Truecoat
Posts: 29 +0
Scan result of Farbar Recovery Scan Tool Version: 05-07-2012
Ran by SYSTEM at 06-07-2012 10:39:53
Running from G:\
Windows 7 Professional (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [162328 2011-02-11] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2011-02-11] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417304 2011-02-11] (Intel Corporation)
HKLM\...\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe" [1873256 2011-08-10] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe [x]
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN [622592 2006-12-18] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun [65536 2006-07-19] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-04-03] (Adobe Systems Incorporated)
HKU\Wanda\...\Run: [Installation Diagnostics] "C:\Program Files (x86)\Brother\Brmfl05c\Brinstck.exe" /I MFC-8860DN LAN#2 [126976 2006-11-04] (Brother Industries, Ltd.)
HKU\Wanda\...\Run: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US [4331392 2012-05-30] (AOL Inc.)
HKLM\...\RunOnce: [*Restore] C:\Windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 68.87.77.134 68.87.72.134
==================== Services (Whitelisted) ======
2 atashost; "C:\Windows\SysWOW64\atashost.exe" [133944 2011-03-16] (Cisco WebEx LLC)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 RapiMgr; C:\Windows\WindowsMobile\rapimgr.dll [225672 2007-05-31] (Microsoft Corporation)
2 WcesComm; C:\Windows\WindowsMobile\wcescomm.dll [443784 2007-05-31] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-05 13:08 - 2012-07-05 13:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F4B13D4CD158A5C
2012-07-05 13:01 - 2012-07-05 13:01 - 00000462 ____A C:\Windows\Tasks\SpeedyPC Update Version3.job
2012-07-05 13:01 - 2012-07-05 13:01 - 00000418 ____A C:\Windows\Tasks\SpeedyPC Pro.job
2012-07-05 13:01 - 2012-07-05 13:01 - 00000000 ____D C:\Users\All Users\SpeedyPC Software
2012-07-05 13:01 - 2012-07-05 13:01 - 00000000 ____D C:\Program Files (x86)\SpeedyPC Software
2012-07-05 13:00 - 2012-07-05 13:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D919F98941C164BD
2012-07-05 12:54 - 2012-07-05 12:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D6ECA92EF71CB65
2012-07-05 12:51 - 2012-07-05 12:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E27BB3C5ECD275CD
2012-07-05 12:49 - 2012-07-05 12:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.138850909EAE450B
2012-07-05 12:46 - 2012-07-05 12:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8F7EE9767B7B87DF
2012-07-05 12:43 - 2012-07-05 12:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6372B1BD2CBEAC10
2012-07-05 12:43 - 2012-07-01 02:34 - 00002480 ____A C:\Users\Tony\Desktop\BITS.reg
2012-07-05 12:43 - 2012-07-01 02:34 - 00002208 ____A C:\Users\Tony\Desktop\wuauserv.reg
2012-07-05 12:43 - 2012-06-07 13:31 - 00002075 ____A C:\Users\Tony\Desktop\wscsvc.reg
2012-07-05 12:43 - 2012-06-07 13:05 - 00120395 ____A C:\Users\Tony\Desktop\bfe.reg
2012-07-05 12:43 - 2012-06-07 12:59 - 00197027 ____A C:\Users\Tony\Desktop\sharedaccess.reg
2012-07-05 12:43 - 2012-06-07 12:56 - 00002380 ____A C:\Users\Tony\Desktop\mpssvc.reg
2012-07-05 12:43 - 2009-07-13 17:39 - 00328704 ____A (Microsoft Corporation) C:\Users\Tony\Desktop\services.exe
2012-07-05 12:41 - 2012-07-05 12:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2BC1D3B4D32A2FE
2012-07-05 12:36 - 2012-07-05 12:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FBC2FB45D0334C88
2012-07-05 12:33 - 2012-07-05 12:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2CCABA87DE832326
2012-07-05 12:31 - 2012-07-05 12:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE297D55A257B084
2012-07-05 12:28 - 2012-07-05 12:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D396217839CB5D2E
2012-07-05 12:28 - 2012-07-05 12:28 - 00000000 ____A C:\Users\Tony\Downloads\FRST64.exe
2012-07-05 12:23 - 2012-07-05 12:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2C43487BA98347D
2012-07-05 12:15 - 2012-07-05 12:15 - 12621696 ____A (Microsoft Corporation) C:\Users\Tony\Downloads\mseinstall.exe
2012-07-05 12:15 - 2012-07-05 12:15 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-05 12:15 - 2012-07-05 12:15 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-05 12:12 - 2012-07-05 12:12 - 00001578 ____A C:\Windows\PFRO.log
2012-07-05 11:29 - 2012-07-05 11:29 - 02617648 ____A (VS Revo Group Ltd.) C:\Users\Tony\Downloads\revosetup.exe
2012-07-05 11:28 - 2012-07-05 11:28 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-05 11:28 - 2012-07-05 11:28 - 00000000 ____D C:\Users\Tony\AppData\Roaming\Malwarebytes
2012-07-05 11:27 - 2012-07-05 11:27 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Tony\Downloads\mbam-setup-1.61.0.1400.exe
2012-07-05 11:21 - 2012-07-05 12:22 - 00126034 ____A C:\Users\Tony\AppData\Local\census.cache
2012-07-05 11:21 - 2012-07-05 11:21 - 00102400 ____A C:\Windows\RegBootClean.exe
2012-07-05 11:20 - 2012-07-05 12:22 - 00080912 ____A C:\Users\Tony\AppData\Local\ars.cache
2012-07-05 11:16 - 2012-07-05 11:16 - 02002944 ____A (Trend Micro Inc.) C:\Users\Tony\Downloads\HousecallLauncher.exe
2012-07-05 11:16 - 2012-07-05 11:16 - 00000036 ____A C:\Users\Tony\AppData\Local\housecall.guid.cache
2012-07-05 11:16 - 2012-06-04 23:37 - 00256904 ____A (Trend Micro Inc.) C:\Windows\SysWOW64\Drivers\tmcomm.sys
2012-07-05 11:12 - 2012-07-05 11:12 - 00000000 ____D C:\Program Files\HijackThis
2012-07-05 11:09 - 2012-07-05 11:09 - 00000000 ____D C:\Program Files (x86)\Hijack this
2012-07-05 11:08 - 2012-07-05 11:09 - 00251392 ____A C:\Users\Tony\Downloads\hijackthis_sfx.exe
2012-07-05 10:43 - 2012-07-05 10:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0A5E498702DF09
2012-07-05 10:35 - 2012-07-05 10:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.26A35AFBD39348A4
2012-07-05 10:33 - 2012-07-05 10:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1EC01D38735E0301
2012-07-05 10:27 - 2012-07-05 10:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE77620C56AD2624
2012-07-05 10:12 - 2012-07-05 10:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A4C4CB375DCAA796
2012-07-05 10:09 - 2012-07-05 10:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD5C983E7C44341C
2012-07-05 10:04 - 2012-07-05 10:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EA70B982FF6D3F14
2012-07-05 09:44 - 2012-07-05 09:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0ED12FE98066BD6D
2012-07-05 09:31 - 2012-07-05 09:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DDBB3068455F163D
2012-07-05 09:26 - 2012-07-05 09:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F1D5AD3C222271F
2012-07-05 09:23 - 2012-07-05 09:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B235131359A432C
2012-07-05 09:20 - 2012-07-05 09:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D200829D103BF9A8
2012-07-05 09:17 - 2012-07-05 09:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9B0F07C8D9E87B6
2012-07-05 09:14 - 2012-07-05 09:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D81AC4A80E8886F1
2012-07-05 09:12 - 2012-07-05 09:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C7DA40BBB3BA3EBC
2012-07-05 09:05 - 2012-07-05 09:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.099F438738A1CCC2
