\Drivers\VX3000.sys [2060144 2010-05-20] (Microsoft Corporation)
3 wanatw; C:\Windows\System32\DRIVERS\wanatw64.sys [24064 2006-11-29] (America Online, Inc.)
1 SASDIFSV; \??\C:\Users\Dan\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x]
1 SASKUTIL; \??\C:\Users\Dan\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS [x]
3 Tosrfcom; [x]

========================== NetSvcs (Whitelisted) ===========


============ One Month Created Files and Folders ==============

2012-06-25 16:49 - 2012-06-25 16:49 - 29188941 ____A (Rel) C:\Users\All Users\GnV0YGUzYm.cpl
2012-06-25 16:46 - 2012-06-25 16:46 - 00000000 ____D C:\Users\Dan\AppData\Local\{64706EE0-03A2-4AB0-98B0-2DF837CECDA1}
2012-06-25 16:46 - 2012-06-25 16:46 - 00000000 ____D C:\Users\Dan\AppData\Local\{5C781CE6-2BD9-4F58-B280-FFD4B51B8A02}
2012-06-25 16:45 - 2012-06-25 16:45 - 00000000 __SHD C:\Users\All Users\kHZH44zq0ihdK
2012-06-25 16:11 - 2012-06-25 16:11 - 00000000 __SHD C:\Users\All Users\Ryrz6XbNNLwgWmp
2012-06-24 20:40 - 2012-06-25 16:45 - 00000304 ____A C:\Users\All Users\6c2c9f7c19cc348bc2ecb60e6fdb722fe298a6fd
2012-06-24 20:20 - 2012-06-24 20:20 - 00032184 ____A C:\ComboFix.txt
2012-06-24 15:55 - 2012-06-24 15:55 - 00000000 __SHD C:\Users\All Users\5YiyzgQKmWPc
2012-06-24 15:26 - 2012-06-24 15:26 - 00000000 ____D C:\Users\Dan\AppData\Roaming\TeamViewer
2012-06-24 15:07 - 2012-06-24 21:21 - 00000000 ____D C:\Qoobox
2012-06-24 14:45 - 2012-06-24 14:45 - 00000393 ____A C:\Users\Dan\Desktop\fixlist.txt
2012-06-24 13:37 - 2012-06-25 18:13 - 00000000 ____D C:\FRST
2012-06-24 09:26 - 2012-06-24 09:26 - 00000000 ____D C:\Users\Dan\AppData\Local\{F79465AE-734E-455C-8B3B-801112C059C1}
2012-06-24 09:25 - 2012-06-24 09:26 - 00000000 ____D C:\Users\Dan\AppData\Local\{29B7DFE9-5C92-431B-A3EB-F5621F6BF397}
2012-06-24 09:22 - 2012-06-25 16:42 - 00000112 ____A C:\Windows\setupact.log
2012-06-24 09:22 - 2012-06-24 09:22 - 00000000 ____A C:\Windows\setuperr.log
2012-06-23 15:10 - 2012-06-23 15:10 - 08828112 ____A (SurfRight B.V.) C:\Users\Dan\Downloads\HitmanPro36_x64(1).exe
2012-06-23 15:01 - 2012-06-25 16:39 - 00000000 ____D C:\Program Files\CCleaner
2012-06-23 15:01 - 2012-06-23 15:01 - 00000833 ____A C:\Users\Public\Desktop\CCleaner.lnk
2012-06-23 15:00 - 2012-06-23 15:00 - 03862112 ____A (Piriform Ltd) C:\Users\Dan\Downloads\ccsetup319.exe
2012-06-23 14:41 - 2012-06-25 16:40 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-23 14:41 - 2012-06-23 14:42 - 08828112 ____A (SurfRight B.V.) C:\Users\Dan\Downloads\HitmanPro36_x64.exe
2012-06-23 14:40 - 2012-06-23 14:41 - 07712104 ____A (SurfRight B.V.) C:\Users\Dan\Downloads\HitmanPro36.exe
2012-06-23 14:38 - 2012-06-23 14:38 - 02128472 ____A (Kaspersky Lab ZAO) C:\Users\Dan\Downloads\tdsskiller(1).exe
2012-06-23 10:35 - 2012-06-23 10:35 - 00000000 ____D C:\Users\Dan\AppData\Local\{5B60CA59-52AF-46E4-8E9E-205F0ECD97F2}
2012-06-23 10:34 - 2012-06-23 10:35 - 00000000 ____D C:\Users\Dan\AppData\Local\{B8E1E2AB-2880-491C-92A4-450657118565}
2012-06-22 20:23 - 2012-06-25 16:40 - 00000000 __SHD C:\Users\All Users\oy8XOlg2sbfSWB
2012-06-22 20:23 - 2012-06-22 20:23 - 29097015 ____A (Nrsft) C:\Users\All Users\uJ422WwP.exe
2012-06-22 19:31 - 2012-06-22 19:31 - 00000000 ____D C:\Users\Dan\AppData\Local\{D6B6EAAA-4B65-4B6E-A05D-0A90D7EF4983}
2012-06-22 19:31 - 2012-06-22 19:31 - 00000000 ____D C:\Users\Dan\AppData\Local\{47EB55E3-B76E-4A73-BA92-2B3DF38B530D}
2012-06-22 14:28 - 2012-06-22 14:29 - 510126615 ____A C:\Users\Dan\Desktop\21741.mov
2012-06-22 07:30 - 2012-06-22 07:30 - 00000000 ____D C:\Users\Dan\AppData\Local\{462A3DEA-58D6-4AAD-AB1A-DA3E42210BF7}
2012-06-22 07:30 - 2012-06-22 07:30 - 00000000 ____D C:\Users\Dan\AppData\Local\{1BF58B33-662B-4CEC-97BA-4AD71BE29833}
2012-06-21 10:05 - 2012-06-21 10:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{58766833-6E73-46BD-9C88-692D274EC3B4}
2012-06-21 10:04 - 2012-06-21 10:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{8467169C-71EA-478E-847B-6939DE23BF30}
2012-06-20 12:36 - 2012-06-20 12:36 - 00000000 ____D C:\Users\Dan\AppData\Local\{BC92BB70-B2FF-4304-9BEC-C7E8709C92F3}
2012-06-20 12:36 - 2012-06-20 12:36 - 00000000 ____D C:\Users\Dan\AppData\Local\{3F805B19-C8A5-4947-B622-A3E5060C7F6B}
2012-06-19 10:34 - 2012-06-19 10:34 - 00048749 ____A C:\Users\Dan\Desktop\snap_3e5d0bc6fa8483d498f9477dbfabbcc5.png
2012-06-19 10:19 - 2012-06-19 10:19 - 00038628 ____A C:\Users\Dan\Desktop\abra.png
2012-06-19 09:11 - 2012-06-19 09:11 - 00000000 ____D C:\Users\Dan\AppData\Local\{89736433-B6FE-4F20-9C49-B62CF3B27638}
2012-06-19 09:11 - 2012-06-19 09:11 - 00000000 ____D C:\Users\Dan\AppData\Local\{40B5B994-7C26-430A-875A-0A9BB6F773EB}
2012-06-18 18:54 - 2012-06-18 18:55 - 00000000 ____D C:\Users\Dan\AppData\Local\{DFC9DD8D-34C5-4812-AA81-42AC6ACE1FDC}
2012-06-18 18:54 - 2012-06-18 18:54 - 00000000 ____D C:\Users\Dan\AppData\Local\{263406F1-F975-494F-8BBB-6F78A94B101B}
2012-06-17 12:25 - 2012-06-17 12:26 - 00000000 ____D C:\Users\Dan\AppData\Local\{D2E3C0E5-9A2D-4BAC-AA23-300EF61B374A}
2012-06-16 21:48 - 2012-06-16 21:48 - 00000000 ____D C:\Users\Dan\AppData\Local\{A1AACBB3-0723-4E7F-9B72-49CBCADDABD9}
2012-06-16 09:47 - 2012-06-16 09:47 - 00000000 ____D C:\Users\Dan\AppData\Local\{8282D691-3842-4EFE-9614-C69D714C13F1}
2012-06-15 21:47 - 2012-06-15 21:47 - 00000000 ____D C:\Users\Dan\AppData\Local\{68F4BAA2-74D6-4117-A900-EA5196DD0BEC}
2012-06-15 08:20 - 2012-06-15 08:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{C650D261-256C-4E1B-A0BB-020A1F7BE532}
2012-06-14 21:17 - 2012-06-14 21:17 - 00000000 ____D C:\Users\Dan\Downloads\Campus Prep Course Book.scriv
2012-06-14 20:20 - 2012-06-14 20:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{78E68589-4CE1-4DD2-A874-8BBE76D367DE}
2012-06-14 08:19 - 2012-06-14 08:19 - 00000000 ____D C:\Users\Dan\AppData\Local\{77914D45-87F9-4D2D-BA29-A23E012450C1}
2012-06-14 08:19 - 2012-06-14 08:19 - 00000000 ____D C:\Users\Dan\AppData\Local\{21DD5BDE-8387-460F-846B-C339AAA6A3C0}
2012-06-13 15:20 - 2012-06-13 15:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{E5B2E040-E0D8-40EA-81DB-30A6911D3D94}
2012-06-13 15:19 - 2012-06-13 15:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{5FD13A09-CFCD-4764-AA34-A329A7788806}
2012-06-12 19:58 - 2012-05-14 20:01 - 01188864 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-12 19:58 - 2012-05-14 19:59 - 00064512 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-12 19:58 - 2012-05-14 19:03 - 00981504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-12 19:58 - 2012-05-14 19:00 - 00048128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-12 19:58 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-12 19:58 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-12 19:58 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-12 19:58 - 2012-04-19 21:42 - 12297216 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-12 19:58 - 2012-04-19 21:42 - 09059840 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-12 19:58 - 2012-04-19 21:42 - 02454528 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-12 19:58 - 2012-04-19 21:42 - 01494016 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-12 19:58 - 2012-04-19 21:42 - 00735744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-06-12 19:58 - 2012-04-19 21:42 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-12 19:58 - 2012-04-19 21:42 - 00134144 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-12 19:58 - 2012-04-19 21:42 - 00097792 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-12 19:58 - 2012-04-19 21:00 - 01231360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-12 19:58 - 2012-04-19 21:00 - 00132096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-12 19:58 - 2012-04-19 20:57 - 06027776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-12 19:58 - 2012-04-19 20:57 - 00627712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-06-12 19:58 - 2012-04-19 20:57 - 00067584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-12 19:58 - 2012-04-19 20:56 - 11020800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-12 19:58 - 2012-04-19 20:56 - 02073600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-12 19:58 - 2012-04-19 20:56 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-12 19:58 - 2012-04-19 19:45 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-12 19:58 - 2012-04-19 19:16 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-12 19:58 - 2012-04-16 21:31 - 00918016 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-12 19:58 - 2012-04-16 20:34 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-12 19:57 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 19:57 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-12 19:57 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-12 19:57 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-12 19:57 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-12 19:57 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 19:57 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 19:57 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 19:57 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-12 19:57 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-12 19:57 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-12 19:57 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-12 19:57 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-12 19:57 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-12 14:57 - 2012-06-12 14:57 - 00000000 ____D C:\Users\Dan\AppData\Local\{FDC6DEB4-966C-493F-9B38-FBE986EF9EB3}
2012-06-12 14:57 - 2012-06-12 14:57 - 00000000 ____D C:\Users\Dan\AppData\Local\{A12A2DA5-3760-4E03-B915-4F161C19B80F}
2012-06-11 19:59 - 2012-06-11 19:59 - 00000000 ____D C:\Users\Dan\AppData\Local\{41189B82-BC2F-45DC-8266-8880BFFB08FD}
2012-06-11 19:59 - 2012-06-11 19:59 - 00000000 ____D C:\Users\Dan\AppData\Local\{111BFB54-846E-4130-836C-90869241A26B}
2012-06-11 07:58 - 2012-06-11 07:58 - 00000000 ____D C:\Users\Dan\AppData\Local\{E641F3C7-8293-4D2B-B8FF-9E30883C2655}
2012-06-11 07:58 - 2012-06-11 07:58 - 00000000 ____D C:\Users\Dan\AppData\Local\{56E267E5-387D-46CE-8A42-42049EB91D05}
2012-06-10 12:30 - 2012-06-10 12:50 - 00140950 ____A C:\Users\Dan\Desktop\Oversold_Draft.rtf
2012-06-10 12:13 - 2012-06-10 12:14 - 00000000 ____D C:\Users\Dan\AppData\Local\{C9503E2B-804A-48F5-872F-321082F4B86C}
2012-06-10 12:13 - 2012-06-10 12:13 - 00000000 ____D C:\Users\Dan\AppData\Local\{8BC3E36F-16A8-4EA4-83EE-A1326A3E78DE}
2012-06-08 15:42 - 2012-06-08 15:42 - 00000000 ____D C:\Users\Dan\AppData\Local\{A9C6A9A1-4E26-4885-8ADE-C6885CF9B5AC}
2012-06-08 15:41 - 2012-06-08 15:42 - 00000000 ____D C:\Users\Dan\AppData\Local\{71ACB9E0-A185-4791-9337-5759BE383566}
2012-06-08 00:25 - 2012-06-08 00:25 - 00000000 ____D C:\Users\Dan\AppData\Local\{49A21C5B-FCB5-473B-A78E-05294CDE7826}
2012-06-08 00:24 - 2012-06-08 00:25 - 00000000 ____D C:\Users\Dan\AppData\Local\{6DD6DB93-46E3-4C9E-848C-705354F25127}
2012-06-07 12:24 - 2012-06-07 12:24 - 00000000 ____D C:\Users\Dan\AppData\Local\{79A065FF-B7C6-430C-8117-C9430B155E31}
2012-06-07 12:23 - 2012-06-07 12:24 - 00000000 ____D C:\Users\Dan\AppData\Local\{752978B8-AEA8-44F0-B96E-E06B49D0D59A}
2012-06-05 20:59 - 2012-06-05 20:59 - 00000000 ____D C:\Users\Dan\AppData\Local\{821061D1-D322-4496-94C2-09A92F13061A}
2012-06-05 20:59 - 2012-06-05 20:59 - 00000000 ____D C:\Users\Dan\AppData\Local\{2EFEDE88-BFE0-442F-A7EA-88EF89F8E68C}
2012-06-05 08:58 - 2012-06-05 08:58 - 00000000 ____D C:\Users\Dan\AppData\Local\{FABB7EBA-DD0E-4F0B-835E-0B19EF3DD37D}
2012-06-05 08:58 - 2012-06-05 08:58 - 00000000 ____D C:\Users\Dan\AppData\Local\{51615FE9-90DF-4F8D-B8EB-9B2EF30D3BD4}
2012-06-04 13:53 - 2012-06-04 13:53 - 00000000 ____D C:\Users\Dan\AppData\Local\{FC9895D4-A797-4891-B57E-B79527AEC425}
2012-06-04 13:52 - 2012-06-04 13:53 - 00000000 ____D C:\Users\Dan\AppData\Local\{83FB3A40-D85A-4E9F-92C1-25CD439747C4}
2012-06-03 22:45 - 2012-06-03 22:45 - 00000000 ____D C:\Users\Dan\AppData\Local\{D3683D46-E858-42F5-AA0D-AE66A75CEF20}
2012-06-03 22:45 - 2012-06-03 22:45 - 00000000 ____D C:\Users\Dan\AppData\Local\{6633E12F-4D54-4C0E-B956-F72F765218A3}
2012-06-03 17:51 - 2012-06-03 18:18 - 00114236 ____A C:\Users\Dan\Desktop\oversold.rtf
2012-06-03 10:44 - 2012-06-03 10:44 - 00000000 ____D C:\Users\Dan\AppData\Local\{D5E4C774-8545-43FF-8DCC-E487C254BE27}
2012-06-03 10:43 - 2012-06-03 10:43 - 00000000 ____D C:\Users\Dan\AppData\Local\{E0A5F164-2439-4A8F-B3DC-E9BA5478F09B}
2012-06-02 09:54 - 2012-06-02 09:55 - 00000000 ____D C:\Users\Dan\AppData\Local\{70E18275-E556-474E-BA88-61EE658021D8}
2012-06-02 09:54 - 2012-06-02 09:54 - 00000000 ____D C:\Users\Dan\AppData\Local\{04F91AEA-BC05-4918-9E1A-E6BE7D1CD91A}
2012-05-31 22:05 - 2012-05-31 22:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{FC8E1B6E-C056-47E4-AB55-F41541785F45}
2012-05-31 22:05 - 2012-05-31 22:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{9479528B-C7FD-4CA5-8F30-DC8218E8854C}
2012-05-31 10:07 - 2012-05-31 10:07 - 00000000 ____D C:\Users\Dan\Downloads\oversold backup.scriv
2012-05-31 10:05 - 2012-05-31 10:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{A54FD627-1AD7-41E4-B16E-84386F7F511E}
2012-05-31 10:04 - 2012-05-31 10:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{AF75446C-8B0F-41E7-94AB-22791F6CE9E4}
2012-05-30 22:04 - 2012-05-30 22:04 - 00000000 ____D C:\Users\Dan\AppData\Local\{46B3CB02-A9CE-4461-9A5A-9A47DD343687}
2012-05-30 22:03 - 2012-05-30 22:04 - 00000000 ____D C:\Users\Dan\AppData\Local\{982B8334-593F-42D6-B482-66EC3CDBE88A}
2012-05-30 09:39 - 2012-05-30 09:39 - 00000000 ____D C:\Users\Dan\AppData\Local\{C7776F67-7AD8-4EE9-895D-84A4CAE54376}
2012-05-30 09:39 - 2012-05-30 09:39 - 00000000 ____D C:\Users\Dan\AppData\Local\{58AEFD87-2EE9-4126-80B6-A695DD139A71}
2012-05-29 23:09 - 2012-05-29 23:09 - 00000000 ____D C:\Users\Dan\Downloads\Mystery.scriv
2012-05-29 23:04 - 2012-05-29 23:04 - 00000000 ____D C:\Users\Dan\Downloads\Mystery Project.scriv
2012-05-29 21:38 - 2012-05-29 21:39 - 00000000 ____D C:\Users\Dan\AppData\Local\{492891C4-C086-4FF4-BC99-ECF86C48ED4A}
2012-05-29 21:38 - 2012-05-29 21:38 - 00000000 ____D C:\Users\Dan\AppData\Local\{BF958220-E1D7-4EED-B74C-AA1C0AA283CE}
2012-05-28 10:11 - 2012-05-28 10:12 - 00000000 ____D C:\Users\Dan\AppData\Local\{E7596530-23A1-4EC4-B72C-DEFF82DE2270}
2012-05-28 10:11 - 2012-05-28 10:11 - 00000000 ____D C:\Users\Dan\AppData\Local\{02990671-A653-4596-B7FE-28DC2C23DECD}
2012-05-26 12:20 - 2012-05-26 12:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{3FF03AF4-DAD9-457C-B2B0-84FEE8F469C8}
2012-05-26 12:20 - 2012-05-26 12:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{1315FE5D-8096-4521-AD01-4625F9E0B3FF}


