Scan result of Farbar Recovery Scan Tool Version: 16-07-2012 02
Ran by SYSTEM at 17-07-2012 00:04:52
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-03-11] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-16] (Synaptics Incorporated)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [336384 2011-04-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [94264 2011-02-15] (Hewlett-Packard Development Company L.P.)
HKLM-x32\...\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-09] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [35736 2012-04-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [318520 2011-01-27] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKU\Moon\...\Policies\system: [DisableLockWorkstation] 0
HKU\Moon\...\Policies\system: [DisableChangePassword] 0
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
==================== Services (Whitelisted) ======
2 HPAuto; "C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe" [682040 2011-02-16] (Hewlett-Packard)
3 hpCMSrv; "C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe" [1071160 2011-02-15] (Hewlett-Packard Development Company L.P.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 NATService; C:\Program Files (x86)\NAT Service\natsvc.exe [655960 2012-06-11] (Network Advanced Technology)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 ALSysIO; \??\C:\Users\Moon\AppData\Local\Temp\ALSysIO64.sys [x]
3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
1 euhbrgyf; \??\C:\Windows\system32\drivers\euhbrgyf.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-17 00:04 - 2012-07-17 00:04 - 00000000 ____D C:\FRST
2012-07-16 18:25 - 2012-07-16 18:25 - 00176940 ____A C:\Users\Moon\Downloads\BFE.reg
2012-07-16 18:25 - 2012-07-16 18:25 - 00006396 ____A C:\Users\Moon\Downloads\MpsSvc.reg
2012-07-16 17:45 - 2012-07-16 18:00 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-07-16 17:43 - 2012-07-16 17:43 - 02115791 ____A C:\Users\Moon\Downloads\tdsskiller.zip
2012-07-16 17:43 - 2012-07-16 17:43 - 00000000 ____D C:\Users\Moon\Downloads\tdsskiller
2012-07-16 11:54 - 2012-07-16 11:54 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-16 11:54 - 2012-07-16 11:54 - 00000000 ____D C:\Users\Moon\AppData\Roaming\Malwarebytes
2012-07-16 11:54 - 2012-07-16 11:54 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-16 11:54 - 2012-07-16 11:54 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-16 11:54 - 2012-07-03 09:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-16 11:44 - 2012-07-16 11:44 - 00607260 ____R (Swearware) C:\Users\Moon\Desktop\dds.scr
2012-07-16 11:43 - 2012-07-16 11:43 - 00302592 ____A C:\Users\Moon\Desktop\4d202pss.exe
2012-07-16 11:42 - 2012-07-16 11:43 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Moon\Desktop\mbam-setup-1.62.0.1300.exe
2012-07-16 11:10 - 2012-07-16 11:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E775365BB20DA273
2012-07-16 11:06 - 2012-07-16 11:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.416F77F32046CA33
2012-07-16 10:49 - 2012-07-16 10:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4E8B6EDB50D64098
2012-07-16 10:45 - 2012-07-16 10:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.336380A398BE0F57
2012-07-16 10:34 - 2012-07-16 10:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC7E72B2239D7D1A
2012-07-16 10:23 - 2012-07-16 10:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1EB8F94C235F4684
2012-07-16 10:19 - 2012-07-16 10:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C7E225A77D82BA02
2012-07-16 10:10 - 2012-07-16 10:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3E2D778EE8A1B672
2012-07-16 09:44 - 2012-07-16 09:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.207042E56D7F8B56
2012-07-16 09:32 - 2012-07-16 09:32 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\zyalpmpd.sys
2012-07-16 09:32 - 2012-07-16 09:32 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\vuluxdse.sys
2012-07-16 09:32 - 2012-07-16 09:32 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tzjbcjir.sys
2012-07-16 09:29 - 2012-07-16 09:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27F25BC75BAEF1A7
2012-07-16 09:21 - 2012-07-16 09:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFFFB71BD0A8BC68
2012-07-16 09:21 - 2012-07-16 09:21 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\jvbiehew.sys
