Terry Ramsey
Posts: 15 +0
Hello. My computer became infected on the weekend with Sirefef.Y and is suffering from constant reboots 1 minute after startup, even in Safe Mode. Microsoft Security Essentials reported the infection in the C:\Windows\System32\services.exe file, but is unable to do anything before the reboot occurs.
I used Farbar Recovery Scan Tool 64-bit to scan my Windows 7 Pro install. Here is the result of that scan. Thanks in advance for any assitance you can provide.
Scan result of Farbar Recovery Scan Tool Version: 03-07-2012 01
Ran by SYSTEM at 03-07-2012 23:52:38
Running from K:\
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe" [163552 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [12681320 2011-08-26] (Realtek Semiconductor)
HKLM\...\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe /minimized [6868280 2012-05-21] (Logitech Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [499608 2011-03-30] (Adobe Systems Incorporated)
HKLM\...\Run: [Acronis Scheduler2 Service] "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [390720 2011-02-01] (Acronis)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281240 2012-06-12] (Microsoft Corporation)
HKLM-x32\...\Run: [TrueImageMonitor.exe] "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" [5550984 2011-09-22] (Acronis)
HKLM-x32\...\Run: [SteelSeries World of Warcraft Cataclysm MMO Gaming Mouse] "C:\Program Files (x86)\SteelSeries\World of Warcraft Cataclysm MMO Gaming Mouse\WoWMHID2.exe" [1993216 2011-08-18] (SteelSeries)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-01-16] (Apple Inc.)
HKLM-x32\...\Run: [iolo Startup] "C:\Program Files (x86)\iolo\Common\Lib\ioloLManager.exe" [938680 2012-04-17] (iolo technologies, LLC)
HKLM-x32\...\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey [1858152 2012-03-30] (Microsoft Corp.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKU\Mcx1-ZOMBIE\...\Winlogon: [Shell] C:\Windows\eHome\McrMgr.exe [343552 2009-07-13] (Microsoft Corporation)
HKU\Terry\...\Run: [DCD5A9DEF340132AE028E0C7EC112B0A9A533117._service_run] "C:\Users\Terry\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service [1239576 2012-06-07] (Google Inc.)
HKU\Terry\...\Run: [Google Update] "C:\Users\Terry\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-09-27] (Google Inc.)
HKU\Terry\...\Run: [DisplayFusion] "C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe" [4480456 2012-05-31] (Binary Fortress Software)
Winlogon\Notify\WB:
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\Terry\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 AcrSch2Svc; "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe" [1112240 2011-02-01] (Acronis)
2 afcdpsrv; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [3246040 2011-11-01] (Acronis)
2 BingDesktopUpdate; "C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe" [151656 2012-03-30] (Microsoft Corp.)
2 ioloSystemService; "C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe" [1047336 2012-04-17] (iolo technologies, LLC)
2 iRacingService; C:\Program Files (x86)\iRacing\iRacingService.exe [519848 2012-06-20] (iRacing.com Motorsport Simulations, LLC
Bedford, MA 01730)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22024 2012-06-12] (Microsoft Corporation)
2 MSSQL$SQLEXPRESS; "C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS [58345832 2011-09-22] (Microsoft Corporation)
4 NetTcpPortSharing; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [124240 2010-03-18] (Microsoft Corporation)
2 PDAgent; "C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe" [2610952 2011-03-15] (Raxco Software, Inc.)
3 PDEngine; "C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe" [2266376 2011-03-15] (Raxco Software, Inc.)
4 SQLAgent$SQLEXPRESS; "C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE" -I SQLEXPRESS [431464 2011-09-22] (Microsoft Corporation)
3 WMZuneComm; "C:\Program Files\Zune\WMZuneComm.exe" [306400 2011-08-05] (Microsoft Corporation)
2 ZuneNetworkSvc; "C:\Program Files\Zune\ZuneNss.exe" [8277728 2011-08-05] (Microsoft Corporation)
3 ZuneWlanCfgSvc; "C:\Program Files\Zune\ZuneWlanCfgSvc.exe" [467680 2011-08-05] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 afcdp; C:\Windows\System32\Drivers\afcdp.sys [285280 2011-11-01] (Acronis)
1 ElRawDisk; \??\C:\Windows\system32\drivers\ElRawDsk.sys [31432 2012-04-17] (EldoS Corporation)
3 mbamchameleon; C:\Windows\System32\Drivers\mbamchameleon.sys [29808 2012-05-14] ()
0 snapman; C:\Windows\System32\Drivers\snapman.sys [277088 2011-11-01] (Acronis)
3 SSMO3v2Filter; C:\Windows\System32\drivers\MO3v2Driver.sys [23040 2010-11-22] (Sagatek Co. Ltd.)
0 tdrpman273; C:\Windows\System32\DRIVERS\tdrpm273.sys [1263200 2011-11-01] (Acronis)
0 timounter; C:\Windows\System32\DRIVERS\timntr.sys [970336 2011-11-01] (Acronis)
3 ALSysIO; \??\C:\Users\Terry\AppData\Local\Temp\ALSysIO64.sys [x]
3 cpuz130; \??\C:\Users\Terry\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-01 03:24 - 2012-07-01 03:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3B92342094B39691
2012-07-01 03:21 - 2012-07-01 03:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F71791E6ADEA137E
2012-07-01 03:18 - 2012-07-01 03:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B08B0339D2F11D5D
2012-07-01 03:15 - 2012-07-01 03:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.041812FB36CB7781
2012-07-01 03:12 - 2012-07-01 03:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1F18242F2631952A
2012-07-01 03:09 - 2012-07-01 03:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D670B6C8846630E
2012-07-01 03:06 - 2012-07-01 03:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DAFD3F03A41E7183
2012-07-01 03:06 - 2012-07-01 03:06 - 00001272 ____A C:\Users\Terry\Desktop\shutdown.lnk
2012-07-01 02:58 - 2012-07-01 02:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AC62FC97DFA59B3F
2012-06-30 19:32 - 2012-06-30 19:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8BA2AF81B98BC5B0
2012-06-30 19:29 - 2012-06-30 19:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB37322D34C32672
2012-06-30 19:22 - 2012-06-30 19:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECF47747A84213B6
2012-06-30 18:22 - 2012-06-30 18:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B3B255BEFD6BEBE0
2012-06-30 18:16 - 2012-06-30 18:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4C5332E139D0F0A3
2012-06-30 18:11 - 2012-06-30 18:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D67820F321D98719
2012-06-30 18:05 - 2012-06-30 18:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C56C36903F0B5EAD
2012-06-30 18:00 - 2012-06-30 18:00 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-30 18:00 - 2012-06-30 18:00 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-30 17:57 - 2012-06-30 17:57 - 13123288 ____A (Microsoft Corporation) C:\Users\Terry\Downloads\mse_x64_prerelease_install.exe
2012-06-30 17:47 - 2012-06-30 17:47 - 00000000 ____D C:\Users\Terry\AppData\Local\{B3D7BE25-3E4D-4078-9912-6E3CB803BE84}
2012-06-30 17:47 - 2012-06-30 17:47 - 00000000 ____D C:\Users\Terry\AppData\Local\{774629D3-6A3A-4C4E-8D1B-8B122E2D57CE}
2012-06-29 14:15 - 2012-06-29 14:15 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-29 06:11 - 2012-06-29 06:11 - 00000000 ____D C:\Users\Terry\AppData\Local\{C33E6D85-481A-4F89-A854-C46C94037CF5}
2012-06-29 06:11 - 2012-06-29 06:11 - 00000000 ____D C:\Users\Terry\AppData\Local\{6EFFB769-92C9-4B4E-8DA7-457E2D32EBBA}
2012-06-28 19:30 - 2012-06-28 19:30 - 00000032 ____A C:\Users\Terry\Documents\new music.txt
2012-06-28 17:49 - 2012-06-28 17:49 - 00000000 ____D C:\Users\Terry\AppData\Local\{45122428-7B84-4F2E-89E4-BB30DACD0492}
2012-06-28 17:48 - 2012-06-28 17:49 - 00000000 ____D C:\Users\Terry\AppData\Local\{ED30F8BB-605C-48D2-BF1A-DF27568742EE}
2012-06-27 19:10 - 2012-06-27 19:10 - 00001624 ____A C:\Users\Terry\Desktop\Widescreen Desktops - Shortcut.lnk
2012-06-26 11:43 - 2012-06-26 11:43 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-06-26 11:38 - 2012-06-26 11:39 - 39483256 ____A (Apple Inc.) C:\Users\Terry\Downloads\QuickTimeInstaller.exe
2012-06-25 14:08 - 2012-06-25 14:08 - 00000000 ____D C:\Users\Terry\AppData\Local\{B0AAA51F-BD9D-46E5-890F-78173ADF8145}
2012-06-25 14:07 - 2012-06-25 14:07 - 00000000 ____D C:\Users\Terry\AppData\Local\{45F795ED-DA92-4B9A-AFD7-B0C179D80C5E}
2012-06-24 11:13 - 2012-06-24 11:13 - 01578684 ____A C:\Users\Terry\Downloads\race inc.rpy
2012-06-23 07:23 - 2012-06-23 07:24 - 00000000 ____D C:\Users\Terry\AppData\Local\{1E2E311D-F0AB-45F6-8E68-8E7801C67BD5}
