Scan result of Farbar Recovery Scan Tool Version: 08-08-2012 02
Ran by SYSTEM at 08-08-2012 19:05:32
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2799912 2011-09-26] (Synaptics Incorporated)
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s [7466600 2011-12-07] (Realtek Semiconductor)
HKLM\...\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden [363064 2010-07-21] (Hewlett-Packard Company)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [336384 2011-03-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [35736 2011-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot [273544 2011-07-04] (RealNetworks, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-06-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Conime] %windir%\system32\conime.exe [x]
HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [EKStatusMonitor] C:\PROGRAM FILES (X86)\KODAK\AIO\STATUSMONITOR\EKStatusMonitor.EXE [2784256 2012-06-19] (Eastman Kodak Company)
HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462920 2012-07-03] (Malwarebytes Corporation)
HKU\Andy Darko\...\Run: [MultiTouch Platform] "C:\Program Files (x86)\PQLabs\MultiTouchPlatform\MultiTouchPlatform.exe" /s [2936832 2011-07-18] (PQLabs Inc.)
HKU\Andy Darko\...\Run: [Google Update] "C:\Users\Andy Darko\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-03-20] (Google Inc.)
HKLM-x32\...\Runonce: [AvgUninstallURL] cmd.exe /c start
http://www.avg.com/ww.special-unins...VMV0gtR0JZUzQtOU5USEQtUUE3WEQtQzJRSEgtTkZGS0o"&"inst=NzctNjg2OTQ4OTAzLUREVCs1NTUyOC1UVUcrMy1GTDEwKzEtREQxMEYrMS1TVDEwRkFQUCsxLUYxME0xMkFUKzItRjEwTTEyQSsxLUYxME0xMkFCKzEtVTEwKzEtRjEwTTEyQVRCKzEtRjEwVEIrMi1TVDEwVEJGKzE"&"prod=90"&"ver=10.0.1416 [x]
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
AppInit_DLLs:
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Snapfish PictureMover.lnk
ShortcutTarget: Snapfish PictureMover.lnk -> C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Hewlett-Packard Company)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\TUSBAudio Control Panel Autostart.lnk
ShortcutTarget: TUSBAudio Control Panel Autostart.lnk -> C:\Program Files\Thesycon\TUSBAudio_Driver\TUSBAudioCpl.exe ()
==================== Services (Whitelisted) ======
2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE" [140672 2011-08-11] (SUPERAntiSpyware.com)
2 AMD Reservation Manager; "C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe" [194496 2010-06-17] (Advanced Micro Devices)
2 FPAVServer; "C:\Program Files (x86)\FRISK Software\F-PROT Antivirus for Windows\FPAVServer.exe" [84136 2011-10-06] (FRISK Software International)
2 HPAuto; "C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe" [682040 2011-02-16] (Hewlett-Packard)
2 Kodak AiO Status Monitor Service; "C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe" [777728 2012-06-19] (Eastman Kodak Company)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation)
2 NitroDriverReadSpool2; "C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe" [341792 2011-12-20] (Nitro PDF Software)
2 NitroReaderDriverReadSpool2; "C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe" [341296 2011-06-21] (Nitro PDF Software)
2 nlsX86cc; C:\Windows\SysWOW64\NLSSRV32.EXE [68896 2011-12-20] (Nalpeiron Ltd.)