============ 3 Months Modified Files and Folders =============

2012-06-25 18:13 - 2012-06-24 13:37 - 00000000 ____D C:\FRST
2012-06-25 17:07 - 2010-08-06 10:45 - 00000286 ___AH C:\Windows\Brownie.ini
2012-06-25 17:07 - 2010-06-29 20:01 - 00000000 ____D C:\Users\Dan\AppData\Roaming\SoftGrid Client
2012-06-25 17:07 - 2010-06-04 01:38 - 02046282 ____A C:\Windows\WindowsUpdate.log
2012-06-25 17:05 - 2011-09-09 11:27 - 00000000 ____D C:\Users\All Users\GameXN
2012-06-25 16:59 - 2010-07-02 09:46 - 00000000 ____D C:\Users\Dan\Documents\Outlook Files
2012-06-25 16:55 - 2010-09-04 07:43 - 00000000 ____D C:\Users\Dan\AppData\Roaming\skypePM
2012-06-25 16:55 - 2010-09-04 07:41 - 00000000 ____D C:\Users\Dan\AppData\Roaming\Skype
2012-06-25 16:55 - 2010-06-27 21:28 - 00086320 ____A C:\Users\Dan\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-25 16:53 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-25 16:53 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-25 16:49 - 2012-06-25 16:49 - 29308871 ____A (Rel) C:\Users\All Users\7nbFgmRtfO.cpl
2012-06-25 16:49 - 2012-06-25 16:49 - 29188941 ____A (Rel) C:\Users\All Users\GnV0YGUzYm.cpl
2012-06-25 16:47 - 2010-11-08 08:20 - 00000000 ____D C:\Users\Dan\AppData\Local\Windows Live
2012-06-25 16:46 - 2012-06-25 16:46 - 00000000 ____D C:\Users\Dan\AppData\Local\{64706EE0-03A2-4AB0-98B0-2DF837CECDA1}
2012-06-25 16:46 - 2012-06-25 16:46 - 00000000 ____D C:\Users\Dan\AppData\Local\{5C781CE6-2BD9-4F58-B280-FFD4B51B8A02}
2012-06-25 16:46 - 2011-06-08 13:14 - 00000000 ___RD C:\Users\Dan\Dropbox
2012-06-25 16:46 - 2011-06-08 13:12 - 00000000 ____D C:\Users\Dan\AppData\Roaming\Dropbox
2012-06-25 16:45 - 2012-06-25 16:45 - 00000000 __SHD C:\Users\All Users\kHZH44zq0ihdK
2012-06-25 16:45 - 2012-06-24 20:40 - 00000304 ____A C:\Users\All Users\6c2c9f7c19cc348bc2ecb60e6fdb722fe298a6fd
2012-06-25 16:45 - 2011-03-22 15:43 - 00000000 ____D C:\Users\Dan\Tracing
2012-06-25 16:44 - 2010-06-27 21:37 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-25 16:43 - 2010-11-10 22:17 - 00000398 ____A C:\Windows\Tasks\Free File Viewer Update Checker.job
2012-06-25 16:43 - 2010-06-27 21:37 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-25 16:43 - 2010-06-27 21:26 - 00000000 ____D C:\users\Dan
2012-06-25 16:42 - 2012-06-24 09:22 - 00000112 ____A C:\Windows\setupact.log
2012-06-25 16:42 - 2011-12-16 00:00 - 00000000 ____D C:\Program Files\Bonjour
2012-06-25 16:42 - 2010-11-24 20:50 - 00004001 __ASH C:\Windows\SysWOW64\mmf.sys
2012-06-25 16:42 - 2010-09-04 07:53 - 00000000 ____D C:\Program Files\Microsoft LifeCam
2012-06-25 16:42 - 2010-06-29 20:00 - 00000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client
2012-06-25 16:42 - 2010-04-13 17:58 - 00000000 ____D C:\Program Files\PlayReady
2012-06-25 16:42 - 2009-07-13 23:45 - 00000000 ____D C:\Program Files\Windows Journal
2012-06-25 16:42 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-25 16:42 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\System
2012-06-25 16:40 - 2012-06-23 14:41 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-25 16:40 - 2012-06-22 20:23 - 00000000 __SHD C:\Users\All Users\oy8XOlg2sbfSWB
2012-06-25 16:40 - 2011-09-12 07:16 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2012-06-25 16:40 - 2011-08-25 20:05 - 00000000 ____D C:\Program Files\Ipswitch
2012-06-25 16:40 - 2010-12-25 23:12 - 00000000 ____D C:\Program Files\iTunes
2012-06-25 16:40 - 2010-12-25 23:11 - 00000000 ____D C:\Users\All Users\Apple Computer
2012-06-25 16:40 - 2010-11-10 22:17 - 00000000 ____D C:\Users\Dan\AppData\Roaming\FreeFileViewer
2012-06-25 16:40 - 2010-11-08 08:23 - 00000000 ____D C:\Program Files\Windows Live
2012-06-25 16:40 - 2010-09-04 07:41 - 00000000 ____D C:\Users\All Users\Skype
2012-06-25 16:40 - 2010-08-10 16:20 - 00000000 ____D C:\Users\All Users\McAfee Security Scan
2012-06-25 16:40 - 2010-07-13 16:06 - 00000000 ____D C:\Users\Dan\AppData\Local\Microsoft Help
2012-06-25 16:40 - 2010-07-07 09:05 - 00000000 ____D C:\Users\All Users\Apple
2012-06-25 16:40 - 2010-07-05 09:51 - 00000000 ____D C:\Users\All Users\Yahoo! Companion
2012-06-25 16:40 - 2010-07-05 09:51 - 00000000 ____D C:\Users\All Users\Yahoo!
2012-06-25 16:40 - 2010-06-27 22:03 - 00000000 ____D C:\Users\All Users\Macromedia
2012-06-25 16:40 - 2010-06-04 02:11 - 00000000 ____D C:\Program Files\Intuit
2012-06-25 16:40 - 2010-06-04 02:07 - 00000000 ____D C:\Users\All Users\WildTangent
2012-06-25 16:40 - 2010-06-04 02:05 - 00000000 ____D C:\Users\All Users\Norton
2012-06-25 16:40 - 2010-06-04 01:58 - 00000000 ____D C:\Program Files\Synaptics
2012-06-25 16:40 - 2010-06-04 01:53 - 00000000 ____D C:\Program Files\Common Files\TOSHIBA Shared
2012-06-25 16:40 - 2010-06-04 01:51 - 00000000 ____D C:\Program Files\CONEXANT
2012-06-25 16:40 - 2010-06-04 01:40 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-06-25 16:40 - 2010-04-13 20:31 - 00000000 ____D C:\Program Files\Google
2012-06-25 16:40 - 2010-04-13 20:26 - 00000000 ____D C:\Users\All Users\Toshiba
2012-06-25 16:40 - 2010-04-13 20:24 - 00000000 ____D C:\Program Files\TOSHIBA
2012-06-25 16:40 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2012-06-25 16:40 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Windows Portable Devices
2012-06-25 16:40 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2012-06-25 16:40 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Windows Defender
2012-06-25 16:40 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Reference Assemblies
2012-06-25 16:40 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\MSBuild
2012-06-25 16:40 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Microsoft Games
2012-06-25 16:40 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\DVD Maker
2012-06-25 16:40 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
2012-06-25 16:40 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
 
