Solved Windows Server 2008, Sirfef.b/y and zeroaccess

avenged187

Posts: 68   +0
Yesterday MSE detected an infection of Sirefef.b and Sirefef.y in one of our administrators folders. Services.exe seems to be infected, and MSE crashes the server every time it tries to clean the files (probably because it's trying to quarantine and delete important system files). Ran MBAM, which attempted to clean infection, but did not seem to help. Ran FRST to confirm infection, which showed ZeroAccess. GMER did not find anything, nor TDSSKiller. DDS will not run on Windows Server 2008. Logs to be posted.
 
Initial MBAM Scan Log

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.08.08

Windows Server 2008 R2 x64 NTFS
Internet Explorer 9.0.8112.16421
frank :: WINDOWS-WQH0732 [administrator]

8/8/2012 12:33:27 PM
mbam-log-2012-08-08 (12-33-27).txt

Scan type: Full scan (C:\|D:\|E:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 795620
Time elapsed: 1 hour(s), 5 minute(s), 34 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 26
D:\Share\EHD\Compusa Backup\LOSTFILE\DIR124\1ind[1].jpg (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\LOSTFILE\DIR143\alisha2[1].jpg (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\LOSTFILE\DIR144\lexi1[1].jpg (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\LOSTFILE\DIR149\pubbannr.gif (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\LOSTFILE\DIR235\Log\4326f31b.LOG (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\LOSTFILE\DIR26\carman4[1].jpg (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\LOSTFILE\DIR26\inescap3[1].jpg (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\LOSTFILE\DIR26\taylor2[1].jpg (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\LOSTFILE\DIR270\buttonslaunch_02-sel[1].gif (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks 2005\Components\DownloadQB15\NewFeatures\.update\.target\accmax.gif (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\DecisionTools\Images\CE_b2_off.gif (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\DecisionTools\Images\weblinks-ratio.gif (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\ECredit\Pages\Images\misc1_btn.gif (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\ECredit\Pages\Images\misc2_btn.gif (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\Help\Images\com_header.gif (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\Services\Images\com_11.gif (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\Services\Images\master_overview.gif (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\Services\Images\merchant_head.gif (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\Services\Images\order_cache_exp_r4_c3.gif (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\Services\Images\order_cache_exp_r5_c2.gif (Extension.Mismatch) -> No action taken.
D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\Services\Images\payreferral_head.gif (Extension.Mismatch) -> No action taken.
C:\Users\frank\AppData\Local\Temp\2\2E86.tmp (Trojan.LameShield) -> Quarantined and deleted successfully.
C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}\n (Trojan.Sirefef) -> Delete on reboot.
C:\Users\Rick\AppData\Local\Temp\5\sdhttt.exe (Exploit.Drop.COD) -> Quarantined and deleted successfully.
C:\Users\Rick\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\77c33b52-4131f7d0 (Exploit.Drop.COD) -> Quarantined and deleted successfully.
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\n (Trojan.Sirefef) -> Quarantined and deleted successfully.

(end)
 
Second scan later in day.

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.08.08

Windows Server 2008 R2 x64 NTFS
Internet Explorer 9.0.8112.16421
frank :: WINDOWS-WQH0732 [administrator]

8/8/2012 1:48:28 PM
mbam-log-2012-08-08 (13-48-28).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 54152
Time elapsed: 5 minute(s), 6 second(s) [aborted]

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
 
Log from FRST this morning.

Scan result of Farbar Recovery Scan Tool Version: 08-08-2012 02
Ran by frank at 09-08-2012 08:58:48
Running from F:\
(X64) OS Language: English(US)
Attention: Could not load system hive.'reg' is not recognized as an internal or external command,
operable program or batch file.
ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.


============ One Month Created Files and Folders ==============

2012-08-09 08:58 - 2012-08-09 08:58 - 00000000 ____D C:\FRST
2012-08-09 08:40 - 2012-08-09 08:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6639107541643CB4
2012-08-09 08:36 - 2012-08-09 08:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB9A1010890AFFEE
2012-08-09 08:33 - 2012-08-09 08:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72E5362A0BD14F2F
2012-08-09 08:29 - 2012-08-09 08:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.44E5779334A7D83E
2012-08-09 08:25 - 2012-08-09 08:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C216B261A64DDCBC
2012-08-09 08:21 - 2012-08-09 08:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5DCF895404AEBB8
2012-08-09 08:18 - 2012-08-09 08:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.69C9D721940BD4BF
2012-08-09 08:14 - 2012-08-09 08:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D82F043A8FEC7CEE
2012-08-09 08:10 - 2012-08-09 08:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8F4E0834D8EFEBC
2012-08-09 08:07 - 2012-08-09 08:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D38393B1BA7246B
2012-08-09 08:03 - 2012-08-09 08:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8071CB9A75191EEB
2012-08-09 07:59 - 2012-08-09 07:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C3011F7E4A785767
2012-08-09 07:55 - 2012-08-09 07:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5EC0E1CF8093BB18
2012-08-09 07:52 - 2012-08-09 07:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9555716B5A2BBFD
2012-08-09 07:48 - 2012-08-09 07:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECBEDE6FCB51C87C
2012-08-09 07:44 - 2012-08-09 07:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBCDD9B8CFE3F464
2012-08-09 07:40 - 2012-08-09 07:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5A9CE81858F92C0D
2012-08-09 07:37 - 2012-08-09 07:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0698789F4ECFC9
2012-08-09 07:33 - 2012-08-09 07:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18B9A90766DC53F5
2012-08-09 07:29 - 2012-08-09 07:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F76E0F11B73876B
2012-08-09 07:26 - 2012-08-09 07:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0844593D2681CF5
2012-08-09 07:22 - 2012-08-09 07:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81A047C03CDC542
2012-08-09 07:18 - 2012-08-09 07:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CEEC5D6C4268E8BC
2012-08-09 07:14 - 2012-08-09 07:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CFD1A50C9191ED21
2012-08-09 07:11 - 2012-08-09 07:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.290B7DA9EDF03385
2012-08-09 07:07 - 2012-08-09 07:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EC804FF5F0FCB85
2012-08-09 07:03 - 2012-08-09 07:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BAA36DBB942413A
2012-08-09 07:00 - 2012-08-09 07:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51DEDEC7ECAFFEFC
2012-08-09 06:56 - 2012-08-09 06:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.880FD5B52EDAAB2C
2012-08-09 06:52 - 2012-08-09 06:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D2EB03BE6D52EB3
2012-08-09 06:48 - 2012-08-09 06:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E65AE579A6C2D61
2012-08-09 06:45 - 2012-08-09 06:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AEDCC9B8D34C361D
2012-08-09 06:41 - 2012-08-09 06:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9C2DC445AF4CAA2
2012-08-09 06:37 - 2012-08-09 06:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C621C95988BA64A
2012-08-09 06:33 - 2012-08-09 06:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DFEBD18377C0AC
2012-08-09 06:30 - 2012-08-09 06:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4CBD7315F69B608B
2012-08-09 06:26 - 2012-08-09 06:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.940A3B643315666D
2012-08-09 06:22 - 2012-08-09 06:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14E93EEEDAAABB17
2012-08-09 06:19 - 2012-08-09 06:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C924DDED6F0FC518
2012-08-09 06:15 - 2012-08-09 06:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2343B3FE8036872A
2012-08-09 06:11 - 2012-08-09 06:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11E81B2BECDB7BC1
2012-08-09 06:07 - 2012-08-09 06:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B261B290D7888CA
2012-08-09 06:04 - 2012-08-09 06:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9692C5AFDCD11D02
2012-08-09 06:00 - 2012-08-09 06:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77291BE6F1228A36
2012-08-09 05:56 - 2012-08-09 05:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9E993F14328744BC
2012-08-09 05:53 - 2012-08-09 05:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B865B3BC9419F04
2012-08-09 05:49 - 2012-08-09 05:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30CAEB12CE87E691
2012-08-09 05:45 - 2012-08-09 05:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.049F9AF61F17D75C
2012-08-09 05:41 - 2012-08-09 05:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.09123E38065282F7
2012-08-09 05:38 - 2012-08-09 05:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.876360F33C92B2C5
2012-08-09 05:34 - 2012-08-09 05:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7C527C7A8B6F50B
2012-08-09 05:30 - 2012-08-09 05:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1D21B448BF10CBA
2012-08-09 05:26 - 2012-08-09 05:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F8E9B38B76A8B0D
2012-08-09 05:23 - 2012-08-09 05:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129B404282E5AE3C
2012-08-09 05:19 - 2012-08-09 05:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2B916F13308CA13
2012-08-09 05:15 - 2012-08-09 05:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4BD5DEF9F7587255
2012-08-09 05:12 - 2012-08-09 05:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94DDAA4175F314B1
2012-08-09 05:08 - 2012-08-09 05:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC302FB3D17C0642
2012-08-09 05:04 - 2012-08-09 05:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DE76FBB01FA45BD3
2012-08-09 05:00 - 2012-08-09 05:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A87AC973177E679
2012-08-09 04:57 - 2012-08-09 04:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FCF899EB194B3AD0
2012-08-09 04:53 - 2012-08-09 04:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1369A8411769F4CD
2012-08-09 04:49 - 2012-08-09 04:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D86BF51DC13B8230
2012-08-09 04:46 - 2012-08-09 04:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B55066EB6B9EEE95
2012-08-09 04:42 - 2012-08-09 04:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87F78F64AC9E978C
2012-08-09 04:38 - 2012-08-09 04:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.46CE1BF2FE39E10B
2012-08-09 04:34 - 2012-08-09 04:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51E9ECFC90321BD5
2012-08-09 04:31 - 2012-08-09 04:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC3CA10830B61336
2012-08-09 04:27 - 2012-08-09 04:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D35B473D6428979
2012-08-09 04:23 - 2012-08-09 04:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A993C76224D14F85
2012-08-09 04:19 - 2012-08-09 04:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B530A5047C73A16A
2012-08-09 04:16 - 2012-08-09 04:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63EAEA5537A808B5
2012-08-09 04:12 - 2012-08-09 04:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD3081176DD59A69
2012-08-09 04:08 - 2012-08-09 04:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F73A1B4CE90B2A7D
2012-08-09 04:05 - 2012-08-09 04:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1A100BAFEECC053
2012-08-09 04:01 - 2012-08-09 04:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.711EEA03DCC5BF9F
2012-08-09 03:57 - 2012-08-09 03:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F091C807FAD0E981
2012-08-09 03:53 - 2012-08-09 03:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9698E79E01BEE1D6
2012-08-09 03:50 - 2012-08-09 03:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FD0E73D6E48DF2DB
2012-08-09 03:46 - 2012-08-09 03:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.373F4D971A931FA2
2012-08-09 03:42 - 2012-08-09 03:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC02870EA8A73758
2012-08-09 03:39 - 2012-08-09 03:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0DDA2AE7A9DE7737
2012-08-09 03:35 - 2012-08-09 03:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33C96B1604B8E4FB
2012-08-09 03:31 - 2012-08-09 03:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24D2F2CA5DC1878C
2012-08-09 03:27 - 2012-08-09 03:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAD55A0BD1D3ACB3
2012-08-09 03:24 - 2012-08-09 03:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBB1583714D0E53F
2012-08-09 03:20 - 2012-08-09 03:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0474DDC0F56A6C98
2012-08-09 03:16 - 2012-08-09 03:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F747776EEE440CA
2012-08-09 03:12 - 2012-08-09 03:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47A1588EEADC79D9
2012-08-09 03:09 - 2012-08-09 03:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA4A3BC2F6AC12CE
2012-08-09 03:05 - 2012-08-09 03:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.155A2A2B10C655C5
2012-08-09 03:01 - 2012-08-09 03:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0879AB483D626932
2012-08-09 02:58 - 2012-08-09 02:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10268C8E76D31502
2012-08-09 02:54 - 2012-08-09 02:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.834B2828FA183CA3
2012-08-09 02:50 - 2012-08-09 02:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2142AABD9A6E03D4
2012-08-09 02:46 - 2012-08-09 02:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7552E461AB63A6C1
2012-08-09 02:43 - 2012-08-09 02:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B6638D582CB5239D
2012-08-09 02:39 - 2012-08-09 02:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0397A3428D3804D4
2012-08-09 02:35 - 2012-08-09 02:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E51DC69051BEA1FC
2012-08-09 02:31 - 2012-08-09 02:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3069EC68AB2E7B57
2012-08-09 02:28 - 2012-08-09 02:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.541103CDEEBBC7B1
2012-08-09 02:24 - 2012-08-09 02:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.00546D2F107C88F6
2012-08-09 02:20 - 2012-08-09 02:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.59B092850D586002
2012-08-09 02:17 - 2012-08-09 02:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88EAA525011D6CD7
2012-08-09 02:13 - 2012-08-09 02:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AFE3CD7BE4C6B273
2012-08-09 02:09 - 2012-08-09 02:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9AE197152C0B6DBE
2012-08-09 02:05 - 2012-08-09 02:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D3C9F9D497408C2
2012-08-09 02:02 - 2012-08-09 02:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169ABF06B61C7DC
2012-08-09 01:58 - 2012-08-09 01:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4FA4C6DEC7FA457
2012-08-09 01:54 - 2012-08-09 01:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F0206D8736558AF0
2012-08-09 01:51 - 2012-08-09 01:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF294788B62887CD
2012-08-09 01:47 - 2012-08-09 01:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7F729FF837B7E1
2012-08-09 01:43 - 2012-08-09 01:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0A702750A1684A1D
2012-08-09 01:39 - 2012-08-09 01:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D82152450C119DA
2012-08-09 01:36 - 2012-08-09 01:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41F7724CB3DB06BB
2012-08-09 01:32 - 2012-08-09 01:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB932C6E4E8EE438
2012-08-09 01:28 - 2012-08-09 01:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF6939662C08E42F
2012-08-09 01:24 - 2012-08-09 01:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.84D746227F91ED91
2012-08-09 01:21 - 2012-08-09 01:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFAAB1B4E5F9F605
2012-08-09 01:17 - 2012-08-09 01:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.92D0F8BF84305E11
2012-08-09 01:13 - 2012-08-09 01:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AB8B992F0731098
2012-08-09 01:10 - 2012-08-09 01:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD6D90A9500B7931
2012-08-09 01:06 - 2012-08-09 01:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1850E1E5AA25B05E
2012-08-09 01:02 - 2012-08-09 01:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.95653D6E21D04D7A
2012-08-09 00:58 - 2012-08-09 00:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8157058AD18E7DAD
2012-08-09 00:55 - 2012-08-09 00:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5D50F07DA5C2D33
2012-08-09 00:51 - 2012-08-09 00:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7E07AB1A607A4F6
2012-08-09 00:47 - 2012-08-09 00:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDF585E84251D56D
2012-08-09 00:44 - 2012-08-09 00:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C8B1AFF015DD2B2
2012-08-09 00:40 - 2012-08-09 00:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D95452728FAECF1
2012-08-09 00:36 - 2012-08-09 00:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E487623797CA617C
2012-08-09 00:32 - 2012-08-09 00:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB438F6E0B2FA2B3
2012-08-09 00:29 - 2012-08-09 00:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C674D1EB924FBB
2012-08-09 00:25 - 2012-08-09 00:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD82D5E5B3B3F72E
2012-08-09 00:21 - 2012-08-09 00:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.67D4F2D8521EED50
2012-08-09 00:17 - 2012-08-09 00:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B33C0521EDC3A884
2012-08-09 00:14 - 2012-08-09 00:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFB723BACF41163
2012-08-09 00:10 - 2012-08-09 00:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E391B3C556D5F42D
2012-08-09 00:06 - 2012-08-09 00:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7FE3577CD164308
2012-08-09 00:03 - 2012-08-09 00:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A5C086D4CB27A94
2012-08-08 23:59 - 2012-08-08 23:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BFB4D489EC266F59
2012-08-08 23:55 - 2012-08-08 23:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E141351D843D5ADB
2012-08-08 23:52 - 2012-08-08 23:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A851C2C7D67203C9
2012-08-08 23:48 - 2012-08-08 23:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1AC6CA500F0B944
2012-08-08 23:44 - 2012-08-08 23:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.877CC8F7C0654369
2012-08-08 23:40 - 2012-08-08 23:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2ABC066A6CB23ED5
2012-08-08 23:37 - 2012-08-08 23:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9FA810BD61820A5
2012-08-08 23:33 - 2012-08-08 23:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D87677A490E90540
2012-08-08 23:29 - 2012-08-08 23:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15B43CCED18E1D14
2012-08-08 23:26 - 2012-08-08 23:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FEB8266FBFAE7339
2012-08-08 23:22 - 2012-08-08 23:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2D9099DA5002738
2012-08-08 23:18 - 2012-08-08 23:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BACC871F522C30B
2012-08-08 23:15 - 2012-08-08 23:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B0AD15D1DF1B2C2
2012-08-08 23:11 - 2012-08-08 23:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB744F045A9AE235
2012-08-08 23:07 - 2012-08-08 23:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8AFD3E376FAC7CB2
2012-08-08 23:03 - 2012-08-08 23:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6235CC19A79237D3
2012-08-08 23:00 - 2012-08-08 23:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E444BD854315046
2012-08-08 22:56 - 2012-08-08 22:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA421768F2A74BA3
2012-08-08 22:52 - 2012-08-08 22:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A83BD7A5E23A315A
2012-08-08 22:49 - 2012-08-08 22:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C641E19DDEE2810
2012-08-08 22:45 - 2012-08-08 22:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BD1E6FA221046C63
2012-08-08 22:41 - 2012-08-08 22:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E190B06FB01BE3D0
2012-08-08 22:38 - 2012-08-08 22:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9160897B82EC0185
2012-08-08 22:34 - 2012-08-08 22:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D46D985EE0FDAD1
2012-08-08 22:30 - 2012-08-08 22:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1457FD0B1E7100F5
2012-08-08 22:27 - 2012-08-08 22:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1798DADE265F227
2012-08-08 21:44 - 2012-08-08 21:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C6A2AF826E71567D
2012-08-08 20:05 - 2012-08-08 20:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E6079324380AA7FD
2012-08-08 19:26 - 2012-08-08 19:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7DAC7B56D306001E
2012-08-08 18:48 - 2012-08-08 18:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74F55DFF4C3A075E
2012-08-08 16:51 - 2012-08-08 16:51 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\frank\Desktop\tdsskiller.exe
2012-08-08 16:50 - 2012-08-08 16:50 - 04727110 ____A (Swearware) C:\Users\frank\Desktop\ComboFix.exe
2012-08-08 16:43 - 2012-08-08 16:43 - 00881494 ____A C:\Users\frank\Desktop\SecurityCheck.exe
2012-08-08 15:02 - 2012-08-08 15:02 - 00000000 ____D C:\Users\frank\AppData\Local\Macromedia
2012-08-08 14:51 - 2012-08-08 14:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.349AEC5204EBA773
2012-08-08 14:47 - 2012-08-08 14:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A4B1FF6622C08F08
2012-08-08 14:44 - 2012-08-08 14:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62B676A461F41E7A
2012-08-08 14:41 - 2012-08-08 14:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7CEB3957CE766A8A
2012-08-08 14:37 - 2012-08-08 14:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89FF8A9A97317FFE
2012-08-08 14:37 - 2012-08-08 14:37 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\uwmbzbaf.sys
2012-08-08 14:34 - 2012-08-08 14:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E8C07ED33CE05A6
2012-08-08 14:31 - 2012-08-08 14:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4E6A751AE46DA9A1
2012-08-08 14:30 - 2012-08-08 14:30 - 00017668 ____A C:\Users\frank\TsAllUsr.Dat
2012-08-08 14:23 - 2012-08-08 14:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8A911C064868CAD
2012-08-08 14:17 - 2012-08-08 14:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B2FF333A3177CB21
2012-08-08 14:14 - 2012-08-08 14:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.399D3E0F3FB865AB
2012-08-08 14:11 - 2012-08-08 14:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB91755D859AF796
2012-08-08 14:07 - 2012-08-08 14:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F93FF9FD3B95AF9
2012-08-08 14:03 - 2012-08-08 14:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.216AEC2C1AD8CA1D
2012-08-08 13:54 - 2012-08-08 13:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-08 13:54 - 2012-08-08 13:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-08 13:52 - 2012-08-08 13:52 - 00000000 ____D C:\Windows\System32\SPReview
2012-08-08 13:45 - 2012-08-08 13:45 - 00000017 ____A C:\Users\Rick\AppData\Local\resmon.resmoncfg
2012-08-08 12:56 - 2012-08-08 12:57 - 12621696 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\mseinstall.exe
2012-08-08 12:51 - 2012-08-08 12:51 - 00000000 ____D C:\Users\Rick\AppData\Roaming\Malwarebytes
2012-08-08 12:32 - 2012-08-08 12:32 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-08 12:32 - 2012-08-08 12:32 - 00000000 ____D C:\Users\frank\AppData\Roaming\Malwarebytes
2012-08-08 12:32 - 2012-08-08 12:32 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-08-08 12:32 - 2012-08-08 12:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-08 12:32 - 2012-07-03 13:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-08 12:30 - 2012-08-08 12:30 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\frank\Downloads\mbam-setup-1.62.0.1300.exe
2012-08-08 12:23 - 2012-08-08 12:23 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-08 12:22 - 2012-08-08 12:22 - 00000000 ____A C:\extensions.sqlite
2012-08-06 18:19 - 2012-08-06 18:19 - 00007607 ____A C:\Users\frank\AppData\Local\Resmon.ResmonCfg
2012-08-02 09:17 - 2012-08-02 09:17 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (3).lnk
2012-08-02 09:16 - 2012-08-02 09:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut.lnk
2012-08-02 09:16 - 2012-08-02 09:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (2).lnk
2012-07-27 11:03 - 2012-07-27 17:58 - 00000000 ____D C:\imagetmp
2012-07-27 10:14 - 2012-07-27 10:14 - 00034770 ____A C:\Users\frank\Desktop\custlist.TXT
2012-07-25 15:08 - 2012-07-25 15:08 - 00000000 ____D C:\Users\frank\AppData\Roaming\SQL Anywhere 12
2012-07-24 10:30 - 2012-07-24 10:30 - 00000000 ____D C:\Users\Rick\AppData\Local\Help
2012-07-24 10:29 - 2012-07-24 10:29 - 00000000 ____D C:\Users\Rick\AppData\Roaming\SQL Anywhere 12
2012-07-19 16:34 - 2012-07-19 16:34 - 00000000 ____D C:\Users\Install\AppData\Local\Adobe
2012-07-19 15:35 - 2012-07-19 15:36 - 00000000 ____D C:\Users\Install\AppData\Roaming\Mozilla
2012-07-19 15:35 - 2012-07-19 15:35 - 00000000 ____D C:\Users\Install\AppData\Local\Mozilla
2012-07-18 15:48 - 2012-07-18 15:48 - 00001349 ____A C:\Users\Install\Desktop\Profit Tools.lnk
2012-07-18 15:38 - 2012-07-18 15:38 - 00000000 ____D C:\Users\Install\AppData\Roaming\Help
2012-07-18 15:38 - 2012-07-18 15:38 - 00000000 ____D C:\Users\Install\AppData\Local\Help
2012-07-18 15:37 - 2012-07-24 10:32 - 00000755 ____A C:\Users\Install\Desktop\Profit Tools Help.lnk
2012-07-18 15:36 - 2012-07-19 16:34 - 00000000 ____D C:\Users\Install\AppData\Roaming\Adobe
2012-07-18 15:36 - 2009-08-04 12:56 - 00296960 ____A (Microsoft Corporation) C:\Windows\winhlp32.exe
2012-07-18 15:36 - 2009-08-04 12:55 - 00195072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftsrch.dll
2012-07-18 15:36 - 2009-08-04 12:55 - 00195072 ____A (Microsoft Corporation) C:\Windows\System32\ftsrch.dll
2012-07-18 15:36 - 2009-08-04 12:55 - 00010240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftlx041e.dll
2012-07-18 15:36 - 2009-08-04 12:55 - 00010240 ____A (Microsoft Corporation) C:\Windows\System32\ftlx041e.dll
2012-07-18 15:36 - 2009-08-04 12:55 - 00009216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftlx0411.dll
2012-07-18 15:36 - 2009-08-04 12:55 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\ftlx0411.dll
2012-07-18 15:11 - 2012-07-18 15:11 - 00000000 ____D C:\Users\Install\AppData\Roaming\WinRAR
2012-07-18 13:28 - 2012-07-18 15:32 - 00000000 ____D C:\Users\Public\Documents\Sybase Central 6.1.0
2012-07-18 13:27 - 2012-07-18 13:31 - 00000166 ____A C:\Windows\ODBC.INI
2012-07-18 13:27 - 2012-07-18 13:31 - 00000000 ____D C:\Users\Install\AppData\Roaming\SQL Anywhere 12
2012-07-18 13:25 - 2012-07-18 15:30 - 00000000 ____D C:\Users\Install\sybase
2012-07-18 13:25 - 2012-07-18 13:25 - 00000000 ____D C:\Users\Public\Documents\DBISQL 12.0.1
2012-07-18 13:06 - 2012-07-18 13:06 - 00103272 ____A C:\Users\Install\GoToAssistDownloadHelper.exe
2012-07-18 13:06 - 2012-07-18 13:06 - 00000000 ____D C:\Users\Install\AppData\Local\Deployment
2012-07-18 13:06 - 2012-07-18 13:06 - 00000000 ____D C:\Users\Install\AppData\Local\Citrix
2012-07-18 13:06 - 2012-07-18 13:06 - 00000000 ____D C:\Users\Install\AppData\Local\Apps\2.0
2012-07-18 13:03 - 2012-07-18 13:25 - 00000000 ____D C:\users\Install
2012-07-18 13:03 - 2012-07-18 13:03 - 00113664 ____A C:\Users\Install\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 13:03 - 2012-07-18 13:03 - 00000020 __ASH C:\Users\Install\ntuser.ini
2012-07-18 13:03 - 2012-07-18 13:03 - 00000000 ____D C:\Users\Install\AppData\Roaming\Apple Computer
2012-07-18 13:03 - 2012-07-18 13:03 - 00000000 ____D C:\Users\Install\AppData\Local\Intuit
2012-07-18 13:03 - 2012-07-18 13:03 - 00000000 ____D C:\Users\Install\AppData\Local\Apple Computer
2012-07-18 13:03 - 2011-10-11 03:01 - 00000000 ____D C:\Users\Install\AppData\Local\Microsoft Help
2012-07-18 13:03 - 2011-02-23 11:42 - 00000000 ____D C:\Users\Install\AppData\Roaming\Macromedia
2012-07-18 12:53 - 2012-07-18 15:12 - 00000000 ____D C:\Users\All Users\SQL Anywhere 12
2012-07-18 12:30 - 2004-07-12 13:50 - 00155648 ____A (Sun Microsystems©) C:\Windows\SysWOW64\JavaAccessBridge.dll
2012-07-18 12:30 - 2004-07-12 13:50 - 00081920 ____A (Sun Microsystems©) C:\Windows\SysWOW64\WindowsAccessBridge.dll
2012-07-18 12:30 - 2004-07-12 13:50 - 00032768 ____A (Sun Microsystems©) C:\Windows\SysWOW64\JAWTAccessBridge.dll
2012-07-18 12:29 - 2012-07-18 12:29 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-07-18 11:06 - 2012-07-18 11:06 - 00103272 ____A C:\Users\frank\GoToAssistDownloadHelper.exe
2012-07-18 11:06 - 2012-07-18 11:06 - 00000000 ____D C:\Users\frank\AppData\Local\Deployment
2012-07-18 11:06 - 2012-07-18 11:06 - 00000000 ____D C:\Users\frank\AppData\Local\Citrix
2012-07-18 11:06 - 2012-07-18 11:06 - 00000000 ____D C:\Users\frank\AppData\Local\Apps\2.0
2012-07-12 10:59 - 2012-07-12 10:59 - 00318904 ____A (Microsoft Corporation) C:\Users\frank\Downloads\wmpfirefoxplugin.exe
2012-07-12 10:53 - 2012-07-12 10:53 - 00318904 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\wmpfirefoxplugin(1).exe
2012-07-12 10:52 - 2012-07-12 10:52 - 00000195 ____A C:\Users\Rick\Downloads\wmpfirefoxplugin.exe
2012-07-11 03:05 - 2012-06-02 07:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 03:05 - 2012-06-02 07:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 03:05 - 2012-06-02 07:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 03:05 - 2012-06-02 07:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 03:05 - 2012-06-02 07:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 03:05 - 2012-06-02 07:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 03:05 - 2012-06-02 07:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 03:05 - 2012-06-02 07:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 03:05 - 2012-06-02 07:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 03:05 - 2012-06-02 07:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 03:05 - 2012-06-02 06:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 03:05 - 2012-06-02 06:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 03:05 - 2012-06-02 06:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 03:05 - 2012-06-02 06:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 03:05 - 2012-06-02 04:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 03:05 - 2012-06-02 03:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 03:05 - 2012-06-02 03:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 03:05 - 2012-06-02 03:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 03:05 - 2012-06-02 03:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 03:05 - 2012-06-02 03:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 03:05 - 2012-06-02 03:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 03:05 - 2012-06-02 03:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 03:05 - 2012-06-02 03:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 03:05 - 2012-06-02 03:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 03:05 - 2012-06-02 03:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 03:05 - 2012-06-02 03:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 03:05 - 2012-06-02 03:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 03:05 - 2012-06-02 03:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 03:01 - 2012-06-11 22:02 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 15:40 - 2012-06-09 00:30 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 15:40 - 2012-06-08 23:46 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 15:40 - 2012-06-06 00:50 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 15:40 - 2012-06-06 00:50 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 15:40 - 2012-06-06 00:09 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 15:40 - 2012-06-06 00:09 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 15:40 - 2012-06-02 00:38 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 15:40 - 2012-06-02 00:38 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 15:40 - 2012-06-02 00:37 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 15:40 - 2012-06-02 00:27 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 15:40 - 2012-06-02 00:27 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 15:40 - 2012-06-01 23:48 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 15:40 - 2012-06-01 23:48 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 15:40 - 2012-06-01 23:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 15:40 - 2012-06-01 23:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll

============ 3 Months Modified Files ========================

2012-08-09 08:55 - 2009-09-22 14:32 - 00851644 ____A C:\Windows\System32\perfh00A.dat
2012-08-09 08:55 - 2009-09-22 14:32 - 00195538 ____A C:\Windows\System32\perfc00A.dat
2012-08-09 08:55 - 2009-09-22 14:18 - 00845594 ____A C:\Windows\System32\perfh010.dat
2012-08-09 08:55 - 2009-09-22 14:18 - 00182856 ____A C:\Windows\System32\perfc010.dat
2012-08-09 08:55 - 2009-09-22 14:06 - 00808956 ____A C:\Windows\System32\perfh007.dat
2012-08-09 08:55 - 2009-09-22 14:06 - 00183696 ____A C:\Windows\System32\perfc007.dat
2012-08-09 08:55 - 2009-09-22 13:53 - 00856886 ____A C:\Windows\System32\perfh00C.dat
2012-08-09 08:55 - 2009-09-22 13:53 - 00187520 ____A C:\Windows\System32\perfc00C.dat
2012-08-09 08:55 - 2009-07-14 00:10 - 05006346 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-09 08:54 - 2009-07-13 23:56 - 00039600 ____A C:\Windows\setupact.log
2012-08-09 08:43 - 2009-07-14 00:06 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-09 08:40 - 2012-08-09 08:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6639107541643CB4
2012-08-09 08:40 - 2011-02-18 13:42 - 01534403 ____A C:\Windows\WindowsUpdate.log
2012-08-09 08:36 - 2012-08-09 08:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB9A1010890AFFEE
2012-08-09 08:33 - 2012-08-09 08:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72E5362A0BD14F2F
2012-08-09 08:29 - 2012-08-09 08:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.44E5779334A7D83E
2012-08-09 08:25 - 2012-08-09 08:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C216B261A64DDCBC
2012-08-09 08:21 - 2012-08-09 08:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5DCF895404AEBB8
2012-08-09 08:18 - 2012-08-09 08:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.69C9D721940BD4BF
2012-08-09 08:14 - 2012-08-09 08:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D82F043A8FEC7CEE
2012-08-09 08:10 - 2012-08-09 08:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8F4E0834D8EFEBC
2012-08-09 08:07 - 2012-08-09 08:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D38393B1BA7246B
2012-08-09 08:03 - 2012-08-09 08:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8071CB9A75191EEB
2012-08-09 07:59 - 2012-08-09 07:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C3011F7E4A785767
2012-08-09 07:55 - 2012-08-09 07:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5EC0E1CF8093BB18
2012-08-09 07:52 - 2012-08-09 07:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9555716B5A2BBFD
2012-08-09 07:48 - 2012-08-09 07:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECBEDE6FCB51C87C
2012-08-09 07:44 - 2012-08-09 07:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBCDD9B8CFE3F464
2012-08-09 07:40 - 2012-08-09 07:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5A9CE81858F92C0D
2012-08-09 07:37 - 2012-08-09 07:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0698789F4ECFC9
2012-08-09 07:33 - 2012-08-09 07:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18B9A90766DC53F5
2012-08-09 07:29 - 2012-08-09 07:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F76E0F11B73876B
2012-08-09 07:26 - 2012-08-09 07:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0844593D2681CF5
2012-08-09 07:22 - 2012-08-09 07:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81A047C03CDC542
2012-08-09 07:18 - 2012-08-09 07:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CEEC5D6C4268E8BC
2012-08-09 07:14 - 2012-08-09 07:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CFD1A50C9191ED21
2012-08-09 07:11 - 2012-08-09 07:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.290B7DA9EDF03385
2012-08-09 07:07 - 2012-08-09 07:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EC804FF5F0FCB85
2012-08-09 07:03 - 2012-08-09 07:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BAA36DBB942413A
2012-08-09 07:00 - 2012-08-09 07:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51DEDEC7ECAFFEFC
2012-08-09 06:56 - 2012-08-09 06:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.880FD5B52EDAAB2C
2012-08-09 06:52 - 2012-08-09 06:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D2EB03BE6D52EB3
2012-08-09 06:48 - 2012-08-09 06:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E65AE579A6C2D61
2012-08-09 06:45 - 2012-08-09 06:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AEDCC9B8D34C361D
2012-08-09 06:41 - 2012-08-09 06:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9C2DC445AF4CAA2
2012-08-09 06:37 - 2012-08-09 06:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C621C95988BA64A
2012-08-09 06:33 - 2012-08-09 06:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DFEBD18377C0AC
2012-08-09 06:30 - 2012-08-09 06:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4CBD7315F69B608B
2012-08-09 06:26 - 2012-08-09 06:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.940A3B643315666D
2012-08-09 06:22 - 2012-08-09 06:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14E93EEEDAAABB17
2012-08-09 06:19 - 2012-08-09 06:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C924DDED6F0FC518
2012-08-09 06:15 - 2012-08-09 06:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2343B3FE8036872A
2012-08-09 06:11 - 2012-08-09 06:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11E81B2BECDB7BC1
2012-08-09 06:07 - 2012-08-09 06:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B261B290D7888CA
2012-08-09 06:04 - 2012-08-09 06:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9692C5AFDCD11D02
2012-08-09 06:00 - 2012-08-09 06:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77291BE6F1228A36
2012-08-09 05:56 - 2012-08-09 05:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9E993F14328744BC
2012-08-09 05:53 - 2012-08-09 05:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B865B3BC9419F04
2012-08-09 05:49 - 2012-08-09 05:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30CAEB12CE87E691
2012-08-09 05:45 - 2012-08-09 05:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.049F9AF61F17D75C
2012-08-09 05:41 - 2012-08-09 05:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.09123E38065282F7
2012-08-09 05:38 - 2012-08-09 05:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.876360F33C92B2C5
2012-08-09 05:34 - 2012-08-09 05:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7C527C7A8B6F50B
2012-08-09 05:30 - 2012-08-09 05:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1D21B448BF10CBA
2012-08-09 05:26 - 2012-08-09 05:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F8E9B38B76A8B0D
2012-08-09 05:23 - 2012-08-09 05:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129B404282E5AE3C
2012-08-09 05:19 - 2012-08-09 05:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2B916F13308CA13
2012-08-09 05:15 - 2012-08-09 05:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4BD5DEF9F7587255
2012-08-09 05:12 - 2012-08-09 05:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94DDAA4175F314B1
2012-08-09 05:08 - 2012-08-09 05:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC302FB3D17C0642
2012-08-09 05:04 - 2012-08-09 05:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DE76FBB01FA45BD3
2012-08-09 05:00 - 2012-08-09 05:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A87AC973177E679
2012-08-09 04:57 - 2012-08-09 04:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FCF899EB194B3AD0
2012-08-09 04:53 - 2012-08-09 04:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1369A8411769F4CD
2012-08-09 04:49 - 2012-08-09 04:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D86BF51DC13B8230
2012-08-09 04:46 - 2012-08-09 04:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B55066EB6B9EEE95
2012-08-09 04:42 - 2012-08-09 04:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87F78F64AC9E978C
2012-08-09 04:38 - 2012-08-09 04:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.46CE1BF2FE39E10B
2012-08-09 04:34 - 2012-08-09 04:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51E9ECFC90321BD5
2012-08-09 04:33 - 2012-05-02 10:49 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-09 04:31 - 2012-08-09 04:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC3CA10830B61336
2012-08-09 04:27 - 2012-08-09 04:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D35B473D6428979
2012-08-09 04:23 - 2012-08-09 04:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A993C76224D14F85
2012-08-09 04:19 - 2012-08-09 04:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B530A5047C73A16A
2012-08-09 04:16 - 2012-08-09 04:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63EAEA5537A808B5
2012-08-09 04:12 - 2012-08-09 04:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD3081176DD59A69
2012-08-09 04:08 - 2012-08-09 04:08 - 00328704 ____A (Microsoft Corporation)
 
C:\Windows\System32\services.exe.F73A1B4CE90B2A7D
2012-08-09 04:05 - 2012-08-09 04:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1A100BAFEECC053
2012-08-09 04:01 - 2012-08-09 04:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.711EEA03DCC5BF9F
2012-08-09 03:57 - 2012-08-09 03:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F091C807FAD0E981
2012-08-09 03:53 - 2012-08-09 03:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9698E79E01BEE1D6
2012-08-09 03:50 - 2012-08-09 03:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FD0E73D6E48DF2DB
2012-08-09 03:46 - 2012-08-09 03:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.373F4D971A931FA2
2012-08-09 03:42 - 2012-08-09 03:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC02870EA8A73758
2012-08-09 03:39 - 2012-08-09 03:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0DDA2AE7A9DE7737
2012-08-09 03:35 - 2012-08-09 03:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33C96B1604B8E4FB
2012-08-09 03:31 - 2012-08-09 03:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24D2F2CA5DC1878C
2012-08-09 03:27 - 2012-08-09 03:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAD55A0BD1D3ACB3
2012-08-09 03:24 - 2012-08-09 03:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBB1583714D0E53F
2012-08-09 03:20 - 2012-08-09 03:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0474DDC0F56A6C98
2012-08-09 03:16 - 2012-08-09 03:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F747776EEE440CA
2012-08-09 03:12 - 2012-08-09 03:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47A1588EEADC79D9
2012-08-09 03:09 - 2012-08-09 03:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA4A3BC2F6AC12CE
2012-08-09 03:05 - 2012-08-09 03:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.155A2A2B10C655C5
2012-08-09 03:01 - 2012-08-09 03:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0879AB483D626932
2012-08-09 02:58 - 2012-08-09 02:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10268C8E76D31502
2012-08-09 02:54 - 2012-08-09 02:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.834B2828FA183CA3
2012-08-09 02:50 - 2012-08-09 02:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2142AABD9A6E03D4
2012-08-09 02:46 - 2012-08-09 02:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7552E461AB63A6C1
2012-08-09 02:43 - 2012-08-09 02:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B6638D582CB5239D
2012-08-09 02:39 - 2012-08-09 02:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0397A3428D3804D4
2012-08-09 02:35 - 2012-08-09 02:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E51DC69051BEA1FC
2012-08-09 02:31 - 2012-08-09 02:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3069EC68AB2E7B57
2012-08-09 02:28 - 2012-08-09 02:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.541103CDEEBBC7B1
2012-08-09 02:24 - 2012-08-09 02:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.00546D2F107C88F6
2012-08-09 02:20 - 2012-08-09 02:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.59B092850D586002
2012-08-09 02:17 - 2012-08-09 02:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88EAA525011D6CD7
2012-08-09 02:13 - 2012-08-09 02:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AFE3CD7BE4C6B273
2012-08-09 02:09 - 2012-08-09 02:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9AE197152C0B6DBE
2012-08-09 02:05 - 2012-08-09 02:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D3C9F9D497408C2
2012-08-09 02:02 - 2012-08-09 02:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169ABF06B61C7DC
2012-08-09 01:58 - 2012-08-09 01:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4FA4C6DEC7FA457
2012-08-09 01:54 - 2012-08-09 01:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F0206D8736558AF0
2012-08-09 01:51 - 2012-08-09 01:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF294788B62887CD
2012-08-09 01:47 - 2012-08-09 01:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7F729FF837B7E1
2012-08-09 01:43 - 2012-08-09 01:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0A702750A1684A1D
2012-08-09 01:39 - 2012-08-09 01:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D82152450C119DA
2012-08-09 01:36 - 2012-08-09 01:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41F7724CB3DB06BB
2012-08-09 01:32 - 2012-08-09 01:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB932C6E4E8EE438
2012-08-09 01:28 - 2012-08-09 01:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF6939662C08E42F
2012-08-09 01:24 - 2012-08-09 01:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.84D746227F91ED91
2012-08-09 01:21 - 2012-08-09 01:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFAAB1B4E5F9F605
2012-08-09 01:20 - 2009-07-14 00:06 - 00032618 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-09 01:17 - 2012-08-09 01:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.92D0F8BF84305E11
2012-08-09 01:13 - 2012-08-09 01:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AB8B992F0731098
2012-08-09 01:10 - 2012-08-09 01:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD6D90A9500B7931
2012-08-09 01:06 - 2012-08-09 01:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1850E1E5AA25B05E
2012-08-09 01:02 - 2012-08-09 01:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.95653D6E21D04D7A
2012-08-09 00:58 - 2012-08-09 00:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8157058AD18E7DAD
2012-08-09 00:55 - 2012-08-09 00:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5D50F07DA5C2D33
2012-08-09 00:51 - 2012-08-09 00:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7E07AB1A607A4F6
2012-08-09 00:47 - 2012-08-09 00:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDF585E84251D56D
2012-08-09 00:44 - 2012-08-09 00:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C8B1AFF015DD2B2
2012-08-09 00:40 - 2012-08-09 00:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D95452728FAECF1
2012-08-09 00:36 - 2012-08-09 00:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E487623797CA617C
2012-08-09 00:32 - 2012-08-09 00:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB438F6E0B2FA2B3
2012-08-09 00:29 - 2012-08-09 00:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C674D1EB924FBB
2012-08-09 00:25 - 2012-08-09 00:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD82D5E5B3B3F72E
2012-08-09 00:21 - 2012-08-09 00:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.67D4F2D8521EED50
2012-08-09 00:17 - 2012-08-09 00:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B33C0521EDC3A884
2012-08-09 00:14 - 2012-08-09 00:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFB723BACF41163
2012-08-09 00:10 - 2012-08-09 00:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E391B3C556D5F42D
2012-08-09 00:06 - 2012-08-09 00:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7FE3577CD164308
2012-08-09 00:03 - 2012-08-09 00:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A5C086D4CB27A94
2012-08-08 23:59 - 2012-08-08 23:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BFB4D489EC266F59
2012-08-08 23:55 - 2012-08-08 23:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E141351D843D5ADB
2012-08-08 23:52 - 2012-08-08 23:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A851C2C7D67203C9
2012-08-08 23:48 - 2012-08-08 23:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1AC6CA500F0B944
2012-08-08 23:44 - 2012-08-08 23:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.877CC8F7C0654369
2012-08-08 23:40 - 2012-08-08 23:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2ABC066A6CB23ED5
2012-08-08 23:37 - 2012-08-08 23:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9FA810BD61820A5
2012-08-08 23:33 - 2012-08-08 23:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D87677A490E90540
2012-08-08 23:29 - 2012-08-08 23:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15B43CCED18E1D14
2012-08-08 23:26 - 2012-08-08 23:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FEB8266FBFAE7339
2012-08-08 23:22 - 2012-08-08 23:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2D9099DA5002738
2012-08-08 23:18 - 2012-08-08 23:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BACC871F522C30B
2012-08-08 23:15 - 2012-08-08 23:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B0AD15D1DF1B2C2
2012-08-08 23:11 - 2012-08-08 23:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB744F045A9AE235
2012-08-08 23:07 - 2012-08-08 23:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8AFD3E376FAC7CB2
2012-08-08 23:03 - 2012-08-08 23:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6235CC19A79237D3
2012-08-08 23:00 - 2012-08-08 23:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E444BD854315046
2012-08-08 22:56 - 2012-08-08 22:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA421768F2A74BA3
2012-08-08 22:52 - 2012-08-08 22:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A83BD7A5E23A315A
2012-08-08 22:49 - 2012-08-08 22:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C641E19DDEE2810
2012-08-08 22:45 - 2012-08-08 22:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BD1E6FA221046C63
2012-08-08 22:41 - 2012-08-08 22:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E190B06FB01BE3D0
2012-08-08 22:38 - 2012-08-08 22:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9160897B82EC0185
2012-08-08 22:34 - 2012-08-08 22:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D46D985EE0FDAD1
2012-08-08 22:30 - 2012-08-08 22:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1457FD0B1E7100F5
2012-08-08 22:27 - 2012-08-08 22:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1798DADE265F227
2012-08-08 22:23 - 2009-07-13 18:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-08 21:54 - 2009-07-13 23:49 - 00014048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-08 21:54 - 2009-07-13 23:49 - 00014048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-08 21:44 - 2012-08-08 21:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C6A2AF826E71567D
2012-08-08 20:05 - 2012-08-08 20:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E6079324380AA7FD
2012-08-08 19:26 - 2012-08-08 19:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7DAC7B56D306001E
2012-08-08 19:01 - 2011-03-25 21:19 - 00000402 ___AH C:\Windows\Tasks\GG Logistics Corp. 1301105924.job
2012-08-08 18:48 - 2012-08-08 18:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74F55DFF4C3A075E
2012-08-08 17:07 - 2011-02-22 13:47 - 00053828 ____A C:\Windows\PFRO.log
2012-08-08 16:51 - 2012-08-08 16:51 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\frank\Desktop\tdsskiller.exe
2012-08-08 16:50 - 2012-08-08 16:50 - 04727110 ____A (Swearware) C:\Users\frank\Desktop\ComboFix.exe
2012-08-08 16:43 - 2012-08-08 16:43 - 00881494 ____A C:\Users\frank\Desktop\SecurityCheck.exe
2012-08-08 15:50 - 2011-02-21 17:24 - 00000072 ____A C:\Users\Public\LMDebug.log
2012-08-08 14:51 - 2012-08-08 14:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.349AEC5204EBA773
2012-08-08 14:47 - 2012-08-08 14:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A4B1FF6622C08F08
2012-08-08 14:44 - 2012-08-08 14:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62B676A461F41E7A
2012-08-08 14:41 - 2012-08-08 14:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7CEB3957CE766A8A
2012-08-08 14:37 - 2012-08-08 14:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89FF8A9A97317FFE
2012-08-08 14:37 - 2012-08-08 14:37 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\uwmbzbaf.sys
2012-08-08 14:34 - 2012-08-08 14:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E8C07ED33CE05A6
2012-08-08 14:31 - 2012-08-08 14:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4E6A751AE46DA9A1
2012-08-08 14:30 - 2012-08-08 14:30 - 00017668 ____A C:\Users\frank\TsAllUsr.Dat
2012-08-08 14:27 - 2011-02-22 17:29 - 00002243 ____A C:\Windows\epplauncher.mif
2012-08-08 14:23 - 2012-08-08 14:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8A911C064868CAD
2012-08-08 14:17 - 2012-08-08 14:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B2FF333A3177CB21
2012-08-08 14:14 - 2012-08-08 14:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.399D3E0F3FB865AB
2012-08-08 14:11 - 2012-08-08 14:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB91755D859AF796
2012-08-08 14:07 - 2012-08-08 14:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F93FF9FD3B95AF9
2012-08-08 14:03 - 2012-08-08 14:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.216AEC2C1AD8CA1D
2012-08-08 13:54 - 2011-02-21 16:48 - 05074708 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-08 13:45 - 2012-08-08 13:45 - 00000017 ____A C:\Users\Rick\AppData\Local\resmon.resmoncfg
2012-08-08 12:57 - 2012-08-08 12:56 - 12621696 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\mseinstall.exe
2012-08-08 12:32 - 2012-08-08 12:32 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-08 12:30 - 2012-08-08 12:30 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\frank\Downloads\mbam-setup-1.62.0.1300.exe
2012-08-08 12:22 - 2012-08-08 12:22 - 00000000 ____A C:\extensions.sqlite
2012-08-08 12:20 - 2011-02-23 10:05 - 00000462 _RASH C:\Users\All Users\ntuser.pol
2012-08-06 18:19 - 2012-08-06 18:19 - 00007607 ____A C:\Users\frank\AppData\Local\Resmon.ResmonCfg
2012-08-02 13:32 - 2012-05-02 10:49 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-02 13:32 - 2011-06-29 08:53 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-02 09:17 - 2012-08-02 09:17 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (3).lnk
2012-08-02 09:16 - 2012-08-02 09:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut.lnk
2012-08-02 09:16 - 2012-08-02 09:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (2).lnk
2012-07-27 10:14 - 2012-07-27 10:14 - 00034770 ____A C:\Users\frank\Desktop\custlist.TXT
2012-07-24 10:32 - 2012-07-18 15:37 - 00000755 ____A C:\Users\Install\Desktop\Profit Tools Help.lnk
2012-07-18 15:48 - 2012-07-18 15:48 - 00001349 ____A C:\Users\Install\Desktop\Profit Tools.lnk
2012-07-18 13:31 - 2012-07-18 13:27 - 00000166 ____A C:\Windows\ODBC.INI
2012-07-18 13:18 - 2011-02-21 17:07 - 00113664 ____A C:\Users\Rick\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 13:06 - 2012-07-18 13:06 - 00103272 ____A C:\Users\Install\GoToAssistDownloadHelper.exe
2012-07-18 13:03 - 2012-07-18 13:03 - 00113664 ____A C:\Users\Install\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 13:03 - 2012-07-18 13:03 - 00000020 __ASH C:\Users\Install\ntuser.ini
2012-07-18 12:55 - 2011-03-18 11:09 - 00113664 ____A C:\Users\MaryBeth\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 12:54 - 2011-07-06 16:15 - 00113664 ____A C:\Users\frank\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 12:53 - 2009-07-13 23:49 - 00422368 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-18 11:06 - 2012-07-18 11:06 - 00103272 ____A C:\Users\frank\GoToAssistDownloadHelper.exe
2012-07-16 10:29 - 2012-01-26 11:04 - 00000036 ___AH C:\Windows\SysWOW64\f9t.dat
2012-07-12 10:59 - 2012-07-12 10:59 - 00318904 ____A (Microsoft Corporation) C:\Users\frank\Downloads\wmpfirefoxplugin.exe
2012-07-12 10:53 - 2012-07-12 10:53 - 00318904 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\wmpfirefoxplugin(1).exe
2012-07-12 10:52 - 2012-07-12 10:52 - 00000195 ____A C:\Users\Rick\Downloads\wmpfirefoxplugin.exe
2012-07-11 03:02 - 2011-02-21 11:49 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-03 13:46 - 2012-08-08 12:32 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-26 16:12 - 2012-06-26 16:12 - 00008467 ____A C:\Users\Rick\Documents\06262012.xls
2012-06-19 13:17 - 2012-06-19 13:17 - 00000000 ___AH C:\Users\Rick\Documents\Default.rdp
2012-06-13 17:32 - 2012-05-25 14:59 - 00011819 ____A C:\Users\nick\Documents\Budget.xlsx
2012-06-11 22:02 - 2012-07-11 03:01 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-09 00:30 - 2012-07-10 15:40 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 23:46 - 2012-07-10 15:40 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 08:39 - 2012-06-08 08:39 - 00026112 ____A C:\Users\frank\Desktop\vacation.oft
2012-06-06 11:31 - 2012-06-06 11:31 - 00741744 ____A (RealVNC Ltd. ) C:\Users\frank\Downloads\vnc-4_1_3-x86_win32.exe
2012-06-06 00:50 - 2012-07-10 15:40 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-06 00:50 - 2012-07-10 15:40 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-06 00:09 - 2012-07-10 15:40 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-06 00:09 - 2012-07-10 15:40 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 13:56 - 2012-06-05 13:55 - 01636224 ____A (Inbox.com, Inc. ) C:\Users\Rick\Downloads\MapsSetup.exe
2012-06-02 17:19 - 2012-06-21 08:05 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 17:19 - 2012-06-21 08:05 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 17:19 - 2012-06-21 08:05 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 17:19 - 2012-06-21 08:05 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 17:19 - 2012-06-21 08:05 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 17:15 - 2012-06-21 08:05 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 17:15 - 2012-06-21 08:05 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 15:19 - 2012-06-21 08:05 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 15:15 - 2012-06-21 08:05 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 07:49 - 2012-07-11 03:05 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 07:17 - 2012-07-11 03:05 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 07:12 - 2012-07-11 03:05 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 07:05 - 2012-07-11 03:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 07:05 - 2012-07-11 03:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 07:04 - 2012-07-11 03:05 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 07:04 - 2012-07-11 03:05 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 07:03 - 2012-07-11 03:05 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 07:01 - 2012-07-11 03:05 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 07:00 - 2012-07-11 03:05 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 06:59 - 2012-07-11 03:05 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 06:57 - 2012-07-11 03:05 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 06:57 - 2012-07-11 03:05 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 06:54 - 2012-07-11 03:05 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 04:07 - 2012-07-11 03:05 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 03:43 - 2012-07-11 03:05 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 03:33 - 2012-07-11 03:05 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 03:26 - 2012-07-11 03:05 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 03:25 - 2012-07-11 03:05 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 03:25 - 2012-07-11 03:05 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 03:23 - 2012-07-11 03:05 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 03:21 - 2012-07-11 03:05 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 03:20 - 2012-07-11 03:05 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 03:19 - 2012-07-11 03:05 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 03:19 - 2012-07-11 03:05 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 03:17 - 2012-07-11 03:05 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 03:16 - 2012-07-11 03:05 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 03:14 - 2012-07-11 03:05 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-02 00:38 - 2012-07-10 15:40 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-02 00:38 - 2012-07-10 15:40 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 00:37 - 2012-07-10 15:40 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-02 00:27 - 2012-07-10 15:40 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-02 00:27 - 2012-07-10 15:40 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 23:48 - 2012-07-10 15:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 23:48 - 2012-07-10 15:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 23:47 - 2012-07-10 15:40 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 23:42 - 2012-07-10 15:40 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 12:25 - 2011-02-21 13:46 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-25 17:19 - 2012-05-25 17:19 - 00009101 ____A C:\Users\Rick\Documents\nate.xlsx
2012-05-14 14:46 - 2012-05-14 14:46 - 00897520 ____A (Dyn, Inc.) C:\Users\frank\Downloads\DynUpSetup.exe