2 PQMTDigitizer; C:\Program Files\PQLabs\MultiTouchDriver\PQMTDigitizer.dll [1773568 2011-07-18] (PQLabs Inc.)
3 AVG Security Toolbar Service; C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [x]
2 NMSAccess; "C:\Program Files (x86)\Blaze Media Pro\NMSAccess32.exe" [x]
========================== Drivers (Whitelisted) =============
1 FPAV_RTP; C:\Windows\System32\Drivers\FPAV_RTP.sys [842144 2011-11-11] (FRISK Software International)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-07-03] (Malwarebytes Corporation)
3 pqbulk; C:\Windows\System32\Drivers\pqbulkPlus.sys [23712 2010-05-19] (PQLabs)
3 pqhid; C:\Windows\System32\DRIVERS\pqmtdrvplus.sys [20128 2010-05-19] (PQLabs)
3 PQMTDrv; C:\Windows\System32\Drivers\PQMTDrv.sys [28160 2010-03-01] (PQLabs)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
3 tusbaudio; C:\Windows\System32\DRIVERS\tusbaudio_x64.sys [217952 2011-02-23] ()
3 tusbaudioks; C:\Windows\System32\DRIVERS\tusbaudioks_x64.sys [51552 2011-02-23] ()
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-08 15:12 - 2012-08-08 15:12 - 00002379 ____A C:\Users\Andy Darko\Desktop\aswMBR.txt
2012-08-08 15:12 - 2012-08-08 15:12 - 00000512 ____A C:\Users\Andy Darko\Desktop\MBR.dat
2012-08-08 13:21 - 2012-08-08 13:23 - 04731392 ____A (AVAST Software) C:\Users\Andy Darko\Desktop\aswMBR.exe
2012-08-08 13:18 - 2012-08-08 13:18 - 00000000 ____D C:\Users\Andy Darko\Desktop\rkill-backup
2012-08-08 13:17 - 2012-08-08 13:18 - 00003732 ____A C:\Users\Andy Darko\Desktop\Rkill.txt
2012-08-08 13:17 - 2012-08-08 13:16 - 01118624 ____A (Bleeping Computer, LLC) C:\Users\Andy Darko\Desktop\rkill.exe
2012-08-08 13:15 - 2012-08-08 13:16 - 01118624 ____A (Bleeping Computer, LLC) C:\Users\Andy Darko\Downloads\rkill.exe
2012-08-07 21:49 - 2012-08-07 21:49 - 00000000 ____A C:\Users\Andy Darko\Desktop\gmer.log
2012-08-07 21:31 - 2012-08-07 21:31 - 00302592 ____A C:\Users\Andy Darko\Downloads\ms4r4yxc.exe
2012-08-06 18:09 - 2012-08-06 18:09 - 00000000 ____D C:\Users\Andy Darko\AppData\Roaming\FRISK Software
2012-08-04 17:42 - 2012-08-04 17:45 - 18727968 ____A (Microsoft Corporation) C:\Users\Andy Darko\Downloads\mpas-fe.exe
2012-08-04 12:13 - 2012-08-04 12:13 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-04 12:13 - 2012-08-04 12:13 - 00000000 ____D C:\Users\Andy Darko\AppData\Roaming\Malwarebytes
2012-08-04 12:13 - 2012-08-04 12:13 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-08-04 12:13 - 2012-08-04 12:13 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-04 12:13 - 2012-07-03 12:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-04 12:12 - 2012-08-04 12:12 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Andy Darko\Downloads\mbam-setup-1.62.0.1300.exe
2012-08-03 21:31 - 2012-08-03 21:31 - 00002175 ____A C:\Users\Public\Desktop\F-PROT Antivirus for Windows.lnk
2012-08-03 21:31 - 2012-08-03 21:31 - 00000000 ____D C:\Users\All Users\FRISK Software
2012-08-03 21:31 - 2012-08-03 21:31 - 00000000 ____D C:\Program Files (x86)\FRISK Software
2012-08-03 21:31 - 2011-11-11 09:24 - 00842144 ____A (FRISK Software International) C:\Windows\System32\Drivers\FPAV_RTP.sys
2012-08-03 21:26 - 2012-08-03 21:28 - 36979200 ____A C:\Users\Andy Darko\Downloads\fpav-windows-x64-hc-en.msi
2012-08-03 21:21 - 2012-08-03 21:23 - 36495872 ____A C:\Users\Andy Darko\Downloads\fpav-windows-x86-hc-en.msi
2012-08-03 13:40 - 2012-08-03 13:40 - 00000169 ____A C:\Users\Andy Darko\Desktop\robdd.txt
2012-08-03 13:40 - 2012-08-03 13:40 - 00000000 ____D C:\Users\Andy Darko\Desktop\New folder
2012-08-01 23:56 - 2012-08-01 23:56 - 00000000 ____D C:\Windows\pss
2012-08-01 23:49 - 2012-08-01 23:49 - 00945272 ____A (Prevx) C:\Users\Andy Darko\Downloads\prevxcsifree.exe
2012-07-31 16:49 - 2012-08-01 06:33 - 00007215 ____A C:\Users\Andy Darko\Desktop\to Gary.txt
2012-07-31 16:12 - 2012-07-31 16:12 - 00000120 ____A C:\Users\Andy Darko\Desktop\CONTACT IMMEDIATELY.txt
2012-07-26 14:29 - 2012-07-26 14:29 - 00000023 ____A C:\Users\Andy Darko\Desktop\suntrust app.txt
2012-07-25 18:30 - 2012-07-25 18:30 - 00000120 ____A C:\Users\Andy Darko\Desktop\information.txt
2012-07-25 17:47 - 2012-07-25 17:47 - 00000034 ____A C:\Users\Andy Darko\Desktop\suntrust.txt