2012-06-23 07:23 - 2012-06-23 07:23 - 00000000 ____D C:\Users\Terry\AppData\Local\{BF3BE502-F00A-4BAF-965C-12C6AEA4DC8F}
2012-06-22 02:25 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-22 02:25 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-22 02:25 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-22 02:25 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-22 02:25 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-22 02:25 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-22 02:25 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-22 02:25 - 2012-06-02 10:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-22 02:25 - 2012-06-02 10:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-21 19:06 - 2012-06-21 19:06 - 130832904 ____A (Lightworks) C:\Users\Terry\Downloads\setup_v11_full.exe
2012-06-21 18:12 - 2012-06-21 18:12 - 00000000 ____D C:\Users\Terry\AppData\Local\{D04FC8E9-D119-4785-9D43-6FF48014BABF}
2012-06-21 06:12 - 2012-06-21 06:12 - 00000000 ____D C:\Users\Terry\AppData\Local\{942D43A2-07A5-45B7-B363-286B4D3A4663}
2012-06-21 06:11 - 2012-06-21 06:12 - 00000000 ____D C:\Users\Terry\AppData\Local\{7D799D8F-B88E-44DF-9954-E7DD9DF02BFC}
2012-06-20 19:02 - 2012-06-20 19:02 - 02688920 ____A C:\Users\Terry\Downloads\GyroscopicTrackIRView.zip
2012-06-20 19:02 - 2012-06-20 19:02 - 00007351 ____A C:\Users\Terry\Downloads\Motion_Cockpit_View.ini
2012-06-20 08:49 - 2012-06-29 05:16 - 00000127 ____A C:\Users\Terry\Documents\default.html
2012-06-20 06:38 - 2012-06-20 06:38 - 00000000 ____D C:\Users\Terry\AppData\Local\{A76E65F2-C3B0-4023-AA5C-DD3606AD526A}
2012-06-20 06:38 - 2012-06-20 06:38 - 00000000 ____D C:\Users\Terry\AppData\Local\{2B771B38-7954-4382-B4E2-4C6500560177}
2012-06-20 05:58 - 2012-06-20 05:58 - 08135064 ____A C:\Users\Terry\Downloads\iSpeed3.3.0.0.exe
2012-06-20 05:55 - 2012-06-20 05:57 - 00001093 ____A C:\Users\Terry\Desktop\GearSound.lnk
2012-06-20 05:52 - 2012-06-20 05:58 - 00000000 ____D C:\Program Files (x86)\GearSound
2012-06-20 05:50 - 2012-06-20 05:49 - 00027324 ____A C:\Users\Terry\Downloads\GearSound.rar
2012-06-18 16:45 - 2012-06-18 16:45 - 00000000 ____D C:\Users\Terry\Documents\Office 2010
2012-06-18 15:46 - 2012-06-18 15:46 - 00000000 ____D C:\Users\Terry\AppData\Local\{E02661B5-53F4-4EF5-B1A1-119F994CD483}
2012-06-14 18:46 - 2012-06-14 18:47 - 00000000 ____D C:\Users\Terry\AppData\Local\{FFAE15D8-B6B3-489F-B06E-BCC12CCFD64E}
2012-06-12 16:19 - 2012-06-12 16:19 - 00000000 ____D C:\Users\Terry\AppData\Local\{5088EB43-F787-4C19-9F7F-A13B76F911BF}
2012-06-12 16:19 - 2012-06-12 16:19 - 00000000 ____D C:\Users\Terry\AppData\Local\{1C00728F-87C0-46E3-9C6F-787F7BD99EA4}
2012-06-12 16:19 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-12 16:19 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-12 16:19 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-12 16:19 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-12 16:19 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-12 16:19 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-12 16:19 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-12 16:19 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-12 16:19 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-12 16:19 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-12 16:19 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-12 16:19 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-12 16:19 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-12 16:19 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-12 16:19 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-12 16:19 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-12 16:19 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-12 16:19 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-12 16:19 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-12 16:19 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-12 16:19 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-12 16:19 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-12 16:19 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-12 16:19 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-12 16:19 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-12 16:19 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-12 16:19 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-12 16:19 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-12 16:19 - 2012-05-04 03:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-06-12 16:19 - 2012-05-04 01:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-06-12 14:57 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 14:57 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-12 14:57 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-12 14:57 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-12 14:57 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-12 14:57 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 14:57 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-12 14:57 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-12 14:57 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-12 14:57 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 14:57 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 14:57 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-12 14:57 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-12 14:57 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-12 14:57 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-12 14:57 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-12 14:57 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-11 12:40 - 2012-06-11 12:40 - 00000000 ____D C:\Users\Terry\AppData\Local\{E8861517-5030-43B5-91E4-0693645BD47F}
2012-06-11 12:40 - 2012-06-11 12:40 - 00000000 ____D C:\Users\Terry\AppData\Local\{47708FEC-68D2-4BCA-ABC7-18D88FF24FF7}
2012-06-10 18:03 - 2012-06-10 18:03 - 00000000 ____D C:\Users\Terry\AppData\Local\{3E55C930-6F44-4067-AAB1-8A32017AEAD8}
2012-06-10 18:03 - 2012-06-10 18:03 - 00000000 ____D C:\Users\Terry\AppData\Local\{3DDF850F-DF5A-48D4-B08C-F3A9F0833CE5}
2012-06-07 17:38 - 2012-06-07 17:38 - 00000000 ____D C:\Users\Terry\AppData\Local\{A5E96585-3C46-4124-996F-982FC396E50E}
2012-06-07 17:38 - 2012-06-07 17:38 - 00000000 ____D C:\Users\Terry\AppData\Local\{805BE2A2-3323-4ABC-B719-23A5D55523FB}
2012-06-06 16:53 - 2012-06-06 16:54 - 00000000 ____D C:\Users\Terry\AppData\Local\{E7CE6FE7-DBD2-4D9B-9EB0-EB1B1BB41165}
2012-06-06 16:53 - 2012-06-06 16:53 - 00000000 ____D C:\Users\Terry\AppData\Local\{399445E1-7756-42F1-94EE-C21E1A0F1E62}
2012-06-05 02:29 - 2012-06-05 02:29 - 00227688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-06-05 02:29 - 2012-06-05 02:29 - 00117464 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-06-04 19:13 - 2012-06-04 19:13 - 00000000 ____D C:\Users\Terry\AppData\Local\{302CB654-AE4F-43E0-B161-40F15DF42026}
2012-06-04 19:12 - 2012-06-04 19:12 - 00000000 ____D C:\Users\Terry\AppData\Local\{D1266BCD-CA2A-43E0-BA4E-492FF43233D3}
============ 3 Months Modified Files ========================
2012-07-03 18:46 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-03 18:46 - 2009-07-13 20:51 - 00013614 ____A C:\Windows\setupact.log
2012-07-03 18:45 - 2012-04-22 05:36 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-01 22:12 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-01 03:24 - 2012-07-01 03:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3B92342094B39691
2012-07-01 03:21 - 2012-07-01 03:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F71791E6ADEA137E
2012-07-01 03:18 - 2012-07-01 03:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B08B0339D2F11D5D
2012-07-01 03:16 - 2011-09-27 17:54 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2069959320-3649819413-638127054-1001UA.job
2012-07-01 03:15 - 2012-07-01 03:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.041812FB36CB7781
2012-07-01 03:12 - 2012-07-01 03:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1F18242F2631952A
2012-07-01 03:09 - 2012-07-01 03:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D670B6C8846630E
2012-07-01 03:06 - 2012-07-01 03:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DAFD3F03A41E7183
2012-07-01 03:06 - 2012-07-01 03:06 - 00001272 ____A C:\Users\Terry\Desktop\shutdown.lnk
2012-07-01 02:58 - 2012-07-01 02:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AC62FC97DFA59B3F