ZeroAccess:
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\@
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\L
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U\00000001.@
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U\80000000.@
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U\800000cb.@

ZeroAccess:
C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}
C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}\@
C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}\L
C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}\U

========================= Bamital & volsnap Check ============

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

========================= Memory info ======================

Percentage of memory in use: 24%
Total physical RAM: 6135.23 MB
Available physical RAM: 4610.82 MB
Total Pagefile: 12268.57 MB
Available Pagefile: 10409.61 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB

======================= Partitions =========================

1 Drive c: () (Fixed) (Total:98.13 GB) (Free:23.24 GB) NTFS
2 Drive d: (Data) (Fixed) (Total:738.97 GB) (Free:687.8 GB) NTFS
3 Drive e: (Iomega HDD) (Fixed) (Total:1863.01 GB) (Free:1734 GB) NTFS
4 Drive f: (USB DISK) (Removable) (Total:1.91 GB) (Free:1.91 GB) FAT


==========================================================

Last Boot: 2012-08-08 18:30

======================= End Of Log ==========================
 
Welcome aboard
yahooo.gif


Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

============================================

You ran FRST from within Windows. That won't work with ZeroAccess infection.
We don't have too many tools for Server 2008 so I'm not sure if it'll work but here is the correct way to do it...

For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:

    • Startup Repair
      System Restore
      Windows Complete PC Restore
      Windows Memory Diagnostic Tool
      Command Prompt
  • Select Command Prompt
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Next...

Re-run FRST again.
Type the following in the edit box after "Search:".

services.exe

Click Search button and post the log (Search.txt) it makes in your reply.

I'll expect two logs:
- FRST.txt
- Search.txt
 
Scan result of Farbar Recovery Scan Tool Version: 08-08-2012 02
Ran by SYSTEM at 09-08-2012 11:23:37
Running from G:\
Windows Server 2008 R2 Standard (X64) OS Language: English(US)
The current controlset is ControlSet002

========================== Registry (Whitelisted) =============

HKLM\...\Run: [QLogicSaveSystemInfo] rundll32.exe qlco1006.dll,QLSaveSystemInfo [x]
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [2305912 2012-06-18] (Intuit Inc. All rights reserved.)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2012-02-23] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKU\MaryBeth\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKU\Rick\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
Tcpip\..\Interfaces\{B0A35114-EF36-4060-B305-19D57C618B96}: [NameServer]208.67.222.222,208.67.220.220
Lsa: [Notification Packages] scecli
rassfm
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Dyn Updater Tray Icon.lnk
ShortcutTarget: Dyn Updater Tray Icon.lnk -> C:\Program Files (x86)\Dyn Updater\DynTray.exe (Dyn, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Intuit Data Protect.lnk
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk
ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files (x86)\Intuit\QuickBooks 2011\QBW32.EXE (Intuit Inc.)
Startup: C:\Users\frank\Start Menu\Programs\Startup\hs_err_pid5788.log ()
Startup: C:\Users\frank\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\MaryBeth\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\nick\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Rick\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

==================== Services (Whitelisted) ======

2 atnthost; "C:\ProgramData\webex\MyWebEx\319\atnthost.exe" [16776 2011-11-10] (WebEx Communications, Inc.)
2 Dyn Updater; C:\Program Files (x86)\Dyn Updater\DynUpSvc.exe [95608 2011-11-15] (Dyn, Inc.)
3 FCRegSvc; C:\Windows\System32\FCRegSvc.dll [25600 2009-07-13] (Microsoft Corporation)
2 HP Digital Sending Software; "C:\Program Files (x86)\Hewlett-Packard\HP Digital Sending Software 4.91\Filesystems\Core\bin\XP-x86\Release\HP.Dss.App.WinService.exe" [16440 2011-03-08] (Hewlett-Packard)
2 McAfee SiteAdvisor Service; C:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [103472 2012-06-15] (McAfee, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 MSSQL$HPDSS; "C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sHPDSS [29293408 2010-12-10] (Microsoft Corporation)
2 NetPipeActivator; "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" [116560 2009-06-10] (Microsoft Corporation)
2 NetTcpActivator; "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" [116560 2009-06-10] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
3 QuickBooksDB20; C:\PROGRA~2\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB20 [678912 2009-08-18] (Intuit, Inc.)
3 QuickBooksDB21; C:\PROGRA~2\Intuit\QUICKB~2\QBDBMgrN.exe -hvQuickBooksDB21 [679936 2010-04-27] (Intuit, Inc.)
3 rqs; C:\Windows\System32\rqs.exe [41472 2009-07-13] (Microsoft Corporation)
3 RSoPProv; C:\Windows\System32\RSoPProv.exe [91648 2009-07-13] (Microsoft Corporation)
3 sacsvr; C:\Windows\System32\sacsvr.dll [14848 2009-07-13] (Microsoft Corporation)
2 SNMP; C:\Windows\System32\snmp.exe [49664 2009-07-13] (Microsoft Corporation)
2 SNMP; C:\Windows\SysWow64\snmp.exe [47616 2009-07-13] (Microsoft Corporation)
2 sysdown; C:\Windows\System32\sysdown.exe [17960 2010-01-25] (Hewlett-Packard Company)
2 TermServLicensing; C:\Windows\System32\lserver.dll [692224 2009-07-13] (Microsoft Corporation)
2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [451072 2009-07-13] (Microsoft Corporation)
2 W3SVC; C:\Windows\SysWow64\inetsrv\iisw3adm.dll [396288 2009-07-13] (Microsoft Corporation)
2 WinVNC4; "C:\Program Files (x86)\RealVNC\VNC4\WinVNC4.exe" -service [439632 2008-10-15] (RealVNC Ltd.)
2 SQLANYs_ptsrv; C:\Program Files\Profit Tools\Sybase\SQLA12\Bin64\dbsrv12.exe -hvSQLANYs_ptsrv [x]

========================== Drivers (Whitelisted) =============

3 aarahci; C:\Windows\System32\Drivers\aarahci.sys [363056 2008-07-31] (Adaptec, Inc.)
3 b06diag; C:\Windows\system32\DRIVERS\bxdiaga.sys [89128 2010-08-02] (Broadcom Corporation)
3 bchtsw64; C:\Windows\System32\Drivers\bchtsw64.sys [90936 2009-10-23] (Broadcom Corporation)
3 be2iscsi; C:\Windows\System32\Drivers\be2iscsi.sys [163376 2010-08-31] (ServerEngines Corporation)
3 bfad; C:\Windows\System32\Drivers\bfad.sys [1125488 2010-04-20] (Brocade Communications Systems, Inc.)
0 bfad_up; C:\Windows\System32\Drivers\bfad_up.sys [15472 2010-04-20] (Brocade Communications Systems, Inc.)
3 BXOIS; C:\Windows\System32\Drivers\BXOIS.sys [524840 2010-08-02] (Broadcom Corporation)
3 elxcna; C:\Windows\System32\Drivers\elxcna.sys [646664 2010-08-05] (Emulex)
3 G200e; C:\Windows\System32\DRIVERS\G200em.sys [242176 2011-03-14] (Matrox Graphics Inc.)
3 HpAHCIsr; C:\Windows\System32\Drivers\HpAHCIsr.sys [223336 2010-05-27] (Hewlett-Packard Company)
0 HpCISSs2; C:\Windows\System32\Drivers\HpCISSs2.sys [156776 2010-02-21] (Hewlett-Packard Company)
3 hpqmgmt; C:\Windows\System32\Drivers\hpqmgmt.sys [98856 2009-03-19] (Hewlett-Packard Company)
3 HPUSBMSC; C:\Windows\system32\DRIVERS\HPUSBXSC.SYS [47144 2009-06-17] (Hewlett-Packard)
3 ioatdma; C:\Windows\System32\Drivers\qd260x64.sys [35328 2009-06-10] (Intel Corporation)
3 mlx4_bus; C:\Windows\System32\Drivers\mlx4_bus.sys [291944 2010-09-01] (Hewlett-Packard)
3 MRxDAV; C:\Windows\SysWow64\Drivers\MRxDAV.sys [115712 2009-07-13] (Microsoft Corporation)
3 q57nd60a; C:\Windows\System32\DRIVERS\b57nd60a.sys [405544 2010-08-02] (Broadcom Corporation)
0 sacdrv; C:\Windows\System32\Drivers\sacdrv.sys [96320 2009-07-13] (Microsoft Corporation)
3 storvsp; C:\Windows\System32\Drivers\storvsp.sys [121856 2009-07-13] (Microsoft Corporation)
3 Vid; C:\Windows\System32\Drivers\Vid.sys [181248 2009-07-13] (Microsoft Corporation)
3 KAPFA; \??\C:\Windows\system32\drivers\KAPFA.SYS [x]

========================== NetSvcs (Whitelisted) ===========

NETSVC: sacsvr -> C:\Windows\system32\sacsvr.dll (Microsoft Corporation)