2012-06-25 16:40 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2012-06-25 16:40 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2012-06-25 16:40 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2012-06-25 16:40 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Windows NT
2012-06-25 16:40 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Services
2012-06-25 16:39 - 2012-06-23 15:01 - 00000000 ____D C:\Program Files\CCleaner
2012-06-25 16:39 - 2012-05-12 22:52 - 00000000 ____D C:\Program Files (x86)\Outline 4D
2012-06-25 16:39 - 2012-05-09 22:28 - 00000000 ____D C:\Program Files (x86)\Scrivener
2012-06-25 16:39 - 2012-05-06 19:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-25 16:39 - 2011-12-13 00:05 - 00000000 ____D C:\Program Files (x86)\FreeTorrentDownloader
2012-06-25 16:39 - 2011-09-12 07:06 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab
2012-06-25 16:39 - 2011-08-25 19:42 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2012-06-25 16:39 - 2011-08-05 15:10 - 00000000 ____D C:\Program Files (x86)\Print Server2
2012-06-25 16:39 - 2011-08-05 14:52 - 00000000 ____D C:\Program Files (x86)\Print Server
2012-06-25 16:39 - 2011-06-09 08:53 - 00000000 ____D C:\Program Files (x86)\WinZip
2012-06-25 16:39 - 2011-06-06 15:44 - 00000000 ____D C:\Program Files (x86)\GridinSoft Trojan Killer
2012-06-25 16:39 - 2011-05-29 08:05 - 00000000 ____D C:\Program Files (x86)\Guild Wars
2012-06-25 16:39 - 2011-04-09 10:33 - 00000000 ____D C:\Program Files (x86)\DominateGame
2012-06-25 16:39 - 2011-04-09 02:02 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-25 16:39 - 2010-12-25 23:12 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-06-25 16:39 - 2010-12-25 23:11 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-06-25 16:39 - 2010-12-25 23:10 - 00000000 ____D C:\Program Files\Common Files\Apple
2012-06-25 16:39 - 2010-12-22 11:18 - 00000000 ____D C:\Program Files (x86)\LeXpert
2012-06-25 16:39 - 2010-12-06 00:06 - 00000000 ____D C:\Program Files (x86)\Guitar-Leads
2012-06-25 16:39 - 2010-11-10 22:16 - 00000000 ____D C:\Program Files (x86)\FreeFileViewer
2012-06-25 16:39 - 2010-09-04 07:53 - 00000000 ____D C:\Program Files (x86)\Microsoft LifeCam
2012-06-25 16:39 - 2010-09-04 07:41 - 00000000 ___RD C:\Program Files (x86)\Skype
2012-06-25 16:39 - 2010-08-20 10:00 - 00000000 ____D C:\Program Files (x86)\Quicken
2012-06-25 16:39 - 2010-08-13 15:15 - 00000000 ____D C:\Program Files (x86)\PokerStars
2012-06-25 16:39 - 2010-08-10 16:20 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan
2012-06-25 16:39 - 2010-07-07 09:03 - 00000000 ____D C:\Program Files (x86)\eMedia Piano and Keyboard Method
2012-06-25 16:39 - 2010-07-05 09:49 - 00000000 ____D C:\Program Files (x86)\Yahoo!
2012-06-25 16:39 - 2010-07-02 18:15 - 00000000 ____D C:\Program Files (x86)\PopCap Games
2012-06-25 16:39 - 2010-06-30 19:06 - 00000000 ____D C:\Program Files (x86)\WordBiz
2012-06-25 16:39 - 2010-06-27 21:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-06-25 16:39 - 2010-06-04 02:12 - 00000000 ____D C:\Program Files (x86)\Norton PC Checkup
2012-06-25 16:39 - 2010-06-04 02:11 - 00000000 ____D C:\Program Files (x86)\Toshiba Online Backup
2012-06-25 16:39 - 2010-06-04 02:07 - 00000000 ____D C:\Program Files (x86)\TOSHIBA Games
2012-06-25 16:39 - 2010-06-04 01:57 - 00000000 ____D C:\Program Files (x86)\Realtek WLAN Driver
2012-06-25 16:39 - 2010-06-04 01:53 - 00000000 ____D C:\Program Files (x86)\O2Micro
2012-06-25 16:39 - 2010-06-04 01:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Office Suite Activation Assistant
2012-06-25 16:39 - 2010-06-04 01:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Works
2012-06-25 16:39 - 2010-04-13 20:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-06-25 16:39 - 2010-04-13 20:31 - 00000000 ____D C:\Program Files (x86)\Google
2012-06-25 16:39 - 2010-04-13 20:29 - 00000000 ____D C:\Program Files (x86)\Windows Live
2012-06-25 16:39 - 2010-04-13 20:24 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-06-25 16:39 - 2010-04-13 20:24 - 00000000 ____D C:\Program Files (x86)\TOSHIBA
2012-06-25 16:39 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\MSBuild
2012-06-25 16:39 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2012-06-25 16:39 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files (x86)\Windows NT
2012-06-25 16:38 - 2011-12-16 00:01 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2012-06-25 16:38 - 2011-12-16 00:00 - 00000000 ____D C:\Program Files (x86)\Bonjour
2012-06-25 16:38 - 2011-08-08 21:31 - 00000000 ____D C:\Jts
2012-06-25 16:38 - 2011-01-07 17:44 - 00000000 ____D C:\Program Files (x86)\Chess Assistant 10
2012-06-25 16:38 - 2011-01-07 17:13 - 00000000 ____D C:\AquariumData
2012-06-25 16:38 - 2011-01-07 17:13 - 00000000 ____D C:\Aquarium
2012-06-25 16:38 - 2011-01-07 16:58 - 00000000 ____D C:\Bridge Buff 19
2012-06-25 16:38 - 2010-08-06 10:53 - 00000000 ____D C:\Program Files (x86)\Brownie
2012-06-25 16:38 - 2010-06-27 22:20 - 00000000 ____D C:\Bridge Base Online
2012-06-25 16:38 - 2010-06-27 22:03 - 00000000 ____D C:\Program Files (x86)\AOL Toolbar
2012-06-25 16:38 - 2010-06-27 22:02 - 00000000 ____D C:\Program Files (x86)\AOL 9.5
2012-06-25 16:37 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration
2012-06-25 16:36 - 2011-02-26 23:28 - 00000000 ____D C:\Users\All Users\WinZip
2012-06-25 16:36 - 2010-12-25 23:12 - 00000000 ____D C:\Users\All Users\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2012-06-25 16:36 - 2009-07-13 19:20 - 00000000 ___RD C:\users\Default
2012-06-25 16:35 - 2012-05-12 22:52 - 00000000 ____D C:\Users\All Users\PACE Anti-Piracy
2012-06-25 16:35 - 2011-05-13 10:45 - 00000000 ____D C:\Users\All Users\Skype Extras
2012-06-25 16:35 - 2010-08-21 23:11 - 00000000 ____D C:\Users\All Users\qfit
2012-06-25 16:35 - 2010-06-27 22:03 - 00000000 ____D C:\Users\All Users\Viewpoint
2012-06-25 16:33 - 2011-08-25 20:05 - 00000000 ____D C:\Users\All Users\Ipswitch
2012-06-25 16:33 - 2011-04-09 02:02 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-25 16:33 - 2010-08-20 09:59 - 00000000 ____D C:\Users\All Users\Intuit
2012-06-25 16:33 - 2010-08-10 16:20 - 00000000 ____D C:\Users\All Users\McAfee
2012-06-25 16:33 - 2010-06-27 22:12 - 00000000 ____D C:\Users\All Users\ESET
2012-06-25 16:33 - 2010-06-27 22:03 - 00000000 ____D C:\Users\All Users\AOL Toolbar
2012-06-25 16:33 - 2010-06-27 22:02 - 00000000 ____D C:\Users\All Users\AOL
2012-06-25 16:33 - 2010-06-04 02:04 - 00000000 ____D C:\Users\All Users\Corel
2012-06-25 16:33 - 2010-04-13 20:31 - 00000000 ____D C:\Users\All Users\Google
2012-06-25 16:33 - 2010-04-13 20:27 - 00000000 ____D C:\Users\All Users\Adobe
2012-06-25 16:30 - 2011-08-05 14:18 - 00000000 ____D C:\Program Files\HP
2012-06-25 16:30 - 2010-12-25 23:12 - 00000000 ____D C:\Program Files\iPod
2012-06-25 16:30 - 2010-06-27 22:12 - 00000000 ____D C:\Program Files\ESET
2012-06-25 16:30 - 2010-06-04 01:40 - 00000000 ____D C:\Program Files\Microsoft Office
2012-06-25 16:29 - 2011-08-05 14:23 - 00000000 ___HD C:\Program Files (x86)\Zenographics
2012-06-25 16:29 - 2010-12-29 00:46 - 00000000 ____D C:\Program Files\Cucusoft
2012-06-25 16:29 - 2010-06-04 02:03 - 00000000 ____D C:\Program Files\Dolby
2012-06-25 16:29 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2012-06-25 16:28 - 2011-12-15 23:45 - 00000000 ____D C:\Program Files (x86)\Secunia
2012-06-25 16:28 - 2011-06-06 14:11 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2012-06-25 16:28 - 2010-12-29 00:07 - 00000000 ____D C:\Program Files (x86)\VOWSoft iPod Software
2012-06-25 16:28 - 2010-10-24 10:03 - 00000000 ____D C:\Program Files (x86)\TransMedia
2012-06-25 16:28 - 2010-06-27 22:03 - 00000000 ____D C:\Program Files (x86)\Viewpoint
2012-06-25 16:27 - 2012-05-23 07:09 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2012-06-25 16:27 - 2012-01-13 16:16 - 00000000 ____D C:\Program Files (x86)\RogerPf_com
2012-06-25 16:27 - 2010-11-25 00:47 - 00000000 ____D C:\Program Files (x86)\Out of the Park Developments
2012-06-25 16:27 - 2010-08-21 23:11 - 00000000 ____D C:\Program Files (x86)\QFIT
2012-06-25 16:27 - 2010-07-05 18:27 - 00000000 ____D C:\Program Files (x86)\PT Software
2012-06-25 16:27 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2012-06-25 16:26 - 2010-06-04 01:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2012-06-25 16:26 - 2010-04-13 20:30 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2012-06-25 16:26 - 2010-04-13 18:17 - 00000000 ____D C:\Program Files (x86)\Java
2012-06-25 16:25 - 2011-08-25 20:05 - 00000000 ____D C:\Program Files (x86)\Ipswitch
2012-06-25 16:25 - 2010-11-24 20:50 - 00000000 ____D C:\Program Files (x86)\GDS
2012-06-25 16:25 - 2010-06-27 22:24 - 00000000 ____D C:\Program Files (x86)\Internet Chess Club
2012-06-25 16:25 - 2010-06-04 02:11 - 00000000 ____D C:\Program Files (x86)\Intuit
2012-06-25 16:25 - 2010-06-04 02:04 - 00000000 ____D C:\Program Files (x86)\Corel
2012-06-25 16:25 - 2010-04-13 18:15 - 00000000 ____D C:\Program Files (x86)\Intel
2012-06-25 16:22 - 2012-01-25 00:12 - 00000000 ____D C:\Program Files (x86)\Barnes & Noble
2012-06-25 16:22 - 2010-11-27 19:45 - 00000000 ____D C:\Program Files (x86)\Amazon
2012-06-25 16:22 - 2010-08-06 10:45 - 00000000 ____D C:\Program Files (x86)\Brother
2012-06-25 16:22 - 2010-06-27 22:02 - 00000000 ____D C:\Program Files (x86)\AOL
2012-06-25 16:22 - 2010-04-13 20:27 - 00000000 ____D C:\Program Files (x86)\Adobe
2012-06-25 16:21 - 2011-09-12 07:15 - 00000000 ____D C:\NVIDIA
2012-06-25 16:21 - 2010-06-04 01:40 - 00000000 __RHD C:\MSOCache
2012-06-25 16:11 - 2012-06-25 16:11 - 00000000 __SHD C:\Users\All Users\Ryrz6XbNNLwgWmp
2012-06-25 16:11 - 2011-05-28 10:08 - 00000000 ____D C:\Users\Dan\AppData\Roaming\go
2012-06-24 21:21 - 2012-06-24 15:07 - 00000000 ____D C:\Qoobox
2012-06-24 21:21 - 2010-07-15 20:58 - 00000000 ____D C:\Windows\Minidump
2012-06-24 21:21 - 2009-07-13 23:44 - 00000000 ___RD C:\Users\Public\Recorded TV
2012-06-24 20:20 - 2012-06-24 20:20 - 00032184 ____A C:\ComboFix.txt
2012-06-24 17:45 - 2011-10-13 11:04 - 00000000 ____D C:\Users\Dan\Desktop\LSAT
2012-06-24 15:55 - 2012-06-24 15:55 - 00000000 __SHD C:\Users\All Users\5YiyzgQKmWPc
2012-06-24 15:26 - 2012-06-24 15:26 - 00000000 ____D C:\Users\Dan\AppData\Roaming\TeamViewer
2012-06-24 14:45 - 2012-06-24 14:45 - 00000393 ____A C:\Users\Dan\Desktop\fixlist.txt
2012-06-24 09:26 - 2012-06-24 09:26 - 00000000 ____D C:\Users\Dan\AppData\Local\{F79465AE-734E-455C-8B3B-801112C059C1}
2012-06-24 09:26 - 2012-06-24 09:25 - 00000000 ____D C:\Users\Dan\AppData\Local\{29B7DFE9-5C92-431B-A3EB-F5621F6BF397}
2012-06-24 09:22 - 2012-06-24 09:22 - 00000000 ____A C:\Windows\setuperr.log
2012-06-23 15:10 - 2012-06-23 15:10 - 08828112 ____A (SurfRight B.V.) C:\Users\Dan\Downloads\HitmanPro36_x64(1).exe
2012-06-23 15:05 - 2011-08-25 19:42 - 00000000 ____D C:\Users\Dan\AppData\Roaming\FileZilla
2012-06-23 15:04 - 2010-04-14 10:32 - 00000000 ____D C:\Windows\Panther
2012-06-23 15:01 - 2012-06-23 15:01 - 00000833 ____A C:\Users\Public\Desktop\CCleaner.lnk
2012-06-23 15:00 - 2012-06-23 15:00 - 03862112 ____A (Piriform Ltd) C:\Users\Dan\Downloads\ccsetup319.exe
2012-06-23 14:42 - 2012-06-23 14:41 - 08828112 ____A (SurfRight B.V.) C:\Users\Dan\Downloads\HitmanPro36_x64.exe
2012-06-23 14:41 - 2012-06-23 14:40 - 07712104 ____A (SurfRight B.V.) C:\Users\Dan\Downloads\HitmanPro36.exe
2012-06-23 14:38 - 2012-06-23 14:38 - 02128472 ____A (Kaspersky Lab ZAO) C:\Users\Dan\Downloads\tdsskiller(1).exe
2012-06-23 12:18 - 2011-12-28 20:00 - 00001124 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-23 10:35 - 2012-06-23 10:35 - 00000000 ____D C:\Users\Dan\AppData\Local\{5B60CA59-52AF-46E4-8E9E-205F0ECD97F2}
2012-06-23 10:35 - 2012-06-23 10:34 - 00000000 ____D C:\Users\Dan\AppData\Local\{B8E1E2AB-2880-491C-92A4-450657118565}
2012-06-22 20:23 - 2012-06-22 20:23 - 29097015 ____A (Nrsft) C:\Users\All Users\uJ422WwP.exe
