Like many I also have a similar infection with Eset constantly showing pop ups about blocked Sirefef and a scan saying there's a Patched.B.gen trojan.
I've read a few threads and noticed that a Farbar scan is required, so here are the results.
Thank you very much for your help!
Scan result of Farbar Recovery Scan Tool Version: 16-07-2012 02
Ran by SYSTEM at 18-07-2012 11:57:29
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [499608 2011-03-15] (Adobe Systems Incorporated)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-11-15] (IDT, Inc.)
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [2918656 2011-01-12] (ESET)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [336384 2011-04-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [94264 2011-02-15] (Hewlett-Packard Development Company L.P.)
HKLM-x32\...\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [87336 2010-02-02] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2011-01-25] (cyberlink)
HKLM-x32\...\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-09] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [35736 2012-04-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-03-16] (EasyBits Software AS)
HKLM-x32\...\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [318520 2011-01-27] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
HKLM-x32\...\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup [305088 2011-04-25] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\adode13\...\Run: [Google Update] "C:\Users\adode13\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-08-28] (Google Inc.)
HKU\adode13\...\Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe" [495616 2007-09-02] ()
HKU\adode13\...\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\adode13\...\Run: [AdobeBridge] [x]
HKU\adode13\...\Run: [cacaoweb] "C:\Users\adode13\AppData\Roaming\cacaoweb\cacaoweb.exe" -noplayer [429056 2012-07-11] ()
HKU\adode13\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2741616 2011-03-04] (Hewlett-Packard Company)
HKU\adode13\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKLM-x32\...\Runonce: [SpybotDeletingA4376] command.com /c del "C:\Users\adode13\AppData\Roaming\svchost.exe" [x]
HKLM-x32\...\Runonce: [SpybotDeletingC7167] cmd.exe /c del "C:\Users\adode13\AppData\Roaming\svchost.exe" [x]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
==================== Services (Whitelisted) ======
2 CLKMSVC10_38F51D56; "C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe" /svc [241648 2011-01-25] (CyberLink)
3 EhttpSrv; "C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe" [42360 2011-01-12] (ESET)
2 ekrn; "C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe" [810144 2011-01-12] (ESET)
2 Giraffic; C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe --service [2232504 2012-07-02] (Giraffic)
3 hpCMSrv; "C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe" [1071160 2011-02-15] (Hewlett-Packard Development Company L.P.)
2 IsaMonitor; C:\Program Files (x86)\Asistente Infinitum\IsaMonitor.exe [185856 2008-07-23] (Fine Point Technologies, Inc.)
2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2011-10-09] ()
2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
========================== Drivers (Whitelisted) =============
1 ctxusbm; C:\Windows\System32\Drivers\ctxusbm.sys [87600 2011-04-25] (Citrix Systems, Inc.)
1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [270912 2011-08-28] (DT Soft Ltd)
2 eamonm; C:\Windows\System32\Drivers\eamonm.sys [170640 2010-12-21] (ESET)
1 ehdrv; C:\Windows\System32\Drivers\ehdrv.sys [141264 2010-12-21] (ESET)
2 epfwwfpr; C:\Windows\System32\Drivers\epfwwfpr.sys [125296 2010-12-21] (ESET)
3 NSNDIS5; \??\C:\Windows\system32\NSNDIS5.SYS [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-18 09:44 - 2012-07-18 09:44 - 01437107 ____A (Farbar) C:\Users\adode13\Desktop\FRST64.exe
2012-07-18 08:53 - 2012-07-18 08:53 - 00000000 ____D C:\Program Files (x86)\Windows Resource Kits
2012-07-18 08:34 - 2012-07-18 08:34 - 00000000 ____D C:\Users\All Users\ESET
2012-07-18 08:34 - 2012-07-18 08:34 - 00000000 ____D C:\Program Files\ESET
2012-07-17 20:44 - 2012-07-17 20:44 - 00000000 ____D C:\Users\adode13\AppData\Local\{7535CF12-162A-4FCA-B9EC-9BF3B78B0BC2}
2012-07-17 09:13 - 2012-07-17 09:26 - 127039024 ____A C:\Users\adode13\Downloads\nanoir.rar
2012-07-17 09:13 - 2012-07-17 09:25 - 35600626 ____A C:\Users\adode13\Downloads\GRETEL_-_Kessei_Kinen_Ongenshuu_(single)_by_kumika.rar
2012-07-17 09:13 - 2012-07-17 09:22 - 64912332 ____A C:\Users\adode13\Downloads\???????.zip
2012-07-17 08:44 - 2012-07-17 08:44 - 00000000 ____D C:\Users\adode13\AppData\Local\{9486025A-74DD-4BAD-B3CA-5398371F2D75}
2012-07-16 20:43 - 2012-07-16 20:44 - 00000000 ____D C:\Users\adode13\AppData\Local\{519C535B-63A0-480C-9619-6C0A6B13C1F7}
2012-07-16 08:43 - 2012-07-17 20:44 - 00000000 ____D C:\Users\adode13\AppData\Local\{FB61B02C-4852-4169-8FD3-C16D98F34B13}
2012-07-16 08:43 - 2012-07-16 08:43 - 00000000 ____D C:\Users\adode13\AppData\Local\{0F52EBD8-F522-41C6-9CE5-6FEC345E528A}
2012-07-15 19:54 - 2012-07-15 19:54 - 00000000 ____D C:\Users\adode13\AppData\Local\{628F4176-E877-4804-9644-00C831439FA9}
2012-07-15 13:48 - 2012-07-15 14:21 - 441375029 ____A C:\Users\adode13\Downloads\[4ls]_katawa_shoujo_[windows][C3798628].exe
2012-07-15 07:54 - 2012-07-15 07:54 - 00000000 ____D C:\Users\adode13\AppData\Local\{409D43F6-0E5D-4A33-BB9F-E75ECD63B8EE}
2012-07-14 19:53 - 2012-07-14 19:54 - 00000000 ____D C:\Users\adode13\AppData\Local\{6BD0808A-70EF-411A-9A47-4277A2C1600E}
2012-07-14 12:17 - 2012-07-18 08:36 - 00000000 ____D C:\Users\adode13\Desktop\Gok
2012-07-14 08:01 - 2012-07-14 08:02 - 27296862 ____A C:\Users\adode13\Downloads\[2012.07.04] BugLug - KILLER×KILLER×KILLER.rar
2012-07-14 07:52 - 2012-07-15 19:54 - 00000000 ____D C:\Users\adode13\AppData\Local\{C33D4F02-2CEA-42A8-80EF-C84C70D98402}
2012-07-14 07:52 - 2012-07-14 07:53 - 00000000 ____D C:\Users\adode13\AppData\Local\{4A2A7961-A2F6-4066-8098-DB39520F5A64}
2012-07-13 12:58 - 2012-07-13 13:00 - 14893793 ____A C:\Users\adode13\Downloads\GnT_Hamada_McDonalds.flv
2012-07-13 12:56 - 2012-07-13 12:59 - 46745288 ____A C:\Users\adode13\Downloads\DT_Manzai_Mounting_Sub.avi
2012-07-13 10:03 - 2012-07-13 10:03 - 00000000 ____D C:\Users\adode13\AppData\Local\{EFBDC62D-9C71-4103-A1FC-8BB58FBFC4A8}
2012-07-13 10:02 - 2012-07-13 10:03 - 00000000 ____D C:\Users\adode13\AppData\Local\{969AEDB5-B639-4875-9F76-34817D55D1A8}
2012-07-12 22:04 - 2012-07-12 22:04 - 00000946 ____A C:\Users\adode13\Desktop\Dolphin.lnk
2012-07-12 21:32 - 2011-06-23 22:25 - 00000000 ___AD C:\Users\adode13\Downloads\dolphin-3.0-win64
2012-07-12 10:36 - 2012-07-12 10:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{AA67E3B1-FC95-427E-B5B8-6E7EF65DDC32}
2012-07-12 10:36 - 2012-07-12 10:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{510FEC62-2A79-480E-AB8F-E3DA2678C088}
2012-07-12 10:24 - 2012-07-12 10:30 - 91139450 ____A C:\Users\adode13\Downloads\Reprise.zip
2012-07-12 09:14 - 2012-07-12 09:14 - 09226440 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-07-12 01:10 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-12 01:01 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-12 01:01 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-12 01:01 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-12 01:01 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-12 01:01 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-12 01:01 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-12 01:01 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-12 01:01 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-12 01:01 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-12 01:01 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-12 01:01 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-12 01:01 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-12 01:01 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-12 01:01 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-12 01:01 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-12 01:01 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-12 01:01 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-12 01:01 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-12 01:01 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-12 01:01 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-12 01:01 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-12 01:01 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-12 01:01 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-12 01:01 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-12 01:01 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-12 01:01 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-12 01:01 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-12 01:01 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 22:36 - 2012-07-11 22:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{72A7231C-394C-4155-98B2-C08304E70063}