============ One Month Created Files and Folders ==============

2012-08-09 06:04 - 2012-08-09 05:50 - 00607260 ____R (Swearware) C:\Users\frank\Desktop\dds.com
2012-08-09 06:04 - 2012-08-09 05:49 - 00302592 ____A C:\Users\frank\Desktop\wy82hjq3.exe
2012-08-09 05:58 - 2012-08-09 05:58 - 00000000 ____D C:\FRST
2012-08-09 05:40 - 2012-08-09 05:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6639107541643CB4
2012-08-09 05:36 - 2012-08-09 05:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB9A1010890AFFEE
2012-08-09 05:33 - 2012-08-09 05:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72E5362A0BD14F2F
2012-08-09 05:29 - 2012-08-09 05:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.44E5779334A7D83E
2012-08-09 05:25 - 2012-08-09 05:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C216B261A64DDCBC
2012-08-09 05:21 - 2012-08-09 05:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5DCF895404AEBB8
2012-08-09 05:18 - 2012-08-09 05:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.69C9D721940BD4BF
2012-08-09 05:14 - 2012-08-09 05:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D82F043A8FEC7CEE
2012-08-09 05:10 - 2012-08-09 05:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8F4E0834D8EFEBC
2012-08-09 05:07 - 2012-08-09 05:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D38393B1BA7246B
2012-08-09 05:03 - 2012-08-09 05:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8071CB9A75191EEB
2012-08-09 04:59 - 2012-08-09 04:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C3011F7E4A785767
2012-08-09 04:55 - 2012-08-09 04:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5EC0E1CF8093BB18
2012-08-09 04:52 - 2012-08-09 04:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9555716B5A2BBFD
2012-08-09 04:48 - 2012-08-09 04:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECBEDE6FCB51C87C
2012-08-09 04:44 - 2012-08-09 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBCDD9B8CFE3F464
2012-08-09 04:40 - 2012-08-09 04:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5A9CE81858F92C0D
2012-08-09 04:37 - 2012-08-09 04:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0698789F4ECFC9
2012-08-09 04:33 - 2012-08-09 04:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18B9A90766DC53F5
2012-08-09 04:29 - 2012-08-09 04:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F76E0F11B73876B
2012-08-09 04:26 - 2012-08-09 04:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0844593D2681CF5
2012-08-09 04:22 - 2012-08-09 04:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81A047C03CDC542
2012-08-09 04:18 - 2012-08-09 04:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CEEC5D6C4268E8BC
2012-08-09 04:14 - 2012-08-09 04:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CFD1A50C9191ED21
2012-08-09 04:11 - 2012-08-09 04:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.290B7DA9EDF03385
2012-08-09 04:07 - 2012-08-09 04:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EC804FF5F0FCB85
2012-08-09 04:03 - 2012-08-09 04:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BAA36DBB942413A
2012-08-09 04:00 - 2012-08-09 04:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51DEDEC7ECAFFEFC
2012-08-09 03:56 - 2012-08-09 03:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.880FD5B52EDAAB2C
2012-08-09 03:52 - 2012-08-09 03:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D2EB03BE6D52EB3
2012-08-09 03:48 - 2012-08-09 03:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E65AE579A6C2D61
2012-08-09 03:45 - 2012-08-09 03:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AEDCC9B8D34C361D
2012-08-09 03:41 - 2012-08-09 03:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9C2DC445AF4CAA2
2012-08-09 03:37 - 2012-08-09 03:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C621C95988BA64A
2012-08-09 03:33 - 2012-08-09 03:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DFEBD18377C0AC
2012-08-09 03:30 - 2012-08-09 03:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4CBD7315F69B608B
2012-08-09 03:26 - 2012-08-09 03:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.940A3B643315666D
2012-08-09 03:22 - 2012-08-09 03:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14E93EEEDAAABB17
2012-08-09 03:19 - 2012-08-09 03:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C924DDED6F0FC518
2012-08-09 03:15 - 2012-08-09 03:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2343B3FE8036872A
2012-08-09 03:11 - 2012-08-09 03:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11E81B2BECDB7BC1
2012-08-09 03:07 - 2012-08-09 03:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B261B290D7888CA
2012-08-09 03:04 - 2012-08-09 03:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9692C5AFDCD11D02
2012-08-09 03:00 - 2012-08-09 03:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77291BE6F1228A36
2012-08-09 02:56 - 2012-08-09 02:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9E993F14328744BC
2012-08-09 02:53 - 2012-08-09 02:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B865B3BC9419F04
2012-08-09 02:49 - 2012-08-09 02:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30CAEB12CE87E691
2012-08-09 02:45 - 2012-08-09 02:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.049F9AF61F17D75C
2012-08-09 02:41 - 2012-08-09 02:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.09123E38065282F7
2012-08-09 02:38 - 2012-08-09 02:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.876360F33C92B2C5
2012-08-09 02:34 - 2012-08-09 02:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7C527C7A8B6F50B
2012-08-09 02:30 - 2012-08-09 02:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1D21B448BF10CBA
2012-08-09 02:26 - 2012-08-09 02:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F8E9B38B76A8B0D
2012-08-09 02:23 - 2012-08-09 02:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129B404282E5AE3C
2012-08-09 02:19 - 2012-08-09 02:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2B916F13308CA13
2012-08-09 02:15 - 2012-08-09 02:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4BD5DEF9F7587255
2012-08-09 02:12 - 2012-08-09 02:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94DDAA4175F314B1
2012-08-09 02:08 - 2012-08-09 02:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC302FB3D17C0642
2012-08-09 02:04 - 2012-08-09 02:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DE76FBB01FA45BD3
2012-08-09 02:00 - 2012-08-09 02:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A87AC973177E679
2012-08-09 01:57 - 2012-08-09 01:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FCF899EB194B3AD0
2012-08-09 01:53 - 2012-08-09 01:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1369A8411769F4CD
2012-08-09 01:49 - 2012-08-09 01:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D86BF51DC13B8230
2012-08-09 01:46 - 2012-08-09 01:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B55066EB6B9EEE95
2012-08-09 01:42 - 2012-08-09 01:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87F78F64AC9E978C
2012-08-09 01:38 - 2012-08-09 01:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.46CE1BF2FE39E10B
2012-08-09 01:34 - 2012-08-09 01:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51E9ECFC90321BD5
2012-08-09 01:31 - 2012-08-09 01:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC3CA10830B61336
2012-08-09 01:27 - 2012-08-09 01:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D35B473D6428979
2012-08-09 01:23 - 2012-08-09 01:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A993C76224D14F85
2012-08-09 01:19 - 2012-08-09 01:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B530A5047C73A16A
2012-08-09 01:16 - 2012-08-09 01:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63EAEA5537A808B5
2012-08-09 01:12 - 2012-08-09 01:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD3081176DD59A69
2012-08-09 01:08 - 2012-08-09 01:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F73A1B4CE90B2A7D
2012-08-09 01:05 - 2012-08-09 01:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1A100BAFEECC053
2012-08-09 01:01 - 2012-08-09 01:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.711EEA03DCC5BF9F
2012-08-09 00:57 - 2012-08-09 00:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F091C807FAD0E981
2012-08-09 00:53 - 2012-08-09 00:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9698E79E01BEE1D6
2012-08-09 00:50 - 2012-08-09 00:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FD0E73D6E48DF2DB
2012-08-09 00:46 - 2012-08-09 00:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.373F4D971A931FA2
2012-08-09 00:42 - 2012-08-09 00:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC02870EA8A73758
2012-08-09 00:39 - 2012-08-09 00:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0DDA2AE7A9DE7737
2012-08-09 00:35 - 2012-08-09 00:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33C96B1604B8E4FB
2012-08-09 00:31 - 2012-08-09 00:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24D2F2CA5DC1878C
2012-08-09 00:27 - 2012-08-09 00:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAD55A0BD1D3ACB3
2012-08-09 00:24 - 2012-08-09 00:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBB1583714D0E53F
2012-08-09 00:20 - 2012-08-09 00:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0474DDC0F56A6C98
2012-08-09 00:16 - 2012-08-09 00:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F747776EEE440CA
2012-08-09 00:12 - 2012-08-09 00:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47A1588EEADC79D9
2012-08-09 00:09 - 2012-08-09 00:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA4A3BC2F6AC12CE
2012-08-09 00:05 - 2012-08-09 00:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.155A2A2B10C655C5
2012-08-09 00:01 - 2012-08-09 00:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0879AB483D626932
2012-08-08 23:58 - 2012-08-08 23:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10268C8E76D31502
2012-08-08 23:54 - 2012-08-08 23:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.834B2828FA183CA3
2012-08-08 23:50 - 2012-08-08 23:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2142AABD9A6E03D4
2012-08-08 23:46 - 2012-08-08 23:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7552E461AB63A6C1
2012-08-08 23:43 - 2012-08-08 23:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B6638D582CB5239D
2012-08-08 23:39 - 2012-08-08 23:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0397A3428D3804D4
2012-08-08 23:35 - 2012-08-08 23:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E51DC69051BEA1FC
2012-08-08 23:31 - 2012-08-08 23:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3069EC68AB2E7B57
2012-08-08 23:28 - 2012-08-08 23:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.541103CDEEBBC7B1
2012-08-08 23:24 - 2012-08-08 23:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.00546D2F107C88F6
2012-08-08 23:20 - 2012-08-08 23:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.59B092850D586002
2012-08-08 23:17 - 2012-08-08 23:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88EAA525011D6CD7
2012-08-08 23:13 - 2012-08-08 23:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AFE3CD7BE4C6B273
2012-08-08 23:09 - 2012-08-08 23:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9AE197152C0B6DBE
2012-08-08 23:05 - 2012-08-08 23:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D3C9F9D497408C2
2012-08-08 23:02 - 2012-08-08 23:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169ABF06B61C7DC
2012-08-08 22:58 - 2012-08-08 22:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4FA4C6DEC7FA457
2012-08-08 22:54 - 2012-08-08 22:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F0206D8736558AF0
2012-08-08 22:51 - 2012-08-08 22:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF294788B62887CD
2012-08-08 22:47 - 2012-08-08 22:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7F729FF837B7E1
2012-08-08 22:43 - 2012-08-08 22:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0A702750A1684A1D
2012-08-08 22:39 - 2012-08-08 22:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D82152450C119DA
2012-08-08 22:36 - 2012-08-08 22:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41F7724CB3DB06BB
2012-08-08 22:32 - 2012-08-08 22:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB932C6E4E8EE438
2012-08-08 22:28 - 2012-08-08 22:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF6939662C08E42F
2012-08-08 22:24 - 2012-08-08 22:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.84D746227F91ED91
2012-08-08 22:21 - 2012-08-08 22:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFAAB1B4E5F9F605
2012-08-08 22:17 - 2012-08-08 22:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.92D0F8BF84305E11
2012-08-08 22:13 - 2012-08-08 22:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AB8B992F0731098
2012-08-08 22:10 - 2012-08-08 22:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD6D90A9500B7931
2012-08-08 22:06 - 2012-08-08 22:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1850E1E5AA25B05E
2012-08-08 22:02 - 2012-08-08 22:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.95653D6E21D04D7A
2012-08-08 21:58 - 2012-08-08 21:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8157058AD18E7DAD
2012-08-08 21:55 - 2012-08-08 21:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5D50F07DA5C2D33
2012-08-08 21:51 - 2012-08-08 21:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7E07AB1A607A4F6
2012-08-08 21:47 - 2012-08-08 21:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDF585E84251D56D
2012-08-08 21:44 - 2012-08-08 21:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C8B1AFF015DD2B2
2012-08-08 21:40 - 2012-08-08 21:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D95452728FAECF1
2012-08-08 21:36 - 2012-08-08 21:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E487623797CA617C
2012-08-08 21:32 - 2012-08-08 21:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB438F6E0B2FA2B3
2012-08-08 21:29 - 2012-08-08 21:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C674D1EB924FBB
2012-08-08 21:25 - 2012-08-08 21:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD82D5E5B3B3F72E
2012-08-08 21:21 - 2012-08-08 21:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.67D4F2D8521EED50
2012-08-08 21:17 - 2012-08-08 21:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B33C0521EDC3A884
2012-08-08 21:14 - 2012-08-08 21:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFB723BACF41163
2012-08-08 21:10 - 2012-08-08 21:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E391B3C556D5F42D
2012-08-08 21:06 - 2012-08-08 21:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7FE3577CD164308
2012-08-08 21:03 - 2012-08-08 21:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A5C086D4CB27A94
2012-08-08 20:59 - 2012-08-08 20:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BFB4D489EC266F59
2012-08-08 20:55 - 2012-08-08 20:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E141351D843D5ADB
2012-08-08 20:52 - 2012-08-08 20:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A851C2C7D67203C9
2012-08-08 20:48 - 2012-08-08 20:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1AC6CA500F0B944
2012-08-08 20:44 - 2012-08-08 20:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.877CC8F7C0654369
2012-08-08 20:40 - 2012-08-08 20:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2ABC066A6CB23ED5
2012-08-08 20:37 - 2012-08-08 20:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9FA810BD61820A5
2012-08-08 20:33 - 2012-08-08 20:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D87677A490E90540
2012-08-08 20:29 - 2012-08-08 20:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15B43CCED18E1D14
2012-08-08 20:26 - 2012-08-08 20:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FEB8266FBFAE7339
2012-08-08 20:22 - 2012-08-08 20:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2D9099DA5002738
2012-08-08 20:18 - 2012-08-08 20:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BACC871F522C30B
2012-08-08 20:15 - 2012-08-08 20:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B0AD15D1DF1B2C2
2012-08-08 20:11 - 2012-08-08 20:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB744F045A9AE235
2012-08-08 20:07 - 2012-08-08 20:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8AFD3E376FAC7CB2
2012-08-08 20:03 - 2012-08-08 20:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6235CC19A79237D3
2012-08-08 20:00 - 2012-08-08 20:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E444BD854315046
2012-08-08 19:56 - 2012-08-08 19:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA421768F2A74BA3
2012-08-08 19:52 - 2012-08-08 19:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A83BD7A5E23A315A
2012-08-08 19:49 - 2012-08-08 19:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C641E19DDEE2810
2012-08-08 19:45 - 2012-08-08 19:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BD1E6FA221046C63
2012-08-08 19:41 - 2012-08-08 19:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E190B06FB01BE3D0
2012-08-08 19:38 - 2012-08-08 19:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9160897B82EC0185
2012-08-08 19:34 - 2012-08-08 19:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D46D985EE0FDAD1
2012-08-08 19:30 - 2012-08-08 19:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1457FD0B1E7100F5
2012-08-08 19:27 - 2012-08-08 19:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1798DADE265F227
2012-08-08 18:44 - 2012-08-08 18:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C6A2AF826E71567D
2012-08-08 17:05 - 2012-08-08 17:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E6079324380AA7FD
2012-08-08 16:26 - 2012-08-08 16:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7DAC7B56D306001E
2012-08-08 15:48 - 2012-08-08 15:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74F55DFF4C3A075E
 
