TechSpot

Black Screen with Cursor in Center

Inactive
By scottcom4
May 20, 2013
  1. Hi Guys,

    Over the weekend I downloaded a file that contained a video file and the supposed codec's packaged as an .EXE. Upon installation of said codecs AVG Pro flagged Services.exe as having a virus that could not be healed as the file was presently in use. I therefore ran AVG from my boot disk, once again this file was located and again could not be healed. I ran a scf /scanfile=c:\windows\system32\service.exe on the file, as I located information online that suggested this might work. Following this I rebooted my laptop and immediately after the windows animation begins the screen goes black and an arrow cursor appears in the centre of the screen. If you leave the screen up for long enough the laptop reboots itself and the process starts again. The sticky key test doesn't work, nor does pressing crlt+alt+del.

    I have attempted to boot in safe mode, safe mode with network support and safe mode with command prompt without success.

    I have created a boot disk using my other laptop and have attempted to use the System Restore, however there are no system restore points available, even though I created one less than a week ago. I therefore began using the Startup Repair. Even though some repairs were undertaken, the system failed to boot sucessfully. I have since attempted to use the Start Repair again, however I get a message saying that another can not be undertaken because a previous repair is still awaiting a restart.

    I have also completed a fix on the MBR, but this had not effect either.

    Could someone please offer me some assistance as I am completely out of ideas?

    Thank you
    Scott
     
  2. Broni

    Broni Malware Annihilator Posts: 47,704   +268

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ====================================

    What Windows version is it?
     
  3. scottcom4

    scottcom4 TS Rookie Topic Starter Posts: 17

    Hi Broni,

    Thank you for your help.

    To answer your question I am presently using Windows 7.
     
  4. Broni

    Broni Malware Annihilator Posts: 47,704   +268

    For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    If you are using Windows 8 consult How to use the Windows 8 System Recovery Environment Command Prompt to enter System Recovery Command prompt.

    If you are using Vista or Windows 7 enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    To enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:


    • Startup Repair
      System Restore
      Windows Complete PC Restore
      Windows Memory Diagnostic Tool
      Command Prompt
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

    Next...

    Re-run FRST again.
    Type the following in the edit box after "Search:".

    services.exe

    Click Search button and post the log (Search.txt) it makes in your reply.

    I'll expect two logs:
    - FRST.txt
    - Search.txt
     
  5. scottcom4

    scottcom4 TS Rookie Topic Starter Posts: 17

    Hi Broni,

    I have carried out your suggestions, however my computer is not recognising my USB drive.

    Do you have any suggestions on how to get around this?
     
  6. Broni

    Broni Malware Annihilator Posts: 47,704   +268

  7. scottcom4

    scottcom4 TS Rookie Topic Starter Posts: 17

    Sorry about that. After about 5 attempts it now appears to work. I will follow the rest of your directions and advise outcomes.
     
  8. Broni

    Broni Malware Annihilator Posts: 47,704   +268

  9. scottcom4

    scottcom4 TS Rookie Topic Starter Posts: 17

    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-05-2013
    Ran by SYSTEM on 20-05-2013 15:09:23
    Running from H:\
    Windows 7 Ultimate (X64) OS Language: English(US)
    Internet Explorer Version 9
    Boot Mode: Recovery
    The current controlset is ControlSet002
    ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.
    ==================== Registry (Whitelisted) ==================
    HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [12446824 2012-01-31] (Realtek Semiconductor)
    HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [617120 2011-03-13] (Atheros Commnucations)
    HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [379552 2011-03-13] (Atheros Commnucations)
    HKLM\...\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [4526 2010-11-29] ()
    HKLM\...\Run: [THXCfg64] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 [25600 2010-09-14] (Creative Technology Ltd.)
    HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2869008 2012-01-25] (Synaptics Incorporated)
    HKLM\...\Run: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe [100112 2012-01-25] (Synaptics Incorporated)
    HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [472992 2013-03-20] (Adobe Systems Incorporated)
    HKLM\...\Run: [BCSSync] "D:\Applications\MSOFFICE\Office14\BCSSync.exe" /DelayServices [x]
    HKLM\...\Run: [PC Monitor Operations] "D:\Applications\PC Monitor\pcmontask.exe" [x]
    HKLM-x32\...\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE" [2018032 2011-04-01] (ASUSTek Computer Inc.)
    HKLM-x32\...\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe /S [731472 2011-02-23] (ecareme)
    HKLM-x32\...\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe [3058304 2011-10-19] (ASUS)
    HKLM-x32\...\Run: [THX TruStudio NB Settings] "C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" /r [909312 2011-03-16] (Creative Technology Ltd)
    HKLM-x32\...\Run: [CPMonitor] "C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe" [84464 2011-04-01] ()
    HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-19] (CyberLink Corp.)
    HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-11-02] (CyberLink)
    HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-19] (CyberLink Corp.)
    HKLM-x32\...\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [318080 2011-12-22] (ASUSTek Computer Inc.)
    HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-23] (ASUS)
    HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-18] (ASUS)
    HKLM-x32\...\Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [102568 2012-02-06] (ASUS)
    HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2321072 2012-02-01] (ASUSTeK Computer Inc.)
    HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-18] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin [1523360 2011-01-11] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [PWRISOVM.EXE] D:\Applications\PowerISO\PWRISOVM.EXE -startup [x]
    HKLM-x32\...\Run: [LWS] D:\Applications\Logitech\LWS\Webcam Software\LWS.exe -hide [x]
    HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [103536 2011-08-21] (VMware, Inc.)
    HKLM-x32\...\Run: [USBChargerPlusTray] C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [1120936 2012-01-29] (ASUSTek Computer Inc.)
    HKLM-x32\...\Run: [AVG_UI] "D:\Applications\AVG\AVG2013\avgui.exe" /TRAYONLY [x]
    HKLM-x32\...\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin [1073312 2012-03-08] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [] [x]
    HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "D:\Applications\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [x]
    HKLM-x32\...\Run: [Acrobat Assistant 8.0] "D:\Applications\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [x]
    HKU\Scott\...\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe [370480 2010-07-19] (syncables, LLC)
    HKU\Scott\...\Run: [WebcamMaxAutoRun] "d:\applications\WebcamMax\WebcamMax.exe" -a [x]
    HKU\Scott\...\Run: [Nike+ Connect] "C:\Users\Scott\AppData\Local\Nike\Nike+ Connect\Nike+ Connect daemon.exe" [70656 2012-06-19] (Nike)
    HKU\Scott\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
    HKU\Scott\...\Run: [DownloadManager] "C:\Program Files (x86)\Zoom Downloader\DownloadManager.exe" /as [1649152 2013-02-25] (Zoom Downloader)
    HKU\Scott\...\Run: [RoboForm] "D:\Applications\RoboForm\RoboTaskBarIcon.exe" [x]
    HKU\Scott\...\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" [1098072 2013-03-26] (Garmin Ltd or its subsidiaries)
    HKU\Scott\...\Run: [MsgCenterExe] "C:\Program Files (x86)\Real\RealPlayer\update\RealOneMessageCenter.exe" -osboot [82632 2013-02-15] (RealNetworks, Inc.)
    HKU\Scott\...\Run: [AdobeBridge] [x]
    Startup: C:\ProgramData\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
    ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
    Startup: C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
    ShortcutTarget: Dropbox.lnk -> (No File)
    Startup: C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.0.lnk
    ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.0.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (IntelĀ® Corporation)
    Startup: C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> D:\Applications\MSOFFICE\Office14\ONENOTEM.EXE (No File)
    BootExecute: autocheck autochk * sdnclean64.exe
    ==================== Services (Whitelisted) =================
    S2 AsusUacSvc; C:\Program Files\Asus\Rotation Desktop for G Series\AsusUacSvc.exe [113840 2010-07-27] ()
    S2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-03-13] (Atheros)
    S2 ATKGFNEXSrv; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896 2011-11-20] (ASUS)
    S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [185688 2013-03-26] (Garmin Ltd or its subsidiaries)
    S2 HyperDeskCustomThemeEnabler; C:\Windows\Installer\MSI7F56.tmp [102400 2012-07-13] ()
    S2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-13] (Microsoft Corporation)
    S2 MSSQL$SQLEXPRESS; C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
    S2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] ()
    S2 TVersityMediaServer; C:\ProgramData\TVersity\Media Server\MediaServer.exe [5279528 2012-08-10] ()
    S2 VMwareHostd; C:\ProgramData\VMware\hostd\config.xml [31995 2012-05-31] ()
    S2 WajamUpdater; C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe [109064 2013-01-09] (Wajam)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] ()
    S3 WiselinkPro; C:\Program Files (x86)\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [3007488 2010-02-16] ()
    S2 avgfws; D:\Applications\AVG\AVG2013\avgfws.exe [x]
    S2 AVGIDSAgent; D:\Applications\AVG\AVG2013\avgidsagent.exe [x]
    S2 avgwd; D:\Applications\AVG\AVG2013\avgwdsvc.exe [x]
    S3 Microsoft SharePoint Workspace Audit Service; D:\Applications\MSOFFICE\Office14\GROOVE.EXE /auditservice [x]
    S2 PC Monitor; "D:\Applications\PC Monitor\PCMonitorSrv.exe" [x]
    S3 rpcapd; "%ProgramFiles(x86)%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles(x86)%\WinPcap\rpcapd.ini" [x]
    S2 SAS Document Conversion; "d:\applications\SASHome\SASTextAnalyticsDocumentConversion\1.2\file-converter-service.exe" [x]
    S2 SAS PC Files Server; "d:\applications\SASHome\SASPCFilesServer\9.3\pcfservice.exe" -name "SAS PC Files Server" [x]
    S2 VisualWebRipper; "D:\applications\Visual Web Ripper\WebRipperService.exe" [x]
    ==================== Drivers (Whitelisted) ====================
    S3 AiCharger; C:\Windows\SysWow64\DRIVERS\AiCharger.sys [17152 2012-01-29] (ASUSTek Computer Inc.)
    S1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-06] (ASUS)
    S1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [50296 2012-09-03] (AVG Technologies CZ, s.r.o.)
    S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [154464 2012-10-21] (AVG Technologies CZ, s.r.o. )
    S0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [63328 2012-10-14] (AVG Technologies CZ, s.r.o. )
    S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [185696 2012-10-01] (AVG Technologies CZ, s.r.o.)
    S0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [225120 2012-09-20] (AVG Technologies CZ, s.r.o.)
    S0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [111968 2012-11-15] (AVG Technologies CZ, s.r.o.)
    S0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40800 2012-09-13] (AVG Technologies CZ, s.r.o.)
    S1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [200032 2012-09-20] (AVG Technologies CZ, s.r.o.)
    S3 FLxHCIh; C:\Windows\System32\DRIVERS\FLxHCIh.sys [76584 2012-07-18] (Fresco Logic)
    S3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
    S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [34304 2012-01-10] (ManyCam LLC)
    S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2012-02-22] (ManyCam LLC)
    S3 mcdevice; C:\Windows\System32\DRIVERS\mcdevice.sys [334400 2011-05-18] (ShiningMorning Inc.)
    S3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-13] (Microsoft Corporation)
    S3 SmbDrv; C:\Windows\System32\DRIVERS\Smb_driver.sys [22800 2012-01-25] (Synaptics Incorporated)
    S3 VCam_WDM; C:\Windows\System32\DRIVERS\VCam_WDM.sys [106424 2011-02-02] (e2eSoft)
    S2 WCMVCAM; C:\Windows\System32\DRIVERS\wcmvcam64.sys [1071032 2011-06-22] (Windows (R) Win 7 DDK provider)
    S1 ElbyCDIO; System32\Drivers\ElbyCDIO.sys [x]
    S2 NPF; system32\drivers\npf.sys [x]
    S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
    S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
    S3 VGPU; System32\drivers\rdvgkmd.sys [x]
    S3 WinRing0_1_2_0; \??\C:\Windows\TEMP\tmpF815.tmp [x]
    ==================== NetSvcs (Whitelisted) ===================
     
