I am also infected with sirefef and get the 1 minute restarts. I did the FRST scan and my log is below. I ran the scan when my computer was not connected to the internet - hopefully that doesn't matter?
Thanks!
Scan result of Farbar Recovery Scan Tool Version: 04-08-2012 01
Ran by SYSTEM at 05-08-2012 12:00:27
Running from H:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry [x]
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [61440 2010-02-10] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\Guest\...\Run: [Facebook Update] "C:\Users\Guest\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-12] (Facebook Inc.)
HKU\jaylew\...\Run: [EPSON Artisan 50 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFFA.EXE /FU "C:\Windows\TEMP\E_S1E78.tmp" /EF "HKCU" [223232 2008-10-09] (SEIKO EPSON CORPORATION)
HKU\jaylew\...\Run: [Google Update] "C:\Users\jaylew\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2012-02-17] (Google Inc.)
HKU\jaylew\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\jaylew\...\Run: [NETGEARGenie] "C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe" -mini -redirect [1091872 2012-03-12] ()
HKU\jaylew\...\Run: [OpenDNS Updater] "C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe" /autostart [839680 2010-06-16] ()
HKU\jaylew\...\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart [12163848 2012-06-20] (Google)
HKU\jaylew\...\Run: [sdrfs] "C:\Windows\System32\rundll32.exe" "C:\Users\jaylew\AppData\Roaming\sdrfs.dll",read_info [401920 2012-07-27] (Stardock Systems, Inc)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\jaylew\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
==================== Services (Whitelisted) ======
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [1370400 2012-03-06] (NETGEAR)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [624856 2012-04-06] (Pandora.TV)
========================== Drivers (Whitelisted) =============
3 E100B; C:\Windows\System32\DRIVERS\efe5b32e.sys [192256 2009-06-10] (Intel Corporation)
2 NPF; C:\Windows\System32\Drivers\NPF.sys [35344 2012-05-10] (CACE Technologies, Inc.)
3 P17; C:\Windows\System32\Drivers\P17.sys [1309696 2009-10-16] (Creative Technology Ltd.)
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-04 12:33 - 2012-08-04 12:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.511C2FC13589DA82
2012-08-04 12:30 - 2012-08-04 12:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A2BFB6E870E35404
2012-08-04 12:27 - 2012-08-04 12:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.990923A08F656C41
2012-08-04 12:23 - 2012-08-04 12:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.68A7E0F2A554FEF2
2012-08-04 12:12 - 2012-08-04 12:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33FB91C51B47D9C0
2012-08-04 12:08 - 2012-08-04 12:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6784E76DC6DD6797
2012-08-04 11:36 - 2012-08-04 11:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.410F7019A3E47DF6
2012-08-04 11:33 - 2012-08-04 11:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88E4748589F250E6
2012-08-04 11:30 - 2012-08-04 11:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.50D44AC29DDC02EA
2012-08-04 11:26 - 2012-08-04 11:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5B83AD76B728BE57
2012-08-04 11:23 - 2012-08-04 11:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0B04096029ACE34A
2012-08-04 11:20 - 2012-08-04 11:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.076AF708EFE19D25
2012-08-04 11:18 - 2012-08-04 11:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2031C523EC85A960
2012-08-04 11:15 - 2012-08-04 11:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F8FA3A42C6AC1938
2012-08-04 11:12 - 2012-08-04 11:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B039D8C3437240D4
2012-08-04 11:08 - 2012-08-04 11:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D9450E568C651AAB
2012-08-04 11:05 - 2012-08-04 11:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B241077791B7EC74
2012-08-02 19:27 - 2012-08-02 19:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5B7CEC5ECBDB852E
2012-08-02 19:23 - 2012-08-02 19:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.35CD4692C176A4D1
2012-08-02 19:20 - 2012-08-02 19:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.839AF74635CCB65C
2012-08-02 19:16 - 2012-08-02 19:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5F62BF72FA33FAF
2012-08-02 19:13 - 2012-08-02 19:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.04EEAB4BB4ECD247
2012-08-02 19:10 - 2012-08-02 19:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8695B827054DC989
2012-08-02 19:07 - 2012-08-02 19:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B1E37CF3108BA47B
2012-08-02 19:04 - 2012-08-02 19:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7FFEFC6FC8B42D9
2012-08-02 19:00 - 2012-08-02 19:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.163DEE6D53864250
2012-08-02 18:58 - 2012-08-02 18:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F13ABBCBCDDB242
2012-08-02 18:54 - 2012-08-02 18:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B7DC66BA2866782
2012-08-02 18:51 - 2012-08-02 18:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3C535F3BFD8A7E43
2012-08-02 18:47 - 2012-08-02 18:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E8BDAE26EE54E693
2012-08-02 18:44 - 2012-08-02 18:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94FA46219A300B86
2012-08-02 18:41 - 2012-08-02 18:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8A0B5266BCBAF16
2012-07-30 17:26 - 2012-07-30 17:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A0E5FD3F6A654672
2012-07-30 17:20 - 2012-07-30 17:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5499FC4136D0A7E0
2012-07-30 17:16 - 2012-07-30 17:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D519A640993AB49
2012-07-30 17:11 - 2012-07-30 17:12 - 12621696 ____A (Microsoft Corporation) C:\Users\jaylew\Downloads\mseinstall(2).exe
2012-07-30 17:10 - 2012-07-30 17:10 - 00347424 ____A (Microsoft Corporation) C:\Users\jaylew\Downloads\MicrosoftFixit.WindowsFirewall.RNP.136267127798690248.1.1.Run.exe
2012-07-30 17:07 - 2009-07-13 17:14 - 00020480 ____A (Microsoft Corporation) C:\Windows\svchost.exe
2012-07-29 11:21 - 2012-07-29 11:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4185522F09C7AE52
2012-07-29 11:18 - 2012-07-29 11:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1A2729A2C5765B40
2012-07-29 11:15 - 2012-07-29 11:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FBFD2CE184A71BFB
2012-07-29 11:10 - 2012-07-29 11:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C8FB6A31690A5334
2012-07-29 11:10 - 2012-07-29 11:10 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\pxcohblz.sys
2012-07-29 11:07 - 2012-07-29 11:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9F79618A4DD2055
2012-07-29 11:04 - 2012-07-29 11:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.024B0C076D4EC22F
2012-07-29 11:01 - 2012-07-29 11:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66209165ABCC3DEC
