Hi all! It's not pretty. I'm running Windows 7 Profession x64 and had major problems. Now my computer shuts down within 1 minute. I did see that I have Sirefef.y, Sirefef.ah, Sirefef.a or something like that (multiple variations... not sure if it matters). I'm spending most of my night changing passwords on all my accounts and then I'll contact my banks tomorrow.
I have checked out the reads already here and did the FRST64/Service logs since that was the general first step. I can barely log into my computer now.. Not touching my laptop at all until I get a reply. Thanks for any help you can provide!
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 30-07-2012 01:23:08
Running from F:\
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [592240 2011-01-04] (Alps Electric Co., Ltd.)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167960 2011-03-30] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [391704 2011-03-30] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [418328 2011-03-30] (Intel Corporation)
HKLM\...\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686704 2010-12-17] ()
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [6492672 2011-01-15] (Dell Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [gdasn] "C:\Windows\System32\rundll32.exe" "C:\Users\Anne\AppData\Roaming\gdasn.dll",set_read_fn [420352 2012-07-25] ()
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [112152 2010-12-03] (Intel Corporation)
HKLM-x32\...\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [462993 2010-03-12] (Creative Technology Ltd)
HKLM-x32\...\Run: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [87336 2009-07-06] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [50472 2010-04-29] (CyberLink Corp.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [514544 2010-11-17] ()
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-06-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.)
HKLM-x32\...\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe" [495616 2011-03-08] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" [856064 2011-03-08] (SEIKO EPSON CORPORATION)
HKU\Anne\...\Run: [Google Update] "C:\Users\Anne\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-12-23] (Google Inc.)
HKU\Anne\...\Run: [AdobeBridge] [x]
HKU\Anne\...\Run: [googletalk] C:\Users\Anne\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart [3739648 2007-01-01] (Google)
HKU\Anne\...\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun [3111744 2012-04-26] (DT Soft Ltd)
HKU\Anne\...\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHVA.EXE /EPT "EPLTarget\P0000000000000000" /M "WorkForce 645" [239488 2011-04-24] (SEIKO EPSON CORPORATION)
HKU\Anne\...\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)
HKU\Anne\...\Run: [gdasn] "C:\Windows\System32\rundll32.exe" "C:\Users\Anne\AppData\Roaming\gdasn.dll",set_read_fn [420352 2012-07-25] ()
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Lsa: [Authentication Packages] msv1_0
wvauth
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Dell System Manager.lnk
ShortcutTarget: Dell System Manager.lnk -> C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe (Dell Inc.)
Startup: C:\Users\Anne\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ======
2 ABBYY.Licensing.FineReader.Sprint.9.0; "C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe" -service [759048 2009-05-14] (ABBYY)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 O2SDIOAssist; C:\Windows\SysWOW64\srvany.exe [8192 2003-04-18] ()
2 RoxWatch12; "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe" [219632 2010-11-25] (Sonic Solutions)
3 stllssvr; "C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe" [74392 2010-11-08] (MicroVision Development, Inc.)
2 tcsd_win32.exe; "C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe" [1629696 2010-07-13] ()
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656280 2010-12-03] (Intel Corporation)
========================== Drivers (Whitelisted) =============
0 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-04-27] (Duplex Secure Ltd.)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-29 20:50 - 2012-07-29 20:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.03E86C6D05C1E43F
2012-07-29 20:42 - 2012-07-29 20:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.58886290833A4289
2012-07-29 20:35 - 2012-07-29 20:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2C31D00BBF6CF89F
2012-07-29 20:31 - 2012-07-29 20:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.211AFBF5E4391C5E
2012-07-29 20:25 - 2012-07-29 20:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47B664D89E53D58B
2012-07-29 20:17 - 2012-07-29 20:19 - 00347424 ____A (Microsoft Corporation) C:\Users\Anne\Downloads\MicrosoftFixit.WindowsFirewall.RNP.19267051685286478.3.1.Run.exe
2012-07-29 20:11 - 2012-07-29 20:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.887F2746A8C90C90
2012-07-29 19:59 - 2012-07-29 19:59 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-29 19:59 - 2012-07-29 19:59 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-29 19:51 - 2012-07-29 19:51 - 12621696 ____A (Microsoft Corporation) C:\Users\Anne\Downloads\mseinstall.exe
2012-07-29 19:11 - 2012-07-29 19:11 - 00000000 ____D C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech
2012-07-29 18:53 - 2012-07-29 19:07 - 50957919 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part6.rar
2012-07-29 18:38 - 2012-07-29 18:38 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-29 18:09 - 2012-07-29 18:24 - 263192577 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part5.rar
2012-07-29 17:35 - 2012-07-29 17:48 - 263192577 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part3.rar
2012-07-29 16:20 - 2012-07-29 17:32 - 263192576 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part2.rar
2012-07-29 16:10 - 2012-07-29 17:21 - 263192577 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part1.rar
2012-07-26 19:58 - 2012-07-26 19:58 - 00000000 ____D C:\Users\Anne\Downloads\iTunes-Jay-Z_and_Kanye_West-Watch_The_Throne_(Deluxe_Version)-(2011)
2012-07-25 12:57 - 2012-07-25 13:16 - 152948744 ____A C:\Users\Anne\Downloads\iTunes-Jay-Z_and_Kanye_West-Watch_The_Throne_(Deluxe_Version)-(2011).rar
2012-07-25 12:41 - 2012-07-25 12:41 - 00420352 ____A C:\Users\Anne\AppData\Roaming\gdasn.dll
2012-07-25 12:41 - 2012-07-25 12:41 - 00000000 ____D C:\Users\Anne\AppData\Local\{215B93C0-D699-11E1-8270-B8AC6F996F26}
2012-07-25 12:41 - 2012-07-25 12:41 - 00000000 ____D C:\Users\Anne\AppData\Local\{215B6270-D699-11E1-8270-B8AC6F996F26}