  10. scottcom4

    scottcom4 TS Rookie Topic Starter Posts: 17

    ==================== One Month Created Files and Folders ========
    2013-05-20 15:08 - 2013-05-20 15:08 - 00000000 ____D C:\FRST
    2013-05-20 12:53 - 2013-05-20 12:53 - 00000000 __SHD C:\$$PendingFiles
    2013-05-20 09:58 - 2013-05-20 09:58 - 00000000 ____D C:\Windows\Microsoft Antimalware
    2013-05-19 21:14 - 2013-05-19 21:14 - 00000000 __SHD C:\found.003
    2013-05-18 19:20 - 2013-05-18 19:20 - 00000000 ____D C:\Program Files (x86)\x264 Video Codec
    2013-05-18 02:26 - 2013-05-18 02:26 - 00030900 ____A C:\Users\Scott\Downloads\The Internship 2013 (English) [DVDRip].x264.torrent
    2013-05-18 02:25 - 2013-05-18 02:25 - 00030852 ____A C:\Users\Scott\Downloads\Brave 2012 (English) DVDRip.AC3.torrent
    2013-05-18 02:24 - 2013-05-18 02:24 - 00030840 ____A C:\Users\Scott\Downloads\Snitch 2013 Eng BDRip (480p).torrent
    2013-05-18 02:09 - 2013-05-18 02:09 - 00033250 ____A C:\Users\Scott\Downloads\[isoHunt] download.torrent
    2013-05-17 01:29 - 2013-05-17 01:29 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{504BE270-A577-4781-BEC4-B53AABDE77EC}
    2013-05-17 01:29 - 2013-05-17 01:29 - 00000000 ____D C:\Users\Scott\Local Settings\{504BE270-A577-4781-BEC4-B53AABDE77EC}
    2013-05-17 01:29 - 2013-05-17 01:29 - 00000000 ____D C:\Users\Scott\AppData\Local\{504BE270-A577-4781-BEC4-B53AABDE77EC}
    2013-05-17 00:29 - 2013-05-17 00:30 - 00657096 ____A C:\Windows\Minidump\051713-43742-01.dmp
    2013-05-16 22:54 - 2013-05-16 22:54 - 00291760 ____A (StarApp) C:\Users\Scott\Downloads\Green Lantern The Animated Series HDTV Season 1 [Extremlym].exe
    2013-05-16 22:54 - 2013-05-16 22:54 - 00013704 ____A C:\Users\Scott\Downloads\[kat.ph]green.lantern.the.animated.series.hdtv.season.1.extremlym.torrent
    2013-05-16 03:27 - 2013-05-16 03:27 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{F456DFA5-C62E-4B89-AAD3-1194BF3F3FEE}
    2013-05-16 03:27 - 2013-05-16 03:27 - 00000000 ____D C:\Users\Scott\Local Settings\{F456DFA5-C62E-4B89-AAD3-1194BF3F3FEE}
    2013-05-16 03:27 - 2013-05-16 03:27 - 00000000 ____D C:\Users\Scott\AppData\Local\{F456DFA5-C62E-4B89-AAD3-1194BF3F3FEE}
    2013-05-15 16:25 - 2013-05-15 16:25 - 00002021 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
    2013-05-15 16:25 - 2013-05-15 16:25 - 00002021 ____A C:\ProgramData\Desktop\Adobe Reader XI.lnk
    2013-05-15 14:44 - 2013-05-15 14:44 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{FA8A81E6-7F11-4F48-9582-1622351CDA23}
    2013-05-15 14:44 - 2013-05-15 14:44 - 00000000 ____D C:\Users\Scott\Local Settings\{FA8A81E6-7F11-4F48-9582-1622351CDA23}
    2013-05-15 14:44 - 2013-05-15 14:44 - 00000000 ____D C:\Users\Scott\AppData\Local\{FA8A81E6-7F11-4F48-9582-1622351CDA23}
    2013-05-15 09:03 - 2013-04-04 22:52 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
    2013-05-15 09:03 - 2013-04-04 22:50 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2013-05-15 09:03 - 2013-04-04 22:50 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2013-05-15 09:03 - 2013-04-04 22:50 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2013-05-15 09:03 - 2013-04-04 22:50 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
    2013-05-15 09:03 - 2013-04-04 22:50 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
    2013-05-15 09:03 - 2013-04-04 22:50 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
    2013-05-15 09:03 - 2013-04-04 21:28 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2013-05-15 09:03 - 2013-04-04 21:26 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2013-05-15 09:03 - 2013-04-04 21:26 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2013-05-15 09:03 - 2013-04-04 21:26 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2013-05-15 09:03 - 2013-04-04 21:26 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
    2013-05-15 09:03 - 2013-04-04 21:26 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2013-05-15 09:03 - 2013-04-04 21:26 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2013-05-15 09:03 - 2013-04-04 20:43 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2013-05-15 09:03 - 2013-04-04 20:29 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2013-05-15 09:03 - 2013-04-04 19:51 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
    2013-05-15 09:03 - 2013-04-04 19:38 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
    2013-05-15 09:02 - 2013-04-04 22:52 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2013-05-15 09:02 - 2013-04-04 22:52 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2013-05-15 09:02 - 2013-04-04 22:50 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2013-05-15 09:02 - 2013-04-04 22:50 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2013-05-15 09:02 - 2013-04-04 22:50 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2013-05-15 09:02 - 2013-04-04 22:50 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2013-05-15 09:02 - 2013-04-04 22:50 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2013-05-15 09:02 - 2013-04-04 21:28 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2013-05-15 09:02 - 2013-04-04 21:26 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2013-05-15 09:02 - 2013-04-04 21:26 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2013-05-15 09:02 - 2013-04-04 21:26 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2013-05-15 09:02 - 2013-04-04 21:26 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2013-05-15 09:02 - 2013-04-04 21:26 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2013-05-14 15:21 - 2013-05-14 15:21 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{A0FB89D4-2DCF-4F7E-967F-55CF70346736}
    2013-05-14 15:21 - 2013-05-14 15:21 - 00000000 ____D C:\Users\Scott\Local Settings\{A0FB89D4-2DCF-4F7E-967F-55CF70346736}
    2013-05-14 15:21 - 2013-05-14 15:21 - 00000000 ____D C:\Users\Scott\AppData\Local\{A0FB89D4-2DCF-4F7E-967F-55CF70346736}
    2013-05-14 14:16 - 2013-04-09 22:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
    2013-05-14 14:16 - 2013-04-09 22:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
    2013-05-14 14:16 - 2011-02-03 03:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll
    2013-05-14 14:15 - 2013-04-09 19:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2013-05-14 14:15 - 2013-03-18 21:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
    2013-05-14 14:15 - 2013-03-18 21:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
    2013-05-14 14:15 - 2013-02-26 22:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
    2013-05-14 14:15 - 2013-02-26 21:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2013-05-14 14:15 - 2013-02-26 21:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
    2013-05-14 14:15 - 2013-02-26 21:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
    2013-05-14 14:15 - 2013-02-26 21:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
    2013-05-14 14:15 - 2013-02-26 20:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2013-05-14 14:15 - 2013-02-26 20:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
    2013-05-14 14:15 - 2013-02-26 20:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
    2013-05-12 14:13 - 2013-05-12 14:13 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{CA4EA4BB-57DD-4056-8062-BEE08BC5CE10}
    2013-05-12 14:13 - 2013-05-12 14:13 - 00000000 ____D C:\Users\Scott\Local Settings\{CA4EA4BB-57DD-4056-8062-BEE08BC5CE10}
    2013-05-12 14:13 - 2013-05-12 14:13 - 00000000 ____D C:\Users\Scott\AppData\Local\{CA4EA4BB-57DD-4056-8062-BEE08BC5CE10}
    2013-05-12 00:14 - 2013-05-12 00:15 - 00645160 ____A C:\Windows\Minidump\051213-60918-01.dmp
    2013-05-11 23:04 - 2013-05-11 23:04 - 00021259 ____A C:\Users\Scott\Downloads\Photoshop CS6 Complete Tutorial [h33t].torrent
    2013-05-11 20:44 - 2013-05-11 20:44 - 00000000 ____D C:\Users\Scott\My Documents\Fragments
    2013-05-11 20:44 - 2013-05-11 20:44 - 00000000 ____D C:\Users\Scott\Documents\Fragments
    2013-05-11 20:41 - 2013-05-12 15:25 - 00000000 ____D C:\Users\Scott\My Documents\Adobe
    2013-05-11 20:41 - 2013-05-12 15:25 - 00000000 ____D C:\Users\Scott\Documents\Adobe
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\Local Settings\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\Application Data\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\AppData\Roaming\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\AppData\Local\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\ProgramData\Application Data\PACE Anti-Piracy
    2013-05-11 18:32 - 2013-05-11 18:33 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{0372A8BF-43BB-4589-9804-D7D59E6C17C5}
    2013-05-11 18:32 - 2013-05-11 18:33 - 00000000 ____D C:\Users\Scott\Local Settings\{0372A8BF-43BB-4589-9804-D7D59E6C17C5}
    2013-05-11 18:32 - 2013-05-11 18:33 - 00000000 ____D C:\Users\Scott\AppData\Local\{0372A8BF-43BB-4589-9804-D7D59E6C17C5}
    2013-05-11 17:40 - 2013-05-15 16:09 - 00001760 ____A C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
    2013-05-11 17:40 - 2013-05-15 16:09 - 00001760 ____A C:\ProgramData\Desktop\Adobe Acrobat X Pro.lnk
    2013-05-11 17:37 - 2013-05-11 17:38 - 00009737 ____A C:\Users\Scott\Desktop\What I want from a job!!!.xlsx
    2013-05-11 17:30 - 2013-05-11 17:30 - 00000000 ____D C:\Program Files\Adobe
    2013-05-11 17:29 - 2013-05-11 17:29 - 00000000 ____D C:\ProgramData\Application Data\ALM
    2013-05-11 17:29 - 2013-05-11 17:29 - 00000000 ____D C:\ProgramData\ALM
    2013-05-11 17:25 - 2013-05-11 17:25 - 00000000 ____D C:\Users\Scott\Adobe Flash Builder 4.6
    2013-05-11 17:20 - 2013-05-11 17:20 - 00000000 ____D C:\Program Files (x86)\My Company Name
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default\Application Data\Macromedia
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default User\Application Data\Macromedia
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
    2013-05-11 17:11 - 2013-05-11 17:58 - 00001520 ____A C:\Users\Public\Desktop\Adobe Application Manager.lnk
    2013-05-11 17:11 - 2013-05-11 17:58 - 00001520 ____A C:\ProgramData\Desktop\Adobe Application Manager.lnk
    2013-05-11 17:01 - 2013-05-11 17:01 - 00150109 ____A C:\Users\Scott\Downloads\Adobe Master Collection CS6 (x86_x64) + Serial +Crack [h33t].torrent
    2013-05-10 22:45 - 2013-05-10 22:45 - 00288671 ____A C:\Users\Scott\Downloads\F55CE73101159D1EBDDBDD99D33650BD925B4680.torrent
    2013-05-10 15:36 - 2013-05-10 15:36 - 00060404 ____A C:\Users\Scott\Downloads\B85E1484E0CE574E140640AEC37263C00E4074D1.torrent
    2013-05-10 15:36 - 2013-05-10 15:36 - 00030013 ____A C:\Users\Scott\Downloads\DCB5315CEBF9F31D47F4E67BBE6CEC697D16AF5F.torrent
    2013-05-10 15:32 - 2013-05-10 15:32 - 00029877 ____A C:\Users\Scott\Downloads\Jordan+Belfort+-+Straight+Line+Persuasion+System.torrent
    2013-05-09 23:57 - 2013-05-09 23:57 - 00055872 ____A (Adobe Systems Inc) C:\Windows\System32\AdobePDF.dll
    2013-05-09 23:57 - 2013-05-09 23:57 - 00027208 ____A (Adobe Systems Inc.) C:\Windows\System32\AdobePDFUI.dll
    2013-05-06 02:01 - 2013-05-06 02:01 - 00014541 ____A C:\Users\Scott\Downloads\iframeupload
    2013-05-06 01:51 - 2013-05-06 01:56 - 00000000 ____D C:\Users\Scott\Desktop\Id Brenda Mitchell
    2013-05-05 03:53 - 2013-05-05 03:53 - 00000132 ____A C:\Users\Scott\Application Data\Adobe PNG Format CS5 Prefs
    2013-05-05 03:53 - 2013-05-05 03:53 - 00000132 ____A C:\Users\Scott\AppData\Roaming\Adobe PNG Format CS5 Prefs
    2013-05-04 03:16 - 2013-05-04 03:16 - 00000750 ____A C:\Users\Public\Desktop\VLC media player.lnk
    2013-05-04 03:16 - 2013-05-04 03:16 - 00000750 ____A C:\ProgramData\Desktop\VLC media player.lnk
    2013-05-04 00:03 - 2013-05-04 01:01 - 592233072 ____A C:\Users\Scott\My Documents\Veda Yoga Teacher Training Sample Class 2_(720p).mp4
    2013-05-04 00:03 - 2013-05-04 01:01 - 592233072 ____A C:\Users\Scott\Documents\Veda Yoga Teacher Training Sample Class 2_(720p).mp4
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000896 ____A C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000896 ____A C:\ProgramData\Desktop\Revo Uninstaller Pro.lnk
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\Users\Scott\Local Settings\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\Users\Scott\AppData\Local\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\ProgramData\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\ProgramData\Application Data\VS Revo Group
    2013-04-29 15:05 - 2009-12-29 17:21 - 00031800 ____A (VS Revo Group) C:\Windows\System32\Drivers\revoflt.sys
    2013-04-29 15:03 - 2013-04-29 15:03 - 09916056 ____A (VS Revo Group ) C:\Users\Scott\Downloads\RevoUninProSetup.exe
    2013-04-28 04:21 - 2013-04-28 04:21 - 00020484 ____A C:\Users\Scott\Downloads\The Big Bang Theory - COMPLETE Season 6 720p HDTV [h33t].torrent
    2013-04-27 01:35 - 2013-04-27 01:36 - 20443632 ____A C:\Users\Scott\Downloads\dgnd3700v2-v1.1.00.08_1.00.08.img
    2013-04-27 01:17 - 2012-07-01 16:42 - 32505856 ____A C:\Users\Scott\Downloads\DGND3700v2.bin
    2013-04-27 01:15 - 2012-07-12 08:36 - 18744576 ____A C:\Users\Scott\Downloads\dgnd3700v2-v1.1.00.12_1.00.12na.img
    2013-04-27 01:14 - 2013-04-27 01:15 - 18734033 ____A C:\Users\Scott\Downloads\dgnd3700v2-v1.1.00.12_1.00.12NA (1).zip
    2013-04-27 01:13 - 2013-04-27 01:14 - 18734033 ____A C:\Users\Scott\Downloads\dgnd3700v2-v1.1.00.12_1.00.12NA.zip
    2013-04-27 00:54 - 2013-04-27 00:56 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{E28E94FD-F483-41A9-A6CE-2F1F8E31ED42}
    2013-04-27 00:54 - 2013-04-27 00:56 - 00000000 ____D C:\Users\Scott\Local Settings\{E28E94FD-F483-41A9-A6CE-2F1F8E31ED42}
    2013-04-27 00:54 - 2013-04-27 00:56 - 00000000 ____D C:\Users\Scott\AppData\Local\{E28E94FD-F483-41A9-A6CE-2F1F8E31ED42}
    2013-04-27 00:43 - 2013-04-27 00:43 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2 (6).cfg
    2013-04-27 00:42 - 2013-04-27 00:42 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (6).cfg
    2013-04-27 00:41 - 2013-04-27 00:42 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (5).cfg
    2013-04-27 00:40 - 2013-04-27 00:40 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (4).cfg
    2013-04-27 00:40 - 2013-04-27 00:40 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2 (4).cfg
    2013-04-27 00:39 - 2013-04-27 00:39 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2 (4).txt
    2013-04-27 00:37 - 2013-04-27 00:37 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (3).cfg
    2013-04-27 00:35 - 2013-04-27 00:37 - 00021937 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (2).cfg
    2013-04-27 00:33 - 2013-04-27 00:33 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (1).cfg
    2013-04-27 00:30 - 2013-04-27 00:30 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2.cfg
    2013-04-27 00:29 - 2013-04-27 00:29 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2.cfg
    2013-04-25 16:05 - 2013-04-25 16:05 - 00693632 ____A (Playtech) C:\Users\Scott\Downloads\SetupCasino_53b9ca_en.exe
    2013-04-24 16:02 - 2013-04-24 16:03 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{24DE84E9-14FD-4954-A42C-F8BAD8684788}
    2013-04-24 16:02 - 2013-04-24 16:03 - 00000000 ____D C:\Users\Scott\Local Settings\{24DE84E9-14FD-4954-A42C-F8BAD8684788}
    2013-04-24 16:02 - 2013-04-24 16:03 - 00000000 ____D C:\Users\Scott\AppData\Local\{24DE84E9-14FD-4954-A42C-F8BAD8684788}
    2013-04-23 18:24 - 2013-04-12 06:45 - 01656680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
    2013-04-23 17:52 - 2013-04-23 17:52 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{4E08EE1D-BAD2-431E-9DE2-8833F3EE7305}
    2013-04-23 17:52 - 2013-04-23 17:52 - 00000000 ____D C:\Users\Scott\Local Settings\{4E08EE1D-BAD2-431E-9DE2-8833F3EE7305}
    2013-04-23 17:52 - 2013-04-23 17:52 - 00000000 ____D C:\Users\Scott\AppData\Local\{4E08EE1D-BAD2-431E-9DE2-8833F3EE7305}
    2013-04-22 01:02 - 2013-04-22 01:02 - 00000000 ____A C:\Users\Scott\Desktop\3124672.txt
    2013-04-20 23:16 - 2013-04-20 23:26 - 00030928 ____A C:\Users\Scott\Downloads\National.Geographic.Megafactories.IKEA.HDTV.XviD-YT.5461842.TPB.torrent
    2013-04-20 21:48 - 2013-04-20 21:51 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{A53544E2-E5A8-4A2C-BAD3-05C7420C959F}
    2013-04-20 21:48 - 2013-04-20 21:51 - 00000000 ____D C:\Users\Scott\Local Settings\{A53544E2-E5A8-4A2C-BAD3-05C7420C959F}
    2013-04-20 21:48 - 2013-04-20 21:51 - 00000000 ____D C:\Users\Scott\AppData\Local\{A53544E2-E5A8-4A2C-BAD3-05C7420C959F}
     