2012-07-05 05:58 - 2012-07-05 14:03 - 00000000 ____D C:\Users\Tony\Downloads\Camera Surveillance Q-See Software Manual
2012-07-03 09:48 - 2012-07-03 09:48 - 00000000 ____D C:\Users\Tony\Downloads\11anweb
2012-07-03 09:47 - 2012-07-03 09:47 - 00823485 ____A C:\Users\Tony\Downloads\11anweb.zip
2012-07-02 10:55 - 2012-06-29 06:23 - 00017920 ____A C:\Users\Tony\Downloads\4. June 25 - 29, 2012.xls
2012-07-02 09:49 - 2012-07-02 09:49 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-29 12:45 - 2012-07-05 13:12 - 00003726 ____A C:\Windows\setupact.log
2012-06-29 12:45 - 2012-06-29 12:45 - 00000000 ____A C:\Windows\setuperr.log
2012-06-29 10:19 - 2012-06-29 10:13 - 00017408 ____A C:\Users\Tony\Downloads\BILLING SUMMARY 6-25 thru 6-29.xls
2012-06-29 09:16 - 2012-06-29 09:14 - 00029696 ____A C:\Users\Tony\Downloads\Client Remit.xls
2012-06-28 11:51 - 2012-06-28 11:48 - 00048128 ____A C:\Users\Tony\Downloads\5-2012 Williams Goodhue county.xls
2012-06-28 11:51 - 2012-06-28 11:35 - 00041984 ____A C:\Users\Tony\Downloads\James Williams correction Transportation .xls
2012-06-25 10:22 - 2012-06-25 10:22 - 00000958 ____A C:\Users\Tony\Desktop\A-PDF Split.lnk
2012-06-25 10:22 - 2012-06-25 10:22 - 00000000 ____D C:\Program Files (x86)\A-PDF Split
2012-06-25 06:26 - 2012-06-25 06:13 - 00017408 ____A C:\Users\Tony\Downloads\3. June 18 - 22, 2012.xls
2012-06-22 10:13 - 2012-07-02 12:01 - 00000000 ____D C:\Users\Tony\Downloads\Aalix D auth
2012-06-22 10:11 - 2012-06-22 10:11 - 00000000 ____D C:\Users\Tony\Desktop\Town and Country
2012-06-22 10:10 - 2012-06-22 10:10 - 00000000 ____D C:\Users\Tony\Downloads\Brian B auth
2012-06-22 10:09 - 2012-07-02 13:37 - 00000000 ____D C:\Users\Tony\Downloads\Jason Revland auth
2012-06-22 05:13 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-22 05:13 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-22 05:13 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-22 05:13 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-22 05:13 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-22 05:13 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-22 05:13 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-22 05:12 - 2012-06-02 12:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-22 05:12 - 2012-06-02 12:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-21 06:54 - 2012-07-03 04:33 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2012-06-21 06:52 - 2012-06-21 06:54 - 00000000 ____D C:\Users\Tony\AppData\Local\BlueStacksSetup
2012-06-15 08:34 - 2012-06-15 09:28 - 00035840 ____A C:\Users\Tony\Downloads\Jessica_Billing_6-8-12.xls
2012-06-14 08:01 - 2012-06-14 09:09 - 00000000 __SHD C:\Users\Tony\Documents\cache
2012-06-14 08:00 - 2012-06-14 08:00 - 00000000 ____D C:\Users\Tony\AppData\Roaming\webex
2012-06-14 04:53 - 2012-06-14 04:53 - 00000000 ____D C:\Users\Tony\AppData\Local\Macromedia
2012-06-13 05:39 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-13 05:39 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-13 05:39 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-13 05:39 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-13 05:39 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-13 05:39 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-13 05:39 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-13 05:39 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-13 05:39 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-13 05:39 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-13 05:39 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-13 05:39 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-13 05:39 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-13 05:39 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-13 05:39 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-13 05:39 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-13 05:39 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-13 05:39 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-13 05:39 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-13 05:39 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-13 05:39 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-13 05:39 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-13 05:39 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-13 05:39 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-13 05:39 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-13 05:39 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 05:38 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-13 05:38 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-13 00:48 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-13 00:48 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 00:48 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 00:48 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 00:47 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 00:47 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 00:47 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 00:47 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 00:47 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 00:47 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 00:47 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 00:47 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 00:47 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 00:47 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 00:47 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-13 00:47 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-13 00:47 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-11 13:03 - 2012-06-11 13:03 - 00000537 ____A C:\Users\Tony\Desktop\Emdeon.lnk
2012-06-11 09:24 - 2012-06-11 09:24 - 00001032 ____A C:\Users\Tony\Desktop\Danette Billing 2012 - Shortcut.lnk
2012-06-06 07:53 - 2012-06-06 07:53 - 00000000 ____D C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2012-06-06 05:44 - 2012-06-06 05:44 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2012-06-06 05:43 - 2012-06-06 05:44 - 00000000 ____D C:\Windows\WindowsMobile
============ 3 Months Modified Files ========================
2012-07-05 13:12 - 2012-06-29 12:45 - 00003726 ____A C:\Windows\setupact.log
2012-07-05 13:12 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-05 13:10 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-05 13:08 - 2012-07-05 13:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F4B13D4CD158A5C
2012-07-05 13:02 - 2010-06-04 11:25 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-05 13:01 - 2012-07-05 13:01 - 00000462 ____A C:\Windows\Tasks\SpeedyPC Update Version3.job
2012-07-05 13:01 - 2012-07-05 13:01 - 00000418 ____A C:\Windows\Tasks\SpeedyPC Pro.job
2012-07-05 13:00 - 2012-07-05 13:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D919F98941C164BD
2012-07-05 12:54 - 2012-07-05 12:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D6ECA92EF71CB65
2012-07-05 12:51 - 2012-07-05 12:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E27BB3C5ECD275CD
2012-07-05 12:49 - 2012-07-05 12:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.138850909EAE450B
2012-07-05 12:46 - 2012-07-05 12:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8F7EE9767B7B87DF