2012-07-16 09:16 - 2012-07-16 09:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4066E6B136677A98
2012-07-16 09:12 - 2012-07-16 09:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FAD77413DC97526C
2012-07-16 09:08 - 2012-07-16 09:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2B67860D1571EF4C
2012-07-16 08:55 - 2012-07-16 08:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24D5453A755E916B
2012-07-16 08:54 - 2012-07-16 08:56 - 52048746 ____A C:\Users\Moon\Downloads\gapps-ics-20120429-signed.zip
2012-07-16 08:45 - 2012-07-16 09:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-16 08:44 - 2012-07-16 09:40 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-16 08:37 - 2012-07-16 08:37 - 00000000 ____D C:\Users\Moon\AppData\Local\{F5990F7A-CB80-44F5-B456-63D3D4BCA5D7}
2012-07-16 08:37 - 2012-07-16 08:37 - 00000000 ____D C:\Users\Moon\AppData\Local\{B4E5E523-6A5C-49A7-8B48-A73932288667}
2012-07-14 16:04 - 2012-07-14 16:04 - 00054156 ___AH C:\Windows\QTFont.qfn
2012-07-14 16:04 - 2012-07-14 16:04 - 00001409 ____A C:\Windows\QTFont.for
2012-07-14 13:26 - 2012-07-14 13:26 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-07-14 10:39 - 2012-07-14 10:39 - 00002103 ____A C:\Users\Moon\Desktop\90147268314.htm
2012-07-14 10:39 - 2012-07-14 10:39 - 00000000 ____D C:\Users\Moon\Desktop\90147268314_files
2012-07-13 13:52 - 2012-07-13 17:35 - 00000000 ____D C:\Program Files\ZipAge
2012-07-13 13:51 - 2012-07-13 13:52 - 02056544 ____A C:\Users\Moon\Downloads\ZIPAGE-20100318-BETA.EXE
2012-07-13 13:49 - 2012-07-16 08:36 - 00000000 ____D C:\Program Files (x86)\ESTsoft
2012-07-13 13:49 - 2012-07-13 13:50 - 00000000 ____D C:\Users\All Users\ESTsoft
2012-07-13 13:49 - 2012-07-13 13:49 - 00000000 ____D C:\Users\Moon\AppData\Roaming\ESTsoft
2012-07-13 13:49 - 2012-07-13 13:49 - 00000000 ____D C:\Users\Moon\AppData\Local\ECRSC
2012-07-13 13:46 - 2012-07-13 13:49 - 10145632 ____A (ESTsoft Corp.) C:\Users\Moon\Downloads\ALZip851.exe
2012-07-12 09:21 - 2012-07-12 09:21 - 00000000 ____D C:\Users\Moon\AppData\Local\{C8958270-1C3C-48AF-A756-195164830FF0}
2012-07-12 09:21 - 2012-07-12 09:21 - 00000000 ____D C:\Users\Moon\AppData\Local\{5917368F-C7B3-4D7C-BC14-7144400AEDC9}
2012-07-11 23:07 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 23:01 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 23:01 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 23:01 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 23:01 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 23:01 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 23:01 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 23:01 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 23:01 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 23:01 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 23:01 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 23:01 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 23:01 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 23:01 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 23:01 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 23:01 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 23:01 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 23:01 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 23:01 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 23:01 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 23:01 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 23:01 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 23:01 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 23:01 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 23:01 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 23:01 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 23:01 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 23:01 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 23:01 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 21:20 - 2012-07-11 21:21 - 00000000 ____D C:\Users\Moon\AppData\Local\{88233D90-C6DC-4EEE-8CA6-92F1278826D3}
2012-07-11 21:20 - 2012-07-11 21:20 - 00000000 ____D C:\Users\Moon\AppData\Local\{8248EBA4-0F24-4806-889D-9E8B47DAD34C}
2012-07-11 19:34 - 2012-07-11 19:34 - 00000000 ____A C:\Windows\SysWOW64\NEXT
2012-07-11 19:33 - 2012-07-11 19:33 - 00000000 ____D C:\Program Files (x86)\NAT Service
2012-07-11 09:20 - 2012-07-11 09:20 - 00000000 ____D C:\Users\Moon\AppData\Local\{CA119ADF-21C8-4B4F-BC8F-A0465264699A}