2012-07-21 10:22 - 2012-07-21 10:40 - 00000000 ____D C:\Users\Anne\Desktop\NAIL POLISH
2012-07-20 20:48 - 2012-07-23 09:29 - 00000000 ____D C:\Users\Anne\Desktop\Summer 2012 Vision Board
2012-07-20 07:06 - 2012-07-20 07:06 - 00112121 ____A C:\Users\Anne\Downloads\644 - Making Small Talk in English a.pptx
2012-07-20 07:04 - 2012-07-20 07:04 - 03338947 ____A C:\Users\Anne\Downloads\644 - Making Small Talk in English .pptx
2012-07-12 15:11 - 2012-07-12 15:11 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-495499240-2845497790-2203762804-1003Core1cd6083b0707453.job
2012-07-11 20:42 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 20:37 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 20:37 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 20:37 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 20:37 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 20:37 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 20:37 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 20:37 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 20:37 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 20:37 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 20:37 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 20:37 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 20:37 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 20:37 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 20:37 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 20:37 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 20:37 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 20:37 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 20:37 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 20:37 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 20:37 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 20:37 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 20:37 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 20:37 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 20:37 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 20:37 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 20:37 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 20:37 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 20:37 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 06:10 - 2012-07-11 06:11 - 00118044 ____A C:\Users\Anne\Downloads\547 - Discussing Work in English.pptx
2012-07-11 04:00 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 04:00 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 04:00 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 04:00 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 04:00 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 04:00 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 04:00 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 04:00 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 04:00 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 04:00 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 04:00 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 04:00 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 04:00 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 04:00 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 04:00 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 04:00 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 04:00 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 04:00 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 04:00 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-10 15:54 - 2012-07-10 15:54 - 00000215 ____A C:\Users\Anne\AppData\Roaming\My Profile.xml
2012-07-10 05:08 - 2012-07-10 05:09 - 03701449 ____A C:\Users\Anne\Desktop\Integrated Reasoning2.pptx
2012-07-10 05:02 - 2012-07-10 05:04 - 03701449 ____A C:\Users\Anne\Desktop\Integrated Reasoning.pptx
2012-07-08 14:22 - 2012-07-08 14:22 - 00000000 ____D C:\Users\Anne\AppData\Roaming\Leadertech
2012-07-08 14:20 - 2012-07-08 14:22 - 00000000 ____D C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint
2012-07-08 14:20 - 2012-07-08 14:20 - 00000000 ____D C:\Users\Anne\AppData\Local\ABBYY
2012-07-08 14:20 - 2012-07-08 14:20 - 00000000 ____D C:\Users\All Users\ABBYY
2012-07-08 14:11 - 2012-07-08 14:11 - 00000000 ____D C:\Program Files\Common Files\EPSON
2012-07-08 14:09 - 2012-07-08 14:09 - 00000000 ____D C:\Users\Anne\AppData\Roaming\InstallShield
2012-07-08 14:09 - 2012-07-08 14:09 - 00000000 ____D C:\Program Files\EpsonNet
2012-07-08 14:09 - 2012-07-08 14:09 - 00000000 ____D C:\Program Files\EPSON
2012-07-08 14:09 - 2010-09-13 11:01 - 00538112 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\ensppui.dll
2012-07-08 14:09 - 2010-09-13 11:01 - 00538112 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\enppui.dll
2012-07-08 14:09 - 2010-09-13 11:00 - 00558592 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\ensppmon.dll
2012-07-08 14:09 - 2010-09-13 11:00 - 00558592 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\enppmon.dll
2012-07-08 14:09 - 2008-06-18 07:49 - 00250880 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\enspres.dll
2012-07-08 14:09 - 2008-06-18 07:49 - 00250880 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\enpres.dll
2012-07-08 14:08 - 2012-07-12 02:59 - 00000000 ____D C:\Users\Anne\AppData\Roaming\Epson
2012-07-08 14:07 - 2012-07-08 14:07 - 00000000 ____D C:\Program Files (x86)\Epson America Inc
2012-07-08 14:06 - 2012-07-08 14:26 - 00000000 ____D C:\Program Files (x86)\Epson Software
2012-07-08 14:05 - 2012-07-08 14:13 - 00000000 ____D C:\Users\All Users\EPSON
2012-07-08 14:05 - 2012-07-08 14:06 - 00000000 ____D C:\Program Files (x86)\epson
2012-07-08 14:05 - 2012-07-08 14:05 - 00000934 ____A C:\Users\Public\Desktop\EPSON Scan.lnk
2012-07-08 14:05 - 2010-09-28 06:01 - 00118784 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\E_YLMHVA.DLL
2012-07-08 14:05 - 2010-08-09 06:02 - 00083456 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\E_YD4BHVA.DLL
2012-07-08 14:05 - 2009-12-08 20:00 - 00464384 ____A (Seiko Epson Corporation) C:\Windows\System32\esxw2ud.dll
2012-07-08 14:05 - 2009-10-15 20:00 - 00132560 ____A (Seiko Epson Corporation) C:\Windows\System32\esdevapp.exe
2012-07-08 14:05 - 2009-10-15 20:00 - 00013824 ____A (Seiko Epson Corporation) C:\Windows\System32\esxcdev.dll
2012-07-08 13:56 - 2012-07-08 14:27 - 00000106 ____A C:\Windows\EWF645.ini
2012-07-02 17:23 - 2012-07-02 17:23 - 07301084 ____A C:\Users\Anne\Downloads\570 - English for Road Trips Around the U.S..pptx
2012-07-02 16:57 - 2012-07-02 17:08 - 00000000 ____D C:\Users\Anne\Desktop\Bank Statements