2012-07-05 12:43 - 2012-07-05 12:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6372B1BD2CBEAC10
2012-07-05 12:41 - 2012-07-05 12:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2BC1D3B4D32A2FE
2012-07-05 12:40 - 2009-07-13 21:08 - 00032556 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-05 12:36 - 2012-07-05 12:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FBC2FB45D0334C88
2012-07-05 12:33 - 2012-07-05 12:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2CCABA87DE832326
2012-07-05 12:32 - 2012-04-12 04:20 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-05 12:31 - 2012-07-05 12:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE297D55A257B084
2012-07-05 12:28 - 2012-07-05 12:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D396217839CB5D2E
2012-07-05 12:28 - 2012-07-05 12:28 - 00000000 ____A C:\Users\Tony\Downloads\FRST64.exe
2012-07-05 12:23 - 2012-07-05 12:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2C43487BA98347D
2012-07-05 12:22 - 2012-07-05 11:21 - 00126034 ____A C:\Users\Tony\AppData\Local\census.cache
2012-07-05 12:22 - 2012-07-05 11:20 - 00080912 ____A C:\Users\Tony\AppData\Local\ars.cache
2012-07-05 12:19 - 2009-07-13 21:13 - 00743290 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-05 12:19 - 2009-07-13 20:45 - 00014256 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-05 12:19 - 2009-07-13 20:45 - 00014256 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-05 12:16 - 2012-03-09 13:31 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-05 12:16 - 2010-05-25 12:15 - 01741153 ____A C:\Windows\WindowsUpdate.log
2012-07-05 12:15 - 2012-07-05 12:15 - 12621696 ____A (Microsoft Corporation) C:\Users\Tony\Downloads\mseinstall.exe
2012-07-05 12:15 - 2012-03-09 13:31 - 00756948 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-05 12:15 - 2010-06-04 11:25 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-05 12:12 - 2012-07-05 12:12 - 00001578 ____A C:\Windows\PFRO.log
2012-07-05 11:29 - 2012-07-05 11:29 - 02617648 ____A (VS Revo Group Ltd.) C:\Users\Tony\Downloads\revosetup.exe
2012-07-05 11:29 - 2012-06-05 05:33 - 00001264 ____A C:\Users\Tony\Desktop\Revo Uninstaller.lnk
2012-07-05 11:28 - 2012-07-05 11:28 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-05 11:27 - 2012-07-05 11:27 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Tony\Downloads\mbam-setup-1.61.0.1400.exe
2012-07-05 11:21 - 2012-07-05 11:21 - 00102400 ____A C:\Windows\RegBootClean.exe
2012-07-05 11:16 - 2012-07-05 11:16 - 02002944 ____A (Trend Micro Inc.) C:\Users\Tony\Downloads\HousecallLauncher.exe
2012-07-05 11:16 - 2012-07-05 11:16 - 00000036 ____A C:\Users\Tony\AppData\Local\housecall.guid.cache
2012-07-05 11:09 - 2012-07-05 11:08 - 00251392 ____A C:\Users\Tony\Downloads\hijackthis_sfx.exe
2012-07-05 10:43 - 2012-07-05 10:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0A5E498702DF09
2012-07-05 10:35 - 2012-07-05 10:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.26A35AFBD39348A4
2012-07-05 10:33 - 2012-07-05 10:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1EC01D38735E0301
2012-07-05 10:27 - 2012-07-05 10:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE77620C56AD2624
2012-07-05 10:12 - 2012-07-05 10:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A4C4CB375DCAA796
2012-07-05 10:09 - 2012-07-05 10:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD5C983E7C44341C
2012-07-05 10:04 - 2012-07-05 10:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EA70B982FF6D3F14
2012-07-05 09:44 - 2012-07-05 09:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0ED12FE98066BD6D
2012-07-05 09:31 - 2012-07-05 09:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DDBB3068455F163D
2012-07-05 09:26 - 2012-07-05 09:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F1D5AD3C222271F
2012-07-05 09:23 - 2012-07-05 09:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B235131359A432C
2012-07-05 09:20 - 2012-07-05 09:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D200829D103BF9A8
2012-07-05 09:17 - 2012-07-05 09:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9B0F07C8D9E87B6
2012-07-05 09:14 - 2012-07-05 09:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D81AC4A80E8886F1
2012-07-05 09:12 - 2012-07-05 09:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C7DA40BBB3BA3EBC
2012-07-05 09:05 - 2012-07-05 09:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.099F438738A1CCC2
2012-07-03 09:47 - 2012-07-03 09:47 - 00823485 ____A C:\Users\Tony\Downloads\11anweb.zip
2012-07-02 13:39 - 2010-05-25 12:21 - 00000956 ____A C:\Windows\Brpfx04a.ini
2012-07-02 09:46 - 2012-04-12 04:20 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-02 09:46 - 2011-06-10 09:53 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-01 02:34 - 2012-07-05 12:43 - 00002480 ____A C:\Users\Tony\Desktop\BITS.reg
2012-07-01 02:34 - 2012-07-05 12:43 - 00002208 ____A C:\Users\Tony\Desktop\wuauserv.reg
2012-06-29 12:45 - 2012-06-29 12:45 - 00000000 ____A C:\Windows\setuperr.log
2012-06-29 10:13 - 2012-06-29 10:19 - 00017408 ____A C:\Users\Tony\Downloads\BILLING SUMMARY 6-25 thru 6-29.xls
2012-06-29 09:14 - 2012-06-29 09:16 - 00029696 ____A C:\Users\Tony\Downloads\Client Remit.xls
2012-06-29 06:23 - 2012-07-02 10:55 - 00017920 ____A C:\Users\Tony\Downloads\4. June 25 - 29, 2012.xls
2012-06-28 11:48 - 2012-06-28 11:51 - 00048128 ____A C:\Users\Tony\Downloads\5-2012 Williams Goodhue county.xls
2012-06-28 11:35 - 2012-06-28 11:51 - 00041984 ____A C:\Users\Tony\Downloads\James Williams correction Transportation .xls
2012-06-25 10:22 - 2012-06-25 10:22 - 00000958 ____A C:\Users\Tony\Desktop\A-PDF Split.lnk
2012-06-25 06:13 - 2012-06-25 06:26 - 00017408 ____A C:\Users\Tony\Downloads\3. June 18 - 22, 2012.xls
2012-06-22 05:02 - 2011-10-14 04:35 - 00000338 ____A C:\Windows\Tasks\Regwork.job
2012-06-15 09:28 - 2012-06-15 08:34 - 00035840 ____A C:\Users\Tony\Downloads\Jessica_Billing_6-8-12.xls
2012-06-13 06:24 - 2009-07-13 20:45 - 00302024 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 05:46 - 2011-10-14 03:30 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-13 05:38 - 2012-03-14 12:08 - 00000748 ___AH C:\IPH.PH
2012-06-13 05:37 - 2012-03-14 12:08 - 00001911 ____A C:\Users\Public\Desktop\AIM.lnk
2012-06-11 13:03 - 2012-06-11 13:03 - 00000537 ____A C:\Users\Tony\Desktop\Emdeon.lnk
2012-06-11 09:24 - 2012-06-11 09:24 - 00001032 ____A C:\Users\Tony\Desktop\Danette Billing 2012 - Shortcut.lnk
2012-06-11 08:29 - 2012-05-18 12:08 - 00029184 ____A C:\Users\Tony\Desktop\Jessica Billing 2012.xls
2012-06-11 08:28 - 2012-04-17 09:00 - 00002184 ____A C:\Users\Tony\Desktop\Shared Folder - Shortcut.lnk
2012-06-07 13:31 - 2012-07-05 12:43 - 00002075 ____A C:\Users\Tony\Desktop\wscsvc.reg
2012-06-07 13:05 - 2012-07-05 12:43 - 00120395 ____A C:\Users\Tony\Desktop\bfe.reg
2012-06-07 12:59 - 2012-07-05 12:43 - 00197027 ____A C:\Users\Tony\Desktop\sharedaccess.reg
2012-06-07 12:56 - 2012-07-05 12:43 - 00002380 ____A C:\Users\Tony\Desktop\mpssvc.reg
2012-06-06 05:44 - 2012-06-06 05:44 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2012-06-05 05:33 - 2012-06-05 05:17 - 00002662 ____A C:\Users\Tony\Documents\tonysci.profile