2012-07-29 10:56 - 2012-07-29 10:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F90D1581347F5587
2012-07-29 10:53 - 2012-07-29 10:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.959B83F37C14C8B4
2012-07-29 10:49 - 2012-07-29 10:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3FC97012005433FC
2012-07-29 10:42 - 2012-07-30 17:12 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-29 10:42 - 2012-07-30 17:12 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-29 10:41 - 2012-07-29 10:41 - 12621696 ____A (Microsoft Corporation) C:\Users\jaylew\Downloads\mseinstall(1).exe
2012-07-27 08:37 - 2012-07-27 08:37 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-07-27 08:32 - 2012-07-27 08:32 - 00401920 ____A (Stardock Systems, Inc) C:\Users\jaylew\AppData\Roaming\sdrfs.dll
2012-07-27 08:32 - 2012-07-27 08:32 - 00000000 ____D C:\Users\jaylew\AppData\Local\{AE9C995C-D808-11E1-8270-B8AC6F996F26}
2012-07-27 08:32 - 2012-07-27 08:32 - 00000000 ____D C:\Users\jaylew\AppData\Local\{AE9C5E63-D808-11E1-8270-B8AC6F996F26}
2012-07-27 08:31 - 2012-07-27 08:31 - 00138752 ____A C:\Users\jaylew\AppData\Roaming\patbrt.dll
2012-07-25 06:45 - 2012-07-25 06:45 - 04419192 ____A (Krzysztof Kowalczyk) C:\Users\jaylew\Downloads\SumatraPDF-2.1.1-install.exe
2012-07-25 06:30 - 2012-07-25 06:30 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-25 06:29 - 2012-07-25 06:30 - 00000000 ____D C:\Program Files\iTunes
2012-07-25 06:29 - 2012-07-25 06:30 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-07-25 06:29 - 2012-07-25 06:29 - 00000000 ____D C:\Program Files\iPod
2012-07-25 06:25 - 2012-07-25 06:25 - 00001845 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-07-25 06:25 - 2012-07-25 06:25 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-07-21 22:20 - 2012-02-29 21:30 - 00000517 ____A C:\Users\jaylew\Downloads\.htaccess
2012-07-19 14:12 - 2012-07-19 14:12 - 00002687 ____A C:\Users\jaylew\Desktop\alg2_syllabus1_0.txt
2012-07-11 00:20 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 00:00 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 00:00 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 00:00 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 00:00 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 00:00 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 00:00 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 00:00 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 00:00 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 00:00 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 00:00 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 00:00 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 00:00 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 00:00 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 00:00 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 00:00 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 00:00 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 00:00 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 00:00 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 00:00 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 00:00 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 00:00 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 00:00 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 00:00 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 00:00 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 00:00 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 00:00 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 00:00 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 00:00 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-10 16:19 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 16:19 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 16:19 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 16:19 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 16:19 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 16:19 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 16:19 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 16:19 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-10 16:19 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 16:19 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 16:19 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 16:19 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 16:19 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 16:19 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 16:19 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 16:19 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 16:19 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-10 16:19 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-07-10 16:19 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-07-10 16:19 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-07-10 16:19 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-07-10 16:19 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-07-10 16:19 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-07-10 16:19 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-10 16:19 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-10 09:54 - 2012-07-21 22:23 - 00000000 ____D C:\Users\jaylew\AppData\Roaming\Cyberduck
2012-07-10 09:54 - 2012-07-21 21:57 - 00000000 __SHD C:\Users\jaylew\wc
2012-07-10 09:54 - 2012-07-10 09:54 - 00000000 __SHD C:\Users\jaylew\AppData\Roaming\wyUpdate AU
2012-07-10 09:51 - 2012-07-10 09:51 - 00001023 ____A C:\Users\Public\Desktop\Cyberduck.lnk
2012-07-10 09:42 - 2012-07-10 09:51 - 00000000 ____D C:\Program Files (x86)\Cyberduck
2012-07-10 09:35 - 2012-07-10 09:35 - 13928312 ____A C:\Users\jaylew\Downloads\Cyberduck-Installer-4.2.1.exe
============ 3 Months Modified Files ========================
2012-08-05 08:44 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-05 08:44 - 2009-07-13 20:51 - 00029709 ____A C:\Windows\setupact.log
2012-08-04 12:33 - 2012-08-04 12:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.511C2FC13589DA82
2012-08-04 12:32 - 2012-05-23 15:39 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-04 12:30 - 2012-08-04 12:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A2BFB6E870E35404
2012-08-04 12:29 - 2012-05-23 15:39 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-04 12:27 - 2012-08-04 12:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.990923A08F656C41
2012-08-04 12:23 - 2012-08-04 12:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.68A7E0F2A554FEF2
2012-08-04 12:12 - 2012-08-04 12:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33FB91C51B47D9C0
2012-08-04 12:08 - 2012-08-04 12:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6784E76DC6DD6797
2012-08-04 11:36 - 2012-08-04 11:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.410F7019A3E47DF6
2012-08-04 11:34 - 2009-07-13 21:08 - 00032560 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-04 11:33 - 2012-08-04 11:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88E4748589F250E6
2012-08-04 11:30 - 2012-08-04 11:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.50D44AC29DDC02EA