2012-07-11 09:20 - 2012-07-11 09:20 - 00000000 ____D C:\Users\Moon\AppData\Local\{1A0DEEAA-75E8-4B6B-915C-08895D3299A0}
2012-07-11 04:25 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 04:25 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 04:25 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 04:25 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 04:25 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 04:25 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 04:25 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 04:25 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 04:25 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 04:25 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 04:25 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 04:25 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 04:25 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 04:25 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 04:25 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 04:25 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 04:25 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 04:25 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 04:25 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-10 21:20 - 2012-07-10 21:20 - 00000000 ____D C:\Users\Moon\AppData\Local\{9250C30C-0B7E-4435-8BF3-2FD24C524124}
2012-07-10 21:19 - 2012-07-10 21:20 - 00000000 ____D C:\Users\Moon\AppData\Local\{331A1211-49EF-4B2A-A328-B5B150086E3C}
2012-07-10 14:24 - 2012-07-10 14:24 - 00000000 ____D C:\Program Files (x86)\NetFolder
2012-07-10 14:24 - 2012-07-09 10:12 - 02006712 ____A ((?)????????) C:\Windows\SysWOW64\NetFolderDown.exe
2012-07-10 14:24 - 2012-07-09 10:12 - 00048816 ____A ((?)????????) C:\Windows\SysWOW64\NetFolderWE.ocx
2012-07-10 14:24 - 2012-07-09 06:21 - 00557056 ____A (Mureka Inc.) C:\Windows\SysWOW64\NetfolderCMC.dll
2012-07-10 14:24 - 1998-06-17 13:08 - 00040960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Mfc42loc.dll
2012-07-10 09:19 - 2012-07-10 09:19 - 00000000 ____D C:\Users\Moon\AppData\Local\{04C0D877-EE67-4AEB-92FB-1DC71784524A}
2012-07-08 21:19 - 2012-07-10 09:19 - 00000000 ____D C:\Users\Moon\AppData\Local\{33F8AC14-4A15-423F-9E92-B5433A809B48}
2012-07-07 08:58 - 2012-07-07 08:58 - 00000000 ____D C:\Users\Moon\AppData\Local\{40186D6C-5BC7-4124-A8E3-721C4C48DEF3}
2012-07-06 17:21 - 2012-07-06 17:21 - 00000000 ____D C:\Users\Moon\AppData\Local\{67DD0119-4556-4D4B-BBC1-4EAA079CB6A9}
2012-07-06 08:18 - 2012-07-06 08:18 - 00000000 ____D C:\Users\Moon\AppData\Local\{9BED2B86-A38E-45D9-8829-4237640771A8}
2012-07-05 15:04 - 2012-07-05 15:04 - 00000000 ____D C:\Users\Moon\AppData\Local\{DC91AD5C-4ED5-4442-B68E-04E6E35080F0}
2012-07-05 13:19 - 2012-07-05 13:19 - 00000000 ____D C:\Users\Moon\AppData\Local\{67807BF3-FEA7-4407-B684-C030063B1D28}
2012-07-05 08:01 - 2012-07-05 08:02 - 00000000 ____D C:\Users\Moon\Desktop\11-12
2012-07-05 06:46 - 2012-07-05 06:46 - 00000000 ____D C:\Users\Moon\AppData\Local\{7FAA6854-4BE9-4DC0-BC65-E05953F7ED0F}
2012-07-03 09:51 - 2012-07-03 09:51 - 00000000 ____D C:\Users\Moon\AppData\Local\{1C6B781D-38E1-493C-8A47-0C1A46B5E895}
2012-07-03 09:51 - 2012-07-03 09:51 - 00000000 ____D C:\Users\Moon\AppData\Local\{0BD51A71-A526-4A05-9AD1-4037C42A1312}
2012-07-02 09:21 - 2012-07-02 09:21 - 00000000 ____D C:\Users\Moon\AppData\Local\{C38D3D38-7F0A-4146-A9AD-72D56FE98E8E}
2012-07-02 09:21 - 2012-07-02 09:21 - 00000000 ____D C:\Users\Moon\AppData\Local\{3F58AB47-8EB7-410C-B72D-2CEDB465F2B5}
2012-07-01 21:14 - 2012-07-01 21:14 - 00833392 ____A (iMusicSoft) C:\Users\Moon\Downloads\NHNComicViewer.exe
2012-07-01 21:14 - 2012-07-01 21:14 - 00000000 ____D C:\Program Files\NHN
2012-07-01 21:14 - 2011-06-11 11:51 - 01190008 ____A (iMusicSoft) C:\Windows\SysWOW64\NHNComicCore.dll
2012-07-01 21:14 - 2011-06-11 11:51 - 00067704 ____A (iMusicSoft) C:\Windows\SysWOW64\IMSComicUtilNV.dll
2012-07-01 14:49 - 2012-07-01 14:49 - 00000000 ____D C:\Users\Moon\AppData\Local\{F896A8E3-5F75-44BC-ABB8-BAD68C821156}
2012-07-01 14:49 - 2012-07-01 14:49 - 00000000 ____D C:\Users\Moon\AppData\Local\{DDFAADC5-7AAC-48B1-B2DA-2AD5DB109714}
2012-06-30 03:10 - 2012-06-30 03:11 - 00000000 ____D C:\Users\Moon\AppData\Local\{9362DF66-D430-4D1B-89D2-52A12970E4F6}
2012-06-30 03:10 - 2012-06-30 03:10 - 00000000 ____D C:\Users\Moon\AppData\Local\{089FCE6B-946E-4163-99D5-0E282680201C}
