technopop
Posts: 16 +0
Looks lke a popular one. Going by what everyone else has, I'm including my frst.txt file here.
Thanking you in advance.
Scan result of Farbar Recovery Scan Tool Version: 09-06-2012 01
Ran by SYSTEM at 24-06-2012 23:52:03
Running from E:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [559616 2011-10-17] (Dell)
HKLM-x32\...\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe [165184 2011-01-13] (Softthinks)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.73.1
AppInit_DLLs: C:\Windows\system32\nvinitx.dll
Startup: C:\Users\ADRS\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 BBSvc; C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [193816 2012-02-10] (Microsoft Corporation.)
3 BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [240408 2012-02-10] (Microsoft Corporation.)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] ()
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 PEVSystemStart; "C:\32788R22FWJFW\pev.3XE" EXEC /I CSCRIPT.exe //NOLOGO //E:VBSCRIPT //B //T:15 "C:\32788R22FWJFW\KNetSvcs.vbs" [407 2012-05-20] ()
2 RapiMgr; C:\Windows\WindowsMobile\rapimgr.dll [225672 2007-05-31] (Microsoft Corporation)
3 RoxMediaDB12OEM; "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe" [1116656 2010-09-04] (Sonic Solutions)
2 RoxWatch12; "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe" [219632 2010-09-04] (Sonic Solutions)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656280 2010-12-20] (Intel Corporation)
2 WcesComm; C:\Windows\WindowsMobile\wcescomm.dll [443784 2007-05-31] (Microsoft Corporation)
3 aspnet_state; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x]
2 WinDefend; C:\Program Files (x86)\Windows Defender\mpsvc.dll [x]
========================== Drivers (Whitelisted) =============
1 ctxusbm; C:\Windows\System32\Drivers\ctxusbm.sys [87600 2009-09-08] (Citrix Systems, Inc.)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
3 NvStUSB; C:\Windows\System32\Drivers\NvStUSB.sys [121960 2010-12-12] ()
3 qicflt; C:\Windows\System32\Drivers\qicflt.sys [29288 2010-07-12] (Quanta Computer)
2 TurboB; C:\Windows\System32\Drivers\TurboB.sys [16120 2010-11-29] (Intel(R) Corporation)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-11 23:22 - 2012-06-11 23:22 - 00000000 ____D C:\Windows\pss
2012-06-11 21:25 - 2012-06-24 23:52 - 00000000 ____D C:\FRST
2012-06-09 11:56 - 2012-06-09 11:56 - 00001268 ____A C:\Users\ADRS\Desktop\shutdown.lnk
2012-06-09 02:46 - 2012-06-09 02:46 - 00007280 ____N C:\bootsqm.dat
2012-06-08 15:38 - 2012-06-08 15:38 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-08 15:38 - 2012-06-08 15:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-08 15:37 - 2012-06-08 15:37 - 12621696 ____A (Microsoft Corporation) C:\Users\ADRS\Downloads\mseinstall(2).exe
2012-06-08 15:26 - 2012-06-08 15:26 - 00003966 ____A C:\Users\ADRS\Desktop\mbam-log-2012-06-08 (16-18-29).txt
2012-06-08 15:11 - 2012-06-08 15:17 - 00000000 ___SD C:\32788R22FWJFW
2012-06-08 15:09 - 2012-06-08 15:09 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-08 15:09 - 2012-06-08 15:09 - 00001111 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\All Users\Application Data\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\ADRS\Application Data\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\ADRS\AppData\Roaming\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-08 15:09 - 2012-04-04 14:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-08 15:08 - 2012-06-08 15:08 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\ADRS\Downloads\mbam-setup-1.61.0.1400.exe
2012-06-08 15:04 - 2012-06-08 15:04 - 04538510 ___RA (Swearware) C:\Users\ADRS\Downloads\ComboFix.exe
2012-06-08 14:54 - 2012-06-08 14:55 - 12621696 ____A (Microsoft Corporation) C:\Users\ADRS\Downloads\mseinstall(1).exe
2012-06-08 14:51 - 2012-06-24 22:34 - 00702462 ____A C:\Windows\ntbtlog.txt
2012-06-08 14:27 - 2012-06-08 14:27 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-08 14:23 - 2012-06-10 02:59 - 00000000 ____D C:\Users\All Users\B7E858A700005EC800035D60A60145BE
2012-06-08 14:23 - 2012-06-10 02:59 - 00000000 ____D C:\Users\All Users\Application Data\B7E858A700005EC800035D60A60145BE
2012-06-08 13:49 - 2012-06-08 13:49 - 00080512 ____A C:\Users\ADRS\Desktop\Jackies_iPod_June8.p2gbk
2012-06-08 13:35 - 2012-06-08 13:35 - 01698823 ____A C:\Users\ADRS\Desktop\EK.p2gbk
2012-06-08 13:23 - 2012-06-08 13:23 - 02338893 ____A C:\Users\ADRS\Desktop\stdprod_080112.pdf
2012-06-08 12:59 - 2012-06-08 12:59 - 00000162 ___AH C:\Users\ADRS\Desktop\~$eferred Hours of Work ADRS-1.doc
2012-06-08 01:41 - 2012-06-08 01:41 - 00415232 ____A C:\Users\ADRS\Desktop\Preferred Hours of Work ADRS-1.doc
2012-06-06 15:17 - 2012-06-06 15:18 - 01049727 ____A C:\Users\ADRS\Downloads\mary_had_a_red_dress.zip
2012-06-06 15:16 - 2012-06-06 15:17 - 01335713 ____A C:\Users\ADRS\Downloads\alpharap.zip
2012-06-06 15:14 - 2012-06-06 20:40 - 06124106 ____A C:\Users\ADRS\Downloads\Pps_SwitchActivities.zip
2012-06-06 15:14 - 2012-06-06 15:15 - 02137485 ____A C:\Users\ADRS\Downloads\Pps_FirstNationsABCRap.zip
2012-06-06 15:14 - 2012-06-06 15:14 - 01415237 ____A C:\Users\ADRS\Downloads\Pps_OutdoorABCRap.zip
2012-06-06 15:12 - 2012-06-06 20:40 - 04380227 ____A C:\Users\ADRS\Downloads\Pps_nursery_rhymes_cause_effect.zip
2012-06-06 15:06 - 2012-06-07 05:02 - 00015287 ____A C:\Users\ADRS\Desktop\meeting with school.docx
2012-06-06 15:06 - 2012-06-06 15:06 - 00015263 ____A C:\Users\ADRS\Desktop\Developing hands.docx
2012-06-06 14:41 - 2012-06-06 14:47 - 17713360 ____A C:\Users\ADRS\Desktop\unity36adv.zip
2012-06-06 14:40 - 2012-06-06 14:42 - 04214406 ____A C:\Users\ADRS\Desktop\pcsaltchat36.zip
2012-06-06 14:39 - 2012-06-06 14:39 - 00032737 ____A C:\Users\ADRS\Downloads\eyecore_june_2011.zip
2012-06-06 14:38 - 2012-06-06 14:44 - 15734894 ____A C:\Users\ADRS\Desktop\sblpcs36.zip
2012-06-06 13:47 - 2012-06-07 09:12 - 00933678 ____A C:\Users\ADRS\Downloads\My Toys - Color.clkt
2012-06-06 13:36 - 2012-06-06 13:36 - 01025205 ____A C:\Users\ADRS\Downloads\My Backyard - Color.clkt
2012-06-06 13:32 - 2012-06-06 13:33 - 01505385 ____A C:\Users\ADRS\Downloads\Read about Sam.clkt
2012-06-06 12:51 - 2012-06-07 09:10 - 02826052 ____A C:\Users\ADRS\Downloads\Cause and Effect - Music.clkx
2012-06-06 12:22 - 2012-06-06 12:24 - 03287333 ____A C:\Users\ADRS\Downloads\Incy Wincy Spider - Read.clkt
2012-06-06 12:18 - 2012-06-07 09:10 - 02028396 ____A C:\Users\ADRS\Downloads\Head Shoulders Knees and Toes.clkx
2012-06-06 12:17 - 2012-06-06 14:30 - 03232747 ____A C:\Users\ADRS\Downloads\The Itsy Bitsy Spider - Read.clkt
2012-06-06 12:17 - 2012-06-06 12:18 - 02025009 ____A C:\Users\ADRS\Downloads\More Head and Shoulders.clkt
2012-06-06 12:16 - 2012-06-07 08:41 - 02196679 ____A C:\Users\ADRS\Downloads\complete-clicker.exe
2012-06-06 12:16 - 2012-06-06 14:35 - 00158549 ____A C:\Users\ADRS\Downloads\nursery-rhymes.zip
2012-06-05 13:37 - 2012-05-18 09:05 - 11593306 ____A C:\Users\ADRS\Desktop\Matthew Proloquo2go.p2gbk
2012-06-05 12:03 - 2012-06-05 12:21 - 00077787 ____A C:\Users\ADRS\Desktop\change of info.pdf
2012-06-01 14:58 - 2012-06-01 14:58 - 01353353 ____A C:\Users\ADRS\Downloads\SD_boards.zip
2012-06-01 14:32 - 2012-06-08 15:11 - 00000000 ____D C:\Users\ADRS\Desktop\personal