2012-06-30 19:32 - 2012-06-30 19:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8BA2AF81B98BC5B0
2012-06-30 19:29 - 2012-06-30 19:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB37322D34C32672
2012-06-30 19:22 - 2012-06-30 19:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECF47747A84213B6
2012-06-30 19:21 - 2011-09-27 17:41 - 00046140 ____A C:\Windows\PFRO.log
2012-06-30 18:22 - 2012-06-30 18:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B3B255BEFD6BEBE0
2012-06-30 18:16 - 2012-06-30 18:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4C5332E139D0F0A3
2012-06-30 18:11 - 2012-06-30 18:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D67820F321D98719
2012-06-30 18:05 - 2012-06-30 18:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C56C36903F0B5EAD
2012-06-30 18:01 - 2011-09-27 17:39 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-30 18:01 - 2011-09-27 17:05 - 01208275 ____A C:\Windows\WindowsUpdate.log
2012-06-30 18:01 - 2009-07-13 20:45 - 00014976 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-30 18:01 - 2009-07-13 20:45 - 00014976 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-30 17:57 - 2012-06-30 17:57 - 13123288 ____A (Microsoft Corporation) C:\Users\Terry\Downloads\mse_x64_prerelease_install.exe
2012-06-30 17:54 - 2011-10-15 14:16 - 00000362 _RASH C:\Users\All Users\ntuser.pol
2012-06-29 14:12 - 2012-04-22 05:36 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-29 14:12 - 2011-10-06 15:04 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-29 12:16 - 2011-09-27 17:54 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2069959320-3649819413-638127054-1001Core.job
2012-06-29 06:09 - 2009-07-13 21:13 - 00872406 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-29 05:16 - 2012-06-20 08:49 - 00000127 ____A C:\Users\Terry\Documents\default.html
2012-06-28 19:30 - 2012-06-28 19:30 - 00000032 ____A C:\Users\Terry\Documents\new music.txt
2012-06-27 19:10 - 2012-06-27 19:10 - 00001624 ____A C:\Users\Terry\Desktop\Widescreen Desktops - Shortcut.lnk
2012-06-26 11:39 - 2012-06-26 11:38 - 39483256 ____A (Apple Inc.) C:\Users\Terry\Downloads\QuickTimeInstaller.exe
2012-06-25 09:57 - 2009-07-13 20:45 - 04968720 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-24 11:13 - 2012-06-24 11:13 - 01578684 ____A C:\Users\Terry\Downloads\race inc.rpy
2012-06-21 19:06 - 2012-06-21 19:06 - 130832904 ____A (Lightworks) C:\Users\Terry\Downloads\setup_v11_full.exe
2012-06-20 19:02 - 2012-06-20 19:02 - 02688920 ____A C:\Users\Terry\Downloads\GyroscopicTrackIRView.zip
2012-06-20 19:02 - 2012-06-20 19:02 - 00007351 ____A C:\Users\Terry\Downloads\Motion_Cockpit_View.ini
2012-06-20 05:58 - 2012-06-20 05:58 - 08135064 ____A C:\Users\Terry\Downloads\iSpeed3.3.0.0.exe
2012-06-20 05:57 - 2012-06-20 05:55 - 00001093 ____A C:\Users\Terry\Desktop\GearSound.lnk
2012-06-20 05:49 - 2012-06-20 05:50 - 00027324 ____A C:\Users\Terry\Downloads\GearSound.rar
2012-06-12 16:23 - 2011-09-27 18:14 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-05 02:29 - 2012-06-05 02:29 - 00227688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-06-05 02:29 - 2012-06-05 02:29 - 00117464 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-06-02 14:19 - 2012-06-22 02:25 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-22 02:25 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-22 02:25 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-22 02:25 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-22 02:25 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-22 02:25 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-22 02:25 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 10:19 - 2012-06-22 02:25 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 10:15 - 2012-06-22 02:25 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 10:44 - 2012-06-01 10:14 - 3515703296 ____A C:\Users\Terry\Downloads\Windows8-ReleasePreview-64bit-English.iso
2012-06-01 10:14 - 2012-06-01 10:13 - 05350616 ____A (Microsoft Corporation) C:\Users\Terry\Downloads\Windows8-ReleasePreview-UpgradeAssistant.exe
2012-05-30 06:23 - 2012-05-30 06:23 - 38561640 ____A (Google Inc.) C:\Users\Terry\Downloads\GoogleSketchUpWEN.exe
2012-05-24 09:45 - 2012-05-24 09:45 - 109597495 ____A C:\Users\Terry\Downloads\23 and 12 hours What is the single best thing we can do for our health.mp4
2012-05-24 03:11 - 2012-05-24 03:11 - 00001597 ____A C:\Users\Terry\Desktop\BingDesktop - Shortcut.lnk
2012-05-23 14:32 - 2012-05-23 14:33 - 00309068 ____A C:\Users\Terry\Downloads\leafygreen.potx
2012-05-22 18:41 - 2012-05-22 18:41 - 01004561 ____A C:\Users\Terry\Downloads\puzzle-swatch.ai.zip
2012-05-22 13:47 - 2012-05-22 13:39 - 735358976 ____A C:\Users\Terry\Downloads\ubuntu-12.04-desktop-i386.iso
2012-05-22 12:35 - 2012-05-22 12:32 - 168454136 ____A (NVIDIA Corporation) C:\Users\Terry\Downloads\301.42-desktop-win7-winvista-64bit-english-whql.exe
2012-05-17 19:24 - 2012-05-17 19:24 - 04932517 ____A C:\Users\Terry\Downloads\dir645_manual_100.zip
2012-05-17 18:47 - 2012-06-12 16:19 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-12 16:19 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-12 16:19 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-12 16:19 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-12 16:19 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-12 16:19 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-12 16:19 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-12 16:19 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-12 16:19 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-12 16:19 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-12 16:19 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-12 16:19 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-12 16:19 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-12 16:19 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-12 16:19 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-12 16:19 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-12 16:19 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-12 16:19 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-12 16:19 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-12 16:19 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-12 16:19 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-12 16:19 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-12 16:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-12 16:19 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-12 16:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-12 16:19 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-12 16:19 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-12 16:19 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-17 03:40 - 2011-09-27 17:39 - 00889500 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-05-16 18:42 - 2012-05-16 17:38 - 2048196608 ____A C:\Users\Terry\Downloads\7601.17514.101119-1850_Update_Sp_Wave1-GRMSP1.1_DVD.iso
2012-05-15 02:48 - 2012-05-22 12:44 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 15322432 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-05-15 02:48 - 2012-05-22 12:44 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2012-05-15 02:48 - 2012-03-13 19:02 - 00068928 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-05-15 02:48 - 2012-03-13 19:02 - 00061248 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2012-05-15 02:48 - 2011-10-30 06:26 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2012-05-15 02:48 - 2011-10-30 06:26 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2012-05-15 02:48 - 2011-10-30 06:26 - 01738048 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco64.dll
2012-05-15 02:48 - 2011-10-30 06:26 - 01468224 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco64.dll
2012-05-15 02:48 - 2011-05-21 01:01 - 02741568 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll
2012-05-15 02:48 - 2011-05-21 01:01 - 00014324 ____A C:\Windows\System32\nvinfo.pb
2012-05-15 02:48 - 2009-07-13 13:59 - 10194752 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
2012-05-15 01:29 - 2011-09-27 18:09 - 03149632 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll
2012-05-15 01:29 - 2011-09-27 18:09 - 00889664 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
2012-05-15 01:29 - 2011-09-27 18:09 - 00118080 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
2012-05-15 01:29 - 2011-09-27 18:09 - 00063296 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