2012-07-25 17:31 - 2012-07-25 17:31 - 00000025 ____A C:\Users\Andy Darko\Desktop\application id.txt
2012-07-24 15:31 - 2012-07-26 03:06 - 00006892 ____A C:\Users\Andy Darko\Desktop\jasonking.txt
2012-07-23 19:08 - 2012-07-23 20:09 - 00005169 ____A C:\Users\Andy Darko\Desktop\rob.txt
2012-07-22 13:42 - 2012-07-22 13:42 - 00318904 ____A (Microsoft Corporation) C:\Users\Andy Darko\Downloads\wmpfirefoxplugin.exe
2012-07-20 16:21 - 2012-07-20 16:23 - 00000000 ____D C:\Users\Default\AppData\Local\Eastman_Kodak_Company
2012-07-20 16:21 - 2012-07-20 16:23 - 00000000 ____D C:\Users\Default User\AppData\Local\Eastman_Kodak_Company
2012-07-20 16:21 - 2012-07-20 16:21 - 00002156 ____A C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
2012-07-20 16:20 - 2012-07-20 16:20 - 00002075 ____A C:\Users\Public\Desktop\Get CleanPrint.lnk
2012-07-20 16:19 - 2012-07-20 16:19 - 00000000 ____D C:\Windows\SysWOW64\kodak
2012-07-20 16:15 - 2012-07-20 16:15 - 00800824 ____A (Microsoft Corporation) C:\Users\Default\AppData\Roaming\DPInst.exe
2012-07-20 16:15 - 2012-07-20 16:15 - 00800824 ____A (Microsoft Corporation) C:\Users\Default User\AppData\Roaming\DPInst.exe
2012-07-20 16:15 - 2012-07-20 16:15 - 00106496 ____A (Microsoft Corporation) C:\Users\Default\AppData\Roaming\gacutil.exe
2012-07-20 16:15 - 2012-07-20 16:15 - 00106496 ____A (Microsoft Corporation) C:\Users\Default User\AppData\Roaming\gacutil.exe
2012-07-20 16:15 - 2012-07-20 16:15 - 00036352 ____A (Microsoft Corporation) C:\Users\Default\AppData\Roaming\PnPutil.exe
2012-07-20 16:15 - 2012-07-20 16:15 - 00036352 ____A (Microsoft Corporation) C:\Users\Default User\AppData\Roaming\PnPutil.exe
2012-07-20 16:15 - 2012-07-20 16:15 - 00000000 ____D C:\Users\Default\AppData\Roaming\KODAK AiO Home Center1033314209
2012-07-20 16:15 - 2012-07-20 16:15 - 00000000 ____D C:\Users\Default User\AppData\Roaming\KODAK AiO Home Center1033314209
2012-07-19 19:24 - 2012-07-19 19:24 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-19 19:24 - 2009-05-18 12:17 - 00034152 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2012-07-19 19:24 - 2008-04-17 11:12 - 00126312 ____A (GEAR Software Inc.) C:\Windows\System32\GEARAspi64.dll
2012-07-19 19:24 - 2008-04-17 11:12 - 00107368 ____A (GEAR Software Inc.) C:\Windows\SysWOW64\GEARAspi.dll
2012-07-19 19:23 - 2012-07-19 19:24 - 00000000 ____D C:\Program Files\iTunes
2012-07-19 19:23 - 2012-07-19 19:24 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-07-19 19:23 - 2012-07-19 19:23 - 00000000 ____D C:\Program Files\iPod
2012-07-19 19:16 - 2012-07-19 19:17 - 79225752 ____A (Apple Inc.) C:\Users\Andy Darko\Downloads\iTunes64Setup (1).exe
2012-07-19 06:56 - 2012-07-19 06:56 - 00000000 ____D C:\Users\Andy Darko\AppData\Local\Macromedia
2012-07-19 06:55 - 2012-08-08 17:58 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-19 06:55 - 2012-08-02 10:58 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-19 06:50 - 2012-06-28 19:20 - 00157488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-07-19 06:50 - 2012-06-28 19:20 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-07-19 06:50 - 2012-06-28 19:20 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-07-19 06:49 - 2012-07-19 06:49 - 00004357 ____A C:\Windows\SysWOW64\jupdate-1.6.0_33-b05.log
2012-07-18 19:55 - 2012-07-18 19:55 - 02543054 ____A C:\Users\Andy Darko\Downloads\MuseScore-1.2.exe
2012-07-18 19:53 - 2012-07-18 19:53 - 00014186 ____A C:\Users\Andy Darko\Downloads\Its You.mid
2012-07-12 01:45 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-12 01:34 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-12 01:34 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-12 01:34 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-12 01:34 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-12 01:34 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-12 01:34 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-12 01:34 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-12 01:34 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-12 01:34 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-12 01:34 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-12 