2012-06-22 19:31 - 2012-06-22 19:31 - 00000000 ____D C:\Users\Dan\AppData\Local\{D6B6EAAA-4B65-4B6E-A05D-0A90D7EF4983}
2012-06-22 19:31 - 2012-06-22 19:31 - 00000000 ____D C:\Users\Dan\AppData\Local\{47EB55E3-B76E-4A73-BA92-2B3DF38B530D}
2012-06-22 14:29 - 2012-06-22 14:28 - 510126615 ____A C:\Users\Dan\Desktop\21741.mov
2012-06-22 07:30 - 2012-06-22 07:30 - 00000000 ____D C:\Users\Dan\AppData\Local\{462A3DEA-58D6-4AAD-AB1A-DA3E42210BF7}
2012-06-22 07:30 - 2012-06-22 07:30 - 00000000 ____D C:\Users\Dan\AppData\Local\{1BF58B33-662B-4CEC-97BA-4AD71BE29833}
2012-06-21 10:05 - 2012-06-21 10:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{58766833-6E73-46BD-9C88-692D274EC3B4}
2012-06-21 10:05 - 2012-06-21 10:04 - 00000000 ____D C:\Users\Dan\AppData\Local\{8467169C-71EA-478E-847B-6939DE23BF30}
2012-06-20 12:36 - 2012-06-20 12:36 - 00000000 ____D C:\Users\Dan\AppData\Local\{BC92BB70-B2FF-4304-9BEC-C7E8709C92F3}
2012-06-20 12:36 - 2012-06-20 12:36 - 00000000 ____D C:\Users\Dan\AppData\Local\{3F805B19-C8A5-4947-B622-A3E5060C7F6B}
2012-06-19 10:34 - 2012-06-19 10:34 - 00048749 ____A C:\Users\Dan\Desktop\snap_3e5d0bc6fa8483d498f9477dbfabbcc5.png
2012-06-19 10:19 - 2012-06-19 10:19 - 00038628 ____A C:\Users\Dan\Desktop\abra.png
2012-06-19 09:11 - 2012-06-19 09:11 - 00000000 ____D C:\Users\Dan\AppData\Local\{89736433-B6FE-4F20-9C49-B62CF3B27638}
2012-06-19 09:11 - 2012-06-19 09:11 - 00000000 ____D C:\Users\Dan\AppData\Local\{40B5B994-7C26-430A-875A-0A9BB6F773EB}
2012-06-18 18:55 - 2012-06-18 18:54 - 00000000 ____D C:\Users\Dan\AppData\Local\{DFC9DD8D-34C5-4812-AA81-42AC6ACE1FDC}
2012-06-18 18:54 - 2012-06-18 18:54 - 00000000 ____D C:\Users\Dan\AppData\Local\{263406F1-F975-494F-8BBB-6F78A94B101B}
2012-06-17 12:26 - 2012-06-17 12:25 - 00000000 ____D C:\Users\Dan\AppData\Local\{D2E3C0E5-9A2D-4BAC-AA23-300EF61B374A}
2012-06-16 21:48 - 2012-06-16 21:48 - 00000000 ____D C:\Users\Dan\AppData\Local\{A1AACBB3-0723-4E7F-9B72-49CBCADDABD9}
2012-06-16 09:47 - 2012-06-16 09:47 - 00000000 ____D C:\Users\Dan\AppData\Local\{8282D691-3842-4EFE-9614-C69D714C13F1}
2012-06-15 21:47 - 2012-06-15 21:47 - 00000000 ____D C:\Users\Dan\AppData\Local\{68F4BAA2-74D6-4117-A900-EA5196DD0BEC}
2012-06-15 08:20 - 2012-06-15 08:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{C650D261-256C-4E1B-A0BB-020A1F7BE532}
2012-06-14 21:17 - 2012-06-14 21:17 - 00000000 ____D C:\Users\Dan\Downloads\Campus Prep Course Book.scriv
2012-06-14 20:20 - 2012-06-14 20:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{78E68589-4CE1-4DD2-A874-8BBE76D367DE}
2012-06-14 15:47 - 2009-07-13 21:08 - 00032622 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-14 08:19 - 2012-06-14 08:19 - 00000000 ____D C:\Users\Dan\AppData\Local\{77914D45-87F9-4D2D-BA29-A23E012450C1}
2012-06-14 08:19 - 2012-06-14 08:19 - 00000000 ____D C:\Users\Dan\AppData\Local\{21DD5BDE-8387-460F-846B-C339AAA6A3C0}
2012-06-13 15:20 - 2012-06-13 15:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{E5B2E040-E0D8-40EA-81DB-30A6911D3D94}
2012-06-13 15:20 - 2012-06-13 15:19 - 00000000 ____D C:\Users\Dan\AppData\Local\{5FD13A09-CFCD-4764-AA34-A329A7788806}
2012-06-13 15:16 - 2009-07-13 20:45 - 00361096 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-12 23:18 - 2009-07-13 21:13 - 00741704 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-12 23:15 - 2010-06-27 22:26 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-12 14:57 - 2012-06-12 14:57 - 00000000 ____D C:\Users\Dan\AppData\Local\{FDC6DEB4-966C-493F-9B38-FBE986EF9EB3}
2012-06-12 14:57 - 2012-06-12 14:57 - 00000000 ____D C:\Users\Dan\AppData\Local\{A12A2DA5-3760-4E03-B915-4F161C19B80F}
2012-06-11 19:59 - 2012-06-11 19:59 - 00000000 ____D C:\Users\Dan\AppData\Local\{41189B82-BC2F-45DC-8266-8880BFFB08FD}
2012-06-11 19:59 - 2012-06-11 19:59 - 00000000 ____D C:\Users\Dan\AppData\Local\{111BFB54-846E-4130-836C-90869241A26B}
2012-06-11 19:47 - 2011-06-06 15:08 - 00002355 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-06-11 07:58 - 2012-06-11 07:58 - 00000000 ____D C:\Users\Dan\AppData\Local\{E641F3C7-8293-4D2B-B8FF-9E30883C2655}
2012-06-11 07:58 - 2012-06-11 07:58 - 00000000 ____D C:\Users\Dan\AppData\Local\{56E267E5-387D-46CE-8A42-42049EB91D05}
2012-06-10 12:50 - 2012-06-10 12:30 - 00140950 ____A C:\Users\Dan\Desktop\Oversold_Draft.rtf
2012-06-10 12:14 - 2012-06-10 12:13 - 00000000 ____D C:\Users\Dan\AppData\Local\{C9503E2B-804A-48F5-872F-321082F4B86C}
2012-06-10 12:13 - 2012-06-10 12:13 - 00000000 ____D C:\Users\Dan\AppData\Local\{8BC3E36F-16A8-4EA4-83EE-A1326A3E78DE}
2012-06-08 15:42 - 2012-06-08 15:42 - 00000000 ____D C:\Users\Dan\AppData\Local\{A9C6A9A1-4E26-4885-8ADE-C6885CF9B5AC}
2012-06-08 15:42 - 2012-06-08 15:41 - 00000000 ____D C:\Users\Dan\AppData\Local\{71ACB9E0-A185-4791-9337-5759BE383566}
2012-06-08 00:25 - 2012-06-08 00:25 - 00000000 ____D C:\Users\Dan\AppData\Local\{49A21C5B-FCB5-473B-A78E-05294CDE7826}
2012-06-08 00:25 - 2012-06-08 00:24 - 00000000 ____D C:\Users\Dan\AppData\Local\{6DD6DB93-46E3-4C9E-848C-705354F25127}
2012-06-07 12:24 - 2012-06-07 12:24 - 00000000 ____D C:\Users\Dan\AppData\Local\{79A065FF-B7C6-430C-8117-C9430B155E31}
2012-06-07 12:24 - 2012-06-07 12:23 - 00000000 ____D C:\Users\Dan\AppData\Local\{752978B8-AEA8-44F0-B96E-E06B49D0D59A}
2012-06-05 20:59 - 2012-06-05 20:59 - 00000000 ____D C:\Users\Dan\AppData\Local\{821061D1-D322-4496-94C2-09A92F13061A}
2012-06-05 20:59 - 2012-06-05 20:59 - 00000000 ____D C:\Users\Dan\AppData\Local\{2EFEDE88-BFE0-442F-A7EA-88EF89F8E68C}
2012-06-05 08:58 - 2012-06-05 08:58 - 00000000 ____D C:\Users\Dan\AppData\Local\{FABB7EBA-DD0E-4F0B-835E-0B19EF3DD37D}
2012-06-05 08:58 - 2012-06-05 08:58 - 00000000 ____D C:\Users\Dan\AppData\Local\{51615FE9-90DF-4F8D-B8EB-9B2EF30D3BD4}
2012-06-04 13:53 - 2012-06-04 13:53 - 00000000 ____D C:\Users\Dan\AppData\Local\{FC9895D4-A797-4891-B57E-B79527AEC425}
2012-06-04 13:53 - 2012-06-04 13:52 - 00000000 ____D C:\Users\Dan\AppData\Local\{83FB3A40-D85A-4E9F-92C1-25CD439747C4}
2012-06-03 22:45 - 2012-06-03 22:45 - 00000000 ____D C:\Users\Dan\AppData\Local\{D3683D46-E858-42F5-AA0D-AE66A75CEF20}
2012-06-03 22:45 - 2012-06-03 22:45 - 00000000 ____D C:\Users\Dan\AppData\Local\{6633E12F-4D54-4C0E-B956-F72F765218A3}
2012-06-03 18:18 - 2012-06-03 17:51 - 00114236 ____A C:\Users\Dan\Desktop\oversold.rtf
2012-06-03 10:44 - 2012-06-03 10:44 - 00000000 ____D C:\Users\Dan\AppData\Local\{D5E4C774-8545-43FF-8DCC-E487C254BE27}
2012-06-03 10:43 - 2012-06-03 10:43 - 00000000 ____D C:\Users\Dan\AppData\Local\{E0A5F164-2439-4A8F-B3DC-E9BA5478F09B}
2012-06-02 15:53 - 2011-06-08 13:14 - 00000984 ____A C:\Users\Dan\Desktop\Dropbox.lnk
2012-06-02 09:55 - 2012-06-02 09:54 - 00000000 ____D C:\Users\Dan\AppData\Local\{70E18275-E556-474E-BA88-61EE658021D8}
2012-06-02 09:54 - 2012-06-02 09:54 - 00000000 ____D C:\Users\Dan\AppData\Local\{04F91AEA-BC05-4918-9E1A-E6BE7D1CD91A}
2012-05-31 22:05 - 2012-05-31 22:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{FC8E1B6E-C056-47E4-AB55-F41541785F45}
2012-05-31 22:05 - 2012-05-31 22:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{9479528B-C7FD-4CA5-8F30-DC8218E8854C}
2012-05-31 10:07 - 2012-05-31 10:07 - 00000000 ____D C:\Users\Dan\Downloads\oversold backup.scriv
2012-05-31 10:05 - 2012-05-31 10:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{A54FD627-1AD7-41E4-B16E-84386F7F511E}
2012-05-31 10:05 - 2012-05-31 10:04 - 00000000 ____D C:\Users\Dan\AppData\Local\{AF75446C-8B0F-41E7-94AB-22791F6CE9E4}
2012-05-30 22:04 - 2012-05-30 22:04 - 00000000 ____D C:\Users\Dan\AppData\Local\{46B3CB02-A9CE-4461-9A5A-9A47DD343687}
2012-05-30 22:04 - 2012-05-30 22:03 - 00000000 ____D C:\Users\Dan\AppData\Local\{982B8334-593F-42D6-B482-66EC3CDBE88A}
2012-05-30 09:39 - 2012-05-30 09:39 - 00000000 ____D C:\Users\Dan\AppData\Local\{C7776F67-7AD8-4EE9-895D-84A4CAE54376}
2012-05-30 09:39 - 2012-05-30 09:39 - 00000000 ____D C:\Users\Dan\AppData\Local\{58AEFD87-2EE9-4126-80B6-A695DD139A71}
2012-05-29 23:09 - 2012-05-29 23:09 - 00000000 ____D C:\Users\Dan\Downloads\Mystery.scriv
2012-05-29 23:04 - 2012-05-29 23:04 - 00000000 ____D C:\Users\Dan\Downloads\Mystery Project.scriv
2012-05-29 21:39 - 2012-05-29 21:38 - 00000000 ____D C:\Users\Dan\AppData\Local\{492891C4-C086-4FF4-BC99-ECF86C48ED4A}
2012-05-29 21:38 - 2012-05-29 21:38 - 00000000 ____D C:\Users\Dan\AppData\Local\{BF958220-E1D7-4EED-B74C-AA1C0AA283CE}
2012-05-28 10:12 - 2012-05-28 10:11 - 00000000 ____D C:\Users\Dan\AppData\Local\{E7596530-23A1-4EC4-B72C-DEFF82DE2270}
2012-05-28 10:11 - 2012-05-28 10:11 - 00000000 ____D C:\Users\Dan\AppData\Local\{02990671-A653-4596-B7FE-28DC2C23DECD}
2012-05-26 12:20 - 2012-05-26 12:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{3FF03AF4-DAD9-457C-B2B0-84FEE8F469C8}
2012-05-26 12:20 - 2012-05-26 12:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{1315FE5D-8096-4521-AD01-4625F9E0B3FF}
2012-05-25 17:32 - 2012-05-25 17:31 - 00000000 ____D C:\Users\Dan\AppData\Local\{94706BBA-5E5D-466D-8106-61612179C09C}
2012-05-25 17:31 - 2012-05-25 17:31 - 00000000 ____D C:\Users\Dan\AppData\Local\{2A8FC5CD-D1E8-4114-8065-12A4ADD54F4E}
2012-05-24 21:06 - 2012-05-24 21:06 - 00000000 ____D C:\Users\Dan\AppData\Local\{84E4343D-6366-434D-801D-A7DEA7FD9BB4}
2012-05-24 21:06 - 2012-05-24 21:06 - 00000000 ____D C:\Users\Dan\AppData\Local\{5CD05D62-3FB6-4F60-8959-DFABA6B36408}
2012-05-24 09:05 - 2012-05-24 09:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{DCE921B2-5FC7-49B0-B24E-B026120B14BC}
2012-05-24 09:05 - 2012-05-24 09:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{CD3764EE-41D3-49A9-9BC9-0CB43F9A432B}
2012-05-23 19:54 - 2012-05-23 19:53 - 00000000 ____D C:\Users\Dan\AppData\Local\{E0930C51-ADC5-4421-94AC-52B09F5C0710}
2012-05-23 19:53 - 2012-05-23 19:53 - 00000000 ____D C:\Users\Dan\AppData\Local\{50E9EF8C-3E93-4D66-8806-34455001B2B6}
2012-05-23 07:08 - 2010-06-04 01:49 - 00000000 ____D C:\Users\All Users\NVIDIA
2012-05-23 07:04 - 2012-05-23 06:59 - 214613632 ____A (NVIDIA Corporation) C:\Users\Dan\Downloads\301.42-notebook-win7-winvista-64bit-international-whql.exe
2012-05-23 06:48 - 2012-05-23 06:48 - 00000000 ____D C:\Users\Dan\AppData\Local\{F83DE537-A41B-478B-98D0-DC340F67E347}
2012-05-23 06:48 - 2012-05-23 06:47 - 00000000 ____D C:\Users\Dan\AppData\Local\{212612A6-2BAC-4990-8DBB-13880701D71D}
2012-05-22 11:56 - 2012-05-22 11:56 - 00000000 ____D C:\Users\Dan\AppData\Local\{234D1E67-D708-43B1-8F98-37221BFCA5AB}
2012-05-22 11:56 - 2012-05-22 11:56 - 00000000 ____D C:\Users\Dan\AppData\Local\{0D9A46AF-3A97-4200-A17E-1D72907753E0}
2012-05-21 21:55 - 2012-05-21 21:54 - 00000000 ____D C:\Users\Dan\AppData\Local\{A257200B-3001-4CF8-B678-77279D050B4A}
2012-05-21 21:54 - 2012-05-21 21:54 - 00000000 ____D C:\Users\Dan\AppData\Local\{121DBA0E-119A-48E6-9AEC-A443EDBB8063}
2012-05-21 08:43 - 2012-05-21 08:43 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{b6427221-97ff-11e1-b571-00038a000015}.TxR.blf
2012-05-21 08:43 - 2012-05-21 08:43 - 00000000 ____D C:\Users\Dan\AppData\Local\{5B73F1A6-CD38-4AAE-AD76-3E3B928190CE}
2012-05-21 08:43 - 2012-05-21 08:43 - 00000000 ____D C:\Users\Dan\AppData\Local\{1C259C62-B28C-4ACC-8A70-C91B6DDF31F8}
2012-05-20 20:54 - 2011-05-18 12:56 - 00265808 ____A C:\Users\Dan\Documents\voice-message.wav
2012-05-20 14:42 - 2012-05-20 14:42 - 00000000 ____D C:\Users\Dan\AppData\Local\{4064419C-FC82-44BC-BBB8-0CEA383C8853}
2012-05-20 14:42 - 2012-05-20 14:41 - 00000000 ____D C:\Users\Dan\AppData\Local\{F31E5E6B-E7C6-4F0F-88B6-871A10A11B6F}
2012-05-19 20:28 - 2012-05-19 20:28 - 00000000 ____D C:\Users\Dan\AppData\Local\{B176701A-1370-4340-B1C3-273AC623C799}
2012-05-19 20:28 - 2012-05-19 20:27 - 00000000 ____D C:\Users\Dan\AppData\Local\{2F4F3D3B-5399-4937-AE51-2F183E2B5FC7}
2012-05-18 17:20 - 2012-05-18 17:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{C3030517-54A1-44A6-9305-9D7660AF37B2}
2012-05-18 17:19 - 2012-05-18 17:19 - 00000000 ____D C:\Users\Dan\AppData\Local\{6FC92F1C-08F0-45C8-96CE-46780EA34C3C}