2012-08-04 11:26 - 2012-08-04 11:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5B83AD76B728BE57
2012-08-04 11:23 - 2012-08-04 11:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0B04096029ACE34A
2012-08-04 11:21 - 2012-02-17 18:38 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2572511198-3776155673-3006782383-1001UA.job
2012-08-04 11:20 - 2012-08-04 11:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.076AF708EFE19D25
2012-08-04 11:18 - 2012-08-04 11:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2031C523EC85A960
2012-08-04 11:15 - 2012-08-04 11:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F8FA3A42C6AC1938
2012-08-04 11:12 - 2012-08-04 11:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B039D8C3437240D4
2012-08-04 11:08 - 2012-08-04 11:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D9450E568C651AAB
2012-08-04 11:05 - 2012-08-04 11:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B241077791B7EC74
2012-08-02 19:27 - 2012-08-02 19:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5B7CEC5ECBDB852E
2012-08-02 19:23 - 2012-08-02 19:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.35CD4692C176A4D1
2012-08-02 19:20 - 2012-08-02 19:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.839AF74635CCB65C
2012-08-02 19:16 - 2012-08-02 19:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5F62BF72FA33FAF
2012-08-02 19:13 - 2012-08-02 19:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.04EEAB4BB4ECD247
2012-08-02 19:10 - 2012-08-02 19:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8695B827054DC989
2012-08-02 19:07 - 2012-08-02 19:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B1E37CF3108BA47B
2012-08-02 19:04 - 2012-08-02 19:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7FFEFC6FC8B42D9
2012-08-02 19:00 - 2012-08-02 19:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.163DEE6D53864250
2012-08-02 18:58 - 2012-08-02 18:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F13ABBCBCDDB242
2012-08-02 18:54 - 2012-08-02 18:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B7DC66BA2866782
2012-08-02 18:51 - 2012-08-02 18:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3C535F3BFD8A7E43
2012-08-02 18:47 - 2012-08-02 18:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E8BDAE26EE54E693
2012-08-02 18:44 - 2012-08-02 18:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94FA46219A300B86
2012-08-02 18:41 - 2012-08-02 18:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8A0B5266BCBAF16
2012-07-30 17:26 - 2012-07-30 17:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A0E5FD3F6A654672
2012-07-30 17:20 - 2012-07-30 17:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5499FC4136D0A7E0
2012-07-30 17:16 - 2012-07-30 17:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D519A640993AB49
2012-07-30 17:13 - 2012-02-15 17:00 - 01572903 ____A C:\Windows\WindowsUpdate.log
2012-07-30 17:13 - 2012-02-15 15:54 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-30 17:12 - 2012-07-30 17:11 - 12621696 ____A (Microsoft Corporation) C:\Users\jaylew\Downloads\mseinstall(2).exe
2012-07-30 17:11 - 2009-07-13 21:13 - 00729514 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-30 17:10 - 2012-07-30 17:10 - 00347424 ____A (Microsoft Corporation) C:\Users\jaylew\Downloads\MicrosoftFixit.WindowsFirewall.RNP.136267127798690248.1.1.Run.exe
2012-07-30 17:06 - 2012-02-15 15:55 - 00008876 ____A C:\Windows\PFRO.log
2012-07-30 17:06 - 2009-07-13 20:45 - 00016640 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-30 17:06 - 2009-07-13 20:45 - 00016640 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-30 16:26 - 2012-02-17 18:38 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2572511198-3776155673-3006782383-1001Core.job
2012-07-29 11:21 - 2012-07-29 11:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4185522F09C7AE52
2012-07-29 11:18 - 2012-07-29 11:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1A2729A2C5765B40
2012-07-29 11:15 - 2012-07-29 11:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FBFD2CE184A71BFB
2012-07-29 11:10 - 2012-07-29 11:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C8FB6A31690A5334
2012-07-29 11:10 - 2012-07-29 11:10 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\pxcohblz.sys
2012-07-29 11:07 - 2012-07-29 11:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9F79618A4DD2055
2012-07-29 11:04 - 2012-07-29 11:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.024B0C076D4EC22F
2012-07-29 11:01 - 2012-07-29 11:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66209165ABCC3DEC
2012-07-29 10:56 - 2012-07-29 10:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F90D1581347F5587
2012-07-29 10:53 - 2012-07-29 10:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.959B83F37C14C8B4
2012-07-29 10:49 - 2012-07-29 10:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3FC97012005433FC
2012-07-29 10:42 - 2012-02-15 15:54 - 00742892 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-29 10:41 - 2012-07-29 10:41 - 12621696 ____A (Microsoft Corporation) C:\Users\jaylew\Downloads\mseinstall(1).exe
2012-07-27 08:32 - 2012-07-27 08:32 - 00401920 ____A (Stardock Systems, Inc) C:\Users\jaylew\AppData\Roaming\sdrfs.dll
2012-07-27 08:32 - 2012-04-02 13:54 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-27 08:32 - 2012-02-15 22:54 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-27 08:31 - 2012-07-27 08:31 - 00138752 ____A C:\Users\jaylew\AppData\Roaming\patbrt.dll
2012-07-25 06:45 - 2012-07-25 06:45 - 04419192 ____A (Krzysztof Kowalczyk) C:\Users\jaylew\Downloads\SumatraPDF-2.1.1-install.exe
2012-07-25 06:30 - 2012-07-25 06:30 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-25 06:25 - 2012-07-25 06:25 - 00001845 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-07-19 14:12 - 2012-07-19 14:12 - 00002687 ____A C:\Users\jaylew\Desktop\alg2_syllabus1_0.txt
2012-07-12 05:18 - 2012-02-17 18:39 - 00002407 ____A C:\Users\jaylew\Desktop\Google Chrome.lnk
2012-07-11 00:37 - 2009-07-13 20:45 - 00309944 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 00:04 - 2012-02-18 16:17 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-10 09:51 - 2012-07-10 09:51 - 00001023 ____A C:\Users\Public\Desktop\Cyberduck.lnk
2012-07-10 09:35 - 2012-07-10 09:35 - 13928312 ____A C:\Users\jaylew\Downloads\Cyberduck-Installer-4.2.1.exe
2012-07-06 01:32 - 2012-07-04 23:09 - 00012756 ____A C:\Users\jaylew\Desktop\supplies.ods
2012-07-06 01:32 - 2012-07-02 02:27 - 00025953 ____A C:\Users\jaylew\Desktop\experiments.odt
2012-07-02 02:31 - 2012-07-02 02:30 - 58619658 ____A C:\Users\jaylew\Downloads\FJ5ZCXMFVO9RGPR.mov
2012-06-26 12:35 - 2012-06-26 12:35 - 00739832 ____A (Google Inc.) C:\Users\jaylew\Downloads\GoogleVoiceAndVideoSetup.exe
2012-06-25 06:08 - 2012-06-25 06:08 - 00000968 ____A C:\Users\jaylew\Desktop\Free Hide Folder.lnk
2012-06-25 06:08 - 2012-06-25 06:08 - 00000968 ____A C:\Users\Guest\Desktop\Free Hide Folder.lnk
2012-06-25 06:07 - 2012-06-25 06:07 - 00895896 ____A C:\Users\jaylew\Downloads\FHFSetup.exe