2012-07-11 22:36 - 2012-07-11 22:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{02F650BA-E171-46A8-B320-48E3E3B691C0}
2012-07-11 16:19 - 2012-07-11 16:19 - 00248730 ____A C:\Users\adode13\Downloads\individigital.zip
2012-07-11 16:19 - 2012-07-11 16:19 - 00008389 ____A C:\Users\adode13\Downloads\dominik.zip
2012-07-11 14:32 - 2012-07-11 14:34 - 15634214 ____A C:\Users\adode13\Downloads\?????????.zip
2012-07-11 14:32 - 2012-07-11 14:34 - 08955362 ____A C:\Users\adode13\Downloads\03 my ugly gene.m4a
2012-07-11 14:32 - 2012-07-11 14:33 - 09744709 ____A C:\Users\adode13\Downloads\02 Fear Dance.m4a
2012-07-11 14:32 - 2012-07-11 14:33 - 09557049 ____A C:\Users\adode13\Downloads\01 ?-kHz.m4a
2012-07-11 14:30 - 2012-07-11 14:30 - 06222779 ____A C:\Users\adode13\Downloads\lakugaki.mp3.zip
2012-07-11 10:35 - 2012-07-11 10:35 - 00000000 ____D C:\Users\adode13\AppData\Local\{E6C4FC21-2713-4F15-89D3-162D1DC46A9B}
2012-07-11 10:35 - 2012-07-11 10:35 - 00000000 ____D C:\Users\adode13\AppData\Local\{4274FC9B-46F9-4B68-984E-762B46820AD3}
2012-07-11 04:04 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 04:04 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 04:04 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 04:04 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 04:04 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 04:04 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 04:04 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 04:04 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 04:04 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 04:04 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 04:04 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 04:04 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 04:04 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 04:04 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 04:04 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 04:04 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 04:04 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 04:04 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 04:04 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-10 22:35 - 2012-07-10 22:35 - 00000000 ____D C:\Users\adode13\AppData\Local\{EE489028-348A-4020-8F01-551B7B289706}
2012-07-10 10:34 - 2012-07-10 10:34 - 00000000 ____D C:\Users\adode13\AppData\Local\{02410FEE-D1EF-4395-A362-C713AFBAFE2C}
2012-07-09 22:33 - 2012-07-09 22:34 - 00000000 ____D C:\Users\adode13\AppData\Local\{898A50E2-8EB4-4218-A623-EA894655D161}
2012-07-09 17:24 - 2012-07-09 17:39 - 123929747 ____A C:\Users\adode13\Downloads\101.rar
2012-07-09 10:33 - 2012-07-10 22:35 - 00000000 ____D C:\Users\adode13\AppData\Local\{7CDA8AF8-65AE-4977-8E3B-3435C4ED9C80}
2012-07-09 10:33 - 2012-07-09 10:33 - 00000000 ____D C:\Users\adode13\AppData\Local\{2A6F18FE-497F-47E1-A1B8-7B9642E901FB}
2012-07-08 22:32 - 2012-07-08 22:32 - 00079819 ____A C:\Users\adode13\Downloads\minecraftia.zip
2012-07-08 22:32 - 2012-07-08 22:32 - 00034009 ____A C:\Users\adode13\Downloads\v5prophit_cell.zip
2012-07-08 22:19 - 2012-07-08 22:19 - 00000000 ____D C:\Users\adode13\AppData\Local\{70E9745B-8A80-4AE9-A275-D6F3829A98C7}
2012-07-08 10:18 - 2012-07-08 22:19 - 00000000 ____D C:\Users\adode13\AppData\Local\{67A35010-2DA5-4661-98F4-17ABDF80CF1B}
2012-07-08 10:18 - 2012-07-08 10:18 - 00000000 ____D C:\Users\adode13\AppData\Local\{0028E128-7AD9-481C-A3BC-BAFDB86844AD}
2012-07-07 22:02 - 2012-07-07 22:02 - 00000000 ____D C:\Users\adode13\AppData\Local\{B5C2C1CA-D0D9-4534-B297-F63A56728580}
2012-07-07 10:01 - 2012-07-07 22:02 - 00000000 ____D C:\Users\adode13\AppData\Local\{CFCD9DE1-8415-4C21-A1FD-ADBA8F3FF04E}
2012-07-07 10:01 - 2012-07-07 10:02 - 00000000 ____D C:\Users\adode13\AppData\Local\{CF5A41A3-71BC-4B11-9853-B6960B15A082}
2012-07-06 23:17 - 2012-07-09 12:55 - 00000000 ____D C:\Users\adode13\Desktop\Ads
2012-07-06 11:28 - 2012-07-06 11:28 - 00000000 ____D C:\Users\adode13\AppData\Local\{42DD3F8D-A46A-47AF-94C9-E0AC3AD34678}
2012-07-06 11:28 - 2012-07-06 11:28 - 00000000 ____D C:\Users\adode13\AppData\Local\{2E820539-7FE6-466D-ACF4-1682D13A74CA}
2012-07-05 19:16 - 2012-07-05 19:20 - 28407468 ____A C:\Users\adode13\Downloads\MSInc SP.rar
2012-07-05 15:22 - 2012-07-05 15:22 - 00027616 ____A C:\Users\adode13\Downloads\stroke.zip
2012-07-05 15:19 - 2012-07-05 15:19 - 00428453 ____A C:\Users\adode13\Downloads\Quicksand.zip
2012-07-05 15:19 - 2012-07-05 15:19 - 00236384 ____A C:\Users\adode13\Downloads\billy-argel_new-garden.zip
2012-07-05 15:19 - 2012-07-05 15:19 - 00159932 ____A C:\Users\adode13\Downloads\TitilliumText.zip
2012-07-05 15:18 - 2012-07-05 15:18 - 00484995 ____A C:\Users\adode13\Downloads\comfortaa___font_by_aajohan-d1qr019.zip
2012-07-05 15:18 - 2012-07-05 15:18 - 00241718 ____A C:\Users\adode13\Downloads\Walkway.zip
2012-07-05 15:17 - 2012-07-05 15:17 - 00064828 ____A C:\Users\adode13\Downloads\CircleD_Font_by_CrazyForMusic.ttf
2012-07-05 15:17 - 2012-07-05 15:17 - 00011850 ____A C:\Users\adode13\Downloads\steiner.zip
2012-07-05 14:54 - 2012-07-05 14:54 - 00075105 ____A C:\Users\adode13\Downloads\Existence-Light.zip
2012-07-05 08:41 - 2012-07-05 08:41 - 00000000 ____D C:\Users\adode13\AppData\Local\{E2C166D2-3A1E-4E08-AF92-1B3A939B753E}
2012-07-05 08:40 - 2012-07-05 08:41 - 00000000 ____D C:\Users\adode13\AppData\Local\{05DD9EA8-2ABE-42C1-BB03-B342EB1A60D0}
2012-07-04 18:19 - 2012-07-04 18:39 - 45035764 ____A C:\Users\adode13\Downloads\[Mini] coldrain - THROUGH CLARITY [2012.07.04].rar
2012-07-04 18:18 - 2012-07-04 18:28 - 52676078 ____A C:\Users\adode13\Downloads\[2012.06.06] NEW BREED - THE PIONEERS OF SENSATION.rar
2012-07-04 18:18 - 2012-07-04 18:25 - 26409419 ____A C:\Users\adode13\Downloads\v-r.rar
2012-07-04 10:49 - 2012-07-04 10:49 - 00000000 ____D C:\Users\adode13\AppData\Local\{922CB157-A5AF-43EC-927D-F57F5CF3E2F0}
2012-07-03 20:39 - 2012-07-03 20:39 - 00000000 ____D C:\Users\adode13\AppData\Local\{492F3854-FE40-47F3-88E3-62198D7B902C}
2012-07-03 20:39 - 2012-07-03 20:39 - 00000000 ____D C:\Users\adode13\AppData\Local\{2420DB70-92C0-4412-9FB7-3769DC54CDD4}
2012-07-03 08:38 - 2012-07-03 08:38 - 00000000 ____D C:\Users\adode13\AppData\Local\{B1F7996B-282C-41B6-B9DF-CEF5F56CD5C0}
2012-07-03 08:38 - 2012-07-03 08:38 - 00000000 ____D C:\Users\adode13\AppData\Local\{08EF80A3-0B7D-4048-86BC-10A574380B1E}
2012-07-02 22:45 - 2012-07-02 22:45 - 00000000 ____D C:\Users\adode13\AppData\Roaming\Opera
2012-07-02 22:45 - 2012-07-02 22:45 - 00000000 ____D C:\Users\adode13\AppData\Local\Opera
2012-07-02 22:45 - 2012-07-02 22:45 - 00000000 ____D C:\Program Files (x86)\Opera
2012-07-02 20:36 - 2012-07-02 20:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{6231A1CE-0458-4590-808A-BB66E144EB78}
2012-07-02 08:36 - 2012-07-02 20:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{286E2FEB-BD4D-47C4-94C8-1CC8C4168C9C}
2012-07-02 08:36 - 2012-07-02 08:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{9884E34A-4ABF-4022-A7DC-D392C3182444}
2012-06-30 21:44 - 2012-06-30 21:44 - 00000000 ____D C:\Users\adode13\AppData\Local\{EB0865DF-14B0-4C91-8235-F3539C73434B}
2012-06-30 09:44 - 2012-06-30 09:44 - 00000000 ____D C:\Users\adode13\AppData\Local\{A0777327-6B78-42A5-ADA6-01A27F8B82D9}
2012-06-30 09:43 - 2012-06-30 21:44 - 00000000 ____D C:\Users\adode13\AppData\Local\{897D7D20-9013-4F2D-B9E9-93A7F793C926}
2012-06-29 21:43 - 2012-06-29 21:43 - 00000000 ____D C:\Users\adode13\AppData\Local\{F3DF2949-2B7E-4B10-A202-6B856E779AD3}
2012-06-29 09:43 - 2012-06-29 09:43 - 00000000 ____D C:\Users\adode13\AppData\Local\{C284CD7C-10F6-4805-A9F8-5F0DC5857801}
2012-06-29 09:42 - 2012-06-29 21:43 - 00000000 ____D C:\Users\adode13\AppData\Local\{6A55338B-F61E-446B-ABD1-274E758A0EA3}
2012-06-28 08:33 - 2012-06-28 08:34 - 00000000 ____D C:\Users\adode13\AppData\Local\{0E3D910A-5B00-44F4-AC5F-E372660AF93E}
2012-06-28 08:33 - 2012-06-28 08:33 - 00000000 ____D C:\Users\adode13\AppData\Local\{7E9356DC-E22C-48B1-8472-09BDD7015426}
2012-06-27 14:36 - 2012-06-27 14:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{4E0BA21F-0E65-43BB-B6FC-0C5CC46E5296}
2012-06-27 14:35 - 2012-06-27 14:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{3A0D4272-CAD4-4E3C-B379-0FC8E00123C9}
2012-06-27 09:03 - 2012-06-27 09:03 - 00000000 ____D C:\Users\adode13\AppData\Local\{F0096238-00A3-4C92-97B7-D48C301BE956}
2012-06-26 09:26 - 2012-06-26 09:26 - 00000000 ____D C:\Users\adode13\AppData\Local\{2DFB6843-EB8C-4D01-8845-C8CA36A04DBD}