2012-05-15 01:28 - 2011-09-27 18:09 - 06151488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
2012-05-14 21:21 - 2012-05-14 21:21 - 00423744 ____A C:\Windows\SysWOW64\nvStreaming.exe
2012-05-14 19:34 - 2012-05-14 19:34 - 00654920 ____A C:\Users\Terry\Downloads\mtinst.exe
2012-05-14 19:09 - 2012-05-14 19:09 - 07331459 ____A (Blizzard Entertainment) C:\Users\Terry\Downloads\Diablo-III-Setup-enGB.exe
2012-05-14 18:46 - 2012-05-14 18:43 - 12621696 ____A (Microsoft Corporation) C:\Users\Terry\Downloads\mseinstall.exe
2012-05-14 18:29 - 2012-05-14 18:29 - 00029808 ____A C:\Windows\System32\Drivers\mbamchameleon.sys
2012-05-14 18:15 - 2012-05-14 18:15 - 00002560 ____A C:\Windows\_MSRSTRT.EXE
2012-05-14 17:32 - 2012-06-12 14:57 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-12 13:23 - 2012-05-12 13:23 - 00074703 ____A C:\Windows\SysWOW64\mfc45.dll
2012-05-12 07:53 - 2012-05-12 07:53 - 03877872 ____A (AVG Technologies) C:\Users\Terry\Downloads\avg_free_stb_all_2012_2171_cnet.exe
2012-05-06 11:45 - 2012-05-06 11:45 - 08769696 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-04 03:14 - 2012-05-04 03:14 - 05134840 ____A (Binary Fortress Software ) C:\Users\Terry\Downloads\DisplayFusionSetup-4.0.exe
2012-05-04 03:06 - 2012-06-12 14:57 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 03:00 - 2012-06-12 16:19 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-05-04 02:03 - 2012-06-12 14:57 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 14:57 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-04 01:59 - 2012-06-12 16:19 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-05-03 05:42 - 2012-05-03 05:42 - 00396288 ____A () C:\Users\Terry\Downloads\Setup.exe
2012-04-30 21:40 - 2012-06-12 14:57 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-30 18:05 - 2012-04-30 18:05 - 07336664 ____A (Blizzard Entertainment) C:\Users\Terry\Downloads\Diablo-III-8370-enGB-Installer-downloader.exe
2012-04-27 19:55 - 2012-06-12 14:57 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-12 14:57 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 14:57 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 14:57 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-25 15:31 - 2012-04-25 15:31 - 02698752 ____A C:\Users\Terry\Downloads\Chronic_Neuropathic_Pain-Slides_Pierce-Smith.ppt
2012-04-25 15:25 - 2012-04-25 15:25 - 01513472 ____A C:\Users\Terry\Downloads\AgrAbilityLivingwithChronicPain.ppt
2012-04-23 21:37 - 2012-06-12 14:57 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 14:57 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 14:57 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 14:57 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 14:57 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 14:57 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-22 05:36 - 2012-04-22 05:36 - 00000406 ____A C:\Windows\System32\ioloBootDefrag.cfg
2012-04-18 19:22 - 2012-04-18 19:22 - 00286720 ____N (Microsoft Corporation) C:\Windows\Setup1.exe
2012-04-18 19:22 - 2012-04-18 19:22 - 00073216 ____A (Microsoft Corporation) C:\Windows\ST6UNST.EXE
2012-04-18 15:56 - 2012-04-18 15:56 - 00094208 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTimeVR.qtx
2012-04-18 15:56 - 2012-04-18 15:56 - 00069632 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTime.qts
2012-04-18 03:34 - 2011-11-22 07:21 - 00001072 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-04-18 03:32 - 2012-04-08 16:26 - 22259528 ____A C:\Users\Terry\Downloads\vlc-2.0.1-win32.exe
2012-04-17 05:11 - 2012-03-15 12:29 - 00049152 ____A (iolo technologies, LLC) C:\Windows\System32\iolobtdfg.exe
2012-04-17 05:11 - 2012-03-15 12:29 - 00017920 ____A (iolo technologies, LLC) C:\Windows\System32\smrgdf.exe
2012-04-17 04:37 - 2012-04-21 02:18 - 02154032 ____A (iolo technologies, LLC) C:\Windows\System32\Incinerator64.dll
2012-04-17 04:37 - 2012-03-15 12:29 - 02095816 ____A (iolo technologies, LLC) C:\Windows\SysWOW64\Incinerator32.dll
2012-04-17 03:25 - 2012-03-15 12:30 - 00031432 ____A (EldoS Corporation) C:\Windows\System32\Drivers\ElRawDsk.sys
2012-04-16 16:36 - 2011-09-27 17:21 - 00110728 ____A C:\Users\Terry\AppData\Local\GDIPFONTCACHEV1.DAT
2012-04-10 13:44 - 2009-07-13 18:34 - 00000531 ____A C:\Windows\win.ini
2012-04-10 11:42 - 2012-04-10 11:42 - 01639789 ____A C:\Users\Terry\Downloads\winrar-x64-411.exe
2012-04-10 11:41 - 2012-04-10 11:41 - 01669854 ____A C:\Users\Terry\Downloads\winrar-x64-411a.exe
2012-04-07 11:34 - 2012-04-07 11:34 - 02031465 ____A C:\Users\Terry\Downloads\Mac OS X Tiger.wba
2012-04-07 04:31 - 2012-06-12 14:57 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-12 14:57 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-05 06:53 - 2012-04-05 06:53 - 68404936 ____A C:\Users\Terry\Downloads\WindowBlinds7_public.exe
ZeroAccess:
C:\Windows\Installer\{4a0ce653-f62d-1574-556d-c223afaf8a7a}
C:\Windows\Installer\{4a0ce653-f62d-1574-556d-c223afaf8a7a}\@
C:\Windows\Installer\{4a0ce653-f62d-1574-556d-c223afaf8a7a}\L
C:\Windows\Installer\{4a0ce653-f62d-1574-556d-c223afaf8a7a}\U
C:\Windows\Installer\{4a0ce653-f62d-1574-556d-c223afaf8a7a}\U\00000001.@
ZeroAccess:
C:\Users\Terry\AppData\Local\{4a0ce653-f62d-1574-556d-c223afaf8a7a}
C:\Users\Terry\AppData\Local\{4a0ce653-f62d-1574-556d-c223afaf8a7a}\@
C:\Users\Terry\AppData\Local\{4a0ce653-f62d-1574-556d-c223afaf8a7a}\L
C:\Users\Terry\AppData\Local\{4a0ce653-f62d-1574-556d-c223afaf8a7a}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe FCB084FA3DCB7449F3BAA13312A215B4 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 12%
Total physical RAM: 6135.14 MB
Available physical RAM: 5338.25 MB
Total Pagefile: 6133.34 MB
Available Pagefile: 5345.95 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (System) (Fixed) (Total:750 GB) (Free:312.57 GB) NTFS
2 Drive d: (Stuff) (Fixed) (Total:596.17 GB) (Free:424.41 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive e: () (Fixed) (Total:596.17 GB) (Free:577.26 GB) NTFS
4 Drive f: (Media Backup) (Fixed) (Total:931.51 GB) (Free:320.5 GB) NTFS
5 Drive g: (System Backup) (Fixed) (Total:1397.26 GB) (Free:69.62 GB) NTFS
6 Drive I: (Media) (Fixed) (Total:1112.92 GB) (Free:514.42 GB) NTFS
7 Drive j: (GRMCHPXFRER_EN_DVD) (CDROM) (Total:3.09 GB) (Free:0 GB) UDF
8 Drive k: () (Removable) (Total:0.49 GB) (Free:0.49 GB) FAT
9 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
10 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 1863 GB 1024 KB
Disk 1 Online 596 GB 3072 KB
Disk 2 Online 596 GB 3072 KB
Disk 3 Online 931 GB 0 B
Disk 4 Online 1397 GB 0 B
Disk 5 Online 499 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 750 GB 101 MB
Partition 3 Primary 1112 GB 750 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C System NTFS Partition 750 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 I Media NTFS Partition 1112 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 596 GB 1024 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 D Stuff NTFS Partition 596 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 596 GB 1024 KB
==================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 E NTFS Partition 596 GB Healthy
==================================================================================
Partitions of Disk 3:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 931 GB 1024 KB
==================================================================================
Disk: 3
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 F Media Backu NTFS Partition 931 GB Healthy
==================================================================================
Partitions of Disk 4:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1397 GB 1024 KB
==================================================================================
Disk: 4
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 G System Back NTFS Partition 1397 GB Healthy
==================================================================================
Partitions of Disk 5:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 499 MB 16 KB
==================================================================================
Disk: 5
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 K FAT Removable 499 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-28 09:55
======================= End Of Log ==========================
I used Farbar Recovery Scan Tool 64-bit to scan my Windows 7 Pro install. Here is the result of that scan. Thanks in advance for any assitance you can provide.