2012-05-31 13:42 - 2012-05-31 13:42 - 00050772 ____A C:\Users\ADRS\Desktop\from email.dotx
2012-05-31 13:39 - 2008-07-31 07:46 - 05538816 ____A C:\Users\ADRS\Desktop\Laurie - changes to FINAL ISAAC PPT A.ppt
2012-05-31 13:11 - 2012-05-31 13:11 - 00363481 ____A C:\Users\ADRS\Desktop\Deming cycle.pdf
2012-05-31 10:31 - 2012-05-31 10:31 - 00048640 ____A C:\Users\ADRS\Desktop\Clinical Note for Word 2003 (May 31 12).dot
2012-05-31 10:15 - 2012-06-01 12:33 - 00050773 ____A C:\Users\ADRS\Desktop\Clinical Note for Word 2007-2010 (May 31 12).dotx
2012-05-30 11:19 - 2012-05-30 11:19 - 00049152 ____A C:\Users\ADRS\Desktop\Clinical note - Revised May 30, 2012.dot
2012-05-29 14:52 - 2012-05-29 14:52 - 00238037 ____A C:\Users\ADRS\Desktop\mediator training.pdf
2012-05-29 09:06 - 2012-05-29 09:06 - 02336200 ____A C:\Users\ADRS\Desktop\Khalinson.p2gbk
2012-05-28 14:44 - 2012-05-28 14:45 - 03945180 ____A C:\Users\ADRS\Downloads\abc-reading.pptx
2012-05-28 14:30 - 2012-05-28 14:30 - 00307200 ____A C:\Users\ADRS\Desktop\DONEHelpyourchildwithADHDsucceedinschool.doc
2012-05-25 12:25 - 2012-05-25 12:27 - 00000568 ____A C:\Users\ADRS\Desktop\Apple device query.4df
2012-05-25 09:51 - 2012-05-25 10:13 - 397619818 ____A C:\Users\ADRS\Desktop\Proloquo2Go.ipa
============ 3 Months Modified Files and Folders =============
2012-06-24 23:52 - 2012-06-11 21:25 - 00000000 ____D C:\FRST
2012-06-24 22:45 - 2011-06-27 12:51 - 00000000 ____D C:\Users\ADRS\Application Data\Dropbox
2012-06-24 22:45 - 2011-06-27 12:51 - 00000000 ____D C:\Users\ADRS\AppData\Roaming\Dropbox
2012-06-24 22:45 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-24 22:44 - 2011-06-27 12:53 - 00000000 ___RD C:\Users\ADRS\Dropbox
2012-06-24 22:44 - 2011-05-13 09:24 - 00000000 ____D C:\Users\ADRS\Local Settings\SoftThinks
2012-06-24 22:44 - 2011-05-13 09:24 - 00000000 ____D C:\Users\ADRS\Local Settings\Application Data\SoftThinks
2012-06-24 22:44 - 2011-05-13 09:24 - 00000000 ____D C:\Users\ADRS\AppData\Local\SoftThinks
2012-06-24 22:44 - 2011-04-13 19:56 - 00000000 ____D C:\Users\All Users\NVIDIA
2012-06-24 22:44 - 2011-04-13 19:56 - 00000000 ____D C:\Users\All Users\Application Data\NVIDIA
2012-06-24 22:44 - 2011-04-13 18:31 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2012-06-24 22:44 - 2009-07-14 00:08 - 00026486 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-24 22:43 - 2009-07-13 23:51 - 00069780 ____A C:\Windows\setupact.log
2012-06-24 22:34 - 2012-06-08 14:51 - 00702462 ____A C:\Windows\ntbtlog.txt
2012-06-11 23:22 - 2012-06-11 23:22 - 00000000 ____D C:\Windows\pss
2012-06-10 02:59 - 2012-06-08 14:23 - 00000000 ____D C:\Users\All Users\B7E858A700005EC800035D60A60145BE
2012-06-10 02:59 - 2012-06-08 14:23 - 00000000 ____D C:\Users\All Users\Application Data\B7E858A700005EC800035D60A60145BE
2012-06-09 12:18 - 2009-07-14 00:10 - 01318128 ____A C:\Windows\WindowsUpdate.log
2012-06-09 11:56 - 2012-06-09 11:56 - 00001268 ____A C:\Users\ADRS\Desktop\shutdown.lnk
2012-06-09 02:46 - 2012-06-09 02:46 - 00007280 ____N C:\bootsqm.dat
2012-06-08 23:06 - 2009-07-13 23:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-08 23:06 - 2009-07-13 23:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-08 16:05 - 2011-04-13 18:59 - 00000000 ____D C:\Users\All Users\Sonic
2012-06-08 16:05 - 2011-04-13 18:59 - 00000000 ____D C:\Users\All Users\Application Data\Sonic
2012-06-08 15:50 - 2012-01-11 14:07 - 00000000 __SHD C:\Users\ADRS\Local Settings\Application Data\{792f4199-0b73-e2f4-7b46-706eb422a6b8}
2012-06-08 15:50 - 2012-01-11 14:07 - 00000000 __SHD C:\Users\ADRS\Local Settings\{792f4199-0b73-e2f4-7b46-706eb422a6b8}
2012-06-08 15:50 - 2012-01-11 14:07 - 00000000 __SHD C:\Users\ADRS\AppData\Local\{792f4199-0b73-e2f4-7b46-706eb422a6b8}
2012-06-08 15:38 - 2012-06-08 15:38 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-08 15:38 - 2012-06-08 15:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-08 15:38 - 2011-06-27 15:27 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-08 15:38 - 2011-06-27 14:55 - 00753204 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-08 15:37 - 2012-06-08 15:37 - 12621696 ____A (Microsoft Corporation) C:\Users\ADRS\Downloads\mseinstall(2).exe
2012-06-08 15:27 - 2011-04-13 19:53 - 00058468 ____A C:\Windows\PFRO.log
2012-06-08 15:26 - 2012-06-08 15:26 - 00003966 ____A C:\Users\ADRS\Desktop\mbam-log-2012-06-08 (16-18-29).txt
2012-06-08 15:17 - 2012-06-08 15:11 - 00000000 ___SD C:\32788R22FWJFW
2012-06-08 15:11 - 2012-06-01 14:32 - 00000000 ____D C:\Users\ADRS\Desktop\personal
2012-06-08 15:11 - 2011-06-27 09:40 - 00000000 ____D C:\Users\ADRS\Desktop\Key contents
2012-06-08 15:09 - 2012-06-08 15:09 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-08 15:09 - 2012-06-08 15:09 - 00001111 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\All Users\Application Data\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\ADRS\Application Data\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\ADRS\AppData\Roaming\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-08 15:08 - 2012-06-08 15:08 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\ADRS\Downloads\mbam-setup-1.61.0.1400.exe
2012-06-08 15:04 - 2012-06-08 15:04 - 04538510 ___RA (Swearware) C:\Users\ADRS\Downloads\ComboFix.exe
2012-06-08 14:55 - 2012-06-08 14:54 - 12621696 ____A (Microsoft Corporation) C:\Users\ADRS\Downloads\mseinstall(1).exe
2012-06-08 14:43 - 2011-06-27 09:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-06-08 14:27 - 2012-06-08 14:27 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-08 13:49 - 2012-06-08 13:49 - 00080512 ____A C:\Users\ADRS\Desktop\Jackies_iPod_June8.p2gbk
2012-06-08 13:35 - 2012-06-08 13:35 - 01698823 ____A C:\Users\ADRS\Desktop\EK.p2gbk
2012-06-08 13:23 - 2012-06-08 13:23 - 02338893 ____A C:\Users\ADRS\Desktop\stdprod_080112.pdf
2012-06-08 12:59 - 2012-06-08 12:59 - 00000162 ___AH C:\Users\ADRS\Desktop\~$eferred Hours of Work ADRS-1.doc
2012-06-08 03:31 - 2011-09-26 10:02 - 00000000 ____D C:\5100
2012-06-08 01:41 - 2012-06-08 01:41 - 00415232 ____A C:\Users\ADRS\Desktop\Preferred Hours of Work ADRS-1.doc
2012-06-07 09:14 - 2011-06-27 15:06 - 00000000 ____D C:\Users\ADRS\Local Settings\ApplicationHistory
2012-06-07 09:14 - 2011-06-27 15:06 - 00000000 ____D C:\Users\ADRS\Local Settings\Application Data\ApplicationHistory
2012-06-07 09:14 - 2011-06-27 15:06 - 00000000 ____D C:\Users\ADRS\AppData\Local\ApplicationHistory
2012-06-07 09:12 - 2012-06-06 13:47 - 00933678 ____A C:\Users\ADRS\Downloads\My Toys - Color.clkt
2012-06-07 09:10 - 2012-06-06 12:51 - 02826052 ____A C:\Users\ADRS\Downloads\Cause and Effect - Music.clkx
2012-06-07 09:10 - 2012-06-06 12:18 - 02028396 ____A C:\Users\ADRS\Downloads\Head Shoulders Knees and Toes.clkx
2012-06-07 09:00 - 2009-07-13 21:34 - 00000534 ____A C:\Windows\win.ini
2012-06-07 08:41 - 2012-06-06 12:16 - 02196679 ____A C:\Users\ADRS\Downloads\complete-clicker.exe
2012-06-07 08:19 - 2009-07-14 00:13 - 00747358 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-07 05:02 - 2012-06-06 15:06 - 00015287 ____A C:\Users\ADRS\Desktop\meeting with school.docx
2012-06-06 21:12 - 2011-06-27 13:10 - 00000000 ____D C:\Users\ADRS\Local Settings\Application Data\Adobe
2012-06-06 21:12 - 2011-06-27 13:10 - 00000000 ____D C:\Users\ADRS\Local Settings\Adobe