2012-06-26 09:25 - 2012-06-26 09:25 - 00000000 ____D C:\Users\adode13\AppData\Local\{DA1FE535-F10F-4CA2-B44D-8615203E9561}
2012-06-25 19:52 - 2012-06-25 19:52 - 00000000 ____D C:\Users\adode13\AppData\Local\{367C03F3-4244-44CB-AC4D-1D4A842CF1AB}
2012-06-25 07:51 - 2012-06-25 19:52 - 00000000 ____D C:\Users\adode13\AppData\Local\{EA7C4460-9BCC-40FF-869B-748F5B2884D9}
2012-06-25 07:51 - 2012-06-25 07:51 - 00000000 ____D C:\Users\adode13\AppData\Local\{887B10BC-6787-41A6-871E-0A73288F4F22}
2012-06-23 10:16 - 2012-06-23 10:16 - 00000000 ____D C:\Users\adode13\AppData\Local\{6322504E-78C3-4269-95F0-F6551087AF18}
2012-06-23 10:15 - 2012-06-23 10:16 - 00000000 ____D C:\Users\adode13\AppData\Local\{735A210E-B474-4C84-9B97-674355253166}
2012-06-23 09:52 - 2012-06-23 09:52 - 00000000 ____D C:\Users\adode13\AppData\Local\{C6287180-79DD-4770-AC6B-A289CFE4D9A0}
2012-06-22 11:00 - 2012-06-22 11:00 - 00000000 ____D C:\Users\adode13\AppData\Local\{B6F198D5-A32E-4ACB-8035-14D1F67C55AF}
2012-06-22 10:59 - 2012-06-22 11:00 - 00000000 ____D C:\Users\adode13\AppData\Local\{57587ACB-B15D-40B4-896A-AFFA9347D118}
2012-06-21 20:03 - 2012-06-21 20:03 - 00000000 ____D C:\Users\adode13\AppData\Local\{289792F2-9C31-47C6-A514-8F4686B1E8ED}
2012-06-21 08:03 - 2012-06-21 08:03 - 00000000 ____D C:\Users\adode13\AppData\Local\{8B55CA86-05B3-4EAC-A2BB-A5CA5064A4CB}
2012-06-21 08:02 - 2012-06-21 20:03 - 00000000 ____D C:\Users\adode13\AppData\Local\{D6E1738D-AAC6-4C69-B784-B3646ED15DCB}
2012-06-20 14:23 - 2012-06-20 14:23 - 00000000 ____D C:\Users\adode13\Downloads\AngleWheels_HMS
2012-06-20 10:27 - 2012-06-20 10:27 - 00000000 ____D C:\Users\adode13\AppData\Local\{E19C8AE8-96B6-4A9A-B37A-6A3CA6F9620D}
2012-06-20 10:27 - 2012-06-20 10:27 - 00000000 ____D C:\Users\adode13\AppData\Local\{C51143C1-B189-436D-9EC2-4FB9E4DB479B}
2012-06-19 21:16 - 2012-06-19 21:16 - 00000000 ____D C:\Users\adode13\AppData\Local\{527C13C7-5BCF-4ECC-9236-252A5CE9A9A3}
2012-06-19 09:16 - 2012-06-19 09:16 - 00000000 ____D C:\Users\adode13\AppData\Local\{28679318-9B3F-445E-8C9E-CD1C115A28AD}
2012-06-19 09:15 - 2012-06-19 21:16 - 00000000 ____D C:\Users\adode13\AppData\Local\{ADD2D68C-8ED0-4CA8-A7C3-966A7395E41F}
2012-06-19 09:15 - 2012-06-19 09:15 - 00000000 ____D C:\Windows\en
2012-06-19 09:12 - 2012-03-08 16:40 - 00048488 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fssfltr.sys
2012-06-19 09:09 - 2012-06-19 09:09 - 00000000 ____D C:\Users\adode13\AppData\Local\{40B286B1-7756-4658-BCC4-802584E24B45}
2012-06-19 09:08 - 2012-06-19 09:09 - 00000000 ____D C:\Users\adode13\AppData\Local\{B588838F-2FB5-4D37-B44A-99B8522432FD}
2012-06-19 08:38 - 2012-06-19 08:38 - 00000000 ____D C:\Users\adode13\AppData\Local\{448E661A-2D36-4BC1-8945-675BA2E9C505}
2012-06-19 08:37 - 2012-06-19 08:38 - 00000000 ____D C:\Users\adode13\AppData\Local\{41874DBA-6FD0-480C-B7BF-B0E546CF99EC}
2012-06-18 18:55 - 2012-06-18 18:53 - 02114362 ___RA C:\Users\adode13\Documents\Technologic___Brush_Pack_by_NextViewDesigns.abr
2012-06-18 18:55 - 2012-06-18 18:53 - 00467206 ___RA C:\Users\adode13\Documents\Tech_Brushes_01_by_Jaaaiiro.abr
2012-06-18 17:30 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-18 17:30 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-18 17:30 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-18 17:30 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-18 17:29 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-18 17:29 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-18 17:29 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-18 17:29 - 2012-06-02 13:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-18 17:29 - 2012-06-02 13:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-18 07:14 - 2012-06-18 07:14 - 00000000 ____D C:\Users\adode13\AppData\Local\{7B8FCDCA-7290-42F7-95DF-4274942813C3}
============ 3 Months Modified Files ========================
2012-07-18 09:51 - 2009-07-13 21:13 - 00779092 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-18 09:47 - 2012-01-24 05:01 - 00000935 ____A C:\Windows\wininit.ini
2012-07-18 09:47 - 2011-08-28 19:06 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1933306683-895702514-590770892-1001UA.job
2012-07-18 09:44 - 2012-07-18 09:44 - 01437107 ____A (Farbar) C:\Users\adode13\Desktop\FRST64.exe
2012-07-18 09:14 - 2012-04-04 07:30 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-18 09:02 - 2011-08-06 19:14 - 01292748 ____A C:\Windows\WindowsUpdate.log
2012-07-18 09:01 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-18 09:01 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-18 08:54 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-18 08:54 - 2009-07-13 20:51 - 00098548 ____A C:\Windows\setupact.log
2012-07-18 07:42 - 2012-02-06 12:23 - 00000340 ____A C:\Windows\Tasks\HPCeeScheduleForadode13.job
2012-07-17 16:47 - 2011-08-28 19:06 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1933306683-895702514-590770892-1001Core.job
2012-07-17 09:26 - 2012-07-17 09:13 - 127039024 ____A C:\Users\adode13\Downloads\nanoir.rar
2012-07-17 09:25 - 2012-07-17 09:13 - 35600626 ____A C:\Users\adode13\Downloads\GRETEL_-_Kessei_Kinen_Ongenshuu_(single)_by_kumika.rar
2012-07-17 09:22 - 2012-07-17 09:13 - 64912332 ____A C:\Users\adode13\Downloads\???????.zip
2012-07-16 09:12 - 2011-11-21 13:28 - 00000000 ____A C:\Windows\System32\HP_ActiveX_Patch_NOT_DETECTED.txt
2012-07-16 09:12 - 2011-08-29 19:09 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-07-16 08:40 - 2009-07-13 21:08 - 00032540 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-15 14:21 - 2012-07-15 13:48 - 441375029 ____A C:\Users\adode13\Downloads\[4ls]_katawa_shoujo_[windows][C3798628].exe
2012-07-14 08:02 - 2012-07-14 08:01 - 27296862 ____A C:\Users\adode13\Downloads\[2012.07.04] BugLug - KILLER×KILLER×KILLER.rar
2012-07-13 13:00 - 2012-07-13 12:58 - 14893793 ____A C:\Users\adode13\Downloads\GnT_Hamada_McDonalds.flv
2012-07-13 12:59 - 2012-07-13 12:56 - 46745288 ____A C:\Users\adode13\Downloads\DT_Manzai_Mounting_Sub.avi
2012-07-12 22:04 - 2012-07-12 22:04 - 00000946 ____A C:\Users\adode13\Desktop\Dolphin.lnk
2012-07-12 10:30 - 2012-07-12 10:24 - 91139450 ____A C:\Users\adode13\Downloads\Reprise.zip
2012-07-12 09:14 - 2012-07-12 09:14 - 09226440 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-07-12 09:14 - 2012-04-04 07:30 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-12 09:14 - 2011-08-28 19:10 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-12 09:04 - 2009-07-13 20:45 - 05121576 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-12 01:09 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-07-12 01:03 - 2011-08-28 13:33 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-11 16:19 - 2012-07-11 16:19 - 00248730 ____A C:\Users\adode13\Downloads\individigital.zip
2012-07-11 16:19 - 2012-07-11 16:19 - 00008389 ____A C:\Users\adode13\Downloads\dominik.zip
2012-07-11 14:34 - 2012-07-11 14:32 - 15634214 ____A C:\Users\adode13\Downloads\?????????.zip
2012-07-11 14:34 - 2012-07-11 14:32 - 08955362 ____A C:\Users\adode13\Downloads\03 my ugly gene.m4a
2012-07-11 14:33 - 2012-07-11 14:32 - 09744709 ____A C:\Users\adode13\Downloads\02 Fear Dance.m4a
2012-07-11 14:33 - 2012-07-11 14:32 - 09557049 ____A C:\Users\adode13\Downloads\01 ?-kHz.m4a
2012-07-11 14:30 - 2012-07-11 14:30 - 06222779 ____A C:\Users\adode13\Downloads\lakugaki.mp3.zip
2012-07-09 17:39 - 2012-07-09 17:24 - 123929747 ____A C:\Users\adode13\Downloads\101.rar
2012-07-08 23:07 - 2011-08-28 18:11 - 00141912 ____A C:\Users\adode13\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-08 22:32 - 2012-07-08 22:32 - 00079819 ____A C:\Users\adode13\Downloads\minecraftia.zip
2012-07-08 22:32 - 2012-07-08 22:32 - 00034009 ____A C:\Users\adode13\Downloads\v5prophit_cell.zip
2012-07-06 23:16 - 2012-04-13 20:45 - 00011595 ____A C:\Users\adode13\Documents\HP POLL1UFA.xlsx
2012-07-06 23:07 - 2012-03-16 18:31 - 00011498 ____A C:\Users\adode13\Documents\HP POLL1.xlsx
2012-07-05 19:20 - 2012-07-05 19:16 - 28407468 ____A C:\Users\adode13\Downloads\MSInc SP.rar
2012-07-05 15:22 - 2012-07-05 15:22 - 00027616 ____A C:\Users\adode13\Downloads\stroke.zip
2012-07-05 15:19 - 2012-07-05 15:19 - 00428453 ____A C:\Users\adode13\Downloads\Quicksand.zip
2012-07-05 15:19 - 2012-07-05 15:19 - 00236384 ____A C:\Users\adode13\Downloads\billy-argel_new-garden.zip
2012-07-05 15:19 - 2012-07-05 15:19 - 00159932 ____A C:\Users\adode13\Downloads\TitilliumText.zip
2012-07-05 15:18 - 2012-07-05 15:18 - 00484995 ____A C:\Users\adode13\Downloads\comfortaa___font_by_aajohan-d1qr019.zip
2012-07-05 15:18 - 2012-07-05 15:18 - 00241718 ____A C:\Users\adode13\Downloads\Walkway.zip