01:34 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-12 01:34 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-12 01:34 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-12 01:34 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-12 01:34 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-12 01:34 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-12 01:34 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-12 01:34 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-12 01:34 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-12 01:34 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-12 01:34 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-12 01:34 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-12 01:34 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-12 01:34 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-12 01:34 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-12 01:34 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-12 01:34 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-12 01:34 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 13:28 - 2012-07-11 13:28 - 00000012 ____A C:\Users\Andy Darko\Desktop\mail.txt
2012-07-11 09:23 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 09:23 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 09:23 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 09:23 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 09:23 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 09:23 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 09:23 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 09:23 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 09:23 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 09:23 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 09:23 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 09:23 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 09:23 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 09:23 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 09:23 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 09:23 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 09:23 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-11 08:34 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 08:34 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-09 13:44 - 2012-08-06 12:34 - 00000000 ____D C:\Users\Andy Darko\Documents\NYU SINGLE
============ 3 Months Modified Files ========================
2012-08-08 17:58 - 2012-07-19 06:55 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-08 17:41 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-08 17:41 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-08 17:36 - 2009-07-13 21:13 - 00751936 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-08 17:03 - 2012-03-26 07:53 - 00000928 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2818201950-4019244992-208703273-1001UA.job
2012-08-08 17:02 - 2012-03-01 09:45 - 00000906 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-08 15:14 - 2009-07-13 20:51 - 00167387 ____A C:\Windows\setupact.log
2012-08-08 15:12 - 2012-08-08 15:12 - 00002379 ____A C:\Users\Andy Darko\Desktop\aswMBR.txt
2012-08-08 15:12 - 2012-08-08 15:12 - 00000512 ____A C:\Users\Andy Darko\Desktop\MBR.dat
2012-08-08 15:03 - 2012-03-26 07:53 - 00000876 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2818201950-4019244992-208703273-1001Core.job
2012-08-08 13:23 - 2012-08-08 13:21 - 04731392 ____A (AVAST Software) C:\Users\Andy Darko\Desktop\aswMBR.exe
2012-08-08 13:18 - 2012-08-08 13:17 - 00003732 ____A C:\Users\Andy Darko\Desktop\Rkill.txt
2012-08-08 13:16 - 2012-08-08 13:17 - 01118624 ____A (Bleeping Computer, LLC) C:\Users\Andy Darko\Desktop\rkill.exe
2012-08-08 13:16 - 2012-08-08 13:15 - 01118624 ____A (Bleeping Computer, LLC) C:\Users\Andy Darko\Downloads\rkill.exe
2012-08-08 13:02 - 2012-03-01 09:45 - 00000902 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-08 10:14 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-07 21:49 - 2012-08-07 21:49 - 00000000 ____A C:\Users\Andy Darko\Desktop\gmer.log