2012-08-08 13:51 - 2012-08-08 13:51 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\frank\Desktop\tdsskiller.exe
2012-08-08 13:50 - 2012-08-08 13:50 - 04727110 ____A (Swearware) C:\Users\frank\Desktop\ComboFix.exe
2012-08-08 13:43 - 2012-08-08 13:43 - 00881494 ____A C:\Users\frank\Desktop\SecurityCheck.exe
2012-08-08 12:02 - 2012-08-08 12:02 - 00000000 ____D C:\Users\frank\AppData\Local\Macromedia
2012-08-08 11:51 - 2012-08-08 11:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.349AEC5204EBA773
2012-08-08 11:47 - 2012-08-08 11:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A4B1FF6622C08F08
2012-08-08 11:44 - 2012-08-08 11:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62B676A461F41E7A
2012-08-08 11:41 - 2012-08-08 11:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7CEB3957CE766A8A
2012-08-08 11:37 - 2012-08-08 11:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89FF8A9A97317FFE
2012-08-08 11:37 - 2012-08-08 11:37 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\uwmbzbaf.sys
2012-08-08 11:34 - 2012-08-08 11:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E8C07ED33CE05A6
2012-08-08 11:31 - 2012-08-08 11:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4E6A751AE46DA9A1
2012-08-08 11:30 - 2012-08-08 11:30 - 00017668 ____A C:\Users\frank\TsAllUsr.Dat
2012-08-08 11:23 - 2012-08-08 11:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8A911C064868CAD
2012-08-08 11:17 - 2012-08-08 11:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B2FF333A3177CB21
2012-08-08 11:14 - 2012-08-08 11:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.399D3E0F3FB865AB
2012-08-08 11:11 - 2012-08-08 11:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB91755D859AF796
2012-08-08 11:07 - 2012-08-08 11:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F93FF9FD3B95AF9
2012-08-08 11:03 - 2012-08-08 11:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.216AEC2C1AD8CA1D
2012-08-08 10:54 - 2012-08-08 10:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-08 10:54 - 2012-08-08 10:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-08 10:52 - 2012-08-08 10:52 - 00000000 ____D C:\Windows\System32\SPReview
2012-08-08 10:45 - 2012-08-08 10:45 - 00000017 ____A C:\Users\Rick\AppData\Local\resmon.resmoncfg
2012-08-08 09:56 - 2012-08-08 09:57 - 12621696 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\mseinstall.exe
2012-08-08 09:51 - 2012-08-08 09:51 - 00000000 ____D C:\Users\Rick\AppData\Roaming\Malwarebytes
2012-08-08 09:32 - 2012-08-08 09:32 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-08 09:32 - 2012-08-08 09:32 - 00000000 ____D C:\Users\frank\AppData\Roaming\Malwarebytes
2012-08-08 09:32 - 2012-08-08 09:32 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-08-08 09:32 - 2012-08-08 09:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-08 09:32 - 2012-07-03 10:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-08 09:30 - 2012-08-08 09:30 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\frank\Downloads\mbam-setup-1.62.0.1300.exe
2012-08-08 09:23 - 2012-08-08 09:23 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-08 09:22 - 2012-08-08 09:22 - 00000000 ____A C:\extensions.sqlite
2012-08-06 15:19 - 2012-08-06 15:19 - 00007607 ____A C:\Users\frank\AppData\Local\Resmon.ResmonCfg
2012-08-02 06:17 - 2012-08-02 06:17 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (3).lnk
2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut.lnk
2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (2).lnk
2012-07-27 08:03 - 2012-07-27 14:58 - 00000000 ____D C:\imagetmp
2012-07-27 07:14 - 2012-07-27 07:14 - 00034770 ____A C:\Users\frank\Desktop\custlist.TXT
2012-07-25 12:08 - 2012-07-25 12:08 - 00000000 ____D C:\Users\frank\AppData\Roaming\SQL Anywhere 12
2012-07-24 07:30 - 2012-07-24 07:30 - 00000000 ____D C:\Users\Rick\AppData\Local\Help
2012-07-24 07:29 - 2012-07-24 07:29 - 00000000 ____D C:\Users\Rick\AppData\Roaming\SQL Anywhere 12
2012-07-19 13:34 - 2012-07-19 13:34 - 00000000 ____D C:\Users\Install\AppData\Local\Adobe
2012-07-19 12:35 - 2012-07-19 12:36 - 00000000 ____D C:\Users\Install\AppData\Roaming\Mozilla
2012-07-19 12:35 - 2012-07-19 12:35 - 00000000 ____D C:\Users\Install\AppData\Local\Mozilla
2012-07-18 12:48 - 2012-07-18 12:48 - 00001349 ____A C:\Users\Install\Desktop\Profit Tools.lnk
2012-07-18 12:38 - 2012-07-18 12:38 - 00000000 ____D C:\Users\Install\AppData\Roaming\Help
2012-07-18 12:38 - 2012-07-18 12:38 - 00000000 ____D C:\Users\Install\AppData\Local\Help
2012-07-18 12:37 - 2012-07-24 07:32 - 00000755 ____A C:\Users\Install\Desktop\Profit Tools Help.lnk
2012-07-18 12:36 - 2012-07-19 13:34 - 00000000 ____D C:\Users\Install\AppData\Roaming\Adobe
2012-07-18 12:36 - 2009-08-04 09:56 - 00296960 ____A (Microsoft Corporation) C:\Windows\winhlp32.exe
2012-07-18 12:36 - 2009-08-04 09:55 - 00195072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftsrch.dll
2012-07-18 12:36 - 2009-08-04 09:55 - 00195072 ____A (Microsoft Corporation) C:\Windows\System32\ftsrch.dll
2012-07-18 12:36 - 2009-08-04 09:55 - 00010240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftlx041e.dll
2012-07-18 12:36 - 2009-08-04 09:55 - 00010240 ____A (Microsoft Corporation) C:\Windows\System32\ftlx041e.dll
2012-07-18 12:36 - 2009-08-04 09:55 - 00009216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftlx0411.dll
2012-07-18 12:36 - 2009-08-04 09:55 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\ftlx0411.dll
2012-07-18 12:11 - 2012-07-18 12:11 - 00000000 ____D C:\Users\Install\AppData\Roaming\WinRAR
2012-07-18 10:28 - 2012-07-18 12:32 - 00000000 ____D C:\Users\Public\Documents\Sybase Central 6.1.0
2012-07-18 10:27 - 2012-07-18 10:31 - 00000166 ____A C:\Windows\ODBC.INI
2012-07-18 10:27 - 2012-07-18 10:31 - 00000000 ____D C:\Users\Install\AppData\Roaming\SQL Anywhere 12
2012-07-18 10:25 - 2012-07-18 12:30 - 00000000 ____D C:\Users\Install\sybase
2012-07-18 10:25 - 2012-07-18 10:25 - 00000000 ____D C:\Users\Public\Documents\DBISQL 12.0.1
2012-07-18 10:06 - 2012-07-18 10:06 - 00103272 ____A C:\Users\Install\GoToAssistDownloadHelper.exe
2012-07-18 10:06 - 2012-07-18 10:06 - 00000000 ____D C:\Users\Install\AppData\Local\Deployment
2012-07-18 10:06 - 2012-07-18 10:06 - 00000000 ____D C:\Users\Install\AppData\Local\Citrix
2012-07-18 10:06 - 2012-07-18 10:06 - 00000000 ____D C:\Users\Install\AppData\Local\Apps\2.0
2012-07-18 10:03 - 2012-07-18 10:25 - 00000000 ____D C:\users\Install
2012-07-18 10:03 - 2012-07-18 10:03 - 00113664 ____A C:\Users\Install\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 10:03 - 2012-07-18 10:03 - 00000020 __ASH C:\Users\Install\ntuser.ini
2012-07-18 10:03 - 2012-07-18 10:03 - 00000000 ____D C:\Users\Install\AppData\Roaming\Apple Computer
2012-07-18 10:03 - 2012-07-18 10:03 - 00000000 ____D C:\Users\Install\AppData\Local\Intuit
2012-07-18 10:03 - 2012-07-18 10:03 - 00000000 ____D C:\Users\Install\AppData\Local\Apple Computer
2012-07-18 10:03 - 2011-10-11 00:01 - 00000000 ____D C:\Users\Install\AppData\Local\Microsoft Help
2012-07-18 10:03 - 2011-02-23 08:42 - 00000000 ____D C:\Users\Install\AppData\Roaming\Macromedia
2012-07-18 09:53 - 2012-07-18 12:12 - 00000000 ____D C:\Users\All Users\SQL Anywhere 12
2012-07-18 09:30 - 2004-07-12 10:50 - 00155648 ____A (Sun Microsystems©) C:\Windows\SysWOW64\JavaAccessBridge.dll
2012-07-18 09:30 - 2004-07-12 10:50 - 00081920 ____A (Sun Microsystems©) C:\Windows\SysWOW64\WindowsAccessBridge.dll
2012-07-18 09:30 - 2004-07-12 10:50 - 00032768 ____A (Sun Microsystems©) C:\Windows\SysWOW64\JAWTAccessBridge.dll
2012-07-18 09:29 - 2012-07-18 09:29 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-07-18 08:06 - 2012-07-18 08:06 - 00103272 ____A C:\Users\frank\GoToAssistDownloadHelper.exe
2012-07-18 08:06 - 2012-07-18 08:06 - 00000000 ____D C:\Users\frank\AppData\Local\Deployment
2012-07-18 08:06 - 2012-07-18 08:06 - 00000000 ____D C:\Users\frank\AppData\Local\Citrix
2012-07-18 08:06 - 2012-07-18 08:06 - 00000000 ____D C:\Users\frank\AppData\Local\Apps\2.0
2012-07-12 07:59 - 2012-07-12 07:59 - 00318904 ____A (Microsoft Corporation) C:\Users\frank\Downloads\wmpfirefoxplugin.exe
2012-07-12 07:53 - 2012-07-12 07:53 - 00318904 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\wmpfirefoxplugin(1).exe
2012-07-12 07:52 - 2012-07-12 07:52 - 00000195 ____A C:\Users\Rick\Downloads\wmpfirefoxplugin.exe
2012-07-11 00:05 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 00:05 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 00:05 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 00:05 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 00:05 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 00:05 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 00:05 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 00:05 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 00:05 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 00:05 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 00:05 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 00:05 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 00:05 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 00:05 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 00:05 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 00:05 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 00:05 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 00:05 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 00:05 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 00:05 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 00:05 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 00:05 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 00:05 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 00:05 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 00:05 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 00:05 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 00:05 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 00:05 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 00:01 - 2012-06-11 19:02 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 12:40 - 2012-06-08 21:30 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 12:40 - 2012-06-08 20:46 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 12:40 - 2012-06-05 21:50 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 12:40 - 2012-06-05 21:50 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 12:40 - 2012-06-05 21:09 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 12:40 - 2012-06-05 21:09 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 12:40 - 2012-06-01 21:38 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 12:40 - 2012-06-01 21:38 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 12:40 - 2012-06-01 21:37 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 12:40 - 2012-06-01 21:27 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 12:40 - 2012-06-01 21:27 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 12:40 - 2012-06-01 20:48 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 12:40 - 2012-06-01 20:48 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 12:40 - 2012-06-01 20:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 12:40 - 2012-06-01 20:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
============ 3 Months Modified Files ========================
2012-08-09 07:39 - 2009-07-13 20:49 - 00014048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-09 07:39 - 2009-07-13 20:49 - 00014048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-09 07:34 - 2011-02-18 10:42 - 01543552 ____A C:\Windows\WindowsUpdate.log
2012-08-09 07:32 - 2012-05-02 07:49 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-09 05:55 - 2009-09-22 11:32 - 00851644 ____A C:\Windows\System32\perfh00A.dat
2012-08-09 05:55 - 2009-09-22 11:32 - 00195538 ____A C:\Windows\System32\perfc00A.dat
2012-08-09 05:55 - 2009-09-22 11:18 - 00845594 ____A C:\Windows\System32\perfh010.dat
2012-08-09 05:55 - 2009-09-22 11:18 - 00182856 ____A C:\Windows\System32\perfc010.dat
2012-08-09 05:55 - 2009-09-22 11:06 - 00808956 ____A C:\Windows\System32\perfh007.dat
2012-08-09 05:55 - 2009-09-22 11:06 - 00183696 ____A C:\Windows\System32\perfc007.dat
2012-08-09 05:55 - 2009-09-22 10:53 - 00856886 ____A C:\Windows\System32\perfh00C.dat
2012-08-09 05:55 - 2009-09-22 10:53 - 00187520 ____A C:\Windows\System32\perfc00C.dat
2012-08-09 05:55 - 2009-07-13 21:10 - 05006346 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-09 05:54 - 2009-07-13 20:56 - 00039600 ____A C:\Windows\setupact.log
2012-08-09 05:50 - 2012-08-09 06:04 - 00607260 ____R (Swearware) C:\Users\frank\Desktop\dds.com
2012-08-09 05:49 - 2012-08-09 06:04 - 00302592 ____A C:\Users\frank\Desktop\wy82hjq3.exe
2012-08-09 05:43 - 2009-07-13 21:06 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-09 05:40 - 2012-08-09 05:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6639107541643CB4
2012-08-09 05:36 - 2012-08-09 05:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB9A1010890AFFEE
2012-08-09 05:33 - 2012-08-09 05:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72E5362A0BD14F2F
2012-08-09 05:29 - 2012-08-09 05:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.44E5779334A7D83E
2012-08-09 05:25 - 2012-08-09 05:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C216B261A64DDCBC
2012-08-09 05:21 - 2012-08-09 05:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5DCF895404AEBB8
2012-08-09 05:18 - 2012-08-09 05:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.69C9D721940BD4BF
2012-08-09 05:14 - 2012-08-09 05:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D82F043A8FEC7CEE
2012-08-09 05:10 - 2012-08-09 05:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8F4E0834D8EFEBC
2012-08-09 05:07 - 2012-08-09 05:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D38393B1BA7246B
2012-08-09 05:03 - 2012-08-09 05:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8071CB9A75191EEB
2012-08-09 04:59 - 2012-08-09 04:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C3011F7E4A785767
2012-08-09 04:55 - 2012-08-09 04:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5EC0E1CF8093BB18
2012-08-09 04:52 - 2012-08-09 04:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9555716B5A2BBFD
2012-08-09 04:48 - 2012-08-09 04:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECBEDE6FCB51C87C
2012-08-09 04:44 - 2012-08-09 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBCDD9B8CFE3F464
2012-08-09 04:40 - 2012-08-09 04:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5A9CE81858F92C0D
2012-08-09 04:37 - 2012-08-09 04:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0698789F4ECFC9
2012-08-09 04:33 - 2012-08-09 04:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18B9A90766DC53F5
2012-08-09 04:29 - 2012-08-09 04:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F76E0F11B73876B
2012-08-09 04:26 - 2012-08-09 04:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0844593D2681CF5
2012-08-09 04:22 - 2012-08-09 04:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81A047C03CDC542
2012-08-09 04:18 - 2012-08-09 04:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CEEC5D6C4268E8BC
2012-08-09 04:14 - 2012-08-09 04:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CFD1A50C9191ED21
2012-08-09 04:11 - 2012-08-09 04:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.290B7DA9EDF03385
2012-08-09 04:07 - 2012-08-09 04:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EC804FF5F0FCB85
2012-08-09 04:03 - 2012-08-09 04:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BAA36DBB942413A
2012-08-09 04:00 - 2012-08-09 04:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51DEDEC7ECAFFEFC
2012-08-09 03:56 - 2012-08-09 03:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.880FD5B52EDAAB2C
2012-08-09 03:52 - 2012-08-09 03:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D2EB03BE6D52EB3
2012-08-09 03:48 - 2012-08-09 03:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E65AE579A6C2D61
2012-08-09 03:45 - 2012-08-09 03:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AEDCC9B8D34C361D
2012-08-09 03:41 - 2012-08-09 03:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9C2DC445AF4CAA2
2012-08-09 03:37 - 2012-08-09 03:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C621C95988BA64A
2012-08-09 03:33 - 2012-08-09 03:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DFEBD18377C0AC
2012-08-09 03:30 - 2012-08-09 03:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4CBD7315F69B608B
2012-08-09 03:26 - 2012-08-09 03:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.940A3B643315666D
2012-08-09 03:22 - 2012-08-09 03:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14E93EEEDAAABB17
2012-08-09 03:19 - 2012-08-09 03:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C924DDED6F0FC518
2012-08-09 03:15 - 2012-08-09 03:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2343B3FE8036872A
2012-08-09 03:11 - 2012-08-09 03:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11E81B2BECDB7BC1
2012-08-09 03:07 - 2012-08-09 03:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B261B290D7888CA
2012-08-09 03:04 - 2012-08-09 03:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9692C5AFDCD11D02
2012-08-09 03:00 - 2012-08-09 03:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77291BE6F1228A36
2012-08-09 02:56 - 2012-08-09 02:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9E993F14328744BC
2012-08-09 02:53 - 2012-08-09 02:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B865B3BC9419F04
2012-08-09 02:49 - 2012-08-09 02:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30CAEB12CE87E691
2012-08-09 02:45 - 2012-08-09 02:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.049F9AF61F17D75C
2012-08-09 02:41 - 2012-08-09 02:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.09123E38065282F7
2012-08-09 02:38 - 2012-08-09 02:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.876360F33C92B2C5
2012-08-09 02:34 - 2012-08-09 02:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7C527C7A8B6F50B
2012-08-09 02:30 - 2012-08-09 02:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1D21B448BF10CBA
2012-08-09 02:26 - 2012-08-09 02:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F8E9B38B76A8B0D
2012-08-09 02:23 - 2012-08-09 02:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129B404282E5AE3C
2012-08-09 02:19 - 2012-08-09 02:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2B916F13308CA13
2012-08-09 02:15 - 2012-08-09 02:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4BD5DEF9F7587255
2012-08-09 02:12 - 2012-08-09 02:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94DDAA4175F314B1
2012-08-09 02:08 - 2012-08-09 02:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC302FB3D17C0642
2012-08-09 02:04 - 2012-08-09 02:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DE76FBB01FA45BD3
2012-08-09 02:00 - 2012-08-09 02:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A87AC973177E679
2012-08-09 01:57 - 2012-08-09 01:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FCF899EB194B3AD0
2012-08-09 01:53 - 2012-08-09 01:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1369A8411769F4CD
2012-08-09 01:49 - 2012-08-09 01:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D86BF51DC13B8230
2012-08-09 01:46 - 2012-08-09 01:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B55066EB6B9EEE95
2012-08-09 01:42 - 2012-08-09 01:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87F78F64AC9E978C
2012-08-09 01:38 - 2012-08-09 01:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.46CE1BF2FE39E10B
2012-08-09 01:34 - 2012-08-09 01:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51E9ECFC90321BD5
2012-08-09 01:31 - 2012-08-09 01:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC3CA10830B61336
2012-08-09 01:27 - 2012-08-09 01:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D35B473D6428979
2012-08-09 01:23 - 2012-08-09 01:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A993C76224D14F85
2012-08-09 01:19 - 2012-08-09 01:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B530A5047C73A16A
2012-08-09 01:16 - 2012-08-09 01:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63EAEA5537A808B5
2012-08-09 01:12 - 2012-08-09 01:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD3081176DD59A69
2012-08-09 01:08 - 2012-08-09 01:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F73A1B4CE90B2A7D
2012-08-09 01:05 - 2012-08-09 01:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1A100BAFEECC053
2012-08-09 01:01 - 2012-08-09 01:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.711EEA03DCC5BF9F
2012-08-09 00:57 - 2012-08-09 00:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F091C807FAD0E981
2012-08-09 00:53 - 2012-08-09 00:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9698E79E01BEE1D6
2012-08-09 00:50 - 2012-08-09 00:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FD0E73D6E48DF2DB
2012-08-09 00:46 - 2012-08-09 00:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.373F4D971A931FA2
2012-08-09 00:42 - 2012-08-09 00:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC02870EA8A73758
2012-08-09 00:39 - 2012-08-09 00:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0DDA2AE7A9DE7737
2012-08-09 00:35 - 2012-08-09 00:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33C96B1604B8E4FB
2012-08-09 00:31 - 2012-08-09 00:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24D2F2CA5DC1878C
2012-08-09 00:27 - 2012-08-09 00:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAD55A0BD1D3ACB3
2012-08-09 00:24 - 2012-08-09 00:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBB1583714D0E53F
2012-08-09 00:20 - 2012-08-09 00:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0474DDC0F56A6C98
2012-08-09 00:16 - 2012-08-09 00:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F747776EEE440CA
2012-08-09 00:12 - 2012-08-09 00:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47A1588EEADC79D9
2012-08-09 00:09 - 2012-08-09 00:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA4A3BC2F6AC12CE
2012-08-09 00:05 - 2012-08-09 00:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.155A2A2B10C655C5
2012-08-09 00:01 - 2012-08-09 00:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0879AB483D626932
2012-08-08 23:58 - 2012-08-08 23:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10268C8E76D31502
2012-08-08 23:54 - 2012-08-08 23:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.834B2828FA183CA3
2012-08-08 23:50 - 2012-08-08 23:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2142AABD9A6E03D4
2012-08-08 23:46 - 2012-08-08 23:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7552E461AB63A6C1
2012-08-08 23:43 - 2012-08-08 23:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B6638D582CB5239D
2012-08-08 23:39 - 2012-08-08 23:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0397A3428D3804D4
2012-08-08 23:35 - 2012-08-08 23:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E51DC69051BEA1FC
2012-08-08 23:31 - 2012-08-08 23:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3069EC68AB2E7B57
2012-08-08 23:28 - 2012-08-08 23:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.541103CDEEBBC7B1
2012-08-08 23:24 - 2012-08-08 23:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.00546D2F107C88F6
2012-08-08 23:20 - 2012-08-08 23:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.59B092850D586002
2012-08-08 23:17 - 2012-08-08 23:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88EAA525011D6CD7
2012-08-08 23:13 - 2012-08-08 23:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AFE3CD7BE4C6B273
2012-08-08 23:09 - 2012-08-08 23:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9AE197152C0B6DBE
2012-08-08 23:05 - 2012-08-08 23:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D3C9F9D497408C2
2012-08-08 23:02 - 2012-08-08 23:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169ABF06B61C7DC
2012-08-08 22:58 - 2012-08-08 22:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4FA4C6DEC7FA457
2012-08-08 22:54 - 2012-08-08 22:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F0206D8736558AF0
2012-08-08 22:51 - 2012-08-08 22:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF294788B62887CD
2012-08-08 22:47 - 2012-08-08 22:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7F729FF837B7E1
2012-08-08 22:43 - 2012-08-08 22:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0A702750A1684A1D
2012-08-08 22:39 - 2012-08-08 22:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D82152450C119DA
2012-08-08 22:36 - 2012-08-08 22:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41F7724CB3DB06BB
2012-08-08 22:32 - 2012-08-08 22:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB932C6E4E8EE438
2012-08-08 22:28 - 2012-08-08 22:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF6939662C08E42F
2012-08-08 22:24 - 2012-08-08 22:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.84D746227F91ED91
2012-08-08 22:21 - 2012-08-08 22:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFAAB1B4E5F9F605
2012-08-08 22:20 - 2009-07-13 21:06 - 00032618 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-08 22:17 - 2012-08-08 22:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.92D0F8BF84305E11
2012-08-08 22:13 - 2012-08-08 22:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AB8B992F0731098
2012-08-08 22:10 - 2012-08-08 22:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD6D90A9500B7931
2012-08-08 22:06 - 2012-08-08 22:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1850E1E5AA25B05E
2012-08-08 22:02 - 2012-08-08 22:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.95653D6E21D04D7A
2012-08-08 21:58 - 2012-08-08 21:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8157058AD18E7DAD
2012-08-08 21:55 - 2012-08-08 21:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5D50F07DA5C2D33
2012-08-08 21:51 - 2012-08-08 21:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7E07AB1A607A4F6
2012-08-08 21:47 - 2012-08-08 21:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDF585E84251D56D
2012-08-08 21:44 - 2012-08-08 21:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C8B1AFF015DD2B2
2012-08-08 21:40 - 2012-08-08 21:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D95452728FAECF1
2012-08-08 21:36 - 2012-08-08 21:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E487623797CA617C
2012-08-08 21:32 - 2012-08-08 21:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB438F6E0B2FA2B3
2012-08-08 21:29 - 2012-08-08 21:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C674D1EB924FBB
2012-08-08 21:25 - 2012-08-08 21:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD82D5E5B3B3F72E
2012-08-08 21:21 - 2012-08-08 21:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.67D4F2D8521EED50
2012-08-08 21:17 - 2012-08-08 21:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B33C0521EDC3A884
2012-08-08 21:14 - 2012-08-08 21:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFB723BACF41163
2012-08-08 21:10 - 2012-08-08 21:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E391B3C556D5F42D
2012-08-08 21:06 - 2012-08-08 21:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7FE3577CD164308
2012-08-08 21:03 - 2012-08-08 21:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A5C086D4CB27A94
2012-08-08 20:59 - 2012-08-08 20:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BFB4D489EC266F59
2012-08-08 20:55 - 2012-08-08 20:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E141351D843D5ADB
2012-08-08 20:52 - 2012-08-08 20:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A851C2C7D67203C9
2012-08-08 20:48 - 2012-08-08 20:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1AC6CA500F0B944
2012-08-08 20:44 - 2012-08-08 20:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.877CC8F7C0654369
2012-08-08 20:40 - 2012-08-08 20:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2ABC066A6CB23ED5
2012-08-08 20:37 - 2012-08-08 20:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9FA810BD61820A5
2012-08-08 20:33 - 2012-08-08 20:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D87677A490E90540
2012-08-08 20:29 - 2012-08-08 20:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15B43CCED18E1D14
2012-08-08 20:26 - 2012-08-08 20:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FEB8266FBFAE7339
2012-08-08 20:22 - 2012-08-08 20:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2D9099DA5002738
2012-08-08 20:18 - 2012-08-08 20:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BACC871F522C30B
2012-08-08 20:15 - 2012-08-08 20:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B0AD15D1DF1B2C2
2012-08-08 20:11 - 2012-08-08 20:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB744F045A9AE235
2012-08-08 20:07 - 2012-08-08 20:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8AFD3E376FAC7CB2
2012-08-08 20:03 - 2012-08-08 20:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6235CC19A79237D3
2012-08-08 20:00 - 2012-08-08 20:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E444BD854315046
2012-08-08 19:56 - 2012-08-08 19:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA421768F2A74BA3
2012-08-08 19:52 - 2012-08-08 19:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A83BD7A5E23A315A
2012-08-08 19:49 - 2012-08-08 19:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C641E19DDEE2810
2012-08-08 19:45 - 2012-08-08 19:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BD1E6FA221046C63
2012-08-08 19:41 - 2012-08-08 19:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E190B06FB01BE3D0
2012-08-08 19:38 - 2012-08-08 19:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9160897B82EC0185
2012-08-08 19:34 - 2012-08-08 19:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D46D985EE0FDAD1
2012-08-08 19:30 - 2012-08-08 19:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1457FD0B1E7100F5
2012-08-08 19:27 - 2012-08-08 19:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1798DADE265F227
2012-08-08 19:23 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-08 18:44 - 2012-08-08 18:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C6A2AF826E71567D
2012-08-08 17:05 - 2012-08-08 17:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E6079324380AA7FD
2012-08-08 16:26 - 2012-08-08 16:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7DAC7B56D306001E
2012-08-08 16:01 - 2011-03-25 18:19 - 00000402 ___AH C:\Windows\Tasks\GG Logistics Corp. 1301105924.job
2012-08-08 15:48 - 2012-08-08 15:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74F55DFF4C3A075E
2012-08-08 14:07 - 2011-02-22 10:47 - 00053828 ____A C:\Windows\PFRO.log
2012-08-08 13:51 - 2012-08-08 13:51 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\frank\Desktop\tdsskiller.exe
2012-08-08 13:50 - 2012-08-08 13:50 - 04727110 ____A (Swearware) C:\Users\frank\Desktop\ComboFix.exe
2012-08-08 13:43 - 2012-08-08 13:43 - 00881494 ____A C:\Users\frank\Desktop\SecurityCheck.exe
2012-08-08 12:50 - 2011-02-21 14:24 - 00000072 ____A C:\Users\Public\LMDebug.log
2012-08-08 11:51 - 2012-08-08 11:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.349AEC5204EBA773
2012-08-08 11:47 - 2012-08-08 11:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A4B1FF6622C08F08
2012-08-08 11:44 - 2012-08-08 11:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62B676A461F41E7A
2012-08-08 11:41 - 2012-08-08 11:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7CEB3957CE766A8A
2012-08-08 11:37 - 2012-08-08 11:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89FF8A9A97317FFE
2012-08-08 11:37 - 2012-08-08 11:37 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\uwmbzbaf.sys
2012-08-08 11:34 - 2012-08-08 11:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E8C07ED33CE05A6
2012-08-08 11:31 - 2012-08-08 11:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4E6A751AE46DA9A1
2012-08-08 11:30 - 2012-08-08 11:30 - 00017668 ____A C:\Users\frank\TsAllUsr.Dat
2012-08-08 11:27 - 2011-02-22 14:29 - 00002243 ____A C:\Windows\epplauncher.mif
2012-08-08 11:23 - 2012-08-08 11:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8A911C064868CAD
2012-08-08 11:17 - 2012-08-08 11:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B2FF333A3177CB21
2012-08-08 11:14 - 2012-08-08 11:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.399D3E0F3FB865AB
2012-08-08 11:11 - 2012-08-08 11:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB91755D859AF796
2012-08-08 11:07 - 2012-08-08 11:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F93FF9FD3B95AF9
2012-08-08 11:03 - 2012-08-08 11:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.216AEC2C1AD8CA1D
2012-08-08 10:54 - 2011-02-21 13:48 - 05074708 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-08 10:45 - 2012-08-08 10:45 - 00000017 ____A C:\Users\Rick\AppData\Local\resmon.resmoncfg
2012-08-08 09:57 - 2012-08-08 09:56 - 12621696 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\mseinstall.exe
2012-08-08 09:32 - 2012-08-08 09:32 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-08 09:30 - 2012-08-08 09:30 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\frank\Downloads\mbam-setup-1.62.0.1300.exe
2012-08-08 09:22 - 2012-08-08 09:22 - 00000000 ____A C:\extensions.sqlite
2012-08-08 09:20 - 2011-02-23 07:05 - 00000462 _RASH C:\Users\All Users\ntuser.pol
2012-08-06 15:19 - 2012-08-06 15:19 - 00007607 ____A C:\Users\frank\AppData\Local\Resmon.ResmonCfg
2012-08-02 10:32 - 2012-05-02 07:49 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-02 10:32 - 2011-06-29 05:53 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-02 06:17 - 2012-08-02 06:17 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (3).lnk
2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut.lnk
2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (2).lnk
2012-07-27 07:14 - 2012-07-27 07:14 - 00034770 ____A C:\Users\frank\Desktop\custlist.TXT
2012-07-24 07:32 - 2012-07-18 12:37 - 00000755 ____A C:\Users\Install\Desktop\Profit Tools Help.lnk
2012-07-18 12:48 - 2012-07-18 12:48 - 00001349 ____A C:\Users\Install\Desktop\Profit Tools.lnk
2012-07-18 10:31 - 2012-07-18 10:27 - 00000166 ____A C:\Windows\ODBC.INI
2012-07-18 10:18 - 2011-02-21 14:07 - 00113664 ____A C:\Users\Rick\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 10:06 - 2012-07-18 10:06 - 00103272 ____A C:\Users\Install\GoToAssistDownloadHelper.exe
2012-07-18 10:03 - 2012-07-18 10:03 - 00113664 ____A C:\Users\Install\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 10:03 - 2012-07-18 10:03 - 00000020 __ASH C:\Users\Install\ntuser.ini
2012-07-18 09:55 - 2011-03-18 08:09 - 00113664 ____A C:\Users\MaryBeth\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 09:54 - 2011-07-06 13:15 - 00113664 ____A C:\Users\frank\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 09:53 - 2009-07-13 20:49 - 00422368 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-18 08:06 - 2012-07-18 08:06 - 00103272 ____A C:\Users\frank\GoToAssistDownloadHelper.exe
2012-07-16 07:29 - 2012-01-26 08:04 - 00000036 ___AH C:\Windows\SysWOW64\f9t.dat
2012-07-12 07:59 - 2012-07-12 07:59 - 00318904 ____A (Microsoft Corporation) C:\Users\frank\Downloads\wmpfirefoxplugin.exe
2012-07-12 07:53 - 2012-07-12 07:53 - 00318904 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\wmpfirefoxplugin(1).exe
2012-07-12 07:52 - 2012-07-12 07:52 - 00000195 ____A C:\Users\Rick\Downloads\wmpfirefoxplugin.exe
2012-07-11 00:02 - 2011-02-21 08:49 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-03 10:46 - 2012-08-08 09:32 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-26 13:12 - 2012-06-26 13:12 - 00008467 ____A C:\Users\Rick\Documents\06262012.xls
2012-06-19 10:17 - 2012-06-19 10:17 - 00000000 ___AH C:\Users\Rick\Documents\Default.rdp
2012-06-13 14:32 - 2012-05-25 11:59 - 00011819 ____A C:\Users\nick\Documents\Budget.xlsx
2012-06-11 19:02 - 2012-07-11 00:01 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:30 - 2012-07-10 12:40 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:46 - 2012-07-10 12:40 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 05:39 - 2012-06-08 05:39 - 00026112 ____A C:\Users\frank\Desktop\vacation.oft
2012-06-06 08:31 - 2012-06-06 08:31 - 00741744 ____A (RealVNC Ltd. ) C:\Users\frank\Downloads\vnc-4_1_3-x86_win32.exe
 
2012-06-05 21:50 - 2012-07-10 12:40 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:50 - 2012-07-10 12:40 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:09 - 2012-07-10 12:40 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:09 - 2012-07-10 12:40 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 10:56 - 2012-06-05 10:55 - 01636224 ____A (Inbox.com, Inc. ) C:\Users\Rick\Downloads\MapsSetup.exe
2012-06-02 14:19 - 2012-06-21 05:05 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 05:05 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 05:05 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 05:05 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 05:05 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 05:05 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 05:05 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 12:19 - 2012-06-21 05:05 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:15 - 2012-06-21 05:05 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-11 00:05 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 00:05 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 00:05 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 00:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 00:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 00:05 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 00:05 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 00:05 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 00:05 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 00:05 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 00:05 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 00:05 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 00:05 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 00:05 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 00:05 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 00:05 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 00:05 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 00:05 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 00:05 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 00:05 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 00:05 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 00:05 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 00:05 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 00:05 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 00:05 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 00:05 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 00:05 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 00:05 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:38 - 2012-07-10 12:40 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:38 - 2012-07-10 12:40 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:37 - 2012-07-10 12:40 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:27 - 2012-07-10 12:40 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:27 - 2012-07-10 12:40 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:48 - 2012-07-10 12:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:48 - 2012-07-10 12:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:47 - 2012-07-10 12:40 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:42 - 2012-07-10 12:40 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 09:25 - 2011-02-21 10:46 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-25 14:19 - 2012-05-25 14:19 - 00009101 ____A C:\Users\Rick\Documents\nate.xlsx
2012-05-14 11:46 - 2012-05-14 11:46 - 00897520 ____A (Dyn, Inc.) C:\Users\frank\Downloads\DynUpSetup.exe
ZeroAccess:
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\@
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\L
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U\00000001.@
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U\80000000.@
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U\800000cb.@
ZeroAccess:
C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}
C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}\@
C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}\L
C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 6135.23 MB
Available physical RAM: 5415.39 MB
Total Pagefile: 6133.38 MB
Available Pagefile: 5415.73 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:98.13 GB) (Free:23.15 GB) NTFS
2 Drive e: (Data) (Fixed) (Total:738.97 GB) (Free:687.8 GB) NTFS
3 Drive f: (Iomega HDD) (Fixed) (Total:1863.01 GB) (Free:1734 GB) NTFS
4 Drive g: (USB DISK) (Removable) (Total:1.91 GB) (Free:1.91 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: () (Fixed) (Total:1 GB) (Free:0.95 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 838 GB 1024 KB
Disk 1 Online 1863 GB 1024 KB
Disk 2 Online 1961 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1024 MB 1024 KB
Partition 2 Primary 98 GB 1025 MB
Partition 3 Primary 738 GB 99 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y NTFS Partition 1024 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 98 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E Data NTFS Partition 738 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1863 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F Iomega HDD NTFS Partition 1863 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1960 MB 248 KB
==================================================================================
Disk: 2
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G USB DISK FAT Removable 1960 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-08 15:30
======================= End Of Log ==========================
 
Farbar Recovery Scan Tool Version: 08-08-2012 02
Ran by SYSTEM at 2012-08-09 11:31:52
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2012-08-08 19:23] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
====== End Of Search ======
 
Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.
On Windows XP: Now please boot into the UBCD.
Run FRST/FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Next....

Restart normally.

Update MSE, run full scan, report on any findings.

Then...

Please download the below tool named Rkill (courtesy of BleepingComputer.com) to your desktop.

There are 2 different versions. If one of them won't run then download and try to run the other one.

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

http://download.bleepingcomputer.com/grinler/beta/rkill.exe
http://download.bleepingcomputer.com/grinler/beta/iExplore.exe

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.

If normal mode still doesn't work, run the tool from safe mode.

When the scan is done Notepad will open with rKill log.
Post it in your next reply.

NOTE. rKill.txt log will also be present on your desktop.
 