  11. scottcom4

    scottcom4 TS Rookie Topic Starter Posts: 17

    ==================== One Month Modified Files and Folders =======
    2013-05-20 15:08 - 2013-05-20 15:08 - 00000000 ____D C:\FRST
    2013-05-20 12:53 - 2013-05-20 12:53 - 00000000 __SHD C:\$$PendingFiles
    2013-05-20 10:14 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
    2013-05-20 09:58 - 2013-05-20 09:58 - 00000000 ____D C:\Windows\Microsoft Antimalware
    2013-05-19 21:14 - 2013-05-19 21:14 - 00000000 __SHD C:\found.003
    2013-05-19 19:11 - 2012-05-31 01:50 - 00000000 ____D C:\ProgramData\VMware
    2013-05-19 19:11 - 2012-05-31 01:50 - 00000000 ____D C:\ProgramData\Application Data\VMware
    2013-05-19 19:11 - 2012-05-30 19:52 - 00000000 ____A C:\pcfservice.log
    2013-05-19 19:11 - 2012-05-25 23:29 - 00000000 ____D C:\ProgramData\NVIDIA
    2013-05-19 19:11 - 2012-05-25 23:29 - 00000000 ____D C:\ProgramData\Application Data\NVIDIA
    2013-05-18 21:19 - 2012-07-14 17:02 - 00000000 ____D C:\Users\Scott\Application Data\vlc
    2013-05-18 21:19 - 2012-07-14 17:02 - 00000000 ____D C:\Users\Scott\AppData\Roaming\vlc
    2013-05-18 21:17 - 2012-05-10 05:13 - 00000000 ____D C:\Users\Scott\Application Data\uTorrent
    2013-05-18 21:17 - 2012-05-10 05:13 - 00000000 ____D C:\Users\Scott\AppData\Roaming\uTorrent
    2013-05-18 20:38 - 2012-06-10 15:39 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2013-05-18 20:25 - 2012-10-08 18:14 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2013-05-18 19:20 - 2013-05-18 19:20 - 00000000 ____D C:\Program Files (x86)\x264 Video Codec
    2013-05-18 19:20 - 2011-10-19 22:40 - 01763092 ____A C:\Windows\WindowsUpdate.log
    2013-05-18 19:18 - 2012-07-14 18:23 - 00000000 ____D C:\ProgramData\MFAData
    2013-05-18 19:18 - 2012-07-14 18:23 - 00000000 ____D C:\ProgramData\Application Data\MFAData
    2013-05-18 17:51 - 2012-08-10 00:29 - 00000000 ____A C:\END
    2013-05-18 17:50 - 2013-04-10 09:03 - 00000356 ____A C:\Windows\Tasks\AmiUpdXp.job
    2013-05-18 08:00 - 2012-05-11 01:38 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\Adobe
    2013-05-18 08:00 - 2012-05-11 01:38 - 00000000 ____D C:\Users\Scott\Local Settings\Adobe
    2013-05-18 08:00 - 2012-05-11 01:38 - 00000000 ____D C:\Users\Scott\AppData\Local\Adobe
    2013-05-18 02:48 - 2013-02-19 04:24 - 00010686 ____A C:\Windows\setupact.log
    2013-05-18 02:26 - 2013-05-18 02:26 - 00030900 ____A C:\Users\Scott\Downloads\The Internship 2013 (English) [DVDRip].x264.torrent
    2013-05-18 02:25 - 2013-05-18 02:25 - 00030852 ____A C:\Users\Scott\Downloads\Brave 2012 (English) DVDRip.AC3.torrent
    2013-05-18 02:24 - 2013-05-18 02:24 - 00030840 ____A C:\Users\Scott\Downloads\Snitch 2013 Eng BDRip (480p).torrent
    2013-05-18 02:09 - 2013-05-18 02:09 - 00033250 ____A C:\Users\Scott\Downloads\[isoHunt] download.torrent
    2013-05-18 01:28 - 2013-01-10 17:49 - 00000292 ____A C:\Windows\Tasks\AutoKMS.job
    2013-05-18 01:06 - 2012-07-13 09:44 - 00576250 ____A C:\Windows\System32\perfh006.dat
    2013-05-18 01:06 - 2012-07-13 09:44 - 00484174 ____A C:\Windows\System32\perfh011.dat
    2013-05-18 01:06 - 2012-07-13 09:44 - 00149850 ____A C:\Windows\System32\perfc011.dat
    2013-05-18 01:06 - 2012-07-13 09:44 - 00126268 ____A C:\Windows\System32\perfc006.dat
    2013-05-18 01:06 - 2012-07-12 18:50 - 00017096 ____A C:\Windows\System32\prfh0404.dat
    2013-05-18 01:06 - 2012-07-12 18:50 - 00008676 ____A C:\Windows\System32\prfc0404.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00810228 ____A C:\Windows\System32\perfh013.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00807070 ____A C:\Windows\System32\perfh015.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00791456 ____A C:\Windows\System32\perfh019.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00735562 ____A C:\Windows\System32\perfh005.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00730624 ____A C:\Windows\System32\perfh01D.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00673726 ____A C:\Windows\System32\perfh008.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00561438 ____A C:\Windows\System32\perfh014.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00548356 ____A C:\Windows\System32\perfh00B.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00495786 ____A C:\Windows\System32\perfh012.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00183418 ____A C:\Windows\System32\perfc015.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00180712 ____A C:\Windows\System32\perfc013.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00178364 ____A C:\Windows\System32\perfc019.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00170168 ____A C:\Windows\System32\perfc01D.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00168964 ____A C:\Windows\System32\perfc005.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00148136 ____A C:\Windows\System32\perfc012.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00138758 ____A C:\Windows\System32\perfc008.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00129024 ____A C:\Windows\System32\perfc00B.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00123046 ____A C:\Windows\System32\perfc014.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00017096 ____A C:\Windows\System32\prfh0816.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00017096 ____A C:\Windows\System32\prfh0804.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00017096 ____A C:\Windows\System32\prfh0416.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00017096 ____A C:\Windows\System32\perfh01F.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00008676 ____A C:\Windows\System32\prfc0816.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00008676 ____A C:\Windows\System32\prfc0804.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00008676 ____A C:\Windows\System32\prfc0416.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00008676 ____A C:\Windows\System32\perfc01F.dat
    2013-05-18 01:06 - 2012-07-12 07:07 - 00750514 ____A C:\Windows\System32\perfh00E.dat
    2013-05-18 01:06 - 2012-07-12 07:07 - 00198804 ____A C:\Windows\System32\perfc00E.dat
    2013-05-18 01:06 - 2012-07-12 07:00 - 00812272 ____A C:\Windows\System32\perfh00A.dat
    2013-05-18 01:06 - 2012-07-12 07:00 - 00186102 ____A C:\Windows\System32\perfc00A.dat
    2013-05-18 01:06 - 2012-07-12 06:56 - 00459464 ____A C:\Windows\System32\perfh00D.dat
    2013-05-18 01:06 - 2012-07-12 06:56 - 00112532 ____A C:\Windows\System32\perfc00D.dat
    2013-05-18 01:06 - 2012-07-12 06:49 - 00806914 ____A C:\Windows\System32\perfh010.dat
    2013-05-18 01:06 - 2012-07-12 06:49 - 00174520 ____A C:\Windows\System32\perfc010.dat
    2013-05-18 01:06 - 2012-07-12 06:44 - 00812480 ____A C:\Windows\System32\perfh00C.dat
    2013-05-18 01:06 - 2012-07-12 06:44 - 00545984 ____A C:\Windows\System32\perfh001.dat
    2013-05-18 01:06 - 2012-07-12 06:44 - 00177170 ____A C:\Windows\System32\perfc00C.dat
    2013-05-18 01:06 - 2012-07-12 06:44 - 00122484 ____A C:\Windows\System32\perfc001.dat
    2013-05-18 01:06 - 2012-07-12 06:34 - 00763868 ____A C:\Windows\System32\perfh007.dat
    2013-05-18 01:06 - 2012-07-12 06:34 - 00176630 ____A C:\Windows\System32\perfc007.dat
    2013-05-18 01:06 - 2009-07-13 21:13 - 15580612 ____A C:\Windows\System32\PerfStringBackup.INI
    2013-05-17 23:38 - 2012-06-10 15:39 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2013-05-17 01:29 - 2013-05-17 01:29 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{504BE270-A577-4781-BEC4-B53AABDE77EC}
    2013-05-17 01:29 - 2013-05-17 01:29 - 00000000 ____D C:\Users\Scott\Local Settings\{504BE270-A577-4781-BEC4-B53AABDE77EC}
    2013-05-17 01:29 - 2013-05-17 01:29 - 00000000 ____D C:\Users\Scott\AppData\Local\{504BE270-A577-4781-BEC4-B53AABDE77EC}
    2013-05-17 01:29 - 2012-06-25 01:00 - 00000000 ____D C:\Users\Scott\Tracing
    2013-05-17 01:29 - 2012-06-10 15:47 - 00001929 ____A C:\Users\Scott\Desktop\MySyncFolder.lnk
    2013-05-17 01:29 - 2012-06-01 00:15 - 00000000 ___RD C:\Users\Scott\Dropbox
    2013-05-17 01:29 - 2012-06-01 00:12 - 00000000 ____D C:\Users\Scott\Application Data\Dropbox
    2013-05-17 01:29 - 2012-06-01 00:12 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Dropbox
    2013-05-17 01:29 - 2012-05-10 04:17 - 00000000 ____D C:\Users\Scott\Application Data\ASUS WebStorage
    2013-05-17 01:29 - 2012-05-10 04:17 - 00000000 ____D C:\Users\Scott\AppData\Roaming\ASUS WebStorage
    2013-05-17 01:28 - 2012-05-11 00:26 - 00000380 ____A C:\Users\Scott\Application Data\sp_data.sys
    2013-05-17 01:28 - 2012-05-11 00:26 - 00000380 ____A C:\Users\Scott\AppData\Roaming\sp_data.sys
    2013-05-17 00:41 - 2009-07-13 20:45 - 00014144 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2013-05-17 00:41 - 2009-07-13 20:45 - 00014144 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2013-05-17 00:31 - 2013-04-08 05:22 - 00000000 ____A C:\Windows\SysWOW64\chrome.log
    2013-05-17 00:30 - 2013-05-17 00:29 - 00657096 ____A C:\Windows\Minidump\051713-43742-01.dmp
    2013-05-17 00:29 - 2013-04-11 16:29 - 880670400 ____A C:\Windows\MEMORY.DMP
    2013-05-17 00:29 - 2012-07-22 14:32 - 00000000 ____D C:\Windows\Minidump
    2013-05-17 00:29 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2013-05-16 22:54 - 2013-05-16 22:54 - 00291760 ____A (StarApp) C:\Users\Scott\Downloads\Green Lantern The Animated Series HDTV Season 1 [Extremlym].exe
    2013-05-16 22:54 - 2013-05-16 22:54 - 00013704 ____A C:\Users\Scott\Downloads\[kat.ph]green.lantern.the.animated.series.hdtv.season.1.extremlym.torrent
    2013-05-16 18:06 - 2012-05-11 01:41 - 00000000 ____D C:\Users\Scott\Local Settings\CrashDumps
    2013-05-16 18:06 - 2012-05-11 01:41 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\CrashDumps
    2013-05-16 18:06 - 2012-05-11 01:41 - 00000000 ____D C:\Users\Scott\AppData\Local\CrashDumps
    2013-05-16 15:19 - 2012-05-11 03:18 - 00000000 ____D C:\Users\Scott\Local Settings\Deployment
    2013-05-16 15:19 - 2012-05-11 03:18 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\Deployment
    2013-05-16 15:19 - 2012-05-11 03:18 - 00000000 ____D C:\Users\Scott\AppData\Local\Deployment
    2013-05-16 03:27 - 2013-05-16 03:27 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{F456DFA5-C62E-4B89-AAD3-1194BF3F3FEE}
    2013-05-16 03:27 - 2013-05-16 03:27 - 00000000 ____D C:\Users\Scott\Local Settings\{F456DFA5-C62E-4B89-AAD3-1194BF3F3FEE}
    2013-05-16 03:27 - 2013-05-16 03:27 - 00000000 ____D C:\Users\Scott\AppData\Local\{F456DFA5-C62E-4B89-AAD3-1194BF3F3FEE}
    2013-05-16 00:47 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
    2013-05-15 16:27 - 2012-05-10 04:48 - 00000000 ____D C:\Users\Scott\Application Data\Adobe
    2013-05-15 16:27 - 2012-05-10 04:48 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Adobe
    2013-05-15 16:26 - 2012-05-11 02:26 - 00000000 ____D C:\ProgramData\Application Data\Adobe
    2013-05-15 16:26 - 2012-05-11 02:26 - 00000000 ____D C:\ProgramData\Adobe
    2013-05-15 16:25 - 2013-05-15 16:25 - 00002021 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
    2013-05-15 16:25 - 2013-05-15 16:25 - 00002021 ____A C:\ProgramData\Desktop\Adobe Reader XI.lnk
    2013-05-15 16:25 - 2012-05-11 02:27 - 00000000 ____D C:\Program Files (x86)\Adobe
    2013-05-15 16:12 - 2013-04-05 03:57 - 00230094 ____A C:\Windows\PFRO.log
    2013-05-15 16:09 - 2013-05-11 17:40 - 00001760 ____A C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
    2013-05-15 16:09 - 2013-05-11 17:40 - 00001760 ____A C:\ProgramData\Desktop\Adobe Acrobat X Pro.lnk
    2013-05-15 14:44 - 2013-05-15 14:44 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{FA8A81E6-7F11-4F48-9582-1622351CDA23}
    2013-05-15 14:44 - 2013-05-15 14:44 - 00000000 ____D C:\Users\Scott\Local Settings\{FA8A81E6-7F11-4F48-9582-1622351CDA23}
    2013-05-15 14:44 - 2013-05-15 14:44 - 00000000 ____D C:\Users\Scott\AppData\Local\{FA8A81E6-7F11-4F48-9582-1622351CDA23}
    2013-05-15 14:40 - 2009-07-13 20:45 - 05113184 ____A C:\Windows\System32\FNTCACHE.DAT
    2013-05-15 09:27 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\uk-UA
    2013-05-15 09:27 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\he-IL
    2013-05-15 09:27 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\bg-BG
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\th-TH
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\sr-Latn-CS
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\sl-SI
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\sk-SK
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\ro-RO
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\lv-LV
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\lt-LT
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\hr-HR
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\et-EE
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\ar-SA
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\zh-HK
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\uk-UA
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\tr-TR
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\th-TH
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\sr-Latn-CS
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\sl-SI
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\sk-SK
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\ro-RO
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\lv-LV
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\lt-LT
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\hr-HR
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\he-IL
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\et-EE
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\bg-BG
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\ar-SA
    2013-05-15 09:05 - 2012-05-18 05:38 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2013-05-15 09:05 - 2012-05-17 20:39 - 00000039 ____A C:\Windows\vbaddin.ini
    2013-05-15 09:05 - 2012-05-11 05:43 - 00000000 ____D C:\ProgramData\Microsoft Help
    2013-05-15 09:05 - 2012-05-11 05:43 - 00000000 ____D C:\ProgramData\Application Data\Microsoft Help
    2013-05-14 16:26 - 2012-06-16 05:37 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2013-05-14 16:26 - 2012-06-16 05:37 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2013-05-14 15:21 - 2013-05-14 15:21 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{A0FB89D4-2DCF-4F7E-967F-55CF70346736}
    2013-05-14 15:21 - 2013-05-14 15:21 - 00000000 ____D C:\Users\Scott\Local Settings\{A0FB89D4-2DCF-4F7E-967F-55CF70346736}
    2013-05-14 15:21 - 2013-05-14 15:21 - 00000000 ____D C:\Users\Scott\AppData\Local\{A0FB89D4-2DCF-4F7E-967F-55CF70346736}
    2013-05-12 15:25 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\My Documents\Adobe
    2013-05-12 15:25 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\Documents\Adobe
    2013-05-12 14:13 - 2013-05-12 14:13 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{CA4EA4BB-57DD-4056-8062-BEE08BC5CE10}
    2013-05-12 14:13 - 2013-05-12 14:13 - 00000000 ____D C:\Users\Scott\Local Settings\{CA4EA4BB-57DD-4056-8062-BEE08BC5CE10}
    2013-05-12 14:13 - 2013-05-12 14:13 - 00000000 ____D C:\Users\Scott\AppData\Local\{CA4EA4BB-57DD-4056-8062-BEE08BC5CE10}
    2013-05-12 00:15 - 2013-05-12 00:14 - 00645160 ____A C:\Windows\Minidump\051213-60918-01.dmp
    2013-05-11 23:04 - 2013-05-11 23:04 - 00021259 ____A C:\Users\Scott\Downloads\Photoshop CS6 Complete Tutorial [h33t].torrent
    2013-05-11 20:45 - 2011-09-25 18:55 - 00000000 __AHD C:\Users\Scott\Local Settings\Application Data\2S2948Gsr7XL
    2013-05-11 20:45 - 2011-09-25 18:55 - 00000000 __AHD C:\Users\Scott\Local Settings\2S2948Gsr7XL
    2013-05-11 20:45 - 2011-09-25 18:55 - 00000000 __AHD C:\Users\Scott\AppData\Local\2S2948Gsr7XL
    2013-05-11 20:44 - 2013-05-11 20:44 - 00000000 ____D C:\Users\Scott\My Documents\Fragments
    2013-05-11 20:44 - 2013-05-11 20:44 - 00000000 ____D C:\Users\Scott\Documents\Fragments
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\Local Settings\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\Application Data\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\AppData\Roaming\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\AppData\Local\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\ProgramData\Application Data\PACE Anti-Piracy
    2013-05-11 20:41 - 2011-09-08 10:10 - 00000000 ___HD C:\Users\Scott\Local Settings\yic4v9qmbLi
    2013-05-11 20:41 - 2011-09-08 10:10 - 00000000 ___HD C:\Users\Scott\Local Settings\Application Data\yic4v9qmbLi
    2013-05-11 20:41 - 2011-09-08 10:10 - 00000000 ___HD C:\Users\Scott\AppData\Local\yic4v9qmbLi
    2013-05-11 20:29 - 2012-10-21 19:47 - 00000000 ____D C:\Users\Public\Documents\Adobe
    2013-05-11 20:29 - 2012-10-21 19:47 - 00000000 ____D C:\ProgramData\Documents\Adobe
    2013-05-11 18:33 - 2013-05-11 18:32 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{0372A8BF-43BB-4589-9804-D7D59E6C17C5}
    2013-05-11 18:33 - 2013-05-11 18:32 - 00000000 ____D C:\Users\Scott\Local Settings\{0372A8BF-43BB-4589-9804-D7D59E6C17C5}
    2013-05-11 18:33 - 2013-05-11 18:32 - 00000000 ____D C:\Users\Scott\AppData\Local\{0372A8BF-43BB-4589-9804-D7D59E6C17C5}
    2013-05-11 18:27 - 2012-05-10 05:13 - 00000000 ____D C:\Program Files (x86)\uTorrent
    2013-05-11 18:02 - 2012-05-11 02:56 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
    2013-05-11 18:02 - 2012-05-11 02:56 - 00000000 ____D C:\ProgramData\Application Data\regid.1986-12.com.adobe
    2013-05-11 18:00 - 2012-05-30 04:04 - 00000000 ____D C:\Users\Scott\Application Data\NVIDIA
    2013-05-11 18:00 - 2012-05-30 04:04 - 00000000 ____D C:\Users\Scott\AppData\Roaming\NVIDIA
    2013-05-11 17:59 - 2012-05-10 04:13 - 00117680 ____A C:\Users\Scott\Local Settings\GDIPFONTCACHEV1.DAT
    2013-05-11 17:59 - 2012-05-10 04:13 - 00117680 ____A C:\Users\Scott\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2013-05-11 17:59 - 2012-05-10 04:13 - 00117680 ____A C:\Users\Scott\AppData\Local\GDIPFONTCACHEV1.DAT
    2013-05-11 17:58 - 2013-05-11 17:11 - 00001520 ____A C:\Users\Public\Desktop\Adobe Application Manager.lnk
    2013-05-11 17:58 - 2013-05-11 17:11 - 00001520 ____A C:\ProgramData\Desktop\Adobe Application Manager.lnk
    2013-05-11 17:38 - 2013-05-11 17:37 - 00009737 ____A C:\Users\Scott\Desktop\What I want from a job!!!.xlsx
    2013-05-11 17:35 - 2012-05-11 02:31 - 00000000 ____D C:\Program Files\Common Files\Adobe
    2013-05-11 17:30 - 2013-05-11 17:30 - 00000000 ____D C:\Program Files\Adobe
    2013-05-11 17:29 - 2013-05-11 17:29 - 00000000 ____D C:\ProgramData\Application Data\ALM
    2013-05-11 17:29 - 2013-05-11 17:29 - 00000000 ____D C:\ProgramData\ALM
    2013-05-11 17:25 - 2013-05-11 17:25 - 00000000 ____D C:\Users\Scott\Adobe Flash Builder 4.6
    2013-05-11 17:25 - 2012-05-10 04:13 - 00000000 ____D C:\users\Scott
    2013-05-11 17:20 - 2013-05-11 17:20 - 00000000 ____D C:\Program Files (x86)\My Company Name
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default\Application Data\Macromedia
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default User\Application Data\Macromedia
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
    2013-05-11 17:01 - 2013-05-11 17:01 - 00150109 ____A C:\Users\Scott\Downloads\Adobe Master Collection CS6 (x86_x64) + Serial +Crack [h33t].torrent
    2013-05-10 22:45 - 2013-05-10 22:45 - 00288671 ____A C:\Users\Scott\Downloads\F55CE73101159D1EBDDBDD99D33650BD925B4680.torrent
    2013-05-10 22:19 - 2012-05-10 05:14 - 00000000 ____D C:\Users\Scott\Local Settings\Conduit
    2013-05-10 22:19 - 2012-05-10 05:14 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\Conduit
    2013-05-10 22:19 - 2012-05-10 05:14 - 00000000 ____D C:\Users\Scott\AppData\Local\Conduit
    2013-05-10 15:36 - 2013-05-10 15:36 - 00060404 ____A C:\Users\Scott\Downloads\B85E1484E0CE574E140640AEC37263C00E4074D1.torrent
    2013-05-10 15:36 - 2013-05-10 15:36 - 00030013 ____A C:\Users\Scott\Downloads\DCB5315CEBF9F31D47F4E67BBE6CEC697D16AF5F.torrent
    2013-05-10 15:32 - 2013-05-10 15:32 - 00029877 ____A C:\Users\Scott\Downloads\Jordan+Belfort+-+Straight+Line+Persuasion+System.torrent
    2013-05-09 23:57 - 2013-05-09 23:57 - 00055872 ____A (Adobe Systems Inc) C:\Windows\System32\AdobePDF.dll
    2013-05-09 23:57 - 2013-05-09 23:57 - 00027208 ____A (Adobe Systems Inc.) C:\Windows\System32\AdobePDFUI.dll
    2013-05-06 02:01 - 2013-05-06 02:01 - 00014541 ____A C:\Users\Scott\Downloads\iframeupload
    2013-05-06 01:56 - 2013-05-06 01:51 - 00000000 ____D C:\Users\Scott\Desktop\Id Brenda Mitchell
    2013-05-05 03:53 - 2013-05-05 03:53 - 00000132 ____A C:\Users\Scott\Application Data\Adobe PNG Format CS5 Prefs
    2013-05-05 03:53 - 2013-05-05 03:53 - 00000132 ____A C:\Users\Scott\AppData\Roaming\Adobe PNG Format CS5 Prefs
    2013-05-04 17:14 - 2012-05-24 03:37 - 00016384 __ASH C:\Users\Scott\My Documents\Thumbs.db
    2013-05-04 17:14 - 2012-05-24 03:37 - 00016384 __ASH C:\Users\Scott\Documents\Thumbs.db
    2013-05-04 03:16 - 2013-05-04 03:16 - 00000750 ____A C:\Users\Public\Desktop\VLC media player.lnk
    2013-05-04 03:16 - 2013-05-04 03:16 - 00000750 ____A C:\ProgramData\Desktop\VLC media player.lnk
    2013-05-04 01:01 - 2013-05-04 00:03 - 592233072 ____A C:\Users\Scott\My Documents\Veda Yoga Teacher Training Sample Class 2_(720p).mp4
    2013-05-04 01:01 - 2013-05-04 00:03 - 592233072 ____A C:\Users\Scott\Documents\Veda Yoga Teacher Training Sample Class 2_(720p).mp4
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000896 ____A C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000896 ____A C:\ProgramData\Desktop\Revo Uninstaller Pro.lnk
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\Users\Scott\Local Settings\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\Users\Scott\AppData\Local\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\ProgramData\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\ProgramData\Application Data\VS Revo Group
    2013-04-29 15:03 - 2013-04-29 15:03 - 09916056 ____A (VS Revo Group ) C:\Users\Scott\Downloads\RevoUninProSetup.exe
    2013-04-28 04:21 - 2013-04-28 04:21 - 00020484 ____A C:\Users\Scott\Downloads\The Big Bang Theory - COMPLETE Season 6 720p HDTV [h33t].torrent
    2013-04-27 01:36 - 2013-04-27 01:35 - 20443632 ____A C:\Users\Scott\Downloads\dgnd3700v2-v1.1.00.08_1.00.08.img
    2013-04-27 01:15 - 2013-04-27 01:14 - 18734033 ____A C:\Users\Scott\Downloads\dgnd3700v2-v1.1.00.12_1.00.12NA (1).zip
    2013-04-27 01:14 - 2013-04-27 01:13 - 18734033 ____A C:\Users\Scott\Downloads\dgnd3700v2-v1.1.00.12_1.00.12NA.zip
    2013-04-27 00:56 - 2013-04-27 00:54 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{E28E94FD-F483-41A9-A6CE-2F1F8E31ED42}
    2013-04-27 00:56 - 2013-04-27 00:54 - 00000000 ____D C:\Users\Scott\Local Settings\{E28E94FD-F483-41A9-A6CE-2F1F8E31ED42}
    2013-04-27 00:56 - 2013-04-27 00:54 - 00000000 ____D C:\Users\Scott\AppData\Local\{E28E94FD-F483-41A9-A6CE-2F1F8E31ED42}
    2013-04-27 00:43 - 2013-04-27 00:43 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2 (6).cfg
    2013-04-27 00:42 - 2013-04-27 00:42 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (6).cfg
    2013-04-27 00:42 - 2013-04-27 00:41 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (5).cfg
    2013-04-27 00:40 - 2013-04-27 00:40 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (4).cfg
    2013-04-27 00:40 - 2013-04-27 00:40 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2 (4).cfg
    2013-04-27 00:39 - 2013-04-27 00:39 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2 (4).txt
    2013-04-27 00:37 - 2013-04-27 00:37 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (3).cfg
    2013-04-27 00:37 - 2013-04-27 00:35 - 00021937 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (2).cfg
    2013-04-27 00:33 - 2013-04-27 00:33 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (1).cfg
    2013-04-27 00:30 - 2013-04-27 00:30 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2.cfg
    2013-04-27 00:29 - 2013-04-27 00:29 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2.cfg
    2013-04-25 16:05 - 2013-04-25 16:05 - 00693632 ____A (Playtech) C:\Users\Scott\Downloads\SetupCasino_53b9ca_en.exe
    2013-04-24 16:03 - 2013-04-24 16:02 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{24DE84E9-14FD-4954-A42C-F8BAD8684788}
    2013-04-24 16:03 - 2013-04-24 16:02 - 00000000 ____D C:\Users\Scott\Local Settings\{24DE84E9-14FD-4954-A42C-F8BAD8684788}
    2013-04-24 16:03 - 2013-04-24 16:02 - 00000000 ____D C:\Users\Scott\AppData\Local\{24DE84E9-14FD-4954-A42C-F8BAD8684788}
    2013-04-24 00:34 - 2013-02-25 02:36 - 00000000 ____D C:\Program Files (x86)\Zoom Downloader
    2013-04-23 17:52 - 2013-04-23 17:52 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{4E08EE1D-BAD2-431E-9DE2-8833F3EE7305}
    2013-04-23 17:52 - 2013-04-23 17:52 - 00000000 ____D C:\Users\Scott\Local Settings\{4E08EE1D-BAD2-431E-9DE2-8833F3EE7305}
    2013-04-23 17:52 - 2013-04-23 17:52 - 00000000 ____D C:\Users\Scott\AppData\Local\{4E08EE1D-BAD2-431E-9DE2-8833F3EE7305}
    2013-04-22 01:02 - 2013-04-22 01:02 - 00000000 ____A C:\Users\Scott\Desktop\3124672.txt
    2013-04-20 23:26 - 2013-04-20 23:16 - 00030928 ____A C:\Users\Scott\Downloads\National.Geographic.Megafactories.IKEA.HDTV.XviD-YT.5461842.TPB.torrent
    2013-04-20 21:51 - 2013-04-20 21:48 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{A53544E2-E5A8-4A2C-BAD3-05C7420C959F}
    2013-04-20 21:51 - 2013-04-20 21:48 - 00000000 ____D C:\Users\Scott\Local Settings\{A53544E2-E5A8-4A2C-BAD3-05C7420C959F}
    2013-04-20 21:51 - 2013-04-20 21:48 - 00000000 ____D C:\Users\Scott\AppData\Local\{A53544E2-E5A8-4A2C-BAD3-05C7420C959F}
     