2012-06-29 15:10 - 2012-06-29 15:10 - 00000000 ____D C:\Users\Moon\AppData\Local\{F6B64D0B-EA19-4CA5-AB83-112D74165705}
2012-06-29 15:10 - 2012-06-29 15:10 - 00000000 ____D C:\Users\Moon\AppData\Local\{338EB6EE-4ACF-434D-AD27-2A2D5E9DC657}
2012-06-28 19:43 - 2012-06-28 19:43 - 00000000 ____D C:\Users\Moon\AppData\Local\{E8211670-9760-4B64-97B7-661F3FBA52F5}
2012-06-28 19:42 - 2012-06-28 19:43 - 00000000 ____D C:\Users\Moon\AppData\Local\{4F1780FF-DCE5-429E-9009-149A100FF229}
2012-06-28 07:42 - 2012-06-28 07:42 - 00000000 ____D C:\Users\Moon\AppData\Local\{E0F078EF-E2F2-4FF6-8D55-6AD6526BF1F2}
2012-06-28 07:42 - 2012-06-28 07:42 - 00000000 ____D C:\Users\Moon\AppData\Local\{C60AA8C6-7986-49C6-8DE0-D56939B72495}
2012-06-27 19:42 - 2012-06-27 19:42 - 00000000 ____D C:\Users\Moon\AppData\Local\{5B306F56-DBED-4813-8085-CA3FF49CF476}
2012-06-27 19:41 - 2012-06-27 19:42 - 00000000 ____D C:\Users\Moon\AppData\Local\{076F464C-E26F-4892-B93A-07F02A7E2B41}
2012-06-27 07:41 - 2012-06-27 07:41 - 00000000 ____D C:\Users\Moon\AppData\Local\{C166969B-C8F9-4750-9A39-756B51CDDCB6}
2012-06-27 07:41 - 2012-06-27 07:41 - 00000000 ____D C:\Users\Moon\AppData\Local\{569E6CB5-C51C-492F-9377-B7416C7236E9}
2012-06-26 10:29 - 2012-07-12 15:50 - 00000003 ____A C:\Windows\System32\HRUPPROG.TXT
2012-06-26 10:29 - 2012-06-26 10:29 - 00000003 ____A C:\Windows\System32\HRUPPROG.DIE.NOW
2012-06-26 10:29 - 2012-06-26 10:29 - 00000000 ____D C:\Users\Moon\AppData\Local\{FB20B2B4-02BD-4491-9D1F-8B6C7825BA03}
2012-06-26 10:29 - 2012-06-26 10:29 - 00000000 ____D C:\Users\Moon\AppData\Local\{70F56399-F361-4719-891D-C8A69E3F3277}
2012-06-25 20:45 - 2012-06-25 20:45 - 00000000 ____D C:\Users\Moon\AppData\Local\{2534C015-DFA3-4AF0-B206-52C63AF24ACC}
2012-06-25 20:45 - 2012-06-25 20:45 - 00000000 ____D C:\Users\Moon\AppData\Local\{07906102-B1CA-4A20-B312-855279E96BFD}
2012-06-25 08:45 - 2012-06-25 08:45 - 00000000 ____D C:\Users\Moon\AppData\Local\{BDB78CF6-A964-4C8E-B0B7-6D4AE909568C}
2012-06-25 08:45 - 2012-06-25 08:45 - 00000000 ____D C:\Users\Moon\AppData\Local\{26988C8A-F347-4B35-BDEB-FFB9871893F0}
2012-06-24 17:55 - 2012-06-24 17:55 - 00000000 ____D C:\Users\Moon\AppData\Local\{6156A916-0EB5-4EEA-9180-E70E956B3732}
2012-06-24 17:54 - 2012-06-24 17:55 - 00000000 ____D C:\Users\Moon\AppData\Local\{FC73E58E-06F4-4F0E-8C82-DA123F250749}
2012-06-23 13:25 - 2012-06-23 13:25 - 00000000 ____D C:\Users\Moon\AppData\Local\Macromedia
2012-06-23 13:23 - 2012-06-23 13:23 - 00000000 ____D C:\Users\Moon\AppData\Local\{AFBBCE59-4B77-48F2-9ACE-5B55DC373D8F}
2012-06-23 13:23 - 2012-06-23 13:23 - 00000000 ____D C:\Users\Moon\AppData\Local\{A74DA063-87D0-42C4-A6E6-20393F5B85CE}
2012-06-22 18:51 - 2012-06-22 18:51 - 00000000 ____D C:\Users\Moon\AppData\Local\{D1242136-EEDD-49C6-A867-91746004899D}
2012-06-22 18:51 - 2012-06-22 18:51 - 00000000 ____D C:\Users\Moon\AppData\Local\{92069FE9-8DBD-43C1-9455-9EA7E1B481F1}
2012-06-22 10:22 - 2012-06-22 10:22 - 490693377 ____A C:\Windows\MEMORY.DMP
2012-06-22 10:22 - 2012-06-22 10:22 - 00275072 ____A C:\Windows\Minidump\062212-28688-01.dmp
2012-06-22 10:22 - 2012-06-22 10:22 - 00000000 ____D C:\Windows\Minidump
2012-06-22 10:05 - 2012-06-22 11:09 - 00000000 ____D C:\Users\Moon\Documents\p95v277.win64
2012-06-22 10:02 - 2012-06-22 11:09 - 00000000 ____D C:\Users\Moon\Documents\K10STAT154
2012-06-22 06:50 - 2012-06-22 06:51 - 00000000 ____D C:\Users\Moon\AppData\Local\{861FDC22-FE1F-4457-A61E-1ADB0711812D}
2012-06-22 06:50 - 2012-06-22 06:50 - 00000000 ____D C:\Users\Moon\AppData\Local\{094EE6DD-8E14-4C19-8EE0-EFF53E0BA64F}
2012-06-21 20:59 - 2012-06-22 20:23 - 00000000 ____D C:\Users\Moon\AppData\Roaming\Cyphers
2012-06-21 18:50 - 2012-06-21 18:50 - 00000000 ____D C:\Users\Moon\AppData\Local\{D5BC9C2F-1A1D-4236-B71F-EDBEFC7AF4ED}
2012-06-21 18:49 - 2012-06-21 18:50 - 00000000 ____D C:\Users\Moon\AppData\Local\{C1ABA2E0-3FE6-4FF3-BB67-1F775DD8ED03}
2012-06-21 17:02 - 2012-06-21 17:02 - 00000000 ____D C:\Users\Moon\AppData\Local\Chromium
2012-06-21 16:43 - 2012-06-21 18:15 - 571867540 ____A C:\Users\Moon\Downloads\Cyphers_full.exe
2012-06-21 16:40 - 2012-06-21 18:31 - 00000000 ____D C:\Neople
2012-06-21 16:39 - 2012-06-21 16:39 - 00783856 ____A (Neople Inc.) C:\Users\Moon\Downloads\CyphersHelper.exe
2012-06-21 16:39 - 2012-06-21 16:39 - 00640480 ____A (Neople Inc.) C:\Users\Moon\Downloads\NeoplePlugin.exe