2012-08-07 21:31 - 2012-08-07 21:31 - 00302592 ____A C:\Users\Andy Darko\Downloads\ms4r4yxc.exe
2012-08-06 18:04 - 2011-07-04 14:00 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-08-04 17:58 - 2011-05-23 10:45 - 01242712 ____A C:\Windows\WindowsUpdate.log
2012-08-04 17:45 - 2012-08-04 17:42 - 18727968 ____A (Microsoft Corporation) C:\Users\Andy Darko\Downloads\mpas-fe.exe
2012-08-04 13:41 - 2012-05-07 18:20 - 00000344 ____A C:\Windows\Tasks\HPCeeScheduleForANDYDARKO$.job
2012-08-04 13:40 - 2010-11-20 19:47 - 00425210 ____A C:\Windows\PFRO.log
2012-08-04 12:13 - 2012-08-04 12:13 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-04 12:12 - 2012-08-04 12:12 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Andy Darko\Downloads\mbam-setup-1.62.0.1300.exe
2012-08-03 21:31 - 2012-08-03 21:31 - 00002175 ____A C:\Users\Public\Desktop\F-PROT Antivirus for Windows.lnk
2012-08-03 21:28 - 2012-08-03 21:26 - 36979200 ____A C:\Users\Andy Darko\Downloads\fpav-windows-x64-hc-en.msi
2012-08-03 21:23 - 2012-08-03 21:21 - 36495872 ____A C:\Users\Andy Darko\Downloads\fpav-windows-x86-hc-en.msi
2012-08-03 13:40 - 2012-08-03 13:40 - 00000169 ____A C:\Users\Andy Darko\Desktop\robdd.txt
2012-08-02 10:58 - 2012-07-19 06:55 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-02 10:58 - 2011-07-03 21:33 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-01 23:49 - 2012-08-01 23:49 - 00945272 ____A (Prevx) C:\Users\Andy Darko\Downloads\prevxcsifree.exe
2012-08-01 15:07 - 2012-04-01 12:31 - 00002340 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-08-01 06:33 - 2012-07-31 16:49 - 00007215 ____A C:\Users\Andy Darko\Desktop\to Gary.txt
2012-07-31 16:12 - 2012-07-31 16:12 - 00000120 ____A C:\Users\Andy Darko\Desktop\CONTACT IMMEDIATELY.txt
2012-07-31 09:14 - 2012-04-30 17:34 - 00000352 ____A C:\Windows\Tasks\HPCeeScheduleForAndy Darko.job
2012-07-26 14:29 - 2012-07-26 14:29 - 00000023 ____A C:\Users\Andy Darko\Desktop\suntrust app.txt
2012-07-26 03:06 - 2012-07-24 15:31 - 00006892 ____A C:\Users\Andy Darko\Desktop\jasonking.txt
2012-07-25 18:30 - 2012-07-25 18:30 - 00000120 ____A C:\Users\Andy Darko\Desktop\information.txt
2012-07-25 17:47 - 2012-07-25 17:47 - 00000034 ____A C:\Users\Andy Darko\Desktop\suntrust.txt
2012-07-25 17:31 - 2012-07-25 17:31 - 00000025 ____A C:\Users\Andy Darko\Desktop\application id.txt
2012-07-24 22:34 - 2011-10-24 20:27 - 00000000 ____A C:\Windows\System32\HP_ActiveX_Patch_NOT_DETECTED.txt
2012-07-23 20:09 - 2012-07-23 19:08 - 00005169 ____A C:\Users\Andy Darko\Desktop\rob.txt
2012-07-22 13:42 - 2012-07-22 13:42 - 00318904 ____A (Microsoft Corporation) C:\Users\Andy Darko\Downloads\wmpfirefoxplugin.exe
2012-07-20 16:21 - 2012-07-20 16:21 - 00002156 ____A C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
2012-07-20 16:20 - 2012-07-20 16:20 - 00002075 ____A C:\Users\Public\Desktop\Get CleanPrint.lnk
2012-07-20 16:15 - 2012-07-20 16:15 - 00800824 ____A (Microsoft Corporation) C:\Users\Default\AppData\Roaming\DPInst.exe
2012-07-20 16:15 - 2012-07-20 16:15 - 00800824 ____A (Microsoft Corporation) C:\Users\Default User\AppData\Roaming\DPInst.exe
2012-07-20 16:15 - 2012-07-20 16:15 - 00106496 ____A (Microsoft Corporation) C:\Users\Default\AppData\Roaming\gacutil.exe
2012-07-20 16:15 - 2012-07-20 16:15 - 00106496 ____A (Microsoft Corporation) C:\Users\Default User\AppData\Roaming\gacutil.exe
2012-07-20 16:15 - 2012-07-20 16:15 - 00036352 ____A (Microsoft Corporation) C:\Users\Default\AppData\Roaming\PnPutil.exe
2012-07-20 16:15 - 2012-07-20 16:15 - 00036352 ____A (Microsoft Corporation) C:\Users\Default User\AppData\Roaming\PnPutil.exe
2012-07-19 19:24 - 2012-07-19 19:24 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-19 19:17 - 2012-07-19 19:16 - 79225752 ____A (Apple Inc.) C:\Users\Andy Darko\Downloads\iTunes64Setup (1).exe
2012-07-19 06:49 - 2012-07-19 06:49 - 00004357 ____A C:\Windows\SysWOW64\jupdate-1.6.0_33-b05.log
2012-07-18 19:55 - 2012-07-18 19:55 - 02543054 ____A C:\Users\Andy Darko\Downloads\MuseScore-1.2.exe
2012-07-18 19:53 - 2012-07-18 19:53 - 00014186 ____A C:\Users\Andy Darko\Downloads\Its You.mid