2012-06-05 05:33 - 2012-06-05 05:16 - 00000245 ____A C:\Users\Tony\Documents\iSafeguard.log
2012-06-04 23:37 - 2012-07-05 11:16 - 00256904 ____A (Trend Micro Inc.) C:\Windows\SysWOW64\Drivers\tmcomm.sys
2012-06-02 14:19 - 2012-06-22 05:13 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-22 05:13 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-22 05:13 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-22 05:13 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-22 05:13 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-22 05:13 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-22 05:13 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 12:19 - 2012-06-22 05:12 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:15 - 2012-06-22 05:12 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-23 09:03 - 2012-05-23 09:03 - 00002659 ____A C:\Users\Public\Desktop\PSS(admin).lnk
2012-05-23 09:03 - 2012-05-23 09:03 - 00002617 ____A C:\Users\Public\Desktop\PSS.lnk
2012-05-23 08:50 - 2012-05-23 08:50 - 00000153 ____A C:\Users\Tony\RmDvrUserCfg85.ini
2012-05-18 05:27 - 2012-05-18 05:31 - 00063488 ____A C:\Users\Tony\Downloads\5-18-12 WHO IS IN GROUP new.xls
2012-05-17 18:47 - 2012-06-13 05:39 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-13 05:38 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-13 05:39 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-13 05:39 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-13 05:39 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-13 05:39 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-13 05:39 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-13 05:39 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-13 05:39 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-13 05:39 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-13 05:39 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-13 05:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-13 05:39 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-13 05:39 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-13 05:39 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-13 05:38 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-13 05:39 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-13 05:39 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-13 05:39 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-13 05:39 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-13 05:39 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-13 05:39 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-13 05:39 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-13 05:39 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-13 05:39 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-13 05:39 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-13 05:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-13 05:39 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 17:32 - 2012-06-13 00:47 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-09 05:45 - 2012-05-09 05:45 - 00001436 ____A C:\Users\Tony\Desktop\Tony Cover Sheet Billing Dept - Shortcut.lnk
2012-05-04 10:03 - 2012-04-20 07:30 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk
2012-05-04 03:06 - 2012-06-13 00:47 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 00:47 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 00:47 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-03 08:24 - 2012-05-03 08:24 - 00002969 ____A C:\Users\Tony\Desktop\EasyPrint.lnk
2012-05-03 08:24 - 2012-05-03 08:24 - 00000092 ____A C:\Users\Tony\AppData\Local\fusioncache.dat
2012-05-02 12:52 - 2012-05-02 12:52 - 00000939 ____A C:\Users\Tony\Desktop\A-PDF PDFLabel.lnk
2012-05-02 09:21 - 2010-05-25 12:55 - 00000426 ____A C:\Windows\BRWMARK.INI
2012-04-30 21:40 - 2012-06-13 00:48 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-13 00:47 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 08:34 - 2012-06-05 04:23 - 00002338 ____A C:\Users\Tony\Desktop\PSYCH - Shortcut.lnk
2012-04-25 21:41 - 2012-06-13 00:48 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 00:48 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 00:48 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-25 10:43 - 2012-04-04 08:14 - 00028160 ____A C:\Users\Tony\Desktop\list of clients and groups.xls
2012-04-23 21:37 - 2012-06-13 00:47 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 00:47 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 00:47 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 00:47 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 00:47 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 00:47 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-18 05:53 - 2012-04-18 05:53 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
2012-04-17 05:25 - 2012-04-11 12:14 - 00017920 ____A C:\Users\Tony\Desktop\Tony's TO DO LIST.xls
2012-04-13 06:41 - 2012-04-13 06:35 - 257265978 ____A C:\Users\Tony\Documents\Matterhorn Bobsleds in HD both tracks at Disneyland.mp4
2012-04-11 12:14 - 2012-04-11 12:14 - 00017920 ____A C:\Users\Tony\Downloads\Tony's TO DO LIST.xls
2012-04-09 04:27 - 2012-04-03 11:11 - 00064648 ____A C:\Users\Tony\AppData\Local\GDIPFONTCACHEV1.DAT
ZeroAccess:
C:\Windows\Installer\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}
C:\Windows\Installer\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\@
C:\Windows\Installer\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\L
C:\Windows\Installer\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\U
C:\Windows\Installer\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\U\00000001.@
C:\Windows\Installer\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\U\80000000.@
C:\Windows\Installer\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\U\800000cb.@
ZeroAccess:
C:\Users\Tony\AppData\Local\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}
C:\Users\Tony\AppData\Local\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\@
C:\Users\Tony\AppData\Local\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\L
C:\Users\Tony\AppData\Local\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 36%
Total physical RAM: 2013.05 MB
Available physical RAM: 1281.43 MB
Total Pagefile: 2013.05 MB
Available Pagefile: 1267.07 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:288.19 GB) (Free:248.25 GB) NTFS
Ran by SYSTEM at 06-07-2012 10:39:53
Running from G:\
Windows 7 Professional (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [162328 2011-02-11] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2011-02-11] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417304 2011-02-11] (Intel Corporation)
HKLM\...\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe" [1873256 2011-08-10] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe [x]
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN [622592 2006-12-18] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun [65536 2006-07-19] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-04-03] (Adobe Systems Incorporated)
HKU\Wanda\...\Run: [Installation Diagnostics] "C:\Program Files (x86)\Brother\Brmfl05c\Brinstck.exe" /I MFC-8860DN LAN#2 [126976 2006-11-04] (Brother Industries, Ltd.)