     
  12. scottcom4

    scottcom4 TS Rookie Topic Starter Posts: 17

    ZeroAccess:
    C:\Windows\Installer\{80aa28bd-953b-0d79-ac52-59b01480de54}
    C:\Windows\Installer\{80aa28bd-953b-0d79-ac52-59b01480de54}\@
    C:\Windows\Installer\{80aa28bd-953b-0d79-ac52-59b01480de54}\L
    C:\Windows\Installer\{80aa28bd-953b-0d79-ac52-59b01480de54}\U
    ==================== Known DLLs (Whitelisted) ================

    ==================== Bamital & volsnap Check =================
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
    ==================== EXE ASSOCIATION =====================
    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK
    ==================== Restore Points =========================

    ==================== Memory info ===========================
    Percentage of memory in use: 11%
    Total physical RAM: 8169.16 MB
    Available physical RAM: 7244.95 MB
    Total Pagefile: 8167.31 MB
    Available Pagefile: 7240.1 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.88 MB
    ==================== Drives ================================
    Drive c: (OS) (Fixed) (Total:279.45 GB) (Free:70.27 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)]
    Drive d: (ISOS) (Fixed) (Total:349.3 GB) (Free:298.61 GB) NTFS (Disk=1 Partition=1)
    Drive e: (APPLICATIONS) (Fixed) (Total:394.18 GB) (Free:371.25 GB) NTFS (Disk=0 Partition=3)
    Drive f: (WORK) (Fixed) (Total:349.33 GB) (Free:84.41 GB) NTFS (Disk=1 Partition=2)
    Drive g: (Repair disc Windows 7 64-bit) (CDROM) (Total:0.14 GB) (Free:0 GB) UDF
    Drive h: (GYM USB) (Removable) (Total:3.73 GB) (Free:3.68 GB) FAT32 (Disk=2 Partition=1)
    Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    ==================== MBR & Partition Table ==================
    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: AA9693FE)
    Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
    Partition 2: (Active) - (Size=279 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=394 GB) - (Type=OF Extended)
    ========================================================
    Disk: 1 (Size: 699 GB) (Disk ID: BBC58B91)
    Partition 1: (Not Active) - (Size=349 GB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=349 GB) - (Type=07 NTFS)
    ========================================================
    Disk: 2 (Size: 4 GB) (Disk ID: 00000000)
    Partition 1: (Not Active) - (Size=4 GB) - (Type=0B)

    Last Boot: 2013-05-13 06:41
    ==================== End Of Log ============================
     