Attachments

  • fixlist.txt
    24 KB · Views: 4
Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 08-08-2012 02
Ran by SYSTEM at 2012-08-09 11:49:28 Run:1
Running from G:\

==============================================

HKEY_LOCAL_MACHINE\System\ControlSet002\Control\Session Manager\SubSystems\\Windows No ZeroAccess entry found.
C:\Windows\System32\consrv.dll not found.
C:\Windows\System32\services.exe.6639107541643CB4 moved successfully.
C:\Windows\System32\services.exe.349AEC5204EBA773 moved successfully.
C:\Windows\System32\services.exe.A4B1FF6622C08F08 moved successfully.
C:\Windows\System32\services.exe.62B676A461F41E7A moved successfully.
C:\Windows\System32\services.exe.7CEB3957CE766A8A moved successfully.
C:\Windows\System32\services.exe.89FF8A9A97317FFE moved successfully.
C:\Windows\System32\Drivers\uwmbzbaf.sys moved successfully.
C:\Windows\System32\services.exe.1E8C07ED33CE05A6 moved successfully.
C:\Windows\System32\services.exe.4E6A751AE46DA9A1 moved successfully.
C:\Windows\System32\services.exe.D8A911C064868CAD moved successfully.
C:\Windows\System32\services.exe.B2FF333A3177CB21 moved successfully.
C:\Windows\System32\services.exe.399D3E0F3FB865AB moved successfully.
C:\Windows\System32\services.exe.FB91755D859AF796 moved successfully.
C:\Windows\System32\services.exe.0F93FF9FD3B95AF9 moved successfully.
C:\Windows\System32\services.exe.216AEC2C1AD8CA1D moved successfully.
C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88} moved successfully.
C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88} moved successfully.
C:\Windows\System32\services.exe moved successfully.
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe copied successfully to C:\Windows\System32\services.exe

==== End of Fixlog ====
 
Scan result of Farbar Recovery Scan Tool Version: 08-08-2012 02
Ran by SYSTEM at 09-08-2012 12:02:48
Running from F:\
Windows Server 2008 R2 Standard (X64) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [QLogicSaveSystemInfo] rundll32.exe qlco1006.dll,QLSaveSystemInfo [x]
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [2305912 2012-06-18] (Intuit Inc. All rights reserved.)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2012-02-23] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKU\MaryBeth\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKU\Rick\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 68.94.156.1
Tcpip\..\Interfaces\{B0A35114-EF36-4060-B305-19D57C618B96}: [NameServer]208.67.222.222,208.67.220.220
Lsa: [Notification Packages] scecli
rassfm
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Dyn Updater Tray Icon.lnk
ShortcutTarget: Dyn Updater Tray Icon.lnk -> C:\Program Files (x86)\Dyn Updater\DynTray.exe (Dyn, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Intuit Data Protect.lnk
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk
ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files (x86)\Intuit\QuickBooks 2011\QBW32.EXE (Intuit Inc.)
Startup: C:\Users\frank\Start Menu\Programs\Startup\hs_err_pid5788.log ()
Startup: C:\Users\frank\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\MaryBeth\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\nick\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Rick\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ======
2 atnthost; "C:\ProgramData\webex\MyWebEx\319\atnthost.exe" [16776 2011-11-10] (WebEx Communications, Inc.)
2 Dyn Updater; C:\Program Files (x86)\Dyn Updater\DynUpSvc.exe [95608 2011-11-15] (Dyn, Inc.)
3 FCRegSvc; C:\Windows\System32\FCRegSvc.dll [25600 2009-07-13] (Microsoft Corporation)
2 HP Digital Sending Software; "C:\Program Files (x86)\Hewlett-Packard\HP Digital Sending Software 4.91\Filesystems\Core\bin\XP-x86\Release\HP.Dss.App.WinService.exe" [16440 2011-03-08] (Hewlett-Packard)
2 McAfee SiteAdvisor Service; C:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [103472 2012-06-15] (McAfee, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 MSSQL$HPDSS; "C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sHPDSS [29293408 2010-12-10] (Microsoft Corporation)
2 NetPipeActivator; "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" [116560 2009-06-10] (Microsoft Corporation)
2 NetTcpActivator; "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" [116560 2009-06-10] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
3 QuickBooksDB20; C:\PROGRA~2\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB20 [678912 2009-08-18] (Intuit, Inc.)
3 QuickBooksDB21; C:\PROGRA~2\Intuit\QUICKB~2\QBDBMgrN.exe -hvQuickBooksDB21 [679936 2010-04-27] (Intuit, Inc.)
3 rqs; C:\Windows\System32\rqs.exe [41472 2009-07-13] (Microsoft Corporation)
3 RSoPProv; C:\Windows\System32\RSoPProv.exe [91648 2009-07-13] (Microsoft Corporation)
3 sacsvr; C:\Windows\System32\sacsvr.dll [14848 2009-07-13] (Microsoft Corporation)
2 SNMP; C:\Windows\System32\snmp.exe [49664 2009-07-13] (Microsoft Corporation)
2 SNMP; C:\Windows\SysWow64\snmp.exe [47616 2009-07-13] (Microsoft Corporation)
2 sysdown; C:\Windows\System32\sysdown.exe [17960 2010-01-25] (Hewlett-Packard Company)
2 TermServLicensing; C:\Windows\System32\lserver.dll [692224 2009-07-13] (Microsoft Corporation)
2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [451072 2009-07-13] (Microsoft Corporation)
2 W3SVC; C:\Windows\SysWow64\inetsrv\iisw3adm.dll [396288 2009-07-13] (Microsoft Corporation)
2 WinVNC4; "C:\Program Files (x86)\RealVNC\VNC4\WinVNC4.exe" -service [439632 2008-10-15] (RealVNC Ltd.)
2 SQLANYs_ptsrv; C:\Program Files\Profit Tools\Sybase\SQLA12\Bin64\dbsrv12.exe -hvSQLANYs_ptsrv [x]
========================== Drivers (Whitelisted) =============
3 aarahci; C:\Windows\System32\Drivers\aarahci.sys [363056 2008-07-31] (Adaptec, Inc.)
3 b06diag; C:\Windows\system32\DRIVERS\bxdiaga.sys [89128 2010-08-02] (Broadcom Corporation)
3 bchtsw64; C:\Windows\System32\Drivers\bchtsw64.sys [90936 2009-10-23] (Broadcom Corporation)
3 be2iscsi; C:\Windows\System32\Drivers\be2iscsi.sys [163376 2010-08-31] (ServerEngines Corporation)
3 bfad; C:\Windows\System32\Drivers\bfad.sys [1125488 2010-04-20] (Brocade Communications Systems, Inc.)
0 bfad_up; C:\Windows\System32\Drivers\bfad_up.sys [15472 2010-04-20] (Brocade Communications Systems, Inc.)
3 BXOIS; C:\Windows\System32\Drivers\BXOIS.sys [524840 2010-08-02] (Broadcom Corporation)
3 elxcna; C:\Windows\System32\Drivers\elxcna.sys [646664 2010-08-05] (Emulex)
3 G200e; C:\Windows\System32\DRIVERS\G200em.sys [242176 2011-03-14] (Matrox Graphics Inc.)
3 HpAHCIsr; C:\Windows\System32\Drivers\HpAHCIsr.sys [223336 2010-05-27] (Hewlett-Packard Company)
0 HpCISSs2; C:\Windows\System32\Drivers\HpCISSs2.sys [156776 2010-02-21] (Hewlett-Packard Company)
3 hpqmgmt; C:\Windows\System32\Drivers\hpqmgmt.sys [98856 2009-03-19] (Hewlett-Packard Company)
3 HPUSBMSC; C:\Windows\system32\DRIVERS\HPUSBXSC.SYS [47144 2009-06-17] (Hewlett-Packard)
3 ioatdma; C:\Windows\System32\Drivers\qd260x64.sys [35328 2009-06-10] (Intel Corporation)
3 mlx4_bus; C:\Windows\System32\Drivers\mlx4_bus.sys [291944 2010-09-01] (Hewlett-Packard)
3 MRxDAV; C:\Windows\SysWow64\Drivers\MRxDAV.sys [115712 2009-07-13] (Microsoft Corporation)
3 q57nd60a; C:\Windows\System32\DRIVERS\b57nd60a.sys [405544 2010-08-02] (Broadcom Corporation)
0 sacdrv; C:\Windows\System32\Drivers\sacdrv.sys [96320 2009-07-13] (Microsoft Corporation)
3 storvsp; C:\Windows\System32\Drivers\storvsp.sys [121856 2009-07-13] (Microsoft Corporation)
3 Vid; C:\Windows\System32\Drivers\Vid.sys [181248 2009-07-13] (Microsoft Corporation)
3 KAPFA; \??\C:\Windows\system32\drivers\KAPFA.SYS [x]
========================== NetSvcs (Whitelisted) ===========
NETSVC: sacsvr -> C:\Windows\system32\sacsvr.dll (Microsoft Corporation)
============ One Month Created Files and Folders ==============
2012-08-09 06:04 - 2012-08-09 05:50 - 00607260 ____R (Swearware) C:\Users\frank\Desktop\dds.com
2012-08-09 06:04 - 2012-08-09 05:49 - 00302592 ____A C:\Users\frank\Desktop\wy82hjq3.exe
2012-08-09 05:58 - 2012-08-09 05:58 - 00000000 ____D C:\FRST
2012-08-09 05:36 - 2012-08-09 05:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB9A1010890AFFEE
2012-08-09 05:33 - 2012-08-09 05:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72E5362A0BD14F2F
2012-08-09 05:29 - 2012-08-09 05:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.44E5779334A7D83E
2012-08-09 05:25 - 2012-08-09 05:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C216B261A64DDCBC
2012-08-09 05:21 - 2012-08-09 05:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5DCF895404AEBB8
2012-08-09 05:18 - 2012-08-09 05:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.69C9D721940BD4BF
2012-08-09 05:14 - 2012-08-09 05:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D82F043A8FEC7CEE
2012-08-09 05:10 - 2012-08-09 05:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8F4E0834D8EFEBC
2012-08-09 05:07 - 2012-08-09 05:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D38393B1BA7246B
2012-08-09 05:03 - 2012-08-09 05:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8071CB9A75191EEB
2012-08-09 04:59 - 2012-08-09 04:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C3011F7E4A785767
2012-08-09 04:55 - 2012-08-09 04:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5EC0E1CF8093BB18
2012-08-09 04:52 - 2012-08-09 04:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9555716B5A2BBFD
2012-08-09 04:48 - 2012-08-09 04:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECBEDE6FCB51C87C
2012-08-09 04:44 - 2012-08-09 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBCDD9B8CFE3F464
2012-08-09 04:40 - 2012-08-09 04:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5A9CE81858F92C0D
2012-08-09 04:37 - 2012-08-09 04:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0698789F4ECFC9
2012-08-09 04:33 - 2012-08-09 04:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18B9A90766DC53F5
2012-08-09 04:29 - 2012-08-09 04:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F76E0F11B73876B
2012-08-09 04:26 - 2012-08-09 04:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0844593D2681CF5
2012-08-09 04:22 - 2012-08-09 04:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81A047C03CDC542
2012-08-09 04:18 - 2012-08-09 04:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CEEC5D6C4268E8BC
2012-08-09 04:14 - 2012-08-09 04:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CFD1A50C9191ED21
2012-08-09 04:11 - 2012-08-09 04:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.290B7DA9EDF03385
2012-08-09 04:07 - 2012-08-09 04:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EC804FF5F0FCB85
2012-08-09 04:03 - 2012-08-09 04:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BAA36DBB942413A
2012-08-09 04:00 - 2012-08-09 04:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51DEDEC7ECAFFEFC
2012-08-09 03:56 - 2012-08-09 03:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.880FD5B52EDAAB2C
2012-08-09 03:52 - 2012-08-09 03:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D2EB03BE6D52EB3
2012-08-09 03:48 - 2012-08-09 03:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E65AE579A6C2D61
2012-08-09 03:45 - 2012-08-09 03:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AEDCC9B8D34C361D
2012-08-09 03:41 - 2012-08-09 03:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9C2DC445AF4CAA2
2012-08-09 03:37 - 2012-08-09 03:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C621C95988BA64A
2012-08-09 03:33 - 2012-08-09 03:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DFEBD18377C0AC
2012-08-09 03:30 - 2012-08-09 03:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4CBD7315F69B608B
2012-08-09 03:26 - 2012-08-09 03:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.940A3B643315666D
2012-08-09 03:22 - 2012-08-09 03:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14E93EEEDAAABB17
2012-08-09 03:19 - 2012-08-09 03:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C924DDED6F0FC518
2012-08-09 03:15 - 2012-08-09 03:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2343B3FE8036872A
2012-08-09 03:11 - 2012-08-09 03:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11E81B2BECDB7BC1
2012-08-09 03:07 - 2012-08-09 03:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B261B290D7888CA
2012-08-09 03:04 - 2012-08-09 03:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9692C5AFDCD11D02
2012-08-09 03:00 - 2012-08-09 03:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77291BE6F1228A36
2012-08-09 02:56 - 2012-08-09 02:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9E993F14328744BC
2012-08-09 02:53 - 2012-08-09 02:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B865B3BC9419F04
2012-08-09 02:49 - 2012-08-09 02:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30CAEB12CE87E691
2012-08-09 02:45 - 2012-08-09 02:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.049F9AF61F17D75C
2012-08-09 02:41 - 2012-08-09 02:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.09123E38065282F7
2012-08-09 02:38 - 2012-08-09 02:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.876360F33C92B2C5
2012-08-09 02:34 - 2012-08-09 02:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7C527C7A8B6F50B
2012-08-09 02:30 - 2012-08-09 02:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1D21B448BF10CBA
2012-08-09 02:26 - 2012-08-09 02:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F8E9B38B76A8B0D
2012-08-09 02:23 - 2012-08-09 02:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129B404282E5AE3C
2012-08-09 02:19 - 2012-08-09 02:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2B916F13308CA13
2012-08-09 02:15 - 2012-08-09 02:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4BD5DEF9F7587255
2012-08-09 02:12 - 2012-08-09 02:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94DDAA4175F314B1
2012-08-09 02:08 - 2012-08-09 02:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC302FB3D17C0642
2012-08-09 02:04 - 2012-08-09 02:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DE76FBB01FA45BD3
2012-08-09 02:00 - 2012-08-09 02:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A87AC973177E679
2012-08-09 01:57 - 2012-08-09 01:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FCF899EB194B3AD0
2012-08-09 01:53 - 2012-08-09 01:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1369A8411769F4CD
2012-08-09 01:49 - 2012-08-09 01:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D86BF51DC13B8230
2012-08-09 01:46 - 2012-08-09 01:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B55066EB6B9EEE95
2012-08-09 01:42 - 2012-08-09 01:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87F78F64AC9E978C
2012-08-09 01:38 - 2012-08-09 01:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.46CE1BF2FE39E10B
2012-08-09 01:34 - 2012-08-09 01:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51E9ECFC90321BD5
2012-08-09 01:31 - 2012-08-09 01:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC3CA10830B61336
2012-08-09 01:27 - 2012-08-09 01:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D35B473D6428979
2012-08-09 01:23 - 2012-08-09 01:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A993C76224D14F85
2012-08-09 01:19 - 2012-08-09 01:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B530A5047C73A16A
2012-08-09 01:16 - 2012-08-09 01:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63EAEA5537A808B5
2012-08-09 01:12 - 2012-08-09 01:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD3081176DD59A69
2012-08-09 01:08 - 2012-08-09 01:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F73A1B4CE90B2A7D
2012-08-09 01:05 - 2012-08-09 01:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1A100BAFEECC053
2012-08-09 01:01 - 2012-08-09 01:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.711EEA03DCC5BF9F
2012-08-09 00:57 - 2012-08-09 00:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F091C807FAD0E981
2012-08-09 00:53 - 2012-08-09 00:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9698E79E01BEE1D6
2012-08-09 00:50 - 2012-08-09 00:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FD0E73D6E48DF2DB
2012-08-09 00:46 - 2012-08-09 00:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.373F4D971A931FA2
2012-08-09 00:42 - 2012-08-09 00:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC02870EA8A73758
2012-08-09 00:39 - 2012-08-09 00:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0DDA2AE7A9DE7737
2012-08-09 00:35 - 2012-08-09 00:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33C96B1604B8E4FB
2012-08-09 00:31 - 2012-08-09 00:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24D2F2CA5DC1878C
2012-08-09 00:27 - 2012-08-09 00:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAD55A0BD1D3ACB3
2012-08-09 00:24 - 2012-08-09 00:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBB1583714D0E53F
2012-08-09 00:20 - 2012-08-09 00:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0474DDC0F56A6C98
2012-08-09 00:16 - 2012-08-09 00:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F747776EEE440CA
2012-08-09 00:12 - 2012-08-09 00:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47A1588EEADC79D9
2012-08-09 00:09 - 2012-08-09 00:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA4A3BC2F6AC12CE
2012-08-09 00:05 - 2012-08-09 00:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.155A2A2B10C655C5
2012-08-09 00:01 - 2012-08-09 00:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0879AB483D626932
2012-08-08 23:58 - 2012-08-08 23:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10268C8E76D31502
2012-08-08 23:54 - 2012-08-08 23:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.834B2828FA183CA3
2012-08-08 23:50 - 2012-08-08 23:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2142AABD9A6E03D4
2012-08-08 23:46 - 2012-08-08 23:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7552E461AB63A6C1
2012-08-08 23:43 - 2012-08-08 23:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B6638D582CB5239D
2012-08-08 23:39 - 2012-08-08 23:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0397A3428D3804D4
2012-08-08 23:35 - 2012-08-08 23:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E51DC69051BEA1FC
2012-08-08 23:31 - 2012-08-08 23:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3069EC68AB2E7B57
2012-08-08 23:28 - 2012-08-08 23:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.541103CDEEBBC7B1
2012-08-08 23:24 - 2012-08-08 23:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.00546D2F107C88F6
2012-08-08 23:20 - 2012-08-08 23:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.59B092850D586002
2012-08-08 23:17 - 2012-08-08 23:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88EAA525011D6CD7
2012-08-08 23:13 - 2012-08-08 23:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AFE3CD7BE4C6B273
2012-08-08 23:09 - 2012-08-08 23:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9AE197152C0B6DBE
2012-08-08 23:05 - 2012-08-08 23:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D3C9F9D497408C2
2012-08-08 23:02 - 2012-08-08 23:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169ABF06B61C7DC
2012-08-08 22:58 - 2012-08-08 22:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4FA4C6DEC7FA457
2012-08-08 22:54 - 2012-08-08 22:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F0206D8736558AF0
2012-08-08 22:51 - 2012-08-08 22:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF294788B62887CD
2012-08-08 22:47 - 2012-08-08 22:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7F729FF837B7E1
2012-08-08 22:43 - 2012-08-08 22:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0A702750A1684A1D
2012-08-08 22:39 - 2012-08-08 22:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D82152450C119DA
2012-08-08 22:36 - 2012-08-08 22:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41F7724CB3DB06BB
2012-08-08 22:32 - 2012-08-08 22:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB932C6E4E8EE438
2012-08-08 22:28 - 2012-08-08 22:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF6939662C08E42F
2012-08-08 22:24 - 2012-08-08 22:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.84D746227F91ED91
2012-08-08 22:21 - 2012-08-08 22:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFAAB1B4E5F9F605
2012-08-08 22:17 - 2012-08-08 22:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.92D0F8BF84305E11
2012-08-08 22:13 - 2012-08-08 22:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AB8B992F0731098
2012-08-08 22:10 - 2012-08-08 22:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD6D90A9500B7931
2012-08-08 22:06 - 2012-08-08 22:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1850E1E5AA25B05E
2012-08-08 22:02 - 2012-08-08 22:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.95653D6E21D04D7A
2012-08-08 21:58 - 2012-08-08 21:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8157058AD18E7DAD
2012-08-08 21:55 - 2012-08-08 21:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5D50F07DA5C2D33
2012-08-08 21:51 - 2012-08-08 21:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7E07AB1A607A4F6
2012-08-08 21:47 - 2012-08-08 21:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDF585E84251D56D
2012-08-08 21:44 - 2012-08-08 21:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C8B1AFF015DD2B2
2012-08-08 21:40 - 2012-08-08 21:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D95452728FAECF1
2012-08-08 21:36 - 2012-08-08 21:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E487623797CA617C
2012-08-08 21:32 - 2012-08-08 21:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB438F6E0B2FA2B3
2012-08-08 21:29 - 2012-08-08 21:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C674D1EB924FBB
2012-08-08 21:25 - 2012-08-08 21:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD82D5E5B3B3F72E
2012-08-08 21:21 - 2012-08-08 21:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.67D4F2D8521EED50
2012-08-08 21:17 - 2012-08-08 21:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B33C0521EDC3A884
2012-08-08 21:14 - 2012-08-08 21:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFB723BACF41163
2012-08-08 21:10 - 2012-08-08 21:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E391B3C556D5F42D
2012-08-08 21:06 - 2012-08-08 21:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7FE3577CD164308
2012-08-08 21:03 - 2012-08-08 21:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A5C086D4CB27A94
2012-08-08 20:59 - 2012-08-08 20:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BFB4D489EC266F59
2012-08-08 20:55 - 2012-08-08 20:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E141351D843D5ADB
2012-08-08 20:52 - 2012-08-08 20:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A851C2C7D67203C9
2012-08-08 20:48 - 2012-08-08 20:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1AC6CA500F0B944
2012-08-08 20:44 - 2012-08-08 20:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.877CC8F7C0654369
2012-08-08 20:40 - 2012-08-08 20:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2ABC066A6CB23ED5
2012-08-08 20:37 - 2012-08-08 20:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9FA810BD61820A5
2012-08-08 20:33 - 2012-08-08 20:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D87677A490E90540
2012-08-08 20:29 - 2012-08-08 20:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15B43CCED18E1D14
2012-08-08 20:26 - 2012-08-08 20:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FEB8266FBFAE7339
2012-08-08 20:22 - 2012-08-08 20:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2D9099DA5002738
2012-08-08 20:18 - 2012-08-08 20:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BACC871F522C30B
2012-08-08 20:15 - 2012-08-08 20:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B0AD15D1DF1B2C2
2012-08-08 20:11 - 2012-08-08 20:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB744F045A9AE235
2012-08-08 20:07 - 2012-08-08 20:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8AFD3E376FAC7CB2
2012-08-08 20:03 - 2012-08-08 20:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6235CC19A79237D3
2012-08-08 20:00 - 2012-08-08 20:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E444BD854315046
2012-08-08 19:56 - 2012-08-08 19:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA421768F2A74BA3
2012-08-08 19:52 - 2012-08-08 19:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A83BD7A5E23A315A
2012-08-08 19:49 - 2012-08-08 19:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C641E19DDEE2810
2012-08-08 19:45 - 2012-08-08 19:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BD1E6FA221046C63
2012-08-08 19:41 - 2012-08-08 19:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E190B06FB01BE3D0
2012-08-08 19:38 - 2012-08-08 19:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9160897B82EC0185
2012-08-08 19:34 - 2012-08-08 19:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D46D985EE0FDAD1
2012-08-08 19:30 - 2012-08-08 19:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1457FD0B1E7100F5
2012-08-08 19:27 - 2012-08-08 19:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1798DADE265F227
2012-08-08 18:44 - 2012-08-08 18:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C6A2AF826E71567D
2012-08-08 17:05 - 2012-08-08 17:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E6079324380AA7FD
2012-08-08 16:26 - 2012-08-08 16:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7DAC7B56D306001E
2012-08-08 15:48 - 2012-08-08 15:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74F55DFF4C3A075E
2012-08-08 13:51 - 2012-08-08 13:51 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\frank\Desktop\tdsskiller.exe
2012-08-08 13:50 - 2012-08-08 13:50 - 04727110 ____A (Swearware) C:\Users\frank\Desktop\ComboFix.exe
2012-08-08 13:43 - 2012-08-08 13:43 - 00881494 ____A C:\Users\frank\Desktop\SecurityCheck.exe
2012-08-08 12:02 - 2012-08-08 12:02 - 00000000 ____D C:\Users\frank\AppData\Local\Macromedia
2012-08-08 11:30 - 2012-08-08 11:30 - 00017668 ____A C:\Users\frank\TsAllUsr.Dat
2012-08-08 10:54 - 2012-08-08 10:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-08 10:54 - 2012-08-08 10:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-08 10:52 - 2012-08-08 10:52 - 00000000 ____D C:\Windows\System32\SPReview
2012-08-08 10:45 - 2012-08-08 10:45 - 00000017 ____A C:\Users\Rick\AppData\Local\resmon.resmoncfg
2012-08-08 09:56 - 2012-08-08 09:57 - 12621696 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\mseinstall.exe
2012-08-08 09:51 - 2012-08-08 09:51 - 00000000 ____D C:\Users\Rick\AppData\Roaming\Malwarebytes
2012-08-08 09:32 - 2012-08-08 09:32 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-08 09:32 - 2012-08-08 09:32 - 00000000 ____D C:\Users\frank\AppData\Roaming\Malwarebytes
2012-08-08 09:32 - 2012-08-08 09:32 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-08-08 09:32 - 2012-08-08 09:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-08 09:32 - 2012-07-03 10:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-08 09:30 - 2012-08-08 09:30 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\frank\Downloads\mbam-setup-1.62.0.1300.exe
2012-08-08 09:23 - 2012-08-08 09:23 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-08 09:22 - 2012-08-08 09:22 - 00000000 ____A C:\extensions.sqlite
 