2012-07-12 09:46 - 2009-07-13 20:45 - 00307880 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-12 01:36 - 2011-07-17 16:55 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-11 14:44 - 2012-06-12 22:20 - 00035328 __ASH C:\Users\Andy Darko\Documents\Thumbs.db
2012-07-11 13:28 - 2012-07-11 13:28 - 00000012 ____A C:\Users\Andy Darko\Desktop\mail.txt
2012-07-08 14:42 - 2012-07-08 14:42 - 00000261 ____A C:\Users\Andy Darko\Documents\LOVE QUOTE.txt
2012-07-08 11:04 - 2012-07-08 11:04 - 00000029 ____A C:\Users\Andy Darko\Documents\money.txt
2012-07-07 13:49 - 2011-07-03 14:04 - 00073992 ____A C:\Users\Andy Darko\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-06 09:59 - 2012-07-06 09:59 - 00056478 ____A C:\Users\Andy Darko\Downloads\smash_mouth_all_star.gp5
2012-07-03 21:45 - 2012-06-30 21:09 - 00003758 ____A C:\Users\Andy Darko\Documents\ROB.txt
2012-07-03 12:46 - 2012-08-04 12:13 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-03 12:21 - 2012-07-03 12:21 - 00042638 ____A C:\Users\Andy Darko\Downloads\jimmy_eat_world_the_middle (1).gp3
2012-07-03 12:01 - 2012-07-03 12:01 - 00042638 ____A C:\Users\Andy Darko\Downloads\jimmy_eat_world_the_middle.gp3
2012-07-02 02:09 - 2012-07-02 02:09 - 00000794 ____A C:\Users\Andy Darko\Desktop\important lessons to put in letters.txt
2012-07-02 01:21 - 2012-07-02 01:21 - 00000756 ____A C:\Users\Andy Darko\Desktop\claire.txt
2012-06-30 20:56 - 2012-06-30 20:56 - 05142104 ____A C:\Users\Andy Darko\Downloads\dakrchild chorus.wav
2012-06-30 15:01 - 2012-06-30 15:01 - 00001871 ____A C:\Users\Public\Desktop\Spotflux.lnk
2012-06-30 14:58 - 2012-06-30 14:58 - 10416800 ____A (Spotflux) C:\Users\Andy Darko\Downloads\spotflux-latestPC.exe
2012-06-29 01:57 - 2012-06-29 01:57 - 00000151 ____A C:\Users\Andy Darko\Desktop\for dad.txt
2012-06-28 19:23 - 2012-04-27 22:42 - 00476976 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-06-28 19:23 - 2011-04-11 10:48 - 00472880 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-06-28 19:20 - 2012-07-19 06:50 - 00157488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-06-28 19:20 - 2012-07-19 06:50 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-06-28 19:20 - 2012-07-19 06:50 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-06-26 08:46 - 2012-06-26 08:46 - 00000031 ____A C:\Users\Andy Darko\Documents\HOW MUCH MY FAMILY OWES ME.txt
2012-06-25 10:48 - 2012-06-21 10:08 - 00085316 ____A C:\Users\Andy Darko\Documents\ANDYDARKO.txt
2012-06-24 13:17 - 2012-06-24 13:17 - 00000000 ____A C:\Users\Andy Darko\Downloads\download
2012-06-21 10:07 - 2012-06-21 10:07 - 00000869 ____A C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2012-06-21 10:07 - 2012-06-21 10:06 - 04387080 ____A ( ) C:\Users\Andy Darko\Downloads\cpu-z_1.60.1-setup-en.exe
2012-06-19 16:52 - 2012-06-19 16:52 - 00038624 ____A (The OpenVPN Project) C:\Windows\System32\Drivers\tap0901.sys
2012-06-19 14:22 - 2012-06-19 14:21 - 01296320 ____A (Coupons.com Incorporated) C:\Users\Andy Darko\Downloads\CouponPrinter (2).exe
2012-06-19 14:18 - 2012-06-19 14:18 - 01284232 ____A (Coupons.com Incorporated) C:\Users\Andy Darko\Downloads\CouponPrinter (1).exe
2012-06-19 14:09 - 2012-06-19 14:09 - 01284232 ____A (Coupons.com Incorporated) C:\Users\Andy Darko\Downloads\CouponPrinter.exe
2012-06-18 08:48 - 2012-06-18 08:48 - 00122368 ____A (Eastman Kodak Company) C:\Windows\System32\EKaio2WiaCoInst.dll
2012-06-18 08:48 - 2012-06-18 08:48 - 00010240 ____A (Eastman Kodak Company) C:\Windows\System32\EKaio2WiaCoInstRes.dll
2012-06-16 14:57 - 2009-07-13 21:08 - 00032584 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-12 08:42 - 2012-06-12 08:42 - 01644544 ____A (Eastman Kodak Company) C:\Windows\System32\EKAiO2MON.dll
2012-06-12 08:41 - 2012-06-12 08:41 - 00177664 ____A (Eastman Kodak Company) C:\Windows\System32\EKAiO2COI09.dll
2012-06-11 19:08 - 2012-07-12 01:45 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-11 17:02 - 2012-06-11 17:02 - 00080149 ____A C:\Users\Andy Darko\Downloads\townlight.zip
2012-06-11 14:37 - 2012-06-11 14:37 - 00294006 ____A C:\Users\Andy Darko\Downloads\1-01 the prelude (1).zip
2012-06-11 14:34 - 2012-06-11 14:34 - 00371194 ____A C:\Users\Andy Darko\Downloads\11 aerith's theme.zip