2012-07-05 15:17 - 2012-07-05 15:17 - 00064828 ____A C:\Users\adode13\Downloads\CircleD_Font_by_CrazyForMusic.ttf
2012-07-05 15:17 - 2012-07-05 15:17 - 00011850 ____A C:\Users\adode13\Downloads\steiner.zip
2012-07-05 14:54 - 2012-07-05 14:54 - 00075105 ____A C:\Users\adode13\Downloads\Existence-Light.zip
2012-07-04 18:39 - 2012-07-04 18:19 - 45035764 ____A C:\Users\adode13\Downloads\[Mini] coldrain - THROUGH CLARITY [2012.07.04].rar
2012-07-04 18:28 - 2012-07-04 18:18 - 52676078 ____A C:\Users\adode13\Downloads\[2012.06.06] NEW BREED - THE PIONEERS OF SENSATION.rar
2012-07-04 18:25 - 2012-07-04 18:18 - 26409419 ____A C:\Users\adode13\Downloads\v-r.rar
2012-06-22 08:34 - 2011-09-02 21:11 - 00000132 ____A C:\Users\adode13\AppData\Roaming\Adobe PNG Format CS5 Prefs
2012-06-19 09:11 - 2011-04-28 16:32 - 00027823 ____A C:\Windows\DirectX.log
2012-06-18 18:53 - 2012-06-18 18:55 - 02114362 ___RA C:\Users\adode13\Documents\Technologic___Brush_Pack_by_NextViewDesigns.abr
2012-06-18 18:53 - 2012-06-18 18:55 - 00467206 ___RA C:\Users\adode13\Documents\Tech_Brushes_01_by_Jaaaiiro.abr
2012-06-11 19:08 - 2012-07-12 01:10 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-11 04:04 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 04:04 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-07 07:05 - 2012-06-07 07:05 - 00011912 ____A C:\Users\adode13\Documents\Original CSS Lightobx Evolution.txt
2012-06-05 22:06 - 2012-07-11 04:04 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 04:04 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 04:04 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 04:04 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 04:04 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 04:04 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-04 22:28 - 2012-06-04 22:28 - 00000712 ____A C:\Users\adode13\Documents\Dandy.txt
2012-06-02 14:19 - 2012-06-18 17:30 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-18 17:30 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-18 17:30 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-18 17:29 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-18 17:29 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-18 17:30 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-18 17:29 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 13:19 - 2012-06-18 17:29 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 13:15 - 2012-06-18 17:29 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-12 01:01 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-12 01:01 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-12 01:01 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-12 01:01 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-12 01:01 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-12 01:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-12 01:01 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-12 01:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-12 01:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-12 01:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-12 01:01 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-12 01:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-12 01:01 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-12 01:01 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-12 01:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-12 01:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-12 01:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-12 01:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-12 01:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-12 01:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-12 01:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-12 01:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-12 01:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-12 01:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-12 01:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-12 01:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-12 01:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-12 01:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-11 04:04 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 04:04 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 04:04 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 04:04 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 04:04 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 04:04 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 04:04 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 04:04 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 04:04 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-19 01:31 - 2012-06-06 01:23 - 1272571834 ____A C:\Users\adode13\Downloads\GakiNoTsukai_Airport_Batsu_2011_subbed.avi
2012-05-12 07:38 - 2010-11-20 19:47 - 00488190 ____A C:\Windows\PFRO.log
2012-05-09 18:58 - 2011-08-29 20:34 - 00443239 ___RA C:\Windows\System32\Drivers\etc\hosts.20120718-113242.backup
2012-05-04 03:06 - 2012-06-13 02:43 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 03:00 - 2012-06-13 19:32 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-05-04 02:03 - 2012-06-13 02:43 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 02:43 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-04 01:59 - 2012-06-13 19:32 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-04-30 21:40 - 2012-06-13 02:43 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-13 02:43 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-13 02:43 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 02:43 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 02:43 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-24 19:33 - 2012-04-24 15:38 - 00733575 ____A C:\Users\adode13\Documents\Andrews.pptx
2012-04-23 21:37 - 2012-06-13 02:42 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 02:42 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 02:42 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 21:03 - 2012-04-23 21:03 - 03523584 ____A C:\Users\adode13\Documents\Distribution%20and%20Supply%20Chain%20Management.ppt
2012-04-23 21:02 - 2012-04-23 21:02 - 01296896 ____A C:\Users\adode13\Documents\PRICING%20STRATEGIES%20AND%20TACTICS.ppt
2012-04-23 20:36 - 2012-06-13 02:42 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 02:42 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 02:42 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}
C:\Windows\Installer\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\@
C:\Windows\Installer\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\L
C:\Windows\Installer\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\n
C:\Windows\Installer\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\U
C:\Windows\Installer\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\U\00000001.@
C:\Windows\Installer\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\U\800000cb.@
ZeroAccess:
C:\Users\adode13\AppData\Local\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}
C:\Users\adode13\AppData\Local\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\@
C:\Users\adode13\AppData\Local\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\L
C:\Users\adode13\AppData\Local\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\n
C:\Users\adode13\AppData\Local\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 5610.9 MB
Available physical RAM: 4787.34 MB
Total Pagefile: 5609.05 MB
Available Pagefile: 4777.36 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:581.28 GB) (Free:22.39 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (RECOVERY) (Fixed) (Total:14.59 GB) (Free:1.62 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
5 Drive h: (KINGSTON) (Removable) (Total:0.93 GB) (Free:0.24 GB) FAT
6 Drive x: (Boot) (Fixed) (Total:0.25 GB) (Free:0.25 GB) NTFS
7 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 596 GB 0 B
Disk 1 Online 954 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 581 GB 200 MB
Partition 3 Primary 14 GB 581 GB
Partition 4 Primary 103 MB 596 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 199 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 581 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E RECOVERY NTFS Partition 14 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F HP_TOOLS FAT32 Partition 103 MB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 953 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H KINGSTON FAT Removable 953 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-18 04:40
======================= End Of Log ==========================
I've read a few threads and noticed that a Farbar scan is required, so here are the results.