2012-06-06 21:12 - 2011-06-27 13:10 - 00000000 ____D C:\Users\ADRS\AppData\Local\Adobe
2012-06-06 20:40 - 2012-06-06 15:14 - 06124106 ____A C:\Users\ADRS\Downloads\Pps_SwitchActivities.zip
2012-06-06 20:40 - 2012-06-06 15:12 - 04380227 ____A C:\Users\ADRS\Downloads\Pps_nursery_rhymes_cause_effect.zip
2012-06-06 15:18 - 2012-06-06 15:17 - 01049727 ____A C:\Users\ADRS\Downloads\mary_had_a_red_dress.zip
2012-06-06 15:17 - 2012-06-06 15:16 - 01335713 ____A C:\Users\ADRS\Downloads\alpharap.zip
2012-06-06 15:15 - 2012-06-06 15:14 - 02137485 ____A C:\Users\ADRS\Downloads\Pps_FirstNationsABCRap.zip
2012-06-06 15:14 - 2012-06-06 15:14 - 01415237 ____A C:\Users\ADRS\Downloads\Pps_OutdoorABCRap.zip
2012-06-06 15:06 - 2012-06-06 15:06 - 00015263 ____A C:\Users\ADRS\Desktop\Developing hands.docx
2012-06-06 14:47 - 2012-06-06 14:41 - 17713360 ____A C:\Users\ADRS\Desktop\unity36adv.zip
2012-06-06 14:44 - 2012-06-06 14:38 - 15734894 ____A C:\Users\ADRS\Desktop\sblpcs36.zip
2012-06-06 14:42 - 2012-06-06 14:40 - 04214406 ____A C:\Users\ADRS\Desktop\pcsaltchat36.zip
2012-06-06 14:39 - 2012-06-06 14:39 - 00032737 ____A C:\Users\ADRS\Downloads\eyecore_june_2011.zip
2012-06-06 14:35 - 2012-06-06 12:16 - 00158549 ____A C:\Users\ADRS\Downloads\nursery-rhymes.zip
2012-06-06 14:30 - 2012-06-06 12:17 - 03232747 ____A C:\Users\ADRS\Downloads\The Itsy Bitsy Spider - Read.clkt
2012-06-06 14:28 - 2011-06-27 14:57 - 00000000 ____D C:\Users\Public\Documents\Clicker 5
2012-06-06 14:28 - 2011-06-27 14:57 - 00000000 ____D C:\Users\All Users\Documents\Clicker 5
2012-06-06 13:36 - 2012-06-06 13:36 - 01025205 ____A C:\Users\ADRS\Downloads\My Backyard - Color.clkt
2012-06-06 13:33 - 2012-06-06 13:32 - 01505385 ____A C:\Users\ADRS\Downloads\Read about Sam.clkt
2012-06-06 12:24 - 2012-06-06 12:22 - 03287333 ____A C:\Users\ADRS\Downloads\Incy Wincy Spider - Read.clkt
2012-06-06 12:18 - 2012-06-06 12:17 - 02025009 ____A C:\Users\ADRS\Downloads\More Head and Shoulders.clkt
2012-06-05 12:21 - 2012-06-05 12:03 - 00077787 ____A C:\Users\ADRS\Desktop\change of info.pdf
2012-06-01 16:28 - 2011-06-27 10:44 - 00000000 ____D C:\Users\ADRS\Desktop\Client files
2012-06-01 15:23 - 2011-06-27 12:41 - 00000000 ____D C:\Users\ADRS\My Documents\My Boards
2012-06-01 15:23 - 2011-06-27 12:41 - 00000000 ____D C:\Users\ADRS\Documents\My Boards
2012-06-01 14:58 - 2012-06-01 14:58 - 01353353 ____A C:\Users\ADRS\Downloads\SD_boards.zip
2012-06-01 12:33 - 2012-05-31 10:15 - 00050773 ____A C:\Users\ADRS\Desktop\Clinical Note for Word 2007-2010 (May 31 12).dotx
2012-05-31 13:42 - 2012-05-31 13:42 - 00050772 ____A C:\Users\ADRS\Desktop\from email.dotx
2012-05-31 13:11 - 2012-05-31 13:11 - 00363481 ____A C:\Users\ADRS\Desktop\Deming cycle.pdf
2012-05-31 10:31 - 2012-05-31 10:31 - 00048640 ____A C:\Users\ADRS\Desktop\Clinical Note for Word 2003 (May 31 12).dot
2012-05-30 11:19 - 2012-05-30 11:19 - 00049152 ____A C:\Users\ADRS\Desktop\Clinical note - Revised May 30, 2012.dot
2012-05-29 14:52 - 2012-05-29 14:52 - 00238037 ____A C:\Users\ADRS\Desktop\mediator training.pdf
2012-05-29 09:06 - 2012-05-29 09:06 - 02336200 ____A C:\Users\ADRS\Desktop\Khalinson.p2gbk
2012-05-28 14:45 - 2012-05-28 14:44 - 03945180 ____A C:\Users\ADRS\Downloads\abc-reading.pptx
2012-05-28 14:30 - 2012-05-28 14:30 - 00307200 ____A C:\Users\ADRS\Desktop\DONEHelpyourchildwithADHDsucceedinschool.doc
2012-05-25 12:27 - 2012-05-25 12:25 - 00000568 ____A C:\Users\ADRS\Desktop\Apple device query.4df
2012-05-25 10:13 - 2012-05-25 09:51 - 397619818 ____A C:\Users\ADRS\Desktop\Proloquo2Go.ipa
2012-05-25 09:42 - 2011-06-27 12:41 - 00008235 ____A C:\Users\ADRS\My Documents\BmSdp Log.txt
2012-05-25 09:42 - 2011-06-27 12:41 - 00008235 ____A C:\Users\ADRS\Documents\BmSdp Log.txt
2012-05-24 12:26 - 2012-05-23 13:41 - 00000280 ____A C:\Windows\WiViK3.ini
2012-05-23 14:04 - 2011-05-13 09:24 - 00128896 ____A C:\Users\ADRS\Local Settings\GDIPFONTCACHEV1.DAT
2012-05-23 14:04 - 2011-05-13 09:24 - 00128896 ____A C:\Users\ADRS\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2012-05-23 14:04 - 2011-05-13 09:24 - 00128896 ____A C:\Users\ADRS\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-23 14:04 - 2009-07-13 23:45 - 00474168 ____A C:\Windows\System32\FNTCACHE.DAT
2012-05-23 14:01 - 2012-05-23 14:01 - 00015042 ____A C:\Users\ADRS\Desktop\CTF Role in Voice Recognition.docx
2012-05-23 14:01 - 2012-05-23 14:01 - 00000162 ___AH C:\Users\ADRS\Desktop\~$linda boon.docx
2012-05-23 14:01 - 2012-05-23 14:01 - 00000162 ___AH C:\Users\ADRS\Desktop\~$F Role in Voice Recognition.docx
2012-05-23 14:01 - 2012-05-23 14:01 - 00000162 ___AH C:\Users\ADRS\Desktop\~$ check the.docx
2012-05-23 13:47 - 2012-05-23 13:42 - 00000000 ____D C:\Program Files (x86)\WordQ
2012-05-23 13:47 - 2012-05-23 13:40 - 00000000 ____D C:\Program Files (x86)\WiViK
2012-05-23 13:46 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\SysWOW64\Setup
2012-05-23 13:44 - 2012-05-23 13:44 - 00002457 ____A C:\Users\Public\Desktop\WordQ.lnk
2012-05-23 13:44 - 2012-05-23 13:44 - 00002457 ____A C:\Users\All Users\Desktop\WordQ.lnk
2012-05-23 13:44 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\Speech
2012-05-23 13:44 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\Help
2012-05-23 13:41 - 2012-05-23 13:41 - 00001558 ____A C:\Users\Public\Desktop\WiViK.lnk
2012-05-23 13:41 - 2012-05-23 13:41 - 00001558 ____A C:\Users\All Users\Desktop\WiViK.lnk
2012-05-23 11:31 - 2011-09-26 13:39 - 00000000 ____D C:\Users\ADRS\My Documents\Personal
2012-05-23 11:31 - 2011-09-26 13:39 - 00000000 ____D C:\Users\ADRS\Documents\Personal
2012-05-22 15:50 - 2011-06-27 12:41 - 00000168 ____A C:\Users\ADRS\My Documents\PrefsBM.prf
2012-05-22 15:50 - 2011-06-27 12:41 - 00000168 ____A C:\Users\ADRS\Documents\PrefsBM.prf
2012-05-22 11:02 - 2012-05-22 11:02 - 00091770 ____A C:\Users\ADRS\Desktop\SBL 4 04 Cheat Sheet-1.pdf
2012-05-22 10:34 - 2011-06-27 12:49 - 00000000 ____D C:\Users\ADRS\Desktop\Forms
2012-05-21 07:18 - 2012-05-21 07:18 - 00381248 ____A (Dassault Systèmes) C:\Users\ADRS\Downloads\3DVIA_player_installer(1).exe
2012-05-21 07:18 - 2012-05-21 07:18 - 00000000 ____D C:\Program Files (x86)\Virtools
2012-05-20 19:30 - 2012-02-29 06:00 - 00000000 ____D C:\Users\ADRS\Application Data\.minecraft
2012-05-20 19:30 - 2012-02-29 06:00 - 00000000 ____D C:\Users\ADRS\AppData\Roaming\.minecraft
2012-05-20 19:29 - 2012-05-20 19:28 - 00278561 ____A C:\Users\ADRS\Downloads\Minecraft(1).exe
2012-05-18 12:42 - 2012-05-18 12:42 - 00012030 ____A C:\Users\ADRS\My Documents\BM Lookup English (US).txt
2012-05-18 12:42 - 2012-05-18 12:42 - 00012030 ____A C:\Users\ADRS\Documents\BM Lookup English (US).txt
2012-05-18 12:21 - 2012-05-18 11:58 - 752104402 ____A C:\Users\ADRS\Downloads\widgit_products_setup_ca_9415.exe
2012-05-18 09:05 - 2012-06-05 13:37 - 11593306 ____A C:\Users\ADRS\Desktop\Matthew Proloquo2go.p2gbk
2012-05-17 14:16 - 2012-05-17 14:16 - 07201610 ____A C:\Users\ADRS\Downloads\pictures.zip
2012-05-17 08:59 - 2012-05-17 08:59 - 00000000 ____D C:\Users\All Users\Mozilla
2012-05-17 08:59 - 2012-05-17 08:59 - 00000000 ____D C:\Users\All Users\Application Data\Mozilla
2012-05-17 08:59 - 2012-05-17 08:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-05-17 08:27 - 2011-04-13 18:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-17 06:23 - 2012-01-18 13:31 - 00008864 ____A C:\BTDEVICES