2012-05-17 09:24 - 2012-05-17 09:23 - 00000000 ____D C:\Users\Dan\AppData\Local\{EE66F888-C42A-4A99-A207-7E74A3F4EB48}
2012-05-17 09:23 - 2012-05-17 09:23 - 00000000 ____D C:\Users\Dan\AppData\Local\{83CBCA9E-4C60-498E-BF10-26DBE1F55499}
2012-05-16 21:12 - 2012-05-16 21:12 - 00476960 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-05-16 21:12 - 2012-05-16 21:12 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-05-16 21:12 - 2012-05-16 21:12 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-05-16 21:12 - 2012-05-16 21:12 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-05-16 21:12 - 2011-09-27 21:39 - 00472864 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-05-16 10:56 - 2012-05-16 10:56 - 00000000 ____D C:\Users\Dan\AppData\Local\{9646E0FC-BAC1-4717-A9D3-1B4336E8E17D}
2012-05-16 10:56 - 2012-05-16 10:55 - 00000000 ____D C:\Users\Dan\AppData\Local\{B256E0C3-CE2E-4F4D-BA14-A2373CB56926}
2012-05-16 10:55 - 2012-05-16 10:55 - 00000000 ____D C:\Windows\en
2012-05-16 10:47 - 2012-05-16 10:47 - 00000000 ____D C:\Users\Dan\AppData\Local\{88EAD73E-5E1E-4934-BB02-F4DB439F531D}
2012-05-16 10:47 - 2012-05-16 10:47 - 00000000 ____D C:\Users\Dan\AppData\Local\{72E40356-EE2E-4CE7-9C8A-974F79FB4118}
2012-05-16 08:12 - 2012-05-16 08:12 - 00000000 ____D C:\Users\Dan\AppData\Local\{8A19A40D-1F74-4C05-8ACD-BA513BD8FB17}
2012-05-16 08:12 - 2012-05-16 08:12 - 00000000 ____D C:\Users\Dan\AppData\Local\{10EC9F2E-ABBE-4664-B685-134E8843F237}
2012-05-15 21:43 - 2012-05-15 21:43 - 00000000 ____D C:\Users\Dan\AppData\Local\{B75E37E4-B01C-4E53-862D-D89AD755D22F}
2012-05-15 21:43 - 2012-05-15 21:43 - 00000000 ____D C:\Users\Dan\AppData\Local\{6EF8CD4A-E986-4C62-BA2F-FD54FC2A35F1}
2012-05-15 13:32 - 2012-05-15 13:32 - 00000000 ____D C:\Users\Dan\AppData\Local\{0AE3D754-F6B5-4141-8A19-0E62CC1915F0}
2012-05-15 13:31 - 2012-05-15 13:31 - 00000000 ____D C:\Users\Dan\AppData\Local\{B113DA0F-CE32-43B7-AB23-BFAE58498F8A}
2012-05-15 11:31 - 2012-05-15 11:31 - 00000000 ____D C:\Users\Dan\AppData\Local\{BE5FBA2B-9CA3-4ED1-8143-13D3F67B7EF4}
2012-05-15 11:30 - 2012-05-15 11:30 - 00000000 ____D C:\Users\Dan\AppData\Local\{68D30CB8-9550-46E8-8F8E-13201C4C3EB7}
2012-05-15 11:03 - 2012-05-15 11:03 - 00000000 ____D C:\Users\Dan\AppData\Local\{C410297D-A78A-4666-AB5C-8A4056A151C0}
2012-05-15 11:03 - 2012-05-15 11:02 - 00000000 ____D C:\Users\Dan\AppData\Local\{EF528750-09C7-4226-907E-8A3C84FBB115}
2012-05-15 08:59 - 2012-05-15 08:59 - 00000000 ____D C:\Users\Dan\AppData\Local\{D0FFC345-DB29-4BA0-B54F-3098481AC508}
2012-05-15 08:59 - 2012-05-15 08:59 - 00000000 ____D C:\Users\Dan\AppData\Local\{5DA7622D-C68E-4954-827F-EAF17D31CD8E}
2012-05-15 02:48 - 2012-05-23 07:06 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2012-05-15 02:48 - 2012-05-23 07:06 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-05-15 02:48 - 2012-05-23 07:06 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2012-05-15 02:48 - 2012-05-23 07:06 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2012-05-15 02:48 - 2012-05-23 07:06 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2012-05-15 02:48 - 2012-05-23 07:06 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-05-15 02:48 - 2012-05-23 07:06 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-05-15 02:48 - 2012-05-23 07:06 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2012-05-15 02:48 - 2012-05-23 07:06 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-05-15 02:48 - 2012-05-23 07:06 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-05-15 02:48 - 2012-05-23 07:06 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2012-05-15 02:48 - 2012-05-23 07:06 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2012-05-15 02:48 - 2012-05-23 07:06 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2012-05-15 02:48 - 2011-09-16 11:19 - 00068928 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-05-15 02:48 - 2011-09-16 11:19 - 00061248 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2012-05-15 02:48 - 2011-09-12 07:16 - 01738048 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco64.dll
2012-05-15 02:48 - 2011-09-12 07:16 - 01468224 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco64.dll
2012-05-15 02:48 - 2011-09-12 07:16 - 00014324 ____A C:\Windows\System32\nvinfo.pb
2012-05-15 02:48 - 2010-01-16 00:02 - 15322432 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2012-05-15 02:48 - 2010-01-16 00:02 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2012-05-15 02:48 - 2009-12-06 17:30 - 10194752 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
2012-05-15 02:48 - 2009-12-06 17:30 - 02741568 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll
2012-05-15 01:29 - 2010-01-17 21:44 - 03149632 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll
2012-05-15 01:29 - 2010-01-17 21:44 - 02561856 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvcr.dll
2012-05-15 01:29 - 2010-01-17 21:44 - 00889664 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
2012-05-15 01:29 - 2010-01-17 21:44 - 00118080 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
2012-05-15 01:29 - 2009-12-07 09:02 - 00063296 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
2012-05-15 01:28 - 2010-01-17 21:44 - 06151488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
2012-05-14 21:51 - 2012-05-14 21:51 - 00000000 ____D C:\Users\Dan\AppData\Local\{CB227CCA-31BF-48C9-A0CA-3B2D35A1D3BD}
2012-05-14 21:51 - 2012-05-14 21:50 - 00000000 ____D C:\Users\Dan\AppData\Local\{7D30A3D0-3E9C-4805-91BD-1EC360074DC8}
2012-05-14 20:01 - 2012-06-12 19:58 - 01188864 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-14 19:59 - 2012-06-12 19:58 - 00064512 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-14 19:03 - 2012-06-12 19:58 - 00981504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-14 19:00 - 2012-06-12 19:58 - 00048128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-14 17:32 - 2012-06-12 19:57 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-13 21:33 - 2012-05-13 21:32 - 00000000 ____D C:\Users\Dan\AppData\Local\{7FAE030A-0DA5-40A1-BD23-6A26B6BDE38E}
2012-05-13 21:32 - 2012-05-13 21:32 - 00000000 ____D C:\Users\Dan\AppData\Local\{11C59D93-D223-4E77-B599-31ECEDE6C54E}
2012-05-13 19:40 - 2012-05-13 19:40 - 00000000 ____D C:\Users\Dan\AppData\Local\{491F773D-3A38-43A4-B2CA-70E4E7FDA291}
2012-05-13 19:40 - 2012-05-13 19:40 - 00000000 ____D C:\Users\Dan\AppData\Local\{43101971-EFE4-490B-AB39-4A2595B6DFFE}
2012-05-13 18:18 - 2012-05-13 18:18 - 00000000 ____D C:\Users\Dan\Downloads\The Earth and Sky.scriv
2012-05-13 18:17 - 2012-05-13 18:17 - 00014876 ____A C:\Users\Dan\The Earth and Sky.syv
2012-05-13 17:14 - 2012-05-13 17:14 - 00000000 ____D C:\Users\Dan\AppData\Local\{D3C63B95-3044-41B6-BE2A-26FE7E42ACF0}
2012-05-13 17:14 - 2012-05-13 17:13 - 00000000 ____D C:\Users\Dan\AppData\Local\{99684A2F-E24A-4DF1-857D-0A4C9AADF089}
2012-05-12 22:52 - 2012-05-12 22:52 - 00001905 ____A C:\Users\Public\Desktop\Outline 4D.lnk
2012-05-12 22:52 - 2012-05-12 22:52 - 00000000 ____D C:\Users\Dan\AppData\Roaming\PACE Anti-Piracy
2012-05-12 22:52 - 2012-05-12 22:52 - 00000000 ____D C:\Users\Dan\AppData\Local\PACE Anti-Piracy
2012-05-12 22:52 - 2010-06-11 09:47 - 00000000 ___HD C:\Users\Dan\AppData\Local\27UHsUnZJVnF
2012-05-12 22:51 - 2012-05-12 22:51 - 00000000 ____D C:\Users\Dan\AppData\Local\Downloaded Installations
2012-05-12 22:40 - 2012-05-12 22:40 - 00000000 ____D C:\Users\Dan\AppData\Local\{E265E54B-2B8B-404E-9838-4CD776FF22BF}
2012-05-12 22:40 - 2012-05-12 22:40 - 00000000 ____D C:\Users\Dan\AppData\Local\{3A7E2D19-4B89-4B1A-8F1D-D95A5C76FEAF}
2012-05-12 18:14 - 2012-05-12 18:14 - 00000000 ____D C:\Users\Dan\AppData\Local\{742E3EFB-59B9-405D-AD45-3FEB1057E4BF}
2012-05-12 18:14 - 2012-05-12 18:13 - 00000000 ____D C:\Users\Dan\AppData\Local\{450FF42D-2BAE-485C-9D23-510244194C6C}
2012-05-12 08:50 - 2012-05-12 08:49 - 00000000 ____D C:\Users\Dan\AppData\Local\{67E7F9B6-193B-4DD8-9328-43AB2BB2E12E}
2012-05-12 08:49 - 2012-05-12 08:49 - 00000000 ____D C:\Users\Dan\AppData\Local\{CABFA940-1B03-4DE7-B1BC-9C238D263F99}
2012-05-11 17:26 - 2012-05-11 17:26 - 00000000 ____D C:\Users\Dan\AppData\Local\{5A47BE29-C13A-4E34-80F2-9FE3DB33F323}
2012-05-11 17:26 - 2012-05-11 17:25 - 00000000 ____D C:\Users\Dan\AppData\Local\{C3822E7E-9655-4820-AFA1-79A0E97ECA30}
2012-05-10 21:47 - 2012-05-10 21:47 - 00000000 ____D C:\Users\Dan\AppData\Local\{BA74826E-01D1-4C3B-B867-4B96ECB6B704}
2012-05-10 21:47 - 2012-05-10 21:47 - 00000000 ____D C:\Users\Dan\AppData\Local\{AFDFEC02-EBD1-4CCC-835B-24EE4ED49FB7}
2012-05-10 20:59 - 2012-05-10 20:59 - 00011506 ____A C:\Users\Dan\Desktop\AcademicChess.xlsx
2012-05-10 18:01 - 2012-05-10 18:01 - 00000000 ____D C:\Users\Dan\AppData\Local\{CAF683E2-BEB4-4A63-8474-F56570293EE2}
2012-05-10 18:01 - 2012-05-10 18:01 - 00000000 ____D C:\Users\Dan\AppData\Local\{6ABD1025-AE1C-47B7-9781-601398892F70}
2012-05-10 12:24 - 2012-05-10 12:24 - 00000000 ____D C:\Users\Dan\AppData\Local\{7AB03690-34D3-41A0-AC92-573D1374F5C5}
2012-05-10 12:24 - 2012-05-10 12:24 - 00000000 ____D C:\Users\Dan\AppData\Local\{11DB446B-834F-48A0-9925-E7F4AB5DB3DD}
2012-05-10 07:21 - 2012-05-10 07:21 - 00000000 ____D C:\Users\Dan\AppData\Local\{1C1F4FD7-27FD-4171-AF6E-409EBD626B9C}
2012-05-10 07:20 - 2012-05-10 07:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{A6BF80C7-B89D-403C-ABA5-482C178E75EE}
2012-05-09 22:32 - 2012-05-09 22:32 - 00000000 ____D C:\Users\Dan\Downloads\Scriv Tutorial.scriv
2012-05-09 22:30 - 2012-05-09 22:30 - 00000000 ____D C:\Users\Dan\AppData\Local\Scrivener
2012-05-09 22:28 - 2012-05-09 22:28 - 00001708 ____A C:\Users\Public\Desktop\Scrivener.lnk
2012-05-09 22:27 - 2012-05-09 22:25 - 52015502 ____A C:\Users\Dan\Downloads\Scrivener-installer.zip
2012-05-09 18:49 - 2012-05-09 18:49 - 00000000 ____D C:\Users\Dan\AppData\Local\{C6FA1CB9-9560-4201-80E4-0FE819CED318}
2012-05-09 18:49 - 2012-05-09 18:49 - 00000000 ____D C:\Users\Dan\AppData\Local\{804FE82D-F0EE-45DE-8754-50ED19272E96}
2012-05-09 14:25 - 2012-05-09 14:25 - 00000000 ____D C:\Users\Dan\AppData\Local\{5D16BB3E-BC5C-412B-9E9C-04FC4CD6B341}
2012-05-09 14:25 - 2012-05-09 14:24 - 00000000 ____D C:\Users\Dan\AppData\Local\{EFA02415-E0C8-45A3-A5E9-F1323C15570A}
2012-05-09 12:05 - 2012-05-09 12:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{B2B67893-0064-46E0-9130-679B2E34AE21}
2012-05-09 12:05 - 2012-05-09 12:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{08A0A36C-5459-472D-A33F-437B26009B23}
2012-05-09 08:32 - 2012-05-09 08:32 - 00000000 ____D C:\Users\Dan\AppData\Local\{9A290F5E-ECBE-4596-B21A-FE28DAB67BD8}
2012-05-09 08:32 - 2012-05-09 08:32 - 00000000 ____D C:\Users\Dan\AppData\Local\{9051781F-8E40-4E81-84EB-E3A73BB6087E}
2012-05-08 14:03 - 2012-05-08 14:02 - 00000000 ____D C:\Users\Dan\AppData\Local\{B0404E8C-91A1-4476-A3B9-19A25CAAAFF2}
2012-05-08 14:02 - 2012-05-08 14:02 - 00000000 ____D C:\Users\Dan\AppData\Local\{0352A91E-0DA2-48A6-B482-C7CC4E5C5444}
2012-05-08 07:28 - 2012-05-08 07:28 - 00000000 ____D C:\Users\Dan\AppData\Local\{C0E8E35D-C182-4F61-8FDB-DD66014CECF8}
2012-05-08 07:28 - 2012-05-08 07:28 - 00000000 ____D C:\Users\Dan\AppData\Local\{B16EC822-C72A-4BD8-BA4F-330BB09E6B46}
2012-05-07 09:23 - 2012-05-07 09:23 - 00000000 ____D C:\Users\Dan\AppData\Local\{0757AD47-AB4A-43EC-B9BF-A17F74BD06C9}
2012-05-07 09:22 - 2012-05-07 09:22 - 00000000 ____D C:\Users\Dan\AppData\Local\{30A713CE-A22C-492D-9181-3E87F2C63B8E}
2012-05-06 20:50 - 2012-05-06 20:49 - 00000000 ____D C:\Users\Dan\AppData\Local\{0907F932-971D-47FC-AEA8-A497FF7C715A}
2012-05-06 20:49 - 2012-05-06 20:49 - 00000000 ____D C:\Users\Dan\AppData\Local\{4E7B0129-98B4-465F-A6F5-E9F0684466F7}
2012-05-06 19:41 - 2012-05-06 19:41 - 00000000 ____D C:\Users\All Users\Mozilla
2012-05-06 19:41 - 2011-06-06 15:08 - 00001064 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-05-06 19:39 - 2012-05-06 19:39 - 16339280 ____A (Mozilla) C:\Users\Dan\Downloads\Firefox Setup 12.0.exe
 