2012-06-21 16:39 - 2012-06-21 16:39 - 00000000 ____D C:\Users\All Users\NeoplePlugin
2012-06-21 16:30 - 2012-06-21 17:01 - 00000000 ____D C:\Users\All Users\Hi-Rez Studios
2012-06-21 16:30 - 2012-06-21 16:30 - 00002024 ____A C:\Users\Public\Desktop\Smite Closed Beta.lnk
2012-06-21 16:29 - 2012-07-12 15:50 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2012-06-21 16:29 - 2012-06-21 16:29 - 13845856 ____A (Hi-Rez Studios) C:\Users\Moon\Downloads\InstallHiRezGamesEnglish.exe
2012-06-21 06:49 - 2012-06-21 06:49 - 00000000 ____D C:\Users\Moon\AppData\Local\{CB263353-2BB4-4E3B-A1E0-AA780F50A45A}
2012-06-21 06:49 - 2012-06-21 06:49 - 00000000 ____D C:\Users\Moon\AppData\Local\{43630AB9-2FE6-4DC4-9ADA-F544E6A3136F}
2012-06-20 08:24 - 2012-06-20 08:24 - 00000000 ____D C:\Users\Moon\AppData\Local\{932F29D1-0B75-43C6-B40B-0D8CBBBCF9C6}
2012-06-20 08:24 - 2012-06-20 08:24 - 00000000 ____D C:\Users\Moon\AppData\Local\{2808A5FF-6F69-426E-8E6C-A2C2C85D6CFC}
2012-06-19 19:48 - 2012-06-19 19:48 - 00000000 ____D C:\Users\Moon\AppData\Local\{D1AADE9E-8AEC-4314-8365-404E63D2FC5F}
2012-06-19 19:48 - 2012-06-19 19:48 - 00000000 ____D C:\Users\Moon\AppData\Local\{C3579053-8328-4316-9D00-4DDE8B037170}
2012-06-19 07:51 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-19 07:51 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-19 07:51 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-19 07:51 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-19 07:51 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-19 07:51 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-19 07:51 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-19 07:51 - 2012-06-02 11:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-19 07:51 - 2012-06-02 11:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-19 07:47 - 2012-06-19 07:48 - 00000000 ____D C:\Users\Moon\AppData\Local\{442BFB1A-F8D2-40B1-A4E3-C3F3699E3133}
2012-06-19 07:47 - 2012-06-19 07:47 - 00000000 ____D C:\Users\Moon\AppData\Local\{A2EA511A-F94F-4740-8BD3-3C7F941AEE4B}
2012-06-18 15:49 - 2012-06-18 15:49 - 00001096 ____A C:\Users\Public\Desktop\?????(show).lnk
2012-06-18 15:49 - 2012-06-18 15:49 - 00000000 ____D C:\Program Files (x86)\donkeyplus
2012-06-18 15:46 - 2012-06-18 15:47 - 03711712 ____A C:\Users\Moon\Downloads\show_setup.exe
2012-06-18 15:44 - 2012-06-18 15:44 - 04803470 ____A C:\Users\Moon\Downloads\VPlayer.Unlocked.1.3.0.Android.zip
2012-06-18 09:09 - 2012-06-18 09:10 - 00000000 ____D C:\Users\Moon\AppData\Local\{059C490E-7123-4160-9CD9-14D3A2B5E745}
2012-06-17 18:08 - 2012-06-17 18:08 - 00000000 ____D C:\Users\Moon\AppData\Local\{C25B6191-3698-4F81-94A5-6B09756F2A72}
============ 3 Months Modified Files ========================
2012-07-16 20:00 - 2012-03-14 07:17 - 01196763 ____A C:\Windows\WindowsUpdate.log
2012-07-16 19:59 - 2009-07-13 21:13 - 00783224 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-16 19:57 - 2009-07-13 20:51 - 00062187 ____A C:\Windows\setupact.log
2012-07-16 19:25 - 2012-05-17 15:57 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-16 18:43 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-16 18:43 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-16 18:34 - 2009-07-13 21:08 - 00032548 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-16 18:34 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-16 18:25 - 2012-07-16 18:25 - 00176940 ____A C:\Users\Moon\Downloads\BFE.reg
2012-07-16 18:25 - 2012-07-16 18:25 - 00006396 ____A C:\Users\Moon\Downloads\MpsSvc.reg
2012-07-16 18:00 - 2012-03-14 07:27 - 00769072 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-16 17:43 - 2012-07-16 17:43 - 02115791 ____A C:\Users\Moon\Downloads\tdsskiller.zip
2012-07-16 12:03 - 2010-11-20 19:47 - 00352280 ____A C:\Windows\PFRO.log
2012-07-16 11:54 - 2012-07-16 11:54 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-16 11:47 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-16 11:44 - 2012-07-16 11:44 - 00607260 ____R (Swearware) C:\Users\Moon\Desktop\dds.scr
2012-07-16 11:43 - 2012-07-16 11:43 - 00302592 ____A C:\Users\Moon\Desktop\4d202pss.exe
2012-07-16 11:43 - 2012-07-16 11:42 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Moon\Desktop\mbam-setup-1.62.0.1300.exe
2012-07-16 11:10 - 2012-07-16 11:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E775365BB20DA273
2012-07-16 11:06 - 2012-07-16 11:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.416F77F32046CA33