HKU\Wanda\...\Run: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US [4331392 2012-05-30] (AOL Inc.)
HKLM\...\RunOnce: [*Restore] C:\Windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 68.87.77.134 68.87.72.134
==================== Services (Whitelisted) ======
2 atashost; "C:\Windows\SysWOW64\atashost.exe" [133944 2011-03-16] (Cisco WebEx LLC)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 RapiMgr; C:\Windows\WindowsMobile\rapimgr.dll [225672 2007-05-31] (Microsoft Corporation)
2 WcesComm; C:\Windows\WindowsMobile\wcescomm.dll [443784 2007-05-31] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-05 13:08 - 2012-07-05 13:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F4B13D4CD158A5C
2012-07-05 13:01 - 2012-07-05 13:01 - 00000462 ____A C:\Windows\Tasks\SpeedyPC Update Version3.job
2012-07-05 13:01 - 2012-07-05 13:01 - 00000418 ____A C:\Windows\Tasks\SpeedyPC Pro.job
2012-07-05 13:01 - 2012-07-05 13:01 - 00000000 ____D C:\Users\All Users\SpeedyPC Software
2012-07-05 13:01 - 2012-07-05 13:01 - 00000000 ____D C:\Program Files (x86)\SpeedyPC Software
2012-07-05 13:00 - 2012-07-05 13:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D919F98941C164BD
2012-07-05 12:54 - 2012-07-05 12:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D6ECA92EF71CB65
2012-07-05 12:51 - 2012-07-05 12:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E27BB3C5ECD275CD
2012-07-05 12:49 - 2012-07-05 12:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.138850909EAE450B
2012-07-05 12:46 - 2012-07-05 12:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8F7EE9767B7B87DF
2012-07-05 12:43 - 2012-07-05 12:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6372B1BD2CBEAC10
2012-07-05 12:43 - 2012-07-01 02:34 - 00002480 ____A C:\Users\Tony\Desktop\BITS.reg
2012-07-05 12:43 - 2012-07-01 02:34 - 00002208 ____A C:\Users\Tony\Desktop\wuauserv.reg
2012-07-05 12:43 - 2012-06-07 13:31 - 00002075 ____A C:\Users\Tony\Desktop\wscsvc.reg
2012-07-05 12:43 - 2012-06-07 13:05 - 00120395 ____A C:\Users\Tony\Desktop\bfe.reg
2012-07-05 12:43 - 2012-06-07 12:59 - 00197027 ____A C:\Users\Tony\Desktop\sharedaccess.reg
2012-07-05 12:43 - 2012-06-07 12:56 - 00002380 ____A C:\Users\Tony\Desktop\mpssvc.reg
2012-07-05 12:43 - 2009-07-13 17:39 - 00328704 ____A (Microsoft Corporation) C:\Users\Tony\Desktop\services.exe
2012-07-05 12:41 - 2012-07-05 12:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2BC1D3B4D32A2FE
2012-07-05 12:36 - 2012-07-05 12:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FBC2FB45D0334C88
2012-07-05 12:33 - 2012-07-05 12:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2CCABA87DE832326
2012-07-05 12:31 - 2012-07-05 12:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE297D55A257B084
2012-07-05 12:28 - 2012-07-05 12:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D396217839CB5D2E
2012-07-05 12:28 - 2012-07-05 12:28 - 00000000 ____A C:\Users\Tony\Downloads\FRST64.exe
2012-07-05 12:23 - 2012-07-05 12:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2C43487BA98347D
2012-07-05 12:15 - 2012-07-05 12:15 - 12621696 ____A (Microsoft Corporation) C:\Users\Tony\Downloads\mseinstall.exe
2012-07-05 12:15 - 2012-07-05 12:15 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-05 12:15 - 2012-07-05 12:15 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-05 12:12 - 2012-07-05 12:12 - 00001578 ____A C:\Windows\PFRO.log
2012-07-05 11:29 - 2012-07-05 11:29 - 02617648 ____A (VS Revo Group Ltd.) C:\Users\Tony\Downloads\revosetup.exe
2012-07-05 11:28 - 2012-07-05 11:28 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-05 11:28 - 2012-07-05 11:28 - 00000000 ____D C:\Users\Tony\AppData\Roaming\Malwarebytes
2012-07-05 11:27 - 2012-07-05 11:27 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Tony\Downloads\mbam-setup-1.61.0.1400.exe
2012-07-05 11:21 - 2012-07-05 12:22 - 00126034 ____A C:\Users\Tony\AppData\Local\census.cache
2012-07-05 11:21 - 2012-07-05 11:21 - 00102400 ____A C:\Windows\RegBootClean.exe
2012-07-05 11:20 - 2012-07-05 12:22 - 00080912 ____A C:\Users\Tony\AppData\Local\ars.cache
2012-07-05 11:16 - 2012-07-05 11:16 - 02002944 ____A (Trend Micro Inc.) C:\Users\Tony\Downloads\HousecallLauncher.exe
2012-07-05 11:16 - 2012-07-05 11:16 - 00000036 ____A C:\Users\Tony\AppData\Local\housecall.guid.cache
2012-07-05 11:16 - 2012-06-04 23:37 - 00256904 ____A (Trend Micro Inc.) C:\Windows\SysWOW64\Drivers\tmcomm.sys
2012-07-05 11:12 - 2012-07-05 11:12 - 00000000 ____D C:\Program Files\HijackThis
2012-07-05 11:09 - 2012-07-05 11:09 - 00000000 ____D C:\Program Files (x86)\Hijack this
2012-07-05 11:08 - 2012-07-05 11:09 - 00251392 ____A C:\Users\Tony\Downloads\hijackthis_sfx.exe
2012-07-05 10:43 - 2012-07-05 10:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0A5E498702DF09
2012-07-05 10:35 - 2012-07-05 10:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.26A35AFBD39348A4
2012-07-05 10:33 - 2012-07-05 10:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1EC01D38735E0301
2012-07-05 10:27 - 2012-07-05 10:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE77620C56AD2624
2012-07-05 10:12 - 2012-07-05 10:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A4C4CB375DCAA796
2012-07-05 10:09 - 2012-07-05 10:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD5C983E7C44341C
2012-07-05 10:04 - 2012-07-05 10:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EA70B982FF6D3F14
2012-07-05 09:44 - 2012-07-05 09:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0ED12FE98066BD6D
2012-07-05 09:31 - 2012-07-05 09:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DDBB3068455F163D
2012-07-05 09:26 - 2012-07-05 09:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F1D5AD3C222271F
2012-07-05 09:23 - 2012-07-05 09:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B235131359A432C
2012-07-05 09:20 - 2012-07-05 09:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D200829D103BF9A8
2012-07-05 09:17 - 2012-07-05 09:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9B0F07C8D9E87B6
2012-07-05 09:14 - 2012-07-05 09:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D81AC4A80E8886F1
2012-07-05 09:12 - 2012-07-05 09:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C7DA40BBB3BA3EBC
2012-07-05 09:05 - 2012-07-05 09:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.099F438738A1CCC2
2012-07-05 05:58 - 2012-07-05 14:03 - 00000000 ____D C:\Users\Tony\Downloads\Camera Surveillance Q-See Software Manual
2012-07-03 09:48 - 2012-07-03 09:48 - 00000000 ____D C:\Users\Tony\Downloads\11anweb
2012-07-03 09:47 - 2012-07-03 09:47 - 00823485 ____A C:\Users\Tony\Downloads\11anweb.zip
2012-07-02 10:55 - 2012-06-29 06:23 - 00017920 ____A C:\Users\Tony\Downloads\4. June 25 - 29, 2012.xls
2012-07-02 09:49 - 2012-07-02 09:49 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-29 12:45 - 2012-07-05 13:12 - 00003726 ____A C:\Windows\setupact.log