Thank you very much for your help!
Scan result of Farbar Recovery Scan Tool Version: 16-07-2012 02
Ran by SYSTEM at 18-07-2012 11:57:29
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [499608 2011-03-15] (Adobe Systems Incorporated)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-11-15] (IDT, Inc.)
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [2918656 2011-01-12] (ESET)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [336384 2011-04-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [94264 2011-02-15] (Hewlett-Packard Development Company L.P.)
HKLM-x32\...\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [87336 2010-02-02] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2011-01-25] (cyberlink)
HKLM-x32\...\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-09] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [35736 2012-04-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-03-16] (EasyBits Software AS)
HKLM-x32\...\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [318520 2011-01-27] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
HKLM-x32\...\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup [305088 2011-04-25] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\adode13\...\Run: [Google Update] "C:\Users\adode13\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-08-28] (Google Inc.)
HKU\adode13\...\Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe" [495616 2007-09-02] ()
HKU\adode13\...\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\adode13\...\Run: [AdobeBridge] [x]
HKU\adode13\...\Run: [cacaoweb] "C:\Users\adode13\AppData\Roaming\cacaoweb\cacaoweb.exe" -noplayer [429056 2012-07-11] ()
HKU\adode13\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2741616 2011-03-04] (Hewlett-Packard Company)
HKU\adode13\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKLM-x32\...\Runonce: [SpybotDeletingA4376] command.com /c del "C:\Users\adode13\AppData\Roaming\svchost.exe" [x]
HKLM-x32\...\Runonce: [SpybotDeletingC7167] cmd.exe /c del "C:\Users\adode13\AppData\Roaming\svchost.exe" [x]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
==================== Services (Whitelisted) ======
2 CLKMSVC10_38F51D56; "C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe" /svc [241648 2011-01-25] (CyberLink)
3 EhttpSrv; "C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe" [42360 2011-01-12] (ESET)
2 ekrn; "C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe" [810144 2011-01-12] (ESET)
2 Giraffic; C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe --service [2232504 2012-07-02] (Giraffic)
3 hpCMSrv; "C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe" [1071160 2011-02-15] (Hewlett-Packard Development Company L.P.)
2 IsaMonitor; C:\Program Files (x86)\Asistente Infinitum\IsaMonitor.exe [185856 2008-07-23] (Fine Point Technologies, Inc.)
2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2011-10-09] ()
2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
========================== Drivers (Whitelisted) =============
1 ctxusbm; C:\Windows\System32\Drivers\ctxusbm.sys [87600 2011-04-25] (Citrix Systems, Inc.)
1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [270912 2011-08-28] (DT Soft Ltd)
2 eamonm; C:\Windows\System32\Drivers\eamonm.sys [170640 2010-12-21] (ESET)
1 ehdrv; C:\Windows\System32\Drivers\ehdrv.sys [141264 2010-12-21] (ESET)
2 epfwwfpr; C:\Windows\System32\Drivers\epfwwfpr.sys [125296 2010-12-21] (ESET)
3 NSNDIS5; \??\C:\Windows\system32\NSNDIS5.SYS [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-18 09:44 - 2012-07-18 09:44 - 01437107 ____A (Farbar) C:\Users\adode13\Desktop\FRST64.exe
2012-07-18 08:53 - 2012-07-18 08:53 - 00000000 ____D C:\Program Files (x86)\Windows Resource Kits
2012-07-18 08:34 - 2012-07-18 08:34 - 00000000 ____D C:\Users\All Users\ESET
2012-07-18 08:34 - 2012-07-18 08:34 - 00000000 ____D C:\Program Files\ESET
2012-07-17 20:44 - 2012-07-17 20:44 - 00000000 ____D C:\Users\adode13\AppData\Local\{7535CF12-162A-4FCA-B9EC-9BF3B78B0BC2}
2012-07-17 09:13 - 2012-07-17 09:26 - 127039024 ____A C:\Users\adode13\Downloads\nanoir.rar
2012-07-17 09:13 - 2012-07-17 09:25 - 35600626 ____A C:\Users\adode13\Downloads\GRETEL_-_Kessei_Kinen_Ongenshuu_(single)_by_kumika.rar
2012-07-17 09:13 - 2012-07-17 09:22 - 64912332 ____A C:\Users\adode13\Downloads\???????.zip
2012-07-17 08:44 - 2012-07-17 08:44 - 00000000 ____D C:\Users\adode13\AppData\Local\{9486025A-74DD-4BAD-B3CA-5398371F2D75}
2012-07-16 20:43 - 2012-07-16 20:44 - 00000000 ____D C:\Users\adode13\AppData\Local\{519C535B-63A0-480C-9619-6C0A6B13C1F7}
2012-07-16 08:43 - 2012-07-17 20:44 - 00000000 ____D C:\Users\adode13\AppData\Local\{FB61B02C-4852-4169-8FD3-C16D98F34B13}
2012-07-16 08:43 - 2012-07-16 08:43 - 00000000 ____D C:\Users\adode13\AppData\Local\{0F52EBD8-F522-41C6-9CE5-6FEC345E528A}
2012-07-15 19:54 - 2012-07-15 19:54 - 00000000 ____D C:\Users\adode13\AppData\Local\{628F4176-E877-4804-9644-00C831439FA9}
2012-07-15 13:48 - 2012-07-15 14:21 - 441375029 ____A C:\Users\adode13\Downloads\[4ls]_katawa_shoujo_[windows][C3798628].exe
2012-07-15 07:54 - 2012-07-15 07:54 - 00000000 ____D C:\Users\adode13\AppData\Local\{409D43F6-0E5D-4A33-BB9F-E75ECD63B8EE}
2012-07-14 19:53 - 2012-07-14 19:54 - 00000000 ____D C:\Users\adode13\AppData\Local\{6BD0808A-70EF-411A-9A47-4277A2C1600E}
2012-07-14 12:17 - 2012-07-18 08:36 - 00000000 ____D C:\Users\adode13\Desktop\Gok
2012-07-14 08:01 - 2012-07-14 08:02 - 27296862 ____A C:\Users\adode13\Downloads\[2012.07.04] BugLug - KILLER×KILLER×KILLER.rar
2012-07-14 07:52 - 2012-07-15 19:54 - 00000000 ____D C:\Users\adode13\AppData\Local\{C33D4F02-2CEA-42A8-80EF-C84C70D98402}
2012-07-14 07:52 - 2012-07-14 07:53 - 00000000 ____D C:\Users\adode13\AppData\Local\{4A2A7961-A2F6-4066-8098-DB39520F5A64}
2012-07-13 12:58 - 2012-07-13 13:00 - 14893793 ____A C:\Users\adode13\Downloads\GnT_Hamada_McDonalds.flv
2012-07-13 12:56 - 2012-07-13 12:59 - 46745288 ____A C:\Users\adode13\Downloads\DT_Manzai_Mounting_Sub.avi
2012-07-13 10:03 - 2012-07-13 10:03 - 00000000 ____D C:\Users\adode13\AppData\Local\{EFBDC62D-9C71-4103-A1FC-8BB58FBFC4A8}
2012-07-13 10:02 - 2012-07-13 10:03 - 00000000 ____D C:\Users\adode13\AppData\Local\{969AEDB5-B639-4875-9F76-34817D55D1A8}
2012-07-12 22:04 - 2012-07-12 22:04 - 00000946 ____A C:\Users\adode13\Desktop\Dolphin.lnk
2012-07-12 21:32 - 2011-06-23 22:25 - 00000000 ___AD C:\Users\adode13\Downloads\dolphin-3.0-win64
2012-07-12 10:36 - 2012-07-12 10:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{AA67E3B1-FC95-427E-B5B8-6E7EF65DDC32}
2012-07-12 10:36 - 2012-07-12 10:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{510FEC62-2A79-480E-AB8F-E3DA2678C088}
2012-07-12 10:24 - 2012-07-12 10:30 - 91139450 ____A C:\Users\adode13\Downloads\Reprise.zip
2012-07-12 09:14 - 2012-07-12 09:14 - 09226440 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-07-12 01:10 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-12 01:01 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-12 01:01 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-12 01:01 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-12 01:01 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-12 01:01 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-12 01:01 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-12 01:01 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-12 01:01 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-12 01:01 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-12 01:01 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-12 01:01 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-12 01:01 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-12 01:01 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-12 01:01 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-12 01:01 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-12 01:01 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-12 01:01 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-12 01:01 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-12 01:01 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-12 01:01 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-12 01:01 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-12 01:01 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-12 01:01 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-12 01:01 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-12 01:01 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-12 01:01 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-12 01:01 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-12 01:01 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 22:36 - 2012-07-11 22:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{72A7231C-394C-4155-98B2-C08304E70063}