2012-05-17 06:21 - 2012-05-17 06:21 - 01388330 ____A C:\Users\ADRS\Downloads\teaching14m343.zip
2012-05-17 06:19 - 2012-05-17 06:18 - 05254427 ____A C:\Users\ADRS\Downloads\Teaching14m245.zip
2012-05-17 06:18 - 2012-05-17 06:18 - 01101833 ____A C:\Users\ADRS\Downloads\play.zip
2012-05-17 06:17 - 2012-05-17 06:17 - 00935939 ____A C:\Users\ADRS\Downloads\eat.zip
2012-05-17 06:15 - 2012-05-17 06:15 - 00941369 ____A C:\Users\ADRS\Downloads\go.zip
2012-05-17 06:09 - 2012-05-17 06:09 - 06825367 ____A C:\Users\ADRS\Downloads\Teaching14m237.zip
2012-05-17 06:07 - 2012-05-17 06:07 - 08886991 ____A C:\Users\ADRS\Downloads\on-and-off.zip
2012-05-16 09:44 - 2011-05-17 09:16 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-05-16 09:44 - 2011-05-17 09:16 - 00000000 ____D C:\Users\All Users\Application Data\Microsoft Help
2012-05-16 09:33 - 2009-07-14 02:45 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-15 12:39 - 2012-05-15 12:39 - 00050176 ____A C:\Users\ADRS\Desktop\Clinical Note revised May 15 12.dot
2012-05-15 11:39 - 2012-05-15 11:39 - 00049470 ____A C:\Users\ADRS\Desktop\Clinical note for Word 2007 2010 (May 15 12).dotx
2012-05-14 11:00 - 2011-08-30 15:18 - 00000000 ____D C:\Users\ADRS\Local Settings\ElevatedDiagnostics
2012-05-14 11:00 - 2011-08-30 15:18 - 00000000 ____D C:\Users\ADRS\Local Settings\Application Data\ElevatedDiagnostics
2012-05-14 11:00 - 2011-08-30 15:18 - 00000000 ____D C:\Users\ADRS\AppData\Local\ElevatedDiagnostics
2012-05-03 10:23 - 2012-05-03 10:23 - 00000162 ___AH C:\Users\ADRS\Desktop\~$lients.docx
2012-05-01 04:53 - 2012-05-01 04:53 - 00000000 ____D C:\Users\ADRS\Desktop\ipad 3 photos
2012-04-30 09:34 - 2012-04-30 09:34 - 00000000 ____D C:\Users\ADRS\Desktop\NichlasD
2012-04-27 14:31 - 2011-06-27 13:21 - 00000000 ____D C:\Users\ADRS\Application Data\Apple Computer
2012-04-27 14:31 - 2011-06-27 13:21 - 00000000 ____D C:\Users\ADRS\AppData\Roaming\Apple Computer
2012-04-25 13:47 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\NDF
2012-04-24 08:11 - 2012-04-26 09:21 - 09019091 ____A C:\Users\ADRS\Desktop\Kaylin.p2gbk
2012-04-20 10:30 - 2011-06-27 12:49 - 00000000 ____D C:\Users\ADRS\Desktop\stats
2012-04-19 05:53 - 2011-06-27 12:47 - 00000000 ____D C:\Users\ADRS\Desktop\Device _ software info and tutorials
2012-04-18 14:02 - 2012-04-18 14:02 - 00013706 ____A C:\Users\ADRS\Downloads\BIBLIOGRAPHY FOR FINAL MARKETING PROJECT.docx
2012-04-18 09:18 - 2012-03-12 09:40 - 00024504 ____A C:\Users\ADRS\Desktop\Clients.docx
2012-04-17 11:33 - 2011-06-27 13:06 - 00000000 ____D C:\Users\ADRS\My Documents\Camtasia Studio
2012-04-17 11:33 - 2011-06-27 13:06 - 00000000 ____D C:\Users\ADRS\Documents\Camtasia Studio
2012-04-17 11:28 - 2012-04-17 11:14 - 00005120 ____A C:\Users\ADRS\Local Settings\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-17 11:28 - 2012-04-17 11:14 - 00005120 ____A C:\Users\ADRS\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-17 11:28 - 2012-04-17 11:14 - 00005120 ____A C:\Users\ADRS\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-17 11:15 - 2011-06-27 13:51 - 00000000 ____D C:\Users\ADRS\Local Settings\TechSmith
2012-04-17 11:15 - 2011-06-27 13:51 - 00000000 ____D C:\Users\ADRS\Local Settings\Application Data\TechSmith
2012-04-17 11:15 - 2011-06-27 13:51 - 00000000 ____D C:\Users\ADRS\AppData\Local\TechSmith
2012-04-17 11:09 - 2011-06-27 15:12 - 00000000 ____D C:\Windows\SysWOW64\QuickTime
2012-04-17 11:09 - 2011-06-27 13:51 - 00000000 ____D C:\Users\All Users\TechSmith
2012-04-17 11:09 - 2011-06-27 13:51 - 00000000 ____D C:\Users\All Users\Application Data\TechSmith
2012-04-17 11:08 - 2011-06-27 13:51 - 00000000 ____D C:\Program Files (x86)\TechSmith
2012-04-16 14:21 - 2011-11-01 14:43 - 00000071 ____A C:\Windows\PVN_ENG.DAT
2012-04-15 07:14 - 2012-04-15 07:14 - 00278561 ____A C:\Users\ADRS\Downloads\Minecraft.exe
2012-04-11 13:28 - 2011-11-01 14:43 - 00023994 ____A C:\Windows\WW_ENG.DAT
2012-04-11 13:10 - 2012-02-07 14:02 - 00000000 ____D C:\Program Files (x86)\Mind Express English Zingui
2012-04-10 08:45 - 2012-04-10 08:46 - 00079360 ____A C:\Users\ADRS\Desktop\ADRS APPTS.XLS
2012-04-10 08:29 - 2012-04-10 08:46 - 00035422 ____A C:\Users\ADRS\Desktop\Scheduling - Data Entry Form 15-Mar-11 Admin.pdf
2012-04-10 07:55 - 2012-04-10 07:54 - 00000000 ____D C:\Program Files\iTunes
2012-04-10 07:55 - 2012-04-10 07:54 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-04-10 07:54 - 2012-04-10 07:54 - 00000000 ____D C:\Program Files\iPod
2012-04-05 15:10 - 2011-11-01 14:42 - 00000000 ____D C:\Program Files (x86)\Mind Express English Smart
2012-04-04 14:56 - 2012-06-08 15:09 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-04-01 22:01 - 2012-05-14 08:29 - 03143680 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-03-31 00:52 - 2012-05-14 08:29 - 05473136 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-03-30 23:43 - 2012-05-14 08:29 - 03970928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-03-30 23:43 - 2012-05-14 08:29 - 03915632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-03-30 06:09 - 2012-05-14 08:29 - 01895280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-28 16:45 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
ZeroAccess:
C:\Windows\Installer\{792f4199-0b73-e2f4-7b46-706eb422a6b8}
C:\Windows\Installer\{792f4199-0b73-e2f4-7b46-706eb422a6b8}\@
C:\Windows\Installer\{792f4199-0b73-e2f4-7b46-706eb422a6b8}\L
C:\Windows\Installer\{792f4199-0b73-e2f4-7b46-706eb422a6b8}\U
C:\Windows\Installer\{792f4199-0b73-e2f4-7b46-706eb422a6b8}\U\800000cb.@
ZeroAccess:
C:\Users\ADRS\AppData\Local\4d0d2e25
C:\Users\ADRS\AppData\Local\4d0d2e25\@
C:\Users\ADRS\AppData\Local\4d0d2e25\loader.tlb
C:\Users\ADRS\AppData\Local\4d0d2e25\U
C:\Users\ADRS\AppData\Local\4d0d2e25\U\800000cb.$
ZeroAccess:
C:\Users\ADRS\AppData\Local\{792f4199-0b73-e2f4-7b46-706eb422a6b8}
C:\Users\ADRS\AppData\Local\{792f4199-0b73-e2f4-7b46-706eb422a6b8}\@
C:\Users\ADRS\AppData\Local\{792f4199-0b73-e2f4-7b46-706eb422a6b8}\L
C:\Users\ADRS\AppData\Local\{792f4199-0b73-e2f4-7b46-706eb422a6b8}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 18:19] - [2009-07-13 20:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 6058.17 MB
Available physical RAM: 5374.04 MB
Total Pagefile: 6056.32 MB
Available Pagefile: 5367.7 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:683.89 GB) (Free:582.59 GB) NTFS
2 Drive d: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:6.4 GB) NTFS
3 Drive e: (DISK1S1) (Removable) (Total:14.98 GB) (Free:14.17 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 698 GB 0 B
Disk 1 Online 15 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 101 MB 31 KB
Partition 2 Primary 14 GB 101 MB
Partition 3 Primary 683 GB 14 GB
======================================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 101 MB Healthy Hidden
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 D RECOVERY NTFS Partition 14 GB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 683 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 31 KB
======================================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E DISK1S1 FAT32 Removable 14 GB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-08 00:28
======================= End Of Log ==========================
Thanking you in advance.