============ 3 Months Modified Files ========================
2012-07-29 21:17 - 2009-07-13 20:51 - 00065427 ____A C:\Windows\setupact.log
2012-07-29 21:15 - 2010-11-20 19:47 - 00051642 ____A C:\Windows\PFRO.log
2012-07-29 21:15 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-29 20:50 - 2012-07-29 20:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.03E86C6D05C1E43F
2012-07-29 20:42 - 2012-07-29 20:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.58886290833A4289
2012-07-29 20:35 - 2012-07-29 20:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2C31D00BBF6CF89F
2012-07-29 20:31 - 2012-07-29 20:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.211AFBF5E4391C5E
2012-07-29 20:25 - 2012-07-29 20:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47B664D89E53D58B
2012-07-29 20:22 - 2009-07-13 20:45 - 00021312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-29 20:22 - 2009-07-13 20:45 - 00021312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-29 20:19 - 2012-07-29 20:17 - 00347424 ____A (Microsoft Corporation) C:\Users\Anne\Downloads\MicrosoftFixit.WindowsFirewall.RNP.19267051685286478.3.1.Run.exe
2012-07-29 20:14 - 2011-11-24 21:09 - 00000940 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-495499240-2845497790-2203762804-1000UA.job
2012-07-29 20:11 - 2012-07-29 20:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.887F2746A8C90C90
2012-07-29 20:00 - 2011-12-05 19:54 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-29 20:00 - 2011-06-18 17:12 - 01294915 ____A C:\Windows\WindowsUpdate.log
2012-07-29 19:59 - 2011-02-10 06:33 - 00796678 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-29 19:51 - 2012-07-29 19:51 - 12621696 ____A (Microsoft Corporation) C:\Users\Anne\Downloads\mseinstall.exe
2012-07-29 19:14 - 2011-11-24 21:09 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-495499240-2845497790-2203762804-1000Core.job
2012-07-29 19:07 - 2012-07-29 18:53 - 50957919 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part6.rar
2012-07-29 19:05 - 2009-07-13 21:13 - 00782592 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-29 18:24 - 2012-07-29 18:09 - 263192577 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part5.rar
2012-07-29 17:48 - 2012-07-29 17:35 - 263192577 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part3.rar
2012-07-29 17:32 - 2012-07-29 16:20 - 263192576 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part2.rar
2012-07-29 17:21 - 2012-07-29 16:10 - 263192577 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part1.rar
2012-07-25 13:16 - 2012-07-25 12:57 - 152948744 ____A C:\Users\Anne\Downloads\iTunes-Jay-Z_and_Kanye_West-Watch_The_Throne_(Deluxe_Version)-(2011).rar
2012-07-25 12:41 - 2012-07-25 12:41 - 00420352 ____A C:\Users\Anne\AppData\Roaming\gdasn.dll
2012-07-20 07:06 - 2012-07-20 07:06 - 00112121 ____A C:\Users\Anne\Downloads\644 - Making Small Talk in English a.pptx
2012-07-20 07:04 - 2012-07-20 07:04 - 03338947 ____A C:\Users\Anne\Downloads\644 - Making Small Talk in English .pptx
2012-07-12 15:11 - 2012-07-12 15:11 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-495499240-2845497790-2203762804-1003Core1cd6083b0707453.job
2012-07-12 02:57 - 2009-07-13 20:45 - 05023264 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 20:38 - 2011-11-26 05:11 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-11 09:34 - 2011-12-23 12:59 - 00002392 ____A C:\Users\Anne\Desktop\Google Chrome.lnk
2012-07-11 06:11 - 2012-07-11 06:10 - 00118044 ____A C:\Users\Anne\Downloads\547 - Discussing Work in English.pptx
2012-07-10 15:54 - 2012-07-10 15:54 - 00000215 ____A C:\Users\Anne\AppData\Roaming\My Profile.xml
2012-07-10 05:09 - 2012-07-10 05:08 - 03701449 ____A C:\Users\Anne\Desktop\Integrated Reasoning2.pptx
2012-07-10 05:04 - 2012-07-10 05:02 - 03701449 ____A C:\Users\Anne\Desktop\Integrated Reasoning.pptx
2012-07-08 14:27 - 2012-07-08 13:56 - 00000106 ____A C:\Windows\EWF645.ini
2012-07-08 14:05 - 2012-07-08 14:05 - 00000934 ____A C:\Users\Public\Desktop\EPSON Scan.lnk
2012-07-02 17:23 - 2012-07-02 17:23 - 07301084 ____A C:\Users\Anne\Downloads\570 - English for Road Trips Around the U.S..pptx
2012-06-28 15:30 - 2012-06-28 15:30 - 01796041 ____A C:\Users\Anne\Downloads\551 - Useful Objects.pptx
2012-06-24 09:29 - 2012-06-24 09:29 - 03465508 ____A C:\Users\Anne\Downloads\Time_Magazine_6-25-12.rar
2012-06-22 14:46 - 2012-04-04 03:10 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-22 14:46 - 2011-12-20 15:21 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-19 06:54 - 2012-06-19 06:28 - 316975859 ____A C:\Users\Anne\Downloads\Scientific_American_Magazine_2011___[12_eBooks_(pdf)].rar
2012-06-14 19:41 - 2012-06-14 19:41 - 00064833 ____A C:\Users\Anne\Desktop\monitor.txt
2012-06-11 19:08 - 2012-07-11 20:42 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-09 14:04 - 2011-12-13 11:59 - 00000132 ____A C:\Users\Anne\AppData\Roaming\Adobe PNG Format CS5 Prefs
2012-06-08 21:43 - 2012-07-11 04:00 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 04:00 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-07 20:51 - 2012-06-07 20:48 - 21332022 ____A C:\Users\Anne\Downloads\0470500778Tests.rar
2012-06-07 10:08 - 2012-06-07 09:39 - 170083563 ____A C:\Users\Anne\Downloads\The_Economist_Jan_7th_-_13th_2012.rar
2012-06-07 09:25 - 2012-06-07 09:19 - 91583475 ____A C:\Users\Anne\Downloads\The_Economist_UK_21st_April 2012.rar
2012-06-05 22:06 - 2012-07-11 04:00 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 04:00 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 04:00 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 04:00 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 04:00 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 04:00 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-05 06:29 - 2012-06-05 06:29 - 01308672 ____A C:\Users\Anne\Downloads\Awesome Error Log_V2-1.xls
2012-06-05 06:23 - 2012-06-05 06:23 - 00362496 ____A C:\Users\Anne\Downloads\og12-gmat-error-log.xls
2012-06-05 06:23 - 2012-06-05 06:23 - 00043008 ____A C:\Users\Anne\Downloads\gmat-error-log.xls
2012-06-05 06:23 - 2012-06-05 06:23 - 00041984 ____A C:\Users\Anne\Downloads\gmat-progress-chart.xls
2012-06-03 12:06 - 2012-06-03 12:06 - 00015012 ____A C:\Users\Anne\Downloads\mental-math.html