2012-08-06 15:19 - 2012-08-06 15:19 - 00007607 ____A C:\Users\frank\AppData\Local\Resmon.ResmonCfg
2012-08-02 06:17 - 2012-08-02 06:17 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (3).lnk
2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut.lnk
2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (2).lnk
2012-07-27 08:03 - 2012-07-27 14:58 - 00000000 ____D C:\imagetmp
2012-07-27 07:14 - 2012-07-27 07:14 - 00034770 ____A C:\Users\frank\Desktop\custlist.TXT
2012-07-25 12:08 - 2012-07-25 12:08 - 00000000 ____D C:\Users\frank\AppData\Roaming\SQL Anywhere 12
2012-07-24 07:30 - 2012-07-24 07:30 - 00000000 ____D C:\Users\Rick\AppData\Local\Help
2012-07-24 07:29 - 2012-07-24 07:29 - 00000000 ____D C:\Users\Rick\AppData\Roaming\SQL Anywhere 12
2012-07-19 13:34 - 2012-07-19 13:34 - 00000000 ____D C:\Users\Install\AppData\Local\Adobe
2012-07-19 12:35 - 2012-07-19 12:36 - 00000000 ____D C:\Users\Install\AppData\Roaming\Mozilla
2012-07-19 12:35 - 2012-07-19 12:35 - 00000000 ____D C:\Users\Install\AppData\Local\Mozilla
2012-07-18 12:48 - 2012-07-18 12:48 - 00001349 ____A C:\Users\Install\Desktop\Profit Tools.lnk
2012-07-18 12:38 - 2012-07-18 12:38 - 00000000 ____D C:\Users\Install\AppData\Roaming\Help
2012-07-18 12:38 - 2012-07-18 12:38 - 00000000 ____D C:\Users\Install\AppData\Local\Help
2012-07-18 12:37 - 2012-07-24 07:32 - 00000755 ____A C:\Users\Install\Desktop\Profit Tools Help.lnk
2012-07-18 12:36 - 2012-07-19 13:34 - 00000000 ____D C:\Users\Install\AppData\Roaming\Adobe
2012-07-18 12:36 - 2009-08-04 09:56 - 00296960 ____A (Microsoft Corporation) C:\Windows\winhlp32.exe
2012-07-18 12:36 - 2009-08-04 09:55 - 00195072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftsrch.dll
2012-07-18 12:36 - 2009-08-04 09:55 - 00195072 ____A (Microsoft Corporation) C:\Windows\System32\ftsrch.dll
2012-07-18 12:36 - 2009-08-04 09:55 - 00010240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftlx041e.dll
2012-07-18 12:36 - 2009-08-04 09:55 - 00010240 ____A (Microsoft Corporation) C:\Windows\System32\ftlx041e.dll
2012-07-18 12:36 - 2009-08-04 09:55 - 00009216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftlx0411.dll
2012-07-18 12:36 - 2009-08-04 09:55 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\ftlx0411.dll
2012-07-18 12:11 - 2012-07-18 12:11 - 00000000 ____D C:\Users\Install\AppData\Roaming\WinRAR
2012-07-18 10:28 - 2012-07-18 12:32 - 00000000 ____D C:\Users\Public\Documents\Sybase Central 6.1.0
2012-07-18 10:27 - 2012-07-18 10:31 - 00000166 ____A C:\Windows\ODBC.INI
2012-07-18 10:27 - 2012-07-18 10:31 - 00000000 ____D C:\Users\Install\AppData\Roaming\SQL Anywhere 12
2012-07-18 10:25 - 2012-07-18 12:30 - 00000000 ____D C:\Users\Install\sybase
2012-07-18 10:25 - 2012-07-18 10:25 - 00000000 ____D C:\Users\Public\Documents\DBISQL 12.0.1
2012-07-18 10:06 - 2012-07-18 10:06 - 00103272 ____A C:\Users\Install\GoToAssistDownloadHelper.exe
2012-07-18 10:06 - 2012-07-18 10:06 - 00000000 ____D C:\Users\Install\AppData\Local\Deployment
2012-07-18 10:06 - 2012-07-18 10:06 - 00000000 ____D C:\Users\Install\AppData\Local\Citrix
2012-07-18 10:06 - 2012-07-18 10:06 - 00000000 ____D C:\Users\Install\AppData\Local\Apps\2.0
2012-07-18 10:03 - 2012-07-18 10:25 - 00000000 ____D C:\users\Install
2012-07-18 10:03 - 2012-07-18 10:03 - 00113664 ____A C:\Users\Install\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 10:03 - 2012-07-18 10:03 - 00000020 __ASH C:\Users\Install\ntuser.ini
2012-07-18 10:03 - 2012-07-18 10:03 - 00000000 ____D C:\Users\Install\AppData\Roaming\Apple Computer
2012-07-18 10:03 - 2012-07-18 10:03 - 00000000 ____D C:\Users\Install\AppData\Local\Intuit
2012-07-18 10:03 - 2012-07-18 10:03 - 00000000 ____D C:\Users\Install\AppData\Local\Apple Computer
2012-07-18 10:03 - 2011-10-11 00:01 - 00000000 ____D C:\Users\Install\AppData\Local\Microsoft Help
2012-07-18 10:03 - 2011-02-23 08:42 - 00000000 ____D C:\Users\Install\AppData\Roaming\Macromedia
2012-07-18 09:53 - 2012-07-18 12:12 - 00000000 ____D C:\Users\All Users\SQL Anywhere 12
2012-07-18 09:30 - 2004-07-12 10:50 - 00155648 ____A (Sun Microsystems©) C:\Windows\SysWOW64\JavaAccessBridge.dll
2012-07-18 09:30 - 2004-07-12 10:50 - 00081920 ____A (Sun Microsystems©) C:\Windows\SysWOW64\WindowsAccessBridge.dll
2012-07-18 09:30 - 2004-07-12 10:50 - 00032768 ____A (Sun Microsystems©) C:\Windows\SysWOW64\JAWTAccessBridge.dll
2012-07-18 09:29 - 2012-07-18 09:29 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-07-18 08:06 - 2012-07-18 08:06 - 00103272 ____A C:\Users\frank\GoToAssistDownloadHelper.exe
2012-07-18 08:06 - 2012-07-18 08:06 - 00000000 ____D C:\Users\frank\AppData\Local\Deployment
2012-07-18 08:06 - 2012-07-18 08:06 - 00000000 ____D C:\Users\frank\AppData\Local\Citrix
2012-07-18 08:06 - 2012-07-18 08:06 - 00000000 ____D C:\Users\frank\AppData\Local\Apps\2.0
2012-07-12 07:59 - 2012-07-12 07:59 - 00318904 ____A (Microsoft Corporation) C:\Users\frank\Downloads\wmpfirefoxplugin.exe
2012-07-12 07:53 - 2012-07-12 07:53 - 00318904 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\wmpfirefoxplugin(1).exe
2012-07-12 07:52 - 2012-07-12 07:52 - 00000195 ____A C:\Users\Rick\Downloads\wmpfirefoxplugin.exe
2012-07-11 00:05 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 00:05 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 00:05 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 00:05 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 00:05 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 00:05 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 00:05 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 00:05 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 00:05 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 00:05 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 00:05 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 00:05 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 00:05 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 00:05 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 00:05 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 00:05 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 00:05 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 00:05 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 00:05 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 00:05 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 00:05 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 00:05 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 00:05 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 00:05 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 00:05 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 00:05 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 00:05 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 00:05 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 00:01 - 2012-06-11 19:02 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 12:40 - 2012-06-08 21:30 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 12:40 - 2012-06-08 20:46 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 12:40 - 2012-06-05 21:50 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 12:40 - 2012-06-05 21:50 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 12:40 - 2012-06-05 21:09 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 12:40 - 2012-06-05 21:09 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 12:40 - 2012-06-01 21:38 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 12:40 - 2012-06-01 21:38 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 12:40 - 2012-06-01 21:37 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 12:40 - 2012-06-01 21:27 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 12:40 - 2012-06-01 21:27 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 12:40 - 2012-06-01 20:48 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 12:40 - 2012-06-01 20:48 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 12:40 - 2012-06-01 20:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 12:40 - 2012-06-01 20:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
============ 3 Months Modified Files ========================
2012-08-09 09:00 - 2009-07-13 20:49 - 00014048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-09 09:00 - 2009-07-13 20:49 - 00014048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-09 08:59 - 2011-02-18 10:42 - 01551283 ____A C:\Windows\WindowsUpdate.log
2012-08-09 08:59 - 2009-09-22 11:32 - 00851644 ____A C:\Windows\System32\perfh00A.dat
2012-08-09 08:59 - 2009-09-22 11:32 - 00195538 ____A C:\Windows\System32\perfc00A.dat
2012-08-09 08:59 - 2009-09-22 11:18 - 00845594 ____A C:\Windows\System32\perfh010.dat
2012-08-09 08:59 - 2009-09-22 11:18 - 00182856 ____A C:\Windows\System32\perfc010.dat
2012-08-09 08:59 - 2009-09-22 11:06 - 00808956 ____A C:\Windows\System32\perfh007.dat
2012-08-09 08:59 - 2009-09-22 11:06 - 00183696 ____A C:\Windows\System32\perfc007.dat
2012-08-09 08:59 - 2009-09-22 10:53 - 00856886 ____A C:\Windows\System32\perfh00C.dat
2012-08-09 08:59 - 2009-09-22 10:53 - 00187520 ____A C:\Windows\System32\perfc00C.dat
2012-08-09 08:59 - 2009-07-13 21:10 - 05006346 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-09 08:53 - 2009-07-13 21:06 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-09 08:53 - 2009-07-13 20:56 - 00039656 ____A C:\Windows\setupact.log
2012-08-09 07:32 - 2012-05-02 07:49 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-09 05:50 - 2012-08-09 06:04 - 00607260 ____R (Swearware) C:\Users\frank\Desktop\dds.com
2012-08-09 05:49 - 2012-08-09 06:04 - 00302592 ____A C:\Users\frank\Desktop\wy82hjq3.exe
2012-08-09 05:36 - 2012-08-09 05:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB9A1010890AFFEE
2012-08-09 05:33 - 2012-08-09 05:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72E5362A0BD14F2F
2012-08-09 05:29 - 2012-08-09 05:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.44E5779334A7D83E
2012-08-09 05:25 - 2012-08-09 05:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C216B261A64DDCBC
2012-08-09 05:21 - 2012-08-09 05:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5DCF895404AEBB8
2012-08-09 05:18 - 2012-08-09 05:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.69C9D721940BD4BF
2012-08-09 05:14 - 2012-08-09 05:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D82F043A8FEC7CEE
2012-08-09 05:10 - 2012-08-09 05:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8F4E0834D8EFEBC
2012-08-09 05:07 - 2012-08-09 05:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D38393B1BA7246B
2012-08-09 05:03 - 2012-08-09 05:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8071CB9A75191EEB
2012-08-09 04:59 - 2012-08-09 04:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C3011F7E4A785767
2012-08-09 04:55 - 2012-08-09 04:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5EC0E1CF8093BB18
2012-08-09 04:52 - 2012-08-09 04:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9555716B5A2BBFD
2012-08-09 04:48 - 2012-08-09 04:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECBEDE6FCB51C87C
2012-08-09 04:44 - 2012-08-09 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBCDD9B8CFE3F464
2012-08-09 04:40 - 2012-08-09 04:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5A9CE81858F92C0D
2012-08-09 04:37 - 2012-08-09 04:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0698789F4ECFC9
2012-08-09 04:33 - 2012-08-09 04:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18B9A90766DC53F5
2012-08-09 04:29 - 2012-08-09 04:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F76E0F11B73876B
2012-08-09 04:26 - 2012-08-09 04:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0844593D2681CF5
2012-08-09 04:22 - 2012-08-09 04:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81A047C03CDC542
2012-08-09 04:18 - 2012-08-09 04:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CEEC5D6C4268E8BC
2012-08-09 04:14 - 2012-08-09 04:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CFD1A50C9191ED21
2012-08-09 04:11 - 2012-08-09 04:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.290B7DA9EDF03385
2012-08-09 04:07 - 2012-08-09 04:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EC804FF5F0FCB85
2012-08-09 04:03 - 2012-08-09 04:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BAA36DBB942413A
2012-08-09 04:00 - 2012-08-09 04:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51DEDEC7ECAFFEFC
2012-08-09 03:56 - 2012-08-09 03:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.880FD5B52EDAAB2C
2012-08-09 03:52 - 2012-08-09 03:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D2EB03BE6D52EB3
2012-08-09 03:48 - 2012-08-09 03:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E65AE579A6C2D61
2012-08-09 03:45 - 2012-08-09 03:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AEDCC9B8D34C361D
2012-08-09 03:41 - 2012-08-09 03:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9C2DC445AF4CAA2
2012-08-09 03:37 - 2012-08-09 03:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C621C95988BA64A
2012-08-09 03:33 - 2012-08-09 03:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DFEBD18377C0AC
2012-08-09 03:30 - 2012-08-09 03:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4CBD7315F69B608B
2012-08-09 03:26 - 2012-08-09 03:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.940A3B643315666D
2012-08-09 03:22 - 2012-08-09 03:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14E93EEEDAAABB17
2012-08-09 03:19 - 2012-08-09 03:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C924DDED6F0FC518
2012-08-09 03:15 - 2012-08-09 03:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2343B3FE8036872A
2012-08-09 03:11 - 2012-08-09 03:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11E81B2BECDB7BC1
2012-08-09 03:07 - 2012-08-09 03:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B261B290D7888CA
2012-08-09 03:04 - 2012-08-09 03:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9692C5AFDCD11D02
2012-08-09 03:00 - 2012-08-09 03:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77291BE6F1228A36
2012-08-09 02:56 - 2012-08-09 02:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9E993F14328744BC
2012-08-09 02:53 - 2012-08-09 02:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B865B3BC9419F04
2012-08-09 02:49 - 2012-08-09 02:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30CAEB12CE87E691
2012-08-09 02:45 - 2012-08-09 02:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.049F9AF61F17D75C
2012-08-09 02:41 - 2012-08-09 02:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.09123E38065282F7
2012-08-09 02:38 - 2012-08-09 02:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.876360F33C92B2C5
2012-08-09 02:34 - 2012-08-09 02:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7C527C7A8B6F50B
2012-08-09 02:30 - 2012-08-09 02:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1D21B448BF10CBA
2012-08-09 02:26 - 2012-08-09 02:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F8E9B38B76A8B0D
2012-08-09 02:23 - 2012-08-09 02:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129B404282E5AE3C
2012-08-09 02:19 - 2012-08-09 02:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2B916F13308CA13
2012-08-09 02:15 - 2012-08-09 02:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4BD5DEF9F7587255
2012-08-09 02:12 - 2012-08-09 02:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94DDAA4175F314B1
2012-08-09 02:08 - 2012-08-09 02:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC302FB3D17C0642
2012-08-09 02:04 - 2012-08-09 02:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DE76FBB01FA45BD3
2012-08-09 02:00 - 2012-08-09 02:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A87AC973177E679
2012-08-09 01:57 - 2012-08-09 01:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FCF899EB194B3AD0
2012-08-09 01:53 - 2012-08-09 01:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1369A8411769F4CD
2012-08-09 01:49 - 2012-08-09 01:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D86BF51DC13B8230
2012-08-09 01:46 - 2012-08-09 01:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B55066EB6B9EEE95
2012-08-09 01:42 - 2012-08-09 01:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87F78F64AC9E978C
2012-08-09 01:38 - 2012-08-09 01:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.46CE1BF2FE39E10B
2012-08-09 01:34 - 2012-08-09 01:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51E9ECFC90321BD5
2012-08-09 01:31 - 2012-08-09 01:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC3CA10830B61336
2012-08-09 01:27 - 2012-08-09 01:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D35B473D6428979
2012-08-09 01:23 - 2012-08-09 01:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A993C76224D14F85
2012-08-09 01:19 - 2012-08-09 01:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B530A5047C73A16A
2012-08-09 01:16 - 2012-08-09 01:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63EAEA5537A808B5
2012-08-09 01:12 - 2012-08-09 01:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD3081176DD59A69
2012-08-09 01:08 - 2012-08-09 01:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F73A1B4CE90B2A7D
2012-08-09 01:05 - 2012-08-09 01:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1A100BAFEECC053
2012-08-09 01:01 - 2012-08-09 01:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.711EEA03DCC5BF9F
2012-08-09 00:57 - 2012-08-09 00:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F091C807FAD0E981
2012-08-09 00:53 - 2012-08-09 00:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9698E79E01BEE1D6
2012-08-09 00:50 - 2012-08-09 00:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FD0E73D6E48DF2DB
2012-08-09 00:46 - 2012-08-09 00:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.373F4D971A931FA2
2012-08-09 00:42 - 2012-08-09 00:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC02870EA8A73758
2012-08-09 00:39 - 2012-08-09 00:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0DDA2AE7A9DE7737
2012-08-09 00:35 - 2012-08-09 00:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33C96B1604B8E4FB
2012-08-09 00:31 - 2012-08-09 00:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24D2F2CA5DC1878C
2012-08-09 00:27 - 2012-08-09 00:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAD55A0BD1D3ACB3
2012-08-09 00:24 - 2012-08-09 00:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBB1583714D0E53F
2012-08-09 00:20 - 2012-08-09 00:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0474DDC0F56A6C98
2012-08-09 00:16 - 2012-08-09 00:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F747776EEE440CA
2012-08-09 00:12 - 2012-08-09 00:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47A1588EEADC79D9
2012-08-09 00:09 - 2012-08-09 00:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA4A3BC2F6AC12CE
2012-08-09 00:05 - 2012-08-09 00:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.155A2A2B10C655C5
2012-08-09 00:01 - 2012-08-09 00:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0879AB483D626932
2012-08-08 23:58 - 2012-08-08 23:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10268C8E76D31502
2012-08-08 23:54 - 2012-08-08 23:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.834B2828FA183CA3
2012-08-08 23:50 - 2012-08-08 23:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2142AABD9A6E03D4
2012-08-08 23:46 - 2012-08-08 23:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7552E461AB63A6C1
2012-08-08 23:43 - 2012-08-08 23:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B6638D582CB5239D
2012-08-08 23:39 - 2012-08-08 23:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0397A3428D3804D4
2012-08-08 23:35 - 2012-08-08 23:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E51DC69051BEA1FC
2012-08-08 23:31 - 2012-08-08 23:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3069EC68AB2E7B57
2012-08-08 23:28 - 2012-08-08 23:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.541103CDEEBBC7B1
2012-08-08 23:24 - 2012-08-08 23:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.00546D2F107C88F6
2012-08-08 23:20 - 2012-08-08 23:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.59B092850D586002
2012-08-08 23:17 - 2012-08-08 23:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88EAA525011D6CD7
2012-08-08 23:13 - 2012-08-08 23:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AFE3CD7BE4C6B273
2012-08-08 23:09 - 2012-08-08 23:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9AE197152C0B6DBE
2012-08-08 23:05 - 2012-08-08 23:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D3C9F9D497408C2
2012-08-08 23:02 - 2012-08-08 23:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169ABF06B61C7DC
2012-08-08 22:58 - 2012-08-08 22:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4FA4C6DEC7FA457
2012-08-08 22:54 - 2012-08-08 22:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F0206D8736558AF0
2012-08-08 22:51 - 2012-08-08 22:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF294788B62887CD
2012-08-08 22:47 - 2012-08-08 22:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7F729FF837B7E1
2012-08-08 22:43 - 2012-08-08 22:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0A702750A1684A1D
2012-08-08 22:39 - 2012-08-08 22:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D82152450C119DA
2012-08-08 22:36 - 2012-08-08 22:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41F7724CB3DB06BB
2012-08-08 22:32 - 2012-08-08 22:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB932C6E4E8EE438
2012-08-08 22:28 - 2012-08-08 22:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF6939662C08E42F
2012-08-08 22:24 - 2012-08-08 22:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.84D746227F91ED91
2012-08-08 22:21 - 2012-08-08 22:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFAAB1B4E5F9F605
2012-08-08 22:20 - 2009-07-13 21:06 - 00032618 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-08 22:17 - 2012-08-08 22:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.92D0F8BF84305E11
2012-08-08 22:13 - 2012-08-08 22:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AB8B992F0731098
2012-08-08 22:10 - 2012-08-08 22:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD6D90A9500B7931
2012-08-08 22:06 - 2012-08-08 22:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1850E1E5AA25B05E
2012-08-08 22:02 - 2012-08-08 22:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.95653D6E21D04D7A
2012-08-08 21:58 - 2012-08-08 21:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8157058AD18E7DAD
2012-08-08 21:55 - 2012-08-08 21:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5D50F07DA5C2D33
2012-08-08 21:51 - 2012-08-08 21:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7E07AB1A607A4F6
2012-08-08 21:47 - 2012-08-08 21:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDF585E84251D56D
2012-08-08 21:44 - 2012-08-08 21:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C8B1AFF015DD2B2
2012-08-08 21:40 - 2012-08-08 21:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D95452728FAECF1
2012-08-08 21:36 - 2012-08-08 21:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E487623797CA617C
2012-08-08 21:32 - 2012-08-08 21:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB438F6E0B2FA2B3
2012-08-08 21:29 - 2012-08-08 21:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C674D1EB924FBB
2012-08-08 21:25 - 2012-08-08 21:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD82D5E5B3B3F72E
2012-08-08 21:21 - 2012-08-08 21:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.67D4F2D8521EED50
2012-08-08 21:17 - 2012-08-08 21:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B33C0521EDC3A884
2012-08-08 21:14 - 2012-08-08 21:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFB723BACF41163
2012-08-08 21:10 - 2012-08-08 21:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E391B3C556D5F42D
2012-08-08 21:06 - 2012-08-08 21:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7FE3577CD164308
2012-08-08 21:03 - 2012-08-08 21:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A5C086D4CB27A94
2012-08-08 20:59 - 2012-08-08 20:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BFB4D489EC266F59
2012-08-08 20:55 - 2012-08-08 20:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E141351D843D5ADB
2012-08-08 20:52 - 2012-08-08 20:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A851C2C7D67203C9
2012-08-08 20:48 - 2012-08-08 20:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1AC6CA500F0B944
2012-08-08 20:44 - 2012-08-08 20:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.877CC8F7C0654369
2012-08-08 20:40 - 2012-08-08 20:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2ABC066A6CB23ED5
2012-08-08 20:37 - 2012-08-08 20:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9FA810BD61820A5
2012-08-08 20:33 - 2012-08-08 20:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D87677A490E90540
2012-08-08 20:29 - 2012-08-08 20:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15B43CCED18E1D14
2012-08-08 20:26 - 2012-08-08 20:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FEB8266FBFAE7339
2012-08-08 20:22 - 2012-08-08 20:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2D9099DA5002738
2012-08-08 20:18 - 2012-08-08 20:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BACC871F522C30B
2012-08-08 20:15 - 2012-08-08 20:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B0AD15D1DF1B2C2
2012-08-08 20:11 - 2012-08-08 20:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB744F045A9AE235
2012-08-08 20:07 - 2012-08-08 20:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8AFD3E376FAC7CB2
2012-08-08 20:03 - 2012-08-08 20:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6235CC19A79237D3
2012-08-08 20:00 - 2012-08-08 20:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E444BD854315046
2012-08-08 19:56 - 2012-08-08 19:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA421768F2A74BA3
2012-08-08 19:52 - 2012-08-08 19:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A83BD7A5E23A315A
2012-08-08 19:49 - 2012-08-08 19:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C641E19DDEE2810
2012-08-08 19:45 - 2012-08-08 19:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BD1E6FA221046C63
2012-08-08 19:41 - 2012-08-08 19:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E190B06FB01BE3D0
2012-08-08 19:38 - 2012-08-08 19:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9160897B82EC0185
2012-08-08 19:34 - 2012-08-08 19:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D46D985EE0FDAD1
2012-08-08 19:30 - 2012-08-08 19:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1457FD0B1E7100F5
2012-08-08 19:27 - 2012-08-08 19:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1798DADE265F227
2012-08-08 18:44 - 2012-08-08 18:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C6A2AF826E71567D
2012-08-08 17:05 - 2012-08-08 17:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E6079324380AA7FD
2012-08-08 16:26 - 2012-08-08 16:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7DAC7B56D306001E
2012-08-08 16:01 - 2011-03-25 18:19 - 00000402 ___AH C:\Windows\Tasks\GG Logistics Corp. 1301105924.job
2012-08-08 15:48 - 2012-08-08 15:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74F55DFF4C3A075E
2012-08-08 14:07 - 2011-02-22 10:47 - 00053828 ____A C:\Windows\PFRO.log
2012-08-08 13:51 - 2012-08-08 13:51 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\frank\Desktop\tdsskiller.exe
2012-08-08 13:50 - 2012-08-08 13:50 - 04727110 ____A (Swearware) C:\Users\frank\Desktop\ComboFix.exe
2012-08-08 13:43 - 2012-08-08 13:43 - 00881494 ____A C:\Users\frank\Desktop\SecurityCheck.exe
2012-08-08 12:50 - 2011-02-21 14:24 - 00000072 ____A C:\Users\Public\LMDebug.log
2012-08-08 11:30 - 2012-08-08 11:30 - 00017668 ____A C:\Users\frank\TsAllUsr.Dat
2012-08-08 11:27 - 2011-02-22 14:29 - 00002243 ____A C:\Windows\epplauncher.mif
2012-08-08 10:54 - 2011-02-21 13:48 - 05074708 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-08 10:45 - 2012-08-08 10:45 - 00000017 ____A C:\Users\Rick\AppData\Local\resmon.resmoncfg
2012-08-08 09:57 - 2012-08-08 09:56 - 12621696 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\mseinstall.exe
2012-08-08 09:32 - 2012-08-08 09:32 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-08 09:30 - 2012-08-08 09:30 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\frank\Downloads\mbam-setup-1.62.0.1300.exe
2012-08-08 09:22 - 2012-08-08 09:22 - 00000000 ____A C:\extensions.sqlite
2012-08-08 09:20 - 2011-02-23 07:05 - 00000462 _RASH C:\Users\All Users\ntuser.pol
2012-08-06 15:19 - 2012-08-06 15:19 - 00007607 ____A C:\Users\frank\AppData\Local\Resmon.ResmonCfg
2012-08-02 10:32 - 2012-05-02 07:49 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-02 10:32 - 2011-06-29 05:53 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-02 06:17 - 2012-08-02 06:17 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (3).lnk
2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut.lnk
2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (2).lnk
2012-07-27 07:14 - 2012-07-27 07:14 - 00034770 ____A C:\Users\frank\Desktop\custlist.TXT
2012-07-24 07:32 - 2012-07-18 12:37 - 00000755 ____A C:\Users\Install\Desktop\Profit Tools Help.lnk
2012-07-18 12:48 - 2012-07-18 12:48 - 00001349 ____A C:\Users\Install\Desktop\Profit Tools.lnk
2012-07-18 10:31 - 2012-07-18 10:27 - 00000166 ____A C:\Windows\ODBC.INI
2012-07-18 10:18 - 2011-02-21 14:07 - 00113664 ____A C:\Users\Rick\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 10:06 - 2012-07-18 10:06 - 00103272 ____A C:\Users\Install\GoToAssistDownloadHelper.exe
2012-07-18 10:03 - 2012-07-18 10:03 - 00113664 ____A C:\Users\Install\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 10:03 - 2012-07-18 10:03 - 00000020 __ASH C:\Users\Install\ntuser.ini
2012-07-18 09:55 - 2011-03-18 08:09 - 00113664 ____A C:\Users\MaryBeth\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 09:54 - 2011-07-06 13:15 - 00113664 ____A C:\Users\frank\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-18 09:53 - 2009-07-13 20:49 - 00422368 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-18 08:06 - 2012-07-18 08:06 - 00103272 ____A C:\Users\frank\GoToAssistDownloadHelper.exe
2012-07-16 07:29 - 2012-01-26 08:04 - 00000036 ___AH C:\Windows\SysWOW64\f9t.dat
2012-07-12 07:59 - 2012-07-12 07:59 - 00318904 ____A (Microsoft Corporation) C:\Users\frank\Downloads\wmpfirefoxplugin.exe
2012-07-12 07:53 - 2012-07-12 07:53 - 00318904 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\wmpfirefoxplugin(1).exe
2012-07-12 07:52 - 2012-07-12 07:52 - 00000195 ____A C:\Users\Rick\Downloads\wmpfirefoxplugin.exe
2012-07-11 00:02 - 2011-02-21 08:49 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-03 10:46 - 2012-08-08 09:32 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-26 13:12 - 2012-06-26 13:12 - 00008467 ____A C:\Users\Rick\Documents\06262012.xls
2012-06-19 10:17 - 2012-06-19 10:17 - 00000000 ___AH C:\Users\Rick\Documents\Default.rdp
2012-06-13 14:32 - 2012-05-25 11:59 - 00011819 ____A C:\Users\nick\Documents\Budget.xlsx
2012-06-11 19:02 - 2012-07-11 00:01 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:30 - 2012-07-10 12:40 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:46 - 2012-07-10 12:40 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 05:39 - 2012-06-08 05:39 - 00026112 ____A C:\Users\frank\Desktop\vacation.oft
2012-06-06 08:31 - 2012-06-06 08:31 - 00741744 ____A (RealVNC Ltd. ) C:\Users\frank\Downloads\vnc-4_1_3-x86_win32.exe
2012-06-05 21:50 - 2012-07-10 12:40 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:50 - 2012-07-10 12:40 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:09 - 2012-07-10 12:40 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:09 - 2012-07-10 12:40 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 10:56 - 2012-06-05 10:55 - 01636224 ____A (Inbox.com, Inc. ) C:\Users\Rick\Downloads\MapsSetup.exe
2012-06-02 14:19 - 2012-06-21 05:05 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 05:05 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 05:05 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 05:05 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 05:05 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 05:05 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 05:05 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 12:19 - 2012-06-21 05:05 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:15 - 2012-06-21 05:05 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-11 00:05 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 00:05 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 00:05 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 00:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 00:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 00:05 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 00:05 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 00:05 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 00:05 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 00:05 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 00:05 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 00:05 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 00:05 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 00:05 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 00:05 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 00:05 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 00:05 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 00:05 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 00:05 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 00:05 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 00:05 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 00:05 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 00:05 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 00:05 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 00:05 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 00:05 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 00:05 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 00:05 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:38 - 2012-07-10 12:40 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:38 - 2012-07-10 12:40 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:37 - 2012-07-10 12:40 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:27 - 2012-07-10 12:40 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:27 - 2012-07-10 12:40 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:48 - 2012-07-10 12:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:48 - 2012-07-10 12:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:47 - 2012-07-10 12:40 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:42 - 2012-07-10 12:40 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 09:25 - 2011-02-21 10:46 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-25 14:19 - 2012-05-25 14:19 - 00009101 ____A C:\Users\Rick\Documents\nate.xlsx
2012-05-14 11:46 - 2012-05-14 11:46 - 00897520 ____A (Dyn, Inc.) C:\Users\frank\Downloads\DynUpSetup.exe
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 6135.23 MB
Available physical RAM: 5413.29 MB
Total Pagefile: 6133.38 MB
Available Pagefile: 5415 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:98.13 GB) (Free:23.01 GB) NTFS
2 Drive e: (Data) (Fixed) (Total:738.97 GB) (Free:687.8 GB) NTFS
3 Drive f: (USB DISK) (Removable) (Total:1.91 GB) (Free:1.91 GB) FAT
4 Drive g: (Iomega HDD) (Fixed) (Total:1863.01 GB) (Free:1734 GB) NTFS
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: () (Fixed) (Total:1 GB) (Free:0.95 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 838 GB 1024 KB
Disk 1 Online 1961 MB 0 B
Disk 2 Online 1863 GB 1024 KB
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1024 MB 1024 KB
Partition 2 Primary 98 GB 1025 MB
Partition 3 Primary 738 GB 99 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y NTFS Partition 1024 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 98 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E Data NTFS Partition 738 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1960 MB 248 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F USB DISK FAT Removable 1960 MB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1863 GB 31 KB
==================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G Iomega HDD NTFS Partition 1863 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-08 15:30
======================= End Of Log ==========================
 
Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.
On Windows XP: Now please boot into the UBCD.
Run FRST/FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Then continue with my reply #11.
 

Attachments

  • fixlist.txt
    21.1 KB · Views: 4
Running back and forth between the server terminal and my laptop to send this info, but when I did try and restart and run a scan, I was getting an error that the MSE could not connect to the update server, even though there was an active network connecction (which has since been disconnected again). Haven't seen if the firewall is still blocked, or windows update, since both of those were giving problems as well.
 
You should be able to operate normally by now.

MSE could have got corrupted.
If it doesn't work properly reinstall it.
 
Ok. posting fixlog first. I'll wait for your reply then try to restart, just to make sure that I don't have to re-run FRST.
 
Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 08-08-2012 02
Ran by SYSTEM at 2012-08-09 12:17:01 Run:2
Running from F:\
==============================================
C:\Windows\System32\services.exe.EB9A1010890AFFEE moved successfully.
C:\Windows\System32\services.exe.72E5362A0BD14F2F moved successfully.
C:\Windows\System32\services.exe.44E5779334A7D83E moved successfully.
C:\Windows\System32\services.exe.C216B261A64DDCBC moved successfully.
C:\Windows\System32\services.exe.D5DCF895404AEBB8 moved successfully.
C:\Windows\System32\services.exe.69C9D721940BD4BF moved successfully.
C:\Windows\System32\services.exe.D82F043A8FEC7CEE moved successfully.
C:\Windows\System32\services.exe.D8F4E0834D8EFEBC moved successfully.
C:\Windows\System32\services.exe.3D38393B1BA7246B moved successfully.
C:\Windows\System32\services.exe.8071CB9A75191EEB moved successfully.
C:\Windows\System32\services.exe.C3011F7E4A785767 moved successfully.
C:\Windows\System32\services.exe.5EC0E1CF8093BB18 moved successfully.
C:\Windows\System32\services.exe.A9555716B5A2BBFD moved successfully.
C:\Windows\System32\services.exe.ECBEDE6FCB51C87C moved successfully.
C:\Windows\System32\services.exe.EBCDD9B8CFE3F464 moved successfully.
C:\Windows\System32\services.exe.5A9CE81858F92C0D moved successfully.
C:\Windows\System32\services.exe.3F0698789F4ECFC9 moved successfully.
C:\Windows\System32\services.exe.18B9A90766DC53F5 moved successfully.
C:\Windows\System32\services.exe.3F76E0F11B73876B moved successfully.
C:\Windows\System32\services.exe.D0844593D2681CF5 moved successfully.
C:\Windows\System32\services.exe.B81A047C03CDC542 moved successfully.
C:\Windows\System32\services.exe.CEEC5D6C4268E8BC moved successfully.
C:\Windows\System32\services.exe.CFD1A50C9191ED21 moved successfully.
C:\Windows\System32\services.exe.290B7DA9EDF03385 moved successfully.
C:\Windows\System32\services.exe.3EC804FF5F0FCB85 moved successfully.
C:\Windows\System32\services.exe.6BAA36DBB942413A moved successfully.
C:\Windows\System32\services.exe.51DEDEC7ECAFFEFC moved successfully.
C:\Windows\System32\services.exe.880FD5B52EDAAB2C moved successfully.
C:\Windows\System32\services.exe.4D2EB03BE6D52EB3 moved successfully.
C:\Windows\System32\services.exe.6E65AE579A6C2D61 moved successfully.
C:\Windows\System32\services.exe.AEDCC9B8D34C361D moved successfully.
C:\Windows\System32\services.exe.A9C2DC445AF4CAA2 moved successfully.
C:\Windows\System32\services.exe.5C621C95988BA64A moved successfully.
C:\Windows\System32\services.exe.C9DFEBD18377C0AC moved successfully.
C:\Windows\System32\services.exe.4CBD7315F69B608B moved successfully.
C:\Windows\System32\services.exe.940A3B643315666D moved successfully.
C:\Windows\System32\services.exe.14E93EEEDAAABB17 moved successfully.
C:\Windows\System32\services.exe.C924DDED6F0FC518 moved successfully.
C:\Windows\System32\services.exe.2343B3FE8036872A moved successfully.
C:\Windows\System32\services.exe.11E81B2BECDB7BC1 moved successfully.
C:\Windows\System32\services.exe.6B261B290D7888CA moved successfully.
C:\Windows\System32\services.exe.9692C5AFDCD11D02 moved successfully.
C:\Windows\System32\services.exe.77291BE6F1228A36 moved successfully.
C:\Windows\System32\services.exe.9E993F14328744BC moved successfully.
C:\Windows\System32\services.exe.7B865B3BC9419F04 moved successfully.
C:\Windows\System32\services.exe.30CAEB12CE87E691 moved successfully.
C:\Windows\System32\services.exe.049F9AF61F17D75C moved successfully.
C:\Windows\System32\services.exe.09123E38065282F7 moved successfully.
C:\Windows\System32\services.exe.876360F33C92B2C5 moved successfully.
C:\Windows\System32\services.exe.A7C527C7A8B6F50B moved successfully.
C:\Windows\System32\services.exe.F1D21B448BF10CBA moved successfully.
C:\Windows\System32\services.exe.0F8E9B38B76A8B0D moved successfully.
C:\Windows\System32\services.exe.129B404282E5AE3C moved successfully.
C:\Windows\System32\services.exe.F2B916F13308CA13 moved successfully.
C:\Windows\System32\services.exe.4BD5DEF9F7587255 moved successfully.
C:\Windows\System32\services.exe.94DDAA4175F314B1 moved successfully.
C:\Windows\System32\services.exe.BC302FB3D17C0642 moved successfully.
C:\Windows\System32\services.exe.DE76FBB01FA45BD3 moved successfully.
C:\Windows\System32\services.exe.4A87AC973177E679 moved successfully.
C:\Windows\System32\services.exe.FCF899EB194B3AD0 moved successfully.
C:\Windows\System32\services.exe.1369A8411769F4CD moved successfully.
C:\Windows\System32\services.exe.D86BF51DC13B8230 moved successfully.
C:\Windows\System32\services.exe.B55066EB6B9EEE95 moved successfully.
C:\Windows\System32\services.exe.87F78F64AC9E978C moved successfully.
C:\Windows\System32\services.exe.46CE1BF2FE39E10B moved successfully.
C:\Windows\System32\services.exe.51E9ECFC90321BD5 moved successfully.
C:\Windows\System32\services.exe.FC3CA10830B61336 moved successfully.
C:\Windows\System32\services.exe.5D35B473D6428979 moved successfully.
C:\Windows\System32\services.exe.A993C76224D14F85 moved successfully.
C:\Windows\System32\services.exe.B530A5047C73A16A moved successfully.
C:\Windows\System32\services.exe.63EAEA5537A808B5 moved successfully.
C:\Windows\System32\services.exe.DD3081176DD59A69 moved successfully.
C:\Windows\System32\services.exe.F73A1B4CE90B2A7D moved successfully.
C:\Windows\System32\services.exe.C1A100BAFEECC053 moved successfully.
C:\Windows\System32\services.exe.711EEA03DCC5BF9F moved successfully.
C:\Windows\System32\services.exe.F091C807FAD0E981 moved successfully.
C:\Windows\System32\services.exe.9698E79E01BEE1D6 moved successfully.
C:\Windows\System32\services.exe.FD0E73D6E48DF2DB moved successfully.
C:\Windows\System32\services.exe.373F4D971A931FA2 moved successfully.
C:\Windows\System32\services.exe.FC02870EA8A73758 moved successfully.
C:\Windows\System32\services.exe.0DDA2AE7A9DE7737 moved successfully.
C:\Windows\System32\services.exe.33C96B1604B8E4FB moved successfully.
C:\Windows\System32\services.exe.24D2F2CA5DC1878C moved successfully.
C:\Windows\System32\services.exe.AAD55A0BD1D3ACB3 moved successfully.
C:\Windows\System32\services.exe.BBB1583714D0E53F moved successfully.
C:\Windows\System32\services.exe.0474DDC0F56A6C98 moved successfully.
C:\Windows\System32\services.exe.3F747776EEE440CA moved successfully.
C:\Windows\System32\services.exe.47A1588EEADC79D9 moved successfully.
C:\Windows\System32\services.exe.CA4A3BC2F6AC12CE moved successfully.
C:\Windows\System32\services.exe.155A2A2B10C655C5 moved successfully.
C:\Windows\System32\services.exe.0879AB483D626932 moved successfully.
C:\Windows\System32\services.exe.10268C8E76D31502 moved successfully.
C:\Windows\System32\services.exe.834B2828FA183CA3 moved successfully.
C:\Windows\System32\services.exe.2142AABD9A6E03D4 moved successfully.
C:\Windows\System32\services.exe.7552E461AB63A6C1 moved successfully.
C:\Windows\System32\services.exe.B6638D582CB5239D moved successfully.
C:\Windows\System32\services.exe.0397A3428D3804D4 moved successfully.
C:\Windows\System32\services.exe.E51DC69051BEA1FC moved successfully.
C:\Windows\System32\services.exe.3069EC68AB2E7B57 moved successfully.
C:\Windows\System32\services.exe.541103CDEEBBC7B1 moved successfully.
C:\Windows\System32\services.exe.00546D2F107C88F6 moved successfully.
C:\Windows\System32\services.exe.59B092850D586002 moved successfully.
C:\Windows\System32\services.exe.88EAA525011D6CD7 moved successfully.
C:\Windows\System32\services.exe.AFE3CD7BE4C6B273 moved successfully.
C:\Windows\System32\services.exe.9AE197152C0B6DBE moved successfully.
C:\Windows\System32\services.exe.7D3C9F9D497408C2 moved successfully.
C:\Windows\System32\services.exe.8169ABF06B61C7DC moved successfully.
C:\Windows\System32\services.exe.E4FA4C6DEC7FA457 moved successfully.
C:\Windows\System32\services.exe.F0206D8736558AF0 moved successfully.
C:\Windows\System32\services.exe.FF294788B62887CD moved successfully.
C:\Windows\System32\services.exe.0D7F729FF837B7E1 moved successfully.
C:\Windows\System32\services.exe.0A702750A1684A1D moved successfully.
C:\Windows\System32\services.exe.6D82152450C119DA moved successfully.
C:\Windows\System32\services.exe.41F7724CB3DB06BB moved successfully.
C:\Windows\System32\services.exe.AB932C6E4E8EE438 moved successfully.
C:\Windows\System32\services.exe.CF6939662C08E42F moved successfully.
C:\Windows\System32\services.exe.84D746227F91ED91 moved successfully.
C:\Windows\System32\services.exe.FFAAB1B4E5F9F605 moved successfully.
C:\Windows\System32\services.exe.92D0F8BF84305E11 moved successfully.
C:\Windows\System32\services.exe.6AB8B992F0731098 moved successfully.
C:\Windows\System32\services.exe.AD6D90A9500B7931 moved successfully.
C:\Windows\System32\services.exe.1850E1E5AA25B05E moved successfully.
C:\Windows\System32\services.exe.95653D6E21D04D7A moved successfully.
C:\Windows\System32\services.exe.8157058AD18E7DAD moved successfully.
C:\Windows\System32\services.exe.A5D50F07DA5C2D33 moved successfully.
C:\Windows\System32\services.exe.F7E07AB1A607A4F6 moved successfully.
C:\Windows\System32\services.exe.CDF585E84251D56D moved successfully.
C:\Windows\System32\services.exe.1C8B1AFF015DD2B2 moved successfully.
C:\Windows\System32\services.exe.4D95452728FAECF1 moved successfully.
C:\Windows\System32\services.exe.E487623797CA617C moved successfully.
C:\Windows\System32\services.exe.CB438F6E0B2FA2B3 moved successfully.
C:\Windows\System32\services.exe.36C674D1EB924FBB moved successfully.
C:\Windows\System32\services.exe.CD82D5E5B3B3F72E moved successfully.
C:\Windows\System32\services.exe.67D4F2D8521EED50 moved successfully.
C:\Windows\System32\services.exe.B33C0521EDC3A884 moved successfully.
C:\Windows\System32\services.exe.1BFB723BACF41163 moved successfully.
C:\Windows\System32\services.exe.E391B3C556D5F42D moved successfully.
C:\Windows\System32\services.exe.A7FE3577CD164308 moved successfully.
C:\Windows\System32\services.exe.8A5C086D4CB27A94 moved successfully.
C:\Windows\System32\services.exe.BFB4D489EC266F59 moved successfully.
C:\Windows\System32\services.exe.E141351D843D5ADB moved successfully.
C:\Windows\System32\services.exe.A851C2C7D67203C9 moved successfully.
C:\Windows\System32\services.exe.A1AC6CA500F0B944 moved successfully.
C:\Windows\System32\services.exe.877CC8F7C0654369 moved successfully.
C:\Windows\System32\services.exe.2ABC066A6CB23ED5 moved successfully.
C:\Windows\System32\services.exe.E9FA810BD61820A5 moved successfully.
C:\Windows\System32\services.exe.D87677A490E90540 moved successfully.
C:\Windows\System32\services.exe.15B43CCED18E1D14 moved successfully.
C:\Windows\System32\services.exe.FEB8266FBFAE7339 moved successfully.
C:\Windows\System32\services.exe.C2D9099DA5002738 moved successfully.
C:\Windows\System32\services.exe.2BACC871F522C30B moved successfully.
C:\Windows\System32\services.exe.8B0AD15D1DF1B2C2 moved successfully.
C:\Windows\System32\services.exe.FB744F045A9AE235 moved successfully.
C:\Windows\System32\services.exe.8AFD3E376FAC7CB2 moved successfully.
C:\Windows\System32\services.exe.6235CC19A79237D3 moved successfully.
C:\Windows\System32\services.exe.0E444BD854315046 moved successfully.
C:\Windows\System32\services.exe.FA421768F2A74BA3 moved successfully.
C:\Windows\System32\services.exe.A83BD7A5E23A315A moved successfully.
C:\Windows\System32\services.exe.5C641E19DDEE2810 moved successfully.
C:\Windows\System32\services.exe.BD1E6FA221046C63 moved successfully.
C:\Windows\System32\services.exe.E190B06FB01BE3D0 moved successfully.
C:\Windows\System32\services.exe.9160897B82EC0185 moved successfully.
C:\Windows\System32\services.exe.6D46D985EE0FDAD1 moved successfully.
C:\Windows\System32\services.exe.1457FD0B1E7100F5 moved successfully.
C:\Windows\System32\services.exe.F1798DADE265F227 moved successfully.
C:\Windows\System32\services.exe.C6A2AF826E71567D moved successfully.
C:\Windows\System32\services.exe.E6079324380AA7FD moved successfully.
C:\Windows\System32\services.exe.7DAC7B56D306001E moved successfully.
C:\Windows\System32\services.exe.74F55DFF4C3A075E moved successfully.
==== End of Fixlog ====
 
Back