2012-05-06 19:36 - 2012-05-06 19:36 - 00000000 ____D C:\Users\Dan\AppData\Local\{E57F967D-2EDB-47A9-BF78-8252A5E713AB}
2012-05-06 19:36 - 2012-05-06 19:36 - 00000000 ____D C:\Users\Dan\AppData\Local\{D348413C-1FF2-4EA0-BE50-9857E1E403B8}
2012-05-06 13:16 - 2012-05-06 13:16 - 00000000 ____D C:\Users\Dan\AppData\Local\{AA15443B-CF90-4BD6-9FF5-669FFF3375FF}
2012-05-06 13:16 - 2012-05-06 13:16 - 00000000 ____D C:\Users\Dan\AppData\Local\{84B38334-312D-4364-8025-29375F7DEE6D}
2012-05-06 08:58 - 2012-05-06 08:58 - 00000000 ____D C:\Users\Dan\AppData\Local\{52DABC01-5293-4C24-AF72-5001181C3C76}
2012-05-06 08:58 - 2012-05-06 08:57 - 00000000 ____D C:\Users\Dan\AppData\Local\{AB896480-0FEE-4E33-AA35-A464E3E714A2}
2012-05-06 07:05 - 2012-05-06 07:01 - 00000000 ____D C:\Users\Dan\Desktop\sd
2012-05-06 06:59 - 2012-05-06 06:59 - 00000000 ____D C:\Users\Dan\AppData\Local\{D6E374CC-2498-4707-86A4-9BCBA576A03E}
2012-05-06 06:59 - 2012-05-06 06:58 - 00000000 ____D C:\Users\Dan\AppData\Local\{3D19F0B6-71C5-402B-9BE6-DA45ED25FFF9}
2012-05-06 06:53 - 2012-05-06 06:53 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{086a564c-972b-11e1-89d0-00038a000015}.TxR.blf
2012-05-05 19:26 - 2012-05-05 19:26 - 00000000 ____D C:\Users\Dan\AppData\Local\{D7363779-9FB8-4A43-95E0-3C0770F27B2E}
2012-05-05 19:26 - 2012-05-05 19:26 - 00000000 ____D C:\Users\Dan\AppData\Local\{99D61BDD-99FC-4C7A-9EA4-F364999F5DD8}
2012-05-05 15:51 - 2012-05-05 15:51 - 00000000 ____D C:\Users\Dan\AppData\Local\{A723BCB8-20FE-4830-82E9-5370B78C275E}
2012-05-05 15:51 - 2012-05-05 15:51 - 00000000 ____D C:\Users\Dan\AppData\Local\{77465BC0-018D-48E3-AE8C-5C3F1BED3B86}
2012-05-04 19:50 - 2012-05-04 19:50 - 00000000 ____D C:\Users\Dan\AppData\Local\{FDF7367A-84F4-4E62-AF18-A6509113984F}
2012-05-04 19:50 - 2012-05-04 19:50 - 00000000 ____D C:\Users\Dan\AppData\Local\{2A25559E-B189-4044-AFCF-9D84CC6D5338}
2012-05-04 17:14 - 2012-05-04 17:14 - 00000000 ____D C:\Users\Dan\AppData\Local\{B3E7229E-3589-4764-88B5-2E797A7A1DB2}
2012-05-04 17:14 - 2012-05-04 17:14 - 00000000 ____D C:\Users\Dan\AppData\Local\{5729D771-38D5-43F7-BB42-B3F55512F3BC}
2012-05-04 03:06 - 2012-06-12 19:57 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 19:57 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 19:57 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-03 19:43 - 2012-05-03 19:43 - 00000000 ____D C:\Users\Dan\AppData\Local\{B44217DD-8854-4426-B7C3-45E9DEBF2D28}
2012-05-03 19:42 - 2012-05-03 19:42 - 00000000 ____D C:\Users\Dan\AppData\Local\{BEE5822C-91C6-4FCE-9003-76188CE2ADA5}
2012-05-02 19:52 - 2012-05-02 19:51 - 00000000 ____D C:\Users\Dan\AppData\Local\{216C371F-5A75-4D19-BC7A-FF041D9C26FE}
2012-05-02 19:51 - 2012-05-02 19:51 - 00000000 ____D C:\Users\Dan\AppData\Local\{BE10ADF2-9E51-4617-B875-BBBF904B80FE}
2012-05-02 08:21 - 2012-05-02 08:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{2AD8ABDA-1133-4D8A-BE1E-24AF37931F39}
2012-05-02 08:20 - 2012-05-02 08:20 - 00000000 ____D C:\Users\Dan\AppData\Local\{1A7DE771-EB7C-4940-8794-84DC46970213}
2012-05-01 14:16 - 2012-05-01 14:15 - 00000000 ____D C:\Users\Dan\AppData\Local\{73CCAA84-81A7-4EA0-A0FA-510B915B110F}
2012-05-01 14:15 - 2012-05-01 14:15 - 00000000 ____D C:\Users\Dan\AppData\Local\{76E1322D-5A7B-4061-904A-048B0BCF018A}
2012-05-01 12:41 - 2012-05-01 12:41 - 00000000 ____D C:\Users\Dan\AppData\Local\{DEF1A724-5D3D-491B-8CD6-AB20E56456A0}
2012-05-01 12:41 - 2012-05-01 12:41 - 00000000 ____D C:\Users\Dan\AppData\Local\{0B82BB6C-0C93-4BE9-B1E4-3BD60BAC6609}
2012-04-30 22:00 - 2012-04-30 22:00 - 00000000 ____D C:\Users\Dan\AppData\Local\{C49FF917-BF01-4960-968D-F892626657B2}
2012-04-30 22:00 - 2012-04-30 22:00 - 00000000 ____D C:\Users\Dan\AppData\Local\{178A914C-F32B-4BFA-B063-DC1902FFD0CB}
2012-04-30 21:40 - 2012-06-12 19:57 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-30 19:40 - 2012-04-30 19:40 - 00000000 ____D C:\Users\Dan\AppData\Local\{B43ED39F-D8AA-4E9E-9420-B327D9AD5299}
2012-04-30 19:40 - 2012-04-30 19:40 - 00000000 ____D C:\Users\Dan\AppData\Local\{83D75079-3B8A-4EAE-B680-6C1FEFF1D1FF}
2012-04-30 18:23 - 2012-04-30 18:23 - 00000000 ____D C:\Users\Dan\AppData\Local\{9B935617-D9D0-4F23-A879-08EEBFA1B2C1}
2012-04-30 18:23 - 2012-04-30 18:23 - 00000000 ____D C:\Users\Dan\AppData\Local\{8C8B8793-8F10-41EE-90FE-4AEACB6608C1}
2012-04-30 15:47 - 2012-04-30 15:47 - 00000000 ____D C:\Users\Dan\AppData\Local\{AB5D2FEF-6F7B-4988-8826-4842EAB405E8}
2012-04-30 15:47 - 2012-04-30 15:47 - 00000000 ____D C:\Users\Dan\AppData\Local\{4993FAFC-1D3D-4326-ADC0-81FC9B821EB3}
2012-04-30 14:46 - 2012-04-30 14:46 - 00000000 ____D C:\Users\Dan\AppData\Local\{60174EF9-0620-4C3A-9692-D91154D97D73}
2012-04-30 14:46 - 2012-04-30 14:46 - 00000000 ____D C:\Users\Dan\AppData\Local\{18DE761C-57EA-409F-8410-815252D4DD0A}
2012-04-30 10:49 - 2012-04-30 10:49 - 00000000 ____D C:\Users\Dan\AppData\Local\{C029DF03-7825-4E31-A6C2-DACA75682BF4}
2012-04-30 10:49 - 2012-04-30 10:49 - 00000000 ____D C:\Users\Dan\AppData\Local\{A485A112-BD8E-4649-A5C9-29D606C42C9E}
2012-04-29 21:48 - 2012-04-29 21:48 - 00000000 ____D C:\Users\Dan\AppData\Local\{BBD264C2-C839-4382-9927-DE9C72444F06}
2012-04-29 21:48 - 2012-04-29 21:48 - 00000000 ____D C:\Users\Dan\AppData\Local\{0EBEB2A2-709A-481E-8E69-D666140EF983}
2012-04-29 19:52 - 2012-04-29 19:52 - 00000000 ____D C:\Users\Dan\AppData\Local\{BDCC9454-3C85-477B-BB84-DE5FCE8D284E}
2012-04-29 19:51 - 2012-04-29 19:51 - 00000000 ____D C:\Users\Dan\AppData\Local\{0B30BA46-60F2-417A-AB3E-5269E1032450}
2012-04-29 12:31 - 2012-04-29 12:31 - 00000000 ____D C:\Users\Dan\AppData\Local\{B84B927A-D5C2-4525-B1EA-385FC0C407B3}
2012-04-29 12:31 - 2012-04-29 12:31 - 00000000 ____D C:\Users\Dan\AppData\Local\{AA4BBACB-6B3B-400D-B045-FE77829A24B3}
2012-04-29 08:39 - 2012-04-29 08:39 - 00000000 ____D C:\Users\Dan\AppData\Local\{3CC6EFE8-05D6-4642-80DD-FFD719A5F149}
2012-04-29 08:39 - 2012-04-29 08:38 - 00000000 ____D C:\Users\Dan\AppData\Local\{0009937B-2CBC-4541-896E-78459CC44C46}
2012-04-27 19:55 - 2012-06-12 19:57 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-27 17:24 - 2012-04-27 17:24 - 00000000 ____D C:\Users\Dan\AppData\Local\{E6FDFD1F-CFDE-4D75-9A61-43FE14090EB4}
2012-04-27 17:24 - 2012-04-27 17:24 - 00000000 ____D C:\Users\Dan\AppData\Local\{3A2005F5-4894-44EB-98A0-4E5A46EE326C}
2012-04-27 10:06 - 2012-04-27 10:06 - 00000000 ____D C:\Users\Dan\AppData\Local\{F38308A0-5229-4EBE-B8DD-F218D322FF5D}
2012-04-27 10:06 - 2012-04-27 10:05 - 00000000 ____D C:\Users\Dan\AppData\Local\{298FABAA-0918-4422-B1F2-FB5EDF6DD29B}
2012-04-26 21:09 - 2012-04-26 21:09 - 00000000 ____D C:\Users\Dan\AppData\Local\{E8291985-017E-4AC3-A4B9-D7F4D80307BD}
2012-04-26 21:09 - 2012-04-26 21:09 - 00000000 ____D C:\Users\Dan\AppData\Local\{46F47C33-AF48-4B9D-8FFF-85FA9F13E8E0}
2012-04-26 14:55 - 2012-04-26 14:55 - 00000000 ____D C:\Users\Dan\AppData\Local\{F1A25581-EE4C-4AE8-92D0-A9089A781CBC}
2012-04-26 14:55 - 2012-04-26 14:55 - 00000000 ____D C:\Users\Dan\AppData\Local\{63653B72-28ED-489A-AABB-65070735DDB0}
2012-04-26 07:11 - 2012-04-26 07:11 - 00000000 ____D C:\Users\Dan\AppData\Local\{E966E06F-2308-4C65-81F1-1AF970DF3F1A}
2012-04-26 07:11 - 2012-04-26 07:11 - 00000000 ____D C:\Users\Dan\AppData\Local\{C128A21D-17FE-40B0-B54F-7A636921E5AA}
2012-04-25 21:41 - 2012-06-12 19:58 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 19:58 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 19:58 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-24 18:39 - 2012-04-24 18:39 - 00000000 ____D C:\Users\Dan\AppData\Local\{8AF06313-0CDF-48CF-A79D-93C656A8BA25}
2012-04-24 18:39 - 2012-04-24 18:38 - 00000000 ____D C:\Users\Dan\AppData\Local\{EC70DF28-F63C-4B2F-AD8E-DCF980F4497B}
2012-04-24 15:55 - 2012-04-24 15:55 - 00000000 ____D C:\Users\Dan\AppData\Local\{909B0BE0-9578-43E6-B07D-1403C104FFD8}
2012-04-24 15:55 - 2012-04-24 15:55 - 00000000 ____D C:\Users\Dan\AppData\Local\{4A5F60C7-722A-41EB-95AF-2C2022344CAA}
2012-04-23 21:54 - 2012-04-23 21:53 - 00000000 ____D C:\Users\Dan\AppData\Local\{22F5FF2D-6789-46BC-9C19-2F399E5A7FBF}
2012-04-23 21:53 - 2012-04-23 21:53 - 00000000 ____D C:\Users\Dan\AppData\Local\{12D67E38-2F97-4B1F-9ECA-04C9839E997C}
2012-04-23 21:37 - 2012-06-12 19:57 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 19:57 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 19:57 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 19:57 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 19:57 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 19:57 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-22 21:32 - 2012-04-22 21:32 - 00000000 ____D C:\Users\Dan\AppData\Local\{490365DD-38BE-4540-9E73-7E0C8C9B5E7C}
2012-04-22 21:32 - 2012-04-22 21:31 - 00000000 ____D C:\Users\Dan\AppData\Local\{A22DD622-BEA1-48A9-8ACB-BA540E9AD00E}
2012-04-22 10:40 - 2012-04-22 10:40 - 00000000 ____D C:\Users\Dan\AppData\Local\{D3A7BD9D-C0DC-4051-8C47-0BDC00E90309}
2012-04-22 10:39 - 2012-04-22 10:39 - 00000000 ____D C:\Users\Dan\AppData\Local\{4F8428A2-4A8B-4092-9B25-5C80C7EFC57C}