2012-06-02 14:19 - 2012-06-21 03:12 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 03:12 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 03:12 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 03:12 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 03:12 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 03:12 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 03:12 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-21 03:11 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-21 03:11 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-11 20:37 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 20:37 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 20:37 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 20:37 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 20:37 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 20:37 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 20:37 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 20:37 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 20:37 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 20:37 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 20:37 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 20:37 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 20:37 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 20:37 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 20:37 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 20:37 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 20:37 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 20:37 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 20:37 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 20:37 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 20:37 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 20:37 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 20:37 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 20:37 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 20:37 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 20:37 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 20:37 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 20:37 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-11 04:00 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 04:00 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 04:00 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 04:00 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 04:00 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 04:00 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 04:00 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 04:00 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 04:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-06-01 14:09 - 2012-06-01 14:09 - 00067839 ____A C:\Users\Anne\Desktop\test.wma
2012-05-18 17:33 - 2012-05-18 17:33 - 01512195 ____A C:\Users\Anne\Downloads\Magnificent.zip
2012-05-17 05:38 - 2012-05-17 05:38 - 372862715 ____A C:\Windows\MEMORY.DMP
2012-05-17 05:38 - 2012-05-17 05:38 - 00262144 ____A C:\Windows\Minidump\051712-33228-01.dmp
2012-05-15 21:49 - 2012-05-15 21:49 - 00522399 ____A C:\Users\Anne\Downloads\Ai 261.zip
2012-05-15 21:48 - 2012-05-15 21:47 - 03886302 ____A C:\Users\Anne\Downloads\Trees Brushes.zip
2012-05-15 21:48 - 2012-05-15 21:47 - 03635023 ____A C:\Users\Anne\Downloads\Trees Png.zip
2012-05-15 21:47 - 2012-05-15 21:46 - 07167924 ____A C:\Users\Anne\Downloads\21.zip
2012-05-15 17:25 - 2012-05-15 17:25 - 00256423 ____A C:\Users\Anne\Downloads\Fresh Sliding Thumbnails Gallery with jQuery and PHP _ Codrops.htm
2012-05-15 08:10 - 2012-05-15 08:09 - 07518054 ____A C:\Users\Anne\Downloads\SimplePressPSD.zip
2012-05-15 08:09 - 2012-05-15 08:09 - 01364630 ____A C:\Users\Anne\Downloads\SimplePress.zip
2012-05-14 17:30 - 2012-05-14 17:30 - 01309354 ____A C:\Users\Anne\Downloads\summernight.zip
2012-05-14 17:17 - 2012-05-14 17:17 - 00974889 ____A C:\Users\Anne\Downloads\cloriato-lite.1.4.zip
2012-05-14 16:58 - 2012-05-14 16:58 - 00110692 ____A C:\Users\Anne\Downloads\ambrosia.1.1.1.zip
2012-05-14 16:56 - 2012-05-14 16:56 - 00059900 ____A C:\Users\Anne\Downloads\softgreen.1.2.zip
2012-05-10 07:08 - 2012-05-10 07:08 - 02530939 ____A C:\Users\Anne\Downloads\GMAT Math Bible.rar
2012-05-06 05:07 - 2012-05-06 05:07 - 00739832 ____A (Google Inc.) C:\Users\Anne\Downloads\GoogleVoiceAndVideoSetup.exe
2012-05-05 10:46 - 2012-04-04 03:47 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-04 03:06 - 2012-06-13 11:14 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 11:14 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 11:14 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
ZeroAccess:
C:\Windows\Installer\{00b598d9-c12d-228a-e17a-a95173c1bd79}
C:\Windows\Installer\{00b598d9-c12d-228a-e17a-a95173c1bd79}\@
C:\Windows\Installer\{00b598d9-c12d-228a-e17a-a95173c1bd79}\L
C:\Windows\Installer\{00b598d9-c12d-228a-e17a-a95173c1bd79}\n
C:\Windows\Installer\{00b598d9-c12d-228a-e17a-a95173c1bd79}\U
C:\Windows\Installer\{00b598d9-c12d-228a-e17a-a95173c1bd79}\U\00000001.@
ZeroAccess:
C:\Users\Anne\AppData\Local\{00b598d9-c12d-228a-e17a-a95173c1bd79}
C:\Users\Anne\AppData\Local\{00b598d9-c12d-228a-e17a-a95173c1bd79}\@
C:\Users\Anne\AppData\Local\{00b598d9-c12d-228a-e17a-a95173c1bd79}\L
C:\Users\Anne\AppData\Local\{00b598d9-c12d-228a-e17a-a95173c1bd79}\U
C:\Users\Anne\AppData\Local\{00b598d9-c12d-228a-e17a-a95173c1bd79}\U\00000001.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3976.9 MB
Available physical RAM: 3340.92 MB
Total Pagefile: 3975.1 MB
Available Pagefile: 3335.76 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (Anne) (Fixed) (Total:232.11 GB) (Free:21.79 GB) NTFS
3 Drive f: () (Removable) (Total:0.25 GB) (Free:0.24 GB) FAT
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (RECOVERY) (Fixed) (Total:0.73 GB) (Free:0.51 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 232 GB 2048 KB
Disk 1 Online 253 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 31 KB
Partition 2 Primary 752 MB 40 MB
Partition 3 Primary 232 GB 792 MB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 39 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y RECOVERY NTFS Partition 752 MB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Anne NTFS Partition 232 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 253 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT Removable 253 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-19 09:13
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-30 01:27:18
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======
I have checked out the reads already here and did the FRST64/Service logs since that was the general first step. I can barely log into my computer now.. Not touching my laptop at all until I get a reply. Thanks for any help you can provide!