2012-06-11 19:08 - 2012-07-11 00:20 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-10 16:19 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-10 16:19 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-10 16:19 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-10 16:19 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-10 16:19 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-10 16:19 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-10 16:19 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-10 16:19 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-22 06:59 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-22 06:59 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-22 06:59 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-22 06:59 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-22 06:59 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-22 06:59 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-22 06:59 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 12:19 - 2012-06-22 06:58 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:15 - 2012-06-22 06:58 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-11 00:00 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 00:00 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 00:00 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 00:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 00:00 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 00:00 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 00:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 00:00 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 00:00 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 00:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 00:00 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 00:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 00:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 00:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 00:00 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 00:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 00:00 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 00:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 00:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 00:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 00:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 00:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 00:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 00:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 00:00 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 00:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 00:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 00:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-10 16:19 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-10 16:19 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-10 16:19 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-10 16:19 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-10 16:19 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-10 16:19 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-10 16:19 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-10 16:19 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-10 16:19 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 19:05 - 2012-05-31 19:05 - 00358246 ____A C:\Users\jaylew\Downloads\Attachments_2012_05_31(1).zip
2012-05-31 18:50 - 2012-05-31 18:50 - 01093184 ____A C:\Users\jaylew\Downloads\Attachments_2012_05_31.zip
2012-05-26 15:21 - 2012-02-16 14:43 - 00001738 ____A C:\Users\jaylew\Desktop\Rainmeter.lnk
2012-05-23 15:41 - 2012-05-23 15:41 - 00001701 ____A C:\Users\jaylew\Desktop\Google Drive.lnk
2012-05-10 21:17 - 2012-05-10 21:16 - 00225336 ____A C:\Users\jaylew\Downloads\OpenDNS-Updater-2.2.1.exe
2012-05-10 20:50 - 2012-02-29 14:23 - 00066984 ____A C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-10 20:06 - 2012-05-10 20:06 - 00198384 ____A C:\Users\jaylew\Downloads\NETGEARUserUtility-1.0b40-install.exe
2012-05-10 17:05 - 2012-05-10 17:05 - 00369168 ____A (CACE Technologies, Inc.) C:\Windows\System32\wpcap.dll
2012-05-10 17:05 - 2012-05-10 17:05 - 00281104 ____A (CACE Technologies, Inc.) C:\Windows\SysWOW64\wpcap.dll
2012-05-10 17:05 - 2012-05-10 17:05 - 00106000 ____A (CACE Technologies, Inc.) C:\Windows\System32\packet.dll
2012-05-10 17:05 - 2012-05-10 17:05 - 00096784 ____A (CACE Technologies, Inc.) C:\Windows\SysWOW64\packet.dll
2012-05-10 17:05 - 2012-05-10 17:05 - 00035344 ____A (CACE Technologies, Inc.) C:\Windows\System32\Drivers\npf.sys
2012-05-10 17:05 - 2012-05-10 17:05 - 00002060 ____A C:\Users\Public\Desktop\NETGEAR Genie.lnk
2012-05-10 17:03 - 2012-05-10 17:03 - 15375408 ____A (NETGEAR Inc.) C:\Users\jaylew\Downloads\NETGEARGenie-install.exe
2012-05-10 16:43 - 2012-02-15 15:55 - 00066984 ____A C:\Users\jaylew\AppData\Local\GDIPFONTCACHEV1.DAT
ZeroAccess:
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\@
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\L
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\n
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\U
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\L\00000004.@
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\L\201d3dde
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\U\00000008.@
ZeroAccess:
C:\Users\jaylew\AppData\Local\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}
C:\Users\jaylew\AppData\Local\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\@
C:\Users\jaylew\AppData\Local\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\L
C:\Users\jaylew\AppData\Local\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\U
Possible partition infection:
C:\Windows\svchost.exe
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3582.16 MB
Available physical RAM: 3023.91 MB
Total Pagefile: 3580.31 MB
Available Pagefile: 3022.55 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:55.8 GB) (Free:23.73 GB) NTFS
2 Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive h: (Transcend) (Removable) (Total:3.73 GB) (Free:1.82 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: () (Fixed) (Total:143.97 GB) (Free:13.24 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 0 B
Disk 1 Online 55 GB 0 B
Disk 2 Online 3830 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 47 MB 31 KB
Partition 2 Primary 143 GB 47 MB
Partition 3 Primary 5114 MB 144 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 FAT Partition 47 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 Y NTFS Partition 143 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : DB
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 55 GB 101 MB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 C NTFS Partition 55 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3826 MB 4096 KB
==================================================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H Transcend FAT32 Removable 3826 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-27 22:04
======================= End Of Log ==========================
Thanks!