2012-06-29 12:45 - 2012-06-29 12:45 - 00000000 ____A C:\Windows\setuperr.log
2012-06-29 10:19 - 2012-06-29 10:13 - 00017408 ____A C:\Users\Tony\Downloads\BILLING SUMMARY 6-25 thru 6-29.xls
2012-06-29 09:16 - 2012-06-29 09:14 - 00029696 ____A C:\Users\Tony\Downloads\Client Remit.xls
2012-06-28 11:51 - 2012-06-28 11:48 - 00048128 ____A C:\Users\Tony\Downloads\5-2012 Williams Goodhue county.xls
2012-06-28 11:51 - 2012-06-28 11:35 - 00041984 ____A C:\Users\Tony\Downloads\James Williams correction Transportation .xls
2012-06-25 10:22 - 2012-06-25 10:22 - 00000958 ____A C:\Users\Tony\Desktop\A-PDF Split.lnk
2012-06-25 10:22 - 2012-06-25 10:22 - 00000000 ____D C:\Program Files (x86)\A-PDF Split
2012-06-25 06:26 - 2012-06-25 06:13 - 00017408 ____A C:\Users\Tony\Downloads\3. June 18 - 22, 2012.xls
2012-06-22 10:13 - 2012-07-02 12:01 - 00000000 ____D C:\Users\Tony\Downloads\Aalix D auth
2012-06-22 10:11 - 2012-06-22 10:11 - 00000000 ____D C:\Users\Tony\Desktop\Town and Country
2012-06-22 10:10 - 2012-06-22 10:10 - 00000000 ____D C:\Users\Tony\Downloads\Brian B auth
2012-06-22 10:09 - 2012-07-02 13:37 - 00000000 ____D C:\Users\Tony\Downloads\Jason Revland auth
2012-06-22 05:13 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-22 05:13 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-22 05:13 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-22 05:13 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-22 05:13 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-22 05:13 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-22 05:13 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-22 05:12 - 2012-06-02 12:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-22 05:12 - 2012-06-02 12:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-21 06:54 - 2012-07-03 04:33 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2012-06-21 06:52 - 2012-06-21 06:54 - 00000000 ____D C:\Users\Tony\AppData\Local\BlueStacksSetup
2012-06-15 08:34 - 2012-06-15 09:28 - 00035840 ____A C:\Users\Tony\Downloads\Jessica_Billing_6-8-12.xls
2012-06-14 08:01 - 2012-06-14 09:09 - 00000000 __SHD C:\Users\Tony\Documents\cache
2012-06-14 08:00 - 2012-06-14 08:00 - 00000000 ____D C:\Users\Tony\AppData\Roaming\webex
2012-06-14 04:53 - 2012-06-14 04:53 - 00000000 ____D C:\Users\Tony\AppData\Local\Macromedia
2012-06-13 05:39 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-13 05:39 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-13 05:39 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-13 05:39 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-13 05:39 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-13 05:39 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-13 05:39 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-13 05:39 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-13 05:39 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-13 05:39 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-13 05:39 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-13 05:39 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-13 05:39 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-13 05:39 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-13 05:39 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-13 05:39 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-13 05:39 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-13 05:39 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-13 05:39 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-13 05:39 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-13 05:39 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-13 05:39 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-13 05:39 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-13 05:39 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-13 05:39 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-13 05:39 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 05:38 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-13 05:38 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-13 00:48 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-13 00:48 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 00:48 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 00:48 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 00:47 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 00:47 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 00:47 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 00:47 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 00:47 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 00:47 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 00:47 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 00:47 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 00:47 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 00:47 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 00:47 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-13 00:47 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-13 00:47 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-11 13:03 - 2012-06-11 13:03 - 00000537 ____A C:\Users\Tony\Desktop\Emdeon.lnk
2012-06-11 09:24 - 2012-06-11 09:24 - 00001032 ____A C:\Users\Tony\Desktop\Danette Billing 2012 - Shortcut.lnk
2012-06-06 07:53 - 2012-06-06 07:53 - 00000000 ____D C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2012-06-06 05:44 - 2012-06-06 05:44 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2012-06-06 05:43 - 2012-06-06 05:44 - 00000000 ____D C:\Windows\WindowsMobile
============ 3 Months Modified Files ========================
2012-07-05 13:12 - 2012-06-29 12:45 - 00003726 ____A C:\Windows\setupact.log
2012-07-05 13:12 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-05 13:10 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-05 13:08 - 2012-07-05 13:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F4B13D4CD158A5C
2012-07-05 13:02 - 2010-06-04 11:25 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-05 13:01 - 2012-07-05 13:01 - 00000462 ____A C:\Windows\Tasks\SpeedyPC Update Version3.job
2012-07-05 13:01 - 2012-07-05 13:01 - 00000418 ____A C:\Windows\Tasks\SpeedyPC Pro.job
2012-07-05 13:00 - 2012-07-05 13:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D919F98941C164BD
2012-07-05 12:54 - 2012-07-05 12:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D6ECA92EF71CB65
2012-07-05 12:51 - 2012-07-05 12:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E27BB3C5ECD275CD
2012-07-05 12:49 - 2012-07-05 12:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.138850909EAE450B
2012-07-05 12:46 - 2012-07-05 12:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8F7EE9767B7B87DF