2012-07-11 22:36 - 2012-07-11 22:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{02F650BA-E171-46A8-B320-48E3E3B691C0}
2012-07-11 16:19 - 2012-07-11 16:19 - 00248730 ____A C:\Users\adode13\Downloads\individigital.zip
2012-07-11 16:19 - 2012-07-11 16:19 - 00008389 ____A C:\Users\adode13\Downloads\dominik.zip
2012-07-11 14:32 - 2012-07-11 14:34 - 15634214 ____A C:\Users\adode13\Downloads\?????????.zip
2012-07-11 14:32 - 2012-07-11 14:34 - 08955362 ____A C:\Users\adode13\Downloads\03 my ugly gene.m4a
2012-07-11 14:32 - 2012-07-11 14:33 - 09744709 ____A C:\Users\adode13\Downloads\02 Fear Dance.m4a
2012-07-11 14:32 - 2012-07-11 14:33 - 09557049 ____A C:\Users\adode13\Downloads\01 ?-kHz.m4a
2012-07-11 14:30 - 2012-07-11 14:30 - 06222779 ____A C:\Users\adode13\Downloads\lakugaki.mp3.zip
2012-07-11 10:35 - 2012-07-11 10:35 - 00000000 ____D C:\Users\adode13\AppData\Local\{E6C4FC21-2713-4F15-89D3-162D1DC46A9B}
2012-07-11 10:35 - 2012-07-11 10:35 - 00000000 ____D C:\Users\adode13\AppData\Local\{4274FC9B-46F9-4B68-984E-762B46820AD3}
2012-07-11 04:04 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 04:04 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 04:04 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 04:04 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 04:04 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 04:04 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 04:04 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 04:04 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 04:04 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 04:04 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 04:04 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 04:04 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 04:04 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 04:04 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 04:04 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 04:04 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 04:04 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 04:04 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 04:04 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-10 22:35 - 2012-07-10 22:35 - 00000000 ____D C:\Users\adode13\AppData\Local\{EE489028-348A-4020-8F01-551B7B289706}
2012-07-10 10:34 - 2012-07-10 10:34 - 00000000 ____D C:\Users\adode13\AppData\Local\{02410FEE-D1EF-4395-A362-C713AFBAFE2C}
2012-07-09 22:33 - 2012-07-09 22:34 - 00000000 ____D C:\Users\adode13\AppData\Local\{898A50E2-8EB4-4218-A623-EA894655D161}
2012-07-09 17:24 - 2012-07-09 17:39 - 123929747 ____A C:\Users\adode13\Downloads\101.rar
2012-07-09 10:33 - 2012-07-10 22:35 - 00000000 ____D C:\Users\adode13\AppData\Local\{7CDA8AF8-65AE-4977-8E3B-3435C4ED9C80}
2012-07-09 10:33 - 2012-07-09 10:33 - 00000000 ____D C:\Users\adode13\AppData\Local\{2A6F18FE-497F-47E1-A1B8-7B9642E901FB}
2012-07-08 22:32 - 2012-07-08 22:32 - 00079819 ____A C:\Users\adode13\Downloads\minecraftia.zip
2012-07-08 22:32 - 2012-07-08 22:32 - 00034009 ____A C:\Users\adode13\Downloads\v5prophit_cell.zip
2012-07-08 22:19 - 2012-07-08 22:19 - 00000000 ____D C:\Users\adode13\AppData\Local\{70E9745B-8A80-4AE9-A275-D6F3829A98C7}
2012-07-08 10:18 - 2012-07-08 22:19 - 00000000 ____D C:\Users\adode13\AppData\Local\{67A35010-2DA5-4661-98F4-17ABDF80CF1B}
2012-07-08 10:18 - 2012-07-08 10:18 - 00000000 ____D C:\Users\adode13\AppData\Local\{0028E128-7AD9-481C-A3BC-BAFDB86844AD}
2012-07-07 22:02 - 2012-07-07 22:02 - 00000000 ____D C:\Users\adode13\AppData\Local\{B5C2C1CA-D0D9-4534-B297-F63A56728580}
2012-07-07 10:01 - 2012-07-07 22:02 - 00000000 ____D C:\Users\adode13\AppData\Local\{CFCD9DE1-8415-4C21-A1FD-ADBA8F3FF04E}
2012-07-07 10:01 - 2012-07-07 10:02 - 00000000 ____D C:\Users\adode13\AppData\Local\{CF5A41A3-71BC-4B11-9853-B6960B15A082}
2012-07-06 23:17 - 2012-07-09 12:55 - 00000000 ____D C:\Users\adode13\Desktop\Ads
2012-07-06 11:28 - 2012-07-06 11:28 - 00000000 ____D C:\Users\adode13\AppData\Local\{42DD3F8D-A46A-47AF-94C9-E0AC3AD34678}
2012-07-06 11:28 - 2012-07-06 11:28 - 00000000 ____D C:\Users\adode13\AppData\Local\{2E820539-7FE6-466D-ACF4-1682D13A74CA}
2012-07-05 19:16 - 2012-07-05 19:20 - 28407468 ____A C:\Users\adode13\Downloads\MSInc SP.rar
2012-07-05 15:22 - 2012-07-05 15:22 - 00027616 ____A C:\Users\adode13\Downloads\stroke.zip
2012-07-05 15:19 - 2012-07-05 15:19 - 00428453 ____A C:\Users\adode13\Downloads\Quicksand.zip
2012-07-05 15:19 - 2012-07-05 15:19 - 00236384 ____A C:\Users\adode13\Downloads\billy-argel_new-garden.zip
2012-07-05 15:19 - 2012-07-05 15:19 - 00159932 ____A C:\Users\adode13\Downloads\TitilliumText.zip
2012-07-05 15:18 - 2012-07-05 15:18 - 00484995 ____A C:\Users\adode13\Downloads\comfortaa___font_by_aajohan-d1qr019.zip
2012-07-05 15:18 - 2012-07-05 15:18 - 00241718 ____A C:\Users\adode13\Downloads\Walkway.zip
2012-07-05 15:17 - 2012-07-05 15:17 - 00064828 ____A C:\Users\adode13\Downloads\CircleD_Font_by_CrazyForMusic.ttf
2012-07-05 15:17 - 2012-07-05 15:17 - 00011850 ____A C:\Users\adode13\Downloads\steiner.zip
2012-07-05 14:54 - 2012-07-05 14:54 - 00075105 ____A C:\Users\adode13\Downloads\Existence-Light.zip
2012-07-05 08:41 - 2012-07-05 08:41 - 00000000 ____D C:\Users\adode13\AppData\Local\{E2C166D2-3A1E-4E08-AF92-1B3A939B753E}
2012-07-05 08:40 - 2012-07-05 08:41 - 00000000 ____D C:\Users\adode13\AppData\Local\{05DD9EA8-2ABE-42C1-BB03-B342EB1A60D0}
2012-07-04 18:19 - 2012-07-04 18:39 - 45035764 ____A C:\Users\adode13\Downloads\[Mini] coldrain - THROUGH CLARITY [2012.07.04].rar
2012-07-04 18:18 - 2012-07-04 18:28 - 52676078 ____A C:\Users\adode13\Downloads\[2012.06.06] NEW BREED - THE PIONEERS OF SENSATION.rar
2012-07-04 18:18 - 2012-07-04 18:25 - 26409419 ____A C:\Users\adode13\Downloads\v-r.rar
2012-07-04 10:49 - 2012-07-04 10:49 - 00000000 ____D C:\Users\adode13\AppData\Local\{922CB157-A5AF-43EC-927D-F57F5CF3E2F0}
2012-07-03 20:39 - 2012-07-03 20:39 - 00000000 ____D C:\Users\adode13\AppData\Local\{492F3854-FE40-47F3-88E3-62198D7B902C}
2012-07-03 20:39 - 2012-07-03 20:39 - 00000000 ____D C:\Users\adode13\AppData\Local\{2420DB70-92C0-4412-9FB7-3769DC54CDD4}
2012-07-03 08:38 - 2012-07-03 08:38 - 00000000 ____D C:\Users\adode13\AppData\Local\{B1F7996B-282C-41B6-B9DF-CEF5F56CD5C0}
2012-07-03 08:38 - 2012-07-03 08:38 - 00000000 ____D C:\Users\adode13\AppData\Local\{08EF80A3-0B7D-4048-86BC-10A574380B1E}
2012-07-02 22:45 - 2012-07-02 22:45 - 00000000 ____D C:\Users\adode13\AppData\Roaming\Opera
2012-07-02 22:45 - 2012-07-02 22:45 - 00000000 ____D C:\Users\adode13\AppData\Local\Opera
2012-07-02 22:45 - 2012-07-02 22:45 - 00000000 ____D C:\Program Files (x86)\Opera
2012-07-02 20:36 - 2012-07-02 20:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{6231A1CE-0458-4590-808A-BB66E144EB78}
2012-07-02 08:36 - 2012-07-02 20:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{286E2FEB-BD4D-47C4-94C8-1CC8C4168C9C}
2012-07-02 08:36 - 2012-07-02 08:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{9884E34A-4ABF-4022-A7DC-D392C3182444}
2012-06-30 21:44 - 2012-06-30 21:44 - 00000000 ____D C:\Users\adode13\AppData\Local\{EB0865DF-14B0-4C91-8235-F3539C73434B}
2012-06-30 09:44 - 2012-06-30 09:44 - 00000000 ____D C:\Users\adode13\AppData\Local\{A0777327-6B78-42A5-ADA6-01A27F8B82D9}
2012-06-30 09:43 - 2012-06-30 21:44 - 00000000 ____D C:\Users\adode13\AppData\Local\{897D7D20-9013-4F2D-B9E9-93A7F793C926}
2012-06-29 21:43 - 2012-06-29 21:43 - 00000000 ____D C:\Users\adode13\AppData\Local\{F3DF2949-2B7E-4B10-A202-6B856E779AD3}
2012-06-29 09:43 - 2012-06-29 09:43 - 00000000 ____D C:\Users\adode13\AppData\Local\{C284CD7C-10F6-4805-A9F8-5F0DC5857801}
2012-06-29 09:42 - 2012-06-29 21:43 - 00000000 ____D C:\Users\adode13\AppData\Local\{6A55338B-F61E-446B-ABD1-274E758A0EA3}
2012-06-28 08:33 - 2012-06-28 08:34 - 00000000 ____D C:\Users\adode13\AppData\Local\{0E3D910A-5B00-44F4-AC5F-E372660AF93E}
2012-06-28 08:33 - 2012-06-28 08:33 - 00000000 ____D C:\Users\adode13\AppData\Local\{7E9356DC-E22C-48B1-8472-09BDD7015426}
2012-06-27 14:36 - 2012-06-27 14:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{4E0BA21F-0E65-43BB-B6FC-0C5CC46E5296}
2012-06-27 14:35 - 2012-06-27 14:36 - 00000000 ____D C:\Users\adode13\AppData\Local\{3A0D4272-CAD4-4E3C-B379-0FC8E00123C9}
2012-06-27 09:03 - 2012-06-27 09:03 - 00000000 ____D C:\Users\adode13\AppData\Local\{F0096238-00A3-4C92-97B7-D48C301BE956}
2012-06-26 09:26 - 2012-06-26 09:26 - 00000000 ____D C:\Users\adode13\AppData\Local\{2DFB6843-EB8C-4D01-8845-C8CA36A04DBD}