Scan result of Farbar Recovery Scan Tool Version: 04-08-2012 01
Ran by SYSTEM at 05-08-2012 12:00:27
Running from H:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry [x]
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [61440 2010-02-10] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\Guest\...\Run: [Facebook Update] "C:\Users\Guest\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-12] (Facebook Inc.)
HKU\jaylew\...\Run: [EPSON Artisan 50 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFFA.EXE /FU "C:\Windows\TEMP\E_S1E78.tmp" /EF "HKCU" [223232 2008-10-09] (SEIKO EPSON CORPORATION)
HKU\jaylew\...\Run: [Google Update] "C:\Users\jaylew\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2012-02-17] (Google Inc.)
HKU\jaylew\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\jaylew\...\Run: [NETGEARGenie] "C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe" -mini -redirect [1091872 2012-03-12] ()
HKU\jaylew\...\Run: [OpenDNS Updater] "C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe" /autostart [839680 2010-06-16] ()
HKU\jaylew\...\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart [12163848 2012-06-20] (Google)
HKU\jaylew\...\Run: [sdrfs] "C:\Windows\System32\rundll32.exe" "C:\Users\jaylew\AppData\Roaming\sdrfs.dll",read_info [401920 2012-07-27] (Stardock Systems, Inc)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\jaylew\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
==================== Services (Whitelisted) ======
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [1370400 2012-03-06] (NETGEAR)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [624856 2012-04-06] (Pandora.TV)
========================== Drivers (Whitelisted) =============
3 E100B; C:\Windows\System32\DRIVERS\efe5b32e.sys [192256 2009-06-10] (Intel Corporation)
2 NPF; C:\Windows\System32\Drivers\NPF.sys [35344 2012-05-10] (CACE Technologies, Inc.)
3 P17; C:\Windows\System32\Drivers\P17.sys [1309696 2009-10-16] (Creative Technology Ltd.)
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-04 12:33 - 2012-08-04 12:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.511C2FC13589DA82
2012-08-04 12:30 - 2012-08-04 12:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A2BFB6E870E35404
2012-08-04 12:27 - 2012-08-04 12:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.990923A08F656C41
2012-08-04 12:23 - 2012-08-04 12:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.68A7E0F2A554FEF2
2012-08-04 12:12 - 2012-08-04 12:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33FB91C51B47D9C0
2012-08-04 12:08 - 2012-08-04 12:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6784E76DC6DD6797
2012-08-04 11:36 - 2012-08-04 11:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.410F7019A3E47DF6
2012-08-04 11:33 - 2012-08-04 11:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88E4748589F250E6
2012-08-04 11:30 - 2012-08-04 11:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.50D44AC29DDC02EA
2012-08-04 11:26 - 2012-08-04 11:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5B83AD76B728BE57
2012-08-04 11:23 - 2012-08-04 11:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0B04096029ACE34A
2012-08-04 11:20 - 2012-08-04 11:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.076AF708EFE19D25
2012-08-04 11:18 - 2012-08-04 11:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2031C523EC85A960
2012-08-04 11:15 - 2012-08-04 11:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F8FA3A42C6AC1938
2012-08-04 11:12 - 2012-08-04 11:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B039D8C3437240D4
2012-08-04 11:08 - 2012-08-04 11:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D9450E568C651AAB
2012-08-04 11:05 - 2012-08-04 11:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B241077791B7EC74
2012-08-02 19:27 - 2012-08-02 19:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5B7CEC5ECBDB852E
2012-08-02 19:23 - 2012-08-02 19:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.35CD4692C176A4D1
2012-08-02 19:20 - 2012-08-02 19:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.839AF74635CCB65C
2012-08-02 19:16 - 2012-08-02 19:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5F62BF72FA33FAF
2012-08-02 19:13 - 2012-08-02 19:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.04EEAB4BB4ECD247
2012-08-02 19:10 - 2012-08-02 19:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8695B827054DC989
2012-08-02 19:07 - 2012-08-02 19:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B1E37CF3108BA47B
2012-08-02 19:04 - 2012-08-02 19:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7FFEFC6FC8B42D9
2012-08-02 19:00 - 2012-08-02 19:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.163DEE6D53864250
2012-08-02 18:58 - 2012-08-02 18:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F13ABBCBCDDB242
2012-08-02 18:54 - 2012-08-02 18:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B7DC66BA2866782
2012-08-02 18:51 - 2012-08-02 18:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3C535F3BFD8A7E43
2012-08-02 18:47 - 2012-08-02 18:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E8BDAE26EE54E693
2012-08-02 18:44 - 2012-08-02 18:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94FA46219A300B86
2012-08-02 18:41 - 2012-08-02 18:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8A0B5266BCBAF16
2012-07-30 17:26 - 2012-07-30 17:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A0E5FD3F6A654672
2012-07-30 17:20 - 2012-07-30 17:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5499FC4136D0A7E0
2012-07-30 17:16 - 2012-07-30 17:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D519A640993AB49
2012-07-30 17:11 - 2012-07-30 17:12 - 12621696 ____A (Microsoft Corporation) C:\Users\jaylew\Downloads\mseinstall(2).exe
2012-07-30 17:10 - 2012-07-30 17:10 - 00347424 ____A (Microsoft Corporation) C:\Users\jaylew\Downloads\MicrosoftFixit.WindowsFirewall.RNP.136267127798690248.1.1.Run.exe
2012-07-30 17:07 - 2009-07-13 17:14 - 00020480 ____A (Microsoft Corporation) C:\Windows\svchost.exe
2012-07-29 11:21 - 2012-07-29 11:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4185522F09C7AE52
2012-07-29 11:18 - 2012-07-29 11:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1A2729A2C5765B40
2012-07-29 11:15 - 2012-07-29 11:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FBFD2CE184A71BFB
2012-07-29 11:10 - 2012-07-29 11:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C8FB6A31690A5334
2012-07-29 11:10 - 2012-07-29 11:10 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\pxcohblz.sys
2012-07-29 11:07 - 2012-07-29 11:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9F79618A4DD2055
2012-07-29 11:04 - 2012-07-29 11:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.024B0C076D4EC22F
2012-07-29 11:01 - 2012-07-29 11:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66209165ABCC3DEC
2012-07-29 10:56 - 2012-07-29 10:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F90D1581347F5587
2012-07-29 10:53 - 2012-07-29 10:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.959B83F37C14C8B4