2012-06-11 14:32 - 2012-06-11 14:32 - 00398007 ____A C:\Users\Andy Darko\Downloads\02 f[1].f.vii main theme (1).zip
2012-06-10 16:23 - 2012-06-10 16:23 - 00005575 ____A C:\Users\Andy Darko\Desktop\Jennie.txt
2012-06-08 21:43 - 2012-07-11 09:23 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 09:23 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 09:44 - 2012-06-08 09:44 - 01505819 ____A C:\Users\Andy Darko\Downloads\driver_v1t (1).zip
2012-06-07 21:34 - 2012-06-07 21:34 - 00000295 ____A C:\Users\Andy Darko\Desktop\LOOK AT TODAY!!!.txt
2012-06-06 20:41 - 2011-07-12 20:58 - 00001398 ____A C:\Users\Andy Darko\Desktop\Free YouTube to MP3 Converter.lnk
2012-06-06 20:40 - 2012-06-06 20:40 - 00001667 ____A C:\Users\Andy Darko\Desktop\avery repsonse.txt
2012-06-06 19:38 - 2012-06-06 19:36 - 27688592 ____A (DVDVideoSoft Ltd. ) C:\Users\Andy Darko\Downloads\FreeYouTubeToMP3Converter(3).exe
2012-06-05 22:06 - 2012-07-11 09:23 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 09:23 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 08:34 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 09:23 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 09:23 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 08:34 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-05 05:59 - 2012-02-24 00:31 - 00001418 ____A C:\Users\Andy Darko\Desktop\CopyTrans Control Center.lnk
2012-06-04 15:00 - 2012-06-04 15:00 - 00026288 ____A C:\Users\Andy Darko\Downloads\global_audition.zip
2012-06-04 08:31 - 2012-06-04 08:30 - 00000093 ____A C:\Users\Andy Darko\Documents\KarmaCredit.txt
2012-06-02 14:19 - 2012-06-21 08:26 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 08:26 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 08:26 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 08:25 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 08:25 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-21 08:25 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 08:26 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 08:25 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-21 08:25 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-12 01:34 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-12 01:34 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-12 01:34 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-12 01:34 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-12 01:34 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-12 01:34 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-12 01:34 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-12 01:34 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-12 01:34 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-12 01:34 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-12 01:34 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-12 01:34 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-12 01:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-12 01:34 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-12 01:34 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-12 01:34 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-12 01:34 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-12 01:34 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-12 01:34 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-12 01:34 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-12 01:34 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-12 01:34 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-12 01:34 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-12 01:34 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-12 01:34 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-12 01:34 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-12 01:34 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-12 01:34 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-11 09:23 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 09:23 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 09:23 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 09:23 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 09:23 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 09:23 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 09:23 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 09:23 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 09:23 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 11:25 - 2010-11-20 19:27 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-28 19:38 - 2011-05-23 10:47 - 00878184 ____A (Realtek Semiconductor Corporation ) C:\Windows\System32\Drivers\rtl8192ce.sys