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 30-07-2012 01:23:08
Running from F:\
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [592240 2011-01-04] (Alps Electric Co., Ltd.)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167960 2011-03-30] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [391704 2011-03-30] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [418328 2011-03-30] (Intel Corporation)
HKLM\...\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686704 2010-12-17] ()
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [6492672 2011-01-15] (Dell Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [gdasn] "C:\Windows\System32\rundll32.exe" "C:\Users\Anne\AppData\Roaming\gdasn.dll",set_read_fn [420352 2012-07-25] ()
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [112152 2010-12-03] (Intel Corporation)
HKLM-x32\...\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [462993 2010-03-12] (Creative Technology Ltd)
HKLM-x32\...\Run: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [87336 2009-07-06] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [50472 2010-04-29] (CyberLink Corp.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [514544 2010-11-17] ()
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-06-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.)
HKLM-x32\...\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe" [495616 2011-03-08] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" [856064 2011-03-08] (SEIKO EPSON CORPORATION)
HKU\Anne\...\Run: [Google Update] "C:\Users\Anne\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-12-23] (Google Inc.)
HKU\Anne\...\Run: [AdobeBridge] [x]
HKU\Anne\...\Run: [googletalk] C:\Users\Anne\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart [3739648 2007-01-01] (Google)
HKU\Anne\...\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun [3111744 2012-04-26] (DT Soft Ltd)
HKU\Anne\...\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHVA.EXE /EPT "EPLTarget\P0000000000000000" /M "WorkForce 645" [239488 2011-04-24] (SEIKO EPSON CORPORATION)
HKU\Anne\...\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)
HKU\Anne\...\Run: [gdasn] "C:\Windows\System32\rundll32.exe" "C:\Users\Anne\AppData\Roaming\gdasn.dll",set_read_fn [420352 2012-07-25] ()
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Lsa: [Authentication Packages] msv1_0
wvauth
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Dell System Manager.lnk
ShortcutTarget: Dell System Manager.lnk -> C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe (Dell Inc.)
Startup: C:\Users\Anne\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ======
2 ABBYY.Licensing.FineReader.Sprint.9.0; "C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe" -service [759048 2009-05-14] (ABBYY)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 O2SDIOAssist; C:\Windows\SysWOW64\srvany.exe [8192 2003-04-18] ()
2 RoxWatch12; "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe" [219632 2010-11-25] (Sonic Solutions)
3 stllssvr; "C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe" [74392 2010-11-08] (MicroVision Development, Inc.)
2 tcsd_win32.exe; "C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe" [1629696 2010-07-13] ()
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656280 2010-12-03] (Intel Corporation)
========================== Drivers (Whitelisted) =============
0 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-04-27] (Duplex Secure Ltd.)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-29 20:50 - 2012-07-29 20:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.03E86C6D05C1E43F
2012-07-29 20:42 - 2012-07-29 20:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.58886290833A4289
2012-07-29 20:35 - 2012-07-29 20:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2C31D00BBF6CF89F
2012-07-29 20:31 - 2012-07-29 20:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.211AFBF5E4391C5E
2012-07-29 20:25 - 2012-07-29 20:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47B664D89E53D58B
2012-07-29 20:17 - 2012-07-29 20:19 - 00347424 ____A (Microsoft Corporation) C:\Users\Anne\Downloads\MicrosoftFixit.WindowsFirewall.RNP.19267051685286478.3.1.Run.exe
2012-07-29 20:11 - 2012-07-29 20:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.887F2746A8C90C90
2012-07-29 19:59 - 2012-07-29 19:59 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-29 19:59 - 2012-07-29 19:59 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-29 19:51 - 2012-07-29 19:51 - 12621696 ____A (Microsoft Corporation) C:\Users\Anne\Downloads\mseinstall.exe
2012-07-29 19:11 - 2012-07-29 19:11 - 00000000 ____D C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech
2012-07-29 18:53 - 2012-07-29 19:07 - 50957919 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part6.rar
2012-07-29 18:38 - 2012-07-29 18:38 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-29 18:09 - 2012-07-29 18:24 - 263192577 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part5.rar
2012-07-29 17:35 - 2012-07-29 17:48 - 263192577 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part3.rar
2012-07-29 16:20 - 2012-07-29 17:32 - 263192576 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part2.rar
2012-07-29 16:10 - 2012-07-29 17:21 - 263192577 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part1.rar
2012-07-26 19:58 - 2012-07-26 19:58 - 00000000 ____D C:\Users\Anne\Downloads\iTunes-Jay-Z_and_Kanye_West-Watch_The_Throne_(Deluxe_Version)-(2011)
2012-07-25 12:57 - 2012-07-25 13:16 - 152948744 ____A C:\Users\Anne\Downloads\iTunes-Jay-Z_and_Kanye_West-Watch_The_Throne_(Deluxe_Version)-(2011).rar
2012-07-25 12:41 - 2012-07-25 12:41 - 00420352 ____A C:\Users\Anne\AppData\Roaming\gdasn.dll
2012-07-25 12:41 - 2012-07-25 12:41 - 00000000 ____D C:\Users\Anne\AppData\Local\{215B93C0-D699-11E1-8270-B8AC6F996F26}
2012-07-25 12:41 - 2012-07-25 12:41 - 00000000 ____D C:\Users\Anne\AppData\Local\{215B6270-D699-11E1-8270-B8AC6F996F26}
2012-07-21 10:22 - 2012-07-21 10:40 - 00000000 ____D C:\Users\Anne\Desktop\NAIL POLISH
2012-07-20 20:48 - 2012-07-23 09:29 - 00000000 ____D C:\Users\Anne\Desktop\Summer 2012 Vision Board
2012-07-20 07:06 - 2012-07-20 07:06 - 00112121 ____A C:\Users\Anne\Downloads\644 - Making Small Talk in English a.pptx
2012-07-20 07:04 - 2012-07-20 07:04 - 03338947 ____A C:\Users\Anne\Downloads\644 - Making Small Talk in English .pptx