2012-07-29 10:49 - 2012-07-29 10:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3FC97012005433FC
2012-07-29 10:42 - 2012-07-30 17:12 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-29 10:42 - 2012-07-30 17:12 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-29 10:41 - 2012-07-29 10:41 - 12621696 ____A (Microsoft Corporation) C:\Users\jaylew\Downloads\mseinstall(1).exe
2012-07-27 08:37 - 2012-07-27 08:37 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-07-27 08:32 - 2012-07-27 08:32 - 00401920 ____A (Stardock Systems, Inc) C:\Users\jaylew\AppData\Roaming\sdrfs.dll
2012-07-27 08:32 - 2012-07-27 08:32 - 00000000 ____D C:\Users\jaylew\AppData\Local\{AE9C995C-D808-11E1-8270-B8AC6F996F26}
2012-07-27 08:32 - 2012-07-27 08:32 - 00000000 ____D C:\Users\jaylew\AppData\Local\{AE9C5E63-D808-11E1-8270-B8AC6F996F26}
2012-07-27 08:31 - 2012-07-27 08:31 - 00138752 ____A C:\Users\jaylew\AppData\Roaming\patbrt.dll
2012-07-25 06:45 - 2012-07-25 06:45 - 04419192 ____A (Krzysztof Kowalczyk) C:\Users\jaylew\Downloads\SumatraPDF-2.1.1-install.exe
2012-07-25 06:30 - 2012-07-25 06:30 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-25 06:29 - 2012-07-25 06:30 - 00000000 ____D C:\Program Files\iTunes
2012-07-25 06:29 - 2012-07-25 06:30 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-07-25 06:29 - 2012-07-25 06:29 - 00000000 ____D C:\Program Files\iPod
2012-07-25 06:25 - 2012-07-25 06:25 - 00001845 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-07-25 06:25 - 2012-07-25 06:25 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-07-21 22:20 - 2012-02-29 21:30 - 00000517 ____A C:\Users\jaylew\Downloads\.htaccess
2012-07-19 14:12 - 2012-07-19 14:12 - 00002687 ____A C:\Users\jaylew\Desktop\alg2_syllabus1_0.txt
2012-07-11 00:20 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 00:00 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 00:00 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 00:00 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 00:00 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 00:00 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 00:00 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 00:00 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 00:00 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 00:00 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 00:00 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 00:00 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 00:00 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 00:00 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 00:00 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 00:00 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 00:00 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 00:00 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 00:00 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 00:00 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 00:00 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 00:00 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 00:00 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 00:00 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 00:00 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 00:00 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 00:00 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 00:00 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 00:00 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-10 16:19 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 16:19 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 16:19 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 16:19 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 16:19 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 16:19 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 16:19 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 16:19 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-10 16:19 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 16:19 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 16:19 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 16:19 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 16:19 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 16:19 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 16:19 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 16:19 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 16:19 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-10 16:19 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-07-10 16:19 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-07-10 16:19 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-07-10 16:19 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-07-10 16:19 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-07-10 16:19 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-07-10 16:19 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-10 16:19 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-10 09:54 - 2012-07-21 22:23 - 00000000 ____D C:\Users\jaylew\AppData\Roaming\Cyberduck
2012-07-10 09:54 - 2012-07-21 21:57 - 00000000 __SHD C:\Users\jaylew\wc
2012-07-10 09:54 - 2012-07-10 09:54 - 00000000 __SHD C:\Users\jaylew\AppData\Roaming\wyUpdate AU
2012-07-10 09:51 - 2012-07-10 09:51 - 00001023 ____A C:\Users\Public\Desktop\Cyberduck.lnk
2012-07-10 09:42 - 2012-07-10 09:51 - 00000000 ____D C:\Program Files (x86)\Cyberduck
2012-07-10 09:35 - 2012-07-10 09:35 - 13928312 ____A C:\Users\jaylew\Downloads\Cyberduck-Installer-4.2.1.exe
============ 3 Months Modified Files ========================
2012-08-05 08:44 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-05 08:44 - 2009-07-13 20:51 - 00029709 ____A C:\Windows\setupact.log
2012-08-04 12:33 - 2012-08-04 12:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.511C2FC13589DA82
2012-08-04 12:32 - 2012-05-23 15:39 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-04 12:30 - 2012-08-04 12:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A2BFB6E870E35404
2012-08-04 12:29 - 2012-05-23 15:39 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-04 12:27 - 2012-08-04 12:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.990923A08F656C41
2012-08-04 12:23 - 2012-08-04 12:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.68A7E0F2A554FEF2
2012-08-04 12:12 - 2012-08-04 12:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33FB91C51B47D9C0
2012-08-04 12:08 - 2012-08-04 12:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6784E76DC6DD6797
2012-08-04 11:36 - 2012-08-04 11:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.410F7019A3E47DF6
2012-08-04 11:34 - 2009-07-13 21:08 - 00032560 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-04 11:33 - 2012-08-04 11:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88E4748589F250E6
2012-08-04 11:30 - 2012-08-04 11:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.50D44AC29DDC02EA
2012-08-04 11:26 - 2012-08-04 11:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5B83AD76B728BE57