2012-07-16 10:49 - 2012-07-16 10:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4E8B6EDB50D64098
2012-07-16 10:45 - 2012-07-16 10:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.336380A398BE0F57
2012-07-16 10:34 - 2012-07-16 10:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC7E72B2239D7D1A
2012-07-16 10:23 - 2012-07-16 10:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1EB8F94C235F4684
2012-07-16 10:19 - 2012-07-16 10:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C7E225A77D82BA02
2012-07-16 10:10 - 2012-07-16 10:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3E2D778EE8A1B672
2012-07-16 09:44 - 2012-07-16 09:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.207042E56D7F8B56
2012-07-16 09:32 - 2012-07-16 09:32 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\zyalpmpd.sys
2012-07-16 09:32 - 2012-07-16 09:32 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\vuluxdse.sys
2012-07-16 09:32 - 2012-07-16 09:32 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tzjbcjir.sys
2012-07-16 09:29 - 2012-07-16 09:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27F25BC75BAEF1A7
2012-07-16 09:21 - 2012-07-16 09:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFFFB71BD0A8BC68
2012-07-16 09:21 - 2012-07-16 09:21 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\jvbiehew.sys
2012-07-16 09:16 - 2012-07-16 09:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4066E6B136677A98
2012-07-16 09:12 - 2012-07-16 09:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FAD77413DC97526C
2012-07-16 09:08 - 2012-07-16 09:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2B67860D1571EF4C
2012-07-16 08:56 - 2012-07-16 08:54 - 52048746 ____A C:\Users\Moon\Downloads\gapps-ics-20120429-signed.zip
2012-07-16 08:55 - 2012-07-16 08:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24D5453A755E916B
2012-07-16 08:45 - 2012-05-17 16:00 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-14 16:04 - 2012-07-14 16:04 - 00054156 ___AH C:\Windows\QTFont.qfn
2012-07-14 16:04 - 2012-07-14 16:04 - 00001409 ____A C:\Windows\QTFont.for
2012-07-14 10:39 - 2012-07-14 10:39 - 00002103 ____A C:\Users\Moon\Desktop\90147268314.htm
2012-07-13 13:52 - 2012-07-13 13:51 - 02056544 ____A C:\Users\Moon\Downloads\ZIPAGE-20100318-BETA.EXE
2012-07-13 13:49 - 2012-07-13 13:46 - 10145632 ____A (ESTsoft Corp.) C:\Users\Moon\Downloads\ALZip851.exe
2012-07-12 15:50 - 2012-06-26 10:29 - 00000003 ____A C:\Windows\System32\HRUPPROG.TXT
2012-07-12 03:26 - 2009-07-13 20:45 - 00276528 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 23:02 - 2012-05-21 10:32 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-11 19:34 - 2012-07-11 19:34 - 00000000 ____A C:\Windows\SysWOW64\NEXT
2012-07-11 10:25 - 2012-05-17 15:57 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-11 10:25 - 2012-05-17 15:57 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-09 10:12 - 2012-07-10 14:24 - 02006712 ____A ((?)????????) C:\Windows\SysWOW64\NetFolderDown.exe
2012-07-09 10:12 - 2012-07-10 14:24 - 00048816 ____A ((?)????????) C:\Windows\SysWOW64\NetFolderWE.ocx
2012-07-09 06:21 - 2012-07-10 14:24 - 00557056 ____A (Mureka Inc.) C:\Windows\SysWOW64\NetfolderCMC.dll
2012-07-03 09:46 - 2012-07-16 11:54 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-01 21:14 - 2012-07-01 21:14 - 00833392 ____A (iMusicSoft) C:\Users\Moon\Downloads\NHNComicViewer.exe
2012-06-26 10:29 - 2012-06-26 10:29 - 00000003 ____A C:\Windows\System32\HRUPPROG.DIE.NOW
2012-06-22 10:22 - 2012-06-22 10:22 - 490693377 ____A C:\Windows\MEMORY.DMP
2012-06-22 10:22 - 2012-06-22 10:22 - 00275072 ____A C:\Windows\Minidump\062212-28688-01.dmp
2012-06-21 18:15 - 2012-06-21 16:43 - 571867540 ____A C:\Users\Moon\Downloads\Cyphers_full.exe
2012-06-21 16:58 - 2011-04-28 16:32 - 00011095 ____A C:\Windows\DirectX.log
2012-06-21 16:39 - 2012-06-21 16:39 - 00783856 ____A (Neople Inc.) C:\Users\Moon\Downloads\CyphersHelper.exe
2012-06-21 16:39 - 2012-06-21 16:39 - 00640480 ____A (Neople Inc.) C:\Users\Moon\Downloads\NeoplePlugin.exe
2012-06-21 16:30 - 2012-06-21 16:30 - 00002024 ____A C:\Users\Public\Desktop\Smite Closed Beta.lnk
2012-06-21 16:29 - 2012-06-21 16:29 - 13845856 ____A (Hi-Rez Studios) C:\Users\Moon\Downloads\InstallHiRezGamesEnglish.exe
2012-06-18 15:49 - 2012-06-18 15:49 - 00001096 ____A C:\Users\Public\Desktop\?????(show).lnk