2012-07-05 12:43 - 2012-07-05 12:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6372B1BD2CBEAC10
2012-07-05 12:41 - 2012-07-05 12:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2BC1D3B4D32A2FE
2012-07-05 12:40 - 2009-07-13 21:08 - 00032556 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-05 12:36 - 2012-07-05 12:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FBC2FB45D0334C88
2012-07-05 12:33 - 2012-07-05 12:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2CCABA87DE832326
2012-07-05 12:32 - 2012-04-12 04:20 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-05 12:31 - 2012-07-05 12:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE297D55A257B084
2012-07-05 12:28 - 2012-07-05 12:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D396217839CB5D2E
2012-07-05 12:28 - 2012-07-05 12:28 - 00000000 ____A C:\Users\Tony\Downloads\FRST64.exe
2012-07-05 12:23 - 2012-07-05 12:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2C43487BA98347D
2012-07-05 12:22 - 2012-07-05 11:21 - 00126034 ____A C:\Users\Tony\AppData\Local\census.cache
2012-07-05 12:22 - 2012-07-05 11:20 - 00080912 ____A C:\Users\Tony\AppData\Local\ars.cache
2012-07-05 12:19 - 2009-07-13 21:13 - 00743290 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-05 12:19 - 2009-07-13 20:45 - 00014256 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-05 12:19 - 2009-07-13 20:45 - 00014256 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-05 12:16 - 2012-03-09 13:31 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-05 12:16 - 2010-05-25 12:15 - 01741153 ____A C:\Windows\WindowsUpdate.log
2012-07-05 12:15 - 2012-07-05 12:15 - 12621696 ____A (Microsoft Corporation) C:\Users\Tony\Downloads\mseinstall.exe
2012-07-05 12:15 - 2012-03-09 13:31 - 00756948 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-05 12:15 - 2010-06-04 11:25 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-05 12:12 - 2012-07-05 12:12 - 00001578 ____A C:\Windows\PFRO.log
2012-07-05 11:29 - 2012-07-05 11:29 - 02617648 ____A (VS Revo Group Ltd.) C:\Users\Tony\Downloads\revosetup.exe
2012-07-05 11:29 - 2012-06-05 05:33 - 00001264 ____A C:\Users\Tony\Desktop\Revo Uninstaller.lnk
2012-07-05 11:28 - 2012-07-05 11:28 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-05 11:27 - 2012-07-05 11:27 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Tony\Downloads\mbam-setup-1.61.0.1400.exe
2012-07-05 11:21 - 2012-07-05 11:21 - 00102400 ____A C:\Windows\RegBootClean.exe
2012-07-05 11:16 - 2012-07-05 11:16 - 02002944 ____A (Trend Micro Inc.) C:\Users\Tony\Downloads\HousecallLauncher.exe
2012-07-05 11:16 - 2012-07-05 11:16 - 00000036 ____A C:\Users\Tony\AppData\Local\housecall.guid.cache
2012-07-05 11:09 - 2012-07-05 11:08 - 00251392 ____A C:\Users\Tony\Downloads\hijackthis_sfx.exe
2012-07-05 10:43 - 2012-07-05 10:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0A5E498702DF09
2012-07-05 10:35 - 2012-07-05 10:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.26A35AFBD39348A4
2012-07-05 10:33 - 2012-07-05 10:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1EC01D38735E0301
2012-07-05 10:27 - 2012-07-05 10:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE77620C56AD2624
2012-07-05 10:12 - 2012-07-05 10:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A4C4CB375DCAA796
2012-07-05 10:09 - 2012-07-05 10:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD5C983E7C44341C
2012-07-05 10:04 - 2012-07-05 10:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EA70B982FF6D3F14
2012-07-05 09:44 - 2012-07-05 09:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0ED12FE98066BD6D
2012-07-05 09:31 - 2012-07-05 09:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DDBB3068455F163D
2012-07-05 09:26 - 2012-07-05 09:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F1D5AD3C222271F
2012-07-05 09:23 - 2012-07-05 09:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B235131359A432C
2012-07-05 09:20 - 2012-07-05 09:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D200829D103BF9A8
2012-07-05 09:17 - 2012-07-05 09:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9B0F07C8D9E87B6
2012-07-05 09:14 - 2012-07-05 09:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D81AC4A80E8886F1
2012-07-05 09:12 - 2012-07-05 09:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C7DA40BBB3BA3EBC
2012-07-05 09:05 - 2012-07-05 09:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.099F438738A1CCC2
2012-07-03 09:47 - 2012-07-03 09:47 - 00823485 ____A C:\Users\Tony\Downloads\11anweb.zip
2012-07-02 13:39 - 2010-05-25 12:21 - 00000956 ____A C:\Windows\Brpfx04a.ini
2012-07-02 09:46 - 2012-04-12 04:20 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-02 09:46 - 2011-06-10 09:53 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-01 02:34 - 2012-07-05 12:43 - 00002480 ____A C:\Users\Tony\Desktop\BITS.reg
2012-07-01 02:34 - 2012-07-05 12:43 - 00002208 ____A C:\Users\Tony\Desktop\wuauserv.reg
2012-06-29 12:45 - 2012-06-29 12:45 - 00000000 ____A C:\Windows\setuperr.log
2012-06-29 10:13 - 2012-06-29 10:19 - 00017408 ____A C:\Users\Tony\Downloads\BILLING SUMMARY 6-25 thru 6-29.xls
2012-06-29 09:14 - 2012-06-29 09:16 - 00029696 ____A C:\Users\Tony\Downloads\Client Remit.xls
2012-06-29 06:23 - 2012-07-02 10:55 - 00017920 ____A C:\Users\Tony\Downloads\4. June 25 - 29, 2012.xls
2012-06-28 11:48 - 2012-06-28 11:51 - 00048128 ____A C:\Users\Tony\Downloads\5-2012 Williams Goodhue county.xls
2012-06-28 11:35 - 2012-06-28 11:51 - 00041984 ____A C:\Users\Tony\Downloads\James Williams correction Transportation .xls
2012-06-25 10:22 - 2012-06-25 10:22 - 00000958 ____A C:\Users\Tony\Desktop\A-PDF Split.lnk
2012-06-25 06:13 - 2012-06-25 06:26 - 00017408 ____A C:\Users\Tony\Downloads\3. June 18 - 22, 2012.xls
2012-06-22 05:02 - 2011-10-14 04:35 - 00000338 ____A C:\Windows\Tasks\Regwork.job
2012-06-15 09:28 - 2012-06-15 08:34 - 00035840 ____A C:\Users\Tony\Downloads\Jessica_Billing_6-8-12.xls
2012-06-13 06:24 - 2009-07-13 20:45 - 00302024 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 05:46 - 2011-10-14 03:30 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-13 05:38 - 2012-03-14 12:08 - 00000748 ___AH C:\IPH.PH
2012-06-13 05:37 - 2012-03-14 12:08 - 00001911 ____A C:\Users\Public\Desktop\AIM.lnk
2012-06-11 13:03 - 2012-06-11 13:03 - 00000537 ____A C:\Users\Tony\Desktop\Emdeon.lnk
2012-06-11 09:24 - 2012-06-11 09:24 - 00001032 ____A C:\Users\Tony\Desktop\Danette Billing 2012 - Shortcut.lnk
2012-06-11 08:29 - 2012-05-18 12:08 - 00029184 ____A C:\Users\Tony\Desktop\Jessica Billing 2012.xls
2012-06-11 08:28 - 2012-04-17 09:00 - 00002184 ____A C:\Users\Tony\Desktop\Shared Folder - Shortcut.lnk
2012-06-07 13:31 - 2012-07-05 12:43 - 00002075 ____A C:\Users\Tony\Desktop\wscsvc.reg
2012-06-07 13:05 - 2012-07-05 12:43 - 00120395 ____A C:\Users\Tony\Desktop\bfe.reg