2012-07-12 15:11 - 2012-07-12 15:11 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-495499240-2845497790-2203762804-1003Core1cd6083b0707453.job
2012-07-11 20:42 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 20:37 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 20:37 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 20:37 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 20:37 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 20:37 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 20:37 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 20:37 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 20:37 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 20:37 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 20:37 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 20:37 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 20:37 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 20:37 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 20:37 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 20:37 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 20:37 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 20:37 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 20:37 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 20:37 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 20:37 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 20:37 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 20:37 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 20:37 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 20:37 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 20:37 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 20:37 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 20:37 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 20:37 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 06:10 - 2012-07-11 06:11 - 00118044 ____A C:\Users\Anne\Downloads\547 - Discussing Work in English.pptx
2012-07-11 04:00 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 04:00 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 04:00 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 04:00 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 04:00 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 04:00 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 04:00 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 04:00 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 04:00 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 04:00 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 04:00 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 04:00 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 04:00 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 04:00 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 04:00 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 04:00 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 04:00 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 04:00 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 04:00 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-10 15:54 - 2012-07-10 15:54 - 00000215 ____A C:\Users\Anne\AppData\Roaming\My Profile.xml
2012-07-10 05:08 - 2012-07-10 05:09 - 03701449 ____A C:\Users\Anne\Desktop\Integrated Reasoning2.pptx
2012-07-10 05:02 - 2012-07-10 05:04 - 03701449 ____A C:\Users\Anne\Desktop\Integrated Reasoning.pptx
2012-07-08 14:22 - 2012-07-08 14:22 - 00000000 ____D C:\Users\Anne\AppData\Roaming\Leadertech
2012-07-08 14:20 - 2012-07-08 14:22 - 00000000 ____D C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint
2012-07-08 14:20 - 2012-07-08 14:20 - 00000000 ____D C:\Users\Anne\AppData\Local\ABBYY
2012-07-08 14:20 - 2012-07-08 14:20 - 00000000 ____D C:\Users\All Users\ABBYY
2012-07-08 14:11 - 2012-07-08 14:11 - 00000000 ____D C:\Program Files\Common Files\EPSON
2012-07-08 14:09 - 2012-07-08 14:09 - 00000000 ____D C:\Users\Anne\AppData\Roaming\InstallShield
2012-07-08 14:09 - 2012-07-08 14:09 - 00000000 ____D C:\Program Files\EpsonNet
2012-07-08 14:09 - 2012-07-08 14:09 - 00000000 ____D C:\Program Files\EPSON
2012-07-08 14:09 - 2010-09-13 11:01 - 00538112 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\ensppui.dll
2012-07-08 14:09 - 2010-09-13 11:01 - 00538112 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\enppui.dll
2012-07-08 14:09 - 2010-09-13 11:00 - 00558592 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\ensppmon.dll
2012-07-08 14:09 - 2010-09-13 11:00 - 00558592 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\enppmon.dll
2012-07-08 14:09 - 2008-06-18 07:49 - 00250880 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\enspres.dll
2012-07-08 14:09 - 2008-06-18 07:49 - 00250880 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\enpres.dll
2012-07-08 14:08 - 2012-07-12 02:59 - 00000000 ____D C:\Users\Anne\AppData\Roaming\Epson
2012-07-08 14:07 - 2012-07-08 14:07 - 00000000 ____D C:\Program Files (x86)\Epson America Inc
2012-07-08 14:06 - 2012-07-08 14:26 - 00000000 ____D C:\Program Files (x86)\Epson Software
2012-07-08 14:05 - 2012-07-08 14:13 - 00000000 ____D C:\Users\All Users\EPSON
2012-07-08 14:05 - 2012-07-08 14:06 - 00000000 ____D C:\Program Files (x86)\epson
2012-07-08 14:05 - 2012-07-08 14:05 - 00000934 ____A C:\Users\Public\Desktop\EPSON Scan.lnk
2012-07-08 14:05 - 2010-09-28 06:01 - 00118784 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\E_YLMHVA.DLL
2012-07-08 14:05 - 2010-08-09 06:02 - 00083456 ____A (SEIKO EPSON CORPORATION) C:\Windows\System32\E_YD4BHVA.DLL
2012-07-08 14:05 - 2009-12-08 20:00 - 00464384 ____A (Seiko Epson Corporation) C:\Windows\System32\esxw2ud.dll
2012-07-08 14:05 - 2009-10-15 20:00 - 00132560 ____A (Seiko Epson Corporation) C:\Windows\System32\esdevapp.exe
2012-07-08 14:05 - 2009-10-15 20:00 - 00013824 ____A (Seiko Epson Corporation) C:\Windows\System32\esxcdev.dll
2012-07-08 13:56 - 2012-07-08 14:27 - 00000106 ____A C:\Windows\EWF645.ini
2012-07-02 17:23 - 2012-07-02 17:23 - 07301084 ____A C:\Users\Anne\Downloads\570 - English for Road Trips Around the U.S..pptx
2012-07-02 16:57 - 2012-07-02 17:08 - 00000000 ____D C:\Users\Anne\Desktop\Bank Statements
============ 3 Months Modified Files ========================
2012-07-29 21:17 - 2009-07-13 20:51 - 00065427 ____A C:\Windows\setupact.log