Scan result of Farbar Recovery Scan Tool Version: 03-07-2012 01
Ran by SYSTEM at 03-07-2012 23:52:38
Running from K:\
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe" [163552 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [12681320 2011-08-26] (Realtek Semiconductor)
HKLM\...\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe /minimized [6868280 2012-05-21] (Logitech Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [499608 2011-03-30] (Adobe Systems Incorporated)
HKLM\...\Run: [Acronis Scheduler2 Service] "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [390720 2011-02-01] (Acronis)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281240 2012-06-12] (Microsoft Corporation)
HKLM-x32\...\Run: [TrueImageMonitor.exe] "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" [5550984 2011-09-22] (Acronis)
HKLM-x32\...\Run: [SteelSeries World of Warcraft Cataclysm MMO Gaming Mouse] "C:\Program Files (x86)\SteelSeries\World of Warcraft Cataclysm MMO Gaming Mouse\WoWMHID2.exe" [1993216 2011-08-18] (SteelSeries)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-01-16] (Apple Inc.)
HKLM-x32\...\Run: [iolo Startup] "C:\Program Files (x86)\iolo\Common\Lib\ioloLManager.exe" [938680 2012-04-17] (iolo technologies, LLC)
HKLM-x32\...\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey [1858152 2012-03-30] (Microsoft Corp.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKU\Mcx1-ZOMBIE\...\Winlogon: [Shell] C:\Windows\eHome\McrMgr.exe [343552 2009-07-13] (Microsoft Corporation)
HKU\Terry\...\Run: [DCD5A9DEF340132AE028E0C7EC112B0A9A533117._service_run] "C:\Users\Terry\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service [1239576 2012-06-07] (Google Inc.)
HKU\Terry\...\Run: [Google Update] "C:\Users\Terry\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-09-27] (Google Inc.)
HKU\Terry\...\Run: [DisplayFusion] "C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe" [4480456 2012-05-31] (Binary Fortress Software)
Winlogon\Notify\WB:
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\Terry\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 AcrSch2Svc; "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe" [1112240 2011-02-01] (Acronis)
2 afcdpsrv; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [3246040 2011-11-01] (Acronis)
2 BingDesktopUpdate; "C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe" [151656 2012-03-30] (Microsoft Corp.)
2 ioloSystemService; "C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe" [1047336 2012-04-17] (iolo technologies, LLC)
2 iRacingService; C:\Program Files (x86)\iRacing\iRacingService.exe [519848 2012-06-20] (iRacing.com Motorsport Simulations, LLC
Bedford, MA 01730)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22024 2012-06-12] (Microsoft Corporation)
2 MSSQL$SQLEXPRESS; "C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS [58345832 2011-09-22] (Microsoft Corporation)
4 NetTcpPortSharing; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [124240 2010-03-18] (Microsoft Corporation)
2 PDAgent; "C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe" [2610952 2011-03-15] (Raxco Software, Inc.)
3 PDEngine; "C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe" [2266376 2011-03-15] (Raxco Software, Inc.)
4 SQLAgent$SQLEXPRESS; "C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE" -I SQLEXPRESS [431464 2011-09-22] (Microsoft Corporation)
3 WMZuneComm; "C:\Program Files\Zune\WMZuneComm.exe" [306400 2011-08-05] (Microsoft Corporation)
2 ZuneNetworkSvc; "C:\Program Files\Zune\ZuneNss.exe" [8277728 2011-08-05] (Microsoft Corporation)
3 ZuneWlanCfgSvc; "C:\Program Files\Zune\ZuneWlanCfgSvc.exe" [467680 2011-08-05] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 afcdp; C:\Windows\System32\Drivers\afcdp.sys [285280 2011-11-01] (Acronis)
1 ElRawDisk; \??\C:\Windows\system32\drivers\ElRawDsk.sys [31432 2012-04-17] (EldoS Corporation)
3 mbamchameleon; C:\Windows\System32\Drivers\mbamchameleon.sys [29808 2012-05-14] ()
0 snapman; C:\Windows\System32\Drivers\snapman.sys [277088 2011-11-01] (Acronis)
3 SSMO3v2Filter; C:\Windows\System32\drivers\MO3v2Driver.sys [23040 2010-11-22] (Sagatek Co. Ltd.)
0 tdrpman273; C:\Windows\System32\DRIVERS\tdrpm273.sys [1263200 2011-11-01] (Acronis)
0 timounter; C:\Windows\System32\DRIVERS\timntr.sys [970336 2011-11-01] (Acronis)
3 ALSysIO; \??\C:\Users\Terry\AppData\Local\Temp\ALSysIO64.sys [x]
3 cpuz130; \??\C:\Users\Terry\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-01 03:24 - 2012-07-01 03:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3B92342094B39691
2012-07-01 03:21 - 2012-07-01 03:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F71791E6ADEA137E
2012-07-01 03:18 - 2012-07-01 03:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B08B0339D2F11D5D
2012-07-01 03:15 - 2012-07-01 03:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.041812FB36CB7781
2012-07-01 03:12 - 2012-07-01 03:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1F18242F2631952A
2012-07-01 03:09 - 2012-07-01 03:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D670B6C8846630E
2012-07-01 03:06 - 2012-07-01 03:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DAFD3F03A41E7183
2012-07-01 03:06 - 2012-07-01 03:06 - 00001272 ____A C:\Users\Terry\Desktop\shutdown.lnk
2012-07-01 02:58 - 2012-07-01 02:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AC62FC97DFA59B3F
2012-06-30 19:32 - 2012-06-30 19:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8BA2AF81B98BC5B0
2012-06-30 19:29 - 2012-06-30 19:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB37322D34C32672
2012-06-30 19:22 - 2012-06-30 19:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECF47747A84213B6
2012-06-30 18:22 - 2012-06-30 18:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B3B255BEFD6BEBE0
2012-06-30 18:16 - 2012-06-30 18:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4C5332E139D0F0A3
2012-06-30 18:11 - 2012-06-30 18:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D67820F321D98719
2012-06-30 18:05 - 2012-06-30 18:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C56C36903F0B5EAD
2012-06-30 18:00 - 2012-06-30 18:00 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-30 18:00 - 2012-06-30 18:00 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-30 17:57 - 2012-06-30 17:57 - 13123288 ____A (Microsoft Corporation) C:\Users\Terry\Downloads\mse_x64_prerelease_install.exe
2012-06-30 17:47 - 2012-06-30 17:47 - 00000000 ____D C:\Users\Terry\AppData\Local\{B3D7BE25-3E4D-4078-9912-6E3CB803BE84}
2012-06-30 17:47 - 2012-06-30 17:47 - 00000000 ____D C:\Users\Terry\AppData\Local\{774629D3-6A3A-4C4E-8D1B-8B122E2D57CE}
2012-06-29 14:15 - 2012-06-29 14:15 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-29 06:11 - 2012-06-29 06:11 - 00000000 ____D C:\Users\Terry\AppData\Local\{C33E6D85-481A-4F89-A854-C46C94037CF5}
2012-06-29 06:11 - 2012-06-29 06:11 - 00000000 ____D C:\Users\Terry\AppData\Local\{6EFFB769-92C9-4B4E-8DA7-457E2D32EBBA}
2012-06-28 19:30 - 2012-06-28 19:30 - 00000032 ____A C:\Users\Terry\Documents\new music.txt
2012-06-28 17:49 - 2012-06-28 17:49 - 00000000 ____D C:\Users\Terry\AppData\Local\{45122428-7B84-4F2E-89E4-BB30DACD0492}
2012-06-28 17:48 - 2012-06-28 17:49 - 00000000 ____D C:\Users\Terry\AppData\Local\{ED30F8BB-605C-48D2-BF1A-DF27568742EE}
2012-06-27 19:10 - 2012-06-27 19:10 - 00001624 ____A C:\Users\Terry\Desktop\Widescreen Desktops - Shortcut.lnk
2012-06-26 11:43 - 2012-06-26 11:43 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-06-26 11:38 - 2012-06-26 11:39 - 39483256 ____A (Apple Inc.) C:\Users\Terry\Downloads\QuickTimeInstaller.exe
2012-06-25 14:08 - 2012-06-25 14:08 - 00000000 ____D C:\Users\Terry\AppData\Local\{B0AAA51F-BD9D-46E5-890F-78173ADF8145}
2012-06-25 14:07 - 2012-06-25 14:07 - 00000000 ____D C:\Users\Terry\AppData\Local\{45F795ED-DA92-4B9A-AFD7-B0C179D80C5E}
2012-06-24 11:13 - 2012-06-24 11:13 - 01578684 ____A C:\Users\Terry\Downloads\race inc.rpy
2012-06-23 07:23 - 2012-06-23 07:24 - 00000000 ____D C:\Users\Terry\AppData\Local\{1E2E311D-F0AB-45F6-8E68-8E7801C67BD5}
2012-06-23 07:23 - 2012-06-23 07:23 - 00000000 ____D C:\Users\Terry\AppData\Local\{BF3BE502-F00A-4BAF-965C-12C6AEA4DC8F}