  13. scottcom4

    scottcom4 TS Rookie Topic Starter Posts: 17

    Scan result of Farbar Recovery Scan Tool (search.txt) (x64) Version: 18-05-2013
    Ran by SYSTEM on 20-05-2013 15:21:14
    Running from H:\
    Windows 7 Ultimate (X64) OS Language: English(US)
    Internet Explorer Version 9
    Boot Mode: Recovery
    The current controlset is ControlSet002
    ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full search.txt log and an extra Addition.txt log.
    ==================== Registry (Whitelisted) ==================
    HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [12446824 2012-01-31] (Realtek Semiconductor)
    HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [617120 2011-03-13] (Atheros Commnucations)
    HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [379552 2011-03-13] (Atheros Commnucations)
    HKLM\...\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [4526 2010-11-29] ()
    HKLM\...\Run: [THXCfg64] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 [25600 2010-09-14] (Creative Technology Ltd.)
    HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2869008 2012-01-25] (Synaptics Incorporated)
    HKLM\...\Run: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe [100112 2012-01-25] (Synaptics Incorporated)
    HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [472992 2013-03-20] (Adobe Systems Incorporated)
    HKLM\...\Run: [BCSSync] "D:\Applications\MSOFFICE\Office14\BCSSync.exe" /DelayServices [x]
    HKLM\...\Run: [PC Monitor Operations] "D:\Applications\PC Monitor\pcmontask.exe" [x]
    HKLM-x32\...\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE" [2018032 2011-04-01] (ASUSTek Computer Inc.)
    HKLM-x32\...\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe /S [731472 2011-02-23] (ecareme)
    HKLM-x32\...\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe [3058304 2011-10-19] (ASUS)
    HKLM-x32\...\Run: [THX TruStudio NB Settings] "C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" /r [909312 2011-03-16] (Creative Technology Ltd)
    HKLM-x32\...\Run: [CPMonitor] "C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe" [84464 2011-04-01] ()
    HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-19] (CyberLink Corp.)
    HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-11-02] (CyberLink)
    HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-19] (CyberLink Corp.)
    HKLM-x32\...\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [318080 2011-12-22] (ASUSTek Computer Inc.)
    HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-23] (ASUS)
    HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-18] (ASUS)
    HKLM-x32\...\Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [102568 2012-02-06] (ASUS)
    HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2321072 2012-02-01] (ASUSTeK Computer Inc.)
    HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-18] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin [1523360 2011-01-11] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [PWRISOVM.EXE] D:\Applications\PowerISO\PWRISOVM.EXE -startup [x]
    HKLM-x32\...\Run: [LWS] D:\Applications\Logitech\LWS\Webcam Software\LWS.exe -hide [x]
    HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [103536 2011-08-21] (VMware, Inc.)
    HKLM-x32\...\Run: [USBChargerPlusTray] C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [1120936 2012-01-29] (ASUSTek Computer Inc.)
    HKLM-x32\...\Run: [AVG_UI] "D:\Applications\AVG\AVG2013\avgui.exe" /TRAYONLY [x]
    HKLM-x32\...\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin [1073312 2012-03-08] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [] [x]
    HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "D:\Applications\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [x]
    HKLM-x32\...\Run: [Acrobat Assistant 8.0] "D:\Applications\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [x]
    HKU\Scott\...\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe [370480 2010-07-19] (syncables, LLC)
    HKU\Scott\...\Run: [WebcamMaxAutoRun] "d:\applications\WebcamMax\WebcamMax.exe" -a [x]
    HKU\Scott\...\Run: [Nike+ Connect] "C:\Users\Scott\AppData\Local\Nike\Nike+ Connect\Nike+ Connect daemon.exe" [70656 2012-06-19] (Nike)
    HKU\Scott\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
    HKU\Scott\...\Run: [DownloadManager] "C:\Program Files (x86)\Zoom Downloader\DownloadManager.exe" /as [1649152 2013-02-25] (Zoom Downloader)
    HKU\Scott\...\Run: [RoboForm] "D:\Applications\RoboForm\RoboTaskBarIcon.exe" [x]
    HKU\Scott\...\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" [1098072 2013-03-26] (Garmin Ltd or its subsidiaries)
    HKU\Scott\...\Run: [MsgCenterExe] "C:\Program Files (x86)\Real\RealPlayer\update\RealOneMessageCenter.exe" -osboot [82632 2013-02-15] (RealNetworks, Inc.)
    HKU\Scott\...\Run: [AdobeBridge] [x]
    Startup: C:\ProgramData\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
    ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
    Startup: C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
    ShortcutTarget: Dropbox.lnk -> (No File)
    Startup: C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.0.lnk
    ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.0.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (IntelĀ® Corporation)
    Startup: C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> D:\Applications\MSOFFICE\Office14\ONENOTEM.EXE (No File)
    BootExecute: autocheck autochk * sdnclean64.exe
    ==================== Services (Whitelisted) =================
    S2 AsusUacSvc; C:\Program Files\Asus\Rotation Desktop for G Series\AsusUacSvc.exe [113840 2010-07-27] ()
    S2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-03-13] (Atheros)
    S2 ATKGFNEXSrv; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896 2011-11-20] (ASUS)
    S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [185688 2013-03-26] (Garmin Ltd or its subsidiaries)
    S2 HyperDeskCustomThemeEnabler; C:\Windows\Installer\MSI7F56.tmp [102400 2012-07-13] ()
    S2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-13] (Microsoft Corporation)
    S2 MSSQL$SQLEXPRESS; C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
    S2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] ()
    S2 TVersityMediaServer; C:\ProgramData\TVersity\Media Server\MediaServer.exe [5279528 2012-08-10] ()
    S2 VMwareHostd; C:\ProgramData\VMware\hostd\config.xml [31995 2012-05-31] ()
    S2 WajamUpdater; C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe [109064 2013-01-09] (Wajam)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] ()
    S3 WiselinkPro; C:\Program Files (x86)\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [3007488 2010-02-16] ()
    S2 avgfws; D:\Applications\AVG\AVG2013\avgfws.exe [x]
    S2 AVGIDSAgent; D:\Applications\AVG\AVG2013\avgidsagent.exe [x]
    S2 avgwd; D:\Applications\AVG\AVG2013\avgwdsvc.exe [x]
    S3 Microsoft SharePoint Workspace Audit Service; D:\Applications\MSOFFICE\Office14\GROOVE.EXE /auditservice [x]
    S2 PC Monitor; "D:\Applications\PC Monitor\PCMonitorSrv.exe" [x]
    S3 rpcapd; "%ProgramFiles(x86)%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles(x86)%\WinPcap\rpcapd.ini" [x]
    S2 SAS Document Conversion; "d:\applications\SASHome\SASTextAnalyticsDocumentConversion\1.2\file-converter-service.exe" [x]
    S2 SAS PC Files Server; "d:\applications\SASHome\SASPCFilesServer\9.3\pcfservice.exe" -name "SAS PC Files Server" [x]
    S2 VisualWebRipper; "D:\applications\Visual Web Ripper\WebRipperService.exe" [x]
    ==================== Drivers (Whitelisted) ====================
    S3 AiCharger; C:\Windows\SysWow64\DRIVERS\AiCharger.sys [17152 2012-01-29] (ASUSTek Computer Inc.)
    S1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-06] (ASUS)
    S1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [50296 2012-09-03] (AVG Technologies CZ, s.r.o.)
    S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [154464 2012-10-21] (AVG Technologies CZ, s.r.o. )
    S0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [63328 2012-10-14] (AVG Technologies CZ, s.r.o. )
    S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [185696 2012-10-01] (AVG Technologies CZ, s.r.o.)
    S0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [225120 2012-09-20] (AVG Technologies CZ, s.r.o.)
    S0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [111968 2012-11-15] (AVG Technologies CZ, s.r.o.)
    S0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40800 2012-09-13] (AVG Technologies CZ, s.r.o.)
    S1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [200032 2012-09-20] (AVG Technologies CZ, s.r.o.)
    S3 FLxHCIh; C:\Windows\System32\DRIVERS\FLxHCIh.sys [76584 2012-07-18] (Fresco Logic)
    S3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
    S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [34304 2012-01-10] (ManyCam LLC)
    S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2012-02-22] (ManyCam LLC)
    S3 mcdevice; C:\Windows\System32\DRIVERS\mcdevice.sys [334400 2011-05-18] (ShiningMorning Inc.)
    S3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-13] (Microsoft Corporation)
    S3 SmbDrv; C:\Windows\System32\DRIVERS\Smb_driver.sys [22800 2012-01-25] (Synaptics Incorporated)
    S3 VCam_WDM; C:\Windows\System32\DRIVERS\VCam_WDM.sys [106424 2011-02-02] (e2eSoft)
    S2 WCMVCAM; C:\Windows\System32\DRIVERS\wcmvcam64.sys [1071032 2011-06-22] (Windows (R) Win 7 DDK provider)
    S1 ElbyCDIO; System32\Drivers\ElbyCDIO.sys [x]
    S2 NPF; system32\drivers\npf.sys [x]
    S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
    S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
    S3 VGPU; System32\drivers\rdvgkmd.sys [x]
    S3 WinRing0_1_2_0; \??\C:\Windows\TEMP\tmpF815.tmp [x]
    ==================== NetSvcs (Whitelisted) ===================
     
  14. Broni

    Broni Malware Annihilator Posts: 47,704   +268

    This is going to be my last post. Getting late here...

    Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    On Vista or Windows 7: Now please enter System Recovery Options.
    On Windows XP: Now please boot into the UBCD.
    Run FRST/FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

    See if you can boot normally.
     

    Attached Files:

  15. scottcom4

    scottcom4 TS Rookie Topic Starter Posts: 17

    ==================== One Month Created Files and Folders ========
    2013-05-20 15:08 - 2013-05-20 15:08 - 00000000 ____D C:\FRST
    2013-05-20 12:53 - 2013-05-20 12:53 - 00000000 __SHD C:\$$PendingFiles
    2013-05-20 09:58 - 2013-05-20 09:58 - 00000000 ____D C:\Windows\Microsoft Antimalware
    2013-05-19 21:14 - 2013-05-19 21:14 - 00000000 __SHD C:\found.003
    2013-05-18 19:20 - 2013-05-18 19:20 - 00000000 ____D C:\Program Files (x86)\x264 Video Codec
    2013-05-18 02:26 - 2013-05-18 02:26 - 00030900 ____A C:\Users\Scott\Downloads\The Internship 2013 (English) [DVDRip].x264.torrent
    2013-05-18 02:25 - 2013-05-18 02:25 - 00030852 ____A C:\Users\Scott\Downloads\Brave 2012 (English) DVDRip.AC3.torrent
    2013-05-18 02:24 - 2013-05-18 02:24 - 00030840 ____A C:\Users\Scott\Downloads\Snitch 2013 Eng BDRip (480p).torrent
    2013-05-18 02:09 - 2013-05-18 02:09 - 00033250 ____A C:\Users\Scott\Downloads\[isoHunt] download.torrent
    2013-05-17 01:29 - 2013-05-17 01:29 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{504BE270-A577-4781-BEC4-B53AABDE77EC}
    2013-05-17 01:29 - 2013-05-17 01:29 - 00000000 ____D C:\Users\Scott\Local Settings\{504BE270-A577-4781-BEC4-B53AABDE77EC}
    2013-05-17 01:29 - 2013-05-17 01:29 - 00000000 ____D C:\Users\Scott\AppData\Local\{504BE270-A577-4781-BEC4-B53AABDE77EC}
    2013-05-17 00:29 - 2013-05-17 00:30 - 00657096 ____A C:\Windows\Minidump\051713-43742-01.dmp
    2013-05-16 22:54 - 2013-05-16 22:54 - 00291760 ____A (StarApp) C:\Users\Scott\Downloads\Green Lantern The Animated Series HDTV Season 1 [Extremlym].exe
    2013-05-16 22:54 - 2013-05-16 22:54 - 00013704 ____A C:\Users\Scott\Downloads\[kat.ph]green.lantern.the.animated.series.hdtv.season.1.extremlym.torrent
    2013-05-16 03:27 - 2013-05-16 03:27 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{F456DFA5-C62E-4B89-AAD3-1194BF3F3FEE}
    2013-05-16 03:27 - 2013-05-16 03:27 - 00000000 ____D C:\Users\Scott\Local Settings\{F456DFA5-C62E-4B89-AAD3-1194BF3F3FEE}
    2013-05-16 03:27 - 2013-05-16 03:27 - 00000000 ____D C:\Users\Scott\AppData\Local\{F456DFA5-C62E-4B89-AAD3-1194BF3F3FEE}
    2013-05-15 16:25 - 2013-05-15 16:25 - 00002021 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
    2013-05-15 16:25 - 2013-05-15 16:25 - 00002021 ____A C:\ProgramData\Desktop\Adobe Reader XI.lnk
    2013-05-15 14:44 - 2013-05-15 14:44 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{FA8A81E6-7F11-4F48-9582-1622351CDA23}
    2013-05-15 14:44 - 2013-05-15 14:44 - 00000000 ____D C:\Users\Scott\Local Settings\{FA8A81E6-7F11-4F48-9582-1622351CDA23}
    2013-05-15 14:44 - 2013-05-15 14:44 - 00000000 ____D C:\Users\Scott\AppData\Local\{FA8A81E6-7F11-4F48-9582-1622351CDA23}
    2013-05-15 09:03 - 2013-04-04 22:52 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
    2013-05-15 09:03 - 2013-04-04 22:50 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2013-05-15 09:03 - 2013-04-04 22:50 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2013-05-15 09:03 - 2013-04-04 22:50 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2013-05-15 09:03 - 2013-04-04 22:50 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
    2013-05-15 09:03 - 2013-04-04 22:50 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
    2013-05-15 09:03 - 2013-04-04 22:50 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
    2013-05-15 09:03 - 2013-04-04 21:28 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2013-05-15 09:03 - 2013-04-04 21:26 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2013-05-15 09:03 - 2013-04-04 21:26 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2013-05-15 09:03 - 2013-04-04 21:26 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2013-05-15 09:03 - 2013-04-04 21:26 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
    2013-05-15 09:03 - 2013-04-04 21:26 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2013-05-15 09:03 - 2013-04-04 21:26 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2013-05-15 09:03 - 2013-04-04 20:43 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2013-05-15 09:03 - 2013-04-04 20:29 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2013-05-15 09:03 - 2013-04-04 19:51 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
    2013-05-15 09:03 - 2013-04-04 19:38 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
    2013-05-15 09:02 - 2013-04-04 22:52 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2013-05-15 09:02 - 2013-04-04 22:52 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2013-05-15 09:02 - 2013-04-04 22:50 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2013-05-15 09:02 - 2013-04-04 22:50 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2013-05-15 09:02 - 2013-04-04 22:50 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2013-05-15 09:02 - 2013-04-04 22:50 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2013-05-15 09:02 - 2013-04-04 22:50 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2013-05-15 09:02 - 2013-04-04 21:28 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2013-05-15 09:02 - 2013-04-04 21:26 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2013-05-15 09:02 - 2013-04-04 21:26 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2013-05-15 09:02 - 2013-04-04 21:26 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2013-05-15 09:02 - 2013-04-04 21:26 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2013-05-15 09:02 - 2013-04-04 21:26 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2013-05-14 15:21 - 2013-05-14 15:21 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{A0FB89D4-2DCF-4F7E-967F-55CF70346736}
    2013-05-14 15:21 - 2013-05-14 15:21 - 00000000 ____D C:\Users\Scott\Local Settings\{A0FB89D4-2DCF-4F7E-967F-55CF70346736}
    2013-05-14 15:21 - 2013-05-14 15:21 - 00000000 ____D C:\Users\Scott\AppData\Local\{A0FB89D4-2DCF-4F7E-967F-55CF70346736}
    2013-05-14 14:16 - 2013-04-09 22:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
    2013-05-14 14:16 - 2013-04-09 22:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
    2013-05-14 14:16 - 2011-02-03 03:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll
    2013-05-14 14:15 - 2013-04-09 19:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2013-05-14 14:15 - 2013-03-18 21:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
    2013-05-14 14:15 - 2013-03-18 21:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
    2013-05-14 14:15 - 2013-02-26 22:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
    2013-05-14 14:15 - 2013-02-26 21:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2013-05-14 14:15 - 2013-02-26 21:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
    2013-05-14 14:15 - 2013-02-26 21:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
    2013-05-14 14:15 - 2013-02-26 21:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
    2013-05-14 14:15 - 2013-02-26 20:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2013-05-14 14:15 - 2013-02-26 20:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
    2013-05-14 14:15 - 2013-02-26 20:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
    2013-05-12 14:13 - 2013-05-12 14:13 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{CA4EA4BB-57DD-4056-8062-BEE08BC5CE10}
    2013-05-12 14:13 - 2013-05-12 14:13 - 00000000 ____D C:\Users\Scott\Local Settings\{CA4EA4BB-57DD-4056-8062-BEE08BC5CE10}
    2013-05-12 14:13 - 2013-05-12 14:13 - 00000000 ____D C:\Users\Scott\AppData\Local\{CA4EA4BB-57DD-4056-8062-BEE08BC5CE10}
    2013-05-12 00:14 - 2013-05-12 00:15 - 00645160 ____A C:\Windows\Minidump\051213-60918-01.dmp
    2013-05-11 23:04 - 2013-05-11 23:04 - 00021259 ____A C:\Users\Scott\Downloads\Photoshop CS6 Complete Tutorial [h33t].torrent
    2013-05-11 20:44 - 2013-05-11 20:44 - 00000000 ____D C:\Users\Scott\My Documents\Fragments
    2013-05-11 20:44 - 2013-05-11 20:44 - 00000000 ____D C:\Users\Scott\Documents\Fragments
    2013-05-11 20:41 - 2013-05-12 15:25 - 00000000 ____D C:\Users\Scott\My Documents\Adobe
    2013-05-11 20:41 - 2013-05-12 15:25 - 00000000 ____D C:\Users\Scott\Documents\Adobe
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\Local Settings\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\Application Data\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\AppData\Roaming\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\AppData\Local\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\ProgramData\Application Data\PACE Anti-Piracy
    2013-05-11 18:32 - 2013-05-11 18:33 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{0372A8BF-43BB-4589-9804-D7D59E6C17C5}
    2013-05-11 18:32 - 2013-05-11 18:33 - 00000000 ____D C:\Users\Scott\Local Settings\{0372A8BF-43BB-4589-9804-D7D59E6C17C5}
    2013-05-11 18:32 - 2013-05-11 18:33 - 00000000 ____D C:\Users\Scott\AppData\Local\{0372A8BF-43BB-4589-9804-D7D59E6C17C5}
    2013-05-11 17:40 - 2013-05-15 16:09 - 00001760 ____A C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
    2013-05-11 17:40 - 2013-05-15 16:09 - 00001760 ____A C:\ProgramData\Desktop\Adobe Acrobat X Pro.lnk
    2013-05-11 17:37 - 2013-05-11 17:38 - 00009737 ____A C:\Users\Scott\Desktop\What I want from a job!!!.xlsx
    2013-05-11 17:30 - 2013-05-11 17:30 - 00000000 ____D C:\Program Files\Adobe
    2013-05-11 17:29 - 2013-05-11 17:29 - 00000000 ____D C:\ProgramData\Application Data\ALM
    2013-05-11 17:29 - 2013-05-11 17:29 - 00000000 ____D C:\ProgramData\ALM
    2013-05-11 17:25 - 2013-05-11 17:25 - 00000000 ____D C:\Users\Scott\Adobe Flash Builder 4.6
    2013-05-11 17:20 - 2013-05-11 17:20 - 00000000 ____D C:\Program Files (x86)\My Company Name
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default\Application Data\Macromedia
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default User\Application Data\Macromedia
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
    2013-05-11 17:11 - 2013-05-11 17:58 - 00001520 ____A C:\Users\Public\Desktop\Adobe Application Manager.lnk
    2013-05-11 17:11 - 2013-05-11 17:58 - 00001520 ____A C:\ProgramData\Desktop\Adobe Application Manager.lnk
    2013-05-11 17:01 - 2013-05-11 17:01 - 00150109 ____A C:\Users\Scott\Downloads\Adobe Master Collection CS6 (x86_x64) + Serial +Crack [h33t].torrent
    2013-05-10 22:45 - 2013-05-10 22:45 - 00288671 ____A C:\Users\Scott\Downloads\F55CE73101159D1EBDDBDD99D33650BD925B4680.torrent
    2013-05-10 15:36 - 2013-05-10 15:36 - 00060404 ____A C:\Users\Scott\Downloads\B85E1484E0CE574E140640AEC37263C00E4074D1.torrent
    2013-05-10 15:36 - 2013-05-10 15:36 - 00030013 ____A C:\Users\Scott\Downloads\DCB5315CEBF9F31D47F4E67BBE6CEC697D16AF5F.torrent
    2013-05-10 15:32 - 2013-05-10 15:32 - 00029877 ____A C:\Users\Scott\Downloads\Jordan+Belfort+-+Straight+Line+Persuasion+System.torrent
    2013-05-09 23:57 - 2013-05-09 23:57 - 00055872 ____A (Adobe Systems Inc) C:\Windows\System32\AdobePDF.dll
    2013-05-09 23:57 - 2013-05-09 23:57 - 00027208 ____A (Adobe Systems Inc.) C:\Windows\System32\AdobePDFUI.dll
    2013-05-06 02:01 - 2013-05-06 02:01 - 00014541 ____A C:\Users\Scott\Downloads\iframeupload
    2013-05-06 01:51 - 2013-05-06 01:56 - 00000000 ____D C:\Users\Scott\Desktop\Id Brenda Mitchell
    2013-05-05 03:53 - 2013-05-05 03:53 - 00000132 ____A C:\Users\Scott\Application Data\Adobe PNG Format CS5 Prefs
    2013-05-05 03:53 - 2013-05-05 03:53 - 00000132 ____A C:\Users\Scott\AppData\Roaming\Adobe PNG Format CS5 Prefs
    2013-05-04 03:16 - 2013-05-04 03:16 - 00000750 ____A C:\Users\Public\Desktop\VLC media player.lnk
    2013-05-04 03:16 - 2013-05-04 03:16 - 00000750 ____A C:\ProgramData\Desktop\VLC media player.lnk
    2013-05-04 00:03 - 2013-05-04 01:01 - 592233072 ____A C:\Users\Scott\My Documents\Veda Yoga Teacher Training Sample Class 2_(720p).mp4
    2013-05-04 00:03 - 2013-05-04 01:01 - 592233072 ____A C:\Users\Scott\Documents\Veda Yoga Teacher Training Sample Class 2_(720p).mp4
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000896 ____A C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000896 ____A C:\ProgramData\Desktop\Revo Uninstaller Pro.lnk
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\Users\Scott\Local Settings\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\Users\Scott\AppData\Local\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\ProgramData\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\ProgramData\Application Data\VS Revo Group
    2013-04-29 15:05 - 2009-12-29 17:21 - 00031800 ____A (VS Revo Group) C:\Windows\System32\Drivers\revoflt.sys
    2013-04-29 15:03 - 2013-04-29 15:03 - 09916056 ____A (VS Revo Group ) C:\Users\Scott\Downloads\RevoUninProSetup.exe
    2013-04-28 04:21 - 2013-04-28 04:21 - 00020484 ____A C:\Users\Scott\Downloads\The Big Bang Theory - COMPLETE Season 6 720p HDTV [h33t].torrent
    2013-04-27 01:35 - 2013-04-27 01:36 - 20443632 ____A C:\Users\Scott\Downloads\dgnd3700v2-v1.1.00.08_1.00.08.img
    2013-04-27 01:17 - 2012-07-01 16:42 - 32505856 ____A C:\Users\Scott\Downloads\DGND3700v2.bin
    2013-04-27 01:15 - 2012-07-12 08:36 - 18744576 ____A C:\Users\Scott\Downloads\dgnd3700v2-v1.1.00.12_1.00.12na.img
    2013-04-27 01:14 - 2013-04-27 01:15 - 18734033 ____A C:\Users\Scott\Downloads\dgnd3700v2-v1.1.00.12_1.00.12NA (1).zip
    2013-04-27 01:13 - 2013-04-27 01:14 - 18734033 ____A C:\Users\Scott\Downloads\dgnd3700v2-v1.1.00.12_1.00.12NA.zip
    2013-04-27 00:54 - 2013-04-27 00:56 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{E28E94FD-F483-41A9-A6CE-2F1F8E31ED42}
    2013-04-27 00:54 - 2013-04-27 00:56 - 00000000 ____D C:\Users\Scott\Local Settings\{E28E94FD-F483-41A9-A6CE-2F1F8E31ED42}
    2013-04-27 00:54 - 2013-04-27 00:56 - 00000000 ____D C:\Users\Scott\AppData\Local\{E28E94FD-F483-41A9-A6CE-2F1F8E31ED42}
    2013-04-27 00:43 - 2013-04-27 00:43 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2 (6).cfg
    2013-04-27 00:42 - 2013-04-27 00:42 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (6).cfg
    2013-04-27 00:41 - 2013-04-27 00:42 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (5).cfg
    2013-04-27 00:40 - 2013-04-27 00:40 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (4).cfg
    2013-04-27 00:40 - 2013-04-27 00:40 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2 (4).cfg
    2013-04-27 00:39 - 2013-04-27 00:39 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2 (4).txt
    2013-04-27 00:37 - 2013-04-27 00:37 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (3).cfg
    2013-04-27 00:35 - 2013-04-27 00:37 - 00021937 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (2).cfg
    2013-04-27 00:33 - 2013-04-27 00:33 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (1).cfg
    2013-04-27 00:30 - 2013-04-27 00:30 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2.cfg
    2013-04-27 00:29 - 2013-04-27 00:29 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2.cfg
    2013-04-25 16:05 - 2013-04-25 16:05 - 00693632 ____A (Playtech) C:\Users\Scott\Downloads\SetupCasino_53b9ca_en.exe
    2013-04-24 16:02 - 2013-04-24 16:03 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{24DE84E9-14FD-4954-A42C-F8BAD8684788}
    2013-04-24 16:02 - 2013-04-24 16:03 - 00000000 ____D C:\Users\Scott\Local Settings\{24DE84E9-14FD-4954-A42C-F8BAD8684788}
    2013-04-24 16:02 - 2013-04-24 16:03 - 00000000 ____D C:\Users\Scott\AppData\Local\{24DE84E9-14FD-4954-A42C-F8BAD8684788}
    2013-04-23 18:24 - 2013-04-12 06:45 - 01656680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
    2013-04-23 17:52 - 2013-04-23 17:52 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{4E08EE1D-BAD2-431E-9DE2-8833F3EE7305}
    2013-04-23 17:52 - 2013-04-23 17:52 - 00000000 ____D C:\Users\Scott\Local Settings\{4E08EE1D-BAD2-431E-9DE2-8833F3EE7305}
    2013-04-23 17:52 - 2013-04-23 17:52 - 00000000 ____D C:\Users\Scott\AppData\Local\{4E08EE1D-BAD2-431E-9DE2-8833F3EE7305}
    2013-04-22 01:02 - 2013-04-22 01:02 - 00000000 ____A C:\Users\Scott\Desktop\3124672.txt
    2013-04-20 23:16 - 2013-04-20 23:26 - 00030928 ____A C:\Users\Scott\Downloads\National.Geographic.Megafactories.IKEA.HDTV.XviD-YT.5461842.TPB.torrent
    2013-04-20 21:48 - 2013-04-20 21:51 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{A53544E2-E5A8-4A2C-BAD3-05C7420C959F}
    2013-04-20 21:48 - 2013-04-20 21:51 - 00000000 ____D C:\Users\Scott\Local Settings\{A53544E2-E5A8-4A2C-BAD3-05C7420C959F}
    2013-04-20 21:48 - 2013-04-20 21:51 - 00000000 ____D C:\Users\Scott\AppData\Local\{A53544E2-E5A8-4A2C-BAD3-05C7420C959F}
     