2012-06-18 15:47 - 2012-06-18 15:46 - 03711712 ____A C:\Users\Moon\Downloads\show_setup.exe
2012-06-18 15:44 - 2012-06-18 15:44 - 04803470 ____A C:\Users\Moon\Downloads\VPlayer.Unlocked.1.3.0.Android.zip
2012-06-11 19:08 - 2012-07-11 23:07 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-09 16:45 - 2012-05-17 15:26 - 00057960 ____A C:\Users\Moon\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-09 16:43 - 2012-06-09 16:43 - 00000932 ____A C:\Users\Moon\Desktop\Guitar Pro 5.lnk
2012-06-09 15:14 - 2012-06-09 15:14 - 00090071 ____A C:\Users\Moon\Downloads\%EA%B5%AD%EC%B9%B4%EC%8A%A4%ED%85%90_%EA%B1%B0%EC%9A%B8.gp5
2012-06-09 15:10 - 2012-06-09 15:10 - 02042672 ____A C:\Users\Moon\Downloads\installer_guitar_pro_6_1_2_r11038_Korean.exe
2012-06-08 21:43 - 2012-07-11 04:25 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 04:25 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 07:13 - 2012-06-08 07:13 - 00031277 ____A C:\Users\Moon\Downloads\Vindictus.htm
2012-06-08 06:52 - 2012-06-07 20:29 - 00002581 ____A C:\Users\Moon\Desktop\DC Universe Online Live.lnk
2012-06-07 20:28 - 2012-06-07 20:27 - 17117624 ____A C:\Users\Moon\Downloads\DCUO_setup.exe
2012-06-05 22:06 - 2012-07-11 04:25 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 04:25 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 04:25 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 04:25 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 04:25 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 04:25 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-19 07:51 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-19 07:51 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-19 07:51 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-19 07:51 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-19 07:51 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-19 07:51 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-19 07:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-19 07:51 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-19 07:51 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-11 23:01 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 23:01 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 23:01 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 23:01 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 23:01 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 23:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 23:01 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 23:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 23:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 23:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 23:01 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 23:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 23:01 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 23:01 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 23:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 23:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 23:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 23:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 23:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 23:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 23:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 23:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 23:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 23:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 23:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 23:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 23:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 23:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-11 04:25 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 04:25 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 04:25 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 04:25 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 04:25 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 04:25 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 04:25 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 04:25 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 04:25 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-28 19:58 - 2012-05-28 19:58 - 04518496 ____A (
www.orbitdownloader.com ) C:\Users\Moon\Downloads\orbitdownloader.exe