2012-06-22 02:25 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-22 02:25 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-22 02:25 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-22 02:25 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-22 02:25 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-22 02:25 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-22 02:25 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-22 02:25 - 2012-06-02 10:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-22 02:25 - 2012-06-02 10:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-21 19:06 - 2012-06-21 19:06 - 130832904 ____A (Lightworks) C:\Users\Terry\Downloads\setup_v11_full.exe
2012-06-21 18:12 - 2012-06-21 18:12 - 00000000 ____D C:\Users\Terry\AppData\Local\{D04FC8E9-D119-4785-9D43-6FF48014BABF}
2012-06-21 06:12 - 2012-06-21 06:12 - 00000000 ____D C:\Users\Terry\AppData\Local\{942D43A2-07A5-45B7-B363-286B4D3A4663}
2012-06-21 06:11 - 2012-06-21 06:12 - 00000000 ____D C:\Users\Terry\AppData\Local\{7D799D8F-B88E-44DF-9954-E7DD9DF02BFC}
2012-06-20 19:02 - 2012-06-20 19:02 - 02688920 ____A C:\Users\Terry\Downloads\GyroscopicTrackIRView.zip
2012-06-20 19:02 - 2012-06-20 19:02 - 00007351 ____A C:\Users\Terry\Downloads\Motion_Cockpit_View.ini
2012-06-20 08:49 - 2012-06-29 05:16 - 00000127 ____A C:\Users\Terry\Documents\default.html
2012-06-20 06:38 - 2012-06-20 06:38 - 00000000 ____D C:\Users\Terry\AppData\Local\{A76E65F2-C3B0-4023-AA5C-DD3606AD526A}
2012-06-20 06:38 - 2012-06-20 06:38 - 00000000 ____D C:\Users\Terry\AppData\Local\{2B771B38-7954-4382-B4E2-4C6500560177}
2012-06-20 05:58 - 2012-06-20 05:58 - 08135064 ____A C:\Users\Terry\Downloads\iSpeed3.3.0.0.exe
2012-06-20 05:55 - 2012-06-20 05:57 - 00001093 ____A C:\Users\Terry\Desktop\GearSound.lnk
2012-06-20 05:52 - 2012-06-20 05:58 - 00000000 ____D C:\Program Files (x86)\GearSound
2012-06-20 05:50 - 2012-06-20 05:49 - 00027324 ____A C:\Users\Terry\Downloads\GearSound.rar
2012-06-18 16:45 - 2012-06-18 16:45 - 00000000 ____D C:\Users\Terry\Documents\Office 2010
2012-06-18 15:46 - 2012-06-18 15:46 - 00000000 ____D C:\Users\Terry\AppData\Local\{E02661B5-53F4-4EF5-B1A1-119F994CD483}
2012-06-14 18:46 - 2012-06-14 18:47 - 00000000 ____D C:\Users\Terry\AppData\Local\{FFAE15D8-B6B3-489F-B06E-BCC12CCFD64E}
2012-06-12 16:19 - 2012-06-12 16:19 - 00000000 ____D C:\Users\Terry\AppData\Local\{5088EB43-F787-4C19-9F7F-A13B76F911BF}
2012-06-12 16:19 - 2012-06-12 16:19 - 00000000 ____D C:\Users\Terry\AppData\Local\{1C00728F-87C0-46E3-9C6F-787F7BD99EA4}
2012-06-12 16:19 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-12 16:19 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-12 16:19 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-12 16:19 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-12 16:19 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-12 16:19 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-12 16:19 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-12 16:19 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-12 16:19 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-12 16:19 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-12 16:19 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-12 16:19 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-12 16:19 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-12 16:19 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-12 16:19 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-12 16:19 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-12 16:19 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-12 16:19 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-12 16:19 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-12 16:19 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-12 16:19 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-12 16:19 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-12 16:19 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-12 16:19 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-12 16:19 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-12 16:19 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-12 16:19 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-12 16:19 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-12 16:19 - 2012-05-04 03:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-06-12 16:19 - 2012-05-04 01:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-06-12 14:57 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 14:57 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-12 14:57 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-12 14:57 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-12 14:57 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-12 14:57 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 14:57 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-12 14:57 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-12 14:57 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-12 14:57 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 14:57 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 14:57 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-12 14:57 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-12 14:57 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-12 14:57 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-12 14:57 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-12 14:57 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-11 12:40 - 2012-06-11 12:40 - 00000000 ____D C:\Users\Terry\AppData\Local\{E8861517-5030-43B5-91E4-0693645BD47F}
2012-06-11 12:40 - 2012-06-11 12:40 - 00000000 ____D C:\Users\Terry\AppData\Local\{47708FEC-68D2-4BCA-ABC7-18D88FF24FF7}
2012-06-10 18:03 - 2012-06-10 18:03 - 00000000 ____D C:\Users\Terry\AppData\Local\{3E55C930-6F44-4067-AAB1-8A32017AEAD8}
2012-06-10 18:03 - 2012-06-10 18:03 - 00000000 ____D C:\Users\Terry\AppData\Local\{3DDF850F-DF5A-48D4-B08C-F3A9F0833CE5}
2012-06-07 17:38 - 2012-06-07 17:38 - 00000000 ____D C:\Users\Terry\AppData\Local\{A5E96585-3C46-4124-996F-982FC396E50E}
2012-06-07 17:38 - 2012-06-07 17:38 - 00000000 ____D C:\Users\Terry\AppData\Local\{805BE2A2-3323-4ABC-B719-23A5D55523FB}
2012-06-06 16:53 - 2012-06-06 16:54 - 00000000 ____D C:\Users\Terry\AppData\Local\{E7CE6FE7-DBD2-4D9B-9EB0-EB1B1BB41165}
2012-06-06 16:53 - 2012-06-06 16:53 - 00000000 ____D C:\Users\Terry\AppData\Local\{399445E1-7756-42F1-94EE-C21E1A0F1E62}
2012-06-05 02:29 - 2012-06-05 02:29 - 00227688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-06-05 02:29 - 2012-06-05 02:29 - 00117464 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-06-04 19:13 - 2012-06-04 19:13 - 00000000 ____D C:\Users\Terry\AppData\Local\{302CB654-AE4F-43E0-B161-40F15DF42026}
2012-06-04 19:12 - 2012-06-04 19:12 - 00000000 ____D C:\Users\Terry\AppData\Local\{D1266BCD-CA2A-43E0-BA4E-492FF43233D3}
============ 3 Months Modified Files ========================
2012-07-03 18:46 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-03 18:46 - 2009-07-13 20:51 - 00013614 ____A C:\Windows\setupact.log
2012-07-03 18:45 - 2012-04-22 05:36 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-01 22:12 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-01 03:24 - 2012-07-01 03:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3B92342094B39691
2012-07-01 03:21 - 2012-07-01 03:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F71791E6ADEA137E
2012-07-01 03:18 - 2012-07-01 03:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B08B0339D2F11D5D
2012-07-01 03:16 - 2011-09-27 17:54 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2069959320-3649819413-638127054-1001UA.job
2012-07-01 03:15 - 2012-07-01 03:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.041812FB36CB7781
2012-07-01 03:12 - 2012-07-01 03:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1F18242F2631952A
2012-07-01 03:09 - 2012-07-01 03:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D670B6C8846630E
2012-07-01 03:06 - 2012-07-01 03:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DAFD3F03A41E7183
2012-07-01 03:06 - 2012-07-01 03:06 - 00001272 ____A C:\Users\Terry\Desktop\shutdown.lnk
2012-07-01 02:58 - 2012-07-01 02:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AC62FC97DFA59B3F
2012-06-30 19:32 - 2012-06-30 19:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8BA2AF81B98BC5B0
2012-06-30 19:29 - 2012-06-30 19:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB37322D34C32672