2012-08-04 11:23 - 2012-08-04 11:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0B04096029ACE34A
2012-08-04 11:21 - 2012-02-17 18:38 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2572511198-3776155673-3006782383-1001UA.job
2012-08-04 11:20 - 2012-08-04 11:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.076AF708EFE19D25
2012-08-04 11:18 - 2012-08-04 11:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2031C523EC85A960
2012-08-04 11:15 - 2012-08-04 11:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F8FA3A42C6AC1938
2012-08-04 11:12 - 2012-08-04 11:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B039D8C3437240D4
2012-08-04 11:08 - 2012-08-04 11:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D9450E568C651AAB
2012-08-04 11:05 - 2012-08-04 11:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B241077791B7EC74
2012-08-02 19:27 - 2012-08-02 19:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5B7CEC5ECBDB852E
2012-08-02 19:23 - 2012-08-02 19:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.35CD4692C176A4D1
2012-08-02 19:20 - 2012-08-02 19:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.839AF74635CCB65C
2012-08-02 19:16 - 2012-08-02 19:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5F62BF72FA33FAF
2012-08-02 19:13 - 2012-08-02 19:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.04EEAB4BB4ECD247
2012-08-02 19:10 - 2012-08-02 19:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8695B827054DC989
2012-08-02 19:07 - 2012-08-02 19:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B1E37CF3108BA47B
2012-08-02 19:04 - 2012-08-02 19:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7FFEFC6FC8B42D9
2012-08-02 19:00 - 2012-08-02 19:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.163DEE6D53864250
2012-08-02 18:58 - 2012-08-02 18:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F13ABBCBCDDB242
2012-08-02 18:54 - 2012-08-02 18:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B7DC66BA2866782
2012-08-02 18:51 - 2012-08-02 18:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3C535F3BFD8A7E43
2012-08-02 18:47 - 2012-08-02 18:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E8BDAE26EE54E693
2012-08-02 18:44 - 2012-08-02 18:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94FA46219A300B86
2012-08-02 18:41 - 2012-08-02 18:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8A0B5266BCBAF16
2012-07-30 17:26 - 2012-07-30 17:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A0E5FD3F6A654672
2012-07-30 17:20 - 2012-07-30 17:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5499FC4136D0A7E0
2012-07-30 17:16 - 2012-07-30 17:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D519A640993AB49
2012-07-30 17:13 - 2012-02-15 17:00 - 01572903 ____A C:\Windows\WindowsUpdate.log
2012-07-30 17:13 - 2012-02-15 15:54 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-30 17:12 - 2012-07-30 17:11 - 12621696 ____A (Microsoft Corporation) C:\Users\jaylew\Downloads\mseinstall(2).exe
2012-07-30 17:11 - 2009-07-13 21:13 - 00729514 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-30 17:10 - 2012-07-30 17:10 - 00347424 ____A (Microsoft Corporation) C:\Users\jaylew\Downloads\MicrosoftFixit.WindowsFirewall.RNP.136267127798690248.1.1.Run.exe
2012-07-30 17:06 - 2012-02-15 15:55 - 00008876 ____A C:\Windows\PFRO.log
2012-07-30 17:06 - 2009-07-13 20:45 - 00016640 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-30 17:06 - 2009-07-13 20:45 - 00016640 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-30 16:26 - 2012-02-17 18:38 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2572511198-3776155673-3006782383-1001Core.job
2012-07-29 11:21 - 2012-07-29 11:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4185522F09C7AE52
2012-07-29 11:18 - 2012-07-29 11:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1A2729A2C5765B40
2012-07-29 11:15 - 2012-07-29 11:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FBFD2CE184A71BFB
2012-07-29 11:10 - 2012-07-29 11:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C8FB6A31690A5334
2012-07-29 11:10 - 2012-07-29 11:10 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\pxcohblz.sys
2012-07-29 11:07 - 2012-07-29 11:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9F79618A4DD2055
2012-07-29 11:04 - 2012-07-29 11:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.024B0C076D4EC22F
2012-07-29 11:01 - 2012-07-29 11:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66209165ABCC3DEC
2012-07-29 10:56 - 2012-07-29 10:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F90D1581347F5587
2012-07-29 10:53 - 2012-07-29 10:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.959B83F37C14C8B4
2012-07-29 10:49 - 2012-07-29 10:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3FC97012005433FC
2012-07-29 10:42 - 2012-02-15 15:54 - 00742892 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-29 10:41 - 2012-07-29 10:41 - 12621696 ____A (Microsoft Corporation) C:\Users\jaylew\Downloads\mseinstall(1).exe
2012-07-27 08:32 - 2012-07-27 08:32 - 00401920 ____A (Stardock Systems, Inc) C:\Users\jaylew\AppData\Roaming\sdrfs.dll
2012-07-27 08:32 - 2012-04-02 13:54 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-27 08:32 - 2012-02-15 22:54 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-27 08:31 - 2012-07-27 08:31 - 00138752 ____A C:\Users\jaylew\AppData\Roaming\patbrt.dll
2012-07-25 06:45 - 2012-07-25 06:45 - 04419192 ____A (Krzysztof Kowalczyk) C:\Users\jaylew\Downloads\SumatraPDF-2.1.1-install.exe
2012-07-25 06:30 - 2012-07-25 06:30 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-25 06:25 - 2012-07-25 06:25 - 00001845 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-07-19 14:12 - 2012-07-19 14:12 - 00002687 ____A C:\Users\jaylew\Desktop\alg2_syllabus1_0.txt
2012-07-12 05:18 - 2012-02-17 18:39 - 00002407 ____A C:\Users\jaylew\Desktop\Google Chrome.lnk
2012-07-11 00:37 - 2009-07-13 20:45 - 00309944 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 00:04 - 2012-02-18 16:17 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-10 09:51 - 2012-07-10 09:51 - 00001023 ____A C:\Users\Public\Desktop\Cyberduck.lnk
2012-07-10 09:35 - 2012-07-10 09:35 - 13928312 ____A C:\Users\jaylew\Downloads\Cyberduck-Installer-4.2.1.exe
2012-07-06 01:32 - 2012-07-04 23:09 - 00012756 ____A C:\Users\jaylew\Desktop\supplies.ods
2012-07-06 01:32 - 2012-07-02 02:27 - 00025953 ____A C:\Users\jaylew\Desktop\experiments.odt
2012-07-02 02:31 - 2012-07-02 02:30 - 58619658 ____A C:\Users\jaylew\Downloads\FJ5ZCXMFVO9RGPR.mov
2012-06-26 12:35 - 2012-06-26 12:35 - 00739832 ____A (Google Inc.) C:\Users\jaylew\Downloads\GoogleVoiceAndVideoSetup.exe
2012-06-25 06:08 - 2012-06-25 06:08 - 00000968 ____A C:\Users\jaylew\Desktop\Free Hide Folder.lnk
2012-06-25 06:08 - 2012-06-25 06:08 - 00000968 ____A C:\Users\Guest\Desktop\Free Hide Folder.lnk
2012-06-25 06:07 - 2012-06-25 06:07 - 00895896 ____A C:\Users\jaylew\Downloads\FHFSetup.exe