2012-04-20 17:29 - 2012-04-20 17:29 - 00000000 ____D C:\Users\Dan\AppData\Local\{4F43F4D2-4BA1-4CA7-B523-507DB42F1B26}
2012-04-20 17:29 - 2012-04-20 17:29 - 00000000 ____D C:\Users\Dan\AppData\Local\{2BB1498C-BE8F-4CA8-B73F-8600902CD89A}
2012-04-19 21:42 - 2012-06-12 19:58 - 12297216 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-04-19 21:42 - 2012-06-12 19:58 - 09059840 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-04-19 21:42 - 2012-06-12 19:58 - 02454528 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-04-19 21:42 - 2012-06-12 19:58 - 01494016 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-04-19 21:42 - 2012-06-12 19:58 - 00735744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-04-19 21:42 - 2012-06-12 19:58 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-04-19 21:42 - 2012-06-12 19:58 - 00134144 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-04-19 21:42 - 2012-06-12 19:58 - 00097792 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-04-19 21:33 - 2012-04-19 21:33 - 00000000 ____D C:\Users\Dan\AppData\Local\{6EA4B401-E6F8-4828-B5FF-AA47D086230D}
2012-04-19 21:33 - 2012-04-19 21:32 - 00000000 ____D C:\Users\Dan\AppData\Local\{A0479E39-FA81-40E9-8763-D941F0541A29}
2012-04-19 21:00 - 2012-06-12 19:58 - 01231360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-04-19 21:00 - 2012-06-12 19:58 - 00132096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-04-19 20:57 - 2012-06-12 19:58 - 06027776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-04-19 20:57 - 2012-06-12 19:58 - 00627712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-04-19 20:57 - 2012-06-12 19:58 - 00067584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-04-19 20:56 - 2012-06-12 19:58 - 11020800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-04-19 20:56 - 2012-06-12 19:58 - 02073600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-04-19 20:56 - 2012-06-12 19:58 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-04-19 19:45 - 2012-06-12 19:58 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-04-19 19:16 - 2012-06-12 19:58 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-04-19 11:11 - 2012-04-19 11:11 - 00000000 ____D C:\Users\Dan\AppData\Local\{21D9A6BA-1B4C-4915-8363-3424479F2060}
2012-04-19 11:11 - 2012-04-19 11:11 - 00000000 ____D C:\Users\Dan\AppData\Local\{1434EF10-79F6-4F99-839D-CD478189E8B0}
2012-04-18 11:58 - 2012-04-18 11:58 - 00000000 ____D C:\Users\Dan\AppData\Local\{C12842F5-F8F3-4D33-A7E0-71186394220F}
2012-04-18 11:58 - 2012-04-18 11:58 - 00000000 ____D C:\Users\Dan\AppData\Local\{6338DC90-05BD-49E5-8D21-714AD6C82B33}
2012-04-18 09:08 - 2012-05-23 07:06 - 01451840 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdagenco6420103.dll
2012-04-18 09:08 - 2012-05-23 07:06 - 00188736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
2012-04-18 09:08 - 2012-05-23 07:06 - 00031040 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
2012-04-17 21:19 - 2012-04-17 21:19 - 00000000 ____D C:\Users\Dan\AppData\Local\{D33586DB-6FC8-40C2-A3F3-701518E88373}
2012-04-17 21:19 - 2012-04-17 21:19 - 00000000 ____D C:\Users\Dan\AppData\Local\{5E2E6EDC-C841-487E-B987-45A515DF7D53}
2012-04-17 16:25 - 2012-04-17 16:25 - 00000000 ____D C:\Users\Dan\AppData\Local\{AAFADF50-B809-4EAF-9265-2C0A60B8794A}
2012-04-17 16:25 - 2012-04-17 16:25 - 00000000 ____D C:\Users\Dan\AppData\Local\{0D303FA9-FB7B-4831-A54B-969D94F92360}
2012-04-17 10:39 - 2012-04-17 10:39 - 00000000 ____D C:\Users\Dan\AppData\Local\{C21878F1-3419-430A-8057-7CA7ED701451}
2012-04-17 10:39 - 2012-04-17 10:39 - 00000000 ____D C:\Users\Dan\AppData\Local\{5053BBD0-F24C-4EBF-A303-345E37A08DB0}
2012-04-16 21:49 - 2012-04-16 21:49 - 00000000 ____D C:\Users\Dan\AppData\Local\{E16274F0-C9DA-4E95-AA78-4B5C6F0904FE}
2012-04-16 21:49 - 2012-04-16 21:48 - 00000000 ____D C:\Users\Dan\AppData\Local\{58551FC3-3DF2-4693-915F-58F76DE92487}
2012-04-16 21:31 - 2012-06-12 19:58 - 00918016 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-04-16 20:34 - 2012-06-12 19:58 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-04-16 11:04 - 2012-04-16 11:04 - 00000000 ____D C:\Users\Dan\AppData\Local\{F7BA92DA-87F7-4891-B667-AD33AF1E0786}
2012-04-16 11:04 - 2012-04-16 11:04 - 00000000 ____D C:\Users\Dan\AppData\Local\{2ADE152D-89FB-4490-90D6-ACF82AEC7353}
2012-04-16 08:36 - 2012-04-16 08:36 - 00000000 ____D C:\Users\Dan\AppData\Local\{D75B642A-4C84-4187-B8D1-8E25CB55E3E9}
2012-04-16 08:36 - 2012-04-16 08:35 - 00000000 ____D C:\Users\Dan\AppData\Local\{6C85B781-965A-4648-AF92-4ABFED4E52ED}
2012-04-15 21:51 - 2012-04-15 21:51 - 00000000 ____D C:\Users\Dan\AppData\Local\{A58900E7-3FFB-47CA-8DBB-689A7481BB58}
2012-04-15 21:51 - 2012-04-15 21:51 - 00000000 ____D C:\Users\Dan\AppData\Local\{9F99D7AF-69C0-4E98-8DD1-A332B3A5B89E}
2012-04-15 19:55 - 2012-04-15 19:55 - 00000000 ____D C:\Users\Dan\AppData\Local\{DAAA2339-2ECF-4D21-8932-7A8FA5BF3AE1}
2012-04-15 19:55 - 2012-04-15 19:54 - 00000000 ____D C:\Users\Dan\AppData\Local\{BEBD1596-6111-4EA2-B3C2-E1A329CA0555}
2012-04-15 17:11 - 2012-04-15 17:11 - 00000000 ____D C:\Users\Dan\AppData\Local\{A7C50E0B-643C-4ABC-A62E-6A32AD9DA0A7}
2012-04-15 17:11 - 2012-04-15 17:11 - 00000000 ____D C:\Users\Dan\AppData\Local\{16E650B0-CB2A-4E8B-8C6A-3BBBAB433C65}
2012-04-15 12:01 - 2012-04-15 12:01 - 00000000 ____D C:\Users\Dan\AppData\Local\{E9996E5B-5E81-4C60-8757-A4D70AD93987}
2012-04-15 12:01 - 2012-04-15 12:00 - 00000000 ____D C:\Users\Dan\AppData\Local\{C92D1E88-971C-429E-9407-E1372528925F}
2012-04-15 10:30 - 2012-04-15 10:29 - 00000000 ____D C:\Users\Dan\AppData\Local\{200525F7-7A2C-40F3-B11F-0ED290724205}
2012-04-15 10:29 - 2012-04-15 10:29 - 00000000 ____D C:\Users\Dan\AppData\Local\{8A23F49B-947D-499B-93BF-A9B1369C1F10}
2012-04-15 06:53 - 2012-04-15 06:52 - 00000000 ____D C:\Users\Dan\AppData\Local\{001447A5-E8AC-4148-BF74-0CC2A3FE1312}
2012-04-15 06:52 - 2012-04-15 06:52 - 00000000 ____D C:\Users\Dan\AppData\Local\{96615B36-7041-4119-AD51-A990AD086E67}
2012-04-14 21:47 - 2012-04-14 21:47 - 00000000 ____D C:\Users\Dan\AppData\Local\{066F8E0B-8095-4A50-A862-4339E046BCC9}
2012-04-14 21:47 - 2012-04-14 21:46 - 00000000 ____D C:\Users\Dan\AppData\Local\{B98BF740-8AFB-4EC7-8D5C-0F4E1B5B8F8D}
2012-04-14 20:55 - 2012-04-14 20:55 - 00000000 ____D C:\Users\Dan\AppData\Local\{3620FBEB-5E27-4435-A9CF-E406A439C098}
2012-04-12 13:18 - 2012-04-12 13:18 - 00000000 ____D C:\Users\Dan\AppData\Local\{289E7A9A-F7A4-4C5A-A9A0-68AE3E9FC9C5}
2012-04-11 12:06 - 2012-04-11 12:06 - 00000000 ____D C:\Users\Dan\AppData\Local\{CFE8456A-0DC7-431D-9AD9-AC4DDE28BBF2}
2012-04-10 18:35 - 2012-04-10 18:35 - 00000000 ____D C:\Users\Dan\AppData\Local\{5AC8C7B1-EAAA-4D8E-8FA1-5CB9EC0D83D8}
2012-04-10 06:34 - 2012-04-10 06:34 - 00000000 ____D C:\Users\Dan\AppData\Local\{690F5274-1D0B-4683-BD0F-E913050653B3}
2012-04-08 19:49 - 2012-04-08 19:49 - 00000000 ____D C:\Users\Dan\AppData\Local\{D3E9AA25-4DDE-4055-BEE1-18C40A245693}
2012-04-07 17:26 - 2012-04-07 17:26 - 00000000 ____D C:\Users\Dan\AppData\Local\{9EB31EA6-FD66-4AB5-8581-B9FF10482522}
2012-04-07 04:31 - 2012-06-12 19:57 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-12 19:57 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-06 19:57 - 2012-04-06 19:57 - 00000000 ____D C:\Users\Dan\AppData\Local\{5CAF6C13-7703-46E0-B8DC-2A17AF897AE1}
2012-04-06 12:36 - 2012-04-06 12:33 - 00000000 ____D C:\Users\Dan\Desktop\KS
2012-04-06 07:56 - 2012-04-06 07:56 - 00000000 ____D C:\Users\Dan\AppData\Local\{9A92BE3D-A3E3-43E7-8CCF-3D4A68AB3306}
2012-04-05 12:16 - 2012-04-05 12:15 - 00000000 ____D C:\Users\Dan\AppData\Local\{6D80198A-0CFF-4B1C-A60F-739592A12DB4}
2012-04-04 14:56 - 2011-04-09 02:02 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-04-04 09:56 - 2012-04-04 09:56 - 00000000 ____D C:\Users\Dan\AppData\Local\{FBE0F65A-5C89-48CC-A291-1201A42955BF}
2012-04-03 21:56 - 2012-04-03 21:56 - 00000000 ____D C:\Users\Dan\AppData\Local\{37CADD5A-0823-4C5D-99B9-AFD6E282D5C7}
2012-04-02 08:38 - 2012-04-02 08:38 - 00000000 ____D C:\Users\Dan\AppData\Local\{D3F03256-E6FF-40A9-8A75-F5BFD18E95C9}
2012-04-01 12:41 - 2012-04-01 12:40 - 00000000 ____D C:\Users\Dan\AppData\Local\{714DC18E-57DE-43E0-B0EE-752FA3D143B7}
2012-03-31 18:17 - 2012-03-31 18:16 - 00000000 ____D C:\Users\Dan\AppData\Local\{D3BABD7A-B89B-438B-BCFB-EA6774C6FA24}
2012-03-31 06:16 - 2012-03-31 06:16 - 00000000 ____D C:\Users\Dan\AppData\Local\{7623A18D-BB2D-4A8C-B611-CF8D92681865}
2012-03-30 14:59 - 2011-10-13 11:03 - 00000000 ____D C:\Users\Dan\Desktop\Law
2012-03-30 11:06 - 2012-03-30 11:06 - 00000000 ____D C:\Users\Dan\AppData\Local\{F9BCCF2E-9F0B-4527-81AD-0936220D2432}
2012-03-30 03:35 - 2012-05-09 16:41 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-29 21:52 - 2012-03-29 21:52 - 00000000 ____D C:\Users\Dan\AppData\Local\{3FF4B51E-F29F-44C6-ACC2-9C5F69FBE8D6}
2012-03-29 09:35 - 2012-03-29 09:35 - 00000000 ____D C:\Users\Dan\AppData\Local\{6743759E-CDE0-4370-BA20-36115B26DE69}
2012-03-28 19:31 - 2012-03-28 19:31 - 00000000 ____D C:\Users\Dan\AppData\Local\{6FDA3A20-C643-40E2-988D-515306BE7139}