2012-06-30 19:22 - 2012-06-30 19:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECF47747A84213B6
2012-06-30 19:21 - 2011-09-27 17:41 - 00046140 ____A C:\Windows\PFRO.log
2012-06-30 18:22 - 2012-06-30 18:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B3B255BEFD6BEBE0
2012-06-30 18:16 - 2012-06-30 18:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4C5332E139D0F0A3
2012-06-30 18:11 - 2012-06-30 18:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D67820F321D98719
2012-06-30 18:05 - 2012-06-30 18:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C56C36903F0B5EAD
2012-06-30 18:01 - 2011-09-27 17:39 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-30 18:01 - 2011-09-27 17:05 - 01208275 ____A C:\Windows\WindowsUpdate.log
2012-06-30 18:01 - 2009-07-13 20:45 - 00014976 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-30 18:01 - 2009-07-13 20:45 - 00014976 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-30 17:57 - 2012-06-30 17:57 - 13123288 ____A (Microsoft Corporation) C:\Users\Terry\Downloads\mse_x64_prerelease_install.exe
2012-06-30 17:54 - 2011-10-15 14:16 - 00000362 _RASH C:\Users\All Users\ntuser.pol
2012-06-29 14:12 - 2012-04-22 05:36 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-29 14:12 - 2011-10-06 15:04 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-29 12:16 - 2011-09-27 17:54 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2069959320-3649819413-638127054-1001Core.job
2012-06-29 06:09 - 2009-07-13 21:13 - 00872406 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-29 05:16 - 2012-06-20 08:49 - 00000127 ____A C:\Users\Terry\Documents\default.html
2012-06-28 19:30 - 2012-06-28 19:30 - 00000032 ____A C:\Users\Terry\Documents\new music.txt
2012-06-27 19:10 - 2012-06-27 19:10 - 00001624 ____A C:\Users\Terry\Desktop\Widescreen Desktops - Shortcut.lnk
2012-06-26 11:39 - 2012-06-26 11:38 - 39483256 ____A (Apple Inc.) C:\Users\Terry\Downloads\QuickTimeInstaller.exe
2012-06-25 09:57 - 2009-07-13 20:45 - 04968720 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-24 11:13 - 2012-06-24 11:13 - 01578684 ____A C:\Users\Terry\Downloads\race inc.rpy
2012-06-21 19:06 - 2012-06-21 19:06 - 130832904 ____A (Lightworks) C:\Users\Terry\Downloads\setup_v11_full.exe
2012-06-20 19:02 - 2012-06-20 19:02 - 02688920 ____A C:\Users\Terry\Downloads\GyroscopicTrackIRView.zip
2012-06-20 19:02 - 2012-06-20 19:02 - 00007351 ____A C:\Users\Terry\Downloads\Motion_Cockpit_View.ini
2012-06-20 05:58 - 2012-06-20 05:58 - 08135064 ____A C:\Users\Terry\Downloads\iSpeed3.3.0.0.exe
2012-06-20 05:57 - 2012-06-20 05:55 - 00001093 ____A C:\Users\Terry\Desktop\GearSound.lnk
2012-06-20 05:49 - 2012-06-20 05:50 - 00027324 ____A C:\Users\Terry\Downloads\GearSound.rar
2012-06-12 16:23 - 2011-09-27 18:14 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-05 02:29 - 2012-06-05 02:29 - 00227688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-06-05 02:29 - 2012-06-05 02:29 - 00117464 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-06-02 14:19 - 2012-06-22 02:25 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-22 02:25 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-22 02:25 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-22 02:25 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-22 02:25 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-22 02:25 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-22 02:25 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 10:19 - 2012-06-22 02:25 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 10:15 - 2012-06-22 02:25 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 10:44 - 2012-06-01 10:14 - 3515703296 ____A C:\Users\Terry\Downloads\Windows8-ReleasePreview-64bit-English.iso
2012-06-01 10:14 - 2012-06-01 10:13 - 05350616 ____A (Microsoft Corporation) C:\Users\Terry\Downloads\Windows8-ReleasePreview-UpgradeAssistant.exe
2012-05-30 06:23 - 2012-05-30 06:23 - 38561640 ____A (Google Inc.) C:\Users\Terry\Downloads\GoogleSketchUpWEN.exe
2012-05-24 09:45 - 2012-05-24 09:45 - 109597495 ____A C:\Users\Terry\Downloads\23 and 12 hours What is the single best thing we can do for our health.mp4
2012-05-24 03:11 - 2012-05-24 03:11 - 00001597 ____A C:\Users\Terry\Desktop\BingDesktop - Shortcut.lnk
2012-05-23 14:32 - 2012-05-23 14:33 - 00309068 ____A C:\Users\Terry\Downloads\leafygreen.potx
2012-05-22 18:41 - 2012-05-22 18:41 - 01004561 ____A C:\Users\Terry\Downloads\puzzle-swatch.ai.zip
2012-05-22 13:47 - 2012-05-22 13:39 - 735358976 ____A C:\Users\Terry\Downloads\ubuntu-12.04-desktop-i386.iso
2012-05-22 12:35 - 2012-05-22 12:32 - 168454136 ____A (NVIDIA Corporation) C:\Users\Terry\Downloads\301.42-desktop-win7-winvista-64bit-english-whql.exe
2012-05-17 19:24 - 2012-05-17 19:24 - 04932517 ____A C:\Users\Terry\Downloads\dir645_manual_100.zip
2012-05-17 18:47 - 2012-06-12 16:19 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-12 16:19 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-12 16:19 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-12 16:19 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-12 16:19 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-12 16:19 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-12 16:19 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-12 16:19 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-12 16:19 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-12 16:19 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-12 16:19 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-12 16:19 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-12 16:19 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-12 16:19 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-12 16:19 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-12 16:19 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-12 16:19 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-12 16:19 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-12 16:19 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-12 16:19 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-12 16:19 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-12 16:19 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-12 16:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-12 16:19 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-12 16:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-12 16:19 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-12 16:19 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-12 16:19 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-17 03:40 - 2011-09-27 17:39 - 00889500 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-05-16 18:42 - 2012-05-16 17:38 - 2048196608 ____A C:\Users\Terry\Downloads\7601.17514.101119-1850_Update_Sp_Wave1-GRMSP1.1_DVD.iso
2012-05-15 02:48 - 2012-05-22 12:44 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 15322432 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-05-15 02:48 - 2012-05-22 12:44 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2012-05-15 02:48 - 2012-05-22 12:44 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2012-05-15 02:48 - 2012-03-13 19:02 - 00068928 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-05-15 02:48 - 2012-03-13 19:02 - 00061248 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2012-05-15 02:48 - 2011-10-30 06:26 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2012-05-15 02:48 - 2011-10-30 06:26 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2012-05-15 02:48 - 2011-10-30 06:26 - 01738048 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco64.dll
2012-05-15 02:48 - 2011-10-30 06:26 - 01468224 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco64.dll
2012-05-15 02:48 - 2011-05-21 01:01 - 02741568 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll
2012-05-15 02:48 - 2011-05-21 01:01 - 00014324 ____A C:\Windows\System32\nvinfo.pb
2012-05-15 02:48 - 2009-07-13 13:59 - 10194752 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
2012-05-15 01:29 - 2011-09-27 18:09 - 03149632 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll
2012-05-15 01:29 - 2011-09-27 18:09 - 00889664 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
2012-05-15 01:29 - 2011-09-27 18:09 - 00118080 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
2012-05-15 01:29 - 2011-09-27 18:09 - 00063296 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