2012-07-29 21:15 - 2010-11-20 19:47 - 00051642 ____A C:\Windows\PFRO.log
2012-07-29 21:15 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-29 20:50 - 2012-07-29 20:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.03E86C6D05C1E43F
2012-07-29 20:42 - 2012-07-29 20:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.58886290833A4289
2012-07-29 20:35 - 2012-07-29 20:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2C31D00BBF6CF89F
2012-07-29 20:31 - 2012-07-29 20:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.211AFBF5E4391C5E
2012-07-29 20:25 - 2012-07-29 20:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47B664D89E53D58B
2012-07-29 20:22 - 2009-07-13 20:45 - 00021312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-29 20:22 - 2009-07-13 20:45 - 00021312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-29 20:19 - 2012-07-29 20:17 - 00347424 ____A (Microsoft Corporation) C:\Users\Anne\Downloads\MicrosoftFixit.WindowsFirewall.RNP.19267051685286478.3.1.Run.exe
2012-07-29 20:14 - 2011-11-24 21:09 - 00000940 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-495499240-2845497790-2203762804-1000UA.job
2012-07-29 20:11 - 2012-07-29 20:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.887F2746A8C90C90
2012-07-29 20:00 - 2011-12-05 19:54 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-29 20:00 - 2011-06-18 17:12 - 01294915 ____A C:\Windows\WindowsUpdate.log
2012-07-29 19:59 - 2011-02-10 06:33 - 00796678 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-29 19:51 - 2012-07-29 19:51 - 12621696 ____A (Microsoft Corporation) C:\Users\Anne\Downloads\mseinstall.exe
2012-07-29 19:14 - 2011-11-24 21:09 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-495499240-2845497790-2203762804-1000Core.job
2012-07-29 19:07 - 2012-07-29 18:53 - 50957919 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part6.rar
2012-07-29 19:05 - 2009-07-13 21:13 - 00782592 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-29 18:24 - 2012-07-29 18:09 - 263192577 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part5.rar
2012-07-29 17:48 - 2012-07-29 17:35 - 263192577 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part3.rar
2012-07-29 17:32 - 2012-07-29 16:20 - 263192576 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part2.rar
2012-07-29 17:21 - 2012-07-29 16:10 - 263192577 ____A C:\Users\Anne\Downloads\Rosetta Stone v3 Portuguese (Brazil) & speech.part1.rar
2012-07-25 13:16 - 2012-07-25 12:57 - 152948744 ____A C:\Users\Anne\Downloads\iTunes-Jay-Z_and_Kanye_West-Watch_The_Throne_(Deluxe_Version)-(2011).rar
2012-07-25 12:41 - 2012-07-25 12:41 - 00420352 ____A C:\Users\Anne\AppData\Roaming\gdasn.dll
2012-07-20 07:06 - 2012-07-20 07:06 - 00112121 ____A C:\Users\Anne\Downloads\644 - Making Small Talk in English a.pptx
2012-07-20 07:04 - 2012-07-20 07:04 - 03338947 ____A C:\Users\Anne\Downloads\644 - Making Small Talk in English .pptx
2012-07-12 15:11 - 2012-07-12 15:11 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-495499240-2845497790-2203762804-1003Core1cd6083b0707453.job
2012-07-12 02:57 - 2009-07-13 20:45 - 05023264 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 20:38 - 2011-11-26 05:11 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-11 09:34 - 2011-12-23 12:59 - 00002392 ____A C:\Users\Anne\Desktop\Google Chrome.lnk
2012-07-11 06:11 - 2012-07-11 06:10 - 00118044 ____A C:\Users\Anne\Downloads\547 - Discussing Work in English.pptx
2012-07-10 15:54 - 2012-07-10 15:54 - 00000215 ____A C:\Users\Anne\AppData\Roaming\My Profile.xml
2012-07-10 05:09 - 2012-07-10 05:08 - 03701449 ____A C:\Users\Anne\Desktop\Integrated Reasoning2.pptx
2012-07-10 05:04 - 2012-07-10 05:02 - 03701449 ____A C:\Users\Anne\Desktop\Integrated Reasoning.pptx
2012-07-08 14:27 - 2012-07-08 13:56 - 00000106 ____A C:\Windows\EWF645.ini
2012-07-08 14:05 - 2012-07-08 14:05 - 00000934 ____A C:\Users\Public\Desktop\EPSON Scan.lnk
2012-07-02 17:23 - 2012-07-02 17:23 - 07301084 ____A C:\Users\Anne\Downloads\570 - English for Road Trips Around the U.S..pptx
2012-06-28 15:30 - 2012-06-28 15:30 - 01796041 ____A C:\Users\Anne\Downloads\551 - Useful Objects.pptx
2012-06-24 09:29 - 2012-06-24 09:29 - 03465508 ____A C:\Users\Anne\Downloads\Time_Magazine_6-25-12.rar
2012-06-22 14:46 - 2012-04-04 03:10 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-22 14:46 - 2011-12-20 15:21 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-19 06:54 - 2012-06-19 06:28 - 316975859 ____A C:\Users\Anne\Downloads\Scientific_American_Magazine_2011___[12_eBooks_(pdf)].rar
2012-06-14 19:41 - 2012-06-14 19:41 - 00064833 ____A C:\Users\Anne\Desktop\monitor.txt
2012-06-11 19:08 - 2012-07-11 20:42 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-09 14:04 - 2011-12-13 11:59 - 00000132 ____A C:\Users\Anne\AppData\Roaming\Adobe PNG Format CS5 Prefs
2012-06-08 21:43 - 2012-07-11 04:00 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 04:00 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-07 20:51 - 2012-06-07 20:48 - 21332022 ____A C:\Users\Anne\Downloads\0470500778Tests.rar
2012-06-07 10:08 - 2012-06-07 09:39 - 170083563 ____A C:\Users\Anne\Downloads\The_Economist_Jan_7th_-_13th_2012.rar
2012-06-07 09:25 - 2012-06-07 09:19 - 91583475 ____A C:\Users\Anne\Downloads\The_Economist_UK_21st_April 2012.rar
2012-06-05 22:06 - 2012-07-11 04:00 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 04:00 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 04:00 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 04:00 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 04:00 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 04:00 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-05 06:29 - 2012-06-05 06:29 - 01308672 ____A C:\Users\Anne\Downloads\Awesome Error Log_V2-1.xls
2012-06-05 06:23 - 2012-06-05 06:23 - 00362496 ____A C:\Users\Anne\Downloads\og12-gmat-error-log.xls
2012-06-05 06:23 - 2012-06-05 06:23 - 00043008 ____A C:\Users\Anne\Downloads\gmat-error-log.xls
2012-06-05 06:23 - 2012-06-05 06:23 - 00041984 ____A C:\Users\Anne\Downloads\gmat-progress-chart.xls
2012-06-03 12:06 - 2012-06-03 12:06 - 00015012 ____A C:\Users\Anne\Downloads\mental-math.html