ZeroAccess:
C:\Windows\Installer\{2530ad49-bb07-94ba-ed79-1caa08e8bbf1}
C:\Windows\Installer\{2530ad49-bb07-94ba-ed79-1caa08e8bbf1}\@
C:\Windows\Installer\{2530ad49-bb07-94ba-ed79-1caa08e8bbf1}\U
C:\Windows\Installer\{2530ad49-bb07-94ba-ed79-1caa08e8bbf1}\U\800000cb.@

========================= Known DLLs (Whitelisted) ============


========================= Bamital & volsnap Check ============

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

========================= Memory info ======================

Percentage of memory in use: 14%
Total physical RAM: 4084.48 MB
Available physical RAM: 3487.25 MB
Total Pagefile: 4082.63 MB
Available Pagefile: 3473.73 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB

======================= Partitions =========================

1 Drive c: (TI105861W0D) (Fixed) (Total:453.79 GB) (Free:375.18 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive d: (System) (Fixed) (Total:1.46 GB) (Free:1.27 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive e: (DRAWMEATREE) (CDROM) (Total:7.04 GB) (Free:0 GB) UDF
4 Drive f: (LATHAM) (Removable) (Total:0.49 GB) (Free:0.46 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 503 MB 0 B

Partitions of Disk 0:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 1500 MB 1024 KB
Partition 2 Primary 453 GB 1501 MB
Partition 3 Primary 10 GB 455 GB

======================================================================================================

Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D System NTFS Partition 1500 MB Healthy Hidden

======================================================================================================

Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C TI105861W0D NTFS Partition 453 GB Healthy

======================================================================================================

Disk: 0
Partition 3
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No

There is no volume associated with this partition.

======================================================================================================

Partitions of Disk 1:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 503 MB 16 KB

======================================================================================================

Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F LATHAM FAT Removable 503 MB Healthy

======================================================================================================

==========================================================

Last Boot: 2011-09-27 17:34

======================= End Of Log ==========================
 
In Vista or Windows 7: Boot to System Recovery Options and run FRST.
In Windows XP: Please boot to UBCD and run FRST.
Type the following in the edit box after "Search:".

services.exe

Click Search button and post the log (Search.txt) it makes to your reply.
 
Farbar Recovery Scan Tool Version: 24-06-2012
Ran by SYSTEM at 2012-06-25 19:00:07
Running from F:\

================== Search: "services.exe" ===================

C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB

C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06

====== End Of Search ======
 
Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.
On Windows XP: Now please boot into the UBCD.
Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Next....

Restart normally and let me know if your internet connection is fine.

We'll go from there.
 

Attachments

  • fixlist.txt
    942 bytes · Views: 1
Status
Not open for further replies.
Back