  16. scottcom4

    scottcom4 TS Rookie Topic Starter Posts: 17

    ==================== One Month Modified Files and Folders =======
    2013-05-20 15:08 - 2013-05-20 15:08 - 00000000 ____D C:\FRST
    2013-05-20 12:53 - 2013-05-20 12:53 - 00000000 __SHD C:\$$PendingFiles
    2013-05-20 10:14 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
    2013-05-20 09:58 - 2013-05-20 09:58 - 00000000 ____D C:\Windows\Microsoft Antimalware
    2013-05-19 21:14 - 2013-05-19 21:14 - 00000000 __SHD C:\found.003
    2013-05-19 19:11 - 2012-05-31 01:50 - 00000000 ____D C:\ProgramData\VMware
    2013-05-19 19:11 - 2012-05-31 01:50 - 00000000 ____D C:\ProgramData\Application Data\VMware
    2013-05-19 19:11 - 2012-05-30 19:52 - 00000000 ____A C:\pcfservice.log
    2013-05-19 19:11 - 2012-05-25 23:29 - 00000000 ____D C:\ProgramData\NVIDIA
    2013-05-19 19:11 - 2012-05-25 23:29 - 00000000 ____D C:\ProgramData\Application Data\NVIDIA
    2013-05-18 21:19 - 2012-07-14 17:02 - 00000000 ____D C:\Users\Scott\Application Data\vlc
    2013-05-18 21:19 - 2012-07-14 17:02 - 00000000 ____D C:\Users\Scott\AppData\Roaming\vlc
    2013-05-18 21:17 - 2012-05-10 05:13 - 00000000 ____D C:\Users\Scott\Application Data\uTorrent
    2013-05-18 21:17 - 2012-05-10 05:13 - 00000000 ____D C:\Users\Scott\AppData\Roaming\uTorrent
    2013-05-18 20:38 - 2012-06-10 15:39 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2013-05-18 20:25 - 2012-10-08 18:14 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2013-05-18 19:20 - 2013-05-18 19:20 - 00000000 ____D C:\Program Files (x86)\x264 Video Codec
    2013-05-18 19:20 - 2011-10-19 22:40 - 01763092 ____A C:\Windows\WindowsUpdate.log
    2013-05-18 19:18 - 2012-07-14 18:23 - 00000000 ____D C:\ProgramData\MFAData
    2013-05-18 19:18 - 2012-07-14 18:23 - 00000000 ____D C:\ProgramData\Application Data\MFAData
    2013-05-18 17:51 - 2012-08-10 00:29 - 00000000 ____A C:\END
    2013-05-18 17:50 - 2013-04-10 09:03 - 00000356 ____A C:\Windows\Tasks\AmiUpdXp.job
    2013-05-18 08:00 - 2012-05-11 01:38 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\Adobe
    2013-05-18 08:00 - 2012-05-11 01:38 - 00000000 ____D C:\Users\Scott\Local Settings\Adobe
    2013-05-18 08:00 - 2012-05-11 01:38 - 00000000 ____D C:\Users\Scott\AppData\Local\Adobe
    2013-05-18 02:48 - 2013-02-19 04:24 - 00010686 ____A C:\Windows\setupact.log
    2013-05-18 02:26 - 2013-05-18 02:26 - 00030900 ____A C:\Users\Scott\Downloads\The Internship 2013 (English) [DVDRip].x264.torrent
    2013-05-18 02:25 - 2013-05-18 02:25 - 00030852 ____A C:\Users\Scott\Downloads\Brave 2012 (English) DVDRip.AC3.torrent
    2013-05-18 02:24 - 2013-05-18 02:24 - 00030840 ____A C:\Users\Scott\Downloads\Snitch 2013 Eng BDRip (480p).torrent
    2013-05-18 02:09 - 2013-05-18 02:09 - 00033250 ____A C:\Users\Scott\Downloads\[isoHunt] download.torrent
    2013-05-18 01:28 - 2013-01-10 17:49 - 00000292 ____A C:\Windows\Tasks\AutoKMS.job
    2013-05-18 01:06 - 2012-07-13 09:44 - 00576250 ____A C:\Windows\System32\perfh006.dat
    2013-05-18 01:06 - 2012-07-13 09:44 - 00484174 ____A C:\Windows\System32\perfh011.dat
    2013-05-18 01:06 - 2012-07-13 09:44 - 00149850 ____A C:\Windows\System32\perfc011.dat
    2013-05-18 01:06 - 2012-07-13 09:44 - 00126268 ____A C:\Windows\System32\perfc006.dat
    2013-05-18 01:06 - 2012-07-12 18:50 - 00017096 ____A C:\Windows\System32\prfh0404.dat
    2013-05-18 01:06 - 2012-07-12 18:50 - 00008676 ____A C:\Windows\System32\prfc0404.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00810228 ____A C:\Windows\System32\perfh013.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00807070 ____A C:\Windows\System32\perfh015.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00791456 ____A C:\Windows\System32\perfh019.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00735562 ____A C:\Windows\System32\perfh005.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00730624 ____A C:\Windows\System32\perfh01D.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00673726 ____A C:\Windows\System32\perfh008.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00561438 ____A C:\Windows\System32\perfh014.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00548356 ____A C:\Windows\System32\perfh00B.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00495786 ____A C:\Windows\System32\perfh012.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00183418 ____A C:\Windows\System32\perfc015.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00180712 ____A C:\Windows\System32\perfc013.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00178364 ____A C:\Windows\System32\perfc019.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00170168 ____A C:\Windows\System32\perfc01D.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00168964 ____A C:\Windows\System32\perfc005.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00148136 ____A C:\Windows\System32\perfc012.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00138758 ____A C:\Windows\System32\perfc008.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00129024 ____A C:\Windows\System32\perfc00B.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00123046 ____A C:\Windows\System32\perfc014.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00017096 ____A C:\Windows\System32\prfh0816.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00017096 ____A C:\Windows\System32\prfh0804.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00017096 ____A C:\Windows\System32\prfh0416.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00017096 ____A C:\Windows\System32\perfh01F.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00008676 ____A C:\Windows\System32\prfc0816.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00008676 ____A C:\Windows\System32\prfc0804.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00008676 ____A C:\Windows\System32\prfc0416.dat
    2013-05-18 01:06 - 2012-07-12 17:53 - 00008676 ____A C:\Windows\System32\perfc01F.dat
    2013-05-18 01:06 - 2012-07-12 07:07 - 00750514 ____A C:\Windows\System32\perfh00E.dat
    2013-05-18 01:06 - 2012-07-12 07:07 - 00198804 ____A C:\Windows\System32\perfc00E.dat
    2013-05-18 01:06 - 2012-07-12 07:00 - 00812272 ____A C:\Windows\System32\perfh00A.dat
    2013-05-18 01:06 - 2012-07-12 07:00 - 00186102 ____A C:\Windows\System32\perfc00A.dat
    2013-05-18 01:06 - 2012-07-12 06:56 - 00459464 ____A C:\Windows\System32\perfh00D.dat
    2013-05-18 01:06 - 2012-07-12 06:56 - 00112532 ____A C:\Windows\System32\perfc00D.dat
    2013-05-18 01:06 - 2012-07-12 06:49 - 00806914 ____A C:\Windows\System32\perfh010.dat
    2013-05-18 01:06 - 2012-07-12 06:49 - 00174520 ____A C:\Windows\System32\perfc010.dat
    2013-05-18 01:06 - 2012-07-12 06:44 - 00812480 ____A C:\Windows\System32\perfh00C.dat
    2013-05-18 01:06 - 2012-07-12 06:44 - 00545984 ____A C:\Windows\System32\perfh001.dat
    2013-05-18 01:06 - 2012-07-12 06:44 - 00177170 ____A C:\Windows\System32\perfc00C.dat
    2013-05-18 01:06 - 2012-07-12 06:44 - 00122484 ____A C:\Windows\System32\perfc001.dat
    2013-05-18 01:06 - 2012-07-12 06:34 - 00763868 ____A C:\Windows\System32\perfh007.dat
    2013-05-18 01:06 - 2012-07-12 06:34 - 00176630 ____A C:\Windows\System32\perfc007.dat
    2013-05-18 01:06 - 2009-07-13 21:13 - 15580612 ____A C:\Windows\System32\PerfStringBackup.INI
    2013-05-17 23:38 - 2012-06-10 15:39 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2013-05-17 01:29 - 2013-05-17 01:29 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{504BE270-A577-4781-BEC4-B53AABDE77EC}
    2013-05-17 01:29 - 2013-05-17 01:29 - 00000000 ____D C:\Users\Scott\Local Settings\{504BE270-A577-4781-BEC4-B53AABDE77EC}
    2013-05-17 01:29 - 2013-05-17 01:29 - 00000000 ____D C:\Users\Scott\AppData\Local\{504BE270-A577-4781-BEC4-B53AABDE77EC}
    2013-05-17 01:29 - 2012-06-25 01:00 - 00000000 ____D C:\Users\Scott\Tracing
    2013-05-17 01:29 - 2012-06-10 15:47 - 00001929 ____A C:\Users\Scott\Desktop\MySyncFolder.lnk
    2013-05-17 01:29 - 2012-06-01 00:15 - 00000000 ___RD C:\Users\Scott\Dropbox
    2013-05-17 01:29 - 2012-06-01 00:12 - 00000000 ____D C:\Users\Scott\Application Data\Dropbox
    2013-05-17 01:29 - 2012-06-01 00:12 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Dropbox
    2013-05-17 01:29 - 2012-05-10 04:17 - 00000000 ____D C:\Users\Scott\Application Data\ASUS WebStorage
    2013-05-17 01:29 - 2012-05-10 04:17 - 00000000 ____D C:\Users\Scott\AppData\Roaming\ASUS WebStorage
    2013-05-17 01:28 - 2012-05-11 00:26 - 00000380 ____A C:\Users\Scott\Application Data\sp_data.sys
    2013-05-17 01:28 - 2012-05-11 00:26 - 00000380 ____A C:\Users\Scott\AppData\Roaming\sp_data.sys
    2013-05-17 00:41 - 2009-07-13 20:45 - 00014144 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2013-05-17 00:41 - 2009-07-13 20:45 - 00014144 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2013-05-17 00:31 - 2013-04-08 05:22 - 00000000 ____A C:\Windows\SysWOW64\chrome.log
    2013-05-17 00:30 - 2013-05-17 00:29 - 00657096 ____A C:\Windows\Minidump\051713-43742-01.dmp
    2013-05-17 00:29 - 2013-04-11 16:29 - 880670400 ____A C:\Windows\MEMORY.DMP
    2013-05-17 00:29 - 2012-07-22 14:32 - 00000000 ____D C:\Windows\Minidump
    2013-05-17 00:29 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2013-05-16 22:54 - 2013-05-16 22:54 - 00291760 ____A (StarApp) C:\Users\Scott\Downloads\Green Lantern The Animated Series HDTV Season 1 [Extremlym].exe
    2013-05-16 22:54 - 2013-05-16 22:54 - 00013704 ____A C:\Users\Scott\Downloads\[kat.ph]green.lantern.the.animated.series.hdtv.season.1.extremlym.torrent
    2013-05-16 18:06 - 2012-05-11 01:41 - 00000000 ____D C:\Users\Scott\Local Settings\CrashDumps
    2013-05-16 18:06 - 2012-05-11 01:41 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\CrashDumps
    2013-05-16 18:06 - 2012-05-11 01:41 - 00000000 ____D C:\Users\Scott\AppData\Local\CrashDumps
    2013-05-16 15:19 - 2012-05-11 03:18 - 00000000 ____D C:\Users\Scott\Local Settings\Deployment
    2013-05-16 15:19 - 2012-05-11 03:18 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\Deployment
    2013-05-16 15:19 - 2012-05-11 03:18 - 00000000 ____D C:\Users\Scott\AppData\Local\Deployment
    2013-05-16 03:27 - 2013-05-16 03:27 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{F456DFA5-C62E-4B89-AAD3-1194BF3F3FEE}
    2013-05-16 03:27 - 2013-05-16 03:27 - 00000000 ____D C:\Users\Scott\Local Settings\{F456DFA5-C62E-4B89-AAD3-1194BF3F3FEE}
    2013-05-16 03:27 - 2013-05-16 03:27 - 00000000 ____D C:\Users\Scott\AppData\Local\{F456DFA5-C62E-4B89-AAD3-1194BF3F3FEE}
    2013-05-16 00:47 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
    2013-05-15 16:27 - 2012-05-10 04:48 - 00000000 ____D C:\Users\Scott\Application Data\Adobe
    2013-05-15 16:27 - 2012-05-10 04:48 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Adobe
    2013-05-15 16:26 - 2012-05-11 02:26 - 00000000 ____D C:\ProgramData\Application Data\Adobe
    2013-05-15 16:26 - 2012-05-11 02:26 - 00000000 ____D C:\ProgramData\Adobe
    2013-05-15 16:25 - 2013-05-15 16:25 - 00002021 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
    2013-05-15 16:25 - 2013-05-15 16:25 - 00002021 ____A C:\ProgramData\Desktop\Adobe Reader XI.lnk
    2013-05-15 16:25 - 2012-05-11 02:27 - 00000000 ____D C:\Program Files (x86)\Adobe
    2013-05-15 16:12 - 2013-04-05 03:57 - 00230094 ____A C:\Windows\PFRO.log
    2013-05-15 16:09 - 2013-05-11 17:40 - 00001760 ____A C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
    2013-05-15 16:09 - 2013-05-11 17:40 - 00001760 ____A C:\ProgramData\Desktop\Adobe Acrobat X Pro.lnk
    2013-05-15 14:44 - 2013-05-15 14:44 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{FA8A81E6-7F11-4F48-9582-1622351CDA23}
    2013-05-15 14:44 - 2013-05-15 14:44 - 00000000 ____D C:\Users\Scott\Local Settings\{FA8A81E6-7F11-4F48-9582-1622351CDA23}
    2013-05-15 14:44 - 2013-05-15 14:44 - 00000000 ____D C:\Users\Scott\AppData\Local\{FA8A81E6-7F11-4F48-9582-1622351CDA23}
    2013-05-15 14:40 - 2009-07-13 20:45 - 05113184 ____A C:\Windows\System32\FNTCACHE.DAT
    2013-05-15 09:27 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\uk-UA
    2013-05-15 09:27 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\he-IL
    2013-05-15 09:27 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\bg-BG
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\th-TH
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\sr-Latn-CS
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\sl-SI
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\sk-SK
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\ro-RO
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\lv-LV
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\lt-LT
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\hr-HR
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\et-EE
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\ar-SA
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\zh-HK
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\uk-UA
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\tr-TR
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\th-TH
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\sr-Latn-CS
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\sl-SI
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\sk-SK
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\ro-RO
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\lv-LV
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\lt-LT
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\hr-HR
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\he-IL
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\et-EE
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\bg-BG
    2013-05-15 09:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\ar-SA
    2013-05-15 09:05 - 2012-05-18 05:38 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2013-05-15 09:05 - 2012-05-17 20:39 - 00000039 ____A C:\Windows\vbaddin.ini
    2013-05-15 09:05 - 2012-05-11 05:43 - 00000000 ____D C:\ProgramData\Microsoft Help
    2013-05-15 09:05 - 2012-05-11 05:43 - 00000000 ____D C:\ProgramData\Application Data\Microsoft Help
    2013-05-14 16:26 - 2012-06-16 05:37 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2013-05-14 16:26 - 2012-06-16 05:37 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2013-05-14 15:21 - 2013-05-14 15:21 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{A0FB89D4-2DCF-4F7E-967F-55CF70346736}
    2013-05-14 15:21 - 2013-05-14 15:21 - 00000000 ____D C:\Users\Scott\Local Settings\{A0FB89D4-2DCF-4F7E-967F-55CF70346736}
    2013-05-14 15:21 - 2013-05-14 15:21 - 00000000 ____D C:\Users\Scott\AppData\Local\{A0FB89D4-2DCF-4F7E-967F-55CF70346736}
    2013-05-12 15:25 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\My Documents\Adobe
    2013-05-12 15:25 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\Documents\Adobe
    2013-05-12 14:13 - 2013-05-12 14:13 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{CA4EA4BB-57DD-4056-8062-BEE08BC5CE10}
    2013-05-12 14:13 - 2013-05-12 14:13 - 00000000 ____D C:\Users\Scott\Local Settings\{CA4EA4BB-57DD-4056-8062-BEE08BC5CE10}
    2013-05-12 14:13 - 2013-05-12 14:13 - 00000000 ____D C:\Users\Scott\AppData\Local\{CA4EA4BB-57DD-4056-8062-BEE08BC5CE10}
    2013-05-12 00:15 - 2013-05-12 00:14 - 00645160 ____A C:\Windows\Minidump\051213-60918-01.dmp
    2013-05-11 23:04 - 2013-05-11 23:04 - 00021259 ____A C:\Users\Scott\Downloads\Photoshop CS6 Complete Tutorial [h33t].torrent
    2013-05-11 20:45 - 2011-09-25 18:55 - 00000000 __AHD C:\Users\Scott\Local Settings\Application Data\2S2948Gsr7XL
    2013-05-11 20:45 - 2011-09-25 18:55 - 00000000 __AHD C:\Users\Scott\Local Settings\2S2948Gsr7XL
    2013-05-11 20:45 - 2011-09-25 18:55 - 00000000 __AHD C:\Users\Scott\AppData\Local\2S2948Gsr7XL
    2013-05-11 20:44 - 2013-05-11 20:44 - 00000000 ____D C:\Users\Scott\My Documents\Fragments
    2013-05-11 20:44 - 2013-05-11 20:44 - 00000000 ____D C:\Users\Scott\Documents\Fragments
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\Local Settings\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\Application Data\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\AppData\Roaming\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\Users\Scott\AppData\Local\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy
    2013-05-11 20:41 - 2013-05-11 20:41 - 00000000 ____D C:\ProgramData\Application Data\PACE Anti-Piracy
    2013-05-11 20:41 - 2011-09-08 10:10 - 00000000 ___HD C:\Users\Scott\Local Settings\yic4v9qmbLi
    2013-05-11 20:41 - 2011-09-08 10:10 - 00000000 ___HD C:\Users\Scott\Local Settings\Application Data\yic4v9qmbLi
    2013-05-11 20:41 - 2011-09-08 10:10 - 00000000 ___HD C:\Users\Scott\AppData\Local\yic4v9qmbLi
    2013-05-11 20:29 - 2012-10-21 19:47 - 00000000 ____D C:\Users\Public\Documents\Adobe
    2013-05-11 20:29 - 2012-10-21 19:47 - 00000000 ____D C:\ProgramData\Documents\Adobe
    2013-05-11 18:33 - 2013-05-11 18:32 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{0372A8BF-43BB-4589-9804-D7D59E6C17C5}
    2013-05-11 18:33 - 2013-05-11 18:32 - 00000000 ____D C:\Users\Scott\Local Settings\{0372A8BF-43BB-4589-9804-D7D59E6C17C5}
    2013-05-11 18:33 - 2013-05-11 18:32 - 00000000 ____D C:\Users\Scott\AppData\Local\{0372A8BF-43BB-4589-9804-D7D59E6C17C5}
    2013-05-11 18:27 - 2012-05-10 05:13 - 00000000 ____D C:\Program Files (x86)\uTorrent
    2013-05-11 18:02 - 2012-05-11 02:56 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
    2013-05-11 18:02 - 2012-05-11 02:56 - 00000000 ____D C:\ProgramData\Application Data\regid.1986-12.com.adobe
    2013-05-11 18:00 - 2012-05-30 04:04 - 00000000 ____D C:\Users\Scott\Application Data\NVIDIA
    2013-05-11 18:00 - 2012-05-30 04:04 - 00000000 ____D C:\Users\Scott\AppData\Roaming\NVIDIA
    2013-05-11 17:59 - 2012-05-10 04:13 - 00117680 ____A C:\Users\Scott\Local Settings\GDIPFONTCACHEV1.DAT
    2013-05-11 17:59 - 2012-05-10 04:13 - 00117680 ____A C:\Users\Scott\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2013-05-11 17:59 - 2012-05-10 04:13 - 00117680 ____A C:\Users\Scott\AppData\Local\GDIPFONTCACHEV1.DAT
    2013-05-11 17:58 - 2013-05-11 17:11 - 00001520 ____A C:\Users\Public\Desktop\Adobe Application Manager.lnk
    2013-05-11 17:58 - 2013-05-11 17:11 - 00001520 ____A C:\ProgramData\Desktop\Adobe Application Manager.lnk
    2013-05-11 17:38 - 2013-05-11 17:37 - 00009737 ____A C:\Users\Scott\Desktop\What I want from a job!!!.xlsx
    2013-05-11 17:35 - 2012-05-11 02:31 - 00000000 ____D C:\Program Files\Common Files\Adobe
    2013-05-11 17:30 - 2013-05-11 17:30 - 00000000 ____D C:\Program Files\Adobe
    2013-05-11 17:29 - 2013-05-11 17:29 - 00000000 ____D C:\ProgramData\Application Data\ALM
    2013-05-11 17:29 - 2013-05-11 17:29 - 00000000 ____D C:\ProgramData\ALM
    2013-05-11 17:25 - 2013-05-11 17:25 - 00000000 ____D C:\Users\Scott\Adobe Flash Builder 4.6
    2013-05-11 17:25 - 2012-05-10 04:13 - 00000000 ____D C:\users\Scott
    2013-05-11 17:20 - 2013-05-11 17:20 - 00000000 ____D C:\Program Files (x86)\My Company Name
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default\Application Data\Macromedia
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default User\Application Data\Macromedia
    2013-05-11 17:16 - 2013-05-11 17:16 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
    2013-05-11 17:01 - 2013-05-11 17:01 - 00150109 ____A C:\Users\Scott\Downloads\Adobe Master Collection CS6 (x86_x64) + Serial +Crack [h33t].torrent
    2013-05-10 22:45 - 2013-05-10 22:45 - 00288671 ____A C:\Users\Scott\Downloads\F55CE73101159D1EBDDBDD99D33650BD925B4680.torrent
    2013-05-10 22:19 - 2012-05-10 05:14 - 00000000 ____D C:\Users\Scott\Local Settings\Conduit
    2013-05-10 22:19 - 2012-05-10 05:14 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\Conduit
    2013-05-10 22:19 - 2012-05-10 05:14 - 00000000 ____D C:\Users\Scott\AppData\Local\Conduit
    2013-05-10 15:36 - 2013-05-10 15:36 - 00060404 ____A C:\Users\Scott\Downloads\B85E1484E0CE574E140640AEC37263C00E4074D1.torrent
    2013-05-10 15:36 - 2013-05-10 15:36 - 00030013 ____A C:\Users\Scott\Downloads\DCB5315CEBF9F31D47F4E67BBE6CEC697D16AF5F.torrent
    2013-05-10 15:32 - 2013-05-10 15:32 - 00029877 ____A C:\Users\Scott\Downloads\Jordan+Belfort+-+Straight+Line+Persuasion+System.torrent
    2013-05-09 23:57 - 2013-05-09 23:57 - 00055872 ____A (Adobe Systems Inc) C:\Windows\System32\AdobePDF.dll
    2013-05-09 23:57 - 2013-05-09 23:57 - 00027208 ____A (Adobe Systems Inc.) C:\Windows\System32\AdobePDFUI.dll
    2013-05-06 02:01 - 2013-05-06 02:01 - 00014541 ____A C:\Users\Scott\Downloads\iframeupload
    2013-05-06 01:56 - 2013-05-06 01:51 - 00000000 ____D C:\Users\Scott\Desktop\Id Brenda Mitchell
    2013-05-05 03:53 - 2013-05-05 03:53 - 00000132 ____A C:\Users\Scott\Application Data\Adobe PNG Format CS5 Prefs
    2013-05-05 03:53 - 2013-05-05 03:53 - 00000132 ____A C:\Users\Scott\AppData\Roaming\Adobe PNG Format CS5 Prefs
    2013-05-04 17:14 - 2012-05-24 03:37 - 00016384 __ASH C:\Users\Scott\My Documents\Thumbs.db
    2013-05-04 17:14 - 2012-05-24 03:37 - 00016384 __ASH C:\Users\Scott\Documents\Thumbs.db
    2013-05-04 03:16 - 2013-05-04 03:16 - 00000750 ____A C:\Users\Public\Desktop\VLC media player.lnk
    2013-05-04 03:16 - 2013-05-04 03:16 - 00000750 ____A C:\ProgramData\Desktop\VLC media player.lnk
    2013-05-04 01:01 - 2013-05-04 00:03 - 592233072 ____A C:\Users\Scott\My Documents\Veda Yoga Teacher Training Sample Class 2_(720p).mp4
    2013-05-04 01:01 - 2013-05-04 00:03 - 592233072 ____A C:\Users\Scott\Documents\Veda Yoga Teacher Training Sample Class 2_(720p).mp4
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000896 ____A C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000896 ____A C:\ProgramData\Desktop\Revo Uninstaller Pro.lnk
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\Users\Scott\Local Settings\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\Users\Scott\AppData\Local\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\ProgramData\VS Revo Group
    2013-04-29 15:05 - 2013-04-29 15:05 - 00000000 ____D C:\ProgramData\Application Data\VS Revo Group
    2013-04-29 15:03 - 2013-04-29 15:03 - 09916056 ____A (VS Revo Group ) C:\Users\Scott\Downloads\RevoUninProSetup.exe
    2013-04-28 04:21 - 2013-04-28 04:21 - 00020484 ____A C:\Users\Scott\Downloads\The Big Bang Theory - COMPLETE Season 6 720p HDTV [h33t].torrent
    2013-04-27 01:36 - 2013-04-27 01:35 - 20443632 ____A C:\Users\Scott\Downloads\dgnd3700v2-v1.1.00.08_1.00.08.img
    2013-04-27 01:15 - 2013-04-27 01:14 - 18734033 ____A C:\Users\Scott\Downloads\dgnd3700v2-v1.1.00.12_1.00.12NA (1).zip
    2013-04-27 01:14 - 2013-04-27 01:13 - 18734033 ____A C:\Users\Scott\Downloads\dgnd3700v2-v1.1.00.12_1.00.12NA.zip
    2013-04-27 00:56 - 2013-04-27 00:54 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{E28E94FD-F483-41A9-A6CE-2F1F8E31ED42}
    2013-04-27 00:56 - 2013-04-27 00:54 - 00000000 ____D C:\Users\Scott\Local Settings\{E28E94FD-F483-41A9-A6CE-2F1F8E31ED42}
    2013-04-27 00:56 - 2013-04-27 00:54 - 00000000 ____D C:\Users\Scott\AppData\Local\{E28E94FD-F483-41A9-A6CE-2F1F8E31ED42}
    2013-04-27 00:43 - 2013-04-27 00:43 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2 (6).cfg
    2013-04-27 00:42 - 2013-04-27 00:42 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (6).cfg
    2013-04-27 00:42 - 2013-04-27 00:41 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (5).cfg
    2013-04-27 00:40 - 2013-04-27 00:40 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (4).cfg
    2013-04-27 00:40 - 2013-04-27 00:40 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2 (4).cfg
    2013-04-27 00:39 - 2013-04-27 00:39 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2 (4).txt
    2013-04-27 00:37 - 2013-04-27 00:37 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (3).cfg
    2013-04-27 00:37 - 2013-04-27 00:35 - 00021937 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (2).cfg
    2013-04-27 00:33 - 2013-04-27 00:33 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2 (1).cfg
    2013-04-27 00:30 - 2013-04-27 00:30 - 00021938 ____A C:\Users\Scott\Desktop\NETGEAR_DGND3700v2.cfg
    2013-04-27 00:29 - 2013-04-27 00:29 - 00021938 ____A C:\Users\Scott\Downloads\NETGEAR_DGND3700v2.cfg
    2013-04-25 16:05 - 2013-04-25 16:05 - 00693632 ____A (Playtech) C:\Users\Scott\Downloads\SetupCasino_53b9ca_en.exe
    2013-04-24 16:03 - 2013-04-24 16:02 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{24DE84E9-14FD-4954-A42C-F8BAD8684788}
    2013-04-24 16:03 - 2013-04-24 16:02 - 00000000 ____D C:\Users\Scott\Local Settings\{24DE84E9-14FD-4954-A42C-F8BAD8684788}
    2013-04-24 16:03 - 2013-04-24 16:02 - 00000000 ____D C:\Users\Scott\AppData\Local\{24DE84E9-14FD-4954-A42C-F8BAD8684788}
    2013-04-24 00:34 - 2013-02-25 02:36 - 00000000 ____D C:\Program Files (x86)\Zoom Downloader
    2013-04-23 17:52 - 2013-04-23 17:52 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{4E08EE1D-BAD2-431E-9DE2-8833F3EE7305}
    2013-04-23 17:52 - 2013-04-23 17:52 - 00000000 ____D C:\Users\Scott\Local Settings\{4E08EE1D-BAD2-431E-9DE2-8833F3EE7305}
    2013-04-23 17:52 - 2013-04-23 17:52 - 00000000 ____D C:\Users\Scott\AppData\Local\{4E08EE1D-BAD2-431E-9DE2-8833F3EE7305}
    2013-04-22 01:02 - 2013-04-22 01:02 - 00000000 ____A C:\Users\Scott\Desktop\3124672.txt
    2013-04-20 23:26 - 2013-04-20 23:16 - 00030928 ____A C:\Users\Scott\Downloads\National.Geographic.Megafactories.IKEA.HDTV.XviD-YT.5461842.TPB.torrent
    2013-04-20 21:51 - 2013-04-20 21:48 - 00000000 ____D C:\Users\Scott\Local Settings\Application Data\{A53544E2-E5A8-4A2C-BAD3-05C7420C959F}
    2013-04-20 21:51 - 2013-04-20 21:48 - 00000000 ____D C:\Users\Scott\Local Settings\{A53544E2-E5A8-4A2C-BAD3-05C7420C959F}
    2013-04-20 21:51 - 2013-04-20 21:48 - 00000000 ____D C:\Users\Scott\AppData\Local\{A53544E2-E5A8-4A2C-BAD3-05C7420C959F}
    ZeroAccess:
    C:\Windows\Installer\{80aa28bd-953b-0d79-ac52-59b01480de54}
    C:\Windows\Installer\{80aa28bd-953b-0d79-ac52-59b01480de54}\@
    C:\Windows\Installer\{80aa28bd-953b-0d79-ac52-59b01480de54}\L
    C:\Windows\Installer\{80aa28bd-953b-0d79-ac52-59b01480de54}\U
    ==================== Known DLLs (Whitelisted) ================