2012-05-15 01:28 - 2011-09-27 18:09 - 06151488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
2012-05-14 21:21 - 2012-05-14 21:21 - 00423744 ____A C:\Windows\SysWOW64\nvStreaming.exe
2012-05-14 19:34 - 2012-05-14 19:34 - 00654920 ____A C:\Users\Terry\Downloads\mtinst.exe
2012-05-14 19:09 - 2012-05-14 19:09 - 07331459 ____A (Blizzard Entertainment) C:\Users\Terry\Downloads\Diablo-III-Setup-enGB.exe
2012-05-14 18:46 - 2012-05-14 18:43 - 12621696 ____A (Microsoft Corporation) C:\Users\Terry\Downloads\mseinstall.exe
2012-05-14 18:29 - 2012-05-14 18:29 - 00029808 ____A C:\Windows\System32\Drivers\mbamchameleon.sys
2012-05-14 18:15 - 2012-05-14 18:15 - 00002560 ____A C:\Windows\_MSRSTRT.EXE
2012-05-14 17:32 - 2012-06-12 14:57 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-12 13:23 - 2012-05-12 13:23 - 00074703 ____A C:\Windows\SysWOW64\mfc45.dll
2012-05-12 07:53 - 2012-05-12 07:53 - 03877872 ____A (AVG Technologies) C:\Users\Terry\Downloads\avg_free_stb_all_2012_2171_cnet.exe
2012-05-06 11:45 - 2012-05-06 11:45 - 08769696 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-04 03:14 - 2012-05-04 03:14 - 05134840 ____A (Binary Fortress Software ) C:\Users\Terry\Downloads\DisplayFusionSetup-4.0.exe
2012-05-04 03:06 - 2012-06-12 14:57 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 03:00 - 2012-06-12 16:19 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-05-04 02:03 - 2012-06-12 14:57 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 14:57 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-04 01:59 - 2012-06-12 16:19 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-05-03 05:42 - 2012-05-03 05:42 - 00396288 ____A () C:\Users\Terry\Downloads\Setup.exe
2012-04-30 21:40 - 2012-06-12 14:57 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-30 18:05 - 2012-04-30 18:05 - 07336664 ____A (Blizzard Entertainment) C:\Users\Terry\Downloads\Diablo-III-8370-enGB-Installer-downloader.exe
2012-04-27 19:55 - 2012-06-12 14:57 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-12 14:57 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 14:57 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 14:57 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-25 15:31 - 2012-04-25 15:31 - 02698752 ____A C:\Users\Terry\Downloads\Chronic_Neuropathic_Pain-Slides_Pierce-Smith.ppt
2012-04-25 15:25 - 2012-04-25 15:25 - 01513472 ____A C:\Users\Terry\Downloads\AgrAbilityLivingwithChronicPain.ppt
2012-04-23 21:37 - 2012-06-12 14:57 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 14:57 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 14:57 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 14:57 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 14:57 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 14:57 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-22 05:36 - 2012-04-22 05:36 - 00000406 ____A C:\Windows\System32\ioloBootDefrag.cfg
2012-04-18 19:22 - 2012-04-18 19:22 - 00286720 ____N (Microsoft Corporation) C:\Windows\Setup1.exe
2012-04-18 19:22 - 2012-04-18 19:22 - 00073216 ____A (Microsoft Corporation) C:\Windows\ST6UNST.EXE
2012-04-18 15:56 - 2012-04-18 15:56 - 00094208 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTimeVR.qtx
2012-04-18 15:56 - 2012-04-18 15:56 - 00069632 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTime.qts
2012-04-18 03:34 - 2011-11-22 07:21 - 00001072 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-04-18 03:32 - 2012-04-08 16:26 - 22259528 ____A C:\Users\Terry\Downloads\vlc-2.0.1-win32.exe
2012-04-17 05:11 - 2012-03-15 12:29 - 00049152 ____A (iolo technologies, LLC) C:\Windows\System32\iolobtdfg.exe
2012-04-17 05:11 - 2012-03-15 12:29 - 00017920 ____A (iolo technologies, LLC) C:\Windows\System32\smrgdf.exe
2012-04-17 04:37 - 2012-04-21 02:18 - 02154032 ____A (iolo technologies, LLC) C:\Windows\System32\Incinerator64.dll
2012-04-17 04:37 - 2012-03-15 12:29 - 02095816 ____A (iolo technologies, LLC) C:\Windows\SysWOW64\Incinerator32.dll
2012-04-17 03:25 - 2012-03-15 12:30 - 00031432 ____A (EldoS Corporation) C:\Windows\System32\Drivers\ElRawDsk.sys
2012-04-16 16:36 - 2011-09-27 17:21 - 00110728 ____A C:\Users\Terry\AppData\Local\GDIPFONTCACHEV1.DAT
2012-04-10 13:44 - 2009-07-13 18:34 - 00000531 ____A C:\Windows\win.ini
2012-04-10 11:42 - 2012-04-10 11:42 - 01639789 ____A C:\Users\Terry\Downloads\winrar-x64-411.exe
2012-04-10 11:41 - 2012-04-10 11:41 - 01669854 ____A C:\Users\Terry\Downloads\winrar-x64-411a.exe
2012-04-07 11:34 - 2012-04-07 11:34 - 02031465 ____A C:\Users\Terry\Downloads\Mac OS X Tiger.wba
2012-04-07 04:31 - 2012-06-12 14:57 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-12 14:57 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-05 06:53 - 2012-04-05 06:53 - 68404936 ____A C:\Users\Terry\Downloads\WindowBlinds7_public.exe
ZeroAccess:
C:\Windows\Installer\{4a0ce653-f62d-1574-556d-c223afaf8a7a}
C:\Windows\Installer\{4a0ce653-f62d-1574-556d-c223afaf8a7a}\@
C:\Windows\Installer\{4a0ce653-f62d-1574-556d-c223afaf8a7a}\L
C:\Windows\Installer\{4a0ce653-f62d-1574-556d-c223afaf8a7a}\U
C:\Windows\Installer\{4a0ce653-f62d-1574-556d-c223afaf8a7a}\U\00000001.@
ZeroAccess:
C:\Users\Terry\AppData\Local\{4a0ce653-f62d-1574-556d-c223afaf8a7a}
C:\Users\Terry\AppData\Local\{4a0ce653-f62d-1574-556d-c223afaf8a7a}\@
C:\Users\Terry\AppData\Local\{4a0ce653-f62d-1574-556d-c223afaf8a7a}\L
C:\Users\Terry\AppData\Local\{4a0ce653-f62d-1574-556d-c223afaf8a7a}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe FCB084FA3DCB7449F3BAA13312A215B4 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 12%
Total physical RAM: 6135.14 MB
Available physical RAM: 5338.25 MB
Total Pagefile: 6133.34 MB
Available Pagefile: 5345.95 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (System) (Fixed) (Total:750 GB) (Free:312.57 GB) NTFS
2 Drive d: (Stuff) (Fixed) (Total:596.17 GB) (Free:424.41 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive e: () (Fixed) (Total:596.17 GB) (Free:577.26 GB) NTFS
4 Drive f: (Media Backup) (Fixed) (Total:931.51 GB) (Free:320.5 GB) NTFS
5 Drive g: (System Backup) (Fixed) (Total:1397.26 GB) (Free:69.62 GB) NTFS
6 Drive I: (Media) (Fixed) (Total:1112.92 GB) (Free:514.42 GB) NTFS
7 Drive j: (GRMCHPXFRER_EN_DVD) (CDROM) (Total:3.09 GB) (Free:0 GB) UDF
8 Drive k: () (Removable) (Total:0.49 GB) (Free:0.49 GB) FAT
9 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
10 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 1863 GB 1024 KB
Disk 1 Online 596 GB 3072 KB
Disk 2 Online 596 GB 3072 KB
Disk 3 Online 931 GB 0 B
Disk 4 Online 1397 GB 0 B
Disk 5 Online 499 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 750 GB 101 MB
Partition 3 Primary 1112 GB 750 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C System NTFS Partition 750 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 I Media NTFS Partition 1112 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 596 GB 1024 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 D Stuff NTFS Partition 596 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 596 GB 1024 KB
==================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 E NTFS Partition 596 GB Healthy
==================================================================================
Partitions of Disk 3:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 931 GB 1024 KB
==================================================================================
Disk: 3
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 F Media Backu NTFS Partition 931 GB Healthy
==================================================================================
Partitions of Disk 4:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1397 GB 1024 KB
==================================================================================
Disk: 4
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 G System Back NTFS Partition 1397 GB Healthy
==================================================================================
Partitions of Disk 5:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 499 MB 16 KB
==================================================================================
Disk: 5
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 K FAT Removable 499 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-28 09:55
======================= End Of Log ==========================