2012-06-07 12:59 - 2012-07-05 12:43 - 00197027 ____A C:\Users\Tony\Desktop\sharedaccess.reg
2012-06-07 12:56 - 2012-07-05 12:43 - 00002380 ____A C:\Users\Tony\Desktop\mpssvc.reg
2012-06-06 05:44 - 2012-06-06 05:44 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2012-06-05 05:33 - 2012-06-05 05:17 - 00002662 ____A C:\Users\Tony\Documents\tonysci.profile
2012-06-05 05:33 - 2012-06-05 05:16 - 00000245 ____A C:\Users\Tony\Documents\iSafeguard.log
2012-06-04 23:37 - 2012-07-05 11:16 - 00256904 ____A (Trend Micro Inc.) C:\Windows\SysWOW64\Drivers\tmcomm.sys
2012-06-02 14:19 - 2012-06-22 05:13 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-22 05:13 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-22 05:13 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-22 05:13 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-22 05:13 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-22 05:13 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-22 05:13 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 12:19 - 2012-06-22 05:12 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:15 - 2012-06-22 05:12 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-23 09:03 - 2012-05-23 09:03 - 00002659 ____A C:\Users\Public\Desktop\PSS(admin).lnk
2012-05-23 09:03 - 2012-05-23 09:03 - 00002617 ____A C:\Users\Public\Desktop\PSS.lnk
2012-05-23 08:50 - 2012-05-23 08:50 - 00000153 ____A C:\Users\Tony\RmDvrUserCfg85.ini
2012-05-18 05:27 - 2012-05-18 05:31 - 00063488 ____A C:\Users\Tony\Downloads\5-18-12 WHO IS IN GROUP new.xls
2012-05-17 18:47 - 2012-06-13 05:39 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-13 05:38 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-13 05:39 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-13 05:39 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-13 05:39 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-13 05:39 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-13 05:39 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-13 05:39 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-13 05:39 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-13 05:39 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-13 05:39 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-13 05:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-13 05:39 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-13 05:39 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-13 05:39 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-13 05:38 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-13 05:39 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-13 05:39 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-13 05:39 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-13 05:39 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-13 05:39 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-13 05:39 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-13 05:39 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-13 05:39 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-13 05:39 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-13 05:39 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-13 05:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-13 05:39 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 17:32 - 2012-06-13 00:47 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-09 05:45 - 2012-05-09 05:45 - 00001436 ____A C:\Users\Tony\Desktop\Tony Cover Sheet Billing Dept - Shortcut.lnk
2012-05-04 10:03 - 2012-04-20 07:30 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk
2012-05-04 03:06 - 2012-06-13 00:47 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 00:47 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 00:47 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-03 08:24 - 2012-05-03 08:24 - 00002969 ____A C:\Users\Tony\Desktop\EasyPrint.lnk
2012-05-03 08:24 - 2012-05-03 08:24 - 00000092 ____A C:\Users\Tony\AppData\Local\fusioncache.dat
2012-05-02 12:52 - 2012-05-02 12:52 - 00000939 ____A C:\Users\Tony\Desktop\A-PDF PDFLabel.lnk
2012-05-02 09:21 - 2010-05-25 12:55 - 00000426 ____A C:\Windows\BRWMARK.INI
2012-04-30 21:40 - 2012-06-13 00:48 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-13 00:47 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 08:34 - 2012-06-05 04:23 - 00002338 ____A C:\Users\Tony\Desktop\PSYCH - Shortcut.lnk
2012-04-25 21:41 - 2012-06-13 00:48 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 00:48 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 00:48 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-25 10:43 - 2012-04-04 08:14 - 00028160 ____A C:\Users\Tony\Desktop\list of clients and groups.xls
2012-04-23 21:37 - 2012-06-13 00:47 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 00:47 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 00:47 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 00:47 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 00:47 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 00:47 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-18 05:53 - 2012-04-18 05:53 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
2012-04-17 05:25 - 2012-04-11 12:14 - 00017920 ____A C:\Users\Tony\Desktop\Tony's TO DO LIST.xls
2012-04-13 06:41 - 2012-04-13 06:35 - 257265978 ____A C:\Users\Tony\Documents\Matterhorn Bobsleds in HD both tracks at Disneyland.mp4
2012-04-11 12:14 - 2012-04-11 12:14 - 00017920 ____A C:\Users\Tony\Downloads\Tony's TO DO LIST.xls
2012-04-09 04:27 - 2012-04-03 11:11 - 00064648 ____A C:\Users\Tony\AppData\Local\GDIPFONTCACHEV1.DAT
ZeroAccess:
C:\Windows\Installer\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}
C:\Windows\Installer\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\@
C:\Windows\Installer\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\L
C:\Windows\Installer\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\U
C:\Windows\Installer\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\U\00000001.@
C:\Windows\Installer\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\U\80000000.@
C:\Windows\Installer\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\U\800000cb.@
ZeroAccess:
C:\Users\Tony\AppData\Local\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}
C:\Users\Tony\AppData\Local\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\@
C:\Users\Tony\AppData\Local\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\L
C:\Users\Tony\AppData\Local\{1a868d5d-dd53-d8ab-fbb9-f391889fbdb9}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 36%
Total physical RAM: 2013.05 MB
Available physical RAM: 1281.43 MB
Total Pagefile: 2013.05 MB
Available Pagefile: 1267.07 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:288.19 GB) (Free:248.25 GB) NTFS