Scan result of Farbar Recovery Scan Tool Version: 09-06-2012 01
Ran by SYSTEM at 24-06-2012 23:52:03
Running from E:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [559616 2011-10-17] (Dell)
HKLM-x32\...\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe [165184 2011-01-13] (Softthinks)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.73.1
AppInit_DLLs: C:\Windows\system32\nvinitx.dll
Startup: C:\Users\ADRS\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 BBSvc; C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [193816 2012-02-10] (Microsoft Corporation.)
3 BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [240408 2012-02-10] (Microsoft Corporation.)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] ()
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 PEVSystemStart; "C:\32788R22FWJFW\pev.3XE" EXEC /I CSCRIPT.exe //NOLOGO //E:VBSCRIPT //B //T:15 "C:\32788R22FWJFW\KNetSvcs.vbs" [407 2012-05-20] ()
2 RapiMgr; C:\Windows\WindowsMobile\rapimgr.dll [225672 2007-05-31] (Microsoft Corporation)
3 RoxMediaDB12OEM; "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe" [1116656 2010-09-04] (Sonic Solutions)
2 RoxWatch12; "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe" [219632 2010-09-04] (Sonic Solutions)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656280 2010-12-20] (Intel Corporation)
2 WcesComm; C:\Windows\WindowsMobile\wcescomm.dll [443784 2007-05-31] (Microsoft Corporation)
3 aspnet_state; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x]
2 WinDefend; C:\Program Files (x86)\Windows Defender\mpsvc.dll [x]
========================== Drivers (Whitelisted) =============
1 ctxusbm; C:\Windows\System32\Drivers\ctxusbm.sys [87600 2009-09-08] (Citrix Systems, Inc.)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
3 NvStUSB; C:\Windows\System32\Drivers\NvStUSB.sys [121960 2010-12-12] ()
3 qicflt; C:\Windows\System32\Drivers\qicflt.sys [29288 2010-07-12] (Quanta Computer)
2 TurboB; C:\Windows\System32\Drivers\TurboB.sys [16120 2010-11-29] (Intel(R) Corporation)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-11 23:22 - 2012-06-11 23:22 - 00000000 ____D C:\Windows\pss
2012-06-11 21:25 - 2012-06-24 23:52 - 00000000 ____D C:\FRST
2012-06-09 11:56 - 2012-06-09 11:56 - 00001268 ____A C:\Users\ADRS\Desktop\shutdown.lnk
2012-06-09 02:46 - 2012-06-09 02:46 - 00007280 ____N C:\bootsqm.dat
2012-06-08 15:38 - 2012-06-08 15:38 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-08 15:38 - 2012-06-08 15:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-08 15:37 - 2012-06-08 15:37 - 12621696 ____A (Microsoft Corporation) C:\Users\ADRS\Downloads\mseinstall(2).exe
2012-06-08 15:26 - 2012-06-08 15:26 - 00003966 ____A C:\Users\ADRS\Desktop\mbam-log-2012-06-08 (16-18-29).txt
2012-06-08 15:11 - 2012-06-08 15:17 - 00000000 ___SD C:\32788R22FWJFW
2012-06-08 15:09 - 2012-06-08 15:09 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-08 15:09 - 2012-06-08 15:09 - 00001111 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\All Users\Application Data\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\ADRS\Application Data\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\ADRS\AppData\Roaming\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-08 15:09 - 2012-04-04 14:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-08 15:08 - 2012-06-08 15:08 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\ADRS\Downloads\mbam-setup-1.61.0.1400.exe
2012-06-08 15:04 - 2012-06-08 15:04 - 04538510 ___RA (Swearware) C:\Users\ADRS\Downloads\ComboFix.exe
2012-06-08 14:54 - 2012-06-08 14:55 - 12621696 ____A (Microsoft Corporation) C:\Users\ADRS\Downloads\mseinstall(1).exe
2012-06-08 14:51 - 2012-06-24 22:34 - 00702462 ____A C:\Windows\ntbtlog.txt
2012-06-08 14:27 - 2012-06-08 14:27 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-08 14:23 - 2012-06-10 02:59 - 00000000 ____D C:\Users\All Users\B7E858A700005EC800035D60A60145BE
2012-06-08 14:23 - 2012-06-10 02:59 - 00000000 ____D C:\Users\All Users\Application Data\B7E858A700005EC800035D60A60145BE
2012-06-08 13:49 - 2012-06-08 13:49 - 00080512 ____A C:\Users\ADRS\Desktop\Jackies_iPod_June8.p2gbk
2012-06-08 13:35 - 2012-06-08 13:35 - 01698823 ____A C:\Users\ADRS\Desktop\EK.p2gbk
2012-06-08 13:23 - 2012-06-08 13:23 - 02338893 ____A C:\Users\ADRS\Desktop\stdprod_080112.pdf
2012-06-08 12:59 - 2012-06-08 12:59 - 00000162 ___AH C:\Users\ADRS\Desktop\~$eferred Hours of Work ADRS-1.doc
2012-06-08 01:41 - 2012-06-08 01:41 - 00415232 ____A C:\Users\ADRS\Desktop\Preferred Hours of Work ADRS-1.doc
2012-06-06 15:17 - 2012-06-06 15:18 - 01049727 ____A C:\Users\ADRS\Downloads\mary_had_a_red_dress.zip
2012-06-06 15:16 - 2012-06-06 15:17 - 01335713 ____A C:\Users\ADRS\Downloads\alpharap.zip
2012-06-06 15:14 - 2012-06-06 20:40 - 06124106 ____A C:\Users\ADRS\Downloads\Pps_SwitchActivities.zip
2012-06-06 15:14 - 2012-06-06 15:15 - 02137485 ____A C:\Users\ADRS\Downloads\Pps_FirstNationsABCRap.zip
2012-06-06 15:14 - 2012-06-06 15:14 - 01415237 ____A C:\Users\ADRS\Downloads\Pps_OutdoorABCRap.zip
2012-06-06 15:12 - 2012-06-06 20:40 - 04380227 ____A C:\Users\ADRS\Downloads\Pps_nursery_rhymes_cause_effect.zip
2012-06-06 15:06 - 2012-06-07 05:02 - 00015287 ____A C:\Users\ADRS\Desktop\meeting with school.docx
2012-06-06 15:06 - 2012-06-06 15:06 - 00015263 ____A C:\Users\ADRS\Desktop\Developing hands.docx
2012-06-06 14:41 - 2012-06-06 14:47 - 17713360 ____A C:\Users\ADRS\Desktop\unity36adv.zip
2012-06-06 14:40 - 2012-06-06 14:42 - 04214406 ____A C:\Users\ADRS\Desktop\pcsaltchat36.zip
2012-06-06 14:39 - 2012-06-06 14:39 - 00032737 ____A C:\Users\ADRS\Downloads\eyecore_june_2011.zip
2012-06-06 14:38 - 2012-06-06 14:44 - 15734894 ____A C:\Users\ADRS\Desktop\sblpcs36.zip
2012-06-06 13:47 - 2012-06-07 09:12 - 00933678 ____A C:\Users\ADRS\Downloads\My Toys - Color.clkt
2012-06-06 13:36 - 2012-06-06 13:36 - 01025205 ____A C:\Users\ADRS\Downloads\My Backyard - Color.clkt
2012-06-06 13:32 - 2012-06-06 13:33 - 01505385 ____A C:\Users\ADRS\Downloads\Read about Sam.clkt
2012-06-06 12:51 - 2012-06-07 09:10 - 02826052 ____A C:\Users\ADRS\Downloads\Cause and Effect - Music.clkx
2012-06-06 12:22 - 2012-06-06 12:24 - 03287333 ____A C:\Users\ADRS\Downloads\Incy Wincy Spider - Read.clkt
2012-06-06 12:18 - 2012-06-07 09:10 - 02028396 ____A C:\Users\ADRS\Downloads\Head Shoulders Knees and Toes.clkx
2012-06-06 12:17 - 2012-06-06 14:30 - 03232747 ____A C:\Users\ADRS\Downloads\The Itsy Bitsy Spider - Read.clkt
2012-06-06 12:17 - 2012-06-06 12:18 - 02025009 ____A C:\Users\ADRS\Downloads\More Head and Shoulders.clkt
2012-06-06 12:16 - 2012-06-07 08:41 - 02196679 ____A C:\Users\ADRS\Downloads\complete-clicker.exe
2012-06-06 12:16 - 2012-06-06 14:35 - 00158549 ____A C:\Users\ADRS\Downloads\nursery-rhymes.zip
2012-06-05 13:37 - 2012-05-18 09:05 - 11593306 ____A C:\Users\ADRS\Desktop\Matthew Proloquo2go.p2gbk
2012-06-05 12:03 - 2012-06-05 12:21 - 00077787 ____A C:\Users\ADRS\Desktop\change of info.pdf
2012-06-01 14:58 - 2012-06-01 14:58 - 01353353 ____A C:\Users\ADRS\Downloads\SD_boards.zip
2012-06-01 14:32 - 2012-06-08 15:11 - 00000000 ____D C:\Users\ADRS\Desktop\personal
2012-05-31 13:42 - 2012-05-31 13:42 - 00050772 ____A C:\Users\ADRS\Desktop\from email.dotx