2012-06-02 14:19 - 2012-06-21 03:12 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 03:12 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 03:12 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 03:12 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 03:12 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 03:12 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 03:12 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-21 03:11 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-21 03:11 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-11 20:37 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 20:37 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 20:37 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 20:37 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 20:37 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 20:37 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 20:37 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 20:37 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 20:37 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 20:37 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 20:37 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 20:37 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 20:37 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 20:37 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 20:37 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 20:37 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 20:37 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 20:37 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 20:37 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 20:37 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 20:37 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 20:37 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 20:37 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 20:37 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 20:37 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 20:37 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 20:37 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 20:37 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-11 04:00 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 04:00 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 04:00 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 04:00 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 04:00 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 04:00 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 04:00 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 04:00 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 04:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-06-01 14:09 - 2012-06-01 14:09 - 00067839 ____A C:\Users\Anne\Desktop\test.wma
2012-05-18 17:33 - 2012-05-18 17:33 - 01512195 ____A C:\Users\Anne\Downloads\Magnificent.zip
2012-05-17 05:38 - 2012-05-17 05:38 - 372862715 ____A C:\Windows\MEMORY.DMP
2012-05-17 05:38 - 2012-05-17 05:38 - 00262144 ____A C:\Windows\Minidump\051712-33228-01.dmp
2012-05-15 21:49 - 2012-05-15 21:49 - 00522399 ____A C:\Users\Anne\Downloads\Ai 261.zip
2012-05-15 21:48 - 2012-05-15 21:47 - 03886302 ____A C:\Users\Anne\Downloads\Trees Brushes.zip
2012-05-15 21:48 - 2012-05-15 21:47 - 03635023 ____A C:\Users\Anne\Downloads\Trees Png.zip
2012-05-15 21:47 - 2012-05-15 21:46 - 07167924 ____A C:\Users\Anne\Downloads\21.zip
2012-05-15 17:25 - 2012-05-15 17:25 - 00256423 ____A C:\Users\Anne\Downloads\Fresh Sliding Thumbnails Gallery with jQuery and PHP _ Codrops.htm
2012-05-15 08:10 - 2012-05-15 08:09 - 07518054 ____A C:\Users\Anne\Downloads\SimplePressPSD.zip
2012-05-15 08:09 - 2012-05-15 08:09 - 01364630 ____A C:\Users\Anne\Downloads\SimplePress.zip
2012-05-14 17:30 - 2012-05-14 17:30 - 01309354 ____A C:\Users\Anne\Downloads\summernight.zip
2012-05-14 17:17 - 2012-05-14 17:17 - 00974889 ____A C:\Users\Anne\Downloads\cloriato-lite.1.4.zip
2012-05-14 16:58 - 2012-05-14 16:58 - 00110692 ____A C:\Users\Anne\Downloads\ambrosia.1.1.1.zip
2012-05-14 16:56 - 2012-05-14 16:56 - 00059900 ____A C:\Users\Anne\Downloads\softgreen.1.2.zip
2012-05-10 07:08 - 2012-05-10 07:08 - 02530939 ____A C:\Users\Anne\Downloads\GMAT Math Bible.rar
2012-05-06 05:07 - 2012-05-06 05:07 - 00739832 ____A (Google Inc.) C:\Users\Anne\Downloads\GoogleVoiceAndVideoSetup.exe
2012-05-05 10:46 - 2012-04-04 03:47 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-04 03:06 - 2012-06-13 11:14 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 11:14 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 11:14 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
ZeroAccess:
C:\Windows\Installer\{00b598d9-c12d-228a-e17a-a95173c1bd79}
C:\Windows\Installer\{00b598d9-c12d-228a-e17a-a95173c1bd79}\@
C:\Windows\Installer\{00b598d9-c12d-228a-e17a-a95173c1bd79}\L
C:\Windows\Installer\{00b598d9-c12d-228a-e17a-a95173c1bd79}\n
C:\Windows\Installer\{00b598d9-c12d-228a-e17a-a95173c1bd79}\U
C:\Windows\Installer\{00b598d9-c12d-228a-e17a-a95173c1bd79}\U\00000001.@
ZeroAccess:
C:\Users\Anne\AppData\Local\{00b598d9-c12d-228a-e17a-a95173c1bd79}
C:\Users\Anne\AppData\Local\{00b598d9-c12d-228a-e17a-a95173c1bd79}\@
C:\Users\Anne\AppData\Local\{00b598d9-c12d-228a-e17a-a95173c1bd79}\L
C:\Users\Anne\AppData\Local\{00b598d9-c12d-228a-e17a-a95173c1bd79}\U
C:\Users\Anne\AppData\Local\{00b598d9-c12d-228a-e17a-a95173c1bd79}\U\00000001.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3976.9 MB
Available physical RAM: 3340.92 MB
Total Pagefile: 3975.1 MB
Available Pagefile: 3335.76 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (Anne) (Fixed) (Total:232.11 GB) (Free:21.79 GB) NTFS
3 Drive f: () (Removable) (Total:0.25 GB) (Free:0.24 GB) FAT
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (RECOVERY) (Fixed) (Total:0.73 GB) (Free:0.51 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 232 GB 2048 KB
Disk 1 Online 253 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 31 KB
Partition 2 Primary 752 MB 40 MB
Partition 3 Primary 232 GB 792 MB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 39 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y RECOVERY NTFS Partition 752 MB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Anne NTFS Partition 232 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 253 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT Removable 253 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-19 09:13
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-30 01:27:18
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======