2012-05-28 13:22 - 2012-05-28 13:22 - 00042711 ____A C:\Users\Moon\Downloads\IVAsiLoader.rar
2012-05-28 13:15 - 2012-05-28 13:15 - 00085370 ____A C:\Users\Moon\Downloads\xliveless-0.999b7.rar
2012-05-28 13:06 - 2012-05-28 13:06 - 02715464 ____A C:\Users\Moon\Downloads\trainerv64(1).rar
2012-05-28 13:05 - 2012-05-28 13:04 - 02715464 ____A C:\Users\Moon\Downloads\trainerv64.rar
2012-05-28 12:58 - 2012-05-28 12:58 - 00883200 ____A (New Technology Studio) C:\Users\Moon\Downloads\1328425145_ovisetup.exe
2012-05-25 20:06 - 2012-05-25 20:06 - 12934148 ____A ( ) C:\Users\Moon\Downloads\quicktimealt181.exe
2012-05-22 20:47 - 2012-05-22 20:47 - 00178800 ____A (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2012-05-22 09:05 - 2012-05-22 09:05 - 00064559 ____A C:\Users\Moon\Downloads\GTA_4_EFLC_Save_Complete.rar
2012-05-22 08:29 - 2012-05-22 08:29 - 00455417 ____A C:\Users\Moon\Downloads\EFLC-mbb.rar
2012-05-18 09:32 - 2012-05-18 09:31 - 00296216 ____A C:\Windows\msxml4-KB973688-enu.LOG
2012-05-18 09:30 - 2012-05-18 09:29 - 00295336 ____A C:\Windows\msxml4-KB954430-enu.LOG
2012-05-17 16:50 - 2012-05-17 16:49 - 04723256 ____A C:\Users\Moon\Downloads\HV3-SETUP.EXE
2012-05-17 16:43 - 2012-05-17 16:42 - 00880496 ____A (BitTorrent, Inc.) C:\Users\Moon\Downloads\uTorrent.exe
2012-05-17 16:20 - 2012-05-17 16:20 - 00476960 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-05-17 16:20 - 2012-05-17 16:20 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-05-17 16:20 - 2012-05-17 16:20 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-05-17 16:20 - 2012-05-17 16:20 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-05-17 16:20 - 2011-04-28 16:39 - 00472864 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-05-17 16:11 - 2012-05-17 16:11 - 01606656 ____A C:\Users\Moon\Downloads\SteamInstall.msi
2012-05-17 16:09 - 2012-05-17 16:08 - 06536160 ____A (Gretech Corporation) C:\Users\Moon\Downloads\GOMPLAYERSETUP.EXE
2012-05-17 15:58 - 2012-05-17 15:56 - 12621696 ____A (Microsoft Corporation) C:\Users\Moon\Downloads\mseinstall.exe
2012-05-17 15:22 - 2012-05-17 15:22 - 00000020 ___SH C:\Users\Moon\ntuser.ini
2012-05-04 03:06 - 2012-06-12 15:56 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 15:56 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 15:56 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-12 15:56 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-30 14:22 - 2012-04-30 14:22 - 01820216 ____A (NHN corp.) C:\Windows\SysWOW64\NaverAXGuide.exe
2012-04-30 14:22 - 2012-04-30 14:22 - 00168504 ____A (NHN Corp.) C:\Windows\SysWOW64\NAxgPluginW_0_1.dll
2012-04-27 19:55 - 2012-06-12 15:56 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-12 15:56 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 15:56 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 15:56 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-12 15:56 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 15:55 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 15:55 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 15:55 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 15:55 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 15:55 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 7658.9 MB
Available physical RAM: 6792.53 MB
Total Pagefile: 7657.05 MB
Available Pagefile: 6780.03 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:581.41 GB) (Free:106.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (RECOVERY) (Fixed) (Total:14.47 GB) (Free:1.61 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
5 Drive h: (KINGSTON) (Removable) (Total:14.92 GB) (Free:12.87 GB) FAT32
8 Drive x: (Boot) (Fixed) (Total:0.25 GB) (Free:0.25 GB) NTFS
9 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 596 GB 0 B
Disk 1 Online 14 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 581 GB 200 MB
Partition 3 Primary 14 GB 581 GB
Partition 4 Primary 103 MB 596 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 199 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 581 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E RECOVERY NTFS Partition 14 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F HP_TOOLS FAT32 Partition 103 MB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H KINGSTON FAT32 Removable 14 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-07 20:34
======================= End Of Log ==========================