2012-05-31 13:39 - 2008-07-31 07:46 - 05538816 ____A C:\Users\ADRS\Desktop\Laurie - changes to FINAL ISAAC PPT A.ppt
2012-05-31 13:11 - 2012-05-31 13:11 - 00363481 ____A C:\Users\ADRS\Desktop\Deming cycle.pdf
2012-05-31 10:31 - 2012-05-31 10:31 - 00048640 ____A C:\Users\ADRS\Desktop\Clinical Note for Word 2003 (May 31 12).dot
2012-05-31 10:15 - 2012-06-01 12:33 - 00050773 ____A C:\Users\ADRS\Desktop\Clinical Note for Word 2007-2010 (May 31 12).dotx
2012-05-30 11:19 - 2012-05-30 11:19 - 00049152 ____A C:\Users\ADRS\Desktop\Clinical note - Revised May 30, 2012.dot
2012-05-29 14:52 - 2012-05-29 14:52 - 00238037 ____A C:\Users\ADRS\Desktop\mediator training.pdf
2012-05-29 09:06 - 2012-05-29 09:06 - 02336200 ____A C:\Users\ADRS\Desktop\Khalinson.p2gbk
2012-05-28 14:44 - 2012-05-28 14:45 - 03945180 ____A C:\Users\ADRS\Downloads\abc-reading.pptx
2012-05-28 14:30 - 2012-05-28 14:30 - 00307200 ____A C:\Users\ADRS\Desktop\DONEHelpyourchildwithADHDsucceedinschool.doc
2012-05-25 12:25 - 2012-05-25 12:27 - 00000568 ____A C:\Users\ADRS\Desktop\Apple device query.4df
2012-05-25 09:51 - 2012-05-25 10:13 - 397619818 ____A C:\Users\ADRS\Desktop\Proloquo2Go.ipa
============ 3 Months Modified Files and Folders =============
2012-06-24 23:52 - 2012-06-11 21:25 - 00000000 ____D C:\FRST
2012-06-24 22:45 - 2011-06-27 12:51 - 00000000 ____D C:\Users\ADRS\Application Data\Dropbox
2012-06-24 22:45 - 2011-06-27 12:51 - 00000000 ____D C:\Users\ADRS\AppData\Roaming\Dropbox
2012-06-24 22:45 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-24 22:44 - 2011-06-27 12:53 - 00000000 ___RD C:\Users\ADRS\Dropbox
2012-06-24 22:44 - 2011-05-13 09:24 - 00000000 ____D C:\Users\ADRS\Local Settings\SoftThinks
2012-06-24 22:44 - 2011-05-13 09:24 - 00000000 ____D C:\Users\ADRS\Local Settings\Application Data\SoftThinks
2012-06-24 22:44 - 2011-05-13 09:24 - 00000000 ____D C:\Users\ADRS\AppData\Local\SoftThinks
2012-06-24 22:44 - 2011-04-13 19:56 - 00000000 ____D C:\Users\All Users\NVIDIA
2012-06-24 22:44 - 2011-04-13 19:56 - 00000000 ____D C:\Users\All Users\Application Data\NVIDIA
2012-06-24 22:44 - 2011-04-13 18:31 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2012-06-24 22:44 - 2009-07-14 00:08 - 00026486 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-24 22:43 - 2009-07-13 23:51 - 00069780 ____A C:\Windows\setupact.log
2012-06-24 22:34 - 2012-06-08 14:51 - 00702462 ____A C:\Windows\ntbtlog.txt
2012-06-11 23:22 - 2012-06-11 23:22 - 00000000 ____D C:\Windows\pss
2012-06-10 02:59 - 2012-06-08 14:23 - 00000000 ____D C:\Users\All Users\B7E858A700005EC800035D60A60145BE
2012-06-10 02:59 - 2012-06-08 14:23 - 00000000 ____D C:\Users\All Users\Application Data\B7E858A700005EC800035D60A60145BE
2012-06-09 12:18 - 2009-07-14 00:10 - 01318128 ____A C:\Windows\WindowsUpdate.log
2012-06-09 11:56 - 2012-06-09 11:56 - 00001268 ____A C:\Users\ADRS\Desktop\shutdown.lnk
2012-06-09 02:46 - 2012-06-09 02:46 - 00007280 ____N C:\bootsqm.dat
2012-06-08 23:06 - 2009-07-13 23:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-08 23:06 - 2009-07-13 23:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-08 16:05 - 2011-04-13 18:59 - 00000000 ____D C:\Users\All Users\Sonic
2012-06-08 16:05 - 2011-04-13 18:59 - 00000000 ____D C:\Users\All Users\Application Data\Sonic
2012-06-08 15:50 - 2012-01-11 14:07 - 00000000 __SHD C:\Users\ADRS\Local Settings\Application Data\{792f4199-0b73-e2f4-7b46-706eb422a6b8}
2012-06-08 15:50 - 2012-01-11 14:07 - 00000000 __SHD C:\Users\ADRS\Local Settings\{792f4199-0b73-e2f4-7b46-706eb422a6b8}
2012-06-08 15:50 - 2012-01-11 14:07 - 00000000 __SHD C:\Users\ADRS\AppData\Local\{792f4199-0b73-e2f4-7b46-706eb422a6b8}
2012-06-08 15:38 - 2012-06-08 15:38 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-08 15:38 - 2012-06-08 15:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-08 15:38 - 2011-06-27 15:27 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-08 15:38 - 2011-06-27 14:55 - 00753204 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-08 15:37 - 2012-06-08 15:37 - 12621696 ____A (Microsoft Corporation) C:\Users\ADRS\Downloads\mseinstall(2).exe
2012-06-08 15:27 - 2011-04-13 19:53 - 00058468 ____A C:\Windows\PFRO.log
2012-06-08 15:26 - 2012-06-08 15:26 - 00003966 ____A C:\Users\ADRS\Desktop\mbam-log-2012-06-08 (16-18-29).txt
2012-06-08 15:17 - 2012-06-08 15:11 - 00000000 ___SD C:\32788R22FWJFW
2012-06-08 15:11 - 2012-06-01 14:32 - 00000000 ____D C:\Users\ADRS\Desktop\personal
2012-06-08 15:11 - 2011-06-27 09:40 - 00000000 ____D C:\Users\ADRS\Desktop\Key contents
2012-06-08 15:09 - 2012-06-08 15:09 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-08 15:09 - 2012-06-08 15:09 - 00001111 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\All Users\Application Data\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\ADRS\Application Data\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Users\ADRS\AppData\Roaming\Malwarebytes
2012-06-08 15:09 - 2012-06-08 15:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-08 15:08 - 2012-06-08 15:08 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\ADRS\Downloads\mbam-setup-1.61.0.1400.exe
2012-06-08 15:04 - 2012-06-08 15:04 - 04538510 ___RA (Swearware) C:\Users\ADRS\Downloads\ComboFix.exe
2012-06-08 14:55 - 2012-06-08 14:54 - 12621696 ____A (Microsoft Corporation) C:\Users\ADRS\Downloads\mseinstall(1).exe
2012-06-08 14:43 - 2011-06-27 09:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-06-08 14:27 - 2012-06-08 14:27 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-08 13:49 - 2012-06-08 13:49 - 00080512 ____A C:\Users\ADRS\Desktop\Jackies_iPod_June8.p2gbk
2012-06-08 13:35 - 2012-06-08 13:35 - 01698823 ____A C:\Users\ADRS\Desktop\EK.p2gbk
2012-06-08 13:23 - 2012-06-08 13:23 - 02338893 ____A C:\Users\ADRS\Desktop\stdprod_080112.pdf
2012-06-08 12:59 - 2012-06-08 12:59 - 00000162 ___AH C:\Users\ADRS\Desktop\~$eferred Hours of Work ADRS-1.doc
2012-06-08 03:31 - 2011-09-26 10:02 - 00000000 ____D C:\5100
2012-06-08 01:41 - 2012-06-08 01:41 - 00415232 ____A C:\Users\ADRS\Desktop\Preferred Hours of Work ADRS-1.doc
2012-06-07 09:14 - 2011-06-27 15:06 - 00000000 ____D C:\Users\ADRS\Local Settings\ApplicationHistory
2012-06-07 09:14 - 2011-06-27 15:06 - 00000000 ____D C:\Users\ADRS\Local Settings\Application Data\ApplicationHistory
2012-06-07 09:14 - 2011-06-27 15:06 - 00000000 ____D C:\Users\ADRS\AppData\Local\ApplicationHistory
2012-06-07 09:12 - 2012-06-06 13:47 - 00933678 ____A C:\Users\ADRS\Downloads\My Toys - Color.clkt
2012-06-07 09:10 - 2012-06-06 12:51 - 02826052 ____A C:\Users\ADRS\Downloads\Cause and Effect - Music.clkx
2012-06-07 09:10 - 2012-06-06 12:18 - 02028396 ____A C:\Users\ADRS\Downloads\Head Shoulders Knees and Toes.clkx
2012-06-07 09:00 - 2009-07-13 21:34 - 00000534 ____A C:\Windows\win.ini
2012-06-07 08:41 - 2012-06-06 12:16 - 02196679 ____A C:\Users\ADRS\Downloads\complete-clicker.exe
2012-06-07 08:19 - 2009-07-14 00:13 - 00747358 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-07 05:02 - 2012-06-06 15:06 - 00015287 ____A C:\Users\ADRS\Desktop\meeting with school.docx
2012-06-06 21:12 - 2011-06-27 13:10 - 00000000 ____D C:\Users\ADRS\Local Settings\Application Data\Adobe
2012-06-06 21:12 - 2011-06-27 13:10 - 00000000 ____D C:\Users\ADRS\Local Settings\Adobe
2012-06-06 21:12 - 2011-06-27 13:10 - 00000000 ____D C:\Users\ADRS\AppData\Local\Adobe