2012-06-26 09:25 - 2012-06-26 09:25 - 00000000 ____D C:\Users\adode13\AppData\Local\{DA1FE535-F10F-4CA2-B44D-8615203E9561}
2012-06-25 19:52 - 2012-06-25 19:52 - 00000000 ____D C:\Users\adode13\AppData\Local\{367C03F3-4244-44CB-AC4D-1D4A842CF1AB}
2012-06-25 07:51 - 2012-06-25 19:52 - 00000000 ____D C:\Users\adode13\AppData\Local\{EA7C4460-9BCC-40FF-869B-748F5B2884D9}
2012-06-25 07:51 - 2012-06-25 07:51 - 00000000 ____D C:\Users\adode13\AppData\Local\{887B10BC-6787-41A6-871E-0A73288F4F22}
2012-06-23 10:16 - 2012-06-23 10:16 - 00000000 ____D C:\Users\adode13\AppData\Local\{6322504E-78C3-4269-95F0-F6551087AF18}
2012-06-23 10:15 - 2012-06-23 10:16 - 00000000 ____D C:\Users\adode13\AppData\Local\{735A210E-B474-4C84-9B97-674355253166}
2012-06-23 09:52 - 2012-06-23 09:52 - 00000000 ____D C:\Users\adode13\AppData\Local\{C6287180-79DD-4770-AC6B-A289CFE4D9A0}
2012-06-22 11:00 - 2012-06-22 11:00 - 00000000 ____D C:\Users\adode13\AppData\Local\{B6F198D5-A32E-4ACB-8035-14D1F67C55AF}
2012-06-22 10:59 - 2012-06-22 11:00 - 00000000 ____D C:\Users\adode13\AppData\Local\{57587ACB-B15D-40B4-896A-AFFA9347D118}
2012-06-21 20:03 - 2012-06-21 20:03 - 00000000 ____D C:\Users\adode13\AppData\Local\{289792F2-9C31-47C6-A514-8F4686B1E8ED}
2012-06-21 08:03 - 2012-06-21 08:03 - 00000000 ____D C:\Users\adode13\AppData\Local\{8B55CA86-05B3-4EAC-A2BB-A5CA5064A4CB}
2012-06-21 08:02 - 2012-06-21 20:03 - 00000000 ____D C:\Users\adode13\AppData\Local\{D6E1738D-AAC6-4C69-B784-B3646ED15DCB}
2012-06-20 14:23 - 2012-06-20 14:23 - 00000000 ____D C:\Users\adode13\Downloads\AngleWheels_HMS
2012-06-20 10:27 - 2012-06-20 10:27 - 00000000 ____D C:\Users\adode13\AppData\Local\{E19C8AE8-96B6-4A9A-B37A-6A3CA6F9620D}
2012-06-20 10:27 - 2012-06-20 10:27 - 00000000 ____D C:\Users\adode13\AppData\Local\{C51143C1-B189-436D-9EC2-4FB9E4DB479B}
2012-06-19 21:16 - 2012-06-19 21:16 - 00000000 ____D C:\Users\adode13\AppData\Local\{527C13C7-5BCF-4ECC-9236-252A5CE9A9A3}
2012-06-19 09:16 - 2012-06-19 09:16 - 00000000 ____D C:\Users\adode13\AppData\Local\{28679318-9B3F-445E-8C9E-CD1C115A28AD}
2012-06-19 09:15 - 2012-06-19 21:16 - 00000000 ____D C:\Users\adode13\AppData\Local\{ADD2D68C-8ED0-4CA8-A7C3-966A7395E41F}
2012-06-19 09:15 - 2012-06-19 09:15 - 00000000 ____D C:\Windows\en
2012-06-19 09:12 - 2012-03-08 16:40 - 00048488 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fssfltr.sys
2012-06-19 09:09 - 2012-06-19 09:09 - 00000000 ____D C:\Users\adode13\AppData\Local\{40B286B1-7756-4658-BCC4-802584E24B45}
2012-06-19 09:08 - 2012-06-19 09:09 - 00000000 ____D C:\Users\adode13\AppData\Local\{B588838F-2FB5-4D37-B44A-99B8522432FD}
2012-06-19 08:38 - 2012-06-19 08:38 - 00000000 ____D C:\Users\adode13\AppData\Local\{448E661A-2D36-4BC1-8945-675BA2E9C505}
2012-06-19 08:37 - 2012-06-19 08:38 - 00000000 ____D C:\Users\adode13\AppData\Local\{41874DBA-6FD0-480C-B7BF-B0E546CF99EC}
2012-06-18 18:55 - 2012-06-18 18:53 - 02114362 ___RA C:\Users\adode13\Documents\Technologic___Brush_Pack_by_NextViewDesigns.abr
2012-06-18 18:55 - 2012-06-18 18:53 - 00467206 ___RA C:\Users\adode13\Documents\Tech_Brushes_01_by_Jaaaiiro.abr
2012-06-18 17:30 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-18 17:30 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-18 17:30 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-18 17:30 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-18 17:29 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-18 17:29 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-18 17:29 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-18 17:29 - 2012-06-02 13:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-18 17:29 - 2012-06-02 13:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-18 07:14 - 2012-06-18 07:14 - 00000000 ____D C:\Users\adode13\AppData\Local\{7B8FCDCA-7290-42F7-95DF-4274942813C3}
============ 3 Months Modified Files ========================
2012-07-18 09:51 - 2009-07-13 21:13 - 00779092 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-18 09:47 - 2012-01-24 05:01 - 00000935 ____A C:\Windows\wininit.ini
2012-07-18 09:47 - 2011-08-28 19:06 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1933306683-895702514-590770892-1001UA.job
2012-07-18 09:44 - 2012-07-18 09:44 - 01437107 ____A (Farbar) C:\Users\adode13\Desktop\FRST64.exe
2012-07-18 09:14 - 2012-04-04 07:30 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-18 09:02 - 2011-08-06 19:14 - 01292748 ____A C:\Windows\WindowsUpdate.log
2012-07-18 09:01 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-18 09:01 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-18 08:54 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-18 08:54 - 2009-07-13 20:51 - 00098548 ____A C:\Windows\setupact.log
2012-07-18 07:42 - 2012-02-06 12:23 - 00000340 ____A C:\Windows\Tasks\HPCeeScheduleForadode13.job
2012-07-17 16:47 - 2011-08-28 19:06 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1933306683-895702514-590770892-1001Core.job
2012-07-17 09:26 - 2012-07-17 09:13 - 127039024 ____A C:\Users\adode13\Downloads\nanoir.rar
2012-07-17 09:25 - 2012-07-17 09:13 - 35600626 ____A C:\Users\adode13\Downloads\GRETEL_-_Kessei_Kinen_Ongenshuu_(single)_by_kumika.rar
2012-07-17 09:22 - 2012-07-17 09:13 - 64912332 ____A C:\Users\adode13\Downloads\???????.zip
2012-07-16 09:12 - 2011-11-21 13:28 - 00000000 ____A C:\Windows\System32\HP_ActiveX_Patch_NOT_DETECTED.txt
2012-07-16 09:12 - 2011-08-29 19:09 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-07-16 08:40 - 2009-07-13 21:08 - 00032540 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-15 14:21 - 2012-07-15 13:48 - 441375029 ____A C:\Users\adode13\Downloads\[4ls]_katawa_shoujo_[windows][C3798628].exe
2012-07-14 08:02 - 2012-07-14 08:01 - 27296862 ____A C:\Users\adode13\Downloads\[2012.07.04] BugLug - KILLER×KILLER×KILLER.rar
2012-07-13 13:00 - 2012-07-13 12:58 - 14893793 ____A C:\Users\adode13\Downloads\GnT_Hamada_McDonalds.flv
2012-07-13 12:59 - 2012-07-13 12:56 - 46745288 ____A C:\Users\adode13\Downloads\DT_Manzai_Mounting_Sub.avi
2012-07-12 22:04 - 2012-07-12 22:04 - 00000946 ____A C:\Users\adode13\Desktop\Dolphin.lnk
2012-07-12 10:30 - 2012-07-12 10:24 - 91139450 ____A C:\Users\adode13\Downloads\Reprise.zip
2012-07-12 09:14 - 2012-07-12 09:14 - 09226440 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-07-12 09:14 - 2012-04-04 07:30 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-12 09:14 - 2011-08-28 19:10 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-12 09:04 - 2009-07-13 20:45 - 05121576 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-12 01:09 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-07-12 01:03 - 2011-08-28 13:33 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-11 16:19 - 2012-07-11 16:19 - 00248730 ____A C:\Users\adode13\Downloads\individigital.zip
2012-07-11 16:19 - 2012-07-11 16:19 - 00008389 ____A C:\Users\adode13\Downloads\dominik.zip
2012-07-11 14:34 - 2012-07-11 14:32 - 15634214 ____A C:\Users\adode13\Downloads\?????????.zip
2012-07-11 14:34 - 2012-07-11 14:32 - 08955362 ____A C:\Users\adode13\Downloads\03 my ugly gene.m4a
2012-07-11 14:33 - 2012-07-11 14:32 - 09744709 ____A C:\Users\adode13\Downloads\02 Fear Dance.m4a
2012-07-11 14:33 - 2012-07-11 14:32 - 09557049 ____A C:\Users\adode13\Downloads\01 ?-kHz.m4a
2012-07-11 14:30 - 2012-07-11 14:30 - 06222779 ____A C:\Users\adode13\Downloads\lakugaki.mp3.zip
2012-07-09 17:39 - 2012-07-09 17:24 - 123929747 ____A C:\Users\adode13\Downloads\101.rar
2012-07-08 23:07 - 2011-08-28 18:11 - 00141912 ____A C:\Users\adode13\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-08 22:32 - 2012-07-08 22:32 - 00079819 ____A C:\Users\adode13\Downloads\minecraftia.zip
2012-07-08 22:32 - 2012-07-08 22:32 - 00034009 ____A C:\Users\adode13\Downloads\v5prophit_cell.zip
2012-07-06 23:16 - 2012-04-13 20:45 - 00011595 ____A C:\Users\adode13\Documents\HP POLL1UFA.xlsx
2012-07-06 23:07 - 2012-03-16 18:31 - 00011498 ____A C:\Users\adode13\Documents\HP POLL1.xlsx
2012-07-05 19:20 - 2012-07-05 19:16 - 28407468 ____A C:\Users\adode13\Downloads\MSInc SP.rar
2012-07-05 15:22 - 2012-07-05 15:22 - 00027616 ____A C:\Users\adode13\Downloads\stroke.zip
2012-07-05 15:19 - 2012-07-05 15:19 - 00428453 ____A C:\Users\adode13\Downloads\Quicksand.zip
2012-07-05 15:19 - 2012-07-05 15:19 - 00236384 ____A C:\Users\adode13\Downloads\billy-argel_new-garden.zip
2012-07-05 15:19 - 2012-07-05 15:19 - 00159932 ____A C:\Users\adode13\Downloads\TitilliumText.zip
2012-07-05 15:18 - 2012-07-05 15:18 - 00484995 ____A C:\Users\adode13\Downloads\comfortaa___font_by_aajohan-d1qr019.zip
2012-07-05 15:18 - 2012-07-05 15:18 - 00241718 ____A C:\Users\adode13\Downloads\Walkway.zip
2012-07-05 15:17 - 2012-07-05 15:17 - 00064828 ____A C:\Users\adode13\Downloads\CircleD_Font_by_CrazyForMusic.ttf