2012-05-28 08:35 - 2012-05-28 08:35 - 00001046 ____A C:\Windows\System32\EKaio2WiaCoInst.ini
2012-05-27 13:58 - 2011-12-30 19:09 - 00009636 ____A C:\Users\Andy Darko\AppData\Local\installer.log
2012-05-23 04:44 - 2012-05-23 04:44 - 00831363 ____A C:\Users\Andy Darko\Downloads\Untitled presentation.pptx
2012-05-21 20:05 - 2012-05-21 20:05 - 00013495 ____A C:\Users\Andy Darko\Downloads\alien_league.zip
2012-05-21 20:04 - 2012-05-21 20:04 - 00166163 ____A C:\Users\Andy Darko\Downloads\earth_kid.zip
2012-05-21 10:18 - 2012-05-21 10:18 - 01505819 ____A C:\Users\Andy Darko\Downloads\driver_v1t(2).zip
2012-05-21 10:10 - 2012-05-21 10:10 - 01505819 ____A C:\Users\Andy Darko\Downloads\driver_v1t(1).zip
2012-05-20 10:58 - 2012-05-20 10:58 - 01598520 ____A (MakeMusic) C:\Users\Andy Darko\Downloads\Finale2012aWinTrial.exe
2012-05-15 09:53 - 2012-05-15 09:53 - 00571376 ____A C:\Windows\Minidump\051512-23852-01.dmp
2012-05-15 09:53 - 2011-07-27 07:19 - 327734265 ____A C:\Windows\MEMORY.DMP
2012-05-14 21:54 - 2012-05-14 21:54 - 00001114 ____A C:\Users\Public\Desktop\Finale NotePad 2012.lnk
2012-05-14 21:49 - 2012-05-14 21:44 - 102564696 ____A (MakeMusic) C:\Users\Andy Darko\Downloads\NotePad2012Win (1).exe
2012-05-14 21:48 - 2012-04-22 17:31 - 00047591 ____A C:\Users\Andy Darko\Desktop\roxanne.mus
2012-05-12 19:29 - 2012-05-12 19:29 - 00000208 ____A C:\Users\Andy Darko\Documents\tyler 3.txt
2012-05-12 13:11 - 2012-05-12 13:10 - 02717528 ____A C:\Users\Andy Darko\Downloads\Joshua_Ballman_Preview_d.wmv
2012-05-12 13:08 - 2012-05-12 13:08 - 02514908 ____A C:\Users\Andy Darko\Downloads\Will_Steiger_Preview_d.wmv
2012-05-11 11:18 - 2012-05-11 11:18 - 00043636 ____A C:\Users\Andy Darko\Downloads\collegiateflf.zip
2012-05-11 11:18 - 2012-05-11 11:18 - 00043636 ____A C:\Users\Andy Darko\Downloads\collegiateflf (1).zip
2012-05-11 11:17 - 2012-05-11 11:16 - 00304718 ____A C:\Users\Andy Darko\Downloads\colleged.zip
ZeroAccess:
C:\Users\Andy Darko\AppData\Local\{e82f9450-296c-c67b-4b55-b9c9491facb5}
C:\Users\Andy Darko\AppData\Local\{e82f9450-296c-c67b-4b55-b9c9491facb5}\@
C:\Users\Andy Darko\AppData\Local\{e82f9450-296c-c67b-4b55-b9c9491facb5}\L
C:\Users\Andy Darko\AppData\Local\{e82f9450-296c-c67b-4b55-b9c9491facb5}\n
C:\Users\Andy Darko\AppData\Local\{e82f9450-296c-c67b-4b55-b9c9491facb5}\U
C:\Users\Andy Darko\AppData\Local\{e82f9450-296c-c67b-4b55-b9c9491facb5}\U\00000001.@
C:\Users\Andy Darko\AppData\Local\{e82f9450-296c-c67b-4b55-b9c9491facb5}\U\800000cb.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 24%
Total physical RAM: 2666.91 MB
Available physical RAM: 2025.93 MB
Total Pagefile: 2665.05 MB
Available Pagefile: 2017.25 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:284.06 GB) (Free:212.84 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (RECOVERY) (Fixed) (Total:13.74 GB) (Free:0.23 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
5 Drive h: (HP v100w) (Removable) (Total:7.44 GB) (Free:1.14 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 7628 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 284 GB 200 MB
Partition 3 Primary 13 GB 284 GB
Partition 4 Primary 103 MB 297 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 199 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 284 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E RECOVERY NTFS Partition 13 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F HP_TOOLS FAT32 Partition 103 MB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7624 MB 4032 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H HP v100w FAT32 Removable 7624 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-07 14:14
======================= End Of Log ==========================