2012-06-11 19:08 - 2012-07-11 00:20 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-10 16:19 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-10 16:19 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-10 16:19 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-10 16:19 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-10 16:19 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-10 16:19 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-10 16:19 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-10 16:19 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-22 06:59 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-22 06:59 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-22 06:59 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-22 06:59 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-22 06:59 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-22 06:59 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-22 06:59 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 12:19 - 2012-06-22 06:58 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:15 - 2012-06-22 06:58 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-11 00:00 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 00:00 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 00:00 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 00:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 00:00 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 00:00 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 00:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 00:00 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 00:00 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 00:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 00:00 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 00:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 00:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 00:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 00:00 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 00:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 00:00 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 00:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 00:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 00:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 00:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 00:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 00:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 00:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 00:00 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 00:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 00:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 00:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-10 16:19 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-10 16:19 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-10 16:19 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-10 16:19 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-10 16:19 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-10 16:19 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-10 16:19 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-10 16:19 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-10 16:19 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 19:05 - 2012-05-31 19:05 - 00358246 ____A C:\Users\jaylew\Downloads\Attachments_2012_05_31(1).zip
2012-05-31 18:50 - 2012-05-31 18:50 - 01093184 ____A C:\Users\jaylew\Downloads\Attachments_2012_05_31.zip
2012-05-26 15:21 - 2012-02-16 14:43 - 00001738 ____A C:\Users\jaylew\Desktop\Rainmeter.lnk
2012-05-23 15:41 - 2012-05-23 15:41 - 00001701 ____A C:\Users\jaylew\Desktop\Google Drive.lnk
2012-05-10 21:17 - 2012-05-10 21:16 - 00225336 ____A C:\Users\jaylew\Downloads\OpenDNS-Updater-2.2.1.exe
2012-05-10 20:50 - 2012-02-29 14:23 - 00066984 ____A C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-10 20:06 - 2012-05-10 20:06 - 00198384 ____A C:\Users\jaylew\Downloads\NETGEARUserUtility-1.0b40-install.exe
2012-05-10 17:05 - 2012-05-10 17:05 - 00369168 ____A (CACE Technologies, Inc.) C:\Windows\System32\wpcap.dll
2012-05-10 17:05 - 2012-05-10 17:05 - 00281104 ____A (CACE Technologies, Inc.) C:\Windows\SysWOW64\wpcap.dll
2012-05-10 17:05 - 2012-05-10 17:05 - 00106000 ____A (CACE Technologies, Inc.) C:\Windows\System32\packet.dll
2012-05-10 17:05 - 2012-05-10 17:05 - 00096784 ____A (CACE Technologies, Inc.) C:\Windows\SysWOW64\packet.dll
2012-05-10 17:05 - 2012-05-10 17:05 - 00035344 ____A (CACE Technologies, Inc.) C:\Windows\System32\Drivers\npf.sys
2012-05-10 17:05 - 2012-05-10 17:05 - 00002060 ____A C:\Users\Public\Desktop\NETGEAR Genie.lnk
2012-05-10 17:03 - 2012-05-10 17:03 - 15375408 ____A (NETGEAR Inc.) C:\Users\jaylew\Downloads\NETGEARGenie-install.exe
2012-05-10 16:43 - 2012-02-15 15:55 - 00066984 ____A C:\Users\jaylew\AppData\Local\GDIPFONTCACHEV1.DAT
ZeroAccess:
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\@
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\L
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\n
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\U
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\L\00000004.@
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\L\201d3dde
C:\Windows\Installer\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\U\00000008.@
ZeroAccess:
C:\Users\jaylew\AppData\Local\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}
C:\Users\jaylew\AppData\Local\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\@
C:\Users\jaylew\AppData\Local\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\L
C:\Users\jaylew\AppData\Local\{a25a49f1-4e6a-3f67-1ed2-711ac4661659}\U
Possible partition infection:
C:\Windows\svchost.exe
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3582.16 MB
Available physical RAM: 3023.91 MB
Total Pagefile: 3580.31 MB
Available Pagefile: 3022.55 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:55.8 GB) (Free:23.73 GB) NTFS
2 Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive h: (Transcend) (Removable) (Total:3.73 GB) (Free:1.82 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: () (Fixed) (Total:143.97 GB) (Free:13.24 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 0 B
Disk 1 Online 55 GB 0 B
Disk 2 Online 3830 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 47 MB 31 KB
Partition 2 Primary 143 GB 47 MB
Partition 3 Primary 5114 MB 144 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 FAT Partition 47 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 Y NTFS Partition 143 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : DB
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 55 GB 101 MB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 C NTFS Partition 55 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3826 MB 4096 KB
==================================================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H Transcend FAT32 Removable 3826 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-27 22:04
======================= End Of Log ==========================