    ==================== Bamital & volsnap Check =================
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
    ==================== EXE ASSOCIATION =====================
    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK
    ==================== Restore Points =========================

    ==================== Memory info ===========================
    Percentage of memory in use: 11%
    Total physical RAM: 8169.16 MB
    Available physical RAM: 7247.13 MB
    Total Pagefile: 8167.31 MB
    Available Pagefile: 7253.59 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.88 MB
    ==================== Drives ================================
    Drive c: (OS) (Fixed) (Total:279.45 GB) (Free:70.27 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)]
    Drive d: (ISOS) (Fixed) (Total:349.3 GB) (Free:298.61 GB) NTFS (Disk=1 Partition=1)
    Drive e: (APPLICATIONS) (Fixed) (Total:394.18 GB) (Free:371.25 GB) NTFS (Disk=0 Partition=3)
    Drive f: (WORK) (Fixed) (Total:349.33 GB) (Free:84.41 GB) NTFS (Disk=1 Partition=2)
    Drive g: (Repair disc Windows 7 64-bit) (CDROM) (Total:0.14 GB) (Free:0 GB) UDF
    Drive h: (GYM USB) (Removable) (Total:3.73 GB) (Free:3.68 GB) FAT32 (Disk=2 Partition=1)
    Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    ==================== MBR & Partition Table ==================
    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: AA9693FE)
    Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
    Partition 2: (Active) - (Size=279 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=394 GB) - (Type=OF Extended)
    ========================================================
    Disk: 1 (Size: 699 GB) (Disk ID: BBC58B91)
    Partition 1: (Not Active) - (Size=349 GB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=349 GB) - (Type=07 NTFS)
    ========================================================
    Disk: 2 (Size: 4 GB) (Disk ID: 00000000)
    Partition 1: (Not Active) - (Size=4 GB) - (Type=0B)

    Last Boot: 2013-05-13 06:41
    ==================== End Of Log ============================
     
  17. Broni

    Broni Malware Annihilator Posts: 47,704   +268

    We posted at the same time.
    Please read my previous reply.
     
  18. scottcom4

    scottcom4 TS Rookie Topic Starter Posts: 17

    Unfortunately that didn't fix the problem.

    I really appreciate your help.

    Enjoy your sleep.

    Regards,
    Scott
     
  19. Broni

    Broni Malware Annihilator Posts: 47,704   +268

    I'm still here. Hold on...
     
  20. Broni

    Broni Malware Annihilator Posts: 47,704   +268

    Delete your existing fixlist.txt file.

    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST/FRST64 and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

    See if you can boot normally.

    Now I'm really off....
     

    Attached Files:

  21. scottcom4

    scottcom4 TS Rookie Topic Starter Posts: 17

    There doesn't appear to be any change in the startup. The following is what appears in the Fixlog.txt file.

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-05-2013
    Ran by SYSTEM at 2013-05-20 15:55:52 Run:2
    Running from H:\
    Boot Mode: Recovery
    ==============================================
    DEFAULT hive was successfully copied to System32\config\HiveBackup
    DEFAULT hive was successfully restored from registry back up.
    SAM hive was successfully copied to System32\config\HiveBackup
    SAM hive was successfully restored from registry back up.
    SECURITY hive was successfully copied to System32\config\HiveBackup
    SECURITY hive was successfully restored from registry back up.
    SOFTWARE hive was successfully copied to System32\config\HiveBackup
    SOFTWARE hive was successfully restored from registry back up.
    SYSTEM hive was successfully copied to System32\config\HiveBackup
    SYSTEM hive was successfully restored from registry back up.
    ==== End of Fixlog ====
     
  22. Broni

    Broni Malware Annihilator Posts: 47,704   +268

    I don't think there is that much more we can try...

    Do you remember what you did?

    Try to boot back to System Recovery Options and try Startup Repair.
     
  23. scottcom4

    scottcom4 TS Rookie Topic Starter Posts: 17

    Alll I did was click on the file that installed the virus. My virus scanner picked up the virus in the Servcices.exe file. I ran AVG Pro in Windows, which stated that the virus could not be removed. I then ran the AVG boot disk which said it could not be removed or healed. That was when this stated.

    I then tried the System Recovery Options, trying both Startup Repair and System Restore, but apparently all my restore points have been deleted and the Repair takes about an hour but says that it can't fix the issue.

    I will try again and let you know the outcome.
     
  24. Broni

    Broni Malware Annihilator Posts: 47,704   +268

  25. scottcom4

    scottcom4 TS Rookie Topic Starter Posts: 17

    I have attempted to run a Startup Repair, but the outcome is the same. I have also tried running SFC, but get the message "Windows Resource Protection could not perform the requested operation".

    I am completely out of ideas.
     


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.