2012-06-06 20:40 - 2012-06-06 15:14 - 06124106 ____A C:\Users\ADRS\Downloads\Pps_SwitchActivities.zip
2012-06-06 20:40 - 2012-06-06 15:12 - 04380227 ____A C:\Users\ADRS\Downloads\Pps_nursery_rhymes_cause_effect.zip
2012-06-06 15:18 - 2012-06-06 15:17 - 01049727 ____A C:\Users\ADRS\Downloads\mary_had_a_red_dress.zip
2012-06-06 15:17 - 2012-06-06 15:16 - 01335713 ____A C:\Users\ADRS\Downloads\alpharap.zip
2012-06-06 15:15 - 2012-06-06 15:14 - 02137485 ____A C:\Users\ADRS\Downloads\Pps_FirstNationsABCRap.zip
2012-06-06 15:14 - 2012-06-06 15:14 - 01415237 ____A C:\Users\ADRS\Downloads\Pps_OutdoorABCRap.zip
2012-06-06 15:06 - 2012-06-06 15:06 - 00015263 ____A C:\Users\ADRS\Desktop\Developing hands.docx
2012-06-06 14:47 - 2012-06-06 14:41 - 17713360 ____A C:\Users\ADRS\Desktop\unity36adv.zip
2012-06-06 14:44 - 2012-06-06 14:38 - 15734894 ____A C:\Users\ADRS\Desktop\sblpcs36.zip
2012-06-06 14:42 - 2012-06-06 14:40 - 04214406 ____A C:\Users\ADRS\Desktop\pcsaltchat36.zip
2012-06-06 14:39 - 2012-06-06 14:39 - 00032737 ____A C:\Users\ADRS\Downloads\eyecore_june_2011.zip
2012-06-06 14:35 - 2012-06-06 12:16 - 00158549 ____A C:\Users\ADRS\Downloads\nursery-rhymes.zip
2012-06-06 14:30 - 2012-06-06 12:17 - 03232747 ____A C:\Users\ADRS\Downloads\The Itsy Bitsy Spider - Read.clkt
2012-06-06 14:28 - 2011-06-27 14:57 - 00000000 ____D C:\Users\Public\Documents\Clicker 5
2012-06-06 14:28 - 2011-06-27 14:57 - 00000000 ____D C:\Users\All Users\Documents\Clicker 5
2012-06-06 13:36 - 2012-06-06 13:36 - 01025205 ____A C:\Users\ADRS\Downloads\My Backyard - Color.clkt
2012-06-06 13:33 - 2012-06-06 13:32 - 01505385 ____A C:\Users\ADRS\Downloads\Read about Sam.clkt
2012-06-06 12:24 - 2012-06-06 12:22 - 03287333 ____A C:\Users\ADRS\Downloads\Incy Wincy Spider - Read.clkt
2012-06-06 12:18 - 2012-06-06 12:17 - 02025009 ____A C:\Users\ADRS\Downloads\More Head and Shoulders.clkt
2012-06-05 12:21 - 2012-06-05 12:03 - 00077787 ____A C:\Users\ADRS\Desktop\change of info.pdf
2012-06-01 16:28 - 2011-06-27 10:44 - 00000000 ____D C:\Users\ADRS\Desktop\Client files
2012-06-01 15:23 - 2011-06-27 12:41 - 00000000 ____D C:\Users\ADRS\My Documents\My Boards
2012-06-01 15:23 - 2011-06-27 12:41 - 00000000 ____D C:\Users\ADRS\Documents\My Boards
2012-06-01 14:58 - 2012-06-01 14:58 - 01353353 ____A C:\Users\ADRS\Downloads\SD_boards.zip
2012-06-01 12:33 - 2012-05-31 10:15 - 00050773 ____A C:\Users\ADRS\Desktop\Clinical Note for Word 2007-2010 (May 31 12).dotx
2012-05-31 13:42 - 2012-05-31 13:42 - 00050772 ____A C:\Users\ADRS\Desktop\from email.dotx
2012-05-31 13:11 - 2012-05-31 13:11 - 00363481 ____A C:\Users\ADRS\Desktop\Deming cycle.pdf
2012-05-31 10:31 - 2012-05-31 10:31 - 00048640 ____A C:\Users\ADRS\Desktop\Clinical Note for Word 2003 (May 31 12).dot
2012-05-30 11:19 - 2012-05-30 11:19 - 00049152 ____A C:\Users\ADRS\Desktop\Clinical note - Revised May 30, 2012.dot
2012-05-29 14:52 - 2012-05-29 14:52 - 00238037 ____A C:\Users\ADRS\Desktop\mediator training.pdf
2012-05-29 09:06 - 2012-05-29 09:06 - 02336200 ____A C:\Users\ADRS\Desktop\Khalinson.p2gbk
2012-05-28 14:45 - 2012-05-28 14:44 - 03945180 ____A C:\Users\ADRS\Downloads\abc-reading.pptx
2012-05-28 14:30 - 2012-05-28 14:30 - 00307200 ____A C:\Users\ADRS\Desktop\DONEHelpyourchildwithADHDsucceedinschool.doc
2012-05-25 12:27 - 2012-05-25 12:25 - 00000568 ____A C:\Users\ADRS\Desktop\Apple device query.4df
2012-05-25 10:13 - 2012-05-25 09:51 - 397619818 ____A C:\Users\ADRS\Desktop\Proloquo2Go.ipa
2012-05-25 09:42 - 2011-06-27 12:41 - 00008235 ____A C:\Users\ADRS\My Documents\BmSdp Log.txt
2012-05-25 09:42 - 2011-06-27 12:41 - 00008235 ____A C:\Users\ADRS\Documents\BmSdp Log.txt
2012-05-24 12:26 - 2012-05-23 13:41 - 00000280 ____A C:\Windows\WiViK3.ini
2012-05-23 14:04 - 2011-05-13 09:24 - 00128896 ____A C:\Users\ADRS\Local Settings\GDIPFONTCACHEV1.DAT
2012-05-23 14:04 - 2011-05-13 09:24 - 00128896 ____A C:\Users\ADRS\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2012-05-23 14:04 - 2011-05-13 09:24 - 00128896 ____A C:\Users\ADRS\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-23 14:04 - 2009-07-13 23:45 - 00474168 ____A C:\Windows\System32\FNTCACHE.DAT
2012-05-23 14:01 - 2012-05-23 14:01 - 00015042 ____A C:\Users\ADRS\Desktop\CTF Role in Voice Recognition.docx
2012-05-23 14:01 - 2012-05-23 14:01 - 00000162 ___AH C:\Users\ADRS\Desktop\~$linda boon.docx
2012-05-23 14:01 - 2012-05-23 14:01 - 00000162 ___AH C:\Users\ADRS\Desktop\~$F Role in Voice Recognition.docx
2012-05-23 14:01 - 2012-05-23 14:01 - 00000162 ___AH C:\Users\ADRS\Desktop\~$ check the.docx
2012-05-23 13:47 - 2012-05-23 13:42 - 00000000 ____D C:\Program Files (x86)\WordQ
2012-05-23 13:47 - 2012-05-23 13:40 - 00000000 ____D C:\Program Files (x86)\WiViK
2012-05-23 13:46 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\SysWOW64\Setup
2012-05-23 13:44 - 2012-05-23 13:44 - 00002457 ____A C:\Users\Public\Desktop\WordQ.lnk
2012-05-23 13:44 - 2012-05-23 13:44 - 00002457 ____A C:\Users\All Users\Desktop\WordQ.lnk
2012-05-23 13:44 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\Speech
2012-05-23 13:44 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\Help
2012-05-23 13:41 - 2012-05-23 13:41 - 00001558 ____A C:\Users\Public\Desktop\WiViK.lnk
2012-05-23 13:41 - 2012-05-23 13:41 - 00001558 ____A C:\Users\All Users\Desktop\WiViK.lnk
2012-05-23 11:31 - 2011-09-26 13:39 - 00000000 ____D C:\Users\ADRS\My Documents\Personal
2012-05-23 11:31 - 2011-09-26 13:39 - 00000000 ____D C:\Users\ADRS\Documents\Personal
2012-05-22 15:50 - 2011-06-27 12:41 - 00000168 ____A C:\Users\ADRS\My Documents\PrefsBM.prf
2012-05-22 15:50 - 2011-06-27 12:41 - 00000168 ____A C:\Users\ADRS\Documents\PrefsBM.prf
2012-05-22 11:02 - 2012-05-22 11:02 - 00091770 ____A C:\Users\ADRS\Desktop\SBL 4 04 Cheat Sheet-1.pdf
2012-05-22 10:34 - 2011-06-27 12:49 - 00000000 ____D C:\Users\ADRS\Desktop\Forms
2012-05-21 07:18 - 2012-05-21 07:18 - 00381248 ____A (Dassault Systèmes) C:\Users\ADRS\Downloads\3DVIA_player_installer(1).exe
2012-05-21 07:18 - 2012-05-21 07:18 - 00000000 ____D C:\Program Files (x86)\Virtools
2012-05-20 19:30 - 2012-02-29 06:00 - 00000000 ____D C:\Users\ADRS\Application Data\.minecraft
2012-05-20 19:30 - 2012-02-29 06:00 - 00000000 ____D C:\Users\ADRS\AppData\Roaming\.minecraft
2012-05-20 19:29 - 2012-05-20 19:28 - 00278561 ____A C:\Users\ADRS\Downloads\Minecraft(1).exe
2012-05-18 12:42 - 2012-05-18 12:42 - 00012030 ____A C:\Users\ADRS\My Documents\BM Lookup English (US).txt
2012-05-18 12:42 - 2012-05-18 12:42 - 00012030 ____A C:\Users\ADRS\Documents\BM Lookup English (US).txt
2012-05-18 12:21 - 2012-05-18 11:58 - 752104402 ____A C:\Users\ADRS\Downloads\widgit_products_setup_ca_9415.exe
2012-05-18 09:05 - 2012-06-05 13:37 - 11593306 ____A C:\Users\ADRS\Desktop\Matthew Proloquo2go.p2gbk
2012-05-17 14:16 - 2012-05-17 14:16 - 07201610 ____A C:\Users\ADRS\Downloads\pictures.zip
2012-05-17 08:59 - 2012-05-17 08:59 - 00000000 ____D C:\Users\All Users\Mozilla
2012-05-17 08:59 - 2012-05-17 08:59 - 00000000 ____D C:\Users\All Users\Application Data\Mozilla
2012-05-17 08:59 - 2012-05-17 08:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-05-17 08:27 - 2011-04-13 18:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-17 06:23 - 2012-01-18 13:31 - 00008864 ____A C:\BTDEVICES