2012-07-05 15:17 - 2012-07-05 15:17 - 00011850 ____A C:\Users\adode13\Downloads\steiner.zip
2012-07-05 14:54 - 2012-07-05 14:54 - 00075105 ____A C:\Users\adode13\Downloads\Existence-Light.zip
2012-07-04 18:39 - 2012-07-04 18:19 - 45035764 ____A C:\Users\adode13\Downloads\[Mini] coldrain - THROUGH CLARITY [2012.07.04].rar
2012-07-04 18:28 - 2012-07-04 18:18 - 52676078 ____A C:\Users\adode13\Downloads\[2012.06.06] NEW BREED - THE PIONEERS OF SENSATION.rar
2012-07-04 18:25 - 2012-07-04 18:18 - 26409419 ____A C:\Users\adode13\Downloads\v-r.rar
2012-06-22 08:34 - 2011-09-02 21:11 - 00000132 ____A C:\Users\adode13\AppData\Roaming\Adobe PNG Format CS5 Prefs
2012-06-19 09:11 - 2011-04-28 16:32 - 00027823 ____A C:\Windows\DirectX.log
2012-06-18 18:53 - 2012-06-18 18:55 - 02114362 ___RA C:\Users\adode13\Documents\Technologic___Brush_Pack_by_NextViewDesigns.abr
2012-06-18 18:53 - 2012-06-18 18:55 - 00467206 ___RA C:\Users\adode13\Documents\Tech_Brushes_01_by_Jaaaiiro.abr
2012-06-11 19:08 - 2012-07-12 01:10 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-11 04:04 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 04:04 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-07 07:05 - 2012-06-07 07:05 - 00011912 ____A C:\Users\adode13\Documents\Original CSS Lightobx Evolution.txt
2012-06-05 22:06 - 2012-07-11 04:04 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 04:04 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 04:04 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 04:04 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 04:04 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 04:04 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-04 22:28 - 2012-06-04 22:28 - 00000712 ____A C:\Users\adode13\Documents\Dandy.txt
2012-06-02 14:19 - 2012-06-18 17:30 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-18 17:30 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-18 17:30 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-18 17:29 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-18 17:29 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-18 17:30 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-18 17:29 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 13:19 - 2012-06-18 17:29 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 13:15 - 2012-06-18 17:29 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-12 01:01 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-12 01:01 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-12 01:01 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-12 01:01 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-12 01:01 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-12 01:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-12 01:01 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-12 01:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-12 01:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-12 01:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-12 01:01 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-12 01:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-12 01:01 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-12 01:01 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-12 01:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-12 01:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-12 01:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-12 01:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-12 01:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-12 01:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-12 01:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-12 01:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-12 01:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-12 01:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-12 01:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-12 01:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-12 01:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-12 01:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-11 04:04 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 04:04 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 04:04 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 04:04 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 04:04 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 04:04 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 04:04 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 04:04 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 04:04 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-19 01:31 - 2012-06-06 01:23 - 1272571834 ____A C:\Users\adode13\Downloads\GakiNoTsukai_Airport_Batsu_2011_subbed.avi
2012-05-12 07:38 - 2010-11-20 19:47 - 00488190 ____A C:\Windows\PFRO.log
2012-05-09 18:58 - 2011-08-29 20:34 - 00443239 ___RA C:\Windows\System32\Drivers\etc\hosts.20120718-113242.backup
2012-05-04 03:06 - 2012-06-13 02:43 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 03:00 - 2012-06-13 19:32 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-05-04 02:03 - 2012-06-13 02:43 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 02:43 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-04 01:59 - 2012-06-13 19:32 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-04-30 21:40 - 2012-06-13 02:43 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-13 02:43 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-13 02:43 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 02:43 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 02:43 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-24 19:33 - 2012-04-24 15:38 - 00733575 ____A C:\Users\adode13\Documents\Andrews.pptx
2012-04-23 21:37 - 2012-06-13 02:42 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 02:42 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 02:42 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 21:03 - 2012-04-23 21:03 - 03523584 ____A C:\Users\adode13\Documents\Distribution%20and%20Supply%20Chain%20Management.ppt
2012-04-23 21:02 - 2012-04-23 21:02 - 01296896 ____A C:\Users\adode13\Documents\PRICING%20STRATEGIES%20AND%20TACTICS.ppt
2012-04-23 20:36 - 2012-06-13 02:42 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 02:42 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 02:42 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}
C:\Windows\Installer\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\@
C:\Windows\Installer\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\L
C:\Windows\Installer\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\n
C:\Windows\Installer\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\U
C:\Windows\Installer\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\U\00000001.@
C:\Windows\Installer\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\U\800000cb.@
ZeroAccess:
C:\Users\adode13\AppData\Local\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}
C:\Users\adode13\AppData\Local\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\@
C:\Users\adode13\AppData\Local\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\L
C:\Users\adode13\AppData\Local\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\n
C:\Users\adode13\AppData\Local\{bbee3ba2-89af-930c-bb78-1fb4e17db3cc}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 5610.9 MB
Available physical RAM: 4787.34 MB
Total Pagefile: 5609.05 MB
Available Pagefile: 4777.36 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:581.28 GB) (Free:22.39 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (RECOVERY) (Fixed) (Total:14.59 GB) (Free:1.62 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
5 Drive h: (KINGSTON) (Removable) (Total:0.93 GB) (Free:0.24 GB) FAT
6 Drive x: (Boot) (Fixed) (Total:0.25 GB) (Free:0.25 GB) NTFS
7 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 596 GB 0 B
Disk 1 Online 954 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 581 GB 200 MB
Partition 3 Primary 14 GB 581 GB
Partition 4 Primary 103 MB 596 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 199 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 581 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E RECOVERY NTFS Partition 14 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F HP_TOOLS FAT32 Partition 103 MB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 953 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H KINGSTON FAT Removable 953 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-18 04:40
======================= End Of Log ==========================