2012-05-17 06:21 - 2012-05-17 06:21 - 01388330 ____A C:\Users\ADRS\Downloads\teaching14m343.zip
2012-05-17 06:19 - 2012-05-17 06:18 - 05254427 ____A C:\Users\ADRS\Downloads\Teaching14m245.zip
2012-05-17 06:18 - 2012-05-17 06:18 - 01101833 ____A C:\Users\ADRS\Downloads\play.zip
2012-05-17 06:17 - 2012-05-17 06:17 - 00935939 ____A C:\Users\ADRS\Downloads\eat.zip
2012-05-17 06:15 - 2012-05-17 06:15 - 00941369 ____A C:\Users\ADRS\Downloads\go.zip
2012-05-17 06:09 - 2012-05-17 06:09 - 06825367 ____A C:\Users\ADRS\Downloads\Teaching14m237.zip
2012-05-17 06:07 - 2012-05-17 06:07 - 08886991 ____A C:\Users\ADRS\Downloads\on-and-off.zip
2012-05-16 09:44 - 2011-05-17 09:16 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-05-16 09:44 - 2011-05-17 09:16 - 00000000 ____D C:\Users\All Users\Application Data\Microsoft Help
2012-05-16 09:33 - 2009-07-14 02:45 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-15 12:39 - 2012-05-15 12:39 - 00050176 ____A C:\Users\ADRS\Desktop\Clinical Note revised May 15 12.dot
2012-05-15 11:39 - 2012-05-15 11:39 - 00049470 ____A C:\Users\ADRS\Desktop\Clinical note for Word 2007 2010 (May 15 12).dotx
2012-05-14 11:00 - 2011-08-30 15:18 - 00000000 ____D C:\Users\ADRS\Local Settings\ElevatedDiagnostics
2012-05-14 11:00 - 2011-08-30 15:18 - 00000000 ____D C:\Users\ADRS\Local Settings\Application Data\ElevatedDiagnostics
2012-05-14 11:00 - 2011-08-30 15:18 - 00000000 ____D C:\Users\ADRS\AppData\Local\ElevatedDiagnostics
2012-05-03 10:23 - 2012-05-03 10:23 - 00000162 ___AH C:\Users\ADRS\Desktop\~$lients.docx
2012-05-01 04:53 - 2012-05-01 04:53 - 00000000 ____D C:\Users\ADRS\Desktop\ipad 3 photos
2012-04-30 09:34 - 2012-04-30 09:34 - 00000000 ____D C:\Users\ADRS\Desktop\NichlasD
2012-04-27 14:31 - 2011-06-27 13:21 - 00000000 ____D C:\Users\ADRS\Application Data\Apple Computer
2012-04-27 14:31 - 2011-06-27 13:21 - 00000000 ____D C:\Users\ADRS\AppData\Roaming\Apple Computer
2012-04-25 13:47 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\NDF
2012-04-24 08:11 - 2012-04-26 09:21 - 09019091 ____A C:\Users\ADRS\Desktop\Kaylin.p2gbk
2012-04-20 10:30 - 2011-06-27 12:49 - 00000000 ____D C:\Users\ADRS\Desktop\stats
2012-04-19 05:53 - 2011-06-27 12:47 - 00000000 ____D C:\Users\ADRS\Desktop\Device _ software info and tutorials
2012-04-18 14:02 - 2012-04-18 14:02 - 00013706 ____A C:\Users\ADRS\Downloads\BIBLIOGRAPHY FOR FINAL MARKETING PROJECT.docx
2012-04-18 09:18 - 2012-03-12 09:40 - 00024504 ____A C:\Users\ADRS\Desktop\Clients.docx
2012-04-17 11:33 - 2011-06-27 13:06 - 00000000 ____D C:\Users\ADRS\My Documents\Camtasia Studio
2012-04-17 11:33 - 2011-06-27 13:06 - 00000000 ____D C:\Users\ADRS\Documents\Camtasia Studio
2012-04-17 11:28 - 2012-04-17 11:14 - 00005120 ____A C:\Users\ADRS\Local Settings\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-17 11:28 - 2012-04-17 11:14 - 00005120 ____A C:\Users\ADRS\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-17 11:28 - 2012-04-17 11:14 - 00005120 ____A C:\Users\ADRS\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-17 11:15 - 2011-06-27 13:51 - 00000000 ____D C:\Users\ADRS\Local Settings\TechSmith
2012-04-17 11:15 - 2011-06-27 13:51 - 00000000 ____D C:\Users\ADRS\Local Settings\Application Data\TechSmith
2012-04-17 11:15 - 2011-06-27 13:51 - 00000000 ____D C:\Users\ADRS\AppData\Local\TechSmith
2012-04-17 11:09 - 2011-06-27 15:12 - 00000000 ____D C:\Windows\SysWOW64\QuickTime
2012-04-17 11:09 - 2011-06-27 13:51 - 00000000 ____D C:\Users\All Users\TechSmith
2012-04-17 11:09 - 2011-06-27 13:51 - 00000000 ____D C:\Users\All Users\Application Data\TechSmith
2012-04-17 11:08 - 2011-06-27 13:51 - 00000000 ____D C:\Program Files (x86)\TechSmith
2012-04-16 14:21 - 2011-11-01 14:43 - 00000071 ____A C:\Windows\PVN_ENG.DAT
2012-04-15 07:14 - 2012-04-15 07:14 - 00278561 ____A C:\Users\ADRS\Downloads\Minecraft.exe
2012-04-11 13:28 - 2011-11-01 14:43 - 00023994 ____A C:\Windows\WW_ENG.DAT
2012-04-11 13:10 - 2012-02-07 14:02 - 00000000 ____D C:\Program Files (x86)\Mind Express English Zingui
2012-04-10 08:45 - 2012-04-10 08:46 - 00079360 ____A C:\Users\ADRS\Desktop\ADRS APPTS.XLS
2012-04-10 08:29 - 2012-04-10 08:46 - 00035422 ____A C:\Users\ADRS\Desktop\Scheduling - Data Entry Form 15-Mar-11 Admin.pdf
2012-04-10 07:55 - 2012-04-10 07:54 - 00000000 ____D C:\Program Files\iTunes
2012-04-10 07:55 - 2012-04-10 07:54 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-04-10 07:54 - 2012-04-10 07:54 - 00000000 ____D C:\Program Files\iPod
2012-04-05 15:10 - 2011-11-01 14:42 - 00000000 ____D C:\Program Files (x86)\Mind Express English Smart
2012-04-04 14:56 - 2012-06-08 15:09 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-04-01 22:01 - 2012-05-14 08:29 - 03143680 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-03-31 00:52 - 2012-05-14 08:29 - 05473136 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-03-30 23:43 - 2012-05-14 08:29 - 03970928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-03-30 23:43 - 2012-05-14 08:29 - 03915632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-03-30 06:09 - 2012-05-14 08:29 - 01895280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-28 16:45 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
ZeroAccess:
C:\Windows\Installer\{792f4199-0b73-e2f4-7b46-706eb422a6b8}
C:\Windows\Installer\{792f4199-0b73-e2f4-7b46-706eb422a6b8}\@
C:\Windows\Installer\{792f4199-0b73-e2f4-7b46-706eb422a6b8}\L
C:\Windows\Installer\{792f4199-0b73-e2f4-7b46-706eb422a6b8}\U
C:\Windows\Installer\{792f4199-0b73-e2f4-7b46-706eb422a6b8}\U\800000cb.@
ZeroAccess:
C:\Users\ADRS\AppData\Local\4d0d2e25
C:\Users\ADRS\AppData\Local\4d0d2e25\@
C:\Users\ADRS\AppData\Local\4d0d2e25\loader.tlb
C:\Users\ADRS\AppData\Local\4d0d2e25\U
C:\Users\ADRS\AppData\Local\4d0d2e25\U\800000cb.$
ZeroAccess:
C:\Users\ADRS\AppData\Local\{792f4199-0b73-e2f4-7b46-706eb422a6b8}
C:\Users\ADRS\AppData\Local\{792f4199-0b73-e2f4-7b46-706eb422a6b8}\@
C:\Users\ADRS\AppData\Local\{792f4199-0b73-e2f4-7b46-706eb422a6b8}\L
C:\Users\ADRS\AppData\Local\{792f4199-0b73-e2f4-7b46-706eb422a6b8}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 18:19] - [2009-07-13 20:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 6058.17 MB
Available physical RAM: 5374.04 MB
Total Pagefile: 6056.32 MB
Available Pagefile: 5367.7 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:683.89 GB) (Free:582.59 GB) NTFS
2 Drive d: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:6.4 GB) NTFS
3 Drive e: (DISK1S1) (Removable) (Total:14.98 GB) (Free:14.17 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 698 GB 0 B
Disk 1 Online 15 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 101 MB 31 KB
Partition 2 Primary 14 GB 101 MB
Partition 3 Primary 683 GB 14 GB
======================================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 101 MB Healthy Hidden
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 D RECOVERY NTFS Partition 14 GB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 683 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 31 KB
======================================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E DISK1S1 FAT32 Removable 14 GB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-08 00:28
======